!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

676 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22211 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
10 Sep 2025
@ss:someonex.netSomeoneSerge (back on matrix) changed their display name from SomeoneSerge (@nixcon & back on matrix) to SomeoneSerge (back on matrix).00:38:08
@hexa:lossy.networkhexahttps://kb.cert.org/vuls/id/461364 no new release yet, releases look like code drops02:17:22
@hexa:lossy.networkhexa* https://kb.cert.org/vuls/id/461364 no new release yet, releases look like code drops https://gitlab.com/hsleisink/hiawatha/-/commits/master?ref_type=HEADS02:17:32
@hexa:lossy.networkhexaonly maintainer was removed in 2019 and the package has been carried forth since by r-ryantm02:20:14
@hexa:lossy.networkhexa

Hiawatha is no longer actively supported by the developer, but the developer acknowledges the vulnerabilities and has included mitigations and remediations to all three vulnerabilities in the next release.

02:20:34
@pyrox:pyrox.devdish [Fox/It/She]there aren't any consumers in nixpkgs, nor in any public config repos from a cursory glance at sourcegraph, so since there's no maintainers we could consider dropping02:23:29
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/44164502:24:21
@hexa:lossy.networkhexasame thought02:24:26
@pyrox:pyrox.devdish [Fox/It/She]🫡02:30:22

Show newer messages


Back to Room ListRoom Version: 6