NixOS Security Triage | 722 Members | |
| Coordination and triage of security issues in nixpkgs | 219 Servers |
| Sender | Message | Time |
|---|---|---|
| 4 Apr 2024 | ||
| https://github.com/NixOS/nixpkgs/pull/301604 | 17:57:02 | |
| 19:55:04 | ||
| 6 Apr 2024 | ||
| 21:03:22 | ||
| 21:21:12 | ||
| hello -- i deleted my github account today due to being angry at some dumpster fire of a PR i got involved with. anyway, some of my other work is now being questioned about me being part of the xz conspiracy https://github.com/NixOS/nixpkgs/pull/301252 i recognize the suspicion but that was just due to the work of cleaning up segfaults and libc++abi / libc++ stuff from LLVM. | 22:55:54 | |
| and cleaning up old LLVMs. | 22:56:56 | |
| i wish i could get that time back... | 22:57:42 | |
| oh dear 😆 | 23:12:39 | |
| i knew getting involved in the PR was a mistake last week but i did it anyway. | 23:13:47 | |
| * i knew getting involved in the PR was a mistake last week but i did it anyway. (https://github.com/NixOS/nixpkgs/pull/294347) | 23:15:22 | |
the RFC process to get meta.sourceProvenance took me a year, and then when I tried to implement it, someone popped up and tried to make me redesign it | 23:16:39 | |
| so i sympathize, it's stressful | 23:19:09 | |
| Hey, I'm sorry that it had to come to this. If you had encountered problems earlier I would hope moderation could've helped | 23:20:02 | |
| I'm sorry for that, thank you for all your contributions. | 23:31:54 | |
In reply to @a-n-n-a-l-e-e:matrix.orgsad to see you go, takae your time and enjoy life. | 23:38:29 | |
| 7 Apr 2024 | ||
In reply to @a-n-n-a-l-e-e:matrix.orgOh what exactly was the tipping point? :< | 02:24:23 | |
| oh, i was wondering what happened... | 02:35:33 | |
| 12:29:14 | ||
| thanks. though the member who was making backhanded comments about my incompetence and lack of professionalism is a member of the moderation team, to my understanding. | 14:59:05 | |
| can you point out details in a DM? | 15:00:13 | |
| 8 Apr 2024 | ||
| 03:38:37 | ||
| botan2 and botan3 had bug fix releases roughly a month ago. I made a combined PR some weeks ago, but was not able to debug the failing build of monotone with botan2 on MacOS myself. So I split this PR into a another one for botan2.
Is someone willing to step in for debugging the failing botan2 build on MacOS or can provide me some debugging hints for debugging from a Linux-based system with ofborg in the CI? | 09:51:18 | |
| * botan2 and botan3 had bug fix releases roughly a month ago. I made a combined PR some weeks ago, but was not able to debug the failing build of monotone with botan2 on MacOS myself. So I split this PR into another one for botan2.
Is someone willing to step in for debugging the failing botan2 build on MacOS or can provide me some debugging hints for debugging from a Linux-based system with ofborg in the CI? | 09:51:40 | |
| 15:17:20 | |
| Cherrypick or wait? I'd wait. | 15:18:07 | |
| * Cherrypick/patch or wait? I'd wait. | 15:18:28 | |
| Another reminder to drop support for 1.1.1, when possible :) | 15:19:00 | |
| Envoy 1.27.4 (CVE-2024-30255) https://github.com/envoyproxy/envoy/releases/tag/v1.27.4 cc lukegb (he/him) (build is already kind of broken and only work thanks to caching of the deps :/ ) | 18:21:01 | |
| 23:11:17 | ||
| 9 Apr 2024 | ||
| The security researchers at exploit.org claimed they've found an RCE in Telegram Desktop's latest version (seems 4.16.1 at least), and updated a demonstration video targeting Windows build. Someone in the comment claimed they could not trigger the PoC in 4.16.4. Original message:
| 06:00:20 | |