!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

682 Members
Coordination and triage of security issues in nixpkgs214 Servers

Load older messages


SenderMessageTime
29 May 2021
@mkos:matrix.orgMark left the room.19:13:34
@cyplo:cyplo.devcyplo joined the room.19:59:15
@onelegend:envs.netOneLegend joined the room.22:21:31
30 May 2021
@r_i_s:matrix.orgris_ if anyone wants to have a go at bumping singularity 3.6.3's umoci dependency to 0.4.7 and thus resolve https://github.com/NixOS/nixpkgs/issues/124678 please be my guest, i give up. golang's packaging tools are :horror: 00:14:32
@onelegend:envs.netOneLegend left the room.00:55:27
@sandro:supersandro.deSandro
In reply to @r_i_s:matrix.org
if anyone wants to have a go at bumping singularity 3.6.3's umoci dependency to 0.4.7 and thus resolve https://github.com/NixOS/nixpkgs/issues/124678 please be my guest, i give up. golang's packaging tools are :horror:
You probably need to create upstream issues for them
02:32:05
@sandro:supersandro.deSandro
In reply to @r_i_s:matrix.org
if anyone wants to have a go at bumping singularity 3.6.3's umoci dependency to 0.4.7 and thus resolve https://github.com/NixOS/nixpkgs/issues/124678 please be my guest, i give up. golang's packaging tools are :horror:
* You probably need to create upstream issues/PRs for them
02:32:18
@wrinkle_hut:matrix.orgKitty joined the room.06:09:43
@arianvp:matrix.orgArianIt seems NixOS is missing DigiCert's new Root CA. E.g. i can not curl https://signup.cloud.oracle.com11:47:00
@arianvp:matrix.orgArianHow is the nixos trust store kept up to date?11:59:36
@janne.hess:helsinki-systems.dedas_j
In reply to @arianvp:matrix.org
How is the nixos trust store kept up to date?
nss's trust store (mozilla) ist used
13:56:56
@janne.hess:helsinki-systems.dedas_j see pkgs/data/misc/cacert 13:57:38
@arianvp:matrix.orgArianInteresting. I think it's something funky with oracle's setup. They aren't returning the entire certificate chain in the handshake13:58:06
@philipp:xndr.dephilippThat's a really common issue, sadly.13:58:55
@hexa:lossy.networkhexa das_j: and the nss version in stlabe doesn't change, should we rely on nss_latest for cacerts possibly? 14:03:04
@hexa:lossy.networkhexa * das_j: and the nss version in stable doesn't change, should we rely on nss_latest for cacerts possibly? 14:03:12
@andi:kack.itandi-nss_latest. -> cacert -> world rebuild-ish14:07:08
@hexa:lossy.networkhexayup14:07:17
@andi:kack.itandi-The idea of nss_latest was to exactly avoid world rebuilds14:07:18
@hexa:lossy.networkhexafair14:07:24
@andi:kack.itandi-while still being able to upgrade firefox14:07:28
@andi:kack.itandi-One option is always to only update cacert indepdendent of NSS14:10:28
@andi:kack.itandi-Still a world rebuild but not as high impact as changing NSS14:10:41
@hexa:lossy.networkhexaon master cacert was already decoupled from nss 14:30:19
@hexa:lossy.networkhexaby you :D14:30:26
@andi:kack.itandi-Yeah :-)14:41:07
@rizary:matrix.orgrizary_andika (@rizary_:matrix.org) (@rizary:matrix.org) joined the room.17:42:25
@kunrooted:matrix.orgkunrootedI haven't asked in here yet I'm currently writing a paper on security of Nix and NixOS maybe someone will suggest other ideas to cover in that paper?17:50:26
@philipp:xndr.dephilippChallenges of having to update entire channels v.s. being able to update a single package.18:16:03
@andi:kack.itandi-Benefits of updating entire channels vs. a single package18:17:27

There are no newer messages yet.


Back to Room ListRoom Version: 6