@dalias curl already does SCP and SFTP with credentials, so that's not really a new problem. But yeah, I don't feel that SSH has a good story for curl.
Thanks for offering to help out and contribute to the curl project.We do have a lack of Windows contributors and developers so all additional help is appreciated!
curl is an Open Source project. No one pays for the Windows version so there is no short-term monetary gain here, and we are not in a position where we are able to pay anyone for this help. Yes, Microsoft has been shipping curl as part of Windows since several years back and yes there are many commercial applications on (cont)
No one in the seven-person curl security team is on or runs Windows. People sending us Windows-only flaws makes us groan and roll eyes. And sometimes hyperventilate a little.
Why this is so? Because no one in the team wants to be on Windows, and no other curl contributor is active enough, Windows-knowledgeable and interested in joining the team. Let me know if you are someone like that who I've just not noticed.
Hey Mozilla, the CVE program made a statement that smells almost directed at you:
"The CVE Program does not support assigning a single CVE ID to multiple distinct vulnerabilities when those vulnerabilities are independently understandable, independently exploitable, independently fixable, or independently relevant to defenders"
As an Open Source person I am apparently expected to keep doing things for free so I get invited to participate in EU policy events in Brussels, with not even an attempt to offer me compensation for travel, lodging or time.
@codingWombat this period of forced calmness has been a true blessing for us and we have truly enjoyed it. We found the fun again. We got the chance to go back to do a lot of things we've been wanting to do for a while.This was possibly our best project decision in a long while.
The kids are alright. From an email I received today:
I am writing to express my huge appreciation for your incredible work and dedication to maintaining curl—one of the most essential building blocks of the modern internet.
I am a 16-year-old IT student from Poland. Inside my home server laboratory, your tool is a vital part of my daily life. Whether I am writing backend web tools, integrating APIs, or creating system automation scripts, curl is always the absolute backbone of my setups.
Today I spotted that musl's inet_ntop() function does not output "::[ipv4]" when asked to output an IPv6 address RFC4291 style. Something both glibc and curl's internal replacements do...
One not too surprising effect of announcing *18* CVEs in one go for #curl tomorrow, is that then all of a sudden the second newest release suddenly contains eighteen known vulnerabilities.
Going back further, the most vulnerable curl release through all time contains 101 known vulnerabilities by tomorrow. That's curl 7.34.0, released in December 2013...