!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

689 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22212 Servers

Load older messages


SenderMessageTime
30 Mar 2024
@spiralp:matrix.orgSpiralP joined the room.03:09:15
@vcunat:matrix.orgvcunat
In reply to @hexa:lossy.network
as mentioned this would remove symbols that packages now depend on, so not as simple
Maybe it's simpler for us thanks to doing all the rebuilds, but I haven't investigated whether those packages can build without the symbols.
05:58:31
@andmuz:matrix.org@andmuz:matrix.org joined the room.07:29:28
@Minijackson:matrix.orgMinijackson
In reply to @r_i_s:matrix.org
i'm struggling to reproduce this now, but I'm sure we've had at least one case in the past where fetchFromGitHub wasn't returning the vanilla repo source
You light have encountered a case were git attributes were used, which can modify the generated git archive. An example that I have on hand: https://github.com/paulscherrerinstitute/StreamDevice/blob/master/.gitattributes
08:21:08
@r_i_s:matrix.orgris_the seems feasible - didn't know about that. at least changes to gitattributes have to be checked in, which limits their stealth11:05:44
@r_i_s:matrix.orgris_ * that seems feasible - didn't know about that. at least changes to gitattributes have to be checked in, which limits their stealth 11:05:51
@cAkwNLHysr:matrix.orgRW joined the room.11:32:07
@alina:kescher.at@alina:kescher.at joined the room.11:38:43
31 Mar 2024
@peter253545:matrix.orgpeter253545 joined the room.02:43:55
@stigo:matrix.orgstigohttps://github.com/NixOS/nixpkgs/pull/30046111:26:12
@clumsily6239:matrix.orgClumsily6239 joined the room.15:14:56
@5m5z3q888q5prxkg:chat.lightnovel-dungeon.de@5m5z3q888q5prxkg:chat.lightnovel-dungeon.de joined the room.17:04:54
@dclmatrix:matrix.org@dclmatrix:matrix.org joined the room.18:01:24
@dclmatrix:matrix.org@dclmatrix:matrix.org changed their display name from dclmatrix to exet.22:32:52
1 Apr 2024
@nevivurn:nevi.devnevivurn joined the room.02:00:20
@tomog:matrix.orgtomf joined the room.03:01:00
2 Apr 2024
@lotte:chir.rs@lotte:chir.rs changed their profile picture.06:56:52
@lotte:chir.rs@lotte:chir.rs changed their profile picture.07:35:07
@xayomer:kif.rocks@xayomer:kif.rocks joined the room.08:59:11
@zimbatm:numtide.comJonas Chevaliersorry if it's out of topic; I think Vulnix needs a new maintainer. Maybe somebody here would be interested: https://github.com/nix-community/vulnix/issues/9510:40:54
@tgerbet:matrix.orgtgerbetNodeJS upgrades tomorrow https://nodejs.org/en/blog/vulnerability/april-2024-security-releases We probably going to have some issues with Node 18 as the last upgrade was reverted due to some breakages (https://github.com/NixOS/nixpkgs/pull/299809)16:16:33
3 Apr 2024
@may:theghostsip.eumay joined the room.12:28:43
@hexa:lossy.networkhexaRedacted or Malformed Event15:21:23
@dclmatrix:matrix.org@dclmatrix:matrix.org changed their display name from exet to blu3.16:01:25
@dclmatrix:matrix.org@dclmatrix:matrix.org set a profile picture.16:44:09
4 Apr 2024
@binarycat:snug.moeネコ
In reply to @zimbatm:numtide.com
sorry if it's out of topic; I think Vulnix needs a new maintainer. Maybe somebody here would be interested: https://github.com/nix-community/vulnix/issues/95
i've been considering it, since i have a bit of experience with data processing and cross-database mapping, but the problem is i don't really know python
00:59:07
@binarycat:snug.moeネコi could learn it without too much trouble, but i don't think being the sole maintainer of a piece of wildly used security software is a good first python project 01:01:23
@zimbatm:numtide.comJonas Chevalier
In reply to @binarycat:snug.moe
i could learn it without too much trouble, but i don't think being the sole maintainer of a piece of wildly used security software is a good first python project
One thing you can do is rebase https://github.com/nix-community/vulnix/pull/89 and test it. Having someone look at PRs and make sure they work as intended is already very valuable, even if you don't know how to write python.
07:36:17
@fabaff:matrix.orgfabaff changed their display name from Fabian Affolter to fabaff.08:40:38
@raitobezarius:matrix.orgraitobezarius
In reply to @binarycat:snug.moe
i've been considering it, since i have a bit of experience with data processing and cross-database mapping, but the problem is i don't really know python
Alternatively, https://github.com/Nix-Security-WG/nix-security-tracker is also looking for more hands, and I can be around for the maintenance and guidance
10:43:17

Show newer messages


Back to Room ListRoom Version: 6