From f27e8695dc78f3c803d71355d75db593677639ea Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn=20Forsman?= Date: Tue, 22 Sep 2026 19:22:19 +0200 Subject: [PATCH 01/11] ndpi: 5.0 -> 6.0 Release notes: https://github.com/ntop/nDPI/releases/tag/6.0 Explicitly build the static library, to have the same library output as before, or else we break ntopng. --- pkgs/by-name/nd/ndpi/package.nix | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/nd/ndpi/package.nix b/pkgs/by-name/nd/ndpi/package.nix index 4d463c63684d..22dcc27f5fe3 100644 --- a/pkgs/by-name/nd/ndpi/package.nix +++ b/pkgs/by-name/nd/ndpi/package.nix @@ -12,13 +12,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "ndpi"; - version = "5.0"; + version = "6.0"; src = fetchFromGitHub { owner = "ntop"; repo = "nDPI"; tag = finalAttrs.version; - hash = "sha256-Elnj6qDuT8UWDxmasiHOt5DxC7GcH5zgrp3J3LYcl0c="; + hash = "sha256-C6SNdXGaKu2MHDK2eA8bA/2yRzDQt8jZWsbPfJzRg2g="; }; nativeBuildInputs = [ @@ -33,6 +33,10 @@ stdenv.mkDerivation (finalAttrs: { libpcap ]; + configureFlags = [ + "--enable-static" + ]; + meta = { description = "Library for deep-packet inspection"; longDescription = '' From 83afc2f71913ba074bff587875525d9273085659 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn=20Forsman?= Date: Tue, 22 Sep 2026 19:24:25 +0200 Subject: [PATCH 02/11] ntopng: 6.6 -> 7.0 Release notes: https://github.com/ntop/ntopng/releases/tag/7.0 --- pkgs/by-name/nt/ntopng/package.nix | 14 ++------------ 1 file changed, 2 insertions(+), 12 deletions(-) diff --git a/pkgs/by-name/nt/ntopng/package.nix b/pkgs/by-name/nt/ntopng/package.nix index 66925afc51a2..7182407e435f 100644 --- a/pkgs/by-name/nt/ntopng/package.nix +++ b/pkgs/by-name/nt/ntopng/package.nix @@ -24,30 +24,20 @@ which, zeromq, cmake, - fetchpatch, }: stdenv.mkDerivation (finalAttrs: { pname = "ntopng"; - version = "6.6"; + version = "7.0"; src = fetchFromGitHub { owner = "ntop"; repo = "ntopng"; tag = finalAttrs.version; - hash = "sha256-BYJtsEuxmo6jzqCoC/A5vDAiFSGqy8XFyqooGDTZE40="; + hash = "sha256-46cqNr3sLa5Xy8PbddofxRjCCvUFeHPlOihgd+5qBE0="; fetchSubmodules = true; }; - patches = [ - # Fix CVE-2026-86091 CVE-2026-86090 - (fetchpatch { - name = "CVE-2026-86090-CVE-2026-86091.patch"; - url = "https://github.com/ntop/ntopng/commit/7d830f31af367745431c5d92e2e82fc432f6bdd8.patch"; - hash = "sha256-8N0q/Ekd5ni1jxZh8Jatipz+z57r1jqu/77o/oI/FuE="; - }) - ]; - preConfigure = '' substituteInPlace Makefile.in \ --replace "/bin/rm" "rm" From bed6c6735cb6a06ae0bb25fb0c57732ede01cb87 Mon Sep 17 00:00:00 2001 From: Rafael Ieda Date: Wed, 23 Sep 2026 10:28:18 -0300 Subject: [PATCH 03/11] mullvad-vpn: add darwin to badPlatforms --- pkgs/by-name/mu/mullvad-vpn/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/mu/mullvad-vpn/package.nix b/pkgs/by-name/mu/mullvad-vpn/package.nix index 08f9f2a9702f..8b8c919425b9 100644 --- a/pkgs/by-name/mu/mullvad-vpn/package.nix +++ b/pkgs/by-name/mu/mullvad-vpn/package.nix @@ -127,5 +127,8 @@ buildNpmPackage (finalAttrs: { sigmasquadron ]; mainProgram = "mullvad-vpn"; + # Never built on darwin since first introduction in nixpkgs + # The build is currently hardcoded for linux (pack:linux), so adding darwin support will likely require major changes + badPlatforms = lib.platforms.darwin; }; }) From 6bde39f7a062ba669a5a47e5982b99c16b220b79 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 23 Sep 2026 15:27:16 +0000 Subject: [PATCH 04/11] copyparty: 1.20.23 -> 1.20.24 --- pkgs/by-name/co/copyparty/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/co/copyparty/package.nix b/pkgs/by-name/co/copyparty/package.nix index 2be18b9212bb..f3a3e0708eef 100644 --- a/pkgs/by-name/co/copyparty/package.nix +++ b/pkgs/by-name/co/copyparty/package.nix @@ -71,11 +71,11 @@ in python3Packages.buildPythonApplication rec { pname = "copyparty${nameSuffix}"; - version = "1.20.23"; + version = "1.20.24"; src = fetchurl { url = "https://github.com/9001/copyparty/releases/download/v${version}/copyparty-${version}.tar.gz"; - hash = "sha256-wJV84HewSUKSVBEWuUc/29oeZZe12RWLL8Rw2woYNN0="; + hash = "sha256-RQ3KfVcB5nI12RbgNfzCFDMozh0Ka1t+PF0sI727c+M="; }; pyproject = true; From 6002c26317d2699e8b30c66beddfb7e94cceafa5 Mon Sep 17 00:00:00 2001 From: AlexAntonik Date: Tue, 22 Sep 2026 18:21:33 +0300 Subject: [PATCH 05/11] lurk: fix license Signed-off-by: AlexAntonik --- pkgs/by-name/lu/lurk/package.nix | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/lu/lurk/package.nix b/pkgs/by-name/lu/lurk/package.nix index b8396f564a54..9d1a56ed4e0b 100644 --- a/pkgs/by-name/lu/lurk/package.nix +++ b/pkgs/by-name/lu/lurk/package.nix @@ -36,7 +36,12 @@ rustPlatform.buildRustPackage (finalAttrs: { changelog = "https://github.com/jakwai01/lurk/releases/tag/v${finalAttrs.version}"; description = "Simple and pretty alternative to strace"; homepage = "https://github.com/jakwai01/lurk"; - license = lib.licenses.agpl3Only; + license = + with lib.licenses; + OR [ + mit + asl20 + ]; mainProgram = "lurk"; maintainers = with lib.maintainers; [ gepbird From 6b5e067e82087eb85db160d49e77e3838a992315 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 23 Sep 2026 21:38:52 +0000 Subject: [PATCH 06/11] lakectl: 1.86.0 -> 1.87.0 --- pkgs/by-name/la/lakectl/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/la/lakectl/package.nix b/pkgs/by-name/la/lakectl/package.nix index 2da1f5c89adc..c51ffc0d861e 100644 --- a/pkgs/by-name/la/lakectl/package.nix +++ b/pkgs/by-name/la/lakectl/package.nix @@ -7,18 +7,18 @@ buildGo126Module (finalAttrs: { pname = "lakectl"; - version = "1.86.0"; + version = "1.87.0"; src = fetchFromGitHub { owner = "treeverse"; repo = "lakeFS"; tag = "v${finalAttrs.version}"; - hash = "sha256-8C0XK1qs7z/1MCSPzDP2elJtJRxLcypZbtDYUpEe4g4="; + hash = "sha256-EuLw61X4+bdhgU9dablxuILcDKKP+OfmabZCPIZ3Y2c="; }; subPackages = [ "cmd/lakectl" ]; proxyVendor = true; - vendorHash = "sha256-Gcmv1b8NwmkGIgMCmLp0E7ZBSWm2PziQWhhUXI3Y3es="; + vendorHash = "sha256-cjRyapoZVYVYn/a09KxNkBsMDdWEpESGmm38M7F0YU8="; ldflags = [ "-s" From 14f0c186e0535df78da205c7d490d92157005781 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Wed, 23 Sep 2026 18:05:15 -0400 Subject: [PATCH 07/11] ci/treefmt.nix: support self-repository syntax --- ci/treefmt.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/ci/treefmt.nix b/ci/treefmt.nix index a0d4ffbc1ef2..4a62db801333 100644 --- a/ci/treefmt.nix +++ b/ci/treefmt.nix @@ -39,6 +39,11 @@ ".github/workflows/*.yml" ".github/workflows/*.yaml" ]; + options = [ + # Support self-repository syntax + ''-ignore=reusable workflow call "\$/.+" at "uses" is not following the format'' + ''-ignore=specifying action "\$/.+" in invalid format because ref is missing.'' + ]; }; biome = { From 903a09b26eeb6d4dbe0e08d3c551bae534dbed77 Mon Sep 17 00:00:00 2001 From: SkohTV Date: Mon, 25 May 2026 10:42:07 -0400 Subject: [PATCH 08/11] python3Packages.verspec: migrate to pyproject --- pkgs/development/python-modules/verspec/default.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/development/python-modules/verspec/default.nix b/pkgs/development/python-modules/verspec/default.nix index c3ea44b0c03d..afbf4134a5ec 100644 --- a/pkgs/development/python-modules/verspec/default.nix +++ b/pkgs/development/python-modules/verspec/default.nix @@ -4,18 +4,21 @@ fetchPypi, pretend, pytestCheckHook, + setuptools, }: buildPythonPackage rec { pname = "verspec"; version = "0.1.0"; - format = "setuptools"; + pyproject = true; src = fetchPypi { inherit pname version; hash = "sha256-xFBMppeyBWzbS/pxIUYfWg6BgJJVtBwD3aS6gjY3wB4="; }; + build-system = [ setuptools ]; + nativeCheckInputs = [ pretend pytestCheckHook From ce0a92aecf87f950ed34f17c2474577e0b265196 Mon Sep 17 00:00:00 2001 From: SkohTV Date: Mon, 25 May 2026 10:43:10 -0400 Subject: [PATCH 09/11] python3Packages.verspec: modernize --- pkgs/development/python-modules/verspec/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/python-modules/verspec/default.nix b/pkgs/development/python-modules/verspec/default.nix index afbf4134a5ec..dff56cebdb5e 100644 --- a/pkgs/development/python-modules/verspec/default.nix +++ b/pkgs/development/python-modules/verspec/default.nix @@ -7,13 +7,13 @@ setuptools, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "verspec"; version = "0.1.0"; pyproject = true; src = fetchPypi { - inherit pname version; + inherit (finalAttrs) pname version; hash = "sha256-xFBMppeyBWzbS/pxIUYfWg6BgJJVtBwD3aS6gjY3wB4="; }; @@ -40,4 +40,4 @@ buildPythonPackage rec { ]; maintainers = [ ]; }; -} +}) From c6dad43f3448fe02e842be9423b6685c58a389bd Mon Sep 17 00:00:00 2001 From: SkohTV Date: Mon, 25 May 2026 16:19:31 -0400 Subject: [PATCH 10/11] python3Packages.verspec: use compound licenses --- pkgs/development/python-modules/verspec/default.nix | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/verspec/default.nix b/pkgs/development/python-modules/verspec/default.nix index dff56cebdb5e..991983b93d7f 100644 --- a/pkgs/development/python-modules/verspec/default.nix +++ b/pkgs/development/python-modules/verspec/default.nix @@ -34,10 +34,12 @@ buildPythonPackage (finalAttrs: { meta = { description = "Flexible version handling"; homepage = "https://github.com/jimporter/verspec"; - license = with lib.licenses; [ - bsd2 # and - asl20 - ]; + license = + with lib.licenses; + AND [ + bsd2 + asl20 + ]; maintainers = [ ]; }; }) From 5a4b5829144640680b198f8c93506b8a48f7fc57 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 24 Sep 2026 01:34:14 +0000 Subject: [PATCH 11/11] stoolap: 0.4.1 -> 0.4.2 --- pkgs/by-name/st/stoolap/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/st/stoolap/package.nix b/pkgs/by-name/st/stoolap/package.nix index e3c228326316..68ccef88b2c3 100644 --- a/pkgs/by-name/st/stoolap/package.nix +++ b/pkgs/by-name/st/stoolap/package.nix @@ -7,16 +7,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "stoolap"; - version = "0.4.1"; + version = "0.4.2"; src = fetchFromGitHub { owner = "stoolap"; repo = "stoolap"; tag = "v${finalAttrs.version}"; - hash = "sha256-xL0MFxtIqSsQh5SDEvIsJgBi/o/To0oht8ZjdEFJX7Q="; + hash = "sha256-e+RUEEADHbbVF4wfY3wrOUV+C2EmzhV+kLA+k21StuI="; }; - cargoHash = "sha256-edWMWY0gBjDNroJ9qm6u7krTy1lskD4s9aSS8jEN/MM="; + cargoHash = "sha256-ZZa+F0yQKBNkxZgPsMi6imjfojn2oUIrGKmMfjY4tD8="; # On aarch64-darwin, dev target needs to set panic strategy to abort # However this must be set while the flag `-Zpanic_abort_tests` is also set,