943 Commits

Author SHA1 Message Date
dependabot[bot]
d90a8da39f .github: Bump actions/checkout from 6.0.2 to 6.0.3
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](de0fac2e45...df4cb1c069)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-05 11:22:54 +00:00
zowoq
10056dd40d linux: add stable staging-nixos workflow
stable counterpart to d28cc2a2f5
2026-05-28 09:42:28 +10:00
Martin Weinelt
1cf127e528 workflows: migrate from app-id to client-id
See https://github.com/actions/create-github-app-token/releases/tag/v3.1.0.
2026-05-26 03:06:17 +02:00
Wolfgang Walther
5439176950 workflows/periodic-merge: update haskell-updates PR's base branch
This gives us better UI in the PR by hiding the commits that are already
on the base branch (mostly staging) after the periodic merge. Without
this, the PR has 100s of commits listed after a few days.
2026-05-25 00:02:51 +02:00
Wolfgang Walther
fe5cea9c90 workflows/periodic-merge: allow testing in forks
Manually dispatching in your fork should still trigger the workflow to
test.
2026-05-24 19:00:02 +02:00
yaya
41a5348c15 .github: Add release-26.05 CI config 2026-05-24 14:51:41 +02:00
Michael Daniels
092416be16 github/workflows: build nixos manual on PRs targeting staging-nixos (#509875) 2026-05-17 21:15:21 +00:00
Michael Daniels
6acad97b9c ci/github-script: update npm versions (#520661) 2026-05-17 18:47:56 +00:00
Michael Daniels
8a89d7a286 ci/github-script: update npm versions 2026-05-17 14:41:57 -04:00
Michael Daniels
f572465c7a workflows/pull-request-target: don't try to use secrets in pull_request context on Dependabot PRs
Secrets can't be accessed on dependabot PRs (https://github.com/dependabot/dependabot-core/issues/3253#issuecomment-852541544), so don't try.

(This should be the only change needed, as all other uses of secrets seem to
be conditioned on pull_request not being the current event.)

Fixes (e.g.) https://github.com/NixOS/nixpkgs/actions/runs/25553044633/job/75065769199?pr=518033
2026-05-15 20:32:58 -04:00
Michael Daniels
21211019cf .github: Bump cachix/cachix-action from 1eb2ef646ac0255473d23a5907ad7b04ce94065c to 5f2d7c5294214f71b873db4b969586b980625e71 (#520405) 2026-05-15 23:21:22 +00:00
Michael Daniels
aa7cf0cd79 .github: Bump actions/create-github-app-token from 3.1.1 to 3.2.0 (#520404) 2026-05-15 22:21:01 +00:00
dependabot[bot]
40120a3150 .github: Bump korthout/backport-action from 4.5.1 to 4.5.2
Bumps [korthout/backport-action](https://github.com/korthout/backport-action) from 4.5.1 to 4.5.2.
- [Release notes](https://github.com/korthout/backport-action/releases)
- [Commits](bf97bcfb53...6606540695)

---
updated-dependencies:
- dependency-name: korthout/backport-action
  dependency-version: 4.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-15 11:25:52 +00:00
dependabot[bot]
5d15d396db .github: Bump cachix/cachix-action
Bumps [cachix/cachix-action](https://github.com/cachix/cachix-action) from 1eb2ef646ac0255473d23a5907ad7b04ce94065c to 5f2d7c5294214f71b873db4b969586b980625e71.
- [Release notes](https://github.com/cachix/cachix-action/releases)
- [Changelog](https://github.com/cachix/cachix-action/blob/master/RELEASE.md)
- [Commits](1eb2ef646a...5f2d7c5294)

---
updated-dependencies:
- dependency-name: cachix/cachix-action
  dependency-version: 5f2d7c5294214f71b873db4b969586b980625e71
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-15 11:25:48 +00:00
dependabot[bot]
8a91364b57 .github: Bump actions/create-github-app-token from 3.1.1 to 3.2.0
Bumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token) from 3.1.1 to 3.2.0.
- [Release notes](https://github.com/actions/create-github-app-token/releases)
- [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md)
- [Commits](1b10c78c78...bcd2ba4921)

---
updated-dependencies:
- dependency-name: actions/create-github-app-token
  dependency-version: 3.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-15 11:25:37 +00:00
yaya
d6dbfa193f workflows/periodic-merges: integrate with staging-26.05
For now this uses `master` as root before branch-off.
2026-05-11 10:49:35 +02:00
Michael Daniels
da5ad661ba .github: Bump actions/labeler from 6.0.1 to 6.1.0 (#518033) 2026-05-10 19:57:52 +00:00
Matt Sturgeon
b4772dcc67 workflows/backport: Label failed backports (#517744) 2026-05-10 10:05:07 +00:00
Michael Daniels
68c93c8ef2 .github: Bump korthout/backport-action from 4.5.0 to 4.5.1 (#518034) 2026-05-08 18:19:37 +00:00
dependabot[bot]
04e886c586 .github: Bump korthout/backport-action from 4.5.0 to 4.5.1
Bumps [korthout/backport-action](https://github.com/korthout/backport-action) from 4.5.0 to 4.5.1.
- [Release notes](https://github.com/korthout/backport-action/releases)
- [Commits](7c3f6cd584...bf97bcfb53)

---
updated-dependencies:
- dependency-name: korthout/backport-action
  dependency-version: 4.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 11:27:34 +00:00
dependabot[bot]
79a640a7f1 .github: Bump actions/labeler from 6.0.1 to 6.1.0
Bumps [actions/labeler](https://github.com/actions/labeler) from 6.0.1 to 6.1.0.
- [Release notes](https://github.com/actions/labeler/releases)
- [Commits](634933edcd...f27b608878)

---
updated-dependencies:
- dependency-name: actions/labeler
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 11:27:27 +00:00
dependabot[bot]
0b995b605e .github: Bump cachix/install-nix-action from 31.10.5 to 31.10.6
Bumps [cachix/install-nix-action](https://github.com/cachix/install-nix-action) from 31.10.5 to 31.10.6.
- [Release notes](https://github.com/cachix/install-nix-action/releases)
- [Changelog](https://github.com/cachix/install-nix-action/blob/master/RELEASE.md)
- [Commits](ab739621df...8aa03977d8)

---
updated-dependencies:
- dependency-name: cachix/install-nix-action
  dependency-version: 31.10.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 11:27:24 +00:00
Samuel Dionne-Riel
afb1bec526 workflows/backport: Label failed backports
The intent behind this new label is to allow filtering on the label,
which can then allow Nixpkgs contributors to *act* on such failures.

The label **must** be removed *only* when a PR was then successfully
made, or the change has been verified to not need a backport.

Removing the label is intended to make the list of PRs with the label
actionable.

The following search query could be used to ensure no security changes
that were marked for being backported are left behind:

 - https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+label%3A%221.severity%3A+security%22+label%3A%228.has%3A+failed+backport%22+

(Obviously not right now. The label does not exist and isn't used.)
2026-05-07 12:05:25 -04:00
Michael Daniels
1c3e149546 Reapply {ci,workflows}: allow multiple blocking reviews"
A couple of bugfixes, but the problem was that the apps weren't installed.
2026-05-03 18:17:03 -04:00
Michael Daniels
cd2e5a371b Revert "{ci,workflows}: allow multiple blocking reviews" 2026-05-03 13:21:39 -04:00
Michael Daniels
636fc13366 {ci,workflows}: allow multiple blocking reviews 2026-05-02 18:09:26 -04:00
dependabot[bot]
e745785f80 .github: Bump korthout/backport-action from 4.4.0 to 4.5.0
Bumps [korthout/backport-action](https://github.com/korthout/backport-action) from 4.4.0 to 4.5.0.
- [Release notes](https://github.com/korthout/backport-action/releases)
- [Commits](ad30f01dbe...7c3f6cd584)

---
updated-dependencies:
- dependency-name: korthout/backport-action
  dependency-version: 4.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-01 13:06:17 +00:00
Michael Daniels
f8b81cd1c9 .github: Bump cachix/install-nix-action from 31.10.4 to 31.10.5 (#513059) 2026-04-25 00:17:53 +00:00
dependabot[bot]
9c623775f2 .github: Bump korthout/backport-action from 4.3.0 to 4.4.0
Bumps [korthout/backport-action](https://github.com/korthout/backport-action) from 4.3.0 to 4.4.0.
- [Release notes](https://github.com/korthout/backport-action/releases)
- [Commits](3c06f323a5...ad30f01dbe)

---
updated-dependencies:
- dependency-name: korthout/backport-action
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-24 11:23:19 +00:00
dependabot[bot]
416db884b3 .github: Bump cachix/install-nix-action from 31.10.4 to 31.10.5
Bumps [cachix/install-nix-action](https://github.com/cachix/install-nix-action) from 31.10.4 to 31.10.5.
- [Release notes](https://github.com/cachix/install-nix-action/releases)
- [Changelog](https://github.com/cachix/install-nix-action/blob/master/RELEASE.md)
- [Commits](616559265b...ab739621df)

---
updated-dependencies:
- dependency-name: cachix/install-nix-action
  dependency-version: 31.10.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-24 11:23:13 +00:00
Michael Schneider
da6b84dbdc github/workflows: build nixos manual on PRs targeting staging-nixos 2026-04-19 10:11:45 +01:00
Michael Daniels
94779b2284 .github: Bump actions/create-github-app-token from 3.0.0 to 3.1.1 (#510858) 2026-04-17 13:33:17 +00:00
Michael Daniels
50bf6747c1 .github: Bump actions/upload-artifact from 7.0.0 to 7.0.1 (#510857) 2026-04-17 13:10:09 +00:00
Michael Daniels
fa4b73ca97 .github: Bump actions/github-script from 8.0.0 to 9.0.0 (#510859) 2026-04-17 12:47:33 +00:00
dependabot[bot]
c39cb78c7a .github: Bump actions/github-script from 8.0.0 to 9.0.0
Bumps [actions/github-script](https://github.com/actions/github-script) from 8.0.0 to 9.0.0.
- [Release notes](https://github.com/actions/github-script/releases)
- [Commits](https://github.com/actions/github-script/compare/v8...3a2844b7e9c422d3c10d287c895573f7108da1b3)

---
updated-dependencies:
- dependency-name: actions/github-script
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-17 11:23:31 +00:00
dependabot[bot]
a641fbe953 .github: Bump actions/create-github-app-token from 3.0.0 to 3.1.1
Bumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token) from 3.0.0 to 3.1.1.
- [Release notes](https://github.com/actions/create-github-app-token/releases)
- [Commits](f8d387b68d...1b10c78c78)

---
updated-dependencies:
- dependency-name: actions/create-github-app-token
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-17 11:23:22 +00:00
dependabot[bot]
a0eec11bf7 .github: Bump actions/upload-artifact from 7.0.0 to 7.0.1
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](bbbca2ddaa...043fb46d1a)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-17 11:23:14 +00:00
dependabot[bot]
3a60da8896 .github: Bump peter-evans/create-pull-request from 8.1.0 to 8.1.1
Bumps [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) from 8.1.0 to 8.1.1.
- [Release notes](https://github.com/peter-evans/create-pull-request/releases)
- [Commits](c0f553fe54...5f6978faf0)

---
updated-dependencies:
- dependency-name: peter-evans/create-pull-request
  dependency-version: 8.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-17 11:23:10 +00:00
Michael Daniels
3b14bf26b5 ci/github-script/manual-file-edits: init (#509418) 2026-04-17 01:33:15 +00:00
Kamil Monicz
8926c73f50 ci/eval/compare: Expose attrdiff by kernel and platform 2026-04-13 10:53:48 +00:00
Michael Daniels
bd7e8b992b ci/github-script/manual-file-edits: init
Blocks manual edits to github-teams.json
2026-04-12 19:57:37 -04:00
Michael Daniels
e209b3a529 .github: Bump actions/github-script from 8.0.0 to 9.0.0 (#508580) 2026-04-10 14:48:07 +00:00
dependabot[bot]
2b2d5e95d4 .github: Bump cachix/install-nix-action from 31.10.3 to 31.10.4
Bumps [cachix/install-nix-action](https://github.com/cachix/install-nix-action) from 31.10.3 to 31.10.4.
- [Release notes](https://github.com/cachix/install-nix-action/releases)
- [Changelog](https://github.com/cachix/install-nix-action/blob/master/RELEASE.md)
- [Commits](96951a368b...616559265b)

---
updated-dependencies:
- dependency-name: cachix/install-nix-action
  dependency-version: 31.10.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-10 11:23:15 +00:00
dependabot[bot]
b7e66be21f .github: Bump actions/github-script from 8.0.0 to 9.0.0
Bumps [actions/github-script](https://github.com/actions/github-script) from 8.0.0 to 9.0.0.
- [Release notes](https://github.com/actions/github-script/releases)
- [Commits](ed597411d8...3a2844b7e9)

---
updated-dependencies:
- dependency-name: actions/github-script
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-10 11:23:10 +00:00
Michael Daniels
47e8e428bf workflows/periodic-merge: replace commenting action with gh cli
Per zizmor's [`superfluous-actions`](https://docs.zizmor.sh/audits/#superfluous-actions)
rule, which is not yet in the pinned version.
2026-03-30 21:12:09 -04:00
Michael Daniels
69a0ec0821 workflows/test: run when updating pinned.json 2026-03-29 15:15:19 -04:00
Michael Daniels
5acbc4d2c2 Revert "ci/pinned: update" 2026-03-29 13:45:45 -04:00
Michael Daniels
65bd8ca1c9 workflows/test: run when updating pinned.json 2026-03-29 12:40:28 -04:00
Michael Daniels
ff444b86a6 workflows/eval: increase timeout
lixPackageSets.lix_2_93.lix seems to need a bit longer on x86_64-linux.
2026-03-28 18:12:40 -04:00
Philip Taron
fc187fc912 .github: Bump korthout/backport-action from 4.2.0 to 4.3.0 (#504024) 2026-03-27 19:58:18 +00:00