!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

700 Members
Coordination and triage of security issues in nixpkgs217 Servers

Load older messages


SenderMessageTime
1 Sep 2024
@zzantares:matrix.org@zzantares:matrix.org removed their display name Hamlet'sPiedPlumber.19:19:29
@zzantares:matrix.org@zzantares:matrix.org left the room.19:19:50
2 Sep 2024
@sandro:supersandro.deSandrohttps://github.com/hedgedoc/hedgedoc/releases/tag/1.10.0 https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-pjf2-269h-cx7p15:02:03
3 Sep 2024
@mtheil:scs.ems.hostMarkus TheilOpenSSL relesed today: https://github.com/openssl/openssl/blob/openssl-3.3/CHANGES.md#changes-between-331-and-332-3-sep-202418:45:49
@mtheil:scs.ems.hostMarkus TheilI'll probably open a PR with some more Cleanups tomorrow (e.g. OpenSSL now only uses Github-Releases).18:46:17
@mtheil:scs.ems.hostMarkus TheilI'd also like to test if we can default to the latest OpenSSL version in 24.11 (currently 3.3). Arch Linux already does this. I don't know what will break, but would like to see some issues and revert, if I/we can't handle this timely.18:48:26
@mtheil:scs.ems.hostMarkus Theil * I'd also like to test if we can default to the latest OpenSSL version in 24.11 (currently 3.3). Arch Linux already does this. I don't know what will break, but would like to see some issues first and revert, if I/we can't handle this timely.18:48:46
@mtheil:scs.ems.hostMarkus Theil * I'd also like to test if we can default to the latest OpenSSL version in 24.11 (currently 3.3). Arch Linux already does this. I don't know what will break, but would like to see some issues first and revert the default back to 3.0.x, if I/we can't handle this timely.18:49:35
@emilazy:matrix.orgemily
In reply to @mtheil:scs.ems.host
I'd also like to test if we can default to the latest OpenSSL version in 24.11 (currently 3.3). Arch Linux already does this. I don't know what will break, but would like to see some issues first and revert the default back to 3.0.x, if I/we can't handle this timely.
will response to this in #security-discuss:nixos.org
18:58:02
@emilazy:matrix.orgemily
In reply to @mtheil:scs.ems.host
I'd also like to test if we can default to the latest OpenSSL version in 24.11 (currently 3.3). Arch Linux already does this. I don't know what will break, but would like to see some issues first and revert the default back to 3.0.x, if I/we can't handle this timely.
* will respond to this in #security-discuss:nixos.org
18:58:07
@emilazy:matrix.orgemily * responded in https://matrix.to/#/!NBBFPbiuttRgTqbrcY:nixos.org/$jYyvEStvrMgr0KMalxi0xegBNvl2mQuzaQ-W49tMM70?via=nixos.org&via=matrix.org&via=nixos.dev 18:59:37
4 Sep 2024
@k900:0upti.meK900What12:48:23
@emilazy:matrix.orgemily(am I missing something?)15:45:44
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] to tlaurion aka Insurgo [UTC-4] (expect delays in answers).20:32:11
@ss:someonex.netSomeoneSerge (back on matrix) changed their display name from SomeoneSerge (UTC+3) to SomeoneSerge (nix.camp).21:49:21
5 Sep 2024
@necoarc:transfem.dev@necoarc:transfem.dev joined the room.03:38:58
@necoarc:transfem.dev@necoarc:transfem.dev removed their display name Neco-Arc.03:49:32
@necoarc:transfem.dev@necoarc:transfem.dev removed their profile picture.03:49:32
@necoarc:transfem.dev@necoarc:transfem.dev left the room.03:49:32
@hexa:lossy.networkhexahttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4550616:23:24
@hexa:lossy.networkhexa * https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45506 haproxy16:23:28
@hexa:lossy.networkhexaI'm bumping release-24.05 to 2.9.10, can someone take master. i have to run16:23:48
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/33984016:25:27
@hexa:lossy.networkhexahttps://groups.google.com/g/golang-announce/c/K-cEzDeCtpc 18:05:50
6 Sep 2024
@sugi:matrix.besaid.desugiforgejo is going to need an update to 8.0.3 or 7.0.916:56:18
@sugi:matrix.besaid.desugi * forgejo is going to need an update to 8.0.3 or 7.0.9 (https://codeberg.org/forgejo/forgejo/milestone/8231)16:59:42
@hexa:lossy.networkhexa emily, adamcstephens 17:01:01
@hexa:lossy.networkhexa(pretty sure they are aware)17:01:10
@hexa:lossy.networkhexa * (pretty sure they are aware, but still)17:01:14
@emilazy:matrix.orgemily(wrong emily?)17:01:17

Show newer messages


Back to Room ListRoom Version: 6