Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

211–220 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#211
post #200
post #187

Earlier quoted context omitted.

A race to the bottom of… unpaid work that eliminates the paid work? Can you elaborate?

Coz just about everyone wants to be that one guy in Nebraska thanklessly maintaining this bit of digital infrastructure, apparently? Yeah me neither. I think the only thing that would convince people to move away from curl at this point would be if curl had a heartbleed level vulnerability and failed to fix it quickly.

Curl is so important that if it had a heartbleed and didn’t patch, someone would and people’d just apply it until it was fixed in tree.

Re: Curl will not accept vulnerability reports during July 2026

#212

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

I wonder how far we are from the agents just maintaining the packages

We have some packages like that, starting with rsync which distributions are having to roll back because it turned into a pile of garbage overnight.

Re: Curl will not accept vulnerability reports during July 2026

#213
post #197

Earlier quoted context omitted.

I think my POV on this is a bit different than what others are expressing… I don’t mind answering the occasional email while on vacation, but I view it as a fair trade - as long as the company doesn’t mind me handling the occasional personal obligation during work hours I don’t mind handling the occasional work obligation during personal hours. If the company wants to be strict about clock in/out hours or taking PTO…

The idea with vacation is that you don't think about work. When I start vacation I disable all the channels that people usually use so that no one asks me even by accident. There needs to be a time when you are completely undisturbed and disconnected. If you are disturbed by work you will think about work while you answer and maybe even after that. That's not good. I also think you should normalize for yourself and y…

I generally work for small companies, and while I'll do something very similar when taking leave (or just at the weekend) I do also make sure someone has contact details for me in the case of anything that truly can't wait until I get back. My experience of doing this has been that people will be judicious about whether something actually warrants interrupting someone's holiday, and it also results in me being less inclined to check in on email/Slack now and again just in case something is up.

Re: Curl will not accept vulnerability reports during July 2026

#214

I read one sentence into this and knew directly that the developer must’ve been Swedish!

For people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break. (See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven... )

This is normal in most countries apart from the contiguous break requirement.

Re: Curl will not accept vulnerability reports during July 2026

#215
post #91

Earlier quoted context omitted.

I've been noticing an unusual number of spuriously dead comments from accounts in good standing for a while now. My suspicion is false positives due to holding back the AI wave yet some of the casualties really don't seem to make any sense.

To be honest I don't think my account is in 100% good standing, but I can't say for certain. There's definitely some dead comments on my account that are deserved and I think there are some small limitations that are or have been placed on it (probably fairly). Mostly around flagging and vouching.

I think that if you get a certain number of comments flagged or downvoted within a certain time window, your account gets flagged as a spammer and has a permanent rate limit applied. Above another threshold, it gets shadowbanned. I think the length of the account's history is also relevant. But https://en.wikipedia.org/wiki/Apophenia

Re: Curl will not accept vulnerability reports during July 2026

#216

Earlier quoted context omitted.

The idea with vacation is that you don't think about work. When I start vacation I disable all the channels that people usually use so that no one asks me even by accident. There needs to be a time when you are completely undisturbed and disconnected. If you are disturbed by work you will think about work while you answer and maybe even after that. That's not good. I also think you should normalize for yourself and y…

I generally work for small companies, and while I'll do something very similar when taking leave (or just at the weekend) I do also make sure someone has contact details for me in the case of anything that truly can't wait until I get back. My experience of doing this has been that people will be judicious about whether something actually warrants interrupting someone's holiday, and it also results in me being less i…

I was the only full time sysadmin of a 20 person company. I went on vacation for three whole weeks. I was half way around the globe and not reachable. The company still existed after I came back. They did have a problem. They tried to reach me. They couldn't. They figured it out by themselves.

I think we believe ourselves to be more irreplaceable than we are. And if you really think you are irreplaceable then the problem is not going on vacation but being irreplaceable. Because then if something were to happen to you they are screwed.

Re: Curl will not accept vulnerability reports during July 2026

#217
post #112
post #54

Earlier quoted context omitted.

Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.

Sweden is fairly unique in allowing the employee to take a 4 week break. Is Australia the same? 2 weeks is the acceptable limit in the UK for example (where also has 20-35 holiday is common) though if you can convince your boss otherwise, you can take longer, but most people can't

In Germany your employer has to grant you two consecutive weeks of vacation by law, and vacation is very rarely denied, even for 3–4 weeks breaks.

Re: Curl will not accept vulnerability reports during July 2026

#218
post #22

Earlier quoted context omitted.

You'd be surprised to learn this about free and open source software, but if a maintainer is unavailable, you have both full rights and full source code to... wait for it... fix it yourself (or pay someone to)! There is something unhealthy in this relationship only if you project "no warranty" into unrealistic expectations.

You don't really though. Sure you can fork it and fix your issue, but then what? Are you going to maintain your fork in perpetuity? Are you going to patch all the software that depends on the code you fixed to use your version instead of upstream? Are you going to get your users to do that too? In most cases this is extremely impractical.

Yes, you can maintain your fork for perpetuity if you can't/will not get your changes upstream. Why is that a problem?

If you're using any complicated FOSS professionally and you have SLA with your customers to say fix issues within day or two you don't have a choice anyway.

Re: Curl will not accept vulnerability reports during July 2026

#219
post #187

Earlier quoted context omitted.

A race to the bottom of… unpaid work that eliminates the paid work? Can you elaborate?

We don’t need to speculate do we, there are tons of real non company run OSS projects Now I personally wish lawyers and plumbers also got into the free work thing but here we are

Plumbers are realistic and don’t live on ideals. They set their rates and set their hours. Lawyers; well if if only people behaved we could have nice things in life, but here we are with people trying to screw each other and misbehave…

Digital assets or work are a bit different in that making a second copy is trivial. It’d be different if every computer in the world were bespoke and needed its own bespoke software. So that makes OSS a viable option for those who can but we also can’t expect everyone to default OSS. We can default to asking that the service and prices be reasonable though.

Re: Curl will not accept vulnerability reports during July 2026

#220
post #197

Earlier quoted context omitted.

I think my POV on this is a bit different than what others are expressing… I don’t mind answering the occasional email while on vacation, but I view it as a fair trade - as long as the company doesn’t mind me handling the occasional personal obligation during work hours I don’t mind handling the occasional work obligation during personal hours. If the company wants to be strict about clock in/out hours or taking PTO…

The idea with vacation is that you don't think about work. When I start vacation I disable all the channels that people usually use so that no one asks me even by accident. There needs to be a time when you are completely undisturbed and disconnected. If you are disturbed by work you will think about work while you answer and maybe even after that. That's not good. I also think you should normalize for yourself and y…

> There needs to be a time when you are completely undisturbed and disconnected. If you are disturbed by work you will think about work while you answer and maybe even after that. That's not good.

IMO this is not a universal truth - I’m sure some people need that level of disconnection, but I don't find I'm one of them. I generally like my job, and don't find that forcing myself to disconnect does me any particular mental good. But other people report needing that separation, and that's fine! I don't think there needs to be a one-size-fits-all answer here.

I do agree with your bus factor argument though.

Post reply on HN