Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

91–100 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#91

Earlier quoted context omitted.

Why was this dead?

I've been noticing an unusual number of spuriously dead comments from accounts in good standing for a while now. My suspicion is false positives due to holding back the AI wave yet some of the casualties really don't seem to make any sense.

To be honest I don't think my account is in 100% good standing, but I can't say for certain. There's definitely some dead comments on my account that are deserved and I think there are some small limitations that are or have been placed on it (probably fairly). Mostly around flagging and vouching.

Re: Curl will not accept vulnerability reports during July 2026

#92
post #29
post #3

> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.

I worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.

Pretty sure if you find a zero day in a software like that you don’t wait until a certain month.

Re: Curl will not accept vulnerability reports during July 2026

#93
post #43

Earlier quoted context omitted.

The thing which bugs me is that OpenAI (which is an unprofitable company) is spending around what 100k$ per month for an completely AI generated slop called Openclaw. (All because of Hype) I have seen there to be an more influx of open source software as people are starting to create more software with vibe-coding and other things and just open-sourcing it, which while good in OSS'ing it but its mostly less valuable…

>The thing which bugs me is that OpenAI (which is an unprofitable company) is spending around what 100k$ per month for an completely AI generated slop called Openclaw. (All because of Hype) For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop. OpenAI is certainly not wasting the money they're spending on Openclaw, even if I personally wouldn't want to touch that…

> For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop.

I can agree with it but I am unsure how much the desperation is out of FOMO or out of real use-cases.

Surely curl has more use-cases and projects relying on it than OpenClaw.

The demand seems to be generated out of hype rather than sustainability. Openclaw project isn't even an year old and from my time hearing about it, it isn't safe or sustainable in any fashion and it seems that the hype around Openclaw has now started to slow down as I hear less about it (which to me is actually a good thing imo) but it shows what the market reality of these tools currently are (at the moment).

Re: Curl will not accept vulnerability reports during July 2026

#94
post #87

Earlier quoted context omitted.

Thanks for the reminder that this shouldn't be taken for granted. I am a German and sometimes this privilege feels so normal that it's unthinkable that it could be different elsewhere in the world.

I help immigrants integrate for a living. Germany can be a frustrating country, but this is one of its best redeeming qualities. I'd also add that the culture allows and encourages sick days. The average is 15 sick days per year IIRC.

[deleted]

Re: Curl will not accept vulnerability reports during July 2026

#95

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

And I'm assuming you're not going to pay for them to have that someone on-call, even though you're worried about this scenario

Re: Curl will not accept vulnerability reports during July 2026

#96

The headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!

I liked the idea as well, maybe OSS should adopt 6 months availability and 6 months for enterprise support schedule. This way both could benefit, OSS gets more funding, enterprise gets support (cheaper than hiring full-time employee for specific OSS)

Re: Curl will not accept vulnerability reports during July 2026

#97
post #65
post #18

Earlier quoted context omitted.

Especially since it appears there is a solution if you truly need a fix. > Or you get a support contract and we get to read about it earlier.

> Especially since it appears there is a solution if you truly need a fix. If you ever really need anything fixed in the open source world, there is always the option of doing it yourself

Yes - and realistically, if you're $BIGCO who's shipped a billion devices with some obscure curl vulnerability you just discovered, then the hard part is going to be rolling out a patch to all of them anyway, which is still a 'you' problem.

Re: Curl will not accept vulnerability reports during July 2026

#98

Earlier quoted context omitted.

Why was this dead?

I've been noticing an unusual number of spuriously dead comments from accounts in good standing for a while now. My suspicion is false positives due to holding back the AI wave yet some of the casualties really don't seem to make any sense.

Yeah, I have seen several people who are completely shadowbanned (all comments dead) without any visible reason. There seems to be no way to report this.

Re: Curl will not accept vulnerability reports during July 2026

#99
post #87

Earlier quoted context omitted.

Thanks for the reminder that this shouldn't be taken for granted. I am a German and sometimes this privilege feels so normal that it's unthinkable that it could be different elsewhere in the world.

I help immigrants integrate for a living. Germany can be a frustrating country, but this is one of its best redeeming qualities. I'd also add that the culture allows and encourages sick days. The average is 15 sick days per year IIRC.

Totally off-topic, but I read your profile to learn about this: https://allaboutberlin.com - you do awesome work, thank you!

Now I wonder if I could help the immigrants in my area (I'm in Hesse/Hessen), thanks for the inspiration too.

Re: Curl will not accept vulnerability reports during July 2026

#100
post #58
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…

It can honestly be annoying, if you're not privvy to it.

I remember years ago needing urgent support for some bespoke European hardware we were developing software for. When we called support, we were greeted with a phone message stating the company was closed for the entire month due to vacation. This was not a one-man operation; the whole office closed for a summer holiday. We thought it was a joke.

Needless to say we started to look for a new vendor shortly thereafter...

Post reply on HN