I think this is much healthier approach to AI reports than curl has. But I understand both sides.

OpenSSH don't have the same luxury of being able to ignore potential vulnerabilities.

Curl doesn't ignore vulnerabilities