andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
<__red__> I wonder how much traffic a bot that spits out changes on issues/pullrequests that are tagged security would cause.
ris has quit [Ping timeout: 246 seconds]
rajivr has joined #nixos-security
<pie_> I imagine this is not terribly a problem but apparently (part of) githubs source code may or may not have been leaked
<pie_> I don't know how much effect this could have on infra but I imagine if the leak is legit theres more opportunity for audit and 0days
<pie_> people have discussed the security of github before and everyone wasnt running around screaming so im assuming its fiiiiiiiine
<pie_> Also not sure if the developer was impersonated or the account compromised
<__red__> right
<__red__> I'm guessing since 99% of our stuff is public only write issues or access to secrets could be problematic for the org - right?
<__red__> Uhh, you need to me a member admin to make a webhook
<pie_> <x> decrypted github enterprise source. trivially obtainable from public data. so, it's just a stunt
<__red__> so much for that idea
<__red__> oh well :-/
* pie_ is not able to substantiate that comment yet
<pie_> but the commenter is generally pretty reputable
<pie_> I imagine you can put anyone's name on a git(hub) commit though so they probably just did that
<pie_> Ill stop spamming now.
<pie_> btw just google the hash in the archive url
<__red__> thanks
<__red__> I was ammused
GUEST48003 has joined #nixos-security
justanotheruser has quit [Ping timeout: 272 seconds]
justanotheruser has joined #nixos-security
GUEST48003 has quit [Remote host closed the connection]
blueberrypie has quit [Quit: leaving]
GUEST48896 has joined #nixos-security
blueberrypie has joined #nixos-security
LnL has quit [Ping timeout: 240 seconds]
LnL has joined #nixos-security
<__red__> Coolio
<__red__> All - can we talk about #96781
<{^_^}> https://github.com/NixOS/nixpkgs/issues/96781 (by ckauhaus, 9 weeks ago, open): Vulnerability roundup 92: aerospike-server-4.2.0.4: 1 advisory [9.8]
<__red__> it's an RCE
<__red__> and upstream is broken
<__red__> unless we bump a major rev
<__red__> how do we want to deal with such things?
kalbasit has quit [Remote host closed the connection]
GUEST48896 has quit [Remote host closed the connection]
star0558 has joined #nixos-security
star0558 has quit [Remote host closed the connection]
star1616 has joined #nixos-security
star1616 has quit [Remote host closed the connection]
watt739 has joined #nixos-security
<__red__> #100296 closed, false positive (NVD database needs updating)
<{^_^}> https://github.com/NixOS/nixpkgs/issues/100296 (by ckauhaus, 3 weeks ago, closed): Vulnerability roundup 94: archiver-3.3.2: 1 advisory [5.5]
<__red__> #90750 - PR opened for it #102860
<{^_^}> https://github.com/NixOS/nixpkgs/issues/90750 (by ckauhaus, 19 weeks ago, open): Vulnerability roundup 85: archiver-3.3.0: 1 advisory [5.5]
<{^_^}> https://github.com/NixOS/nixpkgs/pull/102860 (by redvers, 1 minute ago, open): archiver: 3.3.0 -> 3.3.2 [20.09]
<__red__> #99734 - Closed - patched already
<{^_^}> https://github.com/NixOS/nixpkgs/issues/99734 (by ckauhaus, 4 weeks ago, closed): Vulnerability roundup 93: avahi-0.7: 1 advisory [9.1]
<__red__> Okay - #96775 - for https://github.com/ReadyTalk/avian
<{^_^}> https://github.com/NixOS/nixpkgs/issues/96775 (by ckauhaus, 9 weeks ago, open): Vulnerability roundup 92: avian-1.2.0: 2 advisories [7.8]
<__red__> Upstream is inactive, the release here is old... likie 2015
<__red__> apparently the only thing they're committing are security and reliabilty fixes
<__red__> but they're not bumping the revision
<__red__> ... and they're about 10 patches in 5 years...
<__red__> do I roll all the patches up?
<__red__> do I tag the current ref for master?
<__red__> I guess I'll tag thhe maintainer and ask them?
watt739 has quit [Ping timeout: 256 seconds]
<__red__> #90734
<{^_^}> https://github.com/NixOS/nixpkgs/issues/90734 (by ckauhaus, 19 weeks ago, open): Vulnerability roundup 85: balsa-2.5.9: 1 advisory [6.5]
<__red__> #94729
<{^_^}> https://github.com/NixOS/nixpkgs/issues/94729 (by ckauhaus, 13 weeks ago, open): Vulnerability roundup 91: balsa-2.5.9: 1 advisory [7.5]
<__red__> both ready with PR#102866
<__red__> #88269 closed - patchlevel is not vulnerable
<{^_^}> https://github.com/NixOS/nixpkgs/issues/88269 (by ckauhaus, 24 weeks ago, closed): Vulnerability roundup 84: bash-4.4-p23: 1 advisory
<__red__> #90745 is abandoned, but someone else has forked it and is now maintaining it in another github project (and is fairly active)
<{^_^}> https://github.com/NixOS/nixpkgs/issues/90745 (by ckauhaus, 19 weeks ago, open): Vulnerability roundup 85: beep-1.3: 2 advisories [7]
<__red__> There is no maintainer for the project
<__red__> so I guess I should add myself and switch the versions?
<__red__> Strictly speaking it's not vulnerable as we do not install it suid - so... I guess I can just close it and move on?
<__red__> (but my worry is that someone might suid it in the future)
<__red__> but they shhouldn't do that:tm:
watt976 has joined #nixos-security
watt976 has quit [Remote host closed the connection]
watt332 has joined #nixos-security
FRidh has joined #nixos-security
Guest82 has joined #nixos-security
Guest82 has quit [Client Quit]
watt332 has quit [Ping timeout: 264 seconds]
haiko has quit [Quit: Connection closed for inactivity]
FRidh has quit [Ping timeout: 260 seconds]
FRidh has joined #nixos-security
<ehmry> if you are interested in doing a nixos security voice chat, please mark your availability: https://www.when2meet.com/?10274768-cMAgo
<ehmry> this would be a continuation of the nixcon security breakout room
<ehmry> by security we also mean freaky isolation stuff
<pie_> kinky
<__red__> That's a really well designed tool
<__red__> I really like it
rajivr has quit [Quit: Connection closed for inactivity]
justan0theruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 244 seconds]
FRidh has quit [Quit: Konversation terminated!]
ris has joined #nixos-security
justan0theruser has quit [Ping timeout: 272 seconds]
justanotheruser has joined #nixos-security
<andi-> ehmry: is there a gist of the nixcon discussion?