!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

672 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22210 Servers

Load older messages


SenderMessageTime
17 Oct 2024
@joerg:thalheim.ioMic92 changed their display name from Mic3000 to Mic3000 🌋.06:51:46
@joerg:thalheim.ioMic92 changed their display name from Mic3000 🌋 to Mic92.12:22:31
@tom:dragar.deTomLooks like Grafana is doing some sort of securtiy update https://github.com/grafana/grafana/releases https://github.com/grafana/grafana/tags Usually it takes them a few hours until all tags have releases. Haven't looked into what they've fixed17:46:51
@scrumplex:duckhub.ioScrumplexThe mentioned vulnerability hasn't been disclosed yet it seems https://nvd.nist.gov/vuln/detail/CVE-2024-926417:48:09
@ma27:nicht-so.sexyma27(grafana maintainer here) seen it and keeping an eye on my notifications.17:49:20
@scrumplex:duckhub.ioScrumplexWhile we are at the topic of upcoming security fixes. OpenSSL has disclosed a low severity issue here: https://openssl-library.org/news/secadv/20241016.txt They haven't released an update yet as the issue isn't deemed important.17:51:05
@ma27:nicht-so.sexyma27 for grafana: https://github.com/NixOS/nixpkgs/pull/349364
no release for 10.4 yet (on 24.05), so not sure if it's even affected, but I'll monitor.
21:08:53
19 Oct 2024
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.19:11:37
20 Oct 2024
@meebey:matrix.orgmeebey aka Mirco Bauer joined the room.02:46:43
@omega-800:matrix.orgGeorgiy Shevoroshkin joined the room.20:07:29
21 Oct 2024
@adam:robins.wtfadamcstephens https://guix.gnu.org/blog/2024/build-user-takeover-vulnerability/ 12:17:09
@adam:robins.wtfadamcstephens cafkafk has a number of accounts but maybe this one is active?  12:25:52
@cafkafk:gitter.imcafkafkYup12:26:18
@cafkafk:gitter.imcafkafkThis one also is12:26:23
@cafkafk:fem.ggcafkafk joined the room.12:28:53
@emilazy:matrix.orgemily(do they not realize it's identical to the recent Nix vulnerability or are they just avoiding mentioning it?)13:43:52
@hexa:lossy.networkhexaTheophane had been reaching out to Ludo on a few occasions, but now that he is gone no idea if that still happens s14:07:52
@hexa:lossy.networkhexa * 14:07:57
@fabianhjr:matrix.orgFabián Heredia
In reply to @emilazy:matrix.org
(do they not realize it's identical to the recent Nix vulnerability or are they just avoiding mentioning it?)
probably from a PR standpoint there are downsides and no upsides to making that mention/parallel.
18:15:02
@sigmasquadron:matrix.orgSigmaSquadron
In reply to @fabianhjr:matrix.org
probably from a PR standpoint there are downsides and no upsides to making that mention/parallel.
does guix even publicly acknowledge its status as a fork of Nix?
18:54:41
@k900:0upti.meK900It's not really a fork anymore 19:11:04
@k900:0upti.meK900It diverged so far to effectively be its own thing 19:11:19
22 Oct 2024
@swendel:curious.bio@swendel:curious.bio left the room.06:08:49
@willbush:matrix.org@willbush:matrix.org changed their profile picture.09:29:09
@fernsehmuell:matrix.orgfernsehmuell (☎️ 3376 he/him) set a profile picture.18:13:44
23 Oct 2024
@hexa:lossy.networkhexahttps://about.gitlab.com/releases/2024/10/23/patch-release-gitlab-17-5-1-released/16:28:24
@hexa:lossy.networkhexa yaya: 16:29:01
@yaya:uwu.isyaya
In reply to @hexa:lossy.network
https://about.gitlab.com/releases/2024/10/23/patch-release-gitlab-17-5-1-released/
thanks. i'm out of spoons though 😕
16:32:49
@hexa:lossy.networkhexa srhb maybe? 16:32:58
@ma27:nicht-so.sexyma27 also cc osnyx (he/him) - don't feel pressured, just in case you still have spoons left for today :) 16:35:50

Show newer messages


Back to Room ListRoom Version: 6