!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

687 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
5 Jun 2021
@hexa:lossy.networkhexa * ris_: huh, is 2.9.10 -> 2.9.11/12 such a big jump? 12:04:18
@hexa:lossy.networkhexathere are already patches in there, I don't mind the patching, just wondering if they don't do semver?12:04:50
@r_i_s:matrix.orgris_well, it introduced the annoying lxml breakage12:05:01
@hexa:lossy.networkhexaah, yeah. libxml2.12:05:14
@hexa:lossy.networkhexaI remember 🔥12:05:26
@hexa:lossy.networkhexaI wouldn't be surprised if a handful of things land on staging-20.09 before the months end12:06:32
@r_i_s:matrix.orgris_ok i'll retarget it12:09:25
@r_i_s:matrix.orgris_i generally tend to think of semver as "an aspiration"12:11:04
@r_i_s:matrix.orgris_different projects succeed in following it to different degrees12:12:07
@r_i_s:matrix.orgris_and of course there's no hard definition of what's breaking and what's not so it's hard12:12:26
@hexa:lossy.networkhexaonce merged staging-20.09 will start an eval on hydra15:06:29
@hexa:lossy.networkhexaso let's maybe give it one or two days, idk15:06:38
@hexa:lossy.networkhexathe situation isn't ideal15:06:43
@hexa:lossy.networkhexaThe 20.09 release has received roughtly 260 security related backports until today16:57:39
@hexa:lossy.networkhexa * The 20.09 release has received roughtly 260 security related backports until today 💪17:05:19
@kraftnix:matrix.orgkraftnix joined the room.22:15:09
6 Jun 2021
@henson:matrix.orgHenson joined the room.01:55:09
@r_i_s:matrix.orgris_wanna make it 261? https://github.com/NixOS/nixpkgs/pull/12523310:55:44
@r_i_s:matrix.orgris_or even 262? https://github.com/NixOS/nixpkgs/pull/12508810:56:17
@hexa:lossy.networkhexaInterested, but only at home later tonight12:36:00
7 Jun 2021
@henson:matrix.orgHensonI've got a question about the postgresql_11 package. A couple weeks ago there was a security update announcement in the Debian security mailing list recommending to upgrade from 11.11 to 11.12 due to several bug fixes. I notice that NixOS's postgres_11 package is still at 11.11 in 20.09 and 21.05. Is there a reason this hasn't been bumped to 11.12 yet?12:34:14
@henson:matrix.orgHensonthis is coming from the perspective of somebody who doesn't know much about the NixOS security team and is interested in understanding things better.12:38:47
@ldesgoui:matrix.orgldesgoui joined the room.12:39:00
@hexa:lossy.networkhexaFixed in https://github.com/NixOS/nixpkgs/pull/125751, needs to go through the channels I'd imagine13:29:17
@hexa:lossy.networkhexahttps://nixpk.gs/pr-tracker.html?pr=12575113:29:36
@sandro:supersandro.deSandroYeah, mass rebuild13:30:16
@sandro:supersandro.deSandroIs 11 the default version? If not we can maybe cherry pick it13:30:34
@henson:matrix.orgHenson hexa: thanks for pointing that out, I looked in the issues for it but didn't look in the PRs. 13:54:30
@henson:matrix.orgHenson Sandro: so if postgres_11 gets bumped from 11.11 to 11.12, then all packages that have postgres_11 in their closure have to get rebuilt, right? 13:57:48
@henson:matrix.orgHensonand postgres_11 = postgres is the default postgres for NixOS13:58:43

Show newer messages


Back to Room ListRoom Version: 6