!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

690 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
11 Jan 2025
@hexa:lossy.networkhexawith how you're currently doing it you are also bypassing the cherry-pick check 😄 16:57:59
@hexa:lossy.networkhexa* with how you're currently doing it you are also bypassing the cherry-pick check, because it can't find any references to commits on master/staging/... 😄 16:58:19
@philiptaron:matrix.orgPhilip Taron (UTC-8)Again, happy to do whatever, but I literally cherry-picked the PR commit on top of the staging-24.11 branch. If there's a built-in delay before a PR can be opened against a release branch for security issues, in the immortal words of a certain president, "I'm learning about it right now! Amazing!" I have to go do weekend stuff now, so I'll leave merging/editing/rejecting in all y'all's hands until the evening.17:05:02
@hexa:lossy.networkhexathe master PR is vim: 9.1.0990 -> 9.1.1006 #372980 17:05:55
@hexa:lossy.networkhexathe 24.11 pR is vim: 9.1.0787 -> 9.1.1006 #37298117:06:02
@hexa:lossy.networkhexaso you're hiding at least the 9.1.0787 -> 9.1.0990 commit 17:06:16
@hexa:lossy.networkhexa* the 24.11 PR is vim: 9.1.0787 -> 9.1.1006 #37298117:06:23
@philiptaron:matrix.orgPhilip Taron (UTC-8) I'm still super confused. During the cherry-pick process, I edited the staging commit's description from 9.1.0990 to 9.1.0787 (since when applied on staging-24.11, that's the version it would be upgrading.) Is the assumption that release branches get the full set of PRs backported?! 17:08:44
@hexa:lossy.networkhexaeach individual intermediate commit, yeah17:09:43
@philiptaron:matrix.orgPhilip Taron (UTC-8)Ok, I think I understand.17:12:00
@philiptaron:matrix.orgPhilip Taron (UTC-8)* Ok, I think I understand. I picked the intermediate commits too.17:13:24
@hexa:lossy.networkhexalet's continue on the PR17:16:10
12 Jan 2025
@strutztm:strutztm.de@strutztm:strutztm.de joined the room.00:24:58
13 Jan 2025
@niklaskorz:korz.devNiklas Korz Not sure if these are the same that were fixed in vaultwarden 1.32.7 three weeks ago:
https://chaos.social/@fbausch/113821745299078611
15:28:46
@niklaskorz:korz.devNiklas Korz I think they're all already fixed in the version of vaultwarden we ship 15:29:40
@hexa:lossy.networkhexaearlier15:29:53
@hexa:lossy.networkhexathey were fixed in 1.32.515:30:14
@niklaskorz:korz.devNiklas KorzI see, thanks!15:33:12
14 Jan 2025
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/01/14/4 git 18:14:18
@hexa:lossy.networkhexahttps://kb.cert.org/vuls/id/952657 rsync 18:14:40
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/32201218:14:46
@hexa:lossy.networkhexa* https://github.com/NixOS/nixpkgs/pull/37378418:15:01
@tgerbet:matrix.orgtgerbetCurrently building 2.47.2 :) 18:16:42
@tgerbet:matrix.orgtgerbet* Currently building 2.47.2 :) https://github.com/NixOS/nixpkgs/pull/37378418:31:52
@tgerbet:matrix.orgtgerbet* Currently building 2.47.2 :) https://github.com/NixOS/nixpkgs/pull/37380118:32:10
@aidalgol:matrix.orgaidalgolhttps://www.yubico.com/support/security-advisories/ysa-2025-01/18:44:43
@hexa:lossy.networkhexa

No Yubico hardware is affected.

18:45:16
@hexa:lossy.networkhexapam-u2f18:45:29
@aidalgol:matrix.orgaidalgolAIUI, it's the PAM module for using U2F.18:46:18
@sophie:catgirl.cloudâ›§-440729 [sophie raven] (it/its) changed their profile picture.18:56:36

Show newer messages


Back to Room ListRoom Version: 6