Hi Jonathan,
On 10/8/26 18:54, indieterminacy wrote:
It would be interesting to purge all no longer secure packages (Im sure
there would be more).
It would be interesting to form an overview over this, just so were a
major insecurity discovered that it would be possible to immediately
know what should be removed or (re)edited.
Incase I have the time to look around are there any non obvious areas to
look?
I'm not sure what you mean with (non) obvious; I use `guix lint -c cve`,
and that gives plenty of things to fix.
There are several tickets specifically for tracking CVE's:
- electronics: https://codeberg.org/guix/guix/issues/2317
- sciene: https://codeberg.org/guix/guix/issues/2332
- sysadmin: https://codeberg.org/guix/guix/issues/2333
- python: https://codeberg.org/guix/guix/issues/2334
It has been kinda an uphill battle, so any help is welcome.
It is quite a fulfilling pastime to upgrade these packages, because who
knows, maybe you prevented someone from being hacked.
By the way, since August [1], `guix lint` accepts `--manifest`, so you
can start with packages you have in your own profile (it should also
have `--recursive` though).
Hugo
[1] Add --manifest to guix lint: https://codeberg.org/guix/guix/pulls/10653