!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

759 Members
Coordination and triage of security issues in nixpkgs235 Servers

Load older messages


SenderMessageTime
19 May 2026
@nina.fromm:cyberus-technology.deNina FrommBut that'd be bad for marketing ☝️14:55:59
@hexa:lossy.networkhexa back to #security-discuss:nixos.org, there is nothing to triage here 14:56:53
@grimmauld:m.grimmauld.deGrimmauld (any/all) Ah oops, that didn't show up in PR search at all and also is older than the gimp release (was updated after it was opened), sorry 14:57:13
@todoqki:matrix.orgtodo joined the room.15:41:37
@sandro:supersandro.deSandroBut it isn't even Friday :(20:23:49
@hexa:lossy.networkhexakitty https://db.gcve.eu/vuln/cve-2026-3364220:48:18
@amadaluzia:4d2.orgamadaluzia changed their profile picture.20:56:44
20 May 2026
@hexa:lossy.networkhexahttps://www.drupal.org/psa-2026-05-18 today08:33:03
@hexa:lossy.networkhexa unbound https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/ Scrumplex 09:31:13
@hexa:lossy.networkhexa rsync https://seclists.org/oss-sec/2026/q2/620 balsoft dish [Fox/It/She] 09:31:51
@pyrox:pyrox.devdish [Fox/It/She]
In reply to @hexa:lossy.network
rsync https://seclists.org/oss-sec/2026/q2/620 balsoft dish [Fox/It/She]
working on an update now
12:32:57
@pyrox:pyrox.devdish [Fox/It/She] https://github.com/NixOS/nixpkgs/pull/522245 13:48:57
@pyrox:pyrox.devdish [Fox/It/She]

https://w.on-t.work/activitypub/may-2026-vulnerability

seems like most activitypub servers may have security releases

14:23:00
@hexa:lossy.networkhexa https://seclists.org/oss-sec/2026/q2/630 apparmor Grimmauld (any/all) 16:47:59
@hexa:lossy.networkhexa https://seclists.org/oss-sec/2026/q2/626 pdns Mic92 16:48:39
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q2/625 bind9 (unmaintained)16:48:56
@joerg:thalheim.ioMic92I am not even using pdns.18:33:52
@joerg:thalheim.ioMic92Just a nix-update should be enough on this18:34:33
@leona:leona.isleonabut you are listed as maintainer.18:34:35
@joerg:thalheim.ioMic92I will fix that part18:43:23
@hexa:lossy.networkhexa https://seclists.org/oss-sec/2026/q2/633 cockpit andre4ik3 19:49:36
@andre4ik3:matrix.organdre4ik3It’s not too bad, it’s command injection for authenticated users, but users have shell access anyway as a built-in feature for cockpit. There’s an automatic PR to update to the patched version I’ll test it and merge within the next hour or so. https://github.com/NixOS/nixpkgs/pull/52226419:56:12
21 May 2026
@bart:bartoostveen.nlBart someone else bumped, seems fine https://github.com/NixOS/nixpkgs/pull/522407 09:13:37
@bart:bartoostveen.nlBart https://github.com/NixOS/nixpkgs/pull/522600 10:02:53
@bart:bartoostveen.nlBart https://github.com/NixOS/nixpkgs/pull/522602 manual stable bump, ci complains because this is not a backport 10:03:36
@hythera:matrix.orgHytheraPR is drafted so the maintainer coulnd't merge it themselves. https://github.com/NixOS/nixpkgs/pull/51350814:06:09
@hythera:matrix.orgHythera* PR is drafted so the maintainer couldn't merge it themselve. https://github.com/NixOS/nixpkgs/pull/51350814:06:36
@hythera:matrix.orgHythera* PR is drafted so the maintainer couldn't merge it themself. https://github.com/NixOS/nixpkgs/pull/51350814:07:11
@bonsal2:matrix.orgjayf99 joined the room.18:47:59
22 May 2026
@teutat3s:pub.solarteutat3sdocker version 28 is now officially unmaintained, has not received any updates since November 2025. It's ready to be dropped: https://github.com/moby/moby/commit/941805303910a3749ed8fa9669d078015f6f268c https://github.com/NixOS/nixpkgs/pull/52161113:55:26

Show newer messages


Back to Room ListRoom Version: 6