!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

748 Members
Coordination and triage of security issues in nixpkgs231 Servers

Load older messages


SenderMessageTime
22 Jul 2021
@r_i_s:matrix.orgris_not tonight23:01:09
@hexa:lossy.networkhexano problem, the issues are not going anywhere23:01:32
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/124502#issuecomment-88194444423:02:12
@hexa:lossy.networkhexathat comment is the most intriguing23:02:29
@r_i_s:matrix.orgris_yeah i saw it - it's probably a good idea all in all23:03:07
23 Jul 2021
@nixinator:nixos.devnixinator
In reply to @mlieberman85:matrix.org
Personally I'm looking at building a tool that can generate SPDX and/or CycloneDX formatted SBOMs based on Nix derivations. I have some thoughts on it but would definitely be interested in bouncing my ideas off of some folks who have more experience in the Nix derivation space.
what do you need?
02:08:37
@gytis-ivaskevicius:matrix.orgGytis IvaskeviciusDoes nixos have some sort of security newsletter? Currently I am subscribing to manjaro one and I feel ashamed for it :D07:04:13
@sandro:supersandro.deSandroNo07:07:15
@mic92:nixos.devMic92There was one on google groups quite some time ago07:49:41
@m:marvid.frSamæ joined the room.08:26:07
@m:marvid.frSamæHi everyone. How can I check that my system (kernel) is patched against CVE-2021-33909? I found this PR https://github.com/NixOS/nixpkgs/pull/131113 related to zen-kernels, but it doesn't clearly answer my question.08:27:59
@janne.hess:helsinki-systems.dedas_j Samæ: It's patched if you updated and rebooted recently. But you could try the exploit from the oss mailing lsit 08:28:45

There are no newer messages yet.


Back to Room ListRoom Version: 6