Merge release-26.05 into staging-next-26.05

This commit is contained in:
nixpkgs-ci[bot]
2026-09-05 00:27:29 +00:00
committed by GitHub
35 changed files with 674 additions and 97 deletions

View File

@@ -49,7 +49,7 @@ jobs:
ci/github-script
- name: Install dependencies
run: npm ci --package-lock-only=false @actions/artifact bottleneck
run: npm ci --package-lock-only=false --no-audit @actions/artifact bottleneck
working-directory: ci/github-script
# Use a GitHub App, because it has much higher rate limits: 12,500 instead of 5,000 req / hour.

View File

@@ -51,7 +51,7 @@ jobs:
ci/github-script
- name: Install dependencies
run: npm ci --package-lock-only=false bottleneck
run: npm ci --package-lock-only=false --no-audit bottleneck
working-directory: trusted/ci/github-script
- uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
@@ -153,7 +153,7 @@ jobs:
- name: Install dependencies to trusted/
run: |
npm ci --package-lock-only=false
npm ci --package-lock-only=false --no-audit
echo "$PWD/node_modules/.bin" >> "$GITHUB_PATH"
working-directory: nixpkgs/trusted/ci/github-script

View File

@@ -38,7 +38,7 @@ jobs:
maintainers/github-teams.json
- name: Install dependencies
run: npm ci --package-lock-only=false bottleneck
run: npm ci --package-lock-only=false --no-audit bottleneck
working-directory: ci/github-script
- name: Synchronise teams

View File

@@ -689,16 +689,21 @@ export default async ({ github, context, core, dry }) => {
if (context.payload.pull_request) {
await handle({ item: context.payload.pull_request, stats })
} else {
// We don't use filters here because that causes GitHub to use an often-outdated index,
// resulting in the cursor not being updated, and therefore causing the same PRs
// to use up our rate limit over and over again.
const lastRun = (
await github.rest.actions.listWorkflowRuns({
...context.repo,
workflow_id: 'bot.yml',
event: 'schedule',
status: 'success',
exclude_pull_requests: true,
per_page: 1,
})
).data.workflow_runs[0]
).data.workflow_runs.find(
(run) => run.event === 'schedule' && run.conclusion === 'success',
)
core.info(
`Last successful run created at: ${lastRun?.created_at ?? '<n/a>'}`,
)
const cutoff = new Date(
Math.max(
@@ -794,6 +799,7 @@ export default async ({ github, context, core, dry }) => {
} else {
// No stats.artifacts++, because this does not allow passing a custom token.
// Thus, the upload will not happen with the app token, but the default github.token.
core.info(`pagination-cursor: ${cursor}`)
await artifactClient.uploadArtifact(
'pagination-cursor',
[uploadPath],
@@ -803,6 +809,8 @@ export default async ({ github, context, core, dry }) => {
},
)
}
} else {
core.info('pagination-cursor: <n/a>')
}
// Some items might be in both search results, so filtering out duplicates as well.

View File

@@ -24460,6 +24460,12 @@
githubId = 47582;
name = "Samir Talwar";
};
samiser = {
email = "nixos@me.samiser.xyz";
github = "samiser";
githubId = 32001364;
name = "Sam";
};
samlich = {
email = "nixos@samli.ch";
github = "samlich";

View File

@@ -20,6 +20,7 @@ let
modularServicesModule = {
options = {
"<imports = [ pkgs.ghostunnel.services.default ]>" = fakeSubmodule pkgs.ghostunnel.services.default;
"<imports = [ pkgs.git-pages.services.default ]>" = fakeSubmodule pkgs.git-pages.services.default;
"<imports = [ pkgs.ktls-utils.services.default ]>" = fakeSubmodule pkgs.ktls-utils.services.default;
"<imports = [ pkgs.php.services.default ]>" = fakeSubmodule pkgs.php.services.default;
"<imports = [ pkgs.snid.services.default ]>" = fakeSubmodule pkgs.snid.services.default;

View File

@@ -671,6 +671,7 @@ in
geth = runTest ./geth.nix;
ghostunnel = runTest ./ghostunnel.nix;
ghostunnel-modular = runTest ./ghostunnel-modular.nix;
git-pages-modular = runTest ./git-pages.nix;
gitdaemon = runTest ./gitdaemon.nix;
gitea = handleTest ./gitea.nix { giteaPackage = pkgs.gitea; };
github-runner = runTest ./github-runner.nix;

65
nixos/tests/git-pages.nix Normal file
View File

@@ -0,0 +1,65 @@
{ pkgs, ... }:
{
name = "git-pages-modular-service";
nodes.machine = { pkgs, ... }: {
environment.systemPackages = [ pkgs.curl ];
system.services.git-pages = {
imports = [ pkgs.git-pages.services.default ];
git-pages = {
settings.server = {
pages = "tcp/:3000";
caddy = "tcp/:3001";
metrics = "tcp/:3002";
};
};
systemd.service.environment.PAGES_INSECURE = "1";
};
services.caddy = {
enable = true;
configFile = pkgs.writeText "Caddyfile" ''
{
admin off
persist_config off
auto_https disable_redirects
on_demand_tls {
permission http http://localhost:3001
}
}
https://, http:// {
tls {
on_demand
}
reverse_proxy http://localhost:3000
}
'';
};
networking.firewall.allowedTCPPorts = [ 80 ];
};
testScript =
let
testSite = pkgs.runCommand "git-pages-testsite.tar" { } ''
echo It works! > index.html
tar cvf $out index.html
'';
in
''
start_all()
machine.wait_for_unit("caddy.service")
machine.wait_for_open_port(80)
machine.wait_for_unit("git-pages.service")
machine.wait_for_open_port(3001)
machine.wait_for_open_port(3002)
machine.fail("curl -f http://localhost/.git-pages/health")
machine.succeed("curl -f http://localhost/ -X PUT --data-binary @${testSite} --header 'Content-Type: application/x-tar'")
machine.wait_until_succeeds("test -f /var/lib/git-pages/data/site/localhost/.index")
machine.succeed("curl -f http://localhost/.git-pages/health")
machine.succeed("curl -f http://localhost/ | grep -F 'It works!'")
machine.succeed("curl -f http://localhost:3002/metrics")
'';
}

View File

@@ -86,6 +86,7 @@ stdenv.mkDerivation (finalAttrs: {
strictDeps = true;
__structuredAttrs = true;
__darwinAllowLocalNetworking = true;
nativeBuildInputs = [
cmake
@@ -106,6 +107,16 @@ stdenv.mkDerivation (finalAttrs: {
curl
];
# xeus-cpp probes the host `c++` for its include search path and prepends the
# result, which shadows the hermetic paths we hand it (Xcode's libc++ and SDK
# win on any machine with Xcode). Skip the probe when those paths are supplied.
postPatch = ''
substituteInPlace src/xinterpreter.cpp --replace-fail \
"Cpp::DetectSystemCompilerIncludePaths(CxxSystemIncludes);" \
"if (const char* e = std::getenv(\"CPPINTEROP_EXTRA_INTERPRETER_ARGS\"); !e || !*e)
Cpp::DetectSystemCompilerIncludePaths(CxxSystemIncludes);"
'';
cmakeFlags = [
(lib.cmakeBool "XEUS_CPP_BUILD_TESTS" finalAttrs.finalPackage.doCheck)
"-DXEUS_CPP_RESOURCE_DIR=${resourceDir}"

View File

@@ -1,10 +1,10 @@
{
"chromium": {
"version": "152.0.7977.75",
"version": "152.0.7977.82",
"chromedriver": {
"version": "152.0.7977.76",
"hash_darwin": "sha256-tK7HmSRzWr/ruU484L+Og4wruS87fRHLEBKSZd4SSDA=",
"hash_darwin_aarch64": "sha256-+f0e6EGB0aXeyyYN8Db5u3+G9/RjILI/I0/2QWiVg1M="
"version": "152.0.7977.83",
"hash_darwin": "sha256-cx8v6bu6MuSU+LHOGmxcOWNhH7tZFaegHfcMv+RSZGg=",
"hash_darwin_aarch64": "sha256-OM3ogo/Z76H8E8F9RhbcLwjSEgWNxdBJxngDI/nHhkI="
},
"deps": {
"depot_tools": {
@@ -21,8 +21,8 @@
"DEPS": {
"src": {
"url": "https://chromium.googlesource.com/chromium/src.git",
"rev": "4999cc1efed37c4d91dc4ce6ec4b0a50e2a9a8cb",
"hash": "sha256-RXykREnCulCwk8zkk8OAd62TM4qel6j4uhyaaYzgolY=",
"rev": "d04cdb24d67b081f6cf80200ffc5233f44b61109",
"hash": "sha256-JiYTfMJBtUWMUSicQdSCXNUtgjLGeaMj4vCNpMvYACk=",
"recompress": true
},
"src/third_party/clang-format/script": {
@@ -92,8 +92,8 @@
},
"src/third_party/angle": {
"url": "https://chromium.googlesource.com/angle/angle.git",
"rev": "736ed80c7552a4b267bd54a282b971aa4555cb3e",
"hash": "sha256-3ZCIFT7j944HWPOiADQa88TQZctLej5vbrBFA/FwyHw="
"rev": "7df613367a1d4ca9aea9ece344d4580d32d132a9",
"hash": "sha256-bYGok5QvWJoCfliRPQqrDz0ttKf1r9HoFxoC4qwdI3o="
},
"src/third_party/angle/third_party/glmark2/src": {
"url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2",
@@ -672,8 +672,8 @@
},
"src/third_party/skia": {
"url": "https://skia.googlesource.com/skia.git",
"rev": "b6d106297ff9ef2ff8094033695d045e87775581",
"hash": "sha256-sun/P/JVhTKfRwmVK5dgnz8UZEFnQoyXZZS6PN5z9us="
"rev": "0873ec164a06966b90ae0d43ef783cfb180084ae",
"hash": "sha256-LbSs+UNakFipC2t9TSbZVreylVXHf1PsbK6z2qJh6QI="
},
"src/third_party/smhasher/src": {
"url": "https://chromium.googlesource.com/external/smhasher.git",
@@ -842,8 +842,8 @@
},
"src/v8": {
"url": "https://chromium.googlesource.com/v8/v8.git",
"rev": "3de6ffffbfdcf265e9f11a5c9d1cfb4d486d7550",
"hash": "sha256-ZHEmeSe8r226gjazm91GYqlfbM9a5yi8KnFv4iAWFKE="
"rev": "4323497a6a73839e6d5260f6acd7ec0212cb3321",
"hash": "sha256-HUg4GGtYL4xGk/xw0QXxNZAnsFVcznklWGQaqhZj9QM="
},
"src/agents/shared": {
"url": "https://chromium.googlesource.com/chromium/agents.git",
@@ -853,7 +853,7 @@
}
},
"ungoogled-chromium": {
"version": "152.0.7977.75",
"version": "152.0.7977.82",
"deps": {
"depot_tools": {
"rev": "38c391feba5fb96812f9028da12413ffc39df394",
@@ -865,16 +865,16 @@
"hash": "sha256-ovLx6KaORdXqnWgbsGEty10k2CHuCmTk3yEqy5//ovk="
},
"ungoogled-patches": {
"rev": "152.0.7977.75-1",
"hash": "sha256-HXWnJfk0SxC8sRcgtFdGBOOeiV7kEQD2YXQFBwMsU1s="
"rev": "152.0.7977.82-1",
"hash": "sha256-5KxsbzpRybc/ub6HJbN6QkJVL4iDdoAXE7vwjtjAJXA="
},
"npmHash": "sha256-pF0JtwFpPC4/fodbhSJnQKkczA9WlDg4VqEAy9aDVLg="
},
"DEPS": {
"src": {
"url": "https://chromium.googlesource.com/chromium/src.git",
"rev": "4999cc1efed37c4d91dc4ce6ec4b0a50e2a9a8cb",
"hash": "sha256-RXykREnCulCwk8zkk8OAd62TM4qel6j4uhyaaYzgolY=",
"rev": "d04cdb24d67b081f6cf80200ffc5233f44b61109",
"hash": "sha256-JiYTfMJBtUWMUSicQdSCXNUtgjLGeaMj4vCNpMvYACk=",
"recompress": true
},
"src/third_party/clang-format/script": {
@@ -944,8 +944,8 @@
},
"src/third_party/angle": {
"url": "https://chromium.googlesource.com/angle/angle.git",
"rev": "736ed80c7552a4b267bd54a282b971aa4555cb3e",
"hash": "sha256-3ZCIFT7j944HWPOiADQa88TQZctLej5vbrBFA/FwyHw="
"rev": "7df613367a1d4ca9aea9ece344d4580d32d132a9",
"hash": "sha256-bYGok5QvWJoCfliRPQqrDz0ttKf1r9HoFxoC4qwdI3o="
},
"src/third_party/angle/third_party/glmark2/src": {
"url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2",
@@ -1524,8 +1524,8 @@
},
"src/third_party/skia": {
"url": "https://skia.googlesource.com/skia.git",
"rev": "b6d106297ff9ef2ff8094033695d045e87775581",
"hash": "sha256-sun/P/JVhTKfRwmVK5dgnz8UZEFnQoyXZZS6PN5z9us="
"rev": "0873ec164a06966b90ae0d43ef783cfb180084ae",
"hash": "sha256-LbSs+UNakFipC2t9TSbZVreylVXHf1PsbK6z2qJh6QI="
},
"src/third_party/smhasher/src": {
"url": "https://chromium.googlesource.com/external/smhasher.git",
@@ -1694,8 +1694,8 @@
},
"src/v8": {
"url": "https://chromium.googlesource.com/v8/v8.git",
"rev": "3de6ffffbfdcf265e9f11a5c9d1cfb4d486d7550",
"hash": "sha256-ZHEmeSe8r226gjazm91GYqlfbM9a5yi8KnFv4iAWFKE="
"rev": "4323497a6a73839e6d5260f6acd7ec0212cb3321",
"hash": "sha256-HUg4GGtYL4xGk/xw0QXxNZAnsFVcznklWGQaqhZj9QM="
},
"src/agents/shared": {
"url": "https://chromium.googlesource.com/chromium/agents.git",

View File

@@ -111,8 +111,8 @@ rec {
thunderbird-140 = common {
applicationName = "Thunderbird ESR";
version = "140.14.0esr";
sha512 = "4c95b1ca3fc7f6429b2360a7e732635bdfb60927622a7da4d8af9ca2abd550611b91763c587cddad5d51c0dd4e905ba8e106da3cd21591a1bec3dba1b9a2502d";
version = "140.15.0esr";
sha512 = "52f014fb75ac131780aba924dd973a1fb5d6a60be4f800c258dca931e2c6ad75baaad37a5ad52228e91d3d174823b6b4d38ddc2dbbf9c04b8700cc33079448bb";
updateScript = callPackage ./update.nix {
attrPath = "thunderbirdPackages.thunderbird-140";

View File

@@ -8,16 +8,16 @@
php83.buildComposerProject2 (finalAttrs: {
pname = "bookstack";
version = "26.05.3";
version = "26.05.4";
src = fetchFromGitHub {
owner = "bookstackapp";
repo = "bookstack";
tag = "v${finalAttrs.version}";
hash = "sha256-IRJGgK1MEptQJlnvHVXINSnhr8TVp6S8fZRBi+4VGig=";
hash = "sha256-DDjJZehRUf1GP19S+RqhqZSSGOMF/SzItt2GFXi4+1U=";
};
vendorHash = "sha256-1x0czjCCD9Jf9TMhmkSpUt33q5+E1bw2l0SNP9VPRCE=";
vendorHash = "sha256-Ioth8Kp5fx4iwfy0p7N8xE0L41oWcp+ATfhmq3PUYyY=";
passthru = {
phpPackage = php83;

View File

@@ -8,13 +8,13 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "chhoto-url";
version = "7.5.0";
version = "7.5.1";
src = fetchFromGitHub {
owner = "SinTan1729";
repo = "chhoto-url";
tag = finalAttrs.version;
hash = "sha256-lyrTuZxsVui25JIfxDoezNcMTZDKgYOPJ9+VMOfhHjg=";
hash = "sha256-FAYbqNZVPUpfBKOn+cXvk5d8o29M9+d8t5ecihCQ4aY=";
fetchLFS = true;
};
@@ -27,7 +27,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
--replace-fail 'rust-version = "1.96"' 'rust-version = "1.95"'
'';
cargoHash = "sha256-y1MIiJ7NAP1F1c0IkrrVn1Wd2K+mrQD1RhqiumcPq1o=";
cargoHash = "sha256-C+eH6lrFSpE7zuR3fyyP44KG/rV0N2Uh4E7She0HuEA=";
postInstall = ''
mkdir -p $out/share/chhoto-url

View File

@@ -1,15 +1,16 @@
{
lib,
fetchFromGitHub,
cmake,
ninja,
python3,
llvmPackages_21,
apple-sdk,
cling,
cmake,
fetchFromGitHub,
gcc-unwrapped,
lib,
libffi,
libxml2,
llvmPackages_21,
ncurses,
ninja,
python3,
zlib,
zstd,
@@ -46,20 +47,49 @@ let
"${clingRoot}/lib/clang/20"
else
"${lib.getLib clang}/lib/clang/${lib.versions.major llvm.version}";
# These must precede the resource dir, because libc++ ships its own <stddef.h>
# that include_next's Clang's and errors out if reached second.
cxxIncludeArgs =
if stdenv.hostPlatform.isDarwin then
[
"-isystem"
"${lib.getDev llvmPackages.libcxx}/include/c++/v1"
]
else
[
"-isystem"
"${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}"
"-isystem"
"${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}/${stdenv.hostPlatform.config}"
];
libcIncludeArgs =
if stdenv.hostPlatform.isDarwin then
[
"-isystem"
"${apple-sdk.sdkroot}/usr/include"
"-iframework"
"${apple-sdk.sdkroot}/System/Library/Frameworks"
]
else
[
"-isystem"
"${lib.getDev stdenv.cc.libc}/include"
];
interpreterArgs = [
"-nostdinc"
"-nostdinc++"
"-resource-dir"
resourceDir
]
++ cxxIncludeArgs
++ [
"-isystem"
"${resourceDir}/include"
"-isystem"
"${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}"
"-isystem"
"${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}/${stdenv.hostPlatform.config}"
"-isystem"
"${lib.getDev stdenv.cc.libc}/include"
];
]
++ libcIncludeArgs;
in
assert lib.assertOneOf "backend" backend [

View File

@@ -12,13 +12,13 @@
buildNpmPackage (finalAttrs: {
pname = "ghostfolio";
version = "3.59.1";
version = "3.65.0";
src = fetchFromGitHub {
owner = "ghostfolio";
repo = "ghostfolio";
tag = finalAttrs.version;
hash = "sha256-Wf5uxU4lLB/Xw8SoZKFyyZulmpQCKKIIonDmyUlDyHs=";
hash = "sha256-a6gPbu9HsTTd5nIn2Ydj2CNv6Pg8NLpDhMr2B/pG8Go=";
# populate values that require us to use git. By doing this in postFetch we
# can delete .git afterwards and maintain better reproducibility of the src.
leaveDotGit = true;
@@ -28,7 +28,7 @@ buildNpmPackage (finalAttrs: {
'';
};
npmDepsHash = "sha256-pUE/zXM+q9RcV9pEMBMAhGUMB6Exn3ZWCbvFggzz0N8=";
npmDepsHash = "sha256-WpKjPSCXcP2L/yK8S3L6zxbobxX6blNbWh1dZBeKL58=";
postPatch = ''
substituteInPlace replace.build.mjs \

View File

@@ -2,8 +2,12 @@
lib,
buildGoModule,
fetchFromCodeberg,
fetchpatch,
nix-update-script,
versionCheckHook,
formats,
coreutils,
nixosTests,
}:
buildGoModule (finalAttrs: {
@@ -18,6 +22,16 @@ buildGoModule (finalAttrs: {
hash = "sha256-4yQ3RRJbOfMaqjJJ6CRRN7TuaYY8ScLXxMZPd4tWPwk=";
};
patches = [
# bugfix to avoid creating parent directory on start
# remove when https://codeberg.org/git-pages/git-pages/pulls/258 is available in the release
(fetchpatch {
name = "mkdirall-parent-dir-create.patch";
url = "https://codeberg.org/git-pages/git-pages/commit/507e57edbcfc0ec933a877bf26b1756ca0a61870.patch";
hash = "sha256-1CjU4yGmDOmYsxo3U44Cg2xLJkrmUOX5ZXTycdLs6OE=";
})
];
subPackages = [ "." ];
vendorHash = "sha256-NNIkzgRki2rtCVUnnhT44rEBcMZYiJPmsXySpxiHYR0=";
@@ -31,7 +45,16 @@ buildGoModule (finalAttrs: {
nativeInstallCheckInputs = [ versionCheckHook ];
versionCheckProgramArg = "-version";
passthru.updateScript = nix-update-script { };
passthru = {
tests = { inherit (nixosTests) git-pages-modular; };
updateScript = nix-update-script { };
services.default = {
imports = [
(lib.modules.importApply ./service.nix { inherit formats coreutils; })
];
git-pages.package = finalAttrs.finalPackage;
};
};
meta = {
description = "Scalable static site server for Git forges (like GitHub Pages or Netlify";

View File

@@ -0,0 +1,116 @@
# Non-module dependencies (`importApply`)
{ formats, coreutils }:
{
config,
lib,
options,
name,
...
}:
let
cfg = config.git-pages;
settingsFormat = formats.toml { };
configFile = "git-pages.toml";
configOutPath = config.configData.${configFile}.path;
in
{
_class = "service";
meta.maintainers = with lib.maintainers; [
dtomvan
phanirithvij
];
options.git-pages = {
package = lib.mkOption {
description = "Package to use for git-pages";
defaultText = "The git-pages package that provided this module.";
type = lib.types.package;
};
secretFile = lib.mkOption {
description = ''
File that contains secrets for the git-pages config.
If values in this file are set, any options specified take priority over the options set in
{option}`git-pages.settings`.
::: {.note}
See the [git-pages documentation](https://git-pages.org/running-a-server/#configuration) on
secrets and environment variables.
:::
'';
default = null;
type = lib.types.nullOr lib.types.str;
};
settings = lib.mkOption {
type = settingsFormat.type;
description = ''
Settings to set in config.toml.
::: {.note}
See the [git-pages documentation](https://git-pages.org/running-a-server/#configuration) on configuring the server.
:::
'';
default = { };
};
};
config = {
git-pages.settings.storage.fs.root = lib.mkDefault "/var/lib/${name}/data";
process.argv = [
(lib.getExe cfg.package)
"-config"
configOutPath
];
configData."${configFile}".source = settingsFormat.generate configFile cfg.settings;
}
// lib.optionalAttrs (options ? systemd) {
systemd.service = {
description = "Forge-agnostic static site server";
documentation = [ "https://git-pages.org/running-a-server/" ];
after = [ "network.target" ];
wants = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
restartTriggers = [ config.configData."${configFile}".source ];
serviceConfig = {
Restart = "always";
StateDirectory = name;
WorkingDirectory = "%S/${name}";
BindReadOnlyPaths = [ configOutPath ];
LoadCredential = lib.optional (cfg.secretFile != null) "secrets.toml:${cfg.secretFile}";
User = name;
DynamicUser = true;
# systemd service hardening
ProtectHome = true;
MemoryDenyWriteExecute = true;
PrivateDevices = true;
PrivateTmp = true;
ProtectSystem = "strict";
ProtectControlGroups = true;
RestrictSUIDSGID = true;
RestrictRealtime = true;
RestrictAddressFamilies = "AF_INET AF_INET6 AF_UNIX";
RestrictNamespaces = true;
LockPersonality = true;
ProtectKernelLogs = true;
ProtectKernelTunables = true;
ProtectHostname = true;
ProtectKernelModules = true;
PrivateUsers = true;
ProtectClock = true;
SystemCallArchitectures = "native";
SystemCallErrorNumber = "EPERM";
SystemCallFilter = "@system-service";
};
};
};
}

View File

@@ -180,7 +180,7 @@ let
linux = stdenvNoCC.mkDerivation (finalAttrs: {
inherit pname meta;
version = "152.0.7977.75";
version = "152.0.7977.82";
src =
let
@@ -195,8 +195,8 @@ let
url = "https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-stable/google-chrome-stable_${finalAttrs.version}-1_${debArch}.deb";
hash =
{
amd64 = "sha256-oLemT3aP/A/1zMkmCtnrtT/Rb3oTHi42mU2li4LZE98=";
arm64 = "sha256-OFS2UlA3+NKXBIEqJoGEnE7N9peXdQ2jdCOBQD834dI=";
amd64 = "sha256-TSXkoCjHinrpEGg1UcLyNHksxVlefj40k59Zk0KtpEY=";
arm64 = "sha256-HcBFWH2AjCB6GenrNw9ukS3X5pZpU6+5PIHZnD/jGOM=";
}
.${debArch};
};
@@ -306,11 +306,11 @@ let
darwin = stdenvNoCC.mkDerivation (finalAttrs: {
inherit pname meta;
version = "152.0.7977.76";
version = "152.0.7977.83";
src = fetchurl {
url = "http://dl.google.com/release2/chrome/fwccdneh3i55zgoy366y75r2ya_152.0.7977.76/GoogleChrome-152.0.7977.76.dmg";
hash = "sha256-VuYzRvaOH0YB/I1m1Agk+l4y4al1b4o4dZZnhm7J2PQ=";
url = "http://dl.google.com/release2/chrome/g62gliie746ywu62ed7go3adam_152.0.7977.83/GoogleChrome-152.0.7977.83.dmg";
hash = "sha256-Uc16WeBPhu/r7zB/UE9yt+cgkbpRYkRM3xtENFltqps=";
};
dontPatch = true;

View File

@@ -311,6 +311,11 @@ stdenv.mkDerivation (finalAttrs: {
Scrumplex
titaniumtown
];
knownVulnerabilities = [
"Immich 2.x.x will not receive further updates. Immich 3.x.x is available in NixOS 26.11 (unstable at the time of writing)"
"CVE-2026-59258"
"CVE-2026-82272"
];
platforms = lib.platforms.linux ++ lib.platforms.freebsd;
mainProgram = "server";
};

View File

@@ -12,13 +12,13 @@
buildDotnetModule (finalAttrs: {
pname = "jackett";
version = "0.24.2457";
version = "0.24.2527";
src = fetchFromGitHub {
owner = "jackett";
repo = "jackett";
tag = "v${finalAttrs.version}";
hash = "sha256-oLKej0+Loiwn2yEAOHMeCqv1fU4d0vd7nzX/uTl3dFU=";
hash = "sha256-IbSXGddfsD9r0ElsSToQ+n75F09WUnF2jHirFOAiu+Q=";
};
projectFile = "src/Jackett.Server/Jackett.Server.csproj";

View File

@@ -47,14 +47,14 @@ in
# as bootloader for various platforms and corresponding binary and helper files.
stdenv.mkDerivation (finalAttrs: {
pname = "limine";
version = "12.5.1";
version = "12.5.2";
# We don't use the Git source but the release tarball, as the source has a
# `./bootstrap` script performing network access to download resources.
# Packaging that in Nix is very cumbersome.
src = fetchurl {
url = "https://github.com/Limine-Bootloader/Limine/releases/download/v${finalAttrs.version}/limine-${finalAttrs.version}.tar.gz";
hash = "sha256-aGdx+IynrVBtI3Z5Zic/e5aVNWQeAFsxXr8xjIV1MTM=";
hash = "sha256-F4B4EzbWkMVR/FMFYEtMPj10mfbOvFBL+gzaO3EiE8E=";
};
enableParallelBuilding = true;

View File

@@ -11,17 +11,17 @@
rustPackages_1_97.rustPlatform.buildRustPackage (finalAttrs: {
pname = "mago";
version = "1.47.3";
version = "1.47.4";
src = fetchFromGitHub {
owner = "carthage-software";
repo = "mago";
tag = finalAttrs.version;
hash = "sha256-XHEwkE732i2Is9hl7hzOrdn2AmlqYVccx4DT5F+EYAI=";
hash = "sha256-Qi1Bz5u/ZDupJz/9ueAwCnJ1hUWIpx1B32dGzcp87Fo=";
forceFetchGit = true; # Does not download all files otherwise
};
cargoHash = "sha256-ibZ/YFKwwW1j7ZQonw0tizEFmFItuIDeKqgKOm3KZmc=";
cargoHash = "sha256-iw9ipn86SjXCdmC5W2naJvaSpYCYb6uNPkKVtA/ZMd4=";
env = {
# Get openssl-sys to use pkg-config

View File

@@ -164,11 +164,11 @@ let
in
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "microsoft-edge";
version = "152.0.4191.53";
version = "152.0.4191.62";
src = fetchurl {
url = "https://packages.microsoft.com/repos/edge/pool/main/m/microsoft-edge-stable/microsoft-edge-stable_${finalAttrs.version}-1_amd64.deb";
hash = "sha256-szIkRfvmzh4Lz/hOu+Dt6jZeDq9Jix72E23aUt6m46c=";
hash = "sha256-SzUssNgbFRwQcZUZoUFe/ZJXChydV/BV5eXYD2yZug0=";
};
# With strictDeps on, some shebangs were not being patched correctly

View File

@@ -12,11 +12,11 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "msedgedriver";
version = "152.0.4191.53";
version = "152.0.4191.62";
src = fetchzip {
url = "https://msedgedriver.microsoft.com/${finalAttrs.version}/edgedriver_linux64.zip";
hash = "sha256-3akRs0D76LAJ8Lgr3P7X+cDrMNXiEC+LWNH8lUdBM9k=";
hash = "sha256-dhUC+/XWACG/4In4xP0wOBjb6EIYlBnP9JT7j/xxBJk=";
stripRoot = false;
};

View File

@@ -0,0 +1,104 @@
{
lib,
stdenv,
fetchFromGitHub,
meson,
ninja,
pkg-config,
wayland-scanner,
bashNonInteractive,
cairo,
fontconfig,
freetype,
glib,
libGL,
librsvg,
libwebp,
libxkbcommon,
nlohmann_json,
pango,
stb,
tomlplusplus,
wayland,
wayland-protocols,
wlroots_0_20,
versionCheckHook,
nix-update-script,
}:
let
# nixpkgs stb doesn't have stb_image_resize2.h which noctalia-greeter needs
stb' = stb.overrideAttrs {
version = "0-unstable-2025-10-26";
src = fetchFromGitHub {
owner = "nothings";
repo = "stb";
rev = "f1c79c02822848a9bed4315b12c8c8f3761e1296";
hash = "sha256-BlyXJtAI7WqXCTT3ylww8zoG0hBxaojJnQDvdQOXJPE=";
};
};
in
stdenv.mkDerivation (finalAttrs: {
pname = "noctalia-greeter";
version = "1.3.1";
__structuredAttrs = true;
strictDeps = true;
src = fetchFromGitHub {
owner = "noctalia-dev";
repo = "noctalia-greeter";
tag = "v${finalAttrs.version}";
hash = "sha256-1ZdtgBwndNHDltX8J7DLLl2/LBgywQhmt1JNcanfeMA=";
};
nativeBuildInputs = [
meson
ninja
pkg-config
wayland-scanner
];
buildInputs = [
bashNonInteractive
cairo
fontconfig
freetype
glib
libGL
librsvg
libwebp
libxkbcommon
nlohmann_json
pango
stb'
tomlplusplus
wayland
wayland-protocols
wlroots_0_20
];
doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform;
versionCheckProgram = "${placeholder "out"}/bin/noctalia-greeter";
nativeInstallCheckInputs = [
versionCheckHook
];
passthru.updateScript = nix-update-script { };
meta = {
description = "`greetd` greeter for Noctalia";
homepage = "https://github.com/noctalia-dev/noctalia-greeter";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [
dtomvan
samiser
spacedentist
];
mainProgram = "noctalia-greeter-session";
platforms = lib.platforms.linux;
};
})

View File

@@ -0,0 +1,186 @@
{
lib,
stdenv,
fetchFromGitHub,
nix-update-script,
# build
meson,
ninja,
pkg-config,
wayland-scanner,
makeBinaryWrapper,
autoAddDriverRunpath,
installShellFiles,
versionCheckHook,
# libraries
cairo,
curl,
fontconfig,
freetype,
glib,
harfbuzz,
jemalloc,
libGL,
libical,
libjxl,
libqalculate,
librsvg,
libsecret,
libsndfile,
libsodium,
libwebp,
libxkbcommon,
libxml2,
md4c,
nlohmann_json,
pam,
pango,
pipewire,
polkit,
sdbus-cpp_2,
stb,
systemdLibs,
tomlplusplus,
tzdata,
wayland,
wayland-protocols,
wireplumber,
# runtime
gitMinimal,
}:
let
# nixpkgs stb doesn't have stb_image_resize2.h which noctalia needs
stb' = stb.overrideAttrs {
version = "0-unstable-2025-10-26";
src = fetchFromGitHub {
owner = "nothings";
repo = "stb";
rev = "f1c79c02822848a9bed4315b12c8c8f3761e1296";
hash = "sha256-BlyXJtAI7WqXCTT3ylww8zoG0hBxaojJnQDvdQOXJPE=";
};
};
# libqalculate 5.10.0 makes noctalia segfault, 5.12.0 works
libqalculate' = libqalculate.overrideAttrs {
version = "5.12.0";
src = fetchFromGitHub {
owner = "qalculate";
repo = "libqalculate";
tag = "v5.12.0";
hash = "sha256-f9FzFcu2LtBM6B6apYo7uobeR5uZVb02FxX7Kng/rRI=";
};
};
in
stdenv.mkDerivation (finalAttrs: {
__structuredAttrs = true;
pname = "noctalia";
version = "5.0.1";
src = fetchFromGitHub {
owner = "noctalia-dev";
repo = "noctalia";
tag = "v${finalAttrs.version}";
hash = "sha256-diS3b69rt/IqehH/8Tsd8/JEQmogVc1ml6FP+iTwBzg=";
};
strictDeps = true;
nativeBuildInputs = [
meson
ninja
pkg-config
wayland-scanner
makeBinaryWrapper
autoAddDriverRunpath
installShellFiles
];
buildInputs = [
cairo
curl
fontconfig
freetype
glib
harfbuzz
jemalloc
libGL
libical
libjxl
libqalculate'
librsvg
libsecret
libsndfile
libsodium
libwebp
libxkbcommon
libxml2
md4c
nlohmann_json
pam
pango
pipewire
polkit
sdbus-cpp_2
stb'
systemdLibs
tomlplusplus
wayland
wayland-protocols
wireplumber
];
mesonFlags = [
(lib.mesonEnable "tests" true)
(lib.mesonEnable "jemalloc" (!stdenv.hostPlatform.isMusl))
];
mesonBuildType = "release";
postInstall = lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) ''
installShellCompletion --cmd noctalia \
--bash <($out/bin/noctalia completions bash) \
--fish <($out/bin/noctalia completions fish) \
--zsh <($out/bin/noctalia completions zsh)
'';
# plugins are installed by cloning their repos
postFixup = ''
wrapProgram $out/bin/noctalia \
--prefix PATH : ${lib.makeBinPath [ gitMinimal ]}
'';
doCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform;
nativeCheckInputs = [
tzdata
gitMinimal
];
doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform;
nativeInstallCheckInputs = [
versionCheckHook
];
passthru.updateScript = nix-update-script { };
meta = {
description = "Sleek, customizable desktop shell crafted for Wayland";
homepage = "https://noctalia.dev";
changelog = "https://noctalia.dev/changelogs#v${finalAttrs.version}";
license = with lib.licenses; [
mit
asl20 # material_color_utilities is Apache 2.0
];
mainProgram = "noctalia";
maintainers = with lib.maintainers; [
samiser
pyrox0
];
platforms = lib.platforms.linux;
};
})

View File

@@ -49,8 +49,12 @@ stdenv.mkDerivation (finalAttrs: {
installPhase = ''
runHook preInstall
yarn workspaces focus --production
mkdir -p $out/bin $out/share/outline
mv build server public node_modules $out/share/outline/
find $out/share/outline/node_modules -name "*.map" -delete
find $out/share/outline/node_modules -name "*.d.ts" -delete
node_modules=$out/share/outline/node_modules
build=$out/share/outline/build

View File

@@ -0,0 +1,7 @@
{
perfetto,
...
}@args:
# Alias to perfetto.sdk to improve discoverability
(perfetto.override (removeAttrs args [ "perfetto" ])).sdk

View File

@@ -72,7 +72,7 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "perfetto";
version = "58.2";
version = "58.3";
__structuredAttrs = true;
strictDeps = true;
@@ -81,7 +81,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "google";
repo = "perfetto";
tag = "v${finalAttrs.version}";
hash = "sha256-Ipr86zH0iGjMzz9ZM3QEvtA6FlAN4lhkiDgySSeNj5c=";
hash = "sha256-73aE+qoHOkdD2Br3NmUE48BM6uE6uIBdug0+ZR2nn94=";
};
patches = [
@@ -239,6 +239,10 @@ stdenv.mkDerivation (finalAttrs: {
runHook postInstall
'';
passthru = {
inherit (finalAttrs.passthru) updateScript tests;
};
meta = {
inherit (finalAttrs.meta)
homepage

View File

@@ -69,13 +69,13 @@ in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "servo";
version = "0.4.0";
version = "0.5.0";
src = fetchFromGitHub {
owner = "servo";
repo = "servo";
tag = finalAttrs.version;
hash = "sha256-oA6fFvSajUHFxyu5kgT3BZ8oxWNMdkdaov6tVkxgNrE=";
tag = "v${finalAttrs.version}";
hash = "sha256-cJtmh/gzwno1gIqHPFgDsynGi//BvV9UyevuAbllRtg=";
# Breaks reproducibility depending on whether the picked commit
# has other ref-names or not, which may change over time, i.e. with
# "ref-names: HEAD -> main" as long this commit is the branch HEAD
@@ -85,7 +85,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
'';
};
cargoHash = "sha256-kFuW2RoE37ClYAEcEcRudQoUsRsjbUeEBbz/6d96FPU=";
cargoHash = "sha256-zZeHqxBvs5M0/TO/ifM1m5F0mSdT4cTJzoW2ja1+s28=";
# set `HOME` to a temp dir for write access
# Fix invalid option errors during linking (https://github.com/mozilla/nixpkgs-mozilla/commit/c72ff151a3e25f14182569679ed4cd22ef352328)

View File

@@ -14,13 +14,13 @@ let
in
buildNpmPackage (finalAttrs: {
pname = "sub-store-frontend";
version = "2.29.10";
version = "2.31.1";
src = fetchFromGitHub {
owner = "sub-store-org";
repo = "Sub-Store-Front-End";
tag = finalAttrs.version;
hash = "sha256-jQXIwdt9+yndTFBCrs6bZ7dCZ2fmjti0xQAgAGZbC1M=";
hash = "sha256-eqaS5bPHBx92C6gv2iE9MYtBpI0UsvM0ptG97lPt8HE=";
};
nativeBuildInputs = [

View File

@@ -18,14 +18,17 @@ buildGoModule (finalAttrs: {
pname = "typescript-go";
version = "7.0.2";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "microsoft";
repo = "typescript-go";
tag = "typescript/v${finalAttrs.version}";
hash = "sha256-fRejdQSwaxSS2pjHrbJO2CQgZS5lWJmBNEM/TgbJTJ8=";
fetchSubmodules = false;
repo = "typescript";
tag = "v${finalAttrs.version}";
hash = "sha256-j1AY4sf/Jb6uwOah35lrYooc7BnSeaZ2NO6Fx1zMj60=";
};
modRoot = "tsc";
vendorHash = "sha256-q6dMb2ab4uZ3GTrcA7v2JzfmOM+ZzBcJN6gKOpLfM/k=";
ldflags = [
@@ -53,7 +56,7 @@ buildGoModule (finalAttrs: {
(nix-update-script {
extraArgs = [
"--use-github-releases"
"--version-regex=^typescript/v([\\d.]+)$"
"--version-regex=^v([\\d.]+)$"
"--src-only"
];
})
@@ -67,7 +70,7 @@ buildGoModule (finalAttrs: {
];
text = ''
new_src="$(nix-build --attr 'pkgs.typescript-go.src' --no-out-link)"
new_go_major_minor="$(grep --only-matching --perl-regexp '^go \K([0-9]+\.[0-9]+)' "$new_src/go.mod")"
new_go_major_minor="$(grep --only-matching --perl-regexp '^go \K([0-9]+\.[0-9]+)' "$new_src/tsc/go.mod")"
sed -i -E "s/buildGo[0-9]+Module/buildGo''${new_go_major_minor//./}Module/g" '${toString ./package.nix}'
'';
}))
@@ -81,8 +84,8 @@ buildGoModule (finalAttrs: {
meta = {
description = "Go implementation of TypeScript";
homepage = "https://github.com/microsoft/typescript-go";
changelog = "https://github.com/microsoft/typescript-go/releases/tag/typescript/v${finalAttrs.version}";
homepage = "https://github.com/microsoft/typescript";
changelog = "https://github.com/microsoft/typescript/releases/tag/v${finalAttrs.version}";
license = lib.licenses.asl20;
maintainers = with lib.maintainers; [
kachick

View File

@@ -25,11 +25,11 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "go";
version = "1.27rc3";
version = "1.27.1";
src = fetchurl {
url = "https://go.dev/dl/go${finalAttrs.version}.src.tar.gz";
hash = "sha256-6eIO3RcgCV+RCWluljpmBp0/bUjQDrk4jIiM4GYx31w=";
hash = "sha256-TkCKuuEm2Ra2FkYnGT8sVPDjyhMS1pO4bbRfhiqyOLE=";
};
strictDeps = true;

View File

@@ -45,5 +45,6 @@ stdenv.mkDerivation rec {
philiptaron
];
platforms = with lib.platforms; linux;
broken = lib.versionOlder kernel.version cfg.minKernelVersion;
};
}

View File

@@ -1,14 +1,16 @@
{
version = "2026.2";
version = "2026.3";
minKernelVersion = "5.15";
# To get these, run:
#
# ```
# for tool in alfred batctl batman-adv; do nix-prefetch-url https://downloads.open-mesh.org/batman/releases/batman-adv-2026.2/$tool-2026.2.tar.gz --type sha256 | xargs nix --extra-experimental-features nix-command hash convert --hash-algo sha256 --to sri; done
# for tool in alfred batctl batman-adv; do nix-prefetch-url https://downloads.open-mesh.org/batman/releases/batman-adv-2026.3/$tool-2026.3.tar.gz --type sha256 | xargs nix --extra-experimental-features nix-command hash convert --hash-algo sha256 --to sri; done
# ```
sha256 = {
alfred = "sha256-2ZV0i+X2KkIJFSXMwQLfWsZCGG6bkBRpipVaRGm2m5Y=";
batctl = "sha256-wdWAr7Bm0xZcI5tnQwuUxpkyYZwGqQsSlegoy1CBsSI=";
batman-adv = "sha256-Thf87SyAlF4iYJvodTRIFzP/G10XBQ3k5PMjwXFBgTU=";
alfred = "sha256-H4FQVIGqSIjpcRazdPKVOqQsJdoQYphGciadxZG7BDE=";
batctl = "sha256-LIRD+uezRxpQCDf4z7vCt7urYC5DzoxhsQBWDewdnuA=";
batman-adv = "sha256-w1JOfY8Uh4agUmVKexCQ45R0bTpx7l1lf5ht168WF2I=";
};
}