| 7 Feb 2025 |
Niklas Korz | Not sure if this qualifies for the security label, but as it gets rid of another .NET 6 dependency I guess it might:
https://github.com/NixOS/nixpkgs/pull/380045 | 10:03:29 |
| 8 Feb 2025 |
| Marcel joined the room. | 20:27:55 |
| 9 Feb 2025 |
| @tired:fairydust.space left the room. | 22:50:32 |
| 10 Feb 2025 |
| phelix | 3383 changed their display name from phelix 3383 to phelix. | 01:03:49 |
| 11 Feb 2025 |
Tom | seems to be happening just now Markus Theil | 14:49:44 |
Markus Theil | Yes, PR is already updated for unstable/staging. Now backport to 24.11 is WIP on my side. | 14:52:22 |
hexa | https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250211 | 17:38:50 |
hexa | flx: | 17:38:55 |
| 12 Feb 2025 |
| arcayr joined the room. | 02:50:55 |
| 15 Feb 2025 |
| BenjB83 joined the room. | 10:19:19 |
| BenjB83 changed their display name from Benjamín Buske to BenjB83. | 10:43:19 |
| 16 Feb 2025 |
| aloisw changed their profile picture. | 10:14:33 |
Niklas Korz | https://github.com/indutny/elliptic/security/advisories/GHSA-vjh7-7g9h-fjfh
no idea how to find out what of nixpkgs might potentially be affected, but it has 3063 dependents on npm so there's a good chance it's not zero | 10:42:32 |
Niklas Korz | it doesn't appear to be included in nodePackages at least | 10:48:51 |
Niklas Korz | never mind, it is | 10:50:07 |
| @steeringwheelrules:tchncs.de joined the room. | 15:49:30 |
hexa | https://www.postgresql.org/message-id/173945575457.197393.6175786842655230205%40wrigleys.postgresql.org https://www.postgresql.org/about/news/postgresql-173-167-1511-1416-and-1319-released-3015/
ma27
| 16:37:38 |
vcunat | https://github.com/NixOS/nixpkgs/pull/382282 | 16:38:33 |
ma27 | WIP already: https://github.com/NixOS/nixpkgs/pull/382282 | 16:38:35 |
hexa | I suck at searching the PR tracker, sowwy 😄 | 16:39:35 |
| 17 Feb 2025 |
Sandro | in:title is usually required to find things | 17:54:09 |
| 18 Feb 2025 |
hexa | https://www.openwall.com/lists/oss-security/2025/02/18/1 | 11:39:02 |
hexa | openssh | 11:39:05 |
Arian | VerifyHostKeyDNS is not enabled by default on nixos right | 11:41:20 |
Niklas Korz | no, but there are at least some public configs enabling it: https://grep.app/search?f.lang=Nix&f.lang.pattern=nix&q=VerifyHostKeyDNS | 11:44:04 |
Arian | I definitely had it enabled in my homelab before because if was using SSHFP | 11:45:11 |
Niklas Korz | oh, NuschtOS enables it by default (cc Sandro 🐧 👀) | 11:45:16 |
Sandro | https://www.openssh.com/releasenotes.html#9.9p2 | 12:10:24 |
Sandro | I don't see a PR yet | 12:11:53 |
tgerbet | I'm running the tests right now | 12:45:25 |