!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

683 Members
Coordination and triage of security issues in nixpkgs211 Servers

Load older messages


SenderMessageTime
4 Jun 2025
@hexa:lossy.networkhexaare you preparing patches for 25.05 and 24.11?14:09:55
@scrumplex:duckhub.ioScrumplexBackports should work for both releases, if I am not mistaken14:31:04
@scrumplex:duckhub.ioScrumplex24.11 is a little behind actually. We would need a manual patch there14:31:36
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/41399517:53:16
@hexa:lossy.networkhexacurl updates are imo risky and introduce regressions every now and then18:03:25
@hexa:lossy.networkhexa23.11 looked like this18:04:13
@hexa:lossy.networkhexa
  patches = [
    # fix ipv6 autodetect compile error in configure script
    # remove once https://github.com/curl/curl/pull/12607 released (8.6.0)
    ./configure-ipv6-autodetect.diff
    # https://curl.se/docs/CVE-2023-46219.html
    ./0001-CVE-2023-42619.patch
    # https://curl.se/docs/CVE-2023-46218.html
    ./0002-CVE-2023-42618.patch
    # https://curl.se/docs/CVE-2024-2398.html
    ./0003-CVE-2024-2398.patch
    # https://curl.se/docs/CVE-2024-2004.html
    ./0004-CVE-2024-2004.patch
  ];
18:04:18
@hexa:lossy.networkhexafrankly not sure why that practice changed18:04:36
@hedgemage:unredacted.orgHedgeMage joined the room.19:26:55
5 Jun 2025
@h0nig2k:matrix.orgh0nig2k joined the room.07:36:47
@h0nig2k:matrix.orgh0nig2kHi, is there any planned triage for https://www.cve.org/CVERecord?id=CVE-2025-4517 - python with CVE 9,4?07:40:52
@vcunat:matrix.orgvcunatI saw https://github.com/NixOS/nixpkgs/pull/41368907:41:52
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)Probably more relevant: https://github.com/NixOS/nixpkgs/pull/413987 there is an update, not just patches to cherry-pick08:59:43
@stigo:matrix.orgstigo https://github.com/NixOS/nixpkgs/pull/414219 for CVE-2011-10007 affecting perlPackages.FileFindRule 12:13:00
@b12f:pub.solarb12f changed their display name from b12f to undefined.09:38:08
@b12f:pub.solarb12f changed their display name from undefined to b12f.11:18:22
@mokasin:mokasin.de@mokasin:mokasin.de left the room.18:55:31
@tioan:dunwyn.xyz@tioan:dunwyn.xyz left the room.19:02:18
6 Jun 2025
@arcayr:mischief.expertarcayr changed their profile picture.01:11:39
7 Jun 2025
@deeok:matrix.orgmatrixrooms.info mod bot (does NOT read/send messages and/or invites; used for checking reported rooms) left the room.22:17:28
@deeok:matrix.orgmatrixrooms.info mod bot (does NOT read/send messages and/or invites; used for checking reported rooms) joined the room.23:22:01
8 Jun 2025
@-jb:matrix.org@-jb:matrix.org removed their profile picture.09:16:38
@-jb:matrix.org@-jb:matrix.org removed their display name Jb.09:16:56
@-jb:matrix.org@-jb:matrix.org left the room.09:17:11
9 Jun 2025
@h0nig2k:matrix.orgh0nig2khttps://github.com/NixOS/nixpkgs/issues/415282 for sqlite CVE's related to 25.0512:23:07
@h0nig2k:matrix.orgh0nig2k* https://github.com/NixOS/nixpkgs/issues/415282 for sqlite CVE's related to 25.05, fixes are present for master already12:23:33
@h0nig2k:matrix.orgh0nig2k* https://github.com/NixOS/nixpkgs/issues/415282 for sqlite CVE's related to 25.05, fixes are present for master already but backport PR was closed12:30:06
@konys.synok:matrix.orgKonys Synok joined the room.13:14:21
10 Jun 2025
@teutat3s:pub.solarteutat3s https://github.com/NixOS/nixpkgs/pull/415625 Fixes CVE-2025-48937 18:05:20
@hexa:lossy.networkhexa K900: https://kde.org/info/security/advisory-20250609-1.txt konsole 23:51:04

Show newer messages


Back to Room ListRoom Version: 6