!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

747 Members
Coordination and triage of security issues in nixpkgs228 Servers

Load older messages


SenderMessageTime
11 Jun 2021
@sandro:supersandro.deSandrobut I am personal normally on unstable and for packages on master so upgrading everything is just easier and saves me time.14:36:41
@r_i_s:matrix.orgris_ Henson: you're aware of vulnix aren't you? 19:42:29
@r_i_s:matrix.orgris_also the whole "sniffing patch names for CVE ids" thing is a fairly well trodden path in nix19:44:06
@hexa:lossy.networkhexatbh, it's why I don't rely on channels19:51:38
@hexa:lossy.networkhexamy servers track the nixos-$release branches via niv, and my workstations run from a git checkout of master19:52:11
@hexa:lossy.networkhexa can always just git log --grep=CVE... 19:52:23
@henson:matrix.orgHenson ris_: no I'm not aware of vulnix 20:19:34
* @henson:matrix.orgHenson searches for it20:19:48
@r_i_s:matrix.orgris_it sounds quite a lot like what you're looking for20:20:02
@henson:matrix.orgHenson ris_: is it the hacklab vulnix thing, or something else? 20:20:58
@r_i_s:matrix.orgris_https://github.com/flyingcircusio/vulnix20:21:22
@henson:matrix.orgHenson ris_: awesome, I'll look into that 20:21:54
@henson:matrix.orgHenson hexa: have you ever encountered the need to only upgrade parts of your system (like what I described about updating sudo while intentionally keeping the rest of the system at an older NixOS version?) 20:23:05
@hexa:lossy.networkhexa Henson: I use overlays for a few things, yeah 20:23:33
@henson:matrix.orgHenson hexa: thanks for the suggestion of using niv and the git checkouts. Do you incorporate niv/git into your root user's channels, or import them into the system configuration? 20:25:38
@hexa:lossy.networkhexa Henson: using niv for my servers integrated with morph 20:25:58
@hexa:lossy.networkhexamy workstations have a git checkout at /etc/nixpkgs (whoops)20:26:24
@hexa:lossy.networkhexaI'll sometimes carry patches on there20:27:02
@hexa:lossy.networkhexa and then rebuild with -I nixpkgs=/etc/nixpkgs 20:27:17
@henson:matrix.orgHenson
In reply to @hexa:lossy.network
my workstations have a git checkout at /etc/nixpkgs (whoops)
what's the (whoops) for?
20:30:15
@hexa:lossy.networkhexadropping not-config into /etc 😂20:30:31
@henson:matrix.orgHensonahhh20:30:43
@henson:matrix.orgHenson ok hexa , thanks for your suggestions. Thanks ris_ for the vulnix suggestion, I'll look into these options. 20:31:26
12 Jun 2021
@tnias:stratum0.orgtnias joined the room.17:19:27
@thecannon:matrix.orgCannon joined the room.17:32:54
13 Jun 2021
@schnecfk:ruhr-uni-bochum.deCRTified joined the room.00:47:49
@aaronchall:matrix.orgaaronchall joined the room.04:43:25
@thecannon:matrix.orgCannon changed their display name from thecannon to Mountainous.20:39:25
@thecannon:matrix.orgCannon changed their profile picture.20:40:13
@thecannon:matrix.orgCannon left the room.20:58:08

Show newer messages


Back to Room ListRoom Version: 6