!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

716 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
25 Jan 2024
@felschr:matrix.orgfelschr * https://github.com/NixOS/nixpkgs/pull/283544 (all checks have passed now)01:47:11
@leona:leona.isleona https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/ again… 22:54:34
@yaya:uwu.isyayahttps://github.com/NixOS/nixpkgs/pull/28388823:54:49
26 Jan 2024
@hexa:lossy.networkhexahttps://github.com/rhboot/shim/commit/0226b56513b2b8bd5fd281bce77c40c9bf07c66d02:31:53
@hexa:lossy.networkhexa cc raitobezarius 02:32:17
@raitobezarius:matrix.orgraitobezarius cc @baloo Linux Hackerman: ^ 02:33:12
@hexa:lossy.networkhexaenobaloo02:33:20
@linus:schreibt.jetzt@linus:schreibt.jetztoh no I didn't want to know that shim has HTTP 🤦11:08:20
@linus:schreibt.jetzt@linus:schreibt.jetzt
In reply to @hexa:lossy.network
https://github.com/rhboot/shim/commit/0226b56513b2b8bd5fd281bce77c40c9bf07c66d
https://github.com/NixOS/nixpkgs/pull/283471
12:19:01
27 Jan 2024
@metanoic:matrix.org@metanoic:matrix.org joined the room.13:31:42
@dooy:matrix.org@dooy:matrix.org changed their display name from Dooygoy to stablejoy.13:37:43
28 Jan 2024
@ncfavier:matrix.orgnf changed their profile picture.14:04:04
@kudzu:envs.net@kudzu:envs.net joined the room.20:37:07
29 Jan 2024
@sandro:supersandro.deSandrohttps://github.com/NixOS/nixpkgs/pull/284771 I think https://github.com/paperless-ngx/paperless-ngx/issues/5502 applies only applies to custom configuration but it is an authentication bypass for a very sensitive system.13:42:19
@sandro:supersandro.deSandro

We are planning to release critical security patches for versions 3.5, 4.1, 4.2 and nightly this Thursday, Feb 01, at 15:00 UTC. We encourage server administrators to plan for a timely upgrade to ensure their Mastodon server is protected.

https://c3d2.social/@MastodonEngineering@mastodon.social/111839555900486563

13:52:17
@xfix:matrix.org@xfix:matrix.org left the room.14:52:41
@flandweber:envs.net@flandweber:envs.net joined the room.15:01:57
@jarrrkob:matrix.orgjarrrkob joined the room.15:18:04
@flandweber:envs.net@flandweber:envs.net changed their display name from flandweber to Finn Landweber.18:20:08
30 Jan 2024
@hugosenario:matrix.orgHugo Ribeiro joined the room.02:22:47
@hexa:lossy.networkhexa Markus Theil: openssl updates are live 14:24:45
@mtheil:scs.ems.host@mtheil:scs.ems.hostthx, PR follows soon.14:26:12
@mtheil:scs.ems.host@mtheil:scs.ems.hosthttps://github.com/NixOS/nixpkgs/pull/28501915:31:51
@mtheil:scs.ems.host@mtheil:scs.ems.hostAs the severity of the fixed issues is low, I'm waiting for a list of fixed things to appear on openssl.org15:32:33
@mtheil:scs.ems.host@mtheil:scs.ems.host * As the severity of the fixed issues is low, I'm waiting for a list of fixed things to appear on openssl.org to include it in the descriptions.15:32:45
@hexa:lossy.networkhexahttps://github.com/openssl/openssl/blob/openssl-3.2.1/CHANGES.md#changes-between-320-and-321-30-jan-2024 https://github.com/openssl/openssl/blob/openssl-3.0.13/CHANGES.md#changes-between-3012-and-3013-30-jan-202415:34:07
@hexa:lossy.networkhexause these.15:34:13
@mtheil:scs.ems.host@mtheil:scs.ems.hostthx15:36:10
@vcunat:matrix.orgvcunatOne of these might be a low-rebuild change, but I suppose there's no hurry to get the changes anyway?15:43:08
@ajs124:ajs124.deajs1243.2 should be low rebuild15:45:19

Show newer messages


Back to Room ListRoom Version: 6