gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
{^_^} has quit [Remote host closed the connection]
{^_^} has joined #nixos-security
anselmolsm_ has quit [Quit: Konversation terminated!]
zarel_ has quit [Ping timeout: 265 seconds]
zarel has joined #nixos-security
hmpffff has joined #nixos-security
kleisli has quit [Ping timeout: 256 seconds]
hmpffff has quit [Quit: nchrrrr…]
ris has quit [Ping timeout: 265 seconds]
KeiraT has quit [Remote host closed the connection]
KeiraT has joined #nixos-security
<tokudan[m]> could someone look at https://github.com/NixOS/nixpkgs/pull/82049? it's a backport from unstable to fix a security issue in 19.09
<{^_^}> #82049 (by tokudan, 1 day ago, open): fetchmail: 6.3.26 to 6.4.2 [19.09] [security]
hmpffff has joined #nixos-security
hmpffff has quit [Client Quit]
hmpffff has joined #nixos-security
kleisli has joined #nixos-security
justanotheruser has quit [Ping timeout: 265 seconds]
justanotheruser has joined #nixos-security
justanotheruser has quit [Read error: Connection reset by peer]
<infinisil> "We have disabled TLS 1.0 and TLS 1.1 to improve your website connections. Sites that don't support TLS version 1.2 will now show an error page."
<infinisil> Very nice :)
<andi-> Yeah
<andi-> Ran into them a bunch already. I hope that helps drive TLS further. On the other hand it is scary what kind of pressure browser vendors (the few we have) do have on everyone.
hmpffff_ has joined #nixos-security
hmpffff has quit [Read error: Connection reset by peer]
justanotheruser has joined #nixos-security
hmpffff has joined #nixos-security
hmpffff_ has quit [Ping timeout: 260 seconds]
<tokudan[m]> andi-: don't know if ff74 needs any more updates besides the new version, so I've started a PR: https://github.com/NixOS/nixpkgs/pull/82257
<{^_^}> #82257 (by tokudan, 4 minutes ago, open): firefox{,bin}: 73.0.1 -> 74.0
<tokudan[m]> firefox-bin appears to work fine
<tokudan[m]> apparently a patch fails
<andi-> Yeah, we can drop that aarch64 patch now
<andi-> (that we merged yesterday :D)
<andi-> This new release cycle of mozilla really hasn't become my habit yet... I wasn't expecting the release this week.
<tokudan[m]> yay, the build worked for one whole day! =)
<tokudan[m]> (from yesterday till today)
<andi-> ha, NSS update required..
justanotheruser has quit [Ping timeout: 240 seconds]
justanotheruser has joined #nixos-security
<tokudan[m]> ah, then I'll let you continue with that. feel free to scrap my PR :)
<andi-> I'll just go from there
<tokudan[m]> should I reduce my PR to firefox-bin and you'll do firefox?
<andi-> That also works
<andi-> make sure to update the other -bin's as well please
<andi-> devedition and nightly
<andi-> as those might carry the same "security" fixes (if any)
<tokudan[m]> nightly = beta?
<andi-> Yeah, that makes more sense
hmpffff_ has joined #nixos-security
<tokudan[m]> https://github.com/NixOS/nixpkgs/pull/82257 for the three versions of firefox-bin is ready for review/merge
<{^_^}> #82257 (by tokudan, 29 minutes ago, open): firefox-bin: 73.0.1 -> 74.0
hmpffff has quit [Ping timeout: 258 seconds]
<andi-> tokudan[m]: I think firefox-esr-bin is still todo
<tokudan[m]> nix-repl> firefox-esr-bin
<tokudan[m]> error: undefined variable 'firefox-esr-bin' at (string):1:1
<tokudan[m]> I don't see a bin version of firefox-esr in nixpkgs, though I could be blind
<andi-> nevermind
<andi-> I am confused (and hungry)
hmpffff_ has quit [Quit: nchrrrr…]
kleisli has quit [Ping timeout: 240 seconds]
Synthetica has joined #nixos-security
anselmolsm has joined #nixos-security
hmpffff has joined #nixos-security
kleisli has joined #nixos-security
hmpffff has quit [Ping timeout: 272 seconds]
ris has joined #nixos-security
kleisli has quit [Remote host closed the connection]
kleisli has joined #nixos-security
hmpffff has joined #nixos-security
kleisli has quit [Remote host closed the connection]
kleisli has joined #nixos-security
justanotheruser has quit [Ping timeout: 272 seconds]
hmpffff has quit [Ping timeout: 256 seconds]
hmpffff has joined #nixos-security
kleisli has quit [Ping timeout: 260 seconds]
<andi-> anyone up for a review of the stable version bumps? https://github.com/NixOS/nixpkgs/pull/82280
<{^_^}> #82280 (by andir, 1 hour ago, open): [19.09] firefox: 73.0.1 -> 74.0, firefox-esr-68: 68.5.0esr -> 68.6.0esr, -bin updates
<andi-> I'll do 20.03 only tomorrow.. Gotta do something else now :)
justanotheruser has joined #nixos-security