!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

692 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
16 Jun 2024
@ilex:oakforest.inilexhttps://codeberg.org/forgejo/forgejo/src/branch/forgejo/RELEASE-NOTES.md#7-0-413:07:30
@hexa:lossy.networkhexa

@emily

13:26:27
@me:indeednotjames.comemily?13:26:53
@hexa:lossy.networkhexaForgejo13:27:52
@me:indeednotjames.comemily

already in nixos-unstable-small and nixos-24.05-small. so what is left to do besides marking forgejo as insecure in 23.11?

(though it can be argued over if that CVE is actually all that bad)

13:29:50
@adam:robins.wtfadamcstephensthey did cut a 1.21 release too, but marking as insecure in 23.11 is fine with me :)13:33:10
@me:indeednotjames.comemily

23.11 is on 1.20, not 1.21.

and in the old gitea versioning those are major releases.

13:35:11
@me:indeednotjames.comemilydo you have time to open a PR for this? EOL+vulnerable?13:35:44
@adam:robins.wtfadamcstephensyeah i have a few minutes13:36:32
17 Jun 2024
@joerg:thalheim.ioMic92Electron security fix in deltachat-desktop: https://github.com/NixOS/nixpkgs/pull/32055415:09:49
18 Jun 2024
@ubbabeck:matrix.orgubbabeck joined the room.08:15:55
@blitz:chat.x86.lolblitz left the room.08:59:11
19 Jun 2024
@raitobezarius:matrix.orgraitobezarius cryptsetup security update: https://github.com/NixOS/nixpkgs/pull/308340 -- will run a simple smoketest and merge for staging. 11:49:25
@hexa:lossy.networkhexaand backport, please11:53:51
20 Jun 2024
@niko:puppygock.gaynyanbinary 🏳️‍⚧️ joined the room.00:09:38
@teutat3s:pub.solarteutat3shttps://www.heise.de/en/news/Nextcloud-Attackers-can-bypass-two-factor-authentication-9766141.html10:10:56
@hexa:lossy.networkhexaold news10:11:23
@teutat3s:pub.solarteutat3sAll versions in nixpkgs already have the fixes AFAICT, not sure if vulnerability warnings should be added?10:11:37
@hexa:lossy.networkhexawe expect users to upgrade to get fixed packages always10:11:57
21 Jun 2024
@yuka:yuka.dev@yuka:yuka.dev left the room.10:25:22
@linus:schreibt.jetzt@linus:schreibt.jetzt left the room.14:05:51
@blackwell:fedora.imJason Blackwell joined the room.19:06:16
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion [UTC-4] to Insurgo aka tlaurion [UTC-4] (Happy long Québec national long weekend! back Tuesday).22:09:33
22 Jun 2024
@bumperboat:matrix.org@bumperboat:matrix.org changed their display name from bumperboat (UTC+1) to bumperboat (UTC+2).16:48:09
23 Jun 2024
@networkexception:chat.upi.li@networkexception:chat.upi.li left the room.22:08:37
24 Jun 2024
@dclmatrix:matrix.org@dclmatrix:matrix.org removed their profile picture.05:28:26
@dclmatrix:matrix.org@dclmatrix:matrix.org removed their display name blu3.05:28:31
@dclmatrix:matrix.org@dclmatrix:matrix.org left the room.05:28:36
@lotte:chir.rs@lotte:chir.rs left the room.11:12:55
25 Jun 2024
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion [UTC-4] (Happy long Québec national long weekend! back Tuesday) to tlaurion aka Insurgo [UTC-4].16:53:38

Show newer messages


Back to Room ListRoom Version: 6