frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Your ePub Is fine

https://andreklein.net/your-epub-is-fine-kobo-disagrees-blame-adobe/
519•sohkamyung•9h ago•182 comments

Curl will not accept vulnerability reports during July 2026

https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/
280•secret-noun•1h ago•71 comments

Even more batteries included with Emacs

https://karthinks.com/software/even-more-batteries-included-with-emacs/
162•signa11•5h ago•30 comments

Apple Foundation Models

https://platform.claude.com/docs/en/cli-sdks-libraries/libraries/apple-foundation-models
53•MehrdadKhnzd•3h ago•10 comments

Show HN: Kage – Shadow any website to a single binary for offline viewing

https://github.com/tamnd/kage
539•tamnd•14h ago•108 comments

Bitsy

https://bitsy.org/
170•tosh•3d ago•4 comments

There Is(Ǝ) – Such That (∋)

https://www.fractalkitty.com/there-is-3-such-that/
15•evakhoury•3d ago•3 comments

Dalus (YC W25) Is Hiring a Senior Software Engineer in Germany

https://www.ycombinator.com/companies/dalus/jobs/5IDmKJt-senior-software-frontend-engineer-german...
1•sebastianvoelkl•58m ago

Firewood Splitting Simulator

https://screen.toys/firewood/
785•memalign•5d ago•239 comments

The Last Surviving Japanese Porsche 912 Police Car

https://kottke.org/26/06/the-last-surviving-japanese-porsche-912-police-car
69•zdw•2d ago•17 comments

21 years and counting of 'eight fallacies of distributed computing' (2025)

https://blog.apnic.net/2025/12/08/21-years-and-counting-of-eight-fallacies-of-distributed-computing/
68•teleforce•7h ago•14 comments

Why does paper fold so well?

https://www.bbc.co.uk/programmes/w3ct8k70
32•zeristor•1d ago•7 comments

Rio de Janeiro's "homegrown" LLM appears to be a merge of an existing model

https://github.com/nex-agi/Nex-N2/issues/4
336•unrvl22•16h ago•182 comments

Under-16s to be banned from social media, Starmer announces

https://www.bbc.co.uk/news/live/c77yx1jpg1nt
14•petepete•39m ago•1 comments

A short history of Cerro Torre, the most controversial mountain (2012)

https://www.markhorrell.com/blog/2012/a-short-history-of-cerro-torre/
33•joebig•4d ago•13 comments

Ask HN: What are you working on? (June 2026)

217•david927•15h ago•777 comments

Show HN: Trace – Offline Mac meeting transcripts you can flag mid-call

https://traceapp.info
152•AG342•1d ago•55 comments

Formal methods and the future of programming

https://blog.janestreet.com/formal-methods-at-jane-street-index/?from_theconsensus=1
250•eatonphil•19h ago•91 comments

Chaosnet (1981)

https://tumbleweed.nu/r/lm-3/uv/amber.html
81•RGBCube•12h ago•9 comments

Windows 11 users are tired of MS account requirements creeping into everything

https://www.windowscentral.com/microsoft/windows-11/windows-11-users-are-tired-of-microsoft-accou...
285•josephcsible•10h ago•187 comments

TorchCodec 0.14: HDR Video Decoding for CPU and CUDA, and Fast Wav Decoder

https://github.com/meta-pytorch/torchcodec/releases/tag/v0.14.0
42•scott_s•4d ago•5 comments

Caddy compatibility for zeroserve: 3x throughput and 70% lower latency

https://su3.io/posts/zeroserve-caddy-compat
178•losfair•18h ago•52 comments

The only scalable delete in Postgres is DROP TABLE

https://planetscale.com/blog/the-only-scalable-delete
161•hollylawly•3d ago•58 comments

Perlisisms (1982)

https://www.cs.yale.edu/homes/perlis-alan/quotes.html
110•tosh•17h ago•56 comments

Show HN: Discover Wikipedia articles popular on Hacker News

https://www.orangecrumbs.com/
100•octopus143•14h ago•25 comments

Write for One Person

https://wizardzines.com/comics/write-for-one-person/
196•evakhoury•2d ago•64 comments

Segmented type appreciation corner (2018)

https://aresluna.org/segmented-type/
71•unexpectedVCR•3d ago•16 comments

Prove you're human by winning a claw machine

https://feralui.vercel.app/#/captcha
62•speckx•2d ago•44 comments

How to earn a billion dollars

https://paulgraham.com/earn.html
609•kingstoned•20h ago•1608 comments

I indexed 669 GB of my GoPro videos using my M1 Max computer and local ML models

364•iliashad•16h ago•88 comments
Open in hackernews

Curl will not accept vulnerability reports during July 2026

https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/
269•secret-noun•1h ago

Comments

a13n•1h ago
what a fantastic advertisement
zarzavat•1h ago
> > The bad guys won’t rest

> Probably not. But we will.

A pleasant dose of humanity in decidedly inhuman times.

donw•1h ago
That was just a beautiful, period.
Timshel•1h ago
Especially since it appears there is a solution if you truly need a fix.

> Or you get a support contract and we get to read about it earlier.

bawolff•9m ago
> Especially since it appears there is a solution if you truly need a fix.

If you ever really need anything fixed in the open source world, there is always the option of doing it yourself

Natsu•1h ago
I worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.
Cider9986•29m ago
Mythos found only one. Would have to be pretty serious bad guys.

https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...

bvcp•6m ago
if a company has a problem with this pay for support if its not worth the money …
ubanholzer•1h ago
This is great. Good decision.
vortegne•1h ago
Wish them nothing but good rest!
maxbond•1h ago
Atlas shrugged, but only for a month. I kid, it's well deserved. I do worry about their contract work loophole - if people disclose vulnerabilities publicly, their clients may pressure them to ship a fix anyway.
Cider9986•25m ago
Why was this dead?
intronic•1h ago
down-under says: enjoy your summer :)
dist-epoch•1h ago
> I have been working full-time on curl since 2019. For me, this typically means doing 50 hour work weeks, as I spend all days on it and then I top them off with a few more hours every late night – all days of the week

I wonder what is there to work on curl 50 hour weeks for 7 years?

maxbond•1h ago
It's massive and complex codebase. From the looks of it, pretty much what you'd expect, lots of chores, work on the test suite, keeping docs up to date, bug fixes. I didn't see any new features on my light skim but I'm sure they land occasionally.

https://github.com/curl/curl/commits?author=bagder

0x1ceb00da•1h ago
The entire http, http2, http3, tls, sftp spec for every operating system.
ozim•56m ago
https://curl.se/libcurl/

Let me Google that for you.

supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, MQTTS, POP3, POP3S, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. libcurl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, HTTP/2, HTTP/3, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, Kerberos), file transfer resume, http proxy tunneling and more!

libcurl is highly portable, it builds and works identically on numerous platforms, including Solaris, NetBSD, FreeBSD, OpenBSD, Darwin, HPUX, IRIX, AIX, Tru64, Linux, UnixWare, HURD, Windows, Amiga, OS/2, BeOs, macOS, Ultrix, QNX, OpenVMS, RISC OS, Novell NetWare, DOS and more...

flaburgan•1h ago
I can only applause this decision. Maintainers of FOSS project are constantly overwhelmed with close to 0 reward and with LLMs now the management of merge requests exploded even further. The fact that they actually keep providing support to paying users is enough.
patates•1h ago
For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but it was that bad for me.

Signed: Former workaholic.

donw•1h ago
As a manager, I will quite literally ding people for working when they are supposed to be off.

Work during work time, don't work during not-work time. Good practices mean that everyone is important, but nobody is irreplaceable, the team and the work will move along a little slower, but that's fine.

gertrunde•1h ago
Quote from my partner's manager before a vacation:

"If I see you log on, I'll disable your account."

nottorp•30m ago
Humm he means figure out everything you’re signed in to before going on vacation and log off?

Personally I’m sure I’d forget to sign out of something.

xeonmc•46m ago
extremely relevant recent Kai Lentit skit:

https://www.youtube.com/watch?v=5E7kBOH9owI

laszlojamf•1h ago
as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilight zone that isn't good for anybody. And it surprises - and saddens - me that not even friggin curl has the financial muscles to have somebody on-call for one month...
Nnnes•1h ago
They do.

> Everyone with a paid support contracts will of course still get full and appropriate service even during this period.

ed_elliott_asc•1h ago
They do, he said at the end if you have a support contract then they will respond and deal with security issues.

I guess the whole point of the article is to show that people should buy a support contract if they need support.

necovek•1h ago
You'd be surprised to learn this about free and open source software, but if a maintainer is unavailable, you have both full rights and full source code to... wait for it... fix it yourself (or pay someone to)!

There is something unhealthy in this relationship only if you project "no warranty" into unrealistic expectations.

ValdikSS•48m ago
This is true for the majority of open-source projects, but the most serious ones, on which a lot of software/businesses/infrastructure depends, are controlled by foundations or some kind of other management entity.

cURL also offers paid support and also paid access to the rock-solid (LTS) version, with guaranteed response times, and the blog post states that there's still people to respond to these.

rustyhancock•1h ago
A curious approach, but I like it!

Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)

MatthewWilkes•1h ago
I think very few people would consider that to be responsible disclosure. The common practice is to allow 90 days as a minimum.
cmxch•1h ago
Just publish early due to a documented lack of cooperation. They don’t have to answer, but you dont have to wait.

Naturally some people find that this offensive since this puts a price to that “bliss”.

Dylan16807•29m ago
Taking 1/3 of the standard time budget to get back to you isn't ideal, but it's not "a documented lack of cooperation".

And if you find something halfway through the month then oh no two weeks to reply, that's basically a standard business interaction at that point.

SweetSoftPillow•28m ago
It would certainly be irresponsible.

The responsible thing would have been to simply wait another month, considering you've been warned about the delay.

CamouflagedKiwi•23m ago
Given that most of those users will not be capable of patching it directly, no, that seems like it would be irresponsible.
low_tech_love•1h ago
I read one sentence into this and knew directly that the developer must’ve been Swedish!
robin_reala•1h ago
For people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break.

(See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven...)

low_tech_love•59m ago
Not only that but the vacation is real. If someone is off then you should not expect them to answer at all (because if you do you’ll get very disappointed).
stavros•57m ago
I work for a UK company and most people take basically all of August off (I end up with two months of vacation days a year so I take August off and sprinkle some leave around the year) and I can confirm that taking a month off is great. You forget what it's like to work, really.
jdsnape•51m ago
That’s great! It’s very much not the norm here in general tho, in my experience two weeks would be the max people would take off contiguously.
tempay•47m ago
For anyone who thinks this might matter for security:

* curl is mature enough that the chance of an impactful bug is basically zero * if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co * if there is such a bug, it's more important that it gets patched in package managers and rolled out. Upstream releases can wait.

NietTim•47m ago
Properly euromaxxing, this is the way.
vessenes•41m ago
The headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!
okeuro49•40m ago
> Everyone with a paid support contracts will of course still get full and appropriate service even during this period.
fnoef•15m ago
Based! Amazing approach, enjoy the vacation!
cat_plus_plus•12m ago
SGTM, if I am worried about a curl exploit, I will type details into Zoo Code prompt and it will disappear in about 30 seconds and then I can upload a PR for others concerned. Enjoy your vacation and I will enjoy security for a lot cheaper than an enterprise contract!
napolux•6m ago
Funny, I have the same https://www.lafuma-mobilier.fr/ sunbed from the last pic. Also same color. :D
nubinetwork•33m ago
I think the argument was that curl is fairly feature complete (as shown by your list), is there really that many bugs in curl that require immediate attention?
sph•12m ago
Increasingly so, yes.
kitd•17m ago
TIL it supports mqtt. Happy 10000 day to me :)
hurtigioll•9m ago
Linux started removing support for obsolete protocols and hardware

Maybe there is place for a minicurl which removes BeOS and Novell NetWare...

geysersam•54m ago
This is the HTTP/1.1 standard: https://datatracker.ietf.org/doc/html/rfc2616

Then there are also HTTP/2 and HTTP/3.

That's just HTTP, curl supports 27 other protocols.

dist-epoch•19m ago
HTTP/1.1 - June 1999

It's not like the standard changed since curl was created

sevenzero•13m ago
Being the only dev in a startup since 2 years without a single day off where I wasn't messaged by my employer I want this. At least I'll have a 3 week out of country trip where I do not bring my laptop later this year...
throw93033•1h ago
> Log out of all accounts, remove 2FA keys after backing them up on paper

Seems like a lot of extra work, just to go on vacation :)

I would suggest another approach. Automate your work, that you can work from your phone. I go on multi day hiking trips, or a week long family beach holidays, without taking PTO...

Edit: I do not get negative reactions. Big part of my work is to monitor system, and answer questions. I spend less time on my phone than most social app users! I still do heavy coding in office a few times a month. And I am self employed for nit pickers.

Work does not have to be sufering, you can enjoy it!

ro_sharp•52m ago
This is the ideal, but in practice you need to own the business to live this way..
sayamqazi•44m ago
Also candy is enjoyable but 24/7 sucking on it is not.
throw93033•39m ago
Imagine some people sleep at work... I get paid for being available, not LARPing at desk!

Much better than 2 hour daily unpaid commute at old job.

Dylan16807•33m ago
You're basically saying to get a different job.

That's going to work in some situations, but it's not broadly applicable for many reasons. In particular it's way more work than the act of backing up 2FA and logging out of everything. So yeah, it makes a lot of sense for people to think that's not good advice.

nicbou•18m ago
One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering.

In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office.

Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resting and recovering.

4ndrewl•1h ago
It does. The article clearly says that if you have a paid support contract they will be on-call as per usual.
Imustaskforhelp•58m ago
The thing which bugs me is that OpenAI (which is an unprofitable company) is spending around what 100k$ per month for an completely AI generated slop called Openclaw. (All because of Hype)

I have seen there to be an more influx of open source software as people are starting to create more software with vibe-coding and other things and just open-sourcing it, which while good in OSS'ing it but its mostly less valuable as compared to the curl codebase which was created by hand and over the years improved itself.

Yet the funding is going towards making more and more (OSS/non-OSS) AI slop by people, companies and dare I say countries yet we are unable to take the same wealth and money into, say, the curl project (and the likes)

There is also an visibility issue. We all know curl and this is the state of curl. Imagine all the projects which we all don't know that much about or aware about going through same issues.

l23k4•41m ago
>The thing which bugs me is that OpenAI (which is an unprofitable company) is spending around what 100k$ per month for an completely AI generated slop called Openclaw. (All because of Hype)

For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop.

OpenAI is certainly not wasting the money they're spending on Openclaw, even if I personally wouldn't want to touch that particular piece of software.

simooooo•7m ago
I wonder how far we are from the agents just maintaining the packages
defrost•25m ago
Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave

  Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.
nsbk•36m ago
Hahaha yeah same here! My $dayjob has offices in Sweden and their summer breaks are legendary. We also have offices in the US, and the culture shock with the Americans never gets old