Switch to fetching only certdata.txt directly from the upstream
repository (and a mirror), because:
- While it's possible to deduct that github/nss-dev is an NSS-project-owned
mirror repository, it's not trivial:
- Go to the homepage: https://firefox-source-docs.mozilla.org/security/nss/index.html
- Navigate to the source, e.g.
https://phabricator.services.mozilla.com/source/nss/
- Check the readme.md, which mentions github.com/nss-dev/nss
- GitHub is a mirror of the Mercurial repository, and while I was able
to confirm that the latest version does match, it leaves more room for
a malicious actor:
- It's unknown who owns the nss-dev GitHub organisation, there's no
public members and no contact information
- The mirroring automation from Mercurial to GitHub is not documented
- Git hashes by necessity don't match Mercurial hashes, so it's not
easy to verify that they match
- Previously the build and update script were more complicated and slow
by depending on the entire source, when we really only need a single file.
Furthermore, update the meta.homepage to point to the actual page that
mentions the root certificates, because the old one pointed to a curl
page which we don't even use anymore (if we ever even did, Git history
is inconclusive)
The cacert build was verified to be unchanged
This commit was created by a combination of scripts and tools:
- an ast-grep script to prefix things in meta with `lib.`,
- a modified nixf-diagnose / nixf combination to remove unused `with
lib;`, and
- regular nixfmt.
Co-authored-by: Wolfgang Walther <walther@technowledgy.de>