!VRULIdgoKmKPzJZzjj:nixos.org

Nix Hackers

904 Members
For people hacking on the Nix package manager itself189 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
31 Oct 2024
@k900:0upti.meK900Nix doesn't do dependency resolution 15:56:07
@emilazy:matrix.orgemilyI believe the CVSS in https://github.com/NixOS/nix/security/advisories/GHSA-wf4c-57rh-9pjg is inaccurate. "Attack Complexity: High" seems inaccurate as it's trivial to reproduce and can be easily deployed from a random flake. "Confidentiality: Low" also seems untrue since it's precisely about builds being able to read things they shouldn't be able to. it might not be a very impactful vulnerability, but there's no way it's a CVSS 1.0. note that CVSS quantifies impact of the vulnerability if you run into it, not how likely you are to run into it.15:58:40
@khaleghi:matrix.org..https://www.tweag.io/blog/2022-09-13-nixpkgs-graph/16:01:14
@khaleghi:matrix.org.. * https://www.tweag.io/blog/2022-09-13-nixpkgs-graph/ K900 16:01:31
@k900:0upti.meK900That's not dependency resolution16:01:35
@puck:puck.moepuck
In reply to @emilazy:matrix.org
I believe the CVSS in https://github.com/NixOS/nix/security/advisories/GHSA-wf4c-57rh-9pjg is inaccurate. "Attack Complexity: High" seems inaccurate as it's trivial to reproduce and can be easily deployed from a random flake. "Confidentiality: Low" also seems untrue since it's precisely about builds being able to read things they shouldn't be able to. it might not be a very impactful vulnerability, but there's no way it's a CVSS 1.0. note that CVSS quantifies impact of the vulnerability if you run into it, not how likely you are to run into it.
i ..think it should probably be UI:N, and AC:L? i also don't think the bug itself would be AT:P
16:01:46
@k900:0upti.meK900That's just computing dependencies between packages16:01:50
@k900:0upti.meK900Which is not the slow part16:01:55

Show newer messages


Back to Room ListRoom Version: 6