| 8 Jun 2021 |
Alyssa Ross | this is how you get somebody to care | 11:45:52 |
Alyssa Ross | would you notice if a random package you used didn't have a maintainer? I wouldn't. | 11:46:09 |
das_j | yeah, probably. I'll add the knownVulns to master and add the backport labels | 11:46:13 |
hexa | great, thank you | 11:47:30 |
das_j | btw, should I ping the security team in the future for PRs like this? | 11:50:39 |
das_j | because I just requested a review of hexa in this PR | 11:50:51 |
Alyssa Ross | that's my first time merging a PR with the backport labels -- do I need to do anything else or is the backport entirely automatic now? | 11:51:20 |
Linux Hackerman | The backport PR should be opened and linked automatically after the merge | 11:51:49 |
Linux Hackerman | it does still need a manual merge | 11:52:02 |
Alyssa Ross | okay, cool | 11:53:08 |
Alyssa Ross | hmm, no backport PR yet? | 11:54:16 |
Alyssa Ross | I'd have expected it to be pretty instant? | 11:54:23 |
hexa | das_j: I'm not too sure about the security team, is it more than one person, that has too many stakes in everything anyway? | 11:54:35 |
das_j | it's graham and domen | 11:55:02 |
hexa | Alyssa Ross: takes rougly 4-5m as the action needs to clone nixpkgs first | 11:55:03 |
hexa | oh, it's domen? I didn't know | 11:55:14 |
das_j | or is it the other team? | 11:55:28 |
das_j | https://github.com/orgs/NixOS/teams/security | 11:55:35 |
das_j | vs | 11:55:39 |
Alyssa Ross | ahh okay that makes sense | 11:55:39 |
das_j | https://github.com/orgs/NixOS/teams/security-notifications | 11:55:40 |
hexa | https://nixos.org/community/teams/security.html | 11:56:18 |
das_j | lol the members on the website don't match up with any of the two teams | 11:57:15 |
das_j | ah maybe the security-notifications team | 11:57:33 |
das_j | Alyssa Ross: the backports were just created | 11:57:53 |
das_j | * Alyssa Ross: the backports were created just now | 11:57:58 |
hexa | everything merged | 12:00:05 |
hexa | thanks for taking care of that | 12:00:07 |
das_j | fyi, don't delete your branch before the backports were created: https://github.com/NixOS/nixpkgs/pull/126193#issuecomment-856704261 | 12:04:10 |
Alyssa Ross | that's annoying -- the action shouldn't need the branch | 12:04:54 |