Daniel Stenberg, the creator of curl, revisits a problem he reported three years ago: nuget.org continues to host severely outdated and vulnerable curl packages. The most popular offending package, rmt_curl, ships curl 7.51.0 from November 2016, which has 64 known vulnerabilities, yet is still downloaded ~1,000 times per week.

5m read timeFrom daniel.haxx.se
Post cover image
Table of contents
Trusting randosI reported this again“This is not a Microsoft problem”Outdated effortsHow to addressConclusion
1 Comment

Sort: