!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

660 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22205 Servers

Load older messages


SenderMessageTime
19 Dec 2024
@hexa:lossy.networkhexaRedacted or Malformed Event15:54:23
@hexa:lossy.networkhexa https://www.openwall.com/lists/oss-security/2024/12/19/1 sssd illustris 15:56:07
@hexa:lossy.networkhexa

misskey

  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-m2gq-69fp-6hv4
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5h8r-gq97-xv69
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v236
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
15:57:55
@hexa:lossy.networkhexa *

misskey needs update to 2024.11.0-alpha.3 (sigh)

  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-m2gq-69fp-6hv4
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5h8r-gq97-xv69
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v236
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
15:58:27
@hexa:lossy.networkhexa *

misskey needs update to 2024.11.0

  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-m2gq-69fp-6hv4
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5h8r-gq97-xv69
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v236
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
15:58:58
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/36658816:20:10
@os:matrix.flyingcircus.ioosnyx (he/him)Percona update, that fixes the CVEs of the corresponding oracle mysql: https://github.com/NixOS/nixpkgs/pull/36657918:10:02
20 Dec 2024
@niklaskorz:korz.devNiklas KorzMatomo 4 has reached EOL yesterday16:34:53
@hexa:lossy.networkhexa osnyx (he/him): ^ 16:35:25
@hexa:lossy.networkhexa * osnyx (he/him), ma27 ^ 16:35:46
@ma27:nicht-so.sexyma27I'm perfectly fine with marking it as insecure on stable, just don't have the time to review now.17:06:17
@leona:leona.isleonaI will have a look in a few mins17:42:30
@labataxe:matrix.orglabataxe joined the room.18:47:16
21 Dec 2024
@stablejoy:matrix.org@stablejoy:matrix.org left the room.05:08:23
@dmiskovic:matrix.org@dmiskovic:matrix.org left the room.05:13:45
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] - last crush before holidays! to tlaurion aka Insurgo [UTC-4] - Back 2025-01-06.21:20:18
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.21:37:43
22 Dec 2024
@allrealmsoflife:matrix.orgallrealmsoflife joined the room.15:55:06
@hexa:lossy.networkhexa https://vikunja.io/changelog/vikunja-v0.24.6-was-released leona 21:05:01
@leona:leona.isleona https://github.com/NixOS/nixpkgs/pull/367467 21:30:37
@hexa:lossy.networkhexa leona: as 0.23.0 is affected, can you make the package vulnerable on 24.05? 21:48:08
@leona:leona.isleonasure21:49:30
@hexa:lossy.networkhexa * leona: as 0.23.0 is affected, can you mark the package vulnerable on 24.05? 21:49:40
@leona:leona.isleonathe fix patch is quite trivial to backport, so i did that: https://github.com/NixOS/nixpkgs/pull/36747421:59:32
@hexa:lossy.networkhexaawesome22:00:17
@hexa:lossy.networkhexa https://webkitgtk.org/security/WSA-2024-0008.html Jan Tojnar 22:30:56
@hexa:lossy.networkhexa * https://webkitgtk.org/security/WSA-2024-0008.html Jan Tojnar 2.46.5 22:31:03
23 Dec 2024
@jtojnar:matrix.orgJan Tojnaralready merged https://github.com/NixOS/nixpkgs/pull/36722022:14:28
24 Dec 2024
@phelix:c-base.orgphelix | 3383 changed their display name from phelix to phelix 3383.11:46:55
26 Dec 2024
@elikoga:matrix.orgelikoga changed their display name from elikoga to elikoga (@38c3 📞448{0,1}.15:21:55

Show newer messages


Back to Room ListRoom Version: 6