!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

692 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
26 Jun 2024
@oliviacrain:matrix.org@oliviacrain:matrix.org left the room.17:02:33
@maralorn:maralorn.demaralorn joined the room.20:59:22
@maralorn:maralorn.demaralornI would like to merge this security fix for pandoc into master asap. However it has a 501-1000 tag, is that acceptable in this case? https://github.com/NixOS/nixpkgs/pull/32266921:00:56
@hexa:lossy.networkhexago for it21:01:38
@tgerbet:matrix.orgtgerbetI will have access to my aarch64 builder in ~1h to confirm but my nixpkgs-review for half the builds looked fine21:05:08
@tgerbet:matrix.orgtgerbetThere are a lot of things but mainly small ones21:06:48
@maralorn:maralorn.demaralornI am super certain that that patch will not affect downstream packages.^^21:10:05
@maralorn:maralorn.demaralorn * I am quite certain that that patch will not affect downstream packages.^^ It only modifies a template.21:10:51
27 Jun 2024
@maralorn:maralorn.demaralornHow important is it to back port fixes to 23.11?00:39:13
@vcunat:matrix.orgvcunatI'm not sure, but the promise of maintenance ends in a couple days.05:29:49
@mtheil:scs.ems.hostMarkus Theilhttps://www.openssl.org/news/secadv/20240627.txt11:07:28
@mtheil:scs.ems.hostMarkus TheilEven with low severity, I'll open PRs this evening if time permits.11:07:52
@mtheil:scs.ems.hostMarkus Theil * Even with low severity, I'll open PRs this evening if time permits. I have no real overview, if this is a issue somewhere, but buffer overread/possible information leak should be enough to take some action.11:09:08
@mtheil:scs.ems.hostMarkus TheilThe low severity issues I did not included as patches but waited for the next minor release were causing high load/DoS but no information disclosure. This is just my personal distinction between patch and wait. I hope at least some of you share this view.11:10:44
@mtheil:scs.ems.hostMarkus Theil * The low severity issues I did not include as patches but waited for the next minor release in the past were causing high load/DoS but no information disclosure. This is just my personal distinction between patch and wait. I hope at least some of you share this view.11:11:08
@mtheil:scs.ems.hostMarkus TheilAlso add patches to 23.11 as asked above?11:14:58
@hexa:lossy.networkhexaplease11:15:10
@hexa:lossy.networkhexaif it is not too big a hassle11:15:27
@mtheil:scs.ems.hostMarkus TheilNo real issue, just asking.11:15:47
@hxr404:tchncs.dehxr404 ✨ [she/her] joined the room.23:32:08
28 Jun 2024
@axiomss:matrix.org@axiomss:matrix.org left the room.04:13:15
29 Jun 2024
@mib:kanp.aimib 🥐 changed their profile picture.22:24:23
30 Jun 2024
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] to tlaurion aka Insurgo [UTC-4] (Canadian Dominion holiday, back July 2nd).17:28:30
1 Jul 2024
@ar:is-a.catari ❄https://www.openssh.com/releasenotes.html08:35:55
@k900:0upti.meK900Oh no08:37:08
@emilazy:matrix.orgemilydo openssh bumps go to master or staging?08:40:51
@qyliss:fairydust.spaceAlyssa Rossmaster08:41:12
@qyliss:fairydust.spaceAlyssa Rosse.g. https://github.com/NixOS/nixpkgs/pull/29513308:41:22
@k900:0upti.meK900I can do a PR in like 30 08:41:50
@emilazy:matrix.orgemilyI'm building already & can do the PR but I don't know if there's specific procedure around assigning an advisory or whatever08:41:50

Show newer messages


Back to Room ListRoom Version: 6