Skip to main content

in reply to daniel:// stenberg://

congrats?

sure hope my tax dollars somehow wind up getting into a software support contract for curl.

in reply to daniel:// stenberg://

I'm disappointed, they didn't even threaten you if you don't comply by <date>. this surely is no proper gov agency!
in reply to daniel:// stenberg://

libcurl is probably in lots of commercial software, and they probably will perform this attestation to keep doing business with the government, never having done due diligence on the thousands of open source libraries they use.

This is a cover-your-ass move on the part of the government, because such attestations don't have any teeth. There's no real plan to secure the software they use, so they do this to say they did something.

This entry was edited (3 months ago)
in reply to daniel:// stenberg://

maybe you should make libcurl start an daemon that fetches and applies updates by it self... what can go wrong.. 😉
in reply to daniel:// stenberg://

The Open Source Polylith thing I work on just got its first GitHub sponsor, and that’s one small step towards getting a Letter like the one you got. A new life goal for me 😁
in reply to daniel:// stenberg://

> If you contact support@wolfssl.com we can remedy this oversight and can then arrange for all the paperwork and attestations you need.

I love that response! :)

in reply to daniel:// stenberg://

Ah yes, because security in software flows naturally from filling out forms. And signing them before a notary.
in reply to Elias Mårtenson

@loke none of the ones prompting me like this has, no. It always seems to me like they're content with just asking...
in reply to daniel:// stenberg://

As someone very familiar with government IT (but not with DOE specifically), my hypothesis is that their developers have to create a record of every piece of software they use. And the system where they enter those records requires a vendor contact email address. And someone, lacking a better email address in their rush to fill out the form, found your email address and used it, not understanding the implications.