!QCCCSJHEsTIfozrZxz:nixos.org

Nix + Go

229 Members
Go packaging for and with Nixpkgs. | Be excellent to each other.49 Servers

Load older messages


SenderMessageTime
29 Jun 2023
@kirillrdy:matrix.orgkirillrdy left the room.08:45:34
@kirillrdy:matrix.orgkirillrdy joined the room.08:50:35
5 Jul 2023
@fabianhjr:matrix.orgFabián Herediahttps://github.com/NixOS/nixpkgs/pull/24177622:56:07
7 Jul 2023
@bootstrapper:matrix.org@bootstrapper:matrix.org left the room.05:02:20
10 Jul 2023
@achnazoor:matrix.org@achnazoor:matrix.org joined the room.09:08:27
@rz_mj:freiburg.social@rz_mj:freiburg.social joined the room.19:06:34
13 Jul 2023
@qbit:tapenet.org@qbit:tapenet.orghttps://go.dev/blog/govulncheck - it would be neat if we had some sorta integration with this.. like a checkphase or something15:49:51
@qbit:tapenet.org@qbit:tapenet.orgprobably would be tough though.. because the db is remote15:50:25
@qbit:tapenet.org@qbit:tapenet.org

oh

An experimental tool to generate your own vulnerability database index is provided at golang.org/x/vulndb/cmd/indexdb.

maybe not :D

15:50:43
@j-k:matrix.orgj-koh, 1.0.0, time to update15:51:21
@qbit:tapenet.org@qbit:tapenet.org j-k i created a pr already :D 15:51:34
@j-k:matrix.orgj-kty15:51:42
@qbit:tapenet.org@qbit:tapenet.orghttps://github.com/NixOS/nixpkgs/pull/24329715:52:14
@eyjhb:eyjhb.dkeyJhb
In reply to @qbit:tapenet.org
https://go.dev/blog/govulncheck - it would be neat if we had some sorta integration with this.. like a checkphase or something
Thanks for sharing, didn't even know about this
15:55:08
@j-k:matrix.orgj-kI was very excited when it was announced. I was fed up of explaining no this critical k8s vuln doesn't affect my linter that transitively imports k8s stuff. pretty much every single week.15:57:42
@qbit:tapenet.org@qbit:tapenet.orgheh15:58:30
@qbit:tapenet.org@qbit:tapenet.orgi have been using it for a bit now, it seems to do a really good job15:58:48
@qbit:tapenet.org@qbit:tapenet.orgreally low false positive rate (not sure i have seen one.. )15:59:07
@j-k:matrix.orgj-kI'm surprised they didn't bump the modules for 1.0.0, I doubt none of these have updated since15:59:52
@qbit:tapenet.org@qbit:tapenet.orgoh, hah - i didn't even notice the vendorHash didn't change16:02:47
@qbit:tapenet.org@qbit:tapenet.orghttps://github.com/golang/vuln/compare/v0.2.0...v1.0.0.patch i had to double check (make sure i didn't mess up :D)16:05:48
@qbit:tapenet.org@qbit:tapenet.org (also ... and .diff/.patch are one of my fav features of gh) 16:06:39
@eyjhb:eyjhb.dkeyJhbWhops https://pkg.go.dev/vuln/GO-2023-187818:09:03
@eyjhb:eyjhb.dkeyJhbFound in my code18:09:06
15 Jul 2023
@jarkad:tchncs.de@jarkad:tchncs.de joined the room.19:27:28
18 Jul 2023
@kirillrdy:matrix.orgkirillrdy set a profile picture.12:22:39
22 Jul 2023
@jarkad:tchncs.de@jarkad:tchncs.de left the room.02:13:30
23 Jul 2023
@vcunat:matrix.orgvcunat joined the room.11:52:46
@artturin:matrix.orgArtturinhttps://github.com/NixOS/nixpkgs/pull/242905#issuecomment-164687793716:17:05
@artturin:matrix.orgArtturin

the last message from go mod vendor is

k2tf> go: replacement path ./vendor/k8s.io/cli-runtime/pkg/kustomize/k8sdeps/transformer inside vendor directory
16:19:10

Show newer messages


Back to Room ListRoom Version: 9