-
-
Notifications
You must be signed in to change notification settings - Fork 17.6k
Open
0 / 10 of 1 issue completedOpen
0 / 10 of 1 issue completed
Copy link
Labels
0.kind: questionRequests for a specific question to be answeredRequests for a specific question to be answered6.topic: best practicesDocumentation and discussion around best practices for Nixpkgs developmentDocumentation and discussion around best practices for Nixpkgs development6.topic: developer experiencenixpkgs development workflownixpkgs development workflow6.topic: documentationMeta-discussion about documentation and its workflowMeta-discussion about documentation and its workflow
Description
Starting the conversation on how to handle the additions of knownVulnerabilities.
I am more inclined on merging as soon as possible to notify affected downstream users when doing so doesn't cause mass breakages but there is no policy/procedure in place specially around how to notify maintainers.
This issue was raised as a comment on marking qt5.webengine having known vulnerabilities: #435067 (comment)
cc @NixOS/security
Sub-issues
Metadata
Metadata
Assignees
Labels
0.kind: questionRequests for a specific question to be answeredRequests for a specific question to be answered6.topic: best practicesDocumentation and discussion around best practices for Nixpkgs developmentDocumentation and discussion around best practices for Nixpkgs development6.topic: developer experiencenixpkgs development workflownixpkgs development workflow6.topic: documentationMeta-discussion about documentation and its workflowMeta-discussion about documentation and its workflow