!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

685 Members
Coordination and triage of security issues in nixpkgs214 Servers

Load older messages


SenderMessageTime
18 Feb 2025
@tgerbet:matrix.orgtgerbetI'm running the tests right now12:45:25
@stites:matrix.org@stites:matrix.org left the room.12:54:35
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/pull/38309613:07:40
@emilazy:matrix.orgemily I believe VerifyHostKeyDNS is only safe if you are running a DNSSEC-validating resolver locally. caveat emptor 18:49:56
@emilazy:matrix.orgemily(I mean, even post-fix.)18:50:01
@leona:leona.isleonafun with grub https://www.openwall.com/lists/oss-security/2025/02/18/319:15:47
@hexa:lossy.networkhexaunmaintained … rip19:29:09
19 Feb 2025
@sss:matrix.dark-alexandr.netsss 20:06:15
@hexa:lossy.networkhexa https://www.openwall.com/lists/oss-security/2025/02/19/1 exim @[0x4A6F] 23:28:01
@hexa:lossy.networkhexa
In reply to@leona:leona.is
fun with grub https://www.openwall.com/lists/oss-security/2025/02/18/3
[SECURITY PATCH 00/73] GRUB2 vulnerabilities - 2025/02/18, Daniel Kiper <=

<del>let's just casually apply this 73 patches</del>
23:29:47
@hexa:lossy.networkhexa
[SECURITY PATCH 00/73] GRUB2 vulnerabilities - 2025/02/18, Daniel Kiper <=

let's just casually apply this 73 patches
23:29:52
@hexa:lossy.networkhexa
[SECURITY PATCH 00/73] GRUB2 vulnerabilities - 2025/02/18, Daniel Kiper <=

let's just casually apply these 73 patches
23:29:59
@tgerbet:matrix.orgtgerbet

I gave it a try https://github.com/NixOS/nixpkgs/pull/383375

Something breaks nixosTests.grub, still need to identify what...

23:30:00
@hexa:lossy.networkhexabold, you even broken tree-sitter (github diff)23:30:34
@hexa:lossy.networkhexaah nvm, that's actually commented23:30:47
21 Feb 2025
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/367821#issuecomment-267299984300:15:44
@alexandi:matrix.orgalexandi joined the room.06:53:38
@mtheil:scs.ems.hostMarkus Theilhttps://github.com/cisco/openh264/security/advisories/GHSA-m99q-5j7x-7m9x20:17:47
@mtheil:scs.ems.hostMarkus Theilhttps://github.com/NixOS/nixpkgs/pull/38403320:24:42
23 Feb 2025
@hiengyen:matrix.orgTrungHieu joined the room.08:27:37
@linucifer:envs.net@linucifer:envs.net removed their profile picture.17:24:48
@linucifer:envs.net@linucifer:envs.net removed their display name linucifer.17:24:54
@linucifer:envs.net@linucifer:envs.net left the room.17:24:56
24 Feb 2025
@alina:kescher.at@alina:kescher.at changed their display name from alina🏳️‍⚧️🐾 to alina, dognitohazard 🏳️‍⚧️🐾.08:57:02
@mtheil:scs.ems.hostMarkus TheilBackport of openh264 was not created automagically, here's the manual one: https://github.com/NixOS/nixpkgs/pull/38471709:53:17
25 Feb 2025
@k900:0upti.meK900Can someone handle https://lists.x.org/archives/xorg/2025-February/061894.html please15:56:42
@k900:0upti.meK900I am extremely low on spoons15:56:47
@hexa:lossy.networkhexa Emantor? 15:59:13
@emantor:stratum0.orgEmantorSure, on it.16:02:52
@emantor:stratum0.orgEmantorHm, tarballs are not on the mirror yet, have asked on IRC.16:10:02

Show newer messages


Back to Room ListRoom Version: 6