!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

735 Members
Coordination and triage of security issues in nixpkgs230 Servers

Load older messages


SenderMessageTime
6 Jun 2021
@henson:matrix.orgHenson joined the room.01:55:09
@r_i_s:matrix.orgris_wanna make it 261? https://github.com/NixOS/nixpkgs/pull/12523310:55:44
@r_i_s:matrix.orgris_or even 262? https://github.com/NixOS/nixpkgs/pull/12508810:56:17
@hexa:lossy.networkhexaInterested, but only at home later tonight12:36:00
7 Jun 2021
@henson:matrix.orgHensonI've got a question about the postgresql_11 package. A couple weeks ago there was a security update announcement in the Debian security mailing list recommending to upgrade from 11.11 to 11.12 due to several bug fixes. I notice that NixOS's postgres_11 package is still at 11.11 in 20.09 and 21.05. Is there a reason this hasn't been bumped to 11.12 yet?12:34:14
@henson:matrix.orgHensonthis is coming from the perspective of somebody who doesn't know much about the NixOS security team and is interested in understanding things better.12:38:47
@ldesgoui:matrix.orgldesgoui joined the room.12:39:00
@hexa:lossy.networkhexaFixed in https://github.com/NixOS/nixpkgs/pull/125751, needs to go through the channels I'd imagine13:29:17
@hexa:lossy.networkhexahttps://nixpk.gs/pr-tracker.html?pr=12575113:29:36
@sandro:supersandro.deSandroYeah, mass rebuild13:30:16
@sandro:supersandro.deSandroIs 11 the default version? If not we can maybe cherry pick it13:30:34
@henson:matrix.orgHenson hexa: thanks for pointing that out, I looked in the issues for it but didn't look in the PRs. 13:54:30
@henson:matrix.orgHenson Sandro: so if postgres_11 gets bumped from 11.11 to 11.12, then all packages that have postgres_11 in their closure have to get rebuilt, right? 13:57:48
@henson:matrix.orgHensonand postgres_11 = postgres is the default postgres for NixOS13:58:43
@henson:matrix.orgHensonoops %s/postgres/postgresql/g13:59:12
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/126088 https://github.com/NixOS/nixpkgs/pull/12608916:15:49
@hexa:lossy.networkhexapossible remote code execution in isync/mbsync16:16:01
@sandro:supersandro.deSandro
In reply to @henson:matrix.org
Sandro: so if postgres_11 gets bumped from 11.11 to 11.12, then all packages that have postgres_11 in their closure have to get rebuilt, right?
yes
16:35:26
8 Jun 2021
@dualinverter:matrix.orgdualinverter left the room.08:41:37
@hexa:lossy.networkhexahttps://nvd.nist.gov/vuln/detail/CVE-2021-351411:13:42
@hexa:lossy.networkhexathe package looks unmaintained, only carried ahead by treewide changes, maybe a candidate for removal …11:14:05
@janne.hess:helsinki-systems.dedas_j389 was a Totgeburt imo (don't know an english term for that). I have never heard anyone use it11:31:58
@janne.hess:helsinki-systems.dedas_j * 389 was a Totgeburt imo (don't know an english term for that). I have never heard anyone use it. Only some considered switching but nobody really did11:32:18
@kranzes:matrix.orgkranzes joined the room.11:37:47
@hexa:lossy.networkhexastillborn/stillbirth11:37:56
@janne.hess:helsinki-systems.dedas_jyeah11:38:15
@linus.heckemann:matrix.mayflower.deLinux HackermanUnpleasant metaphor to use for it IMHO though.11:38:18
@hexa:lossy.networkhexaindeed11:38:22
@janne.hess:helsinki-systems.dedas_jyeah, I really didn't think about the actual meaning of it11:38:38
@janne.hess:helsinki-systems.dedas_j * yeah, I really didn't think about the actual meaning of it, sorry11:38:49

Show newer messages


Back to Room ListRoom Version: 6