!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

743 Members
Coordination and triage of security issues in nixpkgs230 Servers

Load older messages


SenderMessageTime
8 Jun 2021
@qyliss:fairydust.spaceAlyssa Rossthis is how you get somebody to care11:45:52
@qyliss:fairydust.spaceAlyssa Rosswould you notice if a random package you used didn't have a maintainer? I wouldn't.11:46:09
@janne.hess:helsinki-systems.dedas_jyeah, probably. I'll add the knownVulns to master and add the backport labels11:46:13
@hexa:lossy.networkhexagreat, thank you11:47:30
@janne.hess:helsinki-systems.dedas_jbtw, should I ping the security team in the future for PRs like this?11:50:39
@janne.hess:helsinki-systems.dedas_jbecause I just requested a review of hexa in this PR11:50:51
@qyliss:fairydust.spaceAlyssa Rossthat's my first time merging a PR with the backport labels -- do I need to do anything else or is the backport entirely automatic now?11:51:20
@linus.heckemann:matrix.mayflower.deLinux HackermanThe backport PR should be opened and linked automatically after the merge11:51:49
@linus.heckemann:matrix.mayflower.deLinux Hackermanit does still need a manual merge11:52:02
@qyliss:fairydust.spaceAlyssa Rossokay, cool11:53:08
@qyliss:fairydust.spaceAlyssa Rosshmm, no backport PR yet?11:54:16
@qyliss:fairydust.spaceAlyssa RossI'd have expected it to be pretty instant?11:54:23
@hexa:lossy.networkhexa das_j: I'm not too sure about the security team, is it more than one person, that has too many stakes in everything anyway? 11:54:35
@janne.hess:helsinki-systems.dedas_jit's graham and domen11:55:02
@hexa:lossy.networkhexa Alyssa Ross: takes rougly 4-5m as the action needs to clone nixpkgs first 11:55:03
@hexa:lossy.networkhexaoh, it's domen? I didn't know11:55:14
@janne.hess:helsinki-systems.dedas_jor is it the other team?11:55:28
@janne.hess:helsinki-systems.dedas_jhttps://github.com/orgs/NixOS/teams/security11:55:35
@janne.hess:helsinki-systems.dedas_jvs11:55:39
@qyliss:fairydust.spaceAlyssa Rossahh okay that makes sense11:55:39
@janne.hess:helsinki-systems.dedas_jhttps://github.com/orgs/NixOS/teams/security-notifications11:55:40
@hexa:lossy.networkhexahttps://nixos.org/community/teams/security.html11:56:18
@janne.hess:helsinki-systems.dedas_jlol the members on the website don't match up with any of the two teams11:57:15
@janne.hess:helsinki-systems.dedas_jah maybe the security-notifications team11:57:33
@janne.hess:helsinki-systems.dedas_j Alyssa Ross: the backports were just created 11:57:53
@janne.hess:helsinki-systems.dedas_j * Alyssa Ross: the backports were created just now 11:57:58
@hexa:lossy.networkhexaeverything merged12:00:05
@hexa:lossy.networkhexathanks for taking care of that12:00:07
@janne.hess:helsinki-systems.dedas_jfyi, don't delete your branch before the backports were created: https://github.com/NixOS/nixpkgs/pull/126193#issuecomment-85670426112:04:10
@qyliss:fairydust.spaceAlyssa Rossthat's annoying -- the action shouldn't need the branch12:04:54

Show newer messages


Back to Room ListRoom Version: 6