From 636f8d415b15b14ece1b56d3715cbd19f564f0b7 Mon Sep 17 00:00:00 2001 From: "Winston R. Milling" Date: Sun, 20 Oct 2024 20:34:46 -0500 Subject: [PATCH 1/8] legcord: 1.0.1 -> 1.0.2 https://github.com/Legcord/Legcord/releases/tag/v1.0.2 --- pkgs/by-name/le/legcord/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/le/legcord/package.nix b/pkgs/by-name/le/legcord/package.nix index 453c42c8bbf5..6298f75f6e3d 100644 --- a/pkgs/by-name/le/legcord/package.nix +++ b/pkgs/by-name/le/legcord/package.nix @@ -38,7 +38,7 @@ stdenv.mkDerivation rec { pname = "legcord"; - version = "1.0.1"; + version = "1.0.2"; src = let @@ -47,11 +47,11 @@ stdenv.mkDerivation rec { { x86_64-linux = fetchurl { url = "${base}/v${version}/Legcord-${version}-linux-amd64.deb"; - hash = "sha256-kZ9dhSJjhYmpZJLbWP8nPP6Lxw+wLe3d9cCahfIomNM="; + hash = "sha256-MvSnYE6JLnZUA/Td0XuvOAENEtMGWSQuFFDa8cnBB1s="; }; aarch64-linux = fetchurl { url = "${base}/v${version}/Legcord-${version}-linux-arm64.deb"; - hash = "sha256-Ikyjmlt1F7f6WaYWuAgyzLP3zvQPCvMRZ1D9e79umgM="; + hash = "sha256-+HD162RfcNxNXpjW5HPAmhCQIFRXuPXdC/jQgT0aV1k="; }; }.${stdenv.hostPlatform.system} or (throw "Unsupported system: ${stdenv.hostPlatform.system}"); From cce85d9d8c590984836c3ad3986f9e124e6c04bf Mon Sep 17 00:00:00 2001 From: DontEatOreo <57304299+DontEatOreo@users.noreply.github.com> Date: Fri, 25 Oct 2024 10:32:50 +0000 Subject: [PATCH 2/8] arc-browser: 1.65.0-54911 -> 1.66.0-55166 Changelog: https://arc.net/e/00D675DF-0127-4340-9396-9616BEB71E57 (cherry picked from commit 1582530fed096ed0ab1532045b92adb45f8ea6eb) --- pkgs/by-name/ar/arc-browser/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ar/arc-browser/package.nix b/pkgs/by-name/ar/arc-browser/package.nix index 00e3e6757d83..8a45049cbf09 100644 --- a/pkgs/by-name/ar/arc-browser/package.nix +++ b/pkgs/by-name/ar/arc-browser/package.nix @@ -10,11 +10,11 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "arc-browser"; - version = "1.65.0-54911"; + version = "1.66.0-55166"; src = fetchurl { url = "https://releases.arc.net/release/Arc-${finalAttrs.version}.dmg"; - hash = "sha256-7p1FizITL4GVvlDTV91nwYQZ7LKEd4snJQX0NvB81Qo="; + hash = "sha256-up+ScCjFgxlATUbCeWZcVF2jZGfCw018MfT6kAqAHO4="; }; nativeBuildInputs = [ undmg ]; From 86b4df87378aefda81ee32e7e548d4e1206ba91b Mon Sep 17 00:00:00 2001 From: Atemu Date: Tue, 6 Aug 2024 03:15:15 +0200 Subject: [PATCH 3/8] maintainers: update Atemu's emails (cherry picked from commit c83ce5bab43f78edd8f7fbcb98f3f2cde07ee25a) --- .mailmap | 1 + maintainers/maintainer-list.nix | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/.mailmap b/.mailmap index ba9bcefb55e1..cac77e9d319a 100644 --- a/.mailmap +++ b/.mailmap @@ -1,5 +1,6 @@ ajs124 Anderson Torres +Atemu Daniel Løvbrøtte Olsen Fabian Affolter Janne Heß diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 03ad4d45ad5d..1ef671942192 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -1860,7 +1860,7 @@ }; atemu = { name = "Atemu"; - email = "atemu.main+nixpkgs@gmail.com"; + email = "nixpkgs@mail.atemu.net"; github = "Atemu"; githubId = 18599032; }; From 5691625565d74d4f7d43e3dfeac36dc64f3dda6b Mon Sep 17 00:00:00 2001 From: Silvan Mosberger Date: Sat, 26 Oct 2024 15:01:12 +0200 Subject: [PATCH 4/8] workflows/codeowners: Fix security issue Co-Authored-By: 13x1 Co-Authored-By: basti564 (cherry picked from commit 59aee1ca5d7b0cf324372795990e2d84d7cc61c1) --- .github/workflows/codeowners.yml | 30 +++++++++++++++++++++--------- 1 file changed, 21 insertions(+), 9 deletions(-) diff --git a/.github/workflows/codeowners.yml b/.github/workflows/codeowners.yml index 56588d45c9cd..f1eccec48970 100644 --- a/.github/workflows/codeowners.yml +++ b/.github/workflows/codeowners.yml @@ -1,12 +1,24 @@ name: Codeowners -# This workflow depends on a GitHub App with the following permissions: -# - Repository > Administration: read-only -# - Organization > Members: read-only -# - Repository > Pull Requests: read-write -# The App needs to be installed on this repository -# the OWNER_APP_ID repository variable needs to be set -# the OWNER_APP_PRIVATE_KEY repository secret needs to be set +# This workflow depends on two GitHub Apps with the following permissions: +# - For checking code owners: +# - Permissions: +# - Repository > Administration: read-only +# - Organization > Members: read-only +# - Install App on this repository, setting these variables: +# - OWNER_RO_APP_ID (variable) +# - OWNER_RO_APP_PRIVATE_KEY (secret) +# - For requesting code owners: +# - Permissions: +# - Repository > Administration: read-only +# - Organization > Members: read-only +# - Repository > Pull Requests: read-write +# - Install App on this repository, setting these variables: +# - OWNER_APP_ID (variable) +# - OWNER_APP_PRIVATE_KEY (secret) +# +# This split is done because checking code owners requires handling untrusted PR input, +# while requesting code owners requires PR write access, and those shouldn't be mixed. on: pull_request_target: @@ -45,8 +57,8 @@ jobs: - uses: actions/create-github-app-token@5d869da34e18e7287c1daad50e0b8ea0f506ce69 # v1.11.0 id: app-token with: - app-id: ${{ vars.OWNER_APP_ID }} - private-key: ${{ secrets.OWNER_APP_PRIVATE_KEY }} + app-id: ${{ vars.OWNER_RO_APP_ID }} + private-key: ${{ secrets.OWNER_RO_APP_PRIVATE_KEY }} - uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0 with: From ccc38ebba10a768c472c40cf34077bd13563d3cc Mon Sep 17 00:00:00 2001 From: Silvan Mosberger Date: Sat, 26 Oct 2024 15:03:37 +0200 Subject: [PATCH 5/8] workflows: Fix security issues read-all permissions gives access to e.g. security-events, which these don't need, and can easily lead to leaks Co-Authored-By: 13x1 Co-Authored-By: basti564 (cherry picked from commit 6b8ce4aedf3e953624a442c02e8e7bf4d974d2b0) --- .github/workflows/codeowners.yml | 3 +++ .github/workflows/editorconfig.yml | 4 +++- .github/workflows/manual-nixos.yml | 3 ++- .github/workflows/manual-nixpkgs.yml | 3 ++- .github/workflows/nix-parse.yml | 4 +++- 5 files changed, 13 insertions(+), 4 deletions(-) diff --git a/.github/workflows/codeowners.yml b/.github/workflows/codeowners.yml index f1eccec48970..d7297213833a 100644 --- a/.github/workflows/codeowners.yml +++ b/.github/workflows/codeowners.yml @@ -24,6 +24,9 @@ on: pull_request_target: types: [opened, ready_for_review, synchronize, reopened, edited] +# We don't need any default GitHub token +permissions: {} + env: OWNERS_FILE: ci/OWNERS # Don't do anything on draft PRs diff --git a/.github/workflows/editorconfig.yml b/.github/workflows/editorconfig.yml index b2b96722993b..2c53ac210657 100644 --- a/.github/workflows/editorconfig.yml +++ b/.github/workflows/editorconfig.yml @@ -1,6 +1,8 @@ name: "Checking EditorConfig" -permissions: read-all +permissions: + pull-requests: read + contents: read on: # avoids approving first time contributors diff --git a/.github/workflows/manual-nixos.yml b/.github/workflows/manual-nixos.yml index a72b1adfeac0..4be7e20b2aa3 100644 --- a/.github/workflows/manual-nixos.yml +++ b/.github/workflows/manual-nixos.yml @@ -1,6 +1,7 @@ name: "Build NixOS manual" -permissions: read-all +permissions: + contents: read on: pull_request_target: diff --git a/.github/workflows/manual-nixpkgs.yml b/.github/workflows/manual-nixpkgs.yml index 52aefa8472ed..33b2d9b51b7f 100644 --- a/.github/workflows/manual-nixpkgs.yml +++ b/.github/workflows/manual-nixpkgs.yml @@ -1,6 +1,7 @@ name: "Build Nixpkgs manual" -permissions: read-all +permissions: + contents: read on: pull_request_target: diff --git a/.github/workflows/nix-parse.yml b/.github/workflows/nix-parse.yml index ffccf9d53de1..7b4706fb8504 100644 --- a/.github/workflows/nix-parse.yml +++ b/.github/workflows/nix-parse.yml @@ -1,6 +1,8 @@ name: "Check whether nix files are parseable" -permissions: read-all +permissions: + pull-requests: read + contents: read on: # avoids approving first time contributors From b246490d8cadf8c8a9eb5d3dfd99eb3b0e70956b Mon Sep 17 00:00:00 2001 From: Silvan Mosberger Date: Sat, 26 Oct 2024 15:23:06 +0200 Subject: [PATCH 6/8] workflows: Rename after security fixes In the previous two commits, security issues with these workflows were fixed. In order for these to not be exploitable for PRs to branches that don't have the fixes yet (including read-only branches like nixos-unstable), these workflows are renamed, so that the old ones can be turned off manually via GitHub interface. Co-Authored-By: 13x1 Co-Authored-By: basti564 (cherry picked from commit 5bbbc3a30b1a843bc2267f3bb4a42e8af3411498) --- .github/workflows/{codeowners.yml => codeowners-v2.yml} | 2 +- .github/workflows/{editorconfig.yml => editorconfig-v2.yml} | 2 +- .github/workflows/{manual-nixos.yml => manual-nixos-v2.yml} | 2 +- .github/workflows/{manual-nixpkgs.yml => manual-nixpkgs-v2.yml} | 2 +- .github/workflows/{nix-parse.yml => nix-parse-v2.yml} | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) rename .github/workflows/{codeowners.yml => codeowners-v2.yml} (99%) rename .github/workflows/{editorconfig.yml => editorconfig-v2.yml} (98%) rename .github/workflows/{manual-nixos.yml => manual-nixos-v2.yml} (97%) rename .github/workflows/{manual-nixpkgs.yml => manual-nixpkgs-v2.yml} (97%) rename .github/workflows/{nix-parse.yml => nix-parse-v2.yml} (96%) diff --git a/.github/workflows/codeowners.yml b/.github/workflows/codeowners-v2.yml similarity index 99% rename from .github/workflows/codeowners.yml rename to .github/workflows/codeowners-v2.yml index d7297213833a..862681fb53b8 100644 --- a/.github/workflows/codeowners.yml +++ b/.github/workflows/codeowners-v2.yml @@ -1,4 +1,4 @@ -name: Codeowners +name: Codeowners v2 # This workflow depends on two GitHub Apps with the following permissions: # - For checking code owners: diff --git a/.github/workflows/editorconfig.yml b/.github/workflows/editorconfig-v2.yml similarity index 98% rename from .github/workflows/editorconfig.yml rename to .github/workflows/editorconfig-v2.yml index 2c53ac210657..e9cb35fbfb8d 100644 --- a/.github/workflows/editorconfig.yml +++ b/.github/workflows/editorconfig-v2.yml @@ -1,4 +1,4 @@ -name: "Checking EditorConfig" +name: "Checking EditorConfig v2" permissions: pull-requests: read diff --git a/.github/workflows/manual-nixos.yml b/.github/workflows/manual-nixos-v2.yml similarity index 97% rename from .github/workflows/manual-nixos.yml rename to .github/workflows/manual-nixos-v2.yml index 4be7e20b2aa3..49871d61bdfb 100644 --- a/.github/workflows/manual-nixos.yml +++ b/.github/workflows/manual-nixos-v2.yml @@ -1,4 +1,4 @@ -name: "Build NixOS manual" +name: "Build NixOS manual v2" permissions: contents: read diff --git a/.github/workflows/manual-nixpkgs.yml b/.github/workflows/manual-nixpkgs-v2.yml similarity index 97% rename from .github/workflows/manual-nixpkgs.yml rename to .github/workflows/manual-nixpkgs-v2.yml index 33b2d9b51b7f..35409d8e106a 100644 --- a/.github/workflows/manual-nixpkgs.yml +++ b/.github/workflows/manual-nixpkgs-v2.yml @@ -1,4 +1,4 @@ -name: "Build Nixpkgs manual" +name: "Build Nixpkgs manual v2" permissions: contents: read diff --git a/.github/workflows/nix-parse.yml b/.github/workflows/nix-parse-v2.yml similarity index 96% rename from .github/workflows/nix-parse.yml rename to .github/workflows/nix-parse-v2.yml index 7b4706fb8504..09cd162817ba 100644 --- a/.github/workflows/nix-parse.yml +++ b/.github/workflows/nix-parse-v2.yml @@ -1,4 +1,4 @@ -name: "Check whether nix files are parseable" +name: "Check whether nix files are parseable v2" permissions: pull-requests: read From 56e9a30c12cbfa8e064f8dd4348942013584c220 Mon Sep 17 00:00:00 2001 From: Silvan Mosberger Date: Sat, 26 Oct 2024 16:26:22 +0200 Subject: [PATCH 7/8] ci/OWNERS: Fix path of codeowners.yml After https://github.com/NixOS/nixpkgs/pull/351446 (cherry picked from commit cd691f8864a82a36334067a0b16f9d668c5d9ecb) --- ci/OWNERS | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/ci/OWNERS b/ci/OWNERS index 8904c846e816..ad39700dde7c 100644 --- a/ci/OWNERS +++ b/ci/OWNERS @@ -11,12 +11,12 @@ # - There is no need for user/team listed here to have write access. # - No reviews will be requested for PRs that target the wrong base branch. # -# Processing of this file is implemented in workflows/codeowners.yml +# Processing of this file is implemented in workflows/codeowners-v2.yml # CI /.github/workflows @NixOS/Security @Mic92 @zowoq /.github/workflows/check-nix-format.yml @infinisil -/.github/workflows/codeowners.yml @infinisil +/.github/workflows/codeowners-v2.yml @infinisil /ci/OWNERS @infinisil /ci @infinisil @philiptaron @NixOS/Security From 9c45f8317492c5a2e74f0c2ce82c0e3ea454c8be Mon Sep 17 00:00:00 2001 From: Silvan Mosberger Date: Sat, 26 Oct 2024 17:37:00 +0200 Subject: [PATCH 8/8] ci/OWNERS: Remove removed path Was removed in 7e73ead5d0ab1fce66c3122c5e8b9c5bc5bb608a, but only started failing once it actually started getting checked with https://github.com/NixOS/nixpkgs/pull/348642 --- ci/OWNERS | 1 - 1 file changed, 1 deletion(-) diff --git a/ci/OWNERS b/ci/OWNERS index ad39700dde7c..b90b8b7699b3 100644 --- a/ci/OWNERS +++ b/ci/OWNERS @@ -367,4 +367,3 @@ nixos/tests/lxd/ @adamcstephens pkgs/by-name/in/incus/ @adamcstephens pkgs/by-name/lx/lxc* @adamcstephens pkgs/by-name/lx/lxd* @adamcstephens -pkgs/os-specific/linux/lxc/ @adamcstephens