Skip to content

Commit 5146347

Browse files
TristanCacquerayfrasertweedale
authored andcommitted
Add ZuriHac trip report to the 2025-q2 report
1 parent b6413de commit 5146347

File tree

1 file changed

+17
-1
lines changed

1 file changed

+17
-1
lines changed

reports/2025-07-13-Q2-report.md

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,23 @@ the mail address is there if no other appropriate channel exists.
4444

4545
## ZuriHac trip report
4646

47-
TODO - Tristan
47+
Members of the team met in person at ZuriHac. We discussed handling
48+
package namespaces to support external registries as part of the
49+
advisories we manage (see [issue#240][issue-240]). With the help of
50+
other attendees, we re-discovered a dependency confusion
51+
vulnerability in older versions of `cabal-install` (see
52+
[HSEC-2025-0005]).
53+
54+
The team also discussed long term project ideas to improve the
55+
ecosystem security. We have a few lists scattered in our meeting
56+
notes and we'll collect the ideas in a top level file to be shared
57+
with the community.
58+
59+
We would like to thank the ZuriHac organizers for the opportunity to
60+
meet with the other members of the ecosystem.
61+
62+
[issue-240]: https://github.com/haskell/security-advisories/issues/240
63+
[HSEC-2025-0005]: https://osv.dev/vulnerability/HSEC-2025-0005
4864

4965

5066
## Advisory database

0 commit comments

Comments
 (0)