!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

703 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22218 Servers

Load older messages


SenderMessageTime
11 May 2026
@hexa:lossy.networkhexahttps://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html17:37:29
@hexa:lossy.networkhexa

With luck, 2.93 could be out in a week or so.

17:37:33
@tgerbet:matrix.orgtgerbetRequested an update of the CERT/CC advisory in the internal case...17:40:14
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/51843023:24:08
12 May 2026
@harinn:matrix.orgHarinn joined the room.18:14:40
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/51950218:32:28
13 May 2026
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/51988219:12:05
@numinit:matrix.orgMorgan (@numinit)

https://depthfirst.com/nginx-rift

FYI, nginx 😬, seems to trigger with captures in rewrite

19:15:16
@tgerbet:matrix.orgtgerbethttps://nginx.org/en/CHANGES https://nginx.org/en/CHANGES-1.30 There are also other sec issues in the releases nginxMainline will need a 1.29 -> 1.31 bump. It would be nice if someone could handle it, I have done the last nginx upgrades but I'm not close to a laptop until tomorrow night19:23:09
@numinit:matrix.orgMorgan (@numinit)It's looking like a "tonight" thing for me (so several hours)19:23:44
@hexa:lossy.networkhexahttps://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/19:35:01
@hexa:lossy.networkhexa ma27 19:35:22
@sandro:supersandro.deSandro 🐧untested https://github.com/NixOS/nixpkgs/pull/51989319:46:05
@ma27:nicht-so.sexyma27tomorrow if noone's faster22:44:35

There are no newer messages yet.


Back to Room ListRoom Version: 6