!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

691 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
24 Sep 2025
@lennart:0520.chlennart
In reply to @lennart:0520.ch
Zammad release notes are yet to be released, I guess that will open in the next 2-4 hours https://github.com/NixOS/nixpkgs/pull/445709

three Security Advisories linkes

- https://zammad.com/en/advisories/zaa-2025-07
- https://zammad.com/en/advisories/zaa-2025-08
- https://zammad.com/en/advisories/zaa-2025-09

09:55:49
@lennart:0520.chlennart* three Security Advisories linked - https://zammad.com/en/advisories/zaa-2025-07 - https://zammad.com/en/advisories/zaa-2025-08 - https://zammad.com/en/advisories/zaa-2025-09 09:56:01
30 Sep 2025
@hexa:lossy.networkhexahttps://www.freeipa.org/release-notes/4-12-5.html16:03:10
@hexa:lossy.networkhexareleased a few hours ago16:04:56
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/44751216:06:54
@mjolnir:nixos.orgNixOS Moderation Bot banned @joepie91:pixie.town@joepie91:pixie.town (divsive behavior).19:23:47
@saiko:knifepoint.net@saiko:knifepoint.net left the room.19:27:19
1 Oct 2025
@mtheil:scs.ems.hostMarkus Theilhttps://github.com/NixOS/nixpkgs/pull/44771311:52:59
@mtheil:scs.ems.hostMarkus TheilWill do the backport for 25.05 later today.11:53:08
@mtheil:scs.ems.hostMarkus Theil(currently at work)11:54:05
@mtheil:scs.ems.hostMarkus TheilOpenSSL 3.6 was released some minutes ago. Shall we directly switch 3.5.2 -> 3.6.0 in unstable?18:22:35
@magic_rb:matrix.redalder.org@magic_rb:matrix.redalder.org left the room.18:23:17
@k900:0upti.meK900staging, but presumably yes?18:25:55
@k900:0upti.meK900Unless it breaks shit again18:25:58
@k900:0upti.meK900Which openssl minor updates tend to18:26:03
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)I am also still waiting for github.com/HDFGroup/hdf5/milestone/10, they pushed it back from sep 29th to nov 3rd, which is a pain. There is security fixes in there, and i somewhat doubt it'll get upstream backports to 1.14.x....18:28:47
@mtheil:scs.ems.hostMarkus Theilhttps://github.com/NixOS/nixpkgs/pull/44780818:56:39
@mtheil:scs.ems.hostMarkus TheilI'm currently doing some short smoke tests on the backport branch.18:56:55
3 Oct 2025
@soundhead:matrix.orgsoundhead joined the room.05:12:02
@hexa:lossy.networkhexahttps://www.fetchmail.info/fetchmail-SA-2025-01.txt20:22:39
@hexa:lossy.networkhexa* https://www.fetchmail.info/fetchmail-SA-2025-01.txt no maintainer20:22:57
@pyrox:pyrox.devdish [Fox/It/She]I'd drop if there's no maintainer and security problems. It's not used anywhere in-tree, so 🤷20:47:27
@pyrox:pyrox.devdish [Fox/It/She] yeah fetchmail_7 hasn't been updated since it was added to the tree in 2022, and fetchmail lost its only maintainer in 2021, and only got updates thanks to r-ryantm. 20:49:05
@pyrox:pyrox.devdish [Fox/It/She] yeah fetchmail_7 hasn't been updated since it was added to the tree in 2022, and fetchmail lost its only maintainer in 2021, and only got updates thanks to r-ryantm. 20:49:11
@pyrox:pyrox.devdish [Fox/It/She]i think a drop would be the best choice, since it doesnt seem that anyone cares about it20:49:24
@pyrox:pyrox.devdish [Fox/It/She]no open issues for it either, so if it doesn't build no one's reported it.20:49:59
@pyrox:pyrox.devdish [Fox/It/She]making a pr to drop both.20:50:04
@pyrox:pyrox.devdish [Fox/It/She]https://github.com/nixos/nixpkgs/pull/44833320:52:58
@pyrox:pyrox.devdish [Fox/It/She]I don't believe this warrants a release note due to the obscurity of the package, if someone disagrees I'm glad to add one20:53:29
@hexa:lossy.networkhexanot really obscure https://repology.org/project/fetchmail/versions20:54:32

Show newer messages


Back to Room ListRoom Version: 6