!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

695 Members
Coordination and triage of security issues in nixpkgs217 Servers

Load older messages


SenderMessageTime
8 Dec 2024
@shawn8901:matrix.orgshawn8901 set a profile picture.19:21:34
9 Dec 2024
@tomodachi94:matrix.orgTomodachi94 (they/them)https://matrix.to/#/#dev:nixos.org/$1QE9j5UPzFb-qL02MAvSbSzX-0UspFEc5FBEtqH8y8s23:33:10
@tomodachi94:matrix.orgTomodachi94 (they/them)
This Matomo update has a "high impact security fix" that came out more than two months ago: > https://github.com/NixOS/nixpkgs/pull/363621
23:33:27
@tomodachi94:matrix.orgTomodachi94 (they/them)
This Matomo update has a "high impact security fix" that came out more than two months ago: https://github.com/NixOS/nixpkgs/pull/363621
23:33:32
@tomodachi94:matrix.orgTomodachi94 (they/them)(oh, nevermind, already merged)23:33:53
10 Dec 2024
@niklaskorz:korz.devNiklas Korz joined the room.19:28:21
@niklaskorz:korz.devNiklas Korz backport to 24.05 is still open: https://github.com/NixOS/nixpkgs/pull/363869 19:29:14
@hexa:lossy.networkhexa Niklas Korz: I browsed the matomo changelog and commit log a bit, but I didn't find anything on whether matomo 4.x is affected 21:07:54
@hexa:lossy.networkhexaand since matomo defaults to 4.16.1 on nixos-24.05 we must know or else21:12:12
@hexa:lossy.networkhexaugh, same for nixos-24.11? 🫠21:12:43
@hexa:lossy.networkhexa5.0 was released in 2023-12 — WHYYYYY21:13:44
@hexa:lossy.networkhexahttps://endoflife.date/matomo21:13:59
@hexa:lossy.networkhexaLTS support ends in 9 days21:14:11
@hexa:lossy.networkhexa👏21:14:17
@niklaskorz:korz.devNiklas Korz yeah I was surprised about that as well 😅 21:24:35
@hexa:lossy.networkhexawe need some kind of remediation here21:24:56
@hexa:lossy.networkhexaworst case we mark 4.x as knownvulnerable and make people migrate to 521:25:14
@hexa:lossy.networkhexa * worst case we mark 4.x as knownvulnerable "eol" and make people migrate to 521:25:22
11 Dec 2024
@scrumplex:duckhub.ioScrumplexhttps://github.com/NixOS/nixpkgs/pull/364160 https://curl.se/docs/CVE-2024-11053.html08:09:30
@hexa:lossy.networkhexahttps://about.gitlab.com/releases/2024/12/11/patch-release-gitlab-17-6-2-released/16:00:02
@hexa:lossy.networkhexa xanderio, leona ^ 16:01:05
@hexa:lossy.networkhexaRedacted or Malformed Event16:01:47
@hexa:lossy.networkhexaI'm too slow 🙂 16:01:49
@leona:leona.isleona
In reply to @hexa:lossy.network
https://about.gitlab.com/releases/2024/12/11/patch-release-gitlab-17-6-2-released/
there are already two open PRs for that: https://github.com/NixOS/nixpkgs/pull/364213 https://github.com/NixOS/nixpkgs/pull/364219 (24.05 as 'hotter' fix)
16:01:52
@stick:matrix.orgprusnak left the room.18:36:40
@fernsehmuell:matrix.orgfernsehmuell (☎️ 3376 he/him) changed their display name from fernsehmuell to fernsehmuell (he/his) DECT: 3376 (fern).18:57:11
12 Dec 2024
@niklaskorz:korz.devNiklas Korz

unless someone's already on it, I'd create two (or three) PRs today:

  • unstable: move matomo to 5.1.2 and alias matomo_5 to matomo (+ release notes)
  • 24.11: add knownVulnerabilities to matomo about EOL and recommend an upgrade to matomo_5 (+ release notes)
  • same for 24.05 or should it be skipped because it's EOL in three weeks?
08:30:47
@tgerbet:matrix.orgtgerbetIdeally same for 24.0508:33:49
@sandro:supersandro.deSandroIf we only would build packages with knowVulnerabilities then we wouldn't need to weigh usability and security against each other 09:50:42
@niklaskorz:korz.devNiklas Korz as someone relying on a handful of libolm based services and applications, I tend to agree 10:05:17

Show newer messages


Back to Room ListRoom Version: 6