!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

725 Members
Coordination and triage of security issues in nixpkgs223 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
25 Jan 2025
@sandro:supersandro.deSandro Well do in an hour or two 14:14:19
@robert:funklause.dedotlambdaI'm on it. The webvault update requires some manual work16:42:43
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/37676518:08:26
27 Jan 2025
@brisingr05:matrix.orgBrisingr joined the room.02:51:21
@niklaskorz:korz.devNiklas KorzBackport of a high severity fix, accepted by original PR author a week ago: https://github.com/NixOS/nixpkgs/pull/375532#issuecomment-260516018316:18:24
28 Jan 2025
@tomog:matrix.orgtomf joined the room.00:23:57
@tomog:matrix.orgtomfFYI, I see the Woodpecker CI plugin for Nix that's advertised on their site has the author's key in extra-trusted-public-keys. I've raised this as https://github.com/woodpecker-ci/woodpecker/issues/478500:25:06
@tomog:matrix.orgtomfIf Woodpecker is popular, it might be nice if that project ends up in nix-community.00:26:30
@adam:robins.wtf@adam:robins.wtf That’s a third party project and not really something for us to fix. You already reported in their repo so I guess that’s all to be done? It’s a pretty simple plugin if you look through the code, and woodpecker can also run with a local backend allowing access to nix without docker  00:30:43

Show newer messages


Back to Room ListRoom Version: 6