3 ms·
You can't make them go away, but you can follow upstream for security fixes as close as possible and communicate them as good as possible. Nixpkg does quite a
by phaer 4y ago
You can't make them go away, but you can follow upstream for security fixes as close as possible and communicate them as good as possible.
Nixpkg does quite a good job in tracking those issues, imho. https://github.com/NixOS/nixpkgs/issues?q=is%3Aopen+is%3Aissue+label%3A%221.severity%3A+security%22 https://github.com/NixOS/nixpkgs/issues?q=is%3Aopen+is%3Aiss... is a list of security issues. Most of them generated by automated scans of nixpkgs-unstable.
But as far as I am aware, there's no mailing list or so for receiving notifications upon critical vulnerabilities(?). https://nixos.org/community/teams/security.html https://nixos.org/community/teams/security.html mentions github issues, discourse and matrix.
Triaging security issues requires significant work and it's a task even more traditional distros like Debian often struggle with.
One thing I'd like to see eventually is an option to nixos-rebuild and other to emit warnings if installed packages are affected by known vulnerabilities. I think that should be doable and would maybe raise awareness and provide most visibility to the issues affecting most users.
https://github.com/flyingcircusio/vulnix https://github.com/flyingcircusio/vulnix does something like this, but it's currently a third-party tool
- 0des 4y agoUpstream doesn't matter if they aren't merging fixes for over a month.