File tree Expand file tree Collapse file tree 1 file changed +17
-1
lines changed Expand file tree Collapse file tree 1 file changed +17
-1
lines changed Original file line number Diff line number Diff line change @@ -44,7 +44,23 @@ the mail address is there if no other appropriate channel exists.
44
44
45
45
## ZuriHac trip report
46
46
47
- TODO - Tristan
47
+ Members of the team met in person at ZuriHac. We discussed handling
48
+ package namespaces to support external registries as part of the
49
+ advisories we manage (see [ issue #240 ] [ issue-240 ] ). With the help of
50
+ other attendees, we re-discovered a dependency confusion
51
+ vulnerability in older versions of ` cabal-install ` (see
52
+ [ HSEC-2025-0005] ).
53
+
54
+ The team also discussed long term project ideas to improve the
55
+ ecosystem security. We have a few lists scattered in our meeting
56
+ notes and we'll collect the ideas in a top level file to be shared
57
+ with the community.
58
+
59
+ We would like to thank the ZuriHac organizers for the opportunity to
60
+ meet with the other members of the ecosystem.
61
+
62
+ [ issue-240 ] : https://github.com/haskell/security-advisories/issues/240
63
+ [ HSEC-2025-0005 ] : https://osv.dev/vulnerability/HSEC-2025-0005
48
64
49
65
50
66
## Advisory database
You can’t perform that action at this time.
0 commit comments