!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

692 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
1 Jul 2024
@emilazy:matrix.orgemilydo we care about waiting for Gentoo's fix backport for stable or should we just do the major bump?08:56:03
@emilazy:matrix.orgemilyhttps://github.com/gentoo/gentoo/commit/1633ef45475afb9eea04e9cf27021c9d994af33808:56:24
@emilazy:matrix.orgemilyah, the backport is already here08:56:27
@emilazy:matrix.orgemilyand is from upstream08:56:38
@emilazy:matrix.orgemilywill defer to others' judgement as to how we want to do the stable fixes08:57:15
@qyliss:fairydust.spaceAlyssa Rossif there's a backport available that probably makes sense08:57:27
@emilazy:matrix.orgemilyI'll do it that way then08:58:39
@emilazy:matrix.orgemilyI don't have merge permissions btw so feel free to hit the button on the master PR when you're confident08:59:23
@emilazy:matrix.orgemilywe probably need to mark _hpn as insecure or see if the patch applies also08:59:59
@qyliss:fairydust.spaceAlyssa Rossmerged09:00:42
@k900:0upti.meK900Thanks whoever started unstable-small09:02:45
@emilazy:matrix.orgemilyI'll look at the HPN nonsense once the stable stuff is done09:04:12
@qyliss:fairydust.spaceAlyssa Ross(finished building on aarch64-linux)09:04:27
@qyliss:fairydust.spaceAlyssa Rossoh, should we move out of the triage channel?09:04:43
@emilazy:matrix.orgemilyI'll move to the discussion room09:06:15
@fadenb:utzutzutz.netfadenb joined the room.10:09:53
@vincenttc:matrix.org@vincenttc:matrix.org joined the room.12:05:28
@vengmark2:matrix.org@vengmark2:matrix.org joined the room.15:05:10
@vengmark2:matrix.org@vengmark2:matrix.org left the room.15:05:28
@annaaurora:artemislena.eu@annaaurora:artemislena.eu joined the room.21:52:04
2 Jul 2024
@b:chreekat.netchreekat joined the room.09:16:36
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] (Canadian Dominion holiday, back July 2nd) to tlaurion aka Insurgo [UTC-4].12:36:49
@david:matrix.galvanix.com@david:matrix.galvanix.com joined the room.17:50:15
@ity:itycodes.org@ity:itycodes.org changed their display name from Tranquil Ity to Tranquil Ity (eepy/cutie).20:49:29
@ity:itycodes.org@ity:itycodes.org changed their display name from Tranquil Ity (eepy/cutie) to Tranquil Ity.20:50:51
@r_i_s:matrix.orgris_sigh https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation/21:26:14
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/commit/2dcfa4787b6fb9fb9e6cb087db382f9ce8556f9921:32:15
@emilazy:matrix.orgemily(don't expose unsandboxed ghostscript to untrusted input folks)21:34:09
@r_i_s:matrix.orgris_
In reply to @tgerbet:matrix.org
https://github.com/NixOS/nixpkgs/commit/2dcfa4787b6fb9fb9e6cb087db382f9ce8556f99
oh awesome we don't even have to backport
21:41:00
@hexa:lossy.networkhexahttps://httpd.apache.org/security/vulnerabilities_24.html22:08:47

Show newer messages


Back to Room ListRoom Version: 6