The headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!
It's an extremely un-European approach. European companies normally ignore their paid customers too from May to August.
Curl will not accept vulnerability reports during July 2026
111–120 of 326 posts
Re: Curl will not accept vulnerability reports during July 2026
#112Earlier quoted context omitted.
For people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break. (See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven... )
Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.
2 weeks is the acceptable limit in the UK for example (where also has 20-35 holiday is common) though if you can convince your boss otherwise, you can take longer, but most people can't
Re: Curl will not accept vulnerability reports during July 2026
#113> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.
I worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.
Re: Curl will not accept vulnerability reports during July 2026
#114I thought this was due to AI slop spam before I read the blog entry.
Re: Curl will not accept vulnerability reports during July 2026
#115Earlier quoted context omitted.
It can honestly be annoying, if you're not privvy to it. I remember years ago needing urgent support for some bespoke European hardware we were developing software for. When we called support, we were greeted with a phone message stating the company was closed for the entire month due to vacation. This was not a one-man operation; the whole office closed for a summer holiday. We thought it was a joke. Needless to say…
I'm surprised, typically we don't all take vacation at the same time, but stagger it.
I know a handful of companies with a week of mandatory Christmas vacation as well (but there's typically not too many working days between Christmas and New Years' either way).
Re: Curl will not accept vulnerability reports during July 2026
#116Earlier quoted context omitted.
One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…
It can honestly be annoying, if you're not privvy to it. I remember years ago needing urgent support for some bespoke European hardware we were developing software for. When we called support, we were greeted with a phone message stating the company was closed for the entire month due to vacation. This was not a one-man operation; the whole office closed for a summer holiday. We thought it was a joke. Needless to say…
Re: Curl will not accept vulnerability reports during July 2026
#117Earlier quoted context omitted.
One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…
It can honestly be annoying, if you're not privvy to it. I remember years ago needing urgent support for some bespoke European hardware we were developing software for. When we called support, we were greeted with a phone message stating the company was closed for the entire month due to vacation. This was not a one-man operation; the whole office closed for a summer holiday. We thought it was a joke. Needless to say…
Many companies force staff to take vacation days during this time, and there are four (yes four!) public holidays during this period.
Re: Curl will not accept vulnerability reports during July 2026
#118Earlier quoted context omitted.
For people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break. (See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven... )
I work for a UK company and most people take basically all of August off (I end up with two months of vacation days a year so I take August off and sprinkle some leave around the year) and I can confirm that taking a month off is great. You forget what it's like to work, really.
Is this at the executive level?
Re: Curl will not accept vulnerability reports during July 2026
#119> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.
I worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.
In other words, I would always go at full speed (as an evil AI slop model) and most likely never release any findings of flaws and loopholes, so they can be exploited lateron. Bad folks don't want to be caught; remember the xz utils backdoor.
I am sure some AI slop models are used by criminals. And they may exploit things at a later time, but they most likely have found issues already. Not every AI slop model would report.
The notion of "the bad guys will now be more active" is strange really in the AI slop age. (We had the stone age; now we have the slop age)
Re: Curl will not accept vulnerability reports during July 2026
#120Earlier quoted context omitted.
It can honestly be annoying, if you're not privvy to it. I remember years ago needing urgent support for some bespoke European hardware we were developing software for. When we called support, we were greeted with a phone message stating the company was closed for the entire month due to vacation. This was not a one-man operation; the whole office closed for a summer holiday. We thought it was a joke. Needless to say…
I'm surprised, typically we don't all take vacation at the same time, but stagger it.