gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
ris has quit [Ping timeout: 246 seconds]
justanotheruser has quit [Ping timeout: 245 seconds]
justanotheruser has joined #nixos-security
justan0theruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 248 seconds]
hmpffff has joined #nixos-security
justan0theruser is now known as justanotheruser
hmpffff_ has joined #nixos-security
hmpffff has quit [Ping timeout: 252 seconds]
hmpffff_ has quit [Quit: nchrrrr…]
pie_ has quit [Ping timeout: 245 seconds]
ivan has quit [Quit: lp0 on fire]
book` has quit [Quit: Leaving]
book` has joined #nixos-security
ivan has joined #nixos-security
globin has joined #nixos-security
hmpffff has joined #nixos-security
hmpffff has quit [Quit: nchrrrr…]
pie_ has joined #nixos-security
hmpffff has joined #nixos-security
LnL7 is now known as LnL
c4rc4s has quit [Quit: Adios]
c4rc4s has joined #nixos-security
justanotheruser has quit [Ping timeout: 245 seconds]
justanotheruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 268 seconds]
justanotheruser has joined #nixos-security
ris has joined #nixos-security
<ris> my outstanding security PRs:
<ris> #64999
<{^_^}> https://github.com/NixOS/nixpkgs/pull/64999 (by risicle, 1 day ago, open): [r19.03] libu2f-host: 1.1.7 -> 1.1.8, fixing CVE-2019-9578
<ris> #64735
<{^_^}> https://github.com/NixOS/nixpkgs/pull/64735 (by risicle, 4 days ago, open): [r19.03] zeromq: 4.3.1 -> 4.3.2, fixing CVE-2019-13132
<gchristensen> btw ris
<ris> yup
<ris> #64729
<{^_^}> https://github.com/NixOS/nixpkgs/pull/64729 (by risicle, 4 days ago, open): [r19.03] dosbox: add patches for CVE-2019-7165 & CVE-2019-12594
<gchristensen> for future backport PRs, use `git cherry-pick -x the-original-commit-hash`
<ris> yeah, i do _sometimes_, but often the backports are different
<gchristensen> aye
<ris> oh and sometimes i do the backports in parallel because it avoids the confusing oh-the-merger-did-the-cherrypick-themselves situation
<ris> that-was-a-waste-of-10-minutes
<ris> and if i just leave it, i will probably forget to come back and check the backport got done
<ris> cool thanks
<ris> oh and #64731
<{^_^}> https://github.com/NixOS/nixpkgs/pull/64731 (by risicle, 4 days ago, open): dosbox: 0.74-2 -> 0.74-3, fixing CVE-2019-7165, CVE-2019-12594
<gchristensen> you're kicking butt
<ris> butt needs kicking
<ris> meanwhile costrouc seems to be managing to add half of pypi to nixpkgs with tests enabled and working
hmpffff has quit [Quit: Bye…]
<gchristensen> woww yay