!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

685 Members
Coordination and triage of security issues in nixpkgs214 Servers

Load older messages


SenderMessageTime
23 Oct 2025
@hexa:lossy.networkhexa* https://www.openwall.com/lists/oss-security/2025/10/23/1 pdns-recursor16:13:55
24 Oct 2025
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its) changed their display name from ⛧-440729 [sophie] (it/its) to ⛧-440729 [sophie raven] (it/its).06:10:51
@hexa:lossy.networkhexahttps://nvd.nist.gov/vuln/detail/CVE-2025-62813 lz410:26:42
@sigmasquadron:matrix.orgSigmaSquadron XSA #476
master: https://github.com/NixOS/nixpkgs/pull/455255
release-25.05:https://github.com/NixOS/nixpkgs/pull/455256
12:42:27
@sigmasquadron:matrix.orgSigmaSquadron * XSA #476
master: https://github.com/NixOS/nixpkgs/pull/455255
release-25.05: https://github.com/NixOS/nixpkgs/pull/455256
12:42:34
@vcunat:matrix.orgvcunatThose issues are private?13:38:51
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/70?13:39:41
@hexa:lossy.networkhexaI'm a security manager on the org and I can't see them either, so probably deleted?13:40:15
@winter:catgirl.cloudWinteri’m an org owner and cannot see them either, my guess is he typo’d?13:49:55
@winter:catgirl.cloudWinteri don’t think you can delete PRs like you can issues13:50:05
@vcunat:matrix.orgvcunatSurely typos. The numbers are significantly beyond what's allocated right now.13:52:58
@tnias:stratum0.orgtniassomeone named sigmasquadron opened those: https://github.com/NixOS/nixpkgs/pull/455225 https://github.com/NixOS/nixpkgs/pull/45522613:53:36
@niklaskorz:matrix.orgniklaskorzTarmageddon tracking issue: https://github.com/NixOS/nixpkgs/issues/455265 The "check manually" part is bigger than I'd have liked (script improvals welcome), but considering there are over 2000 packages that the script handled fine, I think it's still reasonably small.16:20:28
25 Oct 2025
@sigmasquadron:matrix.orgSigmaSquadron * XSA #476
master: https://github.com/NixOS/nixpkgs/pull/455225
release-25.05: https://github.com/NixOS/nixpkgs/pull/455226
03:18:01
@sigmasquadron:matrix.orgSigmaSquadronWhoops, yes. I wrote a 5 when I should've written a 2. Sorry about that; it was late and I went to bed shortly after posting.03:18:37
@sigmasquadron:matrix.orgSigmaSquadron * 03:18:50
26 Oct 2025
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/pull/45594317:42:44
@tgerbet:matrix.orgtgerbetDisputed https://github.com/NixOS/nixpkgs/pull/45594517:43:13
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/455984 fixes two undisclosed vulnerabilities in ImageMagick19:40:54
27 Oct 2025
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/456046 probably fixes a vulnerability in Postfix but there is no official announcement yet01:55:21
@robert:funklause.dedotlambda* https://github.com/NixOS/nixpkgs/pull/455984 fixes two undisclosed vulnerabilities in ImageMagick EDIT: the vulnerability reports were now published01:56:01
@robert:funklause.dedotlambda* https://github.com/NixOS/nixpkgs/pull/455984 fixes two undisclosed vulnerabilities in ImageMagick EDIT: the vulnerability reports are now published01:56:16
@dp:anarchyislove.xyzDustin Plattner changed their display name from Dustin to Dustin Plattner.02:57:36
@amadaluzia:tchncs.de➡️@amadaluzia:unredacted.org joined the room.23:56:26
28 Oct 2025
@k900:0upti.meK900https://www.phoronix.com/news/X.Org-Server-3-Vuln-Oct-2025 Xorg again13:49:07
@k900:0upti.meK900xwayland: https://github.com/NixOS/nixpkgs/pull/456494 Someone else do xorgserver please my brain is very mush16:47:49
@zitrone:utwente.iozitrone joined the room.23:41:42
29 Oct 2025
@mdaniels5757:matrix.orgmdaniels5757Backport, approved by maintainer and containing security fixes: https://github.com/NixOS/nixpkgs/pull/45557000:54:25
2 Nov 2025
@amadaluzia:unredacted.orgamadaluzia (🇹🇷 til 25th) joined the room.22:34:47
@amadaluzia:tchncs.de➡️@amadaluzia:unredacted.org changed their display name from amadaluzia to ➡️@amadaluzia:unredacted.org.22:48:07

Show newer messages


Back to Room ListRoom Version: 6