!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

713 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
20 Mar 2026
@emilazy:matrix.orgemily(I don't think a highlight on every message in here is a good idea, it's not an advisory notification channel, triage has to happen in the triage room even if not extended discussions…)19:16:56
@emilazy:matrix.orgemily(& many many vulnerabilities never come up in here at all đŸ˜…)19:17:31
@lennart:0520.chlennartah sorry, that wasn't clear to me.19:17:36
@lennart:0520.chlennartI vaguely remember that I had this before, sorry, gonna turn of the notifications :D19:48:31
21 Mar 2026
@vcunat:matrix.orgvcunat Noone has reacted the initrd secrets problem apparently? I think it wouldn't be too hard to prevent nixos-unstable from updating, but should we? Also if it's bad, we need to merge quickly to fix nixos-unstable-small. 06:16:30
@k900:0upti.meK900 We should 06:16:46
@k900:0upti.meK900It's stupid06:16:51
@vcunat:matrix.orgvcunat

Done, I think.

Loaded: masked (Reason: Unit update-nixos-unstable.service is masked.)

06:21:35
@emilazy:matrix.orgemilyperhaps revert for now?14:12:53
@k900:0upti.meK900 @ElvishJerricco has a fix 14:20:44
@elvishjerricco:matrix.orgElvishJerriccoIf no one's going to review it then I guess we just revert though14:21:15
@elvishjerricco:matrix.orgElvishJerriccoI'd merge because I'm reasonably sure of the fix. But plausibly the original PR did it that way for some reason and the author / reviewers of it should chime in. I mean I think that's unlikely but that's one reason I haven't just self-merged it14:22:52
@emilazy:matrix.orgemilywe had a fix 20 hours ago, we could have merged a revert like 24 hours ago14:31:17
@vcunat:matrix.orgvcunatRebuilding all tests takes a while, but yes.14:39:49
@vcunat:matrix.orgvcunat* Rebuilding all tests takes a while, but yes. (at least I assume that the fix wouldn't rebuild most tests)14:55:56
@vcunat:matrix.orgvcunatI guess we revert for now: https://github.com/NixOS/nixpkgs/pull/50196315:01:56
23 Mar 2026
@pyrox:pyrox.devdish [Fox/It/She] Closes 10 currently open security issues for siyuan https://github.com/NixOS/nixpkgs/pull/502753 18:20:37
24 Mar 2026
@leona:leona.isleonahttps://github.com/NixOS/nixpkgs/pull/503140 nginx20:11:50
@pyrox:pyrox.devdish [Fox/It/She] https://nodejs.org/en/blog/vulnerability/march-2026-security-releases 21:38:22
@pyrox:pyrox.devdish [Fox/It/She]nodejs21:38:23
@pyrox:pyrox.devdish [Fox/It/She]2 high, 5 medium, 2 low severity CVEs21:40:58
@pyrox:pyrox.devdish [Fox/It/She]24.x and earlier are only affected by 4 of the medium vulns, but all of the high and low ones as well21:41:24
@pyrox:pyrox.devdish [Fox/It/She] PR submitted for all 4 versions https://github.com/NixOS/nixpkgs/pull/503168 21:48:49
@whispers:catgirl.cloudwhispers [& it/fae]aduh95 did this in #503151, #503152, #503153, and #50315421:50:46
@whispers:catgirl.cloudwhispers [& it/fae]* aduh95 did this in #503151, #503152, #503153, and #503154. all are already merged. 24 to staging, the rest to master.21:50:59
@pyrox:pyrox.devdish [Fox/It/She]my apologies, didn't see those. Thank you!21:51:30
25 Mar 2026
@sigmasquadron:matrix.orgFernando Rodrigueshttps://xenbits.xenproject.org/xsa/advisory-482.html XSA targetting a Linux driver01:04:14
@sigmasquadron:matrix.orgFernando Rodrigues * 01:04:31
@sigmasquadron:matrix.orgFernando RodriguesI'm not entirely sure how to patch out kernels though01:04:55
@sigmasquadron:matrix.orgFernando Rodrigues * 01:05:00

Show newer messages


Back to Room ListRoom Version: 6