Merge master into staging-nixos

This commit is contained in:
nixpkgs-ci[bot]
2026-09-19 12:13:37 +00:00
committed by GitHub
37 changed files with 1106 additions and 663 deletions

View File

@@ -301,6 +301,8 @@
- `programs.regreet` has been renamed to `services.displayManager.regreet`.
- `services.harmonia` gained [`gc`](#opt-services.harmonia.gc.enable) options that run `harmonia-gc`, a faster reimplementation of `nix-collect-garbage`, either on demand via `harmonia-gc.service` or on a timer with `services.harmonia.gc.automatic` as an alternative to `nix.gc.automatic`.
- `komodo` has been updated to the v2 release line (2.x). See the [upstream v1 → v2 upgrade guide](https://github.com/moghtech/komodo/releases/tag/v2.0.0).
- `temporal` has been updated to the 1.31 release line. Always consult the [upstream upgrade

View File

@@ -8,6 +8,7 @@ let
cfg = config.services.harmonia;
cacheCfg = cfg.cache;
daemonCfg = cfg.daemon;
gcCfg = cfg.gc;
format = pkgs.formats.toml { };
@@ -69,6 +70,105 @@ in
};
};
gc = {
enable = lib.mkEnableOption "harmonia-gc, a faster nix-collect-garbage";
automatic = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Run garbage collection automatically on a schedule.";
};
dates = lib.mkOption {
type = with lib.types; either singleLineStr (listOf str);
apply = lib.toList;
default = [ "03:15" ];
example = "weekly";
description = ''
When to run garbage collection. Calendar event in the format
specified by {manpage}`systemd.time(7)`.
'';
};
randomizedDelaySec = lib.mkOption {
type = lib.types.singleLineStr;
default = "0";
example = "45min";
description = "Randomized delay before each run.";
};
persistent = lib.mkOption {
type = lib.types.bool;
default = true;
description = "Run on next boot if a scheduled run was missed.";
};
deleteOlderThan = lib.mkOption {
type = lib.types.nullOr lib.types.singleLineStr;
default = null;
example = "30d";
description = "Delete profile generations older than this.";
};
ensureFree = lib.mkOption {
type = lib.types.nullOr lib.types.singleLineStr;
default = null;
example = "50G";
description = ''
Free space until this much is available, then stop. Accepts an
absolute size like "50G" or a percentage of the store's filesystem
like "20%".
'';
};
keepRecent = lib.mkOption {
type = lib.types.nullOr lib.types.singleLineStr;
default = null;
example = "1d";
description = ''
Keep store paths registered within this time window. Avoids deleting
build dependencies fetched during a recent build.
'';
};
noVacuum = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
Skip the SQLite VACUUM after garbage collection. Enable on busy
builders, where concurrent nix-daemon readers prevent cleanup of
the database-sized WAL that VACUUM produces.
'';
};
chunkSize = lib.mkOption {
type = lib.types.nullOr lib.types.ints.positive;
default = null;
description = ''
Number of dead paths invalidated per database transaction. Lower
values keep the WAL (and its disk use) smaller during deletion at
the cost of more checkpoints; null uses the built-in default.
'';
};
gcRootsDirs = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [ ];
example = [ "/mnt/extra-roots" ];
description = ''
Extra directories to scan for GC roots, treated like the standard
gcroots directory. Nix only scans its own state directories; this
keeps roots that live elsewhere from being collected.
'';
};
extraArgs = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [ ];
description = "Extra arguments to pass to harmonia-gc.";
};
};
daemon = {
enable = lib.mkEnableOption "Harmonia daemon: Nix daemon protocol implementation";
@@ -194,6 +294,63 @@ in
};
})
(lib.mkIf gcCfg.enable {
assertions = [
{
assertion = gcCfg.automatic -> config.nix.enable;
message = "services.harmonia.gc.automatic requires nix.enable";
}
];
warnings = lib.optional (gcCfg.automatic && config.nix.gc.automatic) ''
Both services.harmonia.gc.automatic and nix.gc.automatic are enabled.
Disable nix.gc.automatic to avoid running two garbage collectors.
'';
systemd.services.harmonia-gc = {
description = "Harmonia Nix Garbage Collector";
# `nix config show` for keep-derivations/keep-outputs.
path = [ config.nix.package ];
serviceConfig = {
Type = "oneshot";
ExecStart = lib.escapeShellArgs (
[ (lib.getExe' cfg.package "harmonia-gc") ]
++ lib.optionals (gcCfg.deleteOlderThan != null) [
"--delete-older-than"
gcCfg.deleteOlderThan
]
++ lib.optionals (gcCfg.ensureFree != null) [
"--ensure-free"
gcCfg.ensureFree
]
++ lib.optionals (gcCfg.keepRecent != null) [
"--keep-recent"
gcCfg.keepRecent
]
++ lib.optional gcCfg.noVacuum "--no-vacuum"
++ lib.optionals (gcCfg.chunkSize != null) [
"--chunk-size"
(toString gcCfg.chunkSize)
]
++ lib.concatMap (d: [
"--gc-roots-dir"
d
]) gcCfg.gcRootsDirs
++ gcCfg.extraArgs
);
};
startAt = lib.optionals gcCfg.automatic gcCfg.dates;
restartIfChanged = false;
};
systemd.timers.harmonia-gc = lib.mkIf gcCfg.automatic {
timerConfig = {
RandomizedDelaySec = gcCfg.randomizedDelaySec;
Persistent = gcCfg.persistent;
};
};
})
(lib.mkIf daemonCfg.enable {
systemd.services.harmonia-daemon =
let

View File

@@ -833,6 +833,7 @@ in
};
haproxy = runTest ./haproxy.nix;
harmonia = runTest ./harmonia.nix;
harmonia-gc = runTest ./harmonia-gc.nix;
haste-server = runTest ./haste-server.nix;
hbase2 = runTest {
imports = [ ./hbase.nix ];

View File

@@ -0,0 +1,54 @@
{ pkgs, ... }:
{
name = "harmonia-gc";
meta.maintainers = [ pkgs.lib.maintainers.mic92 ];
nodes.machine =
{ pkgs, ... }:
{
services.harmonia.gc = {
enable = true;
automatic = true;
keepRecent = "1h";
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
virtualisation.writableStore = true;
environment.systemPackages = [
pkgs.hello
pkgs.sqlite
];
};
testScript = ''
machine.wait_for_unit("multi-user.target")
machine.succeed("systemctl is-active harmonia-gc.timer")
db = "/nix/var/nix/db/db.sqlite"
def gc() -> None:
machine.succeed("systemctl start harmonia-gc.service")
# load-db at boot sets registrationTime=now; stop keepRecent from pinning everything.
machine.succeed(f"sqlite3 {db} 'UPDATE ValidPaths SET registrationTime = 1'")
machine.succeed("echo dead > /tmp/dead", "echo rooted > /tmp/rooted")
dead = machine.succeed("nix-store --add /tmp/dead").strip()
rooted = machine.succeed("nix-store --add /tmp/rooted").strip()
machine.succeed(f"ln -s {rooted} /nix/var/nix/gcroots/rooted")
machine.succeed(
f"sqlite3 {db} \"UPDATE ValidPaths SET registrationTime = 1 WHERE path IN ('{dead}', '{rooted}')\""
)
gc()
machine.fail(f"test -e {dead}")
machine.succeed(f"test -e {rooted}")
# system profile is a root
machine.succeed("hello --version")
# keepRecent pins freshly registered paths
machine.succeed("echo recent > /tmp/recent")
recent = machine.succeed("nix-store --add /tmp/recent").strip()
gc()
machine.succeed(f"test -e {recent}")
'';
}

View File

@@ -6,11 +6,11 @@
melpaBuild (finalAttrs: {
pname = "ebuild-mode";
version = "1.84";
version = "1.85";
src = fetchzip {
url = "https://gitweb.gentoo.org/proj/ebuild-mode.git/snapshot/ebuild-mode-${finalAttrs.version}.tar.bz2";
hash = "sha256-+WbKgOR0eCIvBgQrXzVOk8k2mV7INObY59vc46KvMYo=";
hash = "sha256-LSXDf4LHqk8+ga36BIQ+LHIaJQRpen293di1rNrMunE=";
};
meta = {

View File

@@ -6,13 +6,13 @@
buildGoModule (finalAttrs: {
pname = "codespelunker";
version = "3.1.0";
version = "3.2.0";
src = fetchFromGitHub {
owner = "boyter";
repo = "cs";
rev = "v${finalAttrs.version}";
hash = "sha256-cPaAuZJ/Flea4BZ2LTprE5BFtHqgVCuF+2VLShgkCrQ=";
hash = "sha256-yjzqy0YgpKUR1ZlRXpBW9GBoLmXZ1AjTfPfkxD9Ht/s=";
};
vendorHash = null;

View File

@@ -11,16 +11,16 @@
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cook-cli";
version = "0.35.0";
version = "0.36.0";
src = fetchFromGitHub {
owner = "cooklang";
repo = "cookcli";
rev = "v${finalAttrs.version}";
hash = "sha256-d2sO25QtElhAATgUeyDQaYMN2ZC7r6Nj8IH9xe+pabs=";
hash = "sha256-ihsVvlyp//A4pNlt1+DlYWyz52enHVeU6uST7bxcwqw=";
};
cargoHash = "sha256-i8vE4iMe8JfghR2k9pNP3CkZlXP+87eF3MZfCBLxhiM=";
cargoHash = "sha256-e47x9XzABpXO+qvTydrBOPU9KTZTYJkbJvWvpUUh7Bo=";
# Build without the self-updating feature
buildNoDefaultFeatures = true;
@@ -40,7 +40,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
npmDeps = fetchNpmDeps {
inherit (finalAttrs) src;
hash = "sha256-ZSRd4tcAsR1tKZ8ZBcb95C1FWEaijsA0WQ5EME0cOfo=";
hash = "sha256-n/pxjcgDqhlUC09ynWExxClVT9WixahpPYRU3GAvzBc=";
};
preBuild = ''

View File

@@ -1,14 +1,14 @@
{
"aarch64-darwin": {
"version": "3.9.19",
"version": "3.10.31",
"vscodeVersion": "1.126.0",
"url": "https://windsurf-stable.codeiumdata.com/darwin-arm64/stable/e2b252e21dd5cdfd88fce58f49477260e90294bc/Devin-darwin-arm64-3.9.19.zip",
"sha256": "105304e149890f3f7efe407725866362f689dbec2a026f1d58340257d810e119"
"url": "https://windsurf-stable.codeiumdata.com/darwin-arm64/stable/b98cc43128712ba73c60cca73876f58a710aaa27/Devin-darwin-arm64-3.10.31.zip",
"sha256": "beb08d1269b7b91d8d64a96b5bb270ebbd9f792217fe526934a9392d69fb5bb8"
},
"x86_64-linux": {
"version": "3.9.19",
"version": "3.10.31",
"vscodeVersion": "1.126.0",
"url": "https://windsurf-stable.codeiumdata.com/linux-x64/stable/e2b252e21dd5cdfd88fce58f49477260e90294bc/Devin-linux-x64-3.9.19.tar.gz",
"sha256": "1c11c9acdb834936bc4e5ebac88e077dff1c100743fe3cbe47ba74e4da46aa46"
"url": "https://windsurf-stable.codeiumdata.com/linux-x64/stable/b98cc43128712ba73c60cca73876f58a710aaa27/Devin-linux-x64-3.10.31.tar.gz",
"sha256": "b3ddf1098c11255354d60a0778d7033989eaed85a37bbd55df90167f42eb5346"
}
}

View File

@@ -10,16 +10,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "difftastic";
version = "0.70.0";
version = "0.71.0";
src = fetchFromGitHub {
owner = "wilfred";
repo = "difftastic";
tag = finalAttrs.version;
hash = "sha256-AqdvPL5VL7H+h1RvGP7613pIHRIK3PEYdtHs1PTiPZw=";
hash = "sha256-xJdR/t6O8PavCKBiKnueiLR01g7nWGUHp9bcjOuDDA8=";
};
cargoHash = "sha256-sF1/bITwmIE2VT769aUgSgVaB059pGspjnMi4Ksx7dY=";
cargoHash = "sha256-HEX8njuArbgMQI8yDr66siRB8t+4P2Q7rxHuCeaD9Uw=";
buildInputs = [ rust-jemalloc-sys ];

View File

@@ -10,7 +10,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "harmonia";
version = "3.2.0";
version = "3.3.0";
__structuredAttrs = true;
strictDeps = true;
@@ -19,10 +19,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "nix-community";
repo = "harmonia";
tag = "harmonia-v${finalAttrs.version}";
hash = "sha256-eA0bEXk1T82oZCaX4HS9aZpwE9locw0pA3I1qf4yoEs=";
hash = "sha256-Q25ZdQ47e3SR/pUf/l9TrmEXvdW9eGSd9Vk3njnXbms=";
};
cargoHash = "sha256-gHsLr2P900Pa236N4fNlJ0w9Pu10Yb0F18zufHuU/b0=";
cargoHash = "sha256-dfQDf+sJYZ0sgcGiQ9BxNQIKEFCNyvYqEmWRUq/SA10=";
doCheck = false;
@@ -38,7 +38,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
"harmonia-v(.*)"
];
};
tests = { inherit (nixosTests) harmonia; };
tests = { inherit (nixosTests) harmonia harmonia-gc; };
};
meta = {

View File

@@ -8,7 +8,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "just-lsp";
version = "0.8.0";
version = "0.9.0";
__structuredAttrs = true;
@@ -16,10 +16,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "terror";
repo = "just-lsp";
tag = finalAttrs.version;
hash = "sha256-V075W4jrHGhOraSzoVCVtK3WSTCyb8lm6Vdfxyo8UOY=";
hash = "sha256-CzxRrXNUMJITGuQNU1D1YX44NHFU6ZePKtD6pw48yAY=";
};
cargoHash = "sha256-yp/4n1WR/JqhyGeK7CTvfaeHAu+9yhRiYI0W2ZBF6VY=";
cargoHash = "sha256-vr7tPcawg8zjnZg6KLVF6t2/9eku9BaieJ6jq4U9OiU=";
nativeInstallCheckInputs = [
versionCheckHook

File diff suppressed because it is too large Load Diff

View File

@@ -3,42 +3,33 @@
stdenv,
fetchFromGitHub,
jdk,
gradle_8,
gradle_9,
jre,
makeWrapper,
makeDesktopItem,
copyDesktopItems,
testers,
z3,
cvc5,
key,
substitute,
versionCheckHook,
}:
let
gradle = gradle_8;
gradle = gradle_9;
in
stdenv.mkDerivation rec {
pname = "key";
version = "2.12.3";
version = "3.0.0";
src = fetchFromGitHub {
owner = "KeYProject";
repo = "key";
tag = "KEY-${version}";
hash = "sha256-1pN0lmr/teVitpMIM9M9lSTkmnVcZwdAQay2pzgJDCk=";
tag = "KeY-${version}";
hash = "sha256-aEkQtTLSdZPXu0g9QHa40Oye4IyCl2BFpxmm5dqjKCk=";
};
patches = [
# Remove linting framework, causes issues with the update script.
(substitute {
src = ./remove-eisop-checker.patch;
substitutions = [
"--subst-var-by"
"version"
version
];
})
./remove-eisop-checker.patch
];
nativeBuildInputs = [
@@ -67,9 +58,11 @@ stdenv.mkDerivation rec {
__darwinAllowLocalNetworking = true;
# TODO: on update to 2.12.4+, try again
# (currently some tests are failing)
doCheck = false;
doCheck = stdenv.hostPlatform.isLinux;
nativeCheckInputs = [
z3
];
installPhase = ''
runHook preInstall
@@ -91,10 +84,11 @@ stdenv.mkDerivation rec {
runHook postInstall
'';
passthru.tests.version = testers.testVersion {
package = key;
command = "KeY --help";
};
doInstallCheck = true;
nativeInstallCheckInputs = [
versionCheckHook
];
versionCheckProgramArg = "--show-properties";
meta = {
description = "Java formal verification tool";

View File

@@ -1,60 +1,106 @@
diff --git a/build.gradle b/build.gradle
index d90fe4733f..26d1e3755d 100644
index 8399c7c8a9..162dbede9e 100644
--- a/build.gradle
+++ b/build.gradle
@@ -24,7 +24,6 @@ plugins {
id "com.diffplug.spotless" version "6.25.0"
@@ -14,9 +14,6 @@ plugins {
// Code formatting
alias(libs.plugins.spotless)
// EISOP Checker Framework
- id "org.checkerframework" version "0.6.43"
}
- // EISOP Checker Framework
- alias(libs.plugins.checkerframework)
-
// Plugin for publishing via the new Nexus API
alias(libs.plugins.maven.publish) apply false
@@ -61,7 +58,6 @@ subprojects {
// apply plugin: libs.plugins.license.report
// Configure this project for use inside IntelliJ:
@@ -56,7 +55,6 @@ subprojects {
apply plugin: "com.diffplug.spotless"
apply plugin: "checkstyle"
apply plugin: "pmd"
- apply plugin: "org.checkerframework"
apply plugin: "com.vanniktech.maven.publish"
//apply plugin: "maven-publish"
group = rootProject.group
version = rootProject.version
@@ -87,7 +85,6 @@ subprojects {
compileOnly "io.github.eisop:checker-qual:$eisop_version"
compileOnly "io.github.eisop:checker-util:$eisop_version"
testCompileOnly "io.github.eisop:checker-qual:$eisop_version"
- checkerFramework "io.github.eisop:checker:$eisop_version"
testImplementation("ch.qos.logback:logback-classic:1.5.7")
testImplementation 'org.junit.jupiter:junit-jupiter-api:5.11.0'
@@ -531,6 +528,7 @@ if (jacocoEnabled.toBoolean()) {
@Memoized
def getChangedFiles() {
+ return []
// Get the target and source branch
def anchor = "git merge-base HEAD origin/main".execute().getText()
@@ -89,8 +85,6 @@ subprojects {
compileOnly(libs.checkerframework.qual)
compileOnly(libs.checkerframework.util)
testCompileOnly(libs.checkerframework.qual)
- checkerFramework(libs.checkerframework.qual)
- checkerFramework(libs.checkerframework)
testImplementation(platform(libs.junit.bom))
testImplementation(libs.junit.jupiter.api)
diff --git a/key.core/build.gradle b/key.core/build.gradle
index 054104438c..8d13452edf 100644
index 76e116f84d..1e524cf8b6 100644
--- a/key.core/build.gradle
+++ b/key.core/build.gradle
@@ -196,7 +196,7 @@ task generateVersionFiles() {
// find names/SHAs for commits
static def gitRevParse(String args) {
try {
- return "git rev-parse $args".execute().text.trim()
+ return "@version@"
} catch (Exception e) {
return ""
}
@@ -164,8 +164,8 @@ tasks.register('generateVersionFiles') {
inputs.files "$project.rootDir/.git/HEAD"
outputs.files sha1, branch, versionf
- def gitRevision = gitRevParse('HEAD')
- def gitBranch = gitRevParse('--abbrev-ref HEAD')
+ def gitRevision = "unknown"
+ def gitBranch = "unknown"
doLast {
sha1.text = gitRevision
diff --git a/key.ncore.calculus/build.gradle b/key.ncore.calculus/build.gradle
index c2a26ef862..869ad03e19 100644
--- a/key.ncore.calculus/build.gradle
+++ b/key.ncore.calculus/build.gradle
@@ -9,19 +9,3 @@ dependencies {
api project(':key.ncore')
implementation(libs.jspecify)
}
-
-checkerFramework {
- if (System.getProperty("ENABLE_NULLNESS")) {
- checkers = [
- "org.checkerframework.checker.nullness.NullnessChecker",
- ]
- extraJavacArgs = [
- //"-AonlyDefs=^org\\.key_project\\.prover",
- "-Xmaxerrs", "10000",
- "-Astubs=$rootDir/key.util/src/main/checkerframework:permit-nullness-assertion-exception.astub",
- "-AstubNoWarnIfNotFound",
- "-Werror",
- "-Aversion",
- ]
- }
-}
\ No newline at end of file
diff --git a/key.ncore.compiler/build.gradle b/key.ncore.compiler/build.gradle
index a4014c8f4e..1b96b6645a 100644
--- a/key.ncore.compiler/build.gradle
+++ b/key.ncore.compiler/build.gradle
@@ -6,18 +6,3 @@ dependencies {
api project(':key.ncore.calculus')
implementation(libs.jspecify)
}
-
-checkerFramework {
- if (System.getProperty("ENABLE_NULLNESS")) {
- checkers = [
- "org.checkerframework.checker.nullness.NullnessChecker",
- ]
- extraJavacArgs = [
- "-Xmaxerrs", "10000",
- "-Astubs=$rootDir/key.util/src/main/checkerframework:permit-nullness-assertion-exception.astub",
- "-AstubNoWarnIfNotFound",
- "-Werror",
- "-Aversion",
- ]
- }
-}
diff --git a/key.ncore/build.gradle b/key.ncore/build.gradle
index 04eabab0a8..a99e8639c1 100644
index b89f926fd4..a96eeaa706 100644
--- a/key.ncore/build.gradle
+++ b/key.ncore/build.gradle
@@ -14,19 +14,3 @@ tasks.withType(Test) {
@@ -46,20 +46,3 @@ sourceSets.main.java.srcDirs(String.valueOf(projectDir) + '/build/generated-src/
tasks.withType(Test).configureEach {
enableAssertions = true
}
-
-
-checkerFramework {
- if(System.getProperty("ENABLE_NULLNESS")) {
@@ -72,13 +118,14 @@ index 04eabab0a8..a99e8639c1 100644
- }
-}
diff --git a/key.util/build.gradle b/key.util/build.gradle
index 382a103b60..7187dc0236 100644
index 70e86cef8c..4729baa9d1 100644
--- a/key.util/build.gradle
+++ b/key.util/build.gradle
@@ -4,18 +4,3 @@ dependencies {
implementation("org.jspecify:jspecify:1.0.0")
}
@@ -24,19 +24,3 @@ dependencies {
testFixturesCompileOnly(libs.checkerframework.qual)
}
-
-checkerFramework {
- if(System.getProperty("ENABLE_NULLNESS")) {
- checkers = [

View File

@@ -7,13 +7,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libuninameslist";
version = "20260107";
version = "20260918";
src = fetchFromGitHub {
owner = "fontforge";
repo = "libuninameslist";
rev = finalAttrs.version;
hash = "sha256-o+moQBFXIhnqvAc9F08kLRiXVS5pJEuUJwWl4Y/8AS4=";
hash = "sha256-QTrC+j12rf3S7boKrsKUc5qRavXbOoP8K93/+K8Wvag=";
};
nativeBuildInputs = [

View File

@@ -9,14 +9,14 @@
stdenvNoCC.mkDerivation {
pname = "mint-l-icons";
version = "1.8.2";
version = "1.8.3";
src = fetchFromGitHub {
owner = "linuxmint";
repo = "mint-l-icons";
# They don't really do tags, this is just a named commit.
rev = "5f5957bc87af839ffdcaa779d099b217bb6825a2";
hash = "sha256-9CwO0x9+hcUSZDviysn5EvH48oJuO6QhsfeNqWakm9M=";
rev = "ddb43425b35aaf15a8d5ba74059b5b72c2a383e2";
hash = "sha256-Vfhlor9RZpDc7zLs90hRreZco3uR/OmoH3QQvMg0kVk=";
};
propagatedBuildInputs = [

View File

@@ -9,13 +9,13 @@
stdenvNoCC.mkDerivation rec {
pname = "mint-y-icons";
version = "1.9.3";
version = "1.9.4";
src = fetchFromGitHub {
owner = "linuxmint";
repo = "mint-y-icons";
rev = version;
hash = "sha256-aDuM3IpnQdkdjNSV0U/wwn1pXVFbPKEeZhDxt9GPcFE=";
hash = "sha256-brgMdV6W7UufkBCMvjiQRUZNNLW6UZm+VmYfDwhXOxY=";
};
propagatedBuildInputs = [

View File

@@ -0,0 +1,38 @@
{
lib,
stdenv,
fetchFromGitHub,
cmake,
versionCheckHook,
nix-update-script,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "mithril";
version = "0.1.3";
__structuredAttrs = true;
strictDeps = true;
src = fetchFromGitHub {
owner = "nmatt0";
repo = "mithril";
tag = "v${finalAttrs.version}";
hash = "sha256-GsJFTsW34e1W4b+zBmy9XfY2y/eGdsg0YANZAd733i4=";
};
nativeBuildInputs = [ cmake ];
doInstallCheck = true;
nativeInstallCheckInputs = [ versionCheckHook ];
passthru.updateScript = nix-update-script { };
meta = {
description = "IoT firmware identification and extraction";
homepage = "https://github.com/nmatt0/mithril";
changelog = "https://github.com/nmatt0/mithril/releases/tag/${finalAttrs.src.tag}";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ felbinger ];
mainProgram = "mithril";
};
})

View File

@@ -0,0 +1,49 @@
{
lib,
stdenv,
fetchFromGitHub,
cmake,
zlib,
xz,
lz4,
zstd,
versionCheckHook,
nix-update-script,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "moria";
version = "0.1.0";
__structuredAttrs = true;
strictDeps = true;
src = fetchFromGitHub {
owner = "nmatt0";
repo = "moria";
tag = "v${finalAttrs.version}";
hash = "sha256-tzBJEUl2AbzZh4exjlhw7yv4JsgTj80DYngoRofJjgY=";
};
nativeBuildInputs = [ cmake ];
buildInputs = [
zlib
xz
lz4
zstd
];
doInstallCheck = true;
nativeInstallCheckInputs = [ versionCheckHook ];
passthru.updateScript = nix-update-script { };
meta = {
description = "IoT firmware identification and extraction";
homepage = "https://github.com/nmatt0/moria";
changelog = "https://github.com/nmatt0/moria/releases/tag/${finalAttrs.src.tag}";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ felbinger ];
mainProgram = "moria";
};
})

View File

@@ -78,7 +78,7 @@ let
in
buildGoModule (finalAttrs: {
pname = "netbird-${componentName}";
version = "0.78.2";
version = "0.79.0";
__structuredAttrs = true;
@@ -86,7 +86,7 @@ buildGoModule (finalAttrs: {
owner = "netbirdio";
repo = "netbird";
tag = "v${finalAttrs.version}";
hash = "sha256-VDYwuo7qMq01QrbV422yd/KAZhnqP9ymrqrgJbDqMGg=";
hash = "sha256-Bi83uh8VKvFGUY+AxP34VCXYxpZI1C/oOa6eHmKXpDw=";
};
overrideModAttrs = final: prev: {
@@ -100,7 +100,7 @@ buildGoModule (finalAttrs: {
};
proxyVendor = true;
vendorHash = "sha256-qbcc/j8tCTnUrX9jhxKFMudnNVKa4Xah+76aBOFS0AQ=";
vendorHash = "sha256-+JwuUz8msyoiPUTz8cH3vn9DrvLp6gaM2NqFuTOcRdg=";
nativeBuildInputs = [
installShellFiles

View File

@@ -18,11 +18,11 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "oils-for-unix";
version = "0.37.0";
version = "0.38.0";
src = fetchurl {
url = "https://oils.pub/download/oils-for-unix-${finalAttrs.version}.tar.gz";
hash = "sha256-9NQdIKBSPbz71LojH4Lt8lsI1JZdZbxx/LVmZtZ0MAA=";
hash = "sha256-ozRTcigZtV7lUr/X88K6uPGUDe9V1ci0avFs6VvfiAM=";
};
postPatch = ''

View File

@@ -15,11 +15,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "padthv1";
version = "1.4.3";
version = "1.5.0";
src = fetchurl {
url = "mirror://sourceforge/padthv1/padthv1-${finalAttrs.version}.tar.gz";
hash = "sha256-LtQ3TSnyJdi4Cb3C3jBLLd+BuK5XXMNEHZj7Cu9/3qw=";
hash = "sha256-23qiYiLQNWzzE0XKP/2uvlZbPtN1yV7x7q5O2ibYl2o=";
};
nativeBuildInputs = [

View File

@@ -0,0 +1,68 @@
{
lib,
cacert,
fetchFromGitHub,
nix-update-script,
rustPlatform,
versionCheckHook,
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "parlov";
version = "0.8.0";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "gnufood";
repo = "parlov";
tag = "v${finalAttrs.version}";
hash = "sha256-NExg4gOnYLNk34LBa5bFwxOAYIC2d86knoAlCqxdMrQ=";
};
cargoHash = "sha256-gNejVgmWb6whiyWU49scwE3zWS1dljBFz8c6UicUwY4=";
nativeInstallCheckInputs = [ versionCheckHook ];
preCheck = ''
export SSL_CERT_FILE=${cacert}/etc/ssl/certs/ca-bundle.crt
export SSL_CERT_DIR=${cacert}/etc/ssl/certs
export CLICOLOR=0
export TERM=dumb
export NO_COLOR=1
'';
doInstallCheck = true;
checkFlags = [
# Skip tests that require network access
"--skip=scan::tests::pipeline::run_plan_specs_returns_exchanges_on_empty_plan"
"--skip=scan::tests::verdict::first_threshold_crossed_by_stays_none_when_not_exhaustive"
"--skip=scan::tests::verdict::stop_decision_none_when_exhaustive"
# Snapshot is unstable due to terminal coloring differences
"--skip=snap_"
"--skip=snapshot_"
"--skip=snap_delete_405_vs_404_table"
"--skip=snap_head_204_vs_404_table"
"--skip=snap_patch_422_vs_404_table"
"--skip=snapshot_table_"
"--skip=emg_body_diff_only_table"
"--skip=emg_status_plus_body_table"
];
passthru.updateScript = nix-update-script { };
__darwinAllowLocalNetworking = true;
meta = {
description = "Tool to detect HTTP oracle vulnerabilities through differential probing of RFC-compliant servers";
homepage = "https://github.com/gnufood/parlov";
changelog = "https://github.com/gnufood/parlov/blob/${finalAttrs.src.rev}/CHANGELOG.md";
license = with lib.licenses; [
asl20
mit
];
maintainers = with lib.maintainers; [ fab ];
mainProgram = "parlov";
};
})

View File

@@ -12,12 +12,12 @@
stdenv.mkDerivation (finalAttrs: {
pname = "rpcbind";
version = "1.2.9";
version = "1.3.1";
src = fetchgit {
url = "git://git.linux-nfs.org/projects/steved/rpcbind.git";
rev = "refs/tags/rpcbind-${builtins.replaceStrings [ "." ] [ "_" ] finalAttrs.version}";
hash = "sha256-uiUGSCUkFTFl+hqzXgJEjl4WZCcMi+QxuAGmY0g+fs4=";
hash = "sha256-xHPVg/2u1GRy1s5nipKK2I5sbHRMF0Cxd+ZHMaLRxvU=";
};
patches = [

View File

@@ -0,0 +1,39 @@
{
lib,
buildGoModule,
fetchFromGitHub,
nix-update-script,
}:
buildGoModule (finalAttrs: {
pname = "sessionprobe";
version = "1.0.0";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "dub-flow";
repo = "sessionprobe";
tag = "v${finalAttrs.version}";
hash = "sha256-D31H/PnRtYqnBCIQOyuTstETAGNRDL79CCZFFW1D2jM=";
};
vendorHash = "sha256-3aE1uGOxMTbYTHOcgCuTi5JNPBVTgLeI+Gdt8yS50sg=";
ldflags = [
"-s"
"-X=main.AppVersion=${finalAttrs.version}"
];
passthru.updateScript = nix-update-script { };
__darwinAllowLocalNetworking = true;
meta = {
description = "Tool for evaluating user privileges in web applications";
homepage = "https://github.com/dub-flow/sessionprobe";
changelog = "https://github.com/dub-flow/sessionprobe/releases/tag/${finalAttrs.src.tag}";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ fab ];
mainProgram = "sessionprobe";
};
})

View File

@@ -6,16 +6,16 @@
}:
buildGoModule (finalAttrs: {
pname = "sftpgo-plugin-auth";
version = "1.0.16";
version = "1.0.17";
src = fetchFromGitHub {
owner = "sftpgo";
repo = "sftpgo-plugin-auth";
tag = "v${finalAttrs.version}";
hash = "sha256-IKCdWr+ZmuPJxRYdjS3FMNS8CT8oy7tqTSlEwqxyNqw=";
hash = "sha256-cVukrMpygPQKbQfRyIFi7Dp6gc9nKPvdo/xdDJEEe+A=";
};
vendorHash = "sha256-AZWwPwumSNwMUEixm+aarJZlUaT647haVM87qm6oE4U=";
vendorHash = "sha256-PVeeBo4lbzzoiI9AI6OnFmow/VgJUtS7qc58COuV36w=";
env.CGO_ENABLED = "0";

View File

@@ -19,16 +19,16 @@ let
in
buildNpmPackage rec {
pname = "teams-for-linux";
version = "2.18.1";
version = "2.20.0";
src = fetchFromGitHub {
owner = "IsmaelMartinez";
repo = "teams-for-linux";
tag = "v${version}";
hash = "sha256-dKTsilBu57Z8XcoyiviuOW/jfIqnbfiBZFl2hpvaiIc=";
hash = "sha256-KWvoms7O5rvfbeI13YvGIyIUZ8FAwN8XznUMYlHVA8E=";
};
npmDepsHash = "sha256-/1CPHy+gBVc79GYLAlfzSEOckM7UxyFblBQO9lZoMTw=";
npmDepsHash = "sha256-1wFoapw/bQ/+9QbT/ky+bKj/hwYh4dSiWvKCTBisgrQ=";
nativeBuildInputs = [
makeWrapper

View File

@@ -18,17 +18,17 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "uv";
version = "0.12.16";
version = "0.12.17";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "astral-sh";
repo = "uv";
tag = finalAttrs.version;
hash = "sha256-Q0lQ8wjqM2ZcLS+s6nitzjSk6XvGPaWgAgDVts130l8=";
hash = "sha256-e/AA9/Uou8c1usaVxGc/kzHSo5bzJOmupWOGk7L8+KI=";
};
cargoHash = "sha256-9yqbPs2eTUO+i1r06+eT4+OgN2opVGyOABjaL+fIUzk=";
cargoHash = "sha256-6AKm5l3snX1gmN5uAp0N9NVFd0nPBdtHz8WwZiFoYPU=";
buildInputs = [
rust-jemalloc-sys

View File

@@ -20,14 +20,14 @@
stdenv.mkDerivation {
pname = "xrgears";
version = "1.0.1-unstable-2026-01-20";
version = "1.0.1-unstable-2026-09-06";
src = fetchFromGitLab {
domain = "gitlab.freedesktop.org";
owner = "monado";
repo = "demos/xrgears";
rev = "034d3dbb17beb4e393f1524a8508fb353bafebea";
sha256 = "sha256-nbAwR4bFBSv2tYJgX3uH318uyRGfz9Qxsj+bAxagqIg=";
rev = "51ef6c779c8d3134d8df9eca1294779e61c8243f";
sha256 = "sha256-/j23NgqazHNKIJuRa05bycnvizifTUhth5XXI7HUNCw=";
};
nativeBuildInputs = [

View File

@@ -358,13 +358,13 @@
buildPythonPackage (finalAttrs: {
pname = "boto3-stubs";
version = "1.43.97";
version = "1.43.98";
pyproject = true;
src = fetchPypi {
pname = "boto3_stubs";
inherit (finalAttrs) version;
hash = "sha256-+6C+nq/36j7sZf7olaeMvjOnr+ZbedRyImsAvMRIt7w=";
hash = "sha256-Q7Oxg7VaLvF3gNpl/X+2ZFbLdnJxgaTt7N4QQFPAYVI=";
};
build-system = [ setuptools ];

View File

@@ -20,14 +20,14 @@
buildPythonPackage (finalAttrs: {
pname = "env-canada";
version = "0.19.2";
version = "0.20.3";
pyproject = true;
src = fetchFromGitHub {
owner = "michaeldavie";
repo = "env_canada";
tag = "v${finalAttrs.version}";
hash = "sha256-YsIqXhaqNXCj2iUBKhW19LDJTN9SsovX8Sh4AHwtBgo=";
hash = "sha256-c8EfYhlEeyCinsK+8TixCfIwTRD1CV5WyfiEbUJsFMg=";
};
build-system = [ setuptools ];

View File

@@ -8,14 +8,14 @@
buildPythonPackage (finalAttrs: {
pname = "iamdata";
version = "0.1.202609181";
version = "0.1.202609191";
pyproject = true;
src = fetchFromGitHub {
owner = "cloud-copilot";
repo = "iam-data-python";
tag = "v${finalAttrs.version}";
hash = "sha256-dVNJ/E9QZqIU7QU1qCa82kL0ZsFe7fPKrKR1viNmo70=";
hash = "sha256-jf0Y5FOwr1eGTiqgSyWo9VekoRVhL/VFR0VB54JmTMo=";
};
__darwinAllowLocalNetworking = true;

View File

@@ -103,8 +103,8 @@ in
"sha256-ReqQLuOIFaNShAbfNOMoo/Y+WadrrrY+jj/y/ftAqCk=";
mypy-boto3-appintegrations =
buildMypyBoto3Package "appintegrations" "1.43.87"
"sha256-wcejwfqmImH7RWgI4nCLdCYHkVLfAu331ZzSic4nR80=";
buildMypyBoto3Package "appintegrations" "1.43.98"
"sha256-ZkBFUgU5J1eVIz/m2baWBwoEc4b/Afnxm79ccFW3L6s=";
mypy-boto3-application-autoscaling =
buildMypyBoto3Package "application-autoscaling" "1.43.33"
@@ -335,8 +335,8 @@ in
"sha256-3JYcWKFk0dKJg/qn+EBvxeAO5xh5PXCU3dTEWDr1oXI=";
mypy-boto3-connect =
buildMypyBoto3Package "connect" "1.43.97"
"sha256-56zFmPmX5g+87mqd6VHHmMBiDyZPRCj3LWjWoPjd0hU=";
buildMypyBoto3Package "connect" "1.43.98"
"sha256-gI283S5VggOoIySj1+v55abhLygdnHFBxW4aJ37Vgus=";
mypy-boto3-connect-contact-lens =
buildMypyBoto3Package "connect-contact-lens" "1.43.79"
@@ -443,8 +443,8 @@ in
"sha256-dXNkOcMonYrBh4yzeubd+v3mW42s9XpmpfvgbtgoJgY=";
mypy-boto3-ec2 =
buildMypyBoto3Package "ec2" "1.43.97"
"sha256-8Z38sXkFUQRi8l2SxUvMh+mHSa0Eh6mYT6KgSdTyWGs=";
buildMypyBoto3Package "ec2" "1.43.98"
"sha256-NmDnuX37V2soiOmcAblB0bM9+dl180Zf/DMIbT0Nvaw=";
mypy-boto3-ec2-instance-connect =
buildMypyBoto3Package "ec2-instance-connect" "1.43.0"
@@ -571,8 +571,8 @@ in
"sha256-vMz4YKm78XMavlPUNiSVAYmAbyUBrJhUXbFrhxIvUJA=";
mypy-boto3-glue =
buildMypyBoto3Package "glue" "1.43.94"
"sha256-sqiuAhdQg1wAwNjrMXz6KgOWNZQ5OLQ80J73omFgLaM=";
buildMypyBoto3Package "glue" "1.43.98"
"sha256-NCo2cg1tdT9wrRkpQR6NwY4K8Vo1a6HYf6BEQ9yszmM=";
mypy-boto3-grafana =
buildMypyBoto3Package "grafana" "1.43.11"
"sha256-XJOSLyL1+uEweZ9zER7IhH3DFLaLtpJKvuRIn8Ri+P4=";
@@ -698,8 +698,8 @@ in
"sha256-VAswBdekr2GBDzQviuu5s6ixvA5R0IGMEYP2dpuxdJk=";
mypy-boto3-ivs-realtime =
buildMypyBoto3Package "ivs-realtime" "1.43.0"
"sha256-0rzVOt5tK99dXME4fBoww2DsvoHEIQ/KXzBxSx3ShXY=";
buildMypyBoto3Package "ivs-realtime" "1.43.98"
"sha256-DdC0VbvthDnBVi2b5uJZ68yLFPYZ1POvVTs68Mx875A=";
mypy-boto3-ivschat =
buildMypyBoto3Package "ivschat" "1.43.0"
@@ -1170,8 +1170,8 @@ in
"sha256-T+JIJpHxD7IzAwq8yxgq6zbVMj/btpbhKnylMyfFvvU=";
mypy-boto3-sagemaker =
buildMypyBoto3Package "sagemaker" "1.43.92"
"sha256-OatmaCJKUQoKsI8u63uN2tMNKt9XiE7httpZjQslewk=";
buildMypyBoto3Package "sagemaker" "1.43.98"
"sha256-cNIdQu8lp6Gzlx/691kT3uO78KvGYpbl4Up2Y3uAI3A=";
mypy-boto3-sagemaker-a2i-runtime =
buildMypyBoto3Package "sagemaker-a2i-runtime" "1.43.0"
@@ -1362,8 +1362,8 @@ in
"sha256-fc0e8DEx/b6M3kPB4Y07qqqMayg2BGSQ69gkuhcrl9Y=";
mypy-boto3-transcribe =
buildMypyBoto3Package "transcribe" "1.43.88"
"sha256-j0jjna9RrTHQRzwwJ8tR82161XXYRc2CJKWYzninfGA=";
buildMypyBoto3Package "transcribe" "1.43.98"
"sha256-tiBz8d9cXwrI+7rsE+MnQzyt3BaXJ86Sd8ysVsRruwE=";
mypy-boto3-transfer =
buildMypyBoto3Package "transfer" "1.43.95"

View File

@@ -11,12 +11,12 @@
buildPythonPackage (finalAttrs: {
pname = "publicsuffixlist";
version = "1.0.2.20260918";
version = "1.0.2.20260919";
pyproject = true;
src = fetchPypi {
inherit (finalAttrs) pname version;
hash = "sha256-FoUGqy7thKFZ1gu4OEgkSbRY0/b9Bztwf4EMnhzCcvs=";
hash = "sha256-2Tg+UQ40ZP3kR4udD5eiSRG2wr05eqFJyEqIU06Y4+s=";
};
postPatch = ''

View File

@@ -22,14 +22,14 @@
buildPythonPackage (finalAttrs: {
pname = "pyenphase";
version = "4.0.3";
version = "4.0.5";
pyproject = true;
src = fetchFromGitHub {
owner = "pyenphase";
repo = "pyenphase";
tag = "v${finalAttrs.version}";
hash = "sha256-1p/QaPK9sDymbG7gzJ+81TtzIT2jINLfMs3/1i12jVA=";
hash = "sha256-JsKB6sSfUhhMeF6j0MP+sbPmKeCz6c3wlm7TIL5Ls2I=";
};
pythonRelaxDeps = [ "tenacity" ];

View File

@@ -10,11 +10,11 @@
}:
mkKdeDerivation rec {
pname = "kirigami-addons";
version = "1.13.1";
version = "1.14.0";
src = fetchurl {
url = "mirror://kde/stable/kirigami-addons/kirigami-addons-${version}.tar.xz";
hash = "sha256-dgJvCr6MlIIIznWgKp7KxgxhisUojKVG4J2mS8SvcFA=";
hash = "sha256-SunvnPH8Vf71kyjSWnCyhXK29qeHOUw9KS9e03jxmEA=";
};
extraNativeBuildInputs = [ qttools ];

View File

@@ -7,11 +7,11 @@
}:
mkKdeDerivation rec {
pname = "pulseaudio-qt";
version = "1.8.1";
version = "1.9.0";
src = fetchurl {
url = "mirror://kde/stable/pulseaudio-qt/pulseaudio-qt-${version}.tar.xz";
hash = "sha256-eWGcVblICKp9MH+yNK05oQltCI8h+Aa+DniL55p2s8k=";
hash = "sha256-wqrOOsGpyMm5xXug/8maPTEHN8wATbBJGALgNTbifGk=";
};
extraNativeBuildInputs = [ pkg-config ];