github.com/curl/curl/pull/2031…
There, now you know.
BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026 by bagder · Pull Request #20312 · curl/curl
Remove mentions of the bounty and hackerone.GitHub
github.com/curl/curl/pull/2031…
There, now you know.
Remove mentions of the bounty and hackerone.GitHub
greem (Graeme, not Graham)
in reply to daniel:// stenberg:// • • •Good decision.
I don't think it will stop the slop though 😔
daniel:// stenberg://
in reply to greem (Graeme, not Graham) • • •greem (Graeme, not Graham)
in reply to daniel:// stenberg:// • • •Benjamin Balder Bach
in reply to daniel:// stenberg:// • • •thanks for curl! ❤️
did the "bad faith" genre grow with the introduction of AI?
daniel:// stenberg://
in reply to Benjamin Balder Bach • • •Gato Negro
in reply to daniel:// stenberg:// • • •Ingvar
in reply to daniel:// stenberg:// • • •Ben Tasker
in reply to daniel:// stenberg:// • • •Tom Walker
in reply to daniel:// stenberg:// • • •flaxo
in reply to daniel:// stenberg:// • • •Josh Bressers
in reply to daniel:// stenberg:// • • •Jordi Boggiano
in reply to daniel:// stenberg:// • • •I totally understand the move. When running web apps with bounties this has been an issue even before AI as there are so many things of little to no value one can report.
Anyway just saw you'll be at FOSDEM, looking forward to see you rant about sloppy security reporters in person ;)
not Evander Sinque
in reply to daniel:// stenberg:// • • •buhtz
in reply to daniel:// stenberg:// • • •Hello @bagder ,
I wonder if moving to a less crowded code hoster might lower the maintenance burden related to AI crap ?
I am sure you are aware of @Codeberg for example.
At @backintime we also have to deal with low-quality (student) and AI-crap PRs. Moving the project to @Codeberg is one item of my todo list.
For all #foss maintainers I hope we can find a way.
daniel:// stenberg://
in reply to buhtz • • •buhtz
in reply to daniel:// stenberg:// • • •But your project is big and popular and still will attract a bunch of "contributors" providing low-quality issues and PRs burning your maintenance resources.
daniel:// stenberg://
in reply to buhtz • • •First: we have not cut anything, we have a proposal about doing it end of January.
Then: we plan to shut down the curl bug-bounty, which is what pays security researchers for reported confirmed security vulnerabilities. Today we get those reported through Hackerone.
There is no perceived problem in the curl project related to issues or PRs on GitHub and we do not intend to change anything in regards to them at this point.
(cont)
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •buhtz
in reply to daniel:// stenberg:// • • •Thank you for clarify that. I thought hackerone is just something like a secondary issue tracker targeting on security issues. Aren't there security issue reports direct on the Microsoft GitHub issue tracker?
Microsoft (GitHub) is sponsoring curl? Give me a number and lets see if we can find an alternative. 😋
daniel:// stenberg://
in reply to buhtz • • •> Aren't security issue reports direct on the GitHub tracker?
No. As they need to be kept private until assessed (and possibly dealt with).
> GitHub is sponsoring curl?
Yes.
> Give me a number
North of 10K USD/month.
buhtz
in reply to daniel:// stenberg:// • • •And this +10K is used for CI, not for your living expenses? The latter is payed by wolfSSL, according to the website?
I think +10K per month might not be a big deal for some other CI companies around. Especially when it is a popular project like curl which they can also use to polish up their image.
Thank you for sharing.
daniel:// stenberg://
in reply to buhtz • • •> I think
You think.