Post Ar9NZ6vYtdfRE2MSZc by hexa@chaos.social
(DIR) More posts by hexa@chaos.social
(DIR) Post #Ar9NZ6vYtdfRE2MSZc by hexa@chaos.social
2025-02-15T17:25:46Z
1 likes, 1 repeats
If you're using #devenv for your projects, please note that #telemetry was added in the 1.4.0 release.It handles `DO_NOT_TRACK=`¹ by sending that value along² with the telemetry instead of not sending any at all.But worse, it tars up all files it can find through `git ls-files -z`³ and exfiltrates them to the service.1/n[1] https://github.com/cachix/devenv/blob/6c987a8795eedea872afe4d1c1ac518d0c7f6db1/devenv/src/cli.rs#L202-L204[2] https://github.com/cachix/devenv/blob/6c987a8795eedea872afe4d1c1ac518d0c7f6db1/devenv/src/devenv.rs#L212-L214[3] https://github.com/cachix/devenv/blob/6c987a8795eedea872afe4d1c1ac518d0c7f6db1/devenv/src/devenv.rs#L226-L257#nixos #nix
(DIR) Post #Ar9NZEkrnHrjVBQ20u by hexa@chaos.social
2025-02-15T17:31:10Z
0 likes, 0 repeats
The #devenv CLI does not tell you any of this and neither `devenv.sh` nor `devenv.new` have a privacy policy or will tell you who runs the service in question and who it shares its data with.In #nixpkgs the package was bumped to 1.4.0 after which Christian Kampka immediately sent a follow-up PR¹ to enable `DO_NOT_TRACK=1` when wrapping the devenv binary.This was promptly reverted² by the author of devenv.2/n[1] https://github.com/NixOS/nixpkgs/pull/381817[2] https://github.com/NixOS/nixpkgs/pull/381981
(DIR) Post #Ar9NZMVuwkf3Z8UCp6 by hexa@chaos.social
2025-02-15T17:42:03Z
0 likes, 0 repeats
Unfortunately #nixpkgs currently does not seem well-equipped to resolve this conflict, due to a lack of policy and common sense seems not to be well distributed.Ultimately this is a governance issue for #NixOS where the steering committee would be in a great position to limit the scope of what is acceptable behaviour.In fact, if you have an opinion on the matter, please reach out to any steering committee representative and tell them:https://github.com/NixOS/org/blob/main/doc/governance.md3/n