| 16 Aug 2024 |
tgerbet | Yup it needs manual interventions, 24.05 is a bit late | 23:41:13 |
emily | (moving non-triage-related comments into the normal dev channel) | 23:41:32 |
emily | anyway, one of you needs to create the equivalent PR on top of staging-24.05 manually | 23:43:57 |
emily | is how the process works :) | 23:44:05 |
| 17 Aug 2024 |
| ·☽•Nameless☆•777 · ± changed their profile picture. | 08:27:32 |
ris_ | undrafted https://github.com/NixOS/nixpkgs/pull/330519 as unstable's fix is now merged | 09:45:49 |
| tollb1 left the room. | 13:20:29 |
| tollb1 joined the room. | 13:23:07 |
| Morgan (@numinit) joined the room. | 23:43:07 |
| 18 Aug 2024 |
| getchoo joined the room. | 07:43:16 |
getchoo | https://github.com/advisories/GHSA-w3h3-4rj7-4ph4 fixed in https://github.com/NixOS/nixpkgs/pull/334522 | 07:45:32 |
hexa |  Download image.png | 08:58:14 |
hexa |  Download image.png | 08:58:24 |
hexa | I think we're good 😄 | 08:58:33 |
getchoo | Ah yeah you're right. I just thought it was fixed this release since for some reason upstream included it in the newer changelog as well lol | 08:59:43 |
| lain joined the room. | 13:17:52 |
| 19 Aug 2024 |
vcunat | nixos-unstable channel blocked due to applying security patches: https://github.com/NixOS/nixpkgs/pull/334899#issuecomment-2295912602 | 08:00:08 |
Alyssa Ross | Looking. | 08:04:56 |
vcunat | The channel has been unlucky with blockers, and thus it's on a 5 days old commit already. | 08:07:20 |
Alyssa Ross | I can't get this test to pass locally even on the last commit Hydra built it on. | 08:26:56 |
vcunat | Some that passed locally now hang for me when --rebuild on the same machine. Not easy to just bisect. | 08:30:29 |
vcunat | * Some that passed locally now hang for me when --rebuild on the same machine. Not easy to just bisect. Anyway, this channel most likely isn't a good place for the topic now. I'm sorry. | 08:31:14 |
| @alejandrosame:matrix.org left the room. | 08:51:37 |
| cafkafk changed their profile picture. | 12:45:29 |
| 20 Aug 2024 |
| a12l left the room. | 12:45:09 |
teutat3s | https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-vhr5-g3pm-49fm
https://github.com/NixOS/nixpkgs/pull/336058 | 13:22:49 |
emily | aha, knownVulnerabilities was just prescience! (taking a look and will merge after confirming aarch64-linux build) | 13:46:07 |
| ⛧-440729 [sophie raven] (it/its) changed their display name from sophie to ⛧-440729 [sophie] (it/its). | 20:59:39 |
| 22 Aug 2024 |
| Jared Baur set a profile picture. | 02:07:15 |
Jassuko | Previously semi-concerning FFmpeg CVEs seem to now have POC RCE published. Probably worth bumping the versions to the safe side rather soon.
https://securityonline.info/cve-2024-7272-critical-heap-overflow-vulnerability-discovered-in-ffmpeg-poc-published/
CVE-2024-7272: Critical Heap Overflow Vulnerability Discovered in FFmpeg, PoC Published | 13:08:28 |