Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Jitsi-meet is marked as insecure by NixOS and cannot be installed without passing export NIXPKGS_ALLOW_INSECURE=1 #15107

Open
11 tasks
amalgame21 opened this issue Sep 10, 2024 · 2 comments

Comments

@amalgame21
Copy link

amalgame21 commented Sep 10, 2024

What happened?

https://github.com/NixOS/nixpkgs/blob/master/pkgs/development/libraries/olm/default.nix#L30-L75

https://github.com/NixOS/nixpkgs/blob/master/pkgs/servers/web-apps/jitsi-meet/default.nix#L37

Platform

  • Chrome (or Chromium based)
  • Firefox
  • Safari
  • Other desktop browser
  • Android browser
  • iOS browser
  • Electron app
  • Android mobile app
  • iOS mobile app
  • Custom app using a mobile SDK

Browser / app / sdk version

jitsi-meet-1.0.7952

Relevant log output

No response

Reproducibility

  • The problem is reproducible on meet.jit.si

More details?

No response

@saghul
Copy link
Member

saghul commented Sep 10, 2024

IMHO that's too harsh from Nix. There are no known explots to those CVEs.

At any rate problem here is that there is no direct path for migrating from Olm to Vodozemac because the JS bindings are unmaintained: matrix-org/vodozemac-bindings#9

We are currently evaluating what to do here.

@amalgame21
Copy link
Author

Thank you for your effort!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants