!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

704 Members
Coordination and triage of security issues in nixpkgs217 Servers

Load older messages


SenderMessageTime
20 Feb 2024
@sofo:matrix.org@sofo:matrix.org changed their profile picture.14:41:09
@sofo:matrix.org@sofo:matrix.org changed their profile picture.14:42:38
@sofo:matrix.org@sofo:matrix.org changed their profile picture.14:43:57
@felschr:matrix.orgfelschrhttps://github.com/NixOS/nixpkgs/pull/290234 https://github.com/NixOS/nixpkgs/pull/290199 (same changes are included in #290234, but CI jobs have already finished here)18:59:26
@felschr:matrix.orgfelschrOh wait, CI hasn't concluded on the 2nd PR either.19:02:05
@felschr:matrix.orgfelschr * https://github.com/NixOS/nixpkgs/pull/290234 https://github.com/NixOS/nixpkgs/pull/290241 https://github.com/NixOS/nixpkgs/pull/290199 (same changes are included in #290234, but CI jobs have already finished here)19:19:18
@niko:conduit.rsnyanbinary joined the room.22:01:09
22 Feb 2024
@koutensky:matrix.nesad.fit.vutbr.czMichal Koutenský joined the room.10:50:40
@dooy:matrix.org@dooy:matrix.orgHello. Is there NixOS triage or there is only security triage. Not sure what triage refers to. I read in a doc how Nix triage needs help and that one can be helpful there. Also is this only for NixOS or all nix?15:06:13
@k900:0upti.meK900Triage in general mostly means sorting through incoming issues15:06:36
@k900:0upti.meK900And prioritizing them and forwarding them to the relevant people15:06:51
@k900:0upti.meK900 This is more of a #dev:nixos.org thing 15:07:05
@reddima100:matrix.org@reddima100:matrix.org joined the room.15:44:15
@reddima100:matrix.org@reddima100:matrix.org left the room.15:45:38
23 Feb 2024
@hexa:lossy.networkhexa https://c-ares.org/changelog.html 07:38:43
@fernsehmuell:matrix.orgfernsehmuell (☎️ 3376 he/him)Hello, there is a CVE for the PostgresSQL-JDBC driver (https://nvd.nist.gov/vuln/detail/CVE-2024-1597). Right now nixpkgs has version 42.6.0. (stable+unstable). It is fixed in 42.6.1. So an update should be enough.12:17:24
@fernsehmuell:matrix.orgfernsehmuell (☎️ 3376 he/him) * Hello, there is a CVE for the PostgresSQL-JDBC driver (https://nvd.nist.gov/vuln/detail/CVE-2024-1597). Right now nixpkgs has version 42.6.0. (stable+unstable). It is fixed in 42.6.1. So an update should be enough. 12:18:24
@fernsehmuell:matrix.orgfernsehmuell (☎️ 3376 he/him) * Hello, there is a CVE for the PostgresSQL-JDBC driver (https://nvd.nist.gov/vuln/detail/CVE-2024-1597). Right now nixpkgs has version 42.6.0. (stable+unstable). It is fixed in 42.6.1. So an update should be enough. 12:18:55
@fernsehmuell:matrix.orgfernsehmuell (☎️ 3376 he/him) changed their display name from fernsehmuell (DECT 3376 (fern)) to fernsehmuell.12:40:12
@forden:envs.net@forden:envs.net joined the room.14:08:56
@forden:envs.net@forden:envs.net left the room.14:09:03
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion [(UTC/GMT)-5] to Insurgo aka tlaurion [AFK until March 20th].18:23:58
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/pull/29101222:54:23
27 Feb 2024
@mclutzifer:matrix.org@mclutzifer:matrix.org left the room.13:05:24
@hhefesto:matrix.orgDaniel Herrera Rendón joined the room.20:47:19
28 Feb 2024
@/yvan:matrix.org@/yvan:matrix.org left the room.15:45:47
29 Feb 2024
@ilex:oakforest.inilexhttps://github.com/HardySimpson/zlog/pull/251/commits/77d8af3b368b564605f3ab34ad9b0ed6ead9b38012:33:07
@blitz:chat.x86.lolblitz
In reply to @ilex:oakforest.in
https://github.com/HardySimpson/zlog/pull/251/commits/77d8af3b368b564605f3ab34ad9b0ed6ead9b380
as someone who (also) writes C code for money, this is a pretty sad bug
17:53:02
@katexochen:matrix.orgPaul Meyer (katexochen)

We plan to issue a security fix for the google.golang.org/protobuf and github.com/golang/protobuf modules on next Tuesday, March 5.
This will cover CVE-2024-24786.

https://groups.google.com/g/golang-announce/c/jiGrhz7X6aU/m/I8gP6k5ABAAJ?utm_medium=email&utm_source=footer&pli=1

21:00:42
1 Mar 2024
@tgerbet:matrix.orgtgerbet
In reply to @ilex:oakforest.in
https://github.com/HardySimpson/zlog/pull/251/commits/77d8af3b368b564605f3ab34ad9b0ed6ead9b380
https://github.com/NixOS/nixpkgs/pull/292517
10:30:25

Show newer messages


Back to Room ListRoom Version: 6