Security: sandbox escape #426

Open
opened 2024-06-27 15:54:57 +00:00 by roberth · 1 comment

With the Nix team we've posted a fix for a sandbox escape vulnerability.
Next time I'd like to coordinate this with you. Perhaps we could set up a private matrix room for this purpose?
Also I couldn't find anything about reporting security issues just now; we provide a security policy through GitHub's UI, so you could perhaps do something similar here, or work around a missing feature with an issue template that contains it.

With the Nix team we've posted a fix for [a sandbox escape vulnerability](https://discourse.nixos.org/t/security-fix-nix-derivation-sandbox-escape/47778). Next time I'd like to coordinate this with you. Perhaps we could set up a private matrix room for this purpose? Also I couldn't find anything about reporting security issues just now; we provide a security policy through GitHub's UI, so you could perhaps do something similar here, or work around a missing feature with an issue template that contains it.
Author

In fact, let me apologize for failing to coordinate anything with you this first time.

In fact, let me apologize for failing to coordinate anything with you this first time.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: lix-project/lix#426
No description provided.