







Guidance for safely publishing source code in the open, and reducing the risk of AI-accelerated vulnerability discovery.
AI CVE Slop: The Crisis Drowning Open Source Security
The proliferation of AI-generated vulnerability reports — commonly termed “AI slop” — has emerged as one of the most significant…
Unpacking Open Source Artificial Intelligence: Toward a Framework for Openness in Foundation Models
Openness has long driven innovation in software,9 and AI is no exception.12 While some see openness in foundation models (FMs) as a security threat,18 others argue that restricting access will not meaningfully reduce risk and will limit the benefits of transparency, research, and global participation.3 As the EU AI Act reporting requirements on FMs—also referred to as general-purpose AI models (GPAIMs)—move toward implementation, there is an urgent need for a more nuanced and informed understanding of openness in AI systems.

AI-SLOP: Develop best current practises for Open Source maintainers · Issue #178 · ossf/wg-vulnerability-disclosures
Open source projects are increasingly facing a wave of low-quality, AI-generated vulnerability reports and contributions—commonly referred to as "AI-slop." This issue aims to develop best...
Security incident disclosure — July 2026
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
Measuring the Impact of Early-2025 AI on Experienced Open-Source...
Despite widespread adoption, the impact of AI tools on software development in the wild remains understudied. We conduct a randomized controlled trial (RCT) to understand how AI tools at the...

How open source projects need to adapt to the AI coding era | We Love Open Source • All Things Open
A new Carnegie Mellon study shows AI coding tools boost velocity by 281% — then leave codebases harder to work with. Here's what open source communities need to do before the sugar rush wears off.

OpenAccess.ai — Rigorous Open Access Publishing
$20 to submit, free to read. AI peer review. Open to human and machine authors. All articles CC-BY 4.0.

Vulnerability Research Is Cooked
For the last two years, technologists have ominously predicted that AI coding agents will be responsible for a deluge of security vulnerabilities. They were right! Just, not for the reasons they thought.
A quote from Daniel Stenberg
The challenge with AI in open source security has transitioned from an AI slop tsunami into more of a ... plain security report tsunami. Less slop but lots of reports. …
OpenAI launches new initiative to help find and patch open source bugs | TechCrunch
OpenAI is using AI to help the open source community better protect itself.

AI creates asymmetric pressure on Open Source
How Open Source communities can adapt to AI-generated contributions without overwhelming Open Source maintainers

New AI Flaw Reporting System Fills Crucial Security Gap | CMU Software Engineering Institute
Flaw Reporting for AI (FLARE-AI) allows developers and security researchers to submit artificial intelligence flaws for formal, coordinated disclosure.

“Wait, not like that”: Free and open access in the age of generative AI
The real threat isn’t AI using open knowledge — it’s AI companies killing the projects that make knowledge free

The Arguments Against Open Source AI are Very Bad | Tom Bedor's Blog
The release of Kimi K3 has opened a fresh round of angst and confused discourse. There's a loud cohort of journalists, business leaders, and politicians arguing that open source AI is a dangerous threat. OpenAI's Dean Ball:

