From 68694ac931304606f4c22549d4ccc1b00a00c608 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 2 Oct 2025 01:00:09 +0000 Subject: [PATCH 01/41] devenv: 1.9 -> 1.9.1 (cherry picked from commit 174cd482e2410833cda7ee398f30931a04cd7f99) --- pkgs/by-name/de/devenv/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/de/devenv/package.nix b/pkgs/by-name/de/devenv/package.nix index f65754fff0d1..f4b97b07c5f5 100644 --- a/pkgs/by-name/de/devenv/package.nix +++ b/pkgs/by-name/de/devenv/package.nix @@ -15,7 +15,7 @@ }: let - version = "1.9"; + version = "1.9.1"; devenvNixVersion = "2.30.4"; devenv_nix = @@ -42,10 +42,10 @@ rustPlatform.buildRustPackage { owner = "cachix"; repo = "devenv"; tag = "v${version}"; - hash = "sha256-MG+c0mo4g9UHSuqibX3OVkiADWmMn/PWDfVhD4U29PM="; + hash = "sha256-v86pQGIWHJPkRryglJSXOp0aEoU6ZtURuURsXLqfqSE="; }; - cargoHash = "sha256-7uB9oC0jHWBFeUtIyVpTjeximU6eSxSCiBzo/whoKxQ="; + cargoHash = "sha256-41VmzZvoRd2pL5/o6apHztpS2XrL4HGPIJPBkUbPL1I="; buildAndTestSubdir = "devenv"; From f4dbec646d742f6a142d5e0850b10b9c785ef2fe Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 4 Oct 2025 17:43:38 +0000 Subject: [PATCH 02/41] paretosecurity: 0.3.8 -> 0.3.11 (cherry picked from commit 652d1da90b182a02b4cb2c9ad418a25cb0119d46) --- pkgs/by-name/pa/paretosecurity/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/pa/paretosecurity/package.nix b/pkgs/by-name/pa/paretosecurity/package.nix index a2b4fb7f56e9..af1940221358 100644 --- a/pkgs/by-name/pa/paretosecurity/package.nix +++ b/pkgs/by-name/pa/paretosecurity/package.nix @@ -17,16 +17,16 @@ buildGoModule (finalAttrs: { webkitgtk_4_1 ]; pname = "paretosecurity"; - version = "0.3.8"; + version = "0.3.11"; src = fetchFromGitHub { owner = "ParetoSecurity"; repo = "agent"; rev = finalAttrs.version; - hash = "sha256-pqqcyWFyJX5IJkkLxAafbQu/8yygBsQL1/BAENFdk4g="; + hash = "sha256-BYSbLeWW0DSVNAgBvWKRLgwDg47QjTbvloGfyCDYIOU="; }; - vendorHash = "sha256-6OQ9SPr9z+uoGeeJwo3jrr1nMECcHgULMvjn2G4uLx4="; + vendorHash = "sha256-hH+4rYvFuDsCa90C1uNM2WaQSYK9n0PpVv6P+o54RoU="; proxyVendor = true; # Skip building the Windows installer From b7ecde50dc423790b571c1b09effe38c3d42d291 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 12 Sep 2025 03:27:07 +0000 Subject: [PATCH 03/41] lock: 1.7.5 -> 1.7.6 (cherry picked from commit 8e63fa6031824306bdbadaf33137e00be3bf57c3) --- pkgs/by-name/lo/lock/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/lo/lock/package.nix b/pkgs/by-name/lo/lock/package.nix index 862a8eaa0e60..92cab5748015 100644 --- a/pkgs/by-name/lo/lock/package.nix +++ b/pkgs/by-name/lo/lock/package.nix @@ -19,13 +19,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "lock"; - version = "1.7.5"; + version = "1.7.6"; src = fetchFromGitHub { owner = "konstantintutsch"; repo = "Lock"; tag = "v${finalAttrs.version}"; - hash = "sha256-vm1Tv3av9x5KZcUwL/yvnE7MeHhdFEutOpbgyWJRR0g="; + hash = "sha256-DfHQKz+DuBnISsX4s0I4+3dvSsCDVGHYp5kcSaUrfjM="; }; strictDeps = true; From cf8d7025d09b7c5527dae9e7bccada976ab09798 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 4 Oct 2025 06:40:34 +0000 Subject: [PATCH 04/41] lock: 1.7.6 -> 1.8.0 (cherry picked from commit fd1eb14a1637c1d3f490025ef692ac9f0b6eb85c) --- pkgs/by-name/lo/lock/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/lo/lock/package.nix b/pkgs/by-name/lo/lock/package.nix index 92cab5748015..e4c969a6b776 100644 --- a/pkgs/by-name/lo/lock/package.nix +++ b/pkgs/by-name/lo/lock/package.nix @@ -19,13 +19,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "lock"; - version = "1.7.6"; + version = "1.8.0"; src = fetchFromGitHub { owner = "konstantintutsch"; repo = "Lock"; tag = "v${finalAttrs.version}"; - hash = "sha256-DfHQKz+DuBnISsX4s0I4+3dvSsCDVGHYp5kcSaUrfjM="; + hash = "sha256-t472uLuuT5QPmfxkRP6wPalblMU68iD2wyKOxSrJfeU="; }; strictDeps = true; From 3507b31995a275314b6b712b6ef6e326af51536a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 8 Sep 2025 23:05:52 +0000 Subject: [PATCH 05/41] sydbox: 3.37.9 -> 3.38.2 (cherry picked from commit 4014ce137cf0a4f28b2c07c65eb404d24ae5a056) --- pkgs/by-name/sy/sydbox/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/sy/sydbox/package.nix b/pkgs/by-name/sy/sydbox/package.nix index 5467a2cc958f..1968fe74d70d 100644 --- a/pkgs/by-name/sy/sydbox/package.nix +++ b/pkgs/by-name/sy/sydbox/package.nix @@ -12,7 +12,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "sydbox"; - version = "3.37.9"; + version = "3.38.2"; outputs = [ "out" @@ -24,10 +24,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "Sydbox"; repo = "sydbox"; tag = "v${finalAttrs.version}"; - hash = "sha256-SG19p7TuN7+TX5tafNBU6R48PzT44WqvGydmpfUo+FU="; + hash = "sha256-yxe3U+n9FL58wI/uk8EM24Mcmxzlk8wmgi0wCu+dcnk="; }; - cargoHash = "sha256-rxlnlu8RziOhSNbCU8ESL0a+f+594E0q+3gmyQLhPaw="; + cargoHash = "sha256-17Ri1QGQFWL/DTjpGEMb4SubsnvHcVTYW6wsjiFR36w="; nativeBuildInputs = [ mandoc From 268d73fbf3bd2e0c71b8bb46a18505ed450fc68d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 30 Sep 2025 22:04:31 +0000 Subject: [PATCH 06/41] sydbox: 3.38.2 -> 3.39.1 (cherry picked from commit 5d5acb3df94ef9d97bafb738a208ff8c0051ff3d) --- pkgs/by-name/sy/sydbox/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/sy/sydbox/package.nix b/pkgs/by-name/sy/sydbox/package.nix index 1968fe74d70d..9951760b51ec 100644 --- a/pkgs/by-name/sy/sydbox/package.nix +++ b/pkgs/by-name/sy/sydbox/package.nix @@ -12,7 +12,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "sydbox"; - version = "3.38.2"; + version = "3.39.1"; outputs = [ "out" @@ -24,10 +24,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "Sydbox"; repo = "sydbox"; tag = "v${finalAttrs.version}"; - hash = "sha256-yxe3U+n9FL58wI/uk8EM24Mcmxzlk8wmgi0wCu+dcnk="; + hash = "sha256-LJHZb4TGo+Lep7yiej2G1H6mXAoEk5ixn/lGDxAWqvg="; }; - cargoHash = "sha256-17Ri1QGQFWL/DTjpGEMb4SubsnvHcVTYW6wsjiFR36w="; + cargoHash = "sha256-mUeJ3A2HW2pXWXW3Abb+aqTaZjVrchYJNCJCDC2Em9s="; nativeBuildInputs = [ mandoc From 433fd94f305621c94fb8a8eb97b1cb115b5faeb4 Mon Sep 17 00:00:00 2001 From: luftmensch-luftmensch Date: Mon, 13 Oct 2025 21:20:52 +0200 Subject: [PATCH 07/41] errands: 46.2.8 -> 46.2.9 (cherry picked from commit c4e48b9fb6c08fb8140ee88ea5601f0750831409) --- pkgs/by-name/er/errands/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/er/errands/package.nix b/pkgs/by-name/er/errands/package.nix index 665a79eee1b1..410d054f3ac2 100644 --- a/pkgs/by-name/er/errands/package.nix +++ b/pkgs/by-name/er/errands/package.nix @@ -18,7 +18,7 @@ }: python3Packages.buildPythonApplication rec { pname = "errands"; - version = "46.2.8"; + version = "46.2.9"; pyproject = false; @@ -26,7 +26,7 @@ python3Packages.buildPythonApplication rec { owner = "mrvladus"; repo = "Errands"; tag = version; - hash = "sha256-Gs3/DPMsoPTxH+fR7H3gPJr8ITrQDPlmw236vDnmBaA"; + hash = "sha256-+x6zp14leFryxwQJdI0UKPp4N0IuJRIX5/94QrlzDAU="; }; nativeBuildInputs = [ From 7c4cdaabe96c688fc4cbf9a88118a2d2145363c6 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 16 Oct 2025 22:31:38 +0000 Subject: [PATCH 08/41] garnet: 1.0.84 -> 1.0.86 (cherry picked from commit 42d199dae18dba1ad0bded02c11c6ccf148cbb4c) --- pkgs/by-name/ga/garnet/deps.json | 29 +++++++++++++++++------------ pkgs/by-name/ga/garnet/package.nix | 4 ++-- 2 files changed, 19 insertions(+), 14 deletions(-) diff --git a/pkgs/by-name/ga/garnet/deps.json b/pkgs/by-name/ga/garnet/deps.json index 59df5983acf4..5259e52e7d4c 100644 --- a/pkgs/by-name/ga/garnet/deps.json +++ b/pkgs/by-name/ga/garnet/deps.json @@ -6,18 +6,18 @@ }, { "pname": "Azure.Core", - "version": "1.47.1", - "hash": "sha256-YJR1bDI9H9lr6p/9QcOWEhnpMD8ePyxxO39S32VAOak=" + "version": "1.47.3", + "hash": "sha256-fWyfqF1lpnap4cF3l9J0fYtZbxIqm6UFsuJgN+/hwW4=" }, { "pname": "Azure.Identity", - "version": "1.15.0", - "hash": "sha256-eqR6Akmrtu4U4fPvkDwMbwk2dPGx+MaKPj+Y80e0/Ak=" + "version": "1.16.0", + "hash": "sha256-vJa746fywiLlC2QoUu2SLf+mQPzGTGxbXzGoWqAUb0Q=" }, { "pname": "Azure.Storage.Blobs", - "version": "12.25.0", - "hash": "sha256-SjIwM1sIBd4I9ShAeaIAfPUzc3K7tbodW6y1vNAD+4U=" + "version": "12.25.1", + "hash": "sha256-OJgmzE7+BJsrqGMErUwG4wmaguYL1zPbhtdQvvqFuHY=" }, { "pname": "Azure.Storage.Common", @@ -126,13 +126,13 @@ }, { "pname": "Microsoft.Identity.Client", - "version": "4.73.1", - "hash": "sha256-cd5ArtDvQK4gdX8M0GHQEsCFWlqpdm6lxvaM2yMHkhc=" + "version": "4.76.0", + "hash": "sha256-v5/iulShs0yMHvNoRo/pbDVYu3tOl9Y7kovSKJbgQnc=" }, { "pname": "Microsoft.Identity.Client.Extensions.Msal", - "version": "4.73.1", - "hash": "sha256-wc4oHBGKCJhAqNIyD4LlugCFvmyiW5iVzGYP88bnWqs=" + "version": "4.76.0", + "hash": "sha256-OCt+XN0tt1URnn0Wh7y19YCNo3ViG5th9HAa6GusFeE=" }, { "pname": "Microsoft.IdentityModel.Abstractions", @@ -181,8 +181,8 @@ }, { "pname": "System.ClientModel", - "version": "1.5.1", - "hash": "sha256-n4PHKtjmFXo37s5yhfUQ9UbfnWplqHpC+wsvlHxctow=" + "version": "1.6.1", + "hash": "sha256-OMnamkT9Nt5ZSR6xPKFmOQRUjdn0a4nP9jkD2eZxxc0=" }, { "pname": "System.Diagnostics.DiagnosticSource", @@ -224,6 +224,11 @@ "version": "8.0.1", "hash": "sha256-cxYZL0Trr6RBplKmECv94ORuyjrOM6JB0D/EwmBSisg=" }, + { + "pname": "System.Numerics.Tensors", + "version": "9.0.9", + "hash": "sha256-wc7lhmydATxle8Wv124yFPT+bkpKpcCQL2TAPGodIAc=" + }, { "pname": "System.Numerics.Vectors", "version": "4.5.0", diff --git a/pkgs/by-name/ga/garnet/package.nix b/pkgs/by-name/ga/garnet/package.nix index c48da99dbe0b..48c8e93411c9 100644 --- a/pkgs/by-name/ga/garnet/package.nix +++ b/pkgs/by-name/ga/garnet/package.nix @@ -8,13 +8,13 @@ buildDotnetModule rec { pname = "garnet"; - version = "1.0.84"; + version = "1.0.86"; src = fetchFromGitHub { owner = "microsoft"; repo = "garnet"; tag = "v${version}"; - hash = "sha256-Bg+WQrGs9HyH3E9Ry4fPrnfDcKL8WuTH798pwHrLIuo="; + hash = "sha256-EmwDc6kbOL++g1Xq4LoV3JuxYWSifOmv8vvWKsU3CE4="; }; projectFile = "main/GarnetServer/GarnetServer.csproj"; From de9ce563108fd06bfa6736cda40de8788eb90207 Mon Sep 17 00:00:00 2001 From: Gliczy <129636582+Gliczy@users.noreply.github.com> Date: Thu, 16 Oct 2025 14:38:39 +0200 Subject: [PATCH 09/41] signal-desktop-bin: update copy-noto-emoji.py and emoji sheets (cherry picked from commit d56912319471fbb6c2668cc99b84cd4f5db796cd) --- .../si/signal-desktop-bin/copy-noto-emoji.py | 25 +++---------------- .../by-name/si/signal-desktop-bin/generic.nix | 11 ++++---- 2 files changed, 8 insertions(+), 28 deletions(-) diff --git a/pkgs/by-name/si/signal-desktop-bin/copy-noto-emoji.py b/pkgs/by-name/si/signal-desktop-bin/copy-noto-emoji.py index 8acaebcb23d7..c873c0b0db4d 100644 --- a/pkgs/by-name/si/signal-desktop-bin/copy-noto-emoji.py +++ b/pkgs/by-name/si/signal-desktop-bin/copy-noto-emoji.py @@ -18,24 +18,6 @@ import sys from pathlib import Path -def signal_name_to_emoji(signal_emoji_name: str) -> str: - r"""Return the emoji corresponding to a Signal emoji name. - - Signal emoji names are concatenations of UTF‐16 code units, - represented in lowercase big‐endian hex padded to four digits. - - >>> signal_name_to_emoji("d83dde36200dd83cdf2bfe0f") - '😶‍🌫️' - >>> b"\xd8\x3d\xde\x36\x20\x0d\xd8\x3c\xdf\x2b\xfe\x0f".decode("utf-16-be") - '😶‍🌫️' - """ - hex_bytes = zip(signal_emoji_name[::2], signal_emoji_name[1::2]) - emoji_utf_16_be = bytes( - int("".join(hex_pair), 16) for hex_pair in hex_bytes - ) - return emoji_utf_16_be.decode("utf-16-be") - - def emoji_to_noto_name(emoji: str) -> str: r"""Return the Noto emoji name of an emoji. @@ -68,16 +50,15 @@ def _main() -> None: for signal_emoji_names in jumbomoji_packs.values(): for signal_emoji_name in signal_emoji_names: - emoji = signal_name_to_emoji(signal_emoji_name) try: shutil.copy( - noto_png_path / f"emoji_u{emoji_to_noto_name(emoji)}.png", - out_path / emoji, + noto_png_path / f"emoji_u{emoji_to_noto_name(signal_emoji_name)}.png", + out_path / signal_emoji_name, ) except FileNotFoundError: print( - f"Missing Noto emoji: {emoji} {signal_emoji_name}", + f"Missing Noto emoji: {signal_emoji_name}", file=sys.stderr, ) continue diff --git a/pkgs/by-name/si/signal-desktop-bin/generic.nix b/pkgs/by-name/si/signal-desktop-bin/generic.nix index 9b0fd4aec65c..e50aeb231456 100644 --- a/pkgs/by-name/si/signal-desktop-bin/generic.nix +++ b/pkgs/by-name/si/signal-desktop-bin/generic.nix @@ -92,12 +92,12 @@ let }); noto-emoji-sheet-32 = fetchurl { - url = "https://raw.githubusercontent.com/iamcal/emoji-data/refs/tags/v15.1.2/sheet_google_32.png"; - hash = "sha256-S03NCTbvB5yeQl62WpLNjNGhjNErtgaOB6tAj/X8vPc="; + url = "https://raw.githubusercontent.com/iamcal/emoji-data/refs/tags/v16.0.0/sheet_google_32.png"; + hash = "sha256-tBfp9s1LvBBla7/V4TtumiVFtV5qTPcxLXW+H6qjSVI="; }; noto-emoji-sheet-64 = fetchurl { - url = "https://raw.githubusercontent.com/iamcal/emoji-data/refs/tags/v15.1.2/sheet_google_64.png"; - hash = "sha256-kZYStR5xAuausSpOD6wJZRJZ1K6nPpweE3aYSgWntS4="; + url = "https://raw.githubusercontent.com/iamcal/emoji-data/refs/tags/v16.0.0/sheet_google_64.png"; + hash = "sha256-eVoMWY0WLJpKriPyGIxge4ybwZEst9hDgkWfjekaOuE="; }; in stdenv.mkDerivation rec { @@ -263,8 +263,7 @@ stdenv.mkDerivation rec { # Fix the desktop link substituteInPlace $out/share/applications/signal-desktop.desktop \ - --replace-fail "/${bindir}/signal-desktop" ${meta.mainProgram} \ - --replace-fail "StartupWMClass=Signal" "StartupWMClass=signal" + --replace-fail "/${bindir}/signal-desktop" ${meta.mainProgram} mv $out/share/applications/signal{-desktop,}.desktop From 0c324aef19a9245b6107e4ca211f9f608456c476 Mon Sep 17 00:00:00 2001 From: Gliczy <129636582+Gliczy@users.noreply.github.com> Date: Thu, 16 Oct 2025 14:38:54 +0200 Subject: [PATCH 10/41] signal-desktop-bin: 7.71.0 -> 7.77.1 (cherry picked from commit 6035553020ebc29538d068648701080094034d97) --- pkgs/by-name/si/signal-desktop-bin/signal-desktop.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/si/signal-desktop-bin/signal-desktop.nix b/pkgs/by-name/si/signal-desktop-bin/signal-desktop.nix index 197937c49e05..9a24b9586266 100644 --- a/pkgs/by-name/si/signal-desktop-bin/signal-desktop.nix +++ b/pkgs/by-name/si/signal-desktop-bin/signal-desktop.nix @@ -1,12 +1,12 @@ { callPackage, commandLineArgs }: callPackage ./generic.nix { inherit commandLineArgs; } rec { pname = "signal-desktop-bin"; - version = "7.71.0"; + version = "7.77.1"; libdir = "opt/Signal"; bindir = libdir; extractPkg = "dpkg-deb -x $downloadedFile $out"; url = "https://updates.signal.org/desktop/apt/pool/s/signal-desktop/signal-desktop_${version}_amd64.deb"; - hash = "sha256-y7ONN6VBVFH8zyXJNM3+cY4JegSolXfhH3T85WiM2Dk="; + hash = "sha256-57sm6wmtp0eXWCv7LviCiBEi5/IysubiuBYSP7eVkkU="; } From 1ac94911f2f0cfd5200b4ae40c90376344dc9034 Mon Sep 17 00:00:00 2001 From: Gliczy <129636582+Gliczy@users.noreply.github.com> Date: Thu, 16 Oct 2025 14:39:11 +0200 Subject: [PATCH 11/41] signal-desktop-bin(aarch64-linux): 7.71.0 -> 7.77.1 (cherry picked from commit 86a71ab2df9b4c22fa5a70fa360b227664859141) --- .../si/signal-desktop-bin/signal-desktop-aarch64.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/si/signal-desktop-bin/signal-desktop-aarch64.nix b/pkgs/by-name/si/signal-desktop-bin/signal-desktop-aarch64.nix index 0133dd2596e7..546c213d48b7 100644 --- a/pkgs/by-name/si/signal-desktop-bin/signal-desktop-aarch64.nix +++ b/pkgs/by-name/si/signal-desktop-bin/signal-desktop-aarch64.nix @@ -1,7 +1,7 @@ { callPackage, commandLineArgs }: callPackage ./generic.nix { inherit commandLineArgs; } { pname = "signal-desktop-bin"; - version = "7.71.0"; + version = "7.77.1"; libdir = "usr/lib64/signal-desktop"; bindir = "usr/bin"; @@ -10,6 +10,6 @@ callPackage ./generic.nix { inherit commandLineArgs; } { bsdtar -xf $downloadedFile -C "$out" ''; - url = "https://download.copr.fedorainfracloud.org/results/useidel/signal-desktop/fedora-42-aarch64/09571107-signal-desktop/signal-desktop-7.71.0-1.fc42.aarch64.rpm"; - hash = "sha256-sNGIkO2HAXl0ykFyZNNV75iVUQ+oRGv6NZW8tVUxfJA="; + url = "https://download.copr.fedorainfracloud.org/results/useidel/signal-desktop/fedora-42-aarch64/09751999-signal-desktop/signal-desktop-7.77.1-1.fc42.aarch64.rpm"; + hash = "sha256-IkAJxq3JK3kKdtLy1lkVUfJNuEStMjn7iQEwsFurwOs="; } From d00ea39e2763ef42a708f37bb251d0c123bc4272 Mon Sep 17 00:00:00 2001 From: Gliczy <129636582+Gliczy@users.noreply.github.com> Date: Thu, 16 Oct 2025 14:39:27 +0200 Subject: [PATCH 12/41] signal-desktop-bin(darwin): 7.71.0 -> 7.77.1 (cherry picked from commit fed69e3a5d3fabec18cec08e5c9e7ac68da2d84a) --- pkgs/by-name/si/signal-desktop-bin/signal-desktop-darwin.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/si/signal-desktop-bin/signal-desktop-darwin.nix b/pkgs/by-name/si/signal-desktop-bin/signal-desktop-darwin.nix index 7ae71cf68b65..495b872e41a6 100644 --- a/pkgs/by-name/si/signal-desktop-bin/signal-desktop-darwin.nix +++ b/pkgs/by-name/si/signal-desktop-bin/signal-desktop-darwin.nix @@ -6,11 +6,11 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "signal-desktop-bin"; - version = "7.71.0"; + version = "7.77.1"; src = fetchurl { url = "https://updates.signal.org/desktop/signal-desktop-mac-universal-${finalAttrs.version}.dmg"; - hash = "sha256-G4wCIzKnWwBYSTuXhZ6681Z2+0Rn2bpvb3vhKMAXFc4="; + hash = "sha256-vnNR5KTdeTKUMlHnjfB+WkBtpcLP+KEmIPoTfk7Q1+w="; }; sourceRoot = "."; From 259a635c5888b4cb7c52f72cbcf4805c22cde9f7 Mon Sep 17 00:00:00 2001 From: Felix Singer Date: Tue, 4 Nov 2025 21:11:58 +0100 Subject: [PATCH 13/41] [release-25.05] gerrit: 3.11.5 -> 3.11.7 Signed-off-by: Felix Singer --- pkgs/by-name/ge/gerrit/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ge/gerrit/package.nix b/pkgs/by-name/ge/gerrit/package.nix index 76a913ac7a6e..a2bf83e090dc 100644 --- a/pkgs/by-name/ge/gerrit/package.nix +++ b/pkgs/by-name/ge/gerrit/package.nix @@ -8,11 +8,11 @@ stdenv.mkDerivation rec { pname = "gerrit"; - version = "3.11.5"; + version = "3.11.7"; src = fetchurl { url = "https://gerrit-releases.storage.googleapis.com/gerrit-${version}.war"; - hash = "sha256-S9hit76hqNUrTfXPetFis3Rs+wA7vGNH+fXprseuBpg="; + hash = "sha256-eDf7MW3ikW2yiPEPVZA5RxRbYeSw0ucbS1rsFcdzdk4="; }; buildCommand = '' From 3762798cbf18997a3b90e8c9dcf7b1bfcd7a101d Mon Sep 17 00:00:00 2001 From: Mio Date: Thu, 6 Nov 2025 11:47:32 +1100 Subject: [PATCH 14/41] linux/hardened/patches/6.12: v6.12.50-hardened1 -> v6.12.56-hardened1 (cherry picked from commit aeb70eaff691d9c68429f3ece8b622dc5fcd768f) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 39103fa98c93..473841e5bcee 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -42,12 +42,12 @@ "6.12": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-v6.12.50-hardened1.patch", - "sha256": "0bzq364d6i7wis9sdljjkzmbvjnv45hmyqikmxagps2rdh57916p", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/v6.12.50-hardened1/linux-hardened-v6.12.50-hardened1.patch" + "name": "linux-hardened-v6.12.56-hardened1.patch", + "sha256": "1s6z7ypkrvd0da5k8wjyidbsi33mgsrj7813nsblrfcs50f65wi4", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/v6.12.56-hardened1/linux-hardened-v6.12.56-hardened1.patch" }, - "sha256": "19bjzhxasj4r6m1lhsa486a96axfigbm06kqa2lwa7y2s5sbsdf4", - "version": "6.12.50" + "sha256": "15pclwn3nbwccdfwcqd3lkmdxwpjkmadhj63acqbzxsjycm2nhsm", + "version": "6.12.56" }, "6.6": { "patch": { From c6f6ec2f7c4a3f14239be37755914594af2ac892 Mon Sep 17 00:00:00 2001 From: Mio Date: Thu, 6 Nov 2025 15:58:19 +1100 Subject: [PATCH 15/41] linux/hardened/patches/5.10: v5.10.245-hardened1 -> v5.10.246-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 473841e5bcee..b34d59de541b 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -2,12 +2,12 @@ "5.10": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-v5.10.245-hardened1.patch", - "sha256": "1yc5bq01nm7h2i8ygv0nnqsy7j31fhl5339al39nd28sffn073hf", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/v5.10.245-hardened1/linux-hardened-v5.10.245-hardened1.patch" + "name": "linux-hardened-v5.10.246-hardened1.patch", + "sha256": "0jdxf6qknp922rp57czbb5vmj6gfwzmf6mjwng1c39gsa2ay1v61", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/v5.10.246-hardened1/linux-hardened-v5.10.246-hardened1.patch" }, - "sha256": "17wxs8i8vd5ivv99ra0sri3wmkw5c22wsaw8nf1xcvys2kmpa7hk", - "version": "5.10.245" + "sha256": "0xd8r8qqgxh3zhqkl4a5plmgsycxrffhpc9q2rwhkp6jd717cszb", + "version": "5.10.246" }, "5.15": { "patch": { From 2d509b64d5412c7a29b53c812d3390aee53ebd83 Mon Sep 17 00:00:00 2001 From: Mio Date: Thu, 6 Nov 2025 15:58:23 +1100 Subject: [PATCH 16/41] linux/hardened/patches/5.15: v5.15.194-hardened1 -> v5.15.196-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index b34d59de541b..5af3e6a91523 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -12,12 +12,12 @@ "5.15": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-v5.15.194-hardened1.patch", - "sha256": "1r2iflsnvg9l9isn5n2d401jvm2pni75vc1g3vbirg55nqp7ykgs", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/v5.15.194-hardened1/linux-hardened-v5.15.194-hardened1.patch" + "name": "linux-hardened-v5.15.196-hardened1.patch", + "sha256": "1k3bc2cdhxmpxl5gjdi69ww4qpxsidaqkiyzbaxb5qq0vf9s45c2", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/v5.15.196-hardened1/linux-hardened-v5.15.196-hardened1.patch" }, - "sha256": "0zi6ihvjmaf940arnc7jjvdqrjf3cvkc9mqc8n24dz85vam6z39l", - "version": "5.15.194" + "sha256": "018ffzi91xh46l7r3fgc4mpri3pxzl6wc1n946vny0lbb59pj5c3", + "version": "5.15.196" }, "5.4": { "patch": { From 5e9a00e1ddbf2f570dfdf36a8deb70013fc7d035 Mon Sep 17 00:00:00 2001 From: Mio Date: Thu, 6 Nov 2025 15:58:28 +1100 Subject: [PATCH 17/41] linux/hardened/patches/5.4: v5.4.300-hardened1 -> v5.4.301-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 5af3e6a91523..f8f7159ede87 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -22,12 +22,12 @@ "5.4": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-v5.4.300-hardened1.patch", - "sha256": "1k6ca8ifcqva6r4qrg403l5d0q9n9ph96vihyz75mzkq08w8kbvb", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/v5.4.300-hardened1/linux-hardened-v5.4.300-hardened1.patch" + "name": "linux-hardened-v5.4.301-hardened1.patch", + "sha256": "0i3cjcbn91pla5g6d7mwp69p368n3rjbighrqx5ydalh2vhzbqhp", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/v5.4.301-hardened1/linux-hardened-v5.4.301-hardened1.patch" }, - "sha256": "0nl1l689d4jq2l39v816yy7z5lzc5dvv8aqn85xlv4najc022jcr", - "version": "5.4.300" + "sha256": "0qkra8ci2mx5p8ngdys2ixsl9s30qdqlq027pr5p3rk0s1k8fwdp", + "version": "5.4.301" }, "6.1": { "patch": { From 5632d19a87e081200ec62e25ab22bdbe127c8cb1 Mon Sep 17 00:00:00 2001 From: Mio Date: Thu, 6 Nov 2025 15:58:33 +1100 Subject: [PATCH 18/41] linux/hardened/patches/6.1: v6.1.155-hardened1 -> v6.1.158-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index f8f7159ede87..0492abfa890b 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -32,12 +32,12 @@ "6.1": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-v6.1.155-hardened1.patch", - "sha256": "0bihz31mic1j6wjfgzkm829d8k1y50p18v024px5yvg1gdkx86ww", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/v6.1.155-hardened1/linux-hardened-v6.1.155-hardened1.patch" + "name": "linux-hardened-v6.1.158-hardened1.patch", + "sha256": "0pvq3sr1rn2fnfbvbskbqsvwf2xw8kk9a3i5578f931rhyyac2xc", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/v6.1.158-hardened1/linux-hardened-v6.1.158-hardened1.patch" }, - "sha256": "0wsw99h2jsrcx9fff59nqjx66l40vywj8qi3j6yvqpq8xsp8g4y2", - "version": "6.1.155" + "sha256": "1nmz4rknw82k9ylyrbm4g2m0hh4lmgkwi1g3gm7hzv04nvyqn1md", + "version": "6.1.158" }, "6.12": { "patch": { From ddfc024a6d67ee56cde6d6896f162fd0dc859c51 Mon Sep 17 00:00:00 2001 From: Mio Date: Thu, 6 Nov 2025 15:58:38 +1100 Subject: [PATCH 19/41] linux/hardened/patches/6.6: v6.6.109-hardened1 -> v6.6.115-hardened1 --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 0492abfa890b..44fb556e1e90 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -52,11 +52,11 @@ "6.6": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-v6.6.109-hardened1.patch", - "sha256": "1hjjacf2gm02wkilimn58ny2y0slazjy1vfm5rx6agjj2pg7nd9f", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/v6.6.109-hardened1/linux-hardened-v6.6.109-hardened1.patch" + "name": "linux-hardened-v6.6.115-hardened1.patch", + "sha256": "0xv7whb6fzqcdycdgx0yn02x3g3wvmdmsbbslxirn1y0122pc1ni", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/v6.6.115-hardened1/linux-hardened-v6.6.115-hardened1.patch" }, - "sha256": "1x1h2x04xvds8k59x36zqxzbj4cm6yl5l6xacgfyxzccfycwscbp", - "version": "6.6.109" + "sha256": "0iwhzlrqcw9hzr21gn0pmsjix0d022a7g38vszx4jsqgimgc160a", + "version": "6.6.115" } } From ef5ef9495727060eb4d409d530d42e5af916e3ab Mon Sep 17 00:00:00 2001 From: Sizhe Zhao Date: Thu, 6 Nov 2025 10:35:24 +0800 Subject: [PATCH 20/41] wechat: 4.1.4.12-31227 -> 4.1.4.15-31252 for darwin (cherry picked from commit 1f34c4856fb29fa535bd35f64e0ce0f483298954) --- pkgs/by-name/we/wechat/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/we/wechat/package.nix b/pkgs/by-name/we/wechat/package.nix index 106a00ad2054..5fb0e58efb5a 100644 --- a/pkgs/by-name/we/wechat/package.nix +++ b/pkgs/by-name/we/wechat/package.nix @@ -30,14 +30,14 @@ let # https://dldir1.qq.com/weixin/mac/mac-release.xml any-darwin = let - version = "4.1.4.12-31227"; + version = "4.1.4.15-31252"; version' = lib.replaceString "-" "_" version; in { inherit version; src = fetchurl { url = "https://dldir1v6.qq.com/weixin/Universal/Mac/xWeChatMac_universal_${version'}.dmg"; - hash = "sha256-xVWEABH3dzQkQpmhJ3gKXJd9lQ4fqN7ptkWLTpJ4vaY="; + hash = "sha256-nG9fYaQjeCwYFV7yKdlUxbXnFALc1VomQ/hnGQtJ17o="; }; }; in From 21722855859dc4f02ea512fee64dea467789a92a Mon Sep 17 00:00:00 2001 From: Sizhe Zhao Date: Thu, 6 Nov 2025 10:51:51 +0800 Subject: [PATCH 21/41] wechat: 4.1.0.10 -> 4.1.0.13 for {aarch64,x86_64}-linux (cherry picked from commit 865a7c548b610d2f1b2cb04448c2e78f6e914b0d) --- pkgs/by-name/we/wechat/package.nix | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/we/wechat/package.nix b/pkgs/by-name/we/wechat/package.nix index 5fb0e58efb5a..5b748f1fac79 100644 --- a/pkgs/by-name/we/wechat/package.nix +++ b/pkgs/by-name/we/wechat/package.nix @@ -45,17 +45,17 @@ let aarch64-darwin = any-darwin; x86_64-darwin = any-darwin; aarch64-linux = { - version = "4.1.0.10"; + version = "4.1.0.13"; src = fetchurl { - url = "https://web.archive.org/web/20250930121708/https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_arm64.AppImage"; - hash = "sha256-qkNLA8nILsIi2ciIzr9pb3PejhbEvZ5fe4GlmjyjrEI="; + url = "https://web.archive.org/web/20251106024910/https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_arm64.AppImage"; + hash = "sha256-/d5crM6IGd0k0fSlBSQx4TpIVX/8iib+an0VMkWMNdw="; }; }; x86_64-linux = { - version = "4.1.0.10"; + version = "4.1.0.13"; src = fetchurl { - url = "https://web.archive.org/web/20250930121506/https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_x86_64.AppImage"; - hash = "sha256-d/zdb69gmIcgAFCbWLKGfmD8ZFfuDlYdOy7vUJ7SiXc="; + url = "https://web.archive.org/web/20251106024907/https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_x86_64.AppImage"; + hash = "sha256-+r5Ebu40GVGG2m2lmCFQ/JkiDsN/u7XEtnLrB98602w="; }; }; }; From 70a6693886107028e11b544752edf73f4f903ce2 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 12:11:00 +0100 Subject: [PATCH 22/41] workflows/pull-request-target: remove leftover secret This was used for reviewers.yml, which has been removed. (cherry picked from commit c58139723adf1499014faf5ceb4e65ac236ee07c) --- .github/workflows/pull-request-target.yml | 3 --- 1 file changed, 3 deletions(-) diff --git a/.github/workflows/pull-request-target.yml b/.github/workflows/pull-request-target.yml index a3774366bc9b..f74ce93de354 100644 --- a/.github/workflows/pull-request-target.yml +++ b/.github/workflows/pull-request-target.yml @@ -12,9 +12,6 @@ on: required: true NIXPKGS_CI_APP_PRIVATE_KEY: required: true - OWNER_APP_PRIVATE_KEY: - # The Test workflow should not actually request reviews from owners. - required: false concurrency: group: pr-${{ github.workflow }}-${{ github.event_name }}-${{ github.event.pull_request.number || github.run_id }} From c6adb4f415e7df7294d34b72c34336145264143f Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 12:11:34 +0100 Subject: [PATCH 23/41] workflows/teams: use single token in team sync The nixpkgs-ci app now has all the privileges needed to see the member lists anyway, so no need for two apps / tokens anymore. (cherry picked from commit 1742aef1e988b884b81d6b6060be33d1b8dd1a41) --- .github/workflows/teams.yml | 27 +++++++++++---------------- 1 file changed, 11 insertions(+), 16 deletions(-) diff --git a/.github/workflows/teams.yml b/.github/workflows/teams.yml index 1cd54cd527e0..b848983b5aa2 100644 --- a/.github/workflows/teams.yml +++ b/.github/workflows/teams.yml @@ -16,13 +16,17 @@ jobs: sync: runs-on: ubuntu-24.04-arm steps: + # Use a GitHub App to create the PR so that CI gets triggered and to + # request team member lists. - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 - id: team-token + id: app-token with: - app-id: ${{ vars.OWNER_APP_ID }} - private-key: ${{ secrets.OWNER_APP_PRIVATE_KEY }} + app-id: ${{ vars.NIXPKGS_CI_APP_ID }} + private-key: ${{ secrets.NIXPKGS_CI_APP_PRIVATE_KEY }} permission-administration: read + permission-contents: write permission-members: read + permission-pull-requests: write - name: Fetch source uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 @@ -38,7 +42,7 @@ jobs: - name: Synchronise teams uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 with: - github-token: ${{ steps.team-token.outputs.token }} + github-token: ${{ steps.app-token.outputs.token }} script: | require('./ci/github-script/get-teams.js')({ github, @@ -47,20 +51,11 @@ jobs: outFile: "maintainers/github-teams.json" }) - # Use a GitHub App to create the PR so that CI gets triggered - - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 - id: sync-token - with: - app-id: ${{ vars.NIXPKGS_CI_APP_ID }} - private-key: ${{ secrets.NIXPKGS_CI_APP_PRIVATE_KEY }} - permission-contents: write - permission-pull-requests: write - - name: Get GitHub App User Git String id: user env: - GH_TOKEN: ${{ steps.sync-token.outputs.token }} - APP_SLUG: ${{ steps.sync-token.outputs.app-slug }} + GH_TOKEN: ${{ steps.app-token.outputs.token }} + APP_SLUG: ${{ steps.app-token.outputs.app-slug }} run: | name="${APP_SLUG}[bot]" userId=$(gh api "/users/$name" --jq .id) @@ -70,7 +65,7 @@ jobs: - name: Create Pull Request uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8 with: - token: ${{ steps.sync-token.outputs.token }} + token: ${{ steps.app-token.outputs.token }} add-paths: maintainers/github-teams.json author: ${{ steps.user.outputs.git-string }} committer: ${{ steps.user.outputs.git-string }} From 1fd41c45c243133d1dfbad73c067861c16a9a872 Mon Sep 17 00:00:00 2001 From: "nixpkgs-ci[bot]" <190413589+nixpkgs-ci[bot]@users.noreply.github.com> Date: Thu, 6 Nov 2025 11:37:24 +0000 Subject: [PATCH 24/41] maintainers/github-teams.json: Automated sync (cherry picked from commit 289ec9eb7bc5e7c927afc6052ddf531f17ee7820) --- maintainers/github-teams.json | 1 - 1 file changed, 1 deletion(-) diff --git a/maintainers/github-teams.json b/maintainers/github-teams.json index e67875efe6c5..289edd306687 100644 --- a/maintainers/github-teams.json +++ b/maintainers/github-teams.json @@ -724,7 +724,6 @@ "description": "Provides leadership for and has authority over Nixpkgs.", "id": 14317027, "maintainers": { - "K900": 386765, "alyssais": 2768870, "emilazy": 18535642, "wolfgangwalther": 9132420 From 9d3e7534f58a4e0da6209c376e3622dfa12a0521 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 11:15:48 +0100 Subject: [PATCH 25/41] ci/github-script/bot: fix needs reviewer label The recent change to use the result of requesting reviewers for setting the `needs: reviewer` label caused a regression: It would not set the label for PRs where no reviewers were requested, because *too many were eligible*. Still - these PRs don't have reviewers, so they need attention otherwise - via the label. (cherry picked from commit 4658d0d5a3affe8457c74351bf012fc9e17fa417) --- ci/github-script/reviewers.js | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/ci/github-script/reviewers.js b/ci/github-script/reviewers.js index 2ac0d346f369..c5f79c11d992 100644 --- a/ci/github-script/reviewers.js +++ b/ci/github-script/reviewers.js @@ -64,14 +64,6 @@ async function handleReviewers({ ).filter(Boolean) log('reviewers - reviewers', reviewers.join(', ')) - if (reviewers.length > 15) { - log( - `Too many reviewers (${reviewers.join(', ')}), skipping review requests.`, - ) - // false indicates, that we do have reviewers and don't need the "needs: reviewers" label. - return false - } - const requested_reviewers = new Set( pull_request.requested_reviewers.map(({ login }) => login), ) @@ -88,6 +80,14 @@ async function handleReviewers({ Array.from(existing_reviewers).join(', '), ) + if (reviewers.length > 15) { + log( + `Too many reviewers (${reviewers.join(', ')}), skipping review requests.`, + ) + // Return a boolean on whether the "needs: reviewers" label should be set. + return existing_reviewers.size === 0 && requested_reviewers.size === 0 + } + const non_requested_reviewers = new Set(reviewers) .difference(requested_reviewers) // We don't want to rerequest reviews from people who already reviewed. @@ -117,7 +117,7 @@ async function handleReviewers({ // Return a boolean on whether the "needs: reviewers" label should be set. return ( - new_reviewers.size === 0 && + non_requested_reviewers.size === 0 && existing_reviewers.size === 0 && requested_reviewers.size === 0 ) From 77c058c7cfd68500956769598a77e5e2e1f696d2 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 6 Nov 2025 11:49:10 +0000 Subject: [PATCH 26/41] linuxKernel.kernels.linux_zen: 6.17.6 -> 6.17.7 (cherry picked from commit 3d70e7f1af76d87403edf921173d9c7f481ade78) --- pkgs/os-specific/linux/kernel/zen-kernels.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/zen-kernels.nix b/pkgs/os-specific/linux/kernel/zen-kernels.nix index a1c407410d10..ff88e2dc7c64 100644 --- a/pkgs/os-specific/linux/kernel/zen-kernels.nix +++ b/pkgs/os-specific/linux/kernel/zen-kernels.nix @@ -16,9 +16,9 @@ let variants = { # ./update-zen.py zen zen = { - version = "6.17.6"; # zen + version = "6.17.7"; # zen suffix = "zen1"; # zen - sha256 = "0kkrfmxj1q7il7njc1s8fnn459rcgviyy5q2kbynasrqij5kdciy"; # zen + sha256 = "01dh7cdqa4rx0fmr22yyn8d6qb8ns7v0x53k2ij3vrp9pz6p5cs4"; # zen isLqx = false; }; # ./update-zen.py lqx From 21ae50d478eded13101946a8bf9a54518511ca32 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Mon, 1 Sep 2025 13:57:55 -0700 Subject: [PATCH 27/41] python313Packages.mat2: fix broken test (cherry picked from commit 16dfcab9b6191f7984da06762474c79e8cbf42fb) --- pkgs/development/python-modules/mat2/default.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/development/python-modules/mat2/default.nix b/pkgs/development/python-modules/mat2/default.nix index 164faca0fe6d..19ec148450c4 100644 --- a/pkgs/development/python-modules/mat2/default.nix +++ b/pkgs/development/python-modules/mat2/default.nix @@ -41,6 +41,16 @@ buildPythonPackage rec { url = "https://0xacab.org/jvoisin/mat2/-/commit/473903b70e1b269a6110242a9c098a10c18554e2.patch"; hash = "sha256-vxxjAFwiTDlcTT3ZlfhOG4rlzBJS+LhLoA++8y2hEok="; }) + (fetchpatch { + name = "fix-test-on-python313.patch"; + url = "https://0xacab.org/jvoisin/mat2/-/commit/f07344444d6d2f04a1f93e2954f4910b194bee0c.patch"; + hash = "sha256-y756sKkjGO11A2lrRsXAwWgupOZ00u0cDypvkbsiNbY="; + }) + (fetchpatch { + name = "fix-test-on-python312.patch"; + url = "https://0xacab.org/jvoisin/mat2/-/commit/7a8ea224bc327b8ee929379d577c74968ea1c352.patch"; + hash = "sha256-pPiYhoql5WhjhLKvd6y3OnvxORSbXIGCsZMc7UH3i1Q="; + }) # hardcode paths to some binaries (replaceVars ./paths.patch { exiftool = lib.getExe exiftool; From 8df2b3b7aa0843ab6ca96ce547e8404aa3d2e39f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Tue, 4 Nov 2025 15:59:09 -0800 Subject: [PATCH 28/41] python312Packages.mat2: fix tests (cherry picked from commit e7e92a1a28f20365a8a513d640e549940dc95fcf) --- pkgs/development/python-modules/mat2/default.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/development/python-modules/mat2/default.nix b/pkgs/development/python-modules/mat2/default.nix index 19ec148450c4..a934ff16b8bc 100644 --- a/pkgs/development/python-modules/mat2/default.nix +++ b/pkgs/development/python-modules/mat2/default.nix @@ -64,6 +64,11 @@ buildPythonPackage rec { ./executable-name.patch # hardcode path to mat2 executable ./tests.patch + (fetchpatch { + name = "fix-test_html.patch"; + url = "https://github.com/jvoisin/mat2/commit/00b4f110711754496932c59d5af3c0b2ed694484.patch"; + hash = "sha256-5h/nM1dK8HmYtoIBVGOvUegMFBpGxcfpn5O6QrjLi9M="; + }) ] ++ lib.optionals (stdenv.hostPlatform.isLinux) [ (replaceVars ./bubblewrap-path.patch { From 988c42dc90bf07c3653d8db8659d6aeae3b0813d Mon Sep 17 00:00:00 2001 From: emilylange Date: Thu, 6 Nov 2025 14:43:10 +0100 Subject: [PATCH 29/41] chromium,chromedriver: 142.0.7444.59 -> 142.0.7444.134 https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop.html This update includes 5 security fixes. CVEs: CVE-2025-12725 CVE-2025-12726 CVE-2025-12727 CVE-2025-12728 CVE-2025-12729 (cherry picked from commit 0bdc7c415b27deff14ab884bfa6a90ce103dab8b) --- .../networking/browsers/chromium/info.json | 24 +++++++++---------- 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/info.json b/pkgs/applications/networking/browsers/chromium/info.json index 1725526143ae..1c0ee2a7a319 100644 --- a/pkgs/applications/networking/browsers/chromium/info.json +++ b/pkgs/applications/networking/browsers/chromium/info.json @@ -1,10 +1,10 @@ { "chromium": { - "version": "142.0.7444.59", + "version": "142.0.7444.134", "chromedriver": { - "version": "142.0.7444.60", - "hash_darwin": "sha256-5Atr7h0jIneU4VbSF20j+3tcYVneYvqOsJ0GG8sD7r4=", - "hash_darwin_aarch64": "sha256-sh2BTEKJaAYbiuNYiSW6iChiCroo95EHoGqxVgX6Jw0=" + "version": "142.0.7444.135", + "hash_darwin": "sha256-i34SR1pfHcAA4N4ppIioa7r33PnvY0OYA8/+U1bQFs8=", + "hash_darwin_aarch64": "sha256-dsbjEDkZ0AVghazgF5w9O3aUWZNSy8R9WiHn9m/Sa9g=" }, "deps": { "depot_tools": { @@ -21,8 +21,8 @@ "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "4b8153ab58d3c3f4c9f7e4baad9616ecf80db5fa", - "hash": "sha256-RZQD9aL/YglC8chM7tqtB1Y2u6DF+6kkgwklUohaBXc=", + "rev": "b6965f826881a60c51151cfc0a0175966a0a4e81", + "hash": "sha256-NTBQrGihsT7kuY/Mac5s4oH1xEn3CFEAR6eOEvZwmYs=", "recompress": true }, "src/third_party/clang-format/script": { @@ -132,8 +132,8 @@ }, "src/third_party/dawn": { "url": "https://dawn.googlesource.com/dawn.git", - "rev": "cee9cb0d67e749bf42f5e90cb3b8a6f525dbb920", - "hash": "sha256-loKRLJfTxBxlTbPVWZqGdx0DyPvEopbs2zIf4gaxoLo=" + "rev": "95f9c2b375395cc82941babdf1e9f0cf60a32831", + "hash": "sha256-BFJsVt7hkSyyPQiX7QCN7Fu6CgTF/2xwAQbWCkJVq6M=" }, "src/third_party/dawn/third_party/glfw": { "url": "https://chromium.googlesource.com/external/github.com/glfw/glfw", @@ -257,8 +257,8 @@ }, "src/third_party/devtools-frontend/src": { "url": "https://chromium.googlesource.com/devtools/devtools-frontend", - "rev": "38cfe98a56a034da33ee62a5f1ea235fe47f58a7", - "hash": "sha256-bUJuFEDqgUFdMfmMyroX4s2ky/2n37PsTWaV+iQHCJg=" + "rev": "f063edc91e3610a60fb9d486ae8694f2a11fcd17", + "hash": "sha256-qiucde85rKA7TefveIa++sOF+MzT56pe8pHUUCj9Zeo=" }, "src/third_party/dom_distiller_js/dist": { "url": "https://chromium.googlesource.com/chromium/dom-distiller/dist.git", @@ -807,8 +807,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "bb294624702efbb17691b642333f06bf5108e600", - "hash": "sha256-ovlKdiBYD9RAjA1XI0PLp/pt25LAvm3fn5AqWlJQfgs=" + "rev": "4427aa4a9c14d3d542866c0ed2ae8a8554cfd68d", + "hash": "sha256-SL9YaplMFA1Ez11bIzAfl/F5qQob/PvCP1uknP1LiLs=" } } }, From 08dbadacbcc01263d6ad39f95e339b8de2068a34 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 16:07:31 +0100 Subject: [PATCH 30/41] ci/github-script/merge: ignore PRs with >= 100 files We use the files endpoint to get a list of all *names* of files touched in the PR - but this endpoint will also actually download the files / their diff, too. That's pointless and actually takes quite some time for huge treewides. We're just putting in a stop-gap for now, so that we're not burning more than 1 API requests on this and don't spend so much time on it either. A limit of 99 files will be more than enough for quite some time - we will only need to raise this when we're able to represent package sets in by-name properly and have "package set maintainers", who are not committers. (cherry picked from commit 51acc56dcb07fa099efc7f8ec921e4e2c67f3732) --- ci/github-script/merge.js | 19 ++++++++++++++----- 1 file changed, 14 insertions(+), 5 deletions(-) diff --git a/ci/github-script/merge.js b/ci/github-script/merge.js index 688a7928fe97..674d8153a7e9 100644 --- a/ci/github-script/merge.js +++ b/ci/github-script/merge.js @@ -128,11 +128,20 @@ async function handleMerge({ (await getTeamMembers('nixpkgs-committers')).map(({ id }) => id), ) - const files = await github.paginate(github.rest.pulls.listFiles, { - ...context.repo, - pull_number, - per_page: 100, - }) + const files = ( + await github.rest.pulls.listFiles({ + ...context.repo, + pull_number, + per_page: 100, + }) + ).data + + // Early exit to prevent treewides from using up a lot of API requests (and time!) to list + // all the files in the pull request. For now, the merge-bot will not work when 100 or more + // files are touched in a PR - which should be more than fine. + // TODO: Find a more efficient way of downloading all the *names* of the touched files, + // including an early exit when the first non-by-name file is found. + if (files.length >= 100) return false // Only look through comments *after* the latest (force) push. const lastPush = events.findLastIndex( From 731f801d31326e78ab74df21709775d84141772c Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 16:11:01 +0100 Subject: [PATCH 31/41] ci/github-script/reviewers: exit early for treewides When hitting a treewide, we would previously find the username for each user and then check all of them for collaborator status - only to then realize that this results in more than 15 reviewers and exit. We can put a simple stop-gap in, even before de-duplicating the combined lists of maintainers and owners as safe guard. We could still hit huge numbers of code owners, but in practice we don't nearly as many as maintainers, so this will be sufficient for now. (cherry picked from commit 9efe926863c5d4e087057fe610ef9eb73fa942a7) --- ci/github-script/reviewers.js | 46 ++++++++++++++++++++++------------- 1 file changed, 29 insertions(+), 17 deletions(-) diff --git a/ci/github-script/reviewers.js b/ci/github-script/reviewers.js index c5f79c11d992..eefa87e36d65 100644 --- a/ci/github-script/reviewers.js +++ b/ci/github-script/reviewers.js @@ -13,6 +13,34 @@ async function handleReviewers({ }) { const pull_number = pull_request.number + const requested_reviewers = new Set( + pull_request.requested_reviewers.map(({ login }) => login), + ) + log( + 'reviewers - requested_reviewers', + Array.from(requested_reviewers).join(', '), + ) + + const existing_reviewers = new Set( + reviews.map(({ user }) => user?.login).filter(Boolean), + ) + log( + 'reviewers - existing_reviewers', + Array.from(existing_reviewers).join(', '), + ) + + // Early sanity check, before we start making any API requests. The list of maintainers + // does not have duplicates so the only user to filter out from this list would be the + // PR author. Therefore, we check for a limit of 15+1, where 15 is the limit we check + // further down again. + // This is to protect against huge treewides consuming all our API requests for no + // reason. + if (maintainers.length > 16) { + core.warning('Too many potential reviewers, skipping review requests.') + // Return a boolean on whether the "needs: reviewers" label should be set. + return existing_reviewers.size === 0 && requested_reviewers.size === 0 + } + const users = new Set([ ...(await Promise.all( maintainers.map(async (id) => (await getUser(id)).login), @@ -64,24 +92,8 @@ async function handleReviewers({ ).filter(Boolean) log('reviewers - reviewers', reviewers.join(', ')) - const requested_reviewers = new Set( - pull_request.requested_reviewers.map(({ login }) => login), - ) - log( - 'reviewers - requested_reviewers', - Array.from(requested_reviewers).join(', '), - ) - - const existing_reviewers = new Set( - reviews.map(({ user }) => user?.login).filter(Boolean), - ) - log( - 'reviewers - existing_reviewers', - Array.from(existing_reviewers).join(', '), - ) - if (reviewers.length > 15) { - log( + core.warning( `Too many reviewers (${reviewers.join(', ')}), skipping review requests.`, ) // Return a boolean on whether the "needs: reviewers" label should be set. From eeb3971911bf05d35684cd506e6338a0f98de8c8 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 16:11:36 +0100 Subject: [PATCH 32/41] ci/github-script/reviewers: add TODO about future optimization We still use a few too many API requests by checking team members for collaborator status - we can improve on that in the future. (cherry picked from commit 17199e5ff6d970c47338c22b07e5e39e305f2a8b) --- ci/github-script/reviewers.js | 3 +++ 1 file changed, 3 insertions(+) diff --git a/ci/github-script/reviewers.js b/ci/github-script/reviewers.js index eefa87e36d65..07a77a5fec0d 100644 --- a/ci/github-script/reviewers.js +++ b/ci/github-script/reviewers.js @@ -75,6 +75,9 @@ async function handleReviewers({ const reviewers = ( await Promise.all( Array.from(new_reviewers, async (username) => { + // TODO: Restructure this file to only do the collaborator check for those users + // who were not already part of a team. Being a member of a team makes them + // collaborators by definition. try { await github.rest.repos.checkCollaborator({ ...context.repo, From 59923caae0c773e16df10ca24ea7c6851f4b93f8 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 16:16:30 +0100 Subject: [PATCH 33/41] ci/github-script/bot: limit concurrency in PR runs This lead to reaching secondary API limits in a treewide recently, so we better limit it to where we actually need it. (cherry picked from commit cd7f83638e0e96f667ce904a3f0363967f654cef) --- ci/github-script/bot.js | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/ci/github-script/bot.js b/ci/github-script/bot.js index c66a91583140..34abe96941fb 100644 --- a/ci/github-script/bot.js +++ b/ci/github-script/bot.js @@ -576,7 +576,10 @@ module.exports = async ({ github, context, core, dry }) => { // Controls level of parallelism. Applies to both the number of concurrent requests // as well as the number of concurrent workers going through the list of PRs. - const maxConcurrent = 20 + // We'll only boost concurrency when we're running many PRs in parallel on a schedule, + // but not for single PRs. This avoids things going wild, when we accidentally make + // too many API requests on treewides. + const maxConcurrent = context.eventName === 'pull_request' ? 1 : 20 await withRateLimit({ github, core, maxConcurrent }, async (stats) => { if (context.payload.pull_request) { From f8acc6cb1ed750beacd7861fb3b4f088fbb476b7 Mon Sep 17 00:00:00 2001 From: Petr Portnov Date: Mon, 27 Oct 2025 02:13:10 +0300 Subject: [PATCH 34/41] chatzone-desktop: 5.4.1 -> 5.5.0 (cherry picked from commit 7bff6223a9bce201d89550e06d2105ab1542dcac) --- pkgs/by-name/ch/chatzone-desktop/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ch/chatzone-desktop/package.nix b/pkgs/by-name/ch/chatzone-desktop/package.nix index 8937af5b3287..f589409a1c01 100644 --- a/pkgs/by-name/ch/chatzone-desktop/package.nix +++ b/pkgs/by-name/ch/chatzone-desktop/package.nix @@ -10,10 +10,10 @@ let pname = "chatzone-desktop"; - version = "5.4.1"; + version = "5.5.0"; src = fetchurl { - url = "https://cdn1.ozone.ru/s3/chatzone-clients/ci/5.4.1/872/chatzone-desktop-linux-5.4.1.AppImage"; - hash = "sha256-ONr8rIP7oXtafACkW4fDHfYew83F4R8un+hGdVI75iA="; + url = "https://cdn1.ozone.ru/s3/chatzone-clients/ci/5.5.0/925/chatzone-desktop-linux-5.5.0.AppImage"; + hash = "sha256-2Ly0qABTqleqH0AoAIJ+JNYFyoikxZroiFrYwSxBtdw="; }; appimageContents = appimageTools.extract { inherit pname version src; }; in From d4f704a8f470a30c70afa8f288ee67e3e203e6af Mon Sep 17 00:00:00 2001 From: Yueh-Shun Li Date: Thu, 6 Nov 2025 19:34:30 +0800 Subject: [PATCH 35/41] lib.extendMkDerivation: adjust default value documentation (cherry picked from commit 918e017d6436ce1683d92af1ee4949e606fb1933) --- lib/customisation.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index db138da4a2ef..4a8e10cf9cc7 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -752,11 +752,11 @@ rec { # Inputs `extendMkDerivation`-specific configurations - : `constructDrv`: Base build helper, the `mkDerivation`-like build helper to extend. - : `excludeDrvArgNames`: Argument names not to pass from the input fixed-point arguments to `constructDrv`. Note: It doesn't apply to the updating arguments returned by `extendDrvArgs`. - : `extendDrvArgs` : An extension (overlay) of the argument set, like the one taken by [overrideAttrs](#sec-pkg-overrideAttrs) but applied before passing to `constructDrv`. - : `inheritFunctionArgs`: Whether to inherit `__functionArgs` from the base build helper (default to `true`). - : `transformDrv`: Function to apply to the result derivation (default to `lib.id`). + : `constructDrv` (required): Base build helper, the `mkDerivation`-like build helper to extend. + : `excludeDrvArgNames` (default to `[ ]`): Argument names not to pass from the input fixed-point arguments to `constructDrv`. Note: It doesn't apply to the updating arguments returned by `extendDrvArgs`. + : `extendDrvArgs` (required): An extension (overlay) of the argument set, like the one taken by [overrideAttrs](#sec-pkg-overrideAttrs) but applied before passing to `constructDrv`. + : `inheritFunctionArgs` (default to `true`): Whether to inherit `__functionArgs` from the base build helper. + : `transformDrv` (default to `lib.id`): Function to apply to the result derivation. # Type From edbac72fadb61a34073b094bea9c28f39ae6f9f2 Mon Sep 17 00:00:00 2001 From: Yueh-Shun Li Date: Thu, 6 Nov 2025 23:35:08 +0800 Subject: [PATCH 36/41] lib.extendMkDerivation: fix argument documentation layout (cherry picked from commit 7f6ce9097f3a37052c60493ec6746f1a8a3eebbe) --- lib/customisation.nix | 20 +++++++++++++++----- 1 file changed, 15 insertions(+), 5 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index 4a8e10cf9cc7..18d94f2b8cf5 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -752,11 +752,21 @@ rec { # Inputs `extendMkDerivation`-specific configurations - : `constructDrv` (required): Base build helper, the `mkDerivation`-like build helper to extend. - : `excludeDrvArgNames` (default to `[ ]`): Argument names not to pass from the input fixed-point arguments to `constructDrv`. Note: It doesn't apply to the updating arguments returned by `extendDrvArgs`. - : `extendDrvArgs` (required): An extension (overlay) of the argument set, like the one taken by [overrideAttrs](#sec-pkg-overrideAttrs) but applied before passing to `constructDrv`. - : `inheritFunctionArgs` (default to `true`): Whether to inherit `__functionArgs` from the base build helper. - : `transformDrv` (default to `lib.id`): Function to apply to the result derivation. + : `constructDrv` (required) + : Base build helper, the `mkDerivation`-like build helper to extend. + + `excludeDrvArgNames` (default to `[ ]`) + : Argument names not to pass from the input fixed-point arguments to `constructDrv`. + It doesn't apply to the updating arguments returned by `extendDrvArgs`. + + `extendDrvArgs` (required) + : An extension (overlay) of the argument set, like the one taken by [overrideAttrs](#sec-pkg-overrideAttrs) but applied before passing to `constructDrv`. + + `inheritFunctionArgs` (default to `true`) + : Whether to inherit `__functionArgs` from the base build helper. + + `transformDrv` (default to `lib.id`) + : Function to apply to the result derivation. # Type From 3930eee7b0ee22cf38e400c0d664dce0bc70ecf0 Mon Sep 17 00:00:00 2001 From: Yueh-Shun Li Date: Thu, 6 Nov 2025 19:37:08 +0800 Subject: [PATCH 37/41] lib.extendMkDerivation: document the typical usage of inheritFunctionArgs (cherry picked from commit d75b2035146827347f53918004d95fcba65be7a0) --- lib/customisation.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/lib/customisation.nix b/lib/customisation.nix index 18d94f2b8cf5..aaf0cf20fc9b 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -764,6 +764,7 @@ rec { `inheritFunctionArgs` (default to `true`) : Whether to inherit `__functionArgs` from the base build helper. + Set `inheritFunctionArgs` to `false` when `extendDrvArgs`'s `args` set pattern does not contain an ellipsis. `transformDrv` (default to `lib.id`) : Function to apply to the result derivation. From 431046845db0df88b8704e48bdff53f581d9ac58 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 12:51:46 +0100 Subject: [PATCH 38/41] ci/github-script/merge: add hint about stuck GitHub Unfortunately it still happens frequently that, after enabling auto-merge, GitHub is stuck even though all checks have passed, and doesn't merge the PR. Any contributor can trigger GitHub again with an approval of the PR - this will then immediately queue the PR for merge. Adding a hint to the posted comment, should help users through this without my intervention. (cherry picked from commit d086c6c6b3f8b2661596f1d424871601e7c5a96f) --- ci/github-script/merge.js | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/ci/github-script/merge.js b/ci/github-script/merge.js index 674d8153a7e9..14d6fd3762ab 100644 --- a/ci/github-script/merge.js +++ b/ci/github-script/merge.js @@ -191,7 +191,9 @@ async function handleMerge({ }`, { node_id: pull_request.node_id, sha: pull_request.head.sha }, ) - return `[Queued](${resp.enqueuePullRequest.mergeQueueEntry.mergeQueue.url}) for merge` + return [ + `:heavy_check_mark: [Queued](${resp.enqueuePullRequest.mergeQueueEntry.mergeQueue.url}) for merge (#306934)`, + ] } catch (e) { log('Enqueing failed', e.response.errors[0].message) } @@ -210,7 +212,12 @@ async function handleMerge({ }`, { node_id: pull_request.node_id, sha: pull_request.head.sha }, ) - return 'Enabled Auto Merge' + return [ + `:heavy_check_mark: Enabled Auto Merge (#306934)`, + '', + '> [!TIP]', + '> Sometimes GitHub gets stuck after enabling Auto Merge. In this case, leaving another approval should trigger the merge.', + ] } catch (e) { log('Auto Merge failed', e.response.errors[0].message) throw new Error(e.response.errors[0].message) @@ -296,7 +303,7 @@ async function handleMerge({ if (result) { await react('ROCKET') try { - body.push(`:heavy_check_mark: ${await merge()} (#306934)`) + body.push(...(await merge())) } catch (e) { // Remove the HTML comment with node_id reference to allow retrying this merge on the next run. body.shift() From 64e777a4d9eb1318c44aa673c7a2acbd0dc653b1 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 17:46:56 +0100 Subject: [PATCH 39/41] ci/github-script/bot: fix concurrency limit This was introduced as part of the hotfix PR to avoid hitting API rate limits - but the condition was wrong. It was supposed to trigger in all PR contexts, not only for the Test workflow. (cherry picked from commit a146035a2b1295b2d349fc1762c04cb4fb1e1f0b) --- ci/github-script/bot.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ci/github-script/bot.js b/ci/github-script/bot.js index 34abe96941fb..2b52955307ae 100644 --- a/ci/github-script/bot.js +++ b/ci/github-script/bot.js @@ -579,7 +579,7 @@ module.exports = async ({ github, context, core, dry }) => { // We'll only boost concurrency when we're running many PRs in parallel on a schedule, // but not for single PRs. This avoids things going wild, when we accidentally make // too many API requests on treewides. - const maxConcurrent = context.eventName === 'pull_request' ? 1 : 20 + const maxConcurrent = context.payload.pull_request ? 1 : 20 await withRateLimit({ github, core, maxConcurrent }, async (stats) => { if (context.payload.pull_request) { From f246b8281a7f01b92fd573bb2c2b5eb4b4a45b81 Mon Sep 17 00:00:00 2001 From: Matt Sturgeon Date: Thu, 6 Nov 2025 15:07:08 +0000 Subject: [PATCH 40/41] =?UTF-8?q?nexusmods-app:=200.19.4=20=E2=86=92=200.2?= =?UTF-8?q?0.2?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit https://github.com/Nexus-Mods/NexusMods.App/releases/tag/v0.20.2 (cherry picked from commit 27cd4f14aca556a05f136afbe586b3417620bd7f) --- pkgs/by-name/ne/nexusmods-app/package.nix | 18 +-------- .../ne/nexusmods-app/vendored/games.json | 40 +++++++++---------- 2 files changed, 22 insertions(+), 36 deletions(-) diff --git a/pkgs/by-name/ne/nexusmods-app/package.nix b/pkgs/by-name/ne/nexusmods-app/package.nix index 5b993929fc93..5041b96063fa 100644 --- a/pkgs/by-name/ne/nexusmods-app/package.nix +++ b/pkgs/by-name/ne/nexusmods-app/package.nix @@ -5,7 +5,6 @@ desktop-file-utils, dotnetCorePackages, fetchFromGitHub, - fetchpatch2, imagemagick, lib, xdg-utils, @@ -23,13 +22,13 @@ let in buildDotnetModule (finalAttrs: { inherit pname; - version = "0.19.4"; + version = "0.20.2"; src = fetchFromGitHub { owner = "Nexus-Mods"; repo = "NexusMods.App"; tag = "v${finalAttrs.version}"; - hash = "sha256-WKfv5y6UmO3dmzkXrqZ+VtIbXf0FszRdsa5Rmp95rYg="; + hash = "sha256-hpsrHHh0Bk+9Z4Qp5aTqH5i8KnqCLQdseYGrbr4sh1k="; fetchSubmodules = true; }; @@ -57,14 +56,6 @@ buildDotnetModule (finalAttrs: { dotnet-sdk = dotnetCorePackages.sdk_9_0; dotnet-runtime = dotnetCorePackages.runtime_9_0; - patches = [ - (fetchpatch2 { - name = "Fix-SMAPI-installation.patch"; - url = "https://github.com/Nexus-Mods/NexusMods.App/pull/4026.patch?full_index=1"; - hash = "sha256-1LgFTi63fVhGUZXZtS6iD2yqd0RxhdpiXKtWMFNEoD4="; - }) - ]; - postPatch = '' # Specify a fixed date to improve build reproducibility echo "1970-01-01T00:00:00Z" >buildDate.txt @@ -82,11 +73,6 @@ buildDotnetModule (finalAttrs: { ${lib.optionalString finalAttrs.doCheck '' # For some reason these tests fail (intermittently?) with a zero timestamp touch tests/NexusMods.UI.Tests/WorkspaceSystem/*.verified.png - - # Fix expected version number in text fixture - # https://github.com/Nexus-Mods/NexusMods.App/issues/4030 - substituteInPlace tests/NexusMods.Backend.Tests/EventTrackerTests.Test_PrepareRequest.verified.txt \ - --replace-fail 0.0.1 ${finalAttrs.version} ''} ''; diff --git a/pkgs/by-name/ne/nexusmods-app/vendored/games.json b/pkgs/by-name/ne/nexusmods-app/vendored/games.json index 478145604579..00e9d035c0dd 100644 --- a/pkgs/by-name/ne/nexusmods-app/vendored/games.json +++ b/pkgs/by-name/ne/nexusmods-app/vendored/games.json @@ -6,12 +6,12 @@ "forum_url": "https://forums.nexusmods.com/games/19-stardew-valley/", "nexusmods_url": "https://www.nexusmods.com/stardewvalley", "genre": "Simulation", - "file_count": 143212, - "downloads": 627187655, + "file_count": 144372, + "downloads": 635510946, "domain_name": "stardewvalley", "approved_date": 1457432329, - "mods": 25945, - "collections": 2020 + "mods": 26187, + "collections": 1990 }, { "id": 1704, @@ -20,12 +20,12 @@ "forum_url": "https://forums.nexusmods.com/games/6-skyrim/", "nexusmods_url": "https://www.nexusmods.com/skyrimspecialedition", "genre": "RPG", - "file_count": 661698, - "downloads": 9193533035, + "file_count": 667120, + "downloads": 9346275237, "domain_name": "skyrimspecialedition", "approved_date": 1477480498, - "mods": 118807, - "collections": 4852 + "mods": 119859, + "collections": 4876 }, { "id": 3174, @@ -34,12 +34,12 @@ "forum_url": "https://forums.nexusmods.com/games/9-mount-blade-ii-bannerlord/", "nexusmods_url": "https://www.nexusmods.com/mountandblade2bannerlord", "genre": "Strategy", - "file_count": 50603, - "downloads": 116400189, + "file_count": 50960, + "downloads": 117558949, "domain_name": "mountandblade2bannerlord", "approved_date": 1582898627, - "mods": 6341, - "collections": 293 + "mods": 6397, + "collections": 294 }, { "id": 3333, @@ -48,12 +48,12 @@ "forum_url": "https://forums.nexusmods.com/games/1-cyberpunk-2077/", "nexusmods_url": "https://www.nexusmods.com/cyberpunk2077", "genre": "Action", - "file_count": 125224, - "downloads": 930909718, + "file_count": 126752, + "downloads": 958960285, "domain_name": "cyberpunk2077", "approved_date": 1607433331, - "mods": 18032, - "collections": 1588 + "mods": 18283, + "collections": 1597 }, { "id": 3474, @@ -62,11 +62,11 @@ "forum_url": "https://forums.nexusmods.com/games/2-baldurs-gate-3/", "nexusmods_url": "https://www.nexusmods.com/baldursgate3", "genre": "RPG", - "file_count": 105632, - "downloads": 351591575, + "file_count": 106755, + "downloads": 359737700, "domain_name": "baldursgate3", "approved_date": 1602863114, - "mods": 15020, - "collections": 1752 + "mods": 15196, + "collections": 1740 } ] From 9bc97698cb44f6be08fda82ec1f228d794871944 Mon Sep 17 00:00:00 2001 From: networkException Date: Thu, 6 Nov 2025 22:41:11 +0100 Subject: [PATCH 41/41] ungoogled-chromium: 142.0.7444.59-2 -> 142.0.7444.134-1 https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop.html This update includes 5 security fixes. CVEs: CVE-2025-12725 CVE-2025-12726 CVE-2025-12727 CVE-2025-12728 CVE-2025-12729 (cherry picked from commit ca2fa5a4ab91d03afac210360715fadb96521eb0) --- .../networking/browsers/chromium/info.json | 22 +++++++++---------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/info.json b/pkgs/applications/networking/browsers/chromium/info.json index 1c0ee2a7a319..be1a0ffd43f0 100644 --- a/pkgs/applications/networking/browsers/chromium/info.json +++ b/pkgs/applications/networking/browsers/chromium/info.json @@ -813,7 +813,7 @@ } }, "ungoogled-chromium": { - "version": "142.0.7444.59", + "version": "142.0.7444.134", "deps": { "depot_tools": { "rev": "675a3a9ccd7cf9367bb4caa58c30f08b56d45ef5", @@ -825,16 +825,16 @@ "hash": "sha256-sm5GWbkm3ua7EkCWTuY4TG6EXKe3asXTrH1APnNARJQ=" }, "ungoogled-patches": { - "rev": "142.0.7444.59-2", - "hash": "sha256-Cjcy6ohVNt2eAD+m4ZTbeoHH9i4znkdgN0ZaysU8Whk=" + "rev": "142.0.7444.134-1", + "hash": "sha256-kwKzDTte0wPnx+tUmIaQ2EVf6HHacunmBbwLlUqYnOI=" }, "npmHash": "sha256-i1eQ4YlrWSgY522OlFtGDDPmxE2zd1hDM03AzR8RafE=" }, "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "4b8153ab58d3c3f4c9f7e4baad9616ecf80db5fa", - "hash": "sha256-RZQD9aL/YglC8chM7tqtB1Y2u6DF+6kkgwklUohaBXc=", + "rev": "b6965f826881a60c51151cfc0a0175966a0a4e81", + "hash": "sha256-NTBQrGihsT7kuY/Mac5s4oH1xEn3CFEAR6eOEvZwmYs=", "recompress": true }, "src/third_party/clang-format/script": { @@ -944,8 +944,8 @@ }, "src/third_party/dawn": { "url": "https://dawn.googlesource.com/dawn.git", - "rev": "cee9cb0d67e749bf42f5e90cb3b8a6f525dbb920", - "hash": "sha256-loKRLJfTxBxlTbPVWZqGdx0DyPvEopbs2zIf4gaxoLo=" + "rev": "95f9c2b375395cc82941babdf1e9f0cf60a32831", + "hash": "sha256-BFJsVt7hkSyyPQiX7QCN7Fu6CgTF/2xwAQbWCkJVq6M=" }, "src/third_party/dawn/third_party/glfw": { "url": "https://chromium.googlesource.com/external/github.com/glfw/glfw", @@ -1069,8 +1069,8 @@ }, "src/third_party/devtools-frontend/src": { "url": "https://chromium.googlesource.com/devtools/devtools-frontend", - "rev": "38cfe98a56a034da33ee62a5f1ea235fe47f58a7", - "hash": "sha256-bUJuFEDqgUFdMfmMyroX4s2ky/2n37PsTWaV+iQHCJg=" + "rev": "f063edc91e3610a60fb9d486ae8694f2a11fcd17", + "hash": "sha256-qiucde85rKA7TefveIa++sOF+MzT56pe8pHUUCj9Zeo=" }, "src/third_party/dom_distiller_js/dist": { "url": "https://chromium.googlesource.com/chromium/dom-distiller/dist.git", @@ -1619,8 +1619,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "bb294624702efbb17691b642333f06bf5108e600", - "hash": "sha256-ovlKdiBYD9RAjA1XI0PLp/pt25LAvm3fn5AqWlJQfgs=" + "rev": "4427aa4a9c14d3d542866c0ed2ae8a8554cfd68d", + "hash": "sha256-SL9YaplMFA1Ez11bIzAfl/F5qQob/PvCP1uknP1LiLs=" } } }