!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

696 Members
Coordination and triage of security issues in nixpkgs215 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
12 Sep 2025
@jordanjoel1:matrix.org@jordanjoel1:matrix.org left the room.03:34:39
@aidalgol:tchncs.de@aidalgol:tchncs.de set a profile picture.09:21:38
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/44207611:26:51
@sandro:supersandro.deSandroI would like to bring this package to the attention of the security minded people https://github.com/NixOS/nixpkgs/pull/433307 It is using very old vendored versions of fontforge and poppler, both over 5 years old, and at least poppler contains 10+ CVEs.11:35:13
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/43999611:44:42
@emilazy:matrix.orgemilyonly been in the tree for 8 hours, let's revert11:45:13
@emilazy:matrix.orgemilyif there's going to be a new release without vulns it can wait for that11:45:26
@sandro:supersandro.deSandroI was thinking the same11:45:43
@emilazy:matrix.orgemilypackage guidelines are pretty clear that we need a good reason to add a new package that has significant vulnerabilities from the start11:46:11
@emilazy:matrix.orgemilyI'd do it but not at a computer rn11:46:17

Show newer messages


Back to Room ListRoom Version: 6