Daniel, I've created an SBOM for the Windows downloadable zip file that has identified 358 individual components in the release. Does that sound about right? This SBOM is just an extrapolation based on the zip file contents downloaded from here: https://curl.se/windows/
I'll be happy to share that extrapolated SBOM with you if interested. Thanks, Dick Brooks Active Member of the CISA Critical Manufacturing Sector, Sector Coordinating Council - A Public-Private Partnership Lifetime IEEE Member Never trust software, always verify and report! T Risk always exists, but trust must be earned and awarded.T https://businesscyberguardian.com/ Email: [email protected] Tel: +1 978-696-1788 -----Original Message----- From: curl-users <[email protected]> On Behalf Of Daniel Stenberg via curl-users Sent: Tuesday, May 26, 2026 4:28 AM To: Jeremy Nicoll via curl-users <[email protected]> Cc: Daniel Stenberg <[email protected]> Subject: Re: curl verification On Tue, 26 May 2026, Jeremy Nicoll via curl-users wrote: > Where does that leave Windows users who download pre-compiled binaries > from the links on YOUR site's downloads page? They have a slightly different story, but they too are signed and are built 100% reproducible, meaning that they can be verified to the same extent, just with a different set of tooling. -- / daniel.haxx.se || https://rock-solid.curl.dev -- Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users Etiquette: https://curl.se/mail/etiquette.html -- Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users Etiquette: https://curl.se/mail/etiquette.html
