pleroma.debian.social

pleroma.debian.social

The project will not accept or otherwise handle any vulnerability reports during the month of July 2026. We call it the curl summer of bliss.

https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/

@bagder happy vacation!

@bagder This is the way.

@bagder I love the boldness of this strategy. Security stuff always seems so urgent and high pressure, the idea of walking away from it completely is refreshingly different

@bagder

I dislike how you're "marketing" this, but overall I can understand what you're trying to say though...

@agowa338 I need to "market" it to make people generally aware ahead of time.

@bagder in a world where people download scripts blindly from some random URL with curl and pipe them into bash, I think it is safe enough for the maintainer to take a holiday instead of working really hard to make a strong door lock even stronger when everyone has other ways of getting in.

@bagder This seems like an excellent approach. Enjoy the time off!

@icing @vsz @bagder et al and so it begins ...

@bagder You should get a medal or something.

Or two.

Maybe three.

Thanks for being a leader in how to do open source.

@bagder
Worth mentioning: In Sweden, having "industry vacation" in summer is a long tradition. Entire businesses may shut down for a few weeks, with phones/email manned only by a lonely summer intern.

Summer is short, and it's the only way for most people to take vacation when it's actually warm and nice; Swedish employment law still guarantees 2(?) weeks of vacation during the summer months I believe.

@jannem sure, I just don't see how that is relevant here...

@bagder
For people not aware that this kind of summer holiday is perfectly normal and expected; not a stunt of some kind.

@bagder Have a nice vacation. You have earned it.

@bagder

Have a nice vacation Daniel: I'm 100% on board with this approach.

@bagder “The bad guys won’t rest.
Probably not. But we will.” - as you should! Enjoy some well-deserved time off and thanks for all you do for the internet

@bagder love this. Enjoy the time off!

@bagder
Now THAT is bold!

@bagder An example I will shamelessly copy. Enjoy your summer of bliss!

@bagder Enjoy your vacation, Daniel :) 🌴

@bagder
you deserve this, even if you didn't work as hard as you do, and i support you (everyone else!) getting the rest that we all need. thank you for leading by example, so others who will look up to you feel encouraged and empowered to take care of themselves and their families, too.

and most importantly, have fun on your vacation!!
🌊🏖️😎

@bagder Love this! Good for you!

@bagder I wish you great bliss and relaxation!

@bagder Fantastic idea. If corporations want anything more from volunteers, they should pay for it.

@bagder @icing The project is following the curl lead and have started today until 1st August.

https://github.com/libexpat/libexpat/issues/1277

@hugovk Great!

@bagder enjoy the summer!

@bagder Enjoy your vacation!
Maybe this move will get some more commercial users to pay your worth - Open Source should not be an invitation to freeload on other people's work. Especially not if you can pay for it and earn from it.

@icing @hugovk @bagder

Every project affected should go on vacation! I would have called it a strike, however you are not the employees of your voluntary work!

@mainec

@hugovk @icing It makes me happy to see!

@thomasfricke @hugovk @bagder @mainec

My grandfather was, after the war, making wooden shoes (sabots) to earn some money. When I was little, he taught me some phrases. Like

"Alle Räder stehen still, wenn mein starker Arm es will!"

😌

@bagder well deserved ❤️

Thanks for the heads-up!

@bagder
Excellent initiative!

@bagder I think I'm going to do the same during my upcoming summer vacation and over the holidays.

Not a horrible amount here so far, especially not compared to you, but managing expectations is always a good idea, and also clarifying the whole situation, even on smaller projects.

@bagder brilliant idea. Enjoy your holidays!

@icing @thomasfricke @hugovk @bagder I love that saying

@bagder enjoy midsummer and the vacation that follows, well deserved

@bagder Total stranger offering a “HELL YES” for that.

@bagder I can't begin to fathom how hard it must have been to make that decision, with all the potential backlash ! Even though this is just you taking a well-deserved vacation 😅

@bagder These damned open source programmers want a vacation. This is a slippery slope. Soon they will also want payment and health insurance and a safe work environment and who knows what else…

Just kidding. Enjoy the vacation!

@bagder
enjoy the break, you deserve it!

@starsider
Not related. I get a vacation from my day job too, and no matter how much money I get I'll still want that.

Paying more for 'not taking a holiday' is kind of a hot take.
@bagder

@wouter @bagder By "anything more" I meant urgent action due to a security issue. Being available in the case the need arises. Even if it's very unlikely and only for very urgent matters, that still has a cost (being able to interrupt a vacation).

Also, it's not "paying more", it's just paying. Open source volunteers are unpaid, generally.

@starsider So you are, in fact, asking someone to be available on holiday for pay. That's a big no to me. Holiday is holiday, no matter how much the customer pays.

It can wait. Or they can fix things themselves, it's open source after all. @bagder

replies
0
announces
0
likes
0