!CJXQiUGqNPcFonEdME:nixos.org

NixOS Foundation

461 Members
Public room for chatting with the NixOS Foundation Board116 Servers

Load older messages


SenderMessageTime
16 May 2024
@piegames:matrix.orgpiegames left the room.18:57:17
@fricklerhandwerk:matrix.orgfricklerhandwerk

Hi everyone, I got an email that the Sovereign Tech Fund extended an invitation to the Bug Resilience Program, because we participated in last year's Contribute Back Challenge, which means that Nix/Nixpkgs/NixOS is considered critical infrastructure.

Very briefly, the offer is:

  • Developer time provided by a software consultancy
  • Get hosted on YesWeHack with a bug bounty program, and get an unspecified amount of funding to pay bounties
  • Get security audits conducted by OSTIF

As these are largely in-kind contributions, those require resources to get accepted. Is there interest in the security community to capture that influx of attention?

The applications are "first come first serve", so if the general sentiment is that we should pursue it, that decision and a write-up should happen very soon (presumably on the order of days).
In particular we would have to define a scope to which the audits and bug bounties extend. A natural choice would be C++ Nix, but it could in principle also be the Nixpkgs/NixOS code base or our contribution workflows.

What do you think? I also posted this on Nix Hackers since getting developer time is something we wanted for many months now, and Security Discussions since it's about security.

19:18:59
@kasper24:matrix.orgKasper joined the room.19:57:07
@halfbit:matrix.org@halfbit:matrix.org left the room.21:31:03
@winter:catgirl.cloudWinter

hi folks -- i have a small concern about conflicts of interest throughout the recently appointed assembly.

while i sincerely appreciate all the work that the board & co have put into the selection process, i'm a bit concerned about infinisil's spot on the assembly, given that he has basically the same level of access as a board observer (while actual board observers were barred from applying to the assembly), and helped design the assembly application process in the first place.

22:58:20
17 May 2024
@winter:catgirl.cloudWinter *

hi folks -- i have a small concern about conflicts of interest throughout the recently appointed assembly.

while i sincerely appreciate all the work that the board & co have put into the selection process, i'm a bit concerned about infinisil's spot on the assembly, given that he has basically the same level of access as a board observer (while actual board observers were barred from applying to the assembly), and helped design the assembly application process in the first place.

what makes him different from the board observers in this case, if i may ask?

01:34:21
@infinisil:matrix.orginfinisilReplied on discourse: https://discourse.nixos.org/t/nixos-foundation-board-constitutional-assembly-appointment/45504/1301:40:38
@federicodschonborn:matrix.orgFederico Damián Schonborn left the room.10:18:02
@weethet:catgirl.cloudWeetHet joined the room.12:25:17
@elvishjerricco:matrix.orgElvishJerricco left the room.20:19:02
@lunaphied:lunaphied.meLunaphied changed their display name from Lunaphied to lunaphied.21:47:32
18 May 2024
@lunaphied:lunaphied.meLunaphied changed their display name from lunaphied to Lunaphied.03:42:13
@yuka:yuka.dev@yuka:yuka.dev left the room.11:06:40
@ss:someonex.netSomeoneSerge (back on matrix) joined the room.22:15:53
19 May 2024
@octomancer:matrix.orgoctomancer joined the room.20:51:19
20 May 2024
@ckie:ckie.devmei 🌒& changed their display name from ckie (they/them) to mei 🌒&.00:07:57
@federicodschonborn:matrix.orgFederico Damián Schonborn joined the room.01:30:06
@federicodschonborn:matrix.orgFederico Damián Schonborn changed their profile picture.03:53:59
@alina:kescher.at@alina:kescher.at changed their display name from alina to alina (DECT: WUFF/WOOF).14:24:59
@dpjyoo:matrix.org@dpjyoo:matrix.org left the room.18:15:26
@daschw:matrix.org@daschw:matrix.org left the room.20:51:19
21 May 2024
@tanja:catgirl.cloudTanja (she/her) - ☎️ 4201 joined the room.11:33:50
22 May 2024
@mjolnir:nixos.orgNixOS Moderation Botchanged room power levels.15:25:50
@mjolnir:nixos.orgNixOS Moderation Botchanged room power levels.15:28:05
@twitchy0:matrix.orgtwitchy0Are there additional steps I need to take for this reimbursement request? https://github.com/NixOS/foundation/issues/15216:47:29
@djacu:matrix.orgdjacu
In reply to @twitchy0:matrix.org
Are there additional steps I need to take for this reimbursement request?
https://github.com/NixOS/foundation/issues/152

Follow the instructions on "How do I get reimbursed"

https://nixos.org/community/event-funding/

17:25:46
@niksnut:matrix.orgEelcoRedacted or Malformed Event18:41:04
@infinidoge:matrix.org@infinidoge:matrix.org changed their display name from Infinidoge to Migrated to @infinidoge:inx.moe.21:36:36
@infinidoge:inx.moeInfinidoge 🏳️‍⚧️ joined the room.21:59:29
@infinidoge:matrix.org@infinidoge:matrix.org left the room.22:28:53

Show newer messages


Back to Room ListRoom Version: 10