gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
ris has quit [Ping timeout: 276 seconds]
hmpffff_ has joined #nixos-security
hmpffff has quit [Ping timeout: 276 seconds]
qyliss has quit [Quit: bye]
qyliss has joined #nixos-security
tokudan[m] has quit [Write error: Connection reset by peer]
timokau[m] has quit [Read error: Connection reset by peer]
timokau[m] has joined #nixos-security
tokudan[m] has joined #nixos-security
ris has joined #nixos-security
<ris> the only use of jackson-databind i can _see_ in nixpkgs is as a maven dep for chronos
<ris> though really anywhere we grab a jar blind, we could have it lurking
<ris> #69973 should also be considered a security issue
<{^_^}> https://github.com/NixOS/nixpkgs/pull/69973 (by r-ryantm, 1 week ago, open): varnish6: 6.2.0 -> 6.3.0
<ris> ^ again it would be nice if someone could add the tag
<ris> #70532
<{^_^}> https://github.com/NixOS/nixpkgs/pull/70532 (by risicle, 23 minutes ago, open): [r19.09] varnish6: 6.2.0 -> 6.2.1, fixing CVE-2019-15892
<fpletz> ris: thanks for the varnish fixes
<ris> :+1:
<fpletz> we should should also remove versions 4 and 5
<fpletz> since they aren't maintained upstream anymore
<ris> 4 certainly isn't
<fpletz> I'll remove those old versions and add the maintained ones
<fpletz> since I'm technically the nixos maintainer of varnish... though I haven't given it much love lately
aanderse[m] has joined #nixos-security
aanderse has quit [Quit: ZNC 1.7.4 - https://znc.in]
aanderse[m] is now known as aanderse
ris has quit [Ping timeout: 250 seconds]