!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

673 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22206 Servers

Load older messages


SenderMessageTime
14 Mar 2026
@amadaluzia:unredacted.orgamadaluzia -> 4d2.org changed their display name from amadaluzia[uorg] to amadaluzia -> 4d2.org.21:23:01
16 Mar 2026
@azban:matrix.orgazban joined the room.01:15:52
@azban:matrix.orgazban left the room.01:18:58
@azban:matrix.orgazban joined the room.01:19:05
@azban:matrix.orgazban left the room.01:19:25
@azban:matrix.orgazban joined the room.01:37:27
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q1/317 gstreamer03:20:03
17 Mar 2026
@sigmasquadron:matrix.orgFernando Rodrigueshttps://github.com/NixOS/nixpkgs/pull/500711 Xen12:14:58
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q1/33121:09:09
@hexa:lossy.networkhexa* https://seclists.org/oss-sec/2026/q1/331 expat21:09:21
18 Mar 2026
@markus.theil:factory.secunet.comMarkus TheilBotan had a new release these days. I don't really know if any packages use TLS from Botan or just crypto operations like hashing, encryption/decryption. The security relevant changes touch OCSP handling and parallel signatures with e.g. ML-DSA. https://botan.randombit.net/news.html#version-3-11-0-2026-03-15 https://github.com/NixOS/nixpkgs/pull/50038408:13:02
@markus.theil:factory.secunet.comMarkus TheilOpenSSL also will release new version in the following weeks: https://openssl-library.org/news/secadv/20260313.txt (sry, if this was already posted here.)08:15:35
@markus.theil:factory.secunet.comMarkus Theil* OpenSSL also will release new versions in the following weeks: https://openssl-library.org/news/secadv/20260313.txt (sry, if this was already posted here.)08:15:43
@eouzoe:matrix.org曜日 joined the room.20:32:49
19 Mar 2026
@uep:matrix.orguephttps://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b09:54:37
@uep:matrix.orguepCVSS 1009:54:59
@tom:dragar.deTomhttps://github.com/NixOS/nixpkgs/pull/50118110:05:08
@hexa:lossy.networkhexahttps://github.com/wolfSSL/wolfssl/releases/tag/v5.9.0-stable12:55:16
@technicus:matrix.orgMiles Dyson set a profile picture.18:06:11
20 Mar 2026
@evrim:matrix.cloud.core.gen.trEvrim Ulu joined the room.02:42:18
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/50104211:37:01
@niklaskorz:matrix.orgniklaskorzhttps://github.com/NixOS/nixpkgs/pull/50160611:57:19
@emilazy:matrix.orgemilyuh, going by that blog post maybe we should just be slapping knownVulnerabilities on this thing or removing it...12:03:08
@emilazy:matrix.orgemily I guess if there's no known compromise in the previous version... 12:04:25
@blitz:chat.x86.lolblitzat least the knownVulnerabilites would be good to warn people that this thing is f***ed16:04:34
@blitz:chat.x86.lolblitz * 16:04:39
@eouzoe:matrix.org曜日@delroth:delroth.net — Greetings, do forgive the intrusion. There is a line from your security wishlist that has stayed with me — that Hydra attestation was dependent on other projects to actually be useful. One of those projects may now exist. The first is already built. https://github.com/eouzoe/Apeiron Apeiron is a deterministic execution fabric — builds run inside Firecracker microVMs, defined by Nix-hermetic closures. The build environment is sealed. Every output is a cryptographic consequence of its inputs, and nothing else. The question of whether the environment itself was clean is a different problem. That is what comes next. An observer at the kernel layer — eBPF LSM inside the boundary, watching at syscall level as execution happens. Signing takes place outside the hypervisor. A compromised guest cannot revise what the kernel recorded. The design is complete. What remains is building it. If any of this is of interest, I would welcome a conversation. 17:36:44
@eouzoe:matrix.org曜日 set a profile picture.17:37:26
@vcunat:matrix.orgvcunatexpat: https://github.com/NixOS/nixpkgs/pull/50168517:41:39
@raitobezarius:matrix.orgraitobezariusyou should DM delroth directly, he's not involved in the NixOS project anymore17:43:02

Show newer messages


Back to Room ListRoom Version: 6