!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

655 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22203 Servers

Load older messages


SenderMessageTime
4 Dec 2025
@leona:leona.isleonahttps://github.com/NixOS/nixpkgs/pull/467875 apacheHttpd16:54:55
5 Dec 2025
@mdaniels5757:matrix.orgmdaniels5757Now realizing I let these pile up:03:42:37
@mdaniels5757:matrix.orgmdaniels5757Security update approved by maintainer, needs merge: https://github.com/NixOS/nixpkgs/pull/466669 and https://github.com/NixOS/nixpkgs/pull/46670203:43:00
@mdaniels5757:matrix.orgmdaniels5757No approvals for these: https://github.com/NixOS/nixpkgs/pull/466677 https://github.com/NixOS/nixpkgs/pull/465816 https://github.com/NixOS/nixpkgs/pull/466341 https://github.com/NixOS/nixpkgs/pull/465846 03:46:09
@mdaniels5757:matrix.orgmdaniels5757Backports/release branch PRs: https://github.com/NixOS/nixpkgs/pull/466999 https://github.com/NixOS/nixpkgs/pull/466128 https://github.com/NixOS/nixpkgs/pull/466127 https://github.com/NixOS/nixpkgs/pull/465969 https://github.com/NixOS/nixpkgs/pull/46729403:47:08
@mdaniels5757:matrix.orgmdaniels5757And finally, unreviewed (and unfortunately harder a bit harder to review, because the version bumps needed included an in-tree formatter bump, sorry): https://github.com/NixOS/nixpkgs/pull/46538903:48:07
@mdaniels5757:matrix.orgmdaniels5757Jfc thats a lot03:48:15
@hexa:lossy.networkhexa https://github.com/hedgedoc/hedgedoc/pull/6196 soon. Sandro 🐧 22:30:29
@qubitnano:matrix.orgqubitnanoRedacted or Malformed Event22:30:57
@hexa:lossy.networkhexaRedacted or Malformed Event22:31:32
@hexa:lossy.networkhexa * qubitnano: is this security relevant? 22:31:53
@qubitnano:matrix.orgqubitnanoRedacted or Malformed Event22:32:21
@hexa:lossy.networkhexahttps://groups.google.com/g/golang-announce/c/8FJoBkPddm4 golang23:31:25
@hexa:lossy.networkhexahttps://github.com/hedgedoc/hedgedoc/releases/tag/1.10.423:31:38
@hexa:lossy.networkhexahttps://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53 urllib3 (mine)23:31:57
6 Dec 2025
@mdaniels5757:matrix.orgmdaniels5757Already handled: https://github.com/NixOS/nixpkgs/pull/467201, https://github.com/NixOS/nixpkgs/pull/467287, and backports.02:06:34
7 Dec 2025
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/460222 doesn't have a backport to 25.05 yet05:23:54
8 Dec 2025
@annaaurora:artemislena.eu@annaaurora:artemislena.eu changed their display name from Anna Aurora 🏴‍☠️ to Anna Aurora (superseded by: @anna:annaaurora.eu).09:21:12
@annaaurora:artemislena.eu@annaaurora:artemislena.eu left the room.09:26:19
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/12/08/1 pdns-recursor14:30:39
@hexa:lossy.networkhexa* https://www.openwall.com/lists/oss-security/2025/12/08/1 pdns-recursor (@rnhmjoj)14:30:56
@teutat3s:pub.solarteutat3shttps://docs.docker.com/engine/release-notes/28/ docker 28.5.2 fixes "three high-severity security vulnerabilities in runc": CVEs CVE-2025-31133, CVE-2025-52565, CVE-2025-52881 https://github.com/NixOS/nixpkgs/pull/46900414:43:21
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/253 c-ares17:32:26
@hexa:lossy.networkhexaRedacted or Malformed Event17:32:45
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/46904120:51:42
9 Dec 2025
@hexa:lossy.networkhexaRedacted or Malformed Event01:01:16
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/45594301:01:40
@hexa:lossy.networkhexahttps://github.com/c-ares/c-ares/security/advisories/GHSA-jq53-42q6-pqr501:02:19
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/46913001:02:25
@robert:funklause.dedotlambdaNot sure if we have more users of Magick.NET: https://github.com/NixOS/nixpkgs/pull/46916303:20:39

There are no newer messages yet.


Back to Room ListRoom Version: 6