!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

695 Members
Coordination and triage of security issues in nixpkgs213 Servers

Load older messages


SenderMessageTime
25 Aug 2025
@sigmasquadron:matrix.orgSigmaSquadron * 09:49:15
@tgerbet:matrix.orgtgerbetUpstream should consider the issue public. Information is likely still accessible in GitHub events Full disclosure is better than half disclosed (and apparently the tendency these days is to publish emboarged issues on public ML 🫠 )10:27:45
@lennart:0520.chlennartIt's not related to nixpkgs, only upstream.10:28:01
@lennart:0520.chlennartI see your point, but it'd let upstream cover and decide on that.10:28:27
@lennart:0520.chlennartNonetheless, they'll apply for an CVE number :b10:28:38
@raitobezarius:matrix.orgraitobezariusIf upstream doesn't do full disclosure, this is a very bad look on them for what seems to be a minor issue.10:28:56
@lennart:0520.chlennartWhat do you mean by half and full disclosure? Lets move to the discussion channel?10:29:44
27 Aug 2025
@martijn:boers.emailmartijn joined the room.13:58:51
28 Aug 2025
@hexa:lossy.networkhexa https://github.com/storaged-project/udisks/security/advisories/GHSA-742q-gggc-473g udisks Jan Tojnar 20:55:32
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/08/28/1 https://www.openwall.com/lists/oss-security/2025/08/28/220:55:56
@hexa:lossy.networkhexa* https://www.openwall.com/lists/oss-security/2025/08/28/120:56:07
29 Aug 2025
@bluebirdlamentations:matrix.org@bluebirdlamentations:matrix.org left the room.16:13:53
@magic_rb:matrix.redalder.org@magic_rb:matrix.redalder.org changed their profile picture.19:27:40
30 Aug 2025
@tgerbet:matrix.orgtgerbet SigmaSquadron: https://xenbits.xen.org/xsa/advisory-471.html
Is this taken into account by the Xen team?
11:13:23
@sigmasquadron:matrix.orgSigmaSquadronuh I already fixed 471 I think11:40:39
@sigmasquadron:matrix.orgSigmaSquadronyeah that's the big one11:41:13
@sigmasquadron:matrix.orgSigmaSquadronwe just updated to the latest branch heads and then updated to 4.20.1 when it released11:41:36
@sigmasquadron:matrix.orgSigmaSquadronditto for 4.19.x on stable11:41:57
@sigmasquadron:matrix.orgSigmaSquadronYes, just confirmed that both 25.05 and 25.11 have all the patches for XSA 471.11:49:37
31 Aug 2025
@alper-celik:matrix.org@alper-celik:matrix.org left the room.16:00:07
1 Sep 2025
@lt1379:matrix.orgLun changed their display name from lun to Lun.15:55:15
2 Sep 2025
@aidalgol:tchncs.de@aidalgol:tchncs.de joined the room.21:55:24
3 Sep 2025
@ghpzin:envs.netghpzin joined the room.07:30:05
4 Sep 2025
@aidalgol:tchncs.de@aidalgol:tchncs.de changed their display name from Aidan Gauland to aidalgol[m].11:23:25
@aidalgol:tchncs.de@aidalgol:tchncs.de changed their display name from aidalgol[m] to aidalgol.11:24:11
5 Sep 2025
@cnorman:matrix.orgChris Norman set a profile picture.15:05:04
@cnorman:matrix.orgChris Norman changed their profile picture.15:05:17
6 Sep 2025
@ss:someonex.netSomeoneSerge (back on matrix) changed their display name from SomeoneSerge (Ever OOMed by Element) to SomeoneSerge (@nixcon & back on matrix).09:24:35
8 Sep 2025
@inayet:matrix.orgInayet set a profile picture.02:16:53
@stigo:matrix.orgstigohttps://github.com/NixOS/nixpkgs/pull/441228 CVE-2025-40928 and CVE-2025-4092915:32:42

Show newer messages


Back to Room ListRoom Version: 6