This day 23 years ago, I uploaded the first ever curl release. Happy birthday to all of us who use and appreciate curl. I love you all.
daniel.haxx.se/blog/2021/03/2…
If you are a multi billion dollar company and are concerned about log4j, why not just email OSS authors you never paid anything and demand a response for free within 24 hours with lots of info? (company name redacted for *my* peace of mind)
This company called @Microsoft runs this package manager called @nuget.
They host a curl package there, that was last updated in 2013 and now contains **68** documented vulnerabilities.
But there is apparently no way I can report this or make them act on this.
I keep getting emails from NASA where they request I inform them about curl. They can land on Mars, sure, but I think they have some other issues left to sort out...
Do NOT. I repeat. Do NOT remove curl.exe from your Windows System32 folder to silence a (stupid) security scanner. It will lead to tears and sorrows.
And if you do, please don't ask *me* for help when you've broken your Windows install. I can't fix that.
One of the silicon valley multi-billion dollar companies started donating monthly to curl. 44 USD/month.
Imagine sitting in the meeting where they came to the conclusion that this amount seems about right.