Daniel,

I've created an SBOM for the Windows downloadable zip file that has
identified 358 individual components in the release.
Does that sound about right? This SBOM is just an extrapolation based on the
zip file contents downloaded from here:
https://curl.se/windows/

I'll be happy to share that extrapolated SBOM with you if interested.


Thanks,

Dick Brooks
   
Active Member of the CISA Critical Manufacturing Sector, 
Sector Coordinating Council - A Public-Private Partnership
Lifetime IEEE Member
Never trust software, always verify and report! T
Risk always exists, but trust must be earned and awarded.T 
https://businesscyberguardian.com/ 
Email: [email protected]
Tel: +1 978-696-1788


-----Original Message-----
From: curl-users <[email protected]> On Behalf Of Daniel
Stenberg via curl-users
Sent: Tuesday, May 26, 2026 4:28 AM
To: Jeremy Nicoll via curl-users <[email protected]>
Cc: Daniel Stenberg <[email protected]>
Subject: Re: curl verification

On Tue, 26 May 2026, Jeremy Nicoll via curl-users wrote:

> Where does that leave Windows users who download pre-compiled binaries 
> from the links on YOUR site's downloads page?

They have a slightly different story, but they too are signed and are built
100% reproducible, meaning that they can be verified to the same extent,
just with a different set of tooling.

-- 

  / daniel.haxx.se || https://rock-solid.curl.dev
--
Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users
Etiquette:   https://curl.se/mail/etiquette.html

-- 
Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users
Etiquette:   https://curl.se/mail/etiquette.html

Reply via email to