<samueldr> ah, no PEAR in nixpkgs, then no worries
<samueldr> except drush which has a component taken from download.pear.php.net
lassulus has quit [Ping timeout: 268 seconds]
lassulus has joined #nixos-security
pie__ has joined #nixos-security
lassulus_ has joined #nixos-security
lassulus has quit [Ping timeout: 246 seconds]
lassulus_ is now known as lassulus
pie___ has quit [Ping timeout: 240 seconds]
<pie__> also theres some php package manager
<pie__> that maybeuses that
<pie__> but thats prooobaly not our problem?
<pie__> [intense shrugging]
<pie__> also idk how phpPackages works
<pie__> (i just installed some thing once(
__Sander__ has joined #nixos-security
r5d has quit [Quit: WeeChat 2.3]
<andi-> I'd like to take a look at our own package management (nix) instead... Have a few people check the signature verification, HTTP handling (besides the fact that it is curl) etc..
<gchristensen> me too
<andi-> I did run some fuzzing for a few months without any results that weren't already fixed.. so at least the language seems to be saneish (for the scope of my fuzzing results)
<gchristensen> https://twitter.com/grhmc/status/1087810921517510657 I tried to nerd-snipe some facebook person and I don't think it worked
<globin> while you are on topic, please way in on https://github.com/NixOS/rfcs/pull/34 if you have opinions :)
<{^_^}> rfcs#34 (by lrvick, 16 weeks ago, open): [RFC 0034] Expression Integrity
<gchristensen> *sigh*
<globin> ;)
<gchristensen> the worst part about that RFC is every reply grows in length
<andi-> I read the thread for a few days but I do not have enough time to come up with a reasonable constribution. It is a very large topic with very different views and opinions.... The technically correct solution might not be the solution we want since it would kill the project..
r5d has joined #nixos-security
<gchristensen> I predict that if we get 12 more replies, the thread will have such density the universe will collapse
<andi-> that would also solve the problem.
<ekleog> andi-: I think that the technically correct solution is what's being developed with git-wotr, but… it's not really making huge progress recently
<ekleog> and good thing is it wouldn't change the workflow, except committers would slowly get up to it and start signing commits before/after merging them
<ekleog> bad thing is even the spec isn't done, and we're at about 0 lines of code effectively running
<andi-> Yeah. I am looking forward to read it once it is done. Can't really work on anything that requires a lot of dedicated time these days.
erictapen has joined #nixos-security
qyliss has quit [Quit: bye]
qyliss has joined #nixos-security
r5d has quit [Ping timeout: 240 seconds]
__Sander__ has quit [Quit: Konversation terminated!]
erictapen has quit [Ping timeout: 246 seconds]
erictapen has joined #nixos-security
pie_ has joined #nixos-security
pie__ has quit [Ping timeout: 250 seconds]
pie__ has joined #nixos-security
pie_ has quit [Ping timeout: 268 seconds]
pie___ has joined #nixos-security
pie__ has quit [Ping timeout: 245 seconds]
pie_ has joined #nixos-security
pie___ has quit [Ping timeout: 240 seconds]
pie__ has joined #nixos-security
pie_ has quit [Ping timeout: 240 seconds]
pie__ has quit [Ping timeout: 240 seconds]
pie_ has joined #nixos-security
pie__ has joined #nixos-security
pie_ has quit [Ping timeout: 240 seconds]
pie_ has joined #nixos-security
pie__ has quit [Ping timeout: 245 seconds]
pie__ has joined #nixos-security
pie_ has quit [Ping timeout: 240 seconds]
pie_ has joined #nixos-security
pie__ has quit [Ping timeout: 246 seconds]
pie__ has joined #nixos-security
pie_ has quit [Ping timeout: 240 seconds]
pie__ has quit [Ping timeout: 268 seconds]