Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 5 hours ago

strcpy density in #curl source code

a graph showing the strcpy density in the curl source code, going from above 2 per KLOC in the early 2000s to zero in the end of 2025
a graph showing the strcpy density in the curl source code, going from above 2 per KLOC in the early 2000s to zero in the end of 2025
a graph showing the strcpy density in the curl source code, going from above 2 per KLOC in the early 2000s to zero in the end of 2025
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 18 hours ago

GitHub is a top sponsor of #curl. They make a real difference. Can you say the same about whoever you work for?

Jimmy Sjölund
Jimmy Sjölund
@jimmysjolund@mastodon.social replied  ·  activity timestamp 13 hours ago

@bagder Not sure, I know there was this one time when the employees got to vote for projects to sponsor and #curl was one of them.

  • Copy link
  • Flag this comment
  • Block
hypebot and 1 other boosted
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 18 hours ago

#curl has a new sponsor. Thanks #github!

GitHub SecureOSS-Fund is now sponsoring curl for 3,000 one time.
GitHub SecureOSS-Fund is now sponsoring curl for 3,000 one time.
GitHub SecureOSS-Fund is now sponsoring curl for 3,000 one time.
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 17 hours ago

Number of hackerone reports on #curl doubled since last year

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 18 hours ago

I spent many hours yesterday debunking another hackerone report against #curl.

It's such a good sigh of relief when the ultimate conclusion is that it is not a vulnerability. (disclosed soon of course)

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 18 hours ago

#curl has a new sponsor. Thanks #github!

GitHub SecureOSS-Fund is now sponsoring curl for 3,000 one time.
GitHub SecureOSS-Fund is now sponsoring curl for 3,000 one time.
GitHub SecureOSS-Fund is now sponsoring curl for 3,000 one time.
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 18 hours ago

GitHub is a top sponsor of #curl. They make a real difference. Can you say the same about whoever you work for?

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 18 hours ago

Welcome to #curl 8.18.0-rc3, the third and final release candidate for the pending release:

https://curl.se/mail/lib-2025-12/0035.html

curl: Release candidate 3: curl 8.18.0-rc3

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 18 hours ago

#curl has a new sponsor. Thanks #github!

GitHub SecureOSS-Fund is now sponsoring curl for 3,000 one time.
GitHub SecureOSS-Fund is now sponsoring curl for 3,000 one time.
GitHub SecureOSS-Fund is now sponsoring curl for 3,000 one time.
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg:// boosted
matdevdug
matdevdug
@matdevdug@c.im  ·  activity timestamp 3 days ago

Probably old news but my mind is always blown by all the stuff #curl can do. I had zero idea that curl has a —form argument that lets you simulate filling out a form, complete with a file upload. Let me automate a super annoying task for a friend with a dead simple bash script.

  • Copy link
  • Flag this post
  • Block
matdevdug
matdevdug
@matdevdug@c.im  ·  activity timestamp 3 days ago

Probably old news but my mind is always blown by all the stuff #curl can do. I had zero idea that curl has a —form argument that lets you simulate filling out a form, complete with a file upload. Let me automate a super annoying task for a friend with a dead simple bash script.

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

We are thirteen days from next #curl release.

At 349 merged bugfixes and five(!) pending CVE announcements.

By 62 contributors out of which 30 are commit authors.

https://curl.se/dev/release-notes.html

Release Notes for next curl release

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg:// boosted
Stefan Eissing
Stefan Eissing
@icing@chaos.social  ·  activity timestamp 3 days ago

@cpu @Bubu @kpcyrd Just confirming what @cpu said here. Rustls support in #curl is not going away and we‘ll remove the experimental once rustls declares it API stable.

(and if you want more rustls, there is also https://github.com/icing/mod_tls)

GitHub

GitHub - icing/mod_tls: rustls based TLS for Apache httpd

rustls based TLS for Apache httpd. Contribute to icing/mod_tls development by creating an account on GitHub.
  • Copy link
  • Flag this post
  • Block
Stefan Eissing
Stefan Eissing
@icing@chaos.social  ·  activity timestamp 3 days ago

@cpu @Bubu @kpcyrd Just confirming what @cpu said here. Rustls support in #curl is not going away and we‘ll remove the experimental once rustls declares it API stable.

(and if you want more rustls, there is also https://github.com/icing/mod_tls)

GitHub

GitHub - icing/mod_tls: rustls based TLS for Apache httpd

rustls based TLS for Apache httpd. Contribute to icing/mod_tls development by creating an account on GitHub.
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

I ordered 6,000 new #curl stickers.

  • Copy link
  • Flag this post
  • Block
hypebot boosted
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 5 days ago

I added a sentence to the #curl hackerone submission page:

"Please present your case briefly and to the point. Do not use an AI to help you blab hundreds of lines that will exhaust us to death instead of making us understand your claim."

  • Copy link
  • Flag this post
  • Block
kpcyrd 🏴
kpcyrd 🏴
@kpcyrd@chaos.social  ·  activity timestamp 3 days ago

There's also an curl-rustls Arch Linux package that dynamically links to rustls instead of openssl, however #curl still considers this experimental:

https://archlinux.org/packages/extra/x86_64/curl-rustls/

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg:// boosted
Stefan Eissing
Stefan Eissing
@icing@chaos.social  ·  activity timestamp 5 days ago

Joshua Rogers on his bug bounty experiences in 2025.

Positive for #curl, kafka-esque for all others mentioned. ‚BugCrowd‘ seems to a typical level-1 support company living on denials.

(Joshua also reported on Apache and pbly other projects where he could talk to the maintainers. I take #curl here as an example for FOSS projects interested in actually securing things.)

https://joshua.hu/2025-bug-bounty-stories-fail

Joshua Rogers’ Scribbles

My 2025 Bug Bounty Stories

A recap of my 2025 bug bounty experiences, featuring failures and stories from Google Cloud, GitHub, Vercel, Opera, and others.
  • Copy link
  • Flag this post
  • Block
Esther Payne :bisexual_flag: boosted
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 4 days ago

If you have ideas for a new #curl sticker design, let me know. I'm about to order a new batch soon.

Logo images to play with: https://curl.se/logo/

https://curl.se/logo/
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg:// boosted
Stefan Eissing
Stefan Eissing
@icing@chaos.social  ·  activity timestamp 4 days ago

Microsoft: „1 engineer, 1 month, 1 million lines of code“

That would mean @bagder
rewriting 5 #curl projects into Rust in a month.

Microsoft revising the „rewrite over a weekend“ meme to it actually taking them 6 days. For a person they have not hired yet. With tools they still have to invent.

If you are a MS customer, you‘d better start putting more money into Copilot right away!

https://www.theregister.com/2025/12/24/microsoft_rust_codebase_migration/

Microsoft wants to replace its entire C and C++ codebase

: Plans move to Rust, with help from AI
  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.40 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct