!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

673 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22206 Servers

Load older messages


SenderMessageTime
21 Mar 2026
@emilazy:matrix.orgemilyperhaps revert for now?14:12:53
@k900:0upti.meK900 @ElvishJerricco has a fix 14:20:44
@elvishjerricco:matrix.orgElvishJerriccoIf no one's going to review it then I guess we just revert though14:21:15
@elvishjerricco:matrix.orgElvishJerriccoI'd merge because I'm reasonably sure of the fix. But plausibly the original PR did it that way for some reason and the author / reviewers of it should chime in. I mean I think that's unlikely but that's one reason I haven't just self-merged it14:22:52
@emilazy:matrix.orgemilywe had a fix 20 hours ago, we could have merged a revert like 24 hours ago14:31:17
@vcunat:matrix.orgvcunatRebuilding all tests takes a while, but yes.14:39:49
@vcunat:matrix.orgvcunat* Rebuilding all tests takes a while, but yes. (at least I assume that the fix wouldn't rebuild most tests)14:55:56
@vcunat:matrix.orgvcunatI guess we revert for now: https://github.com/NixOS/nixpkgs/pull/50196315:01:56
23 Mar 2026
@pyrox:pyrox.devdish [Fox/It/She] Closes 10 currently open security issues for siyuan https://github.com/NixOS/nixpkgs/pull/502753 18:20:37
24 Mar 2026
@leona:leona.isleonahttps://github.com/NixOS/nixpkgs/pull/503140 nginx20:11:50
@pyrox:pyrox.devdish [Fox/It/She] https://nodejs.org/en/blog/vulnerability/march-2026-security-releases 21:38:22
@pyrox:pyrox.devdish [Fox/It/She]nodejs21:38:23
@pyrox:pyrox.devdish [Fox/It/She]2 high, 5 medium, 2 low severity CVEs21:40:58
@pyrox:pyrox.devdish [Fox/It/She]24.x and earlier are only affected by 4 of the medium vulns, but all of the high and low ones as well21:41:24
@pyrox:pyrox.devdish [Fox/It/She] PR submitted for all 4 versions https://github.com/NixOS/nixpkgs/pull/503168 21:48:49
@whispers:catgirl.cloudwhispers [& it/fae]aduh95 did this in #503151, #503152, #503153, and #50315421:50:46
@whispers:catgirl.cloudwhispers [& it/fae]* aduh95 did this in #503151, #503152, #503153, and #503154. all are already merged. 24 to staging, the rest to master.21:50:59
@pyrox:pyrox.devdish [Fox/It/She]my apologies, didn't see those. Thank you!21:51:30
25 Mar 2026
@sigmasquadron:matrix.orgFernando Rodrigueshttps://xenbits.xenproject.org/xsa/advisory-482.html XSA targetting a Linux driver01:04:14
@sigmasquadron:matrix.orgFernando Rodrigues * 01:04:31
@sigmasquadron:matrix.orgFernando RodriguesI'm not entirely sure how to patch out kernels though01:04:55
@sigmasquadron:matrix.orgFernando Rodrigues * 01:05:00
@qyliss:fairydust.spaceAlyssa RossPresumably mainline will have the patch at some point?06:37:24
@qyliss:fairydust.spaceAlyssa Rossbut maybe we should ask…06:41:23
@sigmasquadron:matrix.orgFernando Rodriguesit will; this would be about patching ahead of schedule. We do that for Xen since minor version bumps take forever to release, but I'm not sure how we do things in the kernel.06:56:21
@qyliss:fairydust.spaceAlyssa Rossstable kernels are weekly, but this patch has not even been posted to a kernel list yet06:58:51
@qyliss:fairydust.spaceAlyssa Rossah but it was committed directly to Linus's tree, good07:01:17
@qyliss:fairydust.spaceAlyssa Rossso generally it will be in 7.0-rc6 on Sunday, and then stable kernels the following Friday.07:01:55
@qyliss:fairydust.spaceAlyssa Rossbut in this case, I already see them in the stable kernel queue, so they're likely to make it into this Friday's instead07:04:21
@sigmasquadron:matrix.orgFernando Rodriguesawesome07:42:27

There are no newer messages yet.


Back to Room ListRoom Version: 6