!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

660 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22205 Servers

Load older messages


SenderMessageTime
23 Jul 2024
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2024/07/23/1 bind915:14:52
@hexa:lossy.networkhexa * https://www.openwall.com/lists/oss-security/2024/07/23/1 bind9 globin 15:14:57
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/32944916:31:02
@vcunat:matrix.orgvcunatFTR, one of these CVEs was in a coordinated embargo with https://github.com/NixOS/nixpkgs/pull/32947119:58:02
@emilazy:matrix.orgemilyat last, NixOS is in on an embargo!19:59:59
24 Jul 2024
@vcunat:matrix.orgvcunatSuch embargoes are not new. It's actually hard for major open-source DNS vendors to keep up with researchers trying to break stuff. (though this particular one wasn't from 3rd party but the BIND team)05:24:35
@redstone-menace:matrix.orgR̴̨͕͇͍̞̮̐̅͆̌̀̉̐͋̈́̃̀͒́̎̅̚̚̚͠͝Ĕ̵̡̛͖͖̟̙̫̱͈̘̞̭͍͍͑̌̄͑̓̋̓̀̈̏̈́͊̇͊͆̉͂̏̀̃̚͘͝͝ͅͅD̶̡̢͔̱̖̮͙͉̘̺͓͍̩̮͈͍͗̃̀̏͌͘͜ͅŚ̸̬̭̯̬͙͇͓̬̩̳̤͚͓̤̩̺͉͖̉͛̓̿̎͊̿̆́̐͂̇͌̄̇̓͘ͅͅT̴̞̫̘̝͇͔̟̪̪̦͂̔̎̀̎ͅŎ̷̡̬̹̪͈̭̣͈̭̭͉̦̖̝̘̪͖͔̥̦̘̻̳Ṋ̶̛̫͈̳̘͚̜̔̋͆̅̈́͊̑͊̉̌̈́̾͑̈́̚ͅË̸̡̨̨̛͇̜̖͔͖̻̟̗̠̙͓̘̗̥͉͇̜͑͆͊͑͑̀̓͒͜͝͝ changed their display name from redstone-menace to Redstone.10:17:19
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2024/07/24/1 https://www.openwall.com/lists/oss-security/2024/07/24/2 can't say I've missed curl updates 🫠11:10:45
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/32963612:09:11
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/32964312:09:15
25 Jul 2024
@bumperboat:matrix.org@bumperboat:matrix.org changed their display name from bumperboat (UTC+2) to bumperboat.12:47:25
26 Jul 2024
@sasha:the-apothecary.clubSashanoraa.gay (she/her, ze/zir) changed their display name from Sashanoraa.gay (ze/zir, she/her) to Sashanoraa.gay (she/her, zi/zir).02:06:55
@sasha:the-apothecary.clubSashanoraa.gay (she/her, ze/zir) changed their display name from Sashanoraa.gay (she/her, zi/zir) to Sashanoraa.gay (she/her, ze/zir).02:07:45
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/33010907:48:46
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/32970807:52:23
27 Jul 2024
@bumperboat:matrix.org@bumperboat:matrix.org left the room.11:58:53
28 Jul 2024
@lycheefox:matrix.org@lycheefox:matrix.org left the room.17:02:58
29 Jul 2024
@kenzie:matrix.kenzi.dev@kenzie:matrix.kenzi.dev left the room.06:58:13
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/33022308:40:53
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/33086113:37:01
30 Jul 2024
@quasigod:matrix.orgquasigod left the room.15:08:02
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/33116822:15:05
@hexa:lossy.networkhexahttps://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx722:32:33
@hexa:lossy.networkhexa * https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7 is the actual security issue, in twisted22:32:41
31 Jul 2024
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2024/07/31/1 curl (including 8.9.0)09:50:05
@sandro:supersandro.deSandro 🐧fix is only available in an rc? no links to commits....11:20:07
@teutat3s:pub.solarteutat3sIs the build failure expected here? https://github.com/NixOS/nixpkgs/pull/331177/checks?check_run_id=2813780959812:29:07
1 Aug 2024
@tammi:greyseal.euTammi (ey/em)Redacted or Malformed Event06:33:06
@vsh:nyantec.comVika Shleina (she/her) changed their profile picture.11:50:40
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/33127715:35:59

Show newer messages


Back to Room ListRoom Version: 6