From 4a9d516560e5d7f8d2f1c906dd1b43b06e883264 Mon Sep 17 00:00:00 2001 From: Grayson Tinker Date: Mon, 14 Sep 2026 11:45:18 -0600 Subject: [PATCH 01/29] resources: fix license (cherry picked from commit 767361c89d6fdde8f36aca3b9b1cb2475e198feb) --- pkgs/by-name/re/resources/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/re/resources/package.nix b/pkgs/by-name/re/resources/package.nix index e246a11f51c2..4946f8f1e76e 100644 --- a/pkgs/by-name/re/resources/package.nix +++ b/pkgs/by-name/re/resources/package.nix @@ -79,7 +79,7 @@ stdenv.mkDerivation (finalAttrs: { changelog = "https://github.com/nokyan/resources/releases/tag/v${finalAttrs.version}"; description = "Monitor your system resources and processes"; homepage = "https://github.com/nokyan/resources"; - license = lib.licenses.gpl3Only; + license = lib.licenses.gpl3Plus; mainProgram = "resources"; maintainers = with lib.maintainers; [ lukas-heiligenbrunner From 62973f84027dfe0a41c306db1e20662419a6a7e3 Mon Sep 17 00:00:00 2001 From: Grayson Tinker Date: Mon, 14 Sep 2026 11:45:18 -0600 Subject: [PATCH 02/29] resources: 1.10.2 -> 51 (cherry picked from commit 061813a9b53749f001e0c12847d7c71b5bd71184) --- pkgs/by-name/re/resources/package.nix | 24 +++++++++++------------- 1 file changed, 11 insertions(+), 13 deletions(-) diff --git a/pkgs/by-name/re/resources/package.nix b/pkgs/by-name/re/resources/package.nix index 4946f8f1e76e..1ed6c88a175c 100644 --- a/pkgs/by-name/re/resources/package.nix +++ b/pkgs/by-name/re/resources/package.nix @@ -1,7 +1,7 @@ { lib, stdenv, - fetchFromGitHub, + fetchFromGitLab, appstream-glib, autoAddDriverRunpath, cargo, @@ -18,23 +18,25 @@ dmidecode, util-linux, systemd, + libsoup_3, nix-update-script, }: stdenv.mkDerivation (finalAttrs: { pname = "resources"; - version = "1.10.2"; + version = "51.0"; - src = fetchFromGitHub { - owner = "nokyan"; + src = fetchFromGitLab { + domain = "gitlab.gnome.org"; + owner = "GNOME/Incubator"; repo = "resources"; - tag = "v${finalAttrs.version}"; - hash = "sha256-BkyWq3Cwt34lNQ/p1iQcfIlkCefE2YeiQMd1T6ODbxw="; + tag = finalAttrs.version; + hash = "sha256-ZdLBWawoD07SxC+/QTeyOXx7uAyazP6XjLeTF6lsWRw="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) pname version src; - hash = "sha256-zzSqwc+MoYoieOT0qmgfxKG8/HLGTVsTgcru5wZgn2M="; + hash = "sha256-m4LwmA5mwd2bUK5X26HJvIr6hxf75O+9WGEfYVthSh0="; }; nativeBuildInputs = [ @@ -54,6 +56,7 @@ stdenv.mkDerivation (finalAttrs: { glib gtk4 libadwaita + libsoup_3 ]; # Check all Command::new @@ -63,10 +66,6 @@ stdenv.mkDerivation (finalAttrs: { systemd # udevadm ]; - mesonFlags = [ - (lib.mesonOption "profile" "default") - ]; - preFixup = '' gappsWrapperArgs+=(--prefix PATH : ${lib.makeBinPath finalAttrs.runtimeDeps}) ''; @@ -76,9 +75,8 @@ stdenv.mkDerivation (finalAttrs: { }; meta = { - changelog = "https://github.com/nokyan/resources/releases/tag/v${finalAttrs.version}"; description = "Monitor your system resources and processes"; - homepage = "https://github.com/nokyan/resources"; + homepage = "https://gitlab.gnome.org/GNOME/Incubator/resources"; license = lib.licenses.gpl3Plus; mainProgram = "resources"; maintainers = with lib.maintainers; [ From df4105ad5532e9a10c68c029ba5055e7a336d436 Mon Sep 17 00:00:00 2001 From: Dom Rodriguez Date: Wed, 24 Jun 2026 18:48:08 +0100 Subject: [PATCH 03/29] deskflow: Run tests sequentially to prevent race conditions Deskflow writes to a config file and reads it back during `checkPhase` (specifically, the unit tests), and due to parallelism, this causes a race condition, and fails the unit tests. This commit disables the implicit tests that run during build with CMake, and *explicitly* runs the unit tests in `checkPhase`, with `-j1`, as well as the legacy tests, which mean the tests will not race against the same file. Relates to build failure in #503256. (cherry picked from commit 9a792a7ac3a4fb4a8e04f0a189b48ecc262f3b34) --- pkgs/by-name/de/deskflow/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/de/deskflow/package.nix b/pkgs/by-name/de/deskflow/package.nix index f159d015d3a3..dec4016133dd 100644 --- a/pkgs/by-name/de/deskflow/package.nix +++ b/pkgs/by-name/de/deskflow/package.nix @@ -58,6 +58,7 @@ stdenv.mkDerivation (finalAttrs: { cmakeFlags = [ "-DCMAKE_SKIP_RPATH=ON" # Avoid generating incorrect RPATH + "-DSKIP_BUILD_TESTS=ON" # Perform unit tests in `checkPhase` manually, with one job at a time. ]; strictDeps = true; @@ -99,6 +100,7 @@ stdenv.mkDerivation (finalAttrs: { runHook preCheck export QT_QPA_PLATFORM=offscreen + ctest --test-dir "src/unittests" --output-on-failure ./bin/legacytests runHook postCheck From f0671ac5fa9fc9390e9a8f899fd6866f2f18a038 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 22 Jul 2026 19:57:15 +0000 Subject: [PATCH 04/29] nextcloud-notify_push: 1.3.3 -> 1.3.5 (cherry picked from commit 69e2a2df53228cef7782aa9e9cb39a3ffa143f54) --- pkgs/servers/nextcloud/notify_push.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/servers/nextcloud/notify_push.nix b/pkgs/servers/nextcloud/notify_push.nix index 895362d848af..34d2da330b88 100644 --- a/pkgs/servers/nextcloud/notify_push.nix +++ b/pkgs/servers/nextcloud/notify_push.nix @@ -13,22 +13,22 @@ rustPlatform.buildRustPackage rec { # in nixpkgs! # For that, check the `` section of `appinfo/info.xml` # in the app (https://github.com/nextcloud/notify_push/blob/main/appinfo/info.xml) - version = "1.3.3"; + version = "1.3.5"; src = fetchFromGitHub { owner = "nextcloud"; repo = "notify_push"; tag = "v${version}"; - hash = "sha256-DMyqixeO1SfRvfuIpBHEaym6qH5X5Yw94tfWLCFkrBg="; + hash = "sha256-MLy2W6/D1Gzr4sxYMFjC9yVUdWAkP9h5bEVd6CulIvI="; }; - cargoHash = "sha256-fdf7AvT511WRjsOyM4+3vieuQMh24C+mF49pWtfS41Y="; + cargoHash = "sha256-/1KrN3zDYzxlglhyyyIROwOmNW7STdmMvG8x95UFEZU="; passthru = rec { app = fetchNextcloudApp { appName = "notify_push"; appVersion = version; - hash = "sha256-gHRegrl1VtJOiB6xLUHtG3sxkCDv7/zhrhQ9B+9i8YI="; + hash = "sha256-jyO9TDVc/xUnpUww3GaOY1I5x+rokAxt5FJtMrq1SAY="; license = "agpl3Plus"; homepage = "https://github.com/nextcloud/notify_push"; url = "https://github.com/nextcloud-releases/notify_push/releases/download/v${version}/notify_push-v${version}.tar.gz"; @@ -41,7 +41,7 @@ rustPlatform.buildRustPackage rec { buildAndTestSubdir = "test_client"; - cargoHash = "sha256-fdf7AvT511WRjsOyM4+3vieuQMh24C+mF49pWtfS41Y="; + cargoHash = "sha256-/1KrN3zDYzxlglhyyyIROwOmNW7STdmMvG8x95UFEZU="; meta = meta // { mainProgram = "test_client"; From ae6361cfa55c3e952c2c7246fa6ca4d53d9835e9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 12 Aug 2026 18:40:57 +0000 Subject: [PATCH 05/29] nextcloud-notify_push: 1.3.5 -> 1.4.0 (cherry picked from commit d84b7fe5a93c52ea46338ec00c37c57d6d7b5df5) --- pkgs/servers/nextcloud/notify_push.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/servers/nextcloud/notify_push.nix b/pkgs/servers/nextcloud/notify_push.nix index 34d2da330b88..caea9be116dc 100644 --- a/pkgs/servers/nextcloud/notify_push.nix +++ b/pkgs/servers/nextcloud/notify_push.nix @@ -13,22 +13,22 @@ rustPlatform.buildRustPackage rec { # in nixpkgs! # For that, check the `` section of `appinfo/info.xml` # in the app (https://github.com/nextcloud/notify_push/blob/main/appinfo/info.xml) - version = "1.3.5"; + version = "1.4.0"; src = fetchFromGitHub { owner = "nextcloud"; repo = "notify_push"; tag = "v${version}"; - hash = "sha256-MLy2W6/D1Gzr4sxYMFjC9yVUdWAkP9h5bEVd6CulIvI="; + hash = "sha256-zIYAVNWJ/lXBAWl1MVxZbQH9ep8aNrAJ6l5ypnSQ5ik="; }; - cargoHash = "sha256-/1KrN3zDYzxlglhyyyIROwOmNW7STdmMvG8x95UFEZU="; + cargoHash = "sha256-0BCM9TT1SRa0Y2EC5bNt2lM8qcgYOvr1sms4yhSzgHU="; passthru = rec { app = fetchNextcloudApp { appName = "notify_push"; appVersion = version; - hash = "sha256-jyO9TDVc/xUnpUww3GaOY1I5x+rokAxt5FJtMrq1SAY="; + hash = "sha256-nZbIHZSj7KtvCPYVBZXED0+WfmWwuCN4QHa+yfrxzIg="; license = "agpl3Plus"; homepage = "https://github.com/nextcloud/notify_push"; url = "https://github.com/nextcloud-releases/notify_push/releases/download/v${version}/notify_push-v${version}.tar.gz"; @@ -41,7 +41,7 @@ rustPlatform.buildRustPackage rec { buildAndTestSubdir = "test_client"; - cargoHash = "sha256-/1KrN3zDYzxlglhyyyIROwOmNW7STdmMvG8x95UFEZU="; + cargoHash = "sha256-0BCM9TT1SRa0Y2EC5bNt2lM8qcgYOvr1sms4yhSzgHU="; meta = meta // { mainProgram = "test_client"; From 764cae98fe7a0db7a9c37c2d5d912a97fb246d57 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Tue, 15 Sep 2026 19:06:51 +0200 Subject: [PATCH 06/29] nextcloud-notify_push: 1.4.0 -> 1.4.1 Diff: https://github.com/nextcloud/notify_push/compare/v1.4.0...v1.4.1 Changelog: https://github.com/nextcloud/notify_push/releases/tag/v1.4.1 (cherry picked from commit d6430c930e1a3f85644265a76520d19d6abeebfe) --- pkgs/servers/nextcloud/notify_push.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/servers/nextcloud/notify_push.nix b/pkgs/servers/nextcloud/notify_push.nix index caea9be116dc..5385a01720c5 100644 --- a/pkgs/servers/nextcloud/notify_push.nix +++ b/pkgs/servers/nextcloud/notify_push.nix @@ -13,22 +13,22 @@ rustPlatform.buildRustPackage rec { # in nixpkgs! # For that, check the `` section of `appinfo/info.xml` # in the app (https://github.com/nextcloud/notify_push/blob/main/appinfo/info.xml) - version = "1.4.0"; + version = "1.4.1"; src = fetchFromGitHub { owner = "nextcloud"; repo = "notify_push"; tag = "v${version}"; - hash = "sha256-zIYAVNWJ/lXBAWl1MVxZbQH9ep8aNrAJ6l5ypnSQ5ik="; + hash = "sha256-lg/gffgfUJHLCL1TOPdYAw7DtRZeGDH+jO9deQSUbEY="; }; - cargoHash = "sha256-0BCM9TT1SRa0Y2EC5bNt2lM8qcgYOvr1sms4yhSzgHU="; + cargoHash = "sha256-skKOCJBtpvtdc594eOxbvSIl+SucaH0jl1gFv9kfvNA="; passthru = rec { app = fetchNextcloudApp { appName = "notify_push"; appVersion = version; - hash = "sha256-nZbIHZSj7KtvCPYVBZXED0+WfmWwuCN4QHa+yfrxzIg="; + hash = "sha256-C/2jXLpuIbxjWO3kMb3nkLA5762uVLuzk1YPz/YSfjY="; license = "agpl3Plus"; homepage = "https://github.com/nextcloud/notify_push"; url = "https://github.com/nextcloud-releases/notify_push/releases/download/v${version}/notify_push-v${version}.tar.gz"; @@ -41,7 +41,7 @@ rustPlatform.buildRustPackage rec { buildAndTestSubdir = "test_client"; - cargoHash = "sha256-0BCM9TT1SRa0Y2EC5bNt2lM8qcgYOvr1sms4yhSzgHU="; + cargoHash = "sha256-skKOCJBtpvtdc594eOxbvSIl+SucaH0jl1gFv9kfvNA="; meta = meta // { mainProgram = "test_client"; From 6a65f23a469725558ad651c2bab50a4c47eea732 Mon Sep 17 00:00:00 2001 From: Friedrich Altheide Date: Mon, 24 Aug 2026 08:01:32 +0200 Subject: [PATCH 07/29] virtualboxGuestAdditions: less CI builds (cherry picked from commit f8c929b219df956762df0559aa8f8b5ae9a6e93b) --- .../virtualbox/guest-additions/builder.nix | 43 +++++++++---------- 1 file changed, 20 insertions(+), 23 deletions(-) diff --git a/pkgs/applications/virtualization/virtualbox/guest-additions/builder.nix b/pkgs/applications/virtualization/virtualbox/guest-additions/builder.nix index 39b79420732b..d50770932428 100644 --- a/pkgs/applications/virtualization/virtualbox/guest-additions/builder.nix +++ b/pkgs/applications/virtualization/virtualbox/guest-additions/builder.nix @@ -1,26 +1,26 @@ { - stdenv, - kernel, - fetchurl, - lib, - pam, - libxslt, - libxext, - libxcursor, - libxmu, - glib, - libxrandr, dbus, - xz, + fetchurl, + glib, + lib, + libxcrypt, + libxcursor, + libxext, + libxmu, + libxrandr, + libxslt, + linuxHeaders, + makeself, + openssl, + pam, + patchelf, pkg-config, + stdenv, which, xorg-server, xrandr, + xz, yasm, - patchelf, - makeself, - linuxHeaders, - openssl, virtualboxVersion, virtualboxSubVersion, virtualboxSha256, @@ -31,7 +31,7 @@ let buildType = "release"; in stdenv.mkDerivation (finalAttrs: { - pname = "VirtualBox-GuestAdditions-builder-${kernel.version}"; + pname = "VirtualBox-GuestAdditions-builder"; version = "${virtualboxVersion}${virtualboxSubVersion}"; inherit virtualboxVersion virtualboxSubVersion; @@ -53,8 +53,9 @@ stdenv.mkDerivation (finalAttrs: { openssl linuxHeaders xz - ] - ++ kernel.moduleBuildDependencies; + libxcrypt + ]; + buildInputs = [ dbus libxslt @@ -65,9 +66,6 @@ stdenv.mkDerivation (finalAttrs: { libxrandr ]; - KERN_DIR = "${kernel.dev}/lib/modules/${kernel.modDirVersion}/build"; - KERN_INCL = "${kernel.dev}/lib/modules/${kernel.modDirVersion}/source/include"; - prePatch = '' rm -r src/VBox/Additions/x11/x11include/ rm -r src/VBox/Additions/3D/mesa/mesa-*/ @@ -139,7 +137,6 @@ stdenv.mkDerivation (finalAttrs: { ./configure \ --only-additions \ - --with-linux=${kernel.dev} \ --disable-kmods sed -e 's@PKG_CONFIG_PATH=.*@PKG_CONFIG_PATH=${glib.dev}/lib/pkgconfig @' \ From 10aeb452359aa7291d79a3b9e80eb875c8062e18 Mon Sep 17 00:00:00 2001 From: Friedrich Altheide Date: Wed, 12 Aug 2026 07:57:51 +0200 Subject: [PATCH 08/29] nixos/virtualbox-guest: add package option (cherry picked from commit 8d5c759816002b273cca43c2364c469fc68595cd) --- nixos/modules/tasks/filesystems/vboxsf.nix | 2 +- nixos/modules/virtualisation/virtualbox-guest.nix | 13 ++++++++----- 2 files changed, 9 insertions(+), 6 deletions(-) diff --git a/nixos/modules/tasks/filesystems/vboxsf.nix b/nixos/modules/tasks/filesystems/vboxsf.nix index 3271351a5bca..3cc4b222f755 100644 --- a/nixos/modules/tasks/filesystems/vboxsf.nix +++ b/nixos/modules/tasks/filesystems/vboxsf.nix @@ -13,7 +13,7 @@ let package = pkgs.runCommand "mount.vboxsf" { preferLocalBuild = true; } '' mkdir -p $out/bin - cp ${pkgs.linuxPackages.virtualboxGuestAdditions}/bin/mount.vboxsf $out/bin + cp ${config.virtualisation.virtualbox.guest.package}/bin/mount.vboxsf $out/bin ''; in diff --git a/nixos/modules/virtualisation/virtualbox-guest.nix b/nixos/modules/virtualisation/virtualbox-guest.nix index 882cdf1f0cde..2ce02175b178 100644 --- a/nixos/modules/virtualisation/virtualbox-guest.nix +++ b/nixos/modules/virtualisation/virtualbox-guest.nix @@ -7,7 +7,6 @@ }: let cfg = config.virtualisation.virtualbox.guest; - kernel = config.boot.kernelPackages; mkVirtualBoxUserService = serviceArgs: verbose: { description = "VirtualBox Guest User Services ${serviceArgs}"; @@ -25,7 +24,7 @@ let preStart = "${pkgs.bash}/bin/bash -c \"if [ -z $DISPLAY ]; then exit 1; fi\""; serviceConfig = { ExecStart = - "@${kernel.virtualboxGuestAdditions}/bin/VBoxClient" + "@${cfg.package}/bin/VBoxClient" + (lib.strings.optionalString verbose " --verbose") + " --foreground ${serviceArgs}"; # Wait after a failure, hoping that the display environment is ready after waiting @@ -66,6 +65,10 @@ in description = "Whether to enable the VirtualBox service and other guest additions."; }; + package = lib.mkPackageOption config.boot.kernelPackages "virtualboxGuestAdditions" { + pkgsText = "config.boot.kernelPackages"; + }; + clipboard = lib.mkOption { default = true; type = lib.types.bool; @@ -115,9 +118,9 @@ in } ]; - environment.systemPackages = [ kernel.virtualboxGuestAdditions ]; + environment.systemPackages = [ cfg.package ]; - boot.extraModulePackages = lib.mkIf cfg.use3rdPartyModules [ kernel.virtualboxGuestAdditions ]; + boot.extraModulePackages = lib.mkIf cfg.use3rdPartyModules [ cfg.package ]; systemd.services.virtualbox = { description = "VirtualBox Guest Services"; @@ -128,7 +131,7 @@ in unitConfig.ConditionVirtualization = "oracle"; - serviceConfig.ExecStart = "@${kernel.virtualboxGuestAdditions}/bin/VBoxService VBoxService --foreground"; + serviceConfig.ExecStart = "@${cfg.package}/bin/VBoxService VBoxService --foreground"; }; users.groups.vboxuserdev = { }; From cf87de9290d8fa947621c1ef80c2334baadb3ca1 Mon Sep 17 00:00:00 2001 From: OPNA2608 Date: Mon, 21 Sep 2026 00:22:22 +0200 Subject: [PATCH 09/29] np2kai: Remove OPNA2608 from meta.maintainers I no longer trust the upstream maintainer, so I will no longer look after this. (cherry picked from commit 2c4166100d0fc26d9159693dff6691f8e625e8ff) --- pkgs/by-name/np/np2kai/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/np/np2kai/package.nix b/pkgs/by-name/np/np2kai/package.nix index 3245c09ad3fb..e7b64870179d 100644 --- a/pkgs/by-name/np/np2kai/package.nix +++ b/pkgs/by-name/np/np2kai/package.nix @@ -122,7 +122,7 @@ stdenv.mkDerivation (finalAttrs: { description = "PC-9801 series emulator"; homepage = "https://github.com/AZO234/NP2kai"; license = lib.licenses.mit; - maintainers = with lib.maintainers; [ OPNA2608 ]; + maintainers = [ ]; mainProgram = "${if enableX11 then "x" else "sdl"}np21kai"; platforms = lib.platforms.x86; }; From d8e240aac2f3b5459427d09761bac712c216a32f Mon Sep 17 00:00:00 2001 From: OPNA2608 Date: Mon, 21 Sep 2026 00:25:37 +0200 Subject: [PATCH 10/29] np2kai: Change license to Unfree Licensing information on the repo cannot be fully trusted. This is a fork of Neko Project II, whose source code lacked a proper license for most of its bits, making it source-available Unfree code. (cherry picked from commit d454d2ec4736e669c256bddbc750850d83ed3402) --- pkgs/by-name/np/np2kai/package.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/np/np2kai/package.nix b/pkgs/by-name/np/np2kai/package.nix index e7b64870179d..947addd0aa32 100644 --- a/pkgs/by-name/np/np2kai/package.nix +++ b/pkgs/by-name/np/np2kai/package.nix @@ -121,7 +121,9 @@ stdenv.mkDerivation (finalAttrs: { meta = { description = "PC-9801 series emulator"; homepage = "https://github.com/AZO234/NP2kai"; - license = lib.licenses.mit; + # Information on the repo is untrustworthy. + # This is a fork from the original np2, which lacked any licensing information for most of its code -> Unfree + license = lib.licenses.unfree; maintainers = [ ]; mainProgram = "${if enableX11 then "x" else "sdl"}np21kai"; platforms = lib.platforms.x86; From 01af74ec61637750ae15b6cdb69a564408905df2 Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Fri, 25 Sep 2026 09:56:44 -0400 Subject: [PATCH 11/29] jellyfin: backport two security fixes from 12.0 Fix GHSA-6828-c7cx-hvqm and GHSA-4vx8-xhc9-qg6x. Not-cherry-picked-because: master is on 12.1 and already contains the fixes. --- pkgs/by-name/je/jellyfin/package.nix | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/pkgs/by-name/je/jellyfin/package.nix b/pkgs/by-name/je/jellyfin/package.nix index d0dabbd88fc7..31ae8c923ca0 100644 --- a/pkgs/by-name/je/jellyfin/package.nix +++ b/pkgs/by-name/je/jellyfin/package.nix @@ -32,6 +32,18 @@ buildDotnetModule (finalAttrs: { hash = "sha256-TxGo+sLLG+C9omxrwvO6byzw+iRqONVLXrQKwkrY22s="; }) + # GHSA-6828-c7cx-hvqm: confine virtual-folder operations to the libraries root. + (fetchpatch { + url = "https://github.com/jellyfin/jellyfin/commit/0c560b22ce73323329645b836c9910abc257ce4e.patch"; + hash = "sha256-K/og9MDP4BNexkDGLOm346O9anqAjb13UViSAmOw2OA="; + }) + + # GHSA-4vx8-xhc9-qg6x: enforce remote-control permissions between user sessions. + (fetchpatch { + url = "https://github.com/jellyfin/jellyfin/commit/dd7de4187879082e10b474856f705b6c5d9b963a.patch"; + hash = "sha256-OCj4aaKaX4F/+KbCz6BAsifdYe/6BOu6y39ZgMSUKFA="; + }) + # Fix MaxLoginAttempts not honored. # https://github.com/jellyfin/jellyfin/pull/17274 (fetchpatch { From 26d996950528f7f1fdfca5324a743dfca594b41e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 22 Sep 2026 03:52:56 +0000 Subject: [PATCH 12/29] croaring: 5.2.0 -> 5.2.2 (cherry picked from commit 5b4d759214c059c62876732f73f254fef5328cbe) --- pkgs/by-name/cr/croaring/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/cr/croaring/package.nix b/pkgs/by-name/cr/croaring/package.nix index d020dce7b4b9..7bde08508c2e 100644 --- a/pkgs/by-name/cr/croaring/package.nix +++ b/pkgs/by-name/cr/croaring/package.nix @@ -8,13 +8,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "croaring"; - version = "5.2.0"; + version = "5.2.2"; src = fetchFromGitHub { owner = "RoaringBitmap"; repo = "CRoaring"; tag = "v${finalAttrs.version}"; - hash = "sha256-BDQpqRlle9mjlybOjxctwxkP5rQl2y673EnpthjFbBA="; + hash = "sha256-ZipK1pNdxNaEAVkFygH6pwOHXvQWfGKVk1S6onKpvPE="; }; # roaring.pc.in cannot handle absolute CMAKE_INSTALL_*DIRs, nor From 1cdf9dd6fa7dbda307f3b2fff71f71c176625222 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 25 Sep 2026 14:43:17 +0000 Subject: [PATCH 13/29] gitoxide: 0.58.0 -> 0.59.0 (cherry picked from commit 66ed445bf4b900204529ac9f96899306edb5e58c) --- pkgs/by-name/gi/gitoxide/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/gi/gitoxide/package.nix b/pkgs/by-name/gi/gitoxide/package.nix index f93357c38743..5f7c89f1e744 100644 --- a/pkgs/by-name/gi/gitoxide/package.nix +++ b/pkgs/by-name/gi/gitoxide/package.nix @@ -18,16 +18,16 @@ let in rustPlatform.buildRustPackage (finalAttrs: { pname = "gitoxide"; - version = "0.58.0"; + version = "0.59.0"; src = fetchFromGitHub { owner = "GitoxideLabs"; repo = "gitoxide"; tag = "v${finalAttrs.version}"; - hash = "sha256-NKpOMgB/p7p1tZvU929LUieDKInksCP4gZ3tkI1FIrY="; + hash = "sha256-TWA2SUoqEVjplEtzTApQ/HZgBkUxDeuf/GcM+qJF4fg="; }; - cargoHash = "sha256-0hCkvVFxdVdEDB0x7pd0CnKnKWOxGzbtBO9EFj9z9f4="; + cargoHash = "sha256-Mx6iWy1U8/zYzrgVfbpVG73/0lYJS8juupmbbKQlNQY="; nativeBuildInputs = [ cmake From 8a0699cd8ad0be84d9dd2f7e9b909a6e0f1b4da7 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 25 Sep 2026 21:07:50 +0000 Subject: [PATCH 14/29] edhm-ui: 3.0.71 -> 3.0.72 (cherry picked from commit 36aedebf62c77d33fba2f65e8947a0b7c5bda139) --- pkgs/by-name/ed/edhm-ui/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ed/edhm-ui/package.nix b/pkgs/by-name/ed/edhm-ui/package.nix index 3cdf18a1c09f..ef5ef738dbf0 100644 --- a/pkgs/by-name/ed/edhm-ui/package.nix +++ b/pkgs/by-name/ed/edhm-ui/package.nix @@ -28,13 +28,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "edhm-ui"; - version = "3.0.71"; + version = "3.0.72"; strictDeps = true; src = fetchzip { url = "https://github.com/BlueMystical/EDHM_UI/releases/download/v${finalAttrs.version}/edhm-ui-v3-linux-x64.zip"; - hash = "sha256-wMsP2VeSbo78II/tT5nBAvOIQc3lCBqy+l0F2r3ulEM="; + hash = "sha256-bpYNl/I2T3sNbhjqqbYXo7c8JWi9tUBBDX/aRSIz+rA="; }; nativeBuildInputs = [ From 09941bdb35dc26f787ea65187acb5fe9a8733011 Mon Sep 17 00:00:00 2001 From: bloominstrong Date: Fri, 25 Sep 2026 22:37:15 +1000 Subject: [PATCH 15/29] openvpn: 2.6.21 -> 2.6.23 (cherry picked from commit 3fbe37278b147c6911e1796d51f1b5463ed95e7a) --- pkgs/tools/networking/openvpn/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/networking/openvpn/default.nix b/pkgs/tools/networking/openvpn/default.nix index a61d981d53f0..3aca471c2a70 100644 --- a/pkgs/tools/networking/openvpn/default.nix +++ b/pkgs/tools/networking/openvpn/default.nix @@ -23,11 +23,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "openvpn"; - version = "2.6.21"; + version = "2.6.23"; src = fetchurl { url = "https://swupdate.openvpn.net/community/releases/openvpn-${finalAttrs.version}.tar.gz"; - hash = "sha256-JMthheVEpHMj1nmLA9OfI2fZbyJ77pzRVD6O1Sgxmxc="; + hash = "sha256-QEHHCRYr7BMlq/WqjPJ6JVzEd8Y0sV7jEEEccB/ECpY="; }; nativeBuildInputs = [ From dbf3d95e1ef46523bc22088fb994482b6639753a Mon Sep 17 00:00:00 2001 From: eljamm Date: Sat, 26 Sep 2026 08:04:07 +0000 Subject: [PATCH 16/29] linux_xanmod: 6.18.53 -> 6.18.54 - Changelog: https://dl.xanmod.org/changelog/6.18/ChangeLog-6.18.54-xanmod1.gz - Diff: https://gitlab.com/xanmod/linux/-/compare/6.18.53-xanmod1..6.18.54-xanmod1?from_project_id=51590166 (cherry picked from commit d2b720818b0975ba4ba28327f71f3dac100f9a1a) --- pkgs/os-specific/linux/kernel/xanmod-kernels.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix index af09d19e91dc..ca507f24aedf 100644 --- a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix +++ b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix @@ -15,8 +15,8 @@ let variants = { # ./update-xanmod.sh lts lts = { - version = "6.18.53"; - hash = "sha256-+2DnSpnBekGDBeXMjwGNrBFexnYmqQCc93LjDaseD/8="; + version = "6.18.54"; + hash = "sha256-yD6dpnyQsAxwePJMIcZAi5cECFvH7xKoimcpAVYzGtI="; isLTS = true; }; # ./update-xanmod.sh main From 6634d105518c45c6762e51776d24d78610a3da30 Mon Sep 17 00:00:00 2001 From: eljamm Date: Sat, 26 Sep 2026 08:06:03 +0000 Subject: [PATCH 17/29] linux_xanmod_latest: 7.2.7 -> 7.2.8 - Changelog: https://dl.xanmod.org/changelog/7.2/ChangeLog-7.2.8-xanmod1.gz - Diff: https://gitlab.com/xanmod/linux/-/compare/7.2.7-xanmod1..7.2.8-xanmod1?from_project_id=51590166 (cherry picked from commit 1f1e5214c6bc70d6042ea4aaf83fc61155e9978e) --- pkgs/os-specific/linux/kernel/xanmod-kernels.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix index ca507f24aedf..48c5f29ceb97 100644 --- a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix +++ b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix @@ -21,8 +21,8 @@ let }; # ./update-xanmod.sh main main = { - version = "7.2.7"; - hash = "sha256-QeEJiBJfQloehzZppWX8zvL43UGSMa4xUicA1VXN6f0="; + version = "7.2.8"; + hash = "sha256-jHCIFm1xI3T/2Zl0h91Nf6oAr4ozIPQSYRFo92KmOfc="; }; }; From 0a359416a94aaf8dee50fdafe205b40a4a41d218 Mon Sep 17 00:00:00 2001 From: Dom Rodriguez Date: Thu, 24 Sep 2026 15:51:20 +0100 Subject: [PATCH 18/29] deskflow: Add @shymega to maintainers list (cherry picked from commit c23b6d8f1b0e3bfec7ccd66551386237cba3507f) --- pkgs/by-name/de/deskflow/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/de/deskflow/package.nix b/pkgs/by-name/de/deskflow/package.nix index dec4016133dd..90555c4172f7 100644 --- a/pkgs/by-name/de/deskflow/package.nix +++ b/pkgs/by-name/de/deskflow/package.nix @@ -121,7 +121,10 @@ stdenv.mkDerivation (finalAttrs: { homepage = "https://github.com/deskflow/deskflow"; description = "Share one mouse and keyboard between multiple computers on Windows, macOS and Linux"; mainProgram = "deskflow"; - maintainers = with lib.maintainers; [ flacks ]; + maintainers = with lib.maintainers; [ + flacks + shymega + ]; license = with lib.licenses; [ gpl2Plus openssl From cf5a3d36408618609a37d636274a1599e2d8868d Mon Sep 17 00:00:00 2001 From: Dom Rodriguez Date: Sat, 11 Jul 2026 18:37:18 +0100 Subject: [PATCH 19/29] deskflow: Refactor to add Darwin support This is based on @levonk's comment here (https://github.com/NixOS/nixpkgs/pull/535029#issuecomment-5601270675) and upstream Nix Flake PR here (https://github.com/deskflow/deskflow/pull/10140) I have applied @levonk's points to this PR, and tweaked certain things to be in line with Nix. Assisted-by: Devin (GLM-5.2 High) Co-authored-by: levonk <277861+levonk@users.noreply.github.com> (cherry picked from commit 08699b49e7ff5473d45e5c134f2ba88c3694b3ce) --- pkgs/by-name/de/deskflow/package.nix | 138 ++++++++++++++++----------- 1 file changed, 81 insertions(+), 57 deletions(-) diff --git a/pkgs/by-name/de/deskflow/package.nix b/pkgs/by-name/de/deskflow/package.nix index dec4016133dd..fb3fbdb22812 100644 --- a/pkgs/by-name/de/deskflow/package.nix +++ b/pkgs/by-name/de/deskflow/package.nix @@ -2,31 +2,42 @@ lib, stdenv, fetchFromGitHub, + + # nativeBuildInputs cmake, + doxygen, ninja, pkg-config, + qt6, + + # nativeCheckInputs + writableTmpDirAsHomeHook, + + # buildInputs (Linux and Darwin) gtest, - libei, - libportal, - libx11, - libxkbfile, - libxtst, - libxinerama, - libxi, - libxrandr, - libxkbcommon, + openssl, pugixml, python3, + + # buildInputs (Linux-specific) gdk-pixbuf, - libnotify, - qt6, - xkeyboard_config, - wayland-protocols, - wayland, - libsysprof-capture, lerc, - doxygen, - writableTmpDirAsHomeHook, + libei, + libnotify, + libportal, + libsysprof-capture, + libx11, + libxi, + libxinerama, + libxkbcommon, + libxkbfile, + libxrandr, + libxtst, + wayland, + wayland-protocols, + xkeyboard_config, + + # Update script for `passthru`. nix-update-script, }: @@ -41,57 +52,69 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-XcSG47Ysjn+wrJH5DC/XXGXcneXcW7xIhAn6sguuv+s="; }; - postPatch = '' - substituteInPlace src/lib/deskflow/unix/AppUtilUnix.cpp \ - --replace-fail "/usr/share/X11/xkb/rules/evdev.xml" "${xkeyboard_config}/share/X11/xkb/rules/evdev.xml" - substituteInPlace deploy/linux/deploy.cmake \ - --replace-fail 'message(FATAL_ERROR "Unable to read file /etc/os-release")' 'set(RELEASE_FILE_CONTENTS "")' - ''; - nativeBuildInputs = [ cmake + doxygen ninja pkg-config qt6.wrapQtAppsHook - doxygen # docs ]; + buildInputs = [ + gtest + openssl + pugixml + python3 + qt6.qtbase + qt6.qttools + qt6.qttranslations + ] + ++ (lib.optionals stdenv.hostPlatform.isLinux [ + gdk-pixbuf + lerc + libei + libnotify + libportal + libsysprof-capture + libx11 + libxi + libxinerama + libxkbcommon + libxkbfile + libxrandr + libxtst + qt6.qtdeclarative + qt6.qtwayland + wayland + wayland-protocols + ]); + + preConfigure = lib.optionalString stdenv.hostPlatform.isDarwin '' + export PATH="${qt6.qtbase}/bin:$PATH" + ''; + + postPatch = '' + ${lib.optionalString stdenv.hostPlatform.isLinux '' + substituteInPlace src/lib/deskflow/unix/AppUtilUnix.cpp \ + --replace-fail "/usr/share/X11/xkb/rules/evdev.xml" "${xkeyboard_config}/share/X11/xkb/rules/evdev.xml" + substituteInPlace deploy/linux/deploy.cmake \ + --replace-fail 'message(FATAL_ERROR "Unable to read file /etc/os-release")' 'set(RELEASE_FILE_CONTENTS "")' + ''} + substituteInPlace translations/CMakeLists.txt \ + --replace-fail 'PATHS ''${QT_ROOT_DIR} PATH_SUFFIXES "translations" "share/qt/translations"' 'PATHS "${qt6.qttranslations}/translations"' + substituteInPlace src/lib/net/CMakeLists.txt \ + --replace-fail "set(OPENSSL_USE_STATIC_LIBS TRUE)" "" + ''; + cmakeFlags = [ "-DCMAKE_SKIP_RPATH=ON" # Avoid generating incorrect RPATH "-DSKIP_BUILD_TESTS=ON" # Perform unit tests in `checkPhase` manually, with one job at a time. ]; + qtWrapperArgs = lib.optional stdenv.hostPlatform.isLinux "--set QT_QPA_PLATFORM_PLUGIN_PATH ${qt6.qtwayland}/${qt6.qtbase.qtPluginPrefix}/platforms"; + strictDeps = true; - buildInputs = [ - gtest - libei - libportal - libx11 - libxkbfile - libxinerama - libxi - libxrandr - libxtst - libxkbcommon - pugixml - gdk-pixbuf - libnotify - python3 - qt6.qtbase - wayland-protocols - qt6.qtwayland - qt6.qtdeclarative - qt6.qttools - wayland - libsysprof-capture - lerc - ]; - - qtWrapperArgs = [ - "--set QT_QPA_PLATFORM_PLUGIN_PATH ${qt6.qtwayland}/${qt6.qtbase.qtPluginPrefix}/platforms" - ]; - doCheck = true; nativeCheckInputs = [ writableTmpDirAsHomeHook ]; @@ -100,7 +123,8 @@ stdenv.mkDerivation (finalAttrs: { runHook preCheck export QT_QPA_PLATFORM=offscreen - ctest --test-dir "src/unittests" --output-on-failure + ctest --test-dir "src/unittests" --output-on-failure \ + --exclude-regex "OSX(KeyState|Clipboard)Tests" ./bin/legacytests runHook postCheck @@ -124,9 +148,9 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ flacks ]; license = with lib.licenses; [ gpl2Plus - openssl + lib.licenses.openssl # We have to be explicit here, as `openssl` is a buildInput. mit # share/applications/org.deskflow.deskflow.desktop ]; - platforms = lib.platforms.linux; + platforms = lib.platforms.unix; }; }) From 38c63659f62a8b450fe1e25197cfac6442dff4b0 Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Fri, 25 Sep 2026 10:20:24 -0400 Subject: [PATCH 20/29] element-desktop: avoid duplicating element-web https://github.com/NixOS/nixpkgs/pull/563892 added webapp.asar to satisfy electron-builder. This unintentionally left it in the app bundle (in addition to symlinked electron-web), bloating the package by ~140MB for no good reason. (cherry picked from commit 8a66a0b8fb36bf8a79c6fbf7b92d7f4dd3c6df93) --- pkgs/by-name/el/element-desktop/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/el/element-desktop/package.nix b/pkgs/by-name/el/element-desktop/package.nix index 4a26d243a711..f6c3dc15e8c4 100644 --- a/pkgs/by-name/el/element-desktop/package.nix +++ b/pkgs/by-name/el/element-desktop/package.nix @@ -112,6 +112,9 @@ stdenv.mkDerivation (finalAttrs: { asar pack tmp-app "$packed" + # element-web is linked into the output during installPhase. + find ./dist -name webapp.asar -delete + runHook postBuild ''; From 45618a32effca653edfc4d1bea84607a3767cb56 Mon Sep 17 00:00:00 2001 From: Andrew Dutka Date: Thu, 2 Jul 2026 01:26:20 -0300 Subject: [PATCH 21/29] rojo: 7.6.1 -> 7.7.0 (cherry picked from commit 0a0a3772ca5f9b97ceee75d20f50f15b0b58d534) --- pkgs/by-name/ro/rojo/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ro/rojo/package.nix b/pkgs/by-name/ro/rojo/package.nix index 6641cd8af4ef..cd7fde4df78b 100644 --- a/pkgs/by-name/ro/rojo/package.nix +++ b/pkgs/by-name/ro/rojo/package.nix @@ -10,17 +10,17 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "rojo"; - version = "7.6.1"; + version = "7.7.0"; src = fetchFromGitHub { owner = "rojo-rbx"; repo = "rojo"; tag = "v${finalAttrs.version}"; - hash = "sha256-h8gd91Nc35jTQ4u9YyQGOB+rkgRAos8lsjX+bWzvpDs="; + hash = "sha256-2atNAiv51MNpxXdwvKSvtO1CGvQUOdUUOZszjAm3zi8="; fetchSubmodules = true; }; - cargoHash = "sha256-zl1L8q1AJwVn0o2BazJ30FyBCMq5F5nAQ0FGuEAPGms="; + cargoHash = "sha256-1xTvW3Ra6erYpjxgfp2m8qVMz6u99WCDv2VE/Xh2mFc="; nativeBuildInputs = [ pkg-config ]; buildInputs = [ openssl ]; From e6d2770ad018cb619926b22d291deaa1da558bd8 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Wed, 23 Sep 2026 18:05:56 -0400 Subject: [PATCH 22/29] workflows/*: use self-repository syntax (cherry picked from commit fb37e8e8bd6c8c6dd73434e565271239f27add27) --- .github/actions/checkout/action.yml | 9 ++++++++- .github/workflows/build.yml | 6 +----- .github/workflows/check.yml | 14 ++------------ .github/workflows/eval.yml | 18 +++--------------- .github/workflows/lint.yml | 18 +++--------------- .github/workflows/merge-group.yml | 8 ++++---- .github/workflows/periodic-merge-24h.yml | 2 +- .github/workflows/periodic-merge-6h.yml | 2 +- .github/workflows/pull-request-target.yml | 10 +++++----- .github/workflows/test.yml | 4 ++-- 10 files changed, 30 insertions(+), 61 deletions(-) diff --git a/.github/actions/checkout/action.yml b/.github/actions/checkout/action.yml index 91cca324fcd4..ab8c663e0f0e 100644 --- a/.github/actions/checkout/action.yml +++ b/.github/actions/checkout/action.yml @@ -13,6 +13,13 @@ inputs: runs: using: composite steps: + # We don't actually need anything in this directory, but we need a small + # sparse checkout, and this directory is small. + - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + with: + persist-credentials: false + sparse-checkout: .github/actions + - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: MERGED_SHA: ${{ inputs.merged-as-untrusted-at }} @@ -37,7 +44,7 @@ runs: }) } - // These are set automatically by the spare checkout for .github/actions. + // These are set automatically by the sparse checkout for .github/actions. // Undo them, otherwise git fetch below will not do anything. await run('git', 'config', 'unset', 'remote.origin.promisor') await run('git', 'config', 'unset', 'remote.origin.partialclonefilter') diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index b7ba21272be1..c85a3989219e 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -49,12 +49,8 @@ jobs: runs-on: ${{ matrix.runner }} timeout-minutes: 60 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index faff91d48e6c..84c34887b7f3 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -190,13 +190,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 5 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - - name: Checkout merge and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} @@ -219,13 +214,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 5 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - - name: Checkout merge and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml index 61d8b60d2bab..f971aa0229da 100644 --- a/.github/workflows/eval.yml +++ b/.github/workflows/eval.yml @@ -174,12 +174,8 @@ jobs: sudo mkswap /swap sudo swapon /swap - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Check out the PR at merged and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: # For versioned evals, use the target as the untrusted base and apply the pin-bump commit merged-as-untrusted-at: ${{ matrix.version && inputs.targetSha || inputs.mergedSha }} @@ -259,12 +255,8 @@ jobs: statuses: write # creating 'Eval Summary' commit statuses timeout-minutes: 5 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Check out the PR at the target commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} @@ -477,12 +469,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index b90840319c5b..faa978b13227 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -26,12 +26,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} @@ -61,12 +57,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout the merge commit - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} @@ -90,12 +82,8 @@ jobs: runs-on: ubuntu-24.04-arm timeout-minutes: 10 steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - sparse-checkout: .github/actions - name: Checkout merge and target commits - uses: ./.github/actions/checkout + uses: $/.github/actions/checkout with: merged-as-untrusted-at: ${{ inputs.mergedSha }} target-as-trusted-at: ${{ inputs.targetSha }} diff --git a/.github/workflows/merge-group.yml b/.github/workflows/merge-group.yml index 1156c2a616eb..e111c35ca7c8 100644 --- a/.github/workflows/merge-group.yml +++ b/.github/workflows/merge-group.yml @@ -63,7 +63,7 @@ jobs: check: name: Check needs: [prepare] - uses: ./.github/workflows/check.yml + uses: $/.github/workflows/check.yml permissions: pull-requests: write # cherry-picks: unused in merge queue but required for check workflow secrets: @@ -75,7 +75,7 @@ jobs: lint: name: Lint needs: [prepare] - uses: ./.github/workflows/lint.yml + uses: $/.github/workflows/lint.yml secrets: CACHIX_AUTH_TOKEN_GHA: ${{ secrets.CACHIX_AUTH_TOKEN_GHA }} with: @@ -85,7 +85,7 @@ jobs: eval: name: Eval needs: [prepare] - uses: ./.github/workflows/eval.yml + uses: $/.github/workflows/eval.yml # The eval workflow requests these permissions so we must explicitly allow them, # even though they are unused when working with the merge queue. permissions: @@ -103,7 +103,7 @@ jobs: build: name: Build needs: [prepare] - uses: ./.github/workflows/build.yml + uses: $/.github/workflows/build.yml secrets: CACHIX_AUTH_TOKEN_GHA: ${{ secrets.CACHIX_AUTH_TOKEN_GHA }} with: diff --git a/.github/workflows/periodic-merge-24h.yml b/.github/workflows/periodic-merge-24h.yml index d14c482df755..c6e31f737b6e 100644 --- a/.github/workflows/periodic-merge-24h.yml +++ b/.github/workflows/periodic-merge-24h.yml @@ -40,7 +40,7 @@ jobs: - name: merge-base(master,staging) → haskell-updates from: master staging into: haskell-updates - uses: ./.github/workflows/periodic-merge.yml + uses: $/.github/workflows/periodic-merge.yml with: from: ${{ matrix.pairs.from }} into: ${{ matrix.pairs.into }} diff --git a/.github/workflows/periodic-merge-6h.yml b/.github/workflows/periodic-merge-6h.yml index ad81eb6c9a3b..0da0a3336364 100644 --- a/.github/workflows/periodic-merge-6h.yml +++ b/.github/workflows/periodic-merge-6h.yml @@ -37,7 +37,7 @@ jobs: into: staging - from: master into: staging-nixos - uses: ./.github/workflows/periodic-merge.yml + uses: $/.github/workflows/periodic-merge.yml with: from: ${{ matrix.pairs.from }} into: ${{ matrix.pairs.into }} diff --git a/.github/workflows/pull-request-target.yml b/.github/workflows/pull-request-target.yml index aa42175a0cc1..98d463cb588d 100644 --- a/.github/workflows/pull-request-target.yml +++ b/.github/workflows/pull-request-target.yml @@ -75,7 +75,7 @@ jobs: check: name: Check needs: [prepare] - uses: ./.github/workflows/check.yml + uses: $/.github/workflows/check.yml permissions: # cherry-picks pull-requests: write @@ -92,7 +92,7 @@ jobs: lint: name: Lint needs: [prepare] - uses: ./.github/workflows/lint.yml + uses: $/.github/workflows/lint.yml with: mergedSha: ${{ needs.prepare.outputs.mergedSha }} targetSha: ${{ needs.prepare.outputs.targetSha }} @@ -100,7 +100,7 @@ jobs: eval: name: Eval needs: [prepare] - uses: ./.github/workflows/eval.yml + uses: $/.github/workflows/eval.yml permissions: # compare pull-requests: write @@ -119,7 +119,7 @@ jobs: bot: name: Bot needs: [prepare, eval] - uses: ./.github/workflows/bot.yml + uses: $/.github/workflows/bot.yml permissions: issues: write pull-requests: write @@ -131,7 +131,7 @@ jobs: build: name: Build needs: [prepare] - uses: ./.github/workflows/build.yml + uses: $/.github/workflows/build.yml with: artifact-prefix: ${{ inputs.artifact-prefix }} baseBranch: ${{ needs.prepare.outputs.baseBranch }} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index ad1aaed202ff..35208ae4fab2 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -103,7 +103,7 @@ jobs: if: needs.prepare.outputs.merge-group name: Merge Group needs: [prepare] - uses: ./.github/workflows/merge-group.yml + uses: $/.github/workflows/merge-group.yml # Those are actually only used on the merge_group event, but will throw an error if not set. permissions: pull-requests: write # unused on pull_request, required by merge-group workflow @@ -117,7 +117,7 @@ jobs: if: needs.prepare.outputs.pr name: PR needs: [prepare] - uses: ./.github/workflows/pull-request-target.yml + uses: $/.github/workflows/pull-request-target.yml # Those are actually only used on the pull_request_target event, but will throw an error if not set. permissions: issues: write # unused on pull_request, required by bot workflow From 7673e4c2ace8378da3e711b784b85b4eef226b5a Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Fri, 25 Sep 2026 21:03:08 -0400 Subject: [PATCH 23/29] ci/pinned.json: update [nixpkgs-26.05-darwin] Changes: - revision: 51fe96f9107566e6b8eeb7fc4ba696c01e548b04 + revision: 7486293a941f7b0ec123f0c431517027f705f60f - url: https://github.com/NixOS/nixpkgs/archive/51fe96f9107566e6b8eeb7fc4ba696c01e548b04.tar.gz + url: https://github.com/NixOS/nixpkgs/archive/7486293a941f7b0ec123f0c431517027f705f60f.tar.gz - hash: sha256-yj0LPLnsmYoLmA3FGANjeTEwej0/DHjZBXWnDQDUuIs= + hash: sha256-WQhNWIW3PPijuZexyl5Zf0tJuQ7sKt5C9WPXVO4pMuM= [nixpkgs] Changes: - revision: 7525d999cd850b9a488817abc89c75dc733acf17 + revision: 7d5589bbf421c7b6f4185371abe3c465b1b557e9 - url: https://github.com/NixOS/nixpkgs/archive/7525d999cd850b9a488817abc89c75dc733acf17.tar.gz + url: https://github.com/NixOS/nixpkgs/archive/7d5589bbf421c7b6f4185371abe3c465b1b557e9.tar.gz - hash: sha256-4IHyyLgLBdKefkljdKod4IMn023pQiDXAWJA187cmdY= + hash: sha256-8emM5Z42GzMSLLvjJt7UkX1j2k2TKXQIS7FnPTfeHno= (cherry picked from commit d61db5aa6b86df0e8cdd242dc7eb5c8909d0be74) --- ci/pinned.json | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/ci/pinned.json b/ci/pinned.json index 32f5e186650c..a30aff6f92f8 100644 --- a/ci/pinned.json +++ b/ci/pinned.json @@ -9,9 +9,9 @@ }, "branch": "nixpkgs-unstable", "submodules": false, - "revision": "7525d999cd850b9a488817abc89c75dc733acf17", - "url": "https://github.com/NixOS/nixpkgs/archive/7525d999cd850b9a488817abc89c75dc733acf17.tar.gz", - "hash": "sha256-4IHyyLgLBdKefkljdKod4IMn023pQiDXAWJA187cmdY=" + "revision": "7d5589bbf421c7b6f4185371abe3c465b1b557e9", + "url": "https://github.com/NixOS/nixpkgs/archive/7d5589bbf421c7b6f4185371abe3c465b1b557e9.tar.gz", + "hash": "sha256-8emM5Z42GzMSLLvjJt7UkX1j2k2TKXQIS7FnPTfeHno=" }, "nixpkgs-26.05-darwin": { "type": "Git", @@ -22,9 +22,9 @@ }, "branch": "nixpkgs-26.05-darwin", "submodules": false, - "revision": "51fe96f9107566e6b8eeb7fc4ba696c01e548b04", - "url": "https://github.com/NixOS/nixpkgs/archive/51fe96f9107566e6b8eeb7fc4ba696c01e548b04.tar.gz", - "hash": "sha256-yj0LPLnsmYoLmA3FGANjeTEwej0/DHjZBXWnDQDUuIs=" + "revision": "7486293a941f7b0ec123f0c431517027f705f60f", + "url": "https://github.com/NixOS/nixpkgs/archive/7486293a941f7b0ec123f0c431517027f705f60f.tar.gz", + "hash": "sha256-WQhNWIW3PPijuZexyl5Zf0tJuQ7sKt5C9WPXVO4pMuM=" } }, "version": 8 From 240130920de23758bff7c5d12a15071221dfbeaf Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Fri, 25 Sep 2026 21:21:45 -0400 Subject: [PATCH 24/29] various: fix formatting (cherry picked from commit 53bc4d6aa3a65bd08347344fa05c4d680a9d3088) --- nixos/modules/hardware/facter/camera/ipu6.nix | 2 +- nixos/modules/services/x11/desktop-managers/xfce.nix | 6 +++--- pkgs/build-support/dart/pub2nix/pubspec-lock.nix | 2 +- pkgs/by-name/in/iniparser/package.nix | 6 +++--- pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix | 6 +++--- 5 files changed, 11 insertions(+), 11 deletions(-) diff --git a/nixos/modules/hardware/facter/camera/ipu6.nix b/nixos/modules/hardware/facter/camera/ipu6.nix index 5319d8bf3d49..799c22188824 100644 --- a/nixos/modules/hardware/facter/camera/ipu6.nix +++ b/nixos/modules/hardware/facter/camera/ipu6.nix @@ -66,7 +66,7 @@ let in bus_type.name == "PCI" && devices - ? "${vendorHex}:${deviceHex}:${subVendorHex}:${subDeviceHex}/${baseClassHex}-${subClassHex}-${revisionHex}" + ? "${vendorHex}:${deviceHex}:${subVendorHex}:${subDeviceHex}/${baseClassHex}-${subClassHex}-${revisionHex}" ); in { diff --git a/nixos/modules/services/x11/desktop-managers/xfce.nix b/nixos/modules/services/x11/desktop-managers/xfce.nix index 2d53eb58f287..e87e36882206 100644 --- a/nixos/modules/services/x11/desktop-managers/xfce.nix +++ b/nixos/modules/services/x11/desktop-managers/xfce.nix @@ -209,9 +209,9 @@ in DesktopNames=XFCE Keywords=xfce;wayland;desktop;environment;session; '').overrideAttrs - (_: { - passthru.providedSessions = [ "xfce-wayland" ]; - }) + (_: { + passthru.providedSessions = [ "xfce-wayland" ]; + }) ) ]; diff --git a/pkgs/build-support/dart/pub2nix/pubspec-lock.nix b/pkgs/build-support/dart/pub2nix/pubspec-lock.nix index 456236e18e5e..5ea72683e1fc 100644 --- a/pkgs/build-support/dart/pub2nix/pubspec-lock.nix +++ b/pkgs/build-support/dart/pub2nix/pubspec-lock.nix @@ -150,7 +150,7 @@ let "sdk" = mkSdkDependencySource; } .${details.source} - name + name ) details )) diff --git a/pkgs/by-name/in/iniparser/package.nix b/pkgs/by-name/in/iniparser/package.nix index 260dfdf1887f..5048189a30ad 100644 --- a/pkgs/by-name/in/iniparser/package.nix +++ b/pkgs/by-name/in/iniparser/package.nix @@ -54,9 +54,9 @@ stdenv.mkDerivation (finalAttrs: { (unity-test.override { supportDouble = true; }).overrideAttrs - { - doCheck = false; - } + { + doCheck = false; + } ) ]; diff --git a/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix b/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix index 80dad06be8f8..a5220d11a2fa 100644 --- a/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix +++ b/pkgs/os-specific/bsd/freebsd/pkgs/filterSource.nix @@ -28,9 +28,9 @@ runCommand "${pname}-filtered-src" enableOpenSSL = false; enableLZ4 = false; }).overrideAttrs - { - doCheck = false; - } + { + doCheck = false; + } ) ]; } From deae52eecf2c1d3d841a81e888edfa3e0fb84f92 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 26 Sep 2026 01:05:37 +0000 Subject: [PATCH 25/29] sub-store-frontend: 2.32.2 -> 2.34.0 (cherry picked from commit b7395edf46d458ea7c95c1b0e71ff21d0307df9f) --- pkgs/by-name/su/sub-store-frontend/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/su/sub-store-frontend/package.nix b/pkgs/by-name/su/sub-store-frontend/package.nix index 77829b5c17cc..f72b225d21bd 100644 --- a/pkgs/by-name/su/sub-store-frontend/package.nix +++ b/pkgs/by-name/su/sub-store-frontend/package.nix @@ -14,13 +14,13 @@ let in buildNpmPackage (finalAttrs: { pname = "sub-store-frontend"; - version = "2.32.2"; + version = "2.34.0"; src = fetchFromGitHub { owner = "sub-store-org"; repo = "Sub-Store-Front-End"; tag = finalAttrs.version; - hash = "sha256-TbKJNSA+ivUd7bHDtE9COaZFMqxRkRdBXWkK7y7JMSU="; + hash = "sha256-jphgUjJouLky6jxTSk+6YBbwaNTV7+/oTu2RXc3UNk0="; }; nativeBuildInputs = [ From 95253a912a98debc81dc753ef7289e64ff1960ce Mon Sep 17 00:00:00 2001 From: Tom Herbers Date: Fri, 25 Sep 2026 01:19:54 +0200 Subject: [PATCH 26/29] incus-lts: backport 7.5 security fixes sourced from: - https://github.com/lxc/incus/pull/4071 - https://github.com/lxc/incus/commits/stable-7.0/?before=f22d8a92dff8e4cf01260ab85405db754bcfc026+35 - https://salsa.debian.org/go-team/packages/incus/-/commit/4992bd88f727414d9f02e9966feb235daf8d755d - https://salsa.debian.org/go-team/packages/incus/-/commit/bdec650ea4657450a90300c1e25e4d9b5ba71547 (cherry picked from commit 3312dbf41a41ab1cc115e4920eb4cecc4015907a) --- pkgs/by-name/in/incus/lts.nix | 57 ++++++++++++++++++++++++++++++++++- 1 file changed, 56 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/in/incus/lts.nix b/pkgs/by-name/in/incus/lts.nix index a0185fba0496..db6653351259 100644 --- a/pkgs/by-name/in/incus/lts.nix +++ b/pkgs/by-name/in/incus/lts.nix @@ -111,7 +111,62 @@ import ./generic.nix { url = "https://github.com/lxc/incus/commit/9e188e31e43c21fa8f2a4cac265aa246d4c947f2.patch?full_index=1"; hash = "sha256-KFYKB9PJK/U4/jSe3rmMeR9FWevvvi47BRy055Zj8Io="; }) - + # incus/file: Contain recursive pull symlinks + (fetchpatch2 { + url = "https://salsa.debian.org/go-team/packages/incus/-/raw/4992bd88f727414d9f02e9966feb235daf8d755d/debian/patches/126-GHSA-wfvq-qh87-gm4j.patch"; + hash = "sha256-hD7l9/mlUuISLV1hrvuYMyPFYe1XUWnLO15RJyO1ZlA="; + }) + # incusd: Don't follow symlinks when receiving migration + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/9afa3d58ef9ffae40eb1980bd33592d00fe1feba.patch?full_index=1"; + hash = "sha256-SJKrTdR/BKNVPa9P7Yowukfm71D3M9yGh1iGQpkhEDE="; + }) + # incusd/storage: Treat volume creation with a source as a copy (sourced from stable-7.0) + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/e59d35263a0e027b4a0344ab8d05c80c622a21e2.patch?full_index=1"; + hash = "sha256-oHM9IGGjPRwsmc5JAYaBY65HV+H3ZC1/ebqQts/tDow="; + }) + # incusd/storage/drivers: Confine btrfs subvolume paths + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/99a8ba3101e91be6cd7013e80ff916f32d495b71.patch?full_index=1"; + hash = "sha256-iwybe/E8Lucwf6ih6gWt3b/jnG3UGYep2GoqL/h4qn8="; + }) + # incusd/storage: Validate dependent volume names on backup import + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/2ef78c71a5f3c9db4a6ad438563ec99497686d83.patch?full_index=1"; + hash = "sha256-apBgxM15JA+8q/lR5mJRG85rBn+2pEuZdcgOjPn/y8g="; + }) + # incusd/storage: Ignore backup project for dependent + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/10d6ea9a7163c2a7b16f9e9ccf0bd45981c3355e.patch?full_index=1"; + hash = "sha256-5gkMiAb5Ewzsiv9LmZ2oJx+7xTdIbkVnXEkt67metlU="; + }) + # incusd/storage/s3: Require x-amz-* headers to be signed + (fetchpatch2 { + url = "https://salsa.debian.org/go-team/packages/incus/-/raw/4992bd88f727414d9f02e9966feb235daf8d755d/debian/patches/123-GHSA-mmj7-8rgf-mx2h.patch"; + hash = "sha256-OHjdOPQ3UyNfucLElKXA4iRYVhOF6fq+m0wUnaYGoiI="; + }) + # incusd/operations: Check project access on operation get and wait + # incusd/operations: Hide access token operations from non-admins + (fetchpatch2 { + url = "https://salsa.debian.org/go-team/packages/incus/-/raw/bdec650ea4657450a90300c1e25e4d9b5ba71547/debian/patches/125-GHSA-mfwv-x733-9446.patch"; + hash = "sha256-LMx5sb7rC5U9BLsXYhqN3SaW7K/d4q2H1OvcDQPNm7w="; + }) + # incusd/storage/buckets: Require can_edit to read bucket keys + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/1eaf9b8bfed2b8cf09182c88fd81b10327605ade.patch?full_index=1"; + hash = "sha256-KrQtsS8Ug7K5bMeduV9tPeunHOnCXfNNqlbpVMTNzws="; + }) + # incusd/project: Restrict volume options on update and copy + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/da36896aa8af65080a79fd1a4b8abcf75d46cbd1.patch?full_index=1"; + hash = "sha256-+W+2RXtJO/IGd+ejpkylsaNfH8JtSIMTun9bxbtbPxU="; + }) + # incusd/instances: Check project restrictions on clustered refresh + (fetchpatch2 { + url = "https://github.com/lxc/incus/commit/f22d8a92dff8e4cf01260ab85405db754bcfc026.patch?full_index=1"; + hash = "sha256-LwQRWQzZewU0QjdaerKFJb4h99RKuTLBZ80PifJONkM="; + }) ]; lts = true; nixUpdateExtraArgs = [ From d5d1e23cafd483a5ab16dcead94d9cc5eb3aabc3 Mon Sep 17 00:00:00 2001 From: Rafael Ieda Date: Fri, 25 Sep 2026 06:13:17 -0300 Subject: [PATCH 27/29] microsoft-edge, msedgedriver: 153.0.4234.48 -> 154.0.4258.37 (cherry picked from commit 11a3df0992b39cd001975cb7728f124646bbce62) --- pkgs/by-name/mi/microsoft-edge/package.nix | 4 ++-- pkgs/by-name/ms/msedgedriver/package.nix | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/mi/microsoft-edge/package.nix b/pkgs/by-name/mi/microsoft-edge/package.nix index fe79b99032cd..13cdd8b602e7 100644 --- a/pkgs/by-name/mi/microsoft-edge/package.nix +++ b/pkgs/by-name/mi/microsoft-edge/package.nix @@ -164,11 +164,11 @@ let in stdenvNoCC.mkDerivation (finalAttrs: { pname = "microsoft-edge"; - version = "153.0.4234.48"; + version = "154.0.4258.37"; src = fetchurl { url = "https://packages.microsoft.com/repos/edge/pool/main/m/microsoft-edge-stable/microsoft-edge-stable_${finalAttrs.version}-1_amd64.deb"; - hash = "sha256-JVNZQo8F9xzWNpKmJlwOKnRf/wiuDkJh+c/tUdgIEC8="; + hash = "sha256-xvopdHM5kTIbRsQGS3hc3sWhTYzd0YK8X9oFfjfnYD0="; }; # With strictDeps on, some shebangs were not being patched correctly diff --git a/pkgs/by-name/ms/msedgedriver/package.nix b/pkgs/by-name/ms/msedgedriver/package.nix index c258d19d2f3e..43de4807a9a0 100644 --- a/pkgs/by-name/ms/msedgedriver/package.nix +++ b/pkgs/by-name/ms/msedgedriver/package.nix @@ -12,11 +12,11 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "msedgedriver"; - version = "153.0.4234.48"; + version = "154.0.4258.37"; src = fetchzip { url = "https://msedgedriver.microsoft.com/${finalAttrs.version}/edgedriver_linux64.zip"; - hash = "sha256-5gCrPPjYC/AmsO5vSNTX/r3hm6wATvNeIxRt4TYyZhY="; + hash = "sha256-XbOQl9FyckF3Qybb+40474ImJDKahBkekPoydf/TxV0="; stripRoot = false; }; From aea1a1a7aeae6175297f4b4c51d769e18ffd6068 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 26 Sep 2026 16:52:35 -0400 Subject: [PATCH 28/29] ci/github-script/bot: replace "unmaintained" label with "no default reviewers" (cherry picked from commit 5a6dae13945b70a25f9dfeed7f7c4e74b1dc36cb) --- ci/github-script/bot.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ci/github-script/bot.js b/ci/github-script/bot.js index efb5f4935aa8..aa607d0dfc1b 100644 --- a/ci/github-script/bot.js +++ b/ci/github-script/bot.js @@ -491,7 +491,7 @@ export default async ({ github, context, core, dry }) => { ), ).map((id) => parseInt(id)) - prLabels['7.unmaintained'] = + prLabels['7.no default reviewers'] = user_maintainers.length === 0 && team_maintainers.length === 0 && owners.length === 0 From f28d53e12c50105b86a8d47f850123103a460e8f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 13 Aug 2026 05:03:22 +0000 Subject: [PATCH 29/29] odamex: 12.2.0 -> 12.3.0 (cherry picked from commit 5b7a4c7b977430dbdb25a8b2243a5901db0cbbc4) --- pkgs/by-name/od/odamex/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/od/odamex/package.nix b/pkgs/by-name/od/odamex/package.nix index b98c575dda8f..972b7a209065 100644 --- a/pkgs/by-name/od/odamex/package.nix +++ b/pkgs/by-name/od/odamex/package.nix @@ -43,13 +43,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "odamex"; - version = "12.2.0"; + version = "12.3.0"; src = fetchFromGitHub { owner = "odamex"; repo = "odamex"; tag = finalAttrs.version; - hash = "sha256-cRQtY4C0gjzheE4cG8aPjzAoPf/Hm05a6tidsbce7uM="; + hash = "sha256-JT8flyIEHfCejJnRd+bpUGKNAM746i51EuTItLho5WE="; fetchSubmodules = true; };