
NixOS Security Triage

603 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22187 Servers

Load older messages

10 Oct 2024
@scrumplex:duckhub.ioScrumplexI can create a PR right away ^^08:04:57
In reply to @scrumplex:duckhub.io
I can create a PR right away ^^
@scrumplex:duckhub.ioScrumplexAlso, I have built the new Floorp version here: https://github.com/NixOS/nixpkgs/pull/347677 Should be ready to merge08:13:30
14 Oct 2024
15 Oct 2024
@pyrox:pyrox.devdish [Fox/It/She] joined the room.07:35:53
16 Oct 2024
@eisfunke:eisfunke.com@eisfunke:eisfunke.com left the room.13:35:57
17 Oct 2024
@joerg:thalheim.ioMic92 changed their display name from Mic92 to Mic3000.06:51:17
@joerg:thalheim.ioMic92 changed their display name from Mic3000 to Mic3000 🌋.06:51:46
@joerg:thalheim.ioMic92 changed their display name from Mic3000 🌋 to Mic92.12:22:31
@tom:dragar.deTomLooks like Grafana is doing some sort of securtiy update https://github.com/grafana/grafana/releases https://github.com/grafana/grafana/tags Usually it takes them a few hours until all tags have releases. Haven't looked into what they've fixed17:46:51
@scrumplex:duckhub.ioScrumplexThe mentioned vulnerability hasn't been disclosed yet it seems https://nvd.nist.gov/vuln/detail/CVE-2024-926417:48:09
@ma27:nicht-so.sexyma27(grafana maintainer here) seen it and keeping an eye on my notifications.17:49:20
@scrumplex:duckhub.ioScrumplexWhile we are at the topic of upcoming security fixes. OpenSSL has disclosed a low severity issue here: https://openssl-library.org/news/secadv/20241016.txt They haven't released an update yet as the issue isn't deemed important.17:51:05
@ma27:nicht-so.sexyma27 for grafana: https://github.com/NixOS/nixpkgs/pull/349364
no release for 10.4 yet (on 24.05), so not sure if it's even affected, but I'll monitor.
19 Oct 2024
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.19:11:37
20 Oct 2024
@meebey:matrix.orgmeebey aka Mirco Bauer joined the room.02:46:43
@omega-800:matrix.orgGeorgiy Shevoroshkin joined the room.20:07:29
21 Oct 2024
@adam:robins.wtfadamcstephens https://guix.gnu.org/blog/2024/build-user-takeover-vulnerability/ 12:17:09
@adam:robins.wtfadamcstephens cafkafk has a number of accounts but maybe this one is active?  12:25:52
@cafkafk:gitter.imcafkafkThis one also is12:26:23
@cafkafk:fem.ggcafkafk 🏳️‍⚧️ joined the room.12:28:53
@emilazy:matrix.orgemily(do they not realize it's identical to the recent Nix vulnerability or are they just avoiding mentioning it?)13:43:52
@hexa:lossy.networkhexaTheophane had been reaching out to Ludo on a few occasions, but now that he is gone no idea if that still happens s14:07:52
@hexa:lossy.networkhexa * 14:07:57
@fabianhjr:matrix.orgFabián Heredia
In reply to @emilazy:matrix.org
(do they not realize it's identical to the recent Nix vulnerability or are they just avoiding mentioning it?)
probably from a PR standpoint there are downsides and no upsides to making that mention/parallel.
In reply to @fabianhjr:matrix.org
probably from a PR standpoint there are downsides and no upsides to making that mention/parallel.
does guix even publicly acknowledge its status as a fork of Nix?
@k900:0upti.meK900It's not really a fork anymore 19:11:04
@k900:0upti.meK900It diverged so far to effectively be its own thing 19:11:19

There are no newer messages yet.

Back to Room ListRoom Version: 6