-
-
Notifications
You must be signed in to change notification settings - Fork 14.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update request: all firefox forks (CVE-2024-9680) #347960
Comments
The issue is that channel updates haven't included them yet: https://status.nixos.org/ |
I'm new to nix, so I'm not sure what kind of CI gauntlet PRs have to traverse before ending up in stable. I figured that if firefox can make it then so can its siblings.
How long is "a while"? It's been 2 days since the PRs have been opened. Is >2 days considered a reasonable wait for fixing a critical 0-day that is being exploited in the wild? |
Backport for Floorp was openend hours after the |
The backport for Firefox got merged a bit earlier than those for the other forks, that time was enough to have Firefox included in the last successful Hydra build on 2024-10-10T08:45:02Z that advanced the
It depends. Channels only get updated when all required checks succeed, so if one of those break it can be days until the next release. You can see historic channel age on Grafana:
I don't like the current situation either. However, the reproducible nature of Nix probably makes this harder than for most other Linux distros. E.g. if a core library like I haven't really seen a lot of discussion about this topic. Maybe someone else can point us somewhere? |
Closing this as it's been resolved (in nixos-24.05; unstable is still behind). Thank y'all for fixing this. Sorry for being impatient. I do think it's strange that maintainers aren't able to prioritize builds with important security fixes in Nix. |
This critical 0-day vulnerability affects all forks of firefox and they all need to be backported to stable nixos.
PRs for tor-browser, mullvad-browser, and librewolf were opened 2 days ago and still aren't available on nixos-24.05 or unstable. Why aren't they available yet?
https://search.nixos.org/packages?channel=unstable&from=0&size=50&sort=relevance&type=packages&query=floorp+librewolf+mullvad-browser
Notify maintainers
@felschr @panicgh @dotlambda @christoph-heiss @mweinelt
Note for maintainers: Please tag this issue in your PR.
Add a 👍 reaction to issues you find important.
The text was updated successfully, but these errors were encountered: