!NBBFPbiuttRgTqbrcY:nixos.org

NixOS Security Discussions

368 Members
Discussions around Security | Triaging happens in #security:nixos.org125 Servers

Load older messages


SenderMessageTime
21 Oct 2024
@emilazy:matrix.orgemily Fabián Heredia: I'm thinking we should just revert and do this again if the whack-a-mole with the eval issues continues beyond another push 17:39:56
@emilazy:matrix.orgemilyI'll open a revert17:40:38
@emilazy:matrix.orgemilymerged the revert, sorry about that. better to clean up the strays without time pressure17:45:02
@fabianhjr:matrix.orgFabián Heredia
In reply to @emilazy:matrix.org
Fabián Heredia: I'm thinking we should just revert and do this again if the whack-a-mole with the eval issues continues beyond another push
yeah
17:45:27
@fabianhjr:matrix.orgFabián Heredia
In reply to @emilazy:matrix.org
merged the revert, sorry about that. better to clean up the strays without time pressure
sure, no worries
17:45:39
@fabianhjr:matrix.orgFabián Herediahttps://github.com/NixOS/nixpkgs/pull/350291 vet is happy now but we should probably wait for the whole CI 😅18:00:34
@aleksana:mozilla.orgaleksana (force me to bed after 18:00 UTC)
In reply to @fabianhjr:matrix.org
There was a time when aliases couldn't warn not too long ago if I recall correctly
Also people complaining it being too noisy in nix search
18:07:23
@emilazy:matrix.orgemily that ship has already sailed, nix search spits out a billion warnings 18:07:43
22 Oct 2024
@willbush:matrix.orgwillbush changed their profile picture.09:29:08
@aktaboot:tchncs.deaktaboot changed their profile picture.12:11:08
23 Oct 2024
@aktaboot:tchncs.deaktaboot changed their profile picture.19:54:02
@emilazy:matrix.orgemilyNix security update incoming https://discourse.nixos.org/t/2024-10-23-nix-team-meeting-minutes-189/5484121:09:50
24 Oct 2024
@joerg:thalheim.ioMic92Has someone experience with preparing nixpkgs patches in private forks? So github has this security advisory feature but it seems that nixpkgs is too big for this. I also tried pushing nixpkgs as a private repository with the same result.03:44:35
@tgerbet:matrix.orgtgerbetGHSA are annoying because they require repo admin permission to be created/published/managed. I usually forward patch files :/ 08:27:21
@os:matrix.flyingcircus.ioosnyx (he/him)Anyone at NixCon who'd be interested in discussing how we can better handel the Gitlab upgrade cycle for stable NixOS releases? security patch backporting for at most 3 months makes switching to at least another minor release necessary within a NixOS cycle.10:10:41
25 Oct 2024
@emilazy:matrix.orgemily
In reply to @tgerbet:matrix.org
Yeah I wanted to create a tracking issue so we can follow this more closely and see how it evolves over time but I did not get the time to do it
FWIW, I've opened https://github.com/NixOS/nixpkgs/pull/351205 and https://github.com/NixOS/nixpkgs/pull/351206.
15:48:44
@emilazy:matrix.orgemily
In reply to @tgerbet:matrix.org
Yeah I wanted to create a tracking issue so we can follow this more closely and see how it evolves over time but I did not get the time to do it
* FWIW, I've opened https://github.com/NixOS/nixpkgs/pull/351205 and https://github.com/NixOS/nixpkgs/pull/351206.
15:48:59
26 Oct 2024
@plmh:matrix.orgplmh joined the room.05:19:55
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.07:04:10
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.07:07:56
@willbush:matrix.orgwillbush left the room.23:42:04
@numinit:matrix.orgMorgan (@numinit) left the room.23:46:43
27 Oct 2024
@willbush:matrix.orgwillbush joined the room.00:04:32
@emilazy:matrix.orgemily hexa: did you want https://github.com/NixOS/nixpkgs/pull/351205#pullrequestreview-2396239364 done? I'm agnostic since I'm not the one who does any actual Thunderbird work. (just making sure the PR is ready for before ZHF, if we decide to merge it – don't feel like self-merging is appropriate.) 15:59:16
@hexa:lossy.networkhexawould have expected the author to comment15:59:44
@hexa:lossy.networkhexa * would have expected the package maintainer to comment15:59:52
@emilazy:matrix.orgemilybest to give it a week I guess?16:10:09
@emilazy:matrix.orgemilybut just wanted to check whether the Thunderbird revert is desired.16:10:21
@hexa:lossy.networkhexaask vcunat16:11:25
@hexa:lossy.networkhexaI don't maintain thunderbird16:11:30

Show newer messages


Back to Room ListRoom Version: 9