!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

747 Members
Coordination and triage of security issues in nixpkgs228 Servers

Load older messages


SenderMessageTime
4 Jun 2021
@hexa:lossy.networkhexain debian people are paid for maintaining things, this is especially true for the lts extensions of their releases18:10:28
@hexa:lossy.networkhexaand following debian releases would mean a change to our release cadence, as else you'd need to support multiple stable releases in parallel - not feasible18:12:35
@hexa:lossy.networkhexathe one month overlap between the old and new stable is annoying enough fwiw18:13:47
@hexa:lossy.networkhexa * the one month overlap between the old and new stable right now is annoying enough fwiw18:13:55
@sandro:supersandro.deSandro
In reply to @hexa:lossy.network
and following debian releases would mean a change to our release cadence, as else you'd need to support multiple stable releases in parallel - not feasible
right now we release two times a year a big release. Debian does once every few years.
18:32:00
@philipp:xndr.dephilippJust to be clear I never said we should change the release schedule, I just wondered whether it would be feasible to use debians patches to keep certain packages around a while longer.18:33:15
@sandro:supersandro.deSandroyou can always just pin the older version and apply the patches yourself but doing a minor or major update is a lot of times easier18:35:42
@hexa:lossy.networkhexa
In reply to @sandro:supersandro.de
right now we release two times a year a big release. Debian does once every few years.
roughly every 2 years
18:44:19
@hexa:lossy.networkhexaapplying the patches yourself implies you can't be an end-user 18:44:33
@sandro:supersandro.deSandro
In reply to @hexa:lossy.network
roughly every 2 years
yeah https://wiki.debian.org/DebianReleases#Production_Releases
18:49:19
@r_i_s:matrix.orgris_ hexa: if a need (and the funding/human-power) for LTS emerged, I'd rather they weren't cast out of the project into a fork, where they would need to set up their own infra, hydra, and cause those who find themselves at the end of a regular release's support to have to consciously switch channels etc. 19:16:34
@r_i_s:matrix.orgris_the worst it would mean for us is more noise in github19:16:53
@hexa:lossy.networkhexaagreed19:17:20
@hexa:lossy.networkhexa * agreed, I just said it could be done outside. Can't do that with debian that easily.19:17:32
@r_i_s:matrix.orgris_sure19:17:37
@hexa:lossy.networkhexaother than that: pay me!19:17:47
@hexa:lossy.networkhexa * other than that: pay me! 😛19:18:08
@r_i_s:matrix.orgris_one day19:18:14
@pennae:matrix.eno.spacepennaeis there an update to postgres 13.3 that we searching nixpkgs? https://security.archlinux.org/AVG-195621:54:29
@pennae:matrix.eno.spacepennae * is there an update to postgres 13.3 that we missed searching nixpkgs? https://security.archlinux.org/AVG-195621:55:15
5 Jun 2021
@hexa:lossy.networkhexa pennae: can you please ping marsam? 02:46:19
@hexa:lossy.networkhexaor … well02:47:17
@hexa:lossy.networkhexabrb02:47:18
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/12575102:57:52
@hexa:lossy.networkhexaI'll let marsam do the reviewing/backporting02:58:02
@hexa:lossy.networkhexathanks for pointing out the issue02:58:18
@pennae:matrix.eno.spacepennaethanks for updating :)02:58:33
@pennae:matrix.eno.spacepennaewould've thought the update bot would pick it up rather quickly02:58:56
@hexa:lossy.networkhexayou mean r-ryantm?03:02:22
@pennae:matrix.eno.spacepennaeyup03:02:45

Show newer messages


Back to Room ListRoom Version: 6