Related Article: About the security content of macOS Ventura 13.2

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Could you update curl to 7.87.0 in next ventura?

There is a regression in curl 7.86.0 in the .netrc handling, fixed in 7.87.0.

It's apparently Apple's fault if you have that version shipped and not yet updated.


https://github.com/curl/curl/pull/9973#issuecomment-1408606835

iMac 27″, macOS 10.14

Posted on Jan 30, 2023 7:34 AM

Reply
8 replies

Jan 30, 2023 9:30 AM in response to Barney-15E

I experienced a problem on curl on Ventura 13.2 where I checked the reason by recompiling curl. And linked the commit that fix the problem, which is not included in the curl shipped in 13.2. It's quite a minor issue, that would probably only affect developpers, as I see no reason for other people to use curl.


What do you mean by that stuff isn't true? How do I get a warning against conspiracy theory already?

I just talked about Rapid Security Responses on Apple devices - Apple Support (CA) and I read it was used to update on 13.2 (I had problem to install that 13.2 because of the Preboot) . Now I worry about this :D

Jan 30, 2023 7:47 AM in response to fredS9AmD

fredS9AmD wrote:

There is a regression in curl 7.86.0 in the .netrc handling, fixed in 7.87.0.
It's apparently Apple's fault if you have that version shipped and not yet updated.

https://github.com/curl/curl/pull/9973#issuecomment-1408606835



ref: <curl 7.86.0 October 23 2022 curl(1)>


Terminal version <Version 2.13 (447)>



The best you can do here is keep up with the point updates to the current macOS 13.2...as they become available.


To be proactive you can submit your Apple Feedback here: Product Feedback - Apple





Jan 30, 2023 10:17 AM in response to fredS9AmD

fredS9AmD wrote:

I experienced a problem on curl on Ventura 13.2 where I checked the reason by recompiling curl. And linked the commit that fix the problem, which is not included in the curl shipped in 13.2. It's quite a minor issue, that would probably only affect developpers, as I see no reason for other people to use curl.

It wouldn't affect them either.

What do you mean by that stuff isn't true? How do I get a warning against conspiracy theory already?
I just talked about Rapid Security Responses on Apple devices - Apple Support (CA) and I read it was used to update on 13.2 (I had problem to install that 13.2 because of the Preboot) . Now I worry about this :D

There is no need to worry. There is a security and fear industry that runs on the internet. It is fuelled by people who can't produce anything. They can only find theoretical faults in others' works. Certain large corporations have leveraged this industry to "protect users" by finding faults in their competitors' products. Apple still seems to be an unwilling member, but they are resigned enough to let this fear drive more frequent updates.


And Ventura 13.2 is not on Product Feedback yet. I just used 13.1 to report my problem. That's what I meant, not really important.

I'll say. The produce feedback page is not important at all. If you want to file a real bug report, use the feedback assistant app.

Jan 30, 2023 8:31 AM in response to leroydouglas

I have no idea about point updates... I saw Apple do Rapid Security Responses on 13.2 now. I'm not sure that bug is worth a security update. That specific bug was introduced after a quick patch to a minor security issue, so who knows?


I've fixed my automation script already. But hopefully, a few developers' hours' time could be saved if the fix is shipped ASAP.


And probably Apple should change its handling of curl updates, the way it's being handled upstream.


I'll do product feedback. Ventura 13.2 is not yet on the MacOS list, only Ventura 13.1. Thanks for pointing that out as I had no idea where to report this.

Jan 30, 2023 9:22 AM in response to fredS9AmD

If you actually use curl or have something installed that does, you should probably install an updated version yourself.


Apple may update it since it isn't using a GPLv3 license, but since they don't actually use curl, I doubt it will be a priority. As with etresoft, I don't imagine they will bother until the next major OS release which is usually in the fall timeframe.

Could you update curl to 7.87.0 in next ventura?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.