| 6 Dec 2024 |
| Ahurac joined the room. | 12:30:28 |
Scrumplex | high Python vulnerability 👀
https://www.cve.org/CVERecord?id=CVE-2024-12254
https://github.com/python/cpython/pull/127656 | 17:41:18 |
Scrumplex | Relevant patch for 3.12: https://github.com/python/cpython/commit/9aa0deb2eef2655a1029ba228527b152353135b5 | 17:42:26 |
hexa | meh | 17:42:35 |
Scrumplex | yeah not sure why this is over 8 | 17:42:43 |
@magic_rb:matrix.redalder.org | (i was expecting worse) | 17:42:45 |
Scrumplex | * yeah not sure why this has a score over 8 | 17:42:55 |
@magic_rb:matrix.redalder.org | * (i was expecting worse, great SNR) | 17:43:04 |
hexa | bdraco++ | 17:43:15 |
hexa | https://github.com/NixOS/nixpkgs/pull/362523 | 18:13:05 |
dotlambda | https://github.com/Kludex/python-multipart/security/advisories/GHSA-59g5-xgcq-4qw3 fixed in https://github.com/NixOS/nixpkgs/pull/362558 | 20:53:24 |
| 8 Dec 2024 |
| shawn8901 set a profile picture. | 19:21:34 |
| 9 Dec 2024 |
Tomodachi94 (they/them) | https://matrix.to/#/#dev:nixos.org/$1QE9j5UPzFb-qL02MAvSbSzX-0UspFEc5FBEtqH8y8s | 23:33:10 |
Tomodachi94 (they/them) | This Matomo update has a "high impact security fix" that came out more than two months ago: > https://github.com/NixOS/nixpkgs/pull/363621
| 23:33:27 |
Tomodachi94 (they/them) | This Matomo update has a "high impact security fix" that came out more than two months ago: https://github.com/NixOS/nixpkgs/pull/363621
| 23:33:32 |
Tomodachi94 (they/them) | (oh, nevermind, already merged) | 23:33:53 |
| 10 Dec 2024 |
| Niklas Korz joined the room. | 19:28:21 |
Niklas Korz | backport to 24.05 is still open: https://github.com/NixOS/nixpkgs/pull/363869 | 19:29:14 |
hexa | Niklas Korz: I browsed the matomo changelog and commit log a bit, but I didn't find anything on whether matomo 4.x is affected | 21:07:54 |
hexa | and since matomo defaults to 4.16.1 on nixos-24.05 we must know or else | 21:12:12 |
hexa | ugh, same for nixos-24.11? 🫠| 21:12:43 |
hexa | 5.0 was released in 2023-12 — WHYYYYY | 21:13:44 |