(CC of guix-security removed; please see below) Hi everyone,
I understand wanting the security team to be aware of security discussions and the like, but the guix-security (private) mailing list is really for reporting private security issues. Maybe a ping on some important related matter is fine, but in general please only email that list for non-public security issue reporting. I'm sure it was only the best of intentions (no apology necessary!), but I thought I'd better make a note so that the list can best serve its intended purpose. Thanks all! John On Thursday, October 8th, 2026 at 2:47 PM, Hugo Buddelmeijer via "Development of GNU Guix and the GNU System distribution." <[email protected]> wrote: > Hi Jonathan, > > On 10/8/26 18:54, indieterminacy wrote: > > It would be interesting to purge all no longer secure packages (Im sure > > there would be more). > > > > It would be interesting to form an overview over this, just so were a > > major insecurity discovered that it would be possible to immediately > > know what should be removed or (re)edited. > > > > Incase I have the time to look around are there any non obvious areas to > > look? > > I'm not sure what you mean with (non) obvious; I use `guix lint -c cve`, > and that gives plenty of things to fix. > > There are several tickets specifically for tracking CVE's: > - electronics: https://codeberg.org/guix/guix/issues/2317 > - sciene: https://codeberg.org/guix/guix/issues/2332 > - sysadmin: https://codeberg.org/guix/guix/issues/2333 > - python: https://codeberg.org/guix/guix/issues/2334 > > It has been kinda an uphill battle, so any help is welcome. > > It is quite a fulfilling pastime to upgrade these packages, because who > knows, maybe you prevented someone from being hacked. > > By the way, since August [1], `guix lint` accepts `--manifest`, so you > can start with packages you have in your own profile (it should also > have `--recursive` though). > > Hugo > > > [1] Add --manifest to guix lint: https://codeberg.org/guix/guix/pulls/10653 > >
