!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

673 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22206 Servers

Load older messages


SenderMessageTime
20 Mar 2026
@raitobezarius:matrix.orgraitobezarius(also discussions not here)17:43:10
@eouzoe:matrix.org曜日My apologies for the confusion. I had only meant to share the project here — though I came across a wishlist that seemed to align rather closely with what it does, and one thing led to another.17:54:20
@eouzoe:matrix.org曜日Apologies — should I take this to #security:nixos.org instead?17:55:05
@eouzoe:matrix.org曜日* Apologies — should I take this to #security-discuss:nixos.org instead?17:55:17
@elvishjerricco:matrix.orgElvishJerriccohttps://github.com/NixOS/nixpkgs/pull/501701 fixing a vuln in https://github.com/NixOS/nixpkgs/pull/493445 that is presently on master18:38:59
@elvishjerricco:matrix.orgElvishJerricconeed to make sure it doesn't hit unstable. It's already on unstable-small18:40:19
@robert:funklause.dedotlambdanot sure what to do about https://github.com/NixOS/nixpkgs/issues/500142 on 25.1118:43:45
@robert:funklause.dedotlambdahttps://github.com/jpadilla/pyjwt/commit/051ea341b5573fe3edcd53042f347929b92c2b92 doesn't apply cleanly18:44:18
@elvishjerricco:matrix.orgElvishJerricco K900, vcunat: do we need to cancel an unstable eval or anything like that to keep this from hitting unstable? I suspect it impacts a significant portion of boot.initrd.secrets users. 19:10:05
@vcunat:matrix.orgvcunat Since the tested job passed, cancelling the rest would make it advance immediately. 19:11:42
@vcunat:matrix.orgvcunat And it's in unstable-small channel, too. 19:12:14
@elvishjerricco:matrix.orgElvishJerriccoSo we'll have to just merge and wait for it to reach unstable in a few days? Do we need to issue an advisory then?19:14:01
@vcunat:matrix.orgvcunat unstable-small can get it within a couple hours. 19:14:54
@lennart:0520.chlennart not meaning to be rude, but I have highlight on for every message in this channel. I guess lots of others of us 670+ people do so aswell, can you switch over to #security-discuss:nixos.org? 19:15:33
@emilazy:matrix.orgemily(I don't think a highlight on every message in here is a good idea, it's not an advisory notification channel, triage has to happen in the triage room even if not extended discussions…)19:16:56
@emilazy:matrix.orgemily(& many many vulnerabilities never come up in here at all 😅)19:17:31
@lennart:0520.chlennartah sorry, that wasn't clear to me.19:17:36
@lennart:0520.chlennartI vaguely remember that I had this before, sorry, gonna turn of the notifications :D19:48:31
21 Mar 2026
@vcunat:matrix.orgvcunat Noone has reacted the initrd secrets problem apparently? I think it wouldn't be too hard to prevent nixos-unstable from updating, but should we? Also if it's bad, we need to merge quickly to fix nixos-unstable-small. 06:16:30
@k900:0upti.meK900 We should 06:16:46
@k900:0upti.meK900It's stupid06:16:51
@vcunat:matrix.orgvcunat

Done, I think.

Loaded: masked (Reason: Unit update-nixos-unstable.service is masked.)

06:21:35
@emilazy:matrix.orgemilyperhaps revert for now?14:12:53
@k900:0upti.meK900 @ElvishJerricco has a fix 14:20:44
@elvishjerricco:matrix.orgElvishJerriccoIf no one's going to review it then I guess we just revert though14:21:15
@elvishjerricco:matrix.orgElvishJerriccoI'd merge because I'm reasonably sure of the fix. But plausibly the original PR did it that way for some reason and the author / reviewers of it should chime in. I mean I think that's unlikely but that's one reason I haven't just self-merged it14:22:52
@emilazy:matrix.orgemilywe had a fix 20 hours ago, we could have merged a revert like 24 hours ago14:31:17
@vcunat:matrix.orgvcunatRebuilding all tests takes a while, but yes.14:39:49
@vcunat:matrix.orgvcunat* Rebuilding all tests takes a while, but yes. (at least I assume that the fix wouldn't rebuild most tests)14:55:56
@vcunat:matrix.orgvcunatI guess we revert for now: https://github.com/NixOS/nixpkgs/pull/50196315:01:56

There are no newer messages yet.


Back to Room ListRoom Version: 6