!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

683 Members
Coordination and triage of security issues in nixpkgs214 Servers

Load older messages


SenderMessageTime
10 Sep 2025
@hexa:lossy.networkhexahttps://kb.cert.org/vuls/id/461364 no new release yet, releases look like code drops02:17:22
@hexa:lossy.networkhexa* https://kb.cert.org/vuls/id/461364 no new release yet, releases look like code drops https://gitlab.com/hsleisink/hiawatha/-/commits/master?ref_type=HEADS02:17:32
@hexa:lossy.networkhexaonly maintainer was removed in 2019 and the package has been carried forth since by r-ryantm02:20:14
@hexa:lossy.networkhexa

Hiawatha is no longer actively supported by the developer, but the developer acknowledges the vulnerabilities and has included mitigations and remediations to all three vulnerabilities in the next release.

02:20:34
@pyrox:pyrox.devdish [Fox/It/She]there aren't any consumers in nixpkgs, nor in any public config repos from a cursory glance at sourcegraph, so since there's no maintainers we could consider dropping02:23:29
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/44164502:24:21
@hexa:lossy.networkhexasame thought02:24:26
@pyrox:pyrox.devdish [Fox/It/She]🫡02:30:22
@pyrox:pyrox.devdish [Fox/It/She]considering a drop is technically breaking, add a nixpkgs release note maybe?02:30:55
@hexa:lossy.networkhexasure, why not.02:33:50
@hexa:lossy.networkhexapushed02:33:51
@pyrox:pyrox.devdish [Fox/It/She]perfect, ty! lgtm02:34:48
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)
In reply to @pyrox:pyrox.dev
considering a drop is technically breaking, add a nixpkgs release note maybe?
We have throws in aliases.nix, IMO package removals are discoverable enough to not need release notes. Our rlnotes are already entirely unreadable and way too verbose...
07:06:21
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q3/160 https://seclists.org/oss-sec/2025/q3/16109:44:45
@pyrox:pyrox.devdish [Fox/It/She]
In reply to @grimmauld:grapevine.grimmauld.de
We have throws in aliases.nix, IMO package removals are discoverable enough to not need release notes. Our rlnotes are already entirely unreadable and way too verbose...
fair
12:09:37
@nerves:bark.lgbt@nerves:bark.lgbt left the room.12:31:55
@sandro:supersandro.deSandroFirst time seeing a test without a module 😅13:06:47
@niklaskorz:matrix.orgniklaskorzthe freshly dropped minecraft package had one too! (oops this is triage, not discussion)13:07:23
@matshch:matrix.orgArtem Leshchev joined the room.16:20:25
@matshch:matrix.orgArtem Leshchev set a profile picture.16:25:49
11 Sep 2025
@k900:0upti.meK900It's a day that ends in Y16:15:35
@k900:0upti.meK900And you know what that means16:15:37
@k900:0upti.meK900New! Intel! Side! Channel! Vulns!16:15:43
@k900:0upti.meK900https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.16.716:15:44
@k900:0upti.meK900Can someone please do the thing16:15:48
@qyliss:fairydust.spaceAlyssa Ross I was wondering why I was seeing even more stable kernels 16:17:31
@adam:robins.wtfadamcstephensAMD is also affected16:25:02
@aloisw:julia0815.dealoiswI love how they already vaguely described this years ago when Spectre was published and yet it took until now to actually fix.16:34:59
@pyrox:pyrox.devdish [Fox/It/She]do we have a "days since CPU side channel vulns" counter16:44:04
@pyrox:pyrox.devdish [Fox/It/She]* do we have a "days since new CPU side channel vuln" counter16:44:08

Show newer messages


Back to Room ListRoom Version: 6