!rGlCMuXgAhgEpdvJUz:nixos.org

NixOS KDE

197 Members
57 Servers

Load older messages


SenderMessageTime
18 Aug 2025
@k900:0upti.meK900 ⚡️It's pretty active16:25:26
@emilazy:matrix.orgemilyI know fcitx is very popular with Chinese users16:25:29
@emilazy:matrix.orgemilybut not sure if that package specifically is16:25:35
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)

https://github.com/NixOS/nixpkgs/pull/398783#issuecomment-2824682603

We need this no matter what since it is security relevant and will block further security updates in the future.

Sandro actually had a good point here. And as such on 25.05 the libsoup2 usage is below 100 too

16:26:27
@emilazy:matrix.orgemilyhttps://github.com/jellyfin/jellyfin-media-player/pull/599 😔16:26:41
@emilazy:matrix.orgemilywell I just mean I see people complaining regularly about all their stuff being broken because of it16:27:00
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) but thats offtopic here, would continue that in #security-discuss:nixos.org , lets get back to qtwebengine 16:27:08
@emilazy:matrix.orgemilybackporting that kind of stuff hurts16:27:06
@emilazy:matrix.orgemilyI'm satisfied by the list here though, I think we can move forward with it16:27:20
@emilazy:matrix.orgemilyI don't think we need to block Plasma removal on it16:27:34
@emilazy:matrix.orgemilyer, vice versa16:27:42
@emilazy:matrix.orgemilybecause it's just … choosing what error people get16:27:44
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)fair enough16:27:54
@emilazy:matrix.orgemilyor at least we can get a PR up marking it as vulnerable and land them together16:27:57
@emilazy:matrix.orgemilyhttps://github.com/jellyfin/jellyfin-media-player/pull/844 does not look like anyone is putting real work into it16:28:33
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)should we dig out like 20 CVEs that affect the old qtwebengine or do we not bother and just slap it with some text?16:29:03
@k900:0upti.meK900 ⚡️Probably fine to just say "uses outdated chromium version, figure it out"16:30:54
@emilazy:matrix.orgemily"EOL since April 2025, vulnerable to all Chromium CVEs since then"16:32:03
@emilazy:matrix.orgemily (well, technically there can be CVEs that don't apply to their ancient Chromium) 16:32:21
@emilazy:matrix.orgemily (…there can also be CVEs that apply only to their ancient Chromium) 16:32:33
@emilazy:matrix.orgemilyit's Chromium 87, from 202016:33:20
@emilazy:matrix.orgemilywith half a decade of backported security patches16:33:25
@emilazy:matrix.orgemily and from what I've seen/heard, they were not super proactive about being very diligent about those backports 16:33:36
@emilazy:matrix.orgemilyto be frank, I would not use Qt 6 WebEngine for a daily-driving browser either16:33:48
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)oh hell no16:33:59
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)anyways, i need to pop out, i'll catch up later16:34:53
@k900:0upti.meK900 ⚡️ I don't think they say you should 16:37:17
@emilazy:matrix.orgemilyI dunno. I doubt the Qt company would say "Qt is not suitable for writing web browsers".16:37:40
@emilazy:matrix.orgemilythough they do say "The Qt WebEngine module provides a web browser engine that makes it easy to embed content from the World Wide Web into your Qt application on platforms that do not have a native web engine." 🤔16:37:49
@emilazy:matrix.orgemilydoesn't KDE have a browser16:38:37

Show newer messages


Back to Room ListRoom Version: 9