!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

753 Members
Coordination and triage of security issues in nixpkgs230 Servers

Load older messages


SenderMessageTime
20 May 2026
@hexa:lossy.networkhexa https://seclists.org/oss-sec/2026/q2/630 apparmor Grimmauld (any/all) 16:47:59
@hexa:lossy.networkhexa https://seclists.org/oss-sec/2026/q2/626 pdns Mic92 16:48:39
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q2/625 bind9 (unmaintained)16:48:56
@joerg:thalheim.ioMic92I am not even using pdns.18:33:52
@joerg:thalheim.ioMic92Just a nix-update should be enough on this18:34:33
@leona:leona.isleonabut you are listed as maintainer.18:34:35
@joerg:thalheim.ioMic92I will fix that part18:43:23
@hexa:lossy.networkhexa https://seclists.org/oss-sec/2026/q2/633 cockpit andre4ik3 19:49:36
@andre4ik3:matrix.organdre4ik3It’s not too bad, it’s command injection for authenticated users, but users have shell access anyway as a built-in feature for cockpit. There’s an automatic PR to update to the patched version I’ll test it and merge within the next hour or so. https://github.com/NixOS/nixpkgs/pull/52226419:56:12
21 May 2026
@bart:bartoostveen.nlBart someone else bumped, seems fine https://github.com/NixOS/nixpkgs/pull/522407 09:13:37
@bart:bartoostveen.nlBart https://github.com/NixOS/nixpkgs/pull/522600 10:02:53
@bart:bartoostveen.nlBart https://github.com/NixOS/nixpkgs/pull/522602 manual stable bump, ci complains because this is not a backport 10:03:36
@hythera:matrix.orgHytheraPR is drafted so the maintainer coulnd't merge it themselves. https://github.com/NixOS/nixpkgs/pull/51350814:06:09
@hythera:matrix.orgHythera* PR is drafted so the maintainer couldn't merge it themselve. https://github.com/NixOS/nixpkgs/pull/51350814:06:36
@hythera:matrix.orgHythera* PR is drafted so the maintainer couldn't merge it themself. https://github.com/NixOS/nixpkgs/pull/51350814:07:11
@bonsal2:matrix.orgjayf99 joined the room.18:47:59
22 May 2026
@teutat3s:pub.solarteutat3sdocker version 28 is now officially unmaintained, has not received any updates since November 2025. It's ready to be dropped: https://github.com/moby/moby/commit/941805303910a3749ed8fa9669d078015f6f268c https://github.com/NixOS/nixpkgs/pull/52161113:55:26
@lucasfcnunes:matrix.orglucasfcnunes joined the room.15:45:29
@lucasfcnunes:matrix.orglucasfcnunes set a profile picture.15:54:59
@jonhermansen:matrix.orgJon Hermansen changed their display name from jonhermansen to Jon Hermansen.19:18:40
23 May 2026
@leona:leona.isleonanginx now fixed the latest RCE. https://my.f5.com/manage/s/article/K000161377 unstable: https://github.com/NixOS/nixpkgs/pull/523220 (already merged), https://github.com/NixOS/nixpkgs/pull/523265 25.11: https://github.com/NixOS/nixpkgs/pull/52326707:48:28
@leona:leona.isleona* nginx now fixed the latest RCE. https://my.f5.com/manage/s/article/K000161377 unstable: https://github.com/NixOS/nixpkgs/pull/523220 (already merged), https://github.com/NixOS/nixpkgs/pull/523149 25.11: https://github.com/NixOS/nixpkgs/pull/52326707:49:44
@leona:leona.isleona* nginx now fixed the latest RCE. https://my.f5.com/manage/s/article/K000161377 unstable: https://github.com/NixOS/nixpkgs/pull/523220 (already merged), https://github.com/NixOS/nixpkgs/pull/523149 (merged too) 25.11: https://github.com/NixOS/nixpkgs/pull/52326707:50:04
@jkarlson:kapsi.fiEmil Thorsøe https://github.com/NixOS/nixpkgs/pull/523220 says open to me 08:11:25
@jkarlson:kapsi.fiEmil Thorsøeoh merge queue08:11:47
@jkarlson:kapsi.fiEmil Thorsøeinteresting, you added it again and now it says queued?08:22:15
@jkarlson:kapsi.fiEmil Thorsøeoh failed status checks08:22:32
@leona:leona.isleonanah, GHA currently has problems that the merge queue checks run into authentication errors (401). So I would say trying again is the best way08:26:22
@whitefish:stratum0.orgwhitefish set a profile picture.09:26:14
@whitefish:stratum0.orgwhitefish changed their profile picture.09:26:32

Show newer messages


Back to Room ListRoom Version: 6