!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

690 Members
Coordination and triage of security issues in nixpkgs212 Servers

Load older messages


SenderMessageTime
9 Mar 2026
@hexa:lossy.networkhexa* https://seclists.org/oss-sec/2026/q1/288 misskey/sharkey19:13:28
10 Mar 2026
@kirillrdy:matrix.orgkirillrdy joined the room.08:58:07
@mtheil:scs.ems.host@mtheil:scs.ems.host left the room.14:25:45
11 Mar 2026
@scrumplex:duckhub.ioScrumplex

https://curl.se/docs/vuln-8.18.0.html

curl

If no one gets to it until I am off work, I'll create the bump to 8.19.0

07:28:32
@vcunat:matrix.orgvcunat Highest severity is "Medium", so we target normal staging* branches, I expect. 07:33:24
@tad:mozilla.orgtadrist abdellah joined the room.10:05:08
@ctheune:matrix.flyingcircus.ioTheuni changed their display name from Theuni to Christian Theune.14:11:20
@hexa:lossy.networkhexa https://seclists.org/oss-sec/2026/q1/296 vim @Philip Taron (UTC-8) 19:19:40
12 Mar 2026
@ctheune:matrix.flyingcircus.ioTheuni changed their display name from Christian Theune to Theuni.07:17:34
@elvishjerricco:matrix.orgElvishJerricco K900, Alyssa Ross: Should this PR be targeting staging-next, staging-nixos, or master? https://github.com/NixOS/nixpkgs/pull/499397 23:29:55
@elvishjerricco:matrix.orgElvishJerriccoI had figured staging-next might merge before staging-nixos, but I think that's probably wrong23:30:16
@elvishjerricco:matrix.orgElvishJerriccobut also (for anyone else in the room), this might be serious enough to just go straight to master23:30:38
@elvishjerricco:matrix.orgElvishJerriccoand eat the rebuild of all nixos tests23:30:45
@thamizhamudhu:matrix.orgTHAMIZHAMUDHU GOPALAN joined the room.23:43:19
@whispers:catgirl.cloudwhispers [& it/fae](fwiw staging-nixos merge PR was opened just now by zowoq, though as a draft because of potential kernel regressions: https://github.com/NixOS/nixpkgs/pull/499398)23:53:50
@whispers:catgirl.cloudwhispers [& it/fae]* (fwiw staging-nixos merge PR was opened an hour ago by zowoq, though as a draft because of potential kernel regressions: https://github.com/NixOS/nixpkgs/pull/499398)23:54:04
@whispers:catgirl.cloudwhispers [& it/fae]* (note: staging-nixos merge PR was opened an hour ago by zowoq, though as a draft because of potential kernel regressions: https://github.com/NixOS/nixpkgs/pull/499398)23:54:25
13 Mar 2026
@jammie:matrix.orgJamieMagee joined the room.03:38:10
@vcunat:matrix.orgvcunatGenerally I'm trying to remember to merge also staging-nixos whenever merging staging-next, as almost no tests get pre-cached during staging-next.04:59:05
@elvishjerricco:matrix.orgElvishJerriccoyea that makes sense04:59:55
@qyliss:fairydust.spaceAlyssa Rossif you're doing that you might as well merge into staging-nixos, then staging-nixos to master, so other pending changes come along06:27:41
@k900:0upti.meK900staging-nixos is currently held back due to something something regression in stable kernels06:28:11
@k900:0upti.meK900I am not sure of the details, zowoq is06:28:28
@qyliss:fairydust.spaceAlyssa Rosssurely we should just revert that then?06:28:46
@k900:0upti.meK900It didn't get merged to master yet06:28:56
@qyliss:fairydust.spaceAlyssa Rosson staging-nixos06:29:24
@qyliss:fairydust.spaceAlyssa Rossto avoid exactly this situation06:29:35
@k900:0upti.meK900Possibly06:29:40
@tom:pub.solartom joined the room.07:28:33
@qyliss:fairydust.spaceAlyssa RossMerged into staging-nixos, and staging-nixos merge queued.08:20:21

Show newer messages


Back to Room ListRoom Version: 6