Hacker News new | ask | show | jobs
by bagder 1394 days ago
I only record the introduction commit for security flaws as they are rare and important enough to give that level of attention. And that's not a mandatory or required step in our process, I do it mostly as a service for users and to satisfy my own curiosity.

Our process for handling security problems in curl is documented here: https://curl.se/dev/secprocess.html