From dcc96468d8e5b55719e2b73c886530d9e31070f7 Mon Sep 17 00:00:00 2001 From: whispers Date: Fri, 2 Oct 2026 00:54:21 -0400 Subject: [PATCH] arti: 2.6.0 -> 2.7.0 blog: https://blog.torproject.org/arti_2_7_0_released/ changelog: https://gitlab.torproject.org/tpo/core/arti/-/blob/arti-v2.7.0/CHANGELOG.md diff: https://gitlab.torproject.org/tpo/core/arti/-/compare/arti-v2.6.0...arti-v2.7.0 trove: https://gitlab.torproject.org/tpo/core/team/-/wikis/NetworkTeam/TROVE/2026 this release fixes 1 high, 5 medium, and 6 low severity security vulnerabilities. --- pkgs/by-name/ar/arti/package.nix | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/ar/arti/package.nix b/pkgs/by-name/ar/arti/package.nix index 34b9366e2a5d..8e69f3e6c3db 100644 --- a/pkgs/by-name/ar/arti/package.nix +++ b/pkgs/by-name/ar/arti/package.nix @@ -13,7 +13,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "arti"; - version = "2.6.0"; + version = "2.7.0"; src = fetchFromGitLab { domain = "gitlab.torproject.org"; @@ -21,7 +21,7 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "core"; repo = "arti"; tag = "arti-v${finalAttrs.version}"; - hash = "sha256-ukGplnZz1O1Djh12COKk8FL/3rLmmWGyl0b816wRWBE="; + hash = "sha256-28s2BnesadPGm1gQDxzIqSgGaUd8ZgoTpKK3WXBRU9Q="; }; # Working around a bug in cargo that appears with cargo-auditable, see @@ -29,15 +29,17 @@ rustPlatform.buildRustPackage (finalAttrs: { postPatch = '' substituteInPlace crates/arti/Cargo.toml \ --replace-fail '"http"' '"dep:http"' \ - --replace-fail '"tokio-util"' '"dep:tokio-util"' + --replace-fail '"tokio-util"' '"dep:tokio-util"' \ + --replace-fail '"opentelemetry-appender-tracing",' "" ''; buildAndTestSubdir = "crates/arti"; - cargoHash = "sha256-/7sWTLeVolqliggn1Qw+kxqAeWENHgbCR6hK5Th2z+g="; + cargoHash = "sha256-g+t5X1t0koUzqoHpY8+lncqRobdDuZggXtD3HRk9ryE="; nativeBuildInputs = lib.optionals stdenv.hostPlatform.isLinux [ pkg-config ]; buildInputs = [ sqlite ] ++ lib.optionals stdenv.hostPlatform.isLinux [ openssl ]; + # `full` includes all stable and non-conflicting feature flags. the primary # downsides are increased binary size and memory usage for building, but # those are acceptable for nixpkgs