Sign in

Matthias Sohn

@msohn.bsky.social
99 followers 202 following 11 posts

Open Source fan, runner, maintainer of EGit, JGit, Gerrit Code Review, plays double bass, working for SAP

PostsRepliesMedia
Reposted by Matthias Sohn
Umweltinstitut München e.V. @umweltinstitut.org · 08/10/2026
@ckemfert.bsky.social bringt es auf den Punkt: Das ohnehin wenig ambitionierte Energieeffizienzgesetz weiter abzuschwächen, ist energiepolitisch wie ökonomisch der falsche Weg.
Foto von Prof. Dr. Claudia Kemfert, Energieökonomin am Deutschen Institut für Wirtschaftsforschung. Zitat: "Energieeffizienz ist eine der günstigsten Möglichkeiten, Energiekosten zu senken und unsere Wettbewerbsfähigkeit zu stärken. Wer mit weniger Energie dieselbe Wertschöpfung erzielt, spart Kosten, schützt das Klima und verringert die Abhängigkeit von Energieimporten. Das Energieeffizienzgesetz jetzt an zentralen Stellen zu schwächen, wäre ökonomisch wie energiepolitisch der falsche Weg."
17934
Reposted by Matthias Sohn
Eclipse Foundation @eclipse.org · 07/10/2026
📣 Eclipse Qrisp has won the Quantum Effects Award 2026 in the Quantum Computing Software & Algorithms category. Read the full press release ➡️ newsroom.eclipse.org/news/announc... Join the Eclipse Qrisp Community Day on 29 October ➡️ qrisp.eu/general/comm... #HPC #QuantumComputing #QuantumSoftware
011
Reposted by Matthias Sohn
Olli Garchy @ernesto-761-167.bsky.social · 15/09/2026
Auf jeden Fall erst einmal das Deutschlandticket für alle günstiger machen!
2237
Reposted by Matthias Sohn
Solarenergie Förderverein Deutschland e.V. @sfv.de · 14/09/2026
Aktuelle Energiepolitik in Deutschland ...
Eine Karikatur zeigt einen Transporter mit der Aufschrift „PRIVAT ERZEUGTER SOLARSTROM“, der vor einer Felswand steht. Auf der Felswand schiebt ein Mann einen Stein mit der Aufschrift „EINSPEISEVERBOT“ hinunter, um den Weg zum „STROMMARKT“ zu versperren. Eine Frau lobt ihn: „Super, Friedrich! Ganz toll machst du das!!“.
210534
Reposted by Matthias Sohn
Russ Cox @swtch.com · 14/09/2026
Also worth remembering that people are responsible for running these AI systems. They choose how to train them, how to run them, how to let them interact with their environments, how to use their outputs. Claims by AI companies that "AI will kill us all" are passive voice on steroids.
1338
Reposted by Matthias Sohn
Terence Tao @teorth.bsky.social · 11/09/2026
A group of 25 Fields Medalists, including myself, have made a joint declaration on Math and AI: mathandai.org . We welcome additional signatories. See also this article in the Economist announcing the declaration: www.economist.com/science-and-...
mathandai.org
Declaration — Math and AI
Read the declaration and add your name.
422075934
Reposted by Matthias Sohn
Beatrice @schneckbeth.bsky.social · 07/09/2026
Dem ist nichts hinzuzufügen.
591225512
Reposted by Matthias Sohn
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 02/09/2026
As the #FOSDEM 2027 weekend is confirmed, It might be time to check out my FOSDEM guide and help me polish it further: github.com/bagder/FOSDEM
github.com
GitHub - bagder/FOSDEM: Advice for FOSDEM attendees
Advice for FOSDEM attendees. Contribute to bagder/FOSDEM development by creating an account on GitHub.
0177
Reposted by Matthias Sohn
Ira Hyman @irahyman.bsky.social · 18/08/2026
So this would be a Brass Tax? Getting down to the important point of tariff policy.
6409
Reposted by Matthias Sohn
Der Postillon 📯 @der-postillon.com · 11/08/2026
Anpassung an die Realität: Bundesländer ändern Namen in "Nord-Westfalen" und "Land-Pfalz" www.der-postillon.com/2026/08/nord...
der-postillon.com
Anpassung an die Realität: Bundesländer ändern Namen in "Nord-Westfalen" und "Land-Pfalz"
Deutschlands größte Tageszeitung der Welt
631926450
Reposted by Matthias Sohn
the Juice Media @thejuicemedia.com · 11/08/2026
The Government™ has made an ad about Ai Data Centres, and it’s surprisingly honest and informative.
youtube.com
Honest Government Ad | Ai Data Centres
YouTube video by thejuicemedia
25699418
Reposted by Matthias Sohn
Katharina Nocun @kattascha.bsky.social · 04/08/2026
Das alles fühlt sich zunehmend wie ein „Don‘t look up“-LARP an. 🫤
Das mitunter deprimierendste am Umgang mit der Klimakrise ist: Wenn man mit Umweltökonomen spricht, sagen die: "Das wäre alles locker machbar, wenn der politische Wille da wäre". Auch ohne große Einbußen für den Wohlstand. Einfach nur ordentlich besteuern & regulieren.
Aber je länger wir warten oder gar zurückrudern, desto drastischer werden in Zukunft die Maßnahmen sein müssen. Und irgendwann ist es halt zu spät. Das ist alles so unnötig, dass es weh tut.
612568817
Reposted by Matthias Sohn
Patrick 🥦 @omega2k.de · 03/08/2026
Es ist einfach Irrsinn was da passiert...
youtu.be
Geleakt: So sieht LOBBY Arbeit aus! Energiewende von unten? Gekillt! UND KEINE SAU MERKTS!
YouTube video by Andreas Schmitz (Der Akku Doktor)
0229
Reposted by Matthias Sohn
Bernd von Mallinckrodt @vonmallinckrodt.bsky.social · 31/07/2026
Woran scheitern komplexe #Systeme häufiger … an fehlendem Wissen oder am Ignorieren hochwertiger Rückmeldungen? Wer wissenschaftlich geprüfte #Signale erst dann ernst nimmt, wenn Krisen sichtbar werden, bezahlt am Ende den höchsten Preis. FCQ – Feedback Channel Quality: doi.org/10.5281/zeno...
Die eigentliche Gefahr für die Wettbewerbsfähigkeit ist nicht der Klimaschutz, sondern dass wir die Modernisierung verschleppt haben und die Schäden für das unzureichende Handeln zahlen müssen. Das sind fossile Energieimporte und das sind die Kosten für die Krisenbewältigung.
Ökonomin
Claudia Kemfert
fordert starkere Investitionen in Erneuerbare Energien und E-Mobilität
15117
Reposted by Matthias Sohn
Line Lazarus @linelazarus.eurosky.social · 27/07/2026
Stop Palantir!! A powerful US spy-tech company linked to genocide in Gaza, ICE deportations, and Trump’s war with Iran is now expanding across Europe into our hospitals, police and data systems. We must expose it and stop its expansion action.wemove.eu/sign/2026-03...
action.wemove.eu
Say No to Palantir in Europe
Share the petition and you'll help multiply the impact of this campaign: Say No to Palantir in Europe
02520
Reposted by Matthias Sohn
FragDenStaat @fragdenstaat.de · 24/07/2026
Wirtschaftsministerin Reiche steht seit Amtsantritt für ihre Industrienähe & das Ausbremsen erneuerbarer Energien in der Kritik. Unterlagen, die wir mit dem IFG befreit haben, zeigen: Beim Netzpaket orientiert sie sich an den Wünschen ihres alten Arbeitgebers Eon. fragdenstaat.de/artikel/exkl...
fragdenstaat.de
Katherina Reiche: Die Eon-Ministerin
Die Wirtschaftsministerin plant massive Änderungen beim Ausbau erneuerbarer Energien – und will dabei ein zentrales Konzept ihres vorherigen Arbeitgebers umsetzen. Es ist nicht das erste Mal, dass sie...
371236612
Reposted by Matthias Sohn
Katharina Nocun @kattascha.bsky.social · 21/10/2025
Das ist für mich ein Kennzeichen wahren gesellschaftlichen Fortschritts. Dass wir es schaffen, da wo es darauf ankommt, ein System zu bauen, wo Geld - zumindest in einem bestimmten Rahmen -, nicht mehr über die Würde & das Leben eines Menschen entscheidet. Wünsche mir mehr davon. Und nicht weniger.🤝
461824131
Reposted by Matthias Sohn
WWF Deutschland @wwf.de · 22/07/2026
Wir Umweltverbände warnen die Bundesregierung dringend davor, mit ihren Plänen für EEG und Netzpaket die Energiewende auszubremsen. Die Energiewende wird dadurch auch nicht "billiger" btw, im Gegenteil: www.dnr.de/presse/press...
dnr.de
Fataler Rückschritt für Energiewende und Elektrifizierung | Deutscher Naturschutzring
Zum heutigen Ende der Verbändeanhörung zum Netzpaket und zur EEG-Novelle warnen die Umweltorganisationen BUND, Deutsche Umwelthilfe, Germanwatch, NABU, Umweltinstitut München und WWF Deutschland unter...
06817
Reposted by Matthias Sohn
Dr. Wolfgang Gründinger @wolfibey.bsky.social · 17/07/2026
Claudia Kemfert, was kostet die Energiewende? 😯 Sie ist die Galionsfigur gegen das Weiter-so: Prof. Claudia Kemfert @claudiakem.bsky.social, die bekannteste Energieökonomin Deutschlands. Und sie warnt: Wir verspielen unsere Energiezukunft. youtu.be/N8zVjtu247k?... Reinhören, weiterempfehlen!
youtu.be
Was kostet die Energiewende, Claudia Kemfert?
YouTube video by Enpal: Erfahrungen, Tipps & Produkte
04211
Reposted by Matthias Sohn
Sascha Pallenberg @palle.eurosky.social · 18/07/2026
Am Sonntag gibt es den 2. Teil meiner Analyse zur KI-Investmentblase und der wird, sorry TL;DR-Fraktion, wieder ziemlich ausfuehrlich! Das heisst aber auch, dass ihr wieder massig weiterfuehrende Links/Berichte & nen blegleitenden Podcast bekommt.... fuer Umme 🥳 www.metacheles.de/ki-blase-dur...
metacheles.de
KI-Blase durchgerechnet: Erst zahlen, dann erschrecken!
Heute keine SpaceX-Sonderausgabe, sondern die Mutter aller Bauboome: der globale KI- und Rechenzentrums-Rausch. Ich habe mich durch SEC-Unterlagen, Quartalszahlen, Studien und die Berichterstattung vo...
0267
Reposted by Matthias Sohn
Greenpeace e.V. @greenpeace.de · 17/07/2026
Warum steigt unsere #Wasserrechnung? DE ist EU-Nitrat-Sünder! Niederlande überwachen #Gülle digital, hier erlaubt Minister Rainer (CSU) Zettelwirtschaft & weicht Gesetze auf. Schaden: 182 Mrd. €/Jahr. Schutz vor dem Ganzen würde nur 3 Mrd. kosten. Die Zeche für den Mist zahlen wir Verbraucher:innen!
05133
Reposted by Matthias Sohn
Johannes Bechberger @mostlynerdless.de · 07/07/2026
SAP joined the OpenJDK 15 years ago on the 14th of July 2011, contributing many ports, features, and ecosystem improvements. Let's celebrate: https:// mostlynerdless.de/blog/2026/07/07/celebrating-15-years-of-saps-involvement-in-the-openjdk/
mostlynerdless.de
Celebrating 15 years of SAP's involvement in the OpenJDK - Mostly nerdless
SAP joined the OpenJDK 15 years ago on the 14th of July, contributing many ports, features and ecosystem improvements. Let's celebrate.
031
Reposted by Matthias Sohn
Mikael Barbero @mikael.barbero.tech · 06/07/2026
Go learn, for free, what the CRA entails with this great resource. It should be your top learning priority for the summer!
011
Reposted by Matthias Sohn
Aura Salla @aurasalla.bsky.social · 01/07/2026
Today, we held the @eppgroup.bsky.social Digital Omnibus hearing on simplifying the GDPR and Data Act for European competitiveness. The report is out and amendments can be tabled until 15 July. The requested impact assessment is due in autumn, and our final position can be expected in early 2027.
063
Reposted by Matthias Sohn
Eclipse Foundation @eclipse.org · 16/06/2026
🥁 Google has joined the #EclipseFdn as a Strategic Member, strengthening our shared commitment to open infrastructure for AI-integrated developer tools. Read the news: opensource.googleblog.com/2026/06/goog...
143
Reposted by Matthias Sohn
Markus Pössel @mpoessel.de · 24/05/2026
Dazu haben wir Christian Holler von der Hochschule München in der Sendung. Der kennt sich beim Thema Energiewende aus, und ist u.a. Koautor der deutschen Version von "Erneuerbare Energien ohne heisse Luft" ohne-heisse-luft.de wo das alles mit Zahlen, Abschätzungen, Diagrammen präsentiert wird.
ohne-heisse-luft.de
Erneuerbare Energien – OHNE HEISSE LUFT
1186
Reposted by Matthias Sohn
Deiner Mudda @deinermudda.bsky.social · 16/05/2026
seit wir hier auf dem hausdach Solar und im keller 4 batterien haben, also seit April, ist es ein komplett anderes lebensgefühl. wir geben teilweise 99,5% Strom ans Netz ab, kommen ohne Netzstrom durch die Nacht, um 10 Uhr sind die Batterien wieder voll. Die Diskussion um neue Kraftwerke war
1429
Reposted by Matthias Sohn
The Devil's Therapist @d3v1ls7h3r4p157.bsky.social · 16/05/2026
042
Reposted by Matthias Sohn
Chris Aniszczyk @cra.dev · 15/05/2026
"Fleet-Scale Kubernetes: An Operating Model for Homogeneous Clusters with Decoupled Capacity" lucy.sh/fleet-scale-...
lucy.sh
Fleet-Scale Kubernetes: An Operating Model for Homogeneous Clusters with Decoupled Capacity
Kubernetes was designed for a single cluster. As organisations scale to fleets of tens, hundreds, or thousands of clusters, the operational model hasn't kept up. This paper proposes one that does.
032
Reposted by Matthias Sohn
gerritreview.bsky.social @gerritreview.bsky.social · 16/05/2026
#GerritCodeReview v3.14.0 has been released 🚀 with full support for #AI reviews integrated into the Change Screen. Farewell to v3.11.x, which is now end-of-life, *UPGRADE* now groups.google.com/g/repo-discu...
groups.google.com
[ANNOUNCE] Gerrit 3.14.0
001
Reposted by Matthias Sohn
dertim21.bsky.social @dertim21.bsky.social · 09/05/2026
bsky.app/profile/info...
042
Reposted by Matthias Sohn
Anna Bower @annabower.bsky.social · 07/05/2026
EXCLUSIVE: In 2022, a Georgia grand jury investigated Trump’s alleged interference in the 2020 election. It heard from more than 60 witnesses. For years, the full record of what those witnesses said under oath has remained hidden from public view. Until now. www.lawfaremedia.org/projects-ser...
5230391433
Reposted by Matthias Sohn
howardbealefl.bsky.social @howardbealefl.bsky.social · 01/05/2026
081
Reposted by Matthias Sohn
Mike Meadway 🇪🇺 🇩🇰 🇬🇧 🏴󠁧󠁢󠁳󠁣󠁴󠁿 @mmeadway.bsky.social · 30/04/2026
I was reminded this morning of something IBM noted in 1978: "A computer can never be held accountable. Therefore, a computer must never make a management decision."
16763461577
Reposted by Matthias Sohn
Auke Hoekstra @aukehoekstra.bsky.social · 28/04/2026
Potentially hyper-cheap sodium batteries are becoming commercially available and are getting LFP battery specs. This is nuts! This could lead to *incredibly* cheap batteries! electrek.co/2026/04/27/c...
11394124
Reposted by Matthias Sohn
Claudia Kemfert @ckemfert.bsky.social · 19/04/2026
Sehr guter Zusammenschnitt – danke! Fossile Energiekrise klar benannt, Lösungen aufgezeigt. Darum geht’s. 👇
414646
Reposted by Matthias Sohn
cargobike.bsky.social - Teilen bringt Reichweite bei Bsky! @cargobike.bsky.social · 18/04/2026
Das was @ckemfert.bsky.social sagt!
210624
Reposted by Matthias Sohn
Jan Hegenberg @graslutscher.de · 14/04/2026
Stellt euch vor, ihr steht am Strand und seht eine Gruppe Kinder auf Luftmatratzen, die durch den Sog der Ebbe ins offene Meer hinaustreiben. Ihr seid noch ab Abwägen, ob Ihr Hilfe holen oder euch direkt selbst in die Wellen stürzen sollt, da blitzt von Ferne eine... graslutscher.de/kann-irgendw...
graslutscher.de
Kann irgendwer Katherina Reiche erklären, dass die Energiewende jetzt ihr Job ist?
Stellt euch vor, ihr steht am Strand und seht eine Gruppe Kinder auf Luftmatratzen, die durch den Sog der Ebbe ins offene Meer hinaustreiben. Ihr seid noch ab Abwägen, ob Ihr Hilfe holen oder euch
11341125
Reposted by Matthias Sohn
Timothy Snyder @timothysnyder.bsky.social · 06/04/2026
We are seven months away from the most consequential midterm election in US history. Meanwhile, we are fighting a war. These are the structural conditions for a coup attempt in which a president tries to nullify elections and take permanent power as a dictator. snyder.substack.com/p/the-next-c...
snyder.substack.com
The Next Coup Attempt
And How to Stop It
6725181145
Reposted by Matthias Sohn
Matthias Lambrecht @matlamb.bsky.social · 27/03/2026
Wir brauchen keine fossile Interessenspolitik für wenige, sondern echte Entlastung für alle: Mehr Wärmepumpen, Ausbau des ÖPNV und bezahlbare E-Mobilität. Der Kanzler muss seine Ministerin stoppen! 4/4
072
Reposted by Matthias Sohn
Peter Magulski @magulski.com · 10/03/2026
Leider vermischt sich hier der Humor mit der Realität. Sehr treffend von @ruthe.de.
Eine Frau versteckt sich hinter einem Busch und hat eine Wolke, die eine PV Anlage beschattet, an einer Leine auf der steht "Präsentiert von GASLOBBY". Zwei Menschen unterhalten sich, der eine sagt zum anderen: "WIr können Sie sehen, Frau Reiche!".
1950289
Reposted by Matthias Sohn
Patrick Graichen @pgraichen.bsky.social · 06/03/2026
initiative-klimaneutral.de/mee/
initiative-klimaneutral.de
Monitoring Energiewende im Eigenheim 2025
Eine breite Mehrheit der Haus­besitzerinnen und Hausbesitzer ist bereit, in Photovoltaik, Wärmepumpe & Co. zu investieren – sofern die Rahmenbedingungen stimmen.
1243
Reposted by Matthias Sohn
Martin Hundhausen @mhundhausen.bsky.social · 06/03/2026
Nachdem Trump nun auch Ministerinnen entlässt, frage ich mich, ob Kanzler Merz nach allen Verfehlungen von Gaslobbyiistin Reiche wirklich an ihr festhalten will. Ihre Pläne beim GEG (jetzt Gebäudemonderinsierungsgesetz) und beim EEG sind sehr problematisch und nutzen nur Putin/Trump&Co
4485
Reposted by Matthias Sohn
Jan Rosenow @janrosenow.bsky.social · 04/03/2026
Over 40% of global shipping by volume exists to move fossil fuels from one place to another. A huge share of the world's maritime infrastructure has been built around a system that is going to change dramatically as renewable energy and electrification displace fossil fuels.
33769359
Reposted by Matthias Sohn
Chris Aniszczyk @cra.dev · 18/02/2026
"Open source registries don't have enough money to implement basic security" www.theregister.com/2026/02/16/o...
theregister.com
Open source registries underfunded as security costs rise
fosdem 2026: Free beer is great. Securing the keg costs money
031
Reposted by Matthias Sohn
Léαlinux 🐧 @lea-linux.org · 29/01/2026
Quoi ? Linus n'est pas éternel ? www.clubic.com/actualite-59...
clubic.com
Linux : un plan officiel pour succéder à Linus Torvalds émerge
Le mythe du dictateur bienveillant a la vie dure, mais la biologie est impitoyable. Si Linus Torvalds disparaissait demain, le monde numérique s'arrêterait-il de tourner ? La communauté Linux a enfin ...
3195
Reposted by Matthias Sohn
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 26/01/2026
The end of the #curl bug-bounty daniel.haxx.se/blog/2026/01/26/the-…
daniel.haxx.se
The end of the curl bug-bounty
tldr: an attempt to reduce the _terror reporting_. **There is no longer a curl bug-bounty program.** It officially stops on January 31, 2026. After having had a few half-baked previous takes, in April 2019 we kicked off the first real curl bug-bounty with the help of Hackerone, and while it stumbled a bit at first it has been quite successful I think. We attracted skilled researchers who reported plenty of actual vulnerabilities for which we paid fine monetary rewards. We have certainly made curl better as a direct result of this: **87 confirmed vulnerabilities and over 100,000 USD** paid as rewards to researchers. I’m quite happy and proud of this accomplishment. I would like to especially highlight the awesome Internet Bug Bounty project, which has paid the bounties for us for many years. We could not have done this without them. Also of course Hackerone, who has graciously hosted us and been our partner through these years. Thanks! ## How we got here Looking back, I think we can say that the downfall of the bug-bounty program started slowly in the second half of 2024 but accelerated badly in 2025. We saw an explosion in AI slop reports combined with a lower quality even in the reports that were not obvious slop – presumably because they too were actually misled by AI but with that fact just hidden better. Maybe the first five years made it possible for researchers to find and report the low hanging fruit. Previous years we have had a rate of somewhere north of 15% of the submissions ending up confirmed vulnerabilities. Starting 2025, the confirmed-rate plummeted to below 5%. Not even one in twenty was _real_. The never-ending slop submissions take a serious mental toll to manage and sometimes also a long time to debunk. Time and energy that is completely wasted while also hampering our will to live. I have also started to get the feeling that a lot of the security reporters submit reports with a _bad faith attitude._ These “helpers” try too hard to twist whatever they find into something horribly bad and a critical vulnerability, but they rarely actively contribute to actually _improve_ curl. They can go to extreme efforts to argue and insist on their specific current finding, but not to write a fix or work with the team on improving curl long-term etc. I don’t think we need more of that. There are these three bad trends combined that makes us take this step: the mind-numbing AI slop, humans doing worse than ever and the apparent will to poke holes rather than to help. ## Actions In an attempt to do something about the sorry state of curl security reports, this is what we do: * We no longer offer any monetary rewards for security reports – no matter which severity. In an attempt to remove the incentives for submitting made up lies. * We stop using Hackerone as the recommended channel to report security problems. To make the change immediately obvious and because without a bug-bounty program we don’t need it. * We refer everyone to submit suspected curl security problems on GitHub using their _Private vulnerability reporting_ feature. * We continue to immediately _ban and publicly_ _ridicule_ everyone who submits AI slop to the project. ## Maintain curl security We believe that we can maintain and continue to evolve curl security in spite of this change. Maybe even improve thanks to this, as hopefully this step helps prevent more people pouring sand into the machine. Ideally we reduce the amount of wasted time and effort. I believe the best and our most valued security reporters still will tell us when they find security vulnerabilities. ## Instead If you suspect a security problem in curl going forward, we advise you to head over to GitHub and submit them there. Alternatively, you send an email with the full report to `security @ curl.se`. In both cases, the report is received and handled privately by the curl security team. But with _no monetary reward offered_. ## Leaving Hackerone Hackerone was good to us and they have graciously allowed us to run our program on their platform for free for many years. We thank them for that service. As we now drop the rewards, we feel it makes a clear cut and displays a clearer message to everyone involved by also moving away from Hackerone as a platform for vulnerability reporting. It makes the change more visible. ## Future disclosures It is probably going to be harder for us to publicly disclose every incoming security report in the same way we have done it on Hackerone for the last year. We need to work out something to make sure that we can keep doing it at least imperfectly, because I believe in the goodness of such transparency. ## We stay on GitHub Let me emphasize that this change does not impact our presence and mode of operation with the curl repository and its hosting on GitHub. We hear about projects having problems with low-quality AI slop submissions on GitHub as well, in the form of issues and pull-requests, but for curl we have not (yet) seen this – and frankly I don’t think switching to a GitHub alternative saves us from that. ## Other projects do better Compared to others, we seem to be affected by the sloppy security reports to a higher degree than the average Open Source project. With the help of Hackerone, we got numbers of how the curl bug-bounty has compared with other programs over the last year. It turns out curl’s program has seen more volume and noise than other public open source bug bounty programs in the same cohort. Over the past four quarters, curl’s inbound report volume has risen sharply, while other bounty-paying open source programs in the cohort, such as Ruby, Node, and Rails, have not seen a meaningful increase and have remained mostly flat or declined slightly. In the chart, the pink line represents curl’s report volume, and the gray line reflects the broader cohort. Inbound Report Volume on Hackerone: curl compared to OSS peers We suspect the idea of getting money for it is a big part of the explanation. It brings in real reports, but makes it too easy to be annoying with little to no penalty to the user. The reputation system and available program settings were not sufficient for us to prevent sand from getting into the machine. The exact reason why we suffer more of this abuse than others remains a subject for further speculation and research. ## If the volume keeps up There is a non-zero risk that our guesses are wrong and that the volume and security report frequency will keep up even after these changes go into effect. If that happens, we will deal with it then and take further appropriate steps. I prefer not to overdo things or _overplan_ already now for something that ideally does not happen. ## We won’t charge People keep suggesting that one way to deal with the report tsunami is to _charge_ security researchers a small amount of money for the privilege of submitting a vulnerability report to us. A _curl reporters security club_ with an entrance fee. I think that is a less good solution than just dropping the bounty. Some of the reasons include: * Charging people money in an International context is complicated and a maintenance burden. * Dealing with charge-backs, returns and other complaints and friction add work. * It would limit who could or would submit issues. Even some who actually find legitimate issues. Maybe we need to do this later anyway, but we stay away from it for now. ## Pull requests are less of a problem We have seen other projects and repositories see similar AI-induced problems for pull requests, but this has not been a problem for the curl project. I believe for PRs we have better much means to sort out the weed with automatic means, since we have tools, tests and scanners to verify such contributions. We don’t need to waste any human time on pull requests until the quality is good enough to get green check-marks from 200 CI jobs. ## Related I will do a talk at FOSDEM 2026 titled Open Source Security in spite of AI that of course will touch on this subject. ## Future We never say never. This is now and we might have reasons to reconsider and make a different decision in the future. If we do, we will let you know. These changes are applied now with the hope that they will have a positive effect for the project and its maintainers. If that turns out to not be the outcome, we will of course continue and apply further changes later. ## Media Since I created the pull request for updating the bug-bounty information for curl on January 14, almost two weeks before we merged it, various media picked up the news and published articles. Long before I posted this blog post. * The Register: Curl shutters bug bounty program to remove incentive for submitting AI slop * Elektroniktidningen: cURL removes bug bounties * Heise online: curl: Projekt beendet Bug-Bounty-Programm * Neowin: Beloved tool, cURL is shutting down its bug bounty over AI slop reports * Golem: Curl-Entwickler dreht dem “KI-Schrott” den Geldhahn zu * Linux Easy: cURL chiude il programma bug bounty: troppi report generati dall’AI * Bleeping Computer: Curl ending bug bounty program after flood of AI slop reports * The New Stack: Drowning in AI slop, cURL ends bug bounties * Ars Technica: Overrun with AI slop, cURL scraps bug bounties to ensure “intact mental health” * PressMind Labs: cURL ko?czy program bug bounty – czy to koniec jako?ci zg?osze?? * Socket: curl Shuts Down Bug Bounty Program After Flood of AI Slop Reports Also discussed (indirectly) on Hacker News.
66475
Reposted by Matthias Sohn
Esther Schindler @estherschindler.bsky.social · 22/01/2026
This!
"Think not of the books you've bought as a 'to be read' pile. Instead, think of your bookcase as a wine cellar. You collect books to be read at the right time, the right place, and the right mood." --Luc van Donkersgoed
022
Reposted by Matthias Sohn
Adam Schwarz @adamjschwarz.bsky.social · 19/01/2026
Danish Parliament Deputy Speaker Lars-Christian Brask: "If I could come with some advice, it would be for the Senate & House to start to take control of political power in America because with this erratic & mad behaviour, you have to ask the question, is the President capable of running the US?"
17013472511934