| 2 Jul 2021 |
hexa | just so that the state of these things becomes more visible | 18:31:15 |
philipp | Maybe a separate room just for them? | 18:32:25 |
hexa | maybe a separate room for the chit chat? 😊 | 18:32:52 |
balsoft | I would love a room with advisories | 18:32:54 |
hexa | I don't mind either | 18:33:06 |
hexa |
getxmp() was added in Pillow 8.2.0. It will now use defusedxml instead. If the dependency is not present, an empty dictionary will be returned and a warning raised.
| 18:33:28 |
hexa | alas we are not propagating defusedxml there | 18:33:53 |
hexa | uh, not ours strictly I guess | 18:34:08 |
hexa | just things we find | 18:34:12 |
hexa | * just things we find, and need to remember to take care of | 18:34:20 |
hexa | but sure, we could have an advisory channel, with moderated posts to the pr trackers I guess | 18:44:38 |
hexa | so not advisories per se, but "here is this security related pr, take note" | 18:45:14 |
| julm joined the room. | 18:52:24 |
| 5 Jul 2021 |
| bcdarwin joined the room. | 02:54:12 |
| jceb joined the room. | 11:21:13 |
hexa | https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/ | 19:01:50 |
hexa | are we on top of those? | 19:01:53 |
hexa | the mitre CVE for libuv is still RSVD. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22918 | 19:02:23 |
hexa | relates to this commit https://github.com/nodejs/node/commit/d33aead28bcec32a2a450f884907a6d971631829 | 19:02:45 |
hexa | https://github.com/NixOS/nixpkgs/pull/129360 now we do | 19:18:56 |
hexa | * https://github.com/NixOS/nixpkgs/pull/129360 now we are | 19:19:00 |
| spacesbot - keeps a log of public NixOS channels joined the room. | 19:19:39 |
hexa | * relates to this commit https://github.com/libuv/libuv/commit/b7466e31e4bee160d82a68fca11b1f61d46debae | 19:19:39 |
hexa | now still wondering if we use the vendored libuv in our node package: https://github.com/nodejs/node/commit/d33aead28bcec32a2a450f884907a6d971631829 | 19:19:52 |
hexa | looks like we don't. | 19:20:56 |
| spacesbot - keeps a log of public NixOS channels | 19:49:33 |
| nf changed their profile picture. | 23:32:34 |
| 6 Jul 2021 |
| nurelin joined the room. | 11:42:30 |
hexa | https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-c3hj-rg5h-2772
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-5452-hxj4-773x | 13:59:28 |
hexa | * https://nvd.nist.gov/vuln/detail/CVE-2021-32718
https://nvd.nist.gov/vuln/detail/CVE-2021-32719 | 14:00:22 |