For anyone who thinks this might matter for security: * curl is mature enough that the chance of an impactful bug is basically zero * if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co * if there is such a bug, it's more important that it gets patched in package managers and rolled out. Upstream releases can wait.
> if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co No, that is the point, they are not going to accept your vuln report. They are taking a holiday.
Curl will not accept vulnerability reports during July 2026
81–90 of 326 posts
Re: Curl will not accept vulnerability reports during July 2026
#82Earlier quoted context omitted.
As a manager, I will quite literally ding people for working when they are supposed to be off. Work during work time, don't work during not-work time. Good practices mean that everyone is important, but nobody is irreplaceable, the team and the work will move along a little slower, but that's fine.
Being the only dev in a startup since 2 years without a single day off where I wasn't messaged by my employer I want this. At least I'll have a 3 week out of country trip where I do not bring my laptop later this year...
The only people who should suffer this much are the true busines owners.
Re: Curl will not accept vulnerability reports during July 2026
#83The headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!
Re: Curl will not accept vulnerability reports during July 2026
#84as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…
Re: Curl will not accept vulnerability reports during July 2026
#85Earlier quoted context omitted.
You'd be surprised to learn this about free and open source software, but if a maintainer is unavailable, you have both full rights and full source code to... wait for it... fix it yourself (or pay someone to)! There is something unhealthy in this relationship only if you project "no warranty" into unrealistic expectations.
You don't really though. Sure you can fork it and fix your issue, but then what? Are you going to maintain your fork in perpetuity? Are you going to patch all the software that depends on the code you fixed to use your version instead of upstream? Are you going to get your users to do that too? In most cases this is extremely impractical.
Then you send the patch upstream, they incorporate and maintain it for you. Congratulations, you just FOSSed.
Re: Curl will not accept vulnerability reports during July 2026
#86I read one sentence into this and knew directly that the developer must’ve been Swedish!
Re: Curl will not accept vulnerability reports during July 2026
#87Earlier quoted context omitted.
One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…
Thanks for the reminder that this shouldn't be taken for granted. I am a German and sometimes this privilege feels so normal that it's unthinkable that it could be different elsewhere in the world.
I'd also add that the culture allows and encourages sick days. The average is 15 sick days per year IIRC.
Re: Curl will not accept vulnerability reports during July 2026
#88A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)
Just publish early due to a documented lack of cooperation. They don’t have to answer, but you dont have to wait. Naturally some people find that this offensive since this puts a price to that “bliss”.
Re: Curl will not accept vulnerability reports during July 2026
#89Atlas shrugged, but only for a month. I kid, it's well deserved. I do worry about their contract work loophole - if people disclose vulnerabilities publicly, their clients may pressure them to ship a fix anyway.
Why was this dead?
Re: Curl will not accept vulnerability reports during July 2026
#90Atlas shrugged, but only for a month. I kid, it's well deserved. I do worry about their contract work loophole - if people disclose vulnerabilities publicly, their clients may pressure them to ship a fix anyway.
Why was this dead?