!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

666 Members
Coordination and triage of security issues in nixpkgs211 Servers

Load older messages


SenderMessageTime
17 May 2025
@aloisw:julia0815.dealoisw The wrapper uses musl and erases LD_LIBRARY_PATH, so NixOS should indeed be unaffected. 05:00:12
@ma27:nicht-so.sexyma27 Agreed.
I'll prepare an update todya nonetheless since people are using nixpkgs to build all kinds of stuff.
08:12:34
@vcunat:matrix.orgvcunat Sounds OK for the normal staging* workflow. 08:34:01
@k900:0upti.meK900What's the plan for the next cycle?08:36:37
@k900:0upti.meK900I've got Mesa 25.1.1 and Qt 6.9.1 next week08:36:51
@qyliss:fairydust.spaceAlyssa RossStill looking for Darwin testing on the Meson upgrade https://github.com/NixOS/nixpkgs/pull/40275208:37:33
@qyliss:fairydust.spaceAlyssa RossBut this is the wrong room08:44:58
@ma27:nicht-so.sexyma27

OK we don't have to do anything btw: the advisory states

Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39)

the commit is from 2023 and part of the glibc we're shipping.

08:58:36
@k900:0upti.meK900https://github.com/google/security-research/security/advisories/GHSA-qx2m-rcpc-v43v12:23:49
@k900:0upti.meK900Ayylmao12:24:09
@tgerbet:matrix.orgtgerbetFixed in https://github.com/NixOS/nixpkgs/pull/400278 and https://github.com/NixOS/nixpkgs/pull/403432 It looks like they did not update the fixed version field in the advisory12:26:11
@k900:0upti.meK900Ayylmao, but different 12:27:29
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)https://github.com/NixOS/nixpkgs/pull/401409 I still have an open security fix PR that noone seems to want to review...14:29:27
@oddlama:matrix.orgoddlama changed their display name from oddlama to Malte.20:12:23
18 May 2025
@k900:0upti.meK900https://www.mozilla.org/en-US/security/advisories/mfsa2025-36/14:06:39
@k900:0upti.meK900 @hexa:lossy.network 14:06:43
@me:linj.techlinjfixed in https://github.com/NixOS/nixpkgs/pull/40823614:07:52
@k900:0upti.meK900Cool 14:08:29
@hexa:lossy.networkhexastill testing on 24.1114:08:58
19 May 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)Can we get a merge on https://github.com/NixOS/nixpkgs/pull/408524? Its analogous to the firefox update and i'd really rather have that.... Yes yes, we are on topic with browser forks, but i can't commit this (yet)14:56:55
@oak:universumi.fioak 🏳️‍🌈♥️ changed their display name from oak 🫱⭕🫲 to oak.10:59:05
@hexa:lossy.networkhexa note that we started requiring an active committer on the maintainers list for browsers cough 14:57:48
@oak:universumi.fioak 🏳️‍🌈♥️ changed their display name from oak to oak 🏳️‍🌈♥️.11:00:52
@emilazy:matrix.orgemilyonly for new ones, I think14:58:09
@hexa:lossy.networkhexa* note that we started requiring an active committer on the maintainers list for browsers 😉14:58:33
@hexa:lossy.networkhexanope, we don't do grandfathering for security14:58:47
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)

I agree that different standards for new vs. existing packages doesn't make sense

make me committer then :P

14:59:02
@hexa:lossy.networkhexasmh14:59:13
@hexa:lossy.networkhexa #security-discuss:nixos.org if you want to continue the banter 😜 14:59:47
@emantor:stratum0.orgEmantor changed their profile picture.19:32:12

Show newer messages


Back to Room ListRoom Version: 6