gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
kleisli has joined #nixos-security
anselmolsm has quit [Quit: Konversation terminated!]
_ris has joined #nixos-security
ris has quit [Ping timeout: 258 seconds]
infinisil has quit [Ping timeout: 256 seconds]
justanotheruser has quit [Ping timeout: 265 seconds]
infinisil has joined #nixos-security
<danderson> libsass 2xCVE fix: https://github.com/NixOS/nixpkgs/pull/82377
<{^_^}> #82377 (by danderson, 31 minutes ago, open): libsass: 3.6.1 -> 3.6.3
<danderson> unfortunately triggers a very large rebuild, and needs ports to 19.09 and 20.03.
infinisil has quit [Ping timeout: 256 seconds]
justanotheruser has joined #nixos-security
infinisil has joined #nixos-security
_ris has quit [Ping timeout: 258 seconds]
<danderson> if anyone with issue tracker permissions has a moment, could you go over this list: https://github.com/NixOS/nixpkgs/issues?q=is%3Aissue+is%3Aopen+label%3A%221.severity%3A+security%22+sort%3Aupdated-desc+commenter%3Adanderson
<danderson> I've been triaging and a lot of those issues can be closed. I commented on those that should be closed.
<danderson> (it's not all this list, but most of the issues in that list have a comment where I explain why it should be closed. Usually already patched or not applicable.
FRidh has joined #nixos-security
kleisli_ has joined #nixos-security
kleisli has quit [Ping timeout: 260 seconds]
kleisli has joined #nixos-security
kleisli_ has quit [Ping timeout: 255 seconds]
kleisli has quit [Ping timeout: 256 seconds]
FRidh has quit [Remote host closed the connection]
FRidh has joined #nixos-security
anselmolsm has joined #nixos-security
anselmolsm_ has joined #nixos-security
anselmolsm has quit [Ping timeout: 256 seconds]
anselmolsm has joined #nixos-security
anselmolsm_ has quit [Ping timeout: 260 seconds]
<danderson> Reminder, in a new timezone: could someone with issue tracker permissions go through https://github.com/NixOS/nixpkgs/issues?q=is%3Aissue+is%3Aopen+label%3A%221.severity%3A+security%22+sort%3Aupdated-desc+commenter%3Adanderson and close the bugs where my last comment says the bug can be closed?
<danderson> It should be 10-12 of the 14 bugs. Lots of n/a or already fixed CVE alerts.
<danderson> (or give me permissions to edit issues, if that's separable from commit access, and I'll close obsolete bugs myself :) )
kleisli has joined #nixos-security
anselmolsm has quit [Ping timeout: 256 seconds]
anselmolsm has joined #nixos-security
anselmolsm_ has joined #nixos-security
anselmolsm has quit [Ping timeout: 240 seconds]
_ris has joined #nixos-security
<andi-> danderson: I'll try to do that laster tonight or tomorrow morning
<andi-> (EU TZ)
<danderson> andi-: thanks!
FRidh has quit [Quit: Konversation terminated!]
kleisli has quit [Ping timeout: 255 seconds]
kleisli has joined #nixos-security
<danderson> Yay! If nobody beats me to it, I'll prepare backport PRs tonight after work.
<danderson> Is there a bug open to track?
<andi-> not yet just opened my mail after a few hours of other stuff..
<danderson> heh, sorry for enthusiasm. I'll be back in a couple hours
<andi-> I'll head to bed and be back in ~9h or so... hope to have some time to go throught the current issues then