!NBBFPbiuttRgTqbrcY:nixos.org

NixOS Security Discussions

369 Members
Discussions around Security | Triaging happens in #security:nixos.org125 Servers

Load older messages


SenderMessageTime
28 Nov 2024
@tgerbet:matrix.orgtgerbetOption 2: I do not care that much but it is used so I do it 🥲08:58:30
@tgerbet:matrix.orgtgerbetAh yeah Percona… I will take a look, their releases are delayed after MySQL upgrades so it is easy to forget especially since the CVEs are not mapped to match it09:00:50
@emilazy:matrix.orgemilyah, I wasn't prompting you to update it.09:01:21
@emilazy:matrix.orgemilywell, I mean, it probably should be updated if anyone's using it09:01:34
@ma27:nicht-so.sexyma27
In reply to @emilazy:matrix.org
I notice that the Percona Server fork seems to be on a version that presumably has the trillion CVEs from the last couple MySQL bumps 🥴
osnyx (he/him) fyi ^
09:01:42
@emilazy:matrix.orgemily but they're causing me pain on staging so I was trying to figure out if people actually care. 09:01:44
@emilazy:matrix.orgemilyto which I guess the answer is "sadly, yes" :)09:01:52
@emilazy:matrix.orgemilyI think GCC 14 might break them. I'm double-checking now because I have other stuff piled on top that could be breaking them too.09:02:13
@os:matrix.flyingcircus.ioosnyx (he/him)Both MySQL as well as Percona 8.0 are still LTS-supported, so people tend to still use them.09:05:27
@emilazy:matrix.orgemilyright. I was just wondering since it seemed like nobody had packaged any of the later versions of MySQL (but I guess few are picking MySQL for anything greenfield)09:05:57
@emilazy:matrix.orgemily okay, the good news is that MySQL 8.0 is building fine on staging so it was only my WIP changes breaking it :) 09:10:30
@emilazy:matrix.orgemilybad news is Percona definitely needs bumps09:10:34
@tgerbet:matrix.orgtgerbetLooking at it today 🙂09:11:06
@os:matrix.flyingcircus.ioosnyx (he/him)
In reply to @tgerbet:matrix.org
Looking at it today 🙂
Feel free to do this, but being one of the maintainers I finally subscribed to the new-releases feed of Percona to not miss updates anymore 🤐
09:43:31
@os:matrix.flyingcircus.ioosnyx (he/him)So hopefully the timeliness of Percona updates is going to improve.09:44:05
@shawn8901:matrix.org@shawn8901:matrix.org left the room.18:48:47
29 Nov 2024
@lassulus:lassul.uslassulus changed their profile picture.18:30:08
3 Dec 2024
@stigo:matrix.orgstigo changed their display name from stigo (away) to stigo.00:52:15
@getchoo:matrix.orggetchoo changed their profile picture.06:06:38
6 Dec 2024
@aleksana:mozilla.orgaleksana (force me to bed after 18:00 UTC)https://github.com/ultralytics/ultralytics/issues/1802712:31:20
@aleksana:mozilla.orgaleksana (force me to bed after 18:00 UTC)Not packaging stuff is the best way to avoid supply chain attack12:32:04
@aleksana:mozilla.orgaleksana (force me to bed after 18:00 UTC)Not dealing with package request is even better: https://github.com/NixOS/nixpkgs/issues/30815412:34:59
@ity:itycodes.orgTranquil ItyRofl12:53:36
@joerg:thalheim.ioMic92Is there some issue here, I don't see? https://github.com/NixOS/nixos-wiki-infra/issues/161 18:05:55
@tgerbet:matrix.orgtgerbetI will check, I can reach out to laluka directly. Should probably have been reported to upstream anyway18:10:34
7 Dec 2024
@hexa:lossy.networkhexaso quite recently someone pointed out to me that AMD does not publish microcode updates for consumer CPUs to linux-firmwares17:59:56
@hexa:lossy.networkhexa * so quite recently someone pointed out to me that AMD does not publish microcode updates for consumer CPUs to linux-firmwares, and that those are only shipped through BIOS updates18:00:19
@hexa:lossy.networkhexaThe ones shipped from linux-firmware are apparently only for server CPUs.18:00:37
@zzywysm:matrix.orgzzywysm hexa: that sounds like a fairly recent change? 18:00:35
@hexa:lossy.networkhexawhat makes you say that?18:00:53

Show newer messages


Back to Room ListRoom Version: 9