!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

700 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
7 Jan 2025
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] - Back 2025-01-06 to tlaurion aka Insurgo [UTC-4].16:14:40
@sigmasquadron:matrix.orgSigmaSquadron changed their display name from SigmaSquadron to SigmaSquadron (Away until 2024-01-12).19:35:24
10 Jan 2025
@tomog:matrix.orgtomf left the room.05:03:59
@sigmasquadron:matrix.orgSigmaSquadron changed their display name from SigmaSquadron (Away until 2024-01-12) to SigmaSquadron (Away until 2024-01-11).22:15:42
@sigmasquadron:matrix.orgSigmaSquadron changed their display name from SigmaSquadron (Away until 2024-01-11) to SigmaSquadron (Away until 2025-01-11).22:43:13
11 Jan 2025
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.04:42:40
@sigmasquadron:matrix.orgSigmaSquadron changed their display name from SigmaSquadron (Away until 2025-01-11) to SigmaSquadron.15:06:34
@hexa:lossy.networkhexahttps://github.com/vim/vim/security/advisories/GHSA-5rgf-26wj-48v816:21:59
@hexa:lossy.networkhexa * https://github.com/vim/vim/security/advisories/GHSA-5rgf-26wj-48v8 vim Philip Taron (UTC-8) 16:24:52
@philiptaron:matrix.orgPhilip Taron (UTC-8)On it16:28:08
@philiptaron:matrix.orgPhilip Taron (UTC-8)Will still be a staging PR due to number of rebuilds (all vim plugins)16:29:19
@philiptaron:matrix.orgPhilip Taron (UTC-8)* Will still be a staging PR due to number of rebuilds (all vim plugins) also because IMO these vulns for code editing are only so bad16:29:49
@hexa:lossy.networkhexathe commit looks fairly straightforward to backport into staging-24.1116:30:34
@hexa:lossy.networkhexa * the commit looks fairly straightforward to backport into staging-24.11 16:30:43
@philiptaron:matrix.orgPhilip Taron (UTC-8)I have no problem with backporting the whole editor (patch versions fit into the release branch backports straightforwardly)16:31:19
@philiptaron:matrix.orgPhilip Taron (UTC-8)* I have no problem with backporting the whole editor to staging-24.11 (patch versions fit into the release branch backports straightforwardly)16:31:31
@hexa:lossy.networkhexaif you can ensure there are no breaking changes in there 🙂 16:31:52
@philiptaron:matrix.orgPhilip Taron (UTC-8)I'll look through the commits.16:37:02
@philiptaron:matrix.orgPhilip Taron (UTC-8)https://github.com/NixOS/nixpkgs/pull/37298016:42:56
@oak:universumi.fioak 🏳️‍🌈♥️ changed their profile picture.16:45:21
@oak:universumi.fioak 🏳️‍🌈♥️ removed their profile picture.16:46:24
@oak:universumi.fioak 🏳️‍🌈♥️ set a profile picture.16:46:55
@philiptaron:matrix.orgPhilip Taron (UTC-8)https://github.com/NixOS/nixpkgs/pull/372981 (still reading through the commits)16:51:09
@hexa:lossy.networkhexathat is not a valid backport16:51:51
@hexa:lossy.networkhexa* that is not a valid backport that fits contributing.md16:51:57
@philiptaron:matrix.orgPhilip Taron (UTC-8)tell me more16:52:11
@hexa:lossy.networkhexabackports need to be cherry-picks from master if possible16:52:40
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#manually-backporting-changes16:53:23
@hexa:lossy.networkhexa* backports need to be cherry-picks from master if applicable16:54:04
@philiptaron:matrix.orgPhilip Taron (UTC-8)I'm happy to do whatever. I'll note that none of that mentions staging. The last PRs I've made against release branches have all been in this form, since they had to go to staging, and cherry-picking/rebasing was the order of the day.16:54:46

Show newer messages


Back to Room ListRoom Version: 6