A Library That Runs Everywhere

curl began in 1998 as a small command-line tool for transferring URLs, built by Daniel Stenberg, a Swedish software engineer then working on IRC projects. It was not the product of a foundation grant, a corporate open-source office, or a university research programme. It was a one-person utility that accumulated features and users. By the time Apple began shipping curl inside macOS, and Microsoft embedded it in Windows 10, and every major Linux distribution had made it a default dependency, the project's governance had not changed in any fundamental way: Stenberg remained the primary author, primary reviewer, and de facto steward, working on curl largely in his own time.

The curl project's own FAQ describes the library as present in roughly twenty-two billion installations — a figure Stenberg has cited and updated in public posts over the years, acknowledging that precise auditing of embedded firmware is impossible but that the number is conservative. It runs in cars, in televisions, in payment terminals, in satellite systems. Companies that ship it do not, as a rule, pay for it.

An adult developer's desk with two monitors showing a GitHub pull-request diff and a dependency graph, a coffee cup in the foreground, shot in available office light
PLATE 02Review capacity, not code, is the scarce resource in most of these projects.Photo: Lee Campbell / Pexels

The Support Burden in Public

What makes Stenberg's situation instructive, beyond its scale, is that he has written about it in plain terms. In blog posts and conference talks, he has returned repeatedly to the arithmetic of open-source maintenance: curl receives a large and growing volume of security reports, bug reports, and feature requests; the expectation of timely, professional responses is high precisely because the companies depending on curl are large and professional; and the funding flowing back to the project to support that work is, relative to the dependency's criticality, negligible.

The pattern Stenberg describes matches what researchers at the Harvard Lab for Innovation Science found when examining open-source software dependencies used by US businesses — that a small number of widely used projects receive value from a very large number of organisations while being maintained by very few people. The economic asymmetry is not a secret. It is simply the default condition.

Stenberg has been explicit that curl is supported partly through his employer at any given time tolerating or actively allowing the work, and partly through a relatively small number of corporate sponsors — some named on the curl website, others providing support contracts. The Open Collective and GitHub Sponsors platforms have been used; the inflows have never matched the scale of the dependency. Stenberg's public accounting is not a complaint so much as a demonstration: here is a project embedded in billions of devices, here is roughly what its maintenance costs in time and money, here is what comes back.

When Log4Shell broke in December 2021, one of the questions that followed was how a logging library maintained largely by volunteers had become load-bearing infrastructure for the internet. curl presents the same question in a longer, quieter register. There has been no curl catastrophe. But the structural conditions that produce catastrophes — deep dependency, thin maintenance, no guaranteed funding — are present.

What 'Free' Costs

The Sovereign Tech Fund, a German federal initiative that began investing in open-source infrastructure in 2022, has included curl among its funded projects, providing one of the more concrete examples of public money reaching critical maintenance work. The fund treats open-source infrastructure as a public good requiring deliberate investment, a framing Stenberg has publicly welcomed.

The broader policy conversation has moved in similar directions. The US Executive Order 14028 of May 2021 and the European Commission's work on software resilience have both named dependency risk as a systemic concern. Neither has produced a durable mechanism for getting money to individual maintainers of libraries like curl.

An open sticker-covered laptop on a wooden table, the screen showing a terminal prompt, an adult's hands on the keyboard partially visible at the bottom of the frame
PLATE 03Most of this infrastructure is maintained from a desk like this one, in hours nobody is billing for.
Photo: Rafael Minguet Delgado / Pexels

What Stenberg's public writing does — across more than two decades of posts — is make the cost visible. curl is free in the sense that it carries no licence fee and ships with most operating systems. It is not free in the sense of requiring no labour. The BUSL and SSPL disputes that occupied much of 2023 and 2024 centred on companies trying to change the terms under which their software is used; curl has never taken that route. It remains under its permissive, MIT-style curl licence and genuinely open. The question Stenberg keeps posing is simply whether the people and organisations benefiting from that openness have any obligation to sustain it.