

Nobody is ignoring anything.
It’s not a license, it’s a policy.
AI tends to “discover” previously discovered vulnerabilities, or obvious vulnerabilities. It also tends to hallucinate vulnerabilities. I’m not saying it’s useless at discovering vulnerabilities, just that a human audit is better.
The policy also doesn’t say you can’t use AI to audit a code base, or even a single diff, so that point is moot.














- The maintainer, probably