!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

679 Members
Coordination and triage of security issues in nixpkgs209 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
14 Mar 2025
@hexa:lossy.networkhexahttps://blog.hartwork.org/posts/expat-2-7-0-released/17:05:47
@niklaskorz:korz.devNiklas Korz
In reply to @globin:toznenetl.chat
On holiday right now, just tried but fetchCargoVendor seems to download too old dependencies and currently no further time to investigate, will only be able to check end of next week.
yup they bumped anyhow in upstream but did not update their lockfile in the process...
18:15:01
15 Mar 2025
@vcunat:matrix.orgvcunathttps://github.com/NixOS/nixpkgs/pull/39005208:49:15
18 Mar 2025
@philipp:xndr.dephilipp https://security.opensuse.org/2025/03/12/below-world-writable-log-dir.html I think this is still expolitable in nixos. Package is not updated and no other mitigations seem to be in place. 09:34:34
@sigmasquadron:matrix.orgFernando Rodrigues
In reply to @philipp:xndr.de
https://security.opensuse.org/2025/03/12/below-world-writable-log-dir.html I think this is still expolitable in nixos. Package is not updated and no other mitigations seem to be in place.
On it!
09:56:46
@sigmasquadron:matrix.orgFernando Rodrigueshttps://github.com/NixOS/nixpkgs/pull/39092510:49:37
19 Mar 2025
@bluebirdlamentations:matrix.org@bluebirdlamentations:matrix.org joined the room.17:02:51
@bluebirdlamentations:matrix.org@bluebirdlamentations:matrix.org changed their display name from Bluebird to qenya.17:03:10

Show newer messages


Back to Room ListRoom Version: 6