!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

682 Members
Coordination and triage of security issues in nixpkgs214 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
24 Jan 2025
@niklaskorz:korz.devNiklas Korz
In reply to @niklaskorz:korz.dev

Matomo 5.2.2 has "several high-impact security fixes": https://github.com/NixOS/nixpkgs/pull/376385

PR for release-24.11 following in a moment, automatic backport won't work atm because the package has been refactored in master and I'm still working on manually backporting those changes as well (also non-trivial because we dropped matomo 4 in unstable and renamed matomo_5 to matomo)

Manual backport: https://github.com/NixOS/nixpkgs/pull/376389
13:50:44
25 Jan 2025
@mlieberman85:matrix.org@mlieberman85:matrix.org left the room.04:30:20
@aloisw:julia0815.dealoisw changed their profile picture.10:22:09
@hexa:lossy.networkhexahttps://github.com/dani-garcia/vaultwarden/releases/tag/1.33.013:48:24
@hexa:lossy.networkhexa dotlambda Sandro 🐧 13:48:30
@sandro:supersandro.deSandro Well do in an hour or two 14:14:19
@robert:funklause.dedotlambdaI'm on it. The webvault update requires some manual work16:42:43
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/37676518:08:26
27 Jan 2025
@brisingr05:matrix.orgBrisingr joined the room.02:51:21
@niklaskorz:korz.devNiklas KorzBackport of a high severity fix, accepted by original PR author a week ago: https://github.com/NixOS/nixpkgs/pull/375532#issuecomment-260516018316:18:24
28 Jan 2025
@tomog:matrix.orgtomf joined the room.00:23:57
@tomog:matrix.orgtomfFYI, I see the Woodpecker CI plugin for Nix that's advertised on their site has the author's key in extra-trusted-public-keys. I've raised this as https://github.com/woodpecker-ci/woodpecker/issues/478500:25:06
@tomog:matrix.orgtomfIf Woodpecker is popular, it might be nice if that project ends up in nix-community.00:26:30
@adam:robins.wtfadamcstephens That’s a third party project and not really something for us to fix.Ā You already reported in their repo so I guess that’s all to be done? It’s a pretty simple plugin if you look through the code, and woodpecker can also run with a local backend allowing access to nix without dockerĀ  00:30:43
@tomog:matrix.orgtomfYes, I mentioned it as an FYI to the channel, rather than email to security team because I see it's outside of the team's control/responsibility. I'll keep on top of the issues.00:31:29
@adam:robins.wtfadamcstephens Having woodpecker remove it from their list seems reasonableĀ  00:31:48

Show newer messages


Back to Room ListRoom Version: 6