!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

665 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22206 Servers

Load older messages


SenderMessageTime
27 Feb 2026
@amadaluzia:tchncs.deamadaluzia[tde] changed their profile picture.03:52:35
@amadaluzia:unredacted.orgamadaluzia changed their profile picture.03:55:56
@j-k:matrix.orgj-kstill looking for a review/merge on this one when someone gets the chance šŸ™ Other maintainer approved (non-commiter), I could self-merge but I don't really like doing that17:04:42
1 Mar 2026
@anthonyrsl:matrix.orgAnthony Rsl joined the room.00:42:52
@0xmrtt:envs.net@0xmrtt:envs.net removed their profile picture.02:35:05
@0xmrtt:envs.net@0xmrtt:envs.net removed their display name 0xMRTT [envs.net].02:38:22
@0xmrtt:envs.net@0xmrtt:envs.net left the room.02:40:20
@somasis:matrix.orgkylie changed their profile picture.03:24:44
@somasis:matrix.orgkylie changed their display name from somasis to kylie.03:52:37
@errornointernet:envs.net@errornointernet:envs.net removed their profile picture.11:40:28
@errornointernet:envs.net@errornointernet:envs.net removed their display name ErrorNoInternet.11:41:08
@errornointernet:envs.net@errornointernet:envs.net left the room.11:41:50
@flandweber:envs.net@flandweber:envs.net removed their display name Finn Landweber.12:17:14
@flandweber:envs.net@flandweber:envs.net left the room.12:17:18
@winston:winston.shwinston joined the room.16:56:27
2 Mar 2026
@nam3l33ss:matrix.orgĀ·ā˜½ā€¢Namelessā˜†ā€¢777 Ā· ± changed their profile picture.12:51:19
@nam3l33ss:matrix.orgĀ·ā˜½ā€¢Namelessā˜†ā€¢777 Ā· ± changed their profile picture.13:08:23
@walrusred_foxvapor00314:matrix.org~centipedeā™” joined the room.20:39:08
3 Mar 2026
@genericnerdyusername:matrix.org@genericnerdyusername:matrix.org left the room.00:18:30
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q1/253 freetype ttuegel22:47:16
4 Mar 2026
@nam3l33ss:matrix.orgĀ·ā˜½ā€¢Namelessā˜†ā€¢777 Ā· ± changed their profile picture.03:13:11
@os:matrix.flyingcircus.ioosnyx (he/him)https://github.com/NixOS/nixpkgs/pull/495788 As promised: actually install updated grub packages.09:55:51
5 Mar 2026
@mtheil:scs.ems.hostMarkus Theil (SCS) changed their display name from Markus Theil to Markus Theil (SCS).09:33:45
@markus.theil:factory.secunet.comMarkus Theil joined the room.12:03:01
@hexa:lossy.networkhexa @stigo various cpan security things on oss-security
  1. https://www.openwall.com/lists/oss-security/2026/03/05/5 Compress::Raw::Zlib

  2. https://www.openwall.com/lists/oss-security/2026/03/05/4 UnQLite

  3. https://www.openwall.com/lists/oss-security/2026/03/05/3 Apache:Session::Generate::MD5

  4. https://www.openwall.com/lists/oss-security/2026/03/05/2 Plack::Middleware::Session::Simple

  5. https://www.openwall.com/lists/oss-security/2026/03/05/1 Net::NSCA::Client


anything for us?
18:13:29
@hexa:lossy.networkhexa @stigo 18:14:59
@hexa:lossy.networkhexa Various cpan security things on oss-security
  1. https://www.openwall.com/lists/oss-security/2026/03/05/5 Compress::Raw::Zlib

  2. https://www.openwall.com/lists/oss-security/2026/03/05/4 UnQLite

  3. https://www.openwall.com/lists/oss-security/2026/03/05/3 Apache:Session::Generate::MD5

  4. https://www.openwall.com/lists/oss-security/2026/03/05/2 Plack::Middleware::Session::Simple

  5. https://www.openwall.com/lists/oss-security/2026/03/05/1 Net::NSCA::Client


anything for us?
18:15:12
@stigo:matrix.orgstigo Only Apache::Session (but no fix is available upstream), our Compress::Raw::Zlib is not affected since we use pkgs.zlib and not the vendored one. 18:57:46
6 Mar 2026
@benjaminsparks:chat.alugha.appBen Sparks joined the room.15:57:52
@ctheune:matrix.flyingcircus.ioTheuni changed their display name from Christian Theune to Theuni.19:57:26

There are no newer messages yet.


Back to Room ListRoom Version: 6