!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

672 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22206 Servers

Load older messages


SenderMessageTime
27 Mar 2026
@sasha:the-apothecary.clubMoved to @sashanoraa:matrix.org changed their display name from Sashanoraa.gay (she/her, ze/zir) to Moved to @sashanoraa:matrix.org.15:27:45
@pyrox:pyrox.devdish [Fox/It/She] https://github.com/NixOS/nixpkgs/pull/504174 closes 6 security issues for tandoor-recipes 17:58:25
28 Mar 2026
@qyliss:fairydust.spaceAlyssa RossWhether this is an mbedtls security fix depends on how much you trust in ad-hoc identification and workarounds of each instance of a systemic problem, I suppose, but people in here might like to be aware of it https://github.com/NixOS/nixpkgs/pull/50431808:19:38
@k900:0upti.meK900Ewwwww08:24:30
@k900:0upti.meK900 That's just UB no? 08:24:37
@emilazy:matrix.orgemilyhttps://github.com/wolfSSL/wolfssl/releases/tag/v5.9.0-stable18:04:14
@emilazy:matrix.orgemilythree high-severity CVEs and a bunch of others, no PR after ten days 🫠18:04:28
@emilazy:matrix.orgemily it's used in only 9 other packages and I'm about to make that 8. perhaps we should consider dropping. maybe tgerbet has input since he had to do the last update. (but #security-discuss:nixos.org for that ofc) 18:05:21
@emilazy:matrix.orgemilyoh, very sorry, it was already merged… ignore me18:06:26
29 Mar 2026
@arcayr:mischief.expertarcayr changed their profile picture.11:15:53

There are no newer messages yet.


Back to Room ListRoom Version: 6