andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
supersandro2000 has quit [Disconnected by services]
supersandro2000 has joined #nixos-security
rajivr has joined #nixos-security
ris has quit [Ping timeout: 264 seconds]
dstzd has quit [Quit: ZNC - https://znc.in]
dstzd has joined #nixos-security
andi- has quit [Ping timeout: 272 seconds]
andi- has joined #nixos-security
supersandro2000 has quit [Read error: Connection reset by peer]
supersandro2000 has joined #nixos-security
supersandro2000 has quit [Disconnected by services]
supersandro2000 has joined #nixos-security
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
star_cloud has quit [Excess Flood]
star_cloud has joined #nixos-security
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
red[evilred] has joined #nixos-security
<red[evilred]> Okay
<red[evilred]> I'm finished with my full complete pass of the security vulnerabilty issues.
<red[evilred]> Took me a week or two, but I've closed around 400 of them.
<red[evilred]> only 255 of them left
kalbasit has quit [Ping timeout: 256 seconds]
cole-h has quit [Ping timeout: 240 seconds]
<supersandro2000> red[evilred]++
<{^_^}> red[evilred]'s karma got increased to 2
FRidh has joined #nixos-security
FRidh has quit [Remote host closed the connection]
watt313 has joined #nixos-security
FRidh has joined #nixos-security
watt313 has quit [Ping timeout: 265 seconds]
<stigo> red[evilred]++
<{^_^}> red[evilred]'s karma got increased to 3
red[evilred] has quit [Quit: Idle timeout reached: 10800s]
Rostand has quit [Remote host closed the connection]
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
star_cloud has quit [Excess Flood]
star_cloud has joined #nixos-security
<Yakulu[m]> It seems there will be high priority issue fixed tuesday in OpenSSL : https://mta.openssl.org/pipermail/openssl-announce/2020-December/000186.html
zarel has quit [Quit: ZNC 1.7.5 - https://znc.in]
zarel has joined #nixos-security
cole-h has joined #nixos-security
kalbasit has joined #nixos-security
<maljub01> Hi there, I just had Nix warn me because it was about to install a package with a known vulnerability. I didn't know about this feature. It's pretty awesome! :)
<maljub01> However, I'm wondering if the escape hatch is appropriate
<maljub01> Ideally, a user should permit specific CVEs rather than specific vulnerable packages
<maljub01> Because otherwise, one might think a particular insecure package is ok because it doesn't affect their use-case, but by whitelisting the package as a whole, they'll also be signing up for silently accepting any and all future vulnerabilities.
<maljub01> So, my question is, would there be any interest in introducing an option for that? Basically `nixpkgs.config.permittedCVEs` or `nixpkgs.config.allowedVulnerabilities`
kalbasit_ has joined #nixos-security
kalbasit has quit [Ping timeout: 256 seconds]
red[evilred] has joined #nixos-security
<red[evilred]> I think we have that mechanism kinda already - I'm stull trtying to understand it
<red[evilred]> but it's in the specific nixpkg
<red[evilred]> anyone?
<tilpner> maljub01: You can probably match on specific package versions with allowInsecurePredicate
<tilpner> (That should also allow you to prototype the CVE matching without any changes to nixpkgs)
cole-h has quit [Ping timeout: 240 seconds]
rajivr has quit [Quit: Connection closed for inactivity]
<red[evilred]> I thought we had a meta-field that could list CVEs
<red[evilred]> and blocked a package from being built unless the user accepted the CVEs in their config.nix
<red[evilred]> if not - RFC time? ;-)
KREYREEN has quit [Remote host closed the connection]
KREYREEN has joined #nixos-security
ris has joined #nixos-security
tilpner has quit [Remote host closed the connection]
tilpner has joined #nixos-security
star_cloud has quit [Ping timeout: 240 seconds]
KREYREEN has quit [Remote host closed the connection]
KREYREEN has joined #nixos-security
FRidh has quit [Read error: Connection reset by peer]
ajs124 has quit [Quit: killed]
ajs124 has joined #nixos-security
lukegb has quit [Quit: ~~lukegb out~~]
lukegb has joined #nixos-security
star_cloud has joined #nixos-security
<pie_> red[evilred]: slightly related https://github.com/NixOS/nixpkgs/issues/57833
<{^_^}> #57833 (by deliciouslytyped, 1 year ago, open): Additional meta-information conventions
justanotheruser has quit [Ping timeout: 272 seconds]
star_cloud has quit [Ping timeout: 240 seconds]
star_cloud has joined #nixos-security
justanotheruser has joined #nixos-security
tilpner_ has joined #nixos-security
tilpner_ has quit [Client Quit]
tilpner_ has joined #nixos-security
tilpner has quit [Ping timeout: 260 seconds]
tilpner_ is now known as tilpner
MichaelRaskin has joined #nixos-security
kalbasit_ has quit [Ping timeout: 240 seconds]
zarel has quit [Quit: ZNC 1.7.5 - https://znc.in]
zarel has joined #nixos-security