Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

281–290 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#281

Earlier quoted context omitted.

Races to the bottom to … do work exclusively for free and not make any money out of the hopes that they become the most popular OSS toolkit, with an end goal of … what?

bait and switch

Xz

Re: Curl will not accept vulnerability reports during July 2026

#282

Earlier quoted context omitted.

Mythos found only one. Would have to be pretty serious bad guys. https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...

Remember though that many other AIs had already run and found issues that were fixed. If you had a time machine and took Mythos back a year it probably would have found a lot more. (if anyone has access to mythos it wouldn't be hard to test - download a release from last year and check)

Imagine the bugs you'd find in curl from five years ago! I bet there are tons!

Re: Curl will not accept vulnerability reports during July 2026

#283
post #187

Earlier quoted context omitted.

A race to the bottom of… unpaid work that eliminates the paid work? Can you elaborate?

We don’t need to speculate do we, there are tons of real non company run OSS projects Now I personally wish lawyers and plumbers also got into the free work thing but here we are

Lawyers have a term for it, pro bono, and they do it for good causes. Turns out they're as human as software engineers.

Re: Curl will not accept vulnerability reports during July 2026

#284
post #259

Why is curl catching so many security issues? I can see something like nginx being in that spot but curl is primarily user initiated and pointed at a known target rather than internet facing accepting connections

It presumably runs in a gazillion scripts.

Re: Curl will not accept vulnerability reports during July 2026

#285

Earlier quoted context omitted.

In America we generally ensure there are multiple people who can do the job. Somebody can go on vacation no nobody will know because the backup is just as good. Every once in a while there is an exception. Then that guy says "If your sending me to Australia I'm going to use my vacation to scuba drive the Great Barrier Reef" - and his body is never found. True story, it took months for someone else to figure out every…

> In America we generally ensure there are multiple people who can do the job. Somebody can go on vacation no nobody will know because the backup is just as good. So every single business, everywhere in American, has at least two full-time employees or at least one other backup that is available when you want to vacation and the stores/businesses never close? I'm guessing the ones that don't have that (if they exists…

I wouldn't say "every single business", there's no universals. But there's a lot of American business owners who basically don't take vacations until they have enough staff to run things in their absence, and American culture in general treats vacations as much less sacrosanct. I usually check Slack every few days when I'm on vacation, in case something's come up I can quickly help with.

Re: Curl will not accept vulnerability reports during July 2026

#286

The headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!

I liked the idea as well, maybe OSS should adopt 6 months availability and 6 months for enterprise support schedule. This way both could benefit, OSS gets more funding, enterprise gets support (cheaper than hiring full-time employee for specific OSS)

nice idea to time vacation in the summar, right around major security conferences (blackhat, defcon, etc), when large bulk of CVEs get published, to put some fire under the enterprise butts

Re: Curl will not accept vulnerability reports during July 2026

#287
post #105
post #50

Earlier quoted context omitted.

Humm he means figure out everything you’re signed in to before going on vacation and log off? Personally I’m sure I’d forget to sign out of something.

No, they don't mean "you should log off everywhere" literally; rather, "don't open Teams/Slack/${our_corporate_chat_software}".

Do these things even close on mobile? I'm pretty sure I'm always on on everything. I'm good at ignoring them though.

Re: Curl will not accept vulnerability reports during July 2026

#288
post #228

Earlier quoted context omitted.

Vacation months*, plural. All project timelines were aligned to wrap up important things by the end of May. June is still operational but mostly focused on reporting, shaping and generally preparing for September when (mostly) everyone will be back, refreshed and ready for new adventures.

Time to start looking for a work visa.

Wait till you figure out what happens around the month of December

Re: Curl will not accept vulnerability reports during July 2026

#290
post #259

Why is curl catching so many security issues? I can see something like nginx being in that spot but curl is primarily user initiated and pointed at a known target rather than internet facing accepting connections

curl isn't more prone to security issues, it's just being talked about more. Daniel has an active blog, is active on social media, and interacts with the community. I don't think the nginx team has that presence, hence if they take a vacation or run mythos on their codebase or have an opinion about AI nobody really knows.
Post reply on HN