From 7e19f73bf3ec3da6a812edd866fb034f7795ab4f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 9 Jun 2026 12:48:11 +0000 Subject: [PATCH 01/49] qgis-ltr: 3.44.10 -> 3.44.11 (cherry picked from commit ea30bc1408005565ac22f344882e7a22e0410e41) --- pkgs/applications/gis/qgis/unwrapped-ltr.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/gis/qgis/unwrapped-ltr.nix b/pkgs/applications/gis/qgis/unwrapped-ltr.nix index ee4d1b5a6364..5096d3568716 100644 --- a/pkgs/applications/gis/qgis/unwrapped-ltr.nix +++ b/pkgs/applications/gis/qgis/unwrapped-ltr.nix @@ -85,7 +85,7 @@ let ]; in mkDerivation rec { - version = "3.44.10"; + version = "3.44.11"; pname = "qgis-ltr-unwrapped"; outputs = [ "out" ] ++ lib.optional (!stdenv.hostPlatform.isDarwin) "man"; @@ -93,7 +93,7 @@ mkDerivation rec { owner = "qgis"; repo = "QGIS"; rev = "final-${lib.replaceStrings [ "." ] [ "_" ] version}"; - hash = "sha256-wWLbnZpLIchm0NXuU7jEXCBctrI6G1z8iqf9R2YhS8Y="; + hash = "sha256-gWSl9OrRSxreQdKxKKDCOUWBE5uE2w3/ebW266LCWLI="; }; passthru = { From 0c350a44700272c22fdcfb92dd8bf89b9230978c Mon Sep 17 00:00:00 2001 From: Omar Jatoi Date: Thu, 25 Jun 2026 13:13:28 -0400 Subject: [PATCH 02/49] google-cloud-sdk: use vendored protobuf extensions only Assisted-by: codex with gpt-5.5-high (cherry picked from commit e86e85b2a9f9f409d7445a91e640d3d378905d83) --- .../cloudsdk-vendored-protobuf-upb.patch | 22 +++++++++++++++++++ pkgs/by-name/go/google-cloud-sdk/package.nix | 9 ++++++++ 2 files changed, 31 insertions(+) create mode 100644 pkgs/by-name/go/google-cloud-sdk/cloudsdk-vendored-protobuf-upb.patch diff --git a/pkgs/by-name/go/google-cloud-sdk/cloudsdk-vendored-protobuf-upb.patch b/pkgs/by-name/go/google-cloud-sdk/cloudsdk-vendored-protobuf-upb.patch new file mode 100644 index 000000000000..819947e767d4 --- /dev/null +++ b/pkgs/by-name/go/google-cloud-sdk/cloudsdk-vendored-protobuf-upb.patch @@ -0,0 +1,22 @@ +diff --git a/lib/third_party/cloudsdk/google/protobuf/internal/api_implementation.py b/lib/third_party/cloudsdk/google/protobuf/internal/api_implementation.py +--- a/lib/third_party/cloudsdk/google/protobuf/internal/api_implementation.py ++++ b/lib/third_party/cloudsdk/google/protobuf/internal/api_implementation.py +@@ -55,7 +55,7 @@ _implementation_type = 'python' + if _implementation_type is None: +- if _CanImport('google._upb._message'): ++ if _CanImport('cloudsdk.google._upb._message'): + _implementation_type = 'upb' +- elif _CanImport('google.protobuf.pyext._message'): ++ elif _CanImport('cloudsdk.google.protobuf.pyext._message'): + _implementation_type = 'cpp' + else: + _implementation_type = 'python' +@@ -96,7 +96,7 @@ if _implementation_type == 'cpp': + if _implementation_type == 'upb': + try: + # pylint: disable=g-import-not-at-top +- from google._upb import _message ++ from cloudsdk.google._upb import _message + _c_module = _message + del _message + except ImportError: diff --git a/pkgs/by-name/go/google-cloud-sdk/package.nix b/pkgs/by-name/go/google-cloud-sdk/package.nix index d72d60a32fbe..c27ed5408784 100644 --- a/pkgs/by-name/go/google-cloud-sdk/package.nix +++ b/pkgs/by-name/go/google-cloud-sdk/package.nix @@ -70,6 +70,9 @@ stdenv.mkDerivation rec { ./gcloud-path.patch # Disable checking for updates for the package ./gsutil-disable-updates.patch + # Cloud SDK vendors protobuf under the cloudsdk.google.protobuf namespace. + # Keep that vendored runtime from loading external google._upb modules. + ./cloudsdk-vendored-protobuf-upb.patch ]; installPhase = '' @@ -184,6 +187,12 @@ stdenv.mkDerivation rec { # Avoid trying to write logs to homeless-shelter export HOME=$(mktemp -d) $out/bin/gcloud version --format json | jq '."Google Cloud SDK"' | grep "${version}" + $out/bin/gcloud storage ls --help > /dev/null + # Exercises generated clients that use Cloud SDK's vendored protobuf. This + # catches regressions where external protobuf/upb is selected instead of the + # vendored pure-Python protobuf implementation. + $out/bin/gcloud kms asymmetric-sign --help > /dev/null + PROTOCOL_BUFFERS_PYTHON_IMPLEMENTATION=upb $out/bin/gcloud kms asymmetric-sign --help > /dev/null $out/bin/gsutil version | grep -w "$(cat platform/gsutil/VERSION)" ''; From 4424e4b7cd1102b0032f9bb201ced9bd126da0bd Mon Sep 17 00:00:00 2001 From: teutat3s <10206665+teutat3s@users.noreply.github.com> Date: Thu, 2 Jul 2026 16:39:30 +0200 Subject: [PATCH 03/49] gclient2nix: update, fix for electron_43 Fixes error: ``` KeyError: "host_cpu was used as a variable, but was not declared in the vars dict (file 'DEPS', line 114)" ``` https://chromium.googlesource.com/webpagereplay.git/+/b2b856131e36c99e9de9c419fe8ca02f857082ba/DEPS#114 (cherry picked from commit c6eb78bad219df56465dff8ade35dd2c4829df17) --- pkgs/by-name/gc/gclient2nix/gclient2nix.py | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/gc/gclient2nix/gclient2nix.py b/pkgs/by-name/gc/gclient2nix/gclient2nix.py index b26ef247d2e4..214b0da47f67 100755 --- a/pkgs/by-name/gc/gclient2nix/gclient2nix.py +++ b/pkgs/by-name/gc/gclient2nix/gclient2nix.py @@ -60,7 +60,14 @@ class Repo: ) deps_file = self.get_file("DEPS") - evaluated = gclient_eval.Parse(deps_file, vars_override=repo_vars, filename="DEPS") + evaluated = gclient_eval.Parse( + deps_file, + filename="DEPS", + vars_override=repo_vars, + # KeyError: "host_cpu was used as a variable, but was not declared in the vars dict (file 'DEPS', line 114)" + # https://chromium.googlesource.com/webpagereplay.git/+/b2b856131e36c99e9de9c419fe8ca02f857082ba/DEPS#114 + builtin_vars= {"host_cpu": "*host_cpu_placeholder*"} if path == "src/third_party/webpagereplay" else None, + ) repo_vars = dict(evaluated.get("vars", {})) | repo_vars From 5e7e2a03ba7d72d1c2ce7e9ac8d4f8a5ab2e041a Mon Sep 17 00:00:00 2001 From: teutat3s <10206665+teutat3s@users.noreply.github.com> Date: Thu, 2 Jul 2026 16:40:30 +0200 Subject: [PATCH 04/49] gclient2nix: update depot-tools (cherry picked from commit f4cc6e9411d9727be96691abbd971bc65dde5058) --- pkgs/by-name/gc/gclient2nix/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gc/gclient2nix/package.nix b/pkgs/by-name/gc/gclient2nix/package.nix index b683352b3664..66bbdbad9226 100644 --- a/pkgs/by-name/gc/gclient2nix/package.nix +++ b/pkgs/by-name/gc/gclient2nix/package.nix @@ -68,8 +68,8 @@ runCommand "gclient2nix" # substitutions depot_tools_checkout = fetchgit { url = "https://chromium.googlesource.com/chromium/tools/depot_tools"; - rev = "977d597d75def6781f890cdce459969a9568ea07"; - hash = "sha256-OCIay+a+DHvKKIbDMSjTf6CbHHVfp8k0n1AO3E4yx1U="; + rev = "1b1b01fa912786b88a79f3504176a275183839b5"; + hash = "sha256-SRPeosetXYUklafhcuqsJiIKfItUJACG70m4Z5pBQiU="; }; passthru = { From dea9a51e912a20fbcc4d172e556b08a63ead0ef9 Mon Sep 17 00:00:00 2001 From: teutat3s <10206665+teutat3s@users.noreply.github.com> Date: Thu, 2 Jul 2026 16:28:42 +0200 Subject: [PATCH 05/49] electron-source.electron_43: init at 43.1.0 - Changelog: https://github.com/electron/electron/releases/tag/v43.0.0 - Changelog: https://github.com/electron/electron/releases/tag/v43.1.0 - Diff: https://github.com/electron/electron/compare/refs/tags/v43.0.0...v43.1.0 Synced `gnFlags` with https://github.com/electron/electron/blob/v43.1.0/build/args/all.gn and removed all flags that are no longer in use by either electron 41, 42, 43. - `v8_builtins_profiling_log_file` was removed in https://github.com/electron/electron/commit/29750dda082501f5b728f58fb57765813d59a193 (and backported for all electron versions) - `dawn_use_built_dxc` was removed in https://github.com/electron/electron/commit/9b740594fbdd0a205a1c2062c27184bb691a0b05 - `clang_unsafe_buffers_paths` was removed in https://github.com/electron/electron/commit/041ada15867b4ed24193f2023747f275806bcf10 - `enterprise_cloud_content_analysis` was removed in https://github.com/electron/electron/commit/76c5257fea58dad31de77d85861f88c0cc6aa954 - `node_openssl_path` using boringssl was added in version 43 https://github.com/electron/electron/commit/e4a5c5a3b9532e1ac1bfa561f0ee95b4ee64363a (cherry picked from commit 450726460d9334ab8bc856f40231b9b177f96f22) --- pkgs/development/tools/electron/common.nix | 14 +- pkgs/development/tools/electron/info.json | 1430 ++++++++++++++++++++ pkgs/top-level/all-packages.nix | 2 + 3 files changed, 1441 insertions(+), 5 deletions(-) diff --git a/pkgs/development/tools/electron/common.nix b/pkgs/development/tools/electron/common.nix index 33b98017767b..8c0a1870a22f 100644 --- a/pkgs/development/tools/electron/common.nix +++ b/pkgs/development/tools/electron/common.nix @@ -231,16 +231,20 @@ in allow_runtime_configurable_key_storage = true; enable_cet_shadow_stack = false; is_cfi = false; - v8_builtins_profiling_log_file = ""; enable_dangling_raw_ptr_checks = false; - dawn_use_built_dxc = false; + enable_dangling_raw_ptr_feature_flag = false; v8_enable_private_mapping_fork_optimization = true; v8_expose_public_symbols = true; - enable_dangling_raw_ptr_feature_flag = false; - clang_unsafe_buffers_paths = ""; - enterprise_cloud_content_analysis = false; enable_linux_installer = false; enable_pdf_save_to_drive = false; + } + // lib.optionalAttrs (lib.versionOlder info.version "43") { + enterprise_cloud_content_analysis = false; + } + // lib.optionalAttrs (lib.versionAtLeast info.version "43") { + node_openssl_path = "//third_party/boringssl"; + } + // { # other enable_widevine = false; diff --git a/pkgs/development/tools/electron/info.json b/pkgs/development/tools/electron/info.json index 275cd4b88df1..f1c6b3e49556 100644 --- a/pkgs/development/tools/electron/info.json +++ b/pkgs/development/tools/electron/info.json @@ -4208,5 +4208,1435 @@ "modules": "146", "node": "24.17.0", "version": "42.5.1" + }, + "43": { + "chrome": "150.0.7871.47", + "chromium": { + "deps": { + "gn": { + "hash": "sha256-/1A+DkzAQj2zGPe/A/G0Z3VrYJXUxq4Hd/+d/o5p3G8=", + "rev": "3357c4f51b1a9e676378c695dd9c7e9911c35ee6", + "version": "0-unstable-2026-05-27" + } + }, + "version": "150.0.7871.47" + }, + "chromium_npm_hash": "sha256-pF0JtwFpPC4/fodbhSJnQKkczA9WlDg4VqEAy9aDVLg=", + "deps": { + "src": { + "args": { + "hash": "sha256-LYI9szAqoiJLIu1CUJYRBLdvBrNafaOXQQiYdbp5PRY=", + "postFetch": "rm -rf $(find $out/third_party/blink/web_tests ! -name BUILD.gn -mindepth 1 -maxdepth 1); rm -r $out/content/test/data; rm -rf $out/courgette/testdata; rm -r $out/extensions/test/data; rm -r $out/media/test/data; ", + "tag": "150.0.7871.47", + "url": "https://chromium.googlesource.com/chromium/src.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/agents/shared": { + "args": { + "hash": "sha256-z2GrzF8jDkdfBdq1HP3gTgQpoqjmhc80kEZBmlue0os=", + "rev": "e75efa515896f6bf1dea92eaffbcf8ee711a65d8", + "url": "https://chromium.googlesource.com/chromium/agents.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/chrome/test/data/perf/canvas_bench": { + "args": { + "hash": "sha256-svOuyBGKloBLM11xLlWCDsB4PpRjdKTBdW2UEW4JQjM=", + "rev": "a7b40ea5ae0239517d78845a5fc9b12976bfc732", + "url": "https://chromium.googlesource.com/chromium/canvas_bench.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/chrome/test/data/perf/frame_rate/content": { + "args": { + "hash": "sha256-t4kcuvH0rkPBkcdiMsoNQaRwU09eU+oSvyHDiAHrKXo=", + "rev": "c10272c88463efeef6bb19c9ec07c42bc8fe22b9", + "url": "https://chromium.googlesource.com/chromium/frame_rate/content.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/chrome/test/data/xr/webvr_info": { + "args": { + "hash": "sha256-BsAPwc4oEWri0TlqhyxqFNqKdfgVSrB0vQyISmYY4eg=", + "rev": "c58ae99b9ff9e2aa4c524633519570bf33536248", + "url": "https://chromium.googlesource.com/external/github.com/toji/webvr.info.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/docs/website": { + "args": { + "hash": "sha256-wrkFsPX7jrsjD/Ow1gna/xLvk0E49m5GVxP1G7Vx7HM=", + "rev": "3da515a67f412be05ea1ea6b39832a69aef8f54e", + "url": "https://chromium.googlesource.com/website.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/electron": { + "args": { + "hash": "sha256-HgGRcv5ixKQOQrblfgg0VZ3xTPqxvMV1m6PpK3qxMcI=", + "owner": "electron", + "repo": "electron", + "tag": "v43.1.0" + }, + "fetcher": "fetchFromGitHub" + }, + "src/media/cdm/api": { + "args": { + "hash": "sha256-GsaRxLnsz1jrFZ3m5tv65d1dioG23uJnmfa+WD7XcFc=", + "rev": "33c977516b3dfe5b065bc298aa74175e1999ab51", + "url": "https://chromium.googlesource.com/chromium/cdm.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/net/third_party/quiche/src": { + "args": { + "hash": "sha256-xgDgW2foZZEWpr0ibSG21kf028FN07/1ecOqFCkNj/I=", + "rev": "997d654308b6a1a17435e472ef5190aecb12e3eb", + "url": "https://quiche.googlesource.com/quiche.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/testing/libfuzzer/fuzzers/wasm_corpus": { + "args": { + "hash": "sha256-gItDOfNqm1tHlmelz3l2GGdiKi9adu1EpPP6U7+8EQY=", + "rev": "1df5e50a45db9518a56ebb42cb020a94a090258b", + "url": "https://chromium.googlesource.com/v8/fuzzer_wasm_corpus.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/angle": { + "args": { + "hash": "sha256-8iuHtNgHumlMXeXj2k0ZPcvnTeJ00di298+789OjScs=", + "rev": "bbf3d8a4755268f016087be2f56099fa5a5f3f6e", + "url": "https://chromium.googlesource.com/angle/angle.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/angle/third_party/VK-GL-CTS/src": { + "args": { + "hash": "sha256-SrL+G3osTtJGQslfCBEYbslb2kWtHRrwO87PHi+5o6E=", + "rev": "01471f4b3846c97eceb5b16b8acad950808791b2", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/VK-GL-CTS" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/angle/third_party/glmark2/src": { + "args": { + "hash": "sha256-VebUALLFKwEa4+oE+jF8mBSzhJd6aflphPmcK1Em8bw=", + "rev": "6edcf02205fd1e8979dc3f3964257a81959b80c8", + "url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/angle/third_party/rapidjson/src": { + "args": { + "hash": "sha256-oHHLYRDMb7Y/k0CwsdsxPC5lglr2IChQi0AiOMiFn78=", + "rev": "24b5e7a8b27f42fa16b96fc70aade9106cf7102f", + "url": "https://chromium.googlesource.com/external/github.com/Tencent/rapidjson" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/anonymous_tokens/src": { + "args": { + "hash": "sha256-llPt+UR8hY0yaJkYmq+A3ZfRRReuaXN09qpap6C28jc=", + "rev": "92d1fdf881a932e7aa2a9b20e006136a659c7a20", + "url": "https://chromium.googlesource.com/external/github.com/google/anonymous-tokens.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/aria-practices/src": { + "args": { + "hash": "sha256-POnvoO1KfzJj4CbcMPI0pUTRk5EtHLTOyKKmJCZdXOc=", + "rev": "7b134ce6d19497cce8a67db4a9f59980baf853dc", + "url": "https://chromium.googlesource.com/external/github.com/w3c/aria-practices.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/boringssl/src": { + "args": { + "hash": "sha256-JuMnNppWhIFHYfk6ANIZLC7ABhqMseoV5LYV7slevBE=", + "rev": "3a9254f16eda7a4c5d2260039ff23456a0a34de4", + "url": "https://boringssl.googlesource.com/boringssl.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/breakpad/breakpad": { + "args": { + "hash": "sha256-NplvLz9oET6mhTuBkHH6pZc8qdfhqI7g69eZRCyae0A=", + "rev": "8ef5673404a3bbc192b0997e1c2df559cc5bd79d", + "url": "https://chromium.googlesource.com/breakpad/breakpad.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/cast_core/public/src": { + "args": { + "hash": "sha256-yQxm1GMMne80bLl1P7OAN3bJLz1qRNAvou2/5MKp2ig=", + "rev": "f5ee589bdaea60418f670fa176be15ccb9a34942", + "url": "https://chromium.googlesource.com/cast_core/public" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/catapult": { + "args": { + "hash": "sha256-XYufVvzOXD4voZUWUvumQQqLNsx9sy0QmQzNzrgNEWg=", + "rev": "2852bb7e91e4995502ffb72b7ed21412ee157914", + "url": "https://chromium.googlesource.com/catapult.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/ced/src": { + "args": { + "hash": "sha256-ySG74Rj2i2c/PltEgHVEDq+N8yd9gZmxNktc56zIUiY=", + "rev": "ba412eaaacd3186085babcd901679a48863c7dd5", + "url": "https://chromium.googlesource.com/external/github.com/google/compact_enc_det.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/clang-format/script": { + "args": { + "hash": "sha256-Cm6BOOlEyD0kdYxMSmk6Fj1Dnfs3zCzXsm+BOXgBme0=", + "rev": "6eddfb5ec5f92127a531eda66c568d3a11e7ec11", + "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/clang/tools/clang-format.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/cld_3/src": { + "args": { + "hash": "sha256-C3MOMBUy9jgkT9BAi/Fgm2UH4cxRuwSBEcRl3hzM2Ss=", + "rev": "b48dc46512566f5a2d41118c8c1116c4f96dc661", + "url": "https://chromium.googlesource.com/external/github.com/google/cld_3.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/colorama/src": { + "args": { + "hash": "sha256-6ZTdPYSHdQOLYMSnE+Tp7PgsVTs3U2awGu9Qb4Rg/tk=", + "rev": "3de9f013df4b470069d03d250224062e8cf15c49", + "url": "https://chromium.googlesource.com/external/colorama.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/compiler-rt/src": { + "args": { + "hash": "sha256-KnWESGG6aI0S+fkJ3/T1x4QSiIYaOOvWUAm6l6l9iME=", + "rev": "03641f7a5b05e48e318d64369057db577cafc594", + "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/compiler-rt.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/content_analysis_sdk/src": { + "args": { + "hash": "sha256-f5Jmk1MiGjaRdLun+v/GKVl8Yv9hOZMTQUSxgiJalcY=", + "rev": "9a408736204513e0e95dd2ab3c08de0d95963efc", + "url": "https://chromium.googlesource.com/external/github.com/chromium/content_analysis_sdk.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/cpu_features/src": { + "args": { + "hash": "sha256-TrC1WMLAhko57rAyDCiAC/IJ0unAqVhyjkh7gKibyi4=", + "rev": "81d13c49649f0714dd41fb56bb246398b6584085", + "url": "https://chromium.googlesource.com/external/github.com/google/cpu_features.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/cpuinfo/src": { + "args": { + "hash": "sha256-/QsOjDik0TnH3FnK7LOwsJkvX+O+2DRFX4eF3MxD3fc=", + "rev": "ea6b9f1bb6e1001d8b21574d5bc78ddef62e499d", + "url": "https://chromium.googlesource.com/external/github.com/pytorch/cpuinfo.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/crabbyavif/src": { + "args": { + "hash": "sha256-tN+2YH2O9FTV50o4OVhKcKdwRwTI8NuNA0WqljUcrmo=", + "rev": "5e140b5abb9a91eb25b5ef66d29f6ee784ab7eab", + "url": "https://chromium.googlesource.com/external/github.com/webmproject/CrabbyAvif.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/crc32c/src": { + "args": { + "hash": "sha256-KBraGaO5LmmPP+p8RuDogGldbTWdNDK+WzF4Q09keuE=", + "rev": "d3d60ac6e0f16780bcfcc825385e1d338801a558", + "url": "https://chromium.googlesource.com/external/github.com/google/crc32c.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/cros-components/src": { + "args": { + "hash": "sha256-viuntf6umyLZwDR9BXG+ZOakp9f8rvpZYDBYAUkKzL4=", + "rev": "0abb2efaa3d16db861c9710b193c39e657ac3bdf", + "url": "https://chromium.googlesource.com/external/google3/cros_components.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/cros_system_api": { + "args": { + "hash": "sha256-qIwUs0KVU9xYFLN3UUayPLfz0ObA+EN6owKPW61J/5w=", + "rev": "1c69e700a01a7fd3dd331f526c8a31ac1e5e49d0", + "url": "https://chromium.googlesource.com/chromiumos/platform2/system_api.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/crossbench": { + "args": { + "hash": "sha256-iwwvvIOuRMo/ZEu8Gk0lZaS4P5uGt8zpnYMChpZPcUo=", + "rev": "7d52b4ffbc319a7d5a0e0a0ebff744e5281d60c5", + "url": "https://chromium.googlesource.com/crossbench.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/crossbench-web-tests": { + "args": { + "hash": "sha256-7ly4vaK+Pj4y91t6Q+igQ0890CqKyu9jNBhJnxbNGjI=", + "rev": "7b3de17542cc613aaddbfc72c6e12be37eed7b73", + "url": "https://chromium.googlesource.com/chromium/web-tests.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dav1d/libdav1d": { + "args": { + "hash": "sha256-5cpKTUnhR+QzQJR4KbAvdvqsWnT1fpH0g9MObv8Nx0c=", + "rev": "62501cc7db378532d7e85ea434b70d57e1ba2cb0", + "url": "https://chromium.googlesource.com/external/github.com/videolan/dav1d.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dawn": { + "args": { + "hash": "sha256-tzomo+GTec2zixxk61gtlma/sjcBImgbLMwA+mIp1LM=", + "rev": "01249a97332468dbdd6cf5edb8dd7bae77875de5", + "url": "https://dawn.googlesource.com/dawn.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dawn/third_party/EGL-Registry/src": { + "args": { + "hash": "sha256-csSV8Yp0p0UIrodbX5793uO5iZMjQfy+0D2wPif2+Fw=", + "rev": "3d7796b3721d93976b6bfe536aa97bbc4bce8667", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/EGL-Registry" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dawn/third_party/OpenGL-Registry/src": { + "args": { + "hash": "sha256-xLacUOSy783bCtv+wUnjVnNLwTQ3eLwUJtYXmELqekY=", + "rev": "a30033d3e812c9bf10094f1010374a6b15e192eb", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/OpenGL-Registry" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dawn/third_party/directx-headers/src": { + "args": { + "hash": "sha256-0Miw1Cy/jmOo7bLFBOHuTRDV04cSeyvUEyPkpVsX9DA=", + "rev": "980971e835876dc0cde415e8f9bc646e64667bf7", + "url": "https://chromium.googlesource.com/external/github.com/microsoft/DirectX-Headers" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dawn/third_party/directx-shader-compiler/src": { + "args": { + "hash": "sha256-pzBk+jUp/FUV8ahHquE0942Qw/DjAUemSM9fxdFJ0JA=", + "rev": "35c1b99e9e552267da5efaea07c003e322d65777", + "url": "https://chromium.googlesource.com/external/github.com/microsoft/DirectXShaderCompiler" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dawn/third_party/glfw3/src": { + "args": { + "hash": "sha256-uVJOf+D3bgS/CyEL1y52gvkml6VUTtNPMTU6X5/XyS4=", + "rev": "b00e6a8a88ad1b60c0a045e696301deb92c9a13e", + "url": "https://chromium.googlesource.com/external/github.com/glfw/glfw" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dawn/third_party/webgpu-cts": { + "args": { + "hash": "sha256-f5kWMnaod/Ved1Fz/vTkdL0ihSUnNM8XN5Ht3Vs1YpU=", + "rev": "f08551b0fc4d6cfa5ba582a0235b571aa363102d", + "url": "https://chromium.googlesource.com/external/github.com/gpuweb/cts" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dawn/third_party/webgpu-headers/src": { + "args": { + "hash": "sha256-tFn3OChLKsYz52Vml7WVgqyrK7SI6WR1Z2C2vvFfakI=", + "rev": "dc16b3e531cf4f31be54236d1a3e988ba5f295a2", + "url": "https://chromium.googlesource.com/external/github.com/webgpu-native/webgpu-headers" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/depot_tools": { + "args": { + "hash": "sha256-3atvbwYnFTA40MonAxSQWkF58Jku7O7fUzelGPQvDyY=", + "rev": "f4fadaf6a5ba1bced9d3d9021060667b563bf583", + "url": "https://chromium.googlesource.com/chromium/tools/depot_tools.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/devtools-frontend/src": { + "args": { + "hash": "sha256-VBXch2YwnKm+lMcZ5L0SlW+vAYeaSwgZvcOhg1TE5/A=", + "rev": "1d67dc0dafa344bbd6ca75c124e2d6d9d53074d8", + "url": "https://chromium.googlesource.com/devtools/devtools-frontend" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dom_distiller_js/dist": { + "args": { + "hash": "sha256-yuEBD2XQlV3FGI/i7lTmJbCqzeBiuG1Qow8wvsppGJw=", + "rev": "199de96b345ada7c6e7e6ba3d2fa7a6911b8767d", + "url": "https://chromium.googlesource.com/chromium/dom-distiller/dist.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/domato/src": { + "args": { + "hash": "sha256-fYxoA0fxKe9U23j+Jp0MWj4m7RfsRpM0XjF6/yOhX1I=", + "rev": "053714bccbda79cf76dac3fee48ab2b27f21925e", + "url": "https://chromium.googlesource.com/external/github.com/googleprojectzero/domato.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/dragonbox/src": { + "args": { + "hash": "sha256-j6swuGgYGfiFcK3iqd4EKTeU92rZHKTbF5T1fcak/ko=", + "rev": "beeeef91cf6fef89a4d4ba5e95d47ca64ccb3a44", + "url": "https://chromium.googlesource.com/external/github.com/jk-jeon/dragonbox.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/eigen3/src": { + "args": { + "hash": "sha256-6bZFDeo7TqWNunkkQv8OJ+7/hfKwoIUtqZoXaeLp6M8=", + "rev": "662ba79d796a2851b10cdafc6668e45b65b1120f", + "url": "https://chromium.googlesource.com/external/gitlab.com/libeigen/eigen.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/electron_node": { + "args": { + "hash": "sha256-jlyRCBNU4YV5NKwsibJFcp7dRerfDlNFoCjWU1H1aqE=", + "owner": "nodejs", + "repo": "node", + "tag": "v24.18.0" + }, + "fetcher": "fetchFromGitHub" + }, + "src/third_party/emoji-segmenter/src": { + "args": { + "hash": "sha256-KdQdKBBipEBRT8UmNGao6yCB4m2CU8/SrMVvcXlb5qE=", + "rev": "955936be8b391e00835257059607d7c5b72ce744", + "url": "https://chromium.googlesource.com/external/github.com/google/emoji-segmenter.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/engflow-reclient-configs": { + "args": { + "hash": "sha256-aZXYPj9KYBiZnljqOLlWJWS396Fg3EhjiQLZmkwCBsY=", + "owner": "EngFlow", + "repo": "reclient-configs", + "rev": "955335c30a752e9ef7bff375baab5e0819b6c00d" + }, + "fetcher": "fetchFromGitHub" + }, + "src/third_party/expat/src": { + "args": { + "hash": "sha256-veGg5/QjtBSmxYa8IyHF0NxEdJzlcJSZfzw8ay3ASVU=", + "rev": "9bdfbc77e3355405ceefbe59420abed953a5657e", + "url": "https://chromium.googlesource.com/external/github.com/libexpat/libexpat.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/farmhash/src": { + "args": { + "hash": "sha256-5n58VEUxa/K//jAfZqG4cXyfxrp50ogWDNYcgiXVHdc=", + "rev": "816a4ae622e964763ca0862d9dbd19324a1eaf45", + "url": "https://chromium.googlesource.com/external/github.com/google/farmhash.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/fast_float/src": { + "args": { + "hash": "sha256-hzoB+Mmok3oe6B494uLc5ReWpUcB89zCGPYw4gvanK0=", + "rev": "cfd12ebcf1f82c4fd44a950b1815dd0549bc8d89", + "url": "https://chromium.googlesource.com/external/github.com/fastfloat/fast_float.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/federated_compute/src": { + "args": { + "hash": "sha256-GZYo0FjgW8XCplAi6jzzruwDlIzsWjNEVQuCwXBCPz8=", + "rev": "8de5837b817f28abc54a387a9417631b905ba90a", + "url": "https://chromium.googlesource.com/external/github.com/google-parfait/federated-compute.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/ffmpeg": { + "args": { + "hash": "sha256-41qpsOTedB51WMzzHXDiXA19OIzA7wG/Qgbz6IkmWpk=", + "rev": "ad41607c61898cf7150e0fb20fe4bbabd44922a3", + "url": "https://chromium.googlesource.com/chromium/third_party/ffmpeg.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/flac": { + "args": { + "hash": "sha256-LZFAJf8mF14XvXYvvBoLHGied2P7o23LUxszDpZLe8E=", + "rev": "e7108e2ed031547c3759217819a032065c820d73", + "url": "https://chromium.googlesource.com/chromium/deps/flac.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/flatbuffers/src": { + "args": { + "hash": "sha256-gV1hn1iHI7knFEXy3Oii97mLRZYJUBiBlTh6/sqOoXg=", + "rev": "a86afae9399bbe631d1ea0783f8816e780e236cc", + "url": "https://chromium.googlesource.com/external/github.com/google/flatbuffers.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/fontconfig/src": { + "args": { + "hash": "sha256-Oo4ewK86dbEkO5EXyGWvdmsPHa8Wk1BHQah784vIem0=", + "rev": "d62c2ab268d1679335daa8fb0ea6970f35224a76", + "url": "https://chromium.googlesource.com/external/fontconfig.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/fp16/src": { + "args": { + "hash": "sha256-CR7h1d9RFE86l6btk4N8vbQxy0KQDxSMvckbiO87JEg=", + "rev": "3d2de1816307bac63c16a297e8c4dc501b4076df", + "url": "https://chromium.googlesource.com/external/github.com/Maratyszcza/FP16.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/freetype/src": { + "args": { + "hash": "sha256-xnYeUAJx5n8LSg04AknfiudonfmlUdlj8nzHzSZi65I=", + "rev": "b08a2eb0dd37f4a6c886fa5b0ecf5b3e1d27aac7", + "url": "https://chromium.googlesource.com/chromium/src/third_party/freetype2.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/fuzztest/src": { + "args": { + "hash": "sha256-317zRhJPc0D9A58W8fdCGFmpNZ5vACfd/tlZOsp/Cvw=", + "rev": "da27bcae1a8902af1ae6a5c55d3674f22709bbf5", + "url": "https://chromium.googlesource.com/external/github.com/google/fuzztest.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/fxdiv/src": { + "args": { + "hash": "sha256-LjX5kivfHbqCIA5pF9qUvswG1gjOFo3CMpX0VR+Cn38=", + "rev": "63058eff77e11aa15bf531df5dd34395ec3017c8", + "url": "https://chromium.googlesource.com/external/github.com/Maratyszcza/FXdiv.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/gemmlowp/src": { + "args": { + "hash": "sha256-e6AeRhZioIiTG5R+IA9g2GBqI4o74wijJYmqINLOtQs=", + "rev": "16e8662c34917be0065110bfcd9cc27d30f52fdf", + "url": "https://chromium.googlesource.com/external/github.com/google/gemmlowp.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/glslang/src": { + "args": { + "hash": "sha256-ru3QVyyyqxZRcvSpy9pYhHHhkjuLVhQbgOT/vQJ/oIw=", + "rev": "f6d9303ddaf2e879b9155f7186cd234f5a79079c", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/glslang" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/google_benchmark/src": { + "args": { + "hash": "sha256-M8QkA8+bckoRjlcVneYXNetmPEWEvmWy/mca5JA40Ho=", + "rev": "8abf1e701fbd88c8170f48fe0558247e2e5f8e7d", + "url": "https://chromium.googlesource.com/external/github.com/google/benchmark.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/googletest/src": { + "args": { + "hash": "sha256-gJhv3DQQSP5BQ6GmDobq42/Gkx4AbOg/ZS80bM0WpEw=", + "rev": "4fe3307fb2d9f86d19777c7eb0e4809e9694dde7", + "url": "https://chromium.googlesource.com/external/github.com/google/googletest.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/harfbuzz/src": { + "args": { + "hash": "sha256-uT4zK2hwHzEH6Nrd2rAeyzpQA1TmwtrdcujKYEUbLsY=", + "rev": "d639197ed529b05c27f38ebaab365a621d5edad5", + "url": "https://chromium.googlesource.com/external/github.com/harfbuzz/harfbuzz.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/highway/src": { + "args": { + "hash": "sha256-YUYZO9KLffczjwIz3mBBceD6oM1giLCFLDHgDCevdRA=", + "rev": "2607d3b5b0113992fe84d3848859eae13b3b52c1", + "url": "https://chromium.googlesource.com/external/github.com/google/highway.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/hunspell_dictionaries": { + "args": { + "hash": "sha256-mYDPXa64IOKLMNiBiMqDrQMR7gDPI+vdyVc+M7E+ddc=", + "rev": "cccf64a8acc951afe3f47fee023908e55699bc58", + "url": "https://chromium.googlesource.com/chromium/deps/hunspell_dictionaries.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/icu": { + "args": { + "hash": "sha256-rNErsn11FZUh8GXAl7jK+NyLHIKrQR3LuoM1qFFGtmM=", + "rev": "3859e64eed5d34544b27fbcab0ac1685ce83df3c", + "url": "https://chromium.googlesource.com/chromium/deps/icu.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/ink/src": { + "args": { + "hash": "sha256-LF+OcqNeg+KRuYmGuMZb4tmnr53sZHn/ZW1jg9ArPfc=", + "rev": "0f9c6172b2ccc6b830ae313d522caf09e6933e06", + "url": "https://chromium.googlesource.com/external/github.com/google/ink.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/instrumented_libs": { + "args": { + "hash": "sha256-5cb9qhSEzb941pF5HH0Br+x9wEH7MiGwQttvErb2mZo=", + "rev": "e8cb570a9a2ee9128e2214c73417ad2a3c47780b", + "url": "https://chromium.googlesource.com/chromium/third_party/instrumented_libraries.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/jetstream/main": { + "args": { + "hash": "sha256-s6UMdUYWZqk/MbhyCi2zdQNgni98gGsYxcuUh/5AUy0=", + "rev": "b7babdf323e64e69bd2f6c376189c15825f5c73a", + "url": "https://chromium.googlesource.com/external/github.com/WebKit/JetStream.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/jetstream/v2.2": { + "args": { + "hash": "sha256-zucA2tqNOsvjhwYQKZ5bFUC73ZF/Fu7KpBflSelvixw=", + "rev": "2145cedef4ca2777b792cb0059d3400ee2a6153c", + "url": "https://chromium.googlesource.com/external/github.com/WebKit/JetStream.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/jsoncpp/source": { + "args": { + "hash": "sha256-q+DOwkjRlHacgfWf5UVY02aqfnKK9M/1YRBX6aMce9g=", + "rev": "d4d072177213b117fb81d4cfda140de090616161", + "url": "https://chromium.googlesource.com/external/github.com/open-source-parsers/jsoncpp.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/leveldatabase/src": { + "args": { + "hash": "sha256-a1fcVI9Vsm1qE17Fnx5UxwOy4ZFMMJ0OKwNs/gZHYQI=", + "rev": "7ee830d02b623e8ffe0b95d59a74db1e58da04c5", + "url": "https://chromium.googlesource.com/external/leveldb.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libFuzzer/src": { + "args": { + "hash": "sha256-TDi1OvYClJKmEDikanKVTmy8uxUXJ95nuVKo5u+uFPM=", + "rev": "bea408a6e01f0f7e6c82a43121fe3af4506c932e", + "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/compiler-rt/lib/fuzzer.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libaddressinput/src": { + "args": { + "hash": "sha256-6yDZpZ+CwxGqNO4+lZLFB6ESREeVku1BoOMtR+hKQ3I=", + "rev": "81eb9628382b07d371d8ea0b11badf7de3857fd5", + "url": "https://chromium.googlesource.com/external/libaddressinput.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libaom/source/libaom": { + "args": { + "hash": "sha256-oDubKvgqMk3w0luM//rR3NnCOk1h/WVTyRkuCmYASrw=", + "rev": "137bcff61e73fdd2836dc04e8258bfb49cef595e", + "url": "https://aomedia.googlesource.com/aom.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libc++/src": { + "args": { + "hash": "sha256-vT1km7JgVpotDoNK+ae1gplSHcwrVNLsv/QAFUrDsIM=", + "rev": "5abc7f839700f0f17338434e1c1c6a8c87c00c11", + "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libcxx.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libc++abi/src": { + "args": { + "hash": "sha256-L5CUvhpOLS+NBNGssCv0pY9rsDFuAI0LlPjXQRfy62A=", + "rev": "8f11bb1d4438d0239d0dfc1bd9456a9f31629dda", + "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libcxxabi.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libdrm/src": { + "args": { + "hash": "sha256-kOaTjBeo4IsfWEk/JBTNId5ikrnpoc9DEjIl7DUd2yE=", + "rev": "369990d9660a387f618d0eedc341eb285016243b", + "url": "https://chromium.googlesource.com/chromiumos/third_party/libdrm.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libei/src": { + "args": { + "hash": "sha256-lSrIC93Cke90/Xc8dqd3e/TU32tflYHYqc5fE8wglBI=", + "rev": "5d6d8e6590df210b75559a889baa9459c68d9366", + "url": "https://chromium.googlesource.com/external/gitlab.freedesktop.org/libinput/libei.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libgav1/src": { + "args": { + "hash": "sha256-6/zMaX2DPSKpsaqirhrgi3nL/88Qr2VXacmyL5IyJ3U=", + "rev": "66ac17620652635392f6ab24065c77b035e281c9", + "url": "https://chromium.googlesource.com/codecs/libgav1.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libipp/libipp": { + "args": { + "hash": "sha256-GzLVt6RIN+FgOpcK61ya5lvdIIhQRciAb/ISIirWogY=", + "rev": "4be5f77f672a3a9f1bbf3c935fb0ea8b3f86ce61", + "url": "https://chromium.googlesource.com/chromiumos/platform2/libipp.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libjpeg_turbo": { + "args": { + "hash": "sha256-wor4RTF3/5BFL9EWcGEofY+M4HN2+/KJUaOY+u86K5Q=", + "rev": "640f254ad0fa03f6b1f29f89b7dd9366f2f6e533", + "url": "https://chromium.googlesource.com/chromium/deps/libjpeg_turbo.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/liblouis/src": { + "args": { + "hash": "sha256-EI/uaHXe0NlqdEw764q0SjerThYEVLRogUlmrsZwXnY=", + "rev": "9700847afb92cb35969bdfcbbfbbb74b9c7b3376", + "url": "https://chromium.googlesource.com/external/liblouis-github.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libpfm4/src": { + "args": { + "hash": "sha256-t4LMG38GksMEM5DktyJ0qLUX1biXErQ57MaMtd7hoeo=", + "rev": "977a25bb3dfe45f653a6cee71ffaae9a92fc3095", + "url": "https://chromium.googlesource.com/external/git.code.sf.net/p/perfmon2/libpfm4.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libphonenumber/src": { + "args": { + "hash": "sha256-Lr/gB5Em+TE092McPwJdOU0Ab4zyP4/2ZxlavMZMm+s=", + "rev": "c25558e39e2bcc9f26f7a2a1ef804324169eaf8f", + "url": "https://chromium.googlesource.com/external/libphonenumber.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libprotobuf-mutator/src": { + "args": { + "hash": "sha256-Su1SPr/GEFi7/N8/HrFkVbGfWH0vYdcJ5/on8zLMcyU=", + "rev": "c1c950eae0440c3808f2b8bd7c57d0c6a42c1a90", + "url": "https://chromium.googlesource.com/external/github.com/google/libprotobuf-mutator.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libsrtp": { + "args": { + "hash": "sha256-6tIbthIcUw58AgaNzvSenZPp/e5vHVTp5K2bpPF+Zg0=", + "rev": "cd5d177bf1fde755ddb4c7f0d9ff7693f8b49e5e", + "url": "https://chromium.googlesource.com/chromium/deps/libsrtp.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libsync/src": { + "args": { + "hash": "sha256-aI7Exie3AmTy8R/Ua5lua0lCwMO1k4wMS6cxulU6iD8=", + "rev": "d29ac04dc81e6b072c091c5b1342a282765ea250", + "url": "https://chromium.googlesource.com/aosp/platform/system/core/libsync.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libunwind/src": { + "args": { + "hash": "sha256-EuaVSYiR7qrlYqBR0UqdWCvwdzJSn0RS2wC/lnP19AE=", + "rev": "d6c7a21e978f0adaa43accaad53bc64f0b64f6ec", + "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libunwind.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libva-fake-driver/src": { + "args": { + "hash": "sha256-em/8rNqwv6szlxyji7mnYr3nObSW/x3OzEEnkiLuqpI=", + "rev": "a9bcab9cd6b15d4e3634ca44d5e5f7652c612194", + "url": "https://chromium.googlesource.com/chromiumos/platform/libva-fake-driver.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libvpx/source/libvpx": { + "args": { + "hash": "sha256-uTteQ+z7t5KOtPuBoZazmonRHd8jGS1/YZAq+RAvhX4=", + "rev": "5f00413667d19ad683674524a9d03543d86d188b", + "url": "https://chromium.googlesource.com/webm/libvpx.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libwebm/source": { + "args": { + "hash": "sha256-zXPuisCv2KkGQq23qTNhHeXpyCClUIeyjHra08DHJIw=", + "rev": "6184f4484a826724b5293837134ab9492261b941", + "url": "https://chromium.googlesource.com/webm/libwebm.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libwebp/src": { + "args": { + "hash": "sha256-a7F97BEnwpdx9W8OsVnz+NfIYW+J1XVDSi38KsIZIfI=", + "rev": "c00d83f6642e7838a12bb03bca94237f03cc2e00", + "url": "https://chromium.googlesource.com/webm/libwebp.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/libyuv": { + "args": { + "hash": "sha256-FXFSC9dRb/KhSQdhJUqKEUpZbzU8ZpVnoSXtF/HPiJI=", + "rev": "3c5fa6ef272f6077d76816ee3d6a697ef1d6d272", + "url": "https://chromium.googlesource.com/libyuv/libyuv.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/litert/src": { + "args": { + "hash": "sha256-skMOzpsn67mmOAp7Mf6UrJdi2lbiQQ8b6kBy4Ik2ED8=", + "rev": "09b4b05203fd7a9402ffcce9cc736d887ff7e3fc", + "url": "https://chromium.googlesource.com/external/github.com/google-ai-edge/LiteRT.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/llvm-libc/src": { + "args": { + "hash": "sha256-qrkx8Z1fc088Ja32obIUPxDwklI7i1wdEw051UZ08u8=", + "rev": "6e5ec6f78d8b9f2e8a50fcc5692d1fc8b2964bde", + "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libc.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/lss": { + "args": { + "hash": "sha256-89CdA7vBYudbko0nAIyHcpHMXqFZHC05kwRIUmeEWGo=", + "rev": "29164a80da4d41134950d76d55199ea33fbb9613", + "url": "https://chromium.googlesource.com/linux-syscall-support.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/material_color_utilities/src": { + "args": { + "hash": "sha256-Y85XU+z9W6tvmDNHJ/dXQnUKXvvDkO3nH/kUJRLqbc4=", + "rev": "13434b50dcb64a482cc91191f8cf6151d90f5465", + "url": "https://chromium.googlesource.com/external/github.com/material-foundation/material-color-utilities.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/minigbm/src": { + "args": { + "hash": "sha256-9HwvjTETerbQ7YKXH9kUB2eWa8PxGWMAJfx1jAluhrs=", + "rev": "3018207f4d89395cc271278fb9a6558b660885f5", + "url": "https://chromium.googlesource.com/chromiumos/platform/minigbm.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/nan": { + "args": { + "hash": "sha256-Tq6whJBeGlJhF7/ctFOEgb1W12Tu/HGNTC5ujQtk+Qk=", + "owner": "nodejs", + "repo": "nan", + "rev": "675cefebca42410733da8a454c8d9391fcebfbc2" + }, + "fetcher": "fetchFromGitHub" + }, + "src/third_party/nasm": { + "args": { + "hash": "sha256-uC6bGxSdz1V2SXIQjMsDd6555b3gAPN1Y0ZQtWoqDww=", + "rev": "525a09a813be0f75b646ee93fc2a31c27b87d722", + "url": "https://chromium.googlesource.com/chromium/deps/nasm.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/nearby/src": { + "args": { + "hash": "sha256-Mwuo2RlKweqZPkDw4OcJDD+QNRiXVysSyzLdjHsG1mA=", + "rev": "0bad8b0c9877f92eeeb550654f1ea51a71a085e4", + "url": "https://chromium.googlesource.com/external/github.com/google/nearby-connections.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/neon_2_sse/src": { + "args": { + "hash": "sha256-ydHSMPJS+axvW7KIR/9SLWNFq/lP67dpg9Yt7shLCng=", + "rev": "ed59be8546632d5126ff69c87122ae5de20ffe4f", + "url": "https://chromium.googlesource.com/external/github.com/intel/ARM_NEON_2_x86_SSE.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/nlohmann_json/src": { + "args": { + "hash": "sha256-t+ygFLws+E4D0Avia7swt4wruaDFaAT6shN6tl92q8k=", + "rev": "75d9166a68355d2cd5a98bfd1a75a3a3dae8f071", + "url": "https://chromium.googlesource.com/external/github.com/nlohmann/json.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/oak/src": { + "args": { + "hash": "sha256-+ouwII+i5CbWoJ3NAxQPmczofzkPwtZTtjIPaXyyXt8=", + "rev": "96c00a6c99ac382f3f3a8f376bc7a70890d1adaa", + "url": "https://chromium.googlesource.com/external/github.com/project-oak/oak.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/openh264/src": { + "args": { + "hash": "sha256-tf0lnxATCkoq+xRti6gK6J47HwioAYWnpEsLGSA5Xdg=", + "rev": "652bdb7719f30b52b08e506645a7322ff1b2cc6f", + "url": "https://chromium.googlesource.com/external/github.com/cisco/openh264" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/openscreen/src": { + "args": { + "hash": "sha256-M57un/TVQPfTnKScVHS1VK1cUs8F/YPT3TwMVdo+mhM=", + "rev": "37ff938a93cb04c6b77e019b52328c8e9b320317", + "url": "https://chromium.googlesource.com/openscreen" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/openscreen/src/buildtools": { + "args": { + "hash": "sha256-sWkgWY2rXVQK83WBVaZxCupQsS/8BtlgagNBQywScPE=", + "rev": "eca5f0685c48ed59ff06077cb18cee00934249dd", + "url": "https://chromium.googlesource.com/chromium/src/buildtools" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/openscreen/src/third_party/tinycbor/src": { + "args": { + "hash": "sha256-fMKBFUSKmODQyg4hKIa1hwnEKIV6WBbY1Gb8DOSnaHA=", + "rev": "d393c16f3eb30d0c47e6f9d92db62272f0ec4dc7", + "url": "https://chromium.googlesource.com/external/github.com/intel/tinycbor.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/ots/src": { + "args": { + "hash": "sha256-kiUXrXsaGOzPkKh0dVmU1I13WHt0Stzj7QLMqHN9FbU=", + "rev": "46bea9879127d0ff1c6601b078e2ce98e83fcd33", + "url": "https://chromium.googlesource.com/external/github.com/khaledhosny/ots.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/pdfium": { + "args": { + "hash": "sha256-zqfErp0pDXHXIvRpZ1TJu2UGXNZjATRbPgQWTniKTJs=", + "rev": "c052afb72a08d79a26bcf3103d11f344981b09f1", + "url": "https://pdfium.googlesource.com/pdfium.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/perfetto": { + "args": { + "hash": "sha256-IRzEqgunO4Nfz+FkYir8G/Ht+Zsn6wpzncgkEFpsC+k=", + "rev": "9ede949f025303868fa0c42418f122ac47312539", + "url": "https://chromium.googlesource.com/external/github.com/google/perfetto.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/protobuf-javascript/src": { + "args": { + "hash": "sha256-1o6N9+1wsQSu1B4w5LlGlwzIUmuPCIYHPqwOyt234ZM=", + "rev": "e6d763860001ba1a76a63adcff5efb12b1c96024", + "url": "https://chromium.googlesource.com/external/github.com/protocolbuffers/protobuf-javascript" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/pthreadpool/src": { + "args": { + "hash": "sha256-4EHJzZT+Gbhs8SkOhjSvDIPEqIQU93oJmtF3c/T+qjw=", + "rev": "02460584c6092e527c8b89f7df4de143d70e801f", + "url": "https://chromium.googlesource.com/external/github.com/google/pthreadpool.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/pyelftools": { + "args": { + "hash": "sha256-rEnt08K90/Psfa+SQgTUG3YGrhp4/udXG9VKIwPM7pk=", + "rev": "8047437615d66d3267ac0134834b80e70639d572", + "url": "https://chromium.googlesource.com/chromiumos/third_party/pyelftools.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/pywebsocket3/src": { + "args": { + "hash": "sha256-WEqqu2/7fLqcf/2/IcD7/FewRSZ6jTgVlVBvnihthYQ=", + "rev": "50602a14f1b6da17e0b619833a13addc6ea78bc2", + "url": "https://chromium.googlesource.com/external/github.com/GoogleChromeLabs/pywebsocket3.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/quic_trace/src": { + "args": { + "hash": "sha256-JmK7nmHg/BfXvFNG2oMpOV83EF+LwVLdwL6qX5FGREs=", + "rev": "352288a06d2c83ae68b5a402b2219f4678be9f39", + "url": "https://chromium.googlesource.com/external/github.com/google/quic-trace.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/re2/src": { + "args": { + "hash": "sha256-oEU+dz8ax1S36+f9OysjB0GnQj8mjZx1VsZ/UgckdDI=", + "rev": "972a15cedd008d846f1a39b2e88ce48d7f166cbd", + "url": "https://chromium.googlesource.com/external/github.com/google/re2.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/readability/src": { + "args": { + "hash": "sha256-lFsHXk4kEkzIbHgJiLTgeiKqiGOErzUwADo8WSZlnec=", + "rev": "d7949dc47dd9ed9ee1d3b34ffdcf3bce28cde435", + "url": "https://chromium.googlesource.com/external/github.com/mozilla/readability.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/ruy/src": { + "args": { + "hash": "sha256-4To1BMUgzj2/sV7USN9W0CgHnpRmaktEspfhwWWeVBc=", + "rev": "2af88863614a8298689cc52b1a47b3fcad7be835", + "url": "https://chromium.googlesource.com/external/github.com/google/ruy.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/search_engines_data/resources": { + "args": { + "hash": "sha256-5/XnNx6Pyk4KBb9krVo9u6i7LWNrsLLOIi4qhEY2PZc=", + "rev": "1aab872af8d44dcf59362d7ba8255922f74fafde", + "url": "https://chromium.googlesource.com/external/search_engines_data.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/securemessage/src": { + "args": { + "hash": "sha256-GS4ccnuiqxMs/LVYAtvSlVAYFp4a5GoZsxcriTX3k78=", + "rev": "fa07beb12babc3b25e0c5b1f38c16aa8cb6b8f84", + "url": "https://chromium.googlesource.com/external/github.com/google/securemessage.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/sframe/src": { + "args": { + "hash": "sha256-bw+6ycUpnFZJhtXFUzr7XTOljNrs+7oFdVY+LN0Rqek=", + "rev": "b14090904433bed0d4ec3f875b9b39f3e0555930", + "url": "https://chromium.googlesource.com/external/github.com/cisco/sframe" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/skia": { + "args": { + "hash": "sha256-KZGrztOKaT368KSCxiJAqnsgINpNODUlaXnH/maQNIA=", + "rev": "14d05ec761901b6e9e9193af8b347ab3a7f6fed0", + "url": "https://skia.googlesource.com/skia.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/smhasher/src": { + "args": { + "hash": "sha256-OgZQwkQcVgRMf62ROGuY+3zQhBoWuUSP4naTmSKdq8s=", + "rev": "0ff96f7835817a27d0487325b6c16033e2992eb5", + "url": "https://chromium.googlesource.com/external/smhasher.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/snappy/src": { + "args": { + "hash": "sha256-jUwnjbaqXz7fgI2TPRK7SlUPQUVzcpjp4ZlFbEzwA+o=", + "rev": "32ded457c0b1fe78ceb8397632c416568d6714a0", + "url": "https://chromium.googlesource.com/external/github.com/google/snappy.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/speedometer/main": { + "args": { + "hash": "sha256-oF8ELo2qmkgaTpNzBLaC3A6gyf2iFv+FQNPGwdGqzVU=", + "rev": "e2e2538900938c5d6819e9456bf33d48f806c96c", + "url": "https://chromium.googlesource.com/external/github.com/WebKit/Speedometer.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/speedometer/v2.0": { + "args": { + "hash": "sha256-p7WUS8gZUaS+LOm7pNmRkwgxjx+V8R6yy7bbaEHaIs4=", + "rev": "732af0dfe867f8815e662ac637357e55f285dbbb", + "url": "https://chromium.googlesource.com/external/github.com/WebKit/Speedometer.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/speedometer/v2.1": { + "args": { + "hash": "sha256-0z5tZlz32fYh9I1ALqfLm2WWO8HiRBwt0hcmgKQhaeM=", + "rev": "8bf7946e39e47c875c00767177197aea5727e84a", + "url": "https://chromium.googlesource.com/external/github.com/WebKit/Speedometer.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/speedometer/v3.0": { + "args": { + "hash": "sha256-qMQ4naX+4uUu3vtzzinjkhxX9/dNoTwj6vWCu4FdQmU=", + "rev": "8d67f28d0281ac4330f283495b7f48286654ad7d", + "url": "https://chromium.googlesource.com/external/github.com/WebKit/Speedometer.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/speedometer/v3.1": { + "args": { + "hash": "sha256-G89mrrgRaANT1vqzhKPQKemHbz56YwR+oku7rlRoCHw=", + "rev": "1386415be8fef2f6b6bbdbe1828872471c5d802a", + "url": "https://chromium.googlesource.com/external/github.com/WebKit/Speedometer.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/spirv-cross/src": { + "args": { + "hash": "sha256-H43M9DXfEuyKuvo6rjb5k0KEbYOSFodbPJh8ZKY4PQg=", + "rev": "b8fcf307f1f347089e3c46eb4451d27f32ebc8d3", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/SPIRV-Cross" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/spirv-headers/src": { + "args": { + "hash": "sha256-t8Shkoa90TJt1MbTOefnLaguW4eYKsRFO1Jd0AUc70Y=", + "rev": "1e770e7de8373a8dd49f23416cf7ca4001d01040", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/SPIRV-Headers" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/spirv-tools/src": { + "args": { + "hash": "sha256-q5G4B75xBIXl1aG/vzbIDrc3Hs/MFoQ4nwh4ozb8hys=", + "rev": "b38c4f83024546d4000b2db8e2294cf81b7f26e0", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/SPIRV-Tools" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/sqlite/src": { + "args": { + "hash": "sha256-hf9PxQhXEKT49GbkFYCvRPBT0Qu+hDnDpebI92yO1Oo=", + "rev": "fc121d7d03cd6cbf499ec06a5112b263471b1181", + "url": "https://chromium.googlesource.com/chromium/deps/sqlite.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/squirrel.mac": { + "args": { + "hash": "sha256-4GfKQg0u3c9GI+jl3ixESNqWXQJKRMi+00QT0s2Shqw=", + "owner": "Squirrel", + "repo": "Squirrel.Mac", + "rev": "0e5d146ba13101a1302d59ea6e6e0b3cace4ae38" + }, + "fetcher": "fetchFromGitHub" + }, + "src/third_party/squirrel.mac/vendor/Mantle": { + "args": { + "hash": "sha256-ykR4JFDJyajpzubzptjrxC9WUbGBTma5YLaBiPB6y0s=", + "owner": "Mantle", + "repo": "Mantle", + "rev": "2a8e2123a3931038179ee06105c9e6ec336b12ea" + }, + "fetcher": "fetchFromGitHub" + }, + "src/third_party/squirrel.mac/vendor/ReactiveObjC": { + "args": { + "hash": "sha256-/MCqC1oFe3N9TsmfVLgl+deR6qHU6ZFQQjudb9zB5Mo=", + "owner": "ReactiveCocoa", + "repo": "ReactiveObjC", + "rev": "74ab5baccc6f7202c8ac69a8d1e152c29dc1ea76" + }, + "fetcher": "fetchFromGitHub" + }, + "src/third_party/swiftshader": { + "args": { + "hash": "sha256-bmXZLpz3wv7eQWoqTjZmjwnnILWSIjZ8iqo8CeLk5fw=", + "rev": "fce27a96526f54c6d31fdccf57629788e3712220", + "url": "https://swiftshader.googlesource.com/SwiftShader.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/text-fragments-polyfill/src": { + "args": { + "hash": "sha256-4rW2u1cQAF4iPWHAt1FvVXIpz2pmI901rEPks/w/iFA=", + "rev": "c036420683f672d685e27415de0a5f5e85bdc23f", + "url": "https://chromium.googlesource.com/external/github.com/GoogleChromeLabs/text-fragments-polyfill.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/tflite/src": { + "args": { + "hash": "sha256-eSqaWXtzZ4Bi9ilaJYGdZamzUjmo+AtDZ9KeZhsc/fY=", + "rev": "999d49c10046e240cd5366d349d3a5f6af16a0d4", + "url": "https://chromium.googlesource.com/external/github.com/tensorflow/tensorflow.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/ukey2/src": { + "args": { + "hash": "sha256-aaLs6ZS+CdBlCJ6ZhsmdAPFxiBIij6oufsDcNeRSV1E=", + "rev": "0275885d8e6038c39b8a8ca55e75d1d4d1727f47", + "url": "https://chromium.googlesource.com/external/github.com/google/ukey2.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/vulkan-deps": { + "args": { + "hash": "sha256-lsR+sh+XQP/wKgkBbie6Gp+kQNFnnC8TeNWpiWTdevw=", + "rev": "669a28b1f31f89bfc46b74791f127bcc5e5b2f06", + "url": "https://chromium.googlesource.com/vulkan-deps" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/vulkan-headers/src": { + "args": { + "hash": "sha256-pUxPwFGbOzP8ymTooeA1slFWEFsRoqUROSnndVtLiY8=", + "rev": "015e25c3c91b70eb1a754d36fb14c4ba6ad9b0b9", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/Vulkan-Headers" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/vulkan-loader/src": { + "args": { + "hash": "sha256-uyoysS7lSBNDRfvcwPT+gQqhE20UxiYUEw1UXnYS3fY=", + "rev": "cf0cf82ea16c0ff0be75940f282540d6085b2d3b", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/Vulkan-Loader" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/vulkan-tools/src": { + "args": { + "hash": "sha256-Hs9N0FM3eWWjLm4BrDJoZIrsPDVFx0iRAJeQ4gHTM7o=", + "rev": "e3d18f90c0b8ef1f52539e0674a42f0adfe30381", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/Vulkan-Tools" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/vulkan-utility-libraries/src": { + "args": { + "hash": "sha256-ZBie5uDTVEehxRQW1GZY5Ki/bnp82LoW3jfMUFL0O9A=", + "rev": "8383c46b129c2b3a5f3833e602d946d2fcc57e39", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/Vulkan-Utility-Libraries" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/vulkan-validation-layers/src": { + "args": { + "hash": "sha256-i3hochkK0LZPg8CsZMFkAL+8tf8QuuwtApAc4FDd0RM=", + "rev": "044eaba8a34a6e3bfb1d6aafac7c01068813a2b6", + "url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/Vulkan-ValidationLayers" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/vulkan_memory_allocator": { + "args": { + "hash": "sha256-fOnFkcQDEGIe5yB507qnP9nA1LBBPFblncNiJ8JxAwI=", + "rev": "7e55b011e16182fc349149abbd3aaf3b1db46421", + "url": "https://chromium.googlesource.com/external/github.com/GPUOpen-LibrariesAndSDKs/VulkanMemoryAllocator.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/wayland-protocols/gtk": { + "args": { + "hash": "sha256-75XNnLkF5Lt1LMRGT+T61k0/mLa3kkynfN+QWvZ0LiQ=", + "rev": "40ebed3a03aef096addc0af09fec4ec529d882a0", + "url": "https://chromium.googlesource.com/external/github.com/GNOME/gtk.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/wayland-protocols/kde": { + "args": { + "hash": "sha256-Dmcp/2ms/k7NxPPmPkp0YNfM9z2Es1ZO0uX10bc7N2Y=", + "rev": "0b07950714b3a36c9b9f71fc025fc7783e82926e", + "url": "https://chromium.googlesource.com/external/github.com/KDE/plasma-wayland-protocols.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/wayland-protocols/src": { + "args": { + "hash": "sha256-tdpEK7soY0aKSk6VD4nulH7ORubX8RfjXYmNAd/cWKY=", + "rev": "efbc060534be948b63e1f395d69b583eebba3235", + "url": "https://chromium.googlesource.com/external/anongit.freedesktop.org/git/wayland/wayland-protocols.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/wayland/src": { + "args": { + "hash": "sha256-5iG0HaPXJCEo027TuyXlJQNGluTaAPlvwQDFbiYOEJQ=", + "rev": "736d12ac67c20c60dc406dc49bb06be878501f86", + "url": "https://chromium.googlesource.com/external/anongit.freedesktop.org/git/wayland/wayland.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/webdriver/pylib": { + "args": { + "hash": "sha256-k5qx4xyO83jPtHaMh6aMigMJ3hsytFdFQOcZLmwPEYo=", + "rev": "1e954903022e9386b9acf452c24f4458dd4c4fc1", + "url": "https://chromium.googlesource.com/external/github.com/SeleniumHQ/selenium/py.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/webgl/src": { + "args": { + "hash": "sha256-Aax2hr/9Zq6Avk+TMU1OMBLGshUL6hyRTX6eoOQesqM=", + "rev": "216b10fafd3f6a900c715a8c758a4c7f9883b030", + "url": "https://chromium.googlesource.com/external/khronosgroup/webgl.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/webgpu-cts/src": { + "args": { + "hash": "sha256-6Y5Z0ErtsZdbuWTHa+PEiOxcZSbjBcnuOHbgtI1/+80=", + "rev": "b507bd117e53db86f2fb52d0d858d3ae7d684a85", + "url": "https://chromium.googlesource.com/external/github.com/gpuweb/cts.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/webpagereplay": { + "args": { + "hash": "sha256-+hcaP7C5Eh3SLl5B8mRgOVdM/tvnFnb/oqUIWPoe0NA=", + "rev": "b2b856131e36c99e9de9c419fe8ca02f857082ba", + "url": "https://chromium.googlesource.com/webpagereplay.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/webpagereplay/third_party/clang-format/script": { + "args": { + "hash": "sha256-Cm6BOOlEyD0kdYxMSmk6Fj1Dnfs3zCzXsm+BOXgBme0=", + "rev": "6eddfb5ec5f92127a531eda66c568d3a11e7ec11", + "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/clang/tools/clang-format.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/webrtc": { + "args": { + "hash": "sha256-ucH+9HBkFyOKEItAWVoYmEzyU7h/UgWIvp/eC/JqGWU=", + "rev": "1f975dfd761af6e5d76d28333191973b258d82a8", + "url": "https://webrtc.googlesource.com/src.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/weston/src": { + "args": { + "hash": "sha256-PySen9syu0OshtlHAZw666FeSQXdnsV8nlW9RmxgapM=", + "rev": "b65be9e699847c975440108a42f05412cc7fddac", + "url": "https://chromium.googlesource.com/external/anongit.freedesktop.org/git/wayland/weston.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/wuffs/src": { + "args": { + "hash": "sha256-V7inWJqH7Q4Ac/ZB//7XHrpgfAYUPBxWBerBem6Q/Kk=", + "rev": "50869df0ea703b4f41b238bfe26aec6ec9c86889", + "url": "https://skia.googlesource.com/external/github.com/google/wuffs-mirror-release-c.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/xnnpack/src": { + "args": { + "hash": "sha256-uw3r5g5rWamlFubBkXDb4KRx3hkOAoQyFo8l95GYGZI=", + "rev": "56ac34b3f45fae2eca1f32584f7f0b279be2cf1f", + "url": "https://chromium.googlesource.com/external/github.com/google/XNNPACK.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/third_party/zstd/src": { + "args": { + "hash": "sha256-vEl0s7Mjh+5rciOMxm99PNWiamtCk+sTN4lRYKCIZ+8=", + "rev": "5233c58e6ca0b1c4c6b353ad79649191ed195bdc", + "url": "https://chromium.googlesource.com/external/github.com/facebook/zstd.git" + }, + "fetcher": "fetchFromGitiles" + }, + "src/v8": { + "args": { + "hash": "sha256-x3rCWvC3hEjyJq6PNThhZEp4oRF9Y1JJEPnZTqVNVrY=", + "rev": "968f19a8970f8d91702d86f0ec1522f3909781b7", + "url": "https://chromium.googlesource.com/v8/v8.git" + }, + "fetcher": "fetchFromGitiles" + } + }, + "electron_yarn_data": { + "hash": "sha256-Y2TE5iMVUgXqqKojb90yzcCfFAhEy7STB53yYQQanPM=", + "missing_hashes": { + "@oxfmt/binding-android-arm-eabi@npm:0.42.0": "42c08d87ce491086843070241f8777fa2cb968f4a08f67b3f6c33a8f67e0b3eac50eae146daede743e90e3bc32326951c5188814eea02e9c3e4a9764a4b492ba", + "@oxfmt/binding-android-arm64@npm:0.42.0": "73e6609498d05c655c6a435af9f3e4f341137c260c7ae27fbb0377573574ca5200bd9f187aa90d442879733bbd0c4e91ae023c3b4579c9a57413a0b2922c023a", + "@oxfmt/binding-darwin-arm64@npm:0.42.0": "ed0f486a5085942727e255a9c14bfd99756d4af3ad2c2e702bfb7ab682fc9041d5327f3e89dc4dbfc9a09a6c884dbc9a79a46c720435c5ad2f2fe3f48bb9c3ac", + "@oxfmt/binding-darwin-x64@npm:0.42.0": "b607e67171aa33717f7fe80d9d5c8ca816ff30dbbd2b41c4b129977c749c62a4bb1f6829aa95c564d15246c98689ba153fc003a09a1549e2f3316810b35463be", + "@oxfmt/binding-freebsd-x64@npm:0.42.0": "c038e53f42083a56d548bd2b89765d1b36150c874e83a41631dfa039fe4fd999475a4a5a99414e43fe44654abdbdfb78c17f53fb482ba3bdc9d22f5641931a41", + "@oxfmt/binding-linux-arm-gnueabihf@npm:0.42.0": "79d0b84f3281c7935eb153a53b7032fbb159357580cbcac721096d87ceb124e40863c0b7786ff1b94ad2cdc9b1beabe37e972e1b959423af028e6dea0fc8e0b6", + "@oxfmt/binding-linux-arm-musleabihf@npm:0.42.0": "c67dfa0553ba44f0585c3bba85efcbbd42b63b59f177302693fa83cc7b6fe6a6f2509c972cae9b367eb7cd36e8578209657ac4928cf329bf816fa4bfc578d2c1", + "@oxfmt/binding-linux-arm64-gnu@npm:0.42.0": "f8507b36f7f2673a4d6db227ed2e98f94d30f81275820d0d25e5e6b0b9b20c7f4cc32b646ae02aac0068b90ba3d47bcbd85ad789b27f028b8ea07e168ec731ce", + "@oxfmt/binding-linux-arm64-musl@npm:0.42.0": "c4d0406e36248b4a8ddd62ac2d7c1b6648d23fb2b1eee471e3965d6c411b2dedfc681d227adcff50bbff5f786727bef31420610564691887cdecb50d7f1f7587", + "@oxfmt/binding-linux-ppc64-gnu@npm:0.42.0": "12b0eb3cff0807f898dd2e47de5712c8b57d2373108135e87f1de69902204c0527b383753983388f32e48749c479ce0f6247fbc927a2e035b2fb1f6c31ae5df7", + "@oxfmt/binding-linux-riscv64-gnu@npm:0.42.0": "aff4c5104769388174a69f5f4ad418f33e86ff1286117072e2200b7217aa9d30375ffb4deeabd728aac7975ed5e79832ac725725df9ff2ea6f819aef5e166353", + "@oxfmt/binding-linux-riscv64-musl@npm:0.42.0": "710b0b9fc2d999a66b2c9e656e40e74e71d820d8670d5ee64dc36d373f1132a0c3ddcbedba6130f832b9e8abbb0988ab95de7a6ddd4657007f05fea4a3631835", + "@oxfmt/binding-linux-s390x-gnu@npm:0.42.0": "8fc8ee6c1ea3369d3f7ec2f6dbe3fe846663c8e10a0ea976b1b2e150117359580d7efc904f5da0ead2f59066b1e17076aa09c1c4f2544071c29b623ada15da70", + "@oxfmt/binding-linux-x64-gnu@npm:0.42.0": "d46d962752e0e2978cbd9b552a0d4bebde69fa9581512dfda33e7bc645c849e2787ef6a4e2ae825e7d2abf68b895c90c4a351387d2f0d2ba336e990c54e245f0", + "@oxfmt/binding-linux-x64-musl@npm:0.42.0": "e757b0b12ccf6e7355e2a3123fa0bea0908e1f220b7bb3601c18203bc78f1157be8364af9df3ca56f9c0bb123aeecbf058df31a9ee12612e1149b9c6228dc6f9", + "@oxfmt/binding-openharmony-arm64@npm:0.42.0": "fe85007d6e7e7c1b6662a9756267de459fc7213af9ddf6f0494397d9d666a452d4a1a6f6fe6ce288d8dd4763d07b52b4534cc177bdf0e5613559f144b78e8fbb", + "@oxfmt/binding-win32-arm64-msvc@npm:0.42.0": "04bd529ea236c23d8dc73d95acd365612ab489b0e6a4bdd976302b933b92dcc11d4d1629e2294036f16c1e1f5120140547f65060a9e2dc8adbb21f790e2eca39", + "@oxfmt/binding-win32-ia32-msvc@npm:0.42.0": "9775afa164de049416abf481f062b8c670cd27a70d82a0868fa61749f741e777a76eb0a57a9ef276f158a35741d90a856a492777a0a9f17c9ac01ead32935fe3", + "@oxfmt/binding-win32-x64-msvc@npm:0.42.0": "5c38197ac6f874c2622b68a531b9fc9a221de05aa09c40717bba775f658680ebf964db7aa41c12271f90261bf50713cd4ebb2c10f12bf33cf2103fb9d67a88bb", + "@oxlint/binding-android-arm-eabi@npm:1.57.0": "3860b1c5a2096817da9c18cbbc24f8b56f4b6b0cefdea19e0cc0f278055aac85d891fa9d70e02f551532bf45f6a79bb3ebc63d1c2e1dff724134a9bc398f8060", + "@oxlint/binding-android-arm64@npm:1.57.0": "fb40a768d5608e9b41c35f16cac2e57571cbcbf1b872bc145f60a7e1fd7a478c3806e3a330579e167f8877411fe362561a103976e41cbd1e46fb02d7d0d97611", + "@oxlint/binding-darwin-arm64@npm:1.57.0": "fd75b91d3db274782afec0b1dee319a01b864f11e0a4af1808de23762403000d13f7921c7889302c75d945b09005a44cdf17e3ad345c1ef2842403ac28f0dfb0", + "@oxlint/binding-darwin-x64@npm:1.57.0": "75e2e5423ccc82f61def946317c774f951e0a1443cd9c4c1550e0941da9a645a7acd3ed344c65b50288d4842a3a523a6cd9838a28d452d20c7a041fd1b15fe3a", + "@oxlint/binding-freebsd-x64@npm:1.57.0": "ad0f737171b8d60a1bcfeeb1736f0ecb751ebbfd915ad7e27d5ad25a858419be541a0854fc573be01752def42b9a3864d0aa11176b574571bb44350307ad2f59", + "@oxlint/binding-linux-arm-gnueabihf@npm:1.57.0": "a912a546bab5831bb5ae6e697e67b33f86fc48caaf1615df9ff3234818299845cf27dacecbe17ec679a757eb6354e5e15002c632ba43f76fc890060bebd45d1b", + "@oxlint/binding-linux-arm-musleabihf@npm:1.57.0": "e15e5c951193afd936f155db38b9dd48f9cf0e7de8eaf07acf957c4b5b47e79c2f668d4c47310bf28efb2af5640a5a7d3d6700c723c748efefa7e72c8660b1a3", + "@oxlint/binding-linux-arm64-gnu@npm:1.57.0": "c167c4bcfe4067703c626264b973dd2195192615aa4bb1ef07d918c8cd128cb1d3504ba991dbd78daee29e6bf5997704c87004e93a379231377c7f7b5c505e55", + "@oxlint/binding-linux-arm64-musl@npm:1.57.0": "d0a60e2aa7d491baf85450fb9c0053598da5cc884b9b4e0ed557baa813bcead8e9470259c5f390e412ba173932a0b2703f0b17b06b494ce480fc25ded8074461", + "@oxlint/binding-linux-ppc64-gnu@npm:1.57.0": "7798e0a7e8c71f6f3e2f495fdf1109f08d4c2a7357fa19c7f9111b9510f1417175afb00845e39692e5fa4b510cc56d3e8f76bf3f0372f651d19d587b623cdab8", + "@oxlint/binding-linux-riscv64-gnu@npm:1.57.0": "8cc0cb3eaf2ff0716e52ce8743e5cc7e952b25150a5e75fcb9b5d7a4f82a99295ce7a3ca9a0bf6694e917c629621e01e465d816379acb264c5f2f4e860d44e24", + "@oxlint/binding-linux-riscv64-musl@npm:1.57.0": "1de23e270049060ef5cc1824de2aafbd7129d07c13052c109bd7de62f8bf29ab91bbcf8c15cbbc6ba6aa382b90e1bae456d5160bc8518adb7973cdcd99625127", + "@oxlint/binding-linux-s390x-gnu@npm:1.57.0": "35791cd14a661de5605587c81b5f4d9715de92a2f888b4e5fb1ea85626b59c1b53306feadd9020652598e0ff7db8ec31d0d43f8e647a8e1c38361d1bfdc5f288", + "@oxlint/binding-linux-x64-gnu@npm:1.57.0": "a55364f9d86efa12f38c54f01b02d1310600245a10cdd27a1ec9b0bfc98522a686feb6b15b1a2ef70c7676eb7b3dc7efa5e2e252313496fc910be368d4c05ee3", + "@oxlint/binding-linux-x64-musl@npm:1.57.0": "f6862ffcbd14261528f9a3237d8f52752b745822b54d1c4c6c937830e3712e7b2b8d00aa07838bfc7024f2648d9f3b85c3fa05f6a78c40b5f259e618dbfbeb68", + "@oxlint/binding-openharmony-arm64@npm:1.57.0": "1420c753028b583ce4ea00edb14f47def68d675492ef8611e98ffe0cf0a0749cc368b8619d4760d38e02c15b06bda32eafce907f6bcefa997db4fbff3a900be7", + "@oxlint/binding-win32-arm64-msvc@npm:1.57.0": "2bb5a9f09e1f95e7bf4a9f76af29ba7623d3a83f35e9201cd2f45375ae891c77ddb87a09dcbf2f2416fd3d6e24f34582618da307ed65f8435b943672cb8be5aa", + "@oxlint/binding-win32-ia32-msvc@npm:1.57.0": "a2f8f3387866a6d371c50ec4d3aa2043e420bfe1cd523053083f68a33ee651fc9948485060b4e8827d603695b04d492cfa5ef8cdd1fb760cc34dd7674fe13a0b", + "@oxlint/binding-win32-x64-msvc@npm:1.57.0": "380591b6937dc483e2db3edf5ace4aa48a06d1d17d419ded224df8465b20840fea8f9d1b1aef38dfa89622eb9d7991592d80b15ceb871b5c09ef9b85197c0de4" + } + }, + "modules": "148", + "node": "24.18.0", + "version": "43.1.0" } } diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index ad80a543d4be..830fbe91ae47 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -5151,6 +5151,7 @@ with pkgs; src = electron-source.electron_42; bin = electron_42-bin; }; + electron_43 = electron-source-electron_43; } ) electron_38 @@ -5158,6 +5159,7 @@ with pkgs; electron_40 electron_41 electron_42 + electron_43 ; electron = electron_41; electron-bin = electron_41-bin; From d3112be0609d618ae45187735f0a61c7e6475dcd Mon Sep 17 00:00:00 2001 From: teutat3s <10206665+teutat3s@users.noreply.github.com> Date: Thu, 2 Jul 2026 16:42:11 +0200 Subject: [PATCH 06/49] electron_43-bin: init at 43.1.0 - Changelog: https://github.com/electron/electron/releases/tag/v43.0.0 - Changelog: https://github.com/electron/electron/releases/tag/v43.1.0 - Diff: https://github.com/electron/electron/compare/refs/tags/v43.0.0...v43.1.0 (cherry picked from commit aa8118cd09bc4b4d886025263d945db6b6655371) --- pkgs/development/tools/electron/binary/info.json | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/pkgs/development/tools/electron/binary/info.json b/pkgs/development/tools/electron/binary/info.json index 896922954a0a..657f8b38a396 100644 --- a/pkgs/development/tools/electron/binary/info.json +++ b/pkgs/development/tools/electron/binary/info.json @@ -53,5 +53,16 @@ "x86_64-linux": "3a729b020acb04aefac2c9b4b29c65b37dd7126a14a04d1ef29acb256d3edbd1" }, "version": "42.5.1" + }, + "43": { + "hashes": { + "aarch64-darwin": "2ee24f768c41bc2ed9bd580d7797b185dffb550dafca59c2cd08b51965bcda3a", + "aarch64-linux": "78799ae4fdc7969acb152aa0f33f39bd5eaca2de3eafe817a13487b872abe43c", + "armv7l-linux": "1f32ac165dd1d01f1dcb8bfb881503369c7b739dd292034ef61e2ea75b852a2c", + "headers": "1xqgvsj7pq2j5yvg0yxa4l5l276dmj9zlpxmvy2g993bdypxj8zi", + "x86_64-darwin": "c84cd358a6c58ee9d6ce26ced694ab3b750109e9f29145ff5a639db64037f1de", + "x86_64-linux": "be56b5b8451bda585b56e6a6a67757da2cb7ead59f036b6000431a51c0e0c79b" + }, + "version": "43.1.0" } } From 8e90114015ab242305b6e74d849f678bad576e59 Mon Sep 17 00:00:00 2001 From: teutat3s <10206665+teutat3s@users.noreply.github.com> Date: Thu, 2 Jul 2026 16:43:14 +0200 Subject: [PATCH 07/49] electron-chromedriver_43: init at 43.1.0 - Changelog: https://github.com/electron/electron/releases/tag/v43.0.0 - Changelog: https://github.com/electron/electron/releases/tag/v43.1.0 - Diff: https://github.com/electron/electron/compare/refs/tags/v43.0.0...v43.1.0 (cherry picked from commit ad7bfe94610b4ddaf060c51a015a916c983e3d97) --- .../development/tools/electron/chromedriver/info.json | 11 +++++++++++ pkgs/top-level/all-packages.nix | 7 ++++++- 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/pkgs/development/tools/electron/chromedriver/info.json b/pkgs/development/tools/electron/chromedriver/info.json index 4577a69901ed..e91bb0e7322f 100644 --- a/pkgs/development/tools/electron/chromedriver/info.json +++ b/pkgs/development/tools/electron/chromedriver/info.json @@ -53,5 +53,16 @@ "x86_64-linux": "e0db56b8781035a48aae7fefdac311abb8993a7f6e72009e7adfb70926565bf0" }, "version": "42.5.1" + }, + "43": { + "hashes": { + "aarch64-darwin": "733c8fd5b80e761739cc776c1c6777115bd39cf86d825e895d996734ee3f3515", + "aarch64-linux": "7bdc6d18aafb3aa434374998bbfccdd2087b9495745dd134c06e5f74eafa95d5", + "armv7l-linux": "77a395bb4f4046fb43de81e9eac4b3f5d7d0f5911f2262bcd110bfe2ad1f3076", + "headers": "1xqgvsj7pq2j5yvg0yxa4l5l276dmj9zlpxmvy2g993bdypxj8zi", + "x86_64-darwin": "1450a8af80b7d4c66a4b85779090ce80e1e1b52dacef5dd89322a10b07fe4848", + "x86_64-linux": "e946ae6cad7dc279431e841e0bc19ba4e0dc16a82c5a9c1f7c4d9f3925e5b39a" + }, + "version": "43.1.0" } } diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 830fbe91ae47..156cbea11f42 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -5110,6 +5110,7 @@ with pkgs; electron_40-bin electron_41-bin electron_42-bin + electron_43-bin ; inherit (callPackages ../development/tools/electron/chromedriver { }) @@ -5118,6 +5119,7 @@ with pkgs; electron-chromedriver_40 electron-chromedriver_41 electron-chromedriver_42 + electron-chromedriver_43 ; inherit @@ -5151,7 +5153,10 @@ with pkgs; src = electron-source.electron_42; bin = electron_42-bin; }; - electron_43 = electron-source-electron_43; + electron_43 = getElectronPkg { + src = electron-source.electron_43; + bin = electron_43-bin; + }; } ) electron_38 From 8d1d1f81a4106b558611c1231496e9516a64afba Mon Sep 17 00:00:00 2001 From: Steven Allen Date: Sat, 18 Jul 2026 10:01:35 -0700 Subject: [PATCH 08/49] [Backport release-26.05] python3Packages.stanza: backport security fixes from 1.14.0 Release notes: https://github.com/stanfordnlp/stanza/releases/tag/v1.14.0 Not-cherry-picked-because: manual backport of security fixes --- .../stanza/GHSA-2fwf-f686-7p34.patch | 153 +++++++ .../stanza/GHSA-487q-m798-cp85.patch | 61 +++ .../stanza/GHSA-c9h2-qmqw-qf6h.patch | 399 ++++++++++++++++++ .../python-modules/stanza/default.nix | 13 + 4 files changed, 626 insertions(+) create mode 100644 pkgs/development/python-modules/stanza/GHSA-2fwf-f686-7p34.patch create mode 100644 pkgs/development/python-modules/stanza/GHSA-487q-m798-cp85.patch create mode 100644 pkgs/development/python-modules/stanza/GHSA-c9h2-qmqw-qf6h.patch diff --git a/pkgs/development/python-modules/stanza/GHSA-2fwf-f686-7p34.patch b/pkgs/development/python-modules/stanza/GHSA-2fwf-f686-7p34.patch new file mode 100644 index 000000000000..b9646f37546b --- /dev/null +++ b/pkgs/development/python-modules/stanza/GHSA-2fwf-f686-7p34.patch @@ -0,0 +1,153 @@ +From 3260967d7fdeeec7dd99f057ae8103e0b89844a5 Mon Sep 17 00:00:00 2001 +From: John Bauer +Date: Sat, 20 Jun 2026 15:43:05 -0700 +Subject: [PATCH 1/3] Fix a possible 'zip slip' attack - frankly unlikely given + that we control the resources being downloaded, but worth protecting against. + See + https://github.com/stanfordnlp/stanza/security/advisories/GHSA-2fwf-f686-7p34 + +--- + stanza/resources/common.py | 18 ++++++ + stanza/tests/resources/test_common.py | 87 +++++++++++++++++++++++++++ + 2 files changed, 105 insertions(+) + +diff --git a/stanza/resources/common.py b/stanza/resources/common.py +index 5c73c10e..beeec041 100644 +--- a/stanza/resources/common.py ++++ b/stanza/resources/common.py +@@ -79,12 +79,30 @@ def get_md5(path): + raise + return hashlib.md5(data).hexdigest() + ++def _is_within_directory(directory, target): ++ """ ++ Check that `target` resolves to a path inside `directory`. ++ """ ++ directory = os.path.realpath(directory) ++ target = os.path.realpath(target) ++ return os.path.commonpath([directory]) == os.path.commonpath([directory, target]) ++ + def unzip(path, filename): + """ + Fully unzip a file `filename` that's in a directory `dir`. ++ ++ Before unzipping, paths are checked so that a 'zip slip' error cannot happen. ++ See https://github.com/stanfordnlp/stanza/security/advisories/GHSA-2fwf-f686-7p34 + """ + logger.debug(f'Unzip: {path}/{filename}...') + with zipfile.ZipFile(os.path.join(path, filename)) as f: ++ for member in f.namelist(): ++ member_path = os.path.join(path, member) ++ if not _is_within_directory(path, member_path): ++ raise ValueError( ++ f"Zip file {filename} contains an entry that would extract " ++ f"outside of the target directory: {member}" ++ ) + f.extractall(path) + + def get_root_from_zipfile(filename): +diff --git a/stanza/tests/resources/test_common.py b/stanza/tests/resources/test_common.py +index 75fed45d..ae577451 100644 +--- a/stanza/tests/resources/test_common.py ++++ b/stanza/tests/resources/test_common.py +@@ -6,6 +6,7 @@ import logging + import os + import pytest + import tempfile ++import zipfile + + import stanza + from stanza.resources import common +@@ -155,3 +156,89 @@ def test_download_restores_logging_level(tmp_path, monkeypatch): + assert stanza.logger.level == logging.WARNING, ( + f"Expected WARNING ({logging.WARNING}) after download, got {stanza.logger.level}" + ) ++ ++ ++def _make_malicious_zip(zip_path, member_name, content=b"pwned"): ++ """ ++ Build a zip file containing a single entry whose name is `member_name`. ++ ++ zipfile.ZipFile.write() would normalize a path like this, so we use ++ writestr() with an explicit ZipInfo, which does not sanitize the name - ++ this mirrors what a maliciously crafted zip looks like on disk. ++ """ ++ with zipfile.ZipFile(zip_path, "w") as zf: ++ zf.writestr(zipfile.ZipInfo(member_name), content) ++ ++ ++def test_unzip_blocks_relative_traversal(): ++ """ ++ A zip entry like "../../evil.txt" should not be extracted outside ++ the target directory. ++ """ ++ with tempfile.TemporaryDirectory(dir=TEST_WORKING_DIR) as test_dir: ++ target_dir = os.path.join(test_dir, "target") ++ os.makedirs(target_dir) ++ zip_path = os.path.join(target_dir, "evil.zip") ++ _make_malicious_zip(zip_path, "../../evil.txt") ++ ++ with pytest.raises(ValueError): ++ common.unzip(target_dir, "evil.zip") ++ ++ # nothing should have escaped onto disk outside test_dir ++ assert not os.path.exists(os.path.join(test_dir, "..", "evil.txt")) ++ escaped_path = os.path.normpath(os.path.join(target_dir, "..", "..", "evil.txt")) ++ assert not os.path.exists(escaped_path) ++ ++ ++def test_unzip_blocks_nested_traversal(): ++ """ ++ Traversal hidden a few directories deep, e.g. "subdir/../../../evil.txt", ++ should also be rejected. ++ """ ++ with tempfile.TemporaryDirectory(dir=TEST_WORKING_DIR) as test_dir: ++ target_dir = os.path.join(test_dir, "target") ++ os.makedirs(target_dir) ++ zip_path = os.path.join(target_dir, "evil.zip") ++ _make_malicious_zip(zip_path, "subdir/../../../evil.txt") ++ ++ with pytest.raises(ValueError): ++ common.unzip(target_dir, "evil.zip") ++ ++ ++def test_unzip_blocks_absolute_path(): ++ """ ++ A zip entry with an absolute path should not be written to that ++ absolute location. ++ """ ++ with tempfile.TemporaryDirectory(dir=TEST_WORKING_DIR) as test_dir: ++ target_dir = os.path.join(test_dir, "target") ++ os.makedirs(target_dir) ++ zip_path = os.path.join(target_dir, "evil.zip") ++ ++ # a path well outside any plausible target dir ++ absolute_evil = os.path.join(tempfile.gettempdir(), "stanza_test_evil_absolute.txt") ++ _make_malicious_zip(zip_path, absolute_evil) ++ ++ with pytest.raises(ValueError): ++ common.unzip(target_dir, "evil.zip") ++ ++ assert not os.path.exists(absolute_evil) ++ ++ ++def test_unzip_allows_well_formed_zip(): ++ """ ++ Sanity check: a normal zip with safe relative paths should still ++ extract correctly after the path-safety check is added. ++ """ ++ with tempfile.TemporaryDirectory(dir=TEST_WORKING_DIR) as test_dir: ++ target_dir = os.path.join(test_dir, "target") ++ os.makedirs(target_dir) ++ zip_path = os.path.join(target_dir, "good.zip") ++ with zipfile.ZipFile(zip_path, "w") as zf: ++ zf.writestr("models/default.pt", b"fake model data") ++ zf.writestr("readme.txt", b"safe content") ++ ++ common.unzip(target_dir, "good.zip") ++ ++ assert os.path.exists(os.path.join(target_dir, "models", "default.pt")) ++ assert os.path.exists(os.path.join(target_dir, "readme.txt")) +-- +2.54.0 + diff --git a/pkgs/development/python-modules/stanza/GHSA-487q-m798-cp85.patch b/pkgs/development/python-modules/stanza/GHSA-487q-m798-cp85.patch new file mode 100644 index 000000000000..01144952545b --- /dev/null +++ b/pkgs/development/python-modules/stanza/GHSA-487q-m798-cp85.patch @@ -0,0 +1,61 @@ +From 3b7622351afdd1552c69f717da6a02b1dabb9de1 Mon Sep 17 00:00:00 2001 +From: John Bauer +Date: Thu, 25 Jun 2026 12:07:44 -0700 +Subject: [PATCH 3/3] Multi-step mitigation of pickle security issue - + https://github.com/stanfordnlp/stanza/security/advisories/GHSA-487q-m798-cp85 + - in this change, we make the unpickler heavily restricted. Future releases + will remove this altogether + +(Also, no need to deserialize twice) +--- + stanza/models/common/doc.py | 22 +++++++++++++++++++--- + 1 file changed, 19 insertions(+), 3 deletions(-) + +diff --git a/stanza/models/common/doc.py b/stanza/models/common/doc.py +index 00937171..4543ca18 100644 +--- a/stanza/models/common/doc.py ++++ b/stanza/models/common/doc.py +@@ -64,6 +64,22 @@ class DocJSONEncoder(json.JSONEncoder): + return obj.to_json() + return json.JSONEncoder.default(self, obj) + ++class RestrictedUnpickler(pickle.Unpickler): ++ # Stanza Document serialization only ever produces tuples, lists, dicts, ++ # and scalar primitives. No custom classes are needed. ++ SAFE_CLASSES = frozenset({ ++ ('builtins', 'tuple'), ++ ('builtins', 'list'), ++ ('builtins', 'dict'), ++ }) ++ ++ def find_class(self, module, name): ++ if (module, name) not in self.SAFE_CLASSES: ++ raise pickle.UnpicklingError( ++ f"Blocked unsafe global: {module}.{name}" ++ ) ++ return super().find_class(module, name) ++ + class Document(StanzaObject): + """ A document class that stores attributes of a document and carries a list of sentences. + """ +@@ -540,14 +556,14 @@ class Document(StanzaObject): + def from_serialized(cls, serialized_string): + """ Create and initialize a new document from a serialized string generated by Document.to_serialized_string(): + """ +- stuff = pickle.loads(serialized_string) ++ stuff = RestrictedUnpickler(io.BytesIO(serialized_string)).load() + if not isinstance(stuff, tuple): + raise TypeError("Serialized data was not a tuple when building a Document") + if len(stuff) == 2: +- text, sentences = pickle.loads(serialized_string) ++ text, sentences = stuff + doc = cls(sentences, text) + else: +- text, sentences, comments = pickle.loads(serialized_string) ++ text, sentences, comments = stuff + doc = cls(sentences, text, comments) + return doc + +-- +2.54.0 + diff --git a/pkgs/development/python-modules/stanza/GHSA-c9h2-qmqw-qf6h.patch b/pkgs/development/python-modules/stanza/GHSA-c9h2-qmqw-qf6h.patch new file mode 100644 index 000000000000..c2550d6b4a35 --- /dev/null +++ b/pkgs/development/python-modules/stanza/GHSA-c9h2-qmqw-qf6h.patch @@ -0,0 +1,399 @@ +From 7233600b1bd6897014df3e5fc66655408453f965 Mon Sep 17 00:00:00 2001 +From: John Bauer +Date: Sat, 20 Jun 2026 22:49:02 -0700 +Subject: [PATCH 2/3] From Claude - remove most of the subprocess calls. The + only remaining one is for estimating the size of xz files, has a fallback if + xz is not available, and is not a security hole with the way it is written. + Addresses + https://github.com/stanfordnlp/stanza/security/advisories/GHSA-c9h2-qmqw-qf6h + Although it is worth pointing out that since this script will only be used + with user controlled input files, this is only a theoretical security hole, + and the more significant improvement is making this portable to Windows. + +--- + stanza/utils/charlm/make_lm_data.py | 316 ++++++++++++++++++++++++---- + 1 file changed, 272 insertions(+), 44 deletions(-) + +diff --git a/stanza/utils/charlm/make_lm_data.py b/stanza/utils/charlm/make_lm_data.py +index 4bd28e5a..e6d8d1aa 100644 +--- a/stanza/utils/charlm/make_lm_data.py ++++ b/stanza/utils/charlm/make_lm_data.py +@@ -15,12 +15,48 @@ Args: + - tgt_root: root directory of the target. + - langs: a list of language codes to process; if specified, languages not in this list will be ignored. + Note: edit the {EXCLUDED_FOLDERS} variable to exclude more folders in the source directory. ++ ++Implementation note (shuffle/split): ++ Earlier versions of this script shelled out to `cat`, `xzcat`, `zcat`, `shuf`, and `split` via ++ subprocess(shell=True). This relied on filenames never containing shell metacharacters, and did ++ not work on Windows (no shuf/split/xzcat there). This version avoids the shell entirely and ++ instead does a two pass bucket shuffle: ++ ++ Pass 1: every source file (decompressed on the fly if .gz / .xz) is streamed line by line, and ++ each line is assigned uniformly at random to one of N bucket files, where N is the same ++ as the eventual number of train shards. This scatters every source file's content ++ proportionally across every bucket, which matters when there are few, large source files ++ (e.g. one big Wikipedia dump and one big Common Crawl dump) -- without this step, naive ++ chunked reading would put long runs of a single source into a single shard, badly skewing ++ dev/test (which are just the first couple of shards). Pass 1 only ever needs N file ++ handles open for writing plus one for reading, so it stays well under OS fd limits ++ regardless of how many source files there are (we've seen 400+ for some languages). ++ Pass 2: each bucket (already approximately shard-sized by construction) is read fully into memory, ++ shuffled locally with random.shuffle, and written out as the corresponding final shard. ++ Because every bucket already contains a proportional mix of all source files, every shard ++ -- including dev/test -- ends up with the same source mixture as the corpus as a whole. ++ ++ This trades one extra streaming read+write pass for: no shell dependency, Windows compatibility, and ++ (with the bucket-then-local-shuffle approach) better dev/test distributional properties than a purely ++ local chunk shuffle would give when source files are few and large. ++ ++ One narrow subprocess use remains, deliberately: estimating a target bucket/shard count for .xz ++ *source* files shells out to `xz --robot -l path` (list form, no shell=True, so still safe ++ regardless of filename contents) to read the file's size index in O(1) without a full ++ decompression pass. This is only used to size pass 1 -- not load-bearing for correctness -- and ++ falls back to on-disk size (an underestimate for compressed files, which just makes shards a bit ++ larger than split_size) if the xz binary isn't available. Final .xz compression of output files ++ uses the stdlib lzma module instead (pure Python, no subprocess, no xz binary dependency) -- ++ single threaded, so slower than `xz -T0` on multi-core machines for very large files, but that ++ tradeoff was preferred over a multiprocessing-based parallel compressor for now. + """ + + import argparse +-import glob ++import gzip ++import lzma + import os + from pathlib import Path ++import random + import shutil + import subprocess + import tempfile +@@ -29,6 +65,11 @@ from tqdm import tqdm + + EXCLUDED_FOLDERS = ['raw_corpus'] + ++# Read/write files in fixed-size text chunks to keep streaming I/O fast without ++# loading whole files into memory. ++IO_CHUNK_LINES = 8192 ++ ++ + def main(): + parser = argparse.ArgumentParser() + parser.add_argument("src_root", default="src", help="Root directory with all source files. Expected structure is root dir -> language dirs -> package dirs -> text files to process") +@@ -38,6 +79,8 @@ def main(): + parser.add_argument("--no_xz_output", default=True, dest="xz_output", action="store_false", help="Output compressed xz files") + parser.add_argument("--split_size", default=50, type=int, help="How large to make each split, in MB") + parser.add_argument("--no_make_test_file", default=True, dest="make_test_file", action="store_false", help="Don't save a test file. Honestly, we never even use it. Best for low resource languages where every bit helps") ++ parser.add_argument("--max_open_handles", default=100, type=int, help="Cap on simultaneously open bucket files in pass 1. Mainly relevant if split_size is set very small, producing a huge number of buckets; keep this comfortably under the OS file descriptor limit (ulimit -n).") ++ parser.add_argument("--bucket_compression", default=False, action="store_true", help="Compress intermediate bucket files (pass 1 output) with xz. Saves disk space at the cost of extra CPU; off by default since buckets are temporary and disk is usually cheaper than CPU time.") + args = parser.parse_args() + + print("Processing files:") +@@ -86,54 +129,165 @@ def main(): + if not os.path.exists(tgt_dir): + os.makedirs(tgt_dir) + print(f"-> Processing {lang}-{dataset_name}") +- prepare_lm_data(src_dir, tgt_dir, lang, dataset_name, args.xz_output, split_size, args.make_test_file) ++ prepare_lm_data(src_dir, tgt_dir, lang, dataset_name, args.xz_output, split_size, ++ args.make_test_file, args.max_open_handles, args.bucket_compression) + + print("") + +-def prepare_lm_data(src_dir, tgt_dir, lang, dataset_name, compress, split_size, make_test_file): ++ ++def open_text_read(path): ++ """ ++ Open a .txt / .txt.gz / .txt.xz file for streaming text reading, regardless of compression. ++ """ ++ if path.endswith(".txt"): ++ return open(path, "rt", encoding="utf-8", errors="surrogateescape") ++ elif path.endswith(".txt.xz"): ++ return lzma.open(path, "rt", encoding="utf-8", errors="surrogateescape") ++ elif path.endswith(".txt.gz"): ++ return gzip.open(path, "rt", encoding="utf-8", errors="surrogateescape") ++ else: ++ raise AssertionError("should not have found %s" % path) ++ ++ ++def open_bucket_read(path, compress): ++ if compress: ++ return lzma.open(path + ".xz", "rt", encoding="utf-8", errors="surrogateescape") ++ else: ++ return open(path, "rt", encoding="utf-8", errors="surrogateescape") ++ ++ ++def get_input_files(src_dir): ++ src_dir = Path(src_dir) ++ input_files = (sorted(src_dir.glob("*.txt")) + ++ sorted(src_dir.glob("*.txt.xz")) + ++ sorted(src_dir.glob("*.txt.gz"))) ++ return [str(f) for f in input_files] ++ ++ ++def compress_file_to_xz(path): ++ """ ++ Compress a file to .xz and remove the original, matching the behavior of the `xz` CLI run on ++ a single file (in-place replace: path -> path + ".xz", original deleted). Pure Python via the ++ stdlib lzma module -- single-threaded, so slower than `xz -T0` on multi-core machines for large ++ files, but removes the xz binary as a hard dependency for producing the final deliverable ++ output files. Binary mode + copyfileobj avoids any text encode/decode roundtrip, since we're ++ just recompressing existing bytes, not transforming them. ++ """ ++ xz_path = path + ".xz" ++ with open(path, "rb") as fin, lzma.open(xz_path, "wb") as fout: ++ shutil.copyfileobj(fin, fout) ++ os.remove(path) ++ ++ ++def gzip_uncompressed_size(path): ++ """ ++ Gzip files store the uncompressed size mod 2**32 in their trailer (last 4 bytes) -- a O(1) ++ lookup, no decompression needed. The mod-2**32 wraparound means this is only exact for files ++ under 4GB uncompressed; for anything larger it under-reports, which would just make our bucket ++ count estimate low (buckets/shards end up bigger than split_size) -- a soft target miss, not a ++ correctness problem, and per-source-file files over 4GB uncompressed are not the common case ++ for the per-file granularity this script deals with. ++ """ ++ import struct ++ with open(path, "rb") as f: ++ f.seek(-4, os.SEEK_END) ++ return struct.unpack(" Copying files into {tgt_tmp}...") +- # TODO: we can do this without the shell commands +- input_files = glob.glob(str(src_dir) + '/*.txt') + glob.glob(str(src_dir) + '/*.txt.xz') + glob.glob(str(src_dir) + '/*.txt.gz') +- for src_fn in tqdm(input_files): +- if src_fn.endswith(".txt"): +- cmd = f"cat {src_fn} >> {tgt_tmp}" +- subprocess.run(cmd, shell=True) +- elif src_fn.endswith(".txt.xz"): +- cmd = f"xzcat {src_fn} >> {tgt_tmp}" +- subprocess.run(cmd, shell=True) +- elif src_fn.endswith(".txt.gz"): +- cmd = f"zcat {src_fn} >> {tgt_tmp}" +- subprocess.run(cmd, shell=True) +- else: +- raise AssertionError("should not have found %s" % src_fn) +- tgt_tmp_shuffled = os.path.join(tempdir, f"{lang}-{dataset_name}.tmp.shuffled") + +- print(f"--> Shuffling files into {tgt_tmp_shuffled}...") +- cmd = f"cat {tgt_tmp} | shuf > {tgt_tmp_shuffled}" +- result = subprocess.run(cmd, shell=True) +- if result.returncode != 0: +- raise RuntimeError("Failed to shuffle files!") +- size = os.path.getsize(tgt_tmp_shuffled) / 1024 / 1024 / 1024 +- print(f"--> Shuffled file size: {size:.4f} GB") +- if size < 0.1: ++ input_files = get_input_files(src_dir) ++ if not input_files: ++ print(f"--> No input files found in {src_dir}, skipping.") ++ return ++ ++ on_disk_bytes = measure_size_for_bucket_count(input_files) ++ num_buckets = max(1, round(on_disk_bytes / split_size)) ++ print(f"--> On-disk size: {on_disk_bytes/1024/1024/1024:.4f} GB, targeting ~{num_buckets} shard(s)") ++ ++ train_dir = tgt_dir / 'train' ++ if not os.path.exists(train_dir): ++ os.makedirs(train_dir) ++ ++ with tempfile.TemporaryDirectory(dir=tgt_dir) as tempdir: ++ bucket_paths = [os.path.join(tempdir, f"bucket-{i:04d}.txt") for i in range(num_buckets)] ++ ++ print(f"--> Pass 1/2: scattering {len(input_files)} input file(s) across {num_buckets} bucket(s)...") ++ actual_bytes = scatter_into_buckets(input_files, bucket_paths, max_open_handles, bucket_compression) ++ actual_gb = actual_bytes / 1024 / 1024 / 1024 ++ print(f"--> Actual decompressed size: {actual_gb:.4f} GB") ++ if actual_gb < 0.1: + raise RuntimeError("Not enough data found to build a charlm. At least 100MB data expected") + +- print(f"--> Splitting into smaller files of size {split_size} ...") +- train_dir = tgt_dir / 'train' +- if not os.path.exists(train_dir): # make training dir +- os.makedirs(train_dir) +- cmd = f"split -C {split_size} -a 4 -d --additional-suffix .txt {tgt_tmp_shuffled} {train_dir}/{lang}-{dataset_name}-" +- result = subprocess.run(cmd, shell=True) +- if result.returncode != 0: +- raise RuntimeError("Failed to split files!") +- total = len(glob.glob(f'{train_dir}/*.txt')) ++ print("--> Pass 2/2: shuffling each bucket and writing final shards...") ++ shard_paths = [] ++ random.shuffle(bucket_paths) # randomize which bucket becomes shard 0000, 0001, etc. ++ shard_index = 0 ++ for bucket_path in tqdm(bucket_paths): ++ lines = read_bucket_lines(bucket_path, bucket_compression) ++ if not lines: ++ continue ++ random.shuffle(lines) ++ shard_path = os.path.join(train_dir, f"{lang}-{dataset_name}-{shard_index:04d}.txt") ++ with open(shard_path, "wt", encoding="utf-8", errors="surrogateescape") as fout: ++ fout.writelines(lines) ++ shard_paths.append(shard_path) ++ shard_index += 1 ++ ++ total = len(shard_paths) + print(f"--> {total} total files generated.") + if total < 3: + raise RuntimeError("Something went wrong! %d file(s) produced by shuffle and split, expected at least 3" % total) +@@ -142,21 +296,95 @@ def prepare_lm_data(src_dir, tgt_dir, lang, dataset_name, compress, split_size, + test_file = f"{tgt_dir}/test.txt" + if make_test_file: + print("--> Creating dev and test files...") +- shutil.move(f"{train_dir}/{lang}-{dataset_name}-0000.txt", dev_file) +- shutil.move(f"{train_dir}/{lang}-{dataset_name}-0001.txt", test_file) +- txt_files = [dev_file, test_file] + glob.glob(f'{train_dir}/*.txt') ++ shutil.move(shard_paths[0], dev_file) ++ shutil.move(shard_paths[1], test_file) ++ txt_files = [dev_file, test_file] + shard_paths[2:] + else: + print("--> Creating dev file...") +- shutil.move(f"{train_dir}/{lang}-{dataset_name}-0000.txt", dev_file) +- txt_files = [dev_file] + glob.glob(f'{train_dir}/*.txt') ++ shutil.move(shard_paths[0], dev_file) ++ txt_files = [dev_file] + shard_paths[1:] + + if compress: + print("--> Compressing files...") + for txt_file in tqdm(txt_files): +- subprocess.run(['xz', txt_file]) ++ compress_file_to_xz(txt_file) + + print("--> Cleaning up...") + print(f"--> All done for {lang}-{dataset_name}.\n") + ++ ++def scatter_into_buckets(input_files, bucket_paths, max_open_handles, bucket_compression): ++ """ ++ Pass 1: stream every input file exactly once and randomly assign each line to one bucket file. ++ ++ Bucket files are always written as plain uncompressed text during this pass (append mode is ++ simple and well-supported for plain files; incrementally appending to an .xz stream is not a ++ well-defined operation, since xz framing isn't designed for that). If bucket_compression is ++ requested, buckets are compressed in a separate pass *after* all scattering is done, when each ++ bucket is finished and will only ever be read once in pass 2 -- at that point compressing it is ++ just a single whole-file xz pass per bucket, no different in spirit from the final shard ++ compression already done elsewhere in this script. ++ ++ To bound simultaneously open file descriptors at max_open_handles, we keep in-memory line ++ buffers for every bucket, but only actually hold open OS file handles for up to ++ max_open_handles buckets at a time ("hot" buckets). When a buffer for a "cold" (not currently ++ open) bucket needs to flush, we open it briefly in append mode, write, and close -- this keeps ++ total *concurrently open* handles bounded by max_open_handles + 1 (the source file being read) ++ while still only reading every source file once. ++ ++ Returns the total decompressed byte count actually scattered, measured as a side effect of this ++ pass (avoids a separate, redundant decompression pass just to learn the true input size). ++ """ ++ num_buckets = len(bucket_paths) ++ buffers = [[] for _ in range(num_buckets)] ++ total_bytes = 0 ++ ++ # The first max_open_handles buckets stay open for the whole pass; the rest are flushed via ++ # brief open-append-close, which is cheap relative to the cost of re-reading source data. ++ num_hot = min(max_open_handles, num_buckets) ++ hot_handles = [open(bucket_paths[i], "wt", encoding="utf-8", errors="surrogateescape") ++ for i in range(num_hot)] ++ ++ def flush(bucket_idx): ++ if not buffers[bucket_idx]: ++ return ++ if bucket_idx < num_hot: ++ hot_handles[bucket_idx].writelines(buffers[bucket_idx]) ++ else: ++ with open(bucket_paths[bucket_idx], "at", encoding="utf-8", errors="surrogateescape") as fout: ++ fout.writelines(buffers[bucket_idx]) ++ buffers[bucket_idx] = [] ++ ++ try: ++ for src_fn in tqdm(input_files, desc="scattering source files"): ++ with open_text_read(src_fn) as fin: ++ for line in fin: ++ total_bytes += len(line.encode("utf-8", errors="surrogateescape")) ++ bucket_idx = random.randrange(num_buckets) ++ buffers[bucket_idx].append(line) ++ if len(buffers[bucket_idx]) >= IO_CHUNK_LINES: ++ flush(bucket_idx) ++ for bucket_idx in range(num_buckets): ++ flush(bucket_idx) ++ finally: ++ for fh in hot_handles: ++ fh.close() ++ ++ if bucket_compression: ++ print("--> Compressing buckets...") ++ for path in tqdm(bucket_paths): ++ with open(path, "rt", encoding="utf-8", errors="surrogateescape") as fin, \ ++ lzma.open(path + ".xz", "wt", encoding="utf-8", errors="surrogateescape") as fout: ++ shutil.copyfileobj(fin, fout) ++ os.remove(path) ++ ++ return total_bytes ++ ++ ++def read_bucket_lines(bucket_path, bucket_compression): ++ with open_bucket_read(bucket_path, bucket_compression) as fin: ++ return fin.readlines() ++ ++ + if __name__ == "__main__": + main() +-- +2.54.0 + diff --git a/pkgs/development/python-modules/stanza/default.nix b/pkgs/development/python-modules/stanza/default.nix index 8ba3b9f599c6..9839f03c92d9 100644 --- a/pkgs/development/python-modules/stanza/default.nix +++ b/pkgs/development/python-modules/stanza/default.nix @@ -29,6 +29,19 @@ buildPythonPackage (finalAttrs: { tag = "v${finalAttrs.version}"; hash = "sha256-hUI8sZDwBK8ZRS9asyDiTqpoIGnGbHeH/Q9i/gasut0="; }; + patches = [ + ## Backports from 1.14.0 + # Rebased because they don't apply directly. + # https://github.com/stanfordnlp/stanza/security/advisories/GHSA-c9h2-qmqw-qf6h + # https://github.com/stanfordnlp/stanza/commit/4ca4b154af05d71a66586ea9d77b8782e19f3c67 + ./GHSA-2fwf-f686-7p34.patch + # https://github.com/stanfordnlp/stanza/security/advisories/GHSA-487q-m798-cp85 + # https://github.com/stanfordnlp/stanza/commit/031ab2e4a350eec3c7e8abc89f37617c4669b361 + ./GHSA-487q-m798-cp85.patch + # https://github.com/stanfordnlp/stanza/security/advisories/GHSA-2fwf-f686-7p34 + # https://github.com/stanfordnlp/stanza/commit/a7085e75abdf35f277754dda472bba4e6819bcbb + ./GHSA-c9h2-qmqw-qf6h.patch + ]; build-system = [ setuptools ]; From de36f40b00bb740078e1ad658e0bdee34ee34557 Mon Sep 17 00:00:00 2001 From: SchweGELBin Date: Thu, 16 Jul 2026 15:34:36 +0200 Subject: [PATCH 09/49] libsignal-ffi: 0.94.4 -> 0.97.2 (cherry picked from commit d89a0f65d02ca6eb9fc7dee6f54ad15d23ded9aa) --- pkgs/by-name/li/libsignal-ffi/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/libsignal-ffi/package.nix b/pkgs/by-name/li/libsignal-ffi/package.nix index c221dd578486..d5f380fb9654 100644 --- a/pkgs/by-name/li/libsignal-ffi/package.nix +++ b/pkgs/by-name/li/libsignal-ffi/package.nix @@ -13,14 +13,14 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "libsignal-ffi"; # must match the version used in mautrix-signal # see https://github.com/mautrix/signal/issues/401 - version = "0.94.4"; + version = "0.97.2"; src = fetchFromGitHub { fetchSubmodules = true; owner = "signalapp"; repo = "libsignal"; tag = "v${finalAttrs.version}"; - hash = "sha256-Uh/j8cXUWgWgSo9UBfYOFuC8i+2YdMwGHcXf55PkGgU="; + hash = "sha256-p9NIt+n7MTsYWAFS+FOuSGMJUZi8rBlTb6ATgVJ+uU8="; }; postPatch = @@ -46,7 +46,7 @@ rustPlatform.buildRustPackage (finalAttrs: { NIX_LDFLAGS = if stdenv.hostPlatform.isDarwin then "-lc++" else "-lstdc++"; }; - cargoHash = "sha256-st6zTKvxSsyMce22E8nFsJMGjQkk9sEAzSCmyZP8x20="; + cargoHash = "sha256-JtNGubDMrUINCCiawrAW63L1trcBCAIibFpojK8mzhc="; cargoBuildFlags = [ "-p" From 89acd0d6bc9ab54e12e550bec9967ac7da9f8c22 Mon Sep 17 00:00:00 2001 From: SchweGELBin Date: Thu, 16 Jul 2026 15:39:17 +0200 Subject: [PATCH 10/49] mautrix-signal: 26.06 -> 26.07 (cherry picked from commit b79b555f448a2d02f9dfec7185bd24aff4d453fe) --- pkgs/by-name/ma/mautrix-signal/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/ma/mautrix-signal/package.nix b/pkgs/by-name/ma/mautrix-signal/package.nix index a5aa11b57755..27d3f2040855 100644 --- a/pkgs/by-name/ma/mautrix-signal/package.nix +++ b/pkgs/by-name/ma/mautrix-signal/package.nix @@ -20,14 +20,14 @@ let in buildGoModule rec { pname = "mautrix-signal"; - version = "26.06"; - tag = "v0.2606.0"; + version = "26.07"; + tag = "v0.2607.0"; src = fetchFromGitHub { owner = "mautrix"; repo = "signal"; inherit tag; - hash = "sha256-DSOf6kyNcsknwKM77vUQs6pWX8hMo4mU9dOGai62QR0="; + hash = "sha256-l6IIL2bClC6t5+P0/AkFIjkD/eDpQnnmA8x4i5ROaY4="; }; buildInputs = @@ -46,7 +46,7 @@ buildGoModule rec { CGO_LDFLAGS = toString [ cppStdLib ]; }; - vendorHash = "sha256-e9Et97QEn12kkiqrQTaDtwECLhwvxwDUF6IcWoL/+Mg="; + vendorHash = "sha256-0ifGza94s4+ED5OrlrqoDKIDZIYJWJhB2q3LJRpKiJs="; ldflags = [ "-X" From 423785494573380658a5fbf17575bcdfc4480131 Mon Sep 17 00:00:00 2001 From: SchweGELBin Date: Thu, 16 Jul 2026 15:32:32 +0200 Subject: [PATCH 11/49] mautrix-whatsapp: 26.06 -> 26.07 (cherry picked from commit a060b9d5b3e2f699fd8486cc4e90da09a3493ff5) --- pkgs/by-name/ma/mautrix-whatsapp/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/ma/mautrix-whatsapp/package.nix b/pkgs/by-name/ma/mautrix-whatsapp/package.nix index 78f8d40bb024..237445a9e328 100644 --- a/pkgs/by-name/ma/mautrix-whatsapp/package.nix +++ b/pkgs/by-name/ma/mautrix-whatsapp/package.nix @@ -14,20 +14,20 @@ buildGoModule rec { pname = "mautrix-whatsapp"; - version = "26.06"; - tag = "v0.2606.0"; + version = "26.07"; + tag = "v0.2607.0"; src = fetchFromGitHub { owner = "mautrix"; repo = "whatsapp"; inherit tag; - hash = "sha256-xxUsFrBX6wwANKECwL6ITDkc88XpCyGpWDPjGQlH3fI="; + hash = "sha256-cl3nJY9ui9J9fE9T1hBUV/o8lH0usrsUcpj9OwXxgtY="; }; buildInputs = lib.optional (!withGoolm) olm; tags = lib.optional withGoolm "goolm"; - vendorHash = "sha256-H8dSwOPVJ3TofAJDupYhX6/Vm5qshhFXaMtUDWM/0mw="; + vendorHash = "sha256-fVs5su6UkjvQEkoWJH6WL1FCZNdwj0jzrjfpbWOHWDU="; ldflags = [ "-s" From fe05ef35c2bc91b83168053cdd68384599f2aa19 Mon Sep 17 00:00:00 2001 From: Bouke van der Bijl Date: Tue, 21 Jul 2026 19:24:05 +0200 Subject: [PATCH 12/49] clickhouse: preserve VERSION_REVISION from the source tree The preConfigure that regenerates cmake/autogenerated_versions.txt hardcoded SET(VERSION_REVISION 0), so nixpkgs-built servers report 0 from the revision(), which e.g. clickhouse-go reads. (cherry picked from commit c00f8bc01c332ad7f5d4a6eca53d117938da93d1) --- pkgs/by-name/cl/clickhouse/generic.nix | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/cl/clickhouse/generic.nix b/pkgs/by-name/cl/clickhouse/generic.nix index 4b9b9cfaded9..4616222f3363 100644 --- a/pkgs/by-name/cl/clickhouse/generic.nix +++ b/pkgs/by-name/cl/clickhouse/generic.nix @@ -165,8 +165,17 @@ llvmStdenv.mkDerivation (finalAttrs: { gitHash = rev; in '' - cat <<'EOF' > cmake/autogenerated_versions.txt - SET(VERSION_REVISION 0) + # Preserve VERSION_REVISION from the source tree, like ClickHouse CI + # does. It identifies the server release line to clients (exposed via + # the revision() SQL function) + versionRevision=$(sed -n 's/^SET(VERSION_REVISION \([0-9]\{1,\}\))$/\1/p' cmake/autogenerated_versions.txt) + if [[ -z "$versionRevision" ]]; then + echo "Could not extract VERSION_REVISION from cmake/autogenerated_versions.txt" >&2 + exit 1 + fi + + cat < cmake/autogenerated_versions.txt + SET(VERSION_REVISION $versionRevision) SET(VERSION_MAJOR ${major}) SET(VERSION_MINOR ${minor}) SET(VERSION_PATCH ${patch}) From 4e57c4cd018cc6eb95bbbc8fc8b9e6eb6b69531b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Wed, 22 Jul 2026 11:57:59 +0200 Subject: [PATCH 13/49] knot-resolver_6: 6.4.0 -> 6.4.1 (security!) https://gitlab.nic.cz/knot/knot-resolver/-/releases/v6.4.1 (cherry picked from commit 59d6f14e97a7f43658b74112bc18976f4e91aa6b) --- pkgs/by-name/kn/knot-resolver_6/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/kn/knot-resolver_6/package.nix b/pkgs/by-name/kn/knot-resolver_6/package.nix index f8058a3ad70e..715d78394d0d 100644 --- a/pkgs/by-name/kn/knot-resolver_6/package.nix +++ b/pkgs/by-name/kn/knot-resolver_6/package.nix @@ -36,11 +36,11 @@ let # TODO: we could cut the `let` short here, but it would de-indent everything. unwrapped = stdenv.mkDerivation (finalAttrs: { pname = "knot-resolver_6"; - version = "6.4.0"; + version = "6.4.1"; src = fetchurl { url = "https://secure.nic.cz/files/knot-resolver/knot-resolver-${finalAttrs.version}.tar.xz"; - hash = "sha256-T0v+CfjXOw7n1nDdHJD18qwOkGD5sUeDVfJvJzdGrIA="; + hash = "sha256-GqTClyHAm86amfPVZXIjEQNj1ms1ytSYm5Wyr9qTeag="; }; outputs = [ From 97fbb30fdb5ae6afea48b88018ae154a29a57eca Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Wed, 22 Jul 2026 12:01:56 +0200 Subject: [PATCH 14/49] knot-resolver_5: 5.7.6 -> 5.7.7 (security!) https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.7 (cherry picked from commit 0c2857e469eadde05ad0c009cd89614b19cf6e2d) --- pkgs/by-name/kn/knot-resolver_5/package.nix | 14 ++------------ 1 file changed, 2 insertions(+), 12 deletions(-) diff --git a/pkgs/by-name/kn/knot-resolver_5/package.nix b/pkgs/by-name/kn/knot-resolver_5/package.nix index 1bc541bb9498..af61e7ac71cd 100644 --- a/pkgs/by-name/kn/knot-resolver_5/package.nix +++ b/pkgs/by-name/kn/knot-resolver_5/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchurl, - fetchpatch, # native deps. runCommand, pkg-config, @@ -36,11 +35,11 @@ let unwrapped = stdenv.mkDerivation (finalAttrs: { pname = "knot-resolver_5"; - version = "5.7.6"; + version = "5.7.7"; src = fetchurl { url = "https://secure.nic.cz/files/knot-resolver/knot-resolver-${finalAttrs.version}.tar.xz"; - sha256 = "500ccd3a560300e547b8dc5aaff322f7c8e2e7d6f0d7ef5f36e59cb60504d674"; + sha256 = "481d2a6eb8690023895d389601e56fffbaeba3cc18cc1de5a5f177df9d0f9530"; }; outputs = [ @@ -48,15 +47,6 @@ let "dev" ]; - patches = [ - (fetchpatch { - # https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1772 - url = "https://gitlab.nic.cz/knot/knot-resolver/-/commit/f4eaf8e69cc9839f68b613d0be10103e05c57fe9.patch"; - hash = "sha256-u/YQ85Jb5OxV8G3HeVPQUw0cmA+TLIDPze9mreqJGL4="; - excludes = [ "daemon/ratelimiting.test/tests.inc.c" ]; - }) - ]; - # Path fixups for the NixOS service. postPatch = '' patch meson.build < Date: Wed, 22 Jul 2026 13:29:17 +0200 Subject: [PATCH 15/49] gitlab: 18.11.6 -> 18.11.7 https://gitlab.com/gitlab-org/gitlab/-/blob/v18.11.7-ee/CHANGELOG.md (cherry picked from commit ec5836368941c7fc54664c734d5a66688540fca3) --- pkgs/by-name/gi/gitaly/package.nix | 4 ++-- pkgs/by-name/gi/gitlab-pages/package.nix | 4 ++-- pkgs/by-name/gi/gitlab/data.json | 14 +++++++------- .../by-name/gi/gitlab/gitlab-workhorse/default.nix | 2 +- 4 files changed, 12 insertions(+), 12 deletions(-) diff --git a/pkgs/by-name/gi/gitaly/package.nix b/pkgs/by-name/gi/gitaly/package.nix index ceb96f569302..25348bec2cfb 100644 --- a/pkgs/by-name/gi/gitaly/package.nix +++ b/pkgs/by-name/gi/gitaly/package.nix @@ -7,7 +7,7 @@ }: let - version = "18.11.6"; + version = "18.11.7"; package_version = "v${lib.versions.major version}"; gitaly_package = "gitlab.com/gitlab-org/gitaly/${package_version}"; @@ -21,7 +21,7 @@ let owner = "gitlab-org"; repo = "gitaly"; rev = "v${version}"; - hash = "sha256-fsr8ttV2q2iedTA5yn4iHry92Mgu775K1GW3JBz5N1U="; + hash = "sha256-CupoX+Jv/4JDn50T7KF4+k9dd2bL+1zWd+3BsFIKOM8="; }; vendorHash = "sha256-/RJnCcmUoqGy08MSGEVM/taV1qZK65kiZw19n6S3ZQ0="; diff --git a/pkgs/by-name/gi/gitlab-pages/package.nix b/pkgs/by-name/gi/gitlab-pages/package.nix index 0c6ae216ff5c..3ca2ef8a06e4 100644 --- a/pkgs/by-name/gi/gitlab-pages/package.nix +++ b/pkgs/by-name/gi/gitlab-pages/package.nix @@ -6,14 +6,14 @@ buildGoModule (finalAttrs: { pname = "gitlab-pages"; - version = "18.11.6"; + version = "18.11.7"; # nixpkgs-update: no auto update src = fetchFromGitLab { owner = "gitlab-org"; repo = "gitlab-pages"; rev = "v${finalAttrs.version}"; - hash = "sha256-D/AlIXbcgvPyP2TX/lXVYlnG2HXKZlxOhqRTfTXsaew="; + hash = "sha256-AW/zzQiiGz8JBw1c5JAwo2boWKoeD1wx0dUA4nOyARA="; }; vendorHash = "sha256-PUW4cgAiM1GTtvja894OZ4pe0SWChf5JsL4/fkns2kI="; diff --git a/pkgs/by-name/gi/gitlab/data.json b/pkgs/by-name/gi/gitlab/data.json index 2f8606e66e98..9001efd1dd54 100644 --- a/pkgs/by-name/gi/gitlab/data.json +++ b/pkgs/by-name/gi/gitlab/data.json @@ -1,17 +1,17 @@ { - "version": "18.11.6", - "repo_hash": "sha256-bdnBX6M4BtuA03CP/N0teKnuey3V9qHseBoxTIGXE5Q=", + "version": "18.11.7", + "repo_hash": "sha256-LSrdAz4bt5h3Z2V4vlazH5hKoq3LNvoRz02AyUb4Ka4=", "yarn_hash": "sha256-og09R28lwYvDk4pe7z1dRMaanYiTsUSx+SUKoWc53do=", "frontend_islands_yarn_hash": "sha256-EvGQin+5DqqIgM36jlVkVI49WcJzVvceYnkSS9ybfcY=", "owner": "gitlab-org", "repo": "gitlab", - "rev": "v18.11.6-ee", + "rev": "v18.11.7-ee", "passthru": { - "GITALY_SERVER_VERSION": "18.11.6", - "GITLAB_KAS_VERSION": "18.11.6", - "GITLAB_PAGES_VERSION": "18.11.6", + "GITALY_SERVER_VERSION": "18.11.7", + "GITLAB_KAS_VERSION": "18.11.7", + "GITLAB_PAGES_VERSION": "18.11.7", "GITLAB_SHELL_VERSION": "14.50.0", "GITLAB_ELASTICSEARCH_INDEXER_VERSION": "5.14.7", - "GITLAB_WORKHORSE_VERSION": "18.11.6" + "GITLAB_WORKHORSE_VERSION": "18.11.7" } } diff --git a/pkgs/by-name/gi/gitlab/gitlab-workhorse/default.nix b/pkgs/by-name/gi/gitlab/gitlab-workhorse/default.nix index 1e60673586d2..6aa8bbbc513a 100644 --- a/pkgs/by-name/gi/gitlab/gitlab-workhorse/default.nix +++ b/pkgs/by-name/gi/gitlab/gitlab-workhorse/default.nix @@ -10,7 +10,7 @@ in buildGoModule (finalAttrs: { pname = "gitlab-workhorse"; - version = "18.11.6"; + version = "18.11.7"; # nixpkgs-update: no auto update src = fetchFromGitLab { From eca4de2ddc3a6c8f64280f15970d38a884ff43d8 Mon Sep 17 00:00:00 2001 From: dmkhitaryan Date: Wed, 22 Jul 2026 19:34:26 +0400 Subject: [PATCH 16/49] flameshot: octou symlink attack fix Not-cherry-picked-because: master already has Flameshot 14, while release-26.05 still has 13.3.0 and requires a targeted patch. --- pkgs/by-name/fl/flameshot/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/fl/flameshot/package.nix b/pkgs/by-name/fl/flameshot/package.nix index 7ae09fd008df..a3366d869aa4 100644 --- a/pkgs/by-name/fl/flameshot/package.nix +++ b/pkgs/by-name/fl/flameshot/package.nix @@ -12,6 +12,7 @@ nix-update-script, enableWlrSupport ? !stdenv.hostPlatform.isDarwin, enableMonochromeIcon ? false, + fetchpatch, wrapGAppsHook3, }: @@ -48,6 +49,11 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./load-missing-deps.patch ./macos-build.patch + (fetchpatch { + name = "CVE-2026-62294.patch"; + url = "https://github.com/flameshot-org/flameshot/commit/936716b8d8b7052be461c3d5e2f88492b6eb3b96.patch"; + hash = "sha256-bhJ6fQJXkRoUME8juj6/8bQAO5V50tJfV0wcJfIoPg0="; + }) ]; nativeBuildInputs = [ From 895060e56dbd6ebed90528a5953e9491953b20c9 Mon Sep 17 00:00:00 2001 From: Johan Thomsen Date: Thu, 16 Jul 2026 09:14:48 +0200 Subject: [PATCH 17/49] coredns: 1.14.3 -> 1.14.6 (cherry picked from commit d8a4aa50cfdcf31bc6b5e62bb20c094805cd1249) --- nixos/tests/coredns.nix | 2 +- pkgs/by-name/co/coredns/package.nix | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/nixos/tests/coredns.nix b/nixos/tests/coredns.nix index 6ee6572d57c8..cb485ae34b5c 100644 --- a/nixos/tests/coredns.nix +++ b/nixos/tests/coredns.nix @@ -28,7 +28,7 @@ position = "start-of-file"; } ]; - vendorHash = "sha256-66WNU+t/frHfbxexYdiXzgXKLxPyLnN6JuKnlG/kSQY="; + vendorHash = "sha256-cvgq/Djlxjiu0C5QjaxrlEeG7O2mB6mGAwV7/reYlpY="; }; }; }; diff --git a/pkgs/by-name/co/coredns/package.nix b/pkgs/by-name/co/coredns/package.nix index 189ab608471b..444657a1a513 100644 --- a/pkgs/by-name/co/coredns/package.nix +++ b/pkgs/by-name/co/coredns/package.nix @@ -6,7 +6,7 @@ installShellFiles, nixosTests, externalPlugins ? [ ], - vendorHash ? "sha256-9LLTgIjOOMvYx4nhy+6X9bEBvqlKeTx//39q+YWXeHw=", + vendorHash ? "sha256-K7cHC6IVawJmlCLR45SKEowXw7SfURIePHzj1LvKS84=", }: let @@ -14,13 +14,13 @@ let in buildGoModule (finalAttrs: { pname = "coredns"; - version = "1.14.3"; + version = "1.14.6"; src = fetchFromGitHub { owner = "coredns"; repo = "coredns"; tag = "v${finalAttrs.version}"; - hash = "sha256-Uk4oWsUxaGdLQzX5JywYzi7pmQHGo06uQdLeOkP4U/s"; + hash = "sha256-3BKXmrsSsDWFl6MT6c5Q8wcQiApO1vG0KeUtJLm89jU="; }; inherit vendorHash; From 69dacb3c98ce84499c4ccea05164a3b66049ef16 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 30 Jun 2026 20:51:25 +0000 Subject: [PATCH 18/49] framework-tool-tui: 0.8.3 -> 0.8.4 (cherry picked from commit 0da802590972cc2824223ec8b7f1c3923c69a642) --- pkgs/by-name/fr/framework-tool-tui/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/fr/framework-tool-tui/package.nix b/pkgs/by-name/fr/framework-tool-tui/package.nix index 5eaadae52a7a..0c9c957e1d8b 100644 --- a/pkgs/by-name/fr/framework-tool-tui/package.nix +++ b/pkgs/by-name/fr/framework-tool-tui/package.nix @@ -7,16 +7,16 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "framework-tool-tui"; - version = "0.8.3"; + version = "0.8.4"; src = fetchFromGitHub { owner = "grouzen"; repo = "framework-tool-tui"; tag = "v${finalAttrs.version}"; - hash = "sha256-LNGfjDRJ6sGLBfnANzrLWUFB0ZPDVPLaw7powdsC43I="; + hash = "sha256-IZq2amZYQJxt9ojZfjgrj303vdh+NAKg6fmd2TZa4q8="; }; - cargoHash = "sha256-ERyVdowVf7bFyupAuCKCgih9M0K/ThKjBJ2TEjbPqD4="; + cargoHash = "sha256-jd6M7tq4BTAsETimFsSmX1KLz7G+wTloBFmq4V8svRg="; nativeBuildInputs = [ pkg-config ]; buildInputs = [ udev ]; From a7f19640365bf8f96db3bdfbcab83724355ad18c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 11 Jul 2026 00:37:30 +0000 Subject: [PATCH 19/49] mapserver: 8.6.4 -> 8.6.5 (cherry picked from commit 481d8cbe4196b790f5fb78d456908c43b30ad03e) --- pkgs/by-name/ma/mapserver/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ma/mapserver/package.nix b/pkgs/by-name/ma/mapserver/package.nix index b075c21c6e20..1faa71910363 100644 --- a/pkgs/by-name/ma/mapserver/package.nix +++ b/pkgs/by-name/ma/mapserver/package.nix @@ -30,13 +30,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "mapserver"; - version = "8.6.4"; + version = "8.6.5"; src = fetchFromGitHub { owner = "MapServer"; repo = "MapServer"; rev = "rel-${lib.replaceStrings [ "." ] [ "-" ] finalAttrs.version}"; - hash = "sha256-kqCP0QZ8gNqS54B8nL8M9Wr9WyMQnORCs42O1eiMtRw="; + hash = "sha256-HEQ+bBb6cXXqR+4Yw5H+3xwQMQvlv0LjlBRT0baFeZQ="; }; nativeBuildInputs = [ From ff79292932115ff9d35bd50b5fe88e8e65f3222f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 30 Jun 2026 19:26:12 +0000 Subject: [PATCH 20/49] protozero: 1.8.1 -> 1.8.2 (cherry picked from commit 801431c6deea492dd608d5b28522add2d13fe14f) --- pkgs/by-name/pr/protozero/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pr/protozero/package.nix b/pkgs/by-name/pr/protozero/package.nix index 9fa59741a663..ce4d0a0af84a 100644 --- a/pkgs/by-name/pr/protozero/package.nix +++ b/pkgs/by-name/pr/protozero/package.nix @@ -7,13 +7,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "protozero"; - version = "1.8.1"; + version = "1.8.2"; src = fetchFromGitHub { owner = "mapbox"; repo = "protozero"; tag = "v${finalAttrs.version}"; - hash = "sha256-69GEAz6wSGMGozsWS9xmoTgyH8mTuDM9mUTCXfVI6f8="; + hash = "sha256-pqRlSrCPBybKzKfXClGEIa8Pd1vS5vTpjIDhmz5UhYE="; }; nativeBuildInputs = [ cmake ]; From 49c3f733f94cd70227e70666520e4badd20fa278 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Fri, 26 Jun 2026 15:04:19 +0200 Subject: [PATCH 21/49] nixos/resolved: apply transformations to keys within resolved section Because all options are below the [Resolve] section, and we nest them as such below `settings.Resolve` we need to apply the transformations one level down for it to match the relevant keys. (cherry picked from commit 66353ca989dd68b3070f8932c048860e8354bc01) --- nixos/modules/system/boot/resolved.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/nixos/modules/system/boot/resolved.nix b/nixos/modules/system/boot/resolved.nix index da2b57285a76..78863eb82b4d 100644 --- a/nixos/modules/system/boot/resolved.nix +++ b/nixos/modules/system/boot/resolved.nix @@ -30,9 +30,8 @@ let dnsmasqResolve = config.services.dnsmasq.enable && config.services.dnsmasq.resolveLocalQueries; - transformSettings = - settings: - lib.mapAttrs ( + transformSettings = settings: { + Resolve = lib.mapAttrs ( key: value: # concat lists for options that should result in space-separated values if @@ -46,7 +45,8 @@ let concatStringsSep " " value else value - ) settings; + ) settings.Resolve; + }; resolvedConf = settingsToSections (transformSettings cfg.settings); in From 4c8175371bbd427f1ec08fc96faf752f76155b15 Mon Sep 17 00:00:00 2001 From: Zernix2077 <110056737+zernix2077@users.noreply.github.com> Date: Wed, 22 Jul 2026 19:28:22 +0300 Subject: [PATCH 22/49] bat: fix escaping of shell settings values (cherry picked from commit adc88786a16772b7a36e1c057222eee8b1845cee) --- nixos/modules/programs/bat.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/nixos/modules/programs/bat.nix b/nixos/modules/programs/bat.nix index cbe6ac48e909..3ebc0424a3fd 100644 --- a/nixos/modules/programs/bat.nix +++ b/nixos/modules/programs/bat.nix @@ -8,6 +8,7 @@ let inherit (builtins) isList; inherit (lib) concatMapStrings + escapeShellArg literalExpression maintainers mapAttrs' @@ -34,7 +35,7 @@ let else if isBool value then boolToString value else - toString value; + escapeShellArg (toString value); in { options.programs.bat = { From 6d66618a0379516120c2dcfad49bd8f3efa00b17 Mon Sep 17 00:00:00 2001 From: xqtc Date: Tue, 21 Jul 2026 17:31:07 +0200 Subject: [PATCH 23/49] maintainers: add xqtc161 (cherry picked from commit 042f5c0583a87d89462e651b19028c2a652b2d2d) --- maintainers/maintainer-list.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 555483af5c28..d204996c8027 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -30181,6 +30181,11 @@ githubId = 106241330; name = "Success Kingsley"; }; + xqtc161 = { + github = "xqtc161"; + githubId = 65857432; + name = "tila"; + }; xrelkd = { github = "xrelkd"; githubId = 46590321; From 5cf22903489f2cda3e0c6ee452d2fa045fa28ff2 Mon Sep 17 00:00:00 2001 From: xqtc Date: Tue, 21 Jul 2026 17:31:21 +0200 Subject: [PATCH 24/49] ziglint: init at 0.5.3 (cherry picked from commit 6a1273d665a1e94eb0e3fbdc87fd5b2895327375) --- pkgs/by-name/zi/ziglint/package.nix | 48 +++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 pkgs/by-name/zi/ziglint/package.nix diff --git a/pkgs/by-name/zi/ziglint/package.nix b/pkgs/by-name/zi/ziglint/package.nix new file mode 100644 index 000000000000..36de1a77f914 --- /dev/null +++ b/pkgs/by-name/zi/ziglint/package.nix @@ -0,0 +1,48 @@ +{ + lib, + stdenv, + fetchFromGitHub, + zig_0_16, + versionCheckHook, +}: + +let + zig = zig_0_16; +in +stdenv.mkDerivation (finalAttrs: { + pname = "ziglint"; + version = "0.5.3"; + + src = fetchFromGitHub { + owner = "rockorager"; + repo = "ziglint"; + tag = "v${finalAttrs.version}"; + hash = "sha256-kLcUIFMDJHuCA0rn3l5a3h/E6TUwNWA5mWRADCDB1cw="; + }; + + postPatch = '' + substituteInPlace build.zig \ + --replace-fail "getVersion(b)" '"${finalAttrs.version}"' + ''; + + nativeBuildInputs = [ zig.hook ]; + + strictDeps = true; + + __structuredAttrs = true; + + doCheck = true; + + doInstallCheck = true; + nativeInstallCheckInputs = [ versionCheckHook ]; + + meta = { + homepage = "https://github.com/rockorager/ziglint"; + description = "Linter for Zig source code"; + changelog = "https://github.com/rockorager/ziglint/releases/tag/v${finalAttrs.version}"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ xqtc161 ]; + mainProgram = "ziglint"; + inherit (zig.meta) platforms; + }; +}) From 02ebdf833907d9105f9a688a493eafce8a042ebf Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Wed, 22 Jul 2026 19:54:29 -0400 Subject: [PATCH 25/49] Revert "python3Packages.starsessions: 2.2.1 -> .2.2.0" This reverts commit 9ff5dc67fa0d641351a9f44cb9d8671f5d59781f. Since recently, additional python metadata validation was enabled, exposing this mistake as: packaging.version.InvalidVersion: Invalid version: '.2.2.0' (cherry picked from commit 00d4b4e573d53c2b57afeba67fa21ab70d2d5ee7) --- pkgs/development/python-modules/starsessions/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/starsessions/default.nix b/pkgs/development/python-modules/starsessions/default.nix index b18044fd19d2..9fbd1de35674 100644 --- a/pkgs/development/python-modules/starsessions/default.nix +++ b/pkgs/development/python-modules/starsessions/default.nix @@ -14,14 +14,14 @@ buildPythonPackage rec { pname = "starsessions"; - version = ".2.2.0"; + version = "2.2.1"; pyproject = true; src = fetchFromGitHub { owner = "alex-oleshkevich"; repo = "starsessions"; tag = "v${version}"; - hash = "sha256-CR8eMyYyr+iFf2l1QE0N762LdkxemOayn/s++mBZRqA="; + hash = "sha256-JI044sn6LQI37PvSLdz2dooa3v5qdHmp6DZD0p7VzJU="; }; build-system = [ poetry-core ]; From ad34ce57400043da8565b79972f1e9dac7659ee9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 22 Jul 2026 00:11:54 +0000 Subject: [PATCH 26/49] javaPackages.compiler.openjdk25: 25.0.4+1 -> 25.0.4+7 (cherry picked from commit ce2f48f3909125197934826c5384368853f2ae8e) --- pkgs/development/compilers/openjdk/25/source.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/openjdk/25/source.json b/pkgs/development/compilers/openjdk/25/source.json index bbe61333afa1..f1c94058b6c4 100644 --- a/pkgs/development/compilers/openjdk/25/source.json +++ b/pkgs/development/compilers/openjdk/25/source.json @@ -1,6 +1,6 @@ { - "hash": "sha256-A5TWx/HDFlx46VAgPmkanwcZeBeSwtgGCD90mmUu4Vc=", + "hash": "sha256-/42TUyZnw8LVOuUnupVFBkqsT5IIeTw9/WNQ0eCfQRQ=", "owner": "openjdk", "repo": "jdk25u", - "rev": "refs/tags/jdk-25.0.4+1" + "rev": "refs/tags/jdk-25.0.4+7" } From e99b61017ebc0499eafdf6b8e203f7a89c68d72c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 22 Jul 2026 04:51:17 +0000 Subject: [PATCH 27/49] javaPackages.compiler.openjdk17: 17.0.20+2 -> 17.0.20+8 (cherry picked from commit 0e1aa5a74456fb4efb55cd98ca276df36e091471) --- pkgs/development/compilers/openjdk/17/source.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/openjdk/17/source.json b/pkgs/development/compilers/openjdk/17/source.json index 1de5e512d662..aaaa49a87972 100644 --- a/pkgs/development/compilers/openjdk/17/source.json +++ b/pkgs/development/compilers/openjdk/17/source.json @@ -1,6 +1,6 @@ { - "hash": "sha256-Szed0lCe3parouN7VjBrKY7FcocyIuA4umuDqurbM4Y=", + "hash": "sha256-0cmzR5KZY6q+ZhoF90HkiIqHJsEdMeLOt4bmV8ID5so=", "owner": "openjdk", "repo": "jdk17u", - "rev": "refs/tags/jdk-17.0.20+2" + "rev": "refs/tags/jdk-17.0.20+8" } From 2fa7bc1276395a0e82d8b9860ae6d576dfff8a17 Mon Sep 17 00:00:00 2001 From: Vincent Laporte Date: Fri, 17 Jul 2026 10:24:26 +0200 Subject: [PATCH 28/49] =?UTF-8?q?gecode:=206.2.0=20=E2=86=92=206.3.0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit (cherry picked from commit 1df300f0f37820d6f2e93ce56d43c1596db493e8) --- pkgs/by-name/ge/gecode/package.nix | 20 +++++--------------- 1 file changed, 5 insertions(+), 15 deletions(-) diff --git a/pkgs/by-name/ge/gecode/package.nix b/pkgs/by-name/ge/gecode/package.nix index d07198f78125..78fa99afcb21 100644 --- a/pkgs/by-name/ge/gecode/package.nix +++ b/pkgs/by-name/ge/gecode/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchFromGitHub, - fetchpatch, bison, flex, perl, @@ -12,26 +11,17 @@ enableGist ? true, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "gecode"; - version = "6.2.0"; + version = "6.3.0"; src = fetchFromGitHub { owner = "Gecode"; repo = "gecode"; - rev = "release-${version}"; - sha256 = "0b1cq0c810j1xr2x9y9996p894571sdxng5h74py17c6nr8c6dmk"; + tag = "release-${finalAttrs.version}"; + hash = "sha256-i1geBYMO+edZJekKe/zO+kkgd/S4jSiSZnDLfSRlXwc="; }; - patches = [ - # https://github.com/Gecode/gecode/pull/74 - (fetchpatch { - name = "fix-const-weights-clang.patch"; - url = "https://github.com/Gecode/gecode/commit/c810c96b1ce5d3692e93439f76c4fa7d3daf9fbb.patch"; - sha256 = "0270msm22q5g5sqbdh8kmrihlxnnxqrxszk9a49hdxd72736p4fc"; - }) - ]; - enableParallelBuilding = true; dontWrapQtApps = true; nativeBuildInputs = [ @@ -52,4 +42,4 @@ stdenv.mkDerivation rec { platforms = lib.platforms.all; maintainers = [ ]; }; -} +}) From 120495af75a24ddc35b6389cb4233dd2ae14a5e2 Mon Sep 17 00:00:00 2001 From: Vincent Laporte Date: Fri, 17 Jul 2026 10:33:03 +0200 Subject: [PATCH 29/49] minizinc: use default gecode (cherry picked from commit ad0d10ea6e0d786815ca17200ba56bdbce5656cf) --- pkgs/by-name/mi/minizinc/package.nix | 16 ---------------- 1 file changed, 16 deletions(-) diff --git a/pkgs/by-name/mi/minizinc/package.nix b/pkgs/by-name/mi/minizinc/package.nix index 4747ebe471fa..22ed68a2228d 100644 --- a/pkgs/by-name/mi/minizinc/package.nix +++ b/pkgs/by-name/mi/minizinc/package.nix @@ -13,22 +13,6 @@ zlib, }: -let - gecode_6_3_0 = gecode.overrideAttrs (_: { - version = "6.3.0"; - src = fetchFromGitHub { - owner = "gecode"; - repo = "gecode"; - rev = "f7f0d7c273d6844698f01cec8229ebe0b66a016a"; - hash = "sha256-skf2JEtNkRqEwfHb44WjDGedSygxVuqUixskTozi/5k="; - }; - patches = [ ]; - }); -in -let - gecode = gecode_6_3_0; -in - stdenv.mkDerivation (finalAttrs: { pname = "minizinc"; version = "2.9.7"; From 9fe0f498ed93d62029082ecc66327b3d6987243f Mon Sep 17 00:00:00 2001 From: Vincent Laporte Date: Fri, 17 Jul 2026 10:50:40 +0200 Subject: [PATCH 30/49] =?UTF-8?q?gecode:=206.3.0=20=E2=86=92=206.4.0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit (cherry picked from commit c79cf74bd25be6aa6e6fb4a31dfdddd1d4564a1e) --- pkgs/by-name/ge/gecode/package.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ge/gecode/package.nix b/pkgs/by-name/ge/gecode/package.nix index 78fa99afcb21..d325f2501a3f 100644 --- a/pkgs/by-name/ge/gecode/package.nix +++ b/pkgs/by-name/ge/gecode/package.nix @@ -3,6 +3,7 @@ stdenv, fetchFromGitHub, bison, + cmake, flex, perl, gmp, @@ -13,19 +14,20 @@ stdenv.mkDerivation (finalAttrs: { pname = "gecode"; - version = "6.3.0"; + version = "6.4.0"; src = fetchFromGitHub { owner = "Gecode"; repo = "gecode"; tag = "release-${finalAttrs.version}"; - hash = "sha256-i1geBYMO+edZJekKe/zO+kkgd/S4jSiSZnDLfSRlXwc="; + hash = "sha256-WhMN7QC+VQfvHUV1LLaW7I7fG++/fznh1ZDUY/Q8zD8="; }; enableParallelBuilding = true; dontWrapQtApps = true; nativeBuildInputs = [ bison + cmake flex ]; buildInputs = [ From 21c91a5c169a300e5373af3463274f2d7b7dbb69 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 23 Jul 2026 07:35:22 +0000 Subject: [PATCH 31/49] python3Packages.osmnx: 2.1.0 -> 2.1.1 (cherry picked from commit 47b388f4d31b0e068ebbcd2c829472cb47228cbc) --- pkgs/development/python-modules/osmnx/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/osmnx/default.nix b/pkgs/development/python-modules/osmnx/default.nix index b5660833f762..3c172224d708 100644 --- a/pkgs/development/python-modules/osmnx/default.nix +++ b/pkgs/development/python-modules/osmnx/default.nix @@ -20,14 +20,14 @@ buildPythonPackage rec { pname = "osmnx"; - version = "2.1.0"; + version = "2.1.1"; pyproject = true; src = fetchFromGitHub { owner = "gboeing"; repo = "osmnx"; tag = "v${version}"; - hash = "sha256-3uLgc6zptmXlPg93qtsWbqNxXiBD/SEnXBL/IM/1m2c="; + hash = "sha256-PX4Vhf3R9UGKMYp636+tJ5NV/oURd3Zzxfvj7LLCaPM="; }; build-system = [ uv-build ]; From 457670392bc69b63a7669e8f37547a1955a8755f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 21 Jul 2026 03:30:18 +0000 Subject: [PATCH 32/49] docker: 29.6.1 -> 29.6.2 (cherry picked from commit 519c17452599517e8cfa6f4e5c45729ccdbed961) --- pkgs/applications/virtualization/docker/default.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/applications/virtualization/docker/default.nix b/pkgs/applications/virtualization/docker/default.nix index c953bf906617..91be307654fe 100644 --- a/pkgs/applications/virtualization/docker/default.nix +++ b/pkgs/applications/virtualization/docker/default.nix @@ -420,18 +420,18 @@ in docker_29 = let - version = "29.6.1"; + version = "29.6.2"; in callPackage dockerGen { inherit version; cliRev = "v${version}"; - cliHash = "sha256-cpK2UMRP/WXHsehG9Sq5UJAjhMesmXTrhe00y4RMRZc="; + cliHash = "sha256-WpPSePMCfWAVxCkX1nZyI+sra/Vug009ZPmnVKDaX0I="; mobyRev = "docker-v${version}"; - mobyHash = "sha256-gv+mea9X5TYDWN3IBRpmw0+R2waGxCiubdatNTeUQZI="; + mobyHash = "sha256-zrvrZCRUuiZ2vixZNOUFeGmDehHzSI+FzDMzV1gMqMc="; runcRev = "v1.3.6"; runcHash = "sha256-cBMYZOElWHQ4OkF2NlYJSZrlW4833WD8CRJRkkXeKJc="; - containerdRev = "v2.2.5"; - containerdHash = "sha256-3ui+0AjEU6H4VHYwF3G85ggVMUdONCLJ5KfciFasmkk="; + containerdRev = "v2.2.6"; + containerdHash = "sha256-Ngo9x847cXFYPnj/0I+g7BeV7e1/5T2YXfA1zkIdiPg="; tiniRev = "369448a167e8b3da4ca5bca0b3307500c3371828"; tiniHash = "sha256-jCBNfoJAjmcTJBx08kHs+FmbaU82CbQcf0IVjd56Nuw="; }; From 3a4d5daa0c8ce7058fa2c9bac7f22e0019f8d15f Mon Sep 17 00:00:00 2001 From: Tyce Herrman Date: Wed, 8 Jul 2026 17:12:53 -0400 Subject: [PATCH 33/49] commitizen: 4.13.9 -> 4.16.4 Release: https://github.com/commitizen-tools/commitizen/releases/tag/v4.16.4 Refresh the uv_build postPatch match for upstream pyproject.toml. Add git to the wrapped runtime PATH because commitizen 4.16.4 now invokes git directly during config discovery, which is reached by cz version. Assisted-by: OpenAI Codex (GPT-5) (cherry picked from commit 7c284298731bffda8df711307f17218e0d5ee105) --- pkgs/by-name/co/commitizen/package.nix | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/co/commitizen/package.nix b/pkgs/by-name/co/commitizen/package.nix index 9bbdda3ad1bd..8eb4bf5fb525 100644 --- a/pkgs/by-name/co/commitizen/package.nix +++ b/pkgs/by-name/co/commitizen/package.nix @@ -12,19 +12,19 @@ python3Packages.buildPythonPackage rec { pname = "commitizen"; - version = "4.13.9"; + version = "4.16.4"; pyproject = true; src = fetchFromGitHub { owner = "commitizen-tools"; repo = "commitizen"; tag = "v${version}"; - hash = "sha256-bT154qRnZCf3StYs+acv4Be/SUCA5ovGjY/j2EDmUEc="; + hash = "sha256-lVc1Kdy/IWRa8uoPZfOSSa379bDDknE3dpm0U7DVv0s="; }; postPatch = '' substituteInPlace pyproject.toml \ - --replace-fail "uv_build >= 0.9.17, <0.10.0" "uv-build" + --replace-fail "uv_build >= 0.9.17, <0.12" "uv-build" ''; pythonRelaxDeps = [ @@ -54,6 +54,13 @@ python3Packages.buildPythonPackage rec { tomlkit ]; + makeWrapperArgs = [ + "--prefix" + "PATH" + ":" + (lib.makeBinPath [ gitMinimal ]) + ]; + nativeCheckInputs = [ gitMinimal versionCheckHook From 81c5bc7d1632c320bd7a861f8379d7ce25f4abaf Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 23 Jul 2026 09:47:20 +0000 Subject: [PATCH 34/49] rustywind: 0.25.2 -> 0.26.0 (cherry picked from commit 59e8a8cf215c3ef2db5220a46ad93ae7ea5bd733) --- pkgs/by-name/ru/rustywind/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ru/rustywind/package.nix b/pkgs/by-name/ru/rustywind/package.nix index a48ee1a7133a..5eec1a568907 100644 --- a/pkgs/by-name/ru/rustywind/package.nix +++ b/pkgs/by-name/ru/rustywind/package.nix @@ -8,16 +8,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "rustywind"; - version = "0.25.2"; + version = "0.26.0"; src = fetchFromGitHub { owner = "avencera"; repo = "rustywind"; tag = "v${finalAttrs.version}"; - hash = "sha256-PeYKBLTQ7/fmNuWtIQiqC47omrdGuIlB55OPxBQJQiM="; + hash = "sha256-uxgp8cwOswrhDLtx5ZAxsdy96/+UjYhzNKwvt0DBmhk="; }; - cargoHash = "sha256-76gC+nw/eV4j68O74XsJDaDFYAEdqZB9EzsRj5vdOvs="; + cargoHash = "sha256-W5dPMSkihxWryLEpQhqt9IpiwyAYSsIgQLbwjnXVjEk="; doInstallCheck = true; nativeInstallCheckInputs = [ versionCheckHook ]; From af336bf182c5e335e41a48acd1ddf3d7f905f0b4 Mon Sep 17 00:00:00 2001 From: Pol Dellaiera Date: Thu, 23 Jul 2026 07:57:29 +0200 Subject: [PATCH 35/49] markdown-code-runner: 0.5.1 -> 0.5.2 Diff: https://github.com/drupol/markdown-code-runner/compare/0.5.1...0.5.2 (cherry picked from commit 70136603749761f5ed9ad652202bd35ab0ecb74d) --- pkgs/by-name/ma/markdown-code-runner/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ma/markdown-code-runner/package.nix b/pkgs/by-name/ma/markdown-code-runner/package.nix index ea602fd676af..d734dcb5a4f7 100644 --- a/pkgs/by-name/ma/markdown-code-runner/package.nix +++ b/pkgs/by-name/ma/markdown-code-runner/package.nix @@ -8,16 +8,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "markdown-code-runner"; - version = "0.5.1"; + version = "0.5.2"; src = fetchFromGitHub { owner = "drupol"; repo = "markdown-code-runner"; tag = finalAttrs.version; - hash = "sha256-GcPMkwXwLyHoVljOpfnhmysDYIFXSyvNL5P3f6q/KJw="; + hash = "sha256-xToBnuWjjh1Zle6lcWdYWO9iDhSJh1cbOOEr9p0n1vU="; }; - cargoHash = "sha256-ul5cl6FDYkW02HGtQmLHkOsSaTIn2lCaTpKjCUzdcjM="; + cargoHash = "sha256-tGEXJMlrxIBCzWVgOfcDNHq2Zli0mJVaOMdmwP9GhCk="; dontUseCargoParallelTests = true; From 76f172ecbadb1baee0c88321c4f692becb221cbc Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 22 Jul 2026 08:54:42 +0200 Subject: [PATCH 36/49] matrix-authentication-service: 1.20.0 -> 1.21.0 ChangeLog: https://github.com/element-hq/matrix-authentication-service/releases/tag/v1.21.0 (cherry picked from commit 22f4db51c8a51348ecdc8d7fe443413f4a5c6678) --- pkgs/by-name/ma/matrix-authentication-service/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/ma/matrix-authentication-service/package.nix b/pkgs/by-name/ma/matrix-authentication-service/package.nix index 0d0a55b600af..571119cf272d 100644 --- a/pkgs/by-name/ma/matrix-authentication-service/package.nix +++ b/pkgs/by-name/ma/matrix-authentication-service/package.nix @@ -20,21 +20,21 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "matrix-authentication-service"; - version = "1.20.0"; + version = "1.21.0"; src = fetchFromGitHub { owner = "element-hq"; repo = "matrix-authentication-service"; tag = "v${finalAttrs.version}"; - hash = "sha256-0fvGhBxwXhSzWvNhflreEFoCBycM10vMkMf4sj95vfY="; + hash = "sha256-4z+u1IM2pclccv9+IH8IWjCodDxWZmffbqWPC726sIg="; }; - cargoHash = "sha256-3V50qNvg24WZvQ9z7IZJAnPXHTibZ6o3EzUoinLU6Gw="; + cargoHash = "sha256-HQU0zaK7rLJnTX5WVZrqNEaT5HfFLDzs+pHRxx5XTaA="; pnpmDeps = fetchPnpmDeps { inherit (finalAttrs) pname version src; fetcherVersion = 4; - hash = "sha256-j2A2VCKQPfoyrNDtazu8hzUHpS130Ju/Cy3yfu9tC5I="; + hash = "sha256-9a62WlBQW8lgXluMh+DM21CkFCqFYd7yUz220G1uTIY="; }; pnpmRoot = "frontend"; From 20c259d10d07268e1815231be36c4bd1e4e19788 Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Thu, 23 Jul 2026 09:40:56 +0200 Subject: [PATCH 37/49] perlPackages.NetDNS: 1.48 -> 1.56 https://metacpan.org/release/NLNETLABS/Net-DNS-1.56/changes Addresses CVE-2026-64193 and CVE-2026-64194. Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) (cherry picked from commit 9d44326e4e2b0ff267d6f052457956e455c95dea) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 3ceb0605694b..8f811f1f0c57 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -25491,10 +25491,10 @@ with self; NetDNS = buildPerlPackage { pname = "Net-DNS"; - version = "1.48"; + version = "1.56"; src = fetchurl { - url = "mirror://cpan/authors/id/N/NL/NLNETLABS/Net-DNS-1.48.tar.gz"; - hash = "sha256-5V8+caMcK4VgJL9QYbEWCwP4edgBNUFPONgiBHaUR1M="; + url = "mirror://cpan/authors/id/N/NL/NLNETLABS/Net-DNS-1.56.tar.gz"; + hash = "sha256-WTDjn3aJWzgMfKEfwINS0VrXHEH+hMEt+2oyLRf2aUY="; }; propagatedBuildInputs = [ DigestHMAC ]; makeMakerFlags = [ "--noonline-tests" ]; From 36ad1e809a9f52f17eca573ff5a1a97d5c6aae92 Mon Sep 17 00:00:00 2001 From: Gabgobie <105999094+Gabgobie@users.noreply.github.com> Date: Tue, 21 Jul 2026 21:00:24 +0200 Subject: [PATCH 38/49] proton-pass-cli: Update license - closes #544297 - pulls license change from #529921 - - Applies suggestion from @GraysonTinker (cherry picked from commit 2d74a92b3a7e4407f96f9e52b2a5096e8d221fbe) --- pkgs/by-name/pr/proton-pass-cli/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/pr/proton-pass-cli/package.nix b/pkgs/by-name/pr/proton-pass-cli/package.nix index 425cc765bae0..8fbca80713de 100644 --- a/pkgs/by-name/pr/proton-pass-cli/package.nix +++ b/pkgs/by-name/pr/proton-pass-cli/package.nix @@ -84,7 +84,7 @@ stdenv.mkDerivation (finalAttrs: { meta = { description = "Command-line interface for managing your Proton Pass vaults, items, and secrets"; homepage = "https://github.com/protonpass/pass-cli"; - license = lib.licenses.unfree; + license = lib.licenses.gpl3Plus; mainProgram = "pass-cli"; maintainers = with lib.maintainers; [ delafthi ]; platforms = lib.attrNames finalAttrs.passthru.sources; From bff0a8a5f1122ef88c113eed52777d0735ad293a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 23 Jul 2026 10:30:44 +0000 Subject: [PATCH 39/49] javaPackages.compiler.openjdk8: 8u502-b01 -> 8u502-b07 (cherry picked from commit 4b73eda73cfea2e27cd19060a8b2de96abfa9847) --- pkgs/development/compilers/openjdk/8/source.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/openjdk/8/source.json b/pkgs/development/compilers/openjdk/8/source.json index fc8351b58c97..894732a60e1f 100644 --- a/pkgs/development/compilers/openjdk/8/source.json +++ b/pkgs/development/compilers/openjdk/8/source.json @@ -1,6 +1,6 @@ { - "hash": "sha256-c86eD79qxAHswjSi+GTPPkyRAz8PRA2w+eBLRMazUik=", + "hash": "sha256-7sbEwNSd0SNdsfWREU6EIk+/9UMlZfWYEv+UQ6iJ3VI=", "owner": "openjdk", "repo": "jdk8u", - "rev": "refs/tags/jdk8u502-b01" + "rev": "refs/tags/jdk8u502-b07" } From b0526a5d67477aa9c66e41eb333c57ee59899b42 Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Wed, 22 Jul 2026 23:27:15 +0200 Subject: [PATCH 40/49] exim: 4.99.4 -> 4.99.5 Fixes GCVE-25-2026-07-45-1 and GCVE-25-2026-07-45-3. https://code.exim.org/exim/exim/compare/exim-4.99.4...exim-4.99.5 (cherry picked from commit cf10be71e53ec78f9d296afa719c3ffa1281abc2) --- pkgs/by-name/ex/exim/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ex/exim/package.nix b/pkgs/by-name/ex/exim/package.nix index 0a9330e7b43a..0da92f263656 100644 --- a/pkgs/by-name/ex/exim/package.nix +++ b/pkgs/by-name/ex/exim/package.nix @@ -39,11 +39,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "exim"; - version = "4.99.4"; + version = "4.99.5"; src = fetchurl { url = "https://ftp.exim.org/pub/exim/exim4/exim-${finalAttrs.version}.tar.xz"; - hash = "sha256-h/84gVcA37HuTrfo26eRbfenVZBTVNLQ+qGuF5DE/Z0="; + hash = "sha256-wtL4Ctx8cdQk/YKkZlXqotfZtMoud4g+upB2lHt+5ic="; }; enableParallelBuilding = true; From 6cb1bced1257dd18e4e7a23b40225ef55a10c3db Mon Sep 17 00:00:00 2001 From: networkException Date: Thu, 23 Jul 2026 16:50:36 +0200 Subject: [PATCH 41/49] ungoogled-chromium: 150.0.7871.128-1 -> 150.0.7871.181-1 https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html This update includes 12 security fixes. CVEs: CVE-2026-16420 CVE-2026-16421 CVE-2026-16413 CVE-2026-16414 CVE-2026-16415 CVE-2026-16416 CVE-2026-16417 CVE-2026-16418 CVE-2026-16419 CVE-2026-16422 CVE-2026-16423 CVE-2026-16424 (cherry picked from commit 0337b01dec1597d617cf7df780ecfee2c0f753f5) --- .../networking/browsers/chromium/info.json | 26 +++++++++---------- 1 file changed, 13 insertions(+), 13 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/info.json b/pkgs/applications/networking/browsers/chromium/info.json index 12860a06037d..f7c6d174a0f7 100644 --- a/pkgs/applications/networking/browsers/chromium/info.json +++ b/pkgs/applications/networking/browsers/chromium/info.json @@ -838,7 +838,7 @@ } }, "ungoogled-chromium": { - "version": "150.0.7871.128", + "version": "150.0.7871.181", "deps": { "depot_tools": { "rev": "f4fadaf6a5ba1bced9d3d9021060667b563bf583", @@ -850,16 +850,16 @@ "hash": "sha256-/1A+DkzAQj2zGPe/A/G0Z3VrYJXUxq4Hd/+d/o5p3G8=" }, "ungoogled-patches": { - "rev": "150.0.7871.128-1", - "hash": "sha256-GxSsGTC68IEMPt85RLBCVDT0dTl7ZVVPc8o4vxc50H8=" + "rev": "150.0.7871.181-1", + "hash": "sha256-ifqEnOcvi49cFOYan8ShiwteXYnFrLPclrIBZiE1rGY=" }, "npmHash": "sha256-pF0JtwFpPC4/fodbhSJnQKkczA9WlDg4VqEAy9aDVLg=" }, "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "81891e5ca708047763816c778216799ef14c66cb", - "hash": "sha256-lGHZZ2xIih+TaH145CZwEwyXsM1ZQWwqXsIQjWQ/jvk=", + "rev": "24b04c927b23c39cf9c5227cc8dc6f64a744c8e9", + "hash": "sha256-F52wmxyNPEV26v8YgAz+MRhyEGyV7YUX+/wj95H4Lf0=", "recompress": true }, "src/third_party/clang-format/script": { @@ -929,8 +929,8 @@ }, "src/third_party/angle": { "url": "https://chromium.googlesource.com/angle/angle.git", - "rev": "13e691adf3d4d3ebee2f7239731a07d3b9704956", - "hash": "sha256-fbjREn3D+quRRADGwR7V65BZt5b+1DgnsG4ZMhwGq6o=" + "rev": "edae461ad2122a3a2be0b5d3d067472aa0e3329c", + "hash": "sha256-V4D7jAPJy4llbfJ6WmgCaqaH3TgkWIg5UtRAUaB9dE4=" }, "src/third_party/angle/third_party/glmark2/src": { "url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2", @@ -974,8 +974,8 @@ }, "src/third_party/dawn": { "url": "https://dawn.googlesource.com/dawn.git", - "rev": "01249a97332468dbdd6cf5edb8dd7bae77875de5", - "hash": "sha256-tzomo+GTec2zixxk61gtlma/sjcBImgbLMwA+mIp1LM=" + "rev": "d089fc91e7e4881362463faf8efe9ae435e34660", + "hash": "sha256-ZcfSMBvdAdEJQv+qfwAe8EFHPAfPtuKLTIR5lDRKP3Q=" }, "src/third_party/dawn/third_party/glfw3/src": { "url": "https://chromium.googlesource.com/external/github.com/glfw/glfw", @@ -1494,8 +1494,8 @@ }, "src/third_party/skia": { "url": "https://skia.googlesource.com/skia.git", - "rev": "bee4c917220040e147f14964635ff92ce6c5a3f6", - "hash": "sha256-SWmoX+sNaw4KnlTBPt63uBSYfQavJejB3+Vlw/gtWX8=" + "rev": "587c5b0f5a7b0260826a0c19094c2d952195066e", + "hash": "sha256-COvdvWVfafVhccLIj2dJzu62Rbyi3oDgORtjIGolCRo=" }, "src/third_party/smhasher/src": { "url": "https://chromium.googlesource.com/external/smhasher.git", @@ -1664,8 +1664,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "2b2f69158528fdd9d86b778cfcc2d0a1c4f8c59f", - "hash": "sha256-bqzCZSpKdXgKv3O1I7ck1PEXCa/2jBT7hpBEKW0LgTA=" + "rev": "49df3678d1b6a1511167b15a6b7499d3ab37a638", + "hash": "sha256-T9FWX3zuP1V7wvxeHgv2MEfRiwbJC0ElI3eazSYq3fs=" }, "src/agents/shared": { "url": "https://chromium.googlesource.com/chromium/agents.git", From 46c7ec561e37d648aec2f7f9e20571690efb465c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 3 Jul 2026 05:30:44 +0000 Subject: [PATCH 42/49] mochi: 1.21.16 -> 1.21.17 (cherry picked from commit 168427b171e1947e114f7a741b45d48965c63c97) --- pkgs/by-name/mo/mochi/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/mo/mochi/package.nix b/pkgs/by-name/mo/mochi/package.nix index 0f41fbeb5f90..81d56f9eb8ae 100644 --- a/pkgs/by-name/mo/mochi/package.nix +++ b/pkgs/by-name/mo/mochi/package.nix @@ -12,14 +12,14 @@ let pname = "mochi"; - version = "1.21.16"; + version = "1.21.17"; linux = appimageTools.wrapType2 rec { inherit pname version meta; src = fetchurl { url = "https://download.mochi.cards/releases/Mochi-${version}.AppImage"; - hash = "sha256-LWwv/+2/djc2bdqhnJiG5etXg+MFaEZbpttewVBZdeg="; + hash = "sha256-QYBh9ZvmJse3ZimvpU+9ky6ml0pCSZ3mVrYtWtMQGA0="; }; appimageContents = appimageTools.extractType2 { inherit pname version src; }; @@ -44,9 +44,9 @@ let url = "https://download.mochi.cards/releases/Mochi-${version}${lib.optionalString stdenv.hostPlatform.isAarch64 "-arm64"}.dmg"; hash = if stdenv.hostPlatform.isAarch64 then - "sha256-dtdQZYGrukT/UgfNdsnGxOYmpuebJCDHXW8cAGN2GZE=" + "sha256-2NADaVzkibWjxBymeF1McGEQH6xHaqDMBg080kCI0F8=" else - "sha256-FdNFpuIOMgRzniB9Aze3GUpNY27h++StTdwqfF1k07I="; + "sha256-XM4vQVQ9QtvqyDu2Wx/8/Z+8H2DetfCufJYrX/1JHFw="; }; sourceRoot = "."; From 0bb476f0ec97902406e73e712e8688a09131e58e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 20 Jul 2026 14:45:32 +0000 Subject: [PATCH 43/49] frankenphp: 1.12.4 -> 1.12.5 (cherry picked from commit dbd45dad852b634d97cb3c53937bcb356e143ddc) --- pkgs/by-name/fr/frankenphp/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/fr/frankenphp/package.nix b/pkgs/by-name/fr/frankenphp/package.nix index c297c4e01e00..307dd9b21398 100644 --- a/pkgs/by-name/fr/frankenphp/package.nix +++ b/pkgs/by-name/fr/frankenphp/package.nix @@ -30,13 +30,13 @@ let in buildGoModule (finalAttrs: { pname = "frankenphp"; - version = "1.12.4"; + version = "1.12.5"; src = fetchFromGitHub { owner = "php"; repo = "frankenphp"; tag = "v${finalAttrs.version}"; - hash = "sha256-DzncOAhdDyc5qOipMI8OPss0WciAQIam6GmaUoe8mR8="; + hash = "sha256-1f+3w9x6P1euUZr4hC4jOkgEJEbS/MJ11u+chGShCno="; }; sourceRoot = "${finalAttrs.src.name}/caddy"; @@ -44,7 +44,7 @@ buildGoModule (finalAttrs: { # frankenphp requires C code that would be removed with `go mod tidy` # https://github.com/golang/go/issues/26366 proxyVendor = true; - vendorHash = "sha256-XY5a8pd5vJ/ouZMASzVqPoeXVfPbnEVDJFKkVNQF+2M="; + vendorHash = "sha256-d6ZTi1Ihu011eKVdHMiW9oSdPB4SYpDHMFxH65XLGac="; buildInputs = [ phpUnwrapped From 59aef62837407e2386d525bb538aa15bcca7fcc1 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 29 Jun 2026 08:15:43 +0000 Subject: [PATCH 44/49] listmonk: 6.1.0 -> 6.2.0 (cherry picked from commit cfedd4f94237a409709b83646da8e77af8ed413f) --- pkgs/by-name/li/listmonk/email-builder.nix | 2 +- pkgs/by-name/li/listmonk/frontend.nix | 2 +- pkgs/by-name/li/listmonk/package.nix | 6 +++--- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/li/listmonk/email-builder.nix b/pkgs/by-name/li/listmonk/email-builder.nix index a8c4718730e6..4b069365903e 100644 --- a/pkgs/by-name/li/listmonk/email-builder.nix +++ b/pkgs/by-name/li/listmonk/email-builder.nix @@ -17,7 +17,7 @@ stdenv.mkDerivation { offlineCache = fetchYarnDeps { yarnLock = "${src}/frontend/email-builder/yarn.lock"; - hash = "sha256-sFRmnMPStNp45hxcF+Iq1WhH6LtVFtgq2regq6MPzcc="; + hash = "sha256-ANPLOL9j0gljtNtbfb+ZifVRN9vLexPddAevpeFwX4o="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/li/listmonk/frontend.nix b/pkgs/by-name/li/listmonk/frontend.nix index 4fec2c272de4..cb82721de315 100644 --- a/pkgs/by-name/li/listmonk/frontend.nix +++ b/pkgs/by-name/li/listmonk/frontend.nix @@ -17,7 +17,7 @@ stdenv.mkDerivation (finalAttrs: { offlineCache = fetchYarnDeps { yarnLock = "${src}/frontend/yarn.lock"; - hash = "sha256-VCaEMftA7AzW/6jyceVO596iby0wC3LW9YDG66kLJmw="; + hash = "sha256-R2xHcHksTtFfFh41FLeBhpuz84ceixGt6oz6SQWWyMQ="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/li/listmonk/package.nix b/pkgs/by-name/li/listmonk/package.nix index 7fc3c88b6425..ed62aebb3996 100644 --- a/pkgs/by-name/li/listmonk/package.nix +++ b/pkgs/by-name/li/listmonk/package.nix @@ -11,16 +11,16 @@ buildGoModule (finalAttrs: { pname = "listmonk"; - version = "6.1.0"; + version = "6.2.0"; src = fetchFromGitHub { owner = "knadh"; repo = "listmonk"; rev = "v${finalAttrs.version}"; - hash = "sha256-SG9PhQOu3QB0LA9dNLnNzwwtfaib7MCfvOcBMkWMRPw="; + hash = "sha256-eora/+zJf60trmANEqAhYAQXfEMifyw5gLPKcqBW46w="; }; - vendorHash = "sha256-0KrjaExgT9tN4M99CfyQpqpGYnXOpzsPRk/Ih4qXsuE="; + vendorHash = "sha256-t4l8872bniTmNIW4ias1gImURJgrR6htXkncqfrJ+AU="; nativeBuildInputs = [ stuffbin From 26e64d56722c16b5fd835a3560d8cf21ac181f50 Mon Sep 17 00:00:00 2001 From: Daniel Fahey Date: Mon, 20 Jul 2026 16:18:04 +0100 Subject: [PATCH 45/49] listmonk: fix hash after upstream tag was moved (cherry picked from commit 75bf1f0038363e7d1a7169c401ad41997a01f96d) --- pkgs/by-name/li/listmonk/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/li/listmonk/package.nix b/pkgs/by-name/li/listmonk/package.nix index ed62aebb3996..6525511d748f 100644 --- a/pkgs/by-name/li/listmonk/package.nix +++ b/pkgs/by-name/li/listmonk/package.nix @@ -17,7 +17,7 @@ buildGoModule (finalAttrs: { owner = "knadh"; repo = "listmonk"; rev = "v${finalAttrs.version}"; - hash = "sha256-eora/+zJf60trmANEqAhYAQXfEMifyw5gLPKcqBW46w="; + hash = "sha256-yLOs1vhTV/0zzq/2Rk5rJ3/1z+kE5xaYODM5NO06F6U="; }; vendorHash = "sha256-t4l8872bniTmNIW4ias1gImURJgrR6htXkncqfrJ+AU="; From 7938951b0d655d36988434aed4e2b7326ed5f651 Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Thu, 16 Jul 2026 08:56:45 +0200 Subject: [PATCH 46/49] youtrack: 2026.2.17012 -> 2026.2.17765 https://www.jetbrains.com/privacy-security/issues-fixed/ Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) (cherry picked from commit cfe813b4f6a124840cc97de3d1e3d20733457aa1) --- pkgs/by-name/yo/youtrack/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/yo/youtrack/package.nix b/pkgs/by-name/yo/youtrack/package.nix index 4d310ebc1ac4..25358f378b1f 100644 --- a/pkgs/by-name/yo/youtrack/package.nix +++ b/pkgs/by-name/yo/youtrack/package.nix @@ -10,15 +10,15 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "youtrack"; - version = "2026.2.17012"; + version = "2026.2.17765"; src = dockerTools.exportImage { diskSize = 8192; fromImage = dockerTools.pullImage { imageName = "jetbrains/youtrack"; arch = "amd64"; - imageDigest = "sha256:fa50e2e07435dc91461c00ef05ee064ff76748d4d8feaf8aeaa9f9e4a9bf6606"; - hash = "sha256-8hoMtFqG5T4gnMDorIe6UXs/d3z7epAS352reipPjWI="; + imageDigest = "sha256:54d25c6f100330cc43cc60219846711eed5e598bad11ce3611c42756b5ba197a"; + hash = "sha256-009ZLutj1fv8gPlRuDB+vI3sosIRBg6r87o69aW0v5s="; }; }; unpackPhase = '' From 3264554320ad721e3ab374f1d32107a658687d17 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 23 Jul 2026 19:24:40 +0000 Subject: [PATCH 47/49] dokuwiki: 2025-05-14b -> 2026-07-14a (cherry picked from commit bca9b20051450a414db625fa7f2239789108ad05) --- pkgs/by-name/do/dokuwiki/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/do/dokuwiki/package.nix b/pkgs/by-name/do/dokuwiki/package.nix index 0796e233496a..69f0d9b3461c 100644 --- a/pkgs/by-name/do/dokuwiki/package.nix +++ b/pkgs/by-name/do/dokuwiki/package.nix @@ -9,13 +9,13 @@ stdenv.mkDerivation rec { pname = "dokuwiki"; - version = "2025-05-14b"; + version = "2026-07-14a"; src = fetchFromGitHub { owner = "dokuwiki"; repo = "dokuwiki"; rev = "release-${version}"; - sha256 = "sha256-J7B+mvvGtAPK+WjlkHyadG61vli+zZfozfEmEynYQaE="; + sha256 = "sha256-qj+Ng20aB3qV2afrER309kvlh6gXRFPh3MqnomvvCf4="; }; preload = writeText "preload.php" '' From bf1a8d26edf26f38e9f19d836ee23af81fe4b3ea Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Thu, 23 Jul 2026 17:44:24 -0400 Subject: [PATCH 48/49] google-chrome: 150.0.7871.181 -> 150.0.7871.186 Announcement: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html (cherry picked from commit 49bf18108bb9762b41557d901cbec5e6d1e3ff3f) --- pkgs/by-name/go/google-chrome/package.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/go/google-chrome/package.nix b/pkgs/by-name/go/google-chrome/package.nix index 670056428fc5..faf1f96f7f10 100644 --- a/pkgs/by-name/go/google-chrome/package.nix +++ b/pkgs/by-name/go/google-chrome/package.nix @@ -179,11 +179,11 @@ let linux = stdenvNoCC.mkDerivation (finalAttrs: { inherit pname meta passthru; - version = "150.0.7871.181"; + version = "150.0.7871.186"; src = fetchurl { url = "https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-stable/google-chrome-stable_${finalAttrs.version}-1_amd64.deb"; - hash = "sha256-/sUJBfexI1pECXeoM0duAWKHT1ynnlBs30C3GvZNkvQ="; + hash = "sha256-QZPgC21dWWnuY/emlZaGj1RqoOjLB3s+C/nMHixxnQA="; }; # With strictDeps on, some shebangs were not being patched correctly @@ -289,11 +289,11 @@ let darwin = stdenvNoCC.mkDerivation (finalAttrs: { inherit pname meta passthru; - version = "150.0.7871.182"; + version = "150.0.7871.187"; src = fetchurl { - url = "http://dl.google.com/release2/chrome/mb6usb7722qbv5pqtlgpq72utm_150.0.7871.182/GoogleChrome-150.0.7871.182.dmg"; - hash = "sha256-eNrCQqKqd+6cuvGDbQ0VM5JpolHusOZou2elsAh0TD4="; + url = "http://dl.google.com/release2/chrome/ecziwrw2etq4lm3vlbpv5wzvce_150.0.7871.187/GoogleChrome-150.0.7871.187.dmg"; + hash = "sha256-I1a+wR5zNfOSYyns2ehDek5DP1xccRQvmBLymxB/R7A="; }; dontPatch = true; From 3737c99deb0dc142436a5ce5ec80d71bf5fab4a0 Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Thu, 23 Jul 2026 10:49:30 +0200 Subject: [PATCH 49/49] linux_testing: 7.2-rc3 -> 7.2-rc4 (cherry picked from commit f200b2e380fae64f7aba482e2e61bf60b5a5d4d9) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index a62db4fe6473..08c27feddb44 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -1,7 +1,7 @@ { "testing": { - "version": "7.2-rc3", - "hash": "sha256:1nf6znpalqikblq6g0yb3hp7i689frhlhb4j1yxj6nn8fvma4rwd", + "version": "7.2-rc4", + "hash": "sha256:02qab36m7xzfwqdrylpacvlkjaxfa0mlnmk38fix6anqi3hgjq3q", "lts": false }, "6.1": {