!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

676 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22211 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
28 May 2025
@vcunat:matrix.orgvcunatMerged, but honestly I don't know what to do about stable nixpkgs.09:57:17
@emilazy:matrix.orgemilyseems backportable? is there anything breaking I'm missing?11:10:30
@zhaofeng:zhaofeng.liZhaofeng Li

Is the concern about the new features?

(not sure if replying in a thread will cause notifications - if so, let's move to #security-discuss:nixos.org )

15:42:37
29 May 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)https://github.com/NixOS/nixpkgs/issues/411881 so uh - do we pick commits into our jq? one of the two doesn't even have a fix commit, and i'd be surprised if the fix for the other actually applies properly...09:26:03
@k900:0upti.meK900What the lol09:26:48
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)jq had no release since 2023, but now the second 7.5+ cve09:27:21
@k900:0upti.meK900Has anyone rewritten it in rust yet09:27:37
@alisonjenkins:matrix.orgAlison Jenkinshttps://github.com/MiSawa/xq09:28:18

Show newer messages


Back to Room ListRoom Version: 6