!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

660 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22204 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
21 Oct 2025
@robert:funklause.dedotlambdaLots of crypto coin-related packages seem to use it, I assume that's security-sensitive. Also duplicity, a backup tool. I'm currently looking at how home-assistant is using it21:25:51
@niklaskorz:matrix.orgniklaskorzhome-assistant project chip only seems to use it for testing indeed21:28:47
@robert:funklause.dedotlambda
In reply to @niklaskorz:matrix.org
home-assistant project chip only seems to use it for testing indeed
You're sure about that?
https://matrix.to/#/!TMHsziEPKwNiZHIoRO:lossy.network/$e12yLxQo1zTojp77HVo2qnv_CpXQaP-PRSndOSHpo3Q?via=nixos.dev
21:34:10
@pyrox:pyrox.devdish [Fox/It/She] of course its crypto coins >.> can never trust those projects to do anything right 22:17:52
@hexa:lossy.networkhexa 👉️ #security-discuss:nixos.org 23:02:04
22 Oct 2025
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/45430302:02:25
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/68 bind916:14:45
23 Oct 2025
@ramblurr:outskirtslabs.comramblurr joined the room.08:55:38
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/10/23/1 pdns16:13:53
@hexa:lossy.networkhexa* https://www.openwall.com/lists/oss-security/2025/10/23/1 pdns-recursor16:13:55
24 Oct 2025
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its) changed their display name from ⛧-440729 [sophie] (it/its) to ⛧-440729 [sophie raven] (it/its).06:10:51
@hexa:lossy.networkhexahttps://nvd.nist.gov/vuln/detail/CVE-2025-62813 lz410:26:42
@sigmasquadron:matrix.orgSigmaSquadron XSA #476
master: https://github.com/NixOS/nixpkgs/pull/455255
release-25.05:https://github.com/NixOS/nixpkgs/pull/455256
12:42:27
@sigmasquadron:matrix.orgSigmaSquadron * XSA #476
master: https://github.com/NixOS/nixpkgs/pull/455255
release-25.05: https://github.com/NixOS/nixpkgs/pull/455256
12:42:34
@vcunat:matrix.orgvcunatThose issues are private?13:38:51
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/70?13:39:41
@hexa:lossy.networkhexaI'm a security manager on the org and I can't see them either, so probably deleted?13:40:15
@winter:catgirl.cloudWinteri’m an org owner and cannot see them either, my guess is he typo’d?13:49:55

Show newer messages


Back to Room ListRoom Version: 6