!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

756 Members
Coordination and triage of security issues in nixpkgs235 Servers

Load older messages


SenderMessageTime
2 Jun 2026
@robert:funklause.dedotlambdaand https://github.com/NixOS/nixpkgs/pull/52450715:27:32
@monokles:matrix.monokles.eumonokles joined the room.16:10:45
3 Jun 2026
@samuel.dionne-riel:cyberus-technology.deSamuel Dionne-Riel

the following PRs may need to be labeled with the security label:

  • https://github.com/NixOS/nixpkgs/pull/468076
  • https://github.com/NixOS/nixpkgs/pull/514056
  • https://github.com/NixOS/nixpkgs/pull/507810
21:06:44
4 Jun 2026
@jkarlson:kapsi.fiEmil Thorsøewow, openvpn has been marginally vulnerable since 2026-04-2203:46:53
@callmeecho:matrix.orgEcho changed their profile picture.04:23:41
@k900:0upti.meK900 libinput RCE-ish: https://gitlab.freedesktop.org/libinput/libinput/-/releases/1.31.3 06:54:31
@k900:0upti.meK900Will do a PR in a bit06:54:37
@k900:0upti.meK900 https://github.com/NixOS/nixpkgs/pull/527861 07:07:08
@k900:0upti.meK900 (don't merge yet, waiting for 26.05 backport for previous update) 07:07:34
@arias:arialocke.gayarias 🏳️‍⚧️ joined the room.21:50:55
5 Jun 2026
@stigo:matrix.orgstigo https://github.com/NixOS/nixpkgs/pull/528021 <- perl issues 10:46:52
@zimbatm:numtide.comJonas Chevalier left the room.11:40:58
6 Jun 2026
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q2/822 freetype01:20:35
@whispers:catgirl.cloudwhispers [& it/fae]^ attempt at https://github.com/NixOS/nixpkgs/pull/52865203:54:33
@jkarlson:kapsi.fiEmil ThorsøeCan you elaborate on RCE, I see local privilege escalation?04:24:23
@k900:0upti.meK900 I can't read 07:35:06
7 Jun 2026
@arcayr:mischief.expertarcayri think the apache team figure cve-2026-49975 isn't worth a proper release, so my pr with the debian patches for it is probably going to be it for a while02:31:14
@arcayr:mischief.expertarcayrare we okay to fetchpatch2 from debian directly or would it be preferred to host the patches02:31:25
@arcayr:mischief.expertarcayri originally hosted them but figured it looks a bit more reliable and legitimate if they're actually from debian, idk02:31:57
@arcayr:mischief.expertarcayr * 02:32:06
@arcayr:mischief.expertarcayr * 02:32:13
@hexa:lossy.networkhexafetchpatch is fine02:37:47
@vcunat:matrix.orgvcunatFrom Debian you probably fetchurl, as they have it as a *file* in git.05:56:37
9 Jun 2026
@hexa:lossy.networkhexa Markus Theil are you doing the openssl updates? and 4.0? 12:05:38
10 Jun 2026
@arcayr:mischief.expertarcayrhttps://github.com/NixOS/nixpkgs/pull/530173 2.4.67 -> 2.4.68. killed my prev patch. also adds me back to maintainers.nix because nobody else is maintaining apache.01:55:05
@hugo:okeso.euHugo joined the room.13:42:05
@tgerbet:matrix.orgtgerbetI already had opened https://github.com/NixOS/nixpkgs/pull/529675 but let's go with your if you had yourself as the maintainer :) (Also please it's helpful if PRs with security fixes have the security label + the backport labels)18:23:34
11 Jun 2026
@arcayr:mischief.expertarcayrdon't think i could label stuff until now, i tried previously to tag something else as security and couldn't.02:30:37
@arcayr:mischief.expertarcayrguessing it's because i wasn't in the org.02:30:41
@arcayr:mischief.expertarcayrprevious apache patch actually is what i tried to tag02:30:56

Show newer messages


Back to Room ListRoom Version: 6