!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

690 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
16 Jun 2021
@moritz.hedtke:matrix.orgmoritz.hedtke * Likely https://github.com/NixOS/nixpkgs/commit/b00bcf21abc392ecb1d93bd49f7a5ffbc8524ecf#diff-352faa44c3da86e70bd6b5a55ff13f0a900b0f2fac44229f352ed1fd5b93a262? which is missing on release-21.0521:54:40
@moritz.hedtke:matrix.orgmoritz.hedtkebtw. until when / are we still backporting security fixes to 20.0921:58:24
@hexa:lossy.networkhexa Foxboron: are you using schleuder for disclosures? 22:04:43
@hexa:lossy.networkhexa moritz.hedtke: roughly end of the month 22:07:50
@hexa:lossy.networkhexaat some point we especially want to stop causing staging rebuilds for 20.09, it's costly22:09:37
@foxboron:archlinux.orgFoxboron
In reply to @hexa:lossy.network
Foxboron: are you using schleuder for disclosures?
Idea is to use it for security@archlinux.org. so disclosures and contact point for a possible CNA registration
23:12:09
@hexa:lossy.networkhexaokay, thanks23:14:47
@hexa:lossy.networkhexa Las: I think this change is what is tripping it up: https://git.kernel.org/pub/scm/network/connman/connman.git/commit/?h=1.40&id=17c13bb84972b0ac7bbf4332b09874ad6c59144f 23:23:36
17 Jun 2021
@linus.heckemann:matrix.mayflower.deLinux Hackerman
In reply to @hexa:lossy.network
think I'm going to mention the room, when there are actionable things - starting now
I like how Element for Android displays the room with a red notification bubble, but doesn't highlight the message itself in red, so I have to go through all the messages to find it 🤦
06:53:21
18 Jun 2021
@hexa:lossy.networkhexa Las: were you able to resolve your nix store issues? Still looking for that connman fix :) 17:03:28
@Las:matrix.orgLas hexa: ah I just assumed someone else did it! 17:33:40
@Las:matrix.orgLasI just reinstalled my system from an installer iso17:33:47
@hexa:lossy.networkhexaI looked at it shortly, but I didn't think adding openconnect to buildInputs was a nice solution, when it is passed in via an argument18:08:52
@Las:matrix.orgLasI don't think there is any other solutoin18:37:07
@Las:matrix.orgLas * I don't think there is any other solution18:37:10
@Las:matrix.orgLasit's just used like a normal library now18:37:19
@hexa:lossy.networkhexamight be true, I didn't have time to check18:37:48
@hexa:lossy.networkhexahave to grab some food before the supermarkets close now18:38:03
@Las:matrix.orgLas I made a PR BTW 18:39:01
@Las:matrix.orgLasUntested since I don't use connman18:39:07
@hexa:lossy.networkhexarequested two reviewers that previously did reviews/changes19:27:07
19 Jun 2021
@thecannon:matrix.orgCannon joined the room.00:19:14
@ncfavier:matrix.orgnf joined the room.06:47:24
@hexa:lossy.networkhexacrossposting here: https://github.com/NixOS/nixpkgs/pull/12745313:21:53
@hexa:lossy.networkhexareintroducing certifi with a 2019 version isn't a great idea, but it apparently is required for nixops to continue working13:22:26
@hexa:lossy.networkhexa I insist that it should be marked with knownVulnerablities and added a commit to that end, so that if it should go in, the problem would be glaringly obvious to any user. 13:23:02
@thecannon:matrix.orgCannon changed their display name from NixCannon to Cannon.15:51:54
@thecannon:matrix.orgCannon changed their profile picture.15:53:06
@thecannon:matrix.orgCannon left the room.16:14:01
@putch4r:matrix.orgputchar joined the room.17:16:08

Show newer messages


Back to Room ListRoom Version: 6