!UNVBThoJtlIiVwiDjU:nixos.org

Staging

308 Members
Staging merges | Running staging cycles: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+head%3Astaging-next+head%3Astaging-next-25.05 | Review Reports: https://malob.github.io/nix-review-tools-reports/105 Servers

Load older messages


SenderMessageTime
21 Sep 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)it got 2.13.9 apparently last week. After like 15 other CVEs went unfixed for several months and we needed to do manual backport11:53:25
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)so yes, that exists, but i am not confident this is something we can bet on for our release11:54:03
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)don't get me wrong, 2.13.9 is nice and we should absolutely pick that to 25.05 and drop our current patches on 25.11 where we have our own patches on top of 2.13.8. However, upstream already announced they'd only be maintaining libxml2 until the end of 2025. The libxslt maintainer said they'd step up for libxml2, but expecting them to carry along old versions is a bet that is quite dangerous.11:56:11
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)I am only willing to do it if you are the idiot volunteering to backport all the patches yourself if 2.14.x doesn't get backports!11:56:40
@k900:0upti.meK900Actually a decent chance that I'll finish the rebuild today11:57:49
@vcunat:matrix.orgvcunatOK. I wasn't really following this long-term, just happened to see this 2.13.9. One possibility is always to piggy-back on some distro that takes security seriously (and happens to follow a particular package branch).11:59:17
@k900:0upti.meK900Somehow11:57:52
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)debian is still on ANCIENT versions with tens of patches. Fedora could work...12:02:12
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)i expect arch to just yolo, either upgrading or not patching. That is the arch way anyways, i have looked at this before.12:02:46
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)yeah arch already did 2.15.012:03:20
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)https://repology.org/project/libxml2/versions12:03:23
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)wait even fedora is still on 2.1212:03:47
@vcunat:matrix.orgvcunatFedora is 2.12 ?! https://packages.fedoraproject.org/pkgs/libxml2/libxml2/12:03:47
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)ugh12:03:48
@vcunat:matrix.orgvcunatUbuntu also doesn't go beyond 2.12.12:04:20
@vcunat:matrix.orgvcunat* Ubuntu also doesn't go beyond 2.12 thus far.12:04:25
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)gentoo is patching along 2.1312:04:27
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)and apparently 2.14 too12:04:42
@vcunat:matrix.orgvcunat* Ubuntu also doesn't go beyond 2.12 thus far. (just following Debian in here, I expect)12:04:44
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)so i guess we could fetch gentoo12:04:50
@vcunat:matrix.orgvcunatAh, they have a separate package after the ABI bump? https://packages.ubuntu.com/questing/libxml2-1612:05:58
@vcunat:matrix.orgvcunatIt all looks like a mess.12:06:18
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)thats what i am saying12:06:55
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)i don't want to carry more than necessary12:07:04
@vcunat:matrix.orgvcunatToo new version can also create work, as you see, but the security maintenance work is hard to predict. Though recently they did have lots of CVEs.12:10:06
@vcunat:matrix.orgvcunatAnyway, if you think 2.15 will be better, I certainly don't oppose that.12:10:49
@k900:0upti.meK900So who's getting sniped into writing multilib stdenv for 26.0512:22:22
@k900:0upti.meK900(please don't be me)12:22:29
@k900:0upti.meK900(this message is brought to you by pandoc-i686-linux)12:24:03
@emilazy:matrix.orgemilyI trust containers org13:11:42

Show newer messages


Back to Room ListRoom Version: 6