!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

758 Members
Coordination and triage of security issues in nixpkgs233 Servers

Load older messages


SenderMessageTime
8 Jun 2021
@hexa:lossy.networkhexaweechat-matrix?11:42:44
@qyliss:fairydust.spaceAlyssa Rossmhmm11:43:00
@hexa:lossy.networkhexayeah, there's not really a way to map viewports in a good way to weechat I guess11:43:21
@hexa:lossy.networkhexamaybe code blocks should be urls like pastebins11:43:47
@hexa:lossy.networkhexaRedacted or Malformed Event11:43:59
@qyliss:fairydust.spaceAlyssa RossI actually quite like actual code blocks rendering inline, but a commit log seemed a little silly11:44:09
@hexa:lossy.networkhexafair11:44:40
@qyliss:fairydust.spaceAlyssa RossI'd maybe just mark insecure on master for now, to show that if somebody is using it they are welcome to fix it?11:44:44
@hexa:lossy.networkhexa
In reply to @janne.hess:helsinki-systems.de
we could remove it from master and add knownVulnerabilities to the 20.09 and 21.05 branch, maybe someone who uses it will fix it
sgtm
11:44:50
@hexa:lossy.networkhexaalso fine11:45:00
@qyliss:fairydust.spaceAlyssa Rossa removed package sort of communicates "we don't want this back", imo11:45:12
@qyliss:fairydust.spaceAlyssa Rossbut we'd be fine with the package as long as it was up-to-date, aiui11:45:27
@janne.hess:helsinki-systems.dedas_jwell do we want packages back that nobody cares to maintain?11:45:32
@qyliss:fairydust.spaceAlyssa Rossthis is how you get somebody to care11:45:52
@qyliss:fairydust.spaceAlyssa Rosswould you notice if a random package you used didn't have a maintainer? I wouldn't.11:46:09
@janne.hess:helsinki-systems.dedas_jyeah, probably. I'll add the knownVulns to master and add the backport labels11:46:13
@hexa:lossy.networkhexagreat, thank you11:47:30
@janne.hess:helsinki-systems.dedas_jbtw, should I ping the security team in the future for PRs like this?11:50:39
@janne.hess:helsinki-systems.dedas_jbecause I just requested a review of hexa in this PR11:50:51
@qyliss:fairydust.spaceAlyssa Rossthat's my first time merging a PR with the backport labels -- do I need to do anything else or is the backport entirely automatic now?11:51:20
@linus.heckemann:matrix.mayflower.deLinux HackermanThe backport PR should be opened and linked automatically after the merge11:51:49
@linus.heckemann:matrix.mayflower.deLinux Hackermanit does still need a manual merge11:52:02
@qyliss:fairydust.spaceAlyssa Rossokay, cool11:53:08
@qyliss:fairydust.spaceAlyssa Rosshmm, no backport PR yet?11:54:16
@qyliss:fairydust.spaceAlyssa RossI'd have expected it to be pretty instant?11:54:23
@hexa:lossy.networkhexa das_j: I'm not too sure about the security team, is it more than one person, that has too many stakes in everything anyway? 11:54:35
@janne.hess:helsinki-systems.dedas_jit's graham and domen11:55:02
@hexa:lossy.networkhexa Alyssa Ross: takes rougly 4-5m as the action needs to clone nixpkgs first 11:55:03
@hexa:lossy.networkhexaoh, it's domen? I didn't know11:55:14
@janne.hess:helsinki-systems.dedas_jor is it the other team?11:55:28

Show newer messages


Back to Room ListRoom Version: 6