!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

697 Members
Coordination and triage of security issues in nixpkgs217 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
10 Mar 2025
@akechishiro:matrix.orgAkechiShiroHey just a quick update, I did reach out to him regarding the CVE, he did confirm that versions in Nixpkgs are vulnerable, I also saw that some builds fixes are waiting to get build : https://github.com/NixOS/nixpkgs/pull/387730 OfBorg can't build the package, I guess the version bump would come after this PR which fixes some builds15:24:54
@joey:jdigi.net@joey:jdigi.net left the room.15:42:22
@emilazy:matrix.orgemily(he's the sole listed maintainer for LibreOffice, does he plan to handle the CVEs?)15:59:50
@hexa:lossy.networkhexaexactly my question16:12:18
@gaelj:matrix-ga.eljam.esGaƫl joined the room.22:08:06
@akechishiro:matrix.orgAkechiShiroSorry for the delay, he plans to handle the CVE but he's unsure when he can do it22:14:26
11 Mar 2025
@3wy-kra:matrix.uni-hannover.de@3wy-kra:matrix.uni-hannover.de joined the room.16:59:37
12 Mar 2025
@paq:matrix.orgpaq joined the room.09:25:20
@hexa:lossy.networkhexahttps://security.opensuse.org/2025/03/12/below-world-writable-log-dir.html15:30:08
@hexa:lossy.networkhexa

Upstream released a bugfix in version v0.9.0 and a security advisory on GitHub.

15:30:22
@hexa:lossy.networkhexa globin: 15:30:29
@hexa:lossy.networkhexa * globin please 15:30:33

Show newer messages


Back to Room ListRoom Version: 6