!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

656 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22204 Servers

Load older messages


SenderMessageTime
11 Nov 2024
@k900:0upti.meK900Doing the update, it's probably not quite as bad because the vault is E2EE but still ba04:27:20
@k900:0upti.meK900* Doing the update, it's probably not quite as bad because the vault is E2EE but still bad04:27:21
@k900:0upti.meK900Merged, will run unstable-small now04:53:18
@pyrox:pyrox.devdish [Fox/It/She] i have my suspicions about what the actual security issues were, just reading the code won't speculate though 04:53:47
@pyrox:pyrox.devdish [Fox/It/She] i have my suspicions about what the actual security issues were, just reading the code changes won't speculate though 04:54:03
@pyrox:pyrox.devdish [Fox/It/She]though the comments in one part of the new code do explicitly mention now sanitizing against HTML/XSS injection attacks04:54:32
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/35524017:51:40
12 Nov 2024
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/35540011:38:01
@ma27:nicht-so.sexyma27

https://github.com/grafana/grafana/releases/tag/v11.3.0%2Bsecurity-01

going to prepare & test a PR in about 5min

16:26:16
@hexa:lossy.networkhexahttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-2024111217:25:19
@hexa:lossy.networkhexa @flx-:matrix.org ^ 17:25:31
@flx-:matrix.orgflxOh jesus.17:44:57
@ma27:nicht-so.sexyma27
In reply to @ma27:nicht-so.sexy

https://github.com/grafana/grafana/releases/tag/v11.3.0%2Bsecurity-01

going to prepare & test a PR in about 5min

distracted in between, now opened https://github.com/NixOS/nixpkgs/pull/355481 .
18:10:34
@azahi:azahi.ccazahi changed their profile picture.18:51:18
@shaderoit99:matrix.org@shaderoit99:matrix.org left the room.22:01:44
13 Nov 2024
@yajo:matrix.org@yajo:matrix.org joined the room.07:50:25
@yajo:matrix.org@yajo:matrix.org left the room.07:51:40
@hexa:lossy.networkhexahttps://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/17:44:49
@scrumplex:duckhub.ioScrumplexhttps://github.com/NixOS/nixpkgs/pull/35573320:49:59
@leona:leona.isleona
In reply to @hexa:lossy.network
https://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/
https://github.com/NixOS/nixpkgs/pull/355755
21:31:23
@inayet:matrix.orgInayet joined the room.22:16:33
18 Nov 2024
@k900:0upti.meK900https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.5 another one11:45:48
@k900:0upti.meK900 CC @Sandro 🐧 @dotlambda 11:45:51
@sandro:supersandro.deSandro 🐧I'll do a PR11:46:38
@sandro:supersandro.deSandro 🐧nice https://github.com/vaultwarden11:51:34
@sandro:supersandro.deSandro 🐧https://github.com/NixOS/nixpkgs/pull/35693812:14:25
19 Nov 2024
@shaderoit99:matrix.org@shaderoit99:matrix.org joined the room.03:12:47
@martijn:plebian.nlmartijn changed their display name from martijn to martijn ⚡️.15:40:35
@martijn:plebian.nlmartijn 15:43:13
20 Nov 2024
@inayet:matrix.orgInayet removed their profile picture.00:59:39

Show newer messages


Back to Room ListRoom Version: 6