Security Advisory: Local privilege escalation in Lix and Nix
https://discourse.nixos.org/t/security-advisory-local-privilege-escalation-in-lix-and-nix/77407
Summary Nix and Lix daemon implementations are affected by buffer overflows vulnerabilities that allow a local attacker to gain arbitrary code execution as the daemon user (root in multi-user installations). The vulnerabilities are identified as: Nix: GHSA-vh5x-56v6-4368, CVE ID pending attribution by MITRE. Lix: CVE ID pending attribution by MITRE. This is a coordinated disclosure between the Nix and Lix projects. Guix is NOT affected by this vulnerability. Am I affected? To exploit this ...
Did you know NixOS plans to cut a `26.05` release by the end of May? (schedule: https://github.com/NixOS/nixpkgs/issues/503391)
Today release process entered Zero Hydra Failures phase (https://github.com/NixOS/nixpkgs/issues/516381).
It's a great opportunity to contribute to `nixpkgs`. I tried squashing one `ZHF` failure today: https://trofi.github.io/posts/349-Zero-Hydra-Failures-towards-26.05-NixOS-release.html
(new account, so new introduction post (so i can pin it))
Hiii,
I’m quantenzitrone [ˈkvantn̩t͡siˈtʁoːnə] or short Zitrone, a mostly male #human. If your native language has a word for Zitrone (Lemon) with the same roots as Zitrone (de), e.g. Citron (fr), Cytryna (pl) or Sitruuna (fi), you may also use that one.
I like computers, especially those running #GNUlinux especially #NixOS. I’m still setting up my #homeserver with NixOS. I maintain a few packages and nixos modules in #nixpkgs. I'd call myself a nixpkgs maintainer. No commit bit, tho. Yet.
I like #programming, especially in #rustlang, sometimes when programming in other languages I notice that they are in fact not Rust. Sometimes I complain about it on here.
I like playing board or card games and i like cycling. What else? IDK, life. Just the joy of being, thinking and feeling.
I may meow at you especially if you’re cute OR meow-at-able
I study computer science at @uniheidelberg
You may meet me in the #RaumZeitLabor or at the #GPN, #ChaosCommunicationCongress, #MRMCD, #NixCon or #LixCon. (TODO: try out and go to more events)
My favourite logic gate is XOR.
GitHub recently announced that starting with v2.91.0 GitHub CLI will start sending pseudonymized telemetry data back to GitHub.
https://github.blog/changelog/2026-04-22-github-cli-opt-out-usage-telemetry/
Since this is an opt-out feature, most users will have it activated without knowing it. This is unacceptable in my opinion. So I took the liberty of turning this into an opt-in, disabled by default for nixpkgs.
I did a thing...
(Oh my god I am so nervous posting this!)
It will also be on #youtube tomorrow.
#rustlang #rust #development #softwaredevelopment #git #nixos #nixpkgs #streaming

Nixpkgs is drafting an AI policy and is looking for feedback on it https://github.com/NixOS/nixpkgs/pull/514587

The Nixpkgs core team feels it is overdue to establish an official policy on the use of automation for Nixpkgs contributions. The Code of Conduct has a clause against “Wasting other people’s time w...
#incident_response: Exposed GitHub token with push access
https://github.com/NixOS/nixpkgs/security/advisories/GHSA-67f2-674w-6g63