Commit Graph

23 Commits

Author SHA1 Message Date
Stefan Frijters
0e72b80587 nss-cacert: enable structuredAttrs 2026-08-12 20:37:29 +02:00
Stefan Frijters
107cb3287c nss-cacert: enable strictDeps 2026-08-12 20:37:25 +02:00
Martin Weinelt
9652e1332d cacert: 3.125 -> 3.126
https://github.com/mozilla/nss/blob/master/doc/rst/releases/nss_3_126.rst
2026-07-18 11:18:02 +02:00
Martin Weinelt
3e7b87d61c cacert: 3.123 -> 3.125 2026-06-16 00:37:52 +02:00
Martin Weinelt
b7996f9430 cacert: 3.121 -> 3.123 2026-04-17 00:53:45 +02:00
nixpkgs-ci[bot]
23ee7d594c Merge master into staging-next 2026-03-14 00:21:49 +00:00
Alexander Bantyev
2839911e81 various: add security-review team as a maintainer
Adds the @NixOS/security-review team as a maintainer to multiple
packages deemed to be important security-wise.

For the motivation of the package list, see:
https://github.com/NixOS/nixpkgs/issues/494349#issuecomment-4005099033
2026-03-05 15:19:44 +01:00
Martin Weinelt
b972c9e279 cacert: 3.119.1 -> 3.121
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_121.rst
2026-02-21 00:29:34 +01:00
Michael Daniels
cdb47d5b88 Merge branch 'staging-next' into staging 2026-02-17 19:55:41 -05:00
Alexander Bantyev
22ca96f3a9 various: add meta.identifier.cpeParts to a batch of packages
Co-Authored-By: Silvan Mosberger <silvan.mosberger@tweag.io>
2026-02-16 17:11:52 +01:00
Silvan Mosberger
0e7826fd7a cacert: Improve sourcing
Switch to fetching only certdata.txt directly from the upstream
repository (and a mirror), because:

- While it's possible to deduct that github/nss-dev is an NSS-project-owned
  mirror repository, it's not trivial:
  - Go to the homepage: https://firefox-source-docs.mozilla.org/security/nss/index.html
  - Navigate to the source, e.g.
    https://phabricator.services.mozilla.com/source/nss/
  - Check the readme.md, which mentions github.com/nss-dev/nss
- GitHub is a mirror of the Mercurial repository, and while I was able
  to confirm that the latest version does match, it leaves more room for
  a malicious actor:
  - It's unknown who owns the nss-dev GitHub organisation, there's no
    public members and no contact information
  - The mirroring automation from Mercurial to GitHub is not documented
  - Git hashes by necessity don't match Mercurial hashes, so it's not
    easy to verify that they match
- Previously the build and update script were more complicated and slow
  by depending on the entire source, when we really only need a single file.

Furthermore, update the meta.homepage to point to the actual page that
mentions the root certificates, because the old one pointed to a curl
page which we don't even use anymore (if we ever even did, Git history
is inconclusive)

The cacert build was verified to be unchanged
2026-01-27 21:54:34 +01:00
R. Ryantm
30ddbcaf2f cacert: 3.117 -> 3.119.1 2026-01-03 16:42:41 +00:00
Wolfgang Walther
46c0c0eae7 Merge branch 'staging-next' into staging 2025-12-10 18:42:31 +01:00
Ihar Hrachyshka
567e8dfd8e treewide: clean up 'meta = with' pattern
This commit was created by a combination of scripts and tools:
- an ast-grep script to prefix things in meta with `lib.`,
- a modified nixf-diagnose / nixf combination to remove unused `with
lib;`, and
- regular nixfmt.

Co-authored-by: Wolfgang Walther <walther@technowledgy.de>
2025-12-10 18:09:49 +01:00
R. Ryantm
9e6e5635fa cacert: 3.115 -> 3.117 2025-10-15 02:00:51 +00:00
Martin Weinelt
6cf981fd63 cacert: 3.114 -> 3.115
https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/Ztj7XiauJMM
2025-08-16 02:08:20 +02:00
Martin Weinelt
bd55481970 cacert: 3.113.1 -> 3.114
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_114.rst
2025-07-22 02:12:40 +02:00
Martin Weinelt
aba24327d4 cacert: 3.113 -> 3.113.1
https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/D77eIlZXbr0/m/eQshPDkZAgAJ
2025-07-04 12:30:32 +02:00
Martin Weinelt
ec049d732f cacert: 3.111 -> 3.113
https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_113.rst
2025-06-23 06:26:39 +02:00
Toma
82d049a698 cacert: avoid using unreadable inherited certificate bundle (#401942) 2025-05-15 17:07:31 +02:00
Tim Cuthbertson
d390013091 cacert: avoid using unreadable inherited certificate bundle 2025-05-15 10:32:56 +02:00
R. Ryantm
5e666d1260 cacert: 3.108 -> 3.111 2025-05-05 12:37:53 +00:00
jopejoe1
7d30c40939 treewide: migrate packages to pkgs/by-name, again 2025-03-25 17:00:45 +01:00