Daniel Stenberg said curl will stop accepting vulnerability reports for July 2026 so the maintainers can actually take a vacation. The carveout is explicit: paying support customers still get coverage. That made the post read less like a quirky holiday notice and more like a line in the sand about what free users are, and are not, owed from a piece of software that sits deep in the Internet’s plumbing.
Most people loved the candor. The dominant reaction was that maintainers are allowed to be human, and that any company relying on curl for urgent security work should already be paying for support or carrying its own patching capability. The conversation kept coming back to an uncomfortable truth about open source economics: lots of companies treat critical dependencies as free labor right up until availability disappears, then act surprised. Several comments also pointed out that even if upstream produced an instant fix, the slow part for many organizations is still packaging, rollout, and getting patches onto shipped devices.
The sharper discussion was not really about one month of downtime. It was about
bus factor and dependency management. People noted that “just fork it” is technically true but operationally ugly, especially for security fixes that must propagate through distributions, downstream packages, and customer environments. Others pushed the more pragmatic view that this is exactly what using open source means. You get source code and agency, not an
SLA by magic. A second thread connected the post to broader burnout and work-boundary norms, especially in Europe, where long uninterrupted summer vacations are normal and even seen as a healthy test of organizational resilience. That framing made curl’s move feel less radical than overdue. The strongest conclusion was simple: the project is exposing a risk that already existed, not creating a new one.