AI-generated security reports, Linux Foundation funding, vulnerability disclosure policy converge as projects face spam; OpenSSF, OSTIF detail triage steps.