curl
Command-line tool and library for transferring data with URLs.
Mostly friendly. Welcome, with extra rules.
Code written with AI help is accepted if it meets the normal standards. AI-found bug and security reports must say so and be verified by a human, and pasted AI-generated reports and explanations are discouraged.
Policy by area
- Code contributionsPatches, pull requests and other changes written with AI tools.
- Friendly
- Issues & bug reportsBug reports, security reports and issues found or written with AI tools.
- Mostly friendly
- AI use must be disclosed
- A human must review the output
- AI-written textPull request descriptions, issue comments and summaries written by AI.
- Unfriendly
- Only minor help (autocomplete, grammar)
In their own words
Code contributions
We can accept code written with the help of AI into the project, but the code must still follow coding standards, be written clearly, be documented, feature test cases and adhere to all the normal requirements we have.
Issues & bug reports
If you asked an AI tool to find problems in curl, you must make sure to reveal this fact in your report.
You must also double-check the findings carefully before reporting them to us to validate that the issues are indeed existing and working exactly as the AI says.
AI-written text
Do not lazily paste massive, AI-generated explanations;
If you actually find a problem with an AI and you have verified it yourself to be true: write the report yourself and explain the problem as you have learned it.
Sources
- Contributing to the curl projectgithub.com/curl/curl/blob/master/docs/CONTRIBUTE.mdSnapshot 9 Oct 2026
- curl vulnerability disclosure policygithub.com/curl/curl/blob/master/docs/VULN-DISCLOSURE-POLICY.mdSnapshot 9 Oct 2026