the most recognized upstream for `fortify-headers` is
<git://git.2f30.org/fortify-headers> (see `meta.homepage`, e.g.),
but as per the previous source comment this upstream isn't accessible
over http.
<https://github.com/jvoisin/fortify-headers> is a reasonable
alternative: it's what [chimera linux][Chimera] sources, and
jvoisin is a regular committer to the `git.2f30.org` repo.
moreover, Alpine Linux is stuck at version 1.1, released in 2019.
moving away from Alpine (much as i appreciate their work),
allows us to take updates more timely.
cherry-pick Alpine's own patches, so that the `fortify-headers`
built before and after this patch is bit-for-bit identical.
Alpine's patches have been upstreamed, so they can go away with
a future package bump (see next patch).
Chimera: <183ea38c47/main/fortify-headers/template.py (L11)>
We are migrating packages that meet below requirements:
1. using `callPackage`
2. called path is a directory
3. overriding set is empty (`{ }`)
4. not containing path expressions other than relative path (to
makenixpkgs-vet happy)
5. not referenced by nix files outside of the directory, other
than`pkgs/top-level/all-packages.nix`
6. not referencing nix files outside of the directory
7. not referencing `default.nix` (since it's changed to `package.nix`)
8. `outPath` doesn't change after migration
The tool is here: https://github.com/Aleksanaa/by-name-migrate.