!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

652 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22202 Servers

Load older messages


SenderMessageTime
1 Oct 2025
@mtheil:scs.ems.hostMarkus TheilI'm currently doing some short smoke tests on the backport branch.18:56:55
3 Oct 2025
@soundhead:matrix.orgsoundhead joined the room.05:12:02
@hexa:lossy.networkhexahttps://www.fetchmail.info/fetchmail-SA-2025-01.txt20:22:39
@hexa:lossy.networkhexa* https://www.fetchmail.info/fetchmail-SA-2025-01.txt no maintainer20:22:57
@pyrox:pyrox.devdish [Fox/It/She]I'd drop if there's no maintainer and security problems. It's not used anywhere in-tree, so 🤷20:47:27
@pyrox:pyrox.devdish [Fox/It/She] yeah fetchmail_7 hasn't been updated since it was added to the tree in 2022, and fetchmail lost its only maintainer in 2021, and only got updates thanks to r-ryantm. 20:49:05
@pyrox:pyrox.devdish [Fox/It/She] yeah fetchmail_7 hasn't been updated since it was added to the tree in 2022, and fetchmail lost its only maintainer in 2021, and only got updates thanks to r-ryantm. 20:49:11
@pyrox:pyrox.devdish [Fox/It/She]i think a drop would be the best choice, since it doesnt seem that anyone cares about it20:49:24
@pyrox:pyrox.devdish [Fox/It/She]no open issues for it either, so if it doesn't build no one's reported it.20:49:59
@pyrox:pyrox.devdish [Fox/It/She]making a pr to drop both.20:50:04
@pyrox:pyrox.devdish [Fox/It/She]https://github.com/nixos/nixpkgs/pull/44833320:52:58
@pyrox:pyrox.devdish [Fox/It/She]I don't believe this warrants a release note due to the obscurity of the package, if someone disagrees I'm glad to add one20:53:29
@hexa:lossy.networkhexanot really obscure https://repology.org/project/fetchmail/versions20:54:32
@pyrox:pyrox.devdish [Fox/It/She]fair enough20:55:23
4 Oct 2025
@aidalgol:tchncs.de@aidalgol:tchncs.de left the room.00:51:24
@aleksana:mozilla.orgaleksana 🏳️‍⚧️ (force me to bed after 18:00 UTC) changed their profile picture.08:41:26
@hexa:lossy.networkhexahttps://github.com/redis/redis/releases/tag/8.2.216:55:58
@hexa:lossy.networkhexa globin: berdario 16:56:22
@hexa:lossy.networkhexa * globin: berdario (last commit on the package in 2019 and 2015 😬) 16:58:25
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/44860019:21:12
@hexa:lossy.networkhexahttps://github.com/valkey-io/valkey/releases/tag/8.1.4 🫠 unmaintained19:58:45
@scrumplex:duckhub.ioScrumplexI opened https://github.com/NixOS/nixpkgs/pull/448632, but one of the integration tests are failing now :/21:06:11
@hexa:lossy.networkhexabuilt for me on x86_64-linux, but failed on aarch64-linux21:15:55
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/448627 https://github.com/NixOS/nixpkgs/pull/44862521:16:14
@hexa:lossy.networkhexaI'm out for today, pick yours or mine. I don't particularly care.21:16:41
7 Oct 2025
@fabianhjr:matrix.orgFabián Herediahttps://github.com/NixOS/nixpkgs/pull/449250 Heads up of some binutils security patches04:27:10
@uep:matrix.orguep

The redis thing seems rather worse than the release notes might suggest

https://mastodon.social/@campuscodi/115332411717640276

10:49:36
@uep:matrix.orguepCVSS 10, every version for the last 10 years10:50:26
@uep:matrix.orguep* CVSS 10, every version for the last 13 years10:51:25
@martijn:boers.emailmartijn removed their profile picture.10:54:24

Show newer messages


Back to Room ListRoom Version: 6