Hello!

In addition to the news entry that ‘guix pull’ will display, we may want
to publicize the issue.  In particular, should we:

  1. Apply for a new CVE?

  2. Post an article on the blog to explain in detail what happened?
     That should probably include an analysis like that at
     <https://www.openwall.com/lists/oss-security/2019/10/09/4>, given
     that Guix does things not entirely like Nix here.

  3. Email that analysis to oss-security?

  4. Push a new release?

I’m tempted to think that we should do 1 to 3, as quickly as we can.
Help welcome, in particular on #2!

As for #4, I think we should push a new release soon anyway, but maybe
not just specifically for this issue since it can be addressed simply by
upgrading.

Thoughts?

Ludo’.



  • bug#37744: Per-user pro... Ludovic Courtès
    • bug#37744: Per-use... Ludovic Courtès
      • bug#37744: Per... Tobias Geerinckx-Rice via Bug reports for GNU Guix
        • bug#37744:... Maxim Cournoyer
        • bug#37744:... Ludovic Courtès
          • bug#37... Tobias Geerinckx-Rice via Bug reports for GNU Guix
            • b... Ludovic Courtès
              • ... Ludovic Courtès
                • ... Ludovic Courtès
                • ... pelzflorian (Florian Pelz)
                • ... Tobias Geerinckx-Rice via Bug reports for GNU Guix
                • ... pelzflorian (Florian Pelz)
                • ... Tobias Geerinckx-Rice via Bug reports for GNU Guix
                • ... Ludovic Courtès
                • ... Tobias Geerinckx-Rice via Bug reports for GNU Guix
                • ... Tobias Geerinckx-Rice via Bug reports for GNU Guix
                • ... Ludovic Courtès
                • ... Ludovic Courtès
                • ... Julien Lepiller

Reply via email to