!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

671 Members
Coordination and triage of security issues in nixpkgs209 Servers

Load older messages


SenderMessageTime
11 Sep 2025
@hexa:lossy.networkhexacan't believe I subscribed to cups releases 🫣20:37:01
@hexa:lossy.networkhexafree for anyone to pick up20:37:28
@hexa:lossy.networkhexa* free for anyone to pick up, the maintainer is AWOL20:37:33
@stigo:matrix.orgstigoIt's ☕️ :D20:52:53
12 Sep 2025
@jordanjoel1:matrix.org@jordanjoel1:matrix.org changed their profile picture.03:27:12
@jordanjoel1:matrix.org@jordanjoel1:matrix.org left the room.03:34:39
@aidalgol:tchncs.de@aidalgol:tchncs.de set a profile picture.09:21:38
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/44207611:26:51
@sandro:supersandro.deSandroI would like to bring this package to the attention of the security minded people https://github.com/NixOS/nixpkgs/pull/433307 It is using very old vendored versions of fontforge and poppler, both over 5 years old, and at least poppler contains 10+ CVEs.11:35:13
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/43999611:44:42
@emilazy:matrix.orgemilyonly been in the tree for 8 hours, let's revert11:45:13
@emilazy:matrix.orgemilyif there's going to be a new release without vulns it can wait for that11:45:26
@sandro:supersandro.deSandroI was thinking the same11:45:43
@emilazy:matrix.orgemilypackage guidelines are pretty clear that we need a good reason to add a new package that has significant vulnerabilities from the start11:46:11
@emilazy:matrix.orgemilyI'd do it but not at a computer rn11:46:17
@leona:leona.isleonai created a revert PR https://github.com/NixOS/nixpkgs/pull/442351. I won't merge that myself, happy for reviews.11:52:43
@sandro:supersandro.deSandroI already saw that when clicking revert that the commit was already created. Approved, too.11:54:56
@emilazy:matrix.orgemily(personally I don't think we need tons of ceremony for reverting for things that would have been a blocking review if caught hours before merge rather than after. part of the Hintjens optimistic merging doc people like is unilateral reverts if a change is problematic. so I'll hit the merge button)11:56:38
13 Sep 2025
@oak:universumi.fioak 🏳️‍🌈♥️ changed their profile picture.09:46:05
14 Sep 2025
@emma:rory.gayEmma [it/its] joined the room.08:39:56
15 Sep 2025
@kevincox:matrix.orgkevincox changed their display name from kevincox to kevincox (moved to @kevincox:kevincox.ca).19:40:13
16 Sep 2025
@teutat3s:pub.solarteutat3s https://github.com/NixOS/nixpkgs/pull/443455 | Fix CVE-2025-59161 / GHSA-m6c8-98f4-75rr "A malicious room can hide an unrelated room and cause it to be left when the malicious room is left " 14:41:53
@pyrox:pyrox.devdish [Fox/It/She]queued to merge, ty!16:06:25
@sandro:supersandro.deSandroShould we drop goldwarden if it's development is halted? https://github.com/quexten/goldwarden16:16:13
@hexa:lossy.networkhexa #security-discuss:nixos.org 16:18:47
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/44357321:57:34
18 Sep 2025
@hexa:lossy.networkhexahttps://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2025-05.html12:47:05
19 Sep 2025
@mkg20001:mkg20001.iomkg20001 changed their profile picture.17:21:04
20 Sep 2025
@scr1bbles:matrix.org@scr1bbles:matrix.org left the room.15:40:33
21 Sep 2025
@hexa:lossy.networkhexahttps://paste.swordarmor.fr/raw/GvZ801:02:15

Show newer messages


Back to Room ListRoom Version: 6