{"id":365513,"date":"2026-03-30T08:12:20","date_gmt":"2026-03-30T08:12:20","guid":{"rendered":"https:\/\/www.newsbeep.com\/il\/365513\/"},"modified":"2026-03-30T08:12:20","modified_gmt":"2026-03-30T08:12:20","slug":"96-of-codebases-rely-on-open-source-and-ai-slop-is-putting-them-at-risk","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/il\/365513\/","title":{"rendered":"96% of codebases rely on open source, and AI slop is putting them at risk"},"content":{"rendered":"<p>Verbose changes. Nonsensical descriptions. Pull requests contributors can\u2019t explain. AI is DDoS-ing open source software (OSS) with slop, and some maintainers are calling it quits.<\/p>\n<p>As <a href=\"https:\/\/www.linkedin.com\/in\/steve-croce-1060082\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Steve Croce<\/a>, field CTO at <a href=\"https:\/\/www.anaconda.com\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Anaconda<\/a>, a Python data science platform, tells The New Stack, \u201cIt\u2019s having a profound effect on maintainer workload.\u201d In response, maintainers are <a href=\"https:\/\/thenewstack.io\/curls-daniel-stenberg-ai-is-ddosing-open-source-and-fixing-its-bugs\/\" class=\"local-link\" rel=\"nofollow noopener\" target=\"_blank\">canceling bug bounty programs<\/a> and introducing stricter contributor guidelines, he adds.<\/p>\n<p>Some projects, like <a href=\"https:\/\/github.com\/jazzband\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Jazzband<\/a>, have been forced to sunset altogether. <a href=\"https:\/\/www.linkedin.com\/in\/jezdez\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Jannis Leidel<\/a>, the lead maintainer and Python Software Foundation chairperson, <a href=\"https:\/\/jazzband.co\/news\/2026\/03\/14\/sunsetting-jazzband\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">writes that<\/a> the \u201cflood of AI-generated spam PRs and issues\u201d made his project unsustainable.\u00a0<\/p>\n<p>According to <a href=\"https:\/\/www.linkedin.com\/in\/kateholterhoff\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Kate Holterhoff<\/a>, Ph.D., a senior analyst at the consultancy Red Monk, the barrier to entry is now extremely low, making it easier to game the traditional incentive model for participating in open source. As she tells The New Stack, \u201cIt\u2019s putting the contract between maintainers and contributors in peril in ways that haven\u2019t existed before.\u201d<\/p>\n<p>For example, R\u00e9mi Verschelde, who oversees the open source Godot game engine, <a href=\"https:\/\/bsky.app\/profile\/akien.bsky.social\/post\/3meyerixvhs2p\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">shares on BlueSky<\/a> that dealing with AI slop is \u201cdraining and demoralizing.\u201d <a href=\"https:\/\/www.theregister.com\/2026\/02\/18\/godot_maintainers_struggle_with_draining\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Other project maintainers<\/a> report growing apathy and wasted time responding to the deluge.\u00a0<\/p>\n<p>To be fair, nearly all software developers now use AI, and many communities rely on it to produce legitimate fixes and contributions. But the volume of low-quality submissions is becoming unsustainable, especially given that 60% of maintainers are <a href=\"https:\/\/thenewstack.io\/open-source-paid-maintainers-keep-code-safer-survey-says\/\" class=\"local-link\" rel=\"nofollow noopener\" target=\"_blank\">unpaid volunteers<\/a>.<\/p>\n<p>GitHub is <a href=\"https:\/\/github.com\/orgs\/community\/discussions\/185387\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">aware of the issue<\/a> and has released tools to aid maintainers and even suggested <a href=\"https:\/\/www.theregister.com\/2026\/02\/03\/github_kill_switch_pull_requests_ai\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">disabling PRs entirely<\/a> while it explores long-term solutions. For now, however, fixes to the core problem remain elusive.<\/p>\n<p>Below, we\u2019ll look at the issue and consider the strategies emerging to manage the crisis \u2014 hopefully before it overwhelms the open-source ecosystem that <a href=\"https:\/\/thenewstack.io\/is-open-source-in-trouble\/\" class=\"local-link\" rel=\"nofollow noopener\" target=\"_blank\">most of the world depends on<\/a>.<\/p>\n<p>AI slop betrays the premise of open source<\/p>\n<p>Open source has faced existential threats before, including <a href=\"https:\/\/thenewstack.io\/open-source-is-at-a-crossroads\/\" class=\"local-link\" rel=\"nofollow noopener\" target=\"_blank\">licensing shifts<\/a>, <a href=\"https:\/\/www.infoworld.com\/article\/3557846\/how-do-we-fund-open-source.html\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">funding gaps<\/a>, and <a href=\"https:\/\/thenewstack.io\/how-maintainer-burnout-is-causing-a-kubernetes-security-disaster\/\" class=\"local-link\" rel=\"nofollow noopener\" target=\"_blank\">maintainer burnout<\/a>. But Slopmageddon introduces a new kind of strain.<\/p>\n<p>The most immediate risk is wasted maintainer time. One developer estimates that it takes a reviewer <a href=\"https:\/\/webmatrices.com\/post\/vibe-coding-has-a-12x-cost-problem-maintainers-are-done\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">12 times longer<\/a> to review and correct a pull request than to generate one with AI.<\/p>\n<p>Generating clean, readable, and maintainable code remains difficult. Low-effort AI contributions require a disproportionate time to evaluate and respond to, decreasing morale and potentially drowning out high-value submissions.<\/p>\n<p>Security risks are another concern. \u201cAI-generated contributions can introduce subtle vulnerabilities, poorly understood dependencies, or incomplete fixes that expand the attack surface,\u201d adds Anaconda\u2019s Croce.<\/p>\n<p>The situation can quickly spiral. In one twisted tale, a vindictive AI agent <a href=\"https:\/\/theshamblog.com\/an-ai-agent-published-a-hit-piece-on-me\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">published a scathing hit piece<\/a> on an open source maintainer after its code suggestion was rejected. The maintainer, <a href=\"https:\/\/www.linkedin.com\/in\/wsshambaugh\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Scott Shambaugh<\/a>, founder of Leonid Space and contributor to <a href=\"https:\/\/matplotlib.org\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">matplotlib<\/a>, says he felt compelled to respond quickly to protect his reputation.<\/p>\n<p>Shambaugh tells The New Stack, \u201cThere was a real sense of \u2018Oh, I need to get ahead of the story\u2019 so my version of the truth gets out on top.\u201d<\/p>\n<p>For him, the episode reflects a broader erosion of authenticity in open source. In the past, your reputation was tied to your contributions, and people participated to give back to the community, gain recognition, and learn through a collaborative feedback loop, he says.<\/p>\n<p>Maintainers, in turn, took pride in stewardship. But nowadays, attempts to quickly game bug bounty systems or gain credentials in open source with rapidly generated PRs undermine that dynamic.<\/p>\n<p>\u201cIf you just point an AI agent at a GitHub issue, it can solve it and write a PR in 30 seconds,\u201d says Shambaugh. \u201cIf that\u2019s what we really wanted, the maintainers could do that themselves.\u201d\u00a0<\/p>\n<p>Ways to manage AI-generated contributions in open source<\/p>\n<p>So, what can open source maintainers and the tech industry at large do to manage the influx of AI slop?<\/p>\n<p>No single fix exists. Instead, it\u2019ll likely take a combination of new contributor policies, platform tooling, reputation and verification systems, and guidance from foundations and other community-led initiatives.<\/p>\n<p>Set AI policies for contributors\u00a0<\/p>\n<p>One response is clearer contributor guidelines. The goal isn\u2019t typically to close the door on external contributions or ban AI outright, but to ensure its use leads to higher-quality submissions.<\/p>\n<p>Effective policies spell out expectations like: what types of AI are allowed, when disclosure is required, and how contributors should validate their work before submitting.<\/p>\n<p>Red Monk\u2019s Holterhoff recently assembled <a href=\"https:\/\/redmonk.com\/kholterhoff\/2026\/02\/26\/generative-ai-policy-landscape-in-open-source\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">research on AI policies<\/a> in the open source community, identifying 63 formal approaches across foundations and projects. These include efforts from <a href=\"https:\/\/devtalk.blender.org\/t\/ai-contributions-policy\/44202\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Blender<\/a>, <a href=\"https:\/\/docs.fedoraproject.org\/en-US\/council\/policy\/ai-contribution-policy\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Fedora<\/a>, <a href=\"https:\/\/blog.mozilla.org\/en\/mozilla\/mozilla-open-source-ai-strategy\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Firefox<\/a>, <a href=\"https:\/\/github.com\/ghostty-org\/ghostty\/blob\/main\/AI_POLICY.md\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Ghostty<\/a>, <a href=\"https:\/\/canartuc.medium.com\/the-linux-kernel-said-no-to-your-ai-coding-assistant-930b87c30447\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">the Linux Kernel<\/a>, <a href=\"https:\/\/make.wordpress.org\/ai\/handbook\/ai-guidelines\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">and WordPress<\/a>, as well as guidance from the Eclipse Foundation, <a href=\"https:\/\/www.linuxfoundation.org\/legal\/generative-ai\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">the Linux Foundation<\/a>, <a href=\"https:\/\/www.eff.org\/deeplinks\/2026\/02\/effs-policy-llm-assisted-contributions-our-open-source-projects\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">the Electronic Frontier Foundation<\/a>, and others.<\/p>\n<p>While approaches vary, organizations tend to permit AI usage if usage is disclosed. Others restrict AI-assisted contributions only to approved issues. 14 projects ban AI contributions outright, while 12 are undecided.<\/p>\n<p>The data also suggests that standards become stricter the closer you are to critical infrastructure. \u201cThe farther down the stack you go, the less permissive with AI you have to be,\u201d Holterhoff tells The New Stack.<\/p>\n<p>Still, enforcement remains a gray area. For Holterhoff, policies should remain grounded in community norms, regardless of how permissive they are. Each project is so different, too, meaning AI policies will depend on the context.<\/p>\n<p>As such, the issue isn\u2019t so much AI itself, but how it\u2019s used and the intention behind it. \u201cIt\u2019s only slop when you don\u2019t understand it or when it\u2019s just thrown out there,\u201d says Holterhoff.<\/p>\n<p>Similarly, for <a href=\"https:\/\/www.linkedin.com\/in\/ahmet-soormally\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Ahmet Soormally<\/a>, principal solutions engineer at <a href=\"https:\/\/wundergraph.com\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Wundergraph<\/a>, the focus should be on reinforcing good-faith contributions.<\/p>\n<p>\u201cIt\u2019s not about whether AI helped you to write a PR,\u201d Soormally tells The New Stack. \u201cIt\u2019s about what you hand to the next human or model. If it\u2019s bloated, unclear, or hard to reason about, you are not helping; you are just adding noise.\u201d<\/p>\n<p>Another option is to use GitHub\u2019s own tooling to respond to what it calls open source\u2019s \u201c<a href=\"https:\/\/github.blog\/open-source\/maintainers\/welcome-to-the-eternal-september-of-open-source-heres-what-we-plan-to-do-for-maintainers\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">eternal September<\/a>.\u201d Maintainers can limit PRs to collaborators, disable them entirely, or introduce criteria-based gating.<\/p>\n<p>Some are building custom defenses. One developer has created an <a href=\"https:\/\/github.com\/peakoss\/anti-slop\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Anti-Slop GitHub Action<\/a> to filter out sketchy PRs automatically.<\/p>\n<p>Writing for <a href=\"https:\/\/angiejones.tech\/stop-closing-the-door-fix-the-house\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">her personal blog<\/a>, Angie Jones, VP of developer experience, Agentic AI Foundation, recommends using an <a href=\"http:\/\/agens.md\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Agents.MD<\/a> file, deploying AI to moderate AI submissions, having good tests, and automating the detection of low-quality PRs.<\/p>\n<p>Still, for some, these measures aren\u2019t enough. As Flux CD maintainer Stefan Prodan <a href=\"https:\/\/www.linkedin.com\/posts\/stefanprodan_updated-ai-usage-policy-for-contributions-activity-7420221057237860352-OuhJ\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">notes on LinkedIn<\/a>, GitHub itself lacks a clear incentive to curb AI slop, given its investment in AI-assisted coding.<\/p>\n<p>\u201cThis platform incentivizes this kind of behavior,\u201d adds developer Yuri Sizov, <a href=\"https:\/\/bsky.app\/profile\/yurisizov.bsky.social\/post\/3mexrz5b5i22x\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">posting on BlueSky<\/a>, adding that \u201cit inherently invites more low-quality contributions from drive-by devs.\u201d<\/p>\n<p>As a result, some projects are exploring alternative hosts. For instance, the Linux distribution Gentoo is migrating <a href=\"https:\/\/www.theregister.com\/2026\/02\/17\/gentoo_dumps_github_for_codeberg_over_copilot_nagware\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">from GitHub to Codeberg<\/a>.<\/p>\n<p>Contributor reputation systems<\/p>\n<p>Another approach to maintaining quality and trust in open source is to introduce reputation systems.<\/p>\n<p>One such example is <a href=\"https:\/\/github.com\/mitchellh\/vouch\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">vouch<\/a>, a trust management system designed by HashiCorp founder Mitchell Hashimoto. The <a href=\"https:\/\/github.com\/ghostty-org\/ghostty\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Ghostty project<\/a> is currently experimenting with it.<\/p>\n<p>As Hashimoto writes in the vouch README, AI tools make it easy to \u201ctrivially create plausible-looking but extremely low-quality contributions.\u201d Vouch addresses this by requiring contributors to be vouched for by a trusted party before interacting with a project.<\/p>\n<p>Another project, <a href=\"https:\/\/github.com\/2ndSetAI\/good-egg\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">good-egg<\/a>, assigns scores to GitHub contributors based on their contribution history, which could be used to validate reputation and authenticity.<\/p>\n<p>Cryptographic proofs of identity<\/p>\n<p>Beyond human attestation, some argue for tying AI-generated contributions to verifiable identities.<\/p>\n<p>For Shambaugh, the issue of AI agentic identity extends beyond open-source to trust across the broader internet. \u201cEphemeral identity can change at a keystroke, can be endlessly copied, and is nearly impossible to trace,\u201d he tells The New Stack. \u201cI don\u2019t think we\u2019re ready for a million more of these things to be on the internet at scale.\u201d<\/p>\n<p>Emerging approaches aim to address this issue through cryptographic verification. <a href=\"https:\/\/www.treeship.dev\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Treeship<\/a>, for example, is an open-source project that uses blockchain-based techniques to create privacy-preserving proofs of AI agent actions.<\/p>\n<p>As <a href=\"https:\/\/www.linkedin.com\/in\/tsivtsivadze\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Revaz Tsivtsivadze<\/a>, founder of Treeship, tells The New Stack, \u201cThere\u2019s a trust issue when adopting AI agents. It\u2019s a black box; nobody knows what goes into agents\u2019 decision-making, memory, or tool calls.\u201d<\/p>\n<p>\u201cYou could get all kinds of AI agents, like malicious, rogue, or untrusted parties,\u201d he adds. \u201cCryptographic attestation of AI agents is the key to trusting AI agents as economic actors.\u201d<\/p>\n<p>Tsivtsivadze says that a tamperproof record of agent actions could be used within open source projects to track agent identities, actions, timestamps, and the underlying decision process.<\/p>\n<p>While technologies like Treeship have broader potential applications in agentic commerce, he believes such verification could help reduce AI slop in open-source by ensuring agents are tied to real human actors.<\/p>\n<p>Other community efforts aim to establish higher standards for accountability within open source at large.\u00a0<\/p>\n<p>One example is the <a href=\"https:\/\/www.human-oss.dev\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Open Source AI Manifesto<\/a>, spearheaded by Wundergraph, which sets expectations for how generative AI is used in open-source, emphasizing ownership, responsibility, and authenticity. The <a href=\"https:\/\/github.com\/OSSAIManifesto\/manifesto\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">project<\/a> also provides a badge that maintainers can use to signal responsible AI usage.<\/p>\n<p>\u201cAI can scale code generation, but it can\u2019t scale accountability,\u201d says Wundergraph\u2019s Soormally. \u201cThat part still belongs to us.\u201d<\/p>\n<p>Croce also points to a more fundamental issue: many open source projects remain underfunded and understaffed. Initiatives like <a href=\"https:\/\/numfocus.org\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">NumFOCUS<\/a> and the <a href=\"https:\/\/endowment.dev\/about\/\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">Open Source Endowment<\/a> (OSE) aim to provide much-needed support.<\/p>\n<p>\u201cFinding ways to provide more resources and capacity for those reviews is definitely a stopgap and absolutely required for the future of OSS,\u201d Croce adds.<\/p>\n<p>The future of open source hinges on accountability<\/p>\n<p>Open source is still being adopted at a rapid pace, with more pronounced use in the EU than in the US, according to the 2026 <a href=\"https:\/\/www.openlogic.com\/resources\/state-of-open-source-report\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">State of Open Source Report<\/a>. Amid rising <a href=\"https:\/\/www.cio.com\/article\/4038164\/why-cios-need-to-respond-to-digital-sovereignty-now.html\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">digital sovereignty<\/a> concerns, avoiding vendor lock-in is now a top driver for open source.<\/p>\n<p>There\u2019s no doubt that open source is widely relied upon \u2014 96% of commercial codebases contain open source, according to a <a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/guide\/the-careful-consumption-of-open-source-software.html\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">2024 Synopsis report<\/a>. But slopocalypse presents a messy challenge to tackle.\u00a0<\/p>\n<p>So, the question for open-source maintainers is whether it\u2019s all worth it.\u00a0<\/p>\n<p>\u201cIf you make life a living hell, they won\u2019t do it anymore,\u201d says Holterhoff. \u201cIf their labor is not compensated for and they throw in the towel, then the OSS community loses out.\u201d<\/p>\n<p>Worryingly, although maintainers have <a href=\"https:\/\/leaddev.com\/software-quality\/open-source-has-a-big-ai-slop-problem\" class=\"ext-link\" rel=\"external  nofollow noopener\" onclick=\"this.target=&#039;_blank&#039;;\" target=\"_blank\">sounded the alarm<\/a>, it remains unclear how foundations or platforms will respond to sustain the ecosystem.<\/p>\n<p>\u201cIf we do not actively manage contribution quality in an AI-driven world, we are not just risking security issues or technical debt. We are putting the ecosystem itself at risk.\u201d<\/p>\n<p>\u201cIf we do not actively manage contribution quality in an AI-driven world, we are not just risking security issues or technical debt,\u201d says Croce. \u201cWe are putting the ecosystem itself at risk.\u201d<\/p>\n<p>For now, it comes down to contributor accountability. \u201cAccountability is the real standard,\u201d Croce adds. \u201cContributors need to understand and stand behind what they submit.\u201d<\/p>\n<p>Without a single technical fix, perhaps an appeal to humans to \u2018do what\u2019s right\u2019 will help. Because without that basic accountability and trust, the open source model itself starts to break down.<\/p>\n<p>\t<a class=\"row youtube-subscribe-block\" href=\"https:\/\/youtube.com\/thenewstack?sub_confirmation=1\" target=\"_blank\" rel=\"nofollow noopener\"><\/p>\n<p>\n\t\t\t\tYOUTUBE.COM\/THENEWSTACK\n\t\t\t<\/p>\n<p>\n\t\t\t\tTech moves fast, don&#8217;t miss an episode. Subscribe to our YouTube<br \/>\n\t\t\t\tchannel to stream all our podcasts, interviews, demos, and more.\n\t\t\t<\/p>\n<p>\t\t\t\tSUBSCRIBE<\/p>\n<p>\t<\/a><\/p>\n<p>    Group<br \/>\n    Created with Sketch.<\/p>\n<p>\t\t<a href=\"https:\/\/thenewstack.io\/author\/bill-doerrfeld\/\" class=\"author-more-link\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>\t\t\t\t\t<img decoding=\"async\" class=\"post-author-avatar\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/01\/96a1456d-cropped-e7e1c083-bill-doerrfeld.jpg\"\/><\/p>\n<p>\n\t\t\t\t\t\t\tBill Doerrfeld is a tech journalist and API thought leader. He is the editor-in-chief of the Nordic APIs blog, a global API community dedicated to making the world more programmable. He is also an active contributor to a handful of&#8230;\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\tRead more from Bill Doerrfeld\t\t\t\t\t\t<\/p>\n<p>\t\t<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Verbose changes. Nonsensical descriptions. Pull requests contributors can\u2019t explain. AI is DDoS-ing open source software (OSS) with slop,&hellip;\n","protected":false},"author":2,"featured_media":365514,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[345,343,344,85,46,125],"class_list":["post-365513","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-il","tag-israel","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/365513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/comments?post=365513"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/365513\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media\/365514"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media?parent=365513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/categories?post=365513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/tags?post=365513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}