!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

693 Members
Coordination and triage of security issues in nixpkgs217 Servers

Load older messages


SenderMessageTime
27 May 2021
@fabaff:matrix.orgFabian Affolter joined the room.18:03:03
@robert:funklause.dedotlambdaOn 20.09, libxml2 has at least 5 open CVEs: https://github.com/NixOS/nixpkgs/issues/124650.19:22:36
@robert:funklause.dedotlambdaThe patch for CVE-2021-3518 doesn't apply cleanly.19:22:46
@hexa:lossy.networkhexaawesome, the patches for curl 7.74.0 also don't apply cleanly.19:45:40
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/12469319:56:37
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/12469520:11:08
28 May 2021
@adisbladis:matrix.orgadisbladis left the room.00:39:13
@asymmetric:matrix.dapp.org.ukasymmetric joined the room.16:05:19
29 May 2021
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/12483902:28:02
@hexa:lossy.networkhexa found by moritz.hedtke 02:28:19
@justinrestivo:matrix.orgjustinrestivo changed their display name from justinrestivo to oh caml >>=.12:20:58
@justinrestivo:matrix.orgjustinrestivo changed their profile picture.12:22:00
@justinrestivo:matrix.orgjustinrestivo changed their display name from oh caml >>= to justinrestivo.12:22:28
@justinrestivo:matrix.orgjustinrestivo changed their profile picture.12:24:00
@hexa:lossy.networkhexa ris_: feel free to push to that branch when you have found a solution 13:49:39
@r_i_s:matrix.orgris_hmmmmm though I know what the problem is, the solution is less clear... macos' framework packages are weird13:51:31
@r_i_s:matrix.orgris_ i'll ask #macos:nixos.org 13:52:18
@r_i_s:matrix.orgris_if we were in a hurry security-wise, curl have published patches for all three CVEs14:03:52
@mkos:matrix.orgMark left the room.19:13:34
@cyplo:cyplo.devcyplo joined the room.19:59:15
@onelegend:envs.netOneLegend joined the room.22:21:31
30 May 2021
@r_i_s:matrix.orgris_ if anyone wants to have a go at bumping singularity 3.6.3's umoci dependency to 0.4.7 and thus resolve https://github.com/NixOS/nixpkgs/issues/124678 please be my guest, i give up. golang's packaging tools are :horror: 00:14:32
@onelegend:envs.netOneLegend left the room.00:55:27
@sandro:supersandro.deSandro
In reply to @r_i_s:matrix.org
if anyone wants to have a go at bumping singularity 3.6.3's umoci dependency to 0.4.7 and thus resolve https://github.com/NixOS/nixpkgs/issues/124678 please be my guest, i give up. golang's packaging tools are :horror:
You probably need to create upstream issues for them
02:32:05
@sandro:supersandro.deSandro
In reply to @r_i_s:matrix.org
if anyone wants to have a go at bumping singularity 3.6.3's umoci dependency to 0.4.7 and thus resolve https://github.com/NixOS/nixpkgs/issues/124678 please be my guest, i give up. golang's packaging tools are :horror:
* You probably need to create upstream issues/PRs for them
02:32:18
@wrinkle_hut:matrix.orgKitty joined the room.06:09:43
@arianvp:matrix.orgArianIt seems NixOS is missing DigiCert's new Root CA. E.g. i can not curl https://signup.cloud.oracle.com11:47:00
@arianvp:matrix.orgArianHow is the nixos trust store kept up to date?11:59:36
@janne.hess:helsinki-systems.dedas_j
In reply to @arianvp:matrix.org
How is the nixos trust store kept up to date?
nss's trust store (mozilla) ist used
13:56:56
@janne.hess:helsinki-systems.dedas_j see pkgs/data/misc/cacert 13:57:38

Show newer messages


Back to Room ListRoom Version: 6