Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

131–140 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#131

A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)

Given that most of those users will not be capable of patching it directly, no, that seems like it would be irresponsible.

Why not? Only a tiny fraction of curl user get it from the upstream website/repo. Most users get curl/libcurl from their OS/application vendor or package manager, all of them having their own maintainers. There is no reason a temporary patch couldn't be produced by them in the meantime.

Re: Curl will not accept vulnerability reports during July 2026

#132
post #43

Earlier quoted context omitted.

>The thing which bugs me is that OpenAI (which is an unprofitable company) is spending around what 100k$ per month for an completely AI generated slop called Openclaw. (All because of Hype) For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop. OpenAI is certainly not wasting the money they're spending on Openclaw, even if I personally wouldn't want to touch that…

> For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop. I can agree with it but I am unsure how much the desperation is out of FOMO or out of real use-cases. Surely curl has more use-cases and projects relying on it than OpenClaw. The demand seems to be generated out of hype rather than sustainability. Openclaw project isn't even an year old and from my time hear…

>I can agree with it but I am unsure how much the desperation is out of FOMO or out of real use-cases.

I frequently run into people using it, they seem happy with it. I remain highly skeptical about this being a good idea, but I'm quite convinced that many people genuinely really like it and find it useful.

Re: Curl will not accept vulnerability reports during July 2026

#133
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

My company have accidentally forced this on me, and it is great. I used to have a desktop that I could VPN+RDC into from my personal laptop or desktop to work away from the office¹. I've now got a laptop, that refuses to let me authenticate remotely and they have no interest in fixing that as there are other priorities, so I simply can't work if I don't have that laptop with me and I'm not carting it around when I'm…

I now want to seek an on site role and request a desktop computer.

Re: Curl will not accept vulnerability reports during July 2026

#134
post #87

Earlier quoted context omitted.

I help immigrants integrate for a living. Germany can be a frustrating country, but this is one of its best redeeming qualities. I'd also add that the culture allows and encourages sick days. The average is 15 sick days per year IIRC.

The average number of sick days used is 15 or the number of days offered? In New Zealand we get a minimum of 10 sick working days per year but some companies offer more and allow unused sick leave to accumulate.

Sick days are not “offered” by employers. Sick days are prescribed by the doctors and there is no upper limit. After all, your sickness will not disappear just because it has been N days. That's at last how it is in Poland.

Re: Curl will not accept vulnerability reports during July 2026

#135

The headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!

I liked the idea as well, maybe OSS should adopt 6 months availability and 6 months for enterprise support schedule. This way both could benefit, OSS gets more funding, enterprise gets support (cheaper than hiring full-time employee for specific OSS)

Until someone races to the bottom to do 12 months of availability.

Re: Curl will not accept vulnerability reports during July 2026

#136
post #87

Earlier quoted context omitted.

I help immigrants integrate for a living. Germany can be a frustrating country, but this is one of its best redeeming qualities. I'd also add that the culture allows and encourages sick days. The average is 15 sick days per year IIRC.

The average number of sick days used is 15 or the number of days offered? In New Zealand we get a minimum of 10 sick working days per year but some companies offer more and allow unused sick leave to accumulate.

You don't have an offered number of sick days in Germany. If you're sick, your sick. At some points (after 6 weeks) the employer stops paying for it, and the payment switches to the health insurance and drops down to 70% of your usual gross salary (with some more specifics).

Re: Curl will not accept vulnerability reports during July 2026

#137
post #54

Earlier quoted context omitted.

Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.

Yeah, but there's little culture of actually taking that time.

I guess our experiences vary - our family had month long adventure vacations most years since the 1970s, and growing up we did a half year tour about the whole country when dad got cumulative long service year.

Re: Curl will not accept vulnerability reports during July 2026

#138

Earlier quoted context omitted.

The average number of sick days used is 15 or the number of days offered? In New Zealand we get a minimum of 10 sick working days per year but some companies offer more and allow unused sick leave to accumulate.

Sick days are not “offered” by employers. Sick days are prescribed by the doctors and there is no upper limit. After all, your sickness will not disappear just because it has been N days. That's at last how it is in Poland.

Sweden has 14 sick days no questions asked before you need a doctors note. The German way of having to call your doctor for a flu note is a little odd to me. You do loose the first day's pay (the meme is that too many people were off sick when there was a world cup finals or something), and then 80% pay.

Re: Curl will not accept vulnerability reports during July 2026

#139
post #112
post #54

Earlier quoted context omitted.

Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.

Sweden is fairly unique in allowing the employee to take a 4 week break. Is Australia the same? 2 weeks is the acceptable limit in the UK for example (where also has 20-35 holiday is common) though if you can convince your boss otherwise, you can take longer, but most people can't

Likely varies by industry - a peer Australian (probably in private IT ?) stated it's uncommon to take a break, whereas I'd say in mining, oil, gas, civil service, police and a good number of structured contract employment its more common.

I've "retired" into agriculture and a lot of farmers take a month off after harvest time to go fishing or other wise relax (this generally means filling up a couple of deep chest freezers with fish for the rest of the year).

Re: Curl will not accept vulnerability reports during July 2026

#140

Earlier quoted context omitted.

I liked the idea as well, maybe OSS should adopt 6 months availability and 6 months for enterprise support schedule. This way both could benefit, OSS gets more funding, enterprise gets support (cheaper than hiring full-time employee for specific OSS)

Until someone races to the bottom to do 12 months of availability.

Races to the bottom to … do work exclusively for free and not make any money out of the hopes that they become the most popular OSS toolkit, with an end goal of … what?
Post reply on HN