gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
pie_ has quit [Remote host closed the connection]
pie_ has joined #nixos-security
justanotheruser has quit [Ping timeout: 258 seconds]
justanotheruser has joined #nixos-security
pie_ has quit [Ping timeout: 258 seconds]
Synthetica has joined #nixos-security
pie_ has joined #nixos-security
pie___ has joined #nixos-security
pie_ has quit [Ping timeout: 244 seconds]
<pie___> doesnt it make sense for it to be possible for someone to be listed as a package maintainer pseudonomously? commits need to be reviewed anyway, and code should be clear about what it does
pie_ has joined #nixos-security
pie___ has quit [Ping timeout: 276 seconds]
pie_ has quit [Remote host closed the connection]
pie___ has joined #nixos-security
pie___ has quit [Remote host closed the connection]
pie___ has joined #nixos-security
<andi-> we do not enforce real names IIRC... Not sure what the difference to the status quo would be. Not sure if all the people with the commit bit are "known".
pie_ has joined #nixos-security
pie___ has quit [Ping timeout: 250 seconds]
<pie_> random irc channel xpost <h01ger> https://www.spiegel.de/netzwelt/games/spieleentwickler-verbreiten-versehentlich-infizierte-spiele-a-1264181.html - supply chain attacks via backdoored visual studio, attacking gamers
<pie_> <h01ger> interesting also: the malware doesnt active itself if the computer language is set to russian or simplified chinese :)
<pie_> google translate: "It is unclear whether the studios used illegal copies of the software they had obtained through a swap or other unofficial sources. The alternative would be that hackers have invaded the game maker's computer and manipulated its version of Microsoft Visual Studio."
<andi-> not sure how that is relevant to us in here besides the obvious..
<pie_> just the obvious i guess, and moar supply chainz
<simpson> Sorry, it's not at all obvious. It looks like, ineed, a random cross-post.
<pie_> ok maybe i was a bit trigger happy on that one
Synthetica has quit [Quit: Connection closed for inactivity]
pie___ has joined #nixos-security
pie_ has quit [Ping timeout: 245 seconds]
pie___ has quit [Ping timeout: 258 seconds]
<gchristensen> hey everyone, I'm going to be hosting regular Nix ecosystem office hours starting next week. It'll be a video call where anyone can drop in and chat about the Nix ecosystem: cool PRs, problems, improvements, how to help each other to improve Nix. If you're interested, please tell me when you're available over at https://doodle.com/poll/aq9iytabi3k7z9da#calendar -- thank you!
pie_ has joined #nixos-security
<pie__> pie_, note to self for tomorrow: look into cve quality and related discussion items, misp, feeds, luxembourg feed, open vulnerability database & blog, ideals
<pie_> garbage in time consumption out
n_db has joined #nixos-security
LnL has quit [Ping timeout: 255 seconds]