From f2a1029a0a0aea1b1a8e18a5a0a80b601581597c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 4 Sep 2026 08:25:05 +0000 Subject: [PATCH 01/30] matrix-authentication-service: 1.23.0 -> 1.24.0 (cherry picked from commit a95105539d691fcbc275396dca50a334b99ab810) --- pkgs/by-name/ma/matrix-authentication-service/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/ma/matrix-authentication-service/package.nix b/pkgs/by-name/ma/matrix-authentication-service/package.nix index 96e2315b28bc..bd5429573904 100644 --- a/pkgs/by-name/ma/matrix-authentication-service/package.nix +++ b/pkgs/by-name/ma/matrix-authentication-service/package.nix @@ -20,21 +20,21 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "matrix-authentication-service"; - version = "1.23.0"; + version = "1.24.0"; src = fetchFromGitHub { owner = "element-hq"; repo = "matrix-authentication-service"; tag = "v${finalAttrs.version}"; - hash = "sha256-DnaVIMp+pRRsNlyBZiTiqXajOgGFBT38sNLmC+IF8pU="; + hash = "sha256-LWGnfM7os9GT6fa/Vk1wAEp9m1L5rEL7tSPmgEKMNfQ="; }; - cargoHash = "sha256-3fBikvSbPTiIYXk7TQKoQ/YqjF5ZCoN0xQRSqCmHF9Q="; + cargoHash = "sha256-jAJuRwhc+0IAikLyqctHuCQcS61iNj7iKWHJdRAqsAk="; pnpmDeps = fetchPnpmDeps { inherit (finalAttrs) pname version src; fetcherVersion = 4; - hash = "sha256-8dPqsa1/D4q7hdntV1AmbRxQyZgAf7Q/z+etj+R/jIE="; + hash = "sha256-DxEjMhYqZGbnobQ/F0WFXq7qaxSkWDcoZ0kmWJsdxEQ="; }; pnpmRoot = "frontend"; From ef1b2e6a3b18b9cc96936dc4325daa26bcb66402 Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Sun, 6 Sep 2026 22:31:45 +0200 Subject: [PATCH 02/30] rabbitmq-server: 4.2.5 -> 4.2.9 https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.9 https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.8 https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.7 https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 Fixes https://github.com/NixOS/nixpkgs/issues/542112 Fixes CVE-2026-57220, CVE-2026-57215, CVE-2026-57217, CVE-2026-57216, CVE-2026-57221, CVE-2026-57219, CVE-2026-57218 and CVE-2026-57211. Not-cherry-picked-because: unstable has been bumped to 4.3.x. --- pkgs/by-name/ra/rabbitmq-server/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ra/rabbitmq-server/package.nix b/pkgs/by-name/ra/rabbitmq-server/package.nix index 31fe4e99d498..c6828793ea6b 100644 --- a/pkgs/by-name/ra/rabbitmq-server/package.nix +++ b/pkgs/by-name/ra/rabbitmq-server/package.nix @@ -46,12 +46,12 @@ in stdenv.mkDerivation (finalAttrs: { pname = "rabbitmq-server"; - version = "4.2.5"; + version = "4.2.9"; # when updating, consider bumping elixir version in all-packages.nix src = fetchurl { url = "https://github.com/rabbitmq/rabbitmq-server/releases/download/v${finalAttrs.version}/${finalAttrs.pname}-${finalAttrs.version}.tar.xz"; - hash = "sha256-cI/imLX4pdZTl1HDKaE2WwOOaWpwC78KyqWHmxsFQj0="; + hash = "sha256-3enC+vDQcQh9WMKPpefxjwcYBTxLehJvlBfmixnFEIQ="; }; nativeBuildInputs = [ From 2798a785a67acefd39084a68580a9d83bc5d479d Mon Sep 17 00:00:00 2001 From: phanirithvij Date: Mon, 31 Aug 2026 18:20:44 +0530 Subject: [PATCH 03/30] repath-studio: fix flaky tests in sandbox Signed-off-by: phanirithvij (cherry picked from commit afeb7f7963f922b67532ec3b93c755500d345044) --- .../re/repath-studio/fix-karma-sandbox.patch | 23 +++++++++++++++++++ pkgs/by-name/re/repath-studio/package.nix | 2 ++ 2 files changed, 25 insertions(+) create mode 100644 pkgs/by-name/re/repath-studio/fix-karma-sandbox.patch diff --git a/pkgs/by-name/re/repath-studio/fix-karma-sandbox.patch b/pkgs/by-name/re/repath-studio/fix-karma-sandbox.patch new file mode 100644 index 000000000000..1c78fa1bc21c --- /dev/null +++ b/pkgs/by-name/re/repath-studio/fix-karma-sandbox.patch @@ -0,0 +1,23 @@ +--- a/karma.conf.js ++++ b/karma.conf.js +@@ -7,7 +7,7 @@ + customLaunchers: { + ChromeHeadlessNoSandbox: { + base: 'ChromeHeadless', +- flags: ['--no-sandbox'] ++ flags: ['--no-sandbox', '--disable-dev-shm-usage'] + }, + CustomElectron: { + base: 'Electron', +@@ -42,6 +42,10 @@ + outputDir: junitOutputDir + '/karma', // results will be saved as outputDir/browserName.xml + outputFile: undefined, // if included, results will be saved as outputDir/browserName/outputFile + suite: '' // suite will become the package name attribute in xml testsuite element +- } ++ }, ++ ++ browserDisconnectTimeout: 300000, ++ browserNoActivityTimeout: 300000, ++ pingTimeout: 300000 + }) + } diff --git a/pkgs/by-name/re/repath-studio/package.nix b/pkgs/by-name/re/repath-studio/package.nix index 5f62e0f037b1..9a3c24292f79 100644 --- a/pkgs/by-name/re/repath-studio/package.nix +++ b/pkgs/by-name/re/repath-studio/package.nix @@ -36,6 +36,8 @@ buildNpmPackage (finalAttrs: { # outputHash of clojureHome changes each time `clojure` is updated # https://github.com/ngi-nix/ngipkgs/pull/1727#discussion_r2470180998 ./pin-clojure.patch + # checks have become flaky in nix build sandbox, increase timeout and disable dev/shm for chrome + ./fix-karma-sandbox.patch ./0001-disable-auto-update-check.patch ]; From 6fc32748416d3cfc0f23d03f801eedd9f83aceea Mon Sep 17 00:00:00 2001 From: phanirithvij Date: Tue, 1 Sep 2026 13:34:32 +0530 Subject: [PATCH 04/30] nixosTests.repath-studio: fix failure on aarch64-linux (cherry picked from commit a11e6f1a69ceaf75671dac72ab30d4f183624400) --- nixos/tests/repath-studio.nix | 30 +++++++++++++++++++++--------- 1 file changed, 21 insertions(+), 9 deletions(-) diff --git a/nixos/tests/repath-studio.nix b/nixos/tests/repath-studio.nix index e6761b94ac58..030b597a5f2e 100644 --- a/nixos/tests/repath-studio.nix +++ b/nixos/tests/repath-studio.nix @@ -53,16 +53,28 @@ machine.screenshot("Repath-Studio-GUI-Welcome") machine.send_key("kp_enter") # OK - # sleep is required it needs time to dismiss the dialog + # move the mouse to the "Save" icon on the toolbar + machine.execute("su - alice -c \"DISPLAY=:0 xdotool mousemove --sync 95 65\"") + + # click the save icon until the GTK save dialog appears + for _ in range(30): + status, _ = machine.execute("su - alice -c \"DISPLAY=:0 xdotool search --name 'Save File'\"") + if status == 0: + break + machine.execute("su - alice -c \"DISPLAY=:0 xdotool click 1\"") + machine.sleep(1) + + # wait for the GTK dialog to focus the text input field + machine.sleep(3) + machine.send_chars("saved.rps") # avoid using absolute path here, doesn't work for some reason + # wait for text to be typed machine.sleep(2) - machine.send_key("ctrl-shift-s") - machine.sleep(2) - machine.send_chars("/tmp/saved.rps") - machine.sleep(2) - machine.succeed("su - alice -c 'DISPLAY=:0 xdotool mousemove --sync 975 745 click 1'") # Save file dialog - machine.sleep(2) - print(machine.succeed("cat /tmp/saved.rps")) - assert "${pkgs.repath-studio.version}" in machine.succeed("cat /tmp/saved.rps") + + machine.execute("su - alice -c \"DISPLAY=:0 xdotool key alt+s\"") # save file + machine.wait_until_succeeds("ls /home/alice/saved.rps") + + machine.succeed("cat /home/alice/saved.rps") + assert "${pkgs.repath-studio.version}" in machine.succeed("cat /home/alice/saved.rps") machine.screenshot("Repath-Studio-GUI") ''; From da78167cc50f7327fa0e3190c11f18fac55c4494 Mon Sep 17 00:00:00 2001 From: Diogo Correia Date: Wed, 19 Aug 2026 19:54:08 +0100 Subject: [PATCH 05/30] umami: 3.2.0 -> 3.3.1 (cherry picked from commit 65dcd01ab6a75208ddfe05c5a8dfb4e54b3a61bc) --- pkgs/by-name/um/umami/package.nix | 60 +++++++++++++++++------------- pkgs/by-name/um/umami/sources.json | 6 +-- 2 files changed, 38 insertions(+), 28 deletions(-) diff --git a/pkgs/by-name/um/umami/package.nix b/pkgs/by-name/um/umami/package.nix index 2e68c5304f4b..2bfc4ef968eb 100644 --- a/pkgs/by-name/um/umami/package.nix +++ b/pkgs/by-name/um/umami/package.nix @@ -9,7 +9,7 @@ nodejs, fetchPnpmDeps, pnpmConfigHook, - pnpm_10, + pnpm_11, prisma_7, prisma-engines_7, openssl, @@ -20,7 +20,7 @@ basePath ? "", }: let - pnpm = pnpm_10; + pnpm = pnpm_11; sources = lib.importJSON ./sources.json; @@ -46,14 +46,14 @@ let # to guarantee compatibility. prisma-engines' = prisma-engines_7.overrideAttrs ( finalAttrs: prevAttrs: { - version = "7.8.0"; + version = "7.9.1"; src = fetchFromGitHub { owner = "prisma"; repo = "prisma-engines"; tag = finalAttrs.version; - hash = "sha256-nquIcOmFz+ikD0x/YEPZ5NVKCFPCdR5MSCHldn+b9jI="; + hash = "sha256-bGtVKGoWZc/3s0lhTXksp+6fM/Q461ve/HQsRPxWD0Q="; }; - cargoHash = "sha256-uiFvzxwVJXCW9LUDFRC6ZkzSa7LQk+9ZJcaJw8mrBX4="; + cargoHash = "sha256-zLl2ErsCTXZVShPFLH94GLJ0q2FrMnfnecnfKD7VDL4="; cargoDeps = rustPlatform.fetchCargoVendor { inherit (prevAttrs) pname; @@ -63,25 +63,31 @@ let }; } ); - prisma' = (prisma_7.override { prisma-engines_7 = prisma-engines'; }).overrideAttrs ( - finalAttrs: prevAttrs: { - version = "7.8.0"; - src = fetchFromGitHub { - owner = "prisma"; - repo = "prisma"; - tag = finalAttrs.version; - hash = "sha256-89q5433z54h3oGX+lEYDQykN2mNltGz4+LWlYSE75/E="; - }; - pnpmDeps = prevAttrs.pnpmDeps.override { - inherit (finalAttrs) src version; - hash = "sha256-mrFU5SAF4QuTBJj5TP8tUkYDG4zchttjcQMLtx6OBnI="; - }; - } - ); + prisma' = + (prisma_7.override { + prisma-engines_7 = prisma-engines'; + pnpm_10 = pnpm_11; + }).overrideAttrs + ( + finalAttrs: prevAttrs: { + version = "7.9.1"; + src = fetchFromGitHub { + owner = "prisma"; + repo = "prisma"; + tag = finalAttrs.version; + hash = "sha256-h89lJbGG2ZkK3Viipsqe8hqTSTZk6vEulaMLPPkgn8c="; + }; + pnpmDeps = prevAttrs.pnpmDeps.override { + inherit (finalAttrs) src version; + fetcherVersion = 4; + hash = "sha256-EEfVAdF6QawXV95NUmEL9IqzPqazCz47Y9Hg/F6IybU="; + }; + } + ); in stdenvNoCC.mkDerivation (finalAttrs: { pname = "umami"; - version = "3.2.0"; + version = "3.3.1"; nativeBuildInputs = [ makeWrapper @@ -94,17 +100,21 @@ stdenvNoCC.mkDerivation (finalAttrs: { owner = "umami-software"; repo = "umami"; tag = "v${finalAttrs.version}"; - hash = "sha256-0nfCcaST06cTg43Rz1rCV8GYYDjQLP+6TrVRJF2/Yuk="; + hash = "sha256-LldK8dv3mkgEB9LWzt4X/bfh474G4LWOtJghTo5/n7A="; }; - # Umami uses next/font/google, which tries to download from Google Fonts at build time. - # Replace that code with a copy of the required font(s) from nixpkgs instead. postPatch = '' + # Umami uses next/font/google, which tries to download from Google Fonts at build time. + # Replace that code with a copy of the required font(s) from nixpkgs instead. substituteInPlace ./src/app/layout.tsx \ --replace-fail "import { Inter } from 'next/font/google';" "import localFont from 'next/font/local';" \ --replace-fail 'const inter = Inter({' "const inter = localFont({ src: './Inter.ttf'," cp "${inter}/share/fonts/truetype/InterVariable.ttf" src/app/Inter.ttf + + # Biome executable needs to be patched to run, but we don't need to format code anyway, so just skip it. + substituteInPlace ./package.json \ + --replace-fail ' && biome format --write src/tracker/index.d.ts' ''' ''; pnpmDeps = fetchPnpmDeps { @@ -115,7 +125,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { ; inherit pnpm; fetcherVersion = 4; - hash = "sha256-6ho5xoVdqZdihThL5q8+RhVPfaSwu1y3+p9d8DnfO3o="; + hash = "sha256-253jfz20wXwh/8/d7KVEl4jlaj7IURWJrW2/F0FS4BI="; }; env.NODE_ENV = "production"; diff --git a/pkgs/by-name/um/umami/sources.json b/pkgs/by-name/um/umami/sources.json index 0680e40a0888..1e2c6bd0cb38 100644 --- a/pkgs/by-name/um/umami/sources.json +++ b/pkgs/by-name/um/umami/sources.json @@ -1,7 +1,7 @@ { "geocities": { - "rev": "04017f13909e499135afea605a1e07427e845641", - "date": "2026-07-02", - "hash": "sha256-4IYGsxNGdzilI0mYXlwEo43auqNug307pYyPuilR3aw=" + "rev": "f9f57fe9861c93e7dacf53671b22ea3afe4768ba", + "date": "2026-08-20", + "hash": "sha256-4B78nMlzsXTAosnTgjYrl2YiWLYEWs3Xois8o6BZIuM=" } } From 1764ad8cebae29f0512fb0bc960378b04f70b76e Mon Sep 17 00:00:00 2001 From: Pascal Dietrich Date: Fri, 4 Sep 2026 17:11:41 +0200 Subject: [PATCH 06/30] tauno-monitor: 0.2.20 -> 0.2.24 (cherry picked from commit 4dfff6adc31d02cdccc92fdc12f144071a0a1530) --- pkgs/by-name/ta/tauno-monitor/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ta/tauno-monitor/package.nix b/pkgs/by-name/ta/tauno-monitor/package.nix index 9a02cdd189b5..0899eec44de4 100644 --- a/pkgs/by-name/ta/tauno-monitor/package.nix +++ b/pkgs/by-name/ta/tauno-monitor/package.nix @@ -14,7 +14,7 @@ }: python3Packages.buildPythonApplication (finalAttrs: { pname = "tauno-monitor"; - version = "0.2.20"; + version = "0.2.24"; pyproject = false; __structuredAttrs = true; @@ -23,7 +23,7 @@ python3Packages.buildPythonApplication (finalAttrs: { owner = "taunoe"; repo = "tauno-monitor"; tag = "v${finalAttrs.version}"; - hash = "sha256-rtFnWK1K4S866lgR/lGaTB+REqDExKsEFePX8cwai5E="; + hash = "sha256-HtoXdKKa/2nvBZVUXSrXH/7JHzdQObjW+7QTx/e8IWo="; }; nativeBuildInputs = [ From 789a08b304dc87355485d11ef06efac78aca7ce5 Mon Sep 17 00:00:00 2001 From: Pascal Dietrich Date: Fri, 4 Sep 2026 17:16:39 +0200 Subject: [PATCH 07/30] andcli: 2.8.1 -> 2.9.0 (cherry picked from commit eb209e0afb150c9f4997f015823b5dffdc164875) --- pkgs/by-name/an/andcli/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/an/andcli/package.nix b/pkgs/by-name/an/andcli/package.nix index 1c819c2fb3fd..f0293cc4a704 100644 --- a/pkgs/by-name/an/andcli/package.nix +++ b/pkgs/by-name/an/andcli/package.nix @@ -9,7 +9,7 @@ buildGoModule (finalAttrs: { pname = "andcli"; - version = "2.8.1"; + version = "2.9.0"; __structuredAttrs = true; @@ -19,10 +19,10 @@ buildGoModule (finalAttrs: { owner = "tjblackheart"; repo = "andcli"; tag = "v${finalAttrs.version}"; - hash = "sha256-BVF+r8N+/PvARxANlL7nPf23ABbp+O1DNPblMyXroq8="; + hash = "sha256-ls/QWEAxxnsersk7L3AaRo5jo1Vsao61c2mgjt91sAQ="; }; - vendorHash = "sha256-aFOwfloqFPPMgCufwmDgfM9lDinkFvu4i+BiVUo+Iwk="; + vendorHash = "sha256-+qz2vIh4GTkdmhjGvYqJYZ9ZMI9f+yXObmyGHk/5Cyg="; ldflags = [ "-s" From 18dc58fcce632515fc07a1b3b82bd0793b7a362b Mon Sep 17 00:00:00 2001 From: David McFarland Date: Fri, 28 Aug 2026 12:51:23 -0300 Subject: [PATCH 08/30] godot3: add updateScript (cherry picked from commit ba6dfda54cd7cae81b003fc3c6d4403b9474f2eb) --- pkgs/development/tools/godot/3/default.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/pkgs/development/tools/godot/3/default.nix b/pkgs/development/tools/godot/3/default.nix index 4e5fdcc04a2d..7928cb6ee011 100644 --- a/pkgs/development/tools/godot/3/default.nix +++ b/pkgs/development/tools/godot/3/default.nix @@ -18,6 +18,7 @@ libxrandr, libxrender, makeWrapper, + nix-update-script, openssl, pkg-config, scons, @@ -170,6 +171,13 @@ stdenv.mkDerivation (finalAttrs: { ] ); + passthru.updateScript = nix-update-script { + extraArgs = [ + "--version-regex" + "(3\\..*)-stable" + ]; + }; + meta = { homepage = "https://godotengine.org"; description = From f8d27a3abaa989e6914071dce25332b9f3a05476 Mon Sep 17 00:00:00 2001 From: David McFarland Date: Fri, 28 Aug 2026 12:54:08 -0300 Subject: [PATCH 09/30] godot3: add version test (cherry picked from commit d57054688da331996ffe83d5c56ffc229fa9786c) --- pkgs/development/tools/godot/3/default.nix | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/pkgs/development/tools/godot/3/default.nix b/pkgs/development/tools/godot/3/default.nix index 7928cb6ee011..aa72be732963 100644 --- a/pkgs/development/tools/godot/3/default.nix +++ b/pkgs/development/tools/godot/3/default.nix @@ -22,6 +22,7 @@ openssl, pkg-config, scons, + testers, udev, yasm, zlib, @@ -171,11 +172,17 @@ stdenv.mkDerivation (finalAttrs: { ] ); - passthru.updateScript = nix-update-script { - extraArgs = [ - "--version-regex" - "(3\\..*)-stable" - ]; + passthru = { + tests.version = testers.testVersion { + package = finalAttrs.finalPackage; + }; + + updateScript = nix-update-script { + extraArgs = [ + "--version-regex" + "(3\\..*)-stable" + ]; + }; }; meta = { From ba16ad48fd2c067f133e44e1fdb6a20862f219d5 Mon Sep 17 00:00:00 2001 From: David McFarland Date: Fri, 28 Aug 2026 13:18:35 -0300 Subject: [PATCH 10/30] godot/3/mono/update-glue-version.sh: specify shell for shellcheck (cherry picked from commit fed0095c5c8831ebd6e262aeb3a69d152cc44574) --- pkgs/development/tools/godot/3/mono/update-glue-version.sh | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/tools/godot/3/mono/update-glue-version.sh b/pkgs/development/tools/godot/3/mono/update-glue-version.sh index 8c779b005f3f..ea7680ba1c16 100755 --- a/pkgs/development/tools/godot/3/mono/update-glue-version.sh +++ b/pkgs/development/tools/godot/3/mono/update-glue-version.sh @@ -1,5 +1,6 @@ #! /usr/bin/env nix-shell #! nix-shell -i bash -p steam-run unzip wget +# shellcheck shell=bash # This script updates the hard-coded glue_version in: # From 570bedd60820f68bb828cf3d5b34f73932099524 Mon Sep 17 00:00:00 2001 From: David McFarland Date: Fri, 28 Aug 2026 13:18:56 -0300 Subject: [PATCH 11/30] godot/3/mono/update-glue-version.sh: fix leaking temp dirs (cherry picked from commit ccaee4821170c1dfea4ca8527c35ad5734314254) --- .../tools/godot/3/mono/update-glue-version.sh | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/pkgs/development/tools/godot/3/mono/update-glue-version.sh b/pkgs/development/tools/godot/3/mono/update-glue-version.sh index ea7680ba1c16..6779b1f6b617 100755 --- a/pkgs/development/tools/godot/3/mono/update-glue-version.sh +++ b/pkgs/development/tools/godot/3/mono/update-glue-version.sh @@ -15,14 +15,16 @@ set -e gdversion=$1 # Download and extract the official stable 64-bit X11 mono build of Godot. -gddir="$(mktemp -d)" -trap 'rm -rf -- "$gddir"' EXIT +tmpdir="$(mktemp -d)" +trap 'rm -rf -- "$tmpdir"' EXIT +gddir="$tmpdir"/gd +gluedir="$tmpdir"/glue +mkdir -p "$gddir" "$gludir" + wget -O "$gddir"/Godot_v$gdversion-stable_mono_x11_64.zip "https://downloads.godotengine.org/?version=$gdversion&flavor=stable&slug=mono_x11_64.zip&platform=linux.64" unzip "$gddir"/Godot_v$gdversion-stable_mono_x11_64.zip -d "$gddir" # Generate the mono glue from the official build. -gluedir="$(mktemp -d)" -trap 'rm -rf -- "$gluedir"' EXIT steam-run "$gddir"/Godot_v$gdversion-stable_mono_x11_64/Godot_v$gdversion-stable_mono_x11.64 --generate-mono-glue "$gluedir" # Extract the glue version. From 914ad76208953e1d2b4b951baf7a7e1c116604b4 Mon Sep 17 00:00:00 2001 From: David McFarland Date: Fri, 28 Aug 2026 13:51:27 -0300 Subject: [PATCH 12/30] godot3: update mono glue in updateScript This replaces the use of steam-run with patchelf, so unfree packages aren't needed in evaluation. (cherry picked from commit 99ad7f3c98551045056aaef71a9887789588a93b) --- pkgs/development/tools/godot/3/default.nix | 35 +++++++++++++++---- .../tools/godot/3/mono/update-glue-version.sh | 17 +++++---- 2 files changed, 39 insertions(+), 13 deletions(-) diff --git a/pkgs/development/tools/godot/3/default.nix b/pkgs/development/tools/godot/3/default.nix index aa72be732963..858f1fae90fc 100644 --- a/pkgs/development/tools/godot/3/default.nix +++ b/pkgs/development/tools/godot/3/default.nix @@ -1,12 +1,14 @@ { lib, stdenv, + _experimental-update-script-combinators, alsa-lib, alsa-plugins, autoPatchelfHook, fetchFromGitHub, freetype, installShellFiles, + libGL, libGLU, libpulseaudio, libx11, @@ -24,6 +26,7 @@ scons, testers, udev, + writeScriptBin, yasm, zlib, }: @@ -177,12 +180,32 @@ stdenv.mkDerivation (finalAttrs: { package = finalAttrs.finalPackage; }; - updateScript = nix-update-script { - extraArgs = [ - "--version-regex" - "(3\\..*)-stable" - ]; - }; + updateScript = _experimental-update-script-combinators.sequence [ + (nix-update-script { + extraArgs = [ + "--version-regex" + "(3\\..*)-stable" + ]; + }) + ./mono/update-glue-version.sh + ]; + + patch-godot-bin = + let + libPath = lib.makeLibraryPath [ + libxcursor + libxinerama + libxext + libxrandr + libxrender + libx11 + libxi + libGL + ]; + in + writeScriptBin "patch-godot-bin" '' + patchelf --set-interpreter "${stdenv.cc.bintools.dynamicLinker}" --set-rpath "${libPath}" "$1" + ''; }; meta = { diff --git a/pkgs/development/tools/godot/3/mono/update-glue-version.sh b/pkgs/development/tools/godot/3/mono/update-glue-version.sh index 6779b1f6b617..9bb5b56e8519 100755 --- a/pkgs/development/tools/godot/3/mono/update-glue-version.sh +++ b/pkgs/development/tools/godot/3/mono/update-glue-version.sh @@ -1,5 +1,5 @@ #! /usr/bin/env nix-shell -#! nix-shell -i bash -p steam-run unzip wget +#! nix-shell -i bash -p unzip wget godot3.patch-godot-bin -I nixpkgs=. # shellcheck shell=bash # This script updates the hard-coded glue_version in: @@ -10,27 +10,30 @@ set -e -[ -z "$1" ] && echo "Godot version not specified. Exiting." && exit 1 - -gdversion=$1 +if [[ -z "$1" ]]; then + gdversion=$(nix-instantiate --eval --raw -A ${UPDATE_NIX_ATTR_PATH:-godot3}.version) +else + gdversion=$1 +fi # Download and extract the official stable 64-bit X11 mono build of Godot. tmpdir="$(mktemp -d)" trap 'rm -rf -- "$tmpdir"' EXIT gddir="$tmpdir"/gd gluedir="$tmpdir"/glue -mkdir -p "$gddir" "$gludir" +mkdir -p "$gddir" "$gluedir" wget -O "$gddir"/Godot_v$gdversion-stable_mono_x11_64.zip "https://downloads.godotengine.org/?version=$gdversion&flavor=stable&slug=mono_x11_64.zip&platform=linux.64" unzip "$gddir"/Godot_v$gdversion-stable_mono_x11_64.zip -d "$gddir" # Generate the mono glue from the official build. -steam-run "$gddir"/Godot_v$gdversion-stable_mono_x11_64/Godot_v$gdversion-stable_mono_x11.64 --generate-mono-glue "$gluedir" +patch-godot-bin "$gddir"/Godot_v$gdversion-stable_mono_x11_64/Godot_v$gdversion-stable_mono_x11.64 +"$gddir"/Godot_v$gdversion-stable_mono_x11_64/Godot_v$gdversion-stable_mono_x11.64 --generate-mono-glue "$gluedir" # Extract the glue version. glueversion=$(grep -Po '(?<=get_cs_glue_version\(\) \{ return )[0-9]+(?=; \})' "$gluedir"/mono_glue.gen.cpp) -patchdir=./patches/gen_cs_glue_version.py/ +patchdir="$(dirname "${BASH_SOURCE[0]}")"/patches/gen_cs_glue_version.py/ patchprefix=hardcodeGlueVersion_ newpatchname=$patchprefix$gdversion.patch From 1e80fd3093db1d3f0d05a627ee4f21dbcb24572f Mon Sep 17 00:00:00 2001 From: David McFarland Date: Sat, 29 Aug 2026 00:37:44 -0300 Subject: [PATCH 13/30] godot3-mono: remove version from hardcodeGlueVersion.patch This simplifies the updateScript. (cherry picked from commit 039dc9aef99970e9e4e2f84a07379973e1795814) --- pkgs/development/tools/godot/3/mono/glue.nix | 8 +++----- ...Version_3.6.2.patch => hardcodeGlueVersion.patch} | 0 .../tools/godot/3/mono/update-glue-version.sh | 12 ++++-------- 3 files changed, 7 insertions(+), 13 deletions(-) rename pkgs/development/tools/godot/3/mono/patches/gen_cs_glue_version.py/{hardcodeGlueVersion_3.6.2.patch => hardcodeGlueVersion.patch} (100%) diff --git a/pkgs/development/tools/godot/3/mono/glue.nix b/pkgs/development/tools/godot/3/mono/glue.nix index e4dfc2a9fdd6..6be707dfc5d7 100644 --- a/pkgs/development/tools/godot/3/mono/glue.nix +++ b/pkgs/development/tools/godot/3/mono/glue.nix @@ -44,17 +44,15 @@ # official glue version by building from the official source. # # To address this, we are patching the python script with a hard-coded glue version number. This - # patch file needs to be updated for every new version of godot, so to enforce this, the godot - # version is baked in to the file name, causing the build to fail until the patch is updated. + # patch file needs to be updated for every new version of godot. # # The correct glue version number for a given godot version is obtained by running the official # build of that version of godot with the --generate-mono-glue flag. This generates the mono # glue files. One of those files, mono_glue.gen.cpp, has a function called get_cs_glue_version() # which contains a hard-coded number. This is the glue version to put in the patch file. # - # For convenience, the accompanying update-glue-version.sh script automates this work. Run it by - # passing the godot version as an argument, e.g. "3.5.2". - "/gen_cs_glue_version.py/hardcodeGlueVersion_${self.version}.patch" + # For convenience, the accompanying update-glue-version.sh script automates this work. + "/gen_cs_glue_version.py/hardcodeGlueVersion.patch" ]; outputs = [ "out" ]; diff --git a/pkgs/development/tools/godot/3/mono/patches/gen_cs_glue_version.py/hardcodeGlueVersion_3.6.2.patch b/pkgs/development/tools/godot/3/mono/patches/gen_cs_glue_version.py/hardcodeGlueVersion.patch similarity index 100% rename from pkgs/development/tools/godot/3/mono/patches/gen_cs_glue_version.py/hardcodeGlueVersion_3.6.2.patch rename to pkgs/development/tools/godot/3/mono/patches/gen_cs_glue_version.py/hardcodeGlueVersion.patch diff --git a/pkgs/development/tools/godot/3/mono/update-glue-version.sh b/pkgs/development/tools/godot/3/mono/update-glue-version.sh index 9bb5b56e8519..43ab7b185193 100755 --- a/pkgs/development/tools/godot/3/mono/update-glue-version.sh +++ b/pkgs/development/tools/godot/3/mono/update-glue-version.sh @@ -4,7 +4,7 @@ # This script updates the hard-coded glue_version in: # -# patches/gen_cs_glue_version.py/hardcodeGlueVersionFor{version}.patch +# patches/gen_cs_glue_version.py/hardcodeGlueVersionFor.patch # # It does so by pulling it from the official build. @@ -33,13 +33,9 @@ patch-godot-bin "$gddir"/Godot_v$gdversion-stable_mono_x11_64/Godot_v$gdversion- # Extract the glue version. glueversion=$(grep -Po '(?<=get_cs_glue_version\(\) \{ return )[0-9]+(?=; \})' "$gluedir"/mono_glue.gen.cpp) -patchdir="$(dirname "${BASH_SOURCE[0]}")"/patches/gen_cs_glue_version.py/ -patchprefix=hardcodeGlueVersion_ -newpatchname=$patchprefix$gdversion.patch +patch="$(dirname "${BASH_SOURCE[0]}")"/patches/gen_cs_glue_version.py/hardcodeGlueVersion.patch # Update the patch with the obtained glue version. -sed -i "s/^+ glue_version = [0-9]\+$/+ glue_version = $glueversion/" $patchdir/$patchprefix*.patch +sed -i "s/^+ glue_version = [0-9]\+$/+ glue_version = $glueversion/" "$patch" -mv $patchdir/$patchprefix*.patch $patchdir/$patchprefix$gdversion.patch - -echo "Updated $patchdir/$patchprefix$gdversion.patch with glue_version: $glueversion" +echo "Updated $patch with glue_version: $glueversion" From 99951f9ee5bf4d3481c3cf5f8e0ec60cbb4f939c Mon Sep 17 00:00:00 2001 From: David McFarland Date: Sat, 29 Aug 2026 03:39:36 +0000 Subject: [PATCH 14/30] godot3: 3.6.2 -> 3.6.3 (cherry picked from commit 58cec358eb4326d0295b33092efb9db9516dff1c) --- pkgs/development/tools/godot/3/default.nix | 4 ++-- .../patches/gen_cs_glue_version.py/hardcodeGlueVersion.patch | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/tools/godot/3/default.nix b/pkgs/development/tools/godot/3/default.nix index 858f1fae90fc..c7a4499234f6 100644 --- a/pkgs/development/tools/godot/3/default.nix +++ b/pkgs/development/tools/godot/3/default.nix @@ -33,14 +33,14 @@ stdenv.mkDerivation (finalAttrs: { pname = "godot3"; - version = "3.6.2"; + version = "3.6.3"; godotBuildDescription = "X11 tools"; src = fetchFromGitHub { owner = "godotengine"; repo = "godot"; rev = "${finalAttrs.version}-stable"; - hash = "sha256-loNjE+NmHniZ827Eb9MHSNo27F2LrURhWURjUq4d8xw="; + hash = "sha256-5MerJVY+SAri85mo2dbqxjDftpJJXzjsMAvlwidGEs4="; }; # Fix PIE hardening: https://github.com/godotengine/godot/pull/50737 diff --git a/pkgs/development/tools/godot/3/mono/patches/gen_cs_glue_version.py/hardcodeGlueVersion.patch b/pkgs/development/tools/godot/3/mono/patches/gen_cs_glue_version.py/hardcodeGlueVersion.patch index 1fc353e7cea3..0c6fa18d3e92 100644 --- a/pkgs/development/tools/godot/3/mono/patches/gen_cs_glue_version.py/hardcodeGlueVersion.patch +++ b/pkgs/development/tools/godot/3/mono/patches/gen_cs_glue_version.py/hardcodeGlueVersion.patch @@ -16,7 +16,7 @@ index 98bbb4d9be..5189f2551b 100644 - latest_mtime = mtime if mtime > latest_mtime else latest_mtime - - glue_version = int(latest_mtime) # The latest modified time will do for now -+ glue_version = 1761170065 ++ glue_version = 1787344265 with open(version_header_dst, "w") as version_header: version_header.write("/* THIS FILE IS GENERATED DO NOT EDIT */\n") From fdf7f473fb684eeb1b9b4e0fd091e7ac7468264b Mon Sep 17 00:00:00 2001 From: KangaZero Date: Mon, 24 Aug 2026 10:49:20 +0900 Subject: [PATCH 15/30] cargo-release: 1.1.3 -> 1.1.5 Added `checkFlags` to skip tests that require an internet connection (cherry picked from commit 8530561db835ad0f2c6baeb584881305b70e71fb) --- pkgs/by-name/ca/cargo-release/package.nix | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ca/cargo-release/package.nix b/pkgs/by-name/ca/cargo-release/package.nix index 5f9f688ce43b..3cdda7c8723e 100644 --- a/pkgs/by-name/ca/cargo-release/package.nix +++ b/pkgs/by-name/ca/cargo-release/package.nix @@ -13,16 +13,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "cargo-release"; - version = "1.1.3"; + version = "1.1.5"; src = fetchFromGitHub { owner = "crate-ci"; repo = "cargo-release"; tag = "v${finalAttrs.version}"; - hash = "sha256-5fe+iIPZAKi8aQW2PfanO7U2d70Oc3KvL/RZTV9/ZU8="; + hash = "sha256-ukzR9VAbrvI+r01D7vCXeBouQeamCtEnKmBg8kKGRpg="; }; - cargoHash = "sha256-abTQuKpVcjorr6RQ1t9sAzqvS39XT6lg4fALAqO68YI="; + cargoHash = "sha256-E+ZhFMfASA6rP4E/+hbZihe0Rzf7RRe3I+W+wj389bo="; nativeBuildInputs = [ pkg-config @@ -40,6 +40,12 @@ rustPlatform.buildRustPackage (finalAttrs: { git ]; + checkFlags = [ + # Skip tests that require internet connection + "--skip=publish::unpublished_git_dependency" + "--skip=publish::unpublished_workspace_dependency" + ]; + # disable vendored-libgit2 and vendored-openssl buildNoDefaultFeatures = true; From c05d66308e17058e87bcb4ac67196a5d3b2747ac Mon Sep 17 00:00:00 2001 From: whispers Date: Mon, 7 Sep 2026 17:17:46 -0400 Subject: [PATCH 16/30] mongoc: 1.30.3 -> 1.30.9 https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.4 https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.5 https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6 https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.7 https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.8 https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.9 this also automaticaly fixes the cmake error currently occuring with cmake 4.4.0+ on staging-next (https://hydra.nixos.org/build/344554671) as https://github.com/mongodb/mongo-c-driver/commit/3f9366cb27623f1a6f3b038146235059a378ad6d is included in this release. Fixes: CVE-2026-84964, CVE-2026-84965, CVE-2026-84969, CVE-2026-84963 (cherry picked from commit 9a63787cc28e8c3563386113217d3fa9f9cdd593) --- pkgs/by-name/mo/mongoc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/mo/mongoc/package.nix b/pkgs/by-name/mo/mongoc/package.nix index b6be37873fcb..b5f1754a4a29 100644 --- a/pkgs/by-name/mo/mongoc/package.nix +++ b/pkgs/by-name/mo/mongoc/package.nix @@ -14,13 +14,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "mongoc"; - version = "1.30.3"; + version = "1.30.9"; src = fetchFromGitHub { owner = "mongodb"; repo = "mongo-c-driver"; tag = finalAttrs.version; - hash = "sha256-3mzqsrbXfrtAAC5igIna5dAgU8FH23lkMS2IacVlCmI="; + hash = "sha256-5msXPEt4a/Q/LDSowf2Eu2HD7ktrTrB9Adi/PtPIs5o="; }; nativeBuildInputs = [ From 91daa9c95695a221df7e3b62f34b2602dc674ce9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 7 Sep 2026 05:54:54 +0000 Subject: [PATCH 17/30] deezer-desktop: 7.1.310 -> 7.1.320 (cherry picked from commit adda11834331ba9e5ec84ee7058ac6698c989706) --- pkgs/by-name/de/deezer-desktop/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/de/deezer-desktop/package.nix b/pkgs/by-name/de/deezer-desktop/package.nix index 480c23654c53..1f12e1b5720b 100644 --- a/pkgs/by-name/de/deezer-desktop/package.nix +++ b/pkgs/by-name/de/deezer-desktop/package.nix @@ -8,15 +8,15 @@ }: let - version = "7.1.310"; + version = "7.1.320"; srcs = { x86_64-linux = fetchurl { url = "https://github.com/aunetx/deezer-linux/releases/download/v${version}/deezer-desktop-${version}-x64.tar.xz"; - hash = "sha256-G1nrkyQR3pduZulFE30DTCTfVMmZe7X6nl6bcDfSf8E="; + hash = "sha256-qCi7Yi2phMtN4IWo8eR0SFIe90TpOk2jqJKj3URSeNQ="; }; aarch64-linux = fetchurl { url = "https://github.com/aunetx/deezer-linux/releases/download/v${version}/deezer-desktop-${version}-arm64.tar.xz"; - hash = "sha256-fMShKodtD8/icEcpRIVZZ9H3KlF/GEpMyuihcDkviWk="; + hash = "sha256-xgpdmrM3+v9o0sKyYv09MxdD6xoTNff3hPgD+loyhNE="; }; }; From 17711ad5d336b013f5a0d80517d0a34035f86c6e Mon Sep 17 00:00:00 2001 From: whispers Date: Wed, 2 Sep 2026 20:35:04 -0400 Subject: [PATCH 18/30] arti: 2.5.1 -> 2.6.0 blog: https://blog.torproject.org/arti_2_6_0_released/ changelog: https://gitlab.torproject.org/tpo/core/arti/-/blob/arti-v2.6.0/CHANGELOG.md diff: https://gitlab.torproject.org/tpo/core/arti/-/compare/arti-v2.5.1...arti-v2.6.0 (cherry picked from commit c79c4f807f4cac4989702d22ecc3ea982d4a0277) --- pkgs/by-name/ar/arti/package.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ar/arti/package.nix b/pkgs/by-name/ar/arti/package.nix index 7f968b5902bf..34b9366e2a5d 100644 --- a/pkgs/by-name/ar/arti/package.nix +++ b/pkgs/by-name/ar/arti/package.nix @@ -13,7 +13,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "arti"; - version = "2.5.1"; + version = "2.6.0"; src = fetchFromGitLab { domain = "gitlab.torproject.org"; @@ -21,18 +21,19 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "core"; repo = "arti"; tag = "arti-v${finalAttrs.version}"; - hash = "sha256-fPobYu2ADTeIwpeXyxQKh5yr1zw+yMQfqTkiZMMd8YY="; + hash = "sha256-ukGplnZz1O1Djh12COKk8FL/3rLmmWGyl0b816wRWBE="; }; # Working around a bug in cargo that appears with cargo-auditable, see # https://github.com/rust-secure-code/cargo-auditable/issues/124. postPatch = '' substituteInPlace crates/arti/Cargo.toml \ + --replace-fail '"http"' '"dep:http"' \ --replace-fail '"tokio-util"' '"dep:tokio-util"' ''; buildAndTestSubdir = "crates/arti"; - cargoHash = "sha256-+JQ+SkRLyLl4RUq69nIUn1zJ/DmYpVEICQO5o85FsNw="; + cargoHash = "sha256-/7sWTLeVolqliggn1Qw+kxqAeWENHgbCR6hK5Th2z+g="; nativeBuildInputs = lib.optionals stdenv.hostPlatform.isLinux [ pkg-config ]; From 26bf407c29af0eb2639b3c136f2ba785cb558ba5 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 13 Jun 2026 19:09:50 +0000 Subject: [PATCH 19/30] runc: 1.4.2 -> 1.4.3 (cherry picked from commit ececc384a370d51ce029228a072a99e1cbffff0c) --- pkgs/by-name/ru/runc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ru/runc/package.nix b/pkgs/by-name/ru/runc/package.nix index 6776d0da64dc..a70f8cb683b0 100644 --- a/pkgs/by-name/ru/runc/package.nix +++ b/pkgs/by-name/ru/runc/package.nix @@ -16,13 +16,13 @@ buildGoModule (finalAttrs: { pname = "runc"; - version = "1.4.2"; + version = "1.4.3"; src = fetchFromGitHub { owner = "opencontainers"; repo = "runc"; tag = "v${finalAttrs.version}"; - hash = "sha256-bBZEcFr/w8r0pKb0ijONUogCKRMgbMQt3o2NR+zhXrU="; + hash = "sha256-I9DruagoSWjrEBB4n+w5rzali5wvD/q3tVQFWPDnLAI="; }; vendorHash = null; From 60994d2602338979056121feaccbd445b4bf9f76 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Sat, 29 Aug 2026 19:53:59 +0000 Subject: [PATCH 20/30] zellij-unwrapped: 0.45.0 -> 0.45.1 Diff: https://github.com/zellij-org/zellij/compare/v0.45.0...v0.45.1 Changelog: https://github.com/zellij-org/zellij/blob/v0.45.1/CHANGELOG.md (cherry picked from commit 3b633fee10274c41cfff11c15c49e51ac97d195e) --- pkgs/by-name/ze/zellij-unwrapped/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ze/zellij-unwrapped/package.nix b/pkgs/by-name/ze/zellij-unwrapped/package.nix index f4274a3a9397..eaa10df82797 100644 --- a/pkgs/by-name/ze/zellij-unwrapped/package.nix +++ b/pkgs/by-name/ze/zellij-unwrapped/package.nix @@ -14,14 +14,14 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "zellij-unwrapped"; - version = "0.45.0"; + version = "0.45.1"; __structuredAttrs = true; src = fetchFromGitHub { owner = "zellij-org"; repo = "zellij"; tag = "v${finalAttrs.version}"; - hash = "sha256-1kS0DuF+mO60jf2UZTKhwZuekO31aoXIEytGuljzd08="; + hash = "sha256-pp++8CTIM4PuAYOjM7GnzU4TXTaw8XuDMow5k/7KQgY="; }; # Remove the `vendored_curl` feature in order to link against the libcurl from nixpkgs instead of @@ -31,7 +31,7 @@ rustPlatform.buildRustPackage (finalAttrs: { --replace-fail ', "vendored_curl"' "" ''; - cargoHash = "sha256-ZwxoqdZ73/HvdkdNWOKW3Av6htI/vCFcJ0zVpSL1SuU="; + cargoHash = "sha256-rCK7FyAUIjUq6dxEw9YBaGm29xYvlYjX0b1xHU03XVU="; env.OPENSSL_NO_VENDOR = 1; From 215371e0404c0476086f68065f4f1e161641ec4a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 11 May 2026 15:30:59 +0000 Subject: [PATCH 21/30] crowdsec: 1.7.7 -> 1.7.8 (cherry picked from commit 433cbb426eb6a81b51418fdd4ebdc98050edef77) --- pkgs/by-name/cr/crowdsec/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/cr/crowdsec/package.nix b/pkgs/by-name/cr/crowdsec/package.nix index 3289a53dbc82..41776f0e0418 100644 --- a/pkgs/by-name/cr/crowdsec/package.nix +++ b/pkgs/by-name/cr/crowdsec/package.nix @@ -7,16 +7,16 @@ buildGoModule (finalAttrs: { pname = "crowdsec"; - version = "1.7.7"; + version = "1.7.8"; src = fetchFromGitHub { owner = "crowdsecurity"; repo = "crowdsec"; tag = "v${finalAttrs.version}"; - hash = "sha256-TG9YRKzht9OAnlDNxLNP8060v0klee6GY7vJCu6MugM="; + hash = "sha256-2t9nxuqWNDAUOZHtfNkZ4ZFKXvv8k5LuvKrGNjpdGXc="; }; - vendorHash = "sha256-BjkTMBrQPv8uZzme02WFdobuYdbe1RvRkZ8RjHGubo8="; + vendorHash = "sha256-RDkttsV4PNOfjWPr4v+uIwdkmXYH83vkYFQQIO3CYGE="; nativeBuildInputs = [ installShellFiles ]; From ad61bf22a1d20e3cf996a8401ea694c2ac783ee0 Mon Sep 17 00:00:00 2001 From: Artturin Date: Sat, 30 May 2026 17:26:52 +0300 Subject: [PATCH 22/30] nettle_4: init at 4.0 `neatvnc` in nixpkgs-wayland needs this and presumably other programs will too in the near future. (cherry picked from commit 20aed63e9061b76fb04c4ae221d2a114a4c10e70) --- pkgs/development/libraries/nettle/4.nix | 10 ++++++++++ pkgs/top-level/all-packages.nix | 1 + 2 files changed, 11 insertions(+) create mode 100644 pkgs/development/libraries/nettle/4.nix diff --git a/pkgs/development/libraries/nettle/4.nix b/pkgs/development/libraries/nettle/4.nix new file mode 100644 index 000000000000..ec8d44b3d75e --- /dev/null +++ b/pkgs/development/libraries/nettle/4.nix @@ -0,0 +1,10 @@ +{ callPackage, fetchurl }: + +callPackage ./generic.nix rec { + version = "4.0"; + + src = fetchurl { + url = "mirror://gnu/nettle/nettle-${version}.tar.gz"; + hash = "sha256-Ot28ANoBhGsjL7O8RTU46lRo2kMDPyG7NFyx6Qc/UJQ="; + }; +} diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 5a349d016453..772e69d5b3ff 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6691,6 +6691,7 @@ with pkgs; }; nettle = import ../development/libraries/nettle { inherit callPackage fetchurl; }; + nettle_4 = import ../development/libraries/nettle/4.nix { inherit callPackage fetchurl; }; libnghttp2 = nghttp2.lib; From 05b642989adb925d098e206d7b70928bcbbc4c4d Mon Sep 17 00:00:00 2001 From: Robert Helgesson Date: Tue, 8 Sep 2026 20:13:33 +0200 Subject: [PATCH 23/30] grav: 1.7.53.2 -> 1.7.53.3 (cherry picked from commit a59160023cc62ae557906d31e2fe98f7895e9b73) --- pkgs/by-name/gr/grav/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gr/grav/package.nix b/pkgs/by-name/gr/grav/package.nix index f8e2888e4cc2..7b7375b2145e 100644 --- a/pkgs/by-name/gr/grav/package.nix +++ b/pkgs/by-name/gr/grav/package.nix @@ -6,7 +6,7 @@ }: let - version = "1.7.53.2"; + version = "1.7.53.3"; in stdenvNoCC.mkDerivation { pname = "grav"; @@ -14,7 +14,7 @@ stdenvNoCC.mkDerivation { src = fetchzip { url = "https://github.com/getgrav/grav/releases/download/${version}/grav-admin-v${version}.zip"; - hash = "sha256-6cQotHwIwWFR5phFQI9r79jpd+iYA1HpFBbYIzEVBsc="; + hash = "sha256-O8XhzwCeaJI8Bu5ra5VqR7UGUyLzUl37FLAdLlNlzhI="; }; patches = [ From df9249945852bcba3e054ca248297d8caaac28a2 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 25 May 2026 23:38:05 +0000 Subject: [PATCH 24/30] pangolin-cli: 0.8.2 -> 0.8.3 (cherry picked from commit 6c6c4193ccc7e0e9ab7d152db45e062e3c9455f8) --- pkgs/by-name/pa/pangolin-cli/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pa/pangolin-cli/package.nix b/pkgs/by-name/pa/pangolin-cli/package.nix index b8765bd109c7..f558700c7a2e 100644 --- a/pkgs/by-name/pa/pangolin-cli/package.nix +++ b/pkgs/by-name/pa/pangolin-cli/package.nix @@ -10,13 +10,13 @@ buildGoModule (finalAttrs: { pname = "pangolin-cli"; - version = "0.8.2"; + version = "0.8.3"; src = fetchFromGitHub { owner = "fosrl"; repo = "cli"; tag = finalAttrs.version; - hash = "sha256-LMLeJVYu2L1+FVOLNapEShj36zv8vCP9BVkU4Y/g0vc="; + hash = "sha256-y+B29E6wXUcMQsWLAcLYIpg0uuqjr+zfxf2WVt0oY9A="; }; ldflags = [ From 5fcbf1414260663f0e05e285ba5dd3e509952383 Mon Sep 17 00:00:00 2001 From: whispers Date: Tue, 8 Sep 2026 10:30:09 -0400 Subject: [PATCH 25/30] tor: 0.4.9.11 -> 0.4.9.12 release notes: https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.12/ReleaseNotes diff: https://gitlab.torproject.org/tpo/core/tor/-/compare/tor-0.4.9.11...tor-0.4.9.12 trove: https://gitlab.torproject.org/tpo/core/team/-/wikis/NetworkTeam/TROVE as per TROVE identifiers, this fixes eight high severity security issues. Fixes: TROVE-2026-032, TROVE-2026-033, TROVE-2026-034, TROVE-2026-035, TROVE-2026-036, TROVE-2026-040, TROVE-2026-042, TROVE-2026-043 (cherry picked from commit fa2c5a40ebd821aac7526116ab884b36f4761920) --- pkgs/by-name/to/tor/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/to/tor/package.nix b/pkgs/by-name/to/tor/package.nix index 02543dacc7e4..f7f8824a4b0c 100644 --- a/pkgs/by-name/to/tor/package.nix +++ b/pkgs/by-name/to/tor/package.nix @@ -46,11 +46,11 @@ in stdenv.mkDerivation (finalAttrs: { pname = "tor"; - version = "0.4.9.11"; + version = "0.4.9.12"; src = fetchurl { url = "https://dist.torproject.org/tor-${finalAttrs.version}.tar.gz"; - hash = "sha256-LmwXIBGMgSrPAHn9R8+Rtr+rpddmwyHE09KijWoRqO0="; + hash = "sha256-wNMHydza7khIqMpT6dbE7JKCPk8wvhJ5Cw+938ZRX1s="; }; outputs = [ From 74e3c4312722bc8aa946456dfdb602706d294ab8 Mon Sep 17 00:00:00 2001 From: Samiser Date: Wed, 9 Sep 2026 12:07:50 +0100 Subject: [PATCH 26/30] centrifugo: 6.6.2 -> 6.8.4 Not-cherry-picked-because: unstable is on 6.9.x, 6.8.4 is the lowest release with the fix --- pkgs/by-name/ce/centrifugo/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ce/centrifugo/package.nix b/pkgs/by-name/ce/centrifugo/package.nix index 4724e3565641..db51f554776e 100644 --- a/pkgs/by-name/ce/centrifugo/package.nix +++ b/pkgs/by-name/ce/centrifugo/package.nix @@ -16,16 +16,16 @@ let in buildGoModule (finalAttrs: { pname = "centrifugo"; - version = "6.6.2"; + version = "6.8.4"; src = fetchFromGitHub { owner = "centrifugal"; repo = "centrifugo"; rev = "v${finalAttrs.version}"; - hash = "sha256-V67riIkwBKz4YvCo6PJS3jrVl3Q6DE9ewEzzHPi7YFE="; + hash = "sha256-0c+FxylNxRBhELUSgbLSe14G4P+37XUwOmsF9XU3Y4Q="; }; - vendorHash = "sha256-K/90YrXkwiDt9Zm6h5nVo34WjtQQKBCNigJguwAdW5E="; + vendorHash = "sha256-ElkoxUko+6VuJ+tB3L4P8+G3NAXhrhIYjRJqAFCsajQ="; ldflags = [ "-s" From f2728812efb5a6eef3b1c868bbceecf9b502e926 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 4 Sep 2026 08:49:16 +0000 Subject: [PATCH 27/30] phpExtensions.blackfire: 2026.8.6 -> 2026.9.0 (cherry picked from commit 637e5653c89e5216aacd4d7dfaf5266938370830) --- pkgs/by-name/bl/blackfire/php-probe.nix | 42 ++++++++++++------------- 1 file changed, 21 insertions(+), 21 deletions(-) diff --git a/pkgs/by-name/bl/blackfire/php-probe.nix b/pkgs/by-name/bl/blackfire/php-probe.nix index b531df9fc185..b590196cc9fe 100644 --- a/pkgs/by-name/bl/blackfire/php-probe.nix +++ b/pkgs/by-name/bl/blackfire/php-probe.nix @@ -16,47 +16,47 @@ let phpMajor = lib.versions.majorMinor php.version; inherit (stdenv.hostPlatform) system; - version = "2026.8.6"; + version = "2026.9.0"; hashes = { "x86_64-linux" = { system = "amd64"; hash = { - "8.1" = "sha256-lZyZjyLFcjWDCyA8qoHvWA5UTMA23nwJ60Pi0qnF6FU="; - "8.2" = "sha256-CyukBCV9EDiFYWOhyren7mLDS1m1K43Cqr+gbKONPZU="; - "8.3" = "sha256-6lXP8f302H0isG4a4G25G7F9SeN1/iSN9PXBYoLusOM="; - "8.4" = "sha256-LZN56S7uvMfa/HqJZihbJlOH0tRhSXF1C6vI/dHlfJI="; - "8.5" = "sha256-xtf4tv37DElCPJqSZn+21+wpkYF1jZ49Wgu9pJhPbbs="; + "8.1" = "sha256-0AAgiBdiIQOxSSttD2ERzSTqPM1rLwlQFHZ6ARRSgmI="; + "8.2" = "sha256-usSNoM1XeVWKuHLlSMvONAucVa1ZEAb3+I66oOnzGB0="; + "8.3" = "sha256-65GoEhgFsQbQleSVuRnHPSZAiCfEUmyVWWhnybnrgaA="; + "8.4" = "sha256-0if1fQa7b41TjC3d1ck65cJP7lKdoL670V9t+PLL+qk="; + "8.5" = "sha256-3k5jQ+vbxLGp78MRzjiw7uP+tCcEs5gAYM2MEoiYdtk="; }; }; "i686-linux" = { system = "i386"; hash = { - "8.1" = "sha256-ssEimBtjlRPI3bNMFT+iizetVkv5SVUn9zadHZ9wPr4="; - "8.2" = "sha256-DVz4gm28JhIT0mSiwWYFtRwZ6NJJsrSmS2yYyHLhx6U="; - "8.3" = "sha256-2Kn1J0ckLyls3arA7cGQcJEAYP7gob6jbNwAZrCrZ9g="; - "8.4" = "sha256-k++71n+gUGqTGS1IKYOFoNoTgQpzakFDoU1IFzqqN98="; - "8.5" = "sha256-V3U7GbEcLXw+5jGZCh3QWZa8IHcy3db2/emZhw3IHdM="; + "8.1" = "sha256-fmmbY4ecnE05XNxGKq11HcYhs9z7SggLx9iXICHE6DQ="; + "8.2" = "sha256-9WP+FpULl0PQJ+0qxxZfm5xJS/A6N137yGk9gv4cYvI="; + "8.3" = "sha256-Io2gGAhXLAVdHoaKwKvJWA1N71IJAKeJkudLs8DZUl8="; + "8.4" = "sha256-JoGiB8ew3D/qSi7Pg/q67mXLsUy4UDVsazgxgb5BJTM="; + "8.5" = "sha256-bSfbhFHV8Zs4cpOfDnKItNlF9++0opUtosTpnosacdU="; }; }; "aarch64-linux" = { system = "arm64"; hash = { - "8.1" = "sha256-0SeUcMZGCUrKWD/FI9p0nkOaEq2Q8PWb42esHXFjsNs="; - "8.2" = "sha256-wTuS7IaXRg6B3qxH2QkacuHAq5bbPcqPbVDxgwxy9mA="; - "8.3" = "sha256-/65Yjji+2Hi/OdhZIin3ttidHbZcprYA33e8SIoK6yM="; - "8.4" = "sha256-3n359rNQatVNmKmFIwfQRR9+DMBBhI4wcMpHyJOVWtY="; - "8.5" = "sha256-GDv9gZ2KD8281P0xrzDkq1uI4D5Y4uTMCbGNy2tIcfg="; + "8.1" = "sha256-7/2Q9Kx3ZEpI0Inj88CfTDzr0sjVpws3DH8KTP26PR0="; + "8.2" = "sha256-suFGyE94wY4xHfPk77OXzkqU+Ulb+f42drDZY/M9ZNs="; + "8.3" = "sha256-z5IfXX7DElerdRTnq3R95t8IvG0Hl9EKXBw1QbRlDkY="; + "8.4" = "sha256-ceTjQ6gtiWJEte5WuVuyc+eTEb3khobYoCWNGP+Vkeo="; + "8.5" = "sha256-1jX564B/tLBgb7jN6MB5DfpRgYy0xxmtAaAv768FQqo="; }; }; "aarch64-darwin" = { system = "arm64"; hash = { - "8.1" = "sha256-5gdDsxSWTpxGjelGMY7nyvoAGGC0YftF9qHKdw+XbUs="; - "8.2" = "sha256-jF4xbQ7RAcyb0obbeiJxJXAwLaW+cO8Yf22ZGU7cEu4="; - "8.3" = "sha256-aNtRucr7kBBCAAOcazFq1ZUHDtW8FJpEwqHeYnR0zO4="; - "8.4" = "sha256-HAlT3o6QRVDG07MTDGXxp7cmysoHFN4AdZGhUiaol58="; - "8.5" = "sha256-NRKTuUVM2sMKARfMFlccY0by77kt3goi+B69snmQpC4="; + "8.1" = "sha256-JQZKX8qChvBS3S8cqtxmooZMsFlFqfffnQbNldYNR+M="; + "8.2" = "sha256-nGQdweskEw9tiK51IGcu7cGKJJwtmNBL9fZLMUCuiB8="; + "8.3" = "sha256-sHQOg6QC+Mm5KwQVwKmeOVR3fUkN2NH9utHs667Oipw="; + "8.4" = "sha256-Btrz+U9ejW/Jl1cWBRt5XGV1IzjxK+FJaQwXIgYR/NI="; + "8.5" = "sha256-zSQeBioU/3c7HrqEz+9z8vam3EHkR0KbC80/mIuTAFE="; }; }; "x86_64-darwin" = { From 48909b023247c1e904fc6ce1b18db70c281a4b9a Mon Sep 17 00:00:00 2001 From: Dominic Date: Sat, 5 Sep 2026 22:11:21 +0200 Subject: [PATCH 28/30] maintainers: remove dwrege (cherry picked from commit d81b6abfdf52ba4b10b73b83b4304972dfe656cc) --- maintainers/maintainer-list.nix | 6 ------ pkgs/by-name/li/librewolf-bin-unwrapped/package.nix | 1 - pkgs/by-name/li/librewolf-unwrapped/package.nix | 1 - 3 files changed, 8 deletions(-) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 0d20dab5f25b..0986f37b4b61 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -7513,12 +7513,6 @@ matrix = "@dwoffinden:matrix.org"; name = "Daniel Woffinden"; }; - dwrege = { - email = "email@dwrege.de"; - github = "DominicWrege"; - githubId = 7389000; - name = "Dominic Wrege"; - }; dwt = { email = "spamfaenger@gmx.de"; github = "dwt"; diff --git a/pkgs/by-name/li/librewolf-bin-unwrapped/package.nix b/pkgs/by-name/li/librewolf-bin-unwrapped/package.nix index 31c2af81fa4f..47e764d3295c 100644 --- a/pkgs/by-name/li/librewolf-bin-unwrapped/package.nix +++ b/pkgs/by-name/li/librewolf-bin-unwrapped/package.nix @@ -109,7 +109,6 @@ stdenv.mkDerivation { maintainers = with lib.maintainers; [ azahi eclairevoyant - dwrege ]; platforms = builtins.attrNames mozillaPlatforms; mainProgram = "librewolf"; diff --git a/pkgs/by-name/li/librewolf-unwrapped/package.nix b/pkgs/by-name/li/librewolf-unwrapped/package.nix index 86076f9126aa..cc65b6d50f34 100644 --- a/pkgs/by-name/li/librewolf-unwrapped/package.nix +++ b/pkgs/by-name/li/librewolf-unwrapped/package.nix @@ -31,7 +31,6 @@ in homepage = "https://librewolf.net/"; maintainers = with lib.maintainers; [ azahi - dwrege fpletz hythera mBornand From e3655a35d34b3ed496d4888f3b8c051485de2519 Mon Sep 17 00:00:00 2001 From: Rafael Ieda Date: Wed, 9 Sep 2026 03:27:41 -0300 Subject: [PATCH 29/30] google-chrome: 152.0.7977.82 -> 153.0.8010.36 (linux), 152.0.7977.83 -> 153.0.8010.37 (darwin) (cherry picked from commit 54209c517ce462b6bf128f4602b399c9d0fc0a9f) --- pkgs/by-name/go/google-chrome/package.nix | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/go/google-chrome/package.nix b/pkgs/by-name/go/google-chrome/package.nix index 8a4c6e69186f..9eacd8898a80 100644 --- a/pkgs/by-name/go/google-chrome/package.nix +++ b/pkgs/by-name/go/google-chrome/package.nix @@ -180,7 +180,7 @@ let linux = stdenvNoCC.mkDerivation (finalAttrs: { inherit pname meta; - version = "152.0.7977.82"; + version = "153.0.8010.36"; src = let @@ -195,8 +195,8 @@ let url = "https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-stable/google-chrome-stable_${finalAttrs.version}-1_${debArch}.deb"; hash = { - amd64 = "sha256-TSXkoCjHinrpEGg1UcLyNHksxVlefj40k59Zk0KtpEY="; - arm64 = "sha256-HcBFWH2AjCB6GenrNw9ukS3X5pZpU6+5PIHZnD/jGOM="; + amd64 = "sha256-m7ROMwMcLyhXzza0NDBRoS+TBY5LeB48djE9+H9sjTI="; + arm64 = "sha256-H89uxRqdUuJv8a2AciX3Jb5VBprStoxdaTYaJ0ZmUYg="; } .${debArch}; }; @@ -306,11 +306,11 @@ let darwin = stdenvNoCC.mkDerivation (finalAttrs: { inherit pname meta; - version = "152.0.7977.83"; + version = "153.0.8010.37"; src = fetchurl { - url = "http://dl.google.com/release2/chrome/g62gliie746ywu62ed7go3adam_152.0.7977.83/GoogleChrome-152.0.7977.83.dmg"; - hash = "sha256-Uc16WeBPhu/r7zB/UE9yt+cgkbpRYkRM3xtENFltqps="; + url = "http://dl.google.com/release2/chrome/mtrht6j77xyruy2gnvuwtsjrcm_153.0.8010.37/GoogleChrome-153.0.8010.37.dmg"; + hash = "sha256-mNJM1d0Soi8kb3YROZ4SRG24fgA23CIyxaDFXeFY5tw="; }; dontPatch = true; From ddab83ef6dfd50374d0963f98c944ca078d23ece Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 3 Sep 2026 20:43:49 +0000 Subject: [PATCH 30/30] lockbook-desktop: 26.8.4 -> 26.9.3 (cherry picked from commit 2de18154524f560360cc1e725f3dd1eebc04e8c1) --- pkgs/by-name/lo/lockbook-desktop/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/lo/lockbook-desktop/package.nix b/pkgs/by-name/lo/lockbook-desktop/package.nix index 529bc176d27e..9b2eed94d1df 100644 --- a/pkgs/by-name/lo/lockbook-desktop/package.nix +++ b/pkgs/by-name/lo/lockbook-desktop/package.nix @@ -18,16 +18,16 @@ let in rustPlatform.buildRustPackage (finalAttrs: { pname = "lockbook-desktop"; - version = "26.8.4"; + version = "26.9.3"; src = fetchFromGitHub { owner = "lockbook"; repo = "lockbook"; tag = finalAttrs.version; - hash = "sha256-ge6uo54T6sWYn4z2fE3teelkTofSLjMPeBGJ84a6N5c="; + hash = "sha256-MSRuvyuq8DxQELJHTKCdfYl4cqd9PTDsnAgmA1xeUiw="; }; - cargoHash = "sha256-KPRlvkhHGiYPTOzNoZ3nDmyJ0VmMESTSLpGvQl+I6Oo="; + cargoHash = "sha256-Mo/XO/1/sVRln99Bw1fxtIgn8zkl3s/4OdXI0xcb11c="; nativeBuildInputs = [ pkg-config