They are all getting AI generated bug reports. Hate to say it, but AI is good at finding bugs/vulnerabilities, so most open source projects are heading into triage overload while the technical debt is caught up.
Any open source projects not merging or patching because "AI" discovered it will probably not be a secure place to store your passwords after a while.