I found a bunch of vulnerabilities, which I sent to the maintainer and have now been patched, but some of the most interesting ones I found were that many of these vulnerabilities were actually crafted by (or at least reviewed by) CodeRabbit.
I think there are a lot of reasons to use AI code review tools these days, and no problem with CodeRabbit, but one of the things I've found interesting is a discussion from investors and potential customers about "why would I use a security code reviewer when I have an AI code reviewer in place already". I thought some of the examples here may be interesting for others.