!NBBFPbiuttRgTqbrcY:nixos.org

NixOS Security Discussions

365 Members
Discussions around Security | Triaging happens in #security:nixos.org123 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
22 Nov 2024
@emilazy:matrix.orgemilyunfortunately 24.05 is on manual bump right now because of 24.11 being exciting06:01:39
@emilazy:matrix.orgemilyand Darwin missed an entire staging cycle06:01:43
@emilazy:matrix.orgemilyso… maybe we can get a 24.05 bump for Linux soon? but surely at least a week or two before Darwin picks up this :(06:01:58
@numinit:matrix.orgMorgan (@numinit) joined the room.17:51:27
23 Nov 2024
@6t8k:matrix.org6t8k removed their profile picture.12:17:53
@6t8k:matrix.org6t8k set a profile picture.12:31:27
24 Nov 2024
@fifteenconcierge:matrix.org@fifteenconcierge:matrix.org changed their display name from Neco Arc to Neco Arc 🇵🇸.18:22:05
25 Nov 2024
@sefodopo:matrix.orgSefodopo joined the room.07:07:55
@emilazy:matrix.orgemily tgerbet: were you thinking of dropping freeimage? AFAICT the only painful-seeming thing we'd lose is trenchbroom 09:18:08
@emilazy:matrix.orgemily (and it's keeping alive e.g. jxrlib which is itself in a poor maintenance state and which Debian applies a pile of patches to for worrying-looking UB…) 09:18:54
@emilazy:matrix.orgemilyI think it's safe to say upstream is not going to suddenly fix all those CVEs. I see some downstream forks that purport to try and do so but they don't fill me with confidence09:19:26
@tgerbet:matrix.orgtgerbetYes it is kinda in my list but I'm quite behind things at the moment and the last I looked at it it did not seem like quick adventure 🥲 Some of the consumers might not need it anymore like `kew` once they are upgraded to the latest version09:29:03
@emilazy:matrix.orgemilyoh I mean I don't mind doing it if we want to do it – it's in the way of other stuff09:29:57
@emilazy:matrix.orgemily (colmap uses an old Boost and jxrlib needs patching for GCC 14) 09:30:11
@emilazy:matrix.orgemily kew already doesn't use it 09:30:16
@emilazy:matrix.orgemilyAFAICT the stuff we lose that seems like anyone might care about it is some Deepin apps we don't install by default precisely because of FreeImage, and TrenchBroom09:30:46
@emilazy:matrix.orgemilyok, and https://slade.mancubus.net/index.php?page=news which I guess is another (related?) level editor09:31:49
@emilazy:matrix.orgemily oh sorry you're right kew does still use it. ripgrep failure 09:32:10
@emilazy:matrix.orgemilyand indeed it seems to have dropped the dep09:32:34
@aloisw:kde.org@aloisw:kde.org left the room.18:06:02
26 Nov 2024
@sigmasquadron:matrix.orgSigmaSquadron hexa: Mind if I DM you for discussing a Security Team matter? 01:28:27
@hexa:lossy.networkhexasure01:28:58
@fifteenconcierge:matrix.org@fifteenconcierge:matrix.org removed their display name Neco Arc 🇵🇸.15:07:52
@fifteenconcierge:matrix.org@fifteenconcierge:matrix.org left the room.15:41:40
27 Nov 2024
@sky1e:mildlyfunctional.gay@sky1e:mildlyfunctional.gay left the room.03:14:39
@stigo:matrix.orgstigo changed their display name from stigo to stigo (away).20:49:40
28 Nov 2024
@emilazy:matrix.orgemily tgerbet: do you actually care about MySQL 8.0 or do you just update it as harm reduction because nobody else is? 08:56:28
@emilazy:matrix.orgemilyI notice that the Percona Server fork seems to be on a version that presumably has the trillion CVEs from the last couple MySQL bumps 🥴08:57:48
@tgerbet:matrix.orgtgerbetOption 2: I do not care that much but it is used so I do it 🥲08:58:30

Show newer messages


Back to Room ListRoom Version: 9