Earlier quoted context omitted.
Until someone races to the bottom to do 12 months of availability.
Races to the bottom to … do work exclusively for free and not make any money out of the hopes that they become the most popular OSS toolkit, with an end goal of … what?
Curl will not accept vulnerability reports during July 2026
151–160 of 326 posts
Re: Curl will not accept vulnerability reports during July 2026
#152Earlier quoted context omitted.
I liked the idea as well, maybe OSS should adopt 6 months availability and 6 months for enterprise support schedule. This way both could benefit, OSS gets more funding, enterprise gets support (cheaper than hiring full-time employee for specific OSS)
Until someone races to the bottom to do 12 months of availability.
many engineers actually work that way, right? We are employed for 12 months and give our availability fully to the company and we get salary for it, why isn't it allowed to others?
Re: Curl will not accept vulnerability reports during July 2026
#153Earlier quoted context omitted.
This is the HTTP/1.1 standard: https://datatracker.ietf.org/doc/html/rfc2616 Then there are also HTTP/2 and HTTP/3. That's just HTTP, curl supports 27 other protocols.
HTTP/1.1 - June 1999 It's not like the standard changed since curl was created
Re: Curl will not accept vulnerability reports during July 2026
#154Earlier quoted context omitted.
Sick days are not “offered” by employers. Sick days are prescribed by the doctors and there is no upper limit. After all, your sickness will not disappear just because it has been N days. That's at last how it is in Poland.
Sweden has 14 sick days no questions asked before you need a doctors note. The German way of having to call your doctor for a flu note is a little odd to me. You do loose the first day's pay (the meme is that too many people were off sick when there was a world cup finals or something), and then 80% pay.
And there's an unlimited number of sick days. As long as you have a doctor's note, you still get paid, up to some ridiculous limit at which you might have to get government support instead.
Re: Curl will not accept vulnerability reports during July 2026
#155The headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!
It's an extremely un-European approach. European companies normally ignore their paid customers too from May to August.
Re: Curl will not accept vulnerability reports during July 2026
#156Earlier quoted context omitted.
Until someone races to the bottom to do 12 months of availability.
then it is up to community to fork the project if they find it valuable and can convince people migrating to their fork. many engineers actually work that way, right? We are employed for 12 months and give our availability fully to the company and we get salary for it, why isn't it allowed to others?
Since then a diff of the two projects will be a perfect list of security issues and will make designing an attack rather easy...
Re: Curl will not accept vulnerability reports during July 2026
#157Earlier quoted context omitted.
It's an extremely un-European approach. European companies normally ignore their paid customers too from May to August.
ignore is not the right word.
Re: Curl will not accept vulnerability reports during July 2026
#158If you get sick during vacation, you get those vacation days "refunded" back. If you suddenly are called in to work, somehow, during vacation, that time cannot be vacation time.
You can't (generally) be fired without a notice period, resulting in job security to such a degree that ~6k in an emergency fund is plenty to be VERY secure, as you also get unemployment support otherwise anyway. Does this result in incompetent people not getting fired? No. You still fire them, you just have to deal with them another month after that. It's not a big price to pay.
How is this all possible? Who subsidizes it? We all simply pay some % of our income to support this system. That's it. A couple percent, a couple bucks, and we get to basically never worry about starving or becoming homeless.
You can have this, too, if you vote and protest and use democracy to make life better, not worse, for everyone.
Re: Curl will not accept vulnerability reports during July 2026
#159For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…
Re: Curl will not accept vulnerability reports during July 2026
#160Earlier quoted context omitted.
>> Log out of all accounts, remove 2FA keys after backing them up on paper [...] >> Signed: Former workaholic. > Seems like a lot of extra work, just to go on vacation :) That's the point, this person and plenty others, are NOT able to "just" go and disconnect. If you can do that, wonderful for you, but please don't assume others are like you precisely when they are humble enough to clarify that they do have a proble…
Just not bringing the devices should be enough.
What I was trying to highlight was that HOW depends on whom you are talking to. Here they just mentioned a deep behavior problem. Saying "just" or "simply" or "should" or "ought to" or anything implying it's really not that hard is probably not going to be encouraging to them.