!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

673 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22206 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
11 Dec 2024
@fernsehmuell:matrix.orgfernsehmuell (☎️ 3376 he/him) changed their display name from fernsehmuell to fernsehmuell (he/his) DECT: 3376 (fern).18:57:11
12 Dec 2024
@niklaskorz:korz.devNiklas Korz

unless someone's already on it, I'd create two (or three) PRs today:

  • unstable: move matomo to 5.1.2 and alias matomo_5 to matomo (+ release notes)
  • 24.11: add knownVulnerabilities to matomo about EOL and recommend an upgrade to matomo_5 (+ release notes)
  • same for 24.05 or should it be skipped because it's EOL in three weeks?
08:30:47
@tgerbet:matrix.orgtgerbetIdeally same for 24.0508:33:49
@sandro:supersandro.deSandro 🐧If we only would build packages with knowVulnerabilities then we wouldn't need to weigh usability and security against each other 09:50:42
@niklaskorz:korz.devNiklas Korz as someone relying on a handful of libolm based services and applications, I tend to agree 10:05:17
@flanitz:matrix.flyingcircus.ioFrank LanitzAll software is full of unfixed, known issues ;)10:09:19
@phileas:asra.grsyd installs gentoo (they/them)Reminder there is also #security-discuss:nixos.org (though I can't join the channel for some reason)10:15:55
@ahurac:chat.ahur.acAhurac left the room.10:16:08
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.14:33:59
@niklaskorz:korz.devNiklas Korz
  • unstable: https://github.com/NixOS/nixpkgs/pull/364627
  • 24.11: https://github.com/NixOS/nixpkgs/pull/364633
  • 24.05: https://github.com/NixOS/nixpkgs/pull/364642
16:17:22

Show newer messages


Back to Room ListRoom Version: 6