!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

639 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22200 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
17 May 2025
@qyliss:fairydust.spaceAlyssa RossStill looking for Darwin testing on the Meson upgrade https://github.com/NixOS/nixpkgs/pull/40275208:37:33
@qyliss:fairydust.spaceAlyssa RossBut this is the wrong room08:44:58
@ma27:nicht-so.sexyma27

OK we don't have to do anything btw: the advisory states

Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39)

the commit is from 2023 and part of the glibc we're shipping.

08:58:36
@k900:0upti.meK900https://github.com/google/security-research/security/advisories/GHSA-qx2m-rcpc-v43v12:23:49
@k900:0upti.meK900Ayylmao12:24:09
@tgerbet:matrix.orgtgerbetFixed in https://github.com/NixOS/nixpkgs/pull/400278 and https://github.com/NixOS/nixpkgs/pull/403432 It looks like they did not update the fixed version field in the advisory12:26:11
@k900:0upti.meK900Ayylmao, but different 12:27:29
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)https://github.com/NixOS/nixpkgs/pull/401409 I still have an open security fix PR that noone seems to want to review...14:29:27
@oddlama:matrix.orgoddlama changed their display name from oddlama to Malte.20:12:23
18 May 2025
@k900:0upti.meK900https://www.mozilla.org/en-US/security/advisories/mfsa2025-36/14:06:39
@k900:0upti.meK900 @hexa:lossy.network 14:06:43
@me:linj.techlinjfixed in https://github.com/NixOS/nixpkgs/pull/40823614:07:52
@k900:0upti.meK900Cool 14:08:29
@hexa:lossy.networkhexastill testing on 24.1114:08:58
19 May 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)Can we get a merge on https://github.com/NixOS/nixpkgs/pull/408524? Its analogous to the firefox update and i'd really rather have that.... Yes yes, we are on topic with browser forks, but i can't commit this (yet)14:56:55
@oak:universumi.fioak 🏳️‍🌈♥️ changed their display name from oak 🫱⭕🫲 to oak.10:59:05
@hexa:lossy.networkhexa note that we started requiring an active committer on the maintainers list for browsers cough 14:57:48
@oak:universumi.fioak 🏳️‍🌈♥️ changed their display name from oak to oak 🏳️‍🌈♥️.11:00:52
@emilazy:matrix.orgemilyonly for new ones, I think14:58:09
@hexa:lossy.networkhexa* note that we started requiring an active committer on the maintainers list for browsers 😉14:58:33
@hexa:lossy.networkhexanope, we don't do grandfathering for security14:58:47
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)

I agree that different standards for new vs. existing packages doesn't make sense

make me committer then :P

14:59:02
@hexa:lossy.networkhexasmh14:59:13
@hexa:lossy.networkhexa #security-discuss:nixos.org if you want to continue the banter 😜 14:59:47
@emantor:stratum0.orgEmantor changed their profile picture.19:32:12
20 May 2025
@emilazy:matrix.orgemilyhttps://github.com/NixOS/nixpkgs/pull/409063 https://github.com/NixOS/nixpkgs/pull/40906413:12:40
@emilazy:matrix.orgemily"Patches to fix CVE-2017-12921 and CVE-2017-12925 and possibly CVE-2017-12920." always a good time when the changelog isn't even sure they fixed the CVE13:13:06
@hexa:lossy.networkhexathis is imagemagick, you can always assume a vulnerability lingering13:16:33
@emilazy:matrix.orgemily(fixed aliases merge conflict 🙃)13:24:32

Show newer messages


Back to Room ListRoom Version: 6