| 28 Nov 2023 |
hexa | only worried about release-23.05 here | 12:08:17 |
hexa | https://github.com/go-gitea/gitea/releases/tag/v1.20.6
master and release-23.11 on 1.20.5, release-23.05 on 1.19.4 | 12:27:27 |
hexa | ma27: for gitea | 12:28:56 |
ma27 | will try to take a look today | 13:21:00 |
emily | In reply to @hexa:lossy.network only worried about release-23.05 here All versions back to gogs are affected (depending on the endpoint)
source: https://matrix.to/#/!qjPHwFPdxhpLkXMkyP:matrix.org/$ONM9CMUFMAnJjhtvbaStCoYoWS2lkazKxgfsDjwQzg4?via=matrix.org&via=tchncs.de | 18:04:55 |
| 29 Nov 2023 |
Julien | https://jellyfin.org/posts/jellyfin-security-and-you/ | 13:11:29 |
Julien | Is anyone doing that bump ? Otherwise I can | 13:11:49 |
Julien | https://github.com/NixOS/nixpkgs/pull/270945 | 14:09:22 |
| 30 Nov 2023 |
| mbssrc joined the room. | 12:04:35 |
| 1 Dec 2023 |
| cafkafk joined the room. | 05:31:13 |
| @lotte:chir.rs changed their profile picture. | 09:39:03 |
| cafkafk changed their profile picture. | 10:51:31 |
| moritz.hedtke set their display name to Moritz Hedtke. | 11:08:12 |
| 2 Dec 2023 |
| @mop4987:matrix.org joined the room. | 21:14:44 |
| 3 Dec 2023 |
| @er10:matrix.org joined the room. | 00:05:00 |
| @ThorHop:matrix.org changed their display name from hopland (valorent vicky) to hopland (meticulous montesquieu). | 14:08:43 |
| * ris_ returns to the idea of having something like a meta.knownVendoredIn attribute that lists packages we know vendor copies of this package, to make our lives easier when patching vulnerabilities | 15:07:36 |
| @cf11:0x2c.org joined the room. | 15:10:32 |
ris_ | (wrong channel) | 15:15:51 |
| eryngion joined the room. | 21:24:21 |
eryngion | FYI: I see a bunch of relatively fresh CVE patches in https://github.com/meta-qt5/meta-qt5/tree/master/recipes-qt/qt5/qtbase that we don't have. | 21:42:23 |
K900 | We should have those | 21:43:02 |
K900 | Because we are tracking KDE's patchset and not upstream Qt | 21:43:09 |
K900 | So you need to be looking at https://invent.kde.org/qt/qt/qtbase/-/commits/kde/5.15/ | 21:43:27 |
K900 | As far as I can tell all the patches OE has we also have | 21:48:21 |
K900 | At least the ones marked as CVE | 21:48:59 |
eryngion | Yeah, somebody may have forgotten to refresh his local qtbase repo in moths and should go sleep :) | 21:52:30 |
| 5 Dec 2023 |
| @federicodschonborn:matrix.org changed their profile picture. | 00:38:37 |
hexa | https://webkitgtk.org/security/WSA-2023-0011.html Jan Tojnar et al 🙂 | 21:30:38 |
hexa | https://www.openwall.com/lists/oss-security/2023/12/05/2 Mic92 qbit | 21:44:19 |