!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

696 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
16 Sep 2024
@alisonjenkins:matrix.orgAlison Jenkins changed their profile picture.20:21:09
17 Sep 2024
@lassulus:lassul.uslassulus changed their profile picture.14:38:28
@tomherbers:matrix.orgTom (deprecated) joined the room.21:04:04
18 Sep 2024
@yaya:uwu.isyaya GitLab is open again, I'm on it. 10:15:32
@yaya:uwu.isyaya *

GitLab is open again, I'm on it.

EDIT: Opened #342765

10:42:33
@fabianhjr:matrix.orgFabián Herediahttps://www.tenable.com/cve/CVE-2024-40896 Critical CVSSv3 of 9.7 on libxml2 https://gitlab.gnome.org/GNOME/libxml2/-/issues/761 Currently reserved in MITRE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40896 https://github.com/NixOS/nixpkgs/pull/34289522:41:48
@fabianhjr:matrix.orgFabián HerediaScored as Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H According to the first link22:42:37
@fabianhjr:matrix.orgFabián HerediaSeems not as critital, mentions that it depends on very specific usage of the library by downstream code22:59:24
19 Sep 2024
@adam:robins.wtfadamcstephensenvoy is publishing a series of security updates for all their supported releases. i'm starting on 1.30.6 which is in 24.05. i assume they'll publish a 1.31.2 which would be needed for unstable https://github.com/envoyproxy/envoy/releases/tag/v1.30.621:00:16
@adam:robins.wtfadamcstephens I'll probably be out when the 1.31 release drops, but will get to it later this evening if lukegb (he/him) hasn't 21:06:52
21 Sep 2024
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.18:21:42
22 Sep 2024
@rootname:matrix.org@rootname:matrix.org left the room.10:56:38
@implr:hackerspace.plimplr left the room.18:28:59
@implr:hackerspace.plimplr joined the room.18:36:15
23 Sep 2024
@shaderoit99:matrix.org@shaderoit99:matrix.org joined the room.06:04:19
@elikoga:matrix.orgelikoga joined the room.15:30:45
@purpleseaotter:nope.chat@purpleseaotter:nope.chat joined the room.16:30:49
@purpleseaotter:nope.chat@purpleseaotter:nope.chatAaa16:32:33
@k900:0upti.meK900?16:32:48
@purpleseaotter:nope.chat@purpleseaotter:nope.chatHello16:32:56
@purpleseaotter:nope.chat@purpleseaotter:nope.chatThe room is loading very slowly for me16:33:03
@purpleseaotter:nope.chat@purpleseaotter:nope.chatI cannot see any messages before "Aaa"16:33:20
@k900:0upti.meK900There might be split brain shenanigans again16:33:52
@purpleseaotter:nope.chat@purpleseaotter:nope.chatI had a few questions for this room that I hope Ill get an answer to16:35:04
@k900:0upti.meK900This is not the room for questions16:36:07
@purpleseaotter:nope.chat@purpleseaotter:nope.chat

So I switched from fedora silverblue to NixOS a while back...

All is fine and good, but I am trying to set up a secure system to operate from and im just missing a few things to realize this.

Whats the status on apparmor/selinux/tomoyo support in NixOS? I really want to use one of the 3 and ideally SELinux

16:36:08
@purpleseaotter:nope.chat@purpleseaotter:nope.chat
In reply to @k900:0upti.me
This is not the room for questions
Oh? Then what is the room? Apologies
16:36:16
@k900:0upti.meK900This is a room for reporting security issues in packages16:36:17
@k900:0upti.meK900 You want #NixOS Security Discussions 16:36:21
@purpleseaotter:nope.chat@purpleseaotter:nope.chatThank you sorry. I will delete my message16:36:35

Show newer messages


Back to Room ListRoom Version: 6