From e6d03305e955968d9ccba419cbd654371911d859 Mon Sep 17 00:00:00 2001 From: Marcin Serwin Date: Sat, 1 Aug 2026 10:44:48 +0200 Subject: [PATCH 01/31] gn: enable strictDeps and __structuredAttrs Signed-off-by: Marcin Serwin (cherry picked from commit f048aa98ac4b8aa747f7e4fe3bd87c3e13af4fda) --- pkgs/by-name/gn/gn/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/gn/gn/package.nix b/pkgs/by-name/gn/gn/package.nix index 66f02fcc542a..27ad2436fb53 100644 --- a/pkgs/by-name/gn/gn/package.nix +++ b/pkgs/by-name/gn/gn/package.nix @@ -36,6 +36,9 @@ stdenv.mkDerivation { ''; }; + strictDeps = true; + __structuredAttrs = true; + nativeBuildInputs = [ ninja python3 From e2da080c235ff6f53eab038152acfe167195025c Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 12 Jul 2026 12:58:53 +0200 Subject: [PATCH 02/31] python3Packages.inline-snapshot: 0.32.5 -> 0.34.2 https://redirect.github.com/15r10nk/inline-snapshot/blob/0.34.2/CHANGELOG.md (cherry picked from commit 279d557d56951d86357c504a0b6c7a65e63fca09) --- pkgs/development/python-modules/inline-snapshot/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/inline-snapshot/default.nix b/pkgs/development/python-modules/inline-snapshot/default.nix index 56968ab958bb..fd694d13f53d 100644 --- a/pkgs/development/python-modules/inline-snapshot/default.nix +++ b/pkgs/development/python-modules/inline-snapshot/default.nix @@ -21,14 +21,14 @@ buildPythonPackage rec { pname = "inline-snapshot"; - version = "0.32.5"; + version = "0.34.2"; pyproject = true; src = fetchFromGitHub { owner = "15r10nk"; repo = "inline-snapshot"; tag = version; - hash = "sha256-xnooMIm0UiNOWrZ4JZwbpFzliGsTF7b1DAXi1fxMb30="; + hash = "sha256-4Uvc925/6RxJRHjP3SZaB7T+gqky5KlL9agHy/14Jd0="; }; build-system = [ hatchling ]; From f3b33c28c8675bcf679293d04c9afd39db131ec9 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Mon, 13 Jul 2026 23:33:17 +0200 Subject: [PATCH 03/31] python3Packages.hypothesis-jsonschema: init at 0.23.1 New dependency for datamodel-code-generator. (cherry picked from commit 31280770c23ff95c1422ba3ebdd9514d9745fb18) --- .../hypothesis-jsonschema/default.nix | 50 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 + 2 files changed, 52 insertions(+) create mode 100644 pkgs/development/python-modules/hypothesis-jsonschema/default.nix diff --git a/pkgs/development/python-modules/hypothesis-jsonschema/default.nix b/pkgs/development/python-modules/hypothesis-jsonschema/default.nix new file mode 100644 index 000000000000..e57b566a2874 --- /dev/null +++ b/pkgs/development/python-modules/hypothesis-jsonschema/default.nix @@ -0,0 +1,50 @@ +{ + lib, + buildPythonPackage, + fetchPypi, + setuptools, + hypothesis, + jsonschema, + pytest-cov-stub, + pytestCheckHook, +}: + +buildPythonPackage (finalAttrs: { + pname = "hypothesis-jsonschema"; + version = "0.23.1"; + pyproject = true; + + __structuredAttrs = true; + + # no git tags + src = fetchPypi { + inherit (finalAttrs) pname version; + hash = "sha256-9KwDICQ0KkFJoQJTmE9aVza4Kz/ir7CIjzg0oxFT8hU="; + }; + + build-system = [ + setuptools + ]; + + dependencies = [ + hypothesis + jsonschema + ]; + + doCheck = false; # sdist does not include everything to run the tests + + nativeCheckInputs = [ + pytest-cov-stub + pytestCheckHook + ]; + + pythonImportsCheck = [ + "hypothesis_jsonschema" + ]; + + meta = { + description = "Generate test data from JSON schemata with Hypothesis"; + homepage = "https://github.com/Zac-HD/hypothesis-jsonschema"; + license = lib.licenses.mpl20; + }; +}) diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 2f865c268a02..049f6316df85 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -7415,6 +7415,8 @@ self: super: with self; { hypothesis-auto = callPackage ../development/python-modules/hypothesis-auto { }; + hypothesis-jsonschema = callPackage ../development/python-modules/hypothesis-jsonschema { }; + hypothesis_6_136 = callPackage ../development/python-modules/hypothesis/hypothesis_6_136.nix { }; hypothesmith = callPackage ../development/python-modules/hypothesmith { }; From ac83a6b435695499a2b5b1235083bdbe8be995e5 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Mon, 13 Jul 2026 23:17:44 +0200 Subject: [PATCH 04/31] python3Packages.datamodel-code-generator: 0.55.0 -> 0.68.1 https://redirect.github.com/koxudaxi/datamodel-code-generator/releases/tag/0.68.1 (cherry picked from commit e5ffb383ad62b16419e03087f472955737905964) --- .../datamodel-code-generator/default.nix | 26 ++++++++++++++++--- 1 file changed, 23 insertions(+), 3 deletions(-) diff --git a/pkgs/development/python-modules/datamodel-code-generator/default.nix b/pkgs/development/python-modules/datamodel-code-generator/default.nix index 03a7611f9453..f7d11b92ee19 100644 --- a/pkgs/development/python-modules/datamodel-code-generator/default.nix +++ b/pkgs/development/python-modules/datamodel-code-generator/default.nix @@ -3,15 +3,21 @@ argcomplete, black, buildPythonPackage, + email-validator, fetchFromGitHub, genson, graphql-core, + grpcio-tools, hatch-vcs, hatchling, httpx, + hypothesis, + hypothesis-jsonschema, inflect, inline-snapshot, isort, + jsonschema, + msgspec, jinja2, openapi-spec-validator, packaging, @@ -20,6 +26,8 @@ pydantic, pysnooper, pytest-mock, + pytest-timeout, + pytest-xdist, pytestCheckHook, pyyaml, time-machine, @@ -28,14 +36,14 @@ buildPythonPackage rec { pname = "datamodel-code-generator"; - version = "0.55.0"; + version = "0.68.1"; pyproject = true; src = fetchFromGitHub { owner = "koxudaxi"; repo = "datamodel-code-generator"; tag = version; - hash = "sha256-zsLJv7gKhmnEIS/AUvnBzm+07QFQoMdiFo/PkfRyHek="; + hash = "sha256-fYnI7S4FJ927qZXyAsWQzxhLTrcpscYqJunmcSt/gkk="; }; pythonRelaxDeps = [ @@ -65,6 +73,7 @@ buildPythonPackage rec { debug = [ pysnooper ]; graphql = [ graphql-core ]; http = [ httpx ]; + protobuf = [ grpcio-tools ]; ruff = [ ruff ]; validation = [ openapi-spec-validator @@ -76,20 +85,31 @@ buildPythonPackage rec { }; nativeCheckInputs = [ + email-validator inline-snapshot + hypothesis + hypothesis-jsonschema + jsonschema + msgspec pytest-mock + pytest-timeout + pytest-xdist pytestCheckHook time-machine ] ++ optional-dependencies.all; - pythonImportsCheck = [ "datamodel_code_generator" ]; + pytestFlags = [ + "--maxfail=2" + ]; disabledTests = [ # remote testing, name resolution failure. "test_openapi_parser_parse_remote_ref" ]; + pythonImportsCheck = [ "datamodel_code_generator" ]; + meta = { description = "Pydantic model and dataclasses.dataclass generator for easy conversion of JSON, OpenAPI, JSON Schema, and YAML data sources"; homepage = "https://github.com/koxudaxi/datamodel-code-generator"; From 1f433c15d7e03bd9b887a6dc9dbc65c7fd3f4f18 Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Mon, 27 Jul 2026 16:21:55 +0200 Subject: [PATCH 05/31] python3Packages.datamodel-code-generator: 0.68.1 -> 0.71.0 Update to the latest stable release, which rejects unsafe customBasePath values before generating Python imports. https://redirect.github.com/koxudaxi/datamodel-code-generator/releases/tag/0.71.0 Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) (cherry picked from commit 2cd3018868fd4766b709b5b65c1c18adbf06076d) --- .../python-modules/datamodel-code-generator/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/datamodel-code-generator/default.nix b/pkgs/development/python-modules/datamodel-code-generator/default.nix index f7d11b92ee19..e542fbc0acbb 100644 --- a/pkgs/development/python-modules/datamodel-code-generator/default.nix +++ b/pkgs/development/python-modules/datamodel-code-generator/default.nix @@ -36,14 +36,14 @@ buildPythonPackage rec { pname = "datamodel-code-generator"; - version = "0.68.1"; + version = "0.71.0"; pyproject = true; src = fetchFromGitHub { owner = "koxudaxi"; repo = "datamodel-code-generator"; tag = version; - hash = "sha256-fYnI7S4FJ927qZXyAsWQzxhLTrcpscYqJunmcSt/gkk="; + hash = "sha256-0vh/iynZzmMzvdUXNScb+JWANdSrzPLT1qt+jyKleg4="; }; pythonRelaxDeps = [ From b5e044308f120cbcaaeff4b5c9326c48739c3ff6 Mon Sep 17 00:00:00 2001 From: Sergei Zimmerman Date: Mon, 27 Jul 2026 22:37:12 +0300 Subject: [PATCH 06/31] boost: backport regression fixes for boost.context Applies the fixes for 1.88 regressions that have caused widespread breakage in Nix. Currently we are building with 1.89, so only 2 fixes are relevant [1,2], with the second patch being backported to avoid conflicts - the issue it addresses doesn't blow up in nix - but it does in userver and other stuff too probably. The third patch was authored by NaN-git to unbreak nix with 1.89, so we apply it to 1.88 (the initial version that had the fiber-specific exception state changes with fcontext and libstdc++). This is mostly for consistency and unbreak boost.context on that version. [1]: https://github.com/boostorg/context/pull/337 [2]: https://github.com/boostorg/context/pull/331 (cherry picked from commit 7bb72161e1de8ad847ab8e806e75f3488059be06) --- pkgs/development/libraries/boost/generic.nix | 29 ++++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/pkgs/development/libraries/boost/generic.nix b/pkgs/development/libraries/boost/generic.nix index 09e6aa28c567..f488a3bfce9c 100644 --- a/pkgs/development/libraries/boost/generic.nix +++ b/pkgs/development/libraries/boost/generic.nix @@ -193,6 +193,35 @@ stdenv.mkDerivation { extraPrefix = "libs/context/"; sha256 = "sha256-bCfLL7bD1Rn4Ie/P3X+nIcgTkbXdCX6FW7B9lHsmVW8="; }) + # Backports https://github.com/boostorg/context/pull/331, which prevents + # an optimisation that breaks coroutine migration between threads. + # (mostly needed to avoid conflicts when applying the patch below, + # but it's a meaningful standalone fix too). + ++ + lib.optional (lib.versionAtLeast version "1.88.0" && lib.versionOlder version "1.92.0") + (fetchpatch { + url = "https://github.com/boostorg/context/commit/0921b9fd5c776aec7748475c6c10807e0d51bc6d.patch"; + relative = "include"; + hash = "sha256-nQYMd3HFsDLxijnGdyas0ZHs3ylQVMGQL14K7F6MkF0="; + }) + # Backports https://github.com/boostorg/context/pull/337 which fixes a regression that breaks + # std::uncaught_exceptions for abandoned coroutines under libstdc++ and fcontext implementation. + # This bug also caused subtle breakage in Nix. See https://github.com/NixOS/nix/issues/16174. + ++ + lib.optional (lib.versionAtLeast version "1.88.0" && lib.versionOlder version "1.93.0") + (fetchpatch { + url = "https://github.com/boostorg/context/commit/5883212311535a0046031d74d1568ae173c1e35b.patch"; + relative = "include"; + hash = "sha256-CytNLi2d0wjI/lY5lDv98mwwQaEt7qeIs4UkE6QgCBU="; + }) + ++ + # This also broke Nix https://github.com/NixOS/nix/issues/13145 and probably much more dependants too. + lib.optional (lib.versionAtLeast version "1.88.0" && lib.versionOlder version "1.89.0") + (fetchpatch { + url = "https://github.com/boostorg/context/commit/c79564d0de69422ed33f2fbc892908ad510e6a19.patch"; + relative = "include"; + hash = "sha256-5iZ+rSdtyOupBUYws6U8whd43XMkTlQlApW5xvE0ZB4="; + }) # This fixes another issue regarding ill-formed constant expressions, which is a default error # in clang 16 and will be a hard error in clang 17. ++ lib.optional (lib.versionOlder version "1.80") (fetchpatch { From 4c01ab6de7e04a17a18b055c4d1de664e4b779a6 Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Mon, 3 Aug 2026 14:47:13 +0200 Subject: [PATCH 07/31] python3Packages.gitpython: 3.1.50 -> 3.1.51 https://redirect.github.com/gitpython-developers/GitPython/blob/3.1.51/doc/source/changes.rst (cherry picked from commit 65c5a6dac2c3a7833272b5246598ba39a76a3383) Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- pkgs/development/python-modules/gitpython/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/gitpython/default.nix b/pkgs/development/python-modules/gitpython/default.nix index 10486c955e8f..d612c47d5830 100644 --- a/pkgs/development/python-modules/gitpython/default.nix +++ b/pkgs/development/python-modules/gitpython/default.nix @@ -10,14 +10,14 @@ buildPythonPackage (finalAttrs: { pname = "gitpython"; - version = "3.1.50"; + version = "3.1.51"; pyproject = true; src = fetchFromGitHub { owner = "gitpython-developers"; repo = "GitPython"; tag = finalAttrs.version; - hash = "sha256-oHJrN/iYaAZUNPgOLS+8Ekr1eLES8APfXynmR4OySwk="; + hash = "sha256-c8tjBvWjVR7krR59Tfx5jKoJc/fcLWVt5D4xk15DvP4="; }; postPatch = '' From 0a9b71eb63d1f66e25b8ad8a049c2275fe73f63e Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Mon, 3 Aug 2026 15:49:45 +0200 Subject: [PATCH 08/31] nodejs_24: 24.18.1 -> 24.19.0 (cherry picked from commit d14174cf76b08f145215940c72af608cd8a956e3) --- pkgs/development/web/nodejs/v24.nix | 21 ++++++--------------- 1 file changed, 6 insertions(+), 15 deletions(-) diff --git a/pkgs/development/web/nodejs/v24.nix b/pkgs/development/web/nodejs/v24.nix index 262990f1826e..578c94262c53 100644 --- a/pkgs/development/web/nodejs/v24.nix +++ b/pkgs/development/web/nodejs/v24.nix @@ -29,22 +29,13 @@ let [ ]; in buildNodejs { - version = "24.18.1"; - sha256 = "86d40d594bbdfcf69009a62fdf43cb19ae72b6cb5822d2bdd8349c5a1b2fa628"; + version = "24.19.0"; + sha256 = "f6d95e10a0431ee1067fc6aabe9f762908b4716dd35324e1ddb4b1466b76659f"; patches = - ( - if (stdenv.hostPlatform.emulatorAvailable buildPackages) then - [ - ./configure-emulator.patch - ] - else - [ - (fetchpatch2 { - url = "https://raw.githubusercontent.com/buildroot/buildroot/2f0c31bffdb59fb224387e35134a6d5e09a81d57/package/nodejs/nodejs-src/0003-include-obj-name-in-shared-intermediate.patch"; - hash = "sha256-3g4aS+NmmUYNOYRNc6UMJKYoaTlpP5Knt9UHegx+o0Y="; - }) - ] - ) + (lib.optional (!(stdenv.hostPlatform.emulatorAvailable buildPackages)) (fetchpatch2 { + url = "https://raw.githubusercontent.com/buildroot/buildroot/2f0c31bffdb59fb224387e35134a6d5e09a81d57/package/nodejs/nodejs-src/0003-include-obj-name-in-shared-intermediate.patch"; + hash = "sha256-3g4aS+NmmUYNOYRNc6UMJKYoaTlpP5Knt9UHegx+o0Y="; + })) ++ lib.optionals (stdenv.hostPlatform != stdenv.buildPlatform && stdenv.hostPlatform.isFreeBSD) [ # This patch is concerning. # https://github.com/nodejs/node/issues/54576 From a55f6e31f8b4ffbca524e83abef8151a5d00f14c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Gutyina=20Gerg=C5=91?= Date: Sat, 1 Aug 2026 19:23:19 +0200 Subject: [PATCH 09/31] zulu: enable __structuredAttrs and strictDeps (cherry picked from commit f49b48c48e3047f02a9d7cb9ad5577ca44b37014) --- pkgs/development/compilers/zulu/common.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/compilers/zulu/common.nix b/pkgs/development/compilers/zulu/common.nix index 46724ffea83c..88b0f98aa0f8 100644 --- a/pkgs/development/compilers/zulu/common.nix +++ b/pkgs/development/compilers/zulu/common.nix @@ -81,6 +81,9 @@ let pname = "zulu-${javaPackage}"; version = dist.jdkVersion; + __structuredAttrs = true; + strictDeps = true; + src = fetchurl { url = "https://cdn.azul.com/zulu/bin/zulu${dist.zuluVersion}-${javaPackage}${dist.jdkVersion}-${platform}_${arch}.tar.gz"; inherit (dist) hash; From 519a41460115fdf3de406c9ecea04a4f29a3cedc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Mon, 3 Aug 2026 15:25:36 -0700 Subject: [PATCH 10/31] libadwaita: 1.9.2 -> 1.9.3 Diff: https://gitlab.gnome.org/GNOME/libadwaita/-/compare/1.9.2...1.9.3 Changelog: https://gitlab.gnome.org/GNOME/libadwaita/-/blob/1.9.3/NEWS (cherry picked from commit 6c0c69ed62712c46c5eb5e58b6aa92b37e4e6885) --- pkgs/by-name/li/libadwaita/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libadwaita/package.nix b/pkgs/by-name/li/libadwaita/package.nix index fdad6431655b..c158da4ee9af 100644 --- a/pkgs/by-name/li/libadwaita/package.nix +++ b/pkgs/by-name/li/libadwaita/package.nix @@ -23,7 +23,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libadwaita"; - version = "1.9.2"; + version = "1.9.3"; outputs = [ "out" @@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "GNOME"; repo = "libadwaita"; tag = finalAttrs.version; - hash = "sha256-XKKjnZz4CII6w9fKFptPK3aTNa5eMfyE7rcerbgaDco="; + hash = "sha256-1V3L10YgRnOoJud/lybfSj2AYOY0kRAJdfamJg+S1fo="; }; depsBuildBuild = [ From 94f7778ce7e3eea2b41be67111d979f9def1f29d Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Tue, 4 Aug 2026 20:59:38 -0400 Subject: [PATCH 11/31] python3Packages.cryptography: security patches --- .../python-modules/cryptography/default.nix | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/pkgs/development/python-modules/cryptography/default.nix b/pkgs/development/python-modules/cryptography/default.nix index 729c1801daa7..41f4afb21daf 100644 --- a/pkgs/development/python-modules/cryptography/default.nix +++ b/pkgs/development/python-modules/cryptography/default.nix @@ -9,6 +9,7 @@ cffi, cryptography-vectors ? (callPackage ./vectors.nix { }), fetchFromGitHub, + fetchpatch2, isPyPy, libiconv, openssl, @@ -36,6 +37,27 @@ buildPythonPackage rec { hash = "sha256-mp+1Fw8xNBJD1DM8obAqYBP8erxXiP768+ifqRN1Uqs="; }; + patches = [ + # CVE-2026-69247 + (fetchpatch2 { + url = "https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f.patch?full_index=1"; + excludes = [ "CHANGELOG.rst" ]; + hash = "sha256-BBMsnFozpIJCkRejCYZrfiEikLJSJXCAMCBqa5vRL5E="; + }) + # CVE-2026-69248 + (fetchpatch2 { + url = "https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2.patch?full_index=1"; + excludes = [ ".github/actions/**" ]; + hash = "sha256-Uct2j+kMYVJ0PJ0WtPqQkACVFyqKjK4bi5LMuRHWCZo="; + }) + # CVE-2026-69249 + (fetchpatch2 { + url = "https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582.patch?full_index=1"; + excludes = [ ".github/actions/**" ]; + hash = "sha256-9WFoA+H/OMLLkSfJvhBf9cgSYrhuVokYKLr6WeNJAgI="; + }) + ]; + postPatch = '' substituteInPlace pyproject.toml \ --replace-fail "--benchmark-disable" "" From 846cc3e2f386fb684d81620b4f8ffce76c976250 Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Mon, 3 Aug 2026 15:57:31 +0200 Subject: [PATCH 12/31] python3Packages.gitpython: 3.1.51 -> 3.1.57 Includes the security fixes published in GitPython 3.1.52 through 3.1.57. https://redirect.github.com/gitpython-developers/GitPython/blob/3.1.57/doc/source/changes.rst Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) (cherry picked from commit 1371c6fc0f0c877b25a19d7ae1a35d95ebc7df27) --- pkgs/development/python-modules/gitpython/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/gitpython/default.nix b/pkgs/development/python-modules/gitpython/default.nix index d612c47d5830..a2a183f6e448 100644 --- a/pkgs/development/python-modules/gitpython/default.nix +++ b/pkgs/development/python-modules/gitpython/default.nix @@ -10,14 +10,14 @@ buildPythonPackage (finalAttrs: { pname = "gitpython"; - version = "3.1.51"; + version = "3.1.57"; pyproject = true; src = fetchFromGitHub { owner = "gitpython-developers"; repo = "GitPython"; tag = finalAttrs.version; - hash = "sha256-c8tjBvWjVR7krR59Tfx5jKoJc/fcLWVt5D4xk15DvP4="; + hash = "sha256-pCGDKwIefGqx/UJaVqrsofc0t+ntqZRPMhsdbK2XBB0="; }; postPatch = '' From 73cf5e935e27492737e8bce62038bb600ff0f0e4 Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Tue, 4 Aug 2026 23:22:55 +0200 Subject: [PATCH 13/31] python3Packages.gitpython: 3.1.57 -> 3.1.58 Includes the six security fixes published in GitPython 3.1.58. https://redirect.github.com/gitpython-developers/GitPython/blob/3.1.58/doc/source/changes.rst Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) (cherry picked from commit 2740d7bc7806b77af282cb14fdc1a4993d414e63) --- pkgs/development/python-modules/gitpython/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/gitpython/default.nix b/pkgs/development/python-modules/gitpython/default.nix index a2a183f6e448..2b5b14a297b5 100644 --- a/pkgs/development/python-modules/gitpython/default.nix +++ b/pkgs/development/python-modules/gitpython/default.nix @@ -10,14 +10,14 @@ buildPythonPackage (finalAttrs: { pname = "gitpython"; - version = "3.1.57"; + version = "3.1.58"; pyproject = true; src = fetchFromGitHub { owner = "gitpython-developers"; repo = "GitPython"; tag = finalAttrs.version; - hash = "sha256-pCGDKwIefGqx/UJaVqrsofc0t+ntqZRPMhsdbK2XBB0="; + hash = "sha256-C6hrN7SRWngwkD/NYvsoEVQUagdurkxzWbnn42EJOHE="; }; postPatch = '' From 008fca4b338e19e6bb2913412daf4b13d553ab05 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Sat, 1 Aug 2026 22:05:03 +0100 Subject: [PATCH 14/31] llhttp: 9.4.2 -> 9.4.3 Changes: https://github.com/nodejs/llhttp/releases/tag/release%2Fv9.4.3 (cherry picked from commit 8d9f27a18773794e07c89d56e442bde19da651a8) --- pkgs/by-name/ll/llhttp/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ll/llhttp/package.nix b/pkgs/by-name/ll/llhttp/package.nix index 4487a4518360..a1909b67b458 100644 --- a/pkgs/by-name/ll/llhttp/package.nix +++ b/pkgs/by-name/ll/llhttp/package.nix @@ -11,13 +11,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "llhttp"; - version = "9.4.2"; + version = "9.4.3"; src = fetchFromGitHub { owner = "nodejs"; repo = "llhttp"; tag = "release/v${finalAttrs.version}"; - hash = "sha256-LS8HS8CnXJ3X8WlIvtxBLc0h1wLL/HmTqZWHlvBjTEo="; + hash = "sha256-wz87FgdZn0vtdlTWOZL5/Ujhs/uzSwFMHzQ6D9S7dH8="; }; outputs = [ From 78981bc555f664e9227dd6eaed06f5b6ee3b4694 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Wed, 5 Aug 2026 17:12:43 +0200 Subject: [PATCH 15/31] python314: 3.14.6 -> 3.14.7 https://docs.python.org/release/3.14.7/whatsnew/changelog.html (cherry picked from commit 0ef9e3a24027db909c89c6df6b14366dadd736e3) --- pkgs/development/interpreters/python/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/python/default.nix b/pkgs/development/interpreters/python/default.nix index 1d7b5fe795e0..b94cdecfe957 100644 --- a/pkgs/development/interpreters/python/default.nix +++ b/pkgs/development/interpreters/python/default.nix @@ -79,10 +79,10 @@ sourceVersion = { major = "3"; minor = "14"; - patch = "6"; + patch = "7"; suffix = ""; }; - hash = "sha256-FDsd3e+uw70uIeO4ObNKK3+5hCJyiDxXZCDWBenzDGM="; + hash = "sha256-O0jayPtZ9i6qZ6yDwesSvaG3oIQG3ShuJSwRpmvif4E="; inherit passthruFun; }; From 635910a86aad268a12ed91522593c07e9e9041ae Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Wed, 5 Aug 2026 18:30:03 +0200 Subject: [PATCH 16/31] python313: 3.13.14 -> 3.13.15 https://docs.python.org/release/3.13.15/whatsnew/changelog.html (cherry picked from commit f392f19a940905d33402d498ed578ec0d6320694) --- pkgs/development/interpreters/python/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/python/default.nix b/pkgs/development/interpreters/python/default.nix index b94cdecfe957..a8cb1a46619c 100644 --- a/pkgs/development/interpreters/python/default.nix +++ b/pkgs/development/interpreters/python/default.nix @@ -20,10 +20,10 @@ sourceVersion = { major = "3"; minor = "13"; - patch = "14"; + patch = "15"; suffix = ""; }; - hash = "sha256-Y55DJDxiCjCPloIT354A8vj2IzL3rbqnp+65eDBXxpA="; + hash = "sha256-HmanlFpIOQ7kwqQmig5BhYhAWaE8SqttFIqiCN7qSnY="; }; }; From 2ac419509c484a7601dd4e66826527dffd8e4f5f Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Tue, 4 Aug 2026 18:41:08 +0200 Subject: [PATCH 17/31] python3Packages.django_5: 5.2.16 -> 5.2.17 https://docs.djangoproject.com/en/5.2/releases/5.2.17/ https://www.djangoproject.com/weblog/2026/aug/04/security-releases/ Fixes: CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, CVE-2026-15920 (cherry picked from commit 6cce7828fff3ad67b3384beb701a8ed5cd00d1d5) --- pkgs/development/python-modules/django/5.nix | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/django/5.nix b/pkgs/development/python-modules/django/5.nix index 74dff79704f1..904d93e13300 100644 --- a/pkgs/development/python-modules/django/5.nix +++ b/pkgs/development/python-modules/django/5.nix @@ -41,14 +41,14 @@ buildPythonPackage rec { pname = "django"; - version = "5.2.16"; + version = "5.2.17"; pyproject = true; src = fetchFromGitHub { owner = "django"; repo = "django"; tag = version; - hash = "sha256-DZa3OkqnrgXp1A/HerKYdUdanvi5jxHndo1DV4RVs0M="; + hash = "sha256-7it3opzsiN/hHhpipZz4ogmRKGz7E9/LmTF03/UYIB0="; }; patches = [ @@ -69,6 +69,9 @@ buildPythonPackage rec { ]; postPatch = '' + substituteInPlace pyproject.toml \ + --replace-fail "setuptools>=83" "setuptools" + substituteInPlace tests/utils_tests/test_autoreload.py \ --replace-fail "/usr/bin/python" "${python.interpreter}" ''; From c44624eeb667ffe99ed906a0707106c4fdf598ab Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Fri, 17 Jul 2026 21:14:14 +0000 Subject: [PATCH 18/31] gdk-pixbuf: 2.44.6 -> 2.44.7 https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/compare/2.44.6...2.44.7 (cherry picked from commit 2559a0f30478b0906f3bc361a637c2c82bf2c0d7) --- pkgs/by-name/gd/gdk-pixbuf/package.nix | 12 ++---------- 1 file changed, 2 insertions(+), 10 deletions(-) diff --git a/pkgs/by-name/gd/gdk-pixbuf/package.nix b/pkgs/by-name/gd/gdk-pixbuf/package.nix index 0a1e32428806..a55bfa0909c6 100644 --- a/pkgs/by-name/gd/gdk-pixbuf/package.nix +++ b/pkgs/by-name/gd/gdk-pixbuf/package.nix @@ -1,7 +1,6 @@ { stdenv, fetchurl, - fetchpatch, nixosTests, fixDarwinDylibNames, meson, @@ -29,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gdk-pixbuf"; - version = "2.44.6"; + version = "2.44.7"; outputs = [ "out" @@ -41,19 +40,12 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/gdk-pixbuf/${lib.versions.majorMinor finalAttrs.version}/gdk-pixbuf-${finalAttrs.version}.tar.xz"; - hash = "sha256-FAwtC4mfz4U+6SsmNzydwijbzeCCCkJGaT9DKKJ0Zvo="; + hash = "sha256-Fy+A42JuwxUgqXBADxo2lOBHGPbCzSiF91JQ+1pplaQ="; }; patches = [ # Move installed tests to a separate output ./installed-tests-path.patch - - # Fix loading of xpm module if built-in - # https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/267 - (fetchpatch { - url = "https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/62b8f9fd0bb3b862823cd34afce4b389fbd27569.patch"; - hash = "sha256-ECEIt8lq/jBtDdBetErKpap2PWGav10vqCXKCpIQSyA="; - }) ]; # gdk-pixbuf-thumbnailer is not wrapped therefore strictDeps will work From 6f11c31656be0eb32aa40cadc74a53175ab4eaca Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Fri, 17 Jul 2026 21:38:24 +0000 Subject: [PATCH 19/31] gjs: 1.88.0 -> 1.88.1 https://gitlab.gnome.org/GNOME/gjs/-/compare/1.88.0...1.88.1 (cherry picked from commit 757b81a53b41e062290007938cf71af6c578da4f) --- pkgs/by-name/gj/gjs/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gj/gjs/package.nix b/pkgs/by-name/gj/gjs/package.nix index 30b62ac129a9..08cfe8bd2db4 100644 --- a/pkgs/by-name/gj/gjs/package.nix +++ b/pkgs/by-name/gj/gjs/package.nix @@ -41,7 +41,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "gjs"; - version = "1.88.0"; + version = "1.88.1"; outputs = [ "out" @@ -51,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/gjs/${lib.versions.majorMinor finalAttrs.version}/gjs-${finalAttrs.version}.tar.xz"; - hash = "sha256-MKC58zF+jmCxiW2ykDxw6LDNM9+VPDKHVYA6dRkdxFM="; + hash = "sha256-dnurgOZl1nLLAFY8JfCzkqnsjCmW7R1EVMaYtMLwo9k="; }; patches = [ From 18518413c3e1a2ac70a4126a34f2322f7d4e2929 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 18 Jul 2026 18:31:44 +0000 Subject: [PATCH 20/31] =?UTF-8?q?glib:=202.88.1=20=E2=86=92=202.88.3?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit https://gitlab.gnome.org/GNOME/glib/-/compare/2.88.1...2.88.2 https://gitlab.gnome.org/GNOME/glib/-/compare/2.88.2...2.88.3 (cherry picked from commit 8f4fcbf26bdaed9c7673cb8646c0ea7c2fd356be) --- pkgs/by-name/gl/glib/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gl/glib/package.nix b/pkgs/by-name/gl/glib/package.nix index cf554d53e403..4e15ef3f790c 100644 --- a/pkgs/by-name/gl/glib/package.nix +++ b/pkgs/by-name/gl/glib/package.nix @@ -82,7 +82,7 @@ in stdenv.mkDerivation (finalAttrs: { pname = "glib"; - version = "2.88.1"; + version = "2.88.3"; outputs = [ "bin" @@ -95,7 +95,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/glib/${lib.versions.majorMinor finalAttrs.version}/glib-${finalAttrs.version}.tar.xz"; - hash = "sha256-UauATFb26rPlBFx3TRKQrF5Mkj1Pmj2OMxI77kXBhA4="; + hash = "sha256-qyTSTmmN+h5Ai3vNtQj0qvyQYYWouM5y/febu9ybODs="; }; patches = From a04f06824567ce04d6a92812b2bc53bf1615e9f7 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Sun, 26 Apr 2026 10:32:26 +0100 Subject: [PATCH 21/31] mpg123: 1.33.4 -> 1.33.5 Changes: https://mpg123.org/#2026-04-25 (cherry picked from commit 57cd8cc8a3a34e5d97b64885973eef72dbfd24ef) --- pkgs/applications/audio/mpg123/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/audio/mpg123/default.nix b/pkgs/applications/audio/mpg123/default.nix index df13df07a978..e46a14127710 100644 --- a/pkgs/applications/audio/mpg123/default.nix +++ b/pkgs/applications/audio/mpg123/default.nix @@ -21,11 +21,11 @@ assert withConplay -> !libOnly; stdenv.mkDerivation (finalAttrs: { pname = "${lib.optionalString libOnly "lib"}mpg123"; - version = "1.33.4"; + version = "1.33.5"; src = fetchurl { url = "mirror://sourceforge/mpg123/mpg123-${finalAttrs.version}.tar.bz2"; - hash = "sha256-OujJ/4Cpe/wOIuifvNdGh+yk/B2zFbEmB/J/ActaR9k="; + hash = "sha256-DX68jaCv88o4PIxrWmrb5ALuW7JWaFuMVJnzpzn51t0="; }; outputs = [ From 9b9b6f786a867f4b8544b56e25a9488a8dc4fbf6 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Sat, 13 Jun 2026 16:34:00 +0100 Subject: [PATCH 22/31] mpg123: 1.33.5 -> 1.33.6 Changes: https://www.mpg123.de/#2026-06-06 (cherry picked from commit 0fc90c3e06254ff22e07ab2c25fe2091e75fd05d) --- pkgs/applications/audio/mpg123/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/audio/mpg123/default.nix b/pkgs/applications/audio/mpg123/default.nix index e46a14127710..c3e4a6fd2ffc 100644 --- a/pkgs/applications/audio/mpg123/default.nix +++ b/pkgs/applications/audio/mpg123/default.nix @@ -21,11 +21,11 @@ assert withConplay -> !libOnly; stdenv.mkDerivation (finalAttrs: { pname = "${lib.optionalString libOnly "lib"}mpg123"; - version = "1.33.5"; + version = "1.33.6"; src = fetchurl { url = "mirror://sourceforge/mpg123/mpg123-${finalAttrs.version}.tar.bz2"; - hash = "sha256-DX68jaCv88o4PIxrWmrb5ALuW7JWaFuMVJnzpzn51t0="; + hash = "sha256-kpp8GLpmK4knrtTeIprZroqytIBt0PMLkBE+sbTiGVo="; }; outputs = [ From ee113d013e1551e960dd33937cfe7c28faf4907d Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Tue, 4 Aug 2026 22:51:45 +0100 Subject: [PATCH 23/31] mpg123: 1.33.6 -> 1.33.7 Changes: https://www.mpg123.de/#2026-08-02 (cherry picked from commit 9e51429113d08bca9d502cb45bd010eaa29483a3) --- pkgs/applications/audio/mpg123/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/audio/mpg123/default.nix b/pkgs/applications/audio/mpg123/default.nix index c3e4a6fd2ffc..648dca3f7aaf 100644 --- a/pkgs/applications/audio/mpg123/default.nix +++ b/pkgs/applications/audio/mpg123/default.nix @@ -21,11 +21,11 @@ assert withConplay -> !libOnly; stdenv.mkDerivation (finalAttrs: { pname = "${lib.optionalString libOnly "lib"}mpg123"; - version = "1.33.6"; + version = "1.33.7"; src = fetchurl { url = "mirror://sourceforge/mpg123/mpg123-${finalAttrs.version}.tar.bz2"; - hash = "sha256-kpp8GLpmK4knrtTeIprZroqytIBt0PMLkBE+sbTiGVo="; + hash = "sha256-MdDjWkylZ+ybXr2mwwYrtENdbT6s1u8NlcrdeFTcA+4="; }; outputs = [ From ad1d399557b1ab7b69e6be514bc46e93cd7222e6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Thu, 6 Aug 2026 13:29:13 +0200 Subject: [PATCH 24/31] libxfont_2: 2.0.8 -> 2.0.9 Fixes: CVE-2026-59679 CVE-2026-44950 https://lists.x.org/archives/xorg-announce/2026-August/003734.html https://lists.x.org/archives/xorg-announce/2026-August/003735.html (cherry picked from commit 548c156f109369c0f9334be3a9da4160d96db752) --- pkgs/by-name/li/libxfont_2/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libxfont_2/package.nix b/pkgs/by-name/li/libxfont_2/package.nix index 0156515019d1..beb3abd0d329 100644 --- a/pkgs/by-name/li/libxfont_2/package.nix +++ b/pkgs/by-name/li/libxfont_2/package.nix @@ -15,7 +15,7 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "libxfont_2"; - version = "2.0.8"; + version = "2.0.9"; outputs = [ "out" @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://xorg/individual/lib/libXfont2-${finalAttrs.version}.tar.xz"; - hash = "sha256-9VbA4Qk6TmkRzJC8SxBtIBkC7hh/10ryBv8WL35qJNU="; + hash = "sha256-8EKjcGZoFee5Qem3AZAkdVvRxsKVSvv6UVrzeCUXmeI="; }; strictDeps = true; From fb2be328b4a8e1af95a5667de83888e230af6dfc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Fri, 7 Aug 2026 10:43:50 +0200 Subject: [PATCH 25/31] libxfont_2: keep the fontserver support The update in the previous commit disabled fontserver support: https://lists.x.org/archives/xorg-announce/2026-August/003735.html > Fontservers have been deprecated for many years and the vast > majority of users will not notice this changed default > (Debian has built with --disable-fc for years). On 26.05 we might better keep it by explicitly passing `--enable-fc`. Not-cherry-picked-because: we don't need that much compat on nixpkgs master. --- pkgs/by-name/li/libxfont_2/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/li/libxfont_2/package.nix b/pkgs/by-name/li/libxfont_2/package.nix index beb3abd0d329..bc610cd139ce 100644 --- a/pkgs/by-name/li/libxfont_2/package.nix +++ b/pkgs/by-name/li/libxfont_2/package.nix @@ -41,6 +41,8 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = [ xorgproto ]; + configureFlags = [ "--enable-fc" ]; + passthru = { updateScript = writeScript "update-${finalAttrs.pname}" '' #!/usr/bin/env nix-shell From fc8f57945ced59c35f92d2ec1cd5e6e7a25bce0d Mon Sep 17 00:00:00 2001 From: Samuel Dionne-Riel Date: Tue, 28 Jul 2026 09:56:57 -0400 Subject: [PATCH 26/31] libssh: 0.12.1 -> 0.12.2 https://www.libssh.org/2026/07/28/libssh-0-12-2-security-release/ Fixes: CVE-2026-59843: Denial of service via zero advertised channel packet size (cherry picked from commit d3bdeb580bfe78a74f875d923fef55d27cb3d11e) --- pkgs/by-name/li/libssh/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libssh/package.nix b/pkgs/by-name/li/libssh/package.nix index 41d42b83b65d..af242479a9bc 100644 --- a/pkgs/by-name/li/libssh/package.nix +++ b/pkgs/by-name/li/libssh/package.nix @@ -16,11 +16,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "libssh"; - version = "0.12.1"; + version = "0.12.2"; src = fetchurl { url = "https://www.libssh.org/files/${lib.versions.majorMinor finalAttrs.version}/libssh-${finalAttrs.version}.tar.xz"; - hash = "sha256-05Qa8KLXjV2C7Xo2mI6RM5lDEvA1uWWabkP42zloeEw="; + hash = "sha256-SVYPZ32W43BqkErC3hEW4l82gJN9UeXJIZj8ukocHp8="; }; outputs = [ From 8466e5327dba30f23c746c3f914fc7f37b84e269 Mon Sep 17 00:00:00 2001 From: whispers Date: Thu, 30 Jul 2026 14:48:03 -0400 Subject: [PATCH 27/31] libssh2: apply debian patches for CVE-2026-6603[2345] Fixes: CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 (cherry picked from commit 8a969be9f44de55804cc28231d9a7258448f1f95) --- pkgs/by-name/li/libssh2/package.nix | 34 +++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/pkgs/by-name/li/libssh2/package.nix b/pkgs/by-name/li/libssh2/package.nix index 0fe5cd7290d7..231cf9365c6b 100644 --- a/pkgs/by-name/li/libssh2/package.nix +++ b/pkgs/by-name/li/libssh2/package.nix @@ -27,18 +27,21 @@ stdenv.mkDerivation (finalAttrs: { # https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1 ./CVE-2026-7598.patch + # backport of https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d (fetchurl { name = "CVE-2025-15661.patch"; url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/CVE-2025-15661.patch"; hash = "sha256-Rz6i/881CbObUDcZbcPlgVPaKizSp6ZRTdmJNJ9HLHE="; }) + # backport of https://github.com/libssh2/libssh2/commit/17626857d20b3c9a1addfa45979dadcee1cd84a4 (fetchurl { name = "CVE-2026-55199.patch"; url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/CVE-2026-55199.patch"; hash = "sha256-AFZa5kohha62aE0if5ckmAdJ0TZNcjfP32yDznoEhNo="; }) + # backport of https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8 (fetchurl { name = "CVE-2026-55200.patch"; url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/CVE-2026-55200.patch"; @@ -53,16 +56,47 @@ stdenv.mkDerivation (finalAttrs: { }) # https://github.com/libssh2/libssh2/issues/1925#issuecomment-4938515829 + # backport of https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12 (fetchurl { name = "CVE-2026-58050.patch"; url = "https://raw.githubusercontent.com/JuliaPackaging/Yggdrasil/9404aa5dd96c945a790c425a5f49af19ed2a93b0/L/LibSSH2/LibSSH2%401.11/bundled/patches/CVE-2026-58050-3449752.patch"; hash = "sha256-BZ1ewZgrroev2gkJwdoHCMFJK4wiRmA/Y4tzwaQqBd8="; }) + + # backport of https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a (fetchurl { name = "CVE-2026-58051.patch"; url = "https://github.com/JuliaPackaging/Yggdrasil/raw/9404aa5dd96c945a790c425a5f49af19ed2a93b0/L/LibSSH2/LibSSH2%401.11/bundled/patches/CVE-2026-58051-a9758da.patch"; hash = "sha256-fduXIH02uwzqWV2RDidZmaDBy51V8yuC4XKlGYacjxg="; }) + + # backport of https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0 + (fetchurl { + name = "CVE-2026-66032.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/fe2e3c0848f8501bf729d61790360761a20c75f2/debian/patches/CVE-2026-66032.patch"; + hash = "sha256-H6VXhVc7uCFxj/k3Xouyg+8GYpsn/9IecXZrPkzsgks="; + }) + + # backport of https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6 + (fetchurl { + name = "CVE-2026-66033.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/fe2e3c0848f8501bf729d61790360761a20c75f2/debian/patches/CVE-2026-66033.patch"; + hash = "sha256-To2ul9ibaAkn0BWNu7fUbpaqHqEX+juUsBbjA0BGF6s="; + }) + + # backport of https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9 + (fetchurl { + name = "CVE-2026-66034.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/fe2e3c0848f8501bf729d61790360761a20c75f2/debian/patches/CVE-2026-66034.patch"; + hash = "sha256-xYg9qh87KlExI38snAq5E5hF51mIoaJ1wOX9e1uEdmk="; + }) + + # backport of https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4 + (fetchurl { + name = "CVE-2026-66035.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/fe2e3c0848f8501bf729d61790360761a20c75f2/debian/patches/CVE-2026-66035.patch"; + hash = "sha256-+Wr9dp+g347pgKaJYRNRx+EXHA3iOKgOO4tjxi7zkD8="; + }) ]; # this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion From 5465e2c884bcd655531bfaec6812e835751da099 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 7 Aug 2026 06:56:20 +0000 Subject: [PATCH 28/31] unbound: 1.25.2 -> 1.26.0 (cherry picked from commit 35bf5426bff1a58d31ca08dcb4b0876ec727c01e) --- pkgs/by-name/un/unbound/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/un/unbound/package.nix b/pkgs/by-name/un/unbound/package.nix index a90eb0b1d364..2dba1d12c66d 100644 --- a/pkgs/by-name/un/unbound/package.nix +++ b/pkgs/by-name/un/unbound/package.nix @@ -63,13 +63,13 @@ assert lib.assertMsg ( ) "unbound: withDoQ requires OpenSSL with QUIC support (OpenSSL >= 3.5)"; stdenv.mkDerivation (finalAttrs: { pname = "unbound"; - version = "1.25.2"; + version = "1.26.0"; src = fetchFromGitHub { owner = "NLnetLabs"; repo = "unbound"; tag = "release-${finalAttrs.version}"; - hash = "sha256-zt0JpVmct7w6ay+p8CdH6SGt/rL/v//e7K3MT8KZfOY="; + hash = "sha256-ESRboc5vwsNZ/Yynl2JGRWhH1QEYZumoTzgSvN3NbSU="; }; outputs = [ From ce65fffff8b6486134e7a47c290fa061bc09dc1b Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 9 Aug 2026 13:42:10 +0200 Subject: [PATCH 29/31] nspr: 4.39 -> 4.40 https://github.com/mozilla/nspr/releases/tag/NSPR_4_40_RTM (cherry picked from commit 933765c9ecd54627caeaf66de401bed8a2ddb7c9) --- pkgs/by-name/ns/nspr/package.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ns/nspr/package.nix b/pkgs/by-name/ns/nspr/package.nix index 372a7b3f067f..9784147f643b 100644 --- a/pkgs/by-name/ns/nspr/package.nix +++ b/pkgs/by-name/ns/nspr/package.nix @@ -8,11 +8,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "nspr"; - version = "4.39"; + version = "4.40"; src = fetchurl { url = "mirror://mozilla/nspr/releases/v${finalAttrs.version}/src/nspr-${finalAttrs.version}.tar.gz"; - hash = "sha256-u9Au6HpVZ2Bjpj5byBngIn3iZmtHMHsqATRBTN9CNo4="; + hash = "sha256-wMGITGJ/Pbeng/fHMUxpUiayBDaWeR0VUZ5+BXjBm9w="; }; patches = [ @@ -53,6 +53,7 @@ stdenv.mkDerivation (finalAttrs: { }; meta = { + changelog = "https://github.com/mozilla/nspr/releases/tag/NSPR_${lib.concatStringsSep "_" (lib.splitVersion finalAttrs.version)}_RTM"; homepage = "https://firefox-source-docs.mozilla.org/nspr/index.html"; description = "Netscape Portable Runtime, a platform-neutral API for system-level and libc-like functions"; maintainers = with lib.maintainers; [ From 41ef262cd9f4f9038dd501e53256b8f910c547fe Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 9 Aug 2026 11:08:04 +0000 Subject: [PATCH 30/31] libffi: 3.7.1 -> 3.8.0 (cherry picked from commit a1f52543006d25261136adff8917b5743ac9887a) --- pkgs/by-name/li/libffiReal/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libffiReal/package.nix b/pkgs/by-name/li/libffiReal/package.nix index 069f6508d0ce..3d34ab9f068a 100644 --- a/pkgs/by-name/li/libffiReal/package.nix +++ b/pkgs/by-name/li/libffiReal/package.nix @@ -13,13 +13,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libffi"; - version = "3.7.1"; + version = "3.8.0"; src = fetchurl { url = with finalAttrs; "https://github.com/libffi/libffi/releases/download/v${version}/${pname}-${version}.tar.gz"; - hash = "sha256-1emmY43b0lE921RRjrZ+S75vpwe8wBwQ9iEvCgiNgZ0="; + hash = "sha256-faPi2aFx6woDj1kuytP/K7JVDzSW2Hs7Ka0M9EMMDbQ="; }; # Note: this package is used for bootstrapping fetchurl, and thus From 2a913d42b61f12bba1ca7e9b42ea121ee97e8e2d Mon Sep 17 00:00:00 2001 From: whispers Date: Mon, 10 Aug 2026 21:26:20 -0400 Subject: [PATCH 31/31] expat: 2.8.2 -> 2.8.3 changelog: https://github.com/libexpat/libexpat/blob/R_2_8_3/expat/Changes diff: https://github.com/libexpat/libexpat/compare/R_2_8_2...R_2_8_3 Fixes: CVE-2026-72522 (cherry picked from commit 49076b4ec84292406e66262a7ed7d028dcfe6a6c) --- pkgs/by-name/ex/expat/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ex/expat/package.nix b/pkgs/by-name/ex/expat/package.nix index 72459e1c2ac6..246f1e1af668 100644 --- a/pkgs/by-name/ex/expat/package.nix +++ b/pkgs/by-name/ex/expat/package.nix @@ -18,7 +18,7 @@ # files. let - version = "2.8.2"; + version = "2.8.3"; tag = "R_${lib.replaceStrings [ "." ] [ "_" ] version}"; in stdenv.mkDerivation (finalAttrs: { @@ -29,7 +29,7 @@ stdenv.mkDerivation (finalAttrs: { url = with finalAttrs; "https://github.com/libexpat/libexpat/releases/download/${tag}/${pname}-${version}.tar.xz"; - hash = "sha256-OtibhYjmZEvU5JmBSA1IshKJ7rvNTwoaSvscKfmbarQ="; + hash = "sha256-9iVt+QyQZ3PTRNoIRAK30+TyLtQbGlnJiQmKg9PqDIU="; }; strictDeps = true;