!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

614 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22193 Servers

Load older messages


SenderMessageTime
25 Nov 2024
@aloisw:kde.org@aloisw:kde.org left the room.18:05:55
26 Nov 2024
@fifteenconcierge:matrix.org@fifteenconcierge:matrix.org removed their profile picture.15:03:53
@fifteenconcierge:matrix.org@fifteenconcierge:matrix.org removed their display name Neco Arc 🇵🇸.15:04:06
@fifteenconcierge:matrix.org@fifteenconcierge:matrix.org left the room.15:41:39
@hexa:lossy.networkhexahttps://about.gitlab.com/releases/2024/11/26/patch-release-gitlab-17-6-1-released/ gitlab16:02:39
@xanderio:bitflip.jetztxanderio
In reply to @hexa:lossy.network
https://about.gitlab.com/releases/2024/11/26/patch-release-gitlab-17-6-1-released/ gitlab
Handling this in #gitlab:nixos.org
16:09:10
27 Nov 2024
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/35946910:52:57
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2024/11/27/1 authentik14:48:27
@hexa:lossy.networkhexahttps://github.com/goauthentik/authentik/security/advisories/GHSA-qxqc-27pr-wgc8 nvm, looks like we're patched14:48:55
@hexa:lossy.networkhexajust not on 24.0514:49:27
@hexa:lossy.networkhexa https://webkitgtk.org/security/WSA-2024-0007.html Jan Tojnar 16:58:18
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2024/11/27/3 jenkins17:01:18
@michael:mikitsu.meMichael
In reply to @hexa:lossy.network
https://github.com/goauthentik/authentik/security/advisories/GHSA-qxqc-27pr-wgc8 nvm, looks like we're patched
That's a different (older) advisory. The timing attack one is https://github.com/goauthentik/authentik/security/advisories/GHSA-2xrw-5f2x-m56j
17:50:12
@jtojnar:matrix.orgJan Tojnar Thanks. https://github.com/NixOS/nixpkgs/pull/35966220:32:28
@stigo:matrix.orgstigo changed their display name from stigo to stigo (away).20:49:37
28 Nov 2024
@denkn:denkn.at𝔇𝔢𝔫𝔎𝔫 changed their display name from DenKn to 𝔇𝔢𝔫𝔎𝔫.10:54:07
@shawn8901:matrix.orgshawn8901 left the room.18:48:42
@shawn8901:matrix.orgshawn8901 joined the room.18:54:10
@Minijackson:matrix.orgMinijacksonRedacted or Malformed Event23:19:46
29 Nov 2024
@lassulus:lassul.uslassulus changed their profile picture.18:30:20
1 Dec 2024
@shawn8901:matrix.orgshawn8901 left the room.00:08:10
@shawn8901:matrix.orgshawn8901 joined the room.00:11:08
@maralorn:maralorn.de@maralorn:maralorn.de left the room.09:24:14
2 Dec 2024
@pyrox:pyrox.devdish [Fox/It/She] changed their profile picture.19:59:17
3 Dec 2024
@stigo:matrix.orgstigo changed their display name from stigo (away) to stigo.00:52:02
@getchoo:matrix.orggetchoo changed their profile picture.06:06:26
@fernsehmuell:matrix.orgfernsehmuell (he/his) joined the room.15:20:58
@fernsehmuell:matrix.orgfernsehmuell (he/his)Hello, everyone. I just stumbled about this: https://discuss.rubyonrails.org/t/rails-html-sanitizer-v1-6-1-addresses-multiple-cves/88092 Gitlab, Redmine, Zammad, Mastodon, Discourse and metasploit use that gem.15:23:43
@teutat3s:pub.solarteutat3shttps://github.com/element-hq/synapse/releases/tag/v1.120.216:56:21
6 Dec 2024
@cafkafk:fem.ggcafkafk 🏳️‍⚧️ changed their profile picture.03:43:51

Show newer messages


Back to Room ListRoom Version: 6