!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

678 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22211 Servers

Load older messages


SenderMessageTime
4 Jun 2024
@raitobezarius:matrix.orgraitobezarius changed their display name from raitobezarius (DECT: 7248) to raitobezarius.11:14:54
@mtheil:scs.ems.hostMarkus Theilhttps://github.com/openssl/openssl/releases I'm on it.15:19:20
@mtheil:scs.ems.hostMarkus TheilThe default OpenSSL is currently 3.0.x. I've looked what other distributions do here. E.g. ArchLinux is using the most recent version 3.3.x as their default. Shall we give this a try?15:23:17
@mtheil:scs.ems.hostMarkus TheilSecurity wise IMHO I don't really put trust in backports and try to stay recent with my kernels, OpenSSL and so on.15:25:07
@hexa:lossy.networkhexait depends on what kind of maintenance you want to put into it and what kind of api/abi breakages exist between minor versions15:29:05
@mtheil:scs.ems.hostMarkus TheilI'm currently testing here: https://github.com/NixOS/nixpkgs/pull/31723816:14:07
@mtheil:scs.ems.hostMarkus TheilBackports will follow tomorrow.16:14:16
5 Jun 2024
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion [UTC-4] to Insurgo aka tlaurion [UTC-4] ( back June 6th).12:30:36
@katexochen:matrix.orgPaul Meyer (katexochen)Anyone wants to take a look at https://github.com/NixOS/nixpkgs/pull/317476 before merge?19:19:48
@tgerbet:matrix.orgtgerbetLet me run an aarch64 build, the build process of envoy can be a bit surprising…19:25:07
6 Jun 2024
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion [UTC-4] ( back June 6th) to Insurgo aka tlaurion [UTC-4] (AFK still, replying from phone).16:35:49
@akechishiro:matrix.orgAkechiShiro set a profile picture.23:57:31
7 Jun 2024
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion [UTC-4] (AFK still, replying from phone) to Insurgo aka tlaurion [UTC-4].16:28:05
8 Jun 2024
@alina:kescher.at@alina:kescher.at changed their display name from alina to alina🏳️‍⚧️🐾.10:38:05
@alina:kescher.at@alina:kescher.at changed their profile picture.10:39:44
@mtheil:scs.ems.hostMarkus Theilhttps://github.com/NixOS/nixpkgs/pull/31832217:29:11
9 Jun 2024
@mtheil:scs.ems.hostMarkus TheilFRR just tagged 10.0.1, which fixes multiple security critical bugs, e.g. CVE-2024-31951. The auto update bot already took notice of this tag: https://github.com/NixOS/nixpkgs/pull/31849616:07:06
10 Jun 2024
@mtheil:scs.ems.hostMarkus Theil

frr 10.0.1 and 9.0.3 probably fix at least:

  • CVE-2024-31948
  • CVE-2024-31949
  • CVE-2024-31950
  • CVE-2024-31951

I added a PR for 23.11 here: https://github.com/NixOS/nixpkgs/pull/318758

10:33:46
@Minijackson:matrix.orgMinijacksonJellyfin update that has a small security fix on first time setup: https://github.com/NixOS/nixpkgs/pull/318873 19:04:56
11 Jun 2024
@wxnzemof:matrix.orgwxnzemof joined the room.09:53:35
@wxnzemof:matrix.orgwxnzemofHi, this is probably benign but maybe worth looking into: https://github.com/nix-community/nix-installers/issues/4909:54:13
@sandro:supersandro.deSandroThis is what the GitHub Action does https://github.com/nix-community/nix-installers/blob/master/.github/workflows/gh-pages.yml11:40:17
@aynish:sealight.xyz@aynish:sealight.xyz left the room.14:56:41
@networkexception:chat.upi.li@networkexception:chat.upi.li changed their display name from networkException to networkException (moving to @networkexception:nwex.de).18:34:30
@sasha:the-apothecary.clubSashanoraa.gay (she/her, ze/zir) changed their display name from Sashanoraa.gay (ze/zir) to Sashanoraa.gay (ze/zir, she/her).21:46:14
12 Jun 2024
@hexa:lossy.networkhexahttps://conduit.rs/changelog/#v0-8-0-2024-06-12 (and conduwuit/grapevine for whoever uses those)19:09:11
@networkexception:nwex.denetworkException joined the room.19:28:47
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/31936219:57:39
@hexa:lossy.networkhexawill backport to release-24.05, given that the breaking changes in 0.7.0 don't affect us19:57:52
@hexa:lossy.networkhexa * will backport to release-24.05 and release-23.11, given that the breaking changes in 0.7.0 don't affect us 19:58:11

Show newer messages


Back to Room ListRoom Version: 6