!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

693 Members
Coordination and triage of security issues in nixpkgs217 Servers

Load older messages


SenderMessageTime
21 Dec 2025
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)* i merged them together, if i remember correctly (im not sure anymore since it was on tmpfs and i OOM'd trying to compile it)13:51:03
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)i managed to compile it13:51:16
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe) the 7fa... commit contains // Ensure the sending user isn't a lying bozo which i also have in my commit 13:52:13
@me:indeednotjames.comemily #security-discuss:nixos.org would be a better fit for this discussion. 13:52:30
@magic_rb:matrix.redalder.orgmagic_rb joined the room.14:05:41
@emma:rory.gayEmma [it/its]oh i was about to bring that up here14:08:48
@emma:rory.gayEmma [it/its] should note that tuwunel is also affected: https://github.com/matrix-construct/tuwunel/commit/dc9314de1f8a6e040c5aa331fe52efbe62e6a2c3 14:09:43
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)it is 2 commits merged together14:23:32
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)https://forgejo.ellis.link/continuwuation/continuwuity/commit/b2bead67ac8bc45de9a612578f295e5b7fc6c2b5 https://forgejo.ellis.link/continuwuation/continuwuity/commit/7fa4fa98628593c1a963f5aa8dbc3657d604b04714:24:03
@emma:rory.gayEmma [it/its]

im aware of the commits, i read them :)

i just couldnt tell exactly from the diff file

14:24:31
@n4ch7:n3831.netn4ch723hr3r (putting stuff in your name is cringe)yeah sorry im kind of a noob and when i patch stuff for my overlay i just put everything into one diff >_<14:25:24
@emma:rory.gayEmma [it/its] i tend to use git format-patch start..end -o . (example: https://cgit.rory.gay/Rory-Open-Architecture.git/tree/packages/overlays/matrix-synapse/patches)
though we're veering quite offtopic here lol
14:26:44
22 Dec 2025
@amadaluzia:tchncs.deamadaluzia[tde] changed their display name from ➡️@amadaluzia:unredacted.org to amadALTuzia (tchncs.de).16:11:08
@amadaluzia:tchncs.deamadaluzia[tde] changed their display name from amadALTuzia (tchncs.de) to amadaluzia[tde].17:30:01
24 Dec 2025
@amadaluzia:unredacted.orgamadaluzia changed their profile picture.16:53:38
25 Dec 2025
@lennart:0520.chlennart changed their profile picture.10:33:36
26 Dec 2025
@daniel:routing.rocksdan_nrw changed their profile picture.09:49:04
@zitrone:utwente.iozitrone (39c3 DECT ZITR/9487) changed their display name from zitrone to zitrone (39c3 DECT ZITR/9487).12:19:12
@jappie:jappie.devjasper @ 39c3 ☎️ 62749 changed their display name from jappie to jappie @ 39c3.15:49:41
@qubitnano:matrix.orgqubitnanohttps://github.com/NixOS/nixpkgs/pull/47123917:53:34
@qubitnano:matrix.orgqubitnanoremote unauth exploit for CVE-2025-14847 was released17:53:37
@tgerbet:matrix.orgtgerbetAlso flagged https://github.com/NixOS/nixpkgs/pull/474211 25.05 will need some human work to deal with the backports18:04:59
@emilazy:matrix.orgemily perhaps knownVulnerabilities? support ends in under a week right? 18:15:55
@qubitnano:matrix.orgqubitnano? https://www.mongodb.com/legal/support-policy/lifecycles18:19:24
@tgerbet:matrix.orgtgerbetSupport of the 25.05 branch18:20:13
@qubitnano:matrix.orgqubitnanoright 25.05, sorry18:20:16
27 Dec 2025
@pinpox:matrix.orgpinpox [DECT: 7479] changed their display name from pinpox to pinpox [DECT: 7479].12:01:47
@dues__:matrix.orgDamian Poddebniak @ 39c3 changed their display name from Damian Poddebniak to Damian Poddebniak @ 39c3.12:29:15
@jappie:jappie.devjasper @ 39c3 ☎️ 62749 changed their display name from jappie @ 39c3 to jasper @ 39c3 ☎️ 62749.13:30:50
@realnyte:matrix.orgNyte changed their display name from realnyte to Nyte.21:19:47

Show newer messages


Back to Room ListRoom Version: 6