andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
justanotheruser has quit [Ping timeout: 265 seconds]
<hexa-> one more week of double-backports
<hexa-> eh, five days even
justanotheruser has joined #nixos-security
rajivr has joined #nixos-security
LnL has quit [Quit: exit 1]
LnL has joined #nixos-security
LnL has quit [Ping timeout: 256 seconds]
LnL has joined #nixos-security
ehmry has quit [Quit: https://quassel-irc.org - Chat comfortably. Anywhere.]
justanotheruser has quit [Ping timeout: 260 seconds]
justanotheruser has joined #nixos-security
tokudan has quit [Quit: Dunno.]
tokudan has joined #nixos-security
tokudan has quit [Remote host closed the connection]
tokudan has joined #nixos-security
tokudan has quit [Quit: Dunno.]
tokudan has joined #nixos-security
ris has quit [Ping timeout: 256 seconds]
justanotheruser has quit [Ping timeout: 272 seconds]
justanotheruser has joined #nixos-security
kalbasit has joined #nixos-security
kalbasit has quit [Ping timeout: 240 seconds]
FRidh has joined #nixos-security
red[evilred] has joined #nixos-security
<red[evilred]> exactly hexa-
<red[evilred]> can't lie - been tempted to look the other way a few time
<red[evilred]> s
FRidh has quit [Ping timeout: 264 seconds]
FRidh has joined #nixos-security
FRidh has quit [Ping timeout: 260 seconds]
FRidh has joined #nixos-security
<stigo> hexa-: #104422 probably shouldn't have been merged (my bad), would it be ok to revert the bump which have been merged into release-20.09 in favour of a patch that directly fixes the vuln?
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104422 (by stigtsp, 1 day ago, merged): [20.09] mutt: 1.14.7 -> 2.0.2
<hexa-> stigo: please do
ehmry has joined #nixos-security
<stigo> done. reverted in #104582 fixed in #104583 and #104584
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104582 (by stigtsp, 29 minutes ago, merged): Revert "[20.09] mutt: 1.14.7 -> 2.0.2"
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104583 (by stigtsp, 21 minutes ago, open): [20.03] mutt: apply patch for CVE-2020-28896
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104584 (by stigtsp, 8 minutes ago, open): [20.09] mutt: apply patch for CVE-2020-28896
ris has joined #nixos-security
<stigo> hexa-: i'm looking forward to not having to do double-backports as well.
<FRidh> we should really have a github action for that
<hexa-> well, for security it's often no double backporting
<hexa-> a version one release back often needs special handling due to major version bumps, patches not applying cleanly
<hexa-> but sure, backporting in general should be automated, I agree
<hexa-> i thought mic92 recently mentioned some tool over in #nixos-dev
<hexa-> but seems be affected by shell code injection madness
ehmry has quit [Read error: Connection reset by peer]
ehmry has joined #nixos-security
red[evilred] has quit [Quit: Idle timeout reached: 10800s]
red[evilred] has joined #nixos-security
<red[evilred]> probably
<red[evilred]> I think someone said that nix-something was able to do upgrades if you gave it source and dest versions
<red[evilred]> and it will do the branch, do the testing, open the pr etc ?
FRidh has quit [Quit: Konversation terminated!]
lukegb has quit [Quit: ~~lukegb out~~]
lukegb has joined #nixos-security
FRidh has joined #nixos-security
ehmry has quit [Quit: https://quassel-irc.org - Chat comfortably. Anywhere.]
rajivr has quit [Quit: Connection closed for inactivity]
WilliButz has quit [Remote host closed the connection]
WilliButz has joined #nixos-security
red[evilred] has quit [Quit: Idle timeout reached: 10800s]
IdleBot_4fae1f80 has quit [*.net *.split]
bridge[evilred] has quit [*.net *.split]
ikwildrpepper has quit [*.net *.split]
IdleBot_4fae1f80 has joined #nixos-security
bridge[evilred] has joined #nixos-security
ikwildrpepper has joined #nixos-security
tilpner has quit [Ping timeout: 260 seconds]
tilpner_ has joined #nixos-security
tilpner_ is now known as tilpner
bennofs is now known as bennofs|ALLES
FRidh has quit [Quit: Konversation terminated!]
justanotheruser has quit [Ping timeout: 260 seconds]
justanotheruser has joined #nixos-security