Path to this page:
./
www/curl,
Client that groks URLs
Branch: CURRENT,
Version: 8.22.0,
Package name: curl-8.22.0,
Maintainer: leotCurl is a command line tool for transferring files with URL syntax, supporting
FTP, FTPS, HTTP, HTTPS, GOPHER, TELNET, DICT, FILE and LDAP. Curl supports
HTTPS certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload,
proxies, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate,
kerberos...), file transfer resume, proxy tunneling and a busload of other
useful tricks.
Required to run:[
security/heimdal] [
security/openssl] [
www/nghttp2] [
devel/libidn2]
Required to build:[
pkgtools/cwrappers]
Package options: http2, idn, inet6, openssl
Master sites:
Filesize: 2883.879 KB
Version history: (Expand)
- (2026-09-03) Updated to version: curl-8.22.0
- (2026-06-25) Updated to version: curl-8.21.0
- (2026-05-15) Updated to version: curl-8.20.0nb2
- (2026-05-14) Updated to version: curl-8.20.0nb1
- (2026-04-29) Updated to version: curl-8.20.0
- (2026-03-11) Updated to version: curl-8.19.0
CVS history: (Expand)
2026-09-02 21:19:32 by Thomas Klausner | Files touched by this commit (4) |  |
Log message:
curl: update to 8.22.0.
This release includes the following changes:
o gssapi: add support for Apple GSS Framework [72]
o hardening: add API guards [64]
o RFC 9421 HTTP Message Signatures support [108]
o spnego: block NTLM fallback in SPNEGO negotiation [151]
o TLS: drop support for TLS-SRP [71]
o vquic: add option to use Apple fast UDP [137]
This release includes the following bugfixes:
o altsvc: continue after unknown parameters [198]
o asyn-thrdd: retry link-local ipv6 if missing scope id [118]
o autotools: minor fixes and improvements [33]
o build: always use local `inet_pton()`/`inet_ntop()` implementations [56]
o build: assume POSIX `select()` is available [166]
o build: clear `Require.private` for static-only builds in `libcurl.pc` [188]
o build: drop `dirent.h` and `opendir()` detections on Windows [186]
o build: drop detecting `gettimeofday()` on Windows [184]
o build: drop superfluous `STDC_HEADERS` macro [51]
o build: enable thread-safe `getaddrinfo()` for OpenBSD [35]
o build: minor debug option message fixes/improvements [200]
o build: require `!NDEBUG` for debug-enabled (aka development) builds [202]
o build: strip duplicate spaces after `Libs.private:` in `libcurl.pc` [191]
o build: strip trailing spaces from `libcurl.pc` [194]
o cd2nroff: fix backslashes for 4-space indent lines [104]
o cd2nroff: stricter checks for asterisks for italics [73]
o cf-ngtcp2-cmn: de-duplicate `ngtcp2_conn_client_new()` call code [156]
o cf-ngtcp2-cmn: initialize new callback ptr for ngtcp2 1.24.0+ [52]
o cf-socket: avoid broken NetBSD SOCK_NONBLOCK [275]
o cf-socket: disable TCP SYN retransmissions for localhost on Windows [164]
o cfilters: fix event-based connection shutdown [91]
o clock: save one call [286]
o cmake/FindLibgsasl: fix to set `LIBGSASL_VERSION` with pkg-config detection [229]
o cmake: check libgsasl version at configure time [277]
o cmake: dedupe expressions into local vars in `cmake_uninstall.in.cmake` [9]
o cmake: fix not to build `tunits` when `BUILD_CURL_EXE=OFF` [7]
o cmake: flatten build tree, tidy up base dir variables [12]
o cmake: minor improvements to `cmake_uninstall.in.cmake` [54]
o cmake: optimize OpenSSL fork detection [228]
o cmake: replace `remove` command with `rm` and pass arg safely [11]
o cmake: robustify base path in local file reference [15]
o cmake: stop probing unused `float.h` for `STDC_HEADERS` [10]
o cmake: use built-in variable and target property dump functions with CMake \
4.5+ [155]
o config-riscos.h: delete handcrafted RISC OS config header, in favor of \
autotools [178]
o config-win32.h: drop UWP, c-ares, simplify more [231]
o config-win32.h: limit use to MSVC IDE Project builds [193]
o configure: clarify --enable-debug option [133]
o configure: fix misleading error messages [42]
o configure: link `-lcrypt32` instead of `-lm` for wolfSSL on Windows [79]
o configure: only check in the watt library if WATT_ROOT is set [120]
o configure: remove double check for GnuTLS [21]
o configure: set ldap lib to no by default for non-finds [18]
o conncache: apply multi limits to transfers using a shared pool [41]
o conncache: conn upkeep/alive: move and enhance [152]
o conncache: connection alive checks intervals [20]
o conncache: don't assume curl_off_t increment wrap-around [138]
o conncache: guess maxconnects different [289]
o connect: connection close tweaks [112]
o connect: only set connect timer on first socket [206]
o connection reuse: age check [261]
o connection reuse: check SSL configs when doing a scheme upgrade [249]
o connections: use admin handles only for maintenance [213]
o content_encoding: exact-match the identity transfer-coding token [189]
o content_encoding: give a clear error on multi-member gzip [46]
o cookie: cookies set for an exact PSL domain is host-only [304]
o cookie: improve TAB handling [258]
o cookie: refuse to load cookies set against a PSL domain [139]
o CREDENTIALS.md: remove comment about empty user/pass [50]
o ctype: exclude control bytes from ISPRINT and ISGRAPH [119]
o curl: help category cleanups [169]
o curl_gssapi: document/update feature availability [145]
o curl_threads: always use native threads/mutex on Windows [185]
o curl_trc: remove unused expire timers [147]
o curl_url_set.md: expand the CURLU_NO_AUTHORITY description [134]
o curl_ws_meta.md: polish and better vocabulary [19]
o CURLOPT_HEADERFUNCTION.md: document folded header unfolding [53]
o CURLOPT_SOCKOPTFUNCTION.md: ALREADY_CONNECTED does not work for HTTP/3 [262]
o CURLOPT_SSH_*_KEYFILE: used for setting up, then no more [48]
o CURLOPT_UNRESTRICTED_AUTH.md: 'Authorization', not 'Authentication' [74]
o CURLOPT_USERNAME.md: ambient username caveats [271]
o CURLSHOPT_(UN)SHARE.md: do not modify shares while in use [44]
o curlx_inet_ntop: return `CURLcode`, drop setting `errno` [237]
o curlx_inet_pton: drop setting `errno` on error [236]
o DEPRECATE.md: HTTP/2 Server Push gets removed in March 2027 [174]
o dict: avoid busy-loop in sendf() when the socket is not writable [99]
o dist: fix to drop test bundle .c files from the source tarball [305]
o dnsd: fix bounds check in `read_https_alpn_part()` [143]
o docs/INTERNALS.md -> docs/DEPENDENCIES.md [127]
o docs: clarify that cookies need domain set to match [224]
o docs: connection reuse behavior for socket callbacks [219]
o docs: make 5 example snippets compile cleanly with clang [192]
o docs: mention possible auth option conflicts [114]
o docs: remove doubled word in SECURITY-ADVISORY.md [183]
o DoH: improvements [203]
o easy: fix unused global on non-Windows [292]
o easy_lock: silence `portability-no-assembler` with clang-tidy 23.1.0+ [291]
o FAQ: correct an option typo [278]
o file: support directory listing on Windows [205]
o filter: change time reporting [235]
o FTP: fix TLS session reuse on the data connection [80]
o ftp: reject control bytes in ACCT and alternative-to-user [26]
o gitignore: maintenance updates [170]
o gopher: fix partial sends of CRLF [288]
o gopher: reject CR and LF in the selector [1]
o h2 push: use squeaky clean easy handle [246]
o h2: bootstrap max streams from multi handle if in use [132]
o h3-proxy: fix NULL deref when non-:status header arrives before :status [167]
o Happy Eyeballing v3: resolution delay of 25ms [232]
o header api: add guards [168]
o headers: name the arguments the way the definitions name them [234]
o HISTORY.md: PSL support in 2015
o HISTORY: add when c-ares support was introduced (2004)
o HISTORY: September 1999: started using CVS
o hostip: only cache negative resolves for authoritative answers [16]
o hsts: only match the exact strings [269]
o http digest: tie peer/credentials on input [264]
o http2: make server push transfers inherit share from parent [81]
o http2: remove assert in ingress processing [272]
o http: avoid length underflow in Curl_compareheader [78]
o http: custom Authorization: header overrides Negotiate [223]
o http: fix non-tunneling proxy hostname use [116]
o http: stop dropping large custom headers [69]
o http: trim custom header name before the Authorization drop [17]
o httpsrr: DoH with HTTPS, fix response handling [113]
o idn: restore `MultiByteToWideChar()` `MB_ERR_INVALID_CHARS` flag [103]
o imap: APPEND CRLF fix [256]
o include: include <sys/select.h> when building for modern Linux. [308]
o INSTALL.md: add building-from-source overview section [29]
o INTERNALS.md: require quiche 0.20.0+ [101]
o ipv6 scope_id: set from first peer [242]
o keylog: add a random size argument to Curl_tls_keylog_write() [180]
o ldap: base64-encode LDIF values beginning with colon or less-than [218]
o ldap: reject control characters in URL-decoded filter values [196]
o ldap: support empty username and password [106]
o ldap: support insecure mode for Windows native LDAP [3]
o lib1587: fix gcc `-Wconversion` with LibreSSL on Windows, test in CI [6]
o lib2405: adjust for non-threaded builds [149]
o lib: add "Curl_" prefix to two global functions [84]
o lib: add multi_wakeup_internal [86]
o lib: drop unused `system_win32.h` includes [290]
o lib: fix 'ns' -> 'us' in trace messages [57]
o lib: new easy option string storage [215]
o lib: optimize struct layouts for reduced memory usage [212]
o lib: ratelimit timestamps [14]
o lib: silence gcc-16 compiler warnings `-Wmaybe-uninitialized` [243]
o lib: update mentions of the legacy "sessionhandle" [157]
o libcurl.md: emphasize that the output needs checking [259]
o libcurl.pc: add `License` tag [190]
o libcurl.pc: add Copyright tag to the pkgconf file
o libcurl.pc: add the Link.ABI and Source tags [210]
o macos sectrust: fail ocsp verify when not builtin [252]
o Makefile.am: improve etags [257]
o mbedtls: enforce verifyhost when verifypeer is disabled [208]
o mbedtls: replace `memset()` with `psa_hash_operation_init()` [28]
o md5: replace magic numbers with `MD5_DIGEST_LEN` [122]
o mime.c: avoid integer overflow in base64 size calculation [105]
o mime: reject CR and LF in mail part name and filename [30]
o mod_curltest: fix compiler warnings [49]
o mprintf: acknowledge %F [245]
o mprintf: avoid never-ending loop for positive-infinite [247]
o mprintf: fix long double output [250]
o mqtt: reject control bytes in the topic [43]
o multi: cap expire times to INT_MAX internally [216]
o multi: forbid curl_easy_pause from within multi socket callback [22]
o multi: hold timeout values in 'int' instead of 'long' [165]
o multi: remove #if 0'ed code that uses old struct [150]
o multi: shrink expire timer indices [199]
o multi: timeout improvements [209]
o multi: use index list for expire timeouts [197]
o multi: xfer table initial size and growth [255]
o multihandle: move two struct fields [163]
o ngtcp2+openssL: fix early data [225]
o ngtcp2: avoid NULL deref in cf_ngtcp2_send [260]
o ngtcp2: clean up after ngtcp2 in `curl_global_cleanup` [126]
o ngtcp2: let verify failures win over expiry processing errors [98]
o openldap: handle Curl_sasl_continue() returns better [45]
o openssl+sectrust: fix session reuse [4]
o openssl+sectrust: move session verified set into result check [82]
o openssl: avoid conn reuse if provider is used [214]
o openssl: avoid strlen() on the data from OpenSSL [280]
o openssl: aws-lc ocsp workaround [263]
o openssl: drop unused pre-OpenSSL3 `ctx_option_t` typedef [8]
o openssl: fix DER buffer leak in Apple SecTrust verification [217]
o openssl: no server cert is only okay if also not pinned [226]
o openssl: prefer modern API flavors for `EVP_MD_CTX` new/free [47]
o openssl: replace stray legacy API variant with `EVP_DigestInit_ex()` [27]
o os400: port latest header files changes to ILE/RPG interface [241]
o os400: rewrite upper ebcdic wrappers using dynbuf [227]
o progress: cleanup, less memory [179]
o protocol: simpler Curl_getn_scheme runs faster [239]
o proxy: CONNECT trailers handling [251]
o psl: update a comment to understandable English [162]
o pytest: update two H3 tests for nghttp3 1.18.0+ [158]
o quic: upload improvements [276]
o quiche: set the max field section size [100]
o rtsp: refactor method handling and improve error checks [161]
o runtests: allow comments in `setenv` section, merge sections in test433 [89]
o runtests: fix `mode="warn"` tests passing unconditionally, fix test \
1752 [66]
o runtests: flush cached test parts when (re)loading a file [95]
o runtests: restore `-k` option and actively process as no-op [32]
o sasl: fix zero-length response encoding [36]
o schannel: add ALPN support for mingw-w64 <9 and <VS2015 [295]
o schannel: clear PFX password before free [222]
o schannel: fix ALPN erroneously disabled [282]
o schannel: fix error check logic in `get_client_cert()` file reader [144]
o schannel: refresh stream sizes after renegotiation [248]
o schannel: reuse the send buffer [195]
o schannel: shut off experimental TLS 1.3 support for Win 10 [25]
o scorecard: fix `max_upload` init value in `ul_parallel()` [142]
o scripts/badwords.txt: do not recommend using 'will' in rewrites [141]
o scripts: replace/extend `--` with `--end-of-options` in git commands [128]
o scripts: use end-of-options marker in `cd`, `mkdir`, `mv`, `sha256sum` \
commands [34]
o servers: fix HANDLE leak in UWP builds [65]
o servers: fix to reverse `SA_RESTART` option for `sigaction()` on modern \
codepath [131]
o setopt: allow setting a referer from CURLINFO_REFERER [254]
o setopt: error for CURLOPT_SHARE when easy handle is used [68]
o setopt: make NULL `CURLOPT_AWS_SIGV4` disable aws-sigv4 auth [270]
o setopt: return OK earlier for the deprecated h2 dep options [77]
o share unlink: forget connection [244]
o smtp: reject CR and LF in the envelope address [37]
o spacecheck: cap number of lines per file [111]
o spnego_sspi: drop redundant UNICODE branch [297]
o spnego_sspi: pass channel bindings on initial context [230]
o src: safely clear certain buffers [125]
o sshserver.pl: bump an sshd config to use its modern name [160]
o ssls: fix potential memory leak on import [96]
o sspi: add local helper macro to avoid UNICODE branching [296]
o sspi: enable channel-binding in mingw-w64 <9 builds [306]
o strcase: inline the raw case conversions [207]
o sws: allow connection-monitor to log all disconnects [2]
o sws: log the exact closing reason better, to help debugging tests [85]
o terminal: Enhance terminal size detection for multiple outputs [115]
o test 1560: test RFC4291 style IPv6 IPv4-mapped addresses [40]
o test1560: allow to build and run without LDAP support [109]
o test798: force IPv4 to avoid cross-runner port aliasing [97]
o test: adjust test_06_13 for 0100::/64 being blackholed [13]
o tests: address mutable class vars and naive datetime in Python code
o tests: change whitespace and comments in Python test code
o tests: convert unit test 1396 and 1398 into libtests [146]
o tests: enable and fix some new Python ruff warnings [301]
o tests: fix Content-Length mismatch in test 2064 [233]
o tests: fix the FTP check for unexpected RST [117]
o tests: fix type promotion on 32-bit arches in http test code [88]
o tests: fix typo in assert message in http test
o tests: improve exception handling in Python test code
o tests: remove test1701 [58]
o tests: simplify by removing unneeded Python code
o tests: skip test 311 for wolfSSL 5.9.2 [63]
o tests: target Python 3.8 as the minimum Python version
o tests: use simpler constructions in Python code
o thrdpool: retry failed thread starts while items wait [62]
o thrdqueue: drop name strdups from Curl_thrdq_create [181]
o tidy-up: `TEXT()` vs `_TEXT()` vs `_T()` use (Windows) [102]
o tidy-up: comments, messages, formatting [172]
o tidy-up: drop redundant includes [110]
o tidy-up: fix Perl syntax and formatting nits [123]
o tidy-up: fix typos in docs and comments [173]
o tidy-up: formatting, messages and comments [253]
o tidy-up: minor code fixes and improvements [171]
o tidy-up: typos, comment nits [60]
o timeval: make `Curl_freq` variable static (Windows) [90]
o tool: checkfds, open on null device [307]
o tool: do not flush on out-null [38]
o tool: fix memory use in parallel mode [59]
o tool: init progress bar on demand [39]
o tool: remove duplicate setopts [94]
o tool_cb_hdr: de-duplicate filename setter [24]
o tool_cb_hdr: do not truncate etags output to stdout [273]
o tool_cb_prg: avoid integer overflows [93]
o tool_doswin: add stdin relay auth [130]
o tool_doswin: don't use `TerminateThread` in stdin relay [238]
o tool_doswin: fix stdin data truncation [274]
o tool_msgs: make notef() respect --silent [220]
o tool_operate: limit `is_using_schannel()` call to Windows [140]
o tool_operate: only check for schannel if on windows [187]
o tool_operate: remove call to abort() [23]
o tool_paramhlp: --proto only supports one modifier [268]
o tool_xattr: add support for Windows alternate data stream [129]
o transfer: DID handling [281]
o typecheck-gcc: allow passing `char[]` as callback data [153]
o uint-spbset: reused empty chunks [67]
o unit3214: fix to pass on systems with >=128-bit pointers [107]
o url: fix handling of empty user in NTLM matching [221]
o url: fix negotiate/ntlm connection reuse [176]
o url: reject control codes in credentials set via CURLOPT [70]
o urlapi: allow URLs to not have userauth (hostname) [92]
o urlapi: avoid dedotdotify() if possible [182]
o urlapi: clear password buffer on error path [121]
o urlapi: do not keep an internal port string [31]
o urlapi: improved return codes [148]
o urlapi: preserve empty markers in relative URLs [61]
o urldata: cleanups [175]
o urldata: drop four strings from the aptr struct [136]
o urldata: sort the connectdata struct fields by size [177]
o VERSIONS.md: document Rock-solid curl releases [201]
o vms: fix symbol typo and missing closing quotes in `config_h.com` [124]
o vquic: add Curl_ prefix to some global functions [76]
o vquic: initialize new callback slot for nghttp3 v1.18.0+ [87]
o vquic: silence `-Wmissing-field-initializers` for nghttp3/ngtcp2 callback \
tables [159]
o vquic: use ngtcp2 v1.25.0 new close2 callback [154]
o vssh: keyfile use cleanups [83]
o vssh: silence gcc-11 `-Wnull-dereference`, dedupe `CURL_EASY_STR()` calls [240]
o vtls: move 'native_ca_store' ssl_config_data => ssl_primary_config [211]
o vtls_scache: use case sensitive path match
o VULN-DISCLOSURE-POLICY.md: issues that should be found by tests are LOW [5]
o wcurl: import v2026.08.30 [279]
o websocket: pause writing and meta data fix [135]
o winsock: drop redundant version checks at initialization [284]
o wolfssl: do not run Curl_wssl_setup_x509_store() twice [265]
o wolfssl: fix build for wolfssl without bio chain support [75]
o ws: fix write callback error handling [204]
o ws: pause/unpause write handling [55]
|
| 2026-07-25 22:59:06 by Thomas Klausner | Files touched by this commit (1) |
Log message:
curl: remove rtmp option in bl3.mk as well
|
| 2026-07-25 22:58:53 by Thomas Klausner | Files touched by this commit (1) |
Log message:
curl: remove rtmp option
rtmp support was removed in 8.20.0
https://daniel.haxx.se/blog/2026/03/21/bye-bye-rtmp/
|
| 2026-07-25 22:55:05 by Roland Illig | Files touched by this commit (1) |
Log message:
www/curl: remove unknown configure option
|
2026-06-25 10:25:51 by Thomas Klausner | Files touched by this commit (9) |  |
Log message:
curl: update to 8.21.0.
Lots of security fixes.
Changes:
curl: named globs in output filename for upload glob references
HTTP/3: add proxy CONNECT and MASQUE CONNECT-UDP support (ngtcp2 QUIC)
http2: remove stream dependency tracking
lib: drop support for CURLAUTH_DIGEST_IE
libssh: add support for SHA256 host public keys
tool_urlglob: add named globs
Bugfixes:
_ENVIRONMENT.md. Windows does case insensitive env variables
_URL.md: remove the zone-id mention
AmigaOS: curl_setup.h avoid explicit_bzero with clib2
AmigaOS: fix build fallouts, re-add to CI
asyn-thrdd: add IPv6 guards
asyn-thrdd: fix result processing without wakeup socketpair
autotools: mbedtls detection fixes
BINDINGS: Update Hollywood link
BUFQ.md: re-sync with source code
build: enable `-Wlogical-op` picky warning for GCC 4.4+
build: omit zlib pkg-config reference for Android
cf-h2-prox: fix peer leak
cf-h2-proxy: drop interim responses
cf-https-connect: do not engage on proxy origin
cf-ip-happy.c: minor comment typo
cf-ip-happy: update documentation
cf-socket: make Curl_addr2string static
cf-socket: set scope_id for IPv6 link-local addresses
cf-socket: store errno from do_connect in ctx->error
cfilters: fix busy loop on blocked transfers
chunked: reject invalid bytes in trailer
CIPHERS.md: fix the example that uses only TLS 1.3
cmake/FindGSS: drop "MIT Unknown" version value, related tidy ups
cmake/FindGSS: drop CMake <3.16 compatibility logic
cmake/FindGSS: fix comment, adjust custom flavor property name
cmake/FindGSS: prioritize MIT over GNU in pkg-config detection
cmake: auto-select static nghttp2/nghttp3/ngtcp2 Config
cmake: export/forward `NGTCP2_CRYPTO_BACKEND`
cmake: fix three issues generating lib options in config files
cmake: fix zstd CMake config name
cmake: opt in `MSVC_VERSION` 1951 to picky warnings
cmake: quote `COMPONENTS` string in `curl-config.in.cmake`
cmake: simplify `LINK_ONLY` imported target extraction
config2setopts: use default protocol properly
connect: remove deref of freed pointer in trace call
content_encoding: fix limit failure message
content_encoding: fix non-last chunked rejection
content_encoding: timeout during slow decoding
cookie: check __Secure- and __Host- case sensitively when read from file
cookie: compare path case sensitively
cookie: reject control octets in file-loaded cookies
cookie: simplify strstore(), remove outdated comment
cookie: tailmatch the domains for secure override
cookie: trim trailing dots when checking PSL
creds: add sasl service name
creds: create with empty user+pass
creds: mask OAuth bearer token in trace logs
creds: remove two unused functions
curl_easy_pause.md: rephrase the stream cache when pause clause
curl_easy_setopt.md: change options when no transfer runs
curl_formdata: fix to pass long where missing, document `CURLFORM_NAMELENGTH`
curl_multi_assign.md: clarify lifetime
curl_ntlm_core: fix nettle 4+ builds in certain MultiSSL combos
curl_ntlm_core: propagate DES `CryptEncrypt()` error
curl_sha512_256: fix result code on error
CURLINFO_CONTENT_LENGTH_UPLOAD_T.md: expand
CURLMOPT_SOCKETFUNCTION.md: this sends *all* file descriptors
CURLOPT_CHUNK_BGN_FUNCTION: target is there for symlinks only
CURLOPT_DISALLOW_USERNAME_IN_URL: is for CURLOPT_URL only
CURLOPT_DOH_URL.md: does not inherit proxy options
CURLOPT_ECH.md: simplify the description language
CURLOPT_HAPROXYPROTOCOL.md: only sent for newly setup connections
CURLOPT_MAXFILESIZE: clarify this also works for on-going transfers
CURLOPT_PINNEDPUBLICKEY.md: does not apply for other origins
CURLOPT_PORT.md: use stronger language
CURLOPT_SHARE: warn about early remove
CURLOPT_SSH_HOSTKEYFUNCTION.md: for new connections only
CURLOPT_WRITEFUNCTION.md: mention redirects
CURLOPT_WRITEFUNCTION.md: remove stray reference to HSTS
delta: harden external command invocations
digest: escape control codes too
digest: flush proxy state on proxy or credential change
digest: flush state on origin or credential change
dns-httpsrr-lookup: use origin, not peer
dnscache: remove Curl_dns_entry_link
docs/libcurl: fix the version for curl_multi_socket_action
docs: end "...can be used several times..." sentences with period
docs: fix --follow doc typo
docs: fix a couple of typos
docs: fix grammar and wording in FAQ
docs: fix odd wording in CONTRIBUTE.md
docs: note CURLOPT_PINNEDPUBLICKEY has no effect on legacy LDAP backend
docs: returned header size reflects HTTP/1-style format
doh: cap the maximum TTL to 24 hours
doh: stricter HTTPS RNAME parsing
ECH: cleanups
event: fix wakeup consumption
ftp: avoid accessing EPSV response one byte past the NULL
ftp: remove 2 Curl_resolv_blocking() calls
ftp: remove bits.ftp_use_control_ssl
ftplistparser: clear strings.target if not symlink
gnutls: allow building with nettle 4.0
gnutls: fix more nettle 4+ compatibility issues
gnutls: require 3.7.2 for earlydata
gsasl: fix potential double free
gtls: fix ignored return and uninitialized status in OCSP check
gtls: fix some typos
gtls: minor fixes and improvements
gtls: use the correct return code in trace output
gtls: verify OCSP response signature in gtls_verify_ocsp_status
h3-proxy: fix callback return values, and a typo in tests
hostip: remove unused MAX_HOSTCACHE_LEN and MAX_DNS_CACHE_SIZE
hsts.md: mention multiple curl invokes effect
hsts: duplicate live HSTS data in curl_easy_duphandle
http-proxy: verify CONNECT response headers
HTTP3.md: update quiche build
http: don't pass on set cookies to new origins
http: prefer chunked encoding over Content-Length: 0
http: reject spurious CR bytes in headers
http_digest: return better error
idn: replace header guards with forward declaration
INSTALL-CMAKE.md: document CMake environment variables
INTERNALS.md: document minimum nghttp3 and ngtcp2 versions
KNOWN_BUGS.md: remove fixed GnuTLS <-> OpenSSL incompat bug
KNOWN_BUGS: remove stale Threads::Threads entry
krb5_sspi: fix error message on `DecryptMessage()` fail
ldap: base64 encode binary LDIF values with WinLDAP
ldap: fix minor leak on write callback error
ldap: fix to not leak `attribute` on OOM (WinLDAP)
ldap: switch off chasing referrals
lib678: fix to not be perma-skipped
lib: make `__STDC_VERSION__` literals `L` (where missing)
lib: transfer origin and proxy handling
lib: two minor typos
libcurl-easy.md: minor clarifications
libssh2: do not use deprecated macros when unavailable
libssh2: drop stray double-negative from `strncmp()` result
libssh2: fix to return error code on missing parameter
libssh2: replace macro names with non-misspelled alternatives
libssh2: save non-standard port to `known_hosts`
libssh2: sync version check with INTERNALS.md
libssh2: use non-deprecated `libssh2_knownhost_addc()`
libssh: map SSH_KNOWN_HOSTS_OTHER to CURLKHMATCH_MISMATCH
m4: drop redundant conditions in TLS library detections
Makefile.am: drop test1190 listed twice
managen: apply minor fixes and improvements
mbedtls: null-terminate the private key blob
mk-unity.pl: `#include`, and not concatenate input headers
mqtt: return error on truncated Remaining Length
mqtt: validate PINGRESP and DISCONNECT have remaining_length == 0
multi: handle pause in multi socket callback
multi: remove a stale comment
multi: silence gcc 16 `-Wnull-dereference`, bump CI job to test
multi: xfers_really_alive
netrc: remember and check filename loaded
netrc: scanner refactor
ngtcp2: fail handshake directly
openssl: do not mix OpenSSL int result with `CURLcode` variable
os400sys: fix theoretical length overflows
peer.h: fix typo in comment
pingpong: reject nul byte in server response line
progress: fix CURLINFO time reporting
psl: require libpsl 0.16.0 (2016-12-10) or greater
pytest: pass `--disable` to curl
pytest: re-enable test test_05_01 and test_05_02 for quiche 0.29.0+
pythonlint.sh: make it fail on error, fix ruff warnings in pytest
quic: count zero length packets against max
ratelimits: use minimal burst rate
RELEASE-PROCEDURE.md: update coming release dates
resolve: mention in error that IP address is expected
rtsp: bump buf after rtsp_filter_rtp()
runner.pm: apply minor correctness fix
runner.pm: set `CURL_TESTNUM` for `precheck` commands
runtests: fix tests for curl builds with embedded CA bundle
rustls: error on CURLOPT_CRLFILE with native CA store
schannel: check `schannel_sha256sum()` success, and more
schannel: enforce Extended Key Usage for custom CA roots
schannel: error on TLS 1.3-only with cipher list
schannel: fix https proxy for client cert and certinfo
schannel: fix revoke_best_effort setting for proxy
schannel: use fopen instead CreateFile
schannel_verify: avoid out of blob access
schannel_verify: simplify CryptQueryObject use
scripts: catch Credits-to contributors
SECURITY-ADVISORY.md: expand
setopt: changing the proxy port is also a proxy change
setopt: clear proxy auth properly on NULL
setopt: clear the "custom" CA booleans when set to NULL
setopt: CURLOPT_MAXCONNECTS set to 0 restores default value
setopt: defref the old referer when setting a new
setopt: fix to honor `CURLOPT_PROXY_CAINFO_BLOB` over Native CA
setopt: gate a few proxy TLS options by checking backend support
setopt: more careful cleanup of the HSTS cache
setopt: return error if received `curl_blob->data` is NULL
show-headers.md: mention bold headers and --no-styled-output
sigv4: URL encode the username in the header
smb: constify `strchr()` result variable
smb: integer overflow proof a size check
smbserver: update internal id generation for Python 3
socket: introduce `SOCK_EAGAIN()` and use it
socket: use name `sockerr` for socket error variables
socks_sspi: invalid response length is a fatal error
socks_sspi: store socks5_gssapi_enctype
spnego_sspi: honor CURLOPT_GSSAPI_DELEGATION for Windows SSPI
spnego_sspi: preserve distinction btw policy-only and uncond delegation
src: fix comment typos
src: sync nghttp2 versions checks with current requirements
ssl native_ca_store: always reinit
SSLCERTS: document 8.19.0 default Native CA builds (Windows)
sspi: clear SSPI credentials on AcquireCredentialsHandle failure
sspi: free libcurl allocated memory with curlx_free
telnet: drop an `int` cast no longer necessary
telnet: drop redundant interim variables
telnet: fix error message typos
telnet: fix old copy-paste typo in variable name
telnet: honor CURLOPT_TIMEOUT in send_telnet_data()
test1588: use %TESTNUMBER, not hard-coded number
test1981: explicitly set the locale
tests: add `cookies` feature to some tests
tests: add an assert to avoid IPC blocking
tests: add the "--resolve" keyword to tests that lack it
tests: fix unit1636 with --disable-progress-meter
tftp: avoid the timeout calc if the timeout is crazy
tftp: stricter option name checks
tidy-up: add space around operators, where missing
tidy-up: apply clang-format fixes
tidy-up: drop stray casts for allocated pointers
tidy-up: miscellaneous
tls: fix incomplete mTLS config in conn reuse and session cache
tls: wolfssl: fixes for PQC key shares
tool: warn when --ssl and --ftp-ssl-control override each other
tool_formparse.c: fix two minor comment typos
tool_formparse: polish error message + make two functions static
tool_formparse: tool2curlparts is no longer recursive
tool_help: rectify a bad assert
tool_operhlp: avoid NULL to %s
tool_urlglob: avoid overflow at end of range
tool_urlglob: better 'Duplicate glob name' position
tool_urlglob: make globbing error reported for correct position
tool_writeout: fix %time{} output for %s
transfer: clear referer when set to NULL
unit1675: fix potential memory leak on dynbuf fail path
unix-sockets: ignore proxy settings
URL-SYNTAX: document more URL parsing details
url: compare full origin when setting credentials
url: connection credentials origin
url: connection reuse fixes for starttls
url: detect proxy changes read from environment
url: don't log bits.close state
url: fix connection reuse for starttls protocols
url: keep the question mark for empty queries
url: remove superfluous check
url: url_match_destination fix
urlapi: accept 0X prefix in IPv4 address as well
urlapi: change more lowercase percent-encoded to uppercase
urlapi: compare zone-id in Curl_url_same_origin()
urlapi: consume trailing dots after IPv4 numerical addresses
urlapi: deny hostnames with more than one trailing dot
urlapi: drop base fragment on empty redirect
urlapi: fix an issue parsing file URLs
urlapi: fix memleaks on error in `parse_hostname_login()`
urlapi: fix redirect handling if CURLU_NO_GUESS_SCHEME is set
urlapi: forbid '|' in host
urlapi: handle redirect without set scheme with default-scheme
urlapi: URL decode hostname before IP address normalization
user-agent.md: mention double quotes too
var: use a dedicated pointer for the alloc
verify-release: verify more thoroughly with git
vquic: drop stray casts for `iovec.iov_len`
vtls: more large buffer support and error checks for SHA-256
vtls: use Curl_safecmp for CRLfile and pinned_key comparison
vtls_scache: include signature_algorithms in the SSL peer cache key
vtls_spack: drop redundant macro fallbacks
VULN-DISCLOSURE-POLICY.md: emphasize comm as a human
VULN-DISCLOSURE-POLICY.md: emphasize the no email thank you part
VULN-DISCLOSURE-POLICY.md: test code is not secure
VULN-DISCLOSURE-POLICY: non-released code
websockets: auto-tunnel through http proxy
websockets: buffer upgrade data at connection level
windows: update MS SDK versions in comments
winldap: avoid NULL pointer deref on `ldap_get_dn()` fail
ws: make pong sending lazy
x509asn1: fix DH public key parameter extraction
x509asn1: fix operator order in do_pubkey
|
| 2026-06-07 20:03:46 by Adam Ciarcinski | Files touched by this commit (7) |
Log message:
curl/libcurl-gnutls: fix build with nettle 4.0; support Darwin
|
| 2026-06-01 12:10:12 by Leonardo Taccari | Files touched by this commit (1) |
Log message:
curl: document the circular dependency
We have it in the CVS history, but let's document it as an "XXX" \
comment too so
possible future hands are less tempted to just uncomment them!
Thanks <ryoon> and Marc Baudoin!
|
| 2026-06-01 05:36:08 by Ryo ONODERA | Files touched by this commit (1) |
Log message:
www/curl: Remove http3 option
nghttp3, cmake and curl cause circular dependency.
Reported by Marc Baudoin. Thank you.
|