!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

652 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22202 Servers

Load older messages


SenderMessageTime
21 Oct 2025
@pyrox:pyrox.devdish [Fox/It/She] of course its crypto coins >.> can never trust those projects to do anything right 22:17:52
@hexa:lossy.networkhexa 👉️ #security-discuss:nixos.org 23:02:04
22 Oct 2025
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/45430302:02:25
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/68 bind916:14:45
23 Oct 2025
@ramblurr:outskirtslabs.comramblurr joined the room.08:55:38
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/10/23/1 pdns16:13:53
@hexa:lossy.networkhexa* https://www.openwall.com/lists/oss-security/2025/10/23/1 pdns-recursor16:13:55
24 Oct 2025
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its) changed their display name from ⛧-440729 [sophie] (it/its) to ⛧-440729 [sophie raven] (it/its).06:10:51
@hexa:lossy.networkhexahttps://nvd.nist.gov/vuln/detail/CVE-2025-62813 lz410:26:42
@sigmasquadron:matrix.orgSigmaSquadron XSA #476
master: https://github.com/NixOS/nixpkgs/pull/455255
release-25.05:https://github.com/NixOS/nixpkgs/pull/455256
12:42:27
@sigmasquadron:matrix.orgSigmaSquadron * XSA #476
master: https://github.com/NixOS/nixpkgs/pull/455255
release-25.05: https://github.com/NixOS/nixpkgs/pull/455256
12:42:34
@vcunat:matrix.orgvcunatThose issues are private?13:38:51
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/70?13:39:41
@hexa:lossy.networkhexaI'm a security manager on the org and I can't see them either, so probably deleted?13:40:15
@winter:catgirl.cloudWinteri’m an org owner and cannot see them either, my guess is he typo’d?13:49:55
@winter:catgirl.cloudWinteri don’t think you can delete PRs like you can issues13:50:05
@vcunat:matrix.orgvcunatSurely typos. The numbers are significantly beyond what's allocated right now.13:52:58
@tnias:stratum0.orgtniassomeone named sigmasquadron opened those: https://github.com/NixOS/nixpkgs/pull/455225 https://github.com/NixOS/nixpkgs/pull/45522613:53:36
@niklaskorz:matrix.orgniklaskorzTarmageddon tracking issue: https://github.com/NixOS/nixpkgs/issues/455265 The "check manually" part is bigger than I'd have liked (script improvals welcome), but considering there are over 2000 packages that the script handled fine, I think it's still reasonably small.16:20:28
25 Oct 2025
@sigmasquadron:matrix.orgSigmaSquadron * XSA #476
master: https://github.com/NixOS/nixpkgs/pull/455225
release-25.05: https://github.com/NixOS/nixpkgs/pull/455226
03:18:01
@sigmasquadron:matrix.orgSigmaSquadronWhoops, yes. I wrote a 5 when I should've written a 2. Sorry about that; it was late and I went to bed shortly after posting.03:18:37
@sigmasquadron:matrix.orgSigmaSquadron * 03:18:50
26 Oct 2025
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/pull/45594317:42:44
@tgerbet:matrix.orgtgerbetDisputed https://github.com/NixOS/nixpkgs/pull/45594517:43:13
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/455984 fixes two undisclosed vulnerabilities in ImageMagick19:40:54
27 Oct 2025
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/456046 probably fixes a vulnerability in Postfix but there is no official announcement yet01:55:21
@robert:funklause.dedotlambda* https://github.com/NixOS/nixpkgs/pull/455984 fixes two undisclosed vulnerabilities in ImageMagick EDIT: the vulnerability reports were now published01:56:01
@robert:funklause.dedotlambda* https://github.com/NixOS/nixpkgs/pull/455984 fixes two undisclosed vulnerabilities in ImageMagick EDIT: the vulnerability reports are now published01:56:16
@dp:anarchyislove.xyzDustin Plattner changed their display name from Dustin to Dustin Plattner.02:57:36
@amadaluzia:tchncs.de➡️@amadaluzia:unredacted.org joined the room.23:56:26

Show newer messages


Back to Room ListRoom Version: 6