-
-
Notifications
You must be signed in to change notification settings - Fork 1.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
maintainers: add checklist for security releases #11400
maintainers: add checklist for security releases #11400
Conversation
This issue has been mentioned on NixOS Discourse. There might be relevant details there: https://discourse.nixos.org/t/2024-09-02-nix-team-meeting-minutes-174/51512/2 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good communication is essential because we may only get one chance
This pull request has been mentioned on NixOS Discourse. There might be relevant details there: https://discourse.nixos.org/t/nar-unpacking-vulnerability-post-mortem/52301/1 |
This comment was marked as duplicate.
This comment was marked as duplicate.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks like solid improvement to case handling and communication.
This pull request has been mentioned on NixOS Discourse. There might be relevant details there: https://discourse.nixos.org/t/nix-2-24-8-release-to-fix-builtin-fetchurl-security-issue/52732/7 |
Co-Authored-By: Robert Hensing <[email protected] Co-authored-by: Dan Baker <[email protected]>
33ca556
to
9bb153a
Compare
Motivation
I promised I'll do it, to avoid omissions in the future
Context
Now and then we release security patches. Make sure it's a routine task to minimize risk, uncertainty, and disruption.
Priorities and Process
Add 👍 to pull requests you find important.
The Nix maintainer team uses a GitHub project board to schedule and track reviews.