| 30 Mar 2024 |
Minijackson | In reply to @r_i_s:matrix.org i'm struggling to reproduce this now, but I'm sure we've had at least one case in the past where fetchFromGitHub wasn't returning the vanilla repo source You light have encountered a case were git attributes were used, which can modify the generated git archive. An example that I have on hand: https://github.com/paulscherrerinstitute/StreamDevice/blob/master/.gitattributes | 08:21:08 |
ris_ | the seems feasible - didn't know about that. at least changes to gitattributes have to be checked in, which limits their stealth | 11:05:44 |
ris_ | * that seems feasible - didn't know about that. at least changes to gitattributes have to be checked in, which limits their stealth | 11:05:51 |
| RW joined the room. | 11:32:07 |
| @alina:kescher.at joined the room. | 11:38:43 |
| 31 Mar 2024 |
| peter253545 joined the room. | 02:43:55 |
stigo | https://github.com/NixOS/nixpkgs/pull/300461 | 11:26:12 |
| Clumsily6239 joined the room. | 15:14:56 |
| @5m5z3q888q5prxkg:chat.lightnovel-dungeon.de joined the room. | 17:04:54 |
| @dclmatrix:matrix.org joined the room. | 18:01:24 |
| @dclmatrix:matrix.org changed their display name from dclmatrix to exet. | 22:32:52 |
| 1 Apr 2024 |
| nevivurn joined the room. | 02:00:20 |
| tomf joined the room. | 03:01:00 |
| 2 Apr 2024 |
| @lotte:chir.rs changed their profile picture. | 06:56:52 |
| @lotte:chir.rs changed their profile picture. | 07:35:07 |
| @xayomer:kif.rocks joined the room. | 08:59:11 |
Jonas Chevalier | sorry if it's out of topic; I think Vulnix needs a new maintainer. Maybe somebody here would be interested: https://github.com/nix-community/vulnix/issues/95 | 10:40:54 |
tgerbet | NodeJS upgrades tomorrow https://nodejs.org/en/blog/vulnerability/april-2024-security-releases
We probably going to have some issues with Node 18 as the last upgrade was reverted due to some breakages (https://github.com/NixOS/nixpkgs/pull/299809) | 16:16:33 |
| 3 Apr 2024 |
| may joined the room. | 12:28:43 |
hexa | Redacted or Malformed Event | 15:21:23 |
| @dclmatrix:matrix.org changed their display name from exet to blu3. | 16:01:25 |
| @dclmatrix:matrix.org set a profile picture. | 16:44:09 |
| 4 Apr 2024 |
ネコ | In reply to @zimbatm:numtide.com sorry if it's out of topic; I think Vulnix needs a new maintainer. Maybe somebody here would be interested: https://github.com/nix-community/vulnix/issues/95 i've been considering it, since i have a bit of experience with data processing and cross-database mapping, but the problem is i don't really know python | 00:59:07 |
ネコ | i could learn it without too much trouble, but i don't think being the sole maintainer of a piece of wildly used security software is a good first python project | 01:01:23 |
Jonas Chevalier | In reply to @binarycat:snug.moe i could learn it without too much trouble, but i don't think being the sole maintainer of a piece of wildly used security software is a good first python project One thing you can do is rebase https://github.com/nix-community/vulnix/pull/89 and test it. Having someone look at PRs and make sure they work as intended is already very valuable, even if you don't know how to write python. | 07:36:17 |
| Fabian Affolter changed their display name from Fabian Affolter to fabaff. | 08:40:38 |
raitobezarius | In reply to @binarycat:snug.moe i've been considering it, since i have a bit of experience with data processing and cross-database mapping, but the problem is i don't really know python Alternatively, https://github.com/Nix-Security-WG/nix-security-tracker is also looking for more hands, and I can be around for the maintenance and guidance | 10:43:17 |
| Alison Jenkins joined the room. | 14:21:18 |
Alison Jenkins | Hey everyone, while updating my MacOS system from my nix flake I had Bitdefender for Mac flag a file called test.exe in the Zig 0.11 derivation as a virus. Could well be a false positive but thought I should report it just in case someone is trying to pull an XZ on the Zig project: 4 Apr 2024 at 15:16 Gen:Variant.Lazy.502457 deleted /private/tmp/nix-build-zig-0.11.0.drv-0/source/zig-cache/o/42a1c6e5938d8a1afeef6a9fba4fb62f/test.exe | 14:23:28 |
K900 | I'm pretty sure that's a compiler artifact | 14:24:03 |