gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
anselmolsm_ has quit [Quit: Konversation terminated!]
hmpffff has joined #nixos-security
hmpffff_ has quit [Ping timeout: 272 seconds]
edef_ has joined #nixos-security
edef_ is now known as edef
edef has quit [Killed (cherryh.freenode.net (Nickname regained by services))]
stigo has quit [*.net *.split]
stigo has joined #nixos-security
swapgs has quit [Ping timeout: 246 seconds]
swapgs has joined #nixos-security
swapgs has joined #nixos-security
swapgs has quit [Changing host]
hmpffff_ has joined #nixos-security
hmpffff has quit [Ping timeout: 244 seconds]
hmpffff has joined #nixos-security
hmpffff_ has quit [Ping timeout: 260 seconds]
infinisil has quit [Ping timeout: 246 seconds]
infinisil has joined #nixos-security
lejonet has quit [Ping timeout: 264 seconds]
lejonet has joined #nixos-security
sphalerite has quit [Quit: rebooooooooot]
sphalerite has joined #nixos-security
sphalerite has quit [Client Quit]
sphalerite has joined #nixos-security
<hexa-> andi-: unstable still stuck on the 21st
<hexa-> oh wait, that's newer than yesterday
<hexa-> still two weeks old
<hexa-> is it only evaluating channel bumps?
spacekookie has quit [Quit: **agressive swooshing**]
spacekookie has joined #nixos-security
anselmolsm has joined #nixos-security
justanotheruser has quit [Ping timeout: 260 seconds]
justanotheruser has joined #nixos-security
<andi-> yes otherwise I might as well boil water :D
<andi-> the 27th of april is the newest channel iirc
anselmolsm has quit [Remote host closed the connection]
anselmolsm has joined #nixos-security
<hexa-> looking into ansible now
<hexa-> #86981 #86980
<{^_^}> https://github.com/NixOS/nixpkgs/pull/86981 (by mweinelt, 29 seconds ago, open): [20.03] ansible: v2.8.7 → v2.8.11, v2.7.15 → v2.7.17
<{^_^}> https://github.com/NixOS/nixpkgs/pull/86980 (by mweinelt, 5 minutes ago, open): ansible: v2.9.2 → v2.9.7, v2.8.7 → v2.8.11, v2.7.15 → v2.7.17
<hexa-> is there a consenus on what to do about old packages that patches fixing security vulns, that are not recognizable as such by tools like broken.sh?
<hexa-> e.g. pkgs/applications/office/antiword/10_fix_buffer_overflow_wordole_c.patch
<flokli> I don't understand the question
<hexa-> should 10_fix_buffer_overflow_wordole_c.patch be renamed to CVE-2014-8123.patch so broken.sh can pick that up?
<hexa-> or what does broken.sh use to look up fixes?
<flokli> it usually uses the patch name. if we fetch it via fetchurl, this works, if it's a nonrecognizable patch shipped in nixpkgs, renaming might help.
<hexa-> antiword is shown as being vulnerable although it was ptched
KeiraT has quit [Ping timeout: 240 seconds]
KeiraT has joined #nixos-security
justanotheruser has quit [Ping timeout: 264 seconds]
justanotheruser has joined #nixos-security
stigo has quit [Ping timeout: 256 seconds]
stigo has joined #nixos-security