Three years ago I blogged about #nuget serving outdated #curl packages.
They then removed the packages I found.
I checked nuget again today and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there… with 64 known vulnerabilities.
The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/
This is an unofficial account reposting stories from the KXAN RSS feed. KXAN.com
This is an unofficial account reposting stories from the KXAN RSS feed. KXAN.com
curl and Apache httpd project member, HTTP/2, HTTP/3, Lets Encrypt implementations. Likes to code. "Nobody has any idea what is actually going on."
curl and Apache httpd project member, HTTP/2, HTTP/3, Lets Encrypt implementations. Likes to code. "Nobody has any idea what is actually going on."
I don’t know. Why are we here again? Also, I built a Time Machine out of rubber bands and hope. So in the future, I travel to the Exoplanets in a rental spaceship and photograph interesting sights. The journeys help keep the insanity at bay.
I don’t know. Why are we here again? Also, I built a Time Machine out of rubber bands and hope. So in the future, I travel to the Exoplanets in a rental spaceship and photograph interesting sights. The journeys help keep the insanity at bay.
You've seen all posts