!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

686 Members
Coordination and triage of security issues in nixpkgs214 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
22 Jul 2025
@emilazy:matrix.orgemilyRedacted or Malformed Event02:17:50
@emilazy:matrix.orgemilyoops02:17:52
@emilazy:matrix.orgemily😅 there's a reason we have the "browsers have committer among maintainers" rule02:18:14
@emilazy:matrix.orgemily(but unfortunately the committer who volunteered for Edge hasn't reviewed/merged any PRs)02:18:30
@jonhermansen:matrix.orgjonhermansenThanks emily. Is there anything else I should do there?02:20:44
@emilazy:matrix.orgemily just have to wait for someone to merge. but in the long run there'll need to be an active committer involved in the package to sustainably merge security updates; pretty much every browser update has CVEs. (should probably move to #security-discuss:nixos.org for extended discussion) 02:23:29
23 Jul 2025
@implr:hackerspace.plimplr set a profile picture.10:57:46
@implr:hackerspace.plimplr changed their profile picture.11:21:44
@transcaffeine:finallycoffee.eutranscaffeine https://github.com/NixOS/nixpkgs/pull/427778 snipe-it (due to livewire's CVE-2025-54068) 15:46:29
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) Marking all the libsoup_2_4 vulnerabilities:
https://github.com/NixOS/nixpkgs/pull/427813
(following the conversation in #dev:nixos.org )
17:31:29
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) * Marking all the libsoup_2_4 vulnerabilities, should wait for Jan to ack this:
https://github.com/NixOS/nixpkgs/pull/427813
(following the conversation in #dev:nixos.org )
17:31:46
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) * Marking all the libsoup_2_4 vulnerabilities, should wait for Jan Tojnar to ack this but figured i might as well put it here:
https://github.com/NixOS/nixpkgs/pull/427813
(following the conversation in #dev:nixos.org )
17:32:04
24 Jul 2025
@tgerbet:matrix.orgtgerbet

GLIBC-SA-2025-0005 cc ma27

https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0005;h=8bcccc59a546800624576e3a835b759d9ad1f1e0;hb=HEAD

06:53:09
@vcunat:matrix.orgvcunatThis doesn't seem very serious, fortunately.07:01:27
@ma27:nicht-so.sexyma27preparing an update anyways.08:06:33
@h0nig2k:matrix.orgh0nig2kdoes someone already have sqlite CVE 9.8 CVE-2025-6965 this on his/her radar? https://github.com/NixOS/nixpkgs/issues/42803312:30:15

Show newer messages


Back to Room ListRoom Version: 6