89 days into the year, the #curl project has received 72 security reports on Hackerone and ten additional ones over other channels. Close to one a day on average.

Compared to 2024, this is roughly 4x the volume.

The "obviously AI slop" rate has drastically gone down but the rate of actual vulnerabilities is below 10%.

We continue to spend a significant amount of time and effort on security.

and as a reminder, we keep disclosing every report we close (except the spam ones)
@bagder I wouldn't be against a feed of spam ones, just so the crap is public.