diff --git a/nixos/lib/testing/run.nix b/nixos/lib/testing/run.nix index 0b35007f0c0b..f97489f67be5 100644 --- a/nixos/lib/testing/run.nix +++ b/nixos/lib/testing/run.nix @@ -35,8 +35,7 @@ let options = { devnet = mkOption { type = types.bool; - default = - builtins.length (lib.attrNames containers) > 0 && builtins.length (lib.attrNames nodes) > 0; + default = containers != { } && nodes != { }; defaultText = lib.literalMD "`true` if both VMs and containers are present."; description = '' This heuristic setting that assumes that the majority of tests requires VMs and containers @@ -52,14 +51,14 @@ let }; uid-range = mkOption { type = types.bool; - default = builtins.length (lib.attrNames containers) > 0; + default = containers != { }; defaultText = lib.literalMD "`true` if containers are present."; description = "Containers use systemd-nspawn, which requires pid 0 inside of the sandbox. `uid-range` enables that."; }; kvm = mkOption { type = types.bool; - default = isLinux; - defaultText = lib.literalMD "`true` if built to run on Linux."; + default = isLinux && nodes != { }; + defaultText = lib.literalMD "`true` if built to run on Linux and any virtual machines are specified."; description = "Whether Linux KVM virtualization is required when running this test. Can be disabled to allow emulated execution."; }; apple-virt = mkOption { diff --git a/pkgs/applications/editors/emacs/sources.nix b/pkgs/applications/editors/emacs/sources.nix index a4196cf8a277..2874c94e8de3 100644 --- a/pkgs/applications/editors/emacs/sources.nix +++ b/pkgs/applications/editors/emacs/sources.nix @@ -141,6 +141,11 @@ in url = "https://gitweb.gentoo.org/proj/emacs-patches.git/plain/emacs/30.2/05_all_tramp.patch?id=2a6292f81affedcc468c594c60808e652ae87118"; hash = "sha256-WMjTscIuOXakuTO2H+w/Hd61V61V6ZrLh9WPMd58l+M="; }) + (fetchpatch { + name = "CVE-2024-53920.patch"; + url = "https://cgit.git.savannah.gnu.org/cgit/emacs.git/patch/?id=abc802ee2eb0b1663349ddf22a461f8e54a383fb"; + hash = "sha256-ViRD4E27WDs7lLO6YPNroMo3Zq5/ASqMlmNtVI1V/Lo="; + }) ]; }); diff --git a/pkgs/applications/networking/browsers/chromium/info.json b/pkgs/applications/networking/browsers/chromium/info.json index 2cb44de16b16..3641623861a7 100644 --- a/pkgs/applications/networking/browsers/chromium/info.json +++ b/pkgs/applications/networking/browsers/chromium/info.json @@ -1,10 +1,10 @@ { "chromium": { - "version": "153.0.8010.36", + "version": "153.0.8010.47", "chromedriver": { - "version": "153.0.8010.37", - "hash_darwin": "sha256-IMyEnUmK3slNB/QDZ+vtUyzHyU0AB+L6+BMbpCRluYA=", - "hash_darwin_aarch64": "sha256-cd1ZWatLQFIkPtCdVacrxFaFfj3rjG9qJ7kGlL3C6OA=" + "version": "153.0.8010.48", + "hash_darwin": "sha256-/4yv3KWuvKNAro9oeK+PFsTOrg878yS11aDYSX5S890=", + "hash_darwin_aarch64": "sha256-5eO1WwJ8iQrXUjHb776Z1YahR/A8aCoX7JrJXQEcIQ8=" }, "deps": { "depot_tools": { @@ -21,8 +21,8 @@ "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "507c6ee3e2f3b2ca0e660547e5b9ea4820c67f4c", - "hash": "sha256-q29a3PWQ7wMG4/JL9EyCK7EaDCeG+4Q/ruemOvvgeZM=", + "rev": "73934a44f61e6b3878d1943064c141a5a820f5f7", + "hash": "sha256-D7Oqukze3CzYVWN9AQq9zN6HN2GcZ6b7ZSqhM5bjvUU=", "recompress": true }, "src/third_party/clang-format/script": { @@ -92,8 +92,8 @@ }, "src/third_party/angle": { "url": "https://chromium.googlesource.com/angle/angle.git", - "rev": "fca5efdfeff5daf430bc4458375c8d6b7e457400", - "hash": "sha256-IoHQfdjZ6TV03VVzHZcxhPqGmNYNhKZrPG4BvQQfC7c=" + "rev": "ed04c8113c6538f3e1264042da8cb4afd100369b", + "hash": "sha256-mZrVJ/P3tPoiSkGBH4fEjNAexLsjAzts8jjkCQZ4kOs=" }, "src/third_party/angle/third_party/glmark2/src": { "url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2", @@ -132,8 +132,8 @@ }, "src/third_party/dawn": { "url": "https://dawn.googlesource.com/dawn.git", - "rev": "225a7ba1bcb997d26de3e894e04fb341638e8c5a", - "hash": "sha256-/ic1j1gu2wl5wCLCESfEcsLAPU5Dmsx8oKFb6RhYzg4=" + "rev": "28ffc61fc935c599677cff4dddfa4a12209ce500", + "hash": "sha256-6ySDyyQs/nfFF9AeoUY57GYDx7V8b0GQ17PCwQkzZVk=" }, "src/third_party/dawn/third_party/glfw3/src": { "url": "https://chromium.googlesource.com/external/github.com/glfw/glfw", @@ -632,8 +632,8 @@ }, "src/third_party/pthreadpool/src": { "url": "https://chromium.googlesource.com/external/github.com/google/pthreadpool.git", - "rev": "02460584c6092e527c8b89f7df4de143d70e801f", - "hash": "sha256-4EHJzZT+Gbhs8SkOhjSvDIPEqIQU93oJmtF3c/T+qjw=" + "rev": "15a6644ba1c45f1acc16ac1e883efc3e56c6bed2", + "hash": "sha256-YJD9n8cxoqTrTQJHKuZFW2qnlNcNmh5rQlBpnlF46to=" }, "src/third_party/pyelftools": { "url": "https://chromium.googlesource.com/chromiumos/third_party/pyelftools.git", @@ -672,8 +672,8 @@ }, "src/third_party/skia": { "url": "https://skia.googlesource.com/skia.git", - "rev": "4f574af2444846ceca4d277a8095c5d4229d175f", - "hash": "sha256-HrpA4labNWXPWj/yiS9O8KjdQPwJOllmR5r66TwCjB0=" + "rev": "fca11a08da7c1ed3777b40b31611961c85c63c43", + "hash": "sha256-iQNNgvRVUuyAcSVE+pNJWrWz0NJd/MZLxd9vbYztong=" }, "src/third_party/smhasher/src": { "url": "https://chromium.googlesource.com/external/smhasher.git", @@ -842,8 +842,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "f343157cebb388bfa416baccb5d35507e6fe8cc7", - "hash": "sha256-zSCyFQpDMNygmV6N4TajL8VB5+VRynrMPV/wAiWsJO4=" + "rev": "6b96683d44174e78ff4e65cb274bad56dc108231", + "hash": "sha256-Oa1wzIbWVPX0x7adJVPUxQocK5gofG0vE56QTg0XKCs=" }, "src/agents/shared": { "url": "https://chromium.googlesource.com/chromium/agents.git", @@ -853,7 +853,7 @@ } }, "ungoogled-chromium": { - "version": "153.0.8010.36", + "version": "153.0.8010.47", "deps": { "depot_tools": { "rev": "6411ed52842756261c66b6b8ece6b53ade2570f1", @@ -865,16 +865,16 @@ "hash": "sha256-qvQ13Ws2tb4i2Hdu34kBHivYPAn8w06zjLdQgK4BIJg=" }, "ungoogled-patches": { - "rev": "153.0.8010.36-1", - "hash": "sha256-JyvizS0oJC8J6VhtnpTKUGVbc31KCvTvwa4TmO+CHaY=" + "rev": "153.0.8010.47-1", + "hash": "sha256-J/IiNmqJzL35TfiGbsqrXnI8lUizCWuxzVBHgo7cG80=" }, "npmHash": "sha256-pF0JtwFpPC4/fodbhSJnQKkczA9WlDg4VqEAy9aDVLg=" }, "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "507c6ee3e2f3b2ca0e660547e5b9ea4820c67f4c", - "hash": "sha256-q29a3PWQ7wMG4/JL9EyCK7EaDCeG+4Q/ruemOvvgeZM=", + "rev": "73934a44f61e6b3878d1943064c141a5a820f5f7", + "hash": "sha256-D7Oqukze3CzYVWN9AQq9zN6HN2GcZ6b7ZSqhM5bjvUU=", "recompress": true }, "src/third_party/clang-format/script": { @@ -944,8 +944,8 @@ }, "src/third_party/angle": { "url": "https://chromium.googlesource.com/angle/angle.git", - "rev": "fca5efdfeff5daf430bc4458375c8d6b7e457400", - "hash": "sha256-IoHQfdjZ6TV03VVzHZcxhPqGmNYNhKZrPG4BvQQfC7c=" + "rev": "ed04c8113c6538f3e1264042da8cb4afd100369b", + "hash": "sha256-mZrVJ/P3tPoiSkGBH4fEjNAexLsjAzts8jjkCQZ4kOs=" }, "src/third_party/angle/third_party/glmark2/src": { "url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2", @@ -984,8 +984,8 @@ }, "src/third_party/dawn": { "url": "https://dawn.googlesource.com/dawn.git", - "rev": "225a7ba1bcb997d26de3e894e04fb341638e8c5a", - "hash": "sha256-/ic1j1gu2wl5wCLCESfEcsLAPU5Dmsx8oKFb6RhYzg4=" + "rev": "28ffc61fc935c599677cff4dddfa4a12209ce500", + "hash": "sha256-6ySDyyQs/nfFF9AeoUY57GYDx7V8b0GQ17PCwQkzZVk=" }, "src/third_party/dawn/third_party/glfw3/src": { "url": "https://chromium.googlesource.com/external/github.com/glfw/glfw", @@ -1484,8 +1484,8 @@ }, "src/third_party/pthreadpool/src": { "url": "https://chromium.googlesource.com/external/github.com/google/pthreadpool.git", - "rev": "02460584c6092e527c8b89f7df4de143d70e801f", - "hash": "sha256-4EHJzZT+Gbhs8SkOhjSvDIPEqIQU93oJmtF3c/T+qjw=" + "rev": "15a6644ba1c45f1acc16ac1e883efc3e56c6bed2", + "hash": "sha256-YJD9n8cxoqTrTQJHKuZFW2qnlNcNmh5rQlBpnlF46to=" }, "src/third_party/pyelftools": { "url": "https://chromium.googlesource.com/chromiumos/third_party/pyelftools.git", @@ -1524,8 +1524,8 @@ }, "src/third_party/skia": { "url": "https://skia.googlesource.com/skia.git", - "rev": "4f574af2444846ceca4d277a8095c5d4229d175f", - "hash": "sha256-HrpA4labNWXPWj/yiS9O8KjdQPwJOllmR5r66TwCjB0=" + "rev": "fca11a08da7c1ed3777b40b31611961c85c63c43", + "hash": "sha256-iQNNgvRVUuyAcSVE+pNJWrWz0NJd/MZLxd9vbYztong=" }, "src/third_party/smhasher/src": { "url": "https://chromium.googlesource.com/external/smhasher.git", @@ -1694,8 +1694,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "f343157cebb388bfa416baccb5d35507e6fe8cc7", - "hash": "sha256-zSCyFQpDMNygmV6N4TajL8VB5+VRynrMPV/wAiWsJO4=" + "rev": "6b96683d44174e78ff4e65cb274bad56dc108231", + "hash": "sha256-Oa1wzIbWVPX0x7adJVPUxQocK5gofG0vE56QTg0XKCs=" }, "src/agents/shared": { "url": "https://chromium.googlesource.com/chromium/agents.git", diff --git a/pkgs/applications/science/logic/easycrypt/default.nix b/pkgs/applications/science/logic/easycrypt/default.nix index 494b6c7f3ceb..ea82adf13444 100644 --- a/pkgs/applications/science/logic/easycrypt/default.nix +++ b/pkgs/applications/science/logic/easycrypt/default.nix @@ -11,13 +11,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "easycrypt"; - version = "2026.07"; + version = "2026.09"; src = fetchFromGitHub { owner = "easycrypt"; repo = "easycrypt"; tag = "r${finalAttrs.version}"; - hash = "sha256-ZJRvMdIv75BcU9r8kJdOF7XtTL5dFNycDMSnZjuSp3I="; + hash = "sha256-7ZnGZOZyV5znDGzg0c3XSsliQyOFOwJp2iyAzJtDNwk="; }; nativeBuildInputs = diff --git a/pkgs/applications/virtualization/docker/default.nix b/pkgs/applications/virtualization/docker/default.nix index 52b99ed04569..a402df867621 100644 --- a/pkgs/applications/virtualization/docker/default.nix +++ b/pkgs/applications/virtualization/docker/default.nix @@ -424,18 +424,18 @@ in docker_29 = let - version = "29.7.2"; + version = "29.8.0"; in callPackage dockerGen { inherit version; cliRev = "v${version}"; - cliHash = "sha256-ZYXRX4IQfUbb21yk/NodO5NH5OeX/KFDL9UdFS1e5ng="; + cliHash = "sha256-HV4rdWGDtPoYIaGBnHZbYNKr2D6zk6sb9sA0tNbQce4="; mobyRev = "docker-v${version}"; - mobyHash = "sha256-k28c4cwt+ASVj8FTvM8dgIOL3yqR5wbI21r3LtrVamU="; - runcRev = "v1.4.3"; - runcHash = "sha256-I9DruagoSWjrEBB4n+w5rzali5wvD/q3tVQFWPDnLAI="; - containerdRev = "v2.3.3"; - containerdHash = "sha256-wa9Pixaq5RRrJucWibbBe4n6s53Pdj+mr5gLoFmDgLU="; + mobyHash = "sha256-V8p+MDEEMERGqQ9sWKPE/jkUw43UcO0x3Z1XZ8DWM2E="; + runcRev = "v1.5.1"; + runcHash = "sha256-N059CtWkenSXYksVu5Uh+sGodC+JHc91R56b+VoC96k="; + containerdRev = "v2.3.4"; + containerdHash = "sha256-IGgToUpkbqtjGJD+GtCPSeHW9ZRnSS8NMfECok9HgjU="; tiniRev = "369448a167e8b3da4ca5bca0b3307500c3371828"; tiniHash = "sha256-jCBNfoJAjmcTJBx08kHs+FmbaU82CbQcf0IVjd56Nuw="; }; diff --git a/pkgs/by-name/au/aurral/package.nix b/pkgs/by-name/au/aurral/package.nix index efb66d38fc35..abb0bee3628a 100644 --- a/pkgs/by-name/au/aurral/package.nix +++ b/pkgs/by-name/au/aurral/package.nix @@ -16,7 +16,7 @@ buildNpmPackage (finalAttrs: { pname = "aurral"; - version = "2.8.0"; + version = "2.9.0"; __structuredAttrs = true; @@ -24,7 +24,7 @@ buildNpmPackage (finalAttrs: { owner = "lklynet"; repo = "aurral"; tag = "v${finalAttrs.version}"; - hash = "sha256-Ceo5CHIGa+98XFLazqmAyAV64rzDYqB0gvJ95AKwfUk="; + hash = "sha256-pwk+efWL0dfvKiobRmGXgPtvunpRDOVbtxohbJamVqY="; }; # Specifies files to package leveraging npm & nix hooks. Not used by upstream. @@ -33,7 +33,7 @@ buildNpmPackage (finalAttrs: { ./package.json.patch ]; - npmDepsHash = "sha256-Qa/TcKzMEY/w8FWKMiHUeqVB9cMxxWtEwF30y0nndkg="; + npmDepsHash = "sha256-NVz5eqDDtMBKiTDl3aX0pHBYGTcYal8lmCf8mbKu31I="; nodejs = nodejs_26; diff --git a/pkgs/by-name/bl/bloodhound/package.nix b/pkgs/by-name/bl/bloodhound/package.nix index e9bac8137221..839abb971b87 100644 --- a/pkgs/by-name/bl/bloodhound/package.nix +++ b/pkgs/by-name/bl/bloodhound/package.nix @@ -138,5 +138,8 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ akechishiro ]; platforms = [ "x86_64-linux" ]; mainProgram = "BloodHound"; + knownVulnerabilities = [ + "Upstream is deprecated, using Electron 11 which was EOL in 2021. Consider using bloodhound-ce instead." + ]; }; }) diff --git a/pkgs/by-name/fe/feishin/package.nix b/pkgs/by-name/fe/feishin/package.nix index 094111c60555..07763edfe439 100644 --- a/pkgs/by-name/fe/feishin/package.nix +++ b/pkgs/by-name/fe/feishin/package.nix @@ -8,7 +8,6 @@ fetchPnpmDeps, pnpmConfigHook, pnpm_11, - nodejs-slim_latest, darwin, actool, copyDesktopItems, @@ -20,18 +19,17 @@ let electron = electron_43; - # Fix pnpm issue on darwin https://github.com/NixOS/nixpkgs/issues/525627 - pnpm = pnpm_11.override { nodejs-slim = nodejs-slim_latest; }; + pnpm = pnpm_11; in buildNpmPackage (finalAttrs: { pname = "feishin"; - version = "1.15.1"; + version = "1.17.0"; src = fetchFromGitHub { owner = "jeffvli"; repo = "feishin"; tag = "v${finalAttrs.version}"; - hash = "sha256-2UKJBUZNUpUUZIG1JFXok7YJdzqt+Ge0ykHUm8BeNcw="; + hash = "sha256-1ZIw5XiN+2EhpHmdvN0HxgMSvn4QvN9B+ZJ3RlPXhLw="; }; __structuredAttrs = true; @@ -48,7 +46,7 @@ buildNpmPackage (finalAttrs: { src ; fetcherVersion = 4; - hash = "sha256-9uG0AxIBAmuIPywg3p9fFCXmRvM9zDLhWfluSLRnUXY="; + hash = "sha256-ltpz4e5Vv2vxt/93M4+vHUFJZjwTRwb2zrwvl1Lqjo8="; }; env.ELECTRON_SKIP_BINARY_DOWNLOAD = "1"; @@ -65,7 +63,7 @@ buildNpmPackage (finalAttrs: { postPatch = '' # release/app dependencies are installed on preConfigure substituteInPlace package.json \ - --replace-fail '"postinstall": "electron-builder install-app-deps",' "" + --replace-fail '"postinstall": "install-electron && electron-builder install-app-deps",' "" ''; postBuild = lib.optionalString (!webVersion) '' diff --git a/pkgs/by-name/fl/fluxcd-operator-mcp/package.nix b/pkgs/by-name/fl/fluxcd-operator-mcp/package.nix index 2cfcd09beb1d..e5584d24e38a 100644 --- a/pkgs/by-name/fl/fluxcd-operator-mcp/package.nix +++ b/pkgs/by-name/fl/fluxcd-operator-mcp/package.nix @@ -9,16 +9,16 @@ }: buildGoModule (finalAttrs: { pname = "fluxcd-operator-mcp"; - version = "0.50.0"; + version = "0.58.1"; src = fetchFromGitHub { owner = "controlplaneio-fluxcd"; - repo = "fluxcd-operator"; + repo = "flux-operator"; tag = "v${finalAttrs.version}"; - hash = "sha256-4FIsad3/57KtyTVQE0T4jhQGEvuEw9/ZFWsriLyc6Ok="; + hash = "sha256-XGjRP9JvEpuVNKcErTKmKi4TGBADpbI1DDXYDd0Bbb4="; }; - vendorHash = "sha256-DxXTepwTjgc+Xy3MAIFcYZ/XZZ3zGgyStmXN2/BqM74="; + vendorHash = "sha256-9iDxoWnizmTQ4FqxjlGPQO8Au2FxIdcgggtP+3dTOaU="; ldflags = [ "-s" diff --git a/pkgs/by-name/fl/fluxcd-operator/package.nix b/pkgs/by-name/fl/fluxcd-operator/package.nix index 167480bca502..3b1de7601c8e 100644 --- a/pkgs/by-name/fl/fluxcd-operator/package.nix +++ b/pkgs/by-name/fl/fluxcd-operator/package.nix @@ -9,16 +9,16 @@ }: buildGoModule (finalAttrs: { pname = "fluxcd-operator"; - version = "0.49.0"; + version = "0.58.1"; src = fetchFromGitHub { owner = "controlplaneio-fluxcd"; - repo = "fluxcd-operator"; + repo = "flux-operator"; tag = "v${finalAttrs.version}"; - hash = "sha256-hWMXoJ47+kDmMGkGV9GOJ9ssdK6RVvcmxf3fiQYhvgM="; + hash = "sha256-XGjRP9JvEpuVNKcErTKmKi4TGBADpbI1DDXYDd0Bbb4="; }; - vendorHash = "sha256-UANjDzaYJ5t10ZzG0a7oftKQVqj1HcE6/LmlnLapCPY="; + vendorHash = "sha256-9iDxoWnizmTQ4FqxjlGPQO8Au2FxIdcgggtP+3dTOaU="; ldflags = [ "-s" diff --git a/pkgs/by-name/fl/fluxcd/package.nix b/pkgs/by-name/fl/fluxcd/package.nix index 4982c3c558b8..d87fbdbe31b6 100644 --- a/pkgs/by-name/fl/fluxcd/package.nix +++ b/pkgs/by-name/fl/fluxcd/package.nix @@ -9,10 +9,10 @@ }: let - version = "2.9.4"; - srcHash = "sha256-7Suhsg1tWn6gzkPDQT4BII0hTCM3HCCZTTtFVNumA9A="; - vendorHash = "sha256-3CMj5MI5cILnyWoWkcBzD5X626nsQ6nfipeqN35IQEk="; - manifestsHash = "sha256-+187K4w//AxtSYcrA3NoVCSFpTkjNqZmfOlbdzD9YmI="; + version = "2.9.5"; + srcHash = "sha256-XHK9GkKyLLogtvahcf+hOvfyk2Bxp6kpWN977gOOkHM="; + vendorHash = "sha256-NRt/exSNjgBdFtj6ZsPk0ounwQGKZ4Ndpx8FsupdVNo="; + manifestsHash = "sha256-CncxZ/ADsKlLbCHI5kxcUT/WHlv3hYCfFFoqDIuqvMY="; manifests = fetchzip { url = "https://github.com/fluxcd/flux2/releases/download/v${version}/manifests.tar.gz"; diff --git a/pkgs/by-name/ja/jackett/package.nix b/pkgs/by-name/ja/jackett/package.nix index 1c9c6a2e72b8..62e44b97871b 100644 --- a/pkgs/by-name/ja/jackett/package.nix +++ b/pkgs/by-name/ja/jackett/package.nix @@ -12,13 +12,13 @@ buildDotnetModule (finalAttrs: { pname = "jackett"; - version = "0.24.2527"; + version = "0.24.2586"; src = fetchFromGitHub { owner = "jackett"; repo = "jackett"; tag = "v${finalAttrs.version}"; - hash = "sha256-IbSXGddfsD9r0ElsSToQ+n75F09WUnF2jHirFOAiu+Q="; + hash = "sha256-rYUkxFkMcClN+GFt/nFR/y+zLbgLF9CFQUvfwuwNpo0="; }; projectFile = "src/Jackett.Server/Jackett.Server.csproj"; diff --git a/pkgs/by-name/li/linux-firmware/package.nix b/pkgs/by-name/li/linux-firmware/package.nix index 8a4d77a32889..0919d3131dbd 100644 --- a/pkgs/by-name/li/linux-firmware/package.nix +++ b/pkgs/by-name/li/linux-firmware/package.nix @@ -23,13 +23,13 @@ let in stdenvNoCC.mkDerivation rec { pname = "linux-firmware"; - version = "20260910"; + version = "20260916"; src = fetchFromGitLab { owner = "kernel-firmware"; repo = "linux-firmware"; tag = version; - hash = "sha256-gT9XYrQk5oZvbJgp4u8xkGWR4NdDomx5tzLmB4V52H8="; + hash = "sha256-VbDTRN/i+a1BrKnDtdDFxanp3BQujBhe9CyWay9GTXY="; }; postUnpack = '' diff --git a/pkgs/by-name/ma/mastodon/source.nix b/pkgs/by-name/ma/mastodon/source.nix index cf938f6c2ade..318078c1d8f7 100644 --- a/pkgs/by-name/ma/mastodon/source.nix +++ b/pkgs/by-name/ma/mastodon/source.nix @@ -5,14 +5,14 @@ patches ? [ ], }: let - version = "4.6.7"; + version = "4.6.8"; in applyPatches { src = fetchFromGitHub { owner = "mastodon"; repo = "mastodon"; rev = "v${version}"; - hash = "sha256-gSJXe4/uRYYKQTmjMirD2uFA7ymRl2LQP6VHt8nBD9k="; + hash = "sha256-fDbQunhcpnMnIufEX2oRH9vulsHjtlR95boj0M2O3CQ="; passthru = { inherit version; yarnHash = "sha256-VlOG91ZuO+1UXTbtwIrYUbqHjmSfPSfLhrf4TxCJqJ0="; diff --git a/pkgs/by-name/mu/mullvad-browser/package.nix b/pkgs/by-name/mu/mullvad-browser/package.nix index 3423f0c606ed..7278216666bd 100644 --- a/pkgs/by-name/mu/mullvad-browser/package.nix +++ b/pkgs/by-name/mu/mullvad-browser/package.nix @@ -97,7 +97,7 @@ let ++ lib.optionals mediaSupport [ ffmpeg_7 ] ); - version = "15.0.21"; + version = "15.0.23"; sources = { x86_64-linux = fetchurl { @@ -109,7 +109,7 @@ let "https://tor.eff.org/dist/mullvadbrowser/${version}/mullvad-browser-linux-x86_64-${version}.tar.xz" "https://tor.calyxinstitute.org/dist/mullvadbrowser/${version}/mullvad-browser-linux-x86_64-${version}.tar.xz" ]; - hash = "sha256-LHv/hY/abmy7/8nsNkKiwJh+SvRLzEO97fNNvPuYXQo="; + hash = "sha256-Bzd0atOeqHFhmIlpN3cbGogkwg6SwpNhn5m4yscpIzo="; }; }; diff --git a/pkgs/by-name/pg/pgschema/package.nix b/pkgs/by-name/pg/pgschema/package.nix index 397d3bb6a2c7..4ece50ce711a 100644 --- a/pkgs/by-name/pg/pgschema/package.nix +++ b/pkgs/by-name/pg/pgschema/package.nix @@ -1,4 +1,5 @@ { + stdenv, lib, buildGoModule, fetchFromGitHub, @@ -9,14 +10,14 @@ buildGoModule (finalAttrs: { pname = "pgschema"; - version = "1.12.3"; + version = "1.12.4"; __structuredAttrs = true; src = fetchFromGitHub { owner = "pgplex"; repo = "pgschema"; tag = "v${finalAttrs.version}"; - hash = "sha256-zfG87Uc5bx14zhYnuT3CF+sW5EEQLBRRMyBe57FBHJ4="; + hash = "sha256-xURQHIkvEWaYko9RvEhYl1TPqc5ABx9WTMVKuWYGfwE="; }; # Adapted from $src/nix/pgschema.nix @@ -33,11 +34,15 @@ buildGoModule (finalAttrs: { "github.com/pgplex/pgschema/internal/postgres.binariesPath=${postgresql}" ]; + # Tests fail in sandbox on darwin, with: + # Could not create shared memory segment: Cannot allocate memory + # Failed system call was shmget(key=18446744072262306125, size=56, 03600) + doCheck = !stdenv.hostPlatform.isDarwin; + doInstallCheck = true; nativeInstallCheckInputs = [ versionCheckHook ]; - versionCheckProgramArg = "--help"; # there is no -v/--version passthru.updateScript = nix-update-script { }; diff --git a/pkgs/by-name/qt/qtcreator/package.nix b/pkgs/by-name/qt/qtcreator/package.nix index 1eb30a7702cc..332dc2b396a9 100644 --- a/pkgs/by-name/qt/qtcreator/package.nix +++ b/pkgs/by-name/qt/qtcreator/package.nix @@ -21,10 +21,10 @@ }: let pname = "qtcreator"; - version = "19.0.1"; + version = "20.0.1"; src = fetchurl { url = "mirror://qt/official_releases/${pname}/${lib.versions.majorMinor version}/${version}/qt-creator-opensource-src-${version}.tar.xz"; - hash = "sha256-IAVmOmlQOyQETf7QdwajTETKvBn0dqwcEUTe8cSr+r4="; + hash = "sha256-XsO8zwbumhkFqHYKyfunoShWcvFAqX4MUsniSNkFGrg="; }; goModules = (buildGoModule { @@ -130,6 +130,7 @@ stdenv'.mkDerivation { maintainers = with lib.maintainers; [ wineee zatm8 + l33tname ]; platforms = lib.platforms.linux; mainProgram = "qtcreator"; diff --git a/pkgs/by-name/rl/rlottie/package.nix b/pkgs/by-name/rl/rlottie/package.nix index ee883a52fc86..fb0031f3a7a2 100644 --- a/pkgs/by-name/rl/rlottie/package.nix +++ b/pkgs/by-name/rl/rlottie/package.nix @@ -11,13 +11,13 @@ stdenv.mkDerivation { pname = "rlottie"; - version = "0.2-unstable-2026-09-01"; + version = "0.2-unstable-2026-09-11"; src = fetchFromGitHub { owner = "Samsung"; repo = "rlottie"; - rev = "25648aef19187b3f87f4d9420b8d761453ad4630"; - hash = "sha256-sLjunpnQh1HCy5VLB8EpCTaGuBRPGCLhDovTzAAjAK0="; + rev = "683bbaa39dd0d366cf6b4bc300b4dfbee677ea6b"; + hash = "sha256-4XP/bqMWgJW/XbR0rb8N3U5YMpXhwaQ6oQG9+7Jw5bs="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/ta/tabbyapi/package.nix b/pkgs/by-name/ta/tabbyapi/package.nix index 74fcf6722359..58a6e39e1a23 100644 --- a/pkgs/by-name/ta/tabbyapi/package.nix +++ b/pkgs/by-name/ta/tabbyapi/package.nix @@ -7,14 +7,14 @@ }: python3Packages.buildPythonApplication { pname = "tabbyapi"; - version = "0-unstable-2026-09-07"; + version = "0-unstable-2026-09-14"; pyproject = true; src = fetchFromGitHub { owner = "theroyallab"; repo = "tabbyAPI"; - rev = "92198cca1aa48f83121027f5b9058c24d7c2d894"; - hash = "sha256-IQDsfTnIcaVmxk58Q8StEPS4O7LQwPVie6b04BWoeeQ="; + rev = "53da7919d4e45c63f4acbcbbc00cbe0f60a1ce65"; + hash = "sha256-oKVxMoyMWZCuwLbsimTXO05Hdsw/2u2SVeYSFm1XsFg="; }; build-system = with python3Packages; [ diff --git a/pkgs/by-name/to/tor-browser/package.nix b/pkgs/by-name/to/tor-browser/package.nix index 25ce90f671a4..b6f801ce4acb 100644 --- a/pkgs/by-name/to/tor-browser/package.nix +++ b/pkgs/by-name/to/tor-browser/package.nix @@ -102,7 +102,7 @@ let ++ lib.optionals mediaSupport [ ffmpeg_7 ] ); - version = "15.0.22"; + version = "15.0.23"; sources = { x86_64-linux = fetchurl { @@ -112,7 +112,7 @@ let "https://tor.eff.org/dist/torbrowser/${version}/tor-browser-linux-x86_64-${version}.tar.xz" "https://tor.calyxinstitute.org/dist/torbrowser/${version}/tor-browser-linux-x86_64-${version}.tar.xz" ]; - hash = "sha256-wizrBGx5zl57M7obg3iUr9Y7P/H8ckwCPbVL2BNWZFc="; + hash = "sha256-D2L41lx/w03UuGy6t/yq7HOBVz3aNGrHsX5WjiK0vzk="; }; i686-linux = fetchurl { @@ -122,7 +122,7 @@ let "https://tor.eff.org/dist/torbrowser/${version}/tor-browser-linux-i686-${version}.tar.xz" "https://tor.calyxinstitute.org/dist/torbrowser/${version}/tor-browser-linux-i686-${version}.tar.xz" ]; - hash = "sha256-1J82ddE8DqVSOnS4yI4ayLyx3MBP++TOonLulGsBz4E="; + hash = "sha256-EXCHkprnH1ylopayMN/kckEpYJAePWnzmUlldSqVswk="; }; }; diff --git a/pkgs/by-name/tu/turtle-build/package.nix b/pkgs/by-name/tu/turtle-build/package.nix index 03962bdf8073..65ce7f1146a9 100644 --- a/pkgs/by-name/tu/turtle-build/package.nix +++ b/pkgs/by-name/tu/turtle-build/package.nix @@ -8,16 +8,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "turtle-build"; - version = "0.4.9"; + version = "0.5.1"; src = fetchFromGitHub { owner = "raviqqe"; repo = "turtle-build"; rev = "v${finalAttrs.version}"; - hash = "sha256-sbYDp4r/M6GvCYEshccJ331mVNeN85wwf9TKHiYFv7I="; + hash = "sha256-0WqFflD6WgCyKREOfAdx+NDrFhQlGMhNmEjf9dBdtNo="; }; - cargoHash = "sha256-JZU0Xam4NPiOHdXDtJsTBjOQnaDWReSZMD33sQxeUzQ="; + cargoHash = "sha256-DCZZHkg+mk10aGpgz/XvE1hyl+qDR2KELqxxjVeP0ps="; doInstallCheck = true; nativeInstallCheckInputs = [ versionCheckHook ]; diff --git a/pkgs/by-name/un/undocker/package.nix b/pkgs/by-name/un/undocker/package.nix index f89745d4410a..a5786735ea41 100644 --- a/pkgs/by-name/un/undocker/package.nix +++ b/pkgs/by-name/un/undocker/package.nix @@ -7,7 +7,7 @@ let version = "1.2.3"; src = fetchgit { - url = "https://git.jakstys.lt/motiejus/undocker.git"; + url = "https://git.jakstys.lt/undocker.git"; rev = "v${version}"; hash = "sha256-hyP85pYtXxucAliilUt9Y2qnrfPeSjeGsYEFJndJWyA="; }; @@ -25,7 +25,7 @@ buildGoModule { vendorHash = null; meta = { - homepage = "https://git.jakstys.lt/motiejus/undocker"; + homepage = "https://git.jakstys.lt/undocker"; description = "CLI tool to convert a Docker image to a flattened rootfs tarball"; license = lib.licenses.asl20; maintainers = with lib.maintainers; [ diff --git a/pkgs/by-name/up/upower/package.nix b/pkgs/by-name/up/upower/package.nix index a317da29cb3c..b07dec539ee2 100644 --- a/pkgs/by-name/up/upower/package.nix +++ b/pkgs/by-name/up/upower/package.nix @@ -38,7 +38,7 @@ assert withDocs -> withIntrospection; stdenv.mkDerivation (finalAttrs: { pname = "upower"; - version = "1.91.3"; + version = "1.91.4"; outputs = [ "out" @@ -52,7 +52,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "upower"; repo = "upower"; rev = "v${finalAttrs.version}"; - hash = "sha256-QdAJxaua43iGovQeRg+n1MypS5CS0Ro3gqF9Tv8eMBg="; + hash = "sha256-B/gfrXPLYwOGyheTLP/sEH5RakLUm4OiRAV+U2wL9V0="; }; patches = diff --git a/pkgs/by-name/us/usbvfiod/package.nix b/pkgs/by-name/us/usbvfiod/package.nix index 240990a780b0..706b04da98aa 100644 --- a/pkgs/by-name/us/usbvfiod/package.nix +++ b/pkgs/by-name/us/usbvfiod/package.nix @@ -8,16 +8,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "usbvfiod"; - version = "0.1.0"; + version = "0.3.0"; src = fetchFromGitHub { owner = "cyberus-technology"; repo = "usbvfiod"; rev = "v${finalAttrs.version}"; - hash = "sha256-SG5S0wRue/G31XuR2D8xFrbAIhWG3rl+aNjEnhZ7dmI="; + hash = "sha256-gYKWmUaB7c5netQjR7qHKuBq82X3J+o4gQCsB/3cq50="; }; - cargoHash = "sha256-nTNUC7Tiib2wWYC1g7S1W7wgIkqZLTN8aKUKjpgZlqo="; + cargoHash = "sha256-B4iyADjXjX7VdGaTIdCKUalwJt6vMVnqqUCyLsu5wUI="; nativeInstallCheckInputs = [ versionCheckHook diff --git a/pkgs/by-name/vi/victoriametrics/package.nix b/pkgs/by-name/vi/victoriametrics/package.nix index c03666eef1af..647399a8cad2 100644 --- a/pkgs/by-name/vi/victoriametrics/package.nix +++ b/pkgs/by-name/vi/victoriametrics/package.nix @@ -1,6 +1,6 @@ { lib, - buildGoModule, + buildGo127Module, fetchFromGitHub, nix-update-script, nixosTests, @@ -12,15 +12,15 @@ withVmctl ? true, # vmctl is used to migrate time series }: -buildGoModule (finalAttrs: { +buildGo127Module (finalAttrs: { pname = "VictoriaMetrics"; - version = "1.151.0"; + version = "1.152.0"; src = fetchFromGitHub { owner = "VictoriaMetrics"; repo = "VictoriaMetrics"; tag = "v${finalAttrs.version}"; - hash = "sha256-LMilqB2enkzZr3zLcwnDLojtFV/lcOsXA9EhjiFarqE="; + hash = "sha256-3PDFQbVJhwyMUvA/ToXJKBOIN9xKoBGp/YjHntjwKr4="; }; vendorHash = null; diff --git a/pkgs/by-name/vi/vikunja/frontend.nix b/pkgs/by-name/vi/vikunja/frontend.nix new file mode 100644 index 000000000000..96ee618d35ed --- /dev/null +++ b/pkgs/by-name/vi/vikunja/frontend.nix @@ -0,0 +1,68 @@ +{ + src, + version, + + lib, + stdenv, + nodejs_24, + pnpm_10, + fetchPnpmDeps, + pnpmConfigHook, + dart-sass, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "vikunja-frontend"; + inherit version src; + + sourceRoot = "${finalAttrs.src.name}/frontend"; + + pnpmDeps = fetchPnpmDeps { + inherit (finalAttrs) + pname + version + src + sourceRoot + ; + pnpm = pnpm_10; + fetcherVersion = 3; + hash = "sha256-aQWTzJZU6NJrZxuoCeQDJjujPq+niixmFvqtPdWS4wk="; + }; + + nativeBuildInputs = [ + nodejs_24 + dart-sass + pnpmConfigHook + pnpm_10 + ]; + + postPatch = '' + substituteInPlace src/version.json \ + --replace-fail '"dev"' '"${finalAttrs.version}"' + ''; + + postBuild = '' + # Force sass-embedded to use our dart-sass instead of bundled binaries. + substituteInPlace node_modules/sass-embedded/dist/lib/src/compiler-path.js \ + --replace-fail 'compilerCommand = (() => {' 'compilerCommand = (() => { return ["${lib.getExe dart-sass}"];' + pnpm run build + ''; + + doCheck = true; + + checkPhase = '' + runHook preCheck + + pnpm run test:unit --run + + runHook postCheck + ''; + + installPhase = '' + runHook preInstall + + cp -r dist/ $out + + runHook postInstall + ''; +}) diff --git a/pkgs/by-name/vi/vikunja/package.nix b/pkgs/by-name/vi/vikunja/package.nix index 684b72a32d15..2d838dd52a0a 100644 --- a/pkgs/by-name/vi/vikunja/package.nix +++ b/pkgs/by-name/vi/vikunja/package.nix @@ -1,74 +1,17 @@ { lib, + callPackage, fetchFromGitHub, - stdenv, - nodejs_24, - pnpm_10, - fetchPnpmDeps, - pnpmConfigHook, - buildGoModule, + buildGo127Module, mage, - dart-sass, + writableTmpDirAsHomeHook, writeShellScriptBin, nixosTests, + nix-update-script, }: let - version = "2.5.0"; - src = fetchFromGitHub { - owner = "go-vikunja"; - repo = "vikunja"; - rev = "v${version}"; - hash = "sha256-qI4mkgcN9yYRmh5V+KzIHupX7uWsszV4Xb31OYvukxQ="; - }; - - frontend = stdenv.mkDerivation (finalAttrs: { - pname = "vikunja-frontend"; - inherit version src; - - sourceRoot = "${finalAttrs.src.name}/frontend"; - - pnpmDeps = fetchPnpmDeps { - inherit (finalAttrs) - pname - version - src - sourceRoot - ; - pnpm = pnpm_10; - fetcherVersion = 3; - hash = "sha256-xZBgE4GM59Ihl5a3qgcmkjR4Q3wYlcsiDapiNEzBQOg="; - }; - - nativeBuildInputs = [ - nodejs_24 - dart-sass - pnpmConfigHook - pnpm_10 - ]; - - postPatch = '' - substituteInPlace src/version.json \ - --replace-fail '"dev"' '"${finalAttrs.version}"' - ''; - - doCheck = true; - - postBuild = '' - # Force sass-embedded to use our dart-sass instead of bundled binaries. - substituteInPlace node_modules/sass-embedded/dist/lib/src/compiler-path.js \ - --replace-fail 'compilerCommand = (() => {' 'compilerCommand = (() => { return ["${lib.getExe dart-sass}"];' - pnpm run build - ''; - - checkPhase = '' - pnpm run test:unit --run - ''; - - installPhase = '' - cp -r dist/ $out - ''; - }); + buildGoModule = buildGo127Module; # Injects a `t.Skip()` into a given test since there's apparently no other way to skip tests here. skipTest = @@ -82,15 +25,22 @@ let }' ${file} ''; in -buildGoModule { - inherit src version; +buildGoModule (finalAttrs: { pname = "vikunja"; + version = "2.6.0"; + + src = fetchFromGitHub { + owner = "go-vikunja"; + repo = "vikunja"; + rev = "v${finalAttrs.version}"; + hash = "sha256-Xh1ozUTOVqywk0i8xQWkG/bPRgPH9EABjRW8p4do1mE="; + }; nativeBuildInputs = let fakeGit = writeShellScriptBin "git" '' if [[ $@ = "describe --tags --always --abbrev=10" ]]; then - echo "${version}" + echo "${finalAttrs.version}" else >&2 echo "Unknown command: $@" exit 1 @@ -100,14 +50,23 @@ buildGoModule { [ fakeGit mage + # mage wants to write some files to HOME + writableTmpDirAsHomeHook ]; - vendorHash = "sha256-bn+bcGzeB0/KkhPNkbjK/EgKQG3iqVlJxtt6betGUNE="; + vendorHash = "sha256-R6M5UyF10pIdoAvjWnS6Dqe/U6LTxmS6OwRTgmxfU4g="; - inherit frontend; + frontend = callPackage ./frontend.nix { + inherit (finalAttrs) src version; + }; + + veans = callPackage ./veans.nix { + inherit (finalAttrs) src version meta; + inherit buildGoModule; + }; prePatch = '' - cp -r ${frontend} frontend/dist + cp -r ${finalAttrs.frontend} frontend/dist ''; postConfigure = '' @@ -122,32 +81,46 @@ buildGoModule { buildPhase = '' runHook preBuild - # Fixes "mkdir /homeless-shelter: permission denied" - "Error: error compiling magefiles" during build - export HOME=$(mktemp -d) mage build:build runHook postBuild ''; checkPhase = '' + runHook preCheck + mage test:feature mage test:web + + runHook postCheck ''; installPhase = '' runHook preInstall + install -Dt $out/bin vikunja + runHook postInstall ''; passthru = { + # used by vikunja-desktop + inherit (finalAttrs) frontend; + tests.vikunja = nixosTests.vikunja; - frontend = frontend; - updateScript = ./update.sh; + + updateScript = nix-update-script { + extraArgs = [ + "--subpackage" + "frontend" + "--subpackage" + "veans" + ]; + }; }; meta = { - changelog = "https://github.com/go-vikunja/vikunja/blob/v${version}/CHANGELOG.md"; + changelog = "https://github.com/go-vikunja/vikunja/blob/v${finalAttrs.version}/CHANGELOG.md"; description = "Todo-app to organize your life"; homepage = "https://vikunja.io/"; license = lib.licenses.agpl3Plus; @@ -158,4 +131,4 @@ buildGoModule { mainProgram = "vikunja"; platforms = lib.platforms.linux; }; -} +}) diff --git a/pkgs/by-name/vi/vikunja/update.sh b/pkgs/by-name/vi/vikunja/update.sh deleted file mode 100755 index 1c09f61cb0f6..000000000000 --- a/pkgs/by-name/vi/vikunja/update.sh +++ /dev/null @@ -1,53 +0,0 @@ -#!/usr/bin/env nix-shell -#!nix-shell -i bash -p nix wget jq nurl - -# shellcheck shell=bash - -set -euo pipefail - -if [[ $# -gt 1 || "${1:-}" == -* ]]; then - echo "Regenerates packaging data for the vikunja package." - echo "Usage: $0 [version]" - exit 1 -fi - -version="${1:-}" - -NIXPKGS_ROOT="$(git rev-parse --show-toplevel)" - -if [ -z "$version" ]; then - TOKEN_ARGS=() - if [ -n "${GITHUB_TOKEN:-}" ]; then - TOKEN_ARGS=(--header "Authorization: token $GITHUB_TOKEN") - fi - version="$(wget -q -O- ${TOKEN_ARGS[@]+"${TOKEN_ARGS[@]}"} "https://api.github.com/repos/go-vikunja/vikunja/releases?per_page=10" | jq -r '[.[] | select(.prerelease == false)][0].tag_name')" -fi - -# strip leading "v" -version="${version#v}" - -cd "$(dirname "$0")" - -# Update version, blank out all hashes so nurl can recompute them -sed -i -E 's#version = ".*"#version = "'"$version"'"#' package.nix -sed -i -E '/fetchFromGitHub \{/,/\};/ s#hash = ".*"#hash = ""#' package.nix -sed -i -E '/fetchPnpmDeps \{/,/\};/ s#hash = ".*"#hash = ""#' package.nix -sed -i -E 's#vendorHash = ".*"#vendorHash = ""#' package.nix - -# Source hash (must be computed first, pnpm and vendor depend on it) -src_hash=$(nurl -e "(import $NIXPKGS_ROOT/. { }).vikunja.src") -sed -i -E '/fetchFromGitHub \{/,/\};/ s#hash = ".*"#hash = "'"$src_hash"'"#' package.nix - -# pnpm dependencies hash for frontend -pnpm_hash=$(nurl -e "(import $NIXPKGS_ROOT/. { }).vikunja.frontend.pnpmDeps") -sed -i -E '/fetchPnpmDeps \{/,/\};/ s#hash = ".*"#hash = "'"$pnpm_hash"'"#' package.nix - -# Go modules vendor hash -vendor_hash=$(nurl -e "(import $NIXPKGS_ROOT/. { }).vikunja.goModules") -sed -i -E 's#vendorHash = ".*"#vendorHash = "'"$vendor_hash"'"#' package.nix - -echo "Update complete!" -echo "Version: $version" -echo "Source hash: $src_hash" -echo "Frontend pnpm hash: $pnpm_hash" -echo "Go vendor hash: $vendor_hash" diff --git a/pkgs/by-name/vi/vikunja/veans.nix b/pkgs/by-name/vi/vikunja/veans.nix new file mode 100644 index 000000000000..d5917a71d603 --- /dev/null +++ b/pkgs/by-name/vi/vikunja/veans.nix @@ -0,0 +1,34 @@ +{ + meta, + src, + version, + + buildGoModule, +}: + +buildGoModule (finalAttrs: { + pname = "veans"; + inherit src version; + + __structuredAttrs = true; + + modRoot = "veans"; + + vendorHash = "sha256-ac2M7wNlOn6ku8sn/rZmPCSGPodw88ufR8tr1lh54II="; + + env.CGO_ENABLED = 0; + + ldflags = [ + "-s" + "-X main.version=v${finalAttrs.version}" + ]; + + # needs a running vikunja instance + doCheck = false; + + meta = meta // { + description = "A beans-shaped CLI for Vikunja"; + homepage = "https://vikunja.io/docs/veans/"; + mainProgram = "veans"; + }; +}) diff --git a/pkgs/by-name/vo/vouch-proxy/package.nix b/pkgs/by-name/vo/vouch-proxy/package.nix index a61b99f7790f..b88fe8d4b7e3 100644 --- a/pkgs/by-name/vo/vouch-proxy/package.nix +++ b/pkgs/by-name/vo/vouch-proxy/package.nix @@ -2,6 +2,7 @@ lib, buildGoModule, fetchFromGitHub, + fetchpatch, }: buildGoModule (finalAttrs: { @@ -15,6 +16,14 @@ buildGoModule (finalAttrs: { hash = "sha256-xI9xucRb2D2a1Fvp5DetB4ln3C020qSGEVnuIpy1TMI="; }; + patches = [ + (fetchpatch { + name = "CVE-2026-55149.patch"; + url = "https://github.com/vouch/vouch-proxy/commit/fa18ce30ba50a4863a436acad044c22965329c4f.patch"; + hash = "sha256-hhjqt23BIF4ZU1GswRRDnWNbSV0Wa1wpboYRfRyaaco="; + }) + ]; + vendorHash = "sha256-hieN3RJA0eBqlYxJj6hKgpQhq8s3vg/fPzxW0XSrlPA="; ldflags = [ diff --git a/pkgs/by-name/zi/zinit/package.nix b/pkgs/by-name/zi/zinit/package.nix index a52156552a37..644a83527456 100644 --- a/pkgs/by-name/zi/zinit/package.nix +++ b/pkgs/by-name/zi/zinit/package.nix @@ -4,17 +4,18 @@ fetchFromGitHub, installShellFiles, nix-update-script, + zsh, }: stdenvNoCC.mkDerivation (finalAttrs: { pname = "zinit"; - version = "3.14.0"; + version = "3.17.0"; src = fetchFromGitHub { owner = "zdharma-continuum"; repo = "zinit"; tag = "v${finalAttrs.version}"; - hash = "sha256-cBMGmFrveBes30aCSLMBO8WrtoPZeMNjcEQoQEzBNvM="; + hash = "sha256-5QURQfU0J1zrnJFVlFYM3WNRbQPd5iWTX6MGxManDOs="; }; outputs = [ @@ -34,7 +35,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { # Source files mkdir -p $out/share/zinit - install -m0444 zinit{,-side,-install,-autoload,-additional}.zsh _zinit $out/share/zinit + install -m0444 zinit{,-side,-install,-autoload,-additional}.zsh _zinit VERSION $out/share/zinit mkdir $out/share/zinit/share install -m0555 share/git-process-output.zsh $out/share/zinit/share install -m0444 share/rpm2cpio.zsh $out/share/zinit/share @@ -49,7 +50,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { mkdir -p $doc/share/doc/zinit install -m0444 doc/zsdoc/*.adoc $doc/share/doc/zinit - install -m0444 doc/HACKING.md $doc/share/doc/zinit + install -m0444 CHANGELOG.md doc/HACKING.md $doc/share/doc/zinit runHook postInstall ''; @@ -61,6 +62,21 @@ stdenvNoCC.mkDerivation (finalAttrs: { --replace-fail "ZINIT[MAN_DIR]:=\''${ZPFX}/man" "ZINIT[MAN_DIR]:=$man/share/man" ''; + doInstallCheck = true; + nativeInstallCheckInputs = [ zsh ]; + installCheckPhase = '' + runHook preInstallCheck + + HOME="$TMPDIR" \ + ZINIT_DIR="$out/share/zinit" \ + zsh -dfc ' + source "$ZINIT_DIR/zinit.zsh" + (( $+functions[zinit] )) + ' + + runHook postInstallCheck + ''; + passthru = { updateScript = nix-update-script { }; }; @@ -68,7 +84,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { meta = { homepage = "https://github.com/zdharma-continuum/zinit"; description = "Flexible zsh plugin manager"; - changelog = "https://github.com/zdharma-continuum/zinit/blob/${finalAttrs.src.rev}/doc/CHANGELOG.md"; + changelog = "https://github.com/zdharma-continuum/zinit/blob/${finalAttrs.src.rev}/CHANGELOG.md"; license = lib.licenses.mit; platforms = lib.platforms.unix; maintainers = with lib.maintainers; [ diff --git a/pkgs/development/interpreters/ruby/default.nix b/pkgs/development/interpreters/ruby/default.nix index e6eae5b7f7d2..4d8406f5f113 100644 --- a/pkgs/development/interpreters/ruby/default.nix +++ b/pkgs/development/interpreters/ruby/default.nix @@ -411,8 +411,8 @@ in }; ruby_4_0 = generic { - version = rubyVersion "4" "0" "5" ""; - hash = "sha256-fWFJB5pj+K4dMmyfplxgGbotwxVerns5FZgXkRyIlY4="; + version = rubyVersion "4" "0" "7" ""; + hash = "sha256-kRrOIPkNBoyg5N2m0OTw+B5S5S8t1PQATHIeJTQS6C0="; cargoHash = "sha256-z7NwWc4TaR042hNx0xgRkh/BQEpEJtE53cfrN0qNiE0="; }; diff --git a/pkgs/development/ocaml-modules/mirage-crypto/default.nix b/pkgs/development/ocaml-modules/mirage-crypto/default.nix index 2dea0eb4c218..16854c5d9e5e 100644 --- a/pkgs/development/ocaml-modules/mirage-crypto/default.nix +++ b/pkgs/development/ocaml-modules/mirage-crypto/default.nix @@ -43,5 +43,8 @@ buildDunePackage (finalAttrs: { sternenseemann momeemt ]; + knownVulnerabilities = [ + "CVE-2026-87732" # fixed in 2.2.0 + ]; }; }) diff --git a/pkgs/development/ocaml-modules/mirage-crypto/ec.nix b/pkgs/development/ocaml-modules/mirage-crypto/ec.nix index 6699de8e39cc..accc17fc198a 100644 --- a/pkgs/development/ocaml-modules/mirage-crypto/ec.nix +++ b/pkgs/development/ocaml-modules/mirage-crypto/ec.nix @@ -43,5 +43,10 @@ buildDunePackage { meta = mirage-crypto.meta // { description = "Elliptic Curve Cryptography with primitives taken from Fiat"; + knownVulnerabilities = [ + "CVE-2026-87733" # fixed in 2.2.0 + "CVE-2026-87736" # fixed in 2.3.0 + "CVE-2026-87737" # fixed in 2.4.0 + ]; }; } diff --git a/pkgs/development/ocaml-modules/mirage-crypto/pk.nix b/pkgs/development/ocaml-modules/mirage-crypto/pk.nix index 6700008e7a97..668cb95e74d4 100644 --- a/pkgs/development/ocaml-modules/mirage-crypto/pk.nix +++ b/pkgs/development/ocaml-modules/mirage-crypto/pk.nix @@ -30,5 +30,8 @@ buildDunePackage { meta = mirage-crypto.meta // { description = "Simple public-key cryptography for the modern age"; + knownVulnerabilities = [ + "CVE-2026-87735" # fixed in 2.3.0 + ]; }; } diff --git a/pkgs/development/python-modules/exllamav3/default.nix b/pkgs/development/python-modules/exllamav3/default.nix index 6ec0b3169923..59301c5686e0 100644 --- a/pkgs/development/python-modules/exllamav3/default.nix +++ b/pkgs/development/python-modules/exllamav3/default.nix @@ -22,18 +22,28 @@ typing-extensions, }: let - newerThanTuring = lib.filter (version: lib.versionOlder "7.9" version) torch.cudaCapabilities; + # https://github.com/turboderp-org/exllamav3/blob/master/.github/workflows/build.yml#L55 + # https://github.com/turboderp-org/exllamav3/issues/44 + # Using unsupported platforms the build will fail + cudaCapabilities = lib.intersectLists torch.cudaCapabilities [ + "8.0" + "8.6" + "8.9" + "9.0" + "10.0" + "12.0" + ]; in buildPythonPackage.override { inherit (torch) stdenv; } (finalAttrs: { pname = "exllamav3"; - version = "1.4.8"; + version = "1.5.0"; pyproject = true; src = fetchFromGitHub { owner = "turboderp-org"; repo = "exllamav3"; tag = "v${finalAttrs.version}"; - hash = "sha256-CnbJR5rsHzNEeQBJLdD7LGrrTgy+GKpvop1R4uY4d8U="; + hash = "sha256-gW6A2nWx3lumnJz7r7vxQyC1qM9Agqdr0DiL68yJvAI="; }; pythonRelaxDeps = [ @@ -57,7 +67,7 @@ buildPythonPackage.override { inherit (torch) stdenv; } (finalAttrs: { ]; dependencies = [ - flash-linear-attention + flash-linear-attention # Upstream vendors it instead llguidance marisa-trie numpy @@ -73,9 +83,9 @@ buildPythonPackage.override { inherit (torch) stdenv; } (finalAttrs: { env = lib.optionalAttrs torch.cudaSupport { CUDA_HOME = lib.getDev cudaPackages.cuda_nvcc; - # exllamav3 only supports turing or newer GPUs - # https://github.com/turboderp-org/exllamav3/issues/44 - TORCH_CUDA_ARCH_LIST = lib.concatStringsSep ";" newerThanTuring; + TORCH_CUDA_ARCH_LIST = lib.concatStringsSep ";" ( + cudaCapabilities ++ [ "${lib.last cudaCapabilities}+PTX" ] + ); }; pythonImportsCheck = [ "exllamav3" ]; diff --git a/pkgs/development/tools/pnpm/default.nix b/pkgs/development/tools/pnpm/default.nix index 27a71f849f8d..4474934a9e52 100644 --- a/pkgs/development/tools/pnpm/default.nix +++ b/pkgs/development/tools/pnpm/default.nix @@ -53,8 +53,8 @@ let hash = "sha256-WOFDJYhx31FYm2UcBiBdq+xIdmpdu6PCWZm2m1C+WY4="; }; "11" = { - version = "11.25.0"; - hash = "sha256-M90HSPJ+eRbE8ci2lDRhmD40U7BrvaYxKmKAEwtIgeU="; + version = "11.27.0"; + hash = "sha256-QKMlFaJVB/jyJt+74lOA4vBTlEwuzGTAwcuYtBy7ke8="; }; }; diff --git a/pkgs/development/web/nodejs/v26.nix b/pkgs/development/web/nodejs/v26.nix index c6e7ed20dab4..e204d6b3e4b6 100644 --- a/pkgs/development/web/nodejs/v26.nix +++ b/pkgs/development/web/nodejs/v26.nix @@ -23,8 +23,8 @@ let [ ]; in buildNodejs { - version = "26.8.2"; - sha256 = "36b37bf5ee4d092b9d9dff2d1a90b1444f8b453eddf6ff96cabdebb97d32f41d"; + version = "26.9.0"; + sha256 = "47b970d88511b429e587b740fa733176909d2a2005a29662f01b05205f58468b"; patches = (lib.optional (!(stdenv.hostPlatform.emulatorAvailable buildPackages)) (fetchpatch2 { url = "https://raw.githubusercontent.com/buildroot/buildroot/2f0c31bffdb59fb224387e35134a6d5e09a81d57/package/nodejs/nodejs-src/0003-include-obj-name-in-shared-intermediate.patch"; diff --git a/pkgs/os-specific/linux/kernel/common-config.nix b/pkgs/os-specific/linux/kernel/common-config.nix index 3965a361637b..94d9f55743a1 100644 --- a/pkgs/os-specific/linux/kernel/common-config.nix +++ b/pkgs/os-specific/linux/kernel/common-config.nix @@ -1498,8 +1498,8 @@ let ACPI_HOTPLUG_CPU = yes; ACPI_HOTPLUG_MEMORY = yes; MEMORY_HOTPLUG = yes; - MEMORY_HOTPLUG_DEFAULT_ONLINE = whenOlder "6.14" yes; - MHP_DEFAULT_ONLINE_TYPE_ONLINE_AUTO = whenAtLeast "6.14" yes; + MEMORY_HOTPLUG_DEFAULT_ONLINE = whenOlder "6.12" yes; + MHP_DEFAULT_ONLINE_TYPE_ONLINE_AUTO = whenAtLeast "6.12" yes; MEMORY_HOTREMOVE = lib.mkIf ( with stdenv.hostPlatform; isLoongArch64 diff --git a/pkgs/tools/filesystems/garage/default.nix b/pkgs/tools/filesystems/garage/default.nix index 12ce3e3c5353..9440190740ca 100644 --- a/pkgs/tools/filesystems/garage/default.nix +++ b/pkgs/tools/filesystems/garage/default.nix @@ -113,16 +113,9 @@ rec { }; garage_2 = generic { - version = "2.3.0"; - hash = "sha256-CqHcaVGgXL/jjqq7XN+kzEp6xoNgwBfGpMKYbTd78Ys="; - cargoHash = "sha256-ANh97G/2/KtCMN4gldteq6ROduk1AQJkI5zS9n97OJY="; - cargoPatches = [ - (fetchpatch2 { - # fix: prevent depending on aws-lc via reqwest - url = "https://git.deuxfleurs.fr/Deuxfleurs/garage/commit/7c18abb664d891cdb696b478058b7506e3d53f44.patch"; - hash = "sha256-f/+vDOC+kcmJVLtx1Y6OepoJBZhX30DULwSLnyQN5aI="; - }) - ]; + version = "2.4.1"; + hash = "sha256-+3w4R0IGxc7GCVW3t7Izt6Y5PVUjxHsdLrr74ckR9Mg="; + cargoHash = "sha256-G928EsavtEgxugLzpBGSbo2RMHLzu9PZf9r3GqU5J3E="; }; garage = garage_1;