!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

686 Members
Coordination and triage of security issues in nixpkgs215 Servers

Load older messages


SenderMessageTime
9 Oct 2024
@scrumplex:duckhub.ioScrumplexhttps://github.com/NixOS/nixpkgs/pull/34759420:45:01
@scrumplex:duckhub.ioScrumplexI couldn't quite determine if https://codeberg.org/librewolf/source/releases/tag/131.0.2-1 actually fixes the issue? The diff to the previous tag doesn't seem to change much?20:49:12
@scrumplex:duckhub.ioScrumplexLatest Floorp release is from 30. September 2024, so I guess there is no patched version https://floorp.app/en/download?platform=linux20:51:20
@hexa:lossy.networkhexa131.0.2 is the correct base version20:54:36
@scrumplex:duckhub.ioScrumplexOh I just realized that LibreWolf is obviously following Mozilla's versioning ^^20:55:12
@hexa:lossy.networkhexa dotlambda: ^ 20:55:13
@scrumplex:duckhub.ioScrumplexlibrewolf-bin needs a bump too, but there is no AppImage release yet: https://gitlab.com/librewolf-community/browser/appimage/-/releases20:57:56
@emilazy:matrix.orgemily
In reply to @scrumplex:duckhub.io
Latest Floorp release is from 30. September 2024, so I guess there is no patched version

https://floorp.app/en/download?platform=linux
time for knownVulnerabilities
20:58:26
@emilazy:matrix.orgemilyunless they act soon20:58:34
@emilazy:matrix.orgemilynot going to join their Discord, but from GitHub I don't see any sign they're even aware of the vulnerability20:59:05
@emilazy:matrix.orgemily uh, thought this was #security-discuss:nixos.org though 20:59:15
@emilazy:matrix.orgemily Scrumplex: (maybe join ^?) 21:03:26
@scrumplex:duckhub.ioScrumplexin the process of joining21:03:34
@ereslibre:ereslibre.social@ereslibre:ereslibre.social joined the room.23:21:58
@ereslibre:ereslibre.social@ereslibre:ereslibre.social left the room.23:24:07
@schuelermine:matrix.orgschuelermine changed their profile picture.23:46:36
10 Oct 2024
@cf11:0x2c.org@cf11:0x2c.org left the room.05:03:56
@magic_rb:matrix.redalder.org@magic_rb:matrix.redalder.org
In reply to @scrumplex:duckhub.io
librewolf-bin needs a bump too, but there is no AppImage release yet: https://gitlab.com/librewolf-community/browser/appimage/-/releases
App images are out, currently not at a computer and wont be for a while
08:03:23
@emilazy:matrix.orgemily it's knownVulnerabilities already, so no rush. 08:03:46
@magic_rb:matrix.redalder.org@magic_rb:matrix.redalder.org

Fixing > knownVulnerabilities imho, so not a critical rush, but still would be nice to get it in asap

08:04:40
@scrumplex:duckhub.ioScrumplexI can create a PR right away ^^08:04:57
@scrumplex:duckhub.ioScrumplex
In reply to @scrumplex:duckhub.io
I can create a PR right away ^^
https://github.com/NixOS/nixpkgs/pull/347690
08:12:56
@scrumplex:duckhub.ioScrumplexAlso, I have built the new Floorp version here: https://github.com/NixOS/nixpkgs/pull/347677 Should be ready to merge08:13:30
14 Oct 2024
@scrumplex:duckhub.ioScrumplexhttps://github.com/NixOS/nixpkgs/pull/34734219:50:04
15 Oct 2024
@pyrox:pyrox.devdish [Fox/It/She] joined the room.07:35:53
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/34877912:14:33
16 Oct 2024
@eisfunke:eisfunke.com@eisfunke:eisfunke.com left the room.13:35:57
17 Oct 2024
@joerg:thalheim.ioMic92 changed their display name from Mic92 to Mic3000.06:51:17
@joerg:thalheim.ioMic92 changed their display name from Mic3000 to Mic3000 🌋.06:51:46
@joerg:thalheim.ioMic92 changed their display name from Mic3000 🌋 to Mic92.12:22:31

Show newer messages


Back to Room ListRoom Version: 6