!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

652 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22202 Servers

Load older messages


SenderMessageTime
4 Oct 2025
@hexa:lossy.networkhexa * globin: berdario (last commit on the package in 2019 and 2015 😬) 16:58:25
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/44860019:21:12
@hexa:lossy.networkhexahttps://github.com/valkey-io/valkey/releases/tag/8.1.4 🫠 unmaintained19:58:45
@scrumplex:duckhub.ioScrumplexI opened https://github.com/NixOS/nixpkgs/pull/448632, but one of the integration tests are failing now :/21:06:11
@hexa:lossy.networkhexabuilt for me on x86_64-linux, but failed on aarch64-linux21:15:55
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/448627 https://github.com/NixOS/nixpkgs/pull/44862521:16:14
@hexa:lossy.networkhexaI'm out for today, pick yours or mine. I don't particularly care.21:16:41
7 Oct 2025
@fabianhjr:matrix.orgFabián Herediahttps://github.com/NixOS/nixpkgs/pull/449250 Heads up of some binutils security patches04:27:10
@uep:matrix.orguep

The redis thing seems rather worse than the release notes might suggest

https://mastodon.social/@campuscodi/115332411717640276

10:49:36
@uep:matrix.orguepCVSS 10, every version for the last 10 years10:50:26
@uep:matrix.orguep* CVSS 10, every version for the last 13 years10:51:25
@martijn:boers.emailmartijn removed their profile picture.10:54:24
@martijn:boers.emailmartijn set a profile picture.10:56:00
@enzime:nixos.dev@enzime:nixos.dev joined the room.18:47:34
@enzime:nixos.dev@enzime:nixos.devanyone want to review my stable backports for Matrix homeservers?18:48:16
@enzime:nixos.dev@enzime:nixos.devhttps://github.com/NixOS/nixpkgs/pull/44857918:48:21
@enzime:nixos.dev@enzime:nixos.devhttps://github.com/NixOS/nixpkgs/pull/44855818:48:27
@enzime:nixos.dev@enzime:nixos.devthese packages have tests which pass18:48:54
@pyrox:pyrox.devdish [Fox/It/She] #Nixpkgs Review Requests 19:01:12
@enzime:nixos.dev@enzime:nixos.devthese include a security release so I thought it would be relevant to post here19:02:24
@enzime:nixos.dev@enzime:nixos.devhttps://matrix.org/blog/2025/08/security-release/19:02:46
@hexa:lossy.networkhexait is19:11:00
@hexa:lossy.networkhexacan you run the build & test?19:12:02
@hexa:lossy.networkhexathe PR template is a bit too empty for my taste19:12:20
@enzime:nixos.dev@enzime:nixos.dev
In reply to @hexa:lossy.network
can you run the build & test?
I ran nixpkgs-review on both PRs which includes the NixOS VM tests succeeding
19:13:22
@hexa:lossy.networkhexayeah, the PR template is the relevant bit to get an overview though19:13:46
@enzime:nixos.dev@enzime:nixos.dev
In reply to @hexa:lossy.network
yeah, the PR template is the relevant bit to get an overview though
updated
19:14:55
@mdaniels5757:matrix.orgmdaniels5757Mind taking a look at https://github.com/NixOS/nixpkgs/pull/448639? Backport to fix 4 CVEs: 2 unauthenticated vulns that allow reading arbitrary files, 2 authenticated vulns for RCE.22:34:06
8 Oct 2025
@enzime:nixos.dev@enzime:nixos.dev hexa thanks for the review 06:21:45
@enzime:nixos.dev@enzime:nixos.dev left the room.06:21:54

Show newer messages


Back to Room ListRoom Version: 6