Contributions have never been higher. That's the problem.
Open source contributions hit records in 2025. In January 2026, four major projects narrowed their doors. Both are true, for the same reason.
August 22, 2026 · updated September 29, 2026

On January 31, 2026, a short commit landed in the curl repository. It deleted a file. The message said the bug bounty program was ending.
curl is one of the internet's quiet foundations. It runs on billions of devices, and for six and a half years it had paid people who found security holes in it. That program is now closed.
Three other projects made similar decisions the same month. The reason was the same in all of them, and it wasn't that contributions had dried up.
Start with the numbers

There's a feeling going around that open source is dying. Everyone uses AI, nobody shares anything, contributions are drying up.
The data says otherwise.
GitHub's 2025 Octoverse report counted 1.12 billion contributions to public repositories, up 13% year over year. 395 million public repos. 518.7 million merged pull requests. All records. March 2025 was the biggest month for new open source contributors in GitHub's history: 255,000 first-timers. Over the year, 36 million developers joined the platform, more than one per second on average.
Contributions have never been higher.
But those metrics count pull requests opened, commits pushed, comments written. They measure volume, not value. And in the first month of 2026, those two came apart.
January 2026
In a single month, four unrelated projects narrowed their doors.

curl shut down a bug bounty program it had run for six and a half years. Ghostty announced that drive-by AI-generated pull requests would get you permanently banned. tldraw switched to auto-closing all external pull requests. And Jazzband, the collective that maintained 84 Python packages, shut down entirely.
Node.js raised its HackerOne signal threshold around the same time. GitHub shipped a platform-level pull request cap in February.
All of them point at the same cause.
The mechanism
It comes down to this:
AI drove the cost of producing a contribution to near zero. It did nothing to the cost of evaluating one.
Bug bounties worked because writing a credible vulnerability report was expensive. You had to read the codebase, form a hypothesis, reproduce the issue. That cost was a filter. Nobody submitted garbage because submitting anything at all was work.
A language model removed the filter. A long, confident, perfectly formatted security report now takes minutes. The maintainer who has to read it and verify it got no such discount. If anything the job got harder, because the text is persuasive.
Measured: AI-generated pull requests take roughly twelve times longer to review than human ones.
A maintainer's hours are fixed. Incoming volume is not.
What curl's numbers show
curl is the best-documented case, because Daniel Stenberg wrote the whole thing down as it happened.
Six and a half years. 87 confirmed vulnerabilities. Over a hundred thousand dollars paid out. The confirmed-vulnerability rate historically ran above 15%.
In 2025 it fell below 5%. By the end of that year Stenberg described the hit rate as roughly one in twenty, sometimes one in thirty.
His own summary: volume goes up, quality goes down, so you spend more time than ever to get less out of it than ever. In July 2025 he'd given the condition a name, "death by a thousand slops."
The last straw came in January 2026. Seven submissions in a sixteen-hour window. Some were real bugs. None were vulnerabilities.
The program closed on January 31. The stated reasoning was practical: the payout was the incentive to submit garbage, so remove the payout.
One more detail worth sitting with. The security team was seven people, and Stenberg wrote plainly that the process was wearing them down. Seven volunteers, reading text nobody had bothered to write.
Not burnout
Calling this burnout undersells it.
Burnout means "I'm exhausted," and the fix is rest. That's not what maintainers are describing. RedMonk's framing gets closer: AI slop is tearing up the social contract between maintainers and contributors.
What made maintenance worth doing was that someone cared enough about your work to try to improve it. Even a bad pull request was a signal of interest. Unreviewed machine output removes that, because you can no longer tell whether anyone is on the other end.
And you can't tell. The Open Source Security Foundation's working group put it flatly: there is no reliable technical indicator for AI-generated content. Detection comes down to maintainer intuition.
Which is why the fixes trend toward subtraction rather than rest. Close, restrict, admit by invitation only.
The other side
It would be easy to turn this into a story about AI killing open source. It would also be wrong, because Stenberg says something else too.
At FOSDEM 2026 he described AI as augmenting humans in both directions. curl has run two AI code analyzers since August 2025, and they've found and fixed over a hundred bugs. The same technology that killed the bug bounty is finding defects in that codebase that no earlier tool caught.
His distinction: a clever person with a powerful tool is not the same thing as a volume of unreviewed output.
There's a second point. At curl the slop hit the bug bounty far harder than it hit pull requests. Stenberg's guess is the project's extensive test coverage, since a PR that fails CI never gets attention in the first place. Good tests turn out to be an accidental slop filter.
And third, these closures have a cost, and it's clear who pays it. Most of the proposed fixes, trust networks, invitation-only contribution, humanness verification, shut out newcomers. For a generation already struggling to break into the industry, open source was one of the doors that stayed open. That door is narrowing.
What broke
Open source rested on something nobody wrote down.
Maintainers spent time reading a stranger's patch because that stranger had spent time writing it. Both sides paid a cost, and the costs were roughly comparable. Even a bad pull request meant something, because writing a bad pull request still took effort.
That symmetry is gone. One side's cost went to zero. The other side's didn't move.
Nobody stopped contributing. What got dropped was the assumption that a contribution has a person behind it who spent time producing it. That's why the doors are narrowing, not indifference.
And the real question for open source over the next few years is probably this: without that assumption, how do you decide to trust a stranger's work?
Sources: GitHub Octoverse 2025 · Daniel Stenberg, "The end of the curl bug bounty" (Jan 26, 2026) and "Death by a thousand slops" (Jul 14, 2025) · RedMonk, "AI Slopageddon and the OSS Maintainers" · OSSF wg-vulnerability-disclosures #178 · The New Stack, FOSDEM 2026
Available languages
