!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

715 Members
Coordination and triage of security issues in nixpkgs219 Servers

Load older messages


SenderMessageTime
8 Dec 2023
@hexa:lossy.networkhexa cc cole-h, Winter (she/her) (both release branches are affected) 22:29:29
@cole-h:matrix.orgcole-hI think 3.6.4 has already been merged and backported?22:58:06
@cole-h:matrix.orgcole-hPR to master was 272095, and to release-23.11 was 272366, both have made it to channels (though the PR to master is only in unstable-small, not nixpkgs or nixos unstables)23:00:48
@hexa:lossy.networkhexa cole-h: release-23.05 is on 3.6.1 😉 23:10:00
@cole-h:matrix.orgcole-hOh yeah23:22:35
@cole-h:matrix.orgcole-hPR up at 27303623:28:12
9 Dec 2023
@git_lit_mit_ohne_dir:matrix.org@git_lit_mit_ohne_dir:matrix.org joined the room.20:43:02
@git_lit_mit_ohne_dir:matrix.org@git_lit_mit_ohne_dir:matrix.org left the room.21:45:16
10 Dec 2023
@joepie91:pixie.town@joepie91:pixie.towndon't know if this is something we need to care about, but apparently Debian folks ran into an ext4 data corruption bug: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=105784300:55:53
@joepie91:pixie.town@joepie91:pixie.town'tis the season, apparently00:55:57
@raitobezarius:matrix.orgraitobezariusalready mitigated AFAIK00:56:17
@/yvan:matrix.org@/yvan:matrix.org changed their display name from Yvan Sraka to Yvan Sraka (old).10:56:21
@rootname:matrix.org@rootname:matrix.org joined the room.12:06:33
@r_i_s:matrix.orgris_ would appreciate some reviews of outstanding 23.05 security PRs before we hit the deadline and someone comes along and closes them all 12:31:47
@ctheune:matrix.flyingcircus.ioTheuni ris_: i can do some on monday. Is there a list i can link to? 13:31:32
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+base%3Arelease-23.05+base%3Astaging-23.05+label%3A%221.severity%3A+security%2213:34:20
@ctheune:matrix.flyingcircus.ioTheuniThanks13:49:58
@-jb:matrix.org@-jb:matrix.org joined the room.15:42:57
@fiioul:matrix.orgfiioul joined the room.17:02:59
11 Dec 2023
@ctheune:matrix.flyingcircus.ioTheuni ris_: hexa i'm reviewing stuff now and have an update/fix for https://github.com/NixOS/nixpkgs/pull/267565 07:44:11
@ctheune:matrix.flyingcircus.ioTheuniwhat's the workflow for me as a non-committer to update that PR?07:44:22
@k900:0upti.meK900Submit a new PR and mark it as "fixes #whatever"07:46:16
@ctheune:matrix.flyingcircus.ioTheuniack07:47:20
@ctheune:matrix.flyingcircus.ioTheuniin other news: https://github.com/NixOS/nixpkgs/pull/273117 should be fine and could be merged IMHO07:47:28
@ctheune:matrix.flyingcircus.ioTheuniI replaced the yt-dlp PR with this one: https://github.com/NixOS/nixpkgs/pull/27349307:54:11
@ctheune:matrix.flyingcircus.ioTheuniI think it isn't running any checks because the PR comes from my personal fork. I guess someone needs to poke the checks manually in that case?07:54:35
@ctheune:matrix.flyingcircus.ioTheuni ris_: hexa there were only two open reviews. they're both good now, hope this has helped! 07:54:58
@vcunat:matrix.orgvcunatOfBorg isn't that fast.07:55:36
@ctheune:matrix.flyingcircus.ioTheunifeel free to poke me for further reviews, i think i'll have some spare moments like this until the end of the year and should be able to help out with the 23.05 backports.07:56:03
@ctheune:matrix.flyingcircus.ioTheuni¯\_(ツ)_/¯ alright 🙂07:56:09

Show newer messages


Back to Room ListRoom Version: 6