Damus

Recent Notes

daniel:// stenberg:// profile picture
We are at 9 days to the next #curl release and we have only *three* pending CVEs to announce (two low, one medium).

Three is like nothing!

(Mythos says it can't find any more. Zeropath finds no vulnerabilities. Codex security shows an empty list.)
daniel:// stenberg:// profile picture
Download ten files in parallel from localhost using HTTP/1 over HTTPS, 10 times each - with #curl. Each file is 100MB. Limit the download speed to 5000KB/sec.

How much CPU is "good" to spend on this on a modern intel arch?

Perhaps a median of 2.73% of an i7-13700K core is okay?

https://curl.se/perf/#h1rate-cpu

(the tests run on my local machine, at that single 3.8 spike I probably did something else on the host)

daniel:// stenberg:// profile picture
I've talked to several new #curl customers over the last few weeks who want back-ported security fixes for their older curl releases. To get them secured without having to do a full version upgrade.

Stay tuned for multiple patch releases coming soon for older curl version branches. Shipped under the rock-solid curl umbrella, for paying customers.

If YOU also need a security-fixed older curl release - let's talk!
Michael Boelen · 6d
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqp450apv3j8jmqjct3ddfklzusxyfkkyqpzxx4p33u099xjzvfwwsyh2vzh Is there a name for this nasty action, like command hijacking? I remember when you shared this story and immediately thought about the frustration it must give you. I have a slightly dif...