Search

Items tagged with: curl


I have no less than 72 old (2017 and earlier) #curl security advisories that I want to assign a severity: Low/Medium/High/Critical. It's a very manual labor but here is my initial take that could use more eyes: github.com/curl/curl-www/pull/…
#curl


#curl


#curl


This #curl Friday graph is the "CVE age in code" one refurbished. I cleaned it up a little and added a median plot to it next to the average. Very similar!

The graph shows all 145 curl CVEs and the number of days each of them existing in shipped source code until fixed.

#curl


#curl


My live-streamed #curl release presentation on #twitch starts in a little less than an hour over at twitch.tv/curlhacker


This was the two hundred and nineteenth time I did a #curl release.
#curl


On Tuesday May 30, we will ship #curl 8.1.2 and libssh2 1.11.0
#curl


#curl


It's Friday so I made a new #curl graph. It shows the % share of the vulnerabilities that are "C mistakes" since 2010 - per the date of the findings being reported. The share was 60% of the reported flaws back in 2010, it went down, up and is coming down again and is now at 41.4%

This graph will appear in the regular dashboard starting tomorrow.

#curl


#curl



How many man pages does your project ship? #curl is at 486
#curl


#curl


Tell me, what fun #curl using device is missing from this image?
#curl


#curl is the result of the collected efforts from at least 2,885 named individuals (so far)
#curl


#curl


#curl may be over 25 years old, but look at our amazing authors per month growth over the last 13 years...
#curl


#curl


#curl


#curl


#curl


#curl


#curl


The #curl graph we always get to debate over. Number of *C mistakes* vs *non-C mistakes* among the existing 145 reported vulnerabilities. Updated with the latest 4 reports, and the LOC graph added as a comparison.
#curl


The #curl project has now helped hand out over 60,000 USD in bug-bounties!
#curl


Age of #curl vulnerabilities.

Q: How long did they exist in code until fixed?

A: more than 3,000 days on (all time) average

#curl


#curl


#curl


Join me at 10:00 CEST (UTC +2) for a live-stream presentation of the new #curl release over at
twitch.tv/curlhacker
#curl


#curl


#curl


#curl


This is our best friends. The official #curl sponsors in May 2023.
#curl