!NBBFPbiuttRgTqbrcY:nixos.org

NixOS Security Discussions

366 Members
Discussions around Security | Triaging happens in #security:nixos.org128 Servers

Load older messages


SenderMessageTime
21 Oct 2024
@emilazy:matrix.orgemily Fabián Heredia: I'm thinking we should just revert and do this again if the whack-a-mole with the eval issues continues beyond another push 17:39:56
@emilazy:matrix.orgemilyI'll open a revert17:40:38
@emilazy:matrix.orgemilymerged the revert, sorry about that. better to clean up the strays without time pressure17:45:02
@fabianhjr:matrix.orgFabián Heredia
In reply to @emilazy:matrix.org
Fabián Heredia: I'm thinking we should just revert and do this again if the whack-a-mole with the eval issues continues beyond another push
yeah
17:45:27
@fabianhjr:matrix.orgFabián Heredia
In reply to @emilazy:matrix.org
merged the revert, sorry about that. better to clean up the strays without time pressure
sure, no worries
17:45:39
@fabianhjr:matrix.orgFabián Herediahttps://github.com/NixOS/nixpkgs/pull/350291 vet is happy now but we should probably wait for the whole CI 😅18:00:34
@aleksana:mozilla.orgaleksana (force me to bed after 18:00 UTC)
In reply to @fabianhjr:matrix.org
There was a time when aliases couldn't warn not too long ago if I recall correctly
Also people complaining it being too noisy in nix search
18:07:23
@emilazy:matrix.orgemily that ship has already sailed, nix search spits out a billion warnings 18:07:43
22 Oct 2024
@willbush:matrix.orgwillbush changed their profile picture.09:29:08
@aktaboot:tchncs.deaktaboot changed their profile picture.12:11:08
23 Oct 2024
@aktaboot:tchncs.deaktaboot changed their profile picture.19:54:02
@emilazy:matrix.orgemilyNix security update incoming https://discourse.nixos.org/t/2024-10-23-nix-team-meeting-minutes-189/5484121:09:50
24 Oct 2024
@joerg:thalheim.ioMic92Has someone experience with preparing nixpkgs patches in private forks? So github has this security advisory feature but it seems that nixpkgs is too big for this. I also tried pushing nixpkgs as a private repository with the same result.03:44:35
@tgerbet:matrix.orgtgerbetGHSA are annoying because they require repo admin permission to be created/published/managed. I usually forward patch files :/ 08:27:21
@os:matrix.flyingcircus.ioosnyx (he/him)Anyone at NixCon who'd be interested in discussing how we can better handel the Gitlab upgrade cycle for stable NixOS releases? security patch backporting for at most 3 months makes switching to at least another minor release necessary within a NixOS cycle.10:10:41
4 Jul 2022
@lassulus:nixos.devlassulus joined the room.13:33:52
@robert:funklause.dedotlambda
In reply to @linus:schreibt.jetzt
lassulus: django <- typogrify <- gi-docgen <- librsvg
https://github.com/NixOS/nixpkgs/pull/180120
14:19:51
@ar:hackerspace.plar joined the room.16:44:27
@anodium:matrix.orgAndrea Pascal joined the room.18:01:32
5 Jul 2022
@pennae:matrix.eno.space@pennae:matrix.eno.spaceoh, there's been an issue closing spree for 21.11 cves :D00:52:55
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/issues/17476401:31:15
@hexa:lossy.networkhexasure … don't care about security issues for two months and then close it01:31:29
@hexa:lossy.networkhexaI'm not pleased.01:31:43
@qyliss:fairydust.spaceAlyssa RossI wonder what to do about that GnuPG patch06:16:10
@qyliss:fairydust.spaceAlyssa Rossunlike the last one, it hasn't been merged yet06:16:22
@qyliss:fairydust.spaceAlyssa Rossand "werner removed a reviewer: werner."06:16:28
@qyliss:fairydust.spaceAlyssa Ross so it wouldn't surprise me if there's been a falling out and it won't be, at least not any time soon… 06:16:51
@qyliss:fairydust.spaceAlyssa Ross(a falling out due to the disclosure of the previous issue, I maen)06:17:04
@bdd:mozilla.orgbdd joined the room.06:39:48
@arno:chat.ionlabs.mearno joined the room.08:18:08

Show newer messages


Back to Room ListRoom Version: 9