> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.
Especially since it appears there is a solution if you truly need a fix. > Or you get a support contract and we get to read about it earlier.
Curl will not accept vulnerability reports during July 2026
71–80 of 326 posts
Re: Curl will not accept vulnerability reports during July 2026
#72For anyone who thinks this might matter for security: * curl is mature enough that the chance of an impactful bug is basically zero * if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co * if there is such a bug, it's more important that it gets patched in package managers and rolled out. Upstream releases can wait.
No, that is the point, they are not going to accept your vuln report. They are taking a holiday.
Re: Curl will not accept vulnerability reports during July 2026
#73For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…
One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…
Re: Curl will not accept vulnerability reports during July 2026
#74[flagged]
Re: Curl will not accept vulnerability reports during July 2026
#75For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…
> Log out of all accounts, remove 2FA keys after backing them up on paper Seems like a lot of extra work, just to go on vacation :) I would suggest another approach. Automate your work, that you can work from your phone. I go on multi day hiking trips, or a week long family beach holidays, without taking PTO... Edit: I do not get negative reactions. Big part of my work is to monitor system, and answer questions. I sp…
Truly disconnecting from our work is necessary for our mental health. When I'm on vacation, I want to be on vacation, which means not working.
Again, maybe you don't want to actually fully be on vacation from work. I guess that's fine; you do you. But I don't think that's healthy for most people, and regardless of health, many people do just want to completely disconnect from work for some number of days.
Re: Curl will not accept vulnerability reports during July 2026
#76Earlier quoted context omitted.
As a manager, I will quite literally ding people for working when they are supposed to be off. Work during work time, don't work during not-work time. Good practices mean that everyone is important, but nobody is irreplaceable, the team and the work will move along a little slower, but that's fine.
Being the only dev in a startup since 2 years without a single day off where I wasn't messaged by my employer I want this. At least I'll have a 3 week out of country trip where I do not bring my laptop later this year...
Real engineers think about handling things when stuff goes wrong, not "everything will be on the happy path forever".
Yes, there are constraints, but to me this sounds like an unacceptable level of exposure.
Re: Curl will not accept vulnerability reports during July 2026
#77as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…
You'd be surprised to learn this about free and open source software, but if a maintainer is unavailable, you have both full rights and full source code to... wait for it... fix it yourself (or pay someone to)! There is something unhealthy in this relationship only if you project "no warranty" into unrealistic expectations.
In most cases this is extremely impractical.
Re: Curl will not accept vulnerability reports during July 2026
#78For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…
> Log out of all accounts, remove 2FA keys after backing them up on paper Seems like a lot of extra work, just to go on vacation :) I would suggest another approach. Automate your work, that you can work from your phone. I go on multi day hiking trips, or a week long family beach holidays, without taking PTO... Edit: I do not get negative reactions. Big part of my work is to monitor system, and answer questions. I sp…
>> Signed: Former workaholic.
> Seems like a lot of extra work, just to go on vacation :)
That's the point, this person and plenty others, are NOT able to "just" go and disconnect. If you can do that, wonderful for you, but please don't assume others are like you precisely when they are humble enough to clarify that they do have a problem and try to help others to overcome it.
Re: Curl will not accept vulnerability reports during July 2026
#79Earlier quoted context omitted.
For people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break. (See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven... )
Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.
Re: Curl will not accept vulnerability reports during July 2026
#80A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)
Just publish early due to a documented lack of cooperation. They don’t have to answer, but you dont have to wait. Naturally some people find that this offensive since this puts a price to that “bliss”.
There's no such thing as "responsible disclosure on a technicality". Don't be a dick, and work in good faith to keep users safe.