!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

690 Members
Coordination and triage of security issues in nixpkgs216 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
30 Jun 2025
@daniel:routing.rocksdan_nrw changed their profile picture.17:17:27
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/pull/42131419:31:01
@h0nig2k:matrix.orgh0nig2kpython setuptools CVE 7.7 (only 25.05): https://github.com/NixOS/nixpkgs/pull/42134321:18:40
@h0nig2k:matrix.orgh0nig2k* python setuptools CVE 7.7 (only 25.05): https://github.com/NixOS/nixpkgs/pull/42135021:48:50
1 Jul 2025
@djacu:matrix.orgdjacu joined the room.03:29:06
@djacu:matrix.orgdjacuHey Security Team In case you haven't seen the recent post on discourse, the Marketing Team is preparing this year's community survey. I am reaching out to teams to see if there are any questions they would like to add to the survey to better serve the work you all do. More details in the post linked below. https://discourse.nixos.org/t/community-feedback-requested-2025-nix-community-survey-planning/6615503:29:17
@thefossguy:matrix.orgPratham Patel changed their display name from Pratham Patel (you can mention me) to Pratham Patel.05:10:22
@hexa:lossy.networkhexa https://openssl-library.org/news/secadv/20250522.txt Markus Theil 12:17:09
@mtheil:scs.ems.hostMarkus TheilThx for the hint. Will add a PR this evening.13:57:22
@mtheil:scs.ems.hostMarkus TheilAll mentioned CVEs are also fixed in the PR for 3.5.0 already merged to staging. Currently used version 3.4.x are not affected.13:58:26
@sigmasquadron:matrix.orgSigmaSquadronXSA #470: https://github.com/NixOS/nixpkgs/pull/42151414:19:12
@sigmasquadron:matrix.orgSigmaSquadron * XSA #470: https://github.com/NixOS/nixpkgs/pull/421514 14:19:50
@emilazy:matrix.orgemilyon it. does it need backporting?14:39:36
@zororg:matrix.orgzororg joined the room.14:55:33
@mtheil:scs.ems.hostMarkus Theilhttps://github.com/NixOS/nixpkgs/pull/421531 is still compiling on my side. Will ping here, when ready and some smoke tests are done.15:33:21
@sigmasquadron:matrix.orgSigmaSquadron
In reply to @emilazy:matrix.org
on it. does it need backporting?
yep, forgot the label, sorry.
15:57:16
@dues__:matrix.orgDamian Poddebniak joined the room.20:54:51

Show newer messages


Back to Room ListRoom Version: 6