<
__red__>
I wonder how much traffic a bot that spits out changes on issues/pullrequests that are tagged security would cause.
ris has quit [Ping timeout: 246 seconds]
rajivr has joined #nixos-security
<
pie_>
I imagine this is not terribly a problem but apparently (part of) githubs source code may or may not have been leaked
<
pie_>
I don't know how much effect this could have on infra but I imagine if the leak is legit theres more opportunity for audit and 0days
<
pie_>
people have discussed the security of github before and everyone wasnt running around screaming so im assuming its fiiiiiiiine
<
pie_>
Also not sure if the developer was impersonated or the account compromised
<
__red__>
I'm guessing since 99% of our stuff is public only write issues or access to secrets could be problematic for the org - right?
<
__red__>
Uhh, you need to me a member admin to make a webhook
<
pie_>
<x> decrypted github enterprise source. trivially obtainable from public data. so, it's just a stunt
<
__red__>
so much for that idea
<
__red__>
oh well :-/
* pie_
is not able to substantiate that comment yet
<
pie_>
but the commenter is generally pretty reputable
<
pie_>
I imagine you can put anyone's name on a git(hub) commit though so they probably just did that
<
pie_>
Ill stop spamming now.
<
pie_>
btw just google the hash in the archive url
<
__red__>
I was ammused
GUEST48003 has joined #nixos-security
justanotheruser has quit [Ping timeout: 272 seconds]
justanotheruser has joined #nixos-security
GUEST48003 has quit [Remote host closed the connection]
blueberrypie has quit [Quit: leaving]
GUEST48896 has joined #nixos-security
blueberrypie has joined #nixos-security
LnL has quit [Ping timeout: 240 seconds]
LnL has joined #nixos-security
<
__red__>
All - can we talk about #96781
<
__red__>
it's an RCE
<
__red__>
and upstream is broken
<
__red__>
unless we bump a major rev
<
__red__>
how do we want to deal with such things?
kalbasit has quit [Remote host closed the connection]
GUEST48896 has quit [Remote host closed the connection]
star0558 has joined #nixos-security
star0558 has quit [Remote host closed the connection]
star1616 has joined #nixos-security
star1616 has quit [Remote host closed the connection]
watt739 has joined #nixos-security
<
__red__>
#100296 closed, false positive (NVD database needs updating)
<
__red__>
#90750 - PR opened for it #102860
<
__red__>
#99734 - Closed - patched already
<
__red__>
Upstream is inactive, the release here is old... likie 2015
<
__red__>
apparently the only thing they're committing are security and reliabilty fixes
<
__red__>
but they're not bumping the revision
<
__red__>
... and they're about 10 patches in 5 years...
<
__red__>
do I roll all the patches up?
<
__red__>
do I tag the current ref for master?
<
__red__>
I guess I'll tag thhe maintainer and ask them?
watt739 has quit [Ping timeout: 256 seconds]
<
__red__>
both ready with PR#102866
<
__red__>
#88269 closed - patchlevel is not vulnerable
<
__red__>
#90745 is abandoned, but someone else has forked it and is now maintaining it in another github project (and is fairly active)
<
__red__>
There is no maintainer for the project
<
__red__>
so I guess I should add myself and switch the versions?
<
__red__>
Strictly speaking it's not vulnerable as we do not install it suid - so... I guess I can just close it and move on?
<
__red__>
(but my worry is that someone might suid it in the future)
<
__red__>
but they shhouldn't do that:tm:
watt976 has joined #nixos-security
watt976 has quit [Remote host closed the connection]
watt332 has joined #nixos-security
FRidh has joined #nixos-security
Guest82 has joined #nixos-security
Guest82 has quit [Client Quit]
watt332 has quit [Ping timeout: 264 seconds]
haiko has quit [Quit: Connection closed for inactivity]
FRidh has quit [Ping timeout: 260 seconds]
FRidh has joined #nixos-security
<
ehmry>
this would be a continuation of the nixcon security breakout room
<
ehmry>
by security we also mean freaky isolation stuff
<
__red__>
That's a really well designed tool
<
__red__>
I really like it
rajivr has quit [Quit: Connection closed for inactivity]
justan0theruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 244 seconds]
FRidh has quit [Quit: Konversation terminated!]
ris has joined #nixos-security
justan0theruser has quit [Ping timeout: 272 seconds]
justanotheruser has joined #nixos-security
<
andi->
ehmry: is there a gist of the nixcon discussion?