!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

711 Members
Coordination and triage of security issues in nixpkgs219 Servers

Load older messages


SenderMessageTime
13 Dec 2023
@vcunat:matrix.orgvcunathttps://github.com/NixOS/nixpkgs/pull/27402919:37:07
@vcunat:matrix.orgvcunathttps://github.com/NixOS/nixpkgs/pull/27400119:37:46
@vcunat:matrix.orgvcunat(belonging to the few consecutive X* posts here)19:38:38
14 Dec 2023
@mtheil:scs.ems.host@mtheil:scs.ems.hostI somehow was not aware of frr 8.5.4 which fixes a bgpd crash. https://frrouting.org/release/8.5.4/. I'll create a PR for 23.05. frr 9.1 on master and 23.11 already includes this fix.08:22:32
@mtheil:scs.ems.host@mtheil:scs.ems.hosthttps://github.com/NixOS/nixpkgs/pull/27417608:34:10
@man2dev:fedora.im@man2dev:fedora.im joined the room.08:59:07
15 Dec 2023
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2023/12/15/714:39:24
@tgerbet:matrix.orgtgerbet
In reply to @hexa:lossy.network
https://www.openwall.com/lists/oss-security/2023/12/15/7
https://github.com/NixOS/nixpkgs/pull/274484
15:25:49
16 Dec 2023
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2023/12/15/1001:31:16
@hexa:lossy.networkhexa * jq 1.7.1 https://www.openwall.com/lists/oss-security/2023/12/15/1001:31:23
@hexa:lossy.networkhexa ncfavier: Artturin 01:32:06
@artturin:matrix.orgArtturin
In reply to @hexa:lossy.network
jq 1.7.1 https://www.openwall.com/lists/oss-security/2023/12/15/10
https://github.com/NixOS/nixpkgs/pull/274053
01:41:02
@hexa:lossy.networkhexaany plans for a 23.05 port of the fixes?01:41:48
@artturin:matrix.orgArtturin
In reply to @hexa:lossy.network
any plans for a 23.05 port of the fixes?
Cherry picking the commits to jq 1.6 has large conflicts and the code touched doesn't exist at all
01:47:55
@hexa:lossy.networkhexaso unlikely to be vulnerable?01:48:13
@artturin:matrix.orgArtturinPossibly but 1.6 is 5 years old so01:48:55
@artturin:matrix.orgArtturinThe code could exist in a very different form01:49:14
@lily:lily.flowersLily Foster
In reply to @hexa:lossy.network
so unlikely to be vulnerable?
The GHSA's both say first affected is 1.7
01:49:23
@hexa:lossy.networkhexaawesome!01:50:09
@r_i_s:matrix.orgris_hah jq author does first new release in years, 2 CVEs - that'll teach him!14:05:52
@phileas:asra.grsyd installs gentoo (they/them) joined the room.14:20:11
@phileas:asra.grsyd installs gentoo (they/them)FYI https://discourse.nixos.org/t/nixos-discourse-misconfigured-to-embed-external-img-src/3695614:20:39
@hexa:lossy.networkhexaforwarded to the admin team14:37:32
@phileas:asra.grsyd installs gentoo (they/them)
In reply to @hexa:lossy.network
forwarded to the admin team
thanks, have a nice weekend!
14:49:09
@r_i_s:matrix.orgris_https://github.com/NixOS/nixpkgs/pull/27164518:08:02
17 Dec 2023
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion (away) to Insurgo aka tlaurion (Timezone: UTC-5).04:05:03
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion (Timezone: UTC-5) to Insurgo aka tlaurion (TZ: UTC-5).04:05:11
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their profile picture.04:05:33
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their profile picture.04:06:02
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.04:39:22

Show newer messages


Back to Room ListRoom Version: 6