!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

652 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22202 Servers

Load older messages


SenderMessageTime
11 Sep 2025
@hexa:lossy.networkhexa* free for anyone to pick up, the maintainer is AWOL20:37:33
@stigo:matrix.orgstigoIt's ☕️ :D20:52:53
12 Sep 2025
@jordanjoel1:matrix.org@jordanjoel1:matrix.org changed their profile picture.03:27:12
@jordanjoel1:matrix.org@jordanjoel1:matrix.org left the room.03:34:39
@aidalgol:tchncs.de@aidalgol:tchncs.de set a profile picture.09:21:38
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/44207611:26:51
@sandro:supersandro.deSandro 🐧I would like to bring this package to the attention of the security minded people https://github.com/NixOS/nixpkgs/pull/433307 It is using very old vendored versions of fontforge and poppler, both over 5 years old, and at least poppler contains 10+ CVEs.11:35:13
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/43999611:44:42
@emilazy:matrix.orgemilyonly been in the tree for 8 hours, let's revert11:45:13
@emilazy:matrix.orgemilyif there's going to be a new release without vulns it can wait for that11:45:26
@sandro:supersandro.deSandro 🐧I was thinking the same11:45:43
@emilazy:matrix.orgemilypackage guidelines are pretty clear that we need a good reason to add a new package that has significant vulnerabilities from the start11:46:11
@emilazy:matrix.orgemilyI'd do it but not at a computer rn11:46:17
@leona:leona.isleonai created a revert PR https://github.com/NixOS/nixpkgs/pull/442351. I won't merge that myself, happy for reviews.11:52:43
@sandro:supersandro.deSandro 🐧I already saw that when clicking revert that the commit was already created. Approved, too.11:54:56
@emilazy:matrix.orgemily(personally I don't think we need tons of ceremony for reverting for things that would have been a blocking review if caught hours before merge rather than after. part of the Hintjens optimistic merging doc people like is unilateral reverts if a change is problematic. so I'll hit the merge button)11:56:38
13 Sep 2025
@oak:universumi.fioak 🏳️‍🌈♥️ changed their profile picture.09:46:05
14 Sep 2025
@emma:rory.gayEmma [it/its] joined the room.08:39:56
15 Sep 2025
@kevincox:matrix.org@kevincox:matrix.org changed their display name from kevincox to kevincox (moved to @kevincox:kevincox.ca).19:40:13
16 Sep 2025
@teutat3s:pub.solarteutat3s https://github.com/NixOS/nixpkgs/pull/443455 | Fix CVE-2025-59161 / GHSA-m6c8-98f4-75rr "A malicious room can hide an unrelated room and cause it to be left when the malicious room is left " 14:41:53
@pyrox:pyrox.devdish [Fox/It/She]queued to merge, ty!16:06:25
@sandro:supersandro.deSandro 🐧Should we drop goldwarden if it's development is halted? https://github.com/quexten/goldwarden16:16:13
@hexa:lossy.networkhexa #security-discuss:nixos.org 16:18:47
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/44357321:57:34
18 Sep 2025
@hexa:lossy.networkhexahttps://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2025-05.html12:47:05
19 Sep 2025
@mkg20001:mkg20001.iomkg20001 changed their profile picture.17:21:04
20 Sep 2025
@scr1bbles:matrix.org@scr1bbles:matrix.org left the room.15:40:33
21 Sep 2025
@hexa:lossy.networkhexahttps://paste.swordarmor.fr/raw/GvZ801:02:15
@hexa:lossy.networkhexa *
From: Maria Matejka via Bird-downstream <bird-downstream@lists.nic.cz>
To: BIRD downstream maintainers <bird-downstream@lists.nic.cz>
Cc: Maria Matejka <maria.matejka@nic.cz>
Reply-To: BIRD downstream maintainers <bird-downstream@lists.nic.cz>
Date: Fri, 19 Sep 2025 16:05:44 +0200
Subject: [Bird-downstream] Expected release of BIRD 3.0.5 and 3.1.4

[-- Attachment #1 --]
[-- Type: multipart/alternative, Encoding: 7bit, Size: 4.3K --]

Hello!

Please expect that hopefully on monday we're going to release fixup
versions 3.0.5 and 3.1.4; this time there is an embargoed patch included
so after we're done fixing, we're going to share the TGZs with you
privately before announcing and pushing to the public repository.

Please advise which timing is good for you to coordinate the release.
I would like to aim to monday evening or tuesday morning european time;
if something goes wrong, tuesday evening would be the time.

Thanks!
Maria

--
Maria Matejka (she/her) | BIRD Team Leader | CZ.NIC, z.s.p.o.

[-- Attachment #2 --]
[-- Type: text/plain, Encoding: 7bit, Size: 0.2K --]

_______________________________________________
Bird-downstream mailing list -- bird-downstream@lists.nic.cz
To unsubscribe send an email to bird-downstream-leave@lists.nic.cz
01:02:26
22 Sep 2025
@felix.schroeter:scs.ems.hostFelix Schröter changed their display name from Felix Schröter to Felix Schröter (🌄 29.09. – 05.10.).09:55:50

Show newer messages


Back to Room ListRoom Version: 6