Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

61–70 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#61
post #16
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

As a manager, I will quite literally ding people for working when they are supposed to be off. Work during work time, don't work during not-work time. Good practices mean that everyone is important, but nobody is irreplaceable, the team and the work will move along a little slower, but that's fine.

Being the only dev in a startup since 2 years without a single day off where I wasn't messaged by my employer I want this. At least I'll have a 3 week out of country trip where I do not bring my laptop later this year...

Re: Curl will not accept vulnerability reports during July 2026

#62
post #33

Earlier quoted context omitted.

https://curl.se/libcurl/ Let me Google that for you. supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, MQTTS, POP3, POP3S, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. libcurl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, HTTP/2, HTTP/3, cookies, user+password authentication (Basic, Digest, NTLM, Nego…

I think the argument was that curl is fairly feature complete (as shown by your list), is there really that many bugs in curl that require immediate attention?

Increasingly so, yes.

Re: Curl will not accept vulnerability reports during July 2026

#63
SGTM, if I am worried about a curl exploit, I will type details into Zoo Code prompt and it will disappear in about 30 seconds and then I can upload a PR for others concerned. Enjoy your vacation and I will enjoy security for a lot cheaper than an enterprise contract!

Re: Curl will not accept vulnerability reports during July 2026

#64
post #33

[flagged]

https://curl.se/libcurl/ Let me Google that for you. supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, MQTTS, POP3, POP3S, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. libcurl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, HTTP/2, HTTP/3, cookies, user+password authentication (Basic, Digest, NTLM, Nego…

Linux started removing support for obsolete protocols and hardware

Maybe there is place for a minicurl which removes BeOS and Novell NetWare...

Re: Curl will not accept vulnerability reports during July 2026

#65
post #18
post #3

> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.

Especially since it appears there is a solution if you truly need a fix. > Or you get a support contract and we get to read about it earlier.

> Especially since it appears there is a solution if you truly need a fix.

If you ever really need anything fixed in the open source world, there is always the option of doing it yourself

Re: Curl will not accept vulnerability reports during July 2026

#66

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

I wonder how far we are from the agents just maintaining the packages

Re: Curl will not accept vulnerability reports during July 2026

#67
post #29
post #3

> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.

I worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.

if a company has a problem with this pay for support if its not worth the money …

Re: Curl will not accept vulnerability reports during July 2026

#69

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

> And it surprises - and saddens - me that not even friggin curl has the financial muscles to have somebody on-call for one month...

Is it that they can't or don't want to. I'm sure curl is popular enough that it could attract a co-maintainer if it wanted to. Of course there is a cost to that. Software projects done effectively by a single person are often more focused and designed more coherently. I'm not sure curl would be as good a product if there were multiple maintainers with potentially conflicting visions.

Re: Curl will not accept vulnerability reports during July 2026

#70

Earlier quoted context omitted.

This is the ideal, but in practice you need to own the business to live this way..

Also candy is enjoyable but 24/7 sucking on it is not.

Living your life = sucking on candy?
Post reply on HN