!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

704 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22219 Servers

Load older messages


SenderMessageTime
13 May 2026
@tgerbet:matrix.orgtgerbethttps://nginx.org/en/CHANGES https://nginx.org/en/CHANGES-1.30 There are also other sec issues in the releases nginxMainline will need a 1.29 -> 1.31 bump. It would be nice if someone could handle it, I have done the last nginx upgrades but I'm not close to a laptop until tomorrow night19:23:09
@numinit:matrix.orgMorgan (@numinit)It's looking like a "tonight" thing for me (so several hours)19:23:44
@hexa:lossy.networkhexahttps://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/19:35:01
@hexa:lossy.networkhexa ma27 19:35:22
@sandro:supersandro.deSandro 🐧untested https://github.com/NixOS/nixpkgs/pull/51989319:46:05
@ma27:nicht-so.sexyma27tomorrow if noone's faster22:44:35
14 May 2026
@louis:opter.orglouis joined the room.23:21:54
@louis:opter.orglouis left the room.23:22:37
15 May 2026
@louis:opter.orglouis joined the room.04:50:18
@leona:leona.isleonaRedacted or Malformed Event06:59:27
@leona:leona.isleona https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn/ was again pre-leaked (likely through commit msg + Spengler (as Qualys reported on oss-sec)). Qualys doesn't yet publish their advisory. 07:01:33
@leona:leona.isleona * https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn/ was again pre-leaked (likely through commit msg + LLM + Spengler (as Qualys reported on oss-sec)). Qualys doesn't yet publish their advisory. 07:01:41
@arcayr:mischief.expertarcayrspengler again?07:19:08
@bart:bartoostveen.nlBart https://github.com/NixOS/nixpkgs/pull/517598 12:03:38
@kuflierl:matrix.orgkuflierlhttps://github.com/NixOS/nixpkgs/pull/52064622:58:40

There are no newer messages yet.


Back to Room ListRoom Version: 6