Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Average number of hours between #curl security reports

Average number of hours between #curl security reports

Scheduled Pinned Locked Moved Uncategorized
curl
18 Posts 8 Posters 4 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.social
    wrote last edited by
    #1

    Average number of hours between #curl security reports

    Material for a pending presentation

    stitzl@mastodon.socialS bagder@mastodon.socialB 2 Replies Last reply
    1
    0
    • bagder@mastodon.socialB bagder@mastodon.social

      Average number of hours between #curl security reports

      Material for a pending presentation

      stitzl@mastodon.socialS This user is from outside of this forum
      stitzl@mastodon.socialS This user is from outside of this forum
      stitzl@mastodon.social
      wrote last edited by
      #2

      @bagder Please correlate with number of security related bugs introduced into codebase per time slice. ๐Ÿ˜…

      icing@chaos.socialI 1 Reply Last reply
      0
      • bagder@mastodon.socialB bagder@mastodon.social

        Average number of hours between #curl security reports

        Material for a pending presentation

        bagder@mastodon.socialB This user is from outside of this forum
        bagder@mastodon.socialB This user is from outside of this forum
        bagder@mastodon.social
        wrote last edited by
        #3

        Share of reports that identified bugs (not vulns)

        Link Preview Image
        felix_eckhardt@det.socialF bagder@mastodon.socialB 2 Replies Last reply
        0
        • stitzl@mastodon.socialS stitzl@mastodon.social

          @bagder Please correlate with number of security related bugs introduced into codebase per time slice. ๐Ÿ˜…

          icing@chaos.socialI This user is from outside of this forum
          icing@chaos.socialI This user is from outside of this forum
          icing@chaos.social
          wrote last edited by
          #4

          @stitzl With this: https://curl.se/dashboard1.html#vulnerabilities-in-releases ?

          /cc @bagder

          stitzl@mastodon.socialS 1 Reply Last reply
          0
          • bagder@mastodon.socialB bagder@mastodon.social

            Share of reports that identified bugs (not vulns)

            Link Preview Image
            felix_eckhardt@det.socialF This user is from outside of this forum
            felix_eckhardt@det.socialF This user is from outside of this forum
            felix_eckhardt@det.social
            wrote last edited by
            #5

            @bagder interesting. Any idea what causes the increased share of reports that identified bugs?

            bagder@mastodon.socialB 1 Reply Last reply
            0
            • bagder@mastodon.socialB bagder@mastodon.social

              Share of reports that identified bugs (not vulns)

              Link Preview Image
              bagder@mastodon.socialB This user is from outside of this forum
              bagder@mastodon.socialB This user is from outside of this forum
              bagder@mastodon.social
              wrote last edited by
              #6

              Confirmed vulnerability rate in reports, year to year so far.

              bagder@mastodon.socialB eliskunk@queer.groupE 2 Replies Last reply
              0
              • felix_eckhardt@det.socialF felix_eckhardt@det.social

                @bagder interesting. Any idea what causes the increased share of reports that identified bugs?

                bagder@mastodon.socialB This user is from outside of this forum
                bagder@mastodon.socialB This user is from outside of this forum
                bagder@mastodon.social
                wrote last edited by
                #7

                @felix_eckhardt improved tooling. AI.

                1 Reply Last reply
                0
                • bagder@mastodon.socialB bagder@mastodon.social

                  Confirmed vulnerability rate in reports, year to year so far.

                  bagder@mastodon.socialB This user is from outside of this forum
                  bagder@mastodon.socialB This user is from outside of this forum
                  bagder@mastodon.social
                  wrote last edited by
                  #8

                  To sum up:

                  Much higher submission rate. Much higher quality reports. More bugs and more vulnerabilities identified.

                  bagder@mastodon.socialB 1 Reply Last reply
                  0
                  • icing@chaos.socialI icing@chaos.social

                    @stitzl With this: https://curl.se/dashboard1.html#vulnerabilities-in-releases ?

                    /cc @bagder

                    stitzl@mastodon.socialS This user is from outside of this forum
                    stitzl@mastodon.socialS This user is from outside of this forum
                    stitzl@mastodon.social
                    wrote last edited by
                    #9

                    @icing Yes, close enough. Awesome! โค๏ธ @bagder

                    1 Reply Last reply
                    0
                    • bagder@mastodon.socialB bagder@mastodon.social

                      To sum up:

                      Much higher submission rate. Much higher quality reports. More bugs and more vulnerabilities identified.

                      bagder@mastodon.socialB This user is from outside of this forum
                      bagder@mastodon.socialB This user is from outside of this forum
                      bagder@mastodon.social
                      wrote last edited by
                      #10

                      also of course: the forecast for 2026 says that we will report a lot of #curl CVEs this year...

                      kura@hai.z0ne.socialK bagder@mastodon.socialB 2 Replies Last reply
                      0
                      • bagder@mastodon.socialB bagder@mastodon.social

                        also of course: the forecast for 2026 says that we will report a lot of #curl CVEs this year...

                        kura@hai.z0ne.socialK This user is from outside of this forum
                        kura@hai.z0ne.socialK This user is from outside of this forum
                        kura@hai.z0ne.social
                        wrote last edited by
                        #11

                        @bagder@mastodon.social at least 365?

                        kura@hai.z0ne.socialK 1 Reply Last reply
                        0
                        • kura@hai.z0ne.socialK kura@hai.z0ne.social

                          @bagder@mastodon.social at least 365?

                          kura@hai.z0ne.socialK This user is from outside of this forum
                          kura@hai.z0ne.socialK This user is from outside of this forum
                          kura@hai.z0ne.social
                          wrote last edited by
                          #12

                          @bagder@mastodon.social oh wait, just one fifth of that

                          1 Reply Last reply
                          0
                          • bagder@mastodon.socialB bagder@mastodon.social

                            also of course: the forecast for 2026 says that we will report a lot of #curl CVEs this year...

                            bagder@mastodon.socialB This user is from outside of this forum
                            bagder@mastodon.socialB This user is from outside of this forum
                            bagder@mastodon.social
                            wrote last edited by
                            #13

                            Oh, and... AI slop rate in submissions has gone back to 2024 levels

                            Link Preview Image
                            by_caballero@mastodon.socialB lukstru@toot.kif.rocksL 2 Replies Last reply
                            0
                            • bagder@mastodon.socialB bagder@mastodon.social

                              Oh, and... AI slop rate in submissions has gone back to 2024 levels

                              Link Preview Image
                              by_caballero@mastodon.socialB This user is from outside of this forum
                              by_caballero@mastodon.socialB This user is from outside of this forum
                              by_caballero@mastodon.social
                              wrote last edited by
                              #14

                              @bagder yaaaaaaay nature is healing

                              1 Reply Last reply
                              0
                              • bagder@mastodon.socialB bagder@mastodon.social

                                Confirmed vulnerability rate in reports, year to year so far.

                                eliskunk@queer.groupE This user is from outside of this forum
                                eliskunk@queer.groupE This user is from outside of this forum
                                eliskunk@queer.group
                                wrote last edited by
                                #15

                                @bagder Vulnerability of what/where/who exactly?

                                bagder@mastodon.socialB 1 Reply Last reply
                                0
                                • eliskunk@queer.groupE eliskunk@queer.group

                                  @bagder Vulnerability of what/where/who exactly?

                                  bagder@mastodon.socialB This user is from outside of this forum
                                  bagder@mastodon.socialB This user is from outside of this forum
                                  bagder@mastodon.social
                                  wrote last edited by
                                  #16

                                  @eliskunk in curl

                                  1 Reply Last reply
                                  0
                                  • bagder@mastodon.socialB bagder@mastodon.social

                                    Oh, and... AI slop rate in submissions has gone back to 2024 levels

                                    Link Preview Image
                                    lukstru@toot.kif.rocksL This user is from outside of this forum
                                    lukstru@toot.kif.rocksL This user is from outside of this forum
                                    lukstru@toot.kif.rocks
                                    wrote last edited by
                                    #17

                                    @bagder do you think itโ€™s because you removed the bug bounty program or because the tools are getting better?

                                    bagder@mastodon.socialB 1 Reply Last reply
                                    0
                                    • lukstru@toot.kif.rocksL lukstru@toot.kif.rocks

                                      @bagder do you think itโ€™s because you removed the bug bounty program or because the tools are getting better?

                                      bagder@mastodon.socialB This user is from outside of this forum
                                      bagder@mastodon.socialB This user is from outside of this forum
                                      bagder@mastodon.social
                                      wrote last edited by
                                      #18

                                      @lukstru since this trend is seen across many projects, we can be fairly sure that nothing we did specifically drives this change

                                      1 Reply Last reply
                                      0
                                      • System shared this topic
                                      Reply
                                      • Reply as topic
                                      Log in to reply
                                      • Oldest to Newest
                                      • Newest to Oldest
                                      • Most Votes


                                      • Login

                                      • Login or register to search.
                                      • First post
                                        Last post
                                      0
                                      • Categories
                                      • Recent
                                      • Tags
                                      • Popular
                                      • World
                                      • Users
                                      • Groups