!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

684 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22208 Servers

Load older messages


SenderMessageTime
7 Apr 2026
@leona:leona.isleonadoesn't matter21:49:54
@leona:leona.isleonait waits anyway for release-25.11 to finish eval. That should happen in the next minutes21:50:09
@leona:leona.isleonaI'm going to sleep too. Someone should trigger an eval for nixos:unstable at some point21:50:28
@leona:leona.isleona* I'm going to bed too. Someone should trigger an eval for nixos:unstable at some point21:50:35
@winter:catgirl.cloudWinter (wait, where is that configured in the jobset?) 21:50:51
@leona:leona.isleonahydra-evaluator only evaluates one jobset at at ime21:51:09
@winter:catgirl.cloudWinter can do that once 25.11 and small are done 21:51:11
@leona:leona.isleona* hydra-evaluator only evaluates one jobset at at time21:51:13
@winter:catgirl.cloudWinter ah, right. wait, just to clarify: did you kick off a -small before i did? 21:51:40
@winter:catgirl.cloudWinterjust don't want to have two in a short period of time, if i have to cancel one i will21:51:53
@leona:leona.isleonaI evaled release-25.11. Then I evaled unstable-small (which just means that it will eval once 25.11 is finished). Your additional eval request for unstable-small merges with mine, so only one eval will be created21:52:56
@leona:leona.isleona* I evaled release-25.11. Then I evaled unstable-small (which just means that it will eval once 25.11 is finished / it gets added to the "eval queue"). Your additional eval request for unstable-small merges with mine, so only one eval will be created21:53:44
@tgerbet:matrix.orgtgerbet Flatpak sandbox escape CVE-2026-34078 + arbitrary file deletion on the host CVE-2026-34079 @getchoo:matrix.org https://github.com/flatpak/flatpak/releases/tag/1.16.4 22:22:00
@bart:bartoostveen.nlBart https://github.com/NixOS/nixpkgs/pull/507753 22:41:10
@bart:bartoostveen.nlBartBuilds on x86_64-linux, should not break any builds theoretically22:41:31
@informatic:hackerspace.plinfowski joined the room.23:35:02
8 Apr 2026
@jammie:matrix.orgJamieMagee set a profile picture.03:42:56
@getchoo:matrix.orggetchoothe above was merged. will hopefully do the 25.11 backport tonight thanks for the heads up :)03:48:44
@k900:0upti.meK900Adjacent XDP update: https://www.phoronix.com/news/XDG-Desktop-Portal-1.20.405:17:20
@me:m4rc3l.deMarcel joined the room.13:11:09
@ar:is-a.catari ❄how about some openssl? https://openssl-library.org/news/secadv/20260407.txt15:08:27
@me:m4rc3l.deMarcel ive created a PR https://github.com/NixOS/nixpkgs/pull/507974 15:50:50
@bart:bartoostveen.nlBart https://github.com/NixOS/nixpkgs/pull/507985 16:15:46
@bart:bartoostveen.nlBart https://github.com/NixOS/nixpkgs/pull/507860 16:16:18
9 Apr 2026
@samuel.dionne-riel:cyberus-technology.deSamuel Dionne-Rielavahi CVEs and mitigation https://github.com/NixOS/nixpkgs/pull/50801214:19:37
@andre4ik3:matrix.organdre4ik3 joined the room.21:49:06
@andre4ik3:matrix.organdre4ik3Hi, would appreciate review/and or merge of https://github.com/NixOS/nixpkgs/pull/508083 for Cockpit CVE-2026-4631 (https://github.com/advisories/GHSA-rq49-h582-83m7)21:49:32
@caverav:matrix.orgcaverav joined the room.22:07:46
@opandddd:matrix.orgSapii joined the room.23:06:48
10 Apr 2026
@tom:dragar.deTomCould someone please take a look at this go bump: https://github.com/NixOS/nixpkgs/pull/508457 Particullary relevant for nixos-25.11 since there it's the default go version.20:35:19

There are no newer messages yet.


Back to Room ListRoom Version: 6