On Monday January 26, 2026, I intend to merge this pull-request and post an explainer blog post detailing some further reasoning and details behind this move. The change, the end of the bounty, is officially set for January 31 but I am certain it will take some days to "take effect" and by merging the update a few days early I don't think we actually hurt anyone.
His comments came as cURL users complained that the move was treating the symptoms caused by AI slop without addressing the cause. The users said they were concerned the move would eliminate a key means for ensuring and maintaining the security of the tool.
A single user commented, and they responded. “users complained” and "the users" is wrong. implying something different.
“users complained” feels like a misrepresentation to me as well, at least how I read and understand "complained". The user wrote “As a security researcher, this is honestly painful to see, but also completely understandable.” Is it complaining if they understand the act and change?
In a separate post on Thursday, Stenberg wrote: “We will ban you and ridicule you in public if you waste our time on crap reports.”
The linked separate post is a /.well-known/security.txt file. It's not really a “separate post”. And I don't see where they got the date from. Maybe from whatever linked to that in the first place.
An update to cURL’s official GitHub account made the termination, which takes effect at the end of this month, official.
Isn't that from the merge request, which is not merged yet? It's definitely not in the main branch. Current MR state is something different. The MR discussion clearly states that they will merge on 26th - no early.
“an update to the official GitHub account” makes no sense to me in the first place, when it's a file in a repo, not even the account.
At first, I only wanted to point out one thing. Now this whole article feels like AI slop. Dunno how warranted that feeling/assessment is. Is it sloppy reporting? Am I, as a reader, the problem?
A task that might have taken five hours assisted by AI, and perhaps ten hours without it, is now more commonly taking seven or eight hours, or even longer.
What kind of work do they do?
in my role as CEO of Carrington Labs, a provider of predictive-analytics risk models for lenders. My team has a sandbox where we create, deploy, and run AI-generated code without a human in the loop. We use them to extract useful features for model construction, a natural-selection approach to feature development.
I wonder what I have to imagine this is doing and how. How do they interface with the loop-without-a-human?
Either way, they do seem to have a (small, narrow) systematic test case and the product variance to be useful at least anecdotally/for a sample case.
I posted a comment there, but looks like what I was asking about is no longer part of the post or repo readme this time around.
While trying to determine whether this is that I noticed you wrote “566 pages of theory” but then 573-page manuscript. I assume it became more pages, or are they different things?
Before starting tasks, developers forecast that allowing AI will reduce completion time by 24%. After completing the study, developers estimate that allowing AI reduced completion time by 20%. Surprisingly, we find that allowing AI actually increases completion time by 19%--AI tooling slowed developers down.
When this makes me think of gravity and how that propagades huge distances (if not endlessly until practically ignorable), would that be correct or wrong for this aspect?
What does 'neighbors' mean in this context? Is it meant as something more local, constrained, or scoped towards local physical locality?
relevant, from a PR comment