diff --git a/.github/workflows/bot.yml b/.github/workflows/bot.yml index a9c97db21b6f..3e404d89c8c2 100644 --- a/.github/workflows/bot.yml +++ b/.github/workflows/bot.yml @@ -49,7 +49,7 @@ jobs: ci/github-script - name: Install dependencies - run: npm ci --package-lock-only=false @actions/artifact bottleneck + run: npm ci --package-lock-only=false --no-audit @actions/artifact bottleneck working-directory: ci/github-script # Use a GitHub App, because it has much higher rate limits: 12,500 instead of 5,000 req / hour. diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index d6cdd5564220..fd3404f07a3b 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -51,7 +51,7 @@ jobs: ci/github-script - name: Install dependencies - run: npm ci --package-lock-only=false bottleneck + run: npm ci --package-lock-only=false --no-audit bottleneck working-directory: trusted/ci/github-script - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 @@ -153,7 +153,7 @@ jobs: - name: Install dependencies to trusted/ run: | - npm ci --package-lock-only=false + npm ci --package-lock-only=false --no-audit echo "$PWD/node_modules/.bin" >> "$GITHUB_PATH" working-directory: nixpkgs/trusted/ci/github-script diff --git a/.github/workflows/teams.yml b/.github/workflows/teams.yml index 1e6ed3175cf4..5e8e20497b7f 100644 --- a/.github/workflows/teams.yml +++ b/.github/workflows/teams.yml @@ -38,7 +38,7 @@ jobs: maintainers/github-teams.json - name: Install dependencies - run: npm ci --package-lock-only=false bottleneck + run: npm ci --package-lock-only=false --no-audit bottleneck working-directory: ci/github-script - name: Synchronise teams diff --git a/ci/github-script/bot.js b/ci/github-script/bot.js index 755b1f71dfdc..c1fba12c00c4 100644 --- a/ci/github-script/bot.js +++ b/ci/github-script/bot.js @@ -689,16 +689,21 @@ export default async ({ github, context, core, dry }) => { if (context.payload.pull_request) { await handle({ item: context.payload.pull_request, stats }) } else { + // We don't use filters here because that causes GitHub to use an often-outdated index, + // resulting in the cursor not being updated, and therefore causing the same PRs + // to use up our rate limit over and over again. const lastRun = ( await github.rest.actions.listWorkflowRuns({ ...context.repo, workflow_id: 'bot.yml', - event: 'schedule', - status: 'success', - exclude_pull_requests: true, - per_page: 1, }) - ).data.workflow_runs[0] + ).data.workflow_runs.find( + (run) => run.event === 'schedule' && run.conclusion === 'success', + ) + + core.info( + `Last successful run created at: ${lastRun?.created_at ?? ''}`, + ) const cutoff = new Date( Math.max( @@ -794,6 +799,7 @@ export default async ({ github, context, core, dry }) => { } else { // No stats.artifacts++, because this does not allow passing a custom token. // Thus, the upload will not happen with the app token, but the default github.token. + core.info(`pagination-cursor: ${cursor}`) await artifactClient.uploadArtifact( 'pagination-cursor', [uploadPath], @@ -803,6 +809,8 @@ export default async ({ github, context, core, dry }) => { }, ) } + } else { + core.info('pagination-cursor: ') } // Some items might be in both search results, so filtering out duplicates as well. diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index b4b140190e7e..1be62bb31e4a 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -24460,6 +24460,12 @@ githubId = 47582; name = "Samir Talwar"; }; + samiser = { + email = "nixos@me.samiser.xyz"; + github = "samiser"; + githubId = 32001364; + name = "Sam"; + }; samlich = { email = "nixos@samli.ch"; github = "samlich"; diff --git a/nixos/modules/misc/documentation/modular-services.nix b/nixos/modules/misc/documentation/modular-services.nix index edc60d3bb592..65a2071813a5 100644 --- a/nixos/modules/misc/documentation/modular-services.nix +++ b/nixos/modules/misc/documentation/modular-services.nix @@ -20,6 +20,7 @@ let modularServicesModule = { options = { "" = fakeSubmodule pkgs.ghostunnel.services.default; + "" = fakeSubmodule pkgs.git-pages.services.default; "" = fakeSubmodule pkgs.ktls-utils.services.default; "" = fakeSubmodule pkgs.php.services.default; "" = fakeSubmodule pkgs.snid.services.default; diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 8ca70336a517..44942cc2379d 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -671,6 +671,7 @@ in geth = runTest ./geth.nix; ghostunnel = runTest ./ghostunnel.nix; ghostunnel-modular = runTest ./ghostunnel-modular.nix; + git-pages-modular = runTest ./git-pages.nix; gitdaemon = runTest ./gitdaemon.nix; gitea = handleTest ./gitea.nix { giteaPackage = pkgs.gitea; }; github-runner = runTest ./github-runner.nix; diff --git a/nixos/tests/git-pages.nix b/nixos/tests/git-pages.nix new file mode 100644 index 000000000000..c7e19b7cf846 --- /dev/null +++ b/nixos/tests/git-pages.nix @@ -0,0 +1,65 @@ +{ pkgs, ... }: +{ + name = "git-pages-modular-service"; + + nodes.machine = { pkgs, ... }: { + environment.systemPackages = [ pkgs.curl ]; + + system.services.git-pages = { + imports = [ pkgs.git-pages.services.default ]; + git-pages = { + settings.server = { + pages = "tcp/:3000"; + caddy = "tcp/:3001"; + metrics = "tcp/:3002"; + }; + }; + systemd.service.environment.PAGES_INSECURE = "1"; + }; + + services.caddy = { + enable = true; + configFile = pkgs.writeText "Caddyfile" '' + { + admin off + persist_config off + auto_https disable_redirects + on_demand_tls { + permission http http://localhost:3001 + } + } + https://, http:// { + tls { + on_demand + } + reverse_proxy http://localhost:3000 + } + ''; + }; + + networking.firewall.allowedTCPPorts = [ 80 ]; + }; + + testScript = + let + testSite = pkgs.runCommand "git-pages-testsite.tar" { } '' + echo It works! > index.html + tar cvf $out index.html + ''; + in + '' + start_all() + + machine.wait_for_unit("caddy.service") + machine.wait_for_open_port(80) + machine.wait_for_unit("git-pages.service") + machine.wait_for_open_port(3001) + machine.wait_for_open_port(3002) + machine.fail("curl -f http://localhost/.git-pages/health") + machine.succeed("curl -f http://localhost/ -X PUT --data-binary @${testSite} --header 'Content-Type: application/x-tar'") + machine.wait_until_succeeds("test -f /var/lib/git-pages/data/site/localhost/.index") + machine.succeed("curl -f http://localhost/.git-pages/health") + machine.succeed("curl -f http://localhost/ | grep -F 'It works!'") + machine.succeed("curl -f http://localhost:3002/metrics") + ''; +} diff --git a/pkgs/applications/editors/jupyter-kernels/xeus-cpp/xeus-cpp.nix b/pkgs/applications/editors/jupyter-kernels/xeus-cpp/xeus-cpp.nix index c0e415a4dcfd..ee414f201b0d 100644 --- a/pkgs/applications/editors/jupyter-kernels/xeus-cpp/xeus-cpp.nix +++ b/pkgs/applications/editors/jupyter-kernels/xeus-cpp/xeus-cpp.nix @@ -86,6 +86,7 @@ stdenv.mkDerivation (finalAttrs: { strictDeps = true; __structuredAttrs = true; + __darwinAllowLocalNetworking = true; nativeBuildInputs = [ cmake @@ -106,6 +107,16 @@ stdenv.mkDerivation (finalAttrs: { curl ]; + # xeus-cpp probes the host `c++` for its include search path and prepends the + # result, which shadows the hermetic paths we hand it (Xcode's libc++ and SDK + # win on any machine with Xcode). Skip the probe when those paths are supplied. + postPatch = '' + substituteInPlace src/xinterpreter.cpp --replace-fail \ + "Cpp::DetectSystemCompilerIncludePaths(CxxSystemIncludes);" \ + "if (const char* e = std::getenv(\"CPPINTEROP_EXTRA_INTERPRETER_ARGS\"); !e || !*e) + Cpp::DetectSystemCompilerIncludePaths(CxxSystemIncludes);" + ''; + cmakeFlags = [ (lib.cmakeBool "XEUS_CPP_BUILD_TESTS" finalAttrs.finalPackage.doCheck) "-DXEUS_CPP_RESOURCE_DIR=${resourceDir}" diff --git a/pkgs/applications/networking/browsers/chromium/info.json b/pkgs/applications/networking/browsers/chromium/info.json index 67aa9f0afe9a..b8fff62700cd 100644 --- a/pkgs/applications/networking/browsers/chromium/info.json +++ b/pkgs/applications/networking/browsers/chromium/info.json @@ -1,10 +1,10 @@ { "chromium": { - "version": "152.0.7977.75", + "version": "152.0.7977.82", "chromedriver": { - "version": "152.0.7977.76", - "hash_darwin": "sha256-tK7HmSRzWr/ruU484L+Og4wruS87fRHLEBKSZd4SSDA=", - "hash_darwin_aarch64": "sha256-+f0e6EGB0aXeyyYN8Db5u3+G9/RjILI/I0/2QWiVg1M=" + "version": "152.0.7977.83", + "hash_darwin": "sha256-cx8v6bu6MuSU+LHOGmxcOWNhH7tZFaegHfcMv+RSZGg=", + "hash_darwin_aarch64": "sha256-OM3ogo/Z76H8E8F9RhbcLwjSEgWNxdBJxngDI/nHhkI=" }, "deps": { "depot_tools": { @@ -21,8 +21,8 @@ "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "4999cc1efed37c4d91dc4ce6ec4b0a50e2a9a8cb", - "hash": "sha256-RXykREnCulCwk8zkk8OAd62TM4qel6j4uhyaaYzgolY=", + "rev": "d04cdb24d67b081f6cf80200ffc5233f44b61109", + "hash": "sha256-JiYTfMJBtUWMUSicQdSCXNUtgjLGeaMj4vCNpMvYACk=", "recompress": true }, "src/third_party/clang-format/script": { @@ -92,8 +92,8 @@ }, "src/third_party/angle": { "url": "https://chromium.googlesource.com/angle/angle.git", - "rev": "736ed80c7552a4b267bd54a282b971aa4555cb3e", - "hash": "sha256-3ZCIFT7j944HWPOiADQa88TQZctLej5vbrBFA/FwyHw=" + "rev": "7df613367a1d4ca9aea9ece344d4580d32d132a9", + "hash": "sha256-bYGok5QvWJoCfliRPQqrDz0ttKf1r9HoFxoC4qwdI3o=" }, "src/third_party/angle/third_party/glmark2/src": { "url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2", @@ -672,8 +672,8 @@ }, "src/third_party/skia": { "url": "https://skia.googlesource.com/skia.git", - "rev": "b6d106297ff9ef2ff8094033695d045e87775581", - "hash": "sha256-sun/P/JVhTKfRwmVK5dgnz8UZEFnQoyXZZS6PN5z9us=" + "rev": "0873ec164a06966b90ae0d43ef783cfb180084ae", + "hash": "sha256-LbSs+UNakFipC2t9TSbZVreylVXHf1PsbK6z2qJh6QI=" }, "src/third_party/smhasher/src": { "url": "https://chromium.googlesource.com/external/smhasher.git", @@ -842,8 +842,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "3de6ffffbfdcf265e9f11a5c9d1cfb4d486d7550", - "hash": "sha256-ZHEmeSe8r226gjazm91GYqlfbM9a5yi8KnFv4iAWFKE=" + "rev": "4323497a6a73839e6d5260f6acd7ec0212cb3321", + "hash": "sha256-HUg4GGtYL4xGk/xw0QXxNZAnsFVcznklWGQaqhZj9QM=" }, "src/agents/shared": { "url": "https://chromium.googlesource.com/chromium/agents.git", @@ -853,7 +853,7 @@ } }, "ungoogled-chromium": { - "version": "152.0.7977.75", + "version": "152.0.7977.82", "deps": { "depot_tools": { "rev": "38c391feba5fb96812f9028da12413ffc39df394", @@ -865,16 +865,16 @@ "hash": "sha256-ovLx6KaORdXqnWgbsGEty10k2CHuCmTk3yEqy5//ovk=" }, "ungoogled-patches": { - "rev": "152.0.7977.75-1", - "hash": "sha256-HXWnJfk0SxC8sRcgtFdGBOOeiV7kEQD2YXQFBwMsU1s=" + "rev": "152.0.7977.82-1", + "hash": "sha256-5KxsbzpRybc/ub6HJbN6QkJVL4iDdoAXE7vwjtjAJXA=" }, "npmHash": "sha256-pF0JtwFpPC4/fodbhSJnQKkczA9WlDg4VqEAy9aDVLg=" }, "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "4999cc1efed37c4d91dc4ce6ec4b0a50e2a9a8cb", - "hash": "sha256-RXykREnCulCwk8zkk8OAd62TM4qel6j4uhyaaYzgolY=", + "rev": "d04cdb24d67b081f6cf80200ffc5233f44b61109", + "hash": "sha256-JiYTfMJBtUWMUSicQdSCXNUtgjLGeaMj4vCNpMvYACk=", "recompress": true }, "src/third_party/clang-format/script": { @@ -944,8 +944,8 @@ }, "src/third_party/angle": { "url": "https://chromium.googlesource.com/angle/angle.git", - "rev": "736ed80c7552a4b267bd54a282b971aa4555cb3e", - "hash": "sha256-3ZCIFT7j944HWPOiADQa88TQZctLej5vbrBFA/FwyHw=" + "rev": "7df613367a1d4ca9aea9ece344d4580d32d132a9", + "hash": "sha256-bYGok5QvWJoCfliRPQqrDz0ttKf1r9HoFxoC4qwdI3o=" }, "src/third_party/angle/third_party/glmark2/src": { "url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2", @@ -1524,8 +1524,8 @@ }, "src/third_party/skia": { "url": "https://skia.googlesource.com/skia.git", - "rev": "b6d106297ff9ef2ff8094033695d045e87775581", - "hash": "sha256-sun/P/JVhTKfRwmVK5dgnz8UZEFnQoyXZZS6PN5z9us=" + "rev": "0873ec164a06966b90ae0d43ef783cfb180084ae", + "hash": "sha256-LbSs+UNakFipC2t9TSbZVreylVXHf1PsbK6z2qJh6QI=" }, "src/third_party/smhasher/src": { "url": "https://chromium.googlesource.com/external/smhasher.git", @@ -1694,8 +1694,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "3de6ffffbfdcf265e9f11a5c9d1cfb4d486d7550", - "hash": "sha256-ZHEmeSe8r226gjazm91GYqlfbM9a5yi8KnFv4iAWFKE=" + "rev": "4323497a6a73839e6d5260f6acd7ec0212cb3321", + "hash": "sha256-HUg4GGtYL4xGk/xw0QXxNZAnsFVcznklWGQaqhZj9QM=" }, "src/agents/shared": { "url": "https://chromium.googlesource.com/chromium/agents.git", diff --git a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix index c892025935ff..5232330e0484 100644 --- a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix +++ b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix @@ -111,8 +111,8 @@ rec { thunderbird-140 = common { applicationName = "Thunderbird ESR"; - version = "140.14.0esr"; - sha512 = "4c95b1ca3fc7f6429b2360a7e732635bdfb60927622a7da4d8af9ca2abd550611b91763c587cddad5d51c0dd4e905ba8e106da3cd21591a1bec3dba1b9a2502d"; + version = "140.15.0esr"; + sha512 = "52f014fb75ac131780aba924dd973a1fb5d6a60be4f800c258dca931e2c6ad75baaad37a5ad52228e91d3d174823b6b4d38ddc2dbbf9c04b8700cc33079448bb"; updateScript = callPackage ./update.nix { attrPath = "thunderbirdPackages.thunderbird-140"; diff --git a/pkgs/by-name/bo/bookstack/package.nix b/pkgs/by-name/bo/bookstack/package.nix index 2e568b3d9529..67f9702d5222 100644 --- a/pkgs/by-name/bo/bookstack/package.nix +++ b/pkgs/by-name/bo/bookstack/package.nix @@ -8,16 +8,16 @@ php83.buildComposerProject2 (finalAttrs: { pname = "bookstack"; - version = "26.05.3"; + version = "26.05.4"; src = fetchFromGitHub { owner = "bookstackapp"; repo = "bookstack"; tag = "v${finalAttrs.version}"; - hash = "sha256-IRJGgK1MEptQJlnvHVXINSnhr8TVp6S8fZRBi+4VGig="; + hash = "sha256-DDjJZehRUf1GP19S+RqhqZSSGOMF/SzItt2GFXi4+1U="; }; - vendorHash = "sha256-1x0czjCCD9Jf9TMhmkSpUt33q5+E1bw2l0SNP9VPRCE="; + vendorHash = "sha256-Ioth8Kp5fx4iwfy0p7N8xE0L41oWcp+ATfhmq3PUYyY="; passthru = { phpPackage = php83; diff --git a/pkgs/by-name/ch/chhoto-url/package.nix b/pkgs/by-name/ch/chhoto-url/package.nix index f8b829821716..34215ca96f3f 100644 --- a/pkgs/by-name/ch/chhoto-url/package.nix +++ b/pkgs/by-name/ch/chhoto-url/package.nix @@ -8,13 +8,13 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "chhoto-url"; - version = "7.5.0"; + version = "7.5.1"; src = fetchFromGitHub { owner = "SinTan1729"; repo = "chhoto-url"; tag = finalAttrs.version; - hash = "sha256-lyrTuZxsVui25JIfxDoezNcMTZDKgYOPJ9+VMOfhHjg="; + hash = "sha256-FAYbqNZVPUpfBKOn+cXvk5d8o29M9+d8t5ecihCQ4aY="; fetchLFS = true; }; @@ -27,7 +27,7 @@ rustPlatform.buildRustPackage (finalAttrs: { --replace-fail 'rust-version = "1.96"' 'rust-version = "1.95"' ''; - cargoHash = "sha256-y1MIiJ7NAP1F1c0IkrrVn1Wd2K+mrQD1RhqiumcPq1o="; + cargoHash = "sha256-C+eH6lrFSpE7zuR3fyyP44KG/rV0N2Uh4E7She0HuEA="; postInstall = '' mkdir -p $out/share/chhoto-url diff --git a/pkgs/by-name/cp/cpp-interop/package.nix b/pkgs/by-name/cp/cpp-interop/package.nix index 1360b19794f9..42d4989cc90e 100644 --- a/pkgs/by-name/cp/cpp-interop/package.nix +++ b/pkgs/by-name/cp/cpp-interop/package.nix @@ -1,15 +1,16 @@ { - lib, - fetchFromGitHub, - cmake, - ninja, - python3, - llvmPackages_21, + apple-sdk, cling, + cmake, + fetchFromGitHub, gcc-unwrapped, + lib, libffi, libxml2, + llvmPackages_21, ncurses, + ninja, + python3, zlib, zstd, @@ -46,20 +47,49 @@ let "${clingRoot}/lib/clang/20" else "${lib.getLib clang}/lib/clang/${lib.versions.major llvm.version}"; + + # These must precede the resource dir, because libc++ ships its own + # that include_next's Clang's and errors out if reached second. + cxxIncludeArgs = + if stdenv.hostPlatform.isDarwin then + [ + "-isystem" + "${lib.getDev llvmPackages.libcxx}/include/c++/v1" + ] + else + [ + "-isystem" + "${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}" + "-isystem" + "${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}/${stdenv.hostPlatform.config}" + ]; + + libcIncludeArgs = + if stdenv.hostPlatform.isDarwin then + [ + "-isystem" + "${apple-sdk.sdkroot}/usr/include" + "-iframework" + "${apple-sdk.sdkroot}/System/Library/Frameworks" + ] + else + [ + "-isystem" + "${lib.getDev stdenv.cc.libc}/include" + ]; + interpreterArgs = [ "-nostdinc" "-nostdinc++" "-resource-dir" resourceDir + ] + ++ cxxIncludeArgs + ++ [ "-isystem" "${resourceDir}/include" - "-isystem" - "${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}" - "-isystem" - "${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}/${stdenv.hostPlatform.config}" - "-isystem" - "${lib.getDev stdenv.cc.libc}/include" - ]; + ] + ++ libcIncludeArgs; in assert lib.assertOneOf "backend" backend [ diff --git a/pkgs/by-name/gh/ghostfolio/package.nix b/pkgs/by-name/gh/ghostfolio/package.nix index 87ef4c119c1b..975358dc5a60 100644 --- a/pkgs/by-name/gh/ghostfolio/package.nix +++ b/pkgs/by-name/gh/ghostfolio/package.nix @@ -12,13 +12,13 @@ buildNpmPackage (finalAttrs: { pname = "ghostfolio"; - version = "3.59.1"; + version = "3.65.0"; src = fetchFromGitHub { owner = "ghostfolio"; repo = "ghostfolio"; tag = finalAttrs.version; - hash = "sha256-Wf5uxU4lLB/Xw8SoZKFyyZulmpQCKKIIonDmyUlDyHs="; + hash = "sha256-a6gPbu9HsTTd5nIn2Ydj2CNv6Pg8NLpDhMr2B/pG8Go="; # populate values that require us to use git. By doing this in postFetch we # can delete .git afterwards and maintain better reproducibility of the src. leaveDotGit = true; @@ -28,7 +28,7 @@ buildNpmPackage (finalAttrs: { ''; }; - npmDepsHash = "sha256-pUE/zXM+q9RcV9pEMBMAhGUMB6Exn3ZWCbvFggzz0N8="; + npmDepsHash = "sha256-WpKjPSCXcP2L/yK8S3L6zxbobxX6blNbWh1dZBeKL58="; postPatch = '' substituteInPlace replace.build.mjs \ diff --git a/pkgs/by-name/gi/git-pages/package.nix b/pkgs/by-name/gi/git-pages/package.nix index 311f34df1061..d51fd4513585 100644 --- a/pkgs/by-name/gi/git-pages/package.nix +++ b/pkgs/by-name/gi/git-pages/package.nix @@ -2,8 +2,12 @@ lib, buildGoModule, fetchFromCodeberg, + fetchpatch, nix-update-script, versionCheckHook, + formats, + coreutils, + nixosTests, }: buildGoModule (finalAttrs: { @@ -18,6 +22,16 @@ buildGoModule (finalAttrs: { hash = "sha256-4yQ3RRJbOfMaqjJJ6CRRN7TuaYY8ScLXxMZPd4tWPwk="; }; + patches = [ + # bugfix to avoid creating parent directory on start + # remove when https://codeberg.org/git-pages/git-pages/pulls/258 is available in the release + (fetchpatch { + name = "mkdirall-parent-dir-create.patch"; + url = "https://codeberg.org/git-pages/git-pages/commit/507e57edbcfc0ec933a877bf26b1756ca0a61870.patch"; + hash = "sha256-1CjU4yGmDOmYsxo3U44Cg2xLJkrmUOX5ZXTycdLs6OE="; + }) + ]; + subPackages = [ "." ]; vendorHash = "sha256-NNIkzgRki2rtCVUnnhT44rEBcMZYiJPmsXySpxiHYR0="; @@ -31,7 +45,16 @@ buildGoModule (finalAttrs: { nativeInstallCheckInputs = [ versionCheckHook ]; versionCheckProgramArg = "-version"; - passthru.updateScript = nix-update-script { }; + passthru = { + tests = { inherit (nixosTests) git-pages-modular; }; + updateScript = nix-update-script { }; + services.default = { + imports = [ + (lib.modules.importApply ./service.nix { inherit formats coreutils; }) + ]; + git-pages.package = finalAttrs.finalPackage; + }; + }; meta = { description = "Scalable static site server for Git forges (like GitHub Pages or Netlify"; diff --git a/pkgs/by-name/gi/git-pages/service.nix b/pkgs/by-name/gi/git-pages/service.nix new file mode 100644 index 000000000000..61c8b645d0ad --- /dev/null +++ b/pkgs/by-name/gi/git-pages/service.nix @@ -0,0 +1,116 @@ +# Non-module dependencies (`importApply`) +{ formats, coreutils }: + +{ + config, + lib, + options, + name, + ... +}: +let + cfg = config.git-pages; + settingsFormat = formats.toml { }; + configFile = "git-pages.toml"; + configOutPath = config.configData.${configFile}.path; +in +{ + _class = "service"; + + meta.maintainers = with lib.maintainers; [ + dtomvan + phanirithvij + ]; + + options.git-pages = { + package = lib.mkOption { + description = "Package to use for git-pages"; + defaultText = "The git-pages package that provided this module."; + type = lib.types.package; + }; + + secretFile = lib.mkOption { + description = '' + File that contains secrets for the git-pages config. + If values in this file are set, any options specified take priority over the options set in + {option}`git-pages.settings`. + + ::: {.note} + See the [git-pages documentation](https://git-pages.org/running-a-server/#configuration) on + secrets and environment variables. + ::: + ''; + default = null; + type = lib.types.nullOr lib.types.str; + }; + settings = lib.mkOption { + type = settingsFormat.type; + description = '' + Settings to set in config.toml. + + ::: {.note} + See the [git-pages documentation](https://git-pages.org/running-a-server/#configuration) on configuring the server. + ::: + ''; + default = { }; + }; + }; + + config = { + git-pages.settings.storage.fs.root = lib.mkDefault "/var/lib/${name}/data"; + + process.argv = [ + (lib.getExe cfg.package) + "-config" + configOutPath + ]; + + configData."${configFile}".source = settingsFormat.generate configFile cfg.settings; + } + // lib.optionalAttrs (options ? systemd) { + systemd.service = { + description = "Forge-agnostic static site server"; + documentation = [ "https://git-pages.org/running-a-server/" ]; + + after = [ "network.target" ]; + wants = [ "network.target" ]; + wantedBy = [ "multi-user.target" ]; + restartTriggers = [ config.configData."${configFile}".source ]; + + serviceConfig = { + Restart = "always"; + + StateDirectory = name; + WorkingDirectory = "%S/${name}"; + BindReadOnlyPaths = [ configOutPath ]; + + LoadCredential = lib.optional (cfg.secretFile != null) "secrets.toml:${cfg.secretFile}"; + + User = name; + DynamicUser = true; + + # systemd service hardening + ProtectHome = true; + MemoryDenyWriteExecute = true; + PrivateDevices = true; + PrivateTmp = true; + ProtectSystem = "strict"; + ProtectControlGroups = true; + RestrictSUIDSGID = true; + RestrictRealtime = true; + RestrictAddressFamilies = "AF_INET AF_INET6 AF_UNIX"; + RestrictNamespaces = true; + LockPersonality = true; + ProtectKernelLogs = true; + ProtectKernelTunables = true; + ProtectHostname = true; + ProtectKernelModules = true; + PrivateUsers = true; + ProtectClock = true; + SystemCallArchitectures = "native"; + SystemCallErrorNumber = "EPERM"; + SystemCallFilter = "@system-service"; + }; + }; + }; +} diff --git a/pkgs/by-name/go/google-chrome/package.nix b/pkgs/by-name/go/google-chrome/package.nix index da6cefb03b13..8a4c6e69186f 100644 --- a/pkgs/by-name/go/google-chrome/package.nix +++ b/pkgs/by-name/go/google-chrome/package.nix @@ -180,7 +180,7 @@ let linux = stdenvNoCC.mkDerivation (finalAttrs: { inherit pname meta; - version = "152.0.7977.75"; + version = "152.0.7977.82"; src = let @@ -195,8 +195,8 @@ let url = "https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-stable/google-chrome-stable_${finalAttrs.version}-1_${debArch}.deb"; hash = { - amd64 = "sha256-oLemT3aP/A/1zMkmCtnrtT/Rb3oTHi42mU2li4LZE98="; - arm64 = "sha256-OFS2UlA3+NKXBIEqJoGEnE7N9peXdQ2jdCOBQD834dI="; + amd64 = "sha256-TSXkoCjHinrpEGg1UcLyNHksxVlefj40k59Zk0KtpEY="; + arm64 = "sha256-HcBFWH2AjCB6GenrNw9ukS3X5pZpU6+5PIHZnD/jGOM="; } .${debArch}; }; @@ -306,11 +306,11 @@ let darwin = stdenvNoCC.mkDerivation (finalAttrs: { inherit pname meta; - version = "152.0.7977.76"; + version = "152.0.7977.83"; src = fetchurl { - url = "http://dl.google.com/release2/chrome/fwccdneh3i55zgoy366y75r2ya_152.0.7977.76/GoogleChrome-152.0.7977.76.dmg"; - hash = "sha256-VuYzRvaOH0YB/I1m1Agk+l4y4al1b4o4dZZnhm7J2PQ="; + url = "http://dl.google.com/release2/chrome/g62gliie746ywu62ed7go3adam_152.0.7977.83/GoogleChrome-152.0.7977.83.dmg"; + hash = "sha256-Uc16WeBPhu/r7zB/UE9yt+cgkbpRYkRM3xtENFltqps="; }; dontPatch = true; diff --git a/pkgs/by-name/im/immich/package.nix b/pkgs/by-name/im/immich/package.nix index e94ad087378e..a00894cd16af 100644 --- a/pkgs/by-name/im/immich/package.nix +++ b/pkgs/by-name/im/immich/package.nix @@ -311,6 +311,11 @@ stdenv.mkDerivation (finalAttrs: { Scrumplex titaniumtown ]; + knownVulnerabilities = [ + "Immich 2.x.x will not receive further updates. Immich 3.x.x is available in NixOS 26.11 (unstable at the time of writing)" + "CVE-2026-59258" + "CVE-2026-82272" + ]; platforms = lib.platforms.linux ++ lib.platforms.freebsd; mainProgram = "server"; }; diff --git a/pkgs/by-name/ja/jackett/package.nix b/pkgs/by-name/ja/jackett/package.nix index 840ee662a851..1c9c6a2e72b8 100644 --- a/pkgs/by-name/ja/jackett/package.nix +++ b/pkgs/by-name/ja/jackett/package.nix @@ -12,13 +12,13 @@ buildDotnetModule (finalAttrs: { pname = "jackett"; - version = "0.24.2457"; + version = "0.24.2527"; src = fetchFromGitHub { owner = "jackett"; repo = "jackett"; tag = "v${finalAttrs.version}"; - hash = "sha256-oLKej0+Loiwn2yEAOHMeCqv1fU4d0vd7nzX/uTl3dFU="; + hash = "sha256-IbSXGddfsD9r0ElsSToQ+n75F09WUnF2jHirFOAiu+Q="; }; projectFile = "src/Jackett.Server/Jackett.Server.csproj"; diff --git a/pkgs/by-name/li/limine/package.nix b/pkgs/by-name/li/limine/package.nix index 1b5f6193612a..78458d785ef0 100644 --- a/pkgs/by-name/li/limine/package.nix +++ b/pkgs/by-name/li/limine/package.nix @@ -47,14 +47,14 @@ in # as bootloader for various platforms and corresponding binary and helper files. stdenv.mkDerivation (finalAttrs: { pname = "limine"; - version = "12.5.1"; + version = "12.5.2"; # We don't use the Git source but the release tarball, as the source has a # `./bootstrap` script performing network access to download resources. # Packaging that in Nix is very cumbersome. src = fetchurl { url = "https://github.com/Limine-Bootloader/Limine/releases/download/v${finalAttrs.version}/limine-${finalAttrs.version}.tar.gz"; - hash = "sha256-aGdx+IynrVBtI3Z5Zic/e5aVNWQeAFsxXr8xjIV1MTM="; + hash = "sha256-F4B4EzbWkMVR/FMFYEtMPj10mfbOvFBL+gzaO3EiE8E="; }; enableParallelBuilding = true; diff --git a/pkgs/by-name/ma/mago/package.nix b/pkgs/by-name/ma/mago/package.nix index 32fff71d26d2..c22e7c4a8a20 100644 --- a/pkgs/by-name/ma/mago/package.nix +++ b/pkgs/by-name/ma/mago/package.nix @@ -11,17 +11,17 @@ rustPackages_1_97.rustPlatform.buildRustPackage (finalAttrs: { pname = "mago"; - version = "1.47.3"; + version = "1.47.4"; src = fetchFromGitHub { owner = "carthage-software"; repo = "mago"; tag = finalAttrs.version; - hash = "sha256-XHEwkE732i2Is9hl7hzOrdn2AmlqYVccx4DT5F+EYAI="; + hash = "sha256-Qi1Bz5u/ZDupJz/9ueAwCnJ1hUWIpx1B32dGzcp87Fo="; forceFetchGit = true; # Does not download all files otherwise }; - cargoHash = "sha256-ibZ/YFKwwW1j7ZQonw0tizEFmFItuIDeKqgKOm3KZmc="; + cargoHash = "sha256-iw9ipn86SjXCdmC5W2naJvaSpYCYb6uNPkKVtA/ZMd4="; env = { # Get openssl-sys to use pkg-config diff --git a/pkgs/by-name/mi/microsoft-edge/package.nix b/pkgs/by-name/mi/microsoft-edge/package.nix index b1e10843206c..7a4e931a3e76 100644 --- a/pkgs/by-name/mi/microsoft-edge/package.nix +++ b/pkgs/by-name/mi/microsoft-edge/package.nix @@ -164,11 +164,11 @@ let in stdenvNoCC.mkDerivation (finalAttrs: { pname = "microsoft-edge"; - version = "152.0.4191.53"; + version = "152.0.4191.62"; src = fetchurl { url = "https://packages.microsoft.com/repos/edge/pool/main/m/microsoft-edge-stable/microsoft-edge-stable_${finalAttrs.version}-1_amd64.deb"; - hash = "sha256-szIkRfvmzh4Lz/hOu+Dt6jZeDq9Jix72E23aUt6m46c="; + hash = "sha256-SzUssNgbFRwQcZUZoUFe/ZJXChydV/BV5eXYD2yZug0="; }; # With strictDeps on, some shebangs were not being patched correctly diff --git a/pkgs/by-name/ms/msedgedriver/package.nix b/pkgs/by-name/ms/msedgedriver/package.nix index 36674db8a9c1..64634339c68a 100644 --- a/pkgs/by-name/ms/msedgedriver/package.nix +++ b/pkgs/by-name/ms/msedgedriver/package.nix @@ -12,11 +12,11 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "msedgedriver"; - version = "152.0.4191.53"; + version = "152.0.4191.62"; src = fetchzip { url = "https://msedgedriver.microsoft.com/${finalAttrs.version}/edgedriver_linux64.zip"; - hash = "sha256-3akRs0D76LAJ8Lgr3P7X+cDrMNXiEC+LWNH8lUdBM9k="; + hash = "sha256-dhUC+/XWACG/4In4xP0wOBjb6EIYlBnP9JT7j/xxBJk="; stripRoot = false; }; diff --git a/pkgs/by-name/no/noctalia-greeter/package.nix b/pkgs/by-name/no/noctalia-greeter/package.nix new file mode 100644 index 000000000000..f73d41f32551 --- /dev/null +++ b/pkgs/by-name/no/noctalia-greeter/package.nix @@ -0,0 +1,104 @@ +{ + lib, + stdenv, + fetchFromGitHub, + + meson, + ninja, + pkg-config, + wayland-scanner, + + bashNonInteractive, + cairo, + fontconfig, + freetype, + glib, + libGL, + librsvg, + libwebp, + libxkbcommon, + nlohmann_json, + pango, + stb, + tomlplusplus, + wayland, + wayland-protocols, + wlroots_0_20, + + versionCheckHook, + nix-update-script, +}: + +let + # nixpkgs stb doesn't have stb_image_resize2.h which noctalia-greeter needs + stb' = stb.overrideAttrs { + version = "0-unstable-2025-10-26"; + src = fetchFromGitHub { + owner = "nothings"; + repo = "stb"; + rev = "f1c79c02822848a9bed4315b12c8c8f3761e1296"; + hash = "sha256-BlyXJtAI7WqXCTT3ylww8zoG0hBxaojJnQDvdQOXJPE="; + }; + }; +in +stdenv.mkDerivation (finalAttrs: { + pname = "noctalia-greeter"; + version = "1.3.1"; + + __structuredAttrs = true; + strictDeps = true; + + src = fetchFromGitHub { + owner = "noctalia-dev"; + repo = "noctalia-greeter"; + tag = "v${finalAttrs.version}"; + hash = "sha256-1ZdtgBwndNHDltX8J7DLLl2/LBgywQhmt1JNcanfeMA="; + }; + + nativeBuildInputs = [ + meson + ninja + pkg-config + wayland-scanner + ]; + + buildInputs = [ + bashNonInteractive + cairo + fontconfig + freetype + glib + libGL + librsvg + libwebp + libxkbcommon + nlohmann_json + pango + stb' + tomlplusplus + wayland + wayland-protocols + wlroots_0_20 + ]; + + doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + versionCheckProgram = "${placeholder "out"}/bin/noctalia-greeter"; + nativeInstallCheckInputs = [ + versionCheckHook + ]; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "`greetd` greeter for Noctalia"; + homepage = "https://github.com/noctalia-dev/noctalia-greeter"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ + dtomvan + samiser + spacedentist + ]; + mainProgram = "noctalia-greeter-session"; + platforms = lib.platforms.linux; + }; +}) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix new file mode 100644 index 000000000000..4975e0787460 --- /dev/null +++ b/pkgs/by-name/no/noctalia/package.nix @@ -0,0 +1,186 @@ +{ + lib, + stdenv, + fetchFromGitHub, + nix-update-script, + + # build + meson, + ninja, + pkg-config, + wayland-scanner, + makeBinaryWrapper, + autoAddDriverRunpath, + installShellFiles, + versionCheckHook, + + # libraries + cairo, + curl, + fontconfig, + freetype, + glib, + harfbuzz, + jemalloc, + libGL, + libical, + libjxl, + libqalculate, + librsvg, + libsecret, + libsndfile, + libsodium, + libwebp, + libxkbcommon, + libxml2, + md4c, + nlohmann_json, + pam, + pango, + pipewire, + polkit, + sdbus-cpp_2, + stb, + systemdLibs, + tomlplusplus, + tzdata, + wayland, + wayland-protocols, + wireplumber, + + # runtime + gitMinimal, +}: + +let + # nixpkgs stb doesn't have stb_image_resize2.h which noctalia needs + stb' = stb.overrideAttrs { + version = "0-unstable-2025-10-26"; + src = fetchFromGitHub { + owner = "nothings"; + repo = "stb"; + rev = "f1c79c02822848a9bed4315b12c8c8f3761e1296"; + hash = "sha256-BlyXJtAI7WqXCTT3ylww8zoG0hBxaojJnQDvdQOXJPE="; + }; + }; + # libqalculate 5.10.0 makes noctalia segfault, 5.12.0 works + libqalculate' = libqalculate.overrideAttrs { + version = "5.12.0"; + src = fetchFromGitHub { + owner = "qalculate"; + repo = "libqalculate"; + tag = "v5.12.0"; + hash = "sha256-f9FzFcu2LtBM6B6apYo7uobeR5uZVb02FxX7Kng/rRI="; + }; + }; +in +stdenv.mkDerivation (finalAttrs: { + __structuredAttrs = true; + + pname = "noctalia"; + version = "5.0.1"; + + src = fetchFromGitHub { + owner = "noctalia-dev"; + repo = "noctalia"; + tag = "v${finalAttrs.version}"; + hash = "sha256-diS3b69rt/IqehH/8Tsd8/JEQmogVc1ml6FP+iTwBzg="; + }; + + strictDeps = true; + + nativeBuildInputs = [ + meson + ninja + pkg-config + wayland-scanner + makeBinaryWrapper + autoAddDriverRunpath + installShellFiles + ]; + + buildInputs = [ + cairo + curl + fontconfig + freetype + glib + harfbuzz + jemalloc + libGL + libical + libjxl + libqalculate' + librsvg + libsecret + libsndfile + libsodium + libwebp + libxkbcommon + libxml2 + md4c + nlohmann_json + pam + pango + pipewire + polkit + sdbus-cpp_2 + stb' + systemdLibs + tomlplusplus + wayland + wayland-protocols + wireplumber + ]; + + mesonFlags = [ + (lib.mesonEnable "tests" true) + (lib.mesonEnable "jemalloc" (!stdenv.hostPlatform.isMusl)) + ]; + + mesonBuildType = "release"; + + postInstall = lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) '' + installShellCompletion --cmd noctalia \ + --bash <($out/bin/noctalia completions bash) \ + --fish <($out/bin/noctalia completions fish) \ + --zsh <($out/bin/noctalia completions zsh) + ''; + + # plugins are installed by cloning their repos + postFixup = '' + wrapProgram $out/bin/noctalia \ + --prefix PATH : ${lib.makeBinPath [ gitMinimal ]} + ''; + + doCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + + nativeCheckInputs = [ + tzdata + gitMinimal + ]; + + doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + + nativeInstallCheckInputs = [ + versionCheckHook + ]; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "Sleek, customizable desktop shell crafted for Wayland"; + homepage = "https://noctalia.dev"; + changelog = "https://noctalia.dev/changelogs#v${finalAttrs.version}"; + license = with lib.licenses; [ + mit + asl20 # material_color_utilities is Apache 2.0 + ]; + mainProgram = "noctalia"; + maintainers = with lib.maintainers; [ + samiser + pyrox0 + ]; + platforms = lib.platforms.linux; + }; +}) diff --git a/pkgs/by-name/ou/outline/package.nix b/pkgs/by-name/ou/outline/package.nix index be0800e50df1..add6d2fc50a2 100644 --- a/pkgs/by-name/ou/outline/package.nix +++ b/pkgs/by-name/ou/outline/package.nix @@ -49,8 +49,12 @@ stdenv.mkDerivation (finalAttrs: { installPhase = '' runHook preInstall + yarn workspaces focus --production + mkdir -p $out/bin $out/share/outline mv build server public node_modules $out/share/outline/ + find $out/share/outline/node_modules -name "*.map" -delete + find $out/share/outline/node_modules -name "*.d.ts" -delete node_modules=$out/share/outline/node_modules build=$out/share/outline/build diff --git a/pkgs/by-name/pe/perfetto-sdk/package.nix b/pkgs/by-name/pe/perfetto-sdk/package.nix new file mode 100644 index 000000000000..30ffc38d2a3b --- /dev/null +++ b/pkgs/by-name/pe/perfetto-sdk/package.nix @@ -0,0 +1,7 @@ +{ + perfetto, + ... +}@args: + +# Alias to perfetto.sdk to improve discoverability +(perfetto.override (removeAttrs args [ "perfetto" ])).sdk diff --git a/pkgs/by-name/pe/perfetto/package.nix b/pkgs/by-name/pe/perfetto/package.nix index 87258b56da60..dbc6e506f0d7 100644 --- a/pkgs/by-name/pe/perfetto/package.nix +++ b/pkgs/by-name/pe/perfetto/package.nix @@ -72,7 +72,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "perfetto"; - version = "58.2"; + version = "58.3"; __structuredAttrs = true; strictDeps = true; @@ -81,7 +81,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "google"; repo = "perfetto"; tag = "v${finalAttrs.version}"; - hash = "sha256-Ipr86zH0iGjMzz9ZM3QEvtA6FlAN4lhkiDgySSeNj5c="; + hash = "sha256-73aE+qoHOkdD2Br3NmUE48BM6uE6uIBdug0+ZR2nn94="; }; patches = [ @@ -239,6 +239,10 @@ stdenv.mkDerivation (finalAttrs: { runHook postInstall ''; + passthru = { + inherit (finalAttrs.passthru) updateScript tests; + }; + meta = { inherit (finalAttrs.meta) homepage diff --git a/pkgs/by-name/se/servo/package.nix b/pkgs/by-name/se/servo/package.nix index 96dd5c8acb64..67cd8eae20af 100644 --- a/pkgs/by-name/se/servo/package.nix +++ b/pkgs/by-name/se/servo/package.nix @@ -69,13 +69,13 @@ in rustPlatform.buildRustPackage (finalAttrs: { pname = "servo"; - version = "0.4.0"; + version = "0.5.0"; src = fetchFromGitHub { owner = "servo"; repo = "servo"; - tag = finalAttrs.version; - hash = "sha256-oA6fFvSajUHFxyu5kgT3BZ8oxWNMdkdaov6tVkxgNrE="; + tag = "v${finalAttrs.version}"; + hash = "sha256-cJtmh/gzwno1gIqHPFgDsynGi//BvV9UyevuAbllRtg="; # Breaks reproducibility depending on whether the picked commit # has other ref-names or not, which may change over time, i.e. with # "ref-names: HEAD -> main" as long this commit is the branch HEAD @@ -85,7 +85,7 @@ rustPlatform.buildRustPackage (finalAttrs: { ''; }; - cargoHash = "sha256-kFuW2RoE37ClYAEcEcRudQoUsRsjbUeEBbz/6d96FPU="; + cargoHash = "sha256-zZeHqxBvs5M0/TO/ifM1m5F0mSdT4cTJzoW2ja1+s28="; # set `HOME` to a temp dir for write access # Fix invalid option errors during linking (https://github.com/mozilla/nixpkgs-mozilla/commit/c72ff151a3e25f14182569679ed4cd22ef352328) diff --git a/pkgs/by-name/su/sub-store-frontend/package.nix b/pkgs/by-name/su/sub-store-frontend/package.nix index 33bfd78c7561..7e3c2c8549f8 100644 --- a/pkgs/by-name/su/sub-store-frontend/package.nix +++ b/pkgs/by-name/su/sub-store-frontend/package.nix @@ -14,13 +14,13 @@ let in buildNpmPackage (finalAttrs: { pname = "sub-store-frontend"; - version = "2.29.10"; + version = "2.31.1"; src = fetchFromGitHub { owner = "sub-store-org"; repo = "Sub-Store-Front-End"; tag = finalAttrs.version; - hash = "sha256-jQXIwdt9+yndTFBCrs6bZ7dCZ2fmjti0xQAgAGZbC1M="; + hash = "sha256-eqaS5bPHBx92C6gv2iE9MYtBpI0UsvM0ptG97lPt8HE="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/ty/typescript-go/package.nix b/pkgs/by-name/ty/typescript-go/package.nix index dedb43a35802..5cb3d1e9aa25 100644 --- a/pkgs/by-name/ty/typescript-go/package.nix +++ b/pkgs/by-name/ty/typescript-go/package.nix @@ -18,14 +18,17 @@ buildGoModule (finalAttrs: { pname = "typescript-go"; version = "7.0.2"; + __structuredAttrs = true; + src = fetchFromGitHub { owner = "microsoft"; - repo = "typescript-go"; - tag = "typescript/v${finalAttrs.version}"; - hash = "sha256-fRejdQSwaxSS2pjHrbJO2CQgZS5lWJmBNEM/TgbJTJ8="; - fetchSubmodules = false; + repo = "typescript"; + tag = "v${finalAttrs.version}"; + hash = "sha256-j1AY4sf/Jb6uwOah35lrYooc7BnSeaZ2NO6Fx1zMj60="; }; + modRoot = "tsc"; + vendorHash = "sha256-q6dMb2ab4uZ3GTrcA7v2JzfmOM+ZzBcJN6gKOpLfM/k="; ldflags = [ @@ -53,7 +56,7 @@ buildGoModule (finalAttrs: { (nix-update-script { extraArgs = [ "--use-github-releases" - "--version-regex=^typescript/v([\\d.]+)$" + "--version-regex=^v([\\d.]+)$" "--src-only" ]; }) @@ -67,7 +70,7 @@ buildGoModule (finalAttrs: { ]; text = '' new_src="$(nix-build --attr 'pkgs.typescript-go.src' --no-out-link)" - new_go_major_minor="$(grep --only-matching --perl-regexp '^go \K([0-9]+\.[0-9]+)' "$new_src/go.mod")" + new_go_major_minor="$(grep --only-matching --perl-regexp '^go \K([0-9]+\.[0-9]+)' "$new_src/tsc/go.mod")" sed -i -E "s/buildGo[0-9]+Module/buildGo''${new_go_major_minor//./}Module/g" '${toString ./package.nix}' ''; })) @@ -81,8 +84,8 @@ buildGoModule (finalAttrs: { meta = { description = "Go implementation of TypeScript"; - homepage = "https://github.com/microsoft/typescript-go"; - changelog = "https://github.com/microsoft/typescript-go/releases/tag/typescript/v${finalAttrs.version}"; + homepage = "https://github.com/microsoft/typescript"; + changelog = "https://github.com/microsoft/typescript/releases/tag/v${finalAttrs.version}"; license = lib.licenses.asl20; maintainers = with lib.maintainers; [ kachick diff --git a/pkgs/development/compilers/go/1.27.nix b/pkgs/development/compilers/go/1.27.nix index b6a0efa1040e..5699d79277c8 100644 --- a/pkgs/development/compilers/go/1.27.nix +++ b/pkgs/development/compilers/go/1.27.nix @@ -25,11 +25,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "go"; - version = "1.27rc3"; + version = "1.27.1"; src = fetchurl { url = "https://go.dev/dl/go${finalAttrs.version}.src.tar.gz"; - hash = "sha256-6eIO3RcgCV+RCWluljpmBp0/bUjQDrk4jIiM4GYx31w="; + hash = "sha256-TkCKuuEm2Ra2FkYnGT8sVPDjyhMS1pO4bbRfhiqyOLE="; }; strictDeps = true; diff --git a/pkgs/os-specific/linux/batman-adv/default.nix b/pkgs/os-specific/linux/batman-adv/default.nix index 89c7a4dc30f6..97bd265fb667 100644 --- a/pkgs/os-specific/linux/batman-adv/default.nix +++ b/pkgs/os-specific/linux/batman-adv/default.nix @@ -45,5 +45,6 @@ stdenv.mkDerivation rec { philiptaron ]; platforms = with lib.platforms; linux; + broken = lib.versionOlder kernel.version cfg.minKernelVersion; }; } diff --git a/pkgs/os-specific/linux/batman-adv/version.nix b/pkgs/os-specific/linux/batman-adv/version.nix index 8f05cf345198..e37fc221b31c 100644 --- a/pkgs/os-specific/linux/batman-adv/version.nix +++ b/pkgs/os-specific/linux/batman-adv/version.nix @@ -1,14 +1,16 @@ { - version = "2026.2"; + version = "2026.3"; + + minKernelVersion = "5.15"; # To get these, run: # # ``` - # for tool in alfred batctl batman-adv; do nix-prefetch-url https://downloads.open-mesh.org/batman/releases/batman-adv-2026.2/$tool-2026.2.tar.gz --type sha256 | xargs nix --extra-experimental-features nix-command hash convert --hash-algo sha256 --to sri; done + # for tool in alfred batctl batman-adv; do nix-prefetch-url https://downloads.open-mesh.org/batman/releases/batman-adv-2026.3/$tool-2026.3.tar.gz --type sha256 | xargs nix --extra-experimental-features nix-command hash convert --hash-algo sha256 --to sri; done # ``` sha256 = { - alfred = "sha256-2ZV0i+X2KkIJFSXMwQLfWsZCGG6bkBRpipVaRGm2m5Y="; - batctl = "sha256-wdWAr7Bm0xZcI5tnQwuUxpkyYZwGqQsSlegoy1CBsSI="; - batman-adv = "sha256-Thf87SyAlF4iYJvodTRIFzP/G10XBQ3k5PMjwXFBgTU="; + alfred = "sha256-H4FQVIGqSIjpcRazdPKVOqQsJdoQYphGciadxZG7BDE="; + batctl = "sha256-LIRD+uezRxpQCDf4z7vCt7urYC5DzoxhsQBWDewdnuA="; + batman-adv = "sha256-w1JOfY8Uh4agUmVKexCQ45R0bTpx7l1lf5ht168WF2I="; }; }