(CC of guix-security removed; please see below)

Hi everyone,

I understand wanting the security team to be aware of security discussions and 
the like, but the guix-security (private) mailing list is really for reporting 
private security issues. Maybe a ping on some important related matter is fine, 
but in general please only email that list for non-public security issue 
reporting.

I'm sure it was only the best of intentions (no apology necessary!), but I 
thought I'd better make a note so that the list can best serve its intended 
purpose.

Thanks all!
John



On Thursday, October 8th, 2026 at 2:47 PM, Hugo Buddelmeijer via "Development 
of GNU Guix and the GNU System distribution." <[email protected]> wrote:

> Hi Jonathan,
>
> On 10/8/26 18:54, indieterminacy wrote:
> > It would be interesting to purge all no longer secure packages (Im sure
> > there would be more).
> >
> > It would be interesting to form an overview over this, just so were a
> > major insecurity discovered that it would be possible to immediately
> > know what should be removed or (re)edited.
> >
> > Incase I have the time to look around are there any non obvious areas to
> > look?
>
> I'm not sure what you mean with (non) obvious; I use `guix lint -c cve`,
> and that gives plenty of things to fix.
>
> There are several tickets specifically for tracking CVE's:
> - electronics: https://codeberg.org/guix/guix/issues/2317
> - sciene: https://codeberg.org/guix/guix/issues/2332
> - sysadmin: https://codeberg.org/guix/guix/issues/2333
> - python: https://codeberg.org/guix/guix/issues/2334
>
> It has been kinda an uphill battle, so any help is welcome.
>
> It is quite a fulfilling pastime to upgrade these packages, because who
> knows, maybe you prevented someone from being hacked.
>
> By the way, since August [1], `guix lint` accepts `--manifest`, so you
> can start with packages you have in your own profile (it should also
> have `--recursive` though).
>
> Hugo
>
>
> [1] Add --manifest to guix lint: https://codeberg.org/guix/guix/pulls/10653
>
>

Reply via email to