!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

694 Members
Coordination and triage of security issues in nixpkgs213 Servers

Load older messages


SenderMessageTime
11 Jun 2024
@wxnzemof:matrix.orgwxnzemofHi, this is probably benign but maybe worth looking into: https://github.com/nix-community/nix-installers/issues/4909:54:13
@sandro:supersandro.deSandroThis is what the GitHub Action does https://github.com/nix-community/nix-installers/blob/master/.github/workflows/gh-pages.yml11:40:17
@aynish:sealight.xyz@aynish:sealight.xyz left the room.14:56:41
@networkexception:chat.upi.li@networkexception:chat.upi.li changed their display name from networkException to networkException (moving to @networkexception:nwex.de).18:34:30
@sasha:the-apothecary.clubSashanoraa.gay (she/her, ze/zir) changed their display name from Sashanoraa.gay (ze/zir) to Sashanoraa.gay (ze/zir, she/her).21:46:14
12 Jun 2024
@hexa:lossy.networkhexahttps://conduit.rs/changelog/#v0-8-0-2024-06-12 (and conduwuit/grapevine for whoever uses those)19:09:11
@networkexception:nwex.denetworkException joined the room.19:28:47
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/31936219:57:39
@hexa:lossy.networkhexawill backport to release-24.05, given that the breaking changes in 0.7.0 don't affect us19:57:52
@hexa:lossy.networkhexa * will backport to release-24.05 and release-23.11, given that the breaking changes in 0.7.0 don't affect us 19:58:11
@hexa:lossy.networkhexamarked as vulnerable on 23.11, backport was not possible20:57:43
13 Jun 2024
@george:matrix.geonat.nzOahzEgroeg changed their display name from George to OahzEgroeg.10:49:08
14 Jun 2024
@george:matrix.geonat.nzOahzEgroeg left the room.09:43:26
@george:matrix.geonat.nzOahzEgroeg joined the room.09:47:22
@bernhard:o-g.atcnm joined the room.18:16:58
15 Jun 2024
@felschr:matrix.orgfelschrhttps://github.com/NixOS/nixpkgs/pull/31931511:13:57
@bedridden:matrix.orgbedridden joined the room.21:27:14
@bedridden:matrix.orgbedriddenhttps://github.com/NixOS/nixpkgs/pull/320093 current bootstrap tools for darwin seem to ship with an old version of curl (and was updated 2 months ago), affected by https://www.tenable.com/plugins/nessus/182874 I suppose this change should first go into staging and then backported to other staging-<version> branches... is this correct? (first contribution, so apologies if I am at the wrong place!)21:34:17
@hexa:lossy.networkhexa can you poke #macos:nixos.org? 21:35:09
@fack:cyberia.club@fack:cyberia.club left the room.21:51:56
16 Jun 2024
@vcunat:matrix.orgvcunat Isn't that affecting only if you use the libcurl as a SOCKS5 proxy? (server side) Or am I reading it wrong? 06:10:00
@bedridden:matrix.orgbedriddenI believe so, but I am no security expert. https://www.tenable.com/cve/CVE-2023-38545 has a references to few different updates (even ones from Apple updating curl version), so it seems rather important.09:58:11
@bedridden:matrix.orgbedridden That said, I was told in #macos:nixos.org that this issue doesn't affect nixos-24.05 (which I also verified and seems to be the case), so it might be an issue only on nixos-23.11 darwin (haven't yet verified this one). 09:59:28
@ilex:oakforest.inilexhttps://codeberg.org/forgejo/forgejo/src/branch/forgejo/RELEASE-NOTES.md#7-0-413:07:30
@hexa:lossy.networkhexa

@emily

13:26:27
@me:indeednotjames.comemily?13:26:53
@hexa:lossy.networkhexaForgejo13:27:52
@me:indeednotjames.comemily

already in nixos-unstable-small and nixos-24.05-small. so what is left to do besides marking forgejo as insecure in 23.11?

(though it can be argued over if that CVE is actually all that bad)

13:29:50
@adam:robins.wtf@adam:robins.wtfthey did cut a 1.21 release too, but marking as insecure in 23.11 is fine with me :)13:33:10
@me:indeednotjames.comemily

23.11 is on 1.20, not 1.21.

and in the old gitea versioning those are major releases.

13:35:11

Show newer messages


Back to Room ListRoom Version: 6