!lymvtcwDJ7ZA9Npq:lix.systems

Lix Development

420 Members
(Technical) development of Lix, the package manager, a Nix implementation. Please be mindful of ongoing technical conversations in this channel.142 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
9 Jul 2025
@emilazy:matrix.orgemilythat's not source, I'm afraid15:03:20
@emilazy:matrix.orgemily what gets published to Maven repos is… precompiled .jars 15:03:28
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)ergh15:03:37
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)then i'm not building from source yeah15:03:42
@emilazy:matrix.orgemilyso you have a source build, but the dependencies are binary, and the pinned vulnerable version is hidden in there15:03:49
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)we are calling the gerrit source build15:03:55
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)if they don't do source builds… sad15:04:01
@emilazy:matrix.orgemilyactual recursive source builds for Java is a solvable problem but unfortunately nobody has tried solving it yet15:04:24
@puck:puck.moepuck
In reply to @emilazy:matrix.org
but https://github.com/i2p/i2p.i2p/commit/13190931b9ce7a7abdd7af57380124aaefbcc8be#diff-658f7b1aa34b58d27796fccdb8b756c72702d64ae44703374960f1cb89a5a5c3 has the fix
never been in a release
16:23:32
@puck:puck.moepuckuh, the eddsa jar that i think is being depended upon16:23:59
@puck:puck.moepuckthis is a vendoring of https://github.com/str4d/ed25519-java16:25:08
@jade_:matrix.orgjade_i think they're not maintaining the lib. probably the pragmatic prod fix is the one suggested on the google issue tracker.17:21:37
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)the fix is deployed17:21:47
@jade_:matrix.orgjade_which is a revert of gerrit bazel changes plus the JVM arg to allow crimes17:21:50
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)it would be nice if we could get a proper fix17:21:52
@jade_:matrix.orgjade_ah17:21:54
@jade_:matrix.orgjade_i think the better fix is actually fixing mina to fully support getting rid of the legacy lib17:22:08
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)i'm not clear on the security consequences of all of this17:22:11
@jade_:matrix.orgjade_probably not many or none17:27:25
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)ok17:28:19
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)so for me, i will remove this topic from my mental charge17:28:24
@lambadada:matrix.orglambadada joined the room.23:49:48
10 Jul 2025
@jade_:matrix.orgjade_anyone interested in reviewing some improvements to the notorious dependency propagation section in the nixpkgs manual? I added the necessary explanation for the math in there. https://github.com/NixOS/nixpkgs/pull/42395405:48:41

Show newer messages


Back to Room ListRoom Version: 10