Why #Curl Shut Down Its Bug Bounty Program w/ Daniel Stenberg
https://youtu.be/9CTwcMcvJ_o
Welcome Martin Dürrmeier as #curl commit author 1454: https://github.com/curl/curl/pull/20933
a map with time zones and vertical bars showing most activity in UTC, UTC+1 and UTC+2
commit time zone distribution in #curl
https://github.com/curl/stats/pull/24
📅 Join us at the #curl distro meeting on March 26!
#EmbeddedSystems daniel:// stenberg:// #libcurl
Commit size distribution graph for curl
Toying with a new #curl graph. Commit size distribution over time. It shows a remarkable stability over the years.
https://github.com/curl/stats/pull/22
Welcome crawfordxx as #curl commit author 1453: https://github.com/curl/curl/pull/20923
One hundred #curl graphs
daniel.haxx.se/blog/2026/03/15/one-hund...
The graph showing number of graphs
Some of you will be glad to know that the #curl dashboard now features the "graphs in the dashboard" graph
https://curl.se/dashboard1.html#graphs-on-the-dashboard
🛠️ Practical guide to quantum-resistant TLS is here.
Hybrid ECC + post-quantum certs. X9.146 Chimera certificates. Real demos with #curl & nginx.
See how migrated & unmigrated systems coexist during the transition. 🔀
🎥 Watch now → youtu.be/20dpnrl7bV0...
#PQC #TLS #postquantum
PlaneAlert ICAO: 5083A2 Tail: URCQD Flt: VKA902
Owner: VulkanAir
Aircraft: Antonov An-26 B
2026-03-14 15:39:10 CET
AN26 GotItWhereItCounts Budmo Curl
adsb planefence planealert by kx1t - link
the repository name changed (because more architectures supported now) , but #cURL 8.19 is up for #SailfishOS
Arm: repo.sailfishos.org/obs/home:/nielnielsen/sa...
Aaarch64 […]
In two weeks we run the #curl distro meeting. You are invited!
daniel.haxx.se/blog/2026/01/28/curl-dis...
Is there any reason, why `curl` lists an example in their `--header` section as follows:
curl -H "User-Agent: yes-please/2000" https://example.com
Is there someone a #Jazz fan, or is it some other kind of a pun? 🤔
#foss #OpenSource #curl #manpage #unix
chicken nuget
Insecure #curl packages hosted by Microsoft. They think it's fine.
https://daniel.haxx.se/blog/2026/03/12/chicken-nuget/
vulnerability age in curl
CVE-2026-3784 beat a new #curl record. This flaw existed in curl source code for 24.97 years before it was discovered.
Illustrated in the slightly hard-to-read graph below. The average age of a curl vulnerability when reported is eight years.
https://curl.se/docs/CVE-2026-3784.html
Welcome Vladimír Marek as #curl commit author 1452: https://github.com/curl/curl/pull/20885
To avoid confuse, download it and change the extension from .xz to .tar.xz and extract it. Or, you can use one of those command below to download (for Linux user).
```sh
#wget
wget -O pyongyang_racer_sources.tar.xz " […]
The live-streamed video presentation about this #curl release starts in less than two hours at https://www.twitch.tv/curlhacker
Welcome to #curl 8.19.0
https://daniel.haxx.se/blog/2026/03/11/curl-8-19-0/
8 changes, 4 vulnerabilities and 264 bugs fixed. Enjoy!
(The 4 new CVEs are explained in follow-up toots.)
Code style Banned functions Complexity checks Human reviews Review bots No binary blobs No confusables Document everything Many tests Cl like crazy All the picky compiler options and -Werror Valgrind and sanitizers Static code analyzers Fuzzing (in Cl and non-stop) Cl jobs never “write back" Reproducible releases Signed releases, commits, tags code audits 2fa for all committers
Ahead of tomorrows release of four new #curl CVEs I want you to know: we do our very best to secure curl every step of the way. Security is hard.
The end of the release cycle is really the peak. When a full cycle's worth of work and efforts are combined into a fresh tarball that is sent out into the cold harsh real world with the ideal outcome that everything just keeps on working exactly like before, ideally a little better.
The night […]
All details about the new #curl release will be live-streamed as usual, at 09:00 UTC (10:00 CET) tomorrow.
https://www.twitch.tv/curlhacker
24 hours to #curl release
shows one (single) package that depends on the curl repository
An amusing and telling picture that shows how dependency tracking for #curl and libcurl does not work at all, is to check out GitHub's view of all repositories that depend on curl.
I mean, there are quite a few repositories on there, so the number could be high.
Or it could be... one.
10K #curl downloads per year
daniel.haxx.se/blog/2026/03/09/10k-curl...
10K curl downloads per year The Linux Foundation, the organization that we want to love but that so often makes that a hard bargain, has created something they call “Insights” where they gather...
#cURL #and #libcurl
Origin | Interest | Match
#curl was download 10,467 times last year according to Linux Foundation
😂
insights.linuxfoundation.org/project/curl/repository/...
#curl is at 60% quality accordingly
insights.linuxfoundation.org/project/curl/repository/...
Welcome huanghuihui0904 as #curl commit author 1450: https://github.com/curl/curl/pull/20862