| 30 Jul 2024 |
hexa | * https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7 is the actual security issue, in twisted | 22:32:41 |
| 31 Jul 2024 |
hexa | https://www.openwall.com/lists/oss-security/2024/07/31/1 curl (including 8.9.0) | 09:50:05 |
Sandro | fix is only available in an rc? no links to commits.... | 11:20:07 |
teutat3s | Is the build failure expected here?
https://github.com/NixOS/nixpkgs/pull/331177/checks?check_run_id=28137809598 | 12:29:07 |
| 1 Aug 2024 |
Tammi (ey/em) | Redacted or Malformed Event | 06:33:06 |
| Vika Shleina (she/her) changed their profile picture. | 11:50:40 |
teutat3s | https://github.com/NixOS/nixpkgs/pull/331277 | 15:35:59 |
| 4 Aug 2024 |
ma27 | xss in roundcube: https://github.com/roundcube/roundcubemail/releases/tag/1.6.8
preparing an update now. | 15:06:53 |
| 7 Aug 2024 |
| adamcstephens changed their display name from adamcstephens 🐝 to adamcstephensL. | 00:17:26 |
| adamcstephens changed their display name from adamcstephensL to adamcstephens. | 00:17:46 |
teutat3s | GHSA-f83w-wqhc-cfp4 https://github.com/NixOS/nixpkgs/pull/332940 | 08:17:34 |
felschr | https://github.com/NixOS/nixpkgs/pull/332833 | 11:50:22 |
| 8 Aug 2024 |
| Alyssa Ross set a profile picture. | 18:48:46 |
| 9 Aug 2024 |
emily | https://i.blackhat.com/BH-US-24/Presentations/REVISED02-US24_Moore_Secure_Shells_in_Shambles_Wednesday.pdf#page=72 | 09:57:49 |
emily | RCE in soft-serve, need to bump to 0.7.5 and backport | 09:57:59 |
emily | (also in gogs, but we have that marked as insecure already) | 09:58:05 |
emily | to 0.7.6 rather I guess | 09:58:25 |
emily | https://github.com/NixOS/nixpkgs/pull/331386 | 09:58:49 |
yaya | https://www.postgresql.org/support/security/CVE-2024-7348/ | 11:33:11 |
hexa | cc ma27 | 11:35:02 |
ma27 | oh dang right when I'm on vacation. can you please ping wolfgangwalther (not sure if they have matrix though, obly interacted on github). | 11:57:17 |
ma27 | sowwy | 11:58:11 |
hexa | enjoy! | 12:02:50 |
hexa | via https://github.com/NixOS/nixpkgs/issues/333430 | 12:04:45 |
| 10 Aug 2024 |
| Tristan Ross changed their profile picture. | 03:13:13 |
vcunat | (still needs a manual backport to 24.05, apparently) | 05:30:55 |
| 12 Aug 2024 |
Sandro | https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0 | 09:47:15 |
Sandro | https://github.com/NixOS/nixpkgs/pull/334048 | 09:51:33 |
Sandro | https://github.com/NixOS/nixpkgs/pull/334099 | 10:40:29 |
Sandro | CVE-2024-7589 in openssh is freebsd specific and doesn't apply to us. | 12:07:18 |