gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
<ivan> great
<gchristensen> btw
<gchristensen> I'll be sending an announcement tomorrow(probably) that hydra will be down next Tuesday for a hardware upgrade
justanotheruser has quit [Ping timeout: 260 seconds]
justanotheruser has joined #nixos-security
colemickens_ has quit [Quit: Connection closed for inactivity]
ris has quit [Ping timeout: 258 seconds]
justanotheruser has quit [Ping timeout: 246 seconds]
justanotheruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 248 seconds]
justanotheruser has joined #nixos-security
ris has joined #nixos-security
justanotheruser has quit [Ping timeout: 260 seconds]
pie_ has joined #nixos-security
<flokli> andi-: I opened https://github.com/NixOS/nixpkgs/pull/76785 , which should finally fix CVE-2019-17365 for nixos stable…
<{^_^}> #76785 (by flokli, 46 seconds ago, open): [19.09] nix: 2.3 -> 2.3.1
<gchristensen> o.o
<flokli> yes.
<andi-> but isn't it a breaking change? :)
<gchristensen> I don't think it is
<gchristensen> is it?
<andi-> eelco said so in the other PR
<gchristensen> well, I sort of think we have to
<andi-> Yeah, I also think we have tol..
zarel_ has quit [Ping timeout: 260 seconds]
zarel has joined #nixos-security
pie_ has quit [Ping timeout: 258 seconds]
pie_ has joined #nixos-security
justanotheruser has joined #nixos-security
pie_ has quit [Quit: pie_]
pie_ has joined #nixos-security
pie_ has quit [Client Quit]
zarel has quit [Ping timeout: 260 seconds]
zarel has joined #nixos-security
<flokli> well, the nixpkgs activation script is is somewhat useless/bad if we have both around
<flokli> but simply ignoring the CVE and waiting for half a year isn't acceptable either
<flokli> as we haven't heard of anybody's unstable setup getting broken due to that, backporting to stable should be fine (tm)
kleisli has quit [Ping timeout: 268 seconds]