github.com/curl/curl/pull/2031…
There, now you know.
BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026 by bagder · Pull Request #20312 · curl/curl
Remove mentions of the bounty and hackerone.GitHub
But your project is big and popular and still will attract a bunch of "contributors" providing low-quality issues and PRs burning your maintenance resources.
First: we have not cut anything, we have a proposal about doing it end of January.
Then: we plan to shut down the curl bug-bounty, which is what pays security researchers for reported confirmed security vulnerabilities. Today we get those reported through Hackerone.
There is no perceived problem in the curl project related to issues or PRs on GitHub and we do not intend to change anything in regards to them at this point.
(cont)
Thank you for clarify that. I thought hackerone is just something like a secondary issue tracker targeting on security issues. Aren't there security issue reports direct on the Microsoft GitHub issue tracker?
Microsoft (GitHub) is sponsoring curl? Give me a number and lets see if we can find an alternative. 😋
> Aren't security issue reports direct on the GitHub tracker?
No. As they need to be kept private until assessed (and possibly dealt with).
> GitHub is sponsoring curl?
Yes.
> Give me a number
North of 10K USD/month.
And this +10K is used for CI, not for your living expenses? The latter is payed by wolfSSL, according to the website?
I think +10K per month might not be a big deal for some other CI companies around. Especially when it is a popular project like curl which they can also use to polish up their image.
Thank you for sharing.
KOMENTÁŘ: Co kdyby začali stávkovat bohatí? ptá se po levicové sabotáži Ivana Tykač - iDNES.cz
Už pár dní diskutuji s kolegy z našeho think tanku Solvo o cíleném žhářském útoku na kabelový most u elektrárny Lichterfelde u Berlína. Jak jsme se dočetli, zaútočili na luxusní čtvrť. Za rozsáhlým výpadkem proudu v Berlíně stojí levicoví extremisté.iDNES.cz
"Všem je nám jasné, že čím větší majetek, tím větší starosti"
Normálně mi ukápla slza. Mají to fakt těžký. 😢
@sesivany Tady si zase na bohatstvi stezuje slechta, neco na tom musi byt 🤔 irozhlas.cz/kultura/televize/k…
"Lidé, kteří mají své úkoly, starosti, rodiny, a že není tak jednoduché se o to starat. Neznamená to, že když to dostanete, tak se stanete boháčem. Naopak, stanete se otrokem."
@zoul
Kinský: Rozrážel jsem dveře a ručil svým jménem. Pokračování Modré krve přitáhlo přes 600 tisíc diváků
Česká televize začala vysílat nové díly série Modrá krev o šlechtických rodinách. „Úplně se změnil vztah lidí k nám. Náhle nejsme nepřátelé,“ říká průvodce cyklem František Kinský.Jan Pokorný (iROZHLAS.cz)
Nicméně tady paní Ivana sedí se svým manželem na podílech ve firmách v hodnotě skoro 200 miliard. Stačilo by jednu tisícinu prodat a život si už jen užívat. Ale ona peníze hromadí a svůj kříž tak nese statečně dál.
Okay, so earlier I saw the announcement of Anthropic's grant/sponsorship/agreement with the PSF.
I had a few thoughts on another thread, but decided to expound my thoughts on my blog.
Caution, there's also a sidequest there which was initially unplanned for, but such is life...
pythonbynight.com/blog/on-the-…
PSF Accepts Anthropic Grant
In spite of the optics, the PSF has the opportunity to put these funds to good use. But I'm also lauding the luddites.Python By Night
🚦 New Auphonic Status Page
We’ve launched a new status page to keep you informed about
✔️ downtimes
✔️ service degradations
✔️ ongoing incidents
Subscribe here to get updates straight to your inbox:
👉 status.auphonic.com/
Auphonic status
Welcome to Auphonic status page for real-time and historical data on system performance.status.auphonic.com
It is our moral imperative to consider the "real world" and actual users when assessing the possible security impact of a reported #curl issue. If we deem that there is likely to be zero affected users, then we do more damage than good by insisting on doing the security dance for the issue.
Then we end up with a severity level that is below LOW, and then we treat it as a bug instead. For the good of mankind.
RE: social.bau-ha.us/@CCC/11589238…
How about we declare June 14 Schengen Day – a day of both celebrating the achievement that is the Schengen Agreement and of protest against border checks.
Politicians – and voters – almost exclusively hear the xenophobic ramblings of the nationalists. We need to change that!
CCC (@CCC@social.bau-ha.us)
It is important that the achievements of Schengen, of free movement in Europe without border control are emphasised. German EU law professor Werner Schroeder decided to sue Germany over illegal controls https://euobserver.com/rule-of-law/ar0dff2b9eCCC (mastodon@bau-ha.us)
"In current political debates the only real winner is the Voyager probe heading away from Earth at 17 kilometres a second."
Guys!
How did they even do this?
Click on this YouTube video on iOS, pay attension to the duration it shows you, then click on the channel and look at the video from there.
Pay attension to what VO says the duration of the video is.
youtube.com/watch?si=jYzYIBhGT…
#YouTube
#LongestVideoEver, maybe?
Viele Politiker kritisieren Elon Musk und X als Plattform für Hass, Desinformation und Radikalisierung – und äußern diese Kritik ausgerechnet dort. Damit stabilisieren sie Reichweite, Relevanz und Geschäftsmodell genau jener Plattform, die sie angeblich ablehnen. Wer X nutzt, füttert den Algorithmus mit Aufmerksamkeit. Konsequente Kritik hieße: X verlassen und Kommunikation dorthin verlagern, wo Debatten nicht durch Empörung monetarisiert werden.
kuketz-blog.de/warum-das-argum…
Warum das Argument, man müsse in sozialen Netzwerken bleiben, um Opposition zu leisten, völliger Unsinn ist
Der Mythos der »notwendigen Opposition« auf Plattformen wie X und TikTok ist eine Illusion: Auseinandersetzungen verstärken Desinformation und fördern das Geschäftsmodell.www.kuketz-blog.de
Nope! Try again.
und das, wo ich für meine Liebe zum #Fediverse hier immer eher belächelt wurde 😍 habt den Tag schön 🍀Edit: Ne, den Insta-Account betreue ich nicht ... das ist nicht mehr meins ... nur ehe jemand fragt

blogs.igalia.com/mrego/servo-2…
Servo 2025 Stats
Some numbers about the evolution of the Servo project and its community during the last years.blogs.igalia.com
We really need a new Internet. How do we help?
torrentfreak.com/italy-fines-c…
Italy Fines Cloudflare €14 Million for Refusing to Block Pirate Sites on Public 1.1.1.1 DNS (Update) * TorrentFreak
AGCOM issued a record-breaking €14.2 million fine on Cloudflare after the company failed to implement the required piracy blocking measures.Ernesto Van der Sar (TF Publishing)
Yay good one! Thank you for you work and yes I too keep compliments in a special folder in my picture files, for trying times.
Also, thru @xr I found some people to whom I can vent whenever necessary. Rebel 4 life ❤️🔥🥰.
TBH that trumps any compliment 🤍
youtu.be/N__AkJriaN4?si=TdYC3p…
FRIENDS 💞
I Have Friends - "Crazy Ex-Girlfriend"
No one can say that I do not have friends.BUY ON ITUNES: https://itunes.apple.com/us/album/i-h...And buy the "Crazy Ex-Girlfriend" Season 1 Volume 1 Soundtra...YouTube
I missed this news..
China’s Tsinghua University helps to break 40-year-old maths cap on computer speed
scmp.com/news/china/science/ar…
China’s Tsinghua University helps to break 40-year-old maths cap on computer speed
Award-winning advance increases network performance, that could mean faster response times for drone navigation, telecoms, disaster evacuation.Dannie Peng (South China Morning Post)
Anyway this evening I hope I can get through the setup process. I have already spend to much time with it yesterday lol, went to bed at 1 AM on a work day.
reshared this
archive.org/details/grimalkin-…
Grimalkin Records VirtualFest '25 : Grimalkin Records, Sihn Starr Cartia : Free Download, Borrow, and Streaming : Internet Archive
Premiered Oct. 18th, 2025Grimalkin Virtual Fest '25 - Oct. 18th, 2025 at 4pm-7pm PT // 7pm-10pm ETJoin us for our virtual music fest starring queer, trans,...Internet Archive
Google Gemini-Powered Siri Will Reportedly Have These 7 New Features
Apple and Google this week announced that Gemini will help power a more personalized Siri, and The Information has provided more details. As soon...Joe Rossignol (MacRumors.com)
Okay so tonight I have to brag. So with Termux, Emacs, and Emacspeak, there were 2 big problems I still had from when I got AI to rig DecTalk up. First, the tone used for "blank line" and indentation was not working. Second, after a while the Emacspeak sounds would stop working even though DecTalk still was.
So, Claude Code, Opus 4.5, fixed the tone issue, something about sox and Termux specific stuff, and made the Emacspeak sounds thing less of an issue than it was. It still happens, but on first launch without putting Termux in the background and such, it stays alive.
The coolest part, I was using Claude Code inside of Termux on the bus going out to eat. And by the time I got home, it was all fixed!
Across the U.S., people are rising up against ICE raids and state violence—and the risks are real.
Peaceful protest is a constitutional right. But this Trump regime has made clear it will not respect that right when power is challenged.
I wrote 13 Rules to Protect Yourself While Protesting to help you stay safe, protect one another, and show up with purpose and clarity as we defend our communities.
Please read & share widely. Our safety depends on each other.
lets-address-this-with-qasim-r…
13 Rules to Protect Yourself While Protesting
Read and share as communities across the United States rise up against ICE raids and state violence Peaceful protest is enshrined in the Bill of Rights.Qasim Rashid (Let's Address This with Qasim Rashid)
- Characters and words (6%, 3 votes)
- Words (24%, 12 votes)
- Nothing (63%, 31 votes)
- Characters (6%, 3 votes)
reshared this
npm i potato. The children components of your potatoes may themselves have components and your potatoes might rapidly look like small tree-like structures of components." I'll...get right on that. Potatoes that look like trees and have children is the one thing all of my projects are missing!feld likes this.
I’m almost disappointed that’s a real package and the name can’t be squatted on.
I've gone through @bce 's product purchase process, including product browsing, configuration, adding to cart, viewing cart, and checkout pages to make sure they are accessible to screen reader users. I've replaced all tables with hierarchical headings, and made sure all inputs are labelled. I'm testing with LibreWolf on Debian with Orca. If any blind users out there could test with their setups and have any feedback, it would be greatly appreciated! Thank you!
Here is the link to the top level products page:
bce.center/products
CC: @jackf723
Note that once this web software is stable, it will be released as FOSS to assist other blind entrepreneurs as well.
#blind #a11y #accessibility #fosh #foss #freehardware #freesoftware
Lars Marowsky-Brée 😷
in reply to daniel:// stenberg:// • • •Edvin Malinovskis
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Edvin Malinovskis • • •JP Mens
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to JP Mens • • •curl - Project status dashboard
curl.seVolker Stolz
in reply to daniel:// stenberg:// • • •Wasn’t 📈exponential growth📈 what every project was hoping to achieve?!
Maybe it should be mandatory that the HackerOne submission must be done with `curl -X PUT … `, including BearerTokens/OAuth etc?