!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

720 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
1 Feb 2024
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/ TL;DR multiple container escapes in docker. runc, buildkit and containerd need to be updated. I'm on it07:50:44
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)Well, was already done by the bot, though the first two of these aren't merged yet https://github.com/NixOS/nixpkgs/pull/285438 https://github.com/NixOS/nixpkgs/pull/285407 https://github.com/NixOS/nixpkgs/pull/28541807:54:17
@leona:leona.isleonaI created some backport PRs to 23.11 (automatic wouldn't have worked): https://github.com/NixOS/nixpkgs/pull/285507 https://github.com/NixOS/nixpkgs/pull/285508 https://github.com/NixOS/nixpkgs/pull/28551009:34:13
@ximnoise:infosec.exchangeximnoise joined the room.09:53:02
@ximnoise:infosec.exchangeximnoise set a profile picture.10:03:31
@delroth:delroth.netdelrothhttps://mastodon.social/@MastodonEngineering/111856895554844910 the patches are out apparently15:22:11
@delroth:delroth.netdelrothhttps://github.com/mastodon/mastodon/releases/tag/v4.2.5 presumably15:22:28
@delroth:delroth.netdelrothand taken care of by https://github.com/NixOS/nixpkgs/pull/28555815:22:45
@schmittlauch:ohai.isschmittlauch (he/him) joined the room.16:55:14
@kudzu:envs.net@kudzu:envs.net left the room.17:45:38
2 Feb 2024
@shivayspec:matrix.orgSpecx joined the room.07:11:03
@daniel:routing.rocksdan_nrw joined the room.09:52:50
3 Feb 2024
@neonmei:matrix.orgneonmei changed their profile picture.04:01:08
@raboof:matrix.orgraboof changed their display name from raboof to raboof @FOSDEM.07:38:53
@networkexception:chat.upi.li@networkexception:chat.upi.li changed their profile picture.11:53:46
@hexa:lossy.networkhexahttps://anydesk.com/en/public-statement14:25:06
@hexa:lossy.networkhexalatest version uses a new codesigning cert14:25:57
@hexa:lossy.networkhexaimage.png
Download image.png
14:27:03
@hexa:lossy.networkhexaI don't think they sign linux tarballs 🙂 14:27:11
@tgerbet:matrix.orgtgerbetNope they do not, at least not for what's used in nixpkgs package14:28:18
@tgerbet:matrix.orgtgerbetBut the package pin did not change in the last 5 months so we are probably fine (unless they were already compromised)14:30:31
@k900:0upti.meK900My kingdom for remote desktop software that doesn't suck 14:33:54
@hexa:lossy.networkhexawayland support when14:34:08
@mkg20001:mkg20001.iomkg20001
In reply to @hexa:lossy.network
wayland support when
rustdesk has that
15:01:06
@mclutzifer:matrix.org@mclutzifer:matrix.org joined the room.16:08:01
@pxc:gnulinux.club@pxc:gnulinux.club 17:24:52
@pxc:gnulinux.club@pxc:gnulinux.club left the room.17:40:01
@k900:0upti.meK900
In reply to @mkg20001:mkg20001.io
rustdesk has that
Have you seen Rustdesk
18:18:14
@archhost:matrix.org@archhost:matrix.org left the room.23:02:07
4 Feb 2024
@soispha:vhack.euBenedikt joined the room.07:45:18

Show newer messages


Back to Room ListRoom Version: 6