Hey!
I asked for, and we were granted a security audit of curl from the Mozilla
Secure Open Source program a while ago. This was done by Mozilla getting a 3rd
party company involved to do the job and footing the bill for it.
I blogged about it here:
https://daniel.haxx.se/blog/2016/11/23/curl-security-audit/
--
/ daniel.haxx.se
-------------------------------------------------------------------
List admin: https://cool.haxx.se/list/listinfo/curl-library
Etiquette: https://curl.haxx.se/mail/etiquette.html