gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
[krow] has quit [Remote host closed the connection]
sjkelly1 has joined #nixos-security
kleisli_ has quit [Ping timeout: 272 seconds]
kleisli_ has joined #nixos-security
justanotheruser has quit [Ping timeout: 244 seconds]
tldr32 has quit [Ping timeout: 240 seconds]
tldr32 has joined #nixos-security
anselmolsm has quit [Quit: Konversation terminated!]
sjkelly1 has quit [Remote host closed the connection]
kleisli_ has quit [Ping timeout: 240 seconds]
kleisli_ has joined #nixos-security
kleisli__ has joined #nixos-security
kleisli_ has quit [Read error: Connection reset by peer]
flx has quit [Ping timeout: 246 seconds]
flx has joined #nixos-security
justanotheruser has joined #nixos-security
kleisli__ has quit [Ping timeout: 240 seconds]
kleisli__ has joined #nixos-security
Synthetica has joined #nixos-security
kleisli_ has joined #nixos-security
<tokudan_> this PR was announced as a security issue to be patched immediately: https://github.com/NixOS/nixpkgs/pull/98097
<{^_^}> #98097 (by ajs124, 3 hours ago, open): matrix-synapse: 1.19.1 -> 1.19.2
<tokudan_> i'm setting up a PR for 20.03 and 20.09 in a second
<ajs124> you called?
kleisli__ has quit [Ping timeout: 240 seconds]
<tokudan_> ajs124, just wondering why your matrix PR isn't merged yet :)
<ajs124> I thought we might want to wait for Ma27 to give his ok, but I could just merge it. It's just a minor release (with an apparently important security fix), after all.
<tokudan_> dunno, if you know that Ma27 will respond shortly, we might wait, but for an important security fix I don't want to wait long
<ajs124> in his timezone (assuming he's not travelling, but given the global situation...), it's 19:30 right now, so I'd give him 2-3 more hours
<ajs124> tokudan_: in case you're on matrix, there's a nixos matrix channel (like... it's a channel on matrix, specifically about matrix stuff), where this kind of stuff is normally discussed. are you in there?
<tokudan_> ajs124, no, it's basically the #nixos irc channel bridged
<ajs124> that's not what I mean. I'm talking about matrix-nix:transformierende-gesellschaft.org
<ajs124> It's specifically about matrix-synapse, riot/element and other matrix client and server implementations in nixpkgs
<tokudan_> the backports to 20.03 and 20.09 are #98114 and #98117
<{^_^}> https://github.com/NixOS/nixpkgs/pull/98114 (by tokudan, 11 minutes ago, open): matrix-synapse: 1.19.1 -> 1.19.2 [20.03]
<{^_^}> https://github.com/NixOS/nixpkgs/pull/98117 (by tokudan, 1 minute ago, open): matrix-synapse: 1.19.1 -> 1.19.2 [20.09]
<tokudan_> ajs124, I wasn't aware about that channel, good to know
<tokudan_> ah, that room name is #matrix-nix:transformierende-gesellschaft.org :)
tokudan_ has quit [Remote host closed the connection]
tokudan has joined #nixos-security
justanotheruser has quit [Ping timeout: 244 seconds]
ris has joined #nixos-security
_ris has joined #nixos-security
ris has quit [Ping timeout: 260 seconds]
justanotheruser has joined #nixos-security
tilpner has quit [Ping timeout: 258 seconds]
justanotheruser has quit [Ping timeout: 244 seconds]
tilpner has joined #nixos-security
Synthetica has quit [Quit: Connection closed for inactivity]
hexa- has quit [Quit: WeeChat 2.7.1]