Flood of security patches: Spring Framework ed.

Line chart titled 'Community Security Reports for Spring By Month' showing low, flat counts from July 2025 through January 2026, then a sharp spike up at April 2026 before easing slightly.
Community security reports for Spring, by month.

In April, utilizing new scanning capabilities, we received an unprecedented 482 new security reports across 65 scanned projects. Of those 482 new reports, 370 came from our internal scanning capabilities and 112 came from the community. This means that even without the new scanning, we would still have seen a doubling of community reports compared to our already high number in March. While we clearly had an extreme spike in April’s reports, we do not expect reports to go back down to historic levels for a few months as the influx of AI-based reports continues (May had 72 community reports for example).

🔗 Spring and Security In The Times Of AI