It is probably good general security advice to state that it is not advicable to use open source software that has less than two years of backlog. It's quite too often "an dgentic dump".
I've started to use
arXiv.org to look for open source projects when I need something. GitHub has been "slossed" (is that a word?). So yeah,
arXiv.org is my Github search engine because if few article's reference to a project I have enough heuristical knowledge to considering trying it out :-)
This era reminds me most how factory lines worked in USSR.
If I use AI it is somewhat planned operation or like not anything what is going on right now. Totally different planet.