Skip to content

Policy/Procedure for additions to knownVulnerabilities with dependents #438361

@fabianhjr

Description

@fabianhjr

Starting the conversation on how to handle the additions of knownVulnerabilities.

I am more inclined on merging as soon as possible to notify affected downstream users when doing so doesn't cause mass breakages but there is no policy/procedure in place specially around how to notify maintainers.

This issue was raised as a comment on marking qt5.webengine having known vulnerabilities: #435067 (comment)

cc @NixOS/security

Sub-issues

Metadata

Metadata

Assignees

No one assigned

    Labels

    0.kind: questionRequests for a specific question to be answered6.topic: best practicesDocumentation and discussion around best practices for Nixpkgs development6.topic: developer experiencenixpkgs development workflow6.topic: documentationMeta-discussion about documentation and its workflow

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions