andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
supersandro2000 has quit [Disconnected by services]
supersandro2000 has joined #nixos-security
<ris> i've always been a bit surprised we still allow push access for nixpkgs
<hexa-> ^
<hexa-> do we require 2fa?
<gchristensen> yes
<ris> that's something
<ris> though still, it only requires a single ssh key leak in theory
<ris> then there's the whole area of signed commits
<gchristensen> I'd love to require PRs
<hexa-> even kernel updates use pulls these days
star_cloud has quit [Ping timeout: 246 seconds]
justanotheruser has joined #nixos-security
ris has quit [Ping timeout: 246 seconds]
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
cjb has quit [Read error: Connection reset by peer]
cjb has joined #nixos-security
rajivr has joined #nixos-security
star_cloud has joined #nixos-security
bridge[evilred] has quit [Remote host closed the connection]
bridge[evilred] has joined #nixos-security
bridge[evilred] has quit [Excess Flood]
bridge[evilred] has joined #nixos-security
cjb has quit [Read error: Connection reset by peer]
cjb has joined #nixos-security
cjb has quit []
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
supersandro2000 has quit [Client Quit]
supersandro2000 has joined #nixos-security
cole-h has quit [Ping timeout: 240 seconds]
Guest44411 has quit [Quit: Idle for 30+ days]
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
star_cloud has quit [Excess Flood]
star_cloud has joined #nixos-security
aminechikhaoui has quit [Quit: The Lounge - https://thelounge.github.io]
aminechikhaoui has joined #nixos-security
FRidh has joined #nixos-security
{^_^} has quit [Remote host closed the connection]
{^_^} has joined #nixos-security
cole-h has joined #nixos-security
ris has joined #nixos-security
rajivr has quit [Quit: Connection closed for inactivity]
star_cloud has quit [Read error: Connection reset by peer]
star_cloud has joined #nixos-security
star_cloud has quit [Excess Flood]
star_cloud has joined #nixos-security
FRidh has quit [Quit: Konversation terminated!]
<hexa-> ris: there is this python2 question coming up again
<ris> ?
<hexa-> pillow/6.nix :)
<ris> yeah i don't know wtf i can really do about that, at the moment i'm seeing to what extent i can patch py3 on 20.09 for the recent vulnerabilities
<hexa-> yeah, I totally get it
<hexa-> its a dumbsterfire
<ris> i honestly don't know how they manage it
<ris> it's a one-project vulnerability factory
<hexa-> with lots of good intentions
<ris> i have 5 CVEs myself on it
<ris> well, a lot of legacy code
<ajs124> didn't we just update webkitgtk?
<ris> le sign. i want to do bad things to people who run souce formatters on repos. case in point: https://github.com/python-pillow/Pillow/commit/46b7e86bab79450ec0a2866c6c0c679afb659d17 good luck trying to port a patch past this wall
<hexa-> ajs124: yep
<hexa-> ajs124: also this time no 2.30.7
<hexa-> ris: lets mark pillow for 2.7 as vulnerable and lets move one
<hexa-> s/one/on/
<hexa-> or is that for python3?
<ris> i'm still doing the py3 one - i'll just mangle the patch and keep it in-tree, it's not big at least
<ris> py2 i don't think we have a choice
<ris> don't see it as practical
cjb has joined #nixos-security
cjb is now known as Guest92781
Guest92781 is now known as cjb
<{^_^}> #117991 (by mweinelt, 1 minute ago, open): webkitgtk: 2.30.6 -> 2.32.0
supersandro2000 has quit [Disconnected by services]
supersandro2000 has joined #nixos-security