diff --git a/.github/actions/checkout/action.yml b/.github/actions/checkout/action.yml index 91cca324fcd4..ab8c663e0f0e 100644 --- a/.github/actions/checkout/action.yml +++ b/.github/actions/checkout/action.yml @@ -13,6 +13,13 @@ inputs: runs: using: composite steps: + # We don't actually need anything in this directory, but we need a small + # sparse checkout, and this directory is small. + - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + with: + persist-credentials: false + sparse-checkout: .github/actions + - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: MERGED_SHA: ${{ inputs.merged-as-untrusted-at }} @@ -37,7 +44,7 @@ runs: }) } - // These are set automatically by the spare checkout for .github/actions. + // These are set automatically by the sparse checkout for .github/actions. // Undo them, otherwise git fetch below will not do anything. await run('git', 'config', 'unset', 'remote.origin.promisor') await run('git', 'config', 'unset', 'remote.origin.partialclonefilter') diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index b7ba21272be1..c85a3989219e 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -49,12 +49,8 @@ jobs: runs-on: ${{ matrix.runner }} timeout-minutes: 60 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index faff91d48e6c..84c34887b7f3 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -190,13 +190,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 5 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - - name: Checkout merge and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} @@ -219,13 +214,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 5 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - - name: Checkout merge and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml index 61d8b60d2bab..f971aa0229da 100644 --- a/.github/workflows/eval.yml +++ b/.github/workflows/eval.yml @@ -174,12 +174,8 @@ jobs: sudo mkswap /swap sudo swapon /swap - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Check out the PR at merged and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: # For versioned evals, use the target as the untrusted base and apply the pin-bump commit merged-as-untrusted-at: ${{ matrix.version && inputs.targetSha || inputs.mergedSha }} @@ -259,12 +255,8 @@ jobs: statuses: write # creating 'Eval Summary' commit statuses timeout-minutes: 5 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Check out the PR at the target commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} @@ -477,12 +469,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index b90840319c5b..faa978b13227 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -26,12 +26,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} @@ -61,12 +57,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} @@ -90,12 +82,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout merge and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} diff --git a/.github/workflows/merge-group.yml b/.github/workflows/merge-group.yml index 1156c2a616eb..e111c35ca7c8 100644 --- a/.github/workflows/merge-group.yml +++ b/.github/workflows/merge-group.yml @@ -63,7 +63,7 @@ jobs: check: name: Check needs: [prepare] - uses: ./.github/workflows/check.yml + uses: $/.github/workflows/check.yml permissions: pull-requests: write # cherry-picks: unused in merge queue but required for check workflow secrets: @@ -75,7 +75,7 @@ jobs: lint: name: Lint needs: [prepare] - uses: ./.github/workflows/lint.yml + uses: $/.github/workflows/lint.yml secrets: CACHIX_AUTH_TOKEN_GHA: ${{ secrets.CACHIX_AUTH_TOKEN_GHA }} with: @@ -85,7 +85,7 @@ jobs: eval: name: Eval needs: [prepare] - uses: ./.github/workflows/eval.yml + uses: $/.github/workflows/eval.yml # The eval workflow requests these permissions so we must explicitly allow them, # even though they are unused when working with the merge queue. permissions: @@ -103,7 +103,7 @@ jobs: build: name: Build needs: [prepare] - uses: ./.github/workflows/build.yml + uses: $/.github/workflows/build.yml secrets: CACHIX_AUTH_TOKEN_GHA: ${{ secrets.CACHIX_AUTH_TOKEN_GHA }} with: diff --git a/.github/workflows/periodic-merge-24h.yml b/.github/workflows/periodic-merge-24h.yml index d14c482df755..c6e31f737b6e 100644 --- a/.github/workflows/periodic-merge-24h.yml +++ b/.github/workflows/periodic-merge-24h.yml @@ -40,7 +40,7 @@ jobs: - name: merge-base(master,staging) → haskell-updates from: master staging into: haskell-updates - uses: ./.github/workflows/periodic-merge.yml + uses: $/.github/workflows/periodic-merge.yml with: from: ${{ matrix.pairs.from }} into: ${{ matrix.pairs.into }} diff --git a/.github/workflows/periodic-merge-6h.yml b/.github/workflows/periodic-merge-6h.yml index ad81eb6c9a3b..0da0a3336364 100644 --- a/.github/workflows/periodic-merge-6h.yml +++ b/.github/workflows/periodic-merge-6h.yml @@ -37,7 +37,7 @@ jobs: into: staging - from: master into: staging-nixos - uses: ./.github/workflows/periodic-merge.yml + uses: $/.github/workflows/periodic-merge.yml with: from: ${{ matrix.pairs.from }} into: ${{ matrix.pairs.into }} diff --git a/.github/workflows/pull-request-target.yml b/.github/workflows/pull-request-target.yml index aa42175a0cc1..98d463cb588d 100644 --- a/.github/workflows/pull-request-target.yml +++ b/.github/workflows/pull-request-target.yml @@ -75,7 +75,7 @@ jobs: check: name: Check needs: [prepare] - uses: ./.github/workflows/check.yml + uses: $/.github/workflows/check.yml permissions: # cherry-picks pull-requests: write @@ -92,7 +92,7 @@ jobs: lint: name: Lint needs: [prepare] - uses: ./.github/workflows/lint.yml + uses: $/.github/workflows/lint.yml with: mergedSha: ${{ needs.prepare.outputs.mergedSha }} targetSha: ${{ needs.prepare.outputs.targetSha }} @@ -100,7 +100,7 @@ jobs: eval: name: Eval needs: [prepare] - uses: ./.github/workflows/eval.yml + uses: $/.github/workflows/eval.yml permissions: # compare pull-requests: write @@ -119,7 +119,7 @@ jobs: bot: name: Bot needs: [prepare, eval] - uses: ./.github/workflows/bot.yml + uses: $/.github/workflows/bot.yml permissions: issues: write pull-requests: write @@ -131,7 +131,7 @@ jobs: build: name: Build needs: [prepare] - uses: ./.github/workflows/build.yml + uses: $/.github/workflows/build.yml with: artifact-prefix: ${{ inputs.artifact-prefix }} baseBranch: ${{ needs.prepare.outputs.baseBranch }} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index ad1aaed202ff..35208ae4fab2 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -103,7 +103,7 @@ jobs: if: needs.prepare.outputs.merge-group name: Merge Group needs: [prepare] - uses: ./.github/workflows/merge-group.yml + uses: $/.github/workflows/merge-group.yml # Those are actually only used on the merge_group event, but will throw an error if not set. permissions: pull-requests: write # unused on pull_request, required by merge-group workflow @@ -117,7 +117,7 @@ jobs: if: needs.prepare.outputs.pr name: PR needs: [prepare] - uses: ./.github/workflows/pull-request-target.yml + uses: $/.github/workflows/pull-request-target.yml # Those are actually only used on the pull_request_target event, but will throw an error if not set. permissions: issues: write # unused on pull_request, required by bot workflow diff --git a/ci/github-script/bot.js b/ci/github-script/bot.js index efb5f4935aa8..aa607d0dfc1b 100644 --- a/ci/github-script/bot.js +++ b/ci/github-script/bot.js @@ -491,7 +491,7 @@ export default async ({ github, context, core, dry }) => { ), ).map((id) => parseInt(id)) - prLabels['7.unmaintained'] = + prLabels['7.no default reviewers'] = user_maintainers.length === 0 && team_maintainers.length === 0 && owners.length === 0 diff --git a/ci/pinned.json b/ci/pinned.json index 32f5e186650c..a30aff6f92f8 100644 --- a/ci/pinned.json +++ b/ci/pinned.json @@ -9,9 +9,9 @@ }, "branch": "nixpkgs-unstable", "submodules": false, - "revision": "7525d999cd850b9a488817abc89c75dc733acf17", - "url": "https://github.com/NixOS/nixpkgs/archive/7525d999cd850b9a488817abc89c75dc733acf17.tar.gz", - "hash": "sha256-4IHyyLgLBdKefkljdKod4IMn023pQiDXAWJA187cmdY=" + "revision": "7d5589bbf421c7b6f4185371abe3c465b1b557e9", + "url": "https://github.com/NixOS/nixpkgs/archive/7d5589bbf421c7b6f4185371abe3c465b1b557e9.tar.gz", + "hash": "sha256-8emM5Z42GzMSLLvjJt7UkX1j2k2TKXQIS7FnPTfeHno=" }, "nixpkgs-26.05-darwin": { "type": "Git", @@ -22,9 +22,9 @@ }, "branch": "nixpkgs-26.05-darwin", "submodules": false, - "revision": "51fe96f9107566e6b8eeb7fc4ba696c01e548b04", - "url": "https://github.com/NixOS/nixpkgs/archive/51fe96f9107566e6b8eeb7fc4ba696c01e548b04.tar.gz", - "hash": "sha256-yj0LPLnsmYoLmA3FGANjeTEwej0/DHjZBXWnDQDUuIs=" + "revision": "7486293a941f7b0ec123f0c431517027f705f60f", + "url": "https://github.com/NixOS/nixpkgs/archive/7486293a941f7b0ec123f0c431517027f705f60f.tar.gz", + "hash": "sha256-WQhNWIW3PPijuZexyl5Zf0tJuQ7sKt5C9WPXVO4pMuM=" } }, "version": 8 diff --git a/nixos/modules/hardware/facter/camera/ipu6.nix b/nixos/modules/hardware/facter/camera/ipu6.nix index 5319d8bf3d49..799c22188824 100644 --- a/nixos/modules/hardware/facter/camera/ipu6.nix +++ b/nixos/modules/hardware/facter/camera/ipu6.nix @@ -66,7 +66,7 @@ let in bus_type.name == "PCI" && devices - ? "${vendorHex}:${deviceHex}:${subVendorHex}:${subDeviceHex}/${baseClassHex}-${subClassHex}-${revisionHex}" + ? "${vendorHex}:${deviceHex}:${subVendorHex}:${subDeviceHex}/${baseClassHex}-${subClassHex}-${revisionHex}" ); in { diff --git a/nixos/modules/services/x11/desktop-managers/xfce.nix b/nixos/modules/services/x11/desktop-managers/xfce.nix index 2d53eb58f287..e87e36882206 100644 --- a/nixos/modules/services/x11/desktop-managers/xfce.nix +++ b/nixos/modules/services/x11/desktop-managers/xfce.nix @@ -209,9 +209,9 @@ in DesktopNames=XFCE Keywords=xfce;wayland;desktop;environment;session; '').overrideAttrs - (_: { - passthru.providedSessions = [ "xfce-wayland" ]; - }) + (_: { + passthru.providedSessions = [ "xfce-wayland" ]; + }) ) ]; diff --git a/nixos/modules/tasks/filesystems/vboxsf.nix b/nixos/modules/tasks/filesystems/vboxsf.nix index 3271351a5bca..3cc4b222f755 100644 --- a/nixos/modules/tasks/filesystems/vboxsf.nix +++ b/nixos/modules/tasks/filesystems/vboxsf.nix @@ -13,7 +13,7 @@ let package = pkgs.runCommand "mount.vboxsf" { preferLocalBuild = true; } '' mkdir -p $out/bin - cp ${pkgs.linuxPackages.virtualboxGuestAdditions}/bin/mount.vboxsf $out/bin + cp ${config.virtualisation.virtualbox.guest.package}/bin/mount.vboxsf $out/bin ''; in diff --git a/nixos/modules/virtualisation/virtualbox-guest.nix b/nixos/modules/virtualisation/virtualbox-guest.nix index 882cdf1f0cde..2ce02175b178 100644 --- a/nixos/modules/virtualisation/virtualbox-guest.nix +++ b/nixos/modules/virtualisation/virtualbox-guest.nix @@ -7,7 +7,6 @@ }: let cfg = config.virtualisation.virtualbox.guest; - kernel = config.boot.kernelPackages; mkVirtualBoxUserService = serviceArgs: verbose: { description = "VirtualBox Guest User Services ${serviceArgs}"; @@ -25,7 +24,7 @@ let preStart = "${pkgs.bash}/bin/bash -c \"if [ -z $DISPLAY ]; then exit 1; fi\""; serviceConfig = { ExecStart = - "@${kernel.virtualboxGuestAdditions}/bin/VBoxClient" + "@${cfg.package}/bin/VBoxClient" + (lib.strings.optionalString verbose " --verbose") + " --foreground ${serviceArgs}"; # Wait after a failure, hoping that the display environment is ready after waiting @@ -66,6 +65,10 @@ in description = "Whether to enable the VirtualBox service and other guest additions."; }; + package = lib.mkPackageOption config.boot.kernelPackages "virtualboxGuestAdditions" { + pkgsText = "config.boot.kernelPackages"; + }; + clipboard = lib.mkOption { default = true; type = lib.types.bool; @@ -115,9 +118,9 @@ in } ]; - environment.systemPackages = [ kernel.virtualboxGuestAdditions ]; + environment.systemPackages = [ cfg.package ]; - boot.extraModulePackages = lib.mkIf cfg.use3rdPartyModules [ kernel.virtualboxGuestAdditions ]; + boot.extraModulePackages = lib.mkIf cfg.use3rdPartyModules [ cfg.package ]; systemd.services.virtualbox = { description = "VirtualBox Guest Services"; @@ -128,7 +131,7 @@ in unitConfig.ConditionVirtualization = "oracle"; - serviceConfig.ExecStart = "@${kernel.virtualboxGuestAdditions}/bin/VBoxService VBoxService --foreground"; + serviceConfig.ExecStart = "@${cfg.package}/bin/VBoxService VBoxService --foreground"; }; users.groups.vboxuserdev = { }; diff --git a/pkgs/applications/virtualization/virtualbox/guest-additions/builder.nix b/pkgs/applications/virtualization/virtualbox/guest-additions/builder.nix index 39b79420732b..d50770932428 100644 --- a/pkgs/applications/virtualization/virtualbox/guest-additions/builder.nix +++ b/pkgs/applications/virtualization/virtualbox/guest-additions/builder.nix @@ -1,26 +1,26 @@ { - stdenv, - kernel, - fetchurl, - lib, - pam, - libxslt, - libxext, - libxcursor, - libxmu, - glib, - libxrandr, dbus, - xz, + fetchurl, + glib, + lib, + libxcrypt, + libxcursor, + libxext, + libxmu, + libxrandr, + libxslt, + linuxHeaders, + makeself, + openssl, + pam, + patchelf, pkg-config, + stdenv, which, xorg-server, xrandr, + xz, yasm, - patchelf, - makeself, - linuxHeaders, - openssl, virtualboxVersion, virtualboxSubVersion, virtualboxSha256, @@ -31,7 +31,7 @@ let buildType = "release"; in stdenv.mkDerivation (finalAttrs: { - pname = "VirtualBox-GuestAdditions-builder-${kernel.version}"; + pname = "VirtualBox-GuestAdditions-builder"; version = "${virtualboxVersion}${virtualboxSubVersion}"; inherit virtualboxVersion virtualboxSubVersion; @@ -53,8 +53,9 @@ stdenv.mkDerivation (finalAttrs: { openssl linuxHeaders xz - ] - ++ kernel.moduleBuildDependencies; + libxcrypt + ]; + buildInputs = [ dbus libxslt @@ -65,9 +66,6 @@ stdenv.mkDerivation (finalAttrs: { libxrandr ]; - KERN_DIR = "${kernel.dev}/lib/modules/${kernel.modDirVersion}/build"; - KERN_INCL = "${kernel.dev}/lib/modules/${kernel.modDirVersion}/source/include"; - prePatch = '' rm -r src/VBox/Additions/x11/x11include/ rm -r src/VBox/Additions/3D/mesa/mesa-*/ @@ -139,7 +137,6 @@ stdenv.mkDerivation (finalAttrs: { ./configure \ --only-additions \ - --with-linux=${kernel.dev} \ --disable-kmods sed -e 's@PKG_CONFIG_PATH=.*@PKG_CONFIG_PATH=${glib.dev}/lib/pkgconfig @' \ diff --git a/pkgs/build-support/dart/pub2nix/pubspec-lock.nix b/pkgs/build-support/dart/pub2nix/pubspec-lock.nix index 456236e18e5e..5ea72683e1fc 100644 --- a/pkgs/build-support/dart/pub2nix/pubspec-lock.nix +++ b/pkgs/build-support/dart/pub2nix/pubspec-lock.nix @@ -150,7 +150,7 @@ let "sdk" = mkSdkDependencySource; } .${details.source} - name + name ) details )) diff --git a/pkgs/by-name/cr/croaring/package.nix b/pkgs/by-name/cr/croaring/package.nix index d020dce7b4b9..7bde08508c2e 100644 --- a/pkgs/by-name/cr/croaring/package.nix +++ b/pkgs/by-name/cr/croaring/package.nix @@ -8,13 +8,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "croaring"; - version = "5.2.0"; + version = "5.2.2"; src = fetchFromGitHub { owner = "RoaringBitmap"; repo = "CRoaring"; tag = "v${finalAttrs.version}"; - hash = "sha256-BDQpqRlle9mjlybOjxctwxkP5rQl2y673EnpthjFbBA="; + hash = "sha256-ZipK1pNdxNaEAVkFygH6pwOHXvQWfGKVk1S6onKpvPE="; }; # roaring.pc.in cannot handle absolute CMAKE_INSTALL_*DIRs, nor diff --git a/pkgs/by-name/de/deskflow/package.nix b/pkgs/by-name/de/deskflow/package.nix index f159d015d3a3..6a562cd53954 100644 --- a/pkgs/by-name/de/deskflow/package.nix +++ b/pkgs/by-name/de/deskflow/package.nix @@ -2,31 +2,42 @@ lib, stdenv, fetchFromGitHub, + + # nativeBuildInputs cmake, + doxygen, ninja, pkg-config, + qt6, + + # nativeCheckInputs + writableTmpDirAsHomeHook, + + # buildInputs (Linux and Darwin) gtest, - libei, - libportal, - libx11, - libxkbfile, - libxtst, - libxinerama, - libxi, - libxrandr, - libxkbcommon, + openssl, pugixml, python3, + + # buildInputs (Linux-specific) gdk-pixbuf, - libnotify, - qt6, - xkeyboard_config, - wayland-protocols, - wayland, - libsysprof-capture, lerc, - doxygen, - writableTmpDirAsHomeHook, + libei, + libnotify, + libportal, + libsysprof-capture, + libx11, + libxi, + libxinerama, + libxkbcommon, + libxkbfile, + libxrandr, + libxtst, + wayland, + wayland-protocols, + xkeyboard_config, + + # Update script for `passthru`. nix-update-script, }: @@ -41,55 +52,68 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-XcSG47Ysjn+wrJH5DC/XXGXcneXcW7xIhAn6sguuv+s="; }; - postPatch = '' - substituteInPlace src/lib/deskflow/unix/AppUtilUnix.cpp \ - --replace-fail "/usr/share/X11/xkb/rules/evdev.xml" "${xkeyboard_config}/share/X11/xkb/rules/evdev.xml" - substituteInPlace deploy/linux/deploy.cmake \ - --replace-fail 'message(FATAL_ERROR "Unable to read file /etc/os-release")' 'set(RELEASE_FILE_CONTENTS "")' - ''; - nativeBuildInputs = [ cmake + doxygen ninja pkg-config qt6.wrapQtAppsHook - doxygen # docs ]; - cmakeFlags = [ - "-DCMAKE_SKIP_RPATH=ON" # Avoid generating incorrect RPATH - ]; - - strictDeps = true; - buildInputs = [ gtest - libei - libportal - libx11 - libxkbfile - libxinerama - libxi - libxrandr - libxtst - libxkbcommon + openssl pugixml - gdk-pixbuf - libnotify python3 qt6.qtbase - wayland-protocols - qt6.qtwayland - qt6.qtdeclarative qt6.qttools - wayland - libsysprof-capture + qt6.qttranslations + ] + ++ (lib.optionals stdenv.hostPlatform.isLinux [ + gdk-pixbuf lerc + libei + libnotify + libportal + libsysprof-capture + libx11 + libxi + libxinerama + libxkbcommon + libxkbfile + libxrandr + libxtst + qt6.qtdeclarative + qt6.qtwayland + wayland + wayland-protocols + ]); + + preConfigure = lib.optionalString stdenv.hostPlatform.isDarwin '' + export PATH="${qt6.qtbase}/bin:$PATH" + ''; + + postPatch = '' + ${lib.optionalString stdenv.hostPlatform.isLinux '' + substituteInPlace src/lib/deskflow/unix/AppUtilUnix.cpp \ + --replace-fail "/usr/share/X11/xkb/rules/evdev.xml" "${xkeyboard_config}/share/X11/xkb/rules/evdev.xml" + substituteInPlace deploy/linux/deploy.cmake \ + --replace-fail 'message(FATAL_ERROR "Unable to read file /etc/os-release")' 'set(RELEASE_FILE_CONTENTS "")' + ''} + substituteInPlace translations/CMakeLists.txt \ + --replace-fail 'PATHS ''${QT_ROOT_DIR} PATH_SUFFIXES "translations" "share/qt/translations"' 'PATHS "${qt6.qttranslations}/translations"' + substituteInPlace src/lib/net/CMakeLists.txt \ + --replace-fail "set(OPENSSL_USE_STATIC_LIBS TRUE)" "" + ''; + + cmakeFlags = [ + "-DCMAKE_SKIP_RPATH=ON" # Avoid generating incorrect RPATH + "-DSKIP_BUILD_TESTS=ON" # Perform unit tests in `checkPhase` manually, with one job at a time. ]; - qtWrapperArgs = [ - "--set QT_QPA_PLATFORM_PLUGIN_PATH ${qt6.qtwayland}/${qt6.qtbase.qtPluginPrefix}/platforms" - ]; + qtWrapperArgs = lib.optional stdenv.hostPlatform.isLinux "--set QT_QPA_PLATFORM_PLUGIN_PATH ${qt6.qtwayland}/${qt6.qtbase.qtPluginPrefix}/platforms"; + + strictDeps = true; doCheck = true; @@ -99,6 +123,8 @@ stdenv.mkDerivation (finalAttrs: { runHook preCheck export QT_QPA_PLATFORM=offscreen + ctest --test-dir "src/unittests" --output-on-failure \ + --exclude-regex "OSX(KeyState|Clipboard)Tests" ./bin/legacytests runHook postCheck @@ -119,12 +145,15 @@ stdenv.mkDerivation (finalAttrs: { homepage = "https://github.com/deskflow/deskflow"; description = "Share one mouse and keyboard between multiple computers on Windows, macOS and Linux"; mainProgram = "deskflow"; - maintainers = with lib.maintainers; [ flacks ]; + maintainers = with lib.maintainers; [ + flacks + shymega + ]; license = with lib.licenses; [ gpl2Plus - openssl + lib.licenses.openssl # We have to be explicit here, as `openssl` is a buildInput. mit # share/applications/org.deskflow.deskflow.desktop ]; - platforms = lib.platforms.linux; + platforms = lib.platforms.unix; }; }) diff --git a/pkgs/by-name/ed/edhm-ui/package.nix b/pkgs/by-name/ed/edhm-ui/package.nix index 3cdf18a1c09f..ef5ef738dbf0 100644 --- a/pkgs/by-name/ed/edhm-ui/package.nix +++ b/pkgs/by-name/ed/edhm-ui/package.nix @@ -28,13 +28,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "edhm-ui"; - version = "3.0.71"; + version = "3.0.72"; strictDeps = true; src = fetchzip { url = "https://github.com/BlueMystical/EDHM_UI/releases/download/v${finalAttrs.version}/edhm-ui-v3-linux-x64.zip"; - hash = "sha256-wMsP2VeSbo78II/tT5nBAvOIQc3lCBqy+l0F2r3ulEM="; + hash = "sha256-bpYNl/I2T3sNbhjqqbYXo7c8JWi9tUBBDX/aRSIz+rA="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/el/element-desktop/package.nix b/pkgs/by-name/el/element-desktop/package.nix index 4a26d243a711..f6c3dc15e8c4 100644 --- a/pkgs/by-name/el/element-desktop/package.nix +++ b/pkgs/by-name/el/element-desktop/package.nix @@ -112,6 +112,9 @@ stdenv.mkDerivation (finalAttrs: { asar pack tmp-app "$packed" + # element-web is linked into the output during installPhase. + find ./dist -name webapp.asar -delete + runHook postBuild ''; diff --git a/pkgs/by-name/gi/gitoxide/package.nix b/pkgs/by-name/gi/gitoxide/package.nix index f93357c38743..5f7c89f1e744 100644 --- a/pkgs/by-name/gi/gitoxide/package.nix +++ b/pkgs/by-name/gi/gitoxide/package.nix @@ -18,16 +18,16 @@ let in rustPlatform.buildRustPackage (finalAttrs: { pname = "gitoxide"; - version = "0.58.0"; + version = "0.59.0"; src = fetchFromGitHub { owner = "GitoxideLabs"; repo = "gitoxide"; tag = "v${finalAttrs.version}"; - hash = "sha256-NKpOMgB/p7p1tZvU929LUieDKInksCP4gZ3tkI1FIrY="; + hash = "sha256-TWA2SUoqEVjplEtzTApQ/HZgBkUxDeuf/GcM+qJF4fg="; }; - cargoHash = "sha256-0hCkvVFxdVdEDB0x7pd0CnKnKWOxGzbtBO9EFj9z9f4="; + cargoHash = "sha256-Mx6iWy1U8/zYzrgVfbpVG73/0lYJS8juupmbbKQlNQY="; nativeBuildInputs = [ cmake diff --git a/pkgs/by-name/in/incus/lts.nix b/pkgs/by-name/in/incus/lts.nix index a0185fba0496..db6653351259 100644 --- a/pkgs/by-name/in/incus/lts.nix +++ b/pkgs/by-name/in/incus/lts.nix @@ -111,7 +111,62 @@ import ./generic.nix { url = "https://github.com/lxc/incus/commit/9e188e31e43c21fa8f2a4cac265aa246d4c947f2.patch?full_index=1"; hash = "sha256-KFYKB9PJK/U4/jSe3rmMeR9FWevvvi47BRy055Zj8Io="; }) - + # incus/file: Contain recursive pull symlinks + (fetchpatch2 { + url = "https://salsa.debian.org/go-team/packages/incus/-/raw/4992bd88f727414d9f02e9966feb235daf8d755d/debian/patches/126-GHSA-wfvq-qh87-gm4j.patch"; + hash = "sha256-hD7l9/mlUuISLV1hrvuYMyPFYe1XUWnLO15RJyO1ZlA="; + }) + # incusd: Don't follow symlinks when receiving migration + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/9afa3d58ef9ffae40eb1980bd33592d00fe1feba.patch?full_index=1"; + hash = "sha256-SJKrTdR/BKNVPa9P7Yowukfm71D3M9yGh1iGQpkhEDE="; + }) + # incusd/storage: Treat volume creation with a source as a copy (sourced from stable-7.0) + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/e59d35263a0e027b4a0344ab8d05c80c622a21e2.patch?full_index=1"; + hash = "sha256-oHM9IGGjPRwsmc5JAYaBY65HV+H3ZC1/ebqQts/tDow="; + }) + # incusd/storage/drivers: Confine btrfs subvolume paths + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/99a8ba3101e91be6cd7013e80ff916f32d495b71.patch?full_index=1"; + hash = "sha256-iwybe/E8Lucwf6ih6gWt3b/jnG3UGYep2GoqL/h4qn8="; + }) + # incusd/storage: Validate dependent volume names on backup import + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/2ef78c71a5f3c9db4a6ad438563ec99497686d83.patch?full_index=1"; + hash = "sha256-apBgxM15JA+8q/lR5mJRG85rBn+2pEuZdcgOjPn/y8g="; + }) + # incusd/storage: Ignore backup project for dependent + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/10d6ea9a7163c2a7b16f9e9ccf0bd45981c3355e.patch?full_index=1"; + hash = "sha256-5gkMiAb5Ewzsiv9LmZ2oJx+7xTdIbkVnXEkt67metlU="; + }) + # incusd/storage/s3: Require x-amz-* headers to be signed + (fetchpatch2 { + url = "https://salsa.debian.org/go-team/packages/incus/-/raw/4992bd88f727414d9f02e9966feb235daf8d755d/debian/patches/123-GHSA-mmj7-8rgf-mx2h.patch"; + hash = "sha256-OHjdOPQ3UyNfucLElKXA4iRYVhOF6fq+m0wUnaYGoiI="; + }) + # incusd/operations: Check project access on operation get and wait + # incusd/operations: Hide access token operations from non-admins + (fetchpatch2 { + url = "https://salsa.debian.org/go-team/packages/incus/-/raw/bdec650ea4657450a90300c1e25e4d9b5ba71547/debian/patches/125-GHSA-mfwv-x733-9446.patch"; + hash = "sha256-LMx5sb7rC5U9BLsXYhqN3SaW7K/d4q2H1OvcDQPNm7w="; + }) + # incusd/storage/buckets: Require can_edit to read bucket keys + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/1eaf9b8bfed2b8cf09182c88fd81b10327605ade.patch?full_index=1"; + hash = "sha256-KrQtsS8Ug7K5bMeduV9tPeunHOnCXfNNqlbpVMTNzws="; + }) + # incusd/project: Restrict volume options on update and copy + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/da36896aa8af65080a79fd1a4b8abcf75d46cbd1.patch?full_index=1"; + hash = "sha256-+W+2RXtJO/IGd+ejpkylsaNfH8JtSIMTun9bxbtbPxU="; + }) + # incusd/instances: Check project restrictions on clustered refresh + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/f22d8a92dff8e4cf01260ab85405db754bcfc026.patch?full_index=1"; + hash = "sha256-LwQRWQzZewU0QjdaerKFJb4h99RKuTLBZ80PifJONkM="; + }) ]; lts = true; nixUpdateExtraArgs = [ diff --git a/pkgs/by-name/in/iniparser/package.nix b/pkgs/by-name/in/iniparser/package.nix index 260dfdf1887f..5048189a30ad 100644 --- a/pkgs/by-name/in/iniparser/package.nix +++ b/pkgs/by-name/in/iniparser/package.nix @@ -54,9 +54,9 @@ stdenv.mkDerivation (finalAttrs: { (unity-test.override { supportDouble = true; }).overrideAttrs - { - doCheck = false; - } + { + doCheck = false; + } ) ]; diff --git a/pkgs/by-name/je/jellyfin/package.nix b/pkgs/by-name/je/jellyfin/package.nix index d0dabbd88fc7..31ae8c923ca0 100644 --- a/pkgs/by-name/je/jellyfin/package.nix +++ b/pkgs/by-name/je/jellyfin/package.nix @@ -32,6 +32,18 @@ buildDotnetModule (finalAttrs: { hash = "sha256-TxGo+sLLG+C9omxrwvO6byzw+iRqONVLXrQKwkrY22s="; }) + # GHSA-6828-c7cx-hvqm: confine virtual-folder operations to the libraries root. + (fetchpatch { + url = "https://github.com/jellyfin/jellyfin/commit/0c560b22ce73323329645b836c9910abc257ce4e.patch"; + hash = "sha256-K/og9MDP4BNexkDGLOm346O9anqAjb13UViSAmOw2OA="; + }) + + # GHSA-4vx8-xhc9-qg6x: enforce remote-control permissions between user sessions. + (fetchpatch { + url = "https://github.com/jellyfin/jellyfin/commit/dd7de4187879082e10b474856f705b6c5d9b963a.patch"; + hash = "sha256-OCj4aaKaX4F/+KbCz6BAsifdYe/6BOu6y39ZgMSUKFA="; + }) + # Fix MaxLoginAttempts not honored. # https://github.com/jellyfin/jellyfin/pull/17274 (fetchpatch { diff --git a/pkgs/by-name/mi/microsoft-edge/package.nix b/pkgs/by-name/mi/microsoft-edge/package.nix index fe79b99032cd..13cdd8b602e7 100644 --- a/pkgs/by-name/mi/microsoft-edge/package.nix +++ b/pkgs/by-name/mi/microsoft-edge/package.nix @@ -164,11 +164,11 @@ let in stdenvNoCC.mkDerivation (finalAttrs: { pname = "microsoft-edge"; - version = "153.0.4234.48"; + version = "154.0.4258.37"; src = fetchurl { url = "https://packages.microsoft.com/repos/edge/pool/main/m/microsoft-edge-stable/microsoft-edge-stable_${finalAttrs.version}-1_amd64.deb"; - hash = "sha256-JVNZQo8F9xzWNpKmJlwOKnRf/wiuDkJh+c/tUdgIEC8="; + hash = "sha256-xvopdHM5kTIbRsQGS3hc3sWhTYzd0YK8X9oFfjfnYD0="; }; # With strictDeps on, some shebangs were not being patched correctly diff --git a/pkgs/by-name/ms/msedgedriver/package.nix b/pkgs/by-name/ms/msedgedriver/package.nix index c258d19d2f3e..43de4807a9a0 100644 --- a/pkgs/by-name/ms/msedgedriver/package.nix +++ b/pkgs/by-name/ms/msedgedriver/package.nix @@ -12,11 +12,11 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "msedgedriver"; - version = "153.0.4234.48"; + version = "154.0.4258.37"; src = fetchzip { url = "https://msedgedriver.microsoft.com/${finalAttrs.version}/edgedriver_linux64.zip"; - hash = "sha256-5gCrPPjYC/AmsO5vSNTX/r3hm6wATvNeIxRt4TYyZhY="; + hash = "sha256-XbOQl9FyckF3Qybb+40474ImJDKahBkekPoydf/TxV0="; stripRoot = false; }; diff --git a/pkgs/by-name/np/np2kai/package.nix b/pkgs/by-name/np/np2kai/package.nix index 3245c09ad3fb..947addd0aa32 100644 --- a/pkgs/by-name/np/np2kai/package.nix +++ b/pkgs/by-name/np/np2kai/package.nix @@ -121,8 +121,10 @@ stdenv.mkDerivation (finalAttrs: { meta = { description = "PC-9801 series emulator"; homepage = "https://github.com/AZO234/NP2kai"; - license = lib.licenses.mit; - maintainers = with lib.maintainers; [ OPNA2608 ]; + # Information on the repo is untrustworthy. + # This is a fork from the original np2, which lacked any licensing information for most of its code -> Unfree + license = lib.licenses.unfree; + maintainers = [ ]; mainProgram = "${if enableX11 then "x" else "sdl"}np21kai"; platforms = lib.platforms.x86; }; diff --git a/pkgs/by-name/od/odamex/package.nix b/pkgs/by-name/od/odamex/package.nix index b98c575dda8f..972b7a209065 100644 --- a/pkgs/by-name/od/odamex/package.nix +++ b/pkgs/by-name/od/odamex/package.nix @@ -43,13 +43,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "odamex"; - version = "12.2.0"; + version = "12.3.0"; src = fetchFromGitHub { owner = "odamex"; repo = "odamex"; tag = finalAttrs.version; - hash = "sha256-cRQtY4C0gjzheE4cG8aPjzAoPf/Hm05a6tidsbce7uM="; + hash = "sha256-JT8flyIEHfCejJnRd+bpUGKNAM746i51EuTItLho5WE="; fetchSubmodules = true; }; diff --git a/pkgs/by-name/re/resources/package.nix b/pkgs/by-name/re/resources/package.nix index e246a11f51c2..1ed6c88a175c 100644 --- a/pkgs/by-name/re/resources/package.nix +++ b/pkgs/by-name/re/resources/package.nix @@ -1,7 +1,7 @@ { lib, stdenv, - fetchFromGitHub, + fetchFromGitLab, appstream-glib, autoAddDriverRunpath, cargo, @@ -18,23 +18,25 @@ dmidecode, util-linux, systemd, + libsoup_3, nix-update-script, }: stdenv.mkDerivation (finalAttrs: { pname = "resources"; - version = "1.10.2"; + version = "51.0"; - src = fetchFromGitHub { - owner = "nokyan"; + src = fetchFromGitLab { + domain = "gitlab.gnome.org"; + owner = "GNOME/Incubator"; repo = "resources"; - tag = "v${finalAttrs.version}"; - hash = "sha256-BkyWq3Cwt34lNQ/p1iQcfIlkCefE2YeiQMd1T6ODbxw="; + tag = finalAttrs.version; + hash = "sha256-ZdLBWawoD07SxC+/QTeyOXx7uAyazP6XjLeTF6lsWRw="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) pname version src; - hash = "sha256-zzSqwc+MoYoieOT0qmgfxKG8/HLGTVsTgcru5wZgn2M="; + hash = "sha256-m4LwmA5mwd2bUK5X26HJvIr6hxf75O+9WGEfYVthSh0="; }; nativeBuildInputs = [ @@ -54,6 +56,7 @@ stdenv.mkDerivation (finalAttrs: { glib gtk4 libadwaita + libsoup_3 ]; # Check all Command::new @@ -63,10 +66,6 @@ stdenv.mkDerivation (finalAttrs: { systemd # udevadm ]; - mesonFlags = [ - (lib.mesonOption "profile" "default") - ]; - preFixup = '' gappsWrapperArgs+=(--prefix PATH : ${lib.makeBinPath finalAttrs.runtimeDeps}) ''; @@ -76,10 +75,9 @@ stdenv.mkDerivation (finalAttrs: { }; meta = { - changelog = "https://github.com/nokyan/resources/releases/tag/v${finalAttrs.version}"; description = "Monitor your system resources and processes"; - homepage = "https://github.com/nokyan/resources"; - license = lib.licenses.gpl3Only; + homepage = "https://gitlab.gnome.org/GNOME/Incubator/resources"; + license = lib.licenses.gpl3Plus; mainProgram = "resources"; maintainers = with lib.maintainers; [ lukas-heiligenbrunner diff --git a/pkgs/by-name/ro/rojo/package.nix b/pkgs/by-name/ro/rojo/package.nix index 6641cd8af4ef..cd7fde4df78b 100644 --- a/pkgs/by-name/ro/rojo/package.nix +++ b/pkgs/by-name/ro/rojo/package.nix @@ -10,17 +10,17 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "rojo"; - version = "7.6.1"; + version = "7.7.0"; src = fetchFromGitHub { owner = "rojo-rbx"; repo = "rojo"; tag = "v${finalAttrs.version}"; - hash = "sha256-h8gd91Nc35jTQ4u9YyQGOB+rkgRAos8lsjX+bWzvpDs="; + hash = "sha256-2atNAiv51MNpxXdwvKSvtO1CGvQUOdUUOZszjAm3zi8="; fetchSubmodules = true; }; - cargoHash = "sha256-zl1L8q1AJwVn0o2BazJ30FyBCMq5F5nAQ0FGuEAPGms="; + cargoHash = "sha256-1xTvW3Ra6erYpjxgfp2m8qVMz6u99WCDv2VE/Xh2mFc="; nativeBuildInputs = [ pkg-config ]; buildInputs = [ openssl ]; diff --git a/pkgs/by-name/su/sub-store-frontend/package.nix b/pkgs/by-name/su/sub-store-frontend/package.nix index 77829b5c17cc..f72b225d21bd 100644 --- a/pkgs/by-name/su/sub-store-frontend/package.nix +++ b/pkgs/by-name/su/sub-store-frontend/package.nix @@ -14,13 +14,13 @@ let in buildNpmPackage (finalAttrs: { pname = "sub-store-frontend"; - version = "2.32.2"; + version = "2.34.0"; src = fetchFromGitHub { owner = "sub-store-org"; repo = "Sub-Store-Front-End"; tag = finalAttrs.version; - hash = "sha256-TbKJNSA+ivUd7bHDtE9COaZFMqxRkRdBXWkK7y7JMSU="; + hash = "sha256-jphgUjJouLky6jxTSk+6YBbwaNTV7+/oTu2RXc3UNk0="; }; nativeBuildInputs = [ diff --git a/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix b/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix index 80dad06be8f8..a5220d11a2fa 100644 --- a/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix +++ b/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix @@ -28,9 +28,9 @@ runCommand "${pname}-filtered-src" enableOpenSSL = false; enableLZ4 = false; }).overrideAttrs - { - doCheck = false; - } + { + doCheck = false; + } ) ]; } diff --git a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix index af09d19e91dc..48c5f29ceb97 100644 --- a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix +++ b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix @@ -15,14 +15,14 @@ let variants = { # ./update-xanmod.sh lts lts = { - version = "6.18.53"; - hash = "sha256-+2DnSpnBekGDBeXMjwGNrBFexnYmqQCc93LjDaseD/8="; + version = "6.18.54"; + hash = "sha256-yD6dpnyQsAxwePJMIcZAi5cECFvH7xKoimcpAVYzGtI="; isLTS = true; }; # ./update-xanmod.sh main main = { - version = "7.2.7"; - hash = "sha256-QeEJiBJfQloehzZppWX8zvL43UGSMa4xUicA1VXN6f0="; + version = "7.2.8"; + hash = "sha256-jHCIFm1xI3T/2Zl0h91Nf6oAr4ozIPQSYRFo92KmOfc="; }; }; diff --git a/pkgs/servers/nextcloud/notify_push.nix b/pkgs/servers/nextcloud/notify_push.nix index 895362d848af..5385a01720c5 100644 --- a/pkgs/servers/nextcloud/notify_push.nix +++ b/pkgs/servers/nextcloud/notify_push.nix @@ -13,22 +13,22 @@ rustPlatform.buildRustPackage rec { # in nixpkgs! # For that, check the `` section of `appinfo/info.xml` # in the app (https://github.com/nextcloud/notify_push/blob/main/appinfo/info.xml) - version = "1.3.3"; + version = "1.4.1"; src = fetchFromGitHub { owner = "nextcloud"; repo = "notify_push"; tag = "v${version}"; - hash = "sha256-DMyqixeO1SfRvfuIpBHEaym6qH5X5Yw94tfWLCFkrBg="; + hash = "sha256-lg/gffgfUJHLCL1TOPdYAw7DtRZeGDH+jO9deQSUbEY="; }; - cargoHash = "sha256-fdf7AvT511WRjsOyM4+3vieuQMh24C+mF49pWtfS41Y="; + cargoHash = "sha256-skKOCJBtpvtdc594eOxbvSIl+SucaH0jl1gFv9kfvNA="; passthru = rec { app = fetchNextcloudApp { appName = "notify_push"; appVersion = version; - hash = "sha256-gHRegrl1VtJOiB6xLUHtG3sxkCDv7/zhrhQ9B+9i8YI="; + hash = "sha256-C/2jXLpuIbxjWO3kMb3nkLA5762uVLuzk1YPz/YSfjY="; license = "agpl3Plus"; homepage = "https://github.com/nextcloud/notify_push"; url = "https://github.com/nextcloud-releases/notify_push/releases/download/v${version}/notify_push-v${version}.tar.gz"; @@ -41,7 +41,7 @@ rustPlatform.buildRustPackage rec { buildAndTestSubdir = "test_client"; - cargoHash = "sha256-fdf7AvT511WRjsOyM4+3vieuQMh24C+mF49pWtfS41Y="; + cargoHash = "sha256-skKOCJBtpvtdc594eOxbvSIl+SucaH0jl1gFv9kfvNA="; meta = meta // { mainProgram = "test_client"; diff --git a/pkgs/tools/networking/openvpn/default.nix b/pkgs/tools/networking/openvpn/default.nix index a61d981d53f0..3aca471c2a70 100644 --- a/pkgs/tools/networking/openvpn/default.nix +++ b/pkgs/tools/networking/openvpn/default.nix @@ -23,11 +23,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "openvpn"; - version = "2.6.21"; + version = "2.6.23"; src = fetchurl { url = "https://swupdate.openvpn.net/community/releases/openvpn-${finalAttrs.version}.tar.gz"; - hash = "sha256-JMthheVEpHMj1nmLA9OfI2fZbyJ77pzRVD6O1Sgxmxc="; + hash = "sha256-QEHHCRYr7BMlq/WqjPJ6JVzEd8Y0sV7jEEEccB/ECpY="; }; nativeBuildInputs = [