!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

725 Members
Coordination and triage of security issues in nixpkgs222 Servers

Load older messages


SenderMessageTime
16 Jan 2024
@adam:robins.wtf@adam:robins.wtfrunning the virtual-machine test should be sufficient23:08:05
@raitobezarius:matrix.orgraitobezarius
In reply to @tgerbet:matrix.org
Yep update is not yet available but there is a patch for 7 out of 9 issues in edk2 bugtracker, I will take a look in a moment.

Can you put me in the loop or ping me if you need my actions? I am not sure if I want to patch too early EDK2 shit because their QA is outright bad in general
23:21:46
@tgerbet:matrix.orgtgerbetI just requested a review from you šŸ‘ https://github.com/NixOS/nixpkgs/pull/281405 23:26:39
@mtxyz:the-apothecary.clubBailey (she/they) joined the room.23:36:16
@jowj:awful.club@jowj:awful.club left the room.23:53:11
@rvdp:infosec.exchangeRamses šŸ‡µšŸ‡ø joined the room.23:55:41
17 Jan 2024
@george:matrix.geonat.nzOahzEgroeg changed their display name from George to george.02:18:56
@george:matrix.geonat.nzOahzEgroeg changed their display name from george to George.02:28:32
@george:matrix.geonat.nzOahzEgroeg set a profile picture.02:28:45
@delta231:matrix.orgSwastik Baranwal set a profile picture.21:23:53
18 Jan 2024
@syntheit:matrix.org@syntheit:matrix.org left the room.04:14:23
19 Jan 2024
@ThorHop:matrix.org@ThorHop:matrix.org changed their display name from hopland (meticulous montesquieu) to hopland (manners or stfu).05:11:41
@ThorHop:matrix.org@ThorHop:matrix.org changed their display name from hopland (manners or stfu) to hopland.05:14:27
@room303:matrix.orgRoom303 joined the room.07:05:53
20 Jan 2024
@nikke89:matrix.orgNikke joined the room.21:32:42
@hexa:lossy.networkhexahttps://github.com/python-pillow/Pillow/releases/tag/10.2.023:49:32
@akechishiro:matrix.orgAkechiShirohttps://github.com/NixOS/nixpkgs/pull/28239323:50:25
22 Jan 2024
@ThorHop:matrix.org@ThorHop:matrix.org changed their display name from hopland to IdeallyYes.15:07:12
@behelit:hackliberty.orgbehelit joined the room.19:44:50
23 Jan 2024
@2xsaiko:tchncs.de@2xsaiko:tchncs.de changed their display name from 2xsaiko to Marco.17:54:56
@2xsaiko:tchncs.de@2xsaiko:tchncs.de changed their display name from Marco to 2xsaiko.18:17:35
@mtheil:scs.ems.host@mtheil:scs.ems.hostOpenSSL will release new versions on 2024-01-30.19:34:25
@mtheil:scs.ems.host@mtheil:scs.ems.hostI think there are no news on the website until now. I subscribed to some public OpenSSL mailing lists.19:51:59
@mtheil:scs.ems.host@mtheil:scs.ems.host* I think there are no news on the website until now. I’m subscribed to some public OpenSSL mailing lists.19:52:15
@felschr:matrix.orgfelschrhttps://github.com/NixOS/nixpkgs/pull/28328922:07:51
24 Jan 2024
@vcunat:matrix.orgvcunat
In reply to @mtheil:scs.ems.host
OpenSSL will release new versions on 2024-01-30.
That's just for those low-severity issues announced previously?
09:55:48
@mtheil:scs.ems.host@mtheil:scs.ems.host

Probably. The mail was just:

The OpenSSL project team would like to announce the upcoming release of
OpenSSL versions 3.2.1, 3.1.5 and 3.0.13.

We will be also releasing extended support OpenSSL versions 1.0.2zj and
1.1.1x which will be available to premium support customers.

These releases will be made available on Tuesday 30th January 2024
between 1300-1700 UTC.

These are security-fix releases. The highest severity issue fixed in
each of these releases is Low:

https://www.openssl.org/policies/secpolicy.html

Yours
The OpenSSL Project Team
10:03:15
@vcunat:matrix.orgvcunatOK. OpenSSL marking all "Low" implies that it won't be urgent, I think.10:06:37
@mtheil:scs.ems.host@mtheil:scs.ems.hostI'll open a PR timely after release, but it probably is not urgent.10:10:59
@akechishiro:matrix.orgAkechiShiroHi, should security fixes be backported usually on the stable release ? Asking for https://github.com/NixOS/nixpkgs/pull/283179 related to https://nitter.net/_msw_/status/1749999077100855638#m12:35:54

Show newer messages


Back to Room ListRoom Version: 6