!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

724 Members
Coordination and triage of security issues in nixpkgs223 Servers

Load older messages


SenderMessageTime
4 Jun 2021
@hexa:lossy.networkhexathat can happen outside of nixpkgs, since the nixpkgs model is easy to fork, but alot of being "lts" is about having moldy versions of software, and nobody likes to work with that for free18:09:49
@hexa:lossy.networkhexain debian people are paid for maintaining things, this is especially true for the lts extensions of their releases18:10:28
@hexa:lossy.networkhexaand following debian releases would mean a change to our release cadence, as else you'd need to support multiple stable releases in parallel - not feasible18:12:35
@hexa:lossy.networkhexathe one month overlap between the old and new stable is annoying enough fwiw18:13:47
@hexa:lossy.networkhexa * the one month overlap between the old and new stable right now is annoying enough fwiw18:13:55
@sandro:supersandro.deSandro
In reply to @hexa:lossy.network
and following debian releases would mean a change to our release cadence, as else you'd need to support multiple stable releases in parallel - not feasible
right now we release two times a year a big release. Debian does once every few years.
18:32:00
@philipp:xndr.dephilippJust to be clear I never said we should change the release schedule, I just wondered whether it would be feasible to use debians patches to keep certain packages around a while longer.18:33:15
@sandro:supersandro.deSandroyou can always just pin the older version and apply the patches yourself but doing a minor or major update is a lot of times easier18:35:42
@hexa:lossy.networkhexa
In reply to @sandro:supersandro.de
right now we release two times a year a big release. Debian does once every few years.
roughly every 2 years
18:44:19
@hexa:lossy.networkhexaapplying the patches yourself implies you can't be an end-user 18:44:33
@sandro:supersandro.deSandro
In reply to @hexa:lossy.network
roughly every 2 years
yeah https://wiki.debian.org/DebianReleases#Production_Releases
18:49:19
@r_i_s:matrix.orgris_ hexa: if a need (and the funding/human-power) for LTS emerged, I'd rather they weren't cast out of the project into a fork, where they would need to set up their own infra, hydra, and cause those who find themselves at the end of a regular release's support to have to consciously switch channels etc. 19:16:34
@r_i_s:matrix.orgris_the worst it would mean for us is more noise in github19:16:53
@hexa:lossy.networkhexaagreed19:17:20
@hexa:lossy.networkhexa * agreed, I just said it could be done outside. Can't do that with debian that easily.19:17:32
@r_i_s:matrix.orgris_sure19:17:37
@hexa:lossy.networkhexaother than that: pay me!19:17:47
@hexa:lossy.networkhexa * other than that: pay me! 😛19:18:08
@r_i_s:matrix.orgris_one day19:18:14
@pennae:matrix.eno.spacepennaeis there an update to postgres 13.3 that we searching nixpkgs? https://security.archlinux.org/AVG-195621:54:29
@pennae:matrix.eno.spacepennae * is there an update to postgres 13.3 that we missed searching nixpkgs? https://security.archlinux.org/AVG-195621:55:15
5 Jun 2021
@hexa:lossy.networkhexa pennae: can you please ping marsam? 02:46:19
@hexa:lossy.networkhexaor … well02:47:17
@hexa:lossy.networkhexabrb02:47:18
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/12575102:57:52
@hexa:lossy.networkhexaI'll let marsam do the reviewing/backporting02:58:02
@hexa:lossy.networkhexathanks for pointing out the issue02:58:18
@pennae:matrix.eno.spacepennaethanks for updating :)02:58:33
@pennae:matrix.eno.spacepennaewould've thought the update bot would pick it up rather quickly02:58:56
@hexa:lossy.networkhexayou mean r-ryantm?03:02:22

Show newer messages


Back to Room ListRoom Version: 6