| 22 Sep 2025 |
| @felix.schroeter:scs.ems.host changed their display name from Felix Schröter to Felix Schröter (🌄 29.09. – 05.10.). | 09:55:50 |
hexa | https://trubka.network.cz/pipermail/bird-users/2025-September/018417.html | 21:38:56 |
Tom | https://github.com/NixOS/nixpkgs/pull/445303 | 22:29:47 |
hexa | https://seclists.org/oss-sec/2025/q3/177 Jan Tojnar | 23:16:39 |
hexa | * https://seclists.org/oss-sec/2025/q3/177 webkitgtk Jan Tojnar | 23:16:43 |
hexa | I'm a bit lost on webkitgtk versioning, we seem to be on 2.50.0 for all versions? | 23:17:48 |
| 23 Sep 2025 |
vcunat | bird2 is NOT affected by these security issues, by the way. | 05:33:14 |
Jan Tojnar | yes. The versions in attribute name indicate ABI variant: 6_0 linked against GTK 4 and libsoup 3, 4_1 linked against GTK 3 and libsoup 3, 4_0 linked against GTK 3 and libsoup 2 (insecure) | 09:27:13 |
| kenji changed their display name from a-kenji to kenji. | 10:38:47 |
| 24 Sep 2025 |
lennart | release notes are yet to be released, I guess that will open in the next 2-4 hours https://github.com/NixOS/nixpkgs/pull/445709 | 05:28:45 |
lennart | * Zammad release notes are yet to be released, I guess that will open in the next 2-4 hours https://github.com/NixOS/nixpkgs/pull/445709 | 05:28:51 |
lennart | there is a fix to one security problem included, that I discovered. but they also had more disclosure processes involved in that release. | 05:33:13 |
Markus Theil | OpenSSL Release Announcement
The OpenSSL project team would like to announce the upcoming release of
OpenSSL Library versions 3.5.4, 3.4.3, 3.3.5, 3.2.5 and 3.0.18.
We will also be releasing extended support for OpenSSL Library versions 1.0.2zm and 1.1.1zd, which will be available to premium support customers.
These releases will be made available on Tuesday, 30th September 2025, between 1300 and 1700 UTC.
These are security-fix releases. The highest severity issue fixed in each of these releases is Moderate:
https://openssl-library.org/policies/general/security-policy/index.html
Yours
The OpenSSL Project Team
| 07:27:04 |
Markus Theil | I'd like to skip 3.5.3 and directly bump to 3.5.4 and 3.0.18. | 07:27:56 |
lennart | In reply to @lennart:0520.ch Zammad release notes are yet to be released, I guess that will open in the next 2-4 hours https://github.com/NixOS/nixpkgs/pull/445709 three Security Advisories linkes
- https://zammad.com/en/advisories/zaa-2025-07 - https://zammad.com/en/advisories/zaa-2025-08 - https://zammad.com/en/advisories/zaa-2025-09 | 09:55:49 |
lennart | * three Security Advisories linked
- https://zammad.com/en/advisories/zaa-2025-07
- https://zammad.com/en/advisories/zaa-2025-08
- https://zammad.com/en/advisories/zaa-2025-09
| 09:56:01 |
| 30 Sep 2025 |
hexa | https://www.freeipa.org/release-notes/4-12-5.html | 16:03:10 |