I think this is much healthier approach to AI reports than curl has. But I understand both sides.
OpenSSH don't have the same luxury of being able to ignore potential vulnerabilities.
Curl doesn't ignore vulnerabilities