| 1 Jul 2021 |
Synthetica | oof | 11:36:55 |
Synthetica | sorry | 11:36:57 |
balsoft | Oh | 11:37:36 |
balsoft | No liveusb needed | 11:37:39 |
balsoft | NixOS is fairly self-repairing actually | 11:37:55 |
Synthetica | wait, a reisub-reboot fixed it? | 11:38:35 |
balsoft | What if I do it in the activation script? :P | 11:38:43 |
ris_ | could i get some eyes on https://github.com/NixOS/nixpkgs/pull/126280 before permanent bitrot sets in? | 19:31:37 |
hexa | thanks, lgtm | 19:43:36 |
| 2 Jul 2021 |
| Irenes joined the room. | 09:22:13 |
hexa | https://www.djangoproject.com/weblog/2021/jul/01/security-releases/ | 14:18:35 |
| ๅนธ็ซ joined the room. | 16:07:01 |
| julm left the room. | 18:11:39 |
ris_ | CVE-2021-34552 seems to map to https://github.com/python-pillow/Pillow/pull/5567, which looks pretty hard to expose | 18:28:53 |
hexa | otoh it looks pretty easy to backport | 18:29:57 |
ris_ | you'd have to be passing in mode from untrusted input | 18:29:59 |
ris_ | sure | 18:30:02 |
hexa | uh, should post security advisories here and โ
them when PR is up or so | 18:30:58 |
hexa | just so that the state of these things becomes more visible | 18:31:15 |
philipp | Maybe a separate room just for them? | 18:32:25 |
hexa | maybe a separate room for the chit chat? ๐ | 18:32:52 |
balsoft | I would love a room with advisories | 18:32:54 |
hexa | I don't mind either | 18:33:06 |
hexa |
getxmp() was added in Pillow 8.2.0. It will now use defusedxml instead. If the dependency is not present, an empty dictionary will be returned and a warning raised.
| 18:33:28 |
hexa | alas we are not propagating defusedxml there | 18:33:53 |
hexa | uh, not ours strictly I guess | 18:34:08 |
hexa | just things we find | 18:34:12 |
hexa | * just things we find, and need to remember to take care of | 18:34:20 |
hexa | but sure, we could have an advisory channel, with moderated posts to the pr trackers I guess | 18:44:38 |
hexa | so not advisories per se, but "here is this security related pr, take note" | 18:45:14 |