!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

691 Members
Coordination and triage of security issues in nixpkgs217 Servers

Load older messages


SenderMessageTime
27 Feb 2025
@niklaskorz:korz.devNiklas Korzhttps://github.com/mastodon/mastodon/releases/tag/v4.3.4 can't create a PR right now unfortunately as I'm on the go16:33:15
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.17:12:45
1 Mar 2025
@mokasin:mokasin.de@mokasin:mokasin.de joined the room.06:00:00
@tgerbet:matrix.orgtgerbetI now have something that seems to be in a working shape (79 patches 🙃). It would be great if some grub users could give it a try.11:54:42
3 Mar 2025
@ximnoise:infosec.exchangeximnoise changed their profile picture.14:52:34
@ximnoise:infosec.exchangeximnoise changed their profile picture.16:49:28
@kenmacd:matrix.org@kenmacd:matrix.org left the room.17:58:50
4 Mar 2025
@lassulus:lassul.uslassulus changed their profile picture.17:49:02
6 Mar 2025
@akechishiro:matrix.orgAkechiShiroCould someone handle this please ? (affects LibreOffice versions prior to 24.8.5 and 25.2.1.) : https://www.libreoffice.org/about-us/security/advisories/cve-2025-1080/11:47:22
@hexa:lossy.networkhexacan you reach out to michael raskin?11:49:02
@hexa:lossy.networkhexa@7c6f434c:nitro.chat11:49:40
@grimmauld:grimmauld.deGrimmauld (moving to @grimmauld:grapevine.grimmauld.de) changed their display name from Grimmauld to Grimmauld (any/all).15:53:28
7 Mar 2025
@lisipu:catgirl.cloudlisipu joined the room.18:10:24
@scrumplex:duckhub.ioScrumplexRedacted or Malformed Event20:21:25
8 Mar 2025
@joey:jdigi.net@joey:jdigi.net joined the room.03:31:48
@joey:jdigi.net@joey:jdigi.netHi all. I don't think this is a security issue perse, but its come to my attention the nix librewolf package doesn't appear to be applying privacy and security related patches to firefox as it should and is therefore not a good-faith representation of librewolf and its main claims of added privacy and security. Frankly I think its egregious enough it should be taken down until its fixed. What should be done about this?03:42:32
@joey:jdigi.net@joey:jdigi.netRelevant issue for more context: https://github.com/NixOS/nixpkgs/issues/34441703:43:04
@emilazy:matrix.orgemily (should be in #security-discuss:nixos.org) 03:44:34
@joey:jdigi.net@joey:jdigi.netSorry, will post there03:45:00
@joey:jdigi.net@joey:jdigi.netThanks03:45:02
@emilazy:matrix.orgemily(→ https://matrix.to/#/!ATURSDtpSAgOTfvtbq:lossy.network/$70MCEnnDRUWOYF6uXcpQCBisSTP93faBL6m9JrjcTOI?via=nixos.org&via=matrix.org&via=memes.nz)03:45:44
@ncfavier:matrix.orgnf changed their profile picture.10:43:38
10 Mar 2025
@akechishiro:matrix.orgAkechiShiroHey just a quick update, I did reach out to him regarding the CVE, he did confirm that versions in Nixpkgs are vulnerable, I also saw that some builds fixes are waiting to get build : https://github.com/NixOS/nixpkgs/pull/387730 OfBorg can't build the package, I guess the version bump would come after this PR which fixes some builds15:24:54
@joey:jdigi.net@joey:jdigi.net left the room.15:42:22
@emilazy:matrix.orgemily(he's the sole listed maintainer for LibreOffice, does he plan to handle the CVEs?)15:59:50
@hexa:lossy.networkhexaexactly my question16:12:18
@gaelj:matrix-ga.eljam.esGaël joined the room.22:08:06
@akechishiro:matrix.orgAkechiShiroSorry for the delay, he plans to handle the CVE but he's unsure when he can do it22:14:26
11 Mar 2025
@3wy-kra:matrix.uni-hannover.de@3wy-kra:matrix.uni-hannover.de joined the room.16:59:37
12 Mar 2025
@paq:matrix.orgpaq joined the room.09:25:20

Show newer messages


Back to Room ListRoom Version: 6