Curl creator Daniel Stenberg is looking for reinforcements for his security team. The requirement is unusual: candidates should be willing to dig into the quirks of Windows. That's exactly what nobody on the current seven-person team wants to do, which makes finding and fixing bugs in the widely used open-source software considerably harder.
Nobody on the team likes Windows
"Nobody on the seven-person curl security team uses Windows or runs Windows systems," Stenberg explained on Mastodon. When people report Windows-specific security issues, he says, the team just sighs and rolls its eyes, and sometimes hyperventilates a little. Right now there's also no other curl contributor who is active, experienced with Windows, and interested enough to join the security team. Anyone who fits that description should get in touch, he wrote.
A seat on the security team comes with real responsibility. Curl is a command-line data transfer tool that's also available as the library libcurl. It has existed for nearly 30 years and is baked into countless software projects. Millions upon millions of users worldwide indirectly depend on curl working reliably.
From AI chaos to a bug report pause
Over the past few years, Stenberg has repeatedly complained about low-quality, AI-generated bug reports that burdened the team with unnecessary investigations. The quality of AI submissions later improved significantly, but the sheer volume of reports didn't drop. In April, Stenberg spoke of a new era of "high-quality chaos."
That ultimately prompted him to temporarily pause accepting any bug reports for curl in July. In a wrap-up in early August, Stenberg wrote that it had been one of his best project decisions in a long time. The search for Windows expertise shows, though, that even an established open-source project runs into practical gaps when an entire platform simply fails to excite anyone on the team.