26 years ago, on December 28 1999, we migrated the main #curl source code from self-hosted to Sourceforge. It was the new hot thing. Imagine the idea of a dedicated service devoted to nothing but hosting code! We then kept the code there for ten years (on CVS). A period when the distributed version control systems really exploded.
No strcpy either. #curl
*Seven* new hackerone reports the last 36 hours.
strcpy density in #curl source code image
#curl has a new sponsor. Thanks #github! image
I added a sentence to the #curl hackerone submission page: "Please present your case briefly and to the point. Do not use an AI to help you blab hundreds of lines that will exhaust us to death instead of making us understand your claim."
*Twelve* Hackerone submissions against #curl within the last seven days. Zero of them turned out a confirmed vulnerability. Several of them found, reported, phrased-in-far-too-many-words and mislead by stupid word completion machines.
If your company needs #curl support for OpenSSL 1.1 in 2026, just say so and we can have you covered in no time. OpenSSL 1 support is dropped from the regular #curl releases but is available as a commercial offer.
make a photo realistic embroidered wall piece with the words "never expect two independent URL parsers to treat every URL identically" okay, that failed "again without repeating any words" *ripping my eyes out*
This is not working. The number of #hackerone report submissions for #curl in 2025 is going through the roof, while the quality is going through the floor. And the year isn't over yet. image