Remediating thousands of untracked security vulnerabilities in #nixpkgshttps://fosdem.org/2024/schedule/event/fosdem-2024-1983-remediating-thousands-of-untracked-security-vulnerabilities-in-nixpkgs/
Through vendoring, many packages in #nixpkgs end up including obsolete and vulnerable versions of their dependencies. This is especially prevalent for #Rust, #Go, #JavaScript, #Java and #DotNET software using strict lockfiles. How bad is the current situation really? What can #nixpkgs contributors do to improve it?