From 58b907ad9732fa024fdd7cc89845748343561f0a Mon Sep 17 00:00:00 2001 From: Sizhe Zhao Date: Sun, 26 Jul 2026 22:02:21 +0800 Subject: [PATCH 01/50] limine: 12.5.1 -> 12.5.2 (cherry picked from commit 0dcfd77351fa88819e1be679171360c657f1530d) --- pkgs/by-name/li/limine/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/limine/package.nix b/pkgs/by-name/li/limine/package.nix index 1b5f6193612a..78458d785ef0 100644 --- a/pkgs/by-name/li/limine/package.nix +++ b/pkgs/by-name/li/limine/package.nix @@ -47,14 +47,14 @@ in # as bootloader for various platforms and corresponding binary and helper files. stdenv.mkDerivation (finalAttrs: { pname = "limine"; - version = "12.5.1"; + version = "12.5.2"; # We don't use the Git source but the release tarball, as the source has a # `./bootstrap` script performing network access to download resources. # Packaging that in Nix is very cumbersome. src = fetchurl { url = "https://github.com/Limine-Bootloader/Limine/releases/download/v${finalAttrs.version}/limine-${finalAttrs.version}.tar.gz"; - hash = "sha256-aGdx+IynrVBtI3Z5Zic/e5aVNWQeAFsxXr8xjIV1MTM="; + hash = "sha256-F4B4EzbWkMVR/FMFYEtMPj10mfbOvFBL+gzaO3EiE8E="; }; enableParallelBuilding = true; From 75795d2646644e3367314018fe1d3d3a56b6aa55 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Mon, 31 Aug 2026 18:23:02 +0200 Subject: [PATCH 02/50] servo: 0.4.0 -> 0.5.0 https://github.com/servo/servo/releases/tag/v0.5.0 (cherry picked from commit 5aae7d1c4987ce02f4442adad0f855ce36f9114e) --- pkgs/by-name/se/servo/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/se/servo/package.nix b/pkgs/by-name/se/servo/package.nix index 96dd5c8acb64..67cd8eae20af 100644 --- a/pkgs/by-name/se/servo/package.nix +++ b/pkgs/by-name/se/servo/package.nix @@ -69,13 +69,13 @@ in rustPlatform.buildRustPackage (finalAttrs: { pname = "servo"; - version = "0.4.0"; + version = "0.5.0"; src = fetchFromGitHub { owner = "servo"; repo = "servo"; - tag = finalAttrs.version; - hash = "sha256-oA6fFvSajUHFxyu5kgT3BZ8oxWNMdkdaov6tVkxgNrE="; + tag = "v${finalAttrs.version}"; + hash = "sha256-cJtmh/gzwno1gIqHPFgDsynGi//BvV9UyevuAbllRtg="; # Breaks reproducibility depending on whether the picked commit # has other ref-names or not, which may change over time, i.e. with # "ref-names: HEAD -> main" as long this commit is the branch HEAD @@ -85,7 +85,7 @@ rustPlatform.buildRustPackage (finalAttrs: { ''; }; - cargoHash = "sha256-kFuW2RoE37ClYAEcEcRudQoUsRsjbUeEBbz/6d96FPU="; + cargoHash = "sha256-zZeHqxBvs5M0/TO/ifM1m5F0mSdT4cTJzoW2ja1+s28="; # set `HOME` to a temp dir for write access # Fix invalid option errors during linking (https://github.com/mozilla/nixpkgs-mozilla/commit/c72ff151a3e25f14182569679ed4cd22ef352328) From 8c5cf58d272c202d736f7afbfef1f7d1983fc25a Mon Sep 17 00:00:00 2001 From: Tom Herbers Date: Tue, 1 Sep 2026 07:59:20 +0200 Subject: [PATCH 03/50] batman-adv: 2026.2 -> 2026.3 Changelog: https://www.open-mesh.org/news/129 (cherry picked from commit bc047e7d53e90f9de7a67e5137d23ded602c66dc) --- pkgs/os-specific/linux/batman-adv/default.nix | 1 + pkgs/os-specific/linux/batman-adv/version.nix | 12 +++++++----- 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/batman-adv/default.nix b/pkgs/os-specific/linux/batman-adv/default.nix index 89c7a4dc30f6..97bd265fb667 100644 --- a/pkgs/os-specific/linux/batman-adv/default.nix +++ b/pkgs/os-specific/linux/batman-adv/default.nix @@ -45,5 +45,6 @@ stdenv.mkDerivation rec { philiptaron ]; platforms = with lib.platforms; linux; + broken = lib.versionOlder kernel.version cfg.minKernelVersion; }; } diff --git a/pkgs/os-specific/linux/batman-adv/version.nix b/pkgs/os-specific/linux/batman-adv/version.nix index 8f05cf345198..e37fc221b31c 100644 --- a/pkgs/os-specific/linux/batman-adv/version.nix +++ b/pkgs/os-specific/linux/batman-adv/version.nix @@ -1,14 +1,16 @@ { - version = "2026.2"; + version = "2026.3"; + + minKernelVersion = "5.15"; # To get these, run: # # ``` - # for tool in alfred batctl batman-adv; do nix-prefetch-url https://downloads.open-mesh.org/batman/releases/batman-adv-2026.2/$tool-2026.2.tar.gz --type sha256 | xargs nix --extra-experimental-features nix-command hash convert --hash-algo sha256 --to sri; done + # for tool in alfred batctl batman-adv; do nix-prefetch-url https://downloads.open-mesh.org/batman/releases/batman-adv-2026.3/$tool-2026.3.tar.gz --type sha256 | xargs nix --extra-experimental-features nix-command hash convert --hash-algo sha256 --to sri; done # ``` sha256 = { - alfred = "sha256-2ZV0i+X2KkIJFSXMwQLfWsZCGG6bkBRpipVaRGm2m5Y="; - batctl = "sha256-wdWAr7Bm0xZcI5tnQwuUxpkyYZwGqQsSlegoy1CBsSI="; - batman-adv = "sha256-Thf87SyAlF4iYJvodTRIFzP/G10XBQ3k5PMjwXFBgTU="; + alfred = "sha256-H4FQVIGqSIjpcRazdPKVOqQsJdoQYphGciadxZG7BDE="; + batctl = "sha256-LIRD+uezRxpQCDf4z7vCt7urYC5DzoxhsQBWDewdnuA="; + batman-adv = "sha256-w1JOfY8Uh4agUmVKexCQ45R0bTpx7l1lf5ht168WF2I="; }; } From e0b4f1c50c47509999e09ab617fb56785d6218a9 Mon Sep 17 00:00:00 2001 From: Sefa Eyeoglu Date: Wed, 2 Sep 2026 23:00:18 +0200 Subject: [PATCH 04/50] immich: add knownVulnerabilities Signed-off-by: Sefa Eyeoglu --- pkgs/by-name/im/immich/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/im/immich/package.nix b/pkgs/by-name/im/immich/package.nix index e94ad087378e..a00894cd16af 100644 --- a/pkgs/by-name/im/immich/package.nix +++ b/pkgs/by-name/im/immich/package.nix @@ -311,6 +311,11 @@ stdenv.mkDerivation (finalAttrs: { Scrumplex titaniumtown ]; + knownVulnerabilities = [ + "Immich 2.x.x will not receive further updates. Immich 3.x.x is available in NixOS 26.11 (unstable at the time of writing)" + "CVE-2026-59258" + "CVE-2026-82272" + ]; platforms = lib.platforms.linux ++ lib.platforms.freebsd; mainProgram = "server"; }; From 5d1d9ee364332ea722830069d076dbbe52403bd4 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 28 Aug 2026 08:55:07 +0000 Subject: [PATCH 05/50] mago: 1.47.3 -> 1.47.4 (cherry picked from commit 7c487f6284045eab8c1e30a0c233699d5325e680) --- pkgs/by-name/ma/mago/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ma/mago/package.nix b/pkgs/by-name/ma/mago/package.nix index 32fff71d26d2..c22e7c4a8a20 100644 --- a/pkgs/by-name/ma/mago/package.nix +++ b/pkgs/by-name/ma/mago/package.nix @@ -11,17 +11,17 @@ rustPackages_1_97.rustPlatform.buildRustPackage (finalAttrs: { pname = "mago"; - version = "1.47.3"; + version = "1.47.4"; src = fetchFromGitHub { owner = "carthage-software"; repo = "mago"; tag = finalAttrs.version; - hash = "sha256-XHEwkE732i2Is9hl7hzOrdn2AmlqYVccx4DT5F+EYAI="; + hash = "sha256-Qi1Bz5u/ZDupJz/9ueAwCnJ1hUWIpx1B32dGzcp87Fo="; forceFetchGit = true; # Does not download all files otherwise }; - cargoHash = "sha256-ibZ/YFKwwW1j7ZQonw0tizEFmFItuIDeKqgKOm3KZmc="; + cargoHash = "sha256-iw9ipn86SjXCdmC5W2naJvaSpYCYb6uNPkKVtA/ZMd4="; env = { # Get openssl-sys to use pkg-config From 3824839c5442b92ea54d39f22a2dcd5b46ca48be Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 3 Sep 2026 09:38:25 +0000 Subject: [PATCH 06/50] ghostfolio: 3.59.1 -> 3.65.0 (cherry picked from commit 7d091dc2b580d0f0bca93eb122090c8a75f486a9) --- pkgs/by-name/gh/ghostfolio/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/gh/ghostfolio/package.nix b/pkgs/by-name/gh/ghostfolio/package.nix index 87ef4c119c1b..975358dc5a60 100644 --- a/pkgs/by-name/gh/ghostfolio/package.nix +++ b/pkgs/by-name/gh/ghostfolio/package.nix @@ -12,13 +12,13 @@ buildNpmPackage (finalAttrs: { pname = "ghostfolio"; - version = "3.59.1"; + version = "3.65.0"; src = fetchFromGitHub { owner = "ghostfolio"; repo = "ghostfolio"; tag = finalAttrs.version; - hash = "sha256-Wf5uxU4lLB/Xw8SoZKFyyZulmpQCKKIIonDmyUlDyHs="; + hash = "sha256-a6gPbu9HsTTd5nIn2Ydj2CNv6Pg8NLpDhMr2B/pG8Go="; # populate values that require us to use git. By doing this in postFetch we # can delete .git afterwards and maintain better reproducibility of the src. leaveDotGit = true; @@ -28,7 +28,7 @@ buildNpmPackage (finalAttrs: { ''; }; - npmDepsHash = "sha256-pUE/zXM+q9RcV9pEMBMAhGUMB6Exn3ZWCbvFggzz0N8="; + npmDepsHash = "sha256-WpKjPSCXcP2L/yK8S3L6zxbobxX6blNbWh1dZBeKL58="; postPatch = '' substituteInPlace replace.build.mjs \ From bbe82e89ed8a7d61656980cd72378f2760804375 Mon Sep 17 00:00:00 2001 From: Tom McLaughlin Date: Wed, 2 Sep 2026 15:50:47 -0700 Subject: [PATCH 07/50] {cpp-interop,xeus-cpp}: fix on darwin Co-authored-by: Michael Daniels (cherry picked from commit 2b08e129acb0478b9c648c7ae7a096c61a4e57da) --- .../jupyter-kernels/xeus-cpp/xeus-cpp.nix | 11 ++++ pkgs/by-name/cp/cpp-interop/package.nix | 56 ++++++++++++++----- 2 files changed, 54 insertions(+), 13 deletions(-) diff --git a/pkgs/applications/editors/jupyter-kernels/xeus-cpp/xeus-cpp.nix b/pkgs/applications/editors/jupyter-kernels/xeus-cpp/xeus-cpp.nix index c0e415a4dcfd..ee414f201b0d 100644 --- a/pkgs/applications/editors/jupyter-kernels/xeus-cpp/xeus-cpp.nix +++ b/pkgs/applications/editors/jupyter-kernels/xeus-cpp/xeus-cpp.nix @@ -86,6 +86,7 @@ stdenv.mkDerivation (finalAttrs: { strictDeps = true; __structuredAttrs = true; + __darwinAllowLocalNetworking = true; nativeBuildInputs = [ cmake @@ -106,6 +107,16 @@ stdenv.mkDerivation (finalAttrs: { curl ]; + # xeus-cpp probes the host `c++` for its include search path and prepends the + # result, which shadows the hermetic paths we hand it (Xcode's libc++ and SDK + # win on any machine with Xcode). Skip the probe when those paths are supplied. + postPatch = '' + substituteInPlace src/xinterpreter.cpp --replace-fail \ + "Cpp::DetectSystemCompilerIncludePaths(CxxSystemIncludes);" \ + "if (const char* e = std::getenv(\"CPPINTEROP_EXTRA_INTERPRETER_ARGS\"); !e || !*e) + Cpp::DetectSystemCompilerIncludePaths(CxxSystemIncludes);" + ''; + cmakeFlags = [ (lib.cmakeBool "XEUS_CPP_BUILD_TESTS" finalAttrs.finalPackage.doCheck) "-DXEUS_CPP_RESOURCE_DIR=${resourceDir}" diff --git a/pkgs/by-name/cp/cpp-interop/package.nix b/pkgs/by-name/cp/cpp-interop/package.nix index 1360b19794f9..42d4989cc90e 100644 --- a/pkgs/by-name/cp/cpp-interop/package.nix +++ b/pkgs/by-name/cp/cpp-interop/package.nix @@ -1,15 +1,16 @@ { - lib, - fetchFromGitHub, - cmake, - ninja, - python3, - llvmPackages_21, + apple-sdk, cling, + cmake, + fetchFromGitHub, gcc-unwrapped, + lib, libffi, libxml2, + llvmPackages_21, ncurses, + ninja, + python3, zlib, zstd, @@ -46,20 +47,49 @@ let "${clingRoot}/lib/clang/20" else "${lib.getLib clang}/lib/clang/${lib.versions.major llvm.version}"; + + # These must precede the resource dir, because libc++ ships its own + # that include_next's Clang's and errors out if reached second. + cxxIncludeArgs = + if stdenv.hostPlatform.isDarwin then + [ + "-isystem" + "${lib.getDev llvmPackages.libcxx}/include/c++/v1" + ] + else + [ + "-isystem" + "${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}" + "-isystem" + "${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}/${stdenv.hostPlatform.config}" + ]; + + libcIncludeArgs = + if stdenv.hostPlatform.isDarwin then + [ + "-isystem" + "${apple-sdk.sdkroot}/usr/include" + "-iframework" + "${apple-sdk.sdkroot}/System/Library/Frameworks" + ] + else + [ + "-isystem" + "${lib.getDev stdenv.cc.libc}/include" + ]; + interpreterArgs = [ "-nostdinc" "-nostdinc++" "-resource-dir" resourceDir + ] + ++ cxxIncludeArgs + ++ [ "-isystem" "${resourceDir}/include" - "-isystem" - "${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}" - "-isystem" - "${gcc-unwrapped}/include/c++/${gcc-unwrapped.version}/${stdenv.hostPlatform.config}" - "-isystem" - "${lib.getDev stdenv.cc.libc}/include" - ]; + ] + ++ libcIncludeArgs; in assert lib.assertOneOf "backend" backend [ From 351f53f9c3f3172f9ac15d81e791de38e2a66118 Mon Sep 17 00:00:00 2001 From: Miroslav Valov <91765698+mivalov@users.noreply.github.com> Date: Thu, 3 Sep 2026 23:26:58 +0200 Subject: [PATCH 08/50] google-chrome: 152.0.7977.75 -> 152.0.7977.82 (cherry picked from commit 27973cf344fc756f9ec8f9ba0811184164c69cd9) --- pkgs/by-name/go/google-chrome/package.nix | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/go/google-chrome/package.nix b/pkgs/by-name/go/google-chrome/package.nix index da6cefb03b13..8a4c6e69186f 100644 --- a/pkgs/by-name/go/google-chrome/package.nix +++ b/pkgs/by-name/go/google-chrome/package.nix @@ -180,7 +180,7 @@ let linux = stdenvNoCC.mkDerivation (finalAttrs: { inherit pname meta; - version = "152.0.7977.75"; + version = "152.0.7977.82"; src = let @@ -195,8 +195,8 @@ let url = "https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-stable/google-chrome-stable_${finalAttrs.version}-1_${debArch}.deb"; hash = { - amd64 = "sha256-oLemT3aP/A/1zMkmCtnrtT/Rb3oTHi42mU2li4LZE98="; - arm64 = "sha256-OFS2UlA3+NKXBIEqJoGEnE7N9peXdQ2jdCOBQD834dI="; + amd64 = "sha256-TSXkoCjHinrpEGg1UcLyNHksxVlefj40k59Zk0KtpEY="; + arm64 = "sha256-HcBFWH2AjCB6GenrNw9ukS3X5pZpU6+5PIHZnD/jGOM="; } .${debArch}; }; @@ -306,11 +306,11 @@ let darwin = stdenvNoCC.mkDerivation (finalAttrs: { inherit pname meta; - version = "152.0.7977.76"; + version = "152.0.7977.83"; src = fetchurl { - url = "http://dl.google.com/release2/chrome/fwccdneh3i55zgoy366y75r2ya_152.0.7977.76/GoogleChrome-152.0.7977.76.dmg"; - hash = "sha256-VuYzRvaOH0YB/I1m1Agk+l4y4al1b4o4dZZnhm7J2PQ="; + url = "http://dl.google.com/release2/chrome/g62gliie746ywu62ed7go3adam_152.0.7977.83/GoogleChrome-152.0.7977.83.dmg"; + hash = "sha256-Uc16WeBPhu/r7zB/UE9yt+cgkbpRYkRM3xtENFltqps="; }; dontPatch = true; From e943b12a1c477dbfa881851bcda1177d75509fee Mon Sep 17 00:00:00 2001 From: Leon Klingele Date: Wed, 19 Aug 2026 18:58:51 +0200 Subject: [PATCH 09/50] go_1_27: 1.27rc3 -> 1.27.0 (cherry picked from commit 30a8631bb18996a3cf754344f31f1a49050e56b9) --- pkgs/development/compilers/go/1.27.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/go/1.27.nix b/pkgs/development/compilers/go/1.27.nix index b6a0efa1040e..afa36cce9880 100644 --- a/pkgs/development/compilers/go/1.27.nix +++ b/pkgs/development/compilers/go/1.27.nix @@ -25,11 +25,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "go"; - version = "1.27rc3"; + version = "1.27.0"; src = fetchurl { url = "https://go.dev/dl/go${finalAttrs.version}.src.tar.gz"; - hash = "sha256-6eIO3RcgCV+RCWluljpmBp0/bUjQDrk4jIiM4GYx31w="; + hash = "sha256-cAJAPXzERSnvbSb2mkSBgmM5Xq18FsBaWAiuBH6+sOU="; }; strictDeps = true; From 28c50a5c65d1477e0b936dd32b7751023c6938c9 Mon Sep 17 00:00:00 2001 From: emilylange Date: Thu, 3 Sep 2026 22:08:22 +0200 Subject: [PATCH 10/50] chromium,chromedriver: 152.0.7977.75 -> 152.0.7977.82 https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html This update includes 12 security fixes. Google is aware that an exploit for CVE-2026-85046 exists in the wild. CVEs: CVE-2026-85046 CVE-2026-85052 CVE-2026-85043 CVE-2026-85048 CVE-2026-85045 CVE-2026-85050 CVE-2026-85053 CVE-2026-85042 CVE-2026-85049 CVE-2026-85051 CVE-2026-85047 CVE-2026-85044 (cherry picked from commit b15a1cb620eed50de9c244f74c8e93a6818ca76f) --- .../networking/browsers/chromium/info.json | 24 +++++++++---------- 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/info.json b/pkgs/applications/networking/browsers/chromium/info.json index 67aa9f0afe9a..191cd0d064ef 100644 --- a/pkgs/applications/networking/browsers/chromium/info.json +++ b/pkgs/applications/networking/browsers/chromium/info.json @@ -1,10 +1,10 @@ { "chromium": { - "version": "152.0.7977.75", + "version": "152.0.7977.82", "chromedriver": { - "version": "152.0.7977.76", - "hash_darwin": "sha256-tK7HmSRzWr/ruU484L+Og4wruS87fRHLEBKSZd4SSDA=", - "hash_darwin_aarch64": "sha256-+f0e6EGB0aXeyyYN8Db5u3+G9/RjILI/I0/2QWiVg1M=" + "version": "152.0.7977.83", + "hash_darwin": "sha256-cx8v6bu6MuSU+LHOGmxcOWNhH7tZFaegHfcMv+RSZGg=", + "hash_darwin_aarch64": "sha256-OM3ogo/Z76H8E8F9RhbcLwjSEgWNxdBJxngDI/nHhkI=" }, "deps": { "depot_tools": { @@ -21,8 +21,8 @@ "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "4999cc1efed37c4d91dc4ce6ec4b0a50e2a9a8cb", - "hash": "sha256-RXykREnCulCwk8zkk8OAd62TM4qel6j4uhyaaYzgolY=", + "rev": "d04cdb24d67b081f6cf80200ffc5233f44b61109", + "hash": "sha256-JiYTfMJBtUWMUSicQdSCXNUtgjLGeaMj4vCNpMvYACk=", "recompress": true }, "src/third_party/clang-format/script": { @@ -92,8 +92,8 @@ }, "src/third_party/angle": { "url": "https://chromium.googlesource.com/angle/angle.git", - "rev": "736ed80c7552a4b267bd54a282b971aa4555cb3e", - "hash": "sha256-3ZCIFT7j944HWPOiADQa88TQZctLej5vbrBFA/FwyHw=" + "rev": "7df613367a1d4ca9aea9ece344d4580d32d132a9", + "hash": "sha256-bYGok5QvWJoCfliRPQqrDz0ttKf1r9HoFxoC4qwdI3o=" }, "src/third_party/angle/third_party/glmark2/src": { "url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2", @@ -672,8 +672,8 @@ }, "src/third_party/skia": { "url": "https://skia.googlesource.com/skia.git", - "rev": "b6d106297ff9ef2ff8094033695d045e87775581", - "hash": "sha256-sun/P/JVhTKfRwmVK5dgnz8UZEFnQoyXZZS6PN5z9us=" + "rev": "0873ec164a06966b90ae0d43ef783cfb180084ae", + "hash": "sha256-LbSs+UNakFipC2t9TSbZVreylVXHf1PsbK6z2qJh6QI=" }, "src/third_party/smhasher/src": { "url": "https://chromium.googlesource.com/external/smhasher.git", @@ -842,8 +842,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "3de6ffffbfdcf265e9f11a5c9d1cfb4d486d7550", - "hash": "sha256-ZHEmeSe8r226gjazm91GYqlfbM9a5yi8KnFv4iAWFKE=" + "rev": "4323497a6a73839e6d5260f6acd7ec0212cb3321", + "hash": "sha256-HUg4GGtYL4xGk/xw0QXxNZAnsFVcznklWGQaqhZj9QM=" }, "src/agents/shared": { "url": "https://chromium.googlesource.com/chromium/agents.git", From c6c421e357915f11df85ae83f98450a4e09c53a4 Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Thu, 3 Sep 2026 22:52:34 -0400 Subject: [PATCH 11/50] .github: disable npm ci audit It's currently very slow and often times brings jobs past the 3min limit. No one is reading these audit reports in ci output, and in slight chance we care to stay on top of these CVE audit reports from npm, we should have a dedicated procedure to monitor and bump lock file that doesn't involve routinely executing it in every job. (cherry picked from commit 887655a786fe5839696b99c34380644b6d5ed29d) --- .github/workflows/bot.yml | 2 +- .github/workflows/check.yml | 4 ++-- .github/workflows/teams.yml | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/bot.yml b/.github/workflows/bot.yml index a9c97db21b6f..3e404d89c8c2 100644 --- a/.github/workflows/bot.yml +++ b/.github/workflows/bot.yml @@ -49,7 +49,7 @@ jobs: ci/github-script - name: Install dependencies - run: npm ci --package-lock-only=false @actions/artifact bottleneck + run: npm ci --package-lock-only=false --no-audit @actions/artifact bottleneck working-directory: ci/github-script # Use a GitHub App, because it has much higher rate limits: 12,500 instead of 5,000 req / hour. diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index d6cdd5564220..fd3404f07a3b 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -51,7 +51,7 @@ jobs: ci/github-script - name: Install dependencies - run: npm ci --package-lock-only=false bottleneck + run: npm ci --package-lock-only=false --no-audit bottleneck working-directory: trusted/ci/github-script - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 @@ -153,7 +153,7 @@ jobs: - name: Install dependencies to trusted/ run: | - npm ci --package-lock-only=false + npm ci --package-lock-only=false --no-audit echo "$PWD/node_modules/.bin" >> "$GITHUB_PATH" working-directory: nixpkgs/trusted/ci/github-script diff --git a/.github/workflows/teams.yml b/.github/workflows/teams.yml index 1e6ed3175cf4..5e8e20497b7f 100644 --- a/.github/workflows/teams.yml +++ b/.github/workflows/teams.yml @@ -38,7 +38,7 @@ jobs: maintainers/github-teams.json - name: Install dependencies - run: npm ci --package-lock-only=false bottleneck + run: npm ci --package-lock-only=false --no-audit bottleneck working-directory: ci/github-script - name: Synchronise teams From 340d99c0cf073e13fc6c3bc6220160118ecc9ac7 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 3 Sep 2026 12:49:04 +0000 Subject: [PATCH 12/50] thunderbird-140-unwrapped: 140.14.0esr -> 140.15.0esr (cherry picked from commit f1942caeca5123df0c9f091fb7eade0b21b7a318) --- .../networking/mailreaders/thunderbird/packages.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix index cb64cc45b34c..158c63a47440 100644 --- a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix +++ b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix @@ -111,8 +111,8 @@ rec { thunderbird-140 = common { applicationName = "Thunderbird ESR"; - version = "140.14.0esr"; - sha512 = "4c95b1ca3fc7f6429b2360a7e732635bdfb60927622a7da4d8af9ca2abd550611b91763c587cddad5d51c0dd4e905ba8e106da3cd21591a1bec3dba1b9a2502d"; + version = "140.15.0esr"; + sha512 = "52f014fb75ac131780aba924dd973a1fb5d6a60be4f800c258dca931e2c6ad75baaad37a5ad52228e91d3d174823b6b4d38ddc2dbbf9c04b8700cc33079448bb"; updateScript = callPackage ./update.nix { attrPath = "thunderbirdPackages.thunderbird-140"; From 31ccf19d8419fb5dbf2d91c2ff4eead094357244 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 30 Aug 2026 20:36:38 +0000 Subject: [PATCH 13/50] bookstack: 26.05.3 -> 26.05.4 (cherry picked from commit c6d95e21a7b112cc4f55ba233202202caf95701f) --- pkgs/by-name/bo/bookstack/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/bo/bookstack/package.nix b/pkgs/by-name/bo/bookstack/package.nix index 2e568b3d9529..67f9702d5222 100644 --- a/pkgs/by-name/bo/bookstack/package.nix +++ b/pkgs/by-name/bo/bookstack/package.nix @@ -8,16 +8,16 @@ php83.buildComposerProject2 (finalAttrs: { pname = "bookstack"; - version = "26.05.3"; + version = "26.05.4"; src = fetchFromGitHub { owner = "bookstackapp"; repo = "bookstack"; tag = "v${finalAttrs.version}"; - hash = "sha256-IRJGgK1MEptQJlnvHVXINSnhr8TVp6S8fZRBi+4VGig="; + hash = "sha256-DDjJZehRUf1GP19S+RqhqZSSGOMF/SzItt2GFXi4+1U="; }; - vendorHash = "sha256-1x0czjCCD9Jf9TMhmkSpUt33q5+E1bw2l0SNP9VPRCE="; + vendorHash = "sha256-Ioth8Kp5fx4iwfy0p7N8xE0L41oWcp+ATfhmq3PUYyY="; passthru = { phpPackage = php83; From db829a79a839554b69696b25e6175deae28c0933 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 4 Sep 2026 07:26:59 +0000 Subject: [PATCH 14/50] chhoto-url: 7.5.0 -> 7.5.1 (cherry picked from commit c859b8ce683080f85240bbf850a7acd782a6f758) --- pkgs/by-name/ch/chhoto-url/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ch/chhoto-url/package.nix b/pkgs/by-name/ch/chhoto-url/package.nix index f8b829821716..34215ca96f3f 100644 --- a/pkgs/by-name/ch/chhoto-url/package.nix +++ b/pkgs/by-name/ch/chhoto-url/package.nix @@ -8,13 +8,13 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "chhoto-url"; - version = "7.5.0"; + version = "7.5.1"; src = fetchFromGitHub { owner = "SinTan1729"; repo = "chhoto-url"; tag = finalAttrs.version; - hash = "sha256-lyrTuZxsVui25JIfxDoezNcMTZDKgYOPJ9+VMOfhHjg="; + hash = "sha256-FAYbqNZVPUpfBKOn+cXvk5d8o29M9+d8t5ecihCQ4aY="; fetchLFS = true; }; @@ -27,7 +27,7 @@ rustPlatform.buildRustPackage (finalAttrs: { --replace-fail 'rust-version = "1.96"' 'rust-version = "1.95"' ''; - cargoHash = "sha256-y1MIiJ7NAP1F1c0IkrrVn1Wd2K+mrQD1RhqiumcPq1o="; + cargoHash = "sha256-C+eH6lrFSpE7zuR3fyyP44KG/rV0N2Uh4E7She0HuEA="; postInstall = '' mkdir -p $out/share/chhoto-url From ea29cf4b74f321e24af576108b03d9fbe7d1328f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 3 Sep 2026 16:37:31 +0000 Subject: [PATCH 15/50] jackett: 0.24.2457 -> 0.24.2527 (cherry picked from commit d7fc897c508c95a2f81d5947186752161507d3ee) --- pkgs/by-name/ja/jackett/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ja/jackett/package.nix b/pkgs/by-name/ja/jackett/package.nix index 840ee662a851..1c9c6a2e72b8 100644 --- a/pkgs/by-name/ja/jackett/package.nix +++ b/pkgs/by-name/ja/jackett/package.nix @@ -12,13 +12,13 @@ buildDotnetModule (finalAttrs: { pname = "jackett"; - version = "0.24.2457"; + version = "0.24.2527"; src = fetchFromGitHub { owner = "jackett"; repo = "jackett"; tag = "v${finalAttrs.version}"; - hash = "sha256-oLKej0+Loiwn2yEAOHMeCqv1fU4d0vd7nzX/uTl3dFU="; + hash = "sha256-IbSXGddfsD9r0ElsSToQ+n75F09WUnF2jHirFOAiu+Q="; }; projectFile = "src/Jackett.Server/Jackett.Server.csproj"; From 7977b0320d02aa61d523c60be6e23b6fb60b4003 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 4 Sep 2026 11:09:51 +0000 Subject: [PATCH 16/50] sub-store-frontend: 2.29.10 -> 2.31.1 (cherry picked from commit bafb82c9e23e54f048941ed0b42e7a45af0b03ef) --- pkgs/by-name/su/sub-store-frontend/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/su/sub-store-frontend/package.nix b/pkgs/by-name/su/sub-store-frontend/package.nix index 33bfd78c7561..7e3c2c8549f8 100644 --- a/pkgs/by-name/su/sub-store-frontend/package.nix +++ b/pkgs/by-name/su/sub-store-frontend/package.nix @@ -14,13 +14,13 @@ let in buildNpmPackage (finalAttrs: { pname = "sub-store-frontend"; - version = "2.29.10"; + version = "2.31.1"; src = fetchFromGitHub { owner = "sub-store-org"; repo = "Sub-Store-Front-End"; tag = finalAttrs.version; - hash = "sha256-jQXIwdt9+yndTFBCrs6bZ7dCZ2fmjti0xQAgAGZbC1M="; + hash = "sha256-eqaS5bPHBx92C6gv2iE9MYtBpI0UsvM0ptG97lPt8HE="; }; nativeBuildInputs = [ From 1d64571ef848ee3cf8b4fbb85a203b1695dca887 Mon Sep 17 00:00:00 2001 From: Brad Fitzpatrick Date: Thu, 3 Sep 2026 18:06:48 +0000 Subject: [PATCH 17/50] go_1_27: 1.27.0 -> 1.27.1 Changelog: https://go.dev/doc/devel/release#go1.27.minor (cherry picked from commit 03335609f036c76f18df379369f92b57973fea73) --- pkgs/development/compilers/go/1.27.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/go/1.27.nix b/pkgs/development/compilers/go/1.27.nix index afa36cce9880..5699d79277c8 100644 --- a/pkgs/development/compilers/go/1.27.nix +++ b/pkgs/development/compilers/go/1.27.nix @@ -25,11 +25,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "go"; - version = "1.27.0"; + version = "1.27.1"; src = fetchurl { url = "https://go.dev/dl/go${finalAttrs.version}.src.tar.gz"; - hash = "sha256-cAJAPXzERSnvbSb2mkSBgmM5Xq18FsBaWAiuBH6+sOU="; + hash = "sha256-TkCKuuEm2Ra2FkYnGT8sVPDjyhMS1pO4bbRfhiqyOLE="; }; strictDeps = true; From 138cc42193c33a28c3281d8d5e7e4bfe3bbb76b8 Mon Sep 17 00:00:00 2001 From: dish Date: Mon, 31 Aug 2026 16:14:16 -0400 Subject: [PATCH 18/50] outline: shrink output closure size Shrinks the closure from 1.2GB to 627MB. Removes various unneeded files and runs yarn workspaces focus to go to only production dependencies instead of shipping devDependencies that are unneeded. (cherry picked from commit d791316af5b67c8e5ffdcdb090c7cf037207e7f7) --- pkgs/by-name/ou/outline/package.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/by-name/ou/outline/package.nix b/pkgs/by-name/ou/outline/package.nix index be0800e50df1..add6d2fc50a2 100644 --- a/pkgs/by-name/ou/outline/package.nix +++ b/pkgs/by-name/ou/outline/package.nix @@ -49,8 +49,12 @@ stdenv.mkDerivation (finalAttrs: { installPhase = '' runHook preInstall + yarn workspaces focus --production + mkdir -p $out/bin $out/share/outline mv build server public node_modules $out/share/outline/ + find $out/share/outline/node_modules -name "*.map" -delete + find $out/share/outline/node_modules -name "*.d.ts" -delete node_modules=$out/share/outline/node_modules build=$out/share/outline/build From 5183a51e090cf9a84f47cd99bc0bc8a74fc43279 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 4 Sep 2026 07:44:47 +0000 Subject: [PATCH 19/50] microsoft-edge: 152.0.4191.53 -> 152.0.4191.62 (cherry picked from commit 554553bdc25f687531ae714647b176bf9a9fe345) --- pkgs/by-name/mi/microsoft-edge/package.nix | 4 ++-- pkgs/by-name/ms/msedgedriver/package.nix | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/mi/microsoft-edge/package.nix b/pkgs/by-name/mi/microsoft-edge/package.nix index b1e10843206c..7a4e931a3e76 100644 --- a/pkgs/by-name/mi/microsoft-edge/package.nix +++ b/pkgs/by-name/mi/microsoft-edge/package.nix @@ -164,11 +164,11 @@ let in stdenvNoCC.mkDerivation (finalAttrs: { pname = "microsoft-edge"; - version = "152.0.4191.53"; + version = "152.0.4191.62"; src = fetchurl { url = "https://packages.microsoft.com/repos/edge/pool/main/m/microsoft-edge-stable/microsoft-edge-stable_${finalAttrs.version}-1_amd64.deb"; - hash = "sha256-szIkRfvmzh4Lz/hOu+Dt6jZeDq9Jix72E23aUt6m46c="; + hash = "sha256-SzUssNgbFRwQcZUZoUFe/ZJXChydV/BV5eXYD2yZug0="; }; # With strictDeps on, some shebangs were not being patched correctly diff --git a/pkgs/by-name/ms/msedgedriver/package.nix b/pkgs/by-name/ms/msedgedriver/package.nix index 36674db8a9c1..64634339c68a 100644 --- a/pkgs/by-name/ms/msedgedriver/package.nix +++ b/pkgs/by-name/ms/msedgedriver/package.nix @@ -12,11 +12,11 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "msedgedriver"; - version = "152.0.4191.53"; + version = "152.0.4191.62"; src = fetchzip { url = "https://msedgedriver.microsoft.com/${finalAttrs.version}/edgedriver_linux64.zip"; - hash = "sha256-3akRs0D76LAJ8Lgr3P7X+cDrMNXiEC+LWNH8lUdBM9k="; + hash = "sha256-dhUC+/XWACG/4In4xP0wOBjb6EIYlBnP9JT7j/xxBJk="; stripRoot = false; }; From b4826de80461302e55a956505190f6d15c20f133 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 29 Aug 2026 00:38:31 +0000 Subject: [PATCH 20/50] perfetto: 58.2 -> 58.3 (cherry picked from commit 2768ed43dd3afd35465383ede8937d72edb78a97) --- pkgs/by-name/pe/perfetto/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pe/perfetto/package.nix b/pkgs/by-name/pe/perfetto/package.nix index 87258b56da60..9cb320f68788 100644 --- a/pkgs/by-name/pe/perfetto/package.nix +++ b/pkgs/by-name/pe/perfetto/package.nix @@ -72,7 +72,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "perfetto"; - version = "58.2"; + version = "58.3"; __structuredAttrs = true; strictDeps = true; @@ -81,7 +81,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "google"; repo = "perfetto"; tag = "v${finalAttrs.version}"; - hash = "sha256-Ipr86zH0iGjMzz9ZM3QEvtA6FlAN4lhkiDgySSeNj5c="; + hash = "sha256-73aE+qoHOkdD2Br3NmUE48BM6uE6uIBdug0+ZR2nn94="; }; patches = [ From 3e7976823c8554fecad15b6d08959af3ebddb85d Mon Sep 17 00:00:00 2001 From: Tom Oostveen Date: Mon, 8 Jun 2026 20:01:42 +0200 Subject: [PATCH 21/50] noctalia-greeter: init at 1.0.0 https://github.com/noctalia-dev/noctalia-greeter Assisted-by: nix-init (cherry picked from commit 92849858f938668467d43408335b1c6f4c5e2fe0) --- pkgs/by-name/no/noctalia-greeter/package.nix | 77 ++++++++++++++++++++ 1 file changed, 77 insertions(+) create mode 100644 pkgs/by-name/no/noctalia-greeter/package.nix diff --git a/pkgs/by-name/no/noctalia-greeter/package.nix b/pkgs/by-name/no/noctalia-greeter/package.nix new file mode 100644 index 000000000000..b8468ea63925 --- /dev/null +++ b/pkgs/by-name/no/noctalia-greeter/package.nix @@ -0,0 +1,77 @@ +{ + lib, + stdenv, + fetchFromGitHub, + + meson, + ninja, + pkg-config, + wayland-scanner, + + cairo, + fontconfig, + freetype, + glib, + gtk4, + libGL, + librsvg, + libwebp, + libxkbcommon, + pango, + wayland, + wayland-protocols, + + nix-update-script, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "noctalia-greeter"; + version = "1.0.0"; + + __structuredAttrs = true; + strictDeps = true; + + src = fetchFromGitHub { + owner = "noctalia-dev"; + repo = "noctalia-greeter"; + rev = "367ab83dcd9190010f093cfe0e123ba132a75b5a"; + hash = "sha256-/jQ/lkgjaH5EOTZRXk4YZaFrjrKhq/fzZsU6nm7wPt0="; + }; + + nativeBuildInputs = [ + meson + ninja + pkg-config + wayland-scanner + ]; + + buildInputs = [ + cairo + fontconfig + freetype + glib + gtk4 + libGL + librsvg + libwebp + libxkbcommon + pango + wayland + wayland-protocols + ]; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "`greetd` greeter for Noctalia"; + homepage = "https://github.com/noctalia-dev/noctalia-greeter"; + changelog = "https://github.com/noctalia-dev/noctalia-greeter/blob/${finalAttrs.src.rev}/CHANGELOG.md"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ + dtomvan + spacedentist + ]; + mainProgram = "noctalia-greeter-session"; + platforms = lib.platforms.linux; + }; +}) From c4f3805f4f43a58ae418ac6b2b1d13076c3fd755 Mon Sep 17 00:00:00 2001 From: Samiser Date: Thu, 23 Jul 2026 15:10:06 +0000 Subject: [PATCH 22/50] noctalia: init at 5.0.0-beta.4 (cherry picked from commit 9cb11c26a2fc2d6db99c2c0bdb84791470138b9a) --- pkgs/by-name/no/noctalia/package.nix | 146 +++++++++++++++++++++++++++ 1 file changed, 146 insertions(+) create mode 100644 pkgs/by-name/no/noctalia/package.nix diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix new file mode 100644 index 000000000000..8e3972a6fdad --- /dev/null +++ b/pkgs/by-name/no/noctalia/package.nix @@ -0,0 +1,146 @@ +{ + lib, + stdenv, + fetchFromGitHub, + nix-update-script, + + # build + meson, + ninja, + pkg-config, + wayland-scanner, + makeBinaryWrapper, + + # libraries + cairo, + curl, + fontconfig, + freetype, + glib, + harfbuzz, + jemalloc, + libGL, + libqalculate, + librsvg, + libsecret, + libsodium, + libwebp, + libxkbcommon, + libxml2, + md4c, + nlohmann_json, + pam, + pango, + pipewire, + polkit, + sdbus-cpp_2, + stb, + systemdLibs, + tomlplusplus, + wayland, + wayland-protocols, + wireplumber, + + # runtime + gitMinimal, +}: + +let + # nixpkgs stb doesn't have stb_image_resize2.h which noctalia needs + stb' = stb.overrideAttrs { + version = "0-unstable-2025-10-26"; + src = fetchFromGitHub { + owner = "nothings"; + repo = "stb"; + rev = "f1c79c02822848a9bed4315b12c8c8f3761e1296"; + hash = "sha256-BlyXJtAI7WqXCTT3ylww8zoG0hBxaojJnQDvdQOXJPE="; + }; + }; +in +stdenv.mkDerivation (finalAttrs: { + __structuredAttrs = true; + + pname = "noctalia"; + version = "5.0.0-beta.4"; + + src = fetchFromGitHub { + owner = "noctalia-dev"; + repo = "noctalia"; + tag = "v${finalAttrs.version}"; + hash = "sha256-jXz2vFHgidbyU46ScROLSuBIhsqqtyqNu2M0tmGX/FA="; + }; + + strictDeps = true; + + nativeBuildInputs = [ + meson + ninja + pkg-config + wayland-scanner + makeBinaryWrapper + ]; + + buildInputs = [ + cairo + curl + fontconfig + freetype + glib + harfbuzz + jemalloc + libGL + libqalculate + librsvg + libsecret + libsodium + libwebp + libxkbcommon + libxml2 + md4c + nlohmann_json + pam + pango + pipewire + polkit + sdbus-cpp_2 + stb' + systemdLibs + tomlplusplus + wayland + wayland-protocols + wireplumber + ]; + + mesonBuildType = "release"; + + # plugins are installed by cloning their repos + postFixup = '' + wrapProgram $out/bin/noctalia \ + --prefix PATH : ${lib.makeBinPath [ gitMinimal ]} + ''; + + # remove --version=unstable once 5.0.0 stable is released + passthru.updateScript = nix-update-script { + extraArgs = [ + "--version=unstable" + "--version-regex" + "v(5\\..*)" + ]; + }; + + meta = { + description = "A sleek, customizable desktop shell crafted for Wayland."; + homepage = "https://github.com/noctalia-dev/noctalia"; + changelog = "https://github.com/noctalia-dev/noctalia/releases/tag/v${finalAttrs.version}"; + license = with lib.licenses; [ + mit + asl20 # material_color_utilities is Apache 2.0 + ]; + mainProgram = "noctalia"; + maintainers = with lib.maintainers; [ + samiser + pyrox0 + ]; + platforms = lib.platforms.linux; + }; +}) From 5191e65c84cc99c7158f2c5968bcad48f4882205 Mon Sep 17 00:00:00 2001 From: dish Date: Sat, 25 Jul 2026 15:28:57 -0400 Subject: [PATCH 23/50] noctalia: 5.0.0-beta.4 -> 5.0.0-beta.5 Changelog: https://noctalia.dev/changelogs#v5.0.0-beta.5 (cherry picked from commit dd904cf1103ca69799e9d58856a53b6b38fa8399) --- pkgs/by-name/no/noctalia/package.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 8e3972a6fdad..70e55719d158 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -61,13 +61,13 @@ stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; pname = "noctalia"; - version = "5.0.0-beta.4"; + version = "5.0.0-beta.5"; src = fetchFromGitHub { owner = "noctalia-dev"; repo = "noctalia"; tag = "v${finalAttrs.version}"; - hash = "sha256-jXz2vFHgidbyU46ScROLSuBIhsqqtyqNu2M0tmGX/FA="; + hash = "sha256-iq/Eqx62P/JJDpW7CgEsMWWPwOexIWRKXtqKF/drawA="; }; strictDeps = true; @@ -129,9 +129,9 @@ stdenv.mkDerivation (finalAttrs: { }; meta = { - description = "A sleek, customizable desktop shell crafted for Wayland."; - homepage = "https://github.com/noctalia-dev/noctalia"; - changelog = "https://github.com/noctalia-dev/noctalia/releases/tag/v${finalAttrs.version}"; + description = "Sleek, customizable desktop shell crafted for Wayland"; + homepage = "https://noctalia.dev"; + changelog = "https://noctalia.dev/changelogs#v${finalAttrs.version}"; license = with lib.licenses; [ mit asl20 # material_color_utilities is Apache 2.0 From f1662cc27f9ff075bd8ddd5554ba0071178613be Mon Sep 17 00:00:00 2001 From: dish Date: Mon, 27 Jul 2026 19:27:47 -0400 Subject: [PATCH 24/50] noctalia: 5.0.0-beta.5 -> 5.0.0-beta.6 Changelog: https://noctalia.dev/changelogs#v5.0.0-beta.6 Needs libjxl dependency per release notes (cherry picked from commit fcfbd0acaf562643fd35a9d418d9f3316db5f4f5) --- pkgs/by-name/no/noctalia/package.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 70e55719d158..60ae7e47d635 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -20,6 +20,7 @@ harfbuzz, jemalloc, libGL, + libjxl, libqalculate, librsvg, libsecret, @@ -61,13 +62,13 @@ stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; pname = "noctalia"; - version = "5.0.0-beta.5"; + version = "5.0.0-beta.6"; src = fetchFromGitHub { owner = "noctalia-dev"; repo = "noctalia"; tag = "v${finalAttrs.version}"; - hash = "sha256-iq/Eqx62P/JJDpW7CgEsMWWPwOexIWRKXtqKF/drawA="; + hash = "sha256-VJXqeaxCqyMOt/k7ePNoD4nAHdF1eTSuuddmrh/5O6Q="; }; strictDeps = true; @@ -89,6 +90,7 @@ stdenv.mkDerivation (finalAttrs: { harfbuzz jemalloc libGL + libjxl libqalculate librsvg libsecret From c8020eb7c3bc6a9cd47bbe546d135d3ff6b4af9e Mon Sep 17 00:00:00 2001 From: Samiser Date: Tue, 28 Jul 2026 13:10:46 +0000 Subject: [PATCH 25/50] noctalia: fix nvidia gpu support (cherry picked from commit 13585e73f9a8bf539584d55bc2952fea2eb8e5ae) --- pkgs/by-name/no/noctalia/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 60ae7e47d635..7d7ac5be87a9 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -10,6 +10,7 @@ pkg-config, wayland-scanner, makeBinaryWrapper, + autoAddDriverRunpath, # libraries cairo, @@ -79,6 +80,7 @@ stdenv.mkDerivation (finalAttrs: { pkg-config wayland-scanner makeBinaryWrapper + autoAddDriverRunpath ]; buildInputs = [ From 527bc095406c175e7f1a871c53225408578a12bb Mon Sep 17 00:00:00 2001 From: dish Date: Thu, 30 Jul 2026 18:34:57 -0400 Subject: [PATCH 26/50] noctalia: 5.0.0-beta.6 -> 5.0.0-beta.7 (cherry picked from commit dd6a1ee8dfcdba7f5b3f3a3bd63f9d29a737efcd) --- pkgs/by-name/no/noctalia/package.nix | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 7d7ac5be87a9..bfd9ace5967a 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -21,10 +21,12 @@ harfbuzz, jemalloc, libGL, + libical, libjxl, libqalculate, librsvg, libsecret, + libsndfile, libsodium, libwebp, libxkbcommon, @@ -63,13 +65,13 @@ stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; pname = "noctalia"; - version = "5.0.0-beta.6"; + version = "5.0.0-beta.7"; src = fetchFromGitHub { owner = "noctalia-dev"; repo = "noctalia"; tag = "v${finalAttrs.version}"; - hash = "sha256-VJXqeaxCqyMOt/k7ePNoD4nAHdF1eTSuuddmrh/5O6Q="; + hash = "sha256-9RlJNIy2DFVm9SB2vwGEBsbHc1r3dIB+K+b+nd6Bdho="; }; strictDeps = true; @@ -92,10 +94,12 @@ stdenv.mkDerivation (finalAttrs: { harfbuzz jemalloc libGL + libical libjxl libqalculate librsvg libsecret + libsndfile libsodium libwebp libxkbcommon From 77e5a8e59430d1e59b93ccac5dcf6916eb53f651 Mon Sep 17 00:00:00 2001 From: Samiser Date: Fri, 31 Jul 2026 10:57:56 +0000 Subject: [PATCH 27/50] noctalia-greeter: 1.0.0 -> 1.1.0 (cherry picked from commit 34a3b0ee28a97b49a22ca26be0c3b5585a9433d7) --- pkgs/by-name/no/noctalia-greeter/package.nix | 31 ++++++++++++++++---- 1 file changed, 25 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/no/noctalia-greeter/package.nix b/pkgs/by-name/no/noctalia-greeter/package.nix index b8468ea63925..bd0cba98fed5 100644 --- a/pkgs/by-name/no/noctalia-greeter/package.nix +++ b/pkgs/by-name/no/noctalia-greeter/package.nix @@ -8,25 +8,41 @@ pkg-config, wayland-scanner, + bashNonInteractive, cairo, fontconfig, freetype, glib, - gtk4, libGL, librsvg, libwebp, libxkbcommon, + nlohmann_json, pango, + stb, + tomlplusplus, wayland, wayland-protocols, + wlroots_0_20, nix-update-script, }: +let + # nixpkgs stb doesn't have stb_image_resize2.h which noctalia-greeter needs + stb' = stb.overrideAttrs { + version = "0-unstable-2025-10-26"; + src = fetchFromGitHub { + owner = "nothings"; + repo = "stb"; + rev = "f1c79c02822848a9bed4315b12c8c8f3761e1296"; + hash = "sha256-BlyXJtAI7WqXCTT3ylww8zoG0hBxaojJnQDvdQOXJPE="; + }; + }; +in stdenv.mkDerivation (finalAttrs: { pname = "noctalia-greeter"; - version = "1.0.0"; + version = "1.1.0"; __structuredAttrs = true; strictDeps = true; @@ -34,8 +50,8 @@ stdenv.mkDerivation (finalAttrs: { src = fetchFromGitHub { owner = "noctalia-dev"; repo = "noctalia-greeter"; - rev = "367ab83dcd9190010f093cfe0e123ba132a75b5a"; - hash = "sha256-/jQ/lkgjaH5EOTZRXk4YZaFrjrKhq/fzZsU6nm7wPt0="; + tag = "v${finalAttrs.version}"; + hash = "sha256-3t/+o8Cbve8z43IekUNBj7Ecn/T+v7+p4Ivgs3IEQtk="; }; nativeBuildInputs = [ @@ -46,18 +62,22 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ + bashNonInteractive cairo fontconfig freetype glib - gtk4 libGL librsvg libwebp libxkbcommon + nlohmann_json pango + stb' + tomlplusplus wayland wayland-protocols + wlroots_0_20 ]; passthru.updateScript = nix-update-script { }; @@ -65,7 +85,6 @@ stdenv.mkDerivation (finalAttrs: { meta = { description = "`greetd` greeter for Noctalia"; homepage = "https://github.com/noctalia-dev/noctalia-greeter"; - changelog = "https://github.com/noctalia-dev/noctalia-greeter/blob/${finalAttrs.src.rev}/CHANGELOG.md"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ dtomvan From 827cf8203e0ad1c060fe000634c0aaa7e1b8c907 Mon Sep 17 00:00:00 2001 From: Samiser Date: Fri, 31 Jul 2026 10:58:05 +0000 Subject: [PATCH 28/50] noctalia-greeter: add samiser to maintainers (cherry picked from commit 22244cc6e9f3f8e747d38f5c94561eb5fd04cd79) --- pkgs/by-name/no/noctalia-greeter/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/no/noctalia-greeter/package.nix b/pkgs/by-name/no/noctalia-greeter/package.nix index bd0cba98fed5..bef1e641a1ec 100644 --- a/pkgs/by-name/no/noctalia-greeter/package.nix +++ b/pkgs/by-name/no/noctalia-greeter/package.nix @@ -88,6 +88,7 @@ stdenv.mkDerivation (finalAttrs: { license = lib.licenses.mit; maintainers = with lib.maintainers; [ dtomvan + samiser spacedentist ]; mainProgram = "noctalia-greeter-session"; From 07be12f5bd5580ccd57ee0c395e21fe4f23ad17f Mon Sep 17 00:00:00 2001 From: dish Date: Mon, 10 Aug 2026 12:47:51 -0400 Subject: [PATCH 29/50] noctalia: 5.0.0-beta.7 -> 5.0.0-beta.8 Changelog: https://noctalia.dev/changelogs#v5.0.0-beta.8 Also explicitly disable tests because upstream's meson build scripts have an issue where without explicitly disabling them, they still get built and linked. We never use them, so there's no reason to spend time doing this. (cherry picked from commit e23f3f1665eb2ea368b331a4765f75604c89234d) --- pkgs/by-name/no/noctalia/package.nix | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index bfd9ace5967a..445d0e3dd69b 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -65,13 +65,13 @@ stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; pname = "noctalia"; - version = "5.0.0-beta.7"; + version = "5.0.0-beta.8"; src = fetchFromGitHub { owner = "noctalia-dev"; repo = "noctalia"; tag = "v${finalAttrs.version}"; - hash = "sha256-9RlJNIy2DFVm9SB2vwGEBsbHc1r3dIB+K+b+nd6Bdho="; + hash = "sha256-qy3Cheg/FQ9ZaBPTIgdq4IkmkNtC6XBpmtC8nT+wU/Y="; }; strictDeps = true; @@ -119,6 +119,10 @@ stdenv.mkDerivation (finalAttrs: { wireplumber ]; + mesonFlags = [ + (lib.mesonEnable "tests" false) + ]; + mesonBuildType = "release"; # plugins are installed by cloning their repos From 40469db0efc7582216a45d4b0e2f35ce1830d81d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 11 Aug 2026 12:09:43 +0000 Subject: [PATCH 30/50] noctalia-greeter: 1.1.0 -> 1.2.1 (cherry picked from commit c27e0a3fea68aa8bf0d59c4fd19206b4eac6d08e) --- pkgs/by-name/no/noctalia-greeter/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/no/noctalia-greeter/package.nix b/pkgs/by-name/no/noctalia-greeter/package.nix index bef1e641a1ec..e223372a8a8a 100644 --- a/pkgs/by-name/no/noctalia-greeter/package.nix +++ b/pkgs/by-name/no/noctalia-greeter/package.nix @@ -42,7 +42,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "noctalia-greeter"; - version = "1.1.0"; + version = "1.2.1"; __structuredAttrs = true; strictDeps = true; @@ -51,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "noctalia-dev"; repo = "noctalia-greeter"; tag = "v${finalAttrs.version}"; - hash = "sha256-3t/+o8Cbve8z43IekUNBj7Ecn/T+v7+p4Ivgs3IEQtk="; + hash = "sha256-k/qCnifAoBqpHkRPYn6nUfEoRV1HXac01+Fh4aouWIE="; }; nativeBuildInputs = [ From cc7a7f514fe64b1d67544700652800369ee6b456 Mon Sep 17 00:00:00 2001 From: Samiser Date: Thu, 20 Aug 2026 19:59:08 +0100 Subject: [PATCH 31/50] noctalia: 5.0.0-beta.8 -> 5.0.0-beta.9 Diff: https://github.com/noctalia-dev/noctalia/compare/v5.0.0-beta.8...v5.0.0-beta.9 Changelog: https://noctalia.dev/changelogs#v5.0.0-beta.9 (cherry picked from commit 96cf09d96bfa8647bbf16078cf1d89c35aa148ee) --- pkgs/by-name/no/noctalia/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 445d0e3dd69b..8eeeed588605 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -65,13 +65,13 @@ stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; pname = "noctalia"; - version = "5.0.0-beta.8"; + version = "5.0.0-beta.9"; src = fetchFromGitHub { owner = "noctalia-dev"; repo = "noctalia"; tag = "v${finalAttrs.version}"; - hash = "sha256-qy3Cheg/FQ9ZaBPTIgdq4IkmkNtC6XBpmtC8nT+wU/Y="; + hash = "sha256-O07tHqxugZ/XE/90kx/UCZ0YCbHSI88v2ct2ezuCKi4="; }; strictDeps = true; From 2e5efa24e9c69d1f82806b4c16dfb946a4edf3d5 Mon Sep 17 00:00:00 2001 From: dish Date: Thu, 20 Aug 2026 17:31:33 -0400 Subject: [PATCH 32/50] noctalia: install shell completions (cherry picked from commit 740b19db0bb9dd189cd0f6587c34144063c5affd) --- pkgs/by-name/no/noctalia/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 8eeeed588605..94f7de1874a5 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -11,6 +11,7 @@ wayland-scanner, makeBinaryWrapper, autoAddDriverRunpath, + installShellFiles, # libraries cairo, @@ -83,6 +84,7 @@ stdenv.mkDerivation (finalAttrs: { wayland-scanner makeBinaryWrapper autoAddDriverRunpath + installShellFiles ]; buildInputs = [ @@ -125,6 +127,13 @@ stdenv.mkDerivation (finalAttrs: { mesonBuildType = "release"; + postInstall = '' + installShellCompletion --cmd noctalia \ + --bash <($out/bin/noctalia completions bash) \ + --fish <($out/bin/noctalia completions fish) \ + --zsh <($out/bin/noctalia completions zsh) + ''; + # plugins are installed by cloning their repos postFixup = '' wrapProgram $out/bin/noctalia \ From ee67650fa729c2d23ef3008f259750dfffc9ebd9 Mon Sep 17 00:00:00 2001 From: "Adam C. Stephens" Date: Fri, 21 Aug 2026 08:41:26 -0400 Subject: [PATCH 33/50] noctalia: ensure canExecute when installing shell completions (cherry picked from commit 480b0208dcd609cbaf794260e824e72493c19d25) --- pkgs/by-name/no/noctalia/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 94f7de1874a5..cd253f686ae0 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -127,7 +127,7 @@ stdenv.mkDerivation (finalAttrs: { mesonBuildType = "release"; - postInstall = '' + postInstall = lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) '' installShellCompletion --cmd noctalia \ --bash <($out/bin/noctalia completions bash) \ --fish <($out/bin/noctalia completions fish) \ From ed3e0a8e6a4de16f130102634c5cea801173f5aa Mon Sep 17 00:00:00 2001 From: Conor Date: Thu, 27 Aug 2026 00:59:29 +0100 Subject: [PATCH 34/50] noctalia: fix build on musl (cherry picked from commit 06aed5520729437cdd117b134f5169486147ef86) --- pkgs/by-name/no/noctalia/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index cd253f686ae0..fd5020a71e77 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -123,6 +123,7 @@ stdenv.mkDerivation (finalAttrs: { mesonFlags = [ (lib.mesonEnable "tests" false) + (lib.mesonEnable "jemalloc" (!stdenv.hostPlatform.isMusl)) ]; mesonBuildType = "release"; From 2dd73411a7b62149ca431cdd0ec2528a1c98d338 Mon Sep 17 00:00:00 2001 From: Samiser Date: Thu, 27 Aug 2026 20:57:02 +0100 Subject: [PATCH 35/50] noctalia: 5.0.0-beta.9 -> 5.0.0-beta.10 Diff: https://github.com/noctalia-dev/noctalia/compare/v5.0.0-beta.9...v5.0.0-beta.10 Changelog: https://noctalia.dev/changelogs#v5.0.0-beta.10 (cherry picked from commit 1db923ff8ad1fa5081bb5d465d1d1573d82a944c) --- pkgs/by-name/no/noctalia/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index fd5020a71e77..20f5b5618324 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -66,13 +66,13 @@ stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; pname = "noctalia"; - version = "5.0.0-beta.9"; + version = "5.0.0-beta.10"; src = fetchFromGitHub { owner = "noctalia-dev"; repo = "noctalia"; tag = "v${finalAttrs.version}"; - hash = "sha256-O07tHqxugZ/XE/90kx/UCZ0YCbHSI88v2ct2ezuCKi4="; + hash = "sha256-WijEuINvjcXMO/e/zMqwG1lyGiWNosnVt1QY+ko0Rw8="; }; strictDeps = true; From 6934fe4b644d9aa3cfccbb84bc4f01afa01b6e92 Mon Sep 17 00:00:00 2001 From: Samiser Date: Mon, 31 Aug 2026 21:04:51 +0100 Subject: [PATCH 36/50] noctalia-greeter: 1.2.1 -> 1.3.0 Diff: https://github.com/noctalia-dev/noctalia-greeter/compare/v1.2.1...v1.3.0 (cherry picked from commit 8a07a58cd342d004386ab814470a1fb183628137) --- pkgs/by-name/no/noctalia-greeter/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/no/noctalia-greeter/package.nix b/pkgs/by-name/no/noctalia-greeter/package.nix index e223372a8a8a..d6de935460d0 100644 --- a/pkgs/by-name/no/noctalia-greeter/package.nix +++ b/pkgs/by-name/no/noctalia-greeter/package.nix @@ -42,7 +42,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "noctalia-greeter"; - version = "1.2.1"; + version = "1.3.0"; __structuredAttrs = true; strictDeps = true; @@ -51,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "noctalia-dev"; repo = "noctalia-greeter"; tag = "v${finalAttrs.version}"; - hash = "sha256-k/qCnifAoBqpHkRPYn6nUfEoRV1HXac01+Fh4aouWIE="; + hash = "sha256-veowX6t9Vo6nV6BzJ3YKSUDXgfgX8k8yHccd+6fYlBo="; }; nativeBuildInputs = [ From c99c4b427e501e3510724652146349810460db9d Mon Sep 17 00:00:00 2001 From: Samiser Date: Wed, 2 Sep 2026 17:49:49 +0100 Subject: [PATCH 37/50] noctalia-greeter: 1.3.0 -> 1.3.1 Diff: https://github.com/noctalia-dev/noctalia-greeter/compare/v1.3.0...v1.3.1 (cherry picked from commit 1a1f7c6d7dd2416683e103fa17ede6698c6686a8) --- pkgs/by-name/no/noctalia-greeter/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/no/noctalia-greeter/package.nix b/pkgs/by-name/no/noctalia-greeter/package.nix index d6de935460d0..f14e6dd0a0ac 100644 --- a/pkgs/by-name/no/noctalia-greeter/package.nix +++ b/pkgs/by-name/no/noctalia-greeter/package.nix @@ -42,7 +42,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "noctalia-greeter"; - version = "1.3.0"; + version = "1.3.1"; __structuredAttrs = true; strictDeps = true; @@ -51,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "noctalia-dev"; repo = "noctalia-greeter"; tag = "v${finalAttrs.version}"; - hash = "sha256-veowX6t9Vo6nV6BzJ3YKSUDXgfgX8k8yHccd+6fYlBo="; + hash = "sha256-1ZdtgBwndNHDltX8J7DLLl2/LBgywQhmt1JNcanfeMA="; }; nativeBuildInputs = [ From dc64ad40bd6ea40441beaf4fda5dd07b3beed155 Mon Sep 17 00:00:00 2001 From: Samiser Date: Thu, 3 Sep 2026 18:04:06 +0100 Subject: [PATCH 38/50] noctalia: 5.0.0-beta.10 -> 5.0.1 Diff: https://github.com/noctalia-dev/noctalia/compare/v5.0.0-beta.10...v5.0.1 Changelog: https://noctalia.dev/changelogs#v5.0.1 (cherry picked from commit a3e6be660d46279c510f4f9c5400d3f7760281d4) --- pkgs/by-name/no/noctalia/package.nix | 13 +++---------- 1 file changed, 3 insertions(+), 10 deletions(-) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 20f5b5618324..23f563db01ab 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -66,13 +66,13 @@ stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; pname = "noctalia"; - version = "5.0.0-beta.10"; + version = "5.0.1"; src = fetchFromGitHub { owner = "noctalia-dev"; repo = "noctalia"; tag = "v${finalAttrs.version}"; - hash = "sha256-WijEuINvjcXMO/e/zMqwG1lyGiWNosnVt1QY+ko0Rw8="; + hash = "sha256-diS3b69rt/IqehH/8Tsd8/JEQmogVc1ml6FP+iTwBzg="; }; strictDeps = true; @@ -141,14 +141,7 @@ stdenv.mkDerivation (finalAttrs: { --prefix PATH : ${lib.makeBinPath [ gitMinimal ]} ''; - # remove --version=unstable once 5.0.0 stable is released - passthru.updateScript = nix-update-script { - extraArgs = [ - "--version=unstable" - "--version-regex" - "v(5\\..*)" - ]; - }; + passthru.updateScript = nix-update-script { }; meta = { description = "Sleek, customizable desktop shell crafted for Wayland"; From 67cfb3421dfafcc5991aa229e1468d8d7162a6f1 Mon Sep 17 00:00:00 2001 From: dish Date: Thu, 3 Sep 2026 13:29:05 -0400 Subject: [PATCH 39/50] noctalia: enable tests (cherry picked from commit f3db9db7d06e7d71ccf404780ae79fd081f949f5) --- pkgs/by-name/no/noctalia/package.nix | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 23f563db01ab..3489cb046358 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -42,6 +42,7 @@ stb, systemdLibs, tomlplusplus, + tzdata, wayland, wayland-protocols, wireplumber, @@ -122,7 +123,7 @@ stdenv.mkDerivation (finalAttrs: { ]; mesonFlags = [ - (lib.mesonEnable "tests" false) + (lib.mesonEnable "tests" true) (lib.mesonEnable "jemalloc" (!stdenv.hostPlatform.isMusl)) ]; @@ -141,6 +142,13 @@ stdenv.mkDerivation (finalAttrs: { --prefix PATH : ${lib.makeBinPath [ gitMinimal ]} ''; + doCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + + nativeCheckInputs = [ + tzdata + gitMinimal + ]; + passthru.updateScript = nix-update-script { }; meta = { From 29d176e97ce227990fe5abe6f5f810309ef357ab Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Fri, 4 Sep 2026 15:00:28 +0200 Subject: [PATCH 40/50] perfetto-sdk: init at 58.3 (cherry picked from commit 6ab4307de0ccbbb2c51a36ec3610280fcfebd433) --- pkgs/by-name/pe/perfetto-sdk/package.nix | 7 +++++++ pkgs/by-name/pe/perfetto/package.nix | 4 ++++ 2 files changed, 11 insertions(+) create mode 100644 pkgs/by-name/pe/perfetto-sdk/package.nix diff --git a/pkgs/by-name/pe/perfetto-sdk/package.nix b/pkgs/by-name/pe/perfetto-sdk/package.nix new file mode 100644 index 000000000000..30ffc38d2a3b --- /dev/null +++ b/pkgs/by-name/pe/perfetto-sdk/package.nix @@ -0,0 +1,7 @@ +{ + perfetto, + ... +}@args: + +# Alias to perfetto.sdk to improve discoverability +(perfetto.override (removeAttrs args [ "perfetto" ])).sdk diff --git a/pkgs/by-name/pe/perfetto/package.nix b/pkgs/by-name/pe/perfetto/package.nix index 87258b56da60..0e966d44b1d3 100644 --- a/pkgs/by-name/pe/perfetto/package.nix +++ b/pkgs/by-name/pe/perfetto/package.nix @@ -239,6 +239,10 @@ stdenv.mkDerivation (finalAttrs: { runHook postInstall ''; + passthru = { + inherit (finalAttrs.passthru) updateScript tests; + }; + meta = { inherit (finalAttrs.meta) homepage From 153ed294af91eed7ea8c70fdfcc97fed83bbce7d Mon Sep 17 00:00:00 2001 From: Samiser Date: Fri, 4 Sep 2026 15:53:09 +0100 Subject: [PATCH 41/50] noctalia: pin libqalculate 5.12.0 Not-cherry-picked-because: stable-only pin, master already builds against libqalculate 5.12.0 --- pkgs/by-name/no/noctalia/package.nix | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 3489cb046358..a11c7f1cbcf9 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -62,6 +62,16 @@ let hash = "sha256-BlyXJtAI7WqXCTT3ylww8zoG0hBxaojJnQDvdQOXJPE="; }; }; + # libqalculate 5.10.0 makes noctalia segfault, 5.12.0 works + libqalculate' = libqalculate.overrideAttrs { + version = "5.12.0"; + src = fetchFromGitHub { + owner = "qalculate"; + repo = "libqalculate"; + tag = "v5.12.0"; + hash = "sha256-f9FzFcu2LtBM6B6apYo7uobeR5uZVb02FxX7Kng/rRI="; + }; + }; in stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; @@ -99,7 +109,7 @@ stdenv.mkDerivation (finalAttrs: { libGL libical libjxl - libqalculate + libqalculate' librsvg libsecret libsndfile From 665dca44ce699475fdac6f3cd2b2c5757ac56d8f Mon Sep 17 00:00:00 2001 From: Samiser Date: Wed, 22 Jul 2026 09:47:37 +0000 Subject: [PATCH 42/50] maintainers: add samiser (cherry picked from commit bebbad7e363b91bb167d623cb73248b583e6f38c) --- maintainers/maintainer-list.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index b4b140190e7e..1be62bb31e4a 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -24460,6 +24460,12 @@ githubId = 47582; name = "Samir Talwar"; }; + samiser = { + email = "nixos@me.samiser.xyz"; + github = "samiser"; + githubId = 32001364; + name = "Sam"; + }; samlich = { email = "nixos@samli.ch"; github = "samlich"; From 6086b36645c880e7267c1501f02b4fb21d508296 Mon Sep 17 00:00:00 2001 From: phanirithvij Date: Wed, 19 Aug 2026 20:59:11 +0530 Subject: [PATCH 43/50] git-pages.services.default: init Co-authored-by: Tom Oostveen Co-authored-by: Bart Oostveen Signed-off-by: phanirithvij (cherry picked from commit 775afc1dbc041bd3a4de321fa7988e7fb91dc207) --- .../misc/documentation/modular-services.nix | 1 + nixos/tests/all-tests.nix | 1 + nixos/tests/git-pages.nix | 65 ++++++++++ pkgs/by-name/gi/git-pages/package.nix | 25 +++- pkgs/by-name/gi/git-pages/service.nix | 116 ++++++++++++++++++ 5 files changed, 207 insertions(+), 1 deletion(-) create mode 100644 nixos/tests/git-pages.nix create mode 100644 pkgs/by-name/gi/git-pages/service.nix diff --git a/nixos/modules/misc/documentation/modular-services.nix b/nixos/modules/misc/documentation/modular-services.nix index edc60d3bb592..65a2071813a5 100644 --- a/nixos/modules/misc/documentation/modular-services.nix +++ b/nixos/modules/misc/documentation/modular-services.nix @@ -20,6 +20,7 @@ let modularServicesModule = { options = { "" = fakeSubmodule pkgs.ghostunnel.services.default; + "" = fakeSubmodule pkgs.git-pages.services.default; "" = fakeSubmodule pkgs.ktls-utils.services.default; "" = fakeSubmodule pkgs.php.services.default; "" = fakeSubmodule pkgs.snid.services.default; diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 8ca70336a517..44942cc2379d 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -671,6 +671,7 @@ in geth = runTest ./geth.nix; ghostunnel = runTest ./ghostunnel.nix; ghostunnel-modular = runTest ./ghostunnel-modular.nix; + git-pages-modular = runTest ./git-pages.nix; gitdaemon = runTest ./gitdaemon.nix; gitea = handleTest ./gitea.nix { giteaPackage = pkgs.gitea; }; github-runner = runTest ./github-runner.nix; diff --git a/nixos/tests/git-pages.nix b/nixos/tests/git-pages.nix new file mode 100644 index 000000000000..c7e19b7cf846 --- /dev/null +++ b/nixos/tests/git-pages.nix @@ -0,0 +1,65 @@ +{ pkgs, ... }: +{ + name = "git-pages-modular-service"; + + nodes.machine = { pkgs, ... }: { + environment.systemPackages = [ pkgs.curl ]; + + system.services.git-pages = { + imports = [ pkgs.git-pages.services.default ]; + git-pages = { + settings.server = { + pages = "tcp/:3000"; + caddy = "tcp/:3001"; + metrics = "tcp/:3002"; + }; + }; + systemd.service.environment.PAGES_INSECURE = "1"; + }; + + services.caddy = { + enable = true; + configFile = pkgs.writeText "Caddyfile" '' + { + admin off + persist_config off + auto_https disable_redirects + on_demand_tls { + permission http http://localhost:3001 + } + } + https://, http:// { + tls { + on_demand + } + reverse_proxy http://localhost:3000 + } + ''; + }; + + networking.firewall.allowedTCPPorts = [ 80 ]; + }; + + testScript = + let + testSite = pkgs.runCommand "git-pages-testsite.tar" { } '' + echo It works! > index.html + tar cvf $out index.html + ''; + in + '' + start_all() + + machine.wait_for_unit("caddy.service") + machine.wait_for_open_port(80) + machine.wait_for_unit("git-pages.service") + machine.wait_for_open_port(3001) + machine.wait_for_open_port(3002) + machine.fail("curl -f http://localhost/.git-pages/health") + machine.succeed("curl -f http://localhost/ -X PUT --data-binary @${testSite} --header 'Content-Type: application/x-tar'") + machine.wait_until_succeeds("test -f /var/lib/git-pages/data/site/localhost/.index") + machine.succeed("curl -f http://localhost/.git-pages/health") + machine.succeed("curl -f http://localhost/ | grep -F 'It works!'") + machine.succeed("curl -f http://localhost:3002/metrics") + ''; +} diff --git a/pkgs/by-name/gi/git-pages/package.nix b/pkgs/by-name/gi/git-pages/package.nix index 311f34df1061..d51fd4513585 100644 --- a/pkgs/by-name/gi/git-pages/package.nix +++ b/pkgs/by-name/gi/git-pages/package.nix @@ -2,8 +2,12 @@ lib, buildGoModule, fetchFromCodeberg, + fetchpatch, nix-update-script, versionCheckHook, + formats, + coreutils, + nixosTests, }: buildGoModule (finalAttrs: { @@ -18,6 +22,16 @@ buildGoModule (finalAttrs: { hash = "sha256-4yQ3RRJbOfMaqjJJ6CRRN7TuaYY8ScLXxMZPd4tWPwk="; }; + patches = [ + # bugfix to avoid creating parent directory on start + # remove when https://codeberg.org/git-pages/git-pages/pulls/258 is available in the release + (fetchpatch { + name = "mkdirall-parent-dir-create.patch"; + url = "https://codeberg.org/git-pages/git-pages/commit/507e57edbcfc0ec933a877bf26b1756ca0a61870.patch"; + hash = "sha256-1CjU4yGmDOmYsxo3U44Cg2xLJkrmUOX5ZXTycdLs6OE="; + }) + ]; + subPackages = [ "." ]; vendorHash = "sha256-NNIkzgRki2rtCVUnnhT44rEBcMZYiJPmsXySpxiHYR0="; @@ -31,7 +45,16 @@ buildGoModule (finalAttrs: { nativeInstallCheckInputs = [ versionCheckHook ]; versionCheckProgramArg = "-version"; - passthru.updateScript = nix-update-script { }; + passthru = { + tests = { inherit (nixosTests) git-pages-modular; }; + updateScript = nix-update-script { }; + services.default = { + imports = [ + (lib.modules.importApply ./service.nix { inherit formats coreutils; }) + ]; + git-pages.package = finalAttrs.finalPackage; + }; + }; meta = { description = "Scalable static site server for Git forges (like GitHub Pages or Netlify"; diff --git a/pkgs/by-name/gi/git-pages/service.nix b/pkgs/by-name/gi/git-pages/service.nix new file mode 100644 index 000000000000..61c8b645d0ad --- /dev/null +++ b/pkgs/by-name/gi/git-pages/service.nix @@ -0,0 +1,116 @@ +# Non-module dependencies (`importApply`) +{ formats, coreutils }: + +{ + config, + lib, + options, + name, + ... +}: +let + cfg = config.git-pages; + settingsFormat = formats.toml { }; + configFile = "git-pages.toml"; + configOutPath = config.configData.${configFile}.path; +in +{ + _class = "service"; + + meta.maintainers = with lib.maintainers; [ + dtomvan + phanirithvij + ]; + + options.git-pages = { + package = lib.mkOption { + description = "Package to use for git-pages"; + defaultText = "The git-pages package that provided this module."; + type = lib.types.package; + }; + + secretFile = lib.mkOption { + description = '' + File that contains secrets for the git-pages config. + If values in this file are set, any options specified take priority over the options set in + {option}`git-pages.settings`. + + ::: {.note} + See the [git-pages documentation](https://git-pages.org/running-a-server/#configuration) on + secrets and environment variables. + ::: + ''; + default = null; + type = lib.types.nullOr lib.types.str; + }; + settings = lib.mkOption { + type = settingsFormat.type; + description = '' + Settings to set in config.toml. + + ::: {.note} + See the [git-pages documentation](https://git-pages.org/running-a-server/#configuration) on configuring the server. + ::: + ''; + default = { }; + }; + }; + + config = { + git-pages.settings.storage.fs.root = lib.mkDefault "/var/lib/${name}/data"; + + process.argv = [ + (lib.getExe cfg.package) + "-config" + configOutPath + ]; + + configData."${configFile}".source = settingsFormat.generate configFile cfg.settings; + } + // lib.optionalAttrs (options ? systemd) { + systemd.service = { + description = "Forge-agnostic static site server"; + documentation = [ "https://git-pages.org/running-a-server/" ]; + + after = [ "network.target" ]; + wants = [ "network.target" ]; + wantedBy = [ "multi-user.target" ]; + restartTriggers = [ config.configData."${configFile}".source ]; + + serviceConfig = { + Restart = "always"; + + StateDirectory = name; + WorkingDirectory = "%S/${name}"; + BindReadOnlyPaths = [ configOutPath ]; + + LoadCredential = lib.optional (cfg.secretFile != null) "secrets.toml:${cfg.secretFile}"; + + User = name; + DynamicUser = true; + + # systemd service hardening + ProtectHome = true; + MemoryDenyWriteExecute = true; + PrivateDevices = true; + PrivateTmp = true; + ProtectSystem = "strict"; + ProtectControlGroups = true; + RestrictSUIDSGID = true; + RestrictRealtime = true; + RestrictAddressFamilies = "AF_INET AF_INET6 AF_UNIX"; + RestrictNamespaces = true; + LockPersonality = true; + ProtectKernelLogs = true; + ProtectKernelTunables = true; + ProtectHostname = true; + ProtectKernelModules = true; + PrivateUsers = true; + ProtectClock = true; + SystemCallArchitectures = "native"; + SystemCallErrorNumber = "EPERM"; + SystemCallFilter = "@system-service"; + }; + }; + }; +} From 5c56e091e08b431896553ad7293d533d750ee711 Mon Sep 17 00:00:00 2001 From: dish Date: Fri, 4 Sep 2026 12:25:31 -0400 Subject: [PATCH 44/50] noctalia-greeter: Run versionCheckHook (cherry picked from commit 83ba5b6ef04ad6e5bc296b39b1338f87d498d6d9) --- pkgs/by-name/no/noctalia-greeter/package.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/by-name/no/noctalia-greeter/package.nix b/pkgs/by-name/no/noctalia-greeter/package.nix index f14e6dd0a0ac..f73d41f32551 100644 --- a/pkgs/by-name/no/noctalia-greeter/package.nix +++ b/pkgs/by-name/no/noctalia-greeter/package.nix @@ -25,6 +25,7 @@ wayland-protocols, wlroots_0_20, + versionCheckHook, nix-update-script, }: @@ -80,6 +81,12 @@ stdenv.mkDerivation (finalAttrs: { wlroots_0_20 ]; + doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + versionCheckProgram = "${placeholder "out"}/bin/noctalia-greeter"; + nativeInstallCheckInputs = [ + versionCheckHook + ]; + passthru.updateScript = nix-update-script { }; meta = { From cc19db175e16629455f9bf2e51809dbe03f1586a Mon Sep 17 00:00:00 2001 From: dish Date: Fri, 4 Sep 2026 12:25:44 -0400 Subject: [PATCH 45/50] noctalia: run versionCheckHook (cherry picked from commit 39b29a23c7ec0170095cecbefd634d7b0f44bed5) --- pkgs/by-name/no/noctalia/package.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index a11c7f1cbcf9..4975e0787460 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -12,6 +12,7 @@ makeBinaryWrapper, autoAddDriverRunpath, installShellFiles, + versionCheckHook, # libraries cairo, @@ -159,6 +160,12 @@ stdenv.mkDerivation (finalAttrs: { gitMinimal ]; + doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + + nativeInstallCheckInputs = [ + versionCheckHook + ]; + passthru.updateScript = nix-update-script { }; meta = { From 31d557fd6cbb3354085645d1d0afb0e60086abec Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Fri, 4 Sep 2026 16:32:01 -0400 Subject: [PATCH 46/50] ci/github-script/bot: log pagination cursor This doesn't seem to change, even when it should. I suspect this is related to the rate limit errors. (cherry picked from commit 8cc85b1852f83243173cca8dc080645bb280c3c2) --- ci/github-script/bot.js | 3 +++ 1 file changed, 3 insertions(+) diff --git a/ci/github-script/bot.js b/ci/github-script/bot.js index 755b1f71dfdc..8748bc980c80 100644 --- a/ci/github-script/bot.js +++ b/ci/github-script/bot.js @@ -794,6 +794,7 @@ export default async ({ github, context, core, dry }) => { } else { // No stats.artifacts++, because this does not allow passing a custom token. // Thus, the upload will not happen with the app token, but the default github.token. + core.info(`pagination-cursor: ${cursor}`) await artifactClient.uploadArtifact( 'pagination-cursor', [uploadPath], @@ -803,6 +804,8 @@ export default async ({ github, context, core, dry }) => { }, ) } + } else { + core.info('pagination-cursor: ') } // Some items might be in both search results, so filtering out duplicates as well. From d9191b75771c1e191fa423c92c11b093f509202b Mon Sep 17 00:00:00 2001 From: Kenichi Kamiya Date: Wed, 2 Sep 2026 16:47:38 +0900 Subject: [PATCH 47/50] typescript-go: update repository The typescript-go repository was archived in early September 2026, and the announcement was merged two weeks ago: * https://web.archive.org/web/20260902083209/https://github.com/microsoft/typescript-go * https://github.com/microsoft/typescript-go/commit/89d5d5b2849a0db0957065889ca58536fa6d2e4a The directory structure changed in the new repository, so we need to add modRoot. (cherry picked from commit f871473cccced94c939db18962f4b5f922762b35) --- pkgs/by-name/ty/typescript-go/package.nix | 17 +++++++++-------- 1 file changed, 9 insertions(+), 8 deletions(-) diff --git a/pkgs/by-name/ty/typescript-go/package.nix b/pkgs/by-name/ty/typescript-go/package.nix index dedb43a35802..47b55c9086d0 100644 --- a/pkgs/by-name/ty/typescript-go/package.nix +++ b/pkgs/by-name/ty/typescript-go/package.nix @@ -20,12 +20,13 @@ buildGoModule (finalAttrs: { src = fetchFromGitHub { owner = "microsoft"; - repo = "typescript-go"; - tag = "typescript/v${finalAttrs.version}"; - hash = "sha256-fRejdQSwaxSS2pjHrbJO2CQgZS5lWJmBNEM/TgbJTJ8="; - fetchSubmodules = false; + repo = "typescript"; + tag = "v${finalAttrs.version}"; + hash = "sha256-j1AY4sf/Jb6uwOah35lrYooc7BnSeaZ2NO6Fx1zMj60="; }; + modRoot = "tsc"; + vendorHash = "sha256-q6dMb2ab4uZ3GTrcA7v2JzfmOM+ZzBcJN6gKOpLfM/k="; ldflags = [ @@ -53,7 +54,7 @@ buildGoModule (finalAttrs: { (nix-update-script { extraArgs = [ "--use-github-releases" - "--version-regex=^typescript/v([\\d.]+)$" + "--version-regex=^v([\\d.]+)$" "--src-only" ]; }) @@ -67,7 +68,7 @@ buildGoModule (finalAttrs: { ]; text = '' new_src="$(nix-build --attr 'pkgs.typescript-go.src' --no-out-link)" - new_go_major_minor="$(grep --only-matching --perl-regexp '^go \K([0-9]+\.[0-9]+)' "$new_src/go.mod")" + new_go_major_minor="$(grep --only-matching --perl-regexp '^go \K([0-9]+\.[0-9]+)' "$new_src/tsc/go.mod")" sed -i -E "s/buildGo[0-9]+Module/buildGo''${new_go_major_minor//./}Module/g" '${toString ./package.nix}' ''; })) @@ -81,8 +82,8 @@ buildGoModule (finalAttrs: { meta = { description = "Go implementation of TypeScript"; - homepage = "https://github.com/microsoft/typescript-go"; - changelog = "https://github.com/microsoft/typescript-go/releases/tag/typescript/v${finalAttrs.version}"; + homepage = "https://github.com/microsoft/typescript"; + changelog = "https://github.com/microsoft/typescript/releases/tag/v${finalAttrs.version}"; license = lib.licenses.asl20; maintainers = with lib.maintainers; [ kachick From 83ca8af6aabec6db9edc2704b6ed3260e107556f Mon Sep 17 00:00:00 2001 From: Kenichi Kamiya Date: Wed, 2 Sep 2026 17:40:59 +0900 Subject: [PATCH 48/50] typescript-go: enable __structuredAttrs (cherry picked from commit 9bdf768824312bc10da6587b37e4e81cf3fb65a5) --- pkgs/by-name/ty/typescript-go/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/ty/typescript-go/package.nix b/pkgs/by-name/ty/typescript-go/package.nix index 47b55c9086d0..5cb3d1e9aa25 100644 --- a/pkgs/by-name/ty/typescript-go/package.nix +++ b/pkgs/by-name/ty/typescript-go/package.nix @@ -18,6 +18,8 @@ buildGoModule (finalAttrs: { pname = "typescript-go"; version = "7.0.2"; + __structuredAttrs = true; + src = fetchFromGitHub { owner = "microsoft"; repo = "typescript"; From 531c1b0b4fec5f3c2adbf72986001a7ac43693c2 Mon Sep 17 00:00:00 2001 From: emilylange Date: Fri, 4 Sep 2026 22:42:24 +0200 Subject: [PATCH 49/50] ungoogled-chromium: 152.0.7977.75-1 -> 152.0.7977.82-1 https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html This update includes 12 security fixes. Google is aware that an exploit for CVE-2026-85046 exists in the wild. CVEs: CVE-2026-85046 CVE-2026-85052 CVE-2026-85043 CVE-2026-85048 CVE-2026-85045 CVE-2026-85050 CVE-2026-85053 CVE-2026-85042 CVE-2026-85049 CVE-2026-85051 CVE-2026-85047 CVE-2026-85044 (cherry picked from commit 98d09aad60ea8dee63eea14d5603c0c6ba4e0f80) --- .../networking/browsers/chromium/info.json | 22 +++++++++---------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/info.json b/pkgs/applications/networking/browsers/chromium/info.json index 191cd0d064ef..b8fff62700cd 100644 --- a/pkgs/applications/networking/browsers/chromium/info.json +++ b/pkgs/applications/networking/browsers/chromium/info.json @@ -853,7 +853,7 @@ } }, "ungoogled-chromium": { - "version": "152.0.7977.75", + "version": "152.0.7977.82", "deps": { "depot_tools": { "rev": "38c391feba5fb96812f9028da12413ffc39df394", @@ -865,16 +865,16 @@ "hash": "sha256-ovLx6KaORdXqnWgbsGEty10k2CHuCmTk3yEqy5//ovk=" }, "ungoogled-patches": { - "rev": "152.0.7977.75-1", - "hash": "sha256-HXWnJfk0SxC8sRcgtFdGBOOeiV7kEQD2YXQFBwMsU1s=" + "rev": "152.0.7977.82-1", + "hash": "sha256-5KxsbzpRybc/ub6HJbN6QkJVL4iDdoAXE7vwjtjAJXA=" }, "npmHash": "sha256-pF0JtwFpPC4/fodbhSJnQKkczA9WlDg4VqEAy9aDVLg=" }, "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "4999cc1efed37c4d91dc4ce6ec4b0a50e2a9a8cb", - "hash": "sha256-RXykREnCulCwk8zkk8OAd62TM4qel6j4uhyaaYzgolY=", + "rev": "d04cdb24d67b081f6cf80200ffc5233f44b61109", + "hash": "sha256-JiYTfMJBtUWMUSicQdSCXNUtgjLGeaMj4vCNpMvYACk=", "recompress": true }, "src/third_party/clang-format/script": { @@ -944,8 +944,8 @@ }, "src/third_party/angle": { "url": "https://chromium.googlesource.com/angle/angle.git", - "rev": "736ed80c7552a4b267bd54a282b971aa4555cb3e", - "hash": "sha256-3ZCIFT7j944HWPOiADQa88TQZctLej5vbrBFA/FwyHw=" + "rev": "7df613367a1d4ca9aea9ece344d4580d32d132a9", + "hash": "sha256-bYGok5QvWJoCfliRPQqrDz0ttKf1r9HoFxoC4qwdI3o=" }, "src/third_party/angle/third_party/glmark2/src": { "url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2", @@ -1524,8 +1524,8 @@ }, "src/third_party/skia": { "url": "https://skia.googlesource.com/skia.git", - "rev": "b6d106297ff9ef2ff8094033695d045e87775581", - "hash": "sha256-sun/P/JVhTKfRwmVK5dgnz8UZEFnQoyXZZS6PN5z9us=" + "rev": "0873ec164a06966b90ae0d43ef783cfb180084ae", + "hash": "sha256-LbSs+UNakFipC2t9TSbZVreylVXHf1PsbK6z2qJh6QI=" }, "src/third_party/smhasher/src": { "url": "https://chromium.googlesource.com/external/smhasher.git", @@ -1694,8 +1694,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "3de6ffffbfdcf265e9f11a5c9d1cfb4d486d7550", - "hash": "sha256-ZHEmeSe8r226gjazm91GYqlfbM9a5yi8KnFv4iAWFKE=" + "rev": "4323497a6a73839e6d5260f6acd7ec0212cb3321", + "hash": "sha256-HUg4GGtYL4xGk/xw0QXxNZAnsFVcznklWGQaqhZj9QM=" }, "src/agents/shared": { "url": "https://chromium.googlesource.com/chromium/agents.git", From ace4b0e9137e968bc661b0ab7aa477c9de47e339 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Fri, 4 Sep 2026 19:45:37 -0400 Subject: [PATCH 50/50] ci/github-script/bot: fix pagination (cherry picked from commit 2e4bd2166b42278e89fe89ea16cccbe17163f662) --- ci/github-script/bot.js | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/ci/github-script/bot.js b/ci/github-script/bot.js index 8748bc980c80..c1fba12c00c4 100644 --- a/ci/github-script/bot.js +++ b/ci/github-script/bot.js @@ -689,16 +689,21 @@ export default async ({ github, context, core, dry }) => { if (context.payload.pull_request) { await handle({ item: context.payload.pull_request, stats }) } else { + // We don't use filters here because that causes GitHub to use an often-outdated index, + // resulting in the cursor not being updated, and therefore causing the same PRs + // to use up our rate limit over and over again. const lastRun = ( await github.rest.actions.listWorkflowRuns({ ...context.repo, workflow_id: 'bot.yml', - event: 'schedule', - status: 'success', - exclude_pull_requests: true, - per_page: 1, }) - ).data.workflow_runs[0] + ).data.workflow_runs.find( + (run) => run.event === 'schedule' && run.conclusion === 'success', + ) + + core.info( + `Last successful run created at: ${lastRun?.created_at ?? ''}`, + ) const cutoff = new Date( Math.max(