!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

750 Members
Coordination and triage of security issues in nixpkgs235 Servers

Load older messages


SenderMessageTime
28 May 2026
@kuflierl:matrix.orgkuflierlRedacted or Malformed Event09:13:17
@kuflierl:matrix.orgkuflierl * Libheif https://github.com/NixOS/nixpkgs/pull/522835 11:20:41
@kuflierl:matrix.orgkuflierl

Libheif
CVE-2026-32738 (GHSA-7f2h-cmpf-v9ww), CVE-2026-32739 (GHSA-j9g7-q9hv-gq8c), CVE-2026-32740 (GHSA-frfr-f3vg-2g6j), CVE-2026-32741 (GHSA-j3w5-7whq-p37q), CVE-2026-32814 (GHSA-4m8r-34pg-rvwc), CVE-2026-32882 (GHSA-hg7q-rjr2-8x46), CVE-2026-41069 (GHSA-p82x-fpmv-576r), CVE-2026-41071 (GHSA-xj92-xjff-h8w3), CVE-2026-47178 (GHSA-5x55-x5pf-9c6g), CVE-2026-47247 (GHSA-2vh6-whr3-cmq3), CVE-2026-47251 (GHSA-p6q9-fhf2-vj9v), CVE-2026-47254 (GHSA-wqjg-4x9g-6cvg), CVE-2026-47709 (GHSA-4h72-vqgp-9376), CVE-2026-47714 (GHSA-h4wm-6wwf-qvhx), CVE-2026-48029 (GHSA-6x5f-qchq-cxqv), (GHSA-95jx-g5vf-cpp8),(GHSA-p4r6-6972-g26m), (GHSA-jh2w-m72q-q595), (GHSA-9h96-c44j-jpq9)

https://github.com/NixOS/nixpkgs/pull/522835

18:08:53
@k900:0upti.meK900 https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/ Cargo security-ish 19:58:04
@whispers:catgirl.cloudwhispers [& it/fae] https://github.com/NixOS/nixpkgs/pull/525279 is the update for unstable
https://github.com/NixOS/nixpkgs/pull/524640 is the backport to staging-26.05 and is already merged
20:22:31
@whispers:catgirl.cloudwhispers [& it/fae]* https://github.com/NixOS/nixpkgs/pull/525279 is the update for unstable https://github.com/NixOS/nixpkgs/pull/524640 is the patches picked to staging-26.05 and is already merged20:22:42
@whispers:catgirl.cloudwhispers [& it/fae]* https://github.com/NixOS/nixpkgs/pull/525279 is the update for unstable https://github.com/NixOS/nixpkgs/pull/524640 is the patches picked to staging-26.05 and is already merged it can't make it to 25.11 (no more staging-next-25.11) and i definitely don't think it's a big enough deal to restart a bunch of the current one20:23:34
@whispers:catgirl.cloudwhispers [& it/fae]* https://github.com/NixOS/nixpkgs/pull/525279 is the update for unstable https://github.com/NixOS/nixpkgs/pull/524640 is the patches picked to staging-26.05 and is already merged it can't make it to 25.11 (no more staging-next-25.11 and i definitely don't think it's a big enough deal to restart a bunch of the current one)20:24:53
29 May 2026
@lassulus:lassul.uslassulus changed their profile picture.07:06:35
@h0nig2k:matrix.orgh0nig2khttps://github.com/NixOS/nixpkgs/pull/523468 looking for review15:36:01
@h0nig2k:matrix.orgh0nig2khttps://github.com/NixOS/nixpkgs/pull/520639 as well15:36:52
@ma27:nicht-so.sexyma27can do the glibc one in an hour I guess..16:14:47
30 May 2026
@kuflierl:matrix.orgkuflierlhttps://github.com/NixOS/nixpkgs/pull/52562112:01:53
@613fd0ba9f744876:matrix.orgFlakeyForger joined the room.18:14:06
@613fd0ba9f744876:matrix.orgFlakeyForger set a profile picture.18:21:01
@613fd0ba9f744876:matrix.orgFlakeyForger removed their profile picture.18:25:14
@613fd0ba9f744876:matrix.orgFlakeyForger set a profile picture.18:25:25
31 May 2026
@qweered_real:matrix.orgAliaksandr set a profile picture.00:30:59
@keysmashes:matrix.orgkeysmashes joined the room.12:02:24
@sersorrel:matrix.orgsorrel -> keysmashes changed their display name from sorrel to sorrel -> keysmashes.12:08:33
1 Jun 2026
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/52652914:35:36
2 Jun 2026
@kuflierl:matrix.orgkuflierlhttps://github.com/NixOS/nixpkgs/pull/52716414:51:37
@robert:funklause.dedotlambdaI'm not sure about https://github.com/NixOS/nixpkgs/pull/52451015:26:16
@robert:funklause.dedotlambdasame for https://github.com/NixOS/nixpkgs/pull/52450815:27:00
@robert:funklause.dedotlambdaand https://github.com/NixOS/nixpkgs/pull/52450715:27:32
@monokles:matrix.monokles.eumonokles joined the room.16:10:45
3 Jun 2026
@samuel.dionne-riel:cyberus-technology.deSamuel Dionne-Riel

the following PRs may need to be labeled with the security label:

  • https://github.com/NixOS/nixpkgs/pull/468076
  • https://github.com/NixOS/nixpkgs/pull/514056
  • https://github.com/NixOS/nixpkgs/pull/507810
21:06:44
4 Jun 2026
@jkarlson:kapsi.fiEmil Thorsøewow, openvpn has been marginally vulnerable since 2026-04-2203:46:53
@callmeecho:matrix.orgEcho changed their profile picture.04:23:41
@k900:0upti.meK900 libinput RCE-ish: https://gitlab.freedesktop.org/libinput/libinput/-/releases/1.31.3 06:54:31

Show newer messages


Back to Room ListRoom Version: 6