!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

646 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22202 Servers

Load older messages


SenderMessageTime
10 Aug 2025
@cafkafk:fem.ggcafkafk joined the room.19:19:00
12 Aug 2025
@psalden:matrix.org@psalden:matrix.org left the room.06:56:18
13 Aug 2025
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q3/9818:17:03
@hexa:lossy.networkhexa* https://seclists.org/oss-sec/2025/q3/98 nginx18:17:04
@hexa:lossy.networkhexa* https://seclists.org/oss-sec/2025/q3/98 nginx ngx_mail_smtp_module18:17:27
14 Aug 2025
@jh-devv:matrix.org@jh-devv:matrix.org left the room.15:13:56
@h0nig2k:matrix.orgh0nig2khttps://github.com/NixOS/nixpkgs/pull/43375619:24:51
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)https://nvd.nist.gov/vuln/detail/CVE-2025-47807 https://nvd.nist.gov/vuln/detail/CVE-2025-47806 https://nvd.nist.gov/vuln/detail/CVE-2025-47219 https://nvd.nist.gov/vuln/detail/CVE-2025-47183 https://nvd.nist.gov/vuln/detail/CVE-2025-47808 https://github.com/NixOS/nixpkgs/pull/420649 (was already merged, but still putting this here for documentations sake)19:37:21
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)* GStreamer: https://nvd.nist.gov/vuln/detail/CVE-2025-47807 https://nvd.nist.gov/vuln/detail/CVE-2025-47806 https://nvd.nist.gov/vuln/detail/CVE-2025-47219 https://nvd.nist.gov/vuln/detail/CVE-2025-47183 https://nvd.nist.gov/vuln/detail/CVE-2025-47808 https://github.com/NixOS/nixpkgs/pull/420649 (was already merged, but still putting this here for documentations sake)19:42:42
@lt1379:matrix.orgLunhttps://github.com/NixOS/nixpkgs/pull/43376922:45:10
15 Aug 2025
@flipperskip:matrix.org@flipperskip:matrix.org left the room.04:11:40
@sersorrel:matrix.orgsorrel joined the room.09:52:27
16 Aug 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)ImageMagick: CVE-2025-55005: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v393-38qx-v8fp CVE-2025-55004: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cjc8-g9w8-chfw CVE-2025-55160: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hgw-6x87-578x https://github.com/NixOS/nixpkgs/pull/43324913:01:19
@17lifers:matrix.org17lifers (Ryan) joined the room.21:34:16
17 Aug 2025
@maridonkers:matrix.org@maridonkers:matrix.org left the room.19:07:13
22 Aug 2025
@june:nekover.seJune joined the room.02:57:43
@julian:nekover.se@julian:nekover.se left the room.03:09:18
@leona:leona.isleonavalkey security release https://github.com/valkey-io/valkey/releases/tag/8.0.515:00:50
@leona:leona.isleonaas far as i see only affects 25.05. https://github.com/NixOS/nixpkgs/pull/43590515:06:30
@elikoga:matrix.orgelikoga changed their profile picture.17:28:13
@odoom:matrix.orgodoom joined the room.21:33:14
24 Aug 2025
@honnip:matrix.orgHonnip joined the room.13:29:06
25 Aug 2025
@lennart:0520.chlennarthej, could someone who is allowed to delete Issues in NixOS/nixpkgs write me directly? I found a vulnerability in a software, made an issue in nixpkgs which partly was about that vuln. upstream asks to please delete the ticket.09:31:16
@lennart:0520.chlennartmy fuckup…09:31:33
@lennart:0520.chlennartalready wrote hexa, I guess he's sleeping or busy :) https://github.com/orgs/NixOS/people/security_managers09:33:22
@lennart:0520.chlennart lassulus did the dead, thanks 09:35:17
@sigmasquadron:matrix.orgSigmaSquadronwe should consider that security vulnerability leaked to the public already, as there may be an archive of the deleted issue.09:49:01
@sigmasquadron:matrix.orgSigmaSquadron * 09:49:15
@tgerbet:matrix.orgtgerbetUpstream should consider the issue public. Information is likely still accessible in GitHub events Full disclosure is better than half disclosed (and apparently the tendency these days is to publish emboarged issues on public ML 🫠 )10:27:45
@lennart:0520.chlennartIt's not related to nixpkgs, only upstream.10:28:01

Show newer messages


Back to Room ListRoom Version: 6