!QCCCSJHEsTIfozrZxz:nixos.org

Nix + Go

229 Members
Go packaging for and with Nixpkgs. | Be excellent to each other.49 Servers

Load older messages


SenderMessageTime
13 Jul 2023
@qbit:tapenet.org@qbit:tapenet.orgprobably would be tough though.. because the db is remote15:50:25
@qbit:tapenet.org@qbit:tapenet.org

oh

An experimental tool to generate your own vulnerability database index is provided at golang.org/x/vulndb/cmd/indexdb.

maybe not :D

15:50:43
@j-k:matrix.orgj-koh, 1.0.0, time to update15:51:21
@qbit:tapenet.org@qbit:tapenet.org j-k i created a pr already :D 15:51:34
@j-k:matrix.orgj-kty15:51:42
@qbit:tapenet.org@qbit:tapenet.orghttps://github.com/NixOS/nixpkgs/pull/24329715:52:14
@eyjhb:eyjhb.dkeyJhb
In reply to @qbit:tapenet.org
https://go.dev/blog/govulncheck - it would be neat if we had some sorta integration with this.. like a checkphase or something
Thanks for sharing, didn't even know about this
15:55:08
@j-k:matrix.orgj-kI was very excited when it was announced. I was fed up of explaining no this critical k8s vuln doesn't affect my linter that transitively imports k8s stuff. pretty much every single week.15:57:42
@qbit:tapenet.org@qbit:tapenet.orgheh15:58:30
@qbit:tapenet.org@qbit:tapenet.orgi have been using it for a bit now, it seems to do a really good job15:58:48
@qbit:tapenet.org@qbit:tapenet.orgreally low false positive rate (not sure i have seen one.. )15:59:07
@j-k:matrix.orgj-kI'm surprised they didn't bump the modules for 1.0.0, I doubt none of these have updated since15:59:52
@qbit:tapenet.org@qbit:tapenet.orgoh, hah - i didn't even notice the vendorHash didn't change16:02:47
@qbit:tapenet.org@qbit:tapenet.orghttps://github.com/golang/vuln/compare/v0.2.0...v1.0.0.patch i had to double check (make sure i didn't mess up :D)16:05:48
@qbit:tapenet.org@qbit:tapenet.org (also ... and .diff/.patch are one of my fav features of gh) 16:06:39
@eyjhb:eyjhb.dkeyJhbWhops https://pkg.go.dev/vuln/GO-2023-187818:09:03
@eyjhb:eyjhb.dkeyJhbFound in my code18:09:06
15 Jul 2023
@jarkad:tchncs.de@jarkad:tchncs.de joined the room.19:27:28
18 Jul 2023
@kirillrdy:matrix.orgkirillrdy set a profile picture.12:22:39
22 Jul 2023
@jarkad:tchncs.de@jarkad:tchncs.de left the room.02:13:30
23 Jul 2023
@vcunat:matrix.orgvcunat joined the room.11:52:46
@artturin:matrix.orgArtturinhttps://github.com/NixOS/nixpkgs/pull/242905#issuecomment-164687793716:17:05
@artturin:matrix.orgArtturin

the last message from go mod vendor is

k2tf> go: replacement path ./vendor/k8s.io/cli-runtime/pkg/kustomize/k8sdeps/transformer inside vendor directory
16:19:10
@artturin:matrix.orgArtturin

tinygo.goModules

error: illegal path references in fixed-output derivation '/nix/store/06v7rn03bgsnzvv89dn8i2a6kap1fijl-tinygo-0.26.0-goModules.drv'
16:28:47
@artturin:matrix.orgArtturinThese modules built correctly on older go versions but not on newer go versions16:29:11
@artturin:matrix.orgArtturinHow can vendoring break version to version, Go damn16:29:49
@artturin:matrix.orgArtturin * How can vendoring break in multiple ways version to version, Go damn16:30:43
@qbit:tapenet.org@qbit:tapenet.orgIs there a rewrite in the go.mod?17:17:55
@atalii:matrix.org@atalii:matrix.org joined the room.17:58:44
@atalii:matrix.org@atalii:matrix.org is it okay if i ask a quick question about buildGoModule here? i'm reading through the sourcue to get an idea of how to handle deps for a different language and build system, and it seems that the buildPhase of buildGoModule calls go mod vendor or go mod package. that seems to require the network, but it also seems to work in the sandbox. would anyone be able to tell me what i'm missing here? thanks :) 18:00:56

Show newer messages


Back to Room ListRoom Version: 9