From b0b3191811351b94b8193b1a296f52803c6340e6 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Thu, 9 Jul 2026 12:02:47 +1000 Subject: [PATCH 01/20] ci/OWNERS: remove maintainer from buildbot --- ci/OWNERS | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/ci/OWNERS b/ci/OWNERS index e2153236ced0..8ee2d5cd2d5d 100644 --- a/ci/OWNERS +++ b/ci/OWNERS @@ -446,9 +446,9 @@ nixos/tests/forgejo.nix @adamcstephens @bendlas @christoph-heiss @ /doc/hooks/zig.section.md @RossComputerGuy # Buildbot -nixos/modules/services/continuous-integration/buildbot @Mic92 @zowoq -nixos/tests/buildbot.nix @Mic92 @zowoq -pkgs/development/tools/continuous-integration/buildbot @Mic92 @zowoq +nixos/modules/services/continuous-integration/buildbot @Mic92 +nixos/tests/buildbot.nix @Mic92 +pkgs/development/tools/continuous-integration/buildbot @Mic92 # Pretix pkgs/by-name/pr/pretix/ @mweinelt From 44dc047ef5a06ebac5a5ffd5c952f553e7e1f28b Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Thu, 9 Jul 2026 12:02:47 +1000 Subject: [PATCH 02/20] maintainers/team-list: remove maintainer from buildbot --- maintainers/team-list.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/maintainers/team-list.nix b/maintainers/team-list.nix index 9e83554924dd..cc734beda277 100644 --- a/maintainers/team-list.nix +++ b/maintainers/team-list.nix @@ -104,7 +104,6 @@ with lib.maintainers; members = [ lopsided98 mic92 - zowoq ]; scope = "Maintain Buildbot CI framework"; shortName = "Buildbot"; From 5151482e19af6f3abc65a90de320e2c01ae36d93 Mon Sep 17 00:00:00 2001 From: David Mkhitaryan Date: Thu, 9 Jul 2026 16:31:25 +0400 Subject: [PATCH 03/20] sacad: 2.8.3 -> 3.0.1 --- pkgs/by-name/sa/sacad/package.nix | 40 ++++++++++--------------------- 1 file changed, 12 insertions(+), 28 deletions(-) diff --git a/pkgs/by-name/sa/sacad/package.nix b/pkgs/by-name/sa/sacad/package.nix index 99625089cf31..70d36f43cfd1 100644 --- a/pkgs/by-name/sa/sacad/package.nix +++ b/pkgs/by-name/sa/sacad/package.nix @@ -1,46 +1,30 @@ { lib, - python3Packages, - fetchPypi, - jpegoptim, - optipng, + rustPlatform, + fetchFromGitHub, }: -python3Packages.buildPythonApplication (finalAttrs: { +rustPlatform.buildRustPackage (finalAttrs: { pname = "sacad"; - version = "2.8.3"; - format = "setuptools"; + version = "3.0.1"; - src = fetchPypi { - inherit (finalAttrs) pname version; - hash = "sha256-6bKxFOP4hPbU5d1J/wro1BM/Bh9W//QzcZ4YbfaaqYY="; + src = fetchFromGitHub { + owner = "desbma"; + repo = "sacad"; + tag = finalAttrs.version; + hash = "sha256-dzVppb6Lg/yjLrPAwII/GMy+56jzaWn0WS7vRZOXkgU="; }; - propagatedBuildInputs = with python3Packages; [ - aiohttp - appdirs - bitarray - cssselect - fake-useragent - lxml - mutagen - pillow - tqdm - unidecode - web-cache - jpegoptim - optipng - ]; + cargoHash = "sha256-tySgM7j26vztPOGkIq1kQeZn6YwDbk9mt3SEg94SW2o="; - # tests require internet connection + # Tests require internet connection. doCheck = false; - pythonImportsCheck = [ "sacad" ]; - meta = { description = "Smart Automatic Cover Art Downloader"; homepage = "https://github.com/desbma/sacad"; license = lib.licenses.mpl20; maintainers = with lib.maintainers; [ moni ]; + mainProgram = "sacad"; }; }) From 6936a1272e155418bf552d5290c632a4301f50c7 Mon Sep 17 00:00:00 2001 From: KangaZero Date: Fri, 14 Aug 2026 13:33:26 +0900 Subject: [PATCH 04/20] libinklevel: 0.9.4 -> 0.9.7 Added `libxml2` to `buildInputs`; this was required since `0.9.5` --- pkgs/by-name/li/libinklevel/package.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libinklevel/package.nix b/pkgs/by-name/li/libinklevel/package.nix index b394113664cb..b941635948b8 100644 --- a/pkgs/by-name/li/libinklevel/package.nix +++ b/pkgs/by-name/li/libinklevel/package.nix @@ -4,20 +4,22 @@ fetchurl, pkg-config, libusb1, + libxml2, }: stdenv.mkDerivation (finalAttrs: { pname = "libinklevel"; - version = "0.9.4"; + version = "0.9.7"; src = fetchurl { url = "mirror://sourceforge/libinklevel/libinklevel-${finalAttrs.version}.tar.gz"; - sha256 = "sha256-J0cEaC5v4naO4GGUzdfV55kB7KzA+q+v64i5y5Xbp9Q="; + sha256 = "sha256-gZ07tMJXhyLBBXyfPamZoaPrRmKPD+ka61K/zNOIRnU="; }; nativeBuildInputs = [ pkg-config ]; buildInputs = [ libusb1 + libxml2 ]; outputs = [ From 1bf24d8815be6006ddbfb962db725f18f69d7a0a Mon Sep 17 00:00:00 2001 From: Roman Date: Mon, 31 Aug 2026 22:31:33 +0200 Subject: [PATCH 05/20] proton-cli: don't run the built binary when cross-compiling The completions are generated by running the binary that was just built, which the build machine cannot do when it is not the host platform. stdenv already disables the install check on exactly this condition; postInstall was the one place ignoring it. Assisted-by: pi 0.84.2 (Anthropic claude-opus-5) --- pkgs/by-name/pr/proton-cli/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/pr/proton-cli/package.nix b/pkgs/by-name/pr/proton-cli/package.nix index 98d1c34cb576..f1306dfe8ac0 100644 --- a/pkgs/by-name/pr/proton-cli/package.nix +++ b/pkgs/by-name/pr/proton-cli/package.nix @@ -54,7 +54,7 @@ buildGoModule (finalAttrs: { preBuild = null; }; - postInstall = '' + postInstall = lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) '' installShellCompletion --cmd proton-cli \ --bash <($out/bin/proton-cli completion bash) \ --fish <($out/bin/proton-cli completion fish) \ From 85ccec0a1fe48d36931debc6373598cbd31751dd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Emilio=20L=C3=B3pez?= Date: Fri, 4 Sep 2026 14:07:16 -0300 Subject: [PATCH 06/20] libff: fix header installation with CMake 4.3+ CMake 4.3 (commit 4e7e6928cb, "install: Fix bugs around empty directories") changed install(DIRECTORY "" ...): the empty string used to silently expand to the current source directory, and is now a no-op that creates the destination directory but installs nothing into it. libff uses that form for its headers, so since the cmake 4.3.4 bump the package ships an empty include/libff and dependents such as hevm fail to compile with: fatal error: libff/algebra/fields/bigint.hpp: No such file or directory Replace the empty string with "./" so the header tree is installed again. See https://gitlab.kitware.com/cmake/cmake/-/issues/27568 Assisted-by: Claude Code (Claude Fable 5.1) --- pkgs/by-name/li/libff/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/li/libff/package.nix b/pkgs/by-name/li/libff/package.nix index b75fe6b1bd85..59742596f026 100644 --- a/pkgs/by-name/li/libff/package.nix +++ b/pkgs/by-name/li/libff/package.nix @@ -31,6 +31,11 @@ stdenv.mkDerivation (finalAttrs: { postPatch = '' substituteInPlace CMakeLists.txt --replace "VERSION 2.8" "VERSION 3.10" + # CMake >= 4.3 treats install(DIRECTORY "" ...) as a no-op instead of + # installing the current source directory, so no headers get installed. + # https://gitlab.kitware.com/cmake/cmake/-/issues/27568 + substituteInPlace libff/CMakeLists.txt \ + --replace-fail 'DIRECTORY "" DESTINATION "include/libff"' 'DIRECTORY "./" DESTINATION "include/libff"' '' + lib.optionalString (!enableStatic) '' substituteInPlace libff/CMakeLists.txt --replace "STATIC" "SHARED" From 898ffc9c309c22124651a0ddf03d5e6f1b13b13f Mon Sep 17 00:00:00 2001 From: Roman Date: Sat, 5 Sep 2026 17:52:59 +0200 Subject: [PATCH 07/20] proton-cli: 2.2.3 -> 3.4.0 The command is now `proton`, with `proton-cli` kept as a second name, so `subPackages`, `mainProgram` and the completions move with it. Human verification is solved in the user's own browser, so upstream deleted the embedded CAPTCHA webview, the script that built it and its `webview_go` dependency. The build tag, that script, the vendor-fetch override that kept it out, pkg-config, wrapGAppsHook3 and the GTK stack go with them, leaving a plain pure-Go build: 843.8 MiB -> 57.7 MiB. 3.0.0 reworks the command line: `--output` is the response format on every command, no secret is accepted as a flag value, and several subcommands moved. The release note carries the breaks. https://github.com/roman-16/proton-cli/blob/main/CHANGELOG.md Assisted-by: pi 0.85.0 (Anthropic claude-opus-5) --- pkgs/by-name/pr/proton-cli/package.nix | 47 +++++++++----------------- 1 file changed, 16 insertions(+), 31 deletions(-) diff --git a/pkgs/by-name/pr/proton-cli/package.nix b/pkgs/by-name/pr/proton-cli/package.nix index f1306dfe8ac0..4b6263730d4c 100644 --- a/pkgs/by-name/pr/proton-cli/package.nix +++ b/pkgs/by-name/pr/proton-cli/package.nix @@ -3,17 +3,14 @@ buildGoModule, fetchFromGitHub, installShellFiles, - pkg-config, stdenv, - webkitgtk_4_1, - gtk3, nix-update-script, versionCheckHook, }: buildGoModule (finalAttrs: { pname = "proton-cli"; - version = "2.2.3"; + version = "3.4.0"; __structuredAttrs = true; @@ -21,14 +18,12 @@ buildGoModule (finalAttrs: { owner = "roman-16"; repo = "proton-cli"; tag = "v${finalAttrs.version}"; - hash = "sha256-Mw+hfBStq0Ga/FrKll92//YjFt0XreZ5tjqZGY0enzw="; + hash = "sha256-qTT5f7udkrH+zEQ70bjWj1RbKNX5sKxEnuCS8usTlw4="; }; - vendorHash = "sha256-VjLuSaHW7C1Ar84vusMRjBWVikgVCdLBwd+OFT7ufiQ="; + vendorHash = "sha256-/bUSjdXg+bb+HdBmWrE2M5PDDhivVdh5FfaRp/Nkcvw="; - subPackages = [ "." ]; - - tags = [ "embed_hv" ]; + subPackages = [ "cmd/proton" ]; ldflags = [ "-s" @@ -36,29 +31,19 @@ buildGoModule (finalAttrs: { "-X=github.com/roman-16/proton-cli/internal/cli.version=${finalAttrs.version}" ]; - nativeBuildInputs = [ - installShellFiles - pkg-config - ]; + nativeBuildInputs = [ installShellFiles ]; - buildInputs = lib.optionals stdenv.hostPlatform.isLinux [ - webkitgtk_4_1 - gtk3 - ]; - - preBuild = '' - bash scripts/build-hv-helpers.sh - ''; - - overrideModAttrs = _: { - preBuild = null; - }; - - postInstall = lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) '' + postInstall = '' + ln -s proton $out/bin/proton-cli + '' + + lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) '' + installShellCompletion --cmd proton \ + --bash <($out/bin/proton completion bash) \ + --fish <($out/bin/proton completion fish) \ + --zsh <($out/bin/proton completion zsh) installShellCompletion --cmd proton-cli \ - --bash <($out/bin/proton-cli completion bash) \ - --fish <($out/bin/proton-cli completion fish) \ - --zsh <($out/bin/proton-cli completion zsh) + --bash <($out/bin/proton completion bash) \ + --fish <(echo 'complete -c proton-cli -w proton') ''; nativeInstallCheckInputs = [ versionCheckHook ]; @@ -71,7 +56,7 @@ buildGoModule (finalAttrs: { homepage = "https://github.com/roman-16/proton-cli"; changelog = "https://github.com/roman-16/proton-cli/releases/tag/v${finalAttrs.version}"; license = lib.licenses.mit; - mainProgram = "proton-cli"; + mainProgram = "proton"; maintainers = with lib.maintainers; [ roman-16 ]; platforms = lib.platforms.linux ++ lib.platforms.darwin; }; From d8aad67d985c61dc00ff061d768160f38306384d Mon Sep 17 00:00:00 2001 From: Roman Date: Sat, 5 Sep 2026 17:53:03 +0200 Subject: [PATCH 08/20] proton-cli: update description and homepage The description leads with what the program is for and ends on the property that sets it apart, in the one-sentence form the manual asks for. The homepage is the documentation site upstream publishes. Assisted-by: pi 0.85.0 (Anthropic claude-opus-5) --- pkgs/by-name/pr/proton-cli/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pr/proton-cli/package.nix b/pkgs/by-name/pr/proton-cli/package.nix index 4b6263730d4c..45a75258caa9 100644 --- a/pkgs/by-name/pr/proton-cli/package.nix +++ b/pkgs/by-name/pr/proton-cli/package.nix @@ -52,8 +52,8 @@ buildGoModule (finalAttrs: { passthru.updateScript = nix-update-script { }; meta = { - description = "Unofficial command-line client for the Proton suite (Mail, Drive, Calendar, Contacts, Pass)"; - homepage = "https://github.com/roman-16/proton-cli"; + description = "CLI for Proton Mail, Drive, Calendar, Pass and Contacts, end-to-end encrypted"; + homepage = "https://proton-cli.lerchster.dev/"; changelog = "https://github.com/roman-16/proton-cli/releases/tag/v${finalAttrs.version}"; license = lib.licenses.mit; mainProgram = "proton"; From 5b7e9c9fa27d5dcb8d4c90c42458d4a929185571 Mon Sep 17 00:00:00 2001 From: Roman Date: Sat, 5 Sep 2026 17:53:06 +0200 Subject: [PATCH 09/20] doc/rl-2611: note the proton-cli breaking changes Assisted-by: pi 0.85.0 (Anthropic claude-opus-5) --- doc/release-notes/rl-2611.section.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md index 6261560ecec6..497af2bc8cf4 100644 --- a/doc/release-notes/rl-2611.section.md +++ b/doc/release-notes/rl-2611.section.md @@ -87,6 +87,9 @@ - `himalaya` has been updated from `v1.2.0` to `v2.0.0`, which introduces breaking changes. See the [release notes](https://github.com/pimalaya/himalaya/releases/tag/v2.0.0) and the [migration guide](https://github.com/pimalaya/himalaya/blob/master/MIGRATION.md). +- `proton-cli` has been updated from `2.2.3` to `3.4.0`, and installs its command as `proton`, with `proton-cli` kept beside it as a symlink. + `3.0.0` reworked the command line - `--output` is now the response format, secrets are no longer accepted as flag values, and several subcommands moved - so scripts need a review against the [upstream changelog](https://github.com/roman-16/proton-cli/blob/main/CHANGELOG.md). + - `tengine` has been removed as it has seen seriously delayed responses to security vulnerabilities. - `nix-serve-ng` (and `haskellPackages.nix-serve-ng`) is now built against Lix instead of CppNix, following upstream which has switched to Lix as its supported Nix implementation. From 5d5b93d56be4fac470c175630ffacb606f0236ae Mon Sep 17 00:00:00 2001 From: Thomas Butter Date: Sun, 17 May 2026 16:56:36 +0000 Subject: [PATCH 10/20] cheat: 4.5.0 -> 5.1.0 --- pkgs/by-name/ch/cheat/package.nix | 34 ++++++++++++++----------------- 1 file changed, 15 insertions(+), 19 deletions(-) diff --git a/pkgs/by-name/ch/cheat/package.nix b/pkgs/by-name/ch/cheat/package.nix index 7d5ace6aa359..64426ad8f4c0 100644 --- a/pkgs/by-name/ch/cheat/package.nix +++ b/pkgs/by-name/ch/cheat/package.nix @@ -1,48 +1,44 @@ { + stdenv, lib, fetchFromGitHub, buildGoModule, installShellFiles, + git, }: buildGoModule (finalAttrs: { pname = "cheat"; - version = "4.5.0"; + version = "5.1.0"; src = fetchFromGitHub { owner = "cheat"; repo = "cheat"; tag = finalAttrs.version; - sha256 = "sha256-RDfOdyQL9QICXZmgYCmz532iTuPdCW8GixajvEXmaUQ="; + hash = "sha256-0c8NZzzLxssMJffEWBI5L3leWWOU/Y0slPIg6bPKzfI="; }; - subPackages = [ "cmd/cheat" ]; - nativeBuildInputs = [ installShellFiles ]; - patches = [ - (builtins.toFile "fix-zsh-completion.patch" '' - diff --git a/scripts/cheat.zsh b/scripts/cheat.zsh - index befe1b2..675c9f8 100755 - --- a/scripts/cheat.zsh - +++ b/scripts/cheat.zsh - @@ -62,4 +62,4 @@ _cheat() { - esac - } - - -compdef _cheat cheat - +_cheat "$@" - '') + nativeCheckInputs = [ + git ]; postInstall = '' installManPage doc/cheat.1 - installShellCompletion scripts/cheat.{bash,fish,zsh} + '' + + lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) '' + installShellCompletion --cmd cheat \ + --bash <($out/bin/cheat --completion bash) \ + --fish <($out/bin/cheat --completion fish) \ + --zsh <($out/bin/cheat --completion zsh) ''; vendorHash = null; - doCheck = false; + doCheck = true; + + env.EDITOR = "cat"; meta = { description = "Create and view interactive cheatsheets on the command-line"; From 80398a84a27619079fee180adb3d6cd95ee06f83 Mon Sep 17 00:00:00 2001 From: kyehn Date: Sun, 6 Sep 2026 19:55:50 +0000 Subject: [PATCH 11/20] python3Packages.clickdc: init at 0.1.1 --- .../python-modules/clickdc/default.nix | 66 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 + 2 files changed, 68 insertions(+) create mode 100644 pkgs/development/python-modules/clickdc/default.nix diff --git a/pkgs/development/python-modules/clickdc/default.nix b/pkgs/development/python-modules/clickdc/default.nix new file mode 100644 index 000000000000..634f8cb46644 --- /dev/null +++ b/pkgs/development/python-modules/clickdc/default.nix @@ -0,0 +1,66 @@ +{ + lib, + buildPythonPackage, + fetchFromGitHub, + fetchpatch, + click, + typing-extensions, + setuptools, + pydantic, + pytestCheckHook, +}: + +buildPythonPackage (finalAttrs: { + pname = "clickdc"; + version = "0.1.1"; + pyproject = true; + + src = fetchFromGitHub { + owner = "Kamilcuk"; + repo = "clickdc"; + tag = finalAttrs.version; + hash = "sha256-pOMArEWmoDTWZWSK7IemuqP+lSqOZgzzP6xKtmpOS90="; + }; + + patches = [ + (fetchpatch { + name = "clickdc-fix-click-8.2-tests.patch"; + url = "https://github.com/Kamilcuk/clickdc/commit/906faf8dfc48ff4bde9b3e5eec19620fc5100927.patch"; + hash = "sha256-S6Wl/yotKD3RvqSp0Z3vNls7XnxgF42GBjeCrMWtIMQ="; + }) + (fetchpatch { + name = "clickdc-modernize-tests.patch"; + url = "https://github.com/Kamilcuk/clickdc/commit/83e79a4522b9070fd4bdad2f521f8f502380a7a9.patch"; + hash = "sha256-d2ZxFa2I5StDnJyDrgTHTIasyXcprBF6lcf5s7eGRRE="; + }) + ]; + + postPatch = '' + substituteInPlace pyproject.toml \ + --replace-fail '"setuptools-git-versioning<2",' "" \ + --replace-fail 'dynamic = ["version"]' 'version = "${finalAttrs.version}"' + ''; + + build-system = [ + setuptools + ]; + + dependencies = [ + click + typing-extensions + ]; + + nativeCheckInputs = [ + pydantic + pytestCheckHook + ]; + + pythonImportsCheck = [ "clickdc" ]; + + meta = { + description = "Define click command line options from a python dataclass"; + homepage = "https://github.com/Kamilcuk/clickdc"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ kyehn ]; + }; +}) diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 4c63e32eba85..0aa4fc69987b 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -3244,6 +3244,8 @@ self: super: with self; { clickclick = callPackage ../development/python-modules/clickclick { }; + clickdc = callPackage ../development/python-modules/clickdc { }; + clickgen = callPackage ../development/python-modules/clickgen { }; clickhouse-cityhash = callPackage ../development/python-modules/clickhouse-cityhash { }; From 9021890b0428969da33f50e06859a4a7fd4f9f56 Mon Sep 17 00:00:00 2001 From: kyehn Date: Sun, 6 Sep 2026 19:55:51 +0000 Subject: [PATCH 12/20] mycli: 1.44.2 -> 2.20.0 --- pkgs/by-name/my/mycli/package.nix | 48 ++++++++++++++++++++++++++----- 1 file changed, 41 insertions(+), 7 deletions(-) diff --git a/pkgs/by-name/my/mycli/package.nix b/pkgs/by-name/my/mycli/package.nix index c2719a2a2c59..bbe91377222d 100644 --- a/pkgs/by-name/my/mycli/package.nix +++ b/pkgs/by-name/my/mycli/package.nix @@ -7,20 +7,31 @@ python3Packages.buildPythonApplication (finalAttrs: { pname = "mycli"; - version = "1.44.2"; + version = "2.20.0"; pyproject = true; + # test_ssh_tunnel.py binds to localhost to find a free port; the darwin + # sandbox blocks loopback networking unless this is enabled + __darwinAllowLocalNetworking = true; + src = fetchFromGitHub { owner = "dbcli"; repo = "mycli"; tag = "v${finalAttrs.version}"; - hash = "sha256-7G7Yy0jdULzBiQr4JACWuBG4XdXDYZ8IyfbzGQKF428="; + hash = "sha256-jbEbyY5N6IY344sLiY9cjhPbwzHtNUJK4+SXkXU2lqM="; }; pythonRelaxDeps = [ - "sqlglot" # https://github.com/dbcli/mycli/issues/1696 + "pygments" + "pymysql" + "wcwidth" + "sqlglot" + "sqlglotc" "sqlparse" "click" + "cryptography" + "cli_helpers" + "yaspin" ]; build-system = with python3Packages; [ @@ -33,25 +44,48 @@ python3Packages.buildPythonApplication (finalAttrs: { [ cli-helpers click + clickdc configobj cryptography + jinja2 + keyring llm - paramiko prompt-toolkit pycryptodomex pygments pymysql pyperclip + rapidfuzz sqlglot sqlparse pyfzf + wcwidth ] - ++ cli-helpers.optional-dependencies.styles; + ++ cli-helpers.optional-dependencies.styles + ++ [ yaspin ]; - nativeCheckInputs = [ writableTmpDirAsHomeHook ] ++ (with python3Packages; [ pytestCheckHook ]); + nativeCheckInputs = [ + writableTmpDirAsHomeHook + ] + ++ (with python3Packages; [ + pytestCheckHook + pytest-random-order + ]); disabledTestPaths = [ - "mycli/packages/paramiko_stub/__init__.py" + # require optional polars dependency (not packaged) + "test/pytests/test_polars_transform.py" + "test/pytests/test_polars_completion.py" + ]; + + pytestFlags = [ + # environment-specific completion keyword differences + "--deselect=test/pytests/test_smart_completion_public_schema_only.py::test_backticked_column_completion_three_character" + "--deselect=test/pytests/test_smart_completion_public_schema_only.py::test_backticked_column_completion_two_character" + "--deselect=test/pytests/test_naive_completion.py::test_function_name_completion" + # bash completion harness is sensitive to the system bash version and + # exercises only the static completion script, not the packaged code + "--deselect=test/pytests/test_bash_completion.py::test_bash_completion_matches_mycli_completion_behavior" ]; meta = { From 5c5a16aec35ef2817c84b61f05d8c0d86baeb212 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 00:47:19 +0000 Subject: [PATCH 13/20] stashcat: 6.52.0 -> 6.54.1 --- pkgs/by-name/st/stashcat/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/st/stashcat/package.nix b/pkgs/by-name/st/stashcat/package.nix index 112e2e6429f4..33a0df51ec5b 100644 --- a/pkgs/by-name/st/stashcat/package.nix +++ b/pkgs/by-name/st/stashcat/package.nix @@ -24,11 +24,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "stashcat"; - version = "6.52.0"; + version = "6.54.1"; src = fetchurl { url = "http://deb.stashcat.com/repo01/dists/stashcat-dc/main/binary-amd64/stashcat-dc/${finalAttrs.pname}_${finalAttrs.version}_amd64.deb"; - hash = "sha512-z+riGE4cRsDy/jugkAaGJiQx9uys0ynjrTehOyYskWLX8Nzvqh18VSrrlAxsc0rUXNY0bFDQpFhStSMmQWLC7g=="; + hash = "sha512-S5YWA+X6W3PcwnbHSJ3rDFA1Y/tqTV2pbm+FZx2p9WeFvtSJnTELCPTWKGzbZTcGhU14Dj/ispRRqJdkmzoUPg=="; }; strictDeps = true; From 237afb11b7c05eb4365486a245ef5fd40c8efac9 Mon Sep 17 00:00:00 2001 From: Bobby Rong Date: Sat, 26 Sep 2026 10:17:36 +0800 Subject: [PATCH 14/20] timeshift: 25.12.4 -> 26.09.0 https://github.com/linuxmint/timeshift/compare/25.12.4...26.09.0 --- pkgs/applications/backup/timeshift/unwrapped.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/backup/timeshift/unwrapped.nix b/pkgs/applications/backup/timeshift/unwrapped.nix index 4d7b535eb8ae..1026d0ed6d44 100644 --- a/pkgs/applications/backup/timeshift/unwrapped.nix +++ b/pkgs/applications/backup/timeshift/unwrapped.nix @@ -18,7 +18,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "timeshift"; - version = "25.12.4"; + version = "26.09.0"; outputs = [ "out" "man" @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "linuxmint"; repo = "timeshift"; tag = finalAttrs.version; - hash = "sha256-4iK9RngcqwR0sYo9AXcTwEQ1eoPQPbAmwM5k/rcgU9s="; + hash = "sha256-mMG3rMC4wH8bpwfEntEJfFhn8gXoZf7iLraxTysttQ8="; }; postPatch = '' From 472e9e61c4e0a1d402f07ec0cd7f811e55167db4 Mon Sep 17 00:00:00 2001 From: Bobby Rong Date: Sat, 26 Sep 2026 10:18:23 +0800 Subject: [PATCH 15/20] xviewer: 3.4.16 -> 3.4.17 https://github.com/linuxmint/xviewer/compare/3.4.16...3.4.17 --- pkgs/by-name/xv/xviewer/package.nix | 13 ++----------- 1 file changed, 2 insertions(+), 11 deletions(-) diff --git a/pkgs/by-name/xv/xviewer/package.nix b/pkgs/by-name/xv/xviewer/package.nix index 1d1309d7792b..f69e97fd2092 100644 --- a/pkgs/by-name/xv/xviewer/package.nix +++ b/pkgs/by-name/xv/xviewer/package.nix @@ -2,7 +2,6 @@ stdenv, lib, fetchFromGitHub, - fetchpatch, docbook_xsl, exempi, gdk-pixbuf, @@ -35,23 +34,15 @@ stdenv.mkDerivation (finalAttrs: { pname = "xviewer"; - version = "3.4.16"; + version = "3.4.17"; src = fetchFromGitHub { owner = "linuxmint"; repo = "xviewer"; rev = finalAttrs.version; - hash = "sha256-ayd91gVLuSUVlCxaPSBbx7hg4tthVTaBEnl5V9YYbQw="; + hash = "sha256-U6p79pgiXdCLLnLZ4h3fvXj9UXG0atBccoBXGvAM5Yo="; }; - patches = [ - # build: Add support for GIRepository-2.0. - (fetchpatch { - url = "https://github.com/linuxmint/xviewer/commit/74d7d4ba2584c658ae6fb87208543671664943cc.patch"; - hash = "sha256-lL4MTvC2RvdVZ4O5RaYyK+1sHnLGPYzGNbZ99aN22U8="; - }) - ]; - nativeBuildInputs = [ docbook_xsl gobject-introspection From 73c648c62df73c870882b566252554d943ea7f76 Mon Sep 17 00:00:00 2001 From: Bobby Rong Date: Sat, 26 Sep 2026 10:18:42 +0800 Subject: [PATCH 16/20] xreader: 4.6.7 -> 4.6.9 https://github.com/linuxmint/xreader/compare/4.6.7...4.6.9 Fixes CVE-2026-19772. --- pkgs/by-name/xr/xreader/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/xr/xreader/package.nix b/pkgs/by-name/xr/xreader/package.nix index bb4aef24f9dd..f840b662a5f8 100644 --- a/pkgs/by-name/xr/xreader/package.nix +++ b/pkgs/by-name/xr/xreader/package.nix @@ -34,13 +34,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "xreader"; - version = "4.6.7"; + version = "4.6.9"; src = fetchFromGitHub { owner = "linuxmint"; repo = "xreader"; rev = finalAttrs.version; - hash = "sha256-mSaEVXwX6rErIEi9KxmMrGYunZFK8AbxNCTl8EJQGTM="; + hash = "sha256-D1ztYrdK9GyuHpq6xX44FsRyBYOr4oH9XAuMCkV8vcs="; }; nativeBuildInputs = [ From 308f4366d27eb8c31e3a9941b7885fd20e4e2b03 Mon Sep 17 00:00:00 2001 From: Bobby Rong Date: Sat, 26 Sep 2026 10:19:00 +0800 Subject: [PATCH 17/20] pix: 3.4.10 -> 3.4.11 https://github.com/linuxmint/pix/compare/3.4.10...3.4.11 --- pkgs/by-name/pi/pix/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pi/pix/package.nix b/pkgs/by-name/pi/pix/package.nix index 0d528588167f..34444ff9e65c 100644 --- a/pkgs/by-name/pi/pix/package.nix +++ b/pkgs/by-name/pi/pix/package.nix @@ -35,13 +35,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "pix"; - version = "3.4.10"; + version = "3.4.11"; src = fetchFromGitHub { owner = "linuxmint"; repo = "pix"; rev = finalAttrs.version; - hash = "sha256-IrRE2Bv2+DZMLI48at7npcAd3TSJRuZNzU/YbNK8x3k="; + hash = "sha256-iiqy/IsQE1o1tv5MjdhCOFQnTGheSSZsC/1UwDt2x24="; }; nativeBuildInputs = [ From 32675f4b929e987a020348df5a8c485e64e22311 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 26 Sep 2026 12:45:28 -0400 Subject: [PATCH 18/20] ci/github-script: convert various to TypeScript --- .github/workflows/lint.yml | 2 +- .github/workflows/merge-group.yml | 4 +- .github/workflows/test.yml | 14 +-- ci/README.md | 2 +- ci/github-script/bot.js | 2 +- .../check-target-branch-policy.ts | 2 +- ci/github-script/check-target-branch.ts | 4 +- ci/github-script/commits.ts | 4 +- ...it-details.js => get-pr-commit-details.ts} | 61 +++++++------ .../{lint-commits.js => lint-commits.ts} | 71 ++++++++------- ci/github-script/manual-file-edits.ts | 6 +- ci/github-script/merge.js | 2 +- ci/github-script/prepare.js | 8 +- ci/github-script/reminders.ts | 6 +- ci/github-script/{reviews.js => reviews.ts} | 86 ++++++++++--------- ci/github-script/run | 2 +- ...portedBranches.js => supportedBranches.ts} | 40 ++++++--- ci/github-script/supportedSystems.js | 11 --- ci/github-script/supportedSystems.ts | 30 +++++++ 19 files changed, 204 insertions(+), 153 deletions(-) rename ci/github-script/{get-pr-commit-details.js => get-pr-commit-details.ts} (72%) rename ci/github-script/{lint-commits.js => lint-commits.ts} (83%) rename ci/github-script/{reviews.js => reviews.ts} (82%) rename ci/github-script/{supportedBranches.js => supportedBranches.ts} (70%) delete mode 100644 ci/github-script/supportedSystems.js create mode 100644 ci/github-script/supportedSystems.ts diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index faa978b13227..11bf76a7dbd6 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -130,7 +130,7 @@ jobs: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | - const { default: checkCommitMessages } = await import('${{ github.workspace }}/trusted/ci/github-script/lint-commits.js') + const { default: checkCommitMessages } = await import('${{ github.workspace }}/trusted/ci/github-script/lint-commits.ts') await checkCommitMessages({ github, diff --git a/.github/workflows/merge-group.yml b/.github/workflows/merge-group.yml index e111c35ca7c8..e2ef4e77fe9c 100644 --- a/.github/workflows/merge-group.yml +++ b/.github/workflows/merge-group.yml @@ -38,8 +38,8 @@ jobs: TARGET_SHA: ${{ inputs.targetSha }} with: script: | - const { classify } = await import('${{ github.workspace }}/ci/github-script/supportedBranches.js') - const { default: supportedSystems } = await import('${{ github.workspace }}/ci/github-script/supportedSystems.js') + const { classify } = await import('${{ github.workspace }}/ci/github-script/supportedBranches.ts') + const { default: supportedSystems } = await import('${{ github.workspace }}/ci/github-script/supportedSystems.ts') const baseBranch = ( context.payload.merge_group?.base_ref ?? diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 35208ae4fab2..f5a6c1bfcec4 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -64,8 +64,8 @@ jobs: '.github/workflows/test.yml', 'ci/github-script/package.json', 'ci/github-script/package-lock.json', - 'ci/github-script/supportedBranches.js', - 'ci/github-script/supportedSystems.js', + 'ci/github-script/supportedBranches.ts', + 'ci/github-script/supportedSystems.ts', 'ci/pinned.json', 'pkgs/top-level/release-supported-systems.json', ].includes(file))) core.setOutput('merge-group', true) @@ -82,8 +82,8 @@ jobs: 'ci/github-script/bot.js', 'ci/github-script/check-target-branch.ts', 'ci/github-script/commits.ts', - 'ci/github-script/get-pr-commit-details.js', - 'ci/github-script/lint-commits.js', + 'ci/github-script/get-pr-commit-details.ts', + 'ci/github-script/lint-commits.ts', 'ci/github-script/manual-file-edits.ts', 'ci/github-script/merge.js', 'ci/github-script/package.json', @@ -91,9 +91,9 @@ jobs: 'ci/github-script/prepare.js', 'ci/github-script/reminders.ts', 'ci/github-script/reviewers.js', - 'ci/github-script/reviews.js', - 'ci/github-script/supportedBranches.js', - 'ci/github-script/supportedSystems.js', + 'ci/github-script/reviews.ts', + 'ci/github-script/supportedBranches.ts', + 'ci/github-script/supportedSystems.ts', 'ci/github-script/withRateLimit.js', 'ci/pinned.json', 'pkgs/top-level/release-supported-systems.json', diff --git a/ci/README.md b/ci/README.md index 992ed92ed3ac..dfdf736ae711 100644 --- a/ci/README.md +++ b/ci/README.md @@ -104,7 +104,7 @@ For the purposes of CI, branches in the NixOS/nixpkgs repository are classified Some branches also have a version component, which is either `unstable` or `YY.MM`. -`ci/github-script/supportedBranches.js` is a script imported by CI to classify the base and head branches of a Pull Request. +`ci/github-script/supportedBranches.ts` is a script imported by CI to classify the base and head branches of a Pull Request. This classification will then be used to skip certain jobs. This script can also be run locally to print basic test cases. diff --git a/ci/github-script/bot.js b/ci/github-script/bot.js index efb5f4935aa8..13c7978cbb55 100644 --- a/ci/github-script/bot.js +++ b/ci/github-script/bot.js @@ -4,7 +4,7 @@ import path from 'node:path' import { DefaultArtifactClient } from '@actions/artifact' import { handleMerge } from './merge.js' import { handleReviewers } from './reviewers.js' -import { classify } from './supportedBranches.js' +import { classify } from './supportedBranches.ts' import withRateLimit from './withRateLimit.js' export default async ({ github, context, core, dry }) => { diff --git a/ci/github-script/check-target-branch-policy.ts b/ci/github-script/check-target-branch-policy.ts index a5367ded6925..bf1dc2215e3c 100644 --- a/ci/github-script/check-target-branch-policy.ts +++ b/ci/github-script/check-target-branch-policy.ts @@ -1,4 +1,4 @@ -import { classify, split } from './supportedBranches.js' +import { classify, split } from './supportedBranches.ts' type TargetBranchPolicyFacts = { base: string diff --git a/ci/github-script/check-target-branch.ts b/ci/github-script/check-target-branch.ts index b12c2aa9d68b..709256ba6518 100644 --- a/ci/github-script/check-target-branch.ts +++ b/ci/github-script/check-target-branch.ts @@ -6,8 +6,8 @@ import { evaluateTargetBranchPolicy, getTargetBranchPolicy, } from './check-target-branch-policy.ts' -import { dismissReviews, postReview } from './reviews.js' -import { split } from './supportedBranches.js' +import { dismissReviews, postReview } from './reviews.ts' +import { split } from './supportedBranches.ts' // TODO: should this be combined with the branch checks in prepare.js? // They do seem quite similar, but this needs to run after eval, diff --git a/ci/github-script/commits.ts b/ci/github-script/commits.ts index a1fbceda6589..ef8098f95d14 100644 --- a/ci/github-script/commits.ts +++ b/ci/github-script/commits.ts @@ -2,8 +2,8 @@ import { execFileSync } from 'node:child_process' import type * as actionsCore from '@actions/core' import type { context as actionsContext } from '@actions/github' import type { GitHub } from '@actions/github/lib/utils' -import { dismissReviews, postReview } from './reviews.js' -import { classify } from './supportedBranches.js' +import { dismissReviews, postReview } from './reviews.ts' +import { classify } from './supportedBranches.ts' import withRateLimit from './withRateLimit.js' const dirname = import.meta.dirname diff --git a/ci/github-script/get-pr-commit-details.js b/ci/github-script/get-pr-commit-details.ts similarity index 72% rename from ci/github-script/get-pr-commit-details.js rename to ci/github-script/get-pr-commit-details.ts index a1355e96af24..09b442a06531 100644 --- a/ci/github-script/get-pr-commit-details.js +++ b/ci/github-script/get-pr-commit-details.ts @@ -3,26 +3,23 @@ import { promisify } from 'node:util' const execFile = promisify(nodeExecFile) -/** - * @typedef {{ - * subject: string, - * sha: string, - * author: { name: string, email: string }, - * committer: { name: string, email: string} - * changedPaths: string[], - * changedPathSegments: Set, - * }} Commit - */ +export type Commit = { + subject: string + sha: string + author: { name: string; email: string } + committer: { name: string; email: string } + changedPaths: string[] + changedPathSegments: Set +} -/** - * @param {{ - * args: string[] - * core: typeof import('@actions/core'), - * quiet?: boolean, - * repoPath?: string, - * }} RunGitProps - */ -async function runGit({ args, repoPath, core, quiet }) { +interface RunGitProps { + args: string[] + core: typeof import('@actions/core') + quiet?: boolean + repoPath?: string +} + +async function runGit({ args, repoPath, core, quiet }: RunGitProps) { if (repoPath) { args = ['-C', repoPath, ...args] } @@ -34,21 +31,29 @@ async function runGit({ args, repoPath, core, quiet }) { return await execFile('git', args) } +interface GetCommitMessagesForPRProps { + core: typeof import('@actions/core') + pr: Awaited< + ReturnType< + InstanceType< + typeof import('@actions/github/lib/utils').GitHub + >['rest']['pulls']['get'] + > + >['data'] + repoPath?: string +} + /** * Gets the SHA, subject and changed files for each commit in the given PR. * * Don't use GitHub API at all: the "list commits on PR" endpoint has a limit * of 250 commits and doesn't return the changed files. - * - * @param {{ - * core: typeof import('@actions/core'), - * pr: Awaited["rest"]["pulls"]["get"]>>["data"] - * repoPath?: string, - * }} GetCommitMessagesForPRProps - * - * @returns {Promise} */ -export async function getCommitDetailsForPR({ core, pr, repoPath }) { +export async function getCommitDetailsForPR({ + core, + pr, + repoPath, +}: GetCommitMessagesForPRProps): Promise { await runGit({ args: ['fetch', `--depth=1`, 'origin', pr.base.sha], repoPath, diff --git a/ci/github-script/lint-commits.js b/ci/github-script/lint-commits.ts similarity index 83% rename from ci/github-script/lint-commits.js rename to ci/github-script/lint-commits.ts index bbeea0990213..0c83f6636a85 100644 --- a/ci/github-script/lint-commits.js +++ b/ci/github-script/lint-commits.ts @@ -1,17 +1,23 @@ -import { getCommitDetailsForPR } from './get-pr-commit-details.js' -import { classify } from './supportedBranches.js' +import { type Commit, getCommitDetailsForPR } from './get-pr-commit-details.ts' +import { classify } from './supportedBranches.ts' -/** @typedef {import('./get-pr-commit-details.js').Commit} Commit */ +type GitHub = InstanceType +type Context = typeof import('@actions/github').context +type Core = typeof import('@actions/core') -/** - * @param {{ - * github: InstanceType, - * context: typeof import('@actions/github').context, - * core: typeof import('@actions/core'), - * repoPath?: string, - * }} LintCommitsProps - */ -export default async function lintCommits({ github, context, core, repoPath }) { +interface LintCommitsProps { + github: GitHub + context: Context + core: Core + repoPath?: string +} + +export default async function lintCommits({ + github, + context, + core, + repoPath, +}: LintCommitsProps) { // This check should only be run when we have the pull_request context. const pull_number = context.payload.pull_request?.number if (!pull_number) { @@ -53,13 +59,15 @@ export default async function lintCommits({ github, context, core, repoPath }) { await checkCommitMetadata({ commits, core }) } -/** - * @param {{ - * commits: Commit[], - * core: typeof import('@actions/core'), - * }} CheckCommitMessagesProps - */ -async function checkCommitMessages({ commits, core }) { +interface CheckCommitMessagesProps { + commits: Commit[] + core: Core +} + +async function checkCommitMessages({ + commits, + core, +}: CheckCommitMessagesProps) { const failures = new Set() const conventionalCommitTypes = [ @@ -80,10 +88,13 @@ async function checkCommitMessages({ commits, core }) { ] /** - * @param {string[]} types e.g. ["fix", "feat"] - * @param {string?} sha commit hash + * @param types e.g. ["fix", "feat"] + * @param sha commit hash */ - function makeConventionalCommitRegex(types, sha = null) { + function makeConventionalCommitRegex( + types: string[], + sha: string | null = null, + ) { core.info( `${ sha @@ -166,17 +177,15 @@ async function checkCommitMessages({ commits, core }) { } } -/** - * @param {{ - * commits: Commit[], - * core: typeof import('@actions/core'), - * }} CheckGitFieldsProps - */ -async function checkCommitMetadata({ commits, core }) { +interface CheckGitFieldsProps { + commits: Commit[] + core: Core +} + +async function checkCommitMetadata({ commits, core }: CheckGitFieldsProps) { const failures = new Set() - /** @type {(s: string) => boolean} */ - const isEmail = (s) => /^.+@.*$/.test(s) + const isEmail = (s: string) => /^.+@.*$/.test(s) for (const commit of commits) { if (!commit.author.name) { diff --git a/ci/github-script/manual-file-edits.ts b/ci/github-script/manual-file-edits.ts index f544071dbb78..3cd70e5beb6b 100644 --- a/ci/github-script/manual-file-edits.ts +++ b/ci/github-script/manual-file-edits.ts @@ -1,6 +1,6 @@ -import { getCommitDetailsForPR } from './get-pr-commit-details.js' -import { dismissReviews, postReview } from './reviews.js' -import { classify } from './supportedBranches.js' +import { getCommitDetailsForPR } from './get-pr-commit-details.ts' +import { dismissReviews, postReview } from './reviews.ts' +import { classify } from './supportedBranches.ts' export default async function checkManualFileEdits({ github, diff --git a/ci/github-script/merge.js b/ci/github-script/merge.js index 367d70c415f4..904cb3cbdd79 100644 --- a/ci/github-script/merge.js +++ b/ci/github-script/merge.js @@ -1,5 +1,5 @@ // @ts-nocheck -import { classify } from './supportedBranches.js' +import { classify } from './supportedBranches.ts' function runChecklist({ committers, diff --git a/ci/github-script/prepare.js b/ci/github-script/prepare.js index 1ba90b5fe232..7a4fcc1f1fb1 100644 --- a/ci/github-script/prepare.js +++ b/ci/github-script/prepare.js @@ -1,7 +1,7 @@ // @ts-nocheck -import { dismissReviews, postReview } from './reviews.js' -import { classify } from './supportedBranches.js' -import supportedSystems from './supportedSystems.js' +import { dismissReviews, postReview } from './reviews.ts' +import { classify } from './supportedBranches.ts' +import supportedSystems from './supportedSystems.ts' const reviewKey = 'prepare' @@ -66,7 +66,7 @@ export default async ({ github, context, core, dry }) => { // commits between that base and head is the real base. We can query for this via GitHub's // REST API. There can be multiple candidates for the real base with the same number of // commits. In this case we pick the "best" candidate by a fixed ordering of branches, - // as defined in ci/github-script/supportedBranches.js. + // as defined in ci/github-script/supportedBranches.ts. // // These requests take a while, when comparing against the wrong release - they need // to look at way more than 10k commits in that case. Thus, we try to minimize the diff --git a/ci/github-script/reminders.ts b/ci/github-script/reminders.ts index 49431c752149..98d58af95da4 100644 --- a/ci/github-script/reminders.ts +++ b/ci/github-script/reminders.ts @@ -3,9 +3,9 @@ import path from 'node:path' import type * as actionsCore from '@actions/core' import type { context as actionsContext } from '@actions/github' import type { GitHub } from '@actions/github/lib/utils' -import { getCommitDetailsForPR } from './get-pr-commit-details.js' -import { dismissReviews, postReview } from './reviews.js' -import { classify } from './supportedBranches.js' +import { getCommitDetailsForPR } from './get-pr-commit-details.ts' +import { dismissReviews, postReview } from './reviews.ts' +import { classify } from './supportedBranches.ts' /** * Reminders to post as a non-blocking review when a pull request touches diff --git a/ci/github-script/reviews.js b/ci/github-script/reviews.ts similarity index 82% rename from ci/github-script/reviews.js rename to ci/github-script/reviews.ts index e47270386f1e..be4168e0c549 100644 --- a/ci/github-script/reviews.js +++ b/ci/github-script/reviews.ts @@ -13,30 +13,28 @@ const reviewUsers = [ 'manual-edit', ] -/** - * @typedef {InstanceType} GitHub - * @typedef {typeof import('@actions/github').context} Context - * - * @typedef {Awaited>['data'][number]} Review - * @typedef {Review & { user: NonNullable }} ReviewWithNonNullUser - */ +type GitHub = InstanceType +type Context = typeof import('@actions/github').context +type Review = Awaited< + ReturnType +>['data'][number] +type ReviewWithNonNullUser = Review & { user: NonNullable } + +interface DismissReviewsProps { + github: GitHub + context: Context + core: typeof import('@actions/core') + dry: boolean + reviewKey?: string +} -/** - * @param {{ - * github: GitHub, - * context: Context, - * core: typeof import('@actions/core'), - * dry: boolean, - * reviewKey?: string, - * }} DismissReviewsProps - */ export async function dismissReviews({ github, context, core, dry, reviewKey, -}) { +}: DismissReviewsProps) { const pull_number = context.payload.pull_request?.number if (!pull_number) { core.warning('dismissReviews called outside of pull_request context') @@ -47,23 +45,29 @@ export async function dismissReviews({ return } - const allReviews = await github.paginate(github.rest.pulls.listReviews, { - ...context.repo, - pull_number, - }) + const allReviews: Review[] = await github.paginate( + github.rest.pulls.listReviews, + { + ...context.repo, + pull_number, + }, + ) - const reviews = /** @type {ReviewWithNonNullUser[]} */ ( - allReviews.filter( + const reviews = allReviews + .filter((review): review is ReviewWithNonNullUser => !!review.user) + .filter( (review) => - review.user && review.state !== 'DISMISSED' && review.user.login.endsWith('[bot]') && reviewUsers.some((substr) => review.user?.login.includes(substr)), ) - ) const reviewsByUser = reviews.reduce( (prev, curr) => { + if (!curr.user) { + return prev + } + if (!(curr.user.login in prev)) { prev[curr.user.login] = [] } @@ -72,7 +76,7 @@ export async function dismissReviews({ return prev }, - /** @type {Record } */ ({}), + {} as Record, ) const commentRegex = new RegExp( @@ -86,8 +90,8 @@ export async function dismissReviews({ ) let reviewsToMinimize = reviews - const /** @type {ReviewWithNonNullUser[]} */ reviewsToDismiss = [] - const /** @type {ReviewWithNonNullUser[]} */ reviewsToResolve = [] + const reviewsToDismiss: ReviewWithNonNullUser[] = [] + const reviewsToResolve: ReviewWithNonNullUser[] = [] if (reviewKey && reviews.every((review) => commentRegex.test(review.body))) { reviewsToMinimize = reviews.filter((review) => @@ -165,17 +169,16 @@ export async function dismissReviews({ ]) } -/** - * @param {{ - * github: GitHub, - * context: Context, - * core: typeof import('@actions/core'), - * dry: boolean, - * body: string, - * event: keyof typeof eventToState, - * reviewKey: string, - * }} PostReviewProps - */ +interface PostReviewProps { + github: GitHub + context: Context + core: typeof import('@actions/core') + dry: boolean + body: string + event: keyof typeof eventToState + reviewKey: string +} + export async function postReview({ github, context, @@ -184,7 +187,7 @@ export async function postReview({ body, event = 'REQUEST_CHANGES', reviewKey, -}) { +}: PostReviewProps) { const pull_number = context.payload.pull_request?.number if (!pull_number) { core.warning('postReview called outside of pull_request context') @@ -210,8 +213,7 @@ export async function postReview({ reviewUsers.some((substr) => review.user?.login.includes(substr)), ) - /** @type {null | Review} */ - let pendingReview + let pendingReview: null | Review const matchingReviews = reviews.filter((review) => reviewKeyRegex.test(review.body), ) diff --git a/ci/github-script/run b/ci/github-script/run index 001d3e201a2b..2920ae8b6f44 100755 --- a/ci/github-script/run +++ b/ci/github-script/run @@ -101,7 +101,7 @@ program .argument('', 'Name of the GitHub repository to run on (Example: nixpkgs)') .argument('', 'Number of the Pull Request to run on') .action(async (owner, repo, pr, options) => { - const checkCommitMessages = (await import('./lint-commits.js')).default + const checkCommitMessages = (await import('./lint-commits.ts')).default await run(checkCommitMessages, owner, repo, pr, options) }) diff --git a/ci/github-script/supportedBranches.js b/ci/github-script/supportedBranches.ts similarity index 70% rename from ci/github-script/supportedBranches.js rename to ci/github-script/supportedBranches.ts index bcb3518cde5c..cb947691ca61 100755 --- a/ci/github-script/supportedBranches.js +++ b/ci/github-script/supportedBranches.ts @@ -2,11 +2,12 @@ /* #!nix-shell -i node -p nodejs */ -// @ts-nocheck import { resolve } from 'node:path' import { fileURLToPath } from 'node:url' -const typeConfig = { +type BranchType = 'channel' | 'development' | 'primary' | 'secondary' + +const typeConfig: Record = { master: ['development', 'primary'], release: ['development', 'primary'], staging: ['development', 'secondary'], @@ -19,7 +20,7 @@ const typeConfig = { // "order" ranks the development branches by how likely they are the intended base branch // when they are an otherwise equally good fit according to ci/github-script/prepare.js. -const orderConfig = { +const orderConfig: Record = { master: 0, release: 1, staging: 2, @@ -28,15 +29,30 @@ const orderConfig = { 'staging-next': 4, } -function split(branch) { - return { - ...branch.match( - /(?.+?)(-(?\d{2}\.\d{2}|unstable)(?:-(?.*))?)?$/, - ).groups, - } +type Digit = 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 +type Version = `${Digit}${Digit}.${Digit}${Digit}` | 'unstable' +interface SplitResult { + prefix: string + version: Version + suffix?: string } -function classify(branch) { +function split(branch: string) { + const groups = branch.match( + /(?.+?)(-(?\d{2}\.\d{2}|unstable)(?:-(?.*))?)?$/, + )!.groups! + return groups as unknown as SplitResult +} + +interface BranchClassification { + branch: string + order: number + stable: boolean + type: BranchType[] + version: Version +} + +function classify(branch: string): BranchClassification { const { prefix, version } = split(branch) return { branch, @@ -55,7 +71,7 @@ if ( fileURLToPath(import.meta.url) === resolve(process.argv[1]) ) { console.log('split(branch)') - function testSplit(branch) { + function testSplit(branch: string) { console.log(branch, split(branch)) } testSplit('master') @@ -72,7 +88,7 @@ if ( console.log('') console.log('classify(branch)') - function testClassify(branch) { + function testClassify(branch: string) { console.log(branch, classify(branch)) } testClassify('master') diff --git a/ci/github-script/supportedSystems.js b/ci/github-script/supportedSystems.js deleted file mode 100644 index d035c3fee230..000000000000 --- a/ci/github-script/supportedSystems.js +++ /dev/null @@ -1,11 +0,0 @@ -// @ts-nocheck -export default async ({ github, context, targetSha }) => { - const { content, encoding } = ( - await github.rest.repos.getContent({ - ...context.repo, - path: 'pkgs/top-level/release-supported-systems.json', - ref: targetSha, - }) - ).data - return JSON.parse(Buffer.from(content, encoding).toString()) -} diff --git a/ci/github-script/supportedSystems.ts b/ci/github-script/supportedSystems.ts new file mode 100644 index 000000000000..dd9e898bddd8 --- /dev/null +++ b/ci/github-script/supportedSystems.ts @@ -0,0 +1,30 @@ +interface SupportedSystemsProps { + github: InstanceType + context: typeof import('@actions/github').context + targetSha: string +} + +export default async ({ + github, + context, + targetSha, +}: SupportedSystemsProps) => { + const contentObject = ( + await github.rest.repos.getContent({ + ...context.repo, + path: 'pkgs/top-level/release-supported-systems.json', + ref: targetSha, + }) + ).data + + if ('type' in contentObject && contentObject.type === 'file') { + const { content, encoding } = contentObject + return JSON.parse( + Buffer.from(content, encoding as BufferEncoding).toString(), + ) + } else { + throw new Error( + 'Fetched pkgs/top-level/release-supported-systems.json is not a file', + ) + } +} From 45f06483c572a6c5f8844736ab362deb335c6bc3 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 27 Sep 2026 02:00:15 +0000 Subject: [PATCH 19/20] limine-full: 12.9.0 -> 12.9.1 --- pkgs/by-name/li/limine/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/limine/package.nix b/pkgs/by-name/li/limine/package.nix index 462090b18faf..d04de03f5197 100644 --- a/pkgs/by-name/li/limine/package.nix +++ b/pkgs/by-name/li/limine/package.nix @@ -47,14 +47,14 @@ in # as bootloader for various platforms and corresponding binary and helper files. stdenv.mkDerivation (finalAttrs: { pname = "limine"; - version = "12.9.0"; + version = "12.9.1"; # We don't use the Git source but the release tarball, as the source has a # `./bootstrap` script performing network access to download resources. # Packaging that in Nix is very cumbersome. src = fetchurl { url = "https://github.com/Limine-Bootloader/Limine/releases/download/v${finalAttrs.version}/limine-${finalAttrs.version}.tar.gz"; - hash = "sha256-reqSKvO5yBeaRna87Mjk3y8+9yrTaz9K+rRMv18mXjY="; + hash = "sha256-7nxJhnDQ0WyJfss5HNg3zTdQgc/TZL0xmNsUTJKqzLQ="; }; enableParallelBuilding = true; From b6d2175d999934467c5e4646f378566a979b53c8 Mon Sep 17 00:00:00 2001 From: "Adam C. Stephens" Date: Sat, 26 Sep 2026 22:46:38 -0400 Subject: [PATCH 20/20] omp: 18.2.11 -> 18.3.3 Changelog: https://github.com/can1357/oh-my-pi/releases/tag/v18.3.3 --- pkgs/by-name/om/omp/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/om/omp/package.nix b/pkgs/by-name/om/omp/package.nix index 2960de490ee4..0dbc26ef5ff0 100644 --- a/pkgs/by-name/om/omp/package.nix +++ b/pkgs/by-name/om/omp/package.nix @@ -32,7 +32,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "omp"; - version = "18.2.11"; + version = "18.3.3"; strictDeps = true; __structuredAttrs = true; @@ -41,12 +41,12 @@ stdenv.mkDerivation (finalAttrs: { owner = "can1357"; repo = "oh-my-pi"; tag = "v${finalAttrs.version}"; - hash = "sha256-xzkxOCQbvCRE1I4gYKhnoKBQXpuaFjO+QiZKhVk4TlE="; + hash = "sha256-wyLc5yebo3EswxilJBxYVoXBon58to3OlaxIllq4ZQA="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) src; - hash = "sha256-9tQE1Kg2sVSn7KBHMA1JgvI4kQbc1pTNgv9gXwnsuN0="; + hash = "sha256-NquckJxx4Ibfy3PjUtxL+vfTceavMLRAaEgbqqneFsM="; }; postPatch = '' @@ -91,7 +91,7 @@ stdenv.mkDerivation (finalAttrs: { # Prevents breaking symlinks in node_modules dontFixup = true; - outputHash = "sha256-di12mFSglfXGN2duxDS5wZcevCiGI9+t4SaQ5mjpi7Y="; + outputHash = "sha256-0SpMVoWelw3FVNaDfM8yndXRrXb6K03xxoC7mym6hec="; outputHashMode = "recursive"; };