Since the dawn of time (at least it feels that long) we've included a copy of a ca cert bundle in the curl releases. That ca cert bundle originates from Netscape 4.72 and no cert has been added to it since the year 2000(!)
Anyway, we were recently triggered by a bug report and are discussing updating the bundle in the curl tarballs - we'll just need to sort out the license situation first but we're slowly progressing there and I think we're pretty fine with things as they are right now.
However, the question is perhaps better put the other way: why should we bother to include a ca cert bundle in the first place? Most users will already have one in their system (since basically all SSL-based applications want one) and those that don't can very easily get an updated one using our online server or a recent perl script added to the curl source tree.
I hope I don't have to tell you that I value all input I can get on this issue!