Hacker News new | ask | show | jobs
by CaliforniaKarl 842 days ago
To be clear, the "brief" reference is this:

> Because of curl’s use of third party libraries for doing QUIC and HTTP/3, the report advises that there should be follow-up audits of the involved libraries. Fair proposal, but that is of course something that is beyond what we as a project can do.

Indeed, the next thing would be for the third-party libraries to go through a similar audit!