Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nixpkgs manual: add section on submitting security fixes #72290

Merged
merged 1 commit into from Nov 13, 2019

Conversation

FRidh
Copy link
Member

@FRidh FRidh commented Oct 30, 2019

Motivation for this change
Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nix-review --run "nix-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Ensured that relevant documentation is up to date
  • Fits CONTRIBUTING.md.
Notify maintainers

cc @ckauhaus

@FRidh
Copy link
Member Author

FRidh commented Oct 30, 2019

@c0bw3b
Copy link
Contributor

c0bw3b commented Oct 31, 2019

Another open question:

  • how to name a single patch fixing multiple CVEs ? [A] or [B] or [C]

@c0bw3b
Copy link
Contributor

c0bw3b commented Oct 31, 2019

About version number prefixing the patch name -> I think it should be avoided, as the CVE description (from NVD or other sources) will state which versions are vulnerable and patched, and it is usually a range.

@FRidh
Copy link
Member Author

FRidh commented Oct 31, 2019

I suppose the version number was typically added when there are multiple versions of a package, and each version needs a patch for the CVE but a different one.

@FRidh
Copy link
Member Author

FRidh commented Nov 13, 2019

Going ahead and will open a separate issue with these questions.

@FRidh FRidh merged commit ff06057 into NixOS:master Nov 13, 2019
@FRidh
Copy link
Member Author

FRidh commented Nov 13, 2019

questions are now in #73342

@FRidh FRidh deleted the security branch November 13, 2019 14:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants