!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

716 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
4 Apr 2024
@fabaff:matrix.orgFabian Affolter changed their display name from Fabian Affolter to fabaff.08:40:38
@raitobezarius:matrix.orgraitobezarius
In reply to @binarycat:snug.moe
i've been considering it, since i have a bit of experience with data processing and cross-database mapping, but the problem is i don't really know python
Alternatively, https://github.com/Nix-Security-WG/nix-security-tracker is also looking for more hands, and I can be around for the maintenance and guidance
10:43:17
@alisonjenkins:matrix.orgAlison Jenkins joined the room.14:21:18
@alisonjenkins:matrix.orgAlison Jenkins Hey everyone, while updating my MacOS system from my nix flake I had Bitdefender for Mac flag a file called test.exe in the Zig 0.11 derivation as a virus. Could well be a false positive but thought I should report it just in case someone is trying to pull an XZ on the Zig project: 4 Apr 2024 at 15:16 Gen:Variant.Lazy.502457 deleted /private/tmp/nix-build-zig-0.11.0.drv-0/source/zig-cache/o/42a1c6e5938d8a1afeef6a9fba4fb62f/test.exe 14:23:28
@k900:0upti.meK900I'm pretty sure that's a compiler artifact14:24:03
@raitobezarius:matrix.orgraitobezarius Alison Jenkins: can you go to the zig project directly and report this? zig developers uses Nix 16:13:16
@raitobezarius:matrix.orgraitobezariusso they can chime in directly and pinpoint the potential problem16:13:22
@raitobezarius:matrix.orgraitobezariushttps://framapiaf.org/@peertube/11221326581604627617:27:40
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/pull/30160417:57:02
@falaichte:techsaviours.org@falaichte:techsaviours.org joined the room.19:55:04
6 Apr 2024
@mop4987:matrix.org@mop4987:matrix.org left the room.21:03:22
@tpw_rules:matrix.org@tpw_rules:matrix.org left the room.21:21:12
@a-n-n-a-l-e-e:matrix.org@a-n-n-a-l-e-e:matrix.orghello -- i deleted my github account today due to being angry at some dumpster fire of a PR i got involved with. anyway, some of my other work is now being questioned about me being part of the xz conspiracy https://github.com/NixOS/nixpkgs/pull/301252 i recognize the suspicion but that was just due to the work of cleaning up segfaults and libc++abi / libc++ stuff from LLVM. 22:55:54
@a-n-n-a-l-e-e:matrix.org@a-n-n-a-l-e-e:matrix.organd cleaning up old LLVMs.22:56:56
@a-n-n-a-l-e-e:matrix.org@a-n-n-a-l-e-e:matrix.orgi wish i could get that time back...22:57:42
@r_i_s:matrix.orgris_oh dear 😆23:12:39
@a-n-n-a-l-e-e:matrix.org@a-n-n-a-l-e-e:matrix.orgi knew getting involved in the PR was a mistake last week but i did it anyway.23:13:47
@a-n-n-a-l-e-e:matrix.org@a-n-n-a-l-e-e:matrix.org * i knew getting involved in the PR was a mistake last week but i did it anyway. (https://github.com/NixOS/nixpkgs/pull/294347)23:15:22
@r_i_s:matrix.orgris_ the RFC process to get meta.sourceProvenance took me a year, and then when I tried to implement it, someone popped up and tried to make me redesign it 23:16:39
@r_i_s:matrix.orgris_so i sympathize, it's stressful23:19:09
@hexa:lossy.networkhexaHey, I'm sorry that it had to come to this. If you had encountered problems earlier I would hope moderation could've helped23:20:02
@raitobezarius:matrix.orgraitobezariusI'm sorry for that, thank you for all your contributions.23:31:54
@janik0:matrix.org@janik0:matrix.org
In reply to @a-n-n-a-l-e-e:matrix.org
hello -- i deleted my github account today due to being angry at some dumpster fire of a PR i got involved with. anyway, some of my other work is now being questioned about me being part of the xz conspiracy https://github.com/NixOS/nixpkgs/pull/301252 i recognize the suspicion but that was just due to the work of cleaning up segfaults and libc++abi / libc++ stuff from LLVM.
sad to see you go, takae your time and enjoy life.
23:38:29
7 Apr 2024
@niko:conduit.rsnyanbinary
In reply to @a-n-n-a-l-e-e:matrix.org
i knew getting involved in the PR was a mistake last week but i did it anyway. (https://github.com/NixOS/nixpkgs/pull/294347)
Oh what exactly was the tipping point? :<
02:24:23
@binarycat:snug.moeネコoh, i was wondering what happened...02:35:33
@fl1tzi:matrix.fl1tzi.com@fl1tzi:matrix.fl1tzi.com left the room.12:29:14
@a-n-n-a-l-e-e:matrix.org@a-n-n-a-l-e-e:matrix.orgthanks. though the member who was making backhanded comments about my incompetence and lack of professionalism is a member of the moderation team, to my understanding. 14:59:05
@hexa:lossy.networkhexacan you point out details in a DM?15:00:13
8 Apr 2024
@levigross:matrix.orgLevi changed their display name from levigross to Levi.03:38:37
@mtheil:scs.ems.host@mtheil:scs.ems.host

botan2 and botan3 had bug fix releases roughly a month ago. I made a combined PR some weeks ago, but was not able to debug the failing build of monotone with botan2 on MacOS myself. So I split this PR into a another one for botan2.

  • botan3: https://github.com/NixOS/nixpkgs/pull/298669
  • botan2: https://github.com/NixOS/nixpkgs/pull/302530

Is someone willing to step in for debugging the failing botan2 build on MacOS or can provide me some debugging hints for debugging from a Linux-based system with ofborg in the CI?

09:51:18

Show newer messages


Back to Room ListRoom Version: 6