!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

676 Members
Coordination and triage of security issues in nixpkgs211 Servers

Load older messages


SenderMessageTime
7 Sep 2024
@emilazy:matrix.orgemily
In reply to @mtheil:scs.ems.host
Should we define this to a lower default or should users deal with it?
let's not opt in to worse security, users can deal with it unless it causes mass breakage
10:44:16
@emilazy:matrix.orgemilynot even mail servers should be using SSL 3.0 or 1024-bit RSA10:45:25
@emilazy:matrix.orgemily(let's move this to the non triage room though?)10:46:53
@vincenttc:matrix.org@vincenttc:matrix.org left the room.16:19:37
@qubitnano:matrix.orgqubitnanohttps://community.ui.com/releases/Security-Advisory-Bulletin-042-042/c4f68b56-cdc4-4128-b2cb-5870209d170416:19:42
@qubitnano:matrix.orgqubitnanoJust need to backport 8.4 to 24.05 and drop unifi7, right?16:25:41
@hexa:lossy.networkhexa"just" πŸ™‚ 16:26:43
@hexa:lossy.networkhexa talk to the maintainers globin patryk4815 16:27:13
9 Sep 2024
@david:matrix.galvanix.com@david:matrix.galvanix.com left the room.17:54:26
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/34085219:55:45
@vengmark2:matrix.org@vengmark2:matrix.org joined the room.20:39:55
@vengmark2:matrix.org@vengmark2:matrix.org left the room.20:40:51
@ma27:nicht-so.sexyma27

backport for that: https://github.com/NixOS/nixpkgs/pull/340868

prepared a small advisory, will publish when these hit the channels.

21:17:45
10 Sep 2024
@hexa:lossy.networkhexahttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-2024091018:36:19
11 Sep 2024
@hexa:lossy.networkhexahttps://curl.se/docs/CVE-2024-8096.html12:35:28
@hexa:lossy.networkhexa * https://curl.se/docs/CVE-2024-8096.html curl w/ gnutls12:35:50
@k900:0upti.meK900Steam no longer affected :P12:36:18
@niko:conduit.rsnyanbinary left the room.15:29:00
13 Sep 2024
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] (expect delays in answers) to tlaurion aka Insurgo [UTC-4] (expect long delays in answers).03:45:37
@cafkafk:gitter.imcafkafkis this known https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/, can't find any pr/issue on it, and as far as I can tell gitlab and gitlab-ee is affected05:39:49
@cafkafk:gitter.imcafkafk * is this known https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/, can't find any pr/issue on it, and as far as I can tell gitlab and gitlab-ee is affected (nvm, found https://github.com/NixOS/nixpkgs/pull/341398, I'm just blind)06:01:10
@aidalgol:matrix.orgaidalgol
In reply to @k900:0upti.me
Steam no longer affected :P
Because of the recent PR that removed a ton of optional dependencies, or something else?
20:06:56
@k900:0upti.meK900
In reply to @aidalgol:matrix.org
Because of the recent PR that removed a ton of optional dependencies, or something else?
Because of another recent PR replacing curlWithGnuTls with just curl
20:21:53
14 Sep 2024
@ss:someonex.netSomeoneSerge (back on matrix) changed their display name from SomeoneSerge (nix.camp) to SomeoneSerge (utc+3).11:38:19
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] (expect long delays in answers) to tlaurion aka Insurgo [UTC-4] (πŸ›«πŸ—ΊοΈπŸ›¬: Back 2024-10-01)).19:38:51
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] (πŸ›«πŸ—ΊοΈπŸ›¬: Back 2024-10-01)) to tlaurion aka Insurgo [UTC-4] (πŸ›«πŸ—ΊοΈπŸ›¬: Back 2024-10-01).19:40:33
15 Sep 2024
@amythegay:161.rocks@amythegay:161.rocks changed their display name from amy to amy (Old).10:04:42
@amythegay:161.rocks@amythegay:161.rocks left the room.14:22:36
16 Sep 2024
@silentlurker:matrix.orgsilentlurker joined the room.20:00:41
@alisonjenkins:matrix.orgAlison Jenkins set a profile picture.20:21:01

Show newer messages


Back to Room ListRoom Version: 6