Merge release-26.05 into staging-nixos-26.05

This commit is contained in:
nixpkgs-ci[bot]
2026-09-04 00:27:50 +00:00
committed by GitHub
23 changed files with 477 additions and 113 deletions

View File

@@ -161,7 +161,31 @@ const cases: Array<{
expected: 'mass-rebuild',
},
{
name: 'kernel exemption suppresses a possible mass rebuild',
name: 'kernels-org exemption suppresses a possible mass rebuild',
facts: {
maxRebuildCount: 999,
onlyChangedFile: 'pkgs/os-specific/linux/kernel/kernels-org.json',
},
expected: 'dismiss',
},
{
name: 'kernels-org exemption suppresses a definite mass rebuild',
facts: {
maxRebuildCount: 1000,
onlyChangedFile: 'pkgs/os-specific/linux/kernel/kernels-org.json',
},
expected: 'dismiss',
},
{
name: 'kernels-org exemption suppresses a NixOS test rebuild',
facts: {
rebuildsAllTests: true,
onlyChangedFile: 'pkgs/os-specific/linux/kernel/kernels-org.json',
},
expected: 'dismiss',
},
{
name: 'xanmod kernel exemption suppresses a possible mass rebuild',
facts: {
maxRebuildCount: 999,
onlyChangedFile: 'pkgs/os-specific/linux/kernel/xanmod-kernels.nix',
@@ -169,7 +193,7 @@ const cases: Array<{
expected: 'dismiss',
},
{
name: 'kernel exemption suppresses a definite mass rebuild',
name: 'xanmod kernel exemption suppresses a definite mass rebuild',
facts: {
maxRebuildCount: 1000,
onlyChangedFile: 'pkgs/os-specific/linux/kernel/xanmod-kernels.nix',
@@ -177,7 +201,7 @@ const cases: Array<{
expected: 'dismiss',
},
{
name: 'kernel exemption suppresses a NixOS test rebuild',
name: 'xanmod kernel exemption suppresses a NixOS test rebuild',
facts: {
rebuildsAllTests: true,
onlyChangedFile: 'pkgs/os-specific/linux/kernel/xanmod-kernels.nix',

View File

@@ -62,9 +62,12 @@ export function evaluateTargetBranchPolicy({
shouldCheckNixosRebuild,
} = getTargetBranchPolicy({ base, head })
// https://github.com/NixOS/nixpkgs/pull/553786#issuecomment-5510286851
// kernels-org should go to staging-nixos (or master) and staging-nixos-xx.xx (or release-xx.xx) when backported
// https://github.com/NixOS/nixpkgs/pull/521157
// These should go to master and release-xx.xx when backported
// xanmod should go to master and release-xx.xx when backported
const isExemptKernelUpdate =
onlyChangedFile === 'pkgs/os-specific/linux/kernel/kernels-org.json' ||
onlyChangedFile === 'pkgs/os-specific/linux/kernel/xanmod-kernels.nix'
// https://github.com/NixOS/nixpkgs/pull/483194#issuecomment-3793393218

View File

@@ -802,5 +802,10 @@ in
ProtectProc = "invisible";
};
};
systemd.tmpfiles.settings."frigate" = {
# prevent gc of multiprocessing forkserver socket due to default systemd tmpfiles rules
"/tmp/systemd-private-%b-${config.systemd.services.frigate.name}-*/tmp/pymp-*".x = { };
};
};
}

View File

@@ -10,11 +10,11 @@
buildMozillaMach rec {
pname = "firefox-beta";
binaryName = "firefox-beta";
version = "155.0b5";
version = "156.0b2";
applicationName = "Firefox Beta";
src = fetchurl {
url = "mirror://mozilla/firefox/releases/${version}/source/firefox-${version}.source.tar.xz";
sha512 = "30b4b84c80057a992e763b8f967c65f46308324fd41c0307c9302e262e6428c379861ccd9ce52dde15d0dc3f4410b95a8c047ea7e5af9d90e60e7bb57ee59137";
sha512 = "5b685f8b947af0b519c59a308fba6a41f9481df68b7fb6f4b395707653c3ef1822817d2f867d663081cd2d61c8fd4537f46b8002da84b5efa9b8a57ae9491164";
};
meta = {

View File

@@ -10,13 +10,13 @@
buildMozillaMach rec {
pname = "firefox-devedition";
binaryName = "firefox-devedition";
version = "155.0b5";
version = "156.0b2";
applicationName = "Firefox Developer Edition";
requireSigning = false;
branding = "browser/branding/aurora";
src = fetchurl {
url = "mirror://mozilla/devedition/releases/${version}/source/firefox-${version}.source.tar.xz";
sha512 = "8e9ccc65a8cd6640171d4891fe8d01435cd524cee8164a5829429df827bcc2b49c3b7e6a092aaf5bfa48140d7f40f6c9cb371af48a7321132ea6ee5da0af08e3";
sha512 = "683326ff4367f9b807c4c5b93f100970258ada9838da2c597358105a99ff4aa7e33269fe67d6c68d466e2f539d2bea3015457109516af19e1785588ce43426b5";
};
# buildMozillaMach sets MOZ_APP_REMOTINGNAME during configuration, but

View File

@@ -72,6 +72,7 @@ let
pkcs11Modules ? [ ],
useGlvnd ? (!isDarwin),
cfg ? config.${applicationName} or { },
appDataDir ? null,
## Following options are needed for extra prefs & policies
# For more information about anti tracking (german website)
@@ -341,6 +342,11 @@ let
"MOZ_ALLOW_DOWNGRADE"
"1"
]
++ lib.optionals (appDataDir != null) [
"--set"
"MOZ_APP_DATA"
appDataDir
]
++ lib.optionals (!isDarwin) [
"--suffix"
"GTK_PATH"

View File

@@ -1,21 +1,21 @@
{
"version": "1.3.29-stable",
"version": "1.3.36-stable",
"sources": {
"aarch64-darwin": {
"url": "https://acli.atlassian.com/darwin/1.3.29-stable/acli_1.3.29-stable_darwin_arm64.tar.gz",
"sha256": "b2f6343d13ac8f3c32ea1043aba8317876d845662967793eb00016a2e5b5cf79"
"url": "https://acli.atlassian.com/darwin/1.3.36-stable/acli_1.3.36-stable_darwin_arm64.tar.gz",
"sha256": "f5307d1518364c20f35f92c745bfc1282a41b4cd4a4c83dfdf4e50d4e0ca3945"
},
"aarch64-linux": {
"url": "https://acli.atlassian.com/linux/1.3.29-stable/acli_1.3.29-stable_linux_arm64.tar.gz",
"sha256": "cea39c4eb90c65d8d0cafc869a75fa3b6afaaf4573f8da650f4ae73801f8ec46"
"url": "https://acli.atlassian.com/linux/1.3.36-stable/acli_1.3.36-stable_linux_arm64.tar.gz",
"sha256": "4c404a2a0cb98e516502b6f528ad70fb95187aebf744ea108f0632e41984d0bd"
},
"x86_64-darwin": {
"url": "https://acli.atlassian.com/darwin/1.3.22-stable/acli_1.3.22-stable_darwin_amd64.tar.gz",
"sha256": "993fd692700d602fd1e3cff7f1d29f70e44a2ebb8056fbb93bdc8aed1e5cbbd4"
},
"x86_64-linux": {
"url": "https://acli.atlassian.com/linux/1.3.29-stable/acli_1.3.29-stable_linux_amd64.tar.gz",
"sha256": "8dcfc7bcf9dc788e7143e93d74445310094977ba1bad2513c6c613460851d34e"
"url": "https://acli.atlassian.com/linux/1.3.36-stable/acli_1.3.36-stable_linux_amd64.tar.gz",
"sha256": "b6a9d70fd107ce5e284380d110d2eaee82155c4fc90f7bb17612213c9a1087e1"
}
}
}

View File

@@ -9,13 +9,13 @@
stdenv.mkDerivation rec {
pname = "dokuwiki";
version = "2026-07-14a";
version = "2026-07-14c";
src = fetchFromGitHub {
owner = "dokuwiki";
repo = "dokuwiki";
rev = "release-${version}";
sha256 = "sha256-qj+Ng20aB3qV2afrER309kvlh6gXRFPh3MqnomvvCf4=";
sha256 = "sha256-84kMuFTWYo6Cjd6qpkZsLZoECIP9IzSrc9dX1uKMp0M=";
};
preload = writeText "preload.php" ''

View File

@@ -0,0 +1,241 @@
--- a/htdocs/core/modules/import/import_csv.modules.php
+++ b/htdocs/core/modules/import/import_csv.modules.php
@@ -891,38 +891,53 @@
$insertdone = false;
$is_table_category_link = false;
- $fname = 'rowid';
+ $sanitizedfname = 'rowid';
if (strpos($tablename, '_categorie_') !== false) {
$is_table_category_link = true;
- $fname = '*';
+ $sanitizedfname = '*';
}
if (!empty($updatekeys)) {
// We do SELECT to get the rowid, if we already have the rowid, it's to be used below for related tables (extrafields)
if (empty($lastinsertid)) { // No insert done yet for a parent table
- $sqlSelect = "SELECT ".$fname." FROM ".$tablename;
+ $sqlSelect = "SELECT ".$sanitizedfname." FROM ".$this->db->sanitize($tablename);
$data = array_combine($listfields, $listvalues);
$where = array(); // filters to forge SQL request
$filters = array(); // filters to forge output error message
foreach ($updatekeys as $key) {
+ if (!is_array($objimport->array_import_updatekeys[0]) || !array_key_exists($key, $objimport->array_import_updatekeys[0])) {
+ $this->errors[$error]['lib'] = 'You try to search duplicates on field '.dol_string_nohtmltag($key).' that is not an allowed field.';
+ $this->errors[$error]['type'] = 'UPDATEKEYBADCOLUMN';
+ $error++;
+ break;
+ }
$col = $objimport->array_import_updatekeys[0][$key];
- $key = preg_replace('/^.*\./i', '', $key);
- if (isModEnabled("socialnetworks") && strpos($key, "socialnetworks") !== false) {
- $tmp = explode("_", $key);
- $key = $tmp[0];
+ $keyfordata = preg_replace('/^.*\./i', '', $key);
+ $keyfordata = preg_replace('/[^a-zA-Z0-9\._]/', '', $keyfordata);
+
+ if (isModEnabled("socialnetworks") && strpos($keyfordata, "socialnetworks") !== false) {
+ $tmp = explode("_", $keyfordata);
+ $keyfordata = $tmp[0];
$socialnetwork = $tmp[1];
- $jsondata = $data[$key];
+ $jsondata = $data[$keyfordata];
$json = json_decode($jsondata);
$stringtosearch = json_encode($socialnetwork).':'.json_encode($json->$socialnetwork);
//var_dump($stringtosearch);
//var_dump($this->db->escape($stringtosearch)); // This provide a value for sql string (but not for a like)
- $where[] = $key." LIKE '%".$this->db->escape($this->db->escapeforlike($stringtosearch))."%'";
+ $where[] = $this->db->sanitize($keyfordata)." LIKE '%".$this->db->escape($this->db->escapeforlike($stringtosearch))."%'";
$filters[] = $col." LIKE '%".$this->db->escape($this->db->escapeforlike($stringtosearch))."%'";
//var_dump($where[1]); // This provide a value for sql string inside a like
} else {
- $where[] = $key.' = '.$data[$key];
- $filters[] = $col.' = '.$data[$key];
+ $sanitizedvalue = $data[$keyfordata];
+ if ((string) $sanitizedvalue === '') {
+ $this->errors[$error]['lib'] = 'You request to search duplicates on field '.$keyfordata.' but no value was provided for this field on this line.';
+ $this->errors[$error]['type'] = 'UPDATEKEYBADVALUE';
+ $error++;
+ } else {
+ $where[] = $this->db->sanitize($keyfordata)." = ".$sanitizedvalue;
+ $filters[] = $col." = ".$sanitizedvalue;
+ }
}
}
if (!empty($tablewithentity_cache[$tablename])) {
@@ -931,29 +946,31 @@
}
$sqlSelect .= " WHERE ".implode(' AND ', $where);
- $resql = $this->db->query($sqlSelect);
- if ($resql) {
- $num_rows = $this->db->num_rows($resql);
- if ($num_rows == 1) {
- $res = $this->db->fetch_object($resql);
- $lastinsertid = $res->rowid;
- $keyfield = 'rowid';
- if ($is_table_category_link) {
- $lastinsertid = 'linktable';
- } // used to apply update on tables like llx_categorie_product and avoid being blocked for all file content if at least one entry already exists
- $last_insert_id_array[$tablename] = $lastinsertid;
- } elseif ($num_rows > 1) {
- $this->errors[$error]['lib'] = $langs->trans('MultipleRecordFoundWithTheseFilters', implode(', ', $filters));
+ if (!$error) {
+ $resql = $this->db->query($sqlSelect);
+ if ($resql) {
+ $num_rows = $this->db->num_rows($resql);
+ if ($num_rows == 1) {
+ $res = $this->db->fetch_object($resql);
+ $lastinsertid = $res->rowid;
+ $keyfield = 'rowid';
+ if ($is_table_category_link) {
+ $lastinsertid = 'linktable';
+ } // used to apply update on tables like llx_categorie_product and avoid being blocked for all file content if at least one entry already exists
+ $last_insert_id_array[$tablename] = $lastinsertid;
+ } elseif ($num_rows > 1) {
+ $this->errors[$error]['lib'] = $langs->trans('MultipleRecordFoundWithTheseFilters', implode(', ', $filters));
+ $this->errors[$error]['type'] = 'SQL';
+ $error++;
+ } else {
+ // No record found with filters, insert will be tried below
+ }
+ } else {
+ //print 'E';
+ $this->errors[$error]['lib'] = $this->db->lasterror();
$this->errors[$error]['type'] = 'SQL';
$error++;
- } else {
- // No record found with filters, insert will be tried below
}
- } else {
- //print 'E';
- $this->errors[$error]['lib'] = $this->db->lasterror();
- $this->errors[$error]['type'] = 'SQL';
- $error++;
}
} else {
// We have a last INSERT ID (got by previous pass), so we check if we have a row referencing this foreign key.
--- a/htdocs/core/modules/import/import_xlsx.modules.php
+++ b/htdocs/core/modules/import/import_xlsx.modules.php
@@ -970,17 +970,17 @@
$insertdone = false;
$is_table_category_link = false;
- $fname = 'rowid';
+ $sanitizedfname = 'rowid';
if (strpos($tablename, '_categorie_') !== false) {
$is_table_category_link = true;
- $fname = '*';
+ $sanitizedfname = '*';
}
if (!empty($updatekeys)) {
// We do SELECT to get the rowid, if we already have the rowid, it's to be used below for related tables (extrafields)
if (empty($lastinsertid)) { // No insert done yet for a parent table
- $sqlSelect = "SELECT ".$fname." FROM " . $tablename;
+ $sqlSelect = "SELECT ".$sanitizedfname." FROM " . $this->db->sanitize($tablename);
$data = array_combine($listfields, $listvalues);
@@ -989,23 +989,38 @@
'@phan-var string[] $where';
$filters = array(); // filters to forge output error message
foreach ($updatekeys as $key) {
+ if (!is_array($objimport->array_import_updatekeys[0]) || !array_key_exists($key, $objimport->array_import_updatekeys[0])) {
+ $this->errors[$error]['lib'] = 'You try to search duplicates on field '.dol_string_nohtmltag($key).' that is not an allowed field.';
+ $this->errors[$error]['type'] = 'UPDATEKEYBADCOLUMN';
+ $error++;
+ break;
+ }
$col = $objimport->array_import_updatekeys[0][$key];
- $key = preg_replace('/^.*\./i', '', $key);
- if (isModEnabled("socialnetworks") && strpos($key, "socialnetworks") !== false) {
- $tmp = explode("_", $key);
- $key = $tmp[0];
+ $keyfordata = preg_replace('/^.*\./i', '', $key);
+ $keyfordata = preg_replace('/[^a-zA-Z0-9\._]/', '', $keyfordata);
+
+ if (isModEnabled("socialnetworks") && strpos($keyfordata, "socialnetworks") !== false) {
+ $tmp = explode("_", $keyfordata);
+ $keyfordata = $tmp[0];
$socialnetwork = $tmp[1];
- $jsondata = $data[$key];
+ $jsondata = $data[$keyfordata];
$json = json_decode($jsondata);
$stringtosearch = json_encode($socialnetwork).':'.json_encode($json->$socialnetwork);
//var_dump($stringtosearch);
//var_dump($this->db->escape($stringtosearch)); // This provide a value for sql string (but not for a like)
- $where[] = $key." LIKE '%".$this->db->escape($this->db->escapeforlike($stringtosearch))."%'";
+ $where[] = $this->db->sanitize($keyfordata)." LIKE '%".$this->db->escape($this->db->escapeforlike($stringtosearch))."%'";
$filters[] = $col." LIKE '%".$this->db->escape($this->db->escapeforlike($stringtosearch))."%'";
//var_dump($where[1]); // This provide a value for sql string inside a like
} else {
- $where[] = $key.' = '.$data[$key];
- $filters[] = $col.' = '.$data[$key];
+ $sanitizedvalue = $data[$keyfordata];
+ if ((string) $sanitizedvalue === '') {
+ $this->errors[$error]['lib'] = 'You request to search duplicates on field '.$keyfordata.' but no value was provided for this field on this line.';
+ $this->errors[$error]['type'] = 'UPDATEKEYBADVALUE';
+ $error++;
+ } else {
+ $where[] = $this->db->sanitize($keyfordata)." = ".$sanitizedvalue;
+ $filters[] = $col." = ".$sanitizedvalue;
+ }
}
}
if (!empty($tablewithentity_cache[$tablename])) {
@@ -1014,29 +1029,31 @@
}
$sqlSelect .= " WHERE " . implode(' AND ', $where);
- $resql = $this->db->query($sqlSelect);
- if ($resql) {
- $num_rows = $this->db->num_rows($resql);
- if ($num_rows == 1) {
- $res = $this->db->fetch_object($resql);
- $lastinsertid = $res->rowid;
- $keyfield = 'rowid';
- if ($is_table_category_link) {
- $lastinsertid = 'linktable';
- } // used to apply update on tables like llx_categorie_product and avoid being blocked for all file content if at least one entry already exists
- $last_insert_id_array[$tablename] = $lastinsertid;
- } elseif ($num_rows > 1) {
- $this->errors[$error]['lib'] = $langs->trans('MultipleRecordFoundWithTheseFilters', implode(', ', $filters));
+ if (!$error) {
+ $resql = $this->db->query($sqlSelect);
+ if ($resql) {
+ $num_rows = $this->db->num_rows($resql);
+ if ($num_rows == 1) {
+ $res = $this->db->fetch_object($resql);
+ $lastinsertid = $res->rowid;
+ $keyfield = 'rowid';
+ if ($is_table_category_link) {
+ $lastinsertid = 'linktable';
+ } // used to apply update on tables like llx_categorie_product and avoid being blocked for all file content if at least one entry already exists
+ $last_insert_id_array[$tablename] = $lastinsertid;
+ } elseif ($num_rows > 1) {
+ $this->errors[$error]['lib'] = $langs->trans('MultipleRecordFoundWithTheseFilters', implode(', ', $filters));
+ $this->errors[$error]['type'] = 'SQL';
+ $error++;
+ } else {
+ // No record found with filters, insert will be tried below
+ }
+ } else {
+ //print 'E';
+ $this->errors[$error]['lib'] = $this->db->lasterror();
$this->errors[$error]['type'] = 'SQL';
$error++;
- } else {
- // No record found with filters, insert will be tried below
}
- } else {
- //print 'E';
- $this->errors[$error]['lib'] = $this->db->lasterror();
- $this->errors[$error]['type'] = 'SQL';
- $error++;
}
} else {
// We have a last INSERT ID (got by previous pass), so we check if we have a row referencing this foreign key.

View File

@@ -2,6 +2,7 @@
lib,
stdenv,
fetchFromGitHub,
fetchpatch,
nixosTests,
stateDir ? "/var/lib/dolibarr",
}:
@@ -17,6 +18,17 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-YJKTaLGaILhCFREtAgmX+vzhXIKp0DIj6jn7TtqtFB4=";
};
patches = [
# Remove when updating to Dolibarr 24.0.0 or a 23.x release containing 24b1b99c89c7.
./CVE-2026-81728.patch
# Remove when updating to Dolibarr 24.0.0 or a 23.x release containing fd478850f823.
(fetchpatch {
name = "CVE-2026-82633.patch";
url = "https://github.com/Dolibarr/dolibarr/commit/fd478850f823e27c672300acb4b02baeef79aef1.patch";
hash = "sha256-OkkQh06r9vnyP/02VIg7ZexT4AQit3rYEgiUC/qnXbg=";
})
];
dontBuild = true;
postPatch = ''

View File

@@ -70,13 +70,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "freerdp";
version = "3.30.0";
version = "3.31.1";
src = fetchFromGitHub {
owner = "FreeRDP";
repo = "FreeRDP";
tag = finalAttrs.version;
hash = "sha256-Fy7TB7cRHXB86deb86eg05Cwf9SHU0C/Qnfj5Ylmjug=";
hash = "sha256-6/YMQLcgOogoXu3Lhwl+g3+Ov59t4x7oOFlVLCa8+RU=";
};
postPatch = ''

View File

@@ -1,18 +1,18 @@
[
{
"pname": "Azure.Core",
"version": "1.50.0",
"hash": "sha256-8Pjz0/2wTLK5uY7G5qrxQr4CsmrjiR8gL4g6zJymj5s="
"version": "1.55.0",
"hash": "sha256-6lPqo+pNn0R1JOhlfg7KwD33Do43y2e1hxK0gX6fvhU="
},
{
"pname": "Azure.Storage.Blobs",
"version": "12.27.0",
"hash": "sha256-Ag8kMe/NBfq+HSchFzm0VAAo9xVnrKHFHUjbQ4KpSh0="
"version": "12.29.2",
"hash": "sha256-eyEuuX8CjJfU5FCzxedc4F3oFMAAeIHcL28rurYCDc4="
},
{
"pname": "Azure.Storage.Common",
"version": "12.26.0",
"hash": "sha256-GPiEPi/caj5z2cMFP5TUx/Jrj/zXZmA/xqC9CEoI+qQ="
"version": "12.28.0",
"hash": "sha256-I1LbKRdd9OLXZRP4jsp3A4WiI4ZVrEA640wqcPry81c="
},
{
"pname": "Castle.Core",
@@ -31,13 +31,13 @@
},
{
"pname": "Microsoft.Bcl.AsyncInterfaces",
"version": "8.0.0",
"hash": "sha256-9aWmiwMJKrKr9ohD1KSuol37y+jdDxPGJct3m2/Bknw="
"version": "10.0.3",
"hash": "sha256-+wTcmczUD1qSnnWZ1miijr62/glcRbNWRpEZh/OBU2g="
},
{
"pname": "Microsoft.Bcl.Cryptography",
"version": "10.0.7",
"hash": "sha256-5hOu8j2jLhCj9m7MlBoCjq3Qo0ST+b8n6oG2lLHL24s="
"version": "10.0.11",
"hash": "sha256-+kdPkD18wpCVndcfoGinCINcr2Yk8Txl0RbJ3gYrNUc="
},
{
"pname": "Microsoft.CodeCoverage",
@@ -46,44 +46,89 @@
},
{
"pname": "Microsoft.DevTunnels.Connections",
"version": "1.3.48",
"hash": "sha256-/E7ik2riVOMUyPt/1pxU7laDHG1pG5JpLIf5cQ7x7K4="
"version": "1.3.51",
"hash": "sha256-0XsrCanwQ4E4BueU4njF0K8Ovczf9K4/mw9EhTxnzPM="
},
{
"pname": "Microsoft.DevTunnels.Contracts",
"version": "1.3.48",
"hash": "sha256-YYmyZWmKv03BnOKAwbAeLrKqYDbBQ4ZS26jn92QkLSc="
"version": "1.3.51",
"hash": "sha256-O2JYXYxzjj4AooGdWsEQ8WgE8IxvPz9L58GJcIVPHF8="
},
{
"pname": "Microsoft.DevTunnels.Management",
"version": "1.3.48",
"hash": "sha256-DyDPqIwQkKJESx5K9Y4nKtw05cHrTlTp56rg/JXuVag="
"version": "1.3.51",
"hash": "sha256-AA6t3lboBSdBYTON2QCEBOYoNW9GPh8OquUiQkBogeE="
},
{
"pname": "Microsoft.DevTunnels.Ssh",
"version": "3.12.24",
"hash": "sha256-+GFTJiVQ5NZy3HeCiFIm4DggKAKPlEb90P/ZBB/rRxc="
"version": "3.12.40",
"hash": "sha256-EB/1D5evYbXJ/1jkeUeLgvOQtuPdT+xaJ4P6Na2vd+Q="
},
{
"pname": "Microsoft.DevTunnels.Ssh.Tcp",
"version": "3.12.24",
"hash": "sha256-NCNAGmQ9ugp5ezJ8adujvP0HRtYkIn4Ly0AWq2nDH9M="
"version": "3.12.40",
"hash": "sha256-UrNqqNYxCNUUO4rCs4PsWX4naaJv3mD+eLf0Dxg1PSg="
},
{
"pname": "Microsoft.Extensions.Configuration.Abstractions",
"version": "10.0.3",
"hash": "sha256-OfcPeDv7RJvvv7ns+wCMAQCdG/He2KtxV6MRlwvp35I="
},
{
"pname": "Microsoft.Extensions.DependencyInjection.Abstractions",
"version": "8.0.2",
"hash": "sha256-UfLfEQAkXxDaVPC7foE/J3FVEXd31Pu6uQIhTic3JgY="
"version": "10.0.3",
"hash": "sha256-ShB94jEtsq5X5r6xDZQ+wotZYG3OPKOCHNGy4B7NVFs="
},
{
"pname": "Microsoft.Extensions.Diagnostics.Abstractions",
"version": "10.0.3",
"hash": "sha256-JglKtC6+jfiggRUU5AXC6mR0cW1t3M33wR7WXKyJjBs="
},
{
"pname": "Microsoft.Extensions.FileProviders.Abstractions",
"version": "10.0.3",
"hash": "sha256-uWAZh/RdMEiwTM2311KlDKK2LBo81tIYXPTUzJXbceA="
},
{
"pname": "Microsoft.Extensions.Hosting.Abstractions",
"version": "10.0.3",
"hash": "sha256-d8zXyTfgVdok+Cgg5EC04DH4iPQtLxlU9CsGy5+dr6s="
},
{
"pname": "Microsoft.Extensions.Logging.Abstractions",
"version": "8.0.3",
"hash": "sha256-5MSY1aEwUbRXehSPHYw0cBZyFcUH4jkgabddxhMiu3Q="
"version": "10.0.3",
"hash": "sha256-lIStSIPTxaoCRoUBHsBPXZbuVj5io02390Wkyepyflw="
},
{
"pname": "Microsoft.Extensions.Options",
"version": "10.0.3",
"hash": "sha256-KDYaVBSdNEuhs3U164RV0n20cjwrpi7uI71B0j/UFsA="
},
{
"pname": "Microsoft.Extensions.Primitives",
"version": "10.0.3",
"hash": "sha256-w0G+IW9kz70ug1BEuJTeS1N7werQhms3gQl6ODzNIpQ="
},
{
"pname": "Microsoft.Extensions.Primitives",
"version": "8.0.0",
"hash": "sha256-FU8qj3DR8bDdc1c+WeGZx/PCZeqqndweZM9epcpXjSo="
},
{
"pname": "Microsoft.Identity.Client",
"version": "4.83.1",
"hash": "sha256-WDt1xgK5hdxSYg6cIK5wXtY4/PB+BaT393gNLawzE8A="
},
{
"pname": "Microsoft.Identity.Client.Extensions.Msal",
"version": "4.83.1",
"hash": "sha256-t4hG5KSzfBfhfZ7dJDBS2wr7v2nnDwRjPs78ZziM/b8="
},
{
"pname": "Microsoft.IdentityModel.Abstractions",
"version": "8.14.0",
"hash": "sha256-bkCuz1Wj56N+LHWLvHKLcCtIRqBK+3k5vD2qfB7xXKk="
},
{
"pname": "Microsoft.Net.Http.Headers",
"version": "8.0.25",
@@ -481,8 +526,8 @@
},
{
"pname": "System.ClientModel",
"version": "1.8.0",
"hash": "sha256-ZWVhuw3IRk9rZXkXERhesEET2KMMzHjUH/HDI288WK8="
"version": "1.11.0",
"hash": "sha256-wLbZlxAXOzKtjrdwrzvBdBTujt1QRwwGlbAa+Jx4PCc="
},
{
"pname": "System.Collections",
@@ -524,6 +569,11 @@
"version": "4.3.0",
"hash": "sha256-fkA79SjPbSeiEcrbbUsb70u9B7wqbsdM9s1LnoKj0gM="
},
{
"pname": "System.Diagnostics.DiagnosticSource",
"version": "10.0.3",
"hash": "sha256-YQzu50E7/1slw8IcFkVpQd33/IyWw1hJapTIscnoF5Q="
},
{
"pname": "System.Diagnostics.DiagnosticSource",
"version": "4.3.0",
@@ -536,8 +586,8 @@
},
{
"pname": "System.Diagnostics.EventLog",
"version": "10.0.7",
"hash": "sha256-fV+2RcEzBV/JUnPDOLce3VBQKqvo32zcTWMZeJcAAJg="
"version": "10.0.9",
"hash": "sha256-asuR1KqI8IdI83alSGSvPmcfNuPHK5WweZ2uAhuxe2U="
},
{
"pname": "System.Diagnostics.EventLog",
@@ -561,8 +611,8 @@
},
{
"pname": "System.Formats.Asn1",
"version": "10.0.7",
"hash": "sha256-s48DCef2td3qUMdsRRGFfzkZ/wl/kUaVseQBDDfWUzM="
"version": "10.0.11",
"hash": "sha256-AQ14gRr3Uyn/FsLbc1jUvIE9XzHaudYBiIy9HmOwuYc="
},
{
"pname": "System.Globalization",
@@ -636,8 +686,13 @@
},
{
"pname": "System.IO.Hashing",
"version": "10.0.1",
"hash": "sha256-k8EHcxnLitXo0CxoDZAxFmUlJJdKZVsZJ2+9zDMYB94="
"version": "10.0.3",
"hash": "sha256-IK2hZpaQysKYAoM0AbEVgTwla5hhqaop7360Tb2tZzk="
},
{
"pname": "System.IO.Pipelines",
"version": "10.0.3",
"hash": "sha256-+LsHlaUFMFVb60U7GFcvD1l7IpEcjdm1+Iw2g+qrUik="
},
{
"pname": "System.IO.Pipelines",
@@ -661,8 +716,8 @@
},
{
"pname": "System.Memory.Data",
"version": "8.0.1",
"hash": "sha256-cxYZL0Trr6RBplKmECv94ORuyjrOM6JB0D/EwmBSisg="
"version": "10.0.3",
"hash": "sha256-HefKyCuNJ7bONOVqGi2WScG6XIoFyfGSwTQM9Ol06+U="
},
{
"pname": "System.Net.Http",
@@ -856,8 +911,8 @@
},
{
"pname": "System.Security.Cryptography.Pkcs",
"version": "10.0.7",
"hash": "sha256-+3RdvoSme0k3FoutPdJLkbWPWsmqPVo80hMgpuH3FP0="
"version": "10.0.11",
"hash": "sha256-+L6ZL7/9VeyMlOJDcNjV/Rb7FMxXctLekfWROU0tMIM="
},
{
"pname": "System.Security.Cryptography.Primitives",
@@ -866,8 +921,8 @@
},
{
"pname": "System.Security.Cryptography.ProtectedData",
"version": "10.0.3",
"hash": "sha256-JF/WTKv00v/C4ml4g/VL3j4JMPpZa1HBmVMvUnphHr4="
"version": "10.0.11",
"hash": "sha256-YZi5wcj1Rfnt4SygMIWtdPNitbMwJeNEbtfpa0gPTtE="
},
{
"pname": "System.Security.Cryptography.X509Certificates",
@@ -896,8 +951,8 @@
},
{
"pname": "System.ServiceProcess.ServiceController",
"version": "10.0.7",
"hash": "sha256-koSlZI43JaCrG3ultJ6Sj7Ic9D9N878L+6HtRRGyJSA="
"version": "10.0.9",
"hash": "sha256-Z3M1YYCnY2dThtLcG7661EEXL3GgN3Ea5L2SXpnp32w="
},
{
"pname": "System.Text.Encoding",
@@ -911,8 +966,8 @@
},
{
"pname": "System.Text.Encoding.CodePages",
"version": "10.0.3",
"hash": "sha256-tDbCCtsmw1O8G9QvH2wyJtF7txxt6lpBy35w5rVZ800="
"version": "10.0.11",
"hash": "sha256-qkR7i03teRNMKtmSc0Ap4NnC3CMsuhfbCaDL/8c7U2E="
},
{
"pname": "System.Text.Encoding.Extensions",
@@ -924,6 +979,16 @@
"version": "4.3.0",
"hash": "sha256-vufHXg8QAKxHlujPHHcrtGwAqFmsCD6HKjfDAiHyAYc="
},
{
"pname": "System.Text.Encodings.Web",
"version": "10.0.3",
"hash": "sha256-TuOSPfi9dfFnHvH5++zIi30JpRERp35HFpm2R0NWUAk="
},
{
"pname": "System.Text.Json",
"version": "10.0.3",
"hash": "sha256-E1gPHMAuk2tR4cyScCfsSlDDerhlLAQCUZZMiByIk18="
},
{
"pname": "System.Text.RegularExpressions",
"version": "4.3.1",
@@ -941,8 +1006,8 @@
},
{
"pname": "System.Threading.Channels",
"version": "10.0.3",
"hash": "sha256-JuimR9Phq1bx34EQzFxWINDyANQV8ZCP2zN2cBydGVI="
"version": "10.0.10",
"hash": "sha256-HCTjxLnKxalcdPZatq5/x1YZPcLExAR9cC8h4c2Ar3s="
},
{
"pname": "System.Threading.Tasks",
@@ -974,6 +1039,11 @@
"version": "4.0.1-rc2-24027",
"hash": "sha256-B3qiX7GvZ6wU9lyg4BEQhspVq0LGcF/W4H+4RwWJfBo="
},
{
"pname": "System.ValueTuple",
"version": "4.5.0",
"hash": "sha256-niH6l2fU52vAzuBlwdQMw0OEoRS/7E1w5smBFoqSaAI="
},
{
"pname": "System.Xml.ReaderWriter",
"version": "4.0.11-rc2-24027",
@@ -1021,8 +1091,8 @@
},
{
"pname": "xunit.runner.visualstudio",
"version": "2.8.2",
"hash": "sha256-UlfK348r8kJuraywfdCtpJJxHkv04wPNzpUaz4UM/60="
"version": "4.0.0",
"hash": "sha256-1CY2ZY7UEnMdeTFXW4dX4xHD1mB4VWuU1Rsa8ROHcQE="
},
{
"pname": "YamlDotNet.Signed",

View File

@@ -35,16 +35,16 @@ assert builtins.all (
buildDotnetModule (finalAttrs: {
pname = "github-runner";
version = "2.336.0";
version = "2.337.0";
src = fetchFromGitHub {
owner = "actions";
repo = "runner";
tag = "v${finalAttrs.version}";
hash = "sha256-wzPGtNdKszDT8VMgL13xUUp+IhP8UzpXVHkR0T2Ns1A=";
hash = "sha256-aM8GmgCkjgaipEDBjC5v6U61WPjCAdKnPEGQypfTzmA=";
leaveDotGit = true;
postFetch = ''
git -C $out rev-parse --short HEAD > $out/.git-revision
git -C $out rev-parse HEAD > $out/.git-revision
rm -rf $out/.git
'';
};
@@ -67,8 +67,8 @@ buildDotnetModule (finalAttrs: {
mkdir -p $TMPDIR/bin
cat > $TMPDIR/bin/git <<EOF
#!${runtimeShell}
if [ \$# -eq 1 ] && [ "\$1" = "rev-parse" ]; then
echo $(cat $TMPDIR/src/.git-revision)
if [ \$# -eq 2 ] && [ "\$1" = "rev-parse" ] && [ "\$2" = "HEAD" ]; then
cat $TMPDIR/src/.git-revision
exit 0
fi
exec ${buildPackages.git}/bin/git "\$@"
@@ -111,6 +111,9 @@ buildDotnetModule (finalAttrs: {
};
postConfigure = ''
# Avoid deriving assembly metadata from the nondeterministic temporary Git commit.
export SourceRevisionId="$(cat .git-revision)"
# Generate src/Runner.Sdk/BuildConstants.cs
dotnet msbuild \
-t:GenerateConstant \
@@ -351,7 +354,7 @@ buildDotnetModule (finalAttrs: {
fi
commit=$($out/bin/Runner.Listener --commit)
if [[ "$commit" != "$(git rev-parse HEAD)" ]]; then
if [[ "$commit" != "$(cat .git-revision)" ]]; then
printf 'Unexpected commit %s' "$commit"
exit 1
fi
@@ -374,7 +377,7 @@ buildDotnetModule (finalAttrs: {
kfollesdal
aanderse
zimbatm
schmittlauch
osnyx
];
platforms = [
"x86_64-linux"

View File

@@ -18,11 +18,11 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "jenkins";
version = "2.568.2";
version = "2.568.3";
src = fetchurl {
url = "https://get.jenkins.io/war-stable/${finalAttrs.version}/jenkins.war";
hash = "sha256-m7srMp5Scwun3s0aehCVmH9iUOx2H7IRV9uyy80e9ZA=";
hash = "sha256-zNv9zq3oNInjQoWk1XwSE0/+oKCcogBiKC5YDL+l8J4=";
};
nativeBuildInputs = [ makeWrapper ];

View File

@@ -12,18 +12,18 @@
}:
buildNpmPackage (finalAttrs: {
pname = "openlist-frontend";
version = "4.2.5";
version = "4.2.6";
src = fetchFromGitHub {
owner = "OpenListTeam";
repo = "OpenList-Frontend";
tag = "v${finalAttrs.version}";
hash = "sha256-AOy8IZnrf3893d33Gkuu8Ktz1WY/FnvhUzbiHf9PpGk=";
hash = "sha256-m/5DoGnmOAVv8PGWwUWEUntiQNAzUbJ5pIhP4JsRt+s=";
};
i18n = fetchzip {
url = "https://github.com/OpenListTeam/OpenList-Frontend/releases/download/v${finalAttrs.version}/i18n.tar.gz";
hash = "sha256-ID8fEVBpq68rrppqx1bx3rwD9hJU/JlEDKuKz5g9DPs=";
hash = "sha256-0+y4/stjTMek65Poq8Qfxadta0UrLefdFHxk6S9MGbM=";
stripRoot = false;
};
@@ -41,7 +41,7 @@ buildNpmPackage (finalAttrs: {
inherit (finalAttrs) pname version src;
pnpm = openlistPnpm;
fetcherVersion = 4;
hash = "sha256-+QW8ViG8jNUiGPPAUuAY2AhzSUHuFOlLYB2uHA0ILpU=";
hash = "sha256-06zs01JrlsCFuOWvREEOGuk/6bR7lwGh7cV7ZeBunzQ=";
};
npmConfigHook = pnpmConfigHook;

View File

@@ -12,13 +12,13 @@
buildGoModule (finalAttrs: {
pname = "openlist";
version = "4.2.5";
version = "4.2.6";
src = fetchFromGitHub {
owner = "OpenListTeam";
repo = "OpenList";
tag = "v${finalAttrs.version}";
hash = "sha256-EVKHCyGJMYrD7nrvBGX1xReAPkgTV7ElAG2Uyu3W1cg=";
hash = "sha256-4mr342eIstv8owkBojPwUq1QZ6EhIqIfvntcYLh98y4=";
# populate values that require us to use git. By doing this in postFetch we
# can delete .git afterwards and maintain better reproducibility of the src.
leaveDotGit = true;
@@ -34,7 +34,7 @@ buildGoModule (finalAttrs: {
frontend = callPackage ./frontend.nix { };
proxyVendor = true;
vendorHash = "sha256-G27D6zDuA4HBEOFUWjwf4+gt8OOHBKsPvuPatBussTM=";
vendorHash = "sha256-Jn+4bQbiJW/1nJ9prnI3UFXmb199WcsWdHxm2mcDsXw=";
nativeBuildInputs = [
installShellFiles

View File

@@ -3,6 +3,7 @@
stdenv,
fetchFromGitHub,
fetchPnpmDeps,
nix-update-script,
# build
brotli,
@@ -21,7 +22,7 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "peertube";
version = "8.2.2";
version = "8.2.4";
__structuredAttrs = true;
strictDeps = true;
@@ -30,7 +31,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "Chocobozzz";
repo = "PeerTube";
tag = "v${finalAttrs.version}";
hash = "sha256-huyuaCWJ3w1KHCcQFjH2ZcofPjqwjLpLt+dg6auD/dQ=";
hash = "sha256-ixSa4VV11vgG607I8PJET+0eC060XpAXIFFqJSJNHvM=";
};
outputs = [
@@ -150,6 +151,7 @@ stdenv.mkDerivation (finalAttrs: {
passthru = {
nodejs = nodejs_24;
tests.peertube = nixosTests.peertube;
updateScript = nix-update-script { };
};
meta = {
@@ -170,6 +172,7 @@ stdenv.mkDerivation (finalAttrs: {
'';
license = lib.licenses.agpl3Plus;
homepage = "https://joinpeertube.org/";
changelog = "https://github.com/Chocobozzz/PeerTube/blob/${finalAttrs.src.rev}/CHANGELOG.md";
platforms = [
"x86_64-linux"
"aarch64-linux"

View File

@@ -66,29 +66,19 @@
stdenv.mkDerivation (finalAttrs: {
pname = "rsyslog";
version = "8.2606.0";
version = "8.2608.0";
src = fetchurl {
url = "https://www.rsyslog.com/files/download/rsyslog/rsyslog-${finalAttrs.version}.tar.gz";
hash = "sha256-JXSz8waOaVXrlO9WQ+K2pbhYXMjqp3IJ/1y8Hi5fceU=";
hash = "sha256-49YMg0BSaMQi+V/ux0BFWhzEuRHQC9hCTV0ScrxQmxo=";
};
patches = [
# Remove with rsyslog 8.2608.0 or newer.
# Remove with the first rsyslog release containing this fix.
(fetchpatch {
name = "CVE-2026-19654.patch";
url = "https://github.com/rsyslog/rsyslog/commit/f7f774228273730ba1075f4cd457ae78303a8f08.patch";
hash = "sha256-ww8Ade2eKrQygJduLMPFjxd/fmBnpQ4ePLEzHffPy90=";
})
# Fix imjournal invalidation reopen busy-loop.
# Remove with rsyslog 8.2608.0 or newer.
# https://github.com/rsyslog/rsyslog/pull/7384
(fetchpatch {
name = "imjournal-invalidation-reopen-busy-loop.patch";
url = "https://github.com/rsyslog/rsyslog/commit/383f80f21f16c3c94e7d7a57b0a5af12cdac9d75.patch";
excludes = [ "ChangeLog" ];
hash = "sha256-RlhXoK+dAPBN2wu4V7GoFw/d+uWQzO7+nUkW5+z7QJY=";
name = "CVE-2026-78002.patch";
url = "https://github.com/rsyslog/rsyslog/commit/667e3f61aec5ee02c5c2ee6f0f8accf6fe4301a9.patch";
hash = "sha256-QsxOJCvr6VBbLbXzednwgvCfisSvNm6zfxPaMFxXVT0=";
})
];

View File

@@ -14,13 +14,13 @@
buildGoModule (finalAttrs: {
pname = "VictoriaMetrics";
version = "1.150.0";
version = "1.151.0";
src = fetchFromGitHub {
owner = "VictoriaMetrics";
repo = "VictoriaMetrics";
tag = "v${finalAttrs.version}";
hash = "sha256-fY8rfWuMk46sNiS+IhQYINxoasmHhUJzBKI2ocROZR8=";
hash = "sha256-LMilqB2enkzZr3zLcwnDLojtFV/lcOsXA9EhjiFarqE=";
};
vendorHash = null;

View File

@@ -6,6 +6,7 @@
dbus,
pango,
cairo,
libxkbcommon,
libxscrnsaver,
libxrandr,
libxi,
@@ -46,6 +47,12 @@ rustPlatform.buildRustPackage (finalAttrs: {
install -Dm444 -t $out/etc/wired wired.ron wired_multilayout.ron
'';
preFixup = ''
patchelf $out/bin/wired \
--add-needed libxkbcommon-x11.so \
--add-rpath ${libxkbcommon}/lib
'';
meta = {
description = "Lightweight notification daemon written in Rust";
homepage = "https://github.com/Toqozz/wired-notify";

View File

@@ -8,16 +8,16 @@
buildGoModule (finalAttrs: {
pname = "xq";
version = "1.5.0";
version = "1.5.1";
src = fetchFromGitHub {
owner = "sibprogrammer";
repo = "xq";
tag = "v${finalAttrs.version}";
hash = "sha256-LjY+BQUrqjBZD3//4CULMiIbOfJXVB394ac1yT5DPaU=";
hash = "sha256-cDZdQ0gmyx3h64l+HlPKj9AJVyKR5EGFPaNU+4xX0pw=";
};
vendorHash = "sha256-ILlqmZwC0azNfvC3f5wSV96X7GPy969YUiIYOrFxJmU=";
vendorHash = "sha256-ZYZgac2AW7Yjy3wYjh+VXK5Ng7+CBZebn4bUX2lt2sc=";
ldflags = [
"-s"

View File

@@ -14,20 +14,20 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "zigbee2mqtt";
version = "2.13.0";
version = "2.14.0";
src = fetchFromGitHub {
owner = "Koenkk";
repo = "zigbee2mqtt";
tag = finalAttrs.version;
hash = "sha256-JSmJXjEF0dQ1sWyXvtLmN9gfAg3PjXWPOlb7xCxz8RI=";
hash = "sha256-xV53JrflZsbprHeEgeCtTTPLVPt1neJgzsY9BTT000U=";
};
pnpmDeps = fetchPnpmDeps {
inherit (finalAttrs) pname version src;
pnpm = pnpm_10;
fetcherVersion = 4;
hash = "sha256-5S3VnPxR7P4dwXcFQSjNbTJ5KOWteb4ZBpTy7gtoY4I=";
hash = "sha256-NnrwIJbWmegTfZl5UGSQs/U4ov6sdV2EaX6aVE5XUJ4=";
};
nativeBuildInputs = [

View File

@@ -444,8 +444,8 @@ in
};
openssl_3 = common {
version = "3.0.21";
hash = "sha256-YX4pr45CH0ZklISkk35IxoXkf0ZIgWfJgviLxOwdUi8=";
version = "3.0.22";
hash = "sha256-Z+vKflDRc4MCgEVIZlNJIZW4PblfhVhwlwG7R7XB74E=";
patches = [
# Support for NIX_SSL_CERT_FILE, motivation:
@@ -474,8 +474,8 @@ in
};
openssl_3_5 = common {
version = "3.5.7";
hash = "sha256-qMDSilKcpID582z1eS4s0hmEVSo8jkqhGiSqMa6smOg=";
version = "3.5.8";
hash = "sha256-qPhKOZGOxkFc52XZtCnTE7qXuBQxacFy5zS5UURk9bI=";
patches = [
# Support for NIX_SSL_CERT_FILE, motivation:
@@ -535,8 +535,8 @@ in
};
openssl_4_0 = common {
version = "4.0.1";
hash = "sha256-LbPzoNbqS1nh8JSs4sjNU23/uHzcOQhMWvoeb3833Qk=";
version = "4.0.2";
hash = "sha256-c2tGdTD5FnN7cDExDMsh2CGMYinmHo4WDNHTRYzVQ6g=";
patches = [
# Support for NIX_SSL_CERT_FILE, motivation: