A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)
Given that most of those users will not be capable of patching it directly, no, that seems like it would be irresponsible.
Curl will not accept vulnerability reports during July 2026
131–140 of 326 posts
Re: Curl will not accept vulnerability reports during July 2026
#132Earlier quoted context omitted.
>The thing which bugs me is that OpenAI (which is an unprofitable company) is spending around what 100k$ per month for an completely AI generated slop called Openclaw. (All because of Hype) For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop. OpenAI is certainly not wasting the money they're spending on Openclaw, even if I personally wouldn't want to touch that…
> For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop. I can agree with it but I am unsure how much the desperation is out of FOMO or out of real use-cases. Surely curl has more use-cases and projects relying on it than OpenClaw. The demand seems to be generated out of hype rather than sustainability. Openclaw project isn't even an year old and from my time hear…
I frequently run into people using it, they seem happy with it. I remain highly skeptical about this being a good idea, but I'm quite convinced that many people genuinely really like it and find it useful.
Re: Curl will not accept vulnerability reports during July 2026
#133For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…
My company have accidentally forced this on me, and it is great. I used to have a desktop that I could VPN+RDC into from my personal laptop or desktop to work away from the office¹. I've now got a laptop, that refuses to let me authenticate remotely and they have no interest in fixing that as there are other priorities, so I simply can't work if I don't have that laptop with me and I'm not carting it around when I'm…
Re: Curl will not accept vulnerability reports during July 2026
#134Earlier quoted context omitted.
I help immigrants integrate for a living. Germany can be a frustrating country, but this is one of its best redeeming qualities. I'd also add that the culture allows and encourages sick days. The average is 15 sick days per year IIRC.
The average number of sick days used is 15 or the number of days offered? In New Zealand we get a minimum of 10 sick working days per year but some companies offer more and allow unused sick leave to accumulate.
Re: Curl will not accept vulnerability reports during July 2026
#135The headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!
I liked the idea as well, maybe OSS should adopt 6 months availability and 6 months for enterprise support schedule. This way both could benefit, OSS gets more funding, enterprise gets support (cheaper than hiring full-time employee for specific OSS)
Re: Curl will not accept vulnerability reports during July 2026
#136Earlier quoted context omitted.
I help immigrants integrate for a living. Germany can be a frustrating country, but this is one of its best redeeming qualities. I'd also add that the culture allows and encourages sick days. The average is 15 sick days per year IIRC.
The average number of sick days used is 15 or the number of days offered? In New Zealand we get a minimum of 10 sick working days per year but some companies offer more and allow unused sick leave to accumulate.
Re: Curl will not accept vulnerability reports during July 2026
#137Earlier quoted context omitted.
Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.
Yeah, but there's little culture of actually taking that time.
Re: Curl will not accept vulnerability reports during July 2026
#138Earlier quoted context omitted.
The average number of sick days used is 15 or the number of days offered? In New Zealand we get a minimum of 10 sick working days per year but some companies offer more and allow unused sick leave to accumulate.
Sick days are not “offered” by employers. Sick days are prescribed by the doctors and there is no upper limit. After all, your sickness will not disappear just because it has been N days. That's at last how it is in Poland.
Re: Curl will not accept vulnerability reports during July 2026
#139Earlier quoted context omitted.
Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.
Sweden is fairly unique in allowing the employee to take a 4 week break. Is Australia the same? 2 weeks is the acceptable limit in the UK for example (where also has 20-35 holiday is common) though if you can convince your boss otherwise, you can take longer, but most people can't
I've "retired" into agriculture and a lot of farmers take a month off after harvest time to go fishing or other wise relax (this generally means filling up a couple of deep chest freezers with fish for the rest of the year).
Re: Curl will not accept vulnerability reports during July 2026
#140Earlier quoted context omitted.
I liked the idea as well, maybe OSS should adopt 6 months availability and 6 months for enterprise support schedule. This way both could benefit, OSS gets more funding, enterprise gets support (cheaper than hiring full-time employee for specific OSS)
Until someone races to the bottom to do 12 months of availability.