Andreas Kling
It's irresponsible for any security-sensitive OSS project to accept public PRs. AI code review is amazing, but it doesn't solve this. Attackers can keep trying indefinitely under new identities. You have to catch every malicious contribution. They only have to get one through.