!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

675 Members
Coordination and triage of security issues in nixpkgs211 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
5 Aug 2025
@hexa:lossy.networkhexa Alyssa Ross: patch from ariadne https://git.alpinelinux.org/aports/tree/main/busybox/0001-tar-fix-TOCTOU-symlink-race-condition.patch?__goaway_challenge=cookie&__goaway_id=798fc2a5dc35e31635444270e8cca34a&id=9e42dea5fba84a8afad1f1910b7d3884128a567e 22:55:39
6 Aug 2025
@qyliss:fairydust.spaceAlyssa Ross
In reply to @hexa:lossy.network
Alyssa Ross: patch from ariadne https://git.alpinelinux.org/aports/tree/main/busybox/0001-tar-fix-TOCTOU-symlink-race-condition.patch?__goaway_challenge=cookie&__goaway_id=798fc2a5dc35e31635444270e8cca34a&id=9e42dea5fba84a8afad1f1910b7d3884128a567e
Does Busybox rebuild every NixOS test?
06:41:34
@hexa:lossy.networkhexaI don't know10:44:02
@hexa:lossy.networkhexa Alyssa Ross: yeah, looks like it does 🫣 15:47:16
@qyliss:fairydust.spaceAlyssa RossKeep it for the Friday kernel updates then?15:47:37
@hexa:lossy.networkhexasgtm15:47:43
@qyliss:fairydust.spaceAlyssa Rossleft a comment15:48:14
@sandro:supersandro.deSandroYou need to strip the query strings otherwise the link is dead .... https://git.alpinelinux.org/aports/tree/main/busybox/0001-tar-fix-TOCTOU-symlink-race-condition.patch23:35:43
8 Aug 2025
@0x4a6f:nixos.dev0x4A6F joined the room.06:59:20
9 Aug 2025
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q3/82 7-zip23:02:50
@hexa:lossy.networkhexa emily: do we have that one or the other one? 23:03:23
@emilazy:matrix.orgemilywe have both :(23:03:34
@emilazy:matrix.orgemily this one would be _7zz 23:03:46
@emilazy:matrix.orgemily p7zip is probably vulnerable since it's unmaintained 23:03:53
@emilazy:matrix.orgemilyplease feel free to kill that one with fire23:03:58
10 Aug 2025
@jkarlson:kapsi.fiEmil ThorsøeRedacted or Malformed Event16:28:24
@jkarlson:kapsi.fiEmil Thorsøehttps://github.com/Nheko-Reborn/nheko/releases/tag/v0.12.116:29:47
@jkarlson:kapsi.fiEmil Thorsøenot sure what it is, but marked security16:30:09
@hexa:lossy.networkhexahtml escaping16:57:12
@cafkafk:fem.ggcafkafk joined the room.19:19:00
12 Aug 2025
@psalden:matrix.org@psalden:matrix.org left the room.06:56:18
13 Aug 2025
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q3/9818:17:03
@hexa:lossy.networkhexa* https://seclists.org/oss-sec/2025/q3/98 nginx18:17:04

Show newer messages


Back to Room ListRoom Version: 6