Compare commits

..

600 Commits

Author SHA1 Message Date
Michael Daniels
61b48aa20d python3Packages.typer: 0.25.1 -> 0.27.1 (#556212)
Diff: https://github.com/fastapi/typer/compare/0.25.1...0.27.1

Changelog: https://github.com/tiangolo/typer/releases/tag/0.27.1
2026-08-25 21:49:47 -04:00
Fabian Affolter
b272417adb fixup! python3Packages.sounddevice: 0.5.5 -> 0.5.6 2026-08-26 00:25:53 +02:00
Fabian Affolter
e32c7f646b python3Packages.narwhals: 2.23.0 -> 2.25.0
Changelog: https://github.com/narwhals-dev/narwhals/releases/tag/v2.25.0
2026-08-26 00:18:39 +02:00
Fabian Affolter
5ce51871f1 fixup! python3Packages.netmiko: 4.6.0 -> 4.7.0 2026-08-26 00:18:39 +02:00
Michael Daniels
4c8b3c949a fixup! python3Packages.scipy: relax pybind11 2026-08-25 18:17:40 -04:00
Michael Daniels
e3d61b4a30 fixup! python3Packages.jsonpickle: 4.1.1 -> 4.1.2 2026-08-25 18:17:16 -04:00
Michael Daniels
e1574ff116 fixup! python3Packages.jaraco-text: 4.0.0 -> 4.3.0 2026-08-25 18:16:49 -04:00
Michael Daniels
93be76f22e fixup! python3Packages.geoip2: 5.2.0 -> 5.3.0 2026-08-25 18:16:12 -04:00
Michael Daniels
fb55523cc9 fixup! python3Packages.agentic-threat-hunting-framework: 0.18.0 -> 0.19.0 2026-08-25 18:12:30 -04:00
Michael Daniels
499b069560 fixup! python3Packages.agent-client-protocol: 0.12.0 -> 0.12.1 2026-08-25 18:11:55 -04:00
Michael Daniels
5ce79908e4 fixup! python3Packages.agate: 1.14.1 -> 1.14.2 2026-08-25 18:11:25 -04:00
Michael Daniels
324d00771d fixup! python3Packages.affine-gaps: 0.2.4 -> 0.2.5 2026-08-25 18:10:47 -04:00
Michael Daniels
ba0d9ac39e fixup! python3Packages.adlfs: 2026.5.0 -> 2026.8.0 2026-08-25 18:10:16 -04:00
Michael Daniels
b195440c27 fixup! python3Packages.adb-enhanced: 2.8.0 -> 2.11.0 2026-08-25 18:09:04 -04:00
Fabian Affolter
d9fb8767ea fixup! python3Packages.kserve-storage: 0.16.0 -> 0.20.0 2026-08-25 23:13:50 +02:00
Fabian Affolter
ec24eed6be fixup! python3Packages.krb5: 0.9.0 -> 0.10.0 2026-08-25 22:59:09 +02:00
Fabian Affolter
368b4e3e8f python3Packages.os-service-types: fix build
- modernize
2026-08-25 22:52:46 +02:00
Fabian Affolter
f41f9e40ec fixup! python3Packages.screed: 1.1.3 -> 1.2.0 2026-08-25 22:44:09 +02:00
Fabian Affolter
d7799a5777 fixup! python3Packages.qcelemental: 0.50.4 -> 0.51.0 2026-08-25 22:33:01 +02:00
Fabian Affolter
cacfd88b36 fixup! python3Packages.repoze-lru: 0.7 -> 0.8 2026-08-25 22:22:28 +02:00
Fabian Affolter
0b271e701f python3Packages.pylint-plugin-utils: modernize 2026-08-25 22:04:33 +02:00
Fabian Affolter
9626bfd0b3 python3Packages.pylint-celery: modernize 2026-08-25 22:01:49 +02:00
Fabian Affolter
ed753aa380 python3Packages.pylint: 4.0.6-unstable-2026-07-14 -> 4.0.7 2026-08-25 21:56:18 +02:00
Fabian Affolter
a22b968cde python3Packages.lxml-html-clean: migrate to finalAttrs 2026-08-25 21:51:05 +02:00
Fabian Affolter
37a1386ae4 fixup! python3Packages.accelerate: 1.13.0 -> 1.14.0 2026-08-25 20:11:49 +02:00
Fabian Affolter
0bea3bc3bb fixup! python3Packages.ansitable: 0.11.4 -> 0.11.7 2026-08-25 19:42:42 +02:00
Fabian Affolter
b76a2e5d8a fixup! python3Packages.julius: 0.2.7 -> 0.2.8 2026-08-25 19:11:31 +02:00
Fabian Affolter
e662b812c2 fixup! python3Packages.tika: 3.1.0 -> 3.3.2 2026-08-25 19:07:44 +02:00
Fabian Affolter
26888d68cf python3Packages.oslo-config: migrate to finalAttrs 2026-08-25 18:37:44 +02:00
Fabian Affolter
f48b39f6e2 python3Packages.oslo-utils: migrate to finalAttrs 2026-08-25 18:36:20 +02:00
Fabian Affolter
e2e3dfbe8b python3Packages.oslo-utils: add cryptography 2026-08-25 18:35:20 +02:00
Fabian Affolter
bb8f863ed5 python3Packages.protobuf-py-ext: 0.1.1 -> 0.3.0 2026-08-25 18:08:26 +02:00
Fabian Affolter
4543a1076a python3Packages.uv-build: 0.11.28 -> 0.12.5
Diff: https://github.com/astral-sh/uv/compare/0.11.28...0.12.5

Changelog: https://github.com/astral-sh/uv/blob/0.12.5/CHANGELOG.md
2026-08-25 18:07:14 +02:00
Fabian Affolter
1411e5f2e4 python3Packages.jupyter-server: disable failing test 2026-08-25 17:30:23 +02:00
Fabian Affolter
698e7f1bf8 python3Packages.google-api-python-client: 2.192.0 -> 2.199.0
Diff: https://github.com/googleapis/google-api-python-client/compare/v2.192.0...v2.199.0

Changelog: https://github.com/googleapis/google-api-python-client/releases/tag/v2.199.0
2026-08-25 17:17:53 +02:00
Fabian Affolter
6930f049f7 python3Packages.jupyterlab-widgets: add missing build component 2026-08-25 17:01:53 +02:00
Fabian Affolter
14979ee144 python3Packages.copier: fix makeWrapperArgs 2026-08-25 16:59:01 +02:00
Fabian Affolter
944f2aedef fixup! python3Packages.aioresponses: 0.7.8 -> 0.7.9 2026-08-25 16:53:53 +02:00
Fabian Affolter
287e40969e fixup! python3Packages.types-toml: 0.10.8.20240310 -> 0.10.8.20260518 2026-08-25 16:46:58 +02:00
Fabian Affolter
78606619c9 fixup! python3Packages.prov: 2.1.1 -> 2.5.3 2026-08-25 15:46:37 +02:00
Fabian Affolter
e61bbe73d6 fixup! python3Packages.geoip2: 5.2.0 -> 5.3.0 2026-08-25 15:35:47 +02:00
Fabian Affolter
b60d32eaa0 fixup! python3Packages.ci-info: 0.3.0 -> 0.4.0 2026-08-25 15:32:24 +02:00
Fabian Affolter
52adf233e7 fixup! python3Packages.jsonpickle: 4.1.1 -> 4.1.2 2026-08-25 15:27:25 +02:00
Fabian Affolter
3545da3e6f fixup! python3Packages.getjump: 2.10.0 -> 2.10.2 2026-08-25 15:22:48 +02:00
Fabian Affolter
5a385de6e6 fixup! python3Packages.jaraco-text: 4.0.0 -> 4.3.0 2026-08-25 15:21:04 +02:00
Fabian Affolter
3264dc441f python3Packages.typer: disabled failing tests 2026-08-25 15:16:07 +02:00
Fabian Affolter
26799bffc4 fixup! python3Packages.hyperopt: 0.2.7 -> 0.3.0 2026-08-25 15:05:13 +02:00
Fabian Affolter
f40b43c757 python3Packages.scipy: relax pybind11 2026-08-25 14:37:22 +02:00
Fabian Affolter
f2b8b10dd2 fixup! python3Packages.ledgerblue: 0.1.55 -> 0.1.58 2026-08-25 14:14:24 +02:00
Fabian Affolter
eea26947e0 python3Packages.ipykernel: modernize 2026-08-25 13:31:57 +02:00
Fabian Affolter
9124c445f9 fixup! python3Packages.ipykernel: 7.1.0 -> 7.3.0 2026-08-25 13:30:34 +02:00
Fabian Affolter
dc303a6911 python3Packages.nest-asyncio2: init at 1.7.2
Patch asyncio to allow nested event loops

https://github.com/Chaoses-Ib/nest-asyncio2
2026-08-25 13:27:00 +02:00
Fabian Affolter
5b0714066b python3Packages.nest-asyncio: migrate to finalAttrs 2026-08-25 13:14:44 +02:00
Fabian Affolter
1c0485361e python3Packages.jupyter-client: migrate to finalAttrs 2026-08-25 13:09:44 +02:00
Fabian Affolter
190f48674f fixup! python3Packages.jupyter-client: 8.8.0 -> 8.9.1 2026-08-25 13:07:57 +02:00
Fabian Affolter
dff4bac425 fixup! python3Packages.cssselect: 1.3.0 -> 1.5.0 2026-08-25 11:14:00 +02:00
Fabian Affolter
3647038b49 fixup! python3Packages.lingua: 4.15.0 -> 4.16.2 2026-08-25 11:00:12 +02:00
Fabian Affolter
266771687d fixup! python3Packages.webencodings: 0.5.1 -> 0.6.1 2026-08-25 10:11:56 +02:00
Fabian Affolter
51c34c5cb0 Revert "python3Packages.hatchling: 1.31.0 -> 1.32.0"
This reverts commit eebc652bbc.
2026-08-25 10:04:21 +02:00
Fabian Affolter
3f88eca4ef fixup! python3Packages.uritools: 6.0.2 -> 6.1.3 2026-08-25 10:01:01 +02:00
Fabian Affolter
cf6a587939 python3Packages.pathspec: modernize 2026-08-25 09:45:18 +02:00
Fabian Affolter
aa98290bd5 python3Packages.editables: migrate to fetchFromGitHub
Allows to run the tests if needed
2026-08-25 09:40:02 +02:00
Fabian Affolter
9db3a0f536 python3Packages.vcs-versioning: 1.1.1 -> 2.3.1
Diff: https://github.com/pypa/setuptools-scm/compare/vcs-versioning-v1.1.1...vcs-versioning-v2.3.1

Changelog: https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.3.1
2026-08-25 09:19:35 +02:00
Fabian Affolter
84e5bb992b fixup! python3Packages.imagesize: 2.0.0 -> 2.0.1 2026-08-25 09:16:40 +02:00
Fabian Affolter
5f7017d408 fixup! python3Packages.boto3: fix build 2026-08-25 08:56:49 +02:00
Fabian Affolter
ab4633cdb5 python3Packages.zodbpickle: 4.4 -> 4.5
https://github.com/zopefoundation/zodbpickle/blob/4.5/CHANGES.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:07 +02:00
Fabian Affolter
0b8d1e228b python3Packages.zeroc-ice: 3.8.0.post1 -> 3.8.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:06 +02:00
Fabian Affolter
791ccd6a86 python3Packages.xstatic-jquery-ui: 1.13.0.1 -> 1.13.0.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:06 +02:00
Fabian Affolter
d9576d7a6f python3Packages.xstatic-jquery-file-upload: 10.31.0.1 -> 10.32.0.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:06 +02:00
Fabian Affolter
86fc9e9ea6 python3Packages.xstatic-jquery: 3.5.1.1 -> 3.7.1.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:06 +02:00
Fabian Affolter
821eced83d python3Packages.xstatic-font-awesome: 6.2.1.1 -> 6.2.1.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:06 +02:00
Fabian Affolter
25254b4718 python3Packages.wsme: 0.12.1 -> 0.13.0
https://pythonhosted.org/WSME/changes.html

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:05 +02:00
Fabian Affolter
9c6107fafe python3Packages.widgetsnbextension: 4.0.15 -> 4.0.16
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:05 +02:00
Fabian Affolter
ec5de6e3d8 python3Packages.webencodings: 0.5.1 -> 0.6.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:05 +02:00
Fabian Affolter
8545db5000 python3Packages.wcmatch: 10.1 -> 10.2.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:05 +02:00
Fabian Affolter
4bd2c14901 python3Packages.vsure: 2.10.0 -> 2.10.1
https://github.com/persandstrom/python-verisure#version-history

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:05 +02:00
Fabian Affolter
692674689b python3Packages.vowpalwabbit: 9.10.0 -> 9.11.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:04 +02:00
Fabian Affolter
c88cc0c63a python3Packages.uritools: 6.0.2 -> 6.1.3
https://github.com/tkem/uritools/blob/v6.1.3/CHANGELOG.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:04 +02:00
Fabian Affolter
6da65ad9af python3Packages.unsloth-zoo: 2026.4.7 -> 2026.8.13
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:04 +02:00
Fabian Affolter
caf3208951 python3Packages.unsloth: 2026.4.5 -> 2026.8.19
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:04 +02:00
Fabian Affolter
3ad2416d6e python3Packages.universal-pathlib: 0.3.8 -> 0.3.10
https://github.com/fsspec/universal_pathlib/releases/tag/v0.3.10

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:04 +02:00
Fabian Affolter
925aab1556 python3Packages.unearth: 0.18.2 -> 0.18.3
https://github.com/frostming/unearth/releases/tag/0.18.3

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:03 +02:00
Fabian Affolter
8982190615 python3Packages.types-toml: 0.10.8.20240310 -> 0.10.8.20260518
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:03 +02:00
Fabian Affolter
f0aabcfb11 python3Packages.tskit: 1.0.0 -> 1.0.3
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:03 +02:00
Fabian Affolter
1f09b63abd python3Packages.trytond: 7.8.3 -> 7.8.15
https://foss.heptapod.net/tryton/tryton/-/blob/trytond-7.8.15/trytond/CHANGELOG?ref_type=tags

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:03 +02:00
Fabian Affolter
f892aa56fe python3Packages.trezor-agent: 0.12.0 -> 0.13.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:03 +02:00
Fabian Affolter
2d54c62f24 python3Packages.tpm2-pytss: 3.0.0rc1 -> 3.0.0
https://github.com/tpm2-software/tpm2-pytss/blob/3.0.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:02 +02:00
Fabian Affolter
1469eabcde python3Packages.tomlrt: 2.2.1 -> 2.2.5
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:02 +02:00
Fabian Affolter
15cacb1fae python3Packages.timg: 1.1.6 -> 1.2.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:02 +02:00
Fabian Affolter
e4dc456594 python3Packages.tika: 3.1.0 -> 3.3.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:02 +02:00
Fabian Affolter
c067eaaa9b python3Packages.tifffile: 2026.1.14 -> 2026.8.23
https://github.com/cgohlke/tifffile/blob/v2026.8.23/CHANGES.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:02 +02:00
Fabian Affolter
5718283335 python3Packages.thrift: 0.22.0 -> 0.24.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:01 +02:00
Fabian Affolter
c0ed90edb4 python3Packages.textparser: 0.24.0 -> 0.26.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:01 +02:00
Fabian Affolter
2b08ab0361 python3Packages.text2digits: 0.1.0 -> 0.1.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:01 +02:00
Fabian Affolter
f01f9be291 python3Packages.tempest: 46.2.0 -> 46.3.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:01 +02:00
Fabian Affolter
3be7fd074e python3Packages.tablib: 3.9.0 -> 3.10.0
https://github.com/jazzband/tablib/raw/v3.10.0/HISTORY.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:01 +02:00
Fabian Affolter
504c80164f python3Packages.tableauserverclient: 0.38 -> 0.41
https://github.com/tableau/server-client-python/releases/tag/v0.41

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:00 +02:00
Fabian Affolter
a4a9a62690 python3Packages.swift: 2.37.1 -> 2.38.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:00 +02:00
Fabian Affolter
863df2caa7 python3Packages.svglib: 1.5.1 -> 1.6.0
https://github.com/deeplook/svglib/blob/v1.6.0/CHANGELOG.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:00 +02:00
Fabian Affolter
5dd1b9161b python3Packages.summarytools: 0.3.0 -> 0.4.0
https://github.com/6chaoran/jupyter-summarytools/releases/tag/v0.4.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:00 +02:00
Fabian Affolter
55d525b34d python3Packages.striprtf: 0.0.32 -> 0.0.33
https://github.com/joshy/striprtf/blob/v0.0.33/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:00 +02:00
Fabian Affolter
55b8e342d7 python3Packages.stripe: 15.5.0 -> 15.5.1
https://github.com/stripe/stripe-python/blob/v15.5.1/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:25:00 +02:00
Fabian Affolter
c61a66652f python3Packages.streamlit: 1.61.1 -> 1.62.0
https://github.com/streamlit/streamlit/releases/tag/1.62.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:59 +02:00
Fabian Affolter
d3edbaeb90 python3Packages.streamcontroller-streamdeck: 0.2.0 -> 0.2.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:59 +02:00
Fabian Affolter
7f57362882 python3Packages.stevedore: 5.9.0 -> 5.9.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:59 +02:00
Fabian Affolter
d9598bee2f python3Packages.stestr: 4.2.0 -> 4.2.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:59 +02:00
Fabian Affolter
c050e495b9 python3Packages.stackit-core: 0.2.0 -> 0.3.0
https://github.com/stackitcloud/stackit-sdk-python/releases/tag/core/v0.3.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:59 +02:00
Fabian Affolter
2f332e5484 python3Packages.sqlparse: 0.5.5 -> 0.6.0
https://github.com/andialbrecht/sqlparse/blob/0.6.0/CHANGELOG

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:58 +02:00
Fabian Affolter
942423db98 python3Packages.spyder: 6.1.5 -> 6.1.6
https://github.com/spyder-ide/spyder/blob/v6.1.6/changelogs/Spyder-6.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:58 +02:00
Fabian Affolter
9e53c77b61 python3Packages.spsdk-pyocd: 0.3.4 -> 0.3.10
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:58 +02:00
Fabian Affolter
19d1af29aa python3Packages.spsdk-mcu-link: 0.6.6 -> 0.6.14
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:58 +02:00
Fabian Affolter
1b2a108956 python3Packages.spotapi: 1.2.7 -> 1.2.8
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:58 +02:00
Fabian Affolter
2c77c60443 python3Packages.sounddevice: 0.5.5 -> 0.5.6
https://github.com/spatialaudio/python-sounddevice/releases/tag/0.5.6

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:57 +02:00
Fabian Affolter
b55c0e5856 python3Packages.snowflake-core: 1.12.1 -> 1.13.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:57 +02:00
Fabian Affolter
859d1bf0d5 python3Packages.smg-grpc-servicer: 0.5.5 -> 0.8.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:57 +02:00
Fabian Affolter
f8f90eee14 python3Packages.smg-grpc-proto: 0.4.10 -> 0.4.14
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:57 +02:00
Fabian Affolter
e4c2e37eb7 python3Packages.slh-dsa: 0.2.0 -> 0.2.5
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:57 +02:00
Fabian Affolter
49d5798f40 python3Packages.sip: 6.15.1 -> 6.16.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:56 +02:00
Fabian Affolter
7516eee35a python3Packages.simpy: 4.1.1 -> 4.1.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:56 +02:00
Fabian Affolter
ba4f118c5e python3Packages.show-in-file-manager: 1.1.5 -> 1.1.6
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:56 +02:00
Fabian Affolter
36f1637d2b python3Packages.sgp4: 2.26 -> 2.27
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:56 +02:00
Fabian Affolter
ea48ece60c python3Packages.setuptools-scm: 10.0.5 -> 10.2.1
https://github.com/pypa/setuptools_scm/blob/10.2.1/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:56 +02:00
Fabian Affolter
24c54a9513 python3Packages.screed: 1.1.3 -> 1.2.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:55 +02:00
Fabian Affolter
6f8000896b python3Packages.scikit-learn: 1.8.0 -> 1.9.0
https://scikit-learn.org/stable/whats_new/v1.9.html#version-1-9-0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:55 +02:00
Fabian Affolter
f448359a18 python3Packages.sasdata: 0.11.0 -> 0.12.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:55 +02:00
Fabian Affolter
e924a92468 python3Packages.safety-schemas: 0.0.19 -> 0.0.20
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:55 +02:00
Fabian Affolter
7542cb50fb python3Packages.sabctools: 9.6.3 -> 9.7.0
https://github.com/sabnzbd/sabctools/releases/tag/v9.7.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:55 +02:00
Fabian Affolter
3db5a4aae5 python3Packages.rtb-data: 1.0.1 -> 1.1.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:54 +02:00
Fabian Affolter
bcab3054f9 python3Packages.rpmfile: 2.1.0 -> 2.2.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:54 +02:00
Fabian Affolter
d05fc64b89 python3Packages.rollbar: 1.3.0 -> 1.4.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:54 +02:00
Fabian Affolter
e741a26ae6 python3Packages.robotframework-assertion-engine: 3.0.3 -> 3.5.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:54 +02:00
Fabian Affolter
4ae4a7ca67 python3Packages.rns: 1.4.2 -> 1.5.0
https://github.com/markqvist/Reticulum/blob/1.5.0/Changelog.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:54 +02:00
Fabian Affolter
57d8c9e9ad python3Packages.repoze-sphinx-autointerface: 1.0.0 -> 1.1.0
https://github.com/repoze/repoze.sphinx.autointerface/blob/1.1.0/CHANGES.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:53 +02:00
Fabian Affolter
e8366ad33e python3Packages.repoze-lru: 0.7 -> 0.8
https://github.com/repoze/repoze.lru/blob/0.8/CHANGES.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:53 +02:00
Fabian Affolter
86fa284ce3 python3Packages.reportlab: 5.0.0 -> 5.0.1
https://hg.reportlab.com/hg-public/reportlab/file/tip/CHANGES.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:53 +02:00
Fabian Affolter
89e73983c5 python3Packages.relatorio: 0.11.1 -> 0.12.1
https://hg.tryton.org/relatorio/file/0.12.1/CHANGELOG

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:53 +02:00
Fabian Affolter
9d7d266930 python3Packages.ratarmount: 1.2.2 -> 1.3.0
https://github.com/mxmlnkn/ratarmount/blob/v1.3.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:53 +02:00
Fabian Affolter
5965e56fca python3Packages.r2pipe: 1.9.6 -> 1.9.8
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:52 +02:00
Fabian Affolter
bff998742b python3Packages.qcengine: 0.50.0 -> 0.51.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:52 +02:00
Fabian Affolter
a1c2dc3534 python3Packages.qcelemental: 0.50.4 -> 0.51.0
https://github.com/MolSSI/QCElemental/blob/v0.51.0/docs/changelog.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:52 +02:00
Fabian Affolter
3887b9156c python3Packages.pywikibot: 10.7.4 -> 10.7.6
https://doc.wikimedia.org/pywikibot/master/changelog.html

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:52 +02:00
Fabian Affolter
041d3f0d94 python3Packages.pywebpush: 2.3.0 -> 2.4.0
https://github.com/web-push-libs/pywebpush/releases/tag/2.4.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:52 +02:00
Fabian Affolter
b69582a642 python3Packages.pywayland: 0.4.18 -> 0.4.19
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:51 +02:00
Fabian Affolter
60eb6176ca python3Packages.pyvo: 1.8.1 -> 1.9.1
https://github.com/astropy/pyvo/releases/tag/v1.9.1

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:51 +02:00
Fabian Affolter
7c46d43b6c python3Packages.pyvex: 9.2.154 -> 9.3.3
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:51 +02:00
Fabian Affolter
74f668d5f2 python3Packages.pyvcd: 0.4.1 -> 0.5.0
https://github.com/SanDisk-Open-Source/pyvcd/blob/0.5.0/CHANGELOG.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:51 +02:00
Fabian Affolter
ade1d5dd46 python3Packages.pytz: 2026.2 -> 2026.3.post1
https://launchpad.net/pytz/+announcements

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:51 +02:00
Fabian Affolter
670e6b39d2 python3Packages.python-osc: 1.9.3 -> 1.10.2
https://github.com/attwad/python-osc/blob/v1.10.2/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:50 +02:00
Fabian Affolter
da5861ef2b python3Packages.python-octaviaclient: 3.13.0 -> 3.14.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:50 +02:00
Fabian Affolter
6786ea6325 python3Packages.python-manilaclient: 6.0.0 -> 6.2.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:50 +02:00
Fabian Affolter
0e683a4a39 python3Packages.python-glanceclient: 4.11.0 -> 4.12.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:50 +02:00
Fabian Affolter
1418a69d95 python3Packages.python-gitlab: 8.4.0 -> 8.5.0
https://github.com/python-gitlab/python-gitlab/blob/v8.5.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:50 +02:00
Fabian Affolter
7463d02587 python3Packages.pytest-django: 4.12.0 -> 4.14.0
https://github.com/pytest-dev/pytest-django/blob/v4.14.0/docs/changelog.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:49 +02:00
Fabian Affolter
c7d342aae6 python3Packages.pytest-astropy: 0.11.0 -> 0.12.0
https://github.com/astropy/pytest-astropy/releases/tag/v0.12.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:49 +02:00
Fabian Affolter
89e5386aee python3Packages.pyspark: 4.1.2 -> 4.2.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:49 +02:00
Fabian Affolter
07be90df68 python3Packages.py-sonic: 1.0.3 -> 1.1.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:49 +02:00
Fabian Affolter
0a9ac260bc python3Packages.pyslim: 1.1.0 -> 1.1.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:48 +02:00
Fabian Affolter
ee2fafe994 python3Packages.pyrtlsdr: 0.3.0 -> 0.5.0
https://github.com/pyrtlsdr/pyrtlsdr/releases/tag/v0.5.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:48 +02:00
Fabian Affolter
efb7906bf9 python3Packages.pyquery: 2.0.1 -> 2.1.0
https://github.com/gawel/pyquery/blob/2.1.0/CHANGES.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:48 +02:00
Fabian Affolter
db90242296 python3Packages.pypoolstation: 0.6.0 -> 0.8.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:48 +02:00
Fabian Affolter
f4657d0c3b python3Packages.pymunk: 7.1.0 -> 7.3.0
https://github.com/viblo/pymunk/releases/tag/7.3.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:48 +02:00
Fabian Affolter
f139a08c29 python3Packages.pylzma: 0.6.0 -> 0.6.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:47 +02:00
Fabian Affolter
d8b83369ea python3Packages.pylsqpack: 0.3.23 -> 0.3.24
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:47 +02:00
Fabian Affolter
9e3013116c python3Packages.pylibftdi: 0.23.0 -> 0.24.0
https://github.com/codedstructure/pylibftdi/blob/0.24.0/CHANGES.txt

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:47 +02:00
Fabian Affolter
d07b5a5113 python3Packages.pykmtronic: 0.3.0 -> 0.4.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:47 +02:00
Fabian Affolter
64b62a5cb0 python3Packages.pyisbn: 1.3.1 -> 1.4.3
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:47 +02:00
Fabian Affolter
f1f96de800 python3Packages.pyinstaller-hooks-contrib: 2026.6 -> 2026.7
https://github.com/pyinstaller/pyinstaller-hooks-contrib/blob/master/CHANGELOG.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:47 +02:00
Fabian Affolter
eafd9c1e07 python3Packages.pyinstaller: 6.18.0 -> 6.22.2
https://pyinstaller.org/en/v6.22.2/CHANGES.html

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:46 +02:00
Fabian Affolter
d2b366654a python3Packages.pygtkspellcheck: 5.0.3 -> 5.0.4
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:46 +02:00
Fabian Affolter
828beb3cdf python3Packages.pygit2: 1.19.3 -> 1.20.0
https://github.com/libgit2/pygit2/blob/v1.20.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:46 +02:00
Fabian Affolter
0ed9752f34 python3Packages.pyghmi: 1.6.18 -> 1.6.19
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:46 +02:00
Fabian Affolter
40c53f986a python3Packages.pyexploitdb: 0.3.40 -> 0.3.41
https://github.com/Hackman238/pyExploitDb/blob/master/ChangeLog.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:46 +02:00
Fabian Affolter
51a395e432 python3Packages.pyevtk: 1.6.0 -> 1.7.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:45 +02:00
Fabian Affolter
b4f41c6e2f python3Packages.pyee: 13.0.0 -> 13.0.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:45 +02:00
Fabian Affolter
3031bc9c94 python3Packages.pydy: 0.8.0 -> 0.9.4
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:45 +02:00
Fabian Affolter
4403511ea5 python3Packages.pydeck: 0.9.2 -> 0.9.3
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:45 +02:00
Fabian Affolter
7d9f2917ad python3Packages.pycoin: 0.92.20241201 -> 0.92718.20260405
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:45 +02:00
Fabian Affolter
ddf7e65a07 python3Packages.pybtex: 0.25.1 -> 0.26.1
https://bitbucket.org/pybtex-devs/pybtex/src/master/CHANGES

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:44 +02:00
Fabian Affolter
6ad413f34d python3Packages.pyavm: 0.9.8 -> 0.9.9
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:44 +02:00
Fabian Affolter
a19a79870d python3Packages.pvlib: 0.14.0 -> 0.15.2
https://pvlib-python.readthedocs.io/en/v0.15.2/whatsnew.html

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:44 +02:00
Fabian Affolter
7b00585e50 python3Packages.publicsuffixlist: 1.0.2.20260815 -> 1.0.2.20260821
https://github.com/ko-zu/psl/blob/v1.0.2.20260821-gha/CHANGES.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:44 +02:00
Fabian Affolter
2ef8b564d4 python3Packages.prov: 2.1.1 -> 2.5.3
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:44 +02:00
Fabian Affolter
4aa653f993 python3Packages.protobuf-py: 0.1.1 -> 0.3.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:43 +02:00
Fabian Affolter
8a9c6b007b python3Packages.progressbar2: 4.5.0 -> 4.6.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:43 +02:00
Fabian Affolter
00c45fdb36 python3Packages.pplpy: 0.8.10 -> 0.9.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:43 +02:00
Fabian Affolter
d13bf4b28a python3Packages.pooch: 1.8.2 -> 1.9.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:43 +02:00
Fabian Affolter
2faf0d8eaa python3Packages.pkg-about: 2.4.3 -> 2.4.4
https://github.com/karpierz/pkg_about/blob/2.4.4/CHANGES.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:43 +02:00
Fabian Affolter
0c88b229f8 python3Packages.phonemizer: 3.3.0 -> 3.4.0
https://github.com/bootphon/phonemizer/blob/v3.4.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:42 +02:00
Fabian Affolter
a9e252e639 python3Packages.persistent: 6.5 -> 6.8
https://github.com/zopefoundation/persistent/blob/6.8/CHANGES.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:42 +02:00
Fabian Affolter
893e68d1c0 python3Packages.pbr: 7.0.3 -> 7.1.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:42 +02:00
Fabian Affolter
502f9cc1e9 python3Packages.pathy: 0.11.0 -> 0.14.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:42 +02:00
Fabian Affolter
19adc38062 python3Packages.patch-ng: 1.19.0 -> 1.19.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:41 +02:00
Fabian Affolter
3d6ee9bd0a python3Packages.pan-os-python: 1.12.5 -> 1.13.1
https://github.com/PaloAltoNetworks/pan-os-python/releases/tag/v1.13.1

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:41 +02:00
Fabian Affolter
1b5362f4b6 python3Packages.panel: 1.8.5 -> 1.9.4
https://github.com/holoviz/panel/releases/tag/v1.9.4

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:41 +02:00
Fabian Affolter
18f7864e80 python3Packages.pandas-datareader: 0.10.0 -> 0.11.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:41 +02:00
Fabian Affolter
ff7f396fec python3Packages.packaging: 26.2 -> 26.3
https://github.com/pypa/packaging/blob/26.3/CHANGELOG.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:41 +02:00
Fabian Affolter
a8c7fb30b9 python3Packages.otpauth: 2.2.1 -> 2.2.2
https://github.com/authlib/otpauth/releases/tag/v2.2.2

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:40 +02:00
Fabian Affolter
4677725164 python3Packages.oslo-utils: 10.0.1 -> 10.2.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:40 +02:00
Fabian Affolter
85f00f3888 python3Packages.oslo-db: 18.1.0 -> 18.1.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:40 +02:00
Fabian Affolter
116a83ad8f python3Packages.opentelemetry-resourcedetector-gcp: 1.12.0a0 -> 1.14.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:40 +02:00
Fabian Affolter
184fa95254 python3Packages.openstackdocstheme: 3.5.0 -> 3.6.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:40 +02:00
Fabian Affolter
2385946eb7 python3Packages.opencc: 1.4.1 -> 1.4.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:39 +02:00
Fabian Affolter
ac9a50f8e5 python3Packages.openai-agents: 0.18.1 -> 0.22.0
https://github.com/openai/openai-agents-python/releases/tag/v0.22.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:39 +02:00
Fabian Affolter
87d0c0243c python3Packages.okta: 3.1.0 -> 3.4.4
https://github.com/okta/okta-sdk-python/blob/v3.4.4/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:39 +02:00
Fabian Affolter
e1b5c2f335 python3Packages.oauthenticator: 17.3.0 -> 17.4.0
https://github.com/jupyterhub/oauthenticator/blob/17.4.0/docs/source/reference/changelog.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:39 +02:00
Fabian Affolter
6451c5234e python3Packages.numexpr: 2.14.1 -> 2.14.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:39 +02:00
Fabian Affolter
5119bea3bf python3Packages.nose2: 0.15.1 -> 0.16.0
https://github.com/nose-devs/nose2/blob/0.16.0/docs/changelog.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:38 +02:00
Fabian Affolter
386d5ff2fe python3Packages.nglview: 4.0 -> 4.0.1
https://github.com/nglviewer/nglview/releases/tag/v4.0.1

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:38 +02:00
Fabian Affolter
0ae2782668 python3Packages.nexusformat: 2.0.2 -> 2.0.3
https://github.com/nexpy/nexusformat/releases/tag/v2.0.3

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:38 +02:00
Fabian Affolter
1f0faea2a4 python3Packages.netmiko: 4.6.0 -> 4.7.0
https://github.com/ktbyers/netmiko/releases/tag/v4.7.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:38 +02:00
Fabian Affolter
5e20fb5c99 python3Packages.netapp-ontap: 9.17.1.0 -> 9.19.1.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:38 +02:00
Fabian Affolter
0de0f457a0 python3Packages.nbformat: 5.10.4 -> 5.11.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:37 +02:00
Fabian Affolter
8d48b402a3 python3Packages.nbdev: 3.0.15 -> 3.3.12
https://github.com/AnswerDotAI/nbdev/blob/3.3.12/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:37 +02:00
Fabian Affolter
2be06dd200 python3Packages.nbclassic: 1.2.0 -> 1.3.3
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:37 +02:00
Fabian Affolter
540acca8ed python3Packages.nameparser: 1.1.3 -> 1.4.0
https://github.com/derek73/python-nameparser/releases/tag/v1.4.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:37 +02:00
Fabian Affolter
d06a446383 python3Packages.myst-nb: 1.3.0 -> 1.4.0
https://github.com/executablebooks/MyST-NB/raw/v1.4.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:37 +02:00
Fabian Affolter
d363998154 python3Packages.mss: 10.1.0 -> 10.2.0
https://github.com/BoboTiG/python-mss/blob/v10.2.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:36 +02:00
Fabian Affolter
207d5c3c21 python3Packages.mozart-api: 6.2.0.44.1 -> 6.2.0.44.2
https://github.com/bang-olufsen/mozart-open-api/releases/tag/6.2.0.44.2

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:36 +02:00
Fabian Affolter
7ca2a73185 python3Packages.molecule: 26.6.0 -> 26.8.0
https://github.com/ansible/molecule/releases/tag/v26.8.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:36 +02:00
Fabian Affolter
81dcaa099c python3Packages.mlflow: 3.15.0 -> 3.15.1
https://github.com/mlflow/mlflow/blob/v3.15.1/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:36 +02:00
Fabian Affolter
1409fec3b6 python3Packages.mkdocs-jupyter: 0.26.1 -> 0.26.3
https://github.com/danielfrg/mkdocs-jupyter/blob/0.26.3/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:36 +02:00
Fabian Affolter
57554f3957 python3Packages.mip: 1.15.0 -> 1.17.6
https://github.com/coin-or/python-mip/releases/tag/1.17.6

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:35 +02:00
Fabian Affolter
9fe50455d2 python3Packages.micawber: 0.6.2 -> 0.7.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:35 +02:00
Fabian Affolter
f7a4954bf5 python3Packages.mediawiki-langcodes: 0.2.25 -> 0.2.28
https://github.com/xxyzz/mediawiki_langcodes/releases/tag/v0.2.28

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:35 +02:00
Fabian Affolter
b15e1dd61f python3Packages.mayavi: 4.8.3 -> 4.9.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:35 +02:00
Fabian Affolter
a1a8d2344c python3Packages.marimo: 0.23.16 -> 0.24.0
https://github.com/marimo-team/marimo/releases/tag/0.24.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:35 +02:00
Fabian Affolter
6ecbbd7ee2 python3Packages.manifestoo-core: 1.15.4 -> 1.15.5
https://github.com/acsone/manifestoo-core/blob/v1.15.5/HISTORY.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:34 +02:00
Fabian Affolter
7321cc4e38 python3Packages.localstack-ext: 4.12.0 -> 4.14.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:34 +02:00
Fabian Affolter
9097373d6a python3Packages.localstack-client: 2.11 -> 2.12
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:34 +02:00
Fabian Affolter
8950825857 python3Packages.llama-index-workflows: 2.23.0 -> 2.23.3
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:34 +02:00
Fabian Affolter
94e74097fc python3Packages.llama-index-graph-stores-nebula: 0.5.1 -> 0.6.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:34 +02:00
Fabian Affolter
108906408a python3Packages.llama-cloud: 2.14.0 -> 2.14.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:33 +02:00
Fabian Affolter
ef78334db4 python3Packages.linuxpy: 0.24.0 -> 0.25.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:33 +02:00
Fabian Affolter
a9f07cd22b python3Packages.lingua: 4.15.0 -> 4.16.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:33 +02:00
Fabian Affolter
a604d063ef python3Packages.line-profiler: 5.0.0 -> 5.0.2
https://github.com/pyutils/line_profiler/blob/v5.0.2/CHANGELOG.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:33 +02:00
Fabian Affolter
16ea1b063e python3Packages.limnoria: 2026.3.21 -> 2026.5.8
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:33 +02:00
Fabian Affolter
c56a021c54 python3Packages.libtfr: 2.1.10 -> 2.2.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:32 +02:00
Fabian Affolter
f330d9a250 python3Packages.libknot: 3.5.6 -> 3.5.7
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:32 +02:00
Fabian Affolter
e6851865e1 python3Packages.lib50: 3.2.1 -> 3.2.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:32 +02:00
Fabian Affolter
681888fe13 python3Packages.ledgerblue: 0.1.55 -> 0.1.58
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:32 +02:00
Fabian Affolter
9af19f0383 python3Packages.langgraph-runtime-inmem: 0.32.3 -> 0.33.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:32 +02:00
Fabian Affolter
0dff61d866 python3Packages.kserve-storage: 0.16.0 -> 0.20.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:31 +02:00
Fabian Affolter
92e582fc65 python3Packages.krb5: 0.9.0 -> 0.10.0
https://github.com/jborean93/pykrb5/blob/v0.10.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:31 +02:00
Fabian Affolter
a784fc9480 python3Packages.korean-lunar-calendar: 0.3.1 -> 0.4.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:31 +02:00
Fabian Affolter
ed2e3bd19b python3Packages.kazoo: 2.10.0 -> 2.11.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:31 +02:00
Fabian Affolter
bbeefb4722 python3Packages.jupyter-server-ydoc: 3.0.0 -> 3.0.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:31 +02:00
Fabian Affolter
ece3343867 python3Packages.jupyter-lsp: 2.3.0 -> 2.3.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:30 +02:00
Fabian Affolter
2acab174f1 python3Packages.jupyterlab-widgets: 3.0.16 -> 3.0.17
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:30 +02:00
Fabian Affolter
47e041d7ef python3Packages.jupyter-docprovider: 3.0.0 -> 3.0.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:30 +02:00
Fabian Affolter
58bbcb4a0e python3Packages.jupyter-collaboration-ui: 3.0.0 -> 3.0.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:30 +02:00
Fabian Affolter
3182fa4ff6 python3Packages.jupyter-client: 8.8.0 -> 8.9.1
https://github.com/jupyter/jupyter_client/blob/v8.9.1/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:30 +02:00
Fabian Affolter
11659460f3 python3Packages.julius: 0.2.7 -> 0.2.8
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:29 +02:00
Fabian Affolter
06b5cf8889 python3Packages.jsonrpclib-pelix: 1.1.0 -> 1.2.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:29 +02:00
Fabian Affolter
33384c706e python3Packages.jsonpickle: 4.1.1 -> 4.1.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:29 +02:00
Fabian Affolter
847df597c0 python3Packages.jianpu-ly: 1.870 -> 1.889
https://github.com/ssb22/jianpu-ly/releases/tag/v1.889

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:29 +02:00
Fabian Affolter
876f68c957 python3Packages.javaobj-py3: 0.4.4 -> 0.6.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:29 +02:00
Fabian Affolter
77e8497dde python3Packages.jaraco-text: 4.0.0 -> 4.3.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:28 +02:00
Fabian Affolter
6cc9fddf77 python3Packages.jaraco-functools: 4.4.0 -> 4.6.0
https://github.com/jaraco/jaraco.functools/blob/v4.6.0/NEWS.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:28 +02:00
Fabian Affolter
781d4f8d04 python3Packages.ipywidgets: 8.1.8 -> 8.1.9
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:28 +02:00
Fabian Affolter
a291f75563 python3Packages.ipython: 9.14.0 -> 9.16.1
https://github.com/ipython/ipython/blob/9.16.1/docs/source/whatsnew/version9.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:28 +02:00
Fabian Affolter
a705b6d7e9 python3Packages.ipykernel: 7.1.0 -> 7.3.0
https://github.com/ipython/ipykernel/releases/tag/v7.3.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:28 +02:00
Fabian Affolter
caa4518896 python3Packages.imagesize: 2.0.0 -> 2.0.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:27 +02:00
Fabian Affolter
02adbd6118 python3Packages.hyperopt: 0.2.7 -> 0.3.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:27 +02:00
Fabian Affolter
e5fbdd5244 python3Packages.heudiconv: 1.4.0 -> 1.5.0
https://github.com/nipy/heudiconv/releases/tag/v1.5.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:27 +02:00
Fabian Affolter
40574a2d00 python3Packages.hebi-py: 2.7.9 -> 2.15.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:27 +02:00
Fabian Affolter
eebc652bbc python3Packages.hatchling: 1.31.0 -> 1.32.0
https://github.com/pypa/hatch/releases/tag/hatchling-v1.32.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:27 +02:00
Fabian Affolter
83d990326f python3Packages.gtfs-realtime-bindings: 2.1.0 -> 2.2.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:26 +02:00
Fabian Affolter
d824389ec6 python3Packages.greenlet: 3.5.3 -> 3.5.5
https://github.com/python-greenlet/greenlet/blob/3.5.5/CHANGES.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:26 +02:00
Fabian Affolter
b181a0f6b1 python3Packages.grad-cam: 1.5.5 -> 1.5.7
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:26 +02:00
Fabian Affolter
1cc834e9f1 python3Packages.google-resumable-media: 2.8.0 -> 2.10.1
https://github.com/googleapis/google-resumable-media-python/blob/v2.10.1/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:26 +02:00
Fabian Affolter
af6552c7b1 python3Packages.google-cloud-dataproc: 5.24.0 -> 5.30.0
https://github.com/googleapis/google-cloud-python/blob/google-cloud-dataproc-v5.30.0/packages/google-cloud-dataproc/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:25 +02:00
Fabian Affolter
801e8ee371 python3Packages.google-cloud-bigquery-datatransfer: 3.21.0 -> 3.23.0
https://github.com/googleapis/google-cloud-python/blob/google-cloud-bigquery-datatransfer-v3.23.0/packages/google-cloud-bigquery-datatransfer/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:25 +02:00
Fabian Affolter
5c49c50e7d python3Packages.glyphsets: 1.1.0 -> 1.1.3
https://github.com/googlefonts/glyphsets/blob/v1.1.3/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:25 +02:00
Fabian Affolter
de4945c206 python3Packages.glean-parser: 20.0.1 -> 20.2.0
https://github.com/mozilla/glean_parser/blob/v20.2.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:25 +02:00
Fabian Affolter
cafb11842a python3Packages.gflanguages: 0.7.9 -> 0.7.10
https://github.com/googlefonts/lang/releases/tag/v0.7.10

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:25 +02:00
Fabian Affolter
4706edac92 python3Packages.getjump: 2.10.0 -> 2.10.2
https://github.com/eggplants/getjump/releases/tag/v2.10.2

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:24 +02:00
Fabian Affolter
f4781e37ac python3Packages.geoip2: 5.2.0 -> 5.3.0
https://github.com/maxmind/GeoIP2-python/blob/v5.3.0/HISTORY.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:24 +02:00
Fabian Affolter
54c7fef77a python3Packages.genson: 1.3.0 -> 1.4.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:24 +02:00
Fabian Affolter
b36f03172c python3Packages.genshi: 0.7.10 -> 0.7.11
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:24 +02:00
Fabian Affolter
23f6d25717 python3Packages.functiontrace: 0.5.1 -> 0.5.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:24 +02:00
Fabian Affolter
3fd00ea287 python3Packages.ftputil: 5.1.0 -> 5.2.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:23 +02:00
Fabian Affolter
975a364f9c python3Packages.flower: 2.0.1 -> 2.1.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:23 +02:00
Fabian Affolter
b883d1fda7 python3Packages.flask-wtf: 1.2.2 -> 1.3.0
https://github.com/pallets-eco/flask-wtf/releases/tag/v1.3.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:23 +02:00
Fabian Affolter
97382f6c33 python3Packages.flask-swagger-ui: 5.21.0 -> 5.32.14
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:23 +02:00
Fabian Affolter
3212eb31aa python3Packages.flask-httpauth: 4.8.0 -> 4.8.1
https://github.com/miguelgrinberg/Flask-HTTPAuth/blob/v4.8.1/CHANGES.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:23 +02:00
Fabian Affolter
f9d920fc24 python3Packages.flask-caching: 2.3.1 -> 2.5.0
https://github.com/pallets-eco/flask-caching/blob/v2.5.0/CHANGES.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:22 +02:00
Fabian Affolter
fc75774074 python3Packages.flask-appbuilder: 5.0.2 -> 5.2.2
https://github.com/dpgaspar/Flask-AppBuilder/blob/v5.2.2/CHANGELOG.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:22 +02:00
Fabian Affolter
b97f702f3a python3Packages.fastjet: 3.5.1.2 -> 3.5.1.4
https://github.com/scikit-hep/fastjet/releases/tag/v3.5.1.4

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:22 +02:00
Fabian Affolter
ef9fd1a677 python3Packages.faker: 40.28.1 -> 40.37.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:22 +02:00
Fabian Affolter
5929c9cd9e python3Packages.execnb: 0.1.18 -> 0.3.2
https://github.com/fastai/execnb/releases/tag/0.3.2

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:22 +02:00
Fabian Affolter
a6f1baa456 python3Packages.evolutionhttp: 0.0.19 -> 0.1.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:21 +02:00
Fabian Affolter
587129f931 python3Packages.entrance: 1.1.21 -> 1.3.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:21 +02:00
Fabian Affolter
2794d8b25a python3Packages.enochecker-core: 0.10.0 -> 0.13.0
https://github.com/enowars/enochecker_core/releases/tag/v0.13.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:21 +02:00
Fabian Affolter
79d9f29cf3 python3Packages.empy: 4.2 -> 4.2.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:21 +02:00
Fabian Affolter
d5cd6246c9 python3Packages.elasticsearch: 8.18.1 -> 8.19.3
https://github.com/elastic/elasticsearch-py/releases/tag/v8.19.3

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:21 +02:00
Fabian Affolter
e3eac307b2 python3Packages.dvc-azure: 3.1.0 -> 3.1.1
https://github.com/iterative/dvc-azure/releases/tag/3.1.1

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:20 +02:00
Fabian Affolter
7250d02ee5 python3Packages.draccus: 0.11.5 -> 0.11.6
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:20 +02:00
Fabian Affolter
bd6af361d3 python3Packages.dot2tex: 2.11.3 -> 2.12.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:20 +02:00
Fabian Affolter
a06546d85d python3Packages.django-otp-webauthn: 0.8.0 -> 0.10.0
https://github.com/Stormbase/django-otp-webauthn/blob/v0.10.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:20 +02:00
Fabian Affolter
e5aedf1290 python3Packages.django-leaflet: 0.33.0 -> 0.34.0
https://github.com/makinacorpus/django-leaflet/blob/0.34.0/CHANGES

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:20 +02:00
Fabian Affolter
95bb57062a python3Packages.django-environ: 0.12.0 -> 0.14.0
https://github.com/joke2k/django-environ/releases/tag/v0.14.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:19 +02:00
Fabian Affolter
a4a950b6a2 python3Packages.django-colorful: 1.3 -> 1.4.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:19 +02:00
Fabian Affolter
6b24ce981f python3Packages.distlib: 0.4.0 -> 0.4.3
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:19 +02:00
Fabian Affolter
9d02bb22de python3Packages.disposable-email-domains: 0.0.237 -> 0.0.243
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:19 +02:00
Fabian Affolter
a0ae440586 python3Packages.diff-cover: 10.2.0 -> 10.5.1
https://github.com/Bachmann1234/diff_cover/releases/tag/v10.5.1

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:18 +02:00
Fabian Affolter
6a8d5fb088 python3Packages.dict2css: 0.3.0.post1 -> 0.6.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:18 +02:00
Fabian Affolter
867828012b python3Packages.deepl: 1.27.0 -> 1.32.0
https://github.com/DeepLcom/deepl-python/blob/v1.32.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:18 +02:00
Fabian Affolter
56e0323aca python3Packages.dbt-snowflake: 1.11.1 -> 1.12.0
https://github.com/dbt-labs/dbt-adapters/blob/main/dbt-snowflake/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:18 +02:00
Fabian Affolter
d158c0f829 python3Packages.dbt-adapters: 1.22.10 -> 1.24.5
https://github.com/dbt-labs/dbt-adapters/blob/main/dbt-adapters/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:18 +02:00
Fabian Affolter
babbd29a31 python3Packages.datamodeldict: 0.9.9 -> 0.9.10
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:17 +02:00
Fabian Affolter
33d44ea844 python3Packages.dataconf: 3.6.0 -> 3.7.0
https://github.com/zifeo/dataconf/blob/main/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:17 +02:00
Fabian Affolter
ed99820e7c python3Packages.databricks-connect: 11.3.40 -> 11.3.61
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:17 +02:00
Fabian Affolter
444623526a python3Packages.cutlass: 0.5.0 -> 0.9.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:17 +02:00
Fabian Affolter
7a50c8902c python3Packages.cssselect: 1.3.0 -> 1.5.0
https://github.com/scrapy/cssselect/blob/v1.5.0/CHANGES

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:17 +02:00
Fabian Affolter
cbfc11cf20 python3Packages.cssselect2: 0.8.0 -> 0.9.0
https://github.com/Kozea/cssselect2/releases/tag/0.9.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:16 +02:00
Fabian Affolter
a4387e8de4 python3Packages.css-parser: 1.0.10 -> 1.1.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:16 +02:00
Fabian Affolter
186e316b6e python3Packages.cookiecutter: 2.6.0 -> 2.7.1
https://github.com/cookiecutter/cookiecutter/blob/2.7.1/HISTORY.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:16 +02:00
Fabian Affolter
26b83d4b38 python3Packages.consolekit: 1.12.0 -> 1.13.0
https://github.com/domdfcoding/consolekit/releases/tag/v1.13.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:16 +02:00
Fabian Affolter
8e12cc5caf python3Packages.comfyui-workflow-templates-media-assets-01: 0.1.28 -> 0.1.33
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:16 +02:00
Fabian Affolter
8ba376e900 python3Packages.comfyui-workflow-templates-json: 0.1.47 -> 0.1.55
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:15 +02:00
Fabian Affolter
b61328ad76 python3Packages.comfyui-workflow-templates: 0.11.41 -> 0.11.46
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:15 +02:00
Fabian Affolter
69e30b8505 python3Packages.comfyui-workflow-templates-core: 0.3.312 -> 0.3.320
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:15 +02:00
Fabian Affolter
ea4927edc4 python3Packages.comfyui-frontend-package: 1.48.7 -> 1.50.6
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:15 +02:00
Fabian Affolter
a7441b6046 python3Packages.comfyui-embedded-docs: 0.5.9 -> 0.5.10
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:15 +02:00
Fabian Affolter
41e74b8988 python3Packages.comet-ml: 3.58.4 -> 3.58.5
https://www.comet.com/docs/v2/api-and-sdk/python-sdk/releases/

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:14 +02:00
Fabian Affolter
8f4a4de9be python3Packages.coinmetrics-api-client: 2026.2.9.18 -> 2026.8.13.18
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:14 +02:00
Fabian Affolter
7f8e7883da python3Packages.coiled: 1.135.1 -> 1.135.3
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:14 +02:00
Fabian Affolter
b921db5753 python3Packages.clustershell: 1.9.3 -> 1.10.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:14 +02:00
Fabian Affolter
cffa7f5c84 python3Packages.clr-loader: 0.2.10 -> 0.3.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:14 +02:00
Fabian Affolter
3c4071c408 python3Packages.cloudsmith-api: 2.0.23 -> 2.0.31
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:13 +02:00
Fabian Affolter
73f1682660 python3Packages.cli-helpers: 2.14.0 -> 2.15.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:13 +02:00
Fabian Affolter
b07ecf1f95 python3Packages.click-spinner: 0.1.10 -> 0.2.0
https://github.com/click-contrib/click-spinner/releases/tag/v0.2.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:13 +02:00
Fabian Affolter
4793b25276 python3Packages.clickhouse-cityhash: 1.0.2.5 -> 1.0.2.6
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:13 +02:00
Fabian Affolter
812803d34f python3Packages.citeproc-py: 0.9.0 -> 0.11.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:13 +02:00
Fabian Affolter
e25490001d python3Packages.ci-info: 0.3.0 -> 0.4.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:12 +02:00
Fabian Affolter
a4821e4327 python3Packages.cantools: 41.3.1 -> 41.4.3
https://github.com/cantools/cantools/releases/tag/41.4.3

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:12 +02:00
Fabian Affolter
209819ee59 python3Packages.caido-sdk-client: 0.2.0 -> 0.3.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:12 +02:00
Fabian Affolter
33e595486f python3Packages.caido-schema-proxy: 0.57.1 -> 0.58.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:12 +02:00
Fabian Affolter
79a5400a42 python3Packages.bumps: 1.0.3 -> 1.0.5
https://github.com/bumps/bumps/releases/tag/v1.0.5

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:12 +02:00
Fabian Affolter
39f5970748 python3Packages.btrees: 6.3 -> 6.5
https://github.com/zopefoundation/BTrees/blob/6.5/CHANGES.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:11 +02:00
Fabian Affolter
6b9565d1f7 python3Packages.bsuite: 0.3.5 -> 0.3.6
https://github.com/google-deepmind/bsuite/releases/tag/0.3.6

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:11 +02:00
Fabian Affolter
7a00ab8f5c python3Packages.broadbean: 0.14.0 -> 0.15.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:11 +02:00
Fabian Affolter
27b000ab98 python3Packages.bracex: 2.6 -> 2.7
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:11 +02:00
Fabian Affolter
03570f0fe0 python3Packages.boto3-stubs: 1.43.72 -> 1.43.79
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:11 +02:00
Fabian Affolter
fe7ec9aca8 python3Packages.bokeh: 3.8.2 -> 3.10.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:10 +02:00
Fabian Affolter
570151cab6 python3Packages.bittensor: 11.0.1 -> 11.1.0
https://pypi.org/project/bittensor/11.1.0/

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:10 +02:00
Fabian Affolter
f736366402 python3Packages.biopython: 1.86 -> 1.88
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:10 +02:00
Fabian Affolter
6ccddc4a29 python3Packages.binaryornot: 0.4.4 -> 0.6.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:10 +02:00
Fabian Affolter
60db2bac75 python3Packages.bencode-py: 4.0.0 -> 4.1.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:10 +02:00
Fabian Affolter
8b54bad9b2 python3Packages.bangla: 0.0.5 -> 0.0.6
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:09 +02:00
Fabian Affolter
11392a43ac python3Packages.backtesting: 0.6.5 -> 0.6.6
https://github.com/kernc/backtesting.py/blob/0.6.6/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:09 +02:00
Fabian Affolter
0be3a54895 python3Packages.azure-storage-file-share: 12.24.0 -> 12.26.0
https://github.com/Azure/azure-sdk-for-python/blob/azure-storage-file-share_12.26.0/sdk/storage/azure-storage-file-share/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:09 +02:00
Fabian Affolter
47ba4c4c41 python3Packages.azure-storage-file-datalake: 12.23.0 -> 12.25.0
https://github.com/Azure/azure-sdk-for-python/blob/azure-storage-file-datalake_12.25.0/sdk/storage/azure-storage-file-datalake/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:09 +02:00
Fabian Affolter
094eab3263 python3Packages.azure-storage-blob: 12.28.0 -> 12.30.0
https://github.com/Azure/azure-sdk-for-python/blob/azure-storage-blob_12.30.0/sdk/storage/azure-storage-blob/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:09 +02:00
Fabian Affolter
fc178263ab python3Packages.azure-mgmt-recoveryservices: 4.1.0 -> 4.2.0
https://github.com/Azure/azure-sdk-for-python/blob/azure-mgmt-recoveryservices_4.2.0/sdk/recoveryservices/azure-mgmt-recoveryservices/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:08 +02:00
Fabian Affolter
c7bbc03790 python3Packages.azure-mgmt-domainregistration: 1.0.0b1 -> 1.0.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:08 +02:00
Fabian Affolter
326e2efdf7 python3Packages.azure-mgmt-containerservice: 41.1.0 -> 41.5.0
https://github.com/Azure/azure-sdk-for-python/blob/azure-mgmt-containerservice_41.5.0/sdk/containerservice/azure-mgmt-containerservice/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:08 +02:00
Fabian Affolter
21fc5f6c96 python3Packages.azure-mgmt-compute: 37.1.0 -> 37.2.0
https://github.com/Azure/azure-sdk-for-python/blob/azure-mgmt-compute_37.2.0/sdk/compute/azure-mgmt-compute/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:08 +02:00
Fabian Affolter
7ef8c98605 python3Packages.azure-keyvault-secrets: 4.10.0 -> 4.11.1
https://github.com/Azure/azure-sdk-for-python/tree/azure-keyvault-secrets_4.11.1/sdk/keyvault/azure-keyvault-secrets

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:07 +02:00
Fabian Affolter
bea8e2c42d python3Packages.azure-eventgrid: 4.22.0 -> 4.22.1
https://github.com/Azure/azure-sdk-for-python/blob/azure-eventgrid_4.22.1/sdk/eventgrid/azure-eventgrid/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:07 +02:00
Fabian Affolter
e7075b33df python3Packages.azure-cosmos: 4.14.5 -> 4.16.3
https://github.com/Azure/azure-sdk-for-python/blob/azure-cosmos_4.16.3/sdk/cosmos/azure-cosmos/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:07 +02:00
Fabian Affolter
5588a4114c python3Packages.azure-core: 1.38.0 -> 1.41.0
https://github.com/Azure/azure-sdk-for-python/blob/azure-core_1.41.0/sdk/core/azure-core/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:07 +02:00
Fabian Affolter
ef497fb4dd python3Packages.azure-appconfiguration: 1.8.0 -> 1.9.0
https://github.com/Azure/azure-sdk-for-python/blob/azure-appconfiguration_1.9.0/sdk/appconfiguration/azure-appconfiguration/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:07 +02:00
Fabian Affolter
344b5e4a23 python3Packages.awscrt: 0.33.0 -> 0.36.2
https://github.com/awslabs/aws-crt-python/releases/tag/v0.36.2

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:06 +02:00
Fabian Affolter
f652472d44 python3Packages.avro: 1.12.1 -> 1.12.2
https://github.com/apache/avro/releases/tag/release-1.12.2

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:06 +02:00
Fabian Affolter
71e141a939 python3Packages.avidtools: 0.2.1 -> 0.3.2
https://github.com/avidml/avidtools/releases/tag/0.3.2

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:06 +02:00
Fabian Affolter
fa1ad4bf50 python3Packages.autoit-ripper: 1.1.2 -> 1.2.0
https://github.com/nazywam/AutoIt-Ripper/releases/tag/v1.2.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:06 +02:00
Fabian Affolter
ead2ca9748 python3Packages.autoflake: 2.3.2 -> 2.4.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:06 +02:00
Fabian Affolter
70a9024554 python3Packages.auditwheel: 6.7.0 -> 6.8.1
https://github.com/pypa/auditwheel/blob/6.8.1/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:05 +02:00
Fabian Affolter
42b54470e1 python3Packages.anywidget: 0.9.21 -> 0.11.0
https://github.com/manzt/anywidget/releases/tag/anywidget%400.11.0

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:05 +02:00
Fabian Affolter
4f4f833f03 python3Packages.ansitable: 0.11.4 -> 0.11.7
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:05 +02:00
Fabian Affolter
9020c570ba python3Packages.ansible: 14.2.0 -> 14.3.1
https://github.com/ansible-community/ansible-build-data/blob/14.3.1/14/CHANGELOG-v14.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:05 +02:00
Fabian Affolter
8771698a5b python3Packages.allure-python-commons: 2.15.3 -> 2.16.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:05 +02:00
Fabian Affolter
29b449bb9c python3Packages.alibabacloud-tea-openapi: 0.4.5 -> 0.4.6
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:04 +02:00
Fabian Affolter
dc2287720e python3Packages.alibabacloud-ecs20140526: 7.9.6 -> 7.10.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:04 +02:00
Fabian Affolter
b1eb1d5ac4 python3Packages.alibabacloud-cs20151215: 7.0.5 -> 7.1.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:04 +02:00
Fabian Affolter
d7192ca583 python3Packages.alibabacloud-credentials: 1.0.11 -> 1.0.12
https://github.com/aliyun/credentials-python/releases/tag/v1.0.12

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:04 +02:00
Fabian Affolter
fa0e9d1707 python3Packages.alembic: 1.18.1 -> 1.19.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:04 +02:00
Fabian Affolter
26525e318e python3Packages.aioresponses: 0.7.8 -> 0.7.9
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:03 +02:00
Fabian Affolter
0a5ae99be7 python3Packages.aiopulse: 0.4.7 -> 0.5.3
https://github.com/atmurray/aiopulse/releases/tag/v0.5.3

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:03 +02:00
Fabian Affolter
98a4ac41e7 python3Packages.ago: 0.1.0 -> 0.1.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:03 +02:00
Fabian Affolter
b83cd70661 python3Packages.agentic-threat-hunting-framework: 0.18.0 -> 0.19.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:03 +02:00
Fabian Affolter
1a00846a6d python3Packages.agent-client-protocol: 0.12.0 -> 0.12.1
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:03 +02:00
Fabian Affolter
8d77c864bc python3Packages.agate: 1.14.1 -> 1.14.2
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:02 +02:00
Fabian Affolter
395954da3c python3Packages.affine-gaps: 0.2.4 -> 0.2.5
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:02 +02:00
Fabian Affolter
58f85b60ba python3Packages.aetcd: 1.0.0a4 -> 1.0.0
https://github.com/martyanov/aetcd/blob/v1.0.0/docs/changelog.rst

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:02 +02:00
Fabian Affolter
8b804bca84 python3Packages.aerosandbox: 4.2.8 -> 4.2.10
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:02 +02:00
Fabian Affolter
fad29117cd python3Packages.aenum: 3.1.16 -> 3.1.17
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:02 +02:00
Fabian Affolter
c1528dcf18 python3Packages.aeidon: 1.15 -> 1.16
https://github.com/otsaloma/gaupol/releases/tag/1.16

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:01 +02:00
Fabian Affolter
45c6c0dacf python3Packages.adlfs: 2026.5.0 -> 2026.8.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:01 +02:00
Fabian Affolter
c3f54a0fe7 python3Packages.adb-enhanced: 2.8.0 -> 2.11.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:01 +02:00
Fabian Affolter
525c922663 python3Packages.actron-neo-api: 0.5.12 -> 0.5.14
https://github.com/kclif9/actronneoapi/releases/tag/v0.5.14

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:01 +02:00
Fabian Affolter
5445e5568b python3Packages.accelerate: 1.13.0 -> 1.14.0
This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:01 +02:00
Fabian Affolter
9701f215b6 python3Packages.absl-py: 2.3.1 -> 2.5.0
https://github.com/abseil/abseil-py/blob/v2.5.0/CHANGELOG.md

This commit was automatically generated using update-python-libraries.
2026-08-25 01:24:00 +02:00
Fabian Affolter
40367998de python3Packages.types-webencodings: 0.6.0.20260821 -> 0.6.0.20260824 2026-08-25 00:31:46 +02:00
Fabian Affolter
d86838c3ce python3Packages.time-machine: 3.2.0 -> 3.4.0
Changelog: https://github.com/adamchainz/time-machine/blob/3.4.0/CHANGELOG.rst
2026-08-24 23:56:37 +02:00
Fabian Affolter
a26bbefab7 fixup! python3Packages.boto3: fix build 2026-08-24 23:52:35 +02:00
Fabian Affolter
463b92737c python3Packages.pkgconfig: 1.5.5 -> 1.6.0
Changelog: https://github.com/matze/pkgconfig/releases/tag/v1.6.0
2026-08-24 23:18:16 +02:00
Fabian Affolter
6d526ea03e python3Packages.mkdocstrings: 1.0.4 -> 1.0.6
Diff: https://github.com/mkdocstrings/mkdocstrings/compare/1.0.4...1.0.6

Changelog: https://github.com/mkdocstrings/mkdocstrings/blob/1.0.6/CHANGELOG.md
2026-08-24 23:08:36 +02:00
Fabian Affolter
3d3e7772be python3Packages.moto: 5.2.2 -> 5.2.3
Changelog: https://github.com/getmoto/moto/blob/5.2.3/CHANGELOG.md
2026-08-24 22:58:36 +02:00
Fabian Affolter
462ab4e903 python3Packages.msal: 1.37.0 -> 1.38.0
Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/releases/tag/1.38.0
2026-08-24 22:56:42 +02:00
Fabian Affolter
73e1150055 python3Packages.boto3: fix build 2026-08-24 22:55:59 +02:00
Fabian Affolter
cea8a31013 python3Packages.botocore: 1.42.31 -> 1.43.79
Diff: https://github.com/boto/botocore/compare/1.42.31...1.43.79

Changelog: https://github.com/boto/botocore/blob/1.43.79/CHANGELOG.rst
2026-08-24 22:30:43 +02:00
Fabian Affolter
c1eb87ac8c python3Packages.mysqlclient: 2.2.7 -> 2.2.8 2026-08-24 22:28:55 +02:00
Fabian Affolter
c9eaea5c59 python3Packages.gcsfs: 2026.7.0 -> 2026.8.0
Diff: https://github.com/fsspec/gcsfs/compare/2026.7.0...2026.8.0

Changelog: https://github.com/fsspec/gcsfs/raw/2026.8.0/docs/source/changelog.rst
2026-08-24 22:28:28 +02:00
Fabian Affolter
378034f39b python3Packages.fsspec: 2026.6.0 -> 2026.7.0
Diff: https://github.com/fsspec/filesystem_spec/compare/2026.6.0...2026.7.0

Changelog: https://github.com/fsspec/filesystem_spec/raw/2026.7.0/docs/source/changelog.rst
2026-08-24 22:25:53 +02:00
Fabian Affolter
f4437c20a3 python3Packages.colorlog: 6.11.0 -> 6.12.0
Diff: https://github.com/borntyping/python-colorlog/compare/v6.11.0...v6.12.0

Changelog: https://github.com/borntyping/python-colorlog/releases/tag/v6.12.0
2026-08-24 22:24:11 +02:00
Fabian Affolter
326ed4a489 python3Packages.dulwich: 1.2.10 -> 1.2.13
Diff: https://github.com/jelmer/dulwich/compare/dulwich-1.2.10...dulwich-1.2.13

Changelog: https://github.com/jelmer/dulwich/blob/dulwich-dulwich-1.2.13/NEWS
2026-08-24 22:23:10 +02:00
Fabian Affolter
03bec812cf python3Packages.s3transfer: 0.16.0 -> 0.19.2
Changelog: https://github.com/boto/s3transfer/blob/0.19.2/CHANGELOG.rst
2026-08-24 22:20:02 +02:00
Fabian Affolter
08ed330284 python3Packages.queuelib: migrate to finalAttrs 2026-08-24 22:09:36 +02:00
Fabian Affolter
341b0f006f python3Packages.queuelib: 1.9.0 -> 1.10.0
Changelog: https://github.com/scrapy/queuelib/releases/tag/v1.10.0
2026-08-24 22:07:57 +02:00
Fabian Affolter
7b950c35ea fixup! python3Packages.testscenarios: 0.5.0 -> 0.6.2 2026-08-24 21:52:17 +02:00
Fabian Affolter
170e2c53c2 python3Packages.serializable: unstable-2023-07-13 -> 1.1.0
Diff: ed309a6f8f...ed309a6f8f
2026-08-24 21:43:41 +02:00
Fabian Affolter
18d22c296f python3Packages.serialx: 1.8.2 -> 1.9.0
Diff: https://github.com/puddly/serialx/compare/v1.8.2...v1.9.0

Changelog: https://github.com/puddly/serialx/releases/tag/v1.9.0
2026-08-24 21:42:58 +02:00
Fabian Affolter
f5419112b3 python3Packages.scripttest: 2.0.post1 -> 3.0
Changelog: https://github.com/pypa/scripttest/releases/tag/3.0
2026-08-24 21:41:44 +02:00
Fabian Affolter
76fc62a4ff python3Packages.scp: 0.15.0 -> 0.16.1 2026-08-24 21:36:21 +02:00
Fabian Affolter
f1c8a9dccf python3Packages.slither-analyzer: 0.11.5 -> 0.11.6
Changelog: https://github.com/crytic/slither/releases/tag/0.11.6
2026-08-24 21:35:15 +02:00
Fabian Affolter
243023c59f python3Packages.crytic-compile: 0.3.11 -> 0.4.2
Changelog: https://github.com/crytic/crytic-compile/releases/tag/0.4.2
2026-08-24 21:34:52 +02:00
Fabian Affolter
61426b952c python3Packages.simpleeval: 1.0.4 -> 1.0.7
Diff: https://github.com/danthedeckie/simpleeval/compare/1.0.4...1.0.7

Changelog: https://github.com/danthedeckie/simpleeval/releases/tag/1.0.7
2026-08-24 21:19:51 +02:00
Fabian Affolter
2d72859977 python3Packages.rich-argparse: 1.7.2 -> 1.8.0
Diff: https://github.com/hamdanal/rich-argparse/compare/v1.7.2...v1.8.0

Changelog: https://github.com/hamdanal/rich-argparse/blob/v1.8.0/CHANGELOG.md
2026-08-24 21:18:12 +02:00
Fabian Affolter
092b81d1b2 python3Packages.python-socketio: 5.16.3 -> 5.16.4
Diff: https://github.com/miguelgrinberg/python-socketio/compare/v5.16.3...v5.16.4

Changelog: https://github.com/miguelgrinberg/python-socketio/blob/v5.16.4/CHANGES.md
2026-08-24 21:17:07 +02:00
Fabian Affolter
607b78b8d6 python3Packages.python-engineio: 4.13.3 -> 4.13.5
Diff: https://github.com/miguelgrinberg/python-engineio/compare/v4.13.3...v4.13.5

Changelog: https://github.com/miguelgrinberg/python-engineio/blob/v4.13.5/CHANGES.md
2026-08-24 21:14:23 +02:00
Fabian Affolter
15d87a6f6a python3Packages.python-dotenv: 1.2.2 -> 1.2.3
Diff: https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3

Changelog: https://github.com/theskumar/python-dotenv/blob/v1.2.3/CHANGELOG.md
2026-08-24 21:12:51 +02:00
Fabian Affolter
3a75353415 python3Packages.pytest-socket: 0.8.0 -> 0.8.1
Diff: https://github.com/miketheman/pytest-socket/compare/0.8.0...0.8.1

Changelog: https://github.com/miketheman/pytest-socket/blob/0.8.1/CHANGELOG.md
2026-08-24 21:11:02 +02:00
Fabian Affolter
20cb1af78e python3Packages.pytest-run-parallel: 0.9.1 -> 0.10.0
Diff: https://github.com/Quansight-Labs/pytest-run-parallel/compare/v0.9.1...v0.10.0

Changelog: https://github.com/Quansight-Labs/pytest-run-parallel/releases/tag/v0.10.0
2026-08-24 21:10:46 +02:00
Fabian Affolter
d4c3de4fee python3Packages.pytest-mh: 1.0.29 -> 1.0.30
Changelog: https://github.com/next-actions/pytest-mh/releases/tag/1.0.30
2026-08-24 21:09:15 +02:00
Fabian Affolter
b1e3176308 python3Packages.pytest-markdown-docs: 0.9.1 -> 0.9.2
Changelog: https://github.com/modal-labs/pytest-markdown-docs/releases/tag/v0.9.2
2026-08-24 21:08:07 +02:00
Fabian Affolter
7b3757289d python3Packages.pytest-lazy-fixtures: 1.4.0 -> 1.4.1
Diff: https://github.com/dev-petrov/pytest-lazy-fixtures/compare/1.4.0...1.4.1
2026-08-24 21:03:36 +02:00
Fabian Affolter
16ca00d858 python3Packages.pytest-env: 1.2.0 -> 1.7.0 2026-08-24 21:02:15 +02:00
Fabian Affolter
3cb612acb8 python3Packages.pytest-doctestplus: 1.7.0 -> 1.7.1
Diff: https://github.com/scientific-python/pytest-doctestplus/compare/v1.7.0...v1.7.1
2026-08-24 21:00:49 +02:00
Fabian Affolter
347ed477a4 python3Packages.pytest-remotedata: modernize 2026-08-24 20:54:14 +02:00
Fabian Affolter
864b6b274b python3Packages.pytest-arraydiff: 0.6.1 -> 0.7.0 2026-08-24 20:46:17 +02:00
Fabian Affolter
18fea87be1 python3Packages.pytest-randomly: 4.0.1 -> 4.1.0
Diff: https://github.com/pytest-dev/pytest-randomly/compare/4.0.1...4.1.0

Changelog: https://github.com/pytest-dev/pytest-randomly/blob/4.1.0/CHANGELOG.rst
2026-08-24 19:55:32 +02:00
Fabian Affolter
86cc2ec0bb python3Packages.pytest-rerunfailures: 16.4 -> 16.6
Diff: https://github.com/pytest-dev/pytest-rerunfailures/compare/16.4...16.6

Changelog: https://github.com/pytest-dev/pytest-rerunfailures/blob/16.6/CHANGES.rst
2026-08-24 19:44:55 +02:00
Fabian Affolter
563e58a579 python3Packages.hydra-core: 1.3.4 -> 1.3.5
Diff: https://github.com/facebookresearch/hydra/compare/v1.3.4...v1.3.5

Changelog: https://github.com/facebookresearch/hydra/blob/v1.3.5/NEWS.md
2026-08-24 19:44:33 +02:00
Fabian Affolter
da790a532a python3Packages.commonmark: 0.9.1 -> 0.9.2
Diff: https://github.com/readthedocs/commonmark.py/compare/0.9.1...0.9.2
2026-08-24 19:31:42 +02:00
Fabian Affolter
34623b1337 python3Packages.urwid: 3.0.5 -> 4.0.11
Diff: https://github.com/urwid/urwid/compare/3.0.5...4.0.11

Changelog: https://github.com/urwid/urwid/releases/tag/4.0.11
2026-08-24 16:57:11 +02:00
Fabian Affolter
c3e2ca860c python3Packages.soupsieve: 2.8.4 -> 2.9.2 2026-08-24 16:53:55 +02:00
Fabian Affolter
40cd37e2e7 python3Packages.tenacity: 9.1.4 -> 9.2.0
Changelog: https://github.com/jd/tenacity/releases/tag/9.2.0
2026-08-24 16:53:18 +02:00
Fabian Affolter
1cedc5c564 python3Packages.httpx2: 2.9.1 -> 2.12.0
Diff: https://github.com/pydantic/httpx2/compare/v2.9.1...v2.12.0

Changelog: https://github.com/pydantic/httpx2/blob/v2.12.0/src/httpx2/CHANGELOG.md
2026-08-24 16:44:18 +02:00
Fabian Affolter
ee8846f1ef python3Packages.aiotools: 2.2.3 -> 2.2.4
Changelog: https://github.com/achimnol/aiotools/blob/2.2.4/CHANGES.md
2026-08-24 16:40:19 +02:00
Fabian Affolter
401ac6a1d5 python3Packages.cliff: 4.15.0 -> 4.16.0 2026-08-24 16:37:46 +02:00
Fabian Affolter
ffd93b67a1 python3Packages.cmd2: 3.2.1 -> 4.2.1
Changelog: https://github.com/python-cmd2/cmd2/releases/tag/4.2.1
2026-08-24 16:29:20 +02:00
Fabian Affolter
31a7d3558e python3Packages.hatch-argparse-manpage: 1.0.1 -> 1.0.2
Changelog: https://github.com/damonlynch/hatch-argparse-manpage/blob/v1.0.2/CHANGES.md
2026-08-24 16:24:06 +02:00
Fabian Affolter
f0c4efeff2 python3Packages.aiohttp-basicauth: 1.1.0 -> 1.2.0
Diff: https://github.com/romis2012/aiohttp-basicauth/compare/v1.1.0...v1.2.0

Changelog: https://github.com/romis2012/aiohttp-basicauth/releases/tag/vv1.2.0
2026-08-24 16:20:11 +02:00
Fabian Affolter
5dc7bd083a python3Packages.zopfli: 0.4.0 -> 0.4.3 2026-08-24 16:05:29 +02:00
Fabian Affolter
2b68575862 python3Packages.sphinxcontrib-bibtex: 2.6.5 -> 2.7.0
Changelog: https://github.com/mcmtroffaes/sphinxcontrib-bibtex/blob/2.7.0/CHANGELOG.rst
2026-08-24 16:03:55 +02:00
Fabian Affolter
cf46a560b4 python3Packages.sphinxcontrib-openapi: 0.8.4 -> 0.9.0
Changelog: https://github.com/sphinx-contrib/openapi/releases/tag/v0.9.0
2026-08-24 16:00:56 +02:00
Fabian Affolter
3c6c57a723 python3Packages.sphinxcontrib-httpdomain: 1.8.1 -> 2.0.0
Changelog: https://github.com/sphinx-contrib/httpdomain/releases/tag/2.0.0
2026-08-24 15:53:15 +02:00
Fabian Affolter
186cec7145 python3Packages.sphinxcontrib-programoutput: 0.18 -> 0.20
Changelog: https://github.com/NextThought/sphinxcontrib-programoutput/releases/tag/v0.20
2026-08-24 15:39:40 +02:00
Fabian Affolter
bf5197a65e python3Packages.sphinxcontrib-svg2pdfconverter: 2.0.0 -> 2.1.0
Changelog: https://github.com/missinglinkelectronics/sphinxcontrib-svg2pdfconverter/releases/tag/v2.1.0
2026-08-24 15:35:36 +02:00
Fabian Affolter
4f8b588c9b python3Packages.sphinxcontrib-mermaid: 2.0.0 -> 2.1.0
Changelog: https://github.com/mgaitan/sphinxcontrib-mermaid/releases/tag/v2.1.0
2026-08-24 15:27:54 +02:00
Fabian Affolter
268af4fa13 python3Packages.sphinx-toolbox: 4.1.2 -> 4.3.0
Changelog: https://github.com/sphinx-toolbox/sphinx-toolbox/releases/tag/v4.3.0
2026-08-24 15:24:26 +02:00
Fabian Affolter
9389f532c8 python3Packages.sphinx-prompt: modernize 2026-08-24 15:16:20 +02:00
Fabian Affolter
b06f598d96 python3Packages.sphinx-prompt: migrate to pyprojectVersionPatchHook 2026-08-24 15:15:01 +02:00
Fabian Affolter
2cd69df9e2 python3Packages.sphinx-prompt: disable failing test 2026-08-24 15:14:02 +02:00
Fabian Affolter
d7e449dd55 python3Packages.sphinx-markdown-builder: 0.6.10 -> 0.6.11
Diff: https://github.com/liran-funaro/sphinx-markdown-builder/compare/0.6.10...0.6.11
2026-08-24 15:10:24 +02:00
Fabian Affolter
676e32f018 python3Packages.sphinx-book-theme: 1.2.0 -> 1.4.0
Changelog: https://github.com/executablebooks/sphinx-book-theme/raw/v1.4.0/CHANGELOG.md
2026-08-24 15:10:00 +02:00
Fabian Affolter
a8f84fd85f python3Packages.pydata-sphinx-theme: 0.16.1 -> 0.20.0
Changelog: https://github.com/pydata/pydata-sphinx-theme/releases/tag/v0.20.0
2026-08-24 15:09:55 +02:00
Fabian Affolter
15c7bd4ac0 python3Packages.sphinx-autodoc-typehints: 3.12.1 -> 3.13.2
Diff: https://github.com/tox-dev/sphinx-autodoc-typehints/compare/3.12.1...3.13.2

Changelog: https://github.com/tox-dev/sphinx-autodoc-typehints/releases/tag/3.13.2
2026-08-24 15:08:43 +02:00
Fabian Affolter
09cbb7889c python3Packages.sphinx-argparse: 0.6.0 -> 0.6.1 2026-08-24 15:08:31 +02:00
Fabian Affolter
ce3d864a96 python3Packages.tornado: 6.5.7 -> 6.5.8
Diff: https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8

Changelog: https://www.tornadoweb.org/en/stable/releases/v6.5.8.html
2026-08-24 15:07:51 +02:00
Fabian Affolter
5a2006a03f python3Packages.testtools: modernize 2026-08-24 15:04:20 +02:00
Fabian Affolter
835b4eae9b python3Packages.testscenarios: 0.5.0 -> 0.6.2
Changelog: https://github.com/testing-cabal/testscenarios/releases/tag/0.6.2
2026-08-24 15:02:18 +02:00
Fabian Affolter
a276ae0a21 python3Packages.testresources: 2.0.2 -> 2.1.2 2026-08-24 14:56:05 +02:00
Fabian Affolter
e4243618e5 python3Packages.testfixtures: 10.0.0 -> 12.3.0
Changelog: https://github.com/simplistix/testfixtures/blob/12.3.0/CHANGELOG.rst
2026-08-24 14:52:30 +02:00
Fabian Affolter
63566738ae python3Packages.typeguard: 4.5.2 -> 4.6.0
Changelog: https://github.com/agronholm/typeguard/releases/tag/4.6.0
2026-08-24 14:11:47 +02:00
Fabian Affolter
9362859ce4 python3Packages.regex: 2026.7.11 -> 2026.8.12 2026-08-24 14:09:00 +02:00
Fabian Affolter
0f3cfe4f81 python3Packages.syrupy: 5.5.3 -> 6.0.0
Diff: https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0

Changelog: https://github.com/syrupy-project/syrupy/blob/v6.0.0/CHANGELOG.md
2026-08-24 14:05:07 +02:00
Fabian Affolter
25ae24bb9b python3Packages.htmltools: 0.6.1 -> 0.7.0
Diff: https://github.com/posit-dev/py-htmltools/compare/v0.6.1...v0.7.0

Changelog: https://github.com/posit-dev/py-htmltools/blob/refs/tags/v0.7.0/CHANGELOG.md
2026-08-24 13:58:13 +02:00
Fabian Affolter
5c0064324e python3Packages.httpbin: 0.10.2 -> 0.10.4 2026-08-24 13:56:53 +02:00
Fabian Affolter
2481a68a59 python3Packages.h2: 4.3.0 -> 4.4.1
Diff: https://github.com/python-hyper/h2/compare/v4.3.0...v4.4.1

Changelog: https://github.com/python-hyper/h2/blob/v4.4.1/CHANGELOG.rst
2026-08-24 13:55:28 +02:00
Fabian Affolter
2a85e1db6c python3Packages.httpcore2: 2.9.1 -> 2.12.0
Changelog: https://github.com/pydantic/httpx2/blob/v2.12.0/src/httpcore2/CHANGELOG.md
2026-08-24 13:55:14 +02:00
Fabian Affolter
29a5aa357c python3Packages.uv-dynamic-versioning: 0.13.0 -> 0.14.1
Changelog: https://github.com/ninoseki/uv-dynamic-versioning/releases/tag/v0.14.1
2026-08-24 13:55:05 +02:00
Fabian Affolter
b195596045 python3Packages.dunamai: 1.25.0 -> 1.26.2
Diff: https://github.com/mtkennerly/dunamai/compare/v1.25.0...v1.26.2

Changelog: https://github.com/mtkennerly/dunamai/blob/v1.26.2/CHANGELOG.md
2026-08-24 13:54:59 +02:00
Fabian Affolter
94846c88fb python3Packages.jsonargparse: 4.50.0 -> 4.51.0
Diff: https://github.com/omni-us/jsonargparse/compare/v4.50.0...v4.51.0

Changelog: https://github.com/omni-us/jsonargparse/blob/v4.51.0/CHANGELOG.rst
2026-08-24 13:47:58 +02:00
Fabian Affolter
54022c9502 python3Packages.hypothesis: 6.156.1 -> 6.165.10
Diff: https://github.com/HypothesisWorks/hypothesis/compare/v6.156.1...v6.165.10

Changelog: https://hypothesis.readthedocs.io/en/latest/changes.html#v6-165-10
2026-08-24 12:55:02 +02:00
Fabian Affolter
475a60b7d5 python3Packages.maxminddb: 3.0.0 -> 3.1.1
Changelog: https://github.com/maxmind/MaxMind-DB-Reader-python/blob/v3.1.1/HISTORY.rst
2026-08-24 12:52:16 +02:00
Fabian Affolter
6e837cd77c python3Packages.trio: migrate to finalAttrs 2026-08-24 12:24:02 +02:00
Fabian Affolter
9a2f606c8d python3Packages.trio: jedi has support for Python 3.14 2026-08-24 12:22:44 +02:00
Fabian Affolter
70df608e3b python3Packages.trio: 0.33.0 -> 0.34.0
Diff: https://github.com/python-trio/trio/compare/v0.33.0...v0.34.0

Changelog: https://github.com/python-trio/trio/blob/v0.34.0/docs/source/history.rst
2026-08-24 12:17:57 +02:00
Fabian Affolter
bfd2076960 python3Packages.pytest-benchmark: 5.2.3 -> 5.3.0
Changelog: https://github.com/ionelmc/pytest-benchmark/blob/v5.3.0/CHANGELOG.rst
2026-08-24 12:08:38 +02:00
Fabian Affolter
b3741499c4 python3Packages.py-cpuinfo2: init at 10.0.1
Module for getting CPU info with pure Python

https://github.com/akx/py-cpuinfo2
2026-08-24 12:01:47 +02:00
Fabian Affolter
b1f7cfc432 python3Packages.pytest-benchmark: migrate to finalAttrs 2026-08-24 11:50:23 +02:00
Fabian Affolter
a9ab24dcfd python3Packages.humanize: 4.15.0 -> 4.16.0
Changelog: https://github.com/python-humanize/humanize/releases/tag/4.16.0
2026-08-24 11:05:43 +02:00
Fabian Affolter
8266a99042 python3Packages.jsonschema-rs: 0.46.5 -> 0.51.0
Changelog: https://github.com/Stranger6667/jsonschema/blob/python-v0.51.0/crates/jsonschema-py/CHANGELOG.md
2026-08-24 10:52:41 +02:00
Fabian Affolter
b0c27a86e1 python3Packages.lxml-html-clean: 0.4.4 -> 0.4.5
Diff: https://github.com/fedora-python/lxml_html_clean/compare/0.4.4...0.4.5

Changelog: https://github.com/fedora-python/lxml_html_clean/blob/0.4.5/CHANGES.rst
2026-08-24 10:49:26 +02:00
Fabian Affolter
49476baf49 python3Packages.soundfile: modernize
- add missing input
- migrate to finalAttrs
2026-08-24 10:46:54 +02:00
Fabian Affolter
489ac8d8f7 python3Packages.rarfile: modernize 2026-08-24 10:41:00 +02:00
Fabian Affolter
6cdf08861c python3Packages.rarfile: 4.2 -> 4.5
Diff: https://github.com/markokr/rarfile/compare/v4.2...v4.5

Changelog: https://github.com/markokr/rarfile/releases/tag/v4.5
2026-08-24 10:33:36 +02:00
Fabian Affolter
08994be3c7 python3Packages.pyzmq: migrate to finalAttrs 2026-08-24 10:32:31 +02:00
Fabian Affolter
ffe2e13bad python3Packages.pyzmq: 27.1.0 -> 27.2.0 2026-08-24 10:30:33 +02:00
Fabian Affolter
77f0199bcc python3Packages.prompt-toolkit: 3.0.52 -> 3.0.53
Diff: https://github.com/prompt-toolkit/python-prompt-toolkit/compare/3.0.52...3.0.53

Changelog: https://github.com/prompt-toolkit/python-prompt-toolkit/releases/tag/3.0.53
2026-08-24 10:25:35 +02:00
Fabian Affolter
ad2f178027 python3Packages.phonenumbers: 9.0.34 -> 9.0.37
Changelog: https://github.com/daviddrysdale/python-phonenumbers/blob/v9.0.37/python/HISTORY.md
2026-08-24 10:04:11 +02:00
Fabian Affolter
214edf7b8c python3Packages.autobahn: 25.12.2 -> 26.7.1
Changelog: https://github.com/crossbario/autobahn-python/blob/v26.7.1/docs/changelog.rst
2026-08-24 09:43:54 +02:00
Fabian Affolter
880c342134 python3Packages.websockets: 16.1 -> 17.0.1
Changelog: https://github.com/aaugustin/websockets/blob/17.0.1/docs/project/changelog.rst
2026-08-24 09:34:09 +02:00
Fabian Affolter
2bb81d73ef python3Packages.sybil: migrate to finalAttrs 2026-08-24 09:30:06 +02:00
Fabian Affolter
48cf1eb80f python3Packages.sybil: 9.3.0 -> 10.1.0
Changelog: https://github.com/simplistix/sybil/blob/10.1.0/CHANGELOG.rst
2026-08-24 09:30:06 +02:00
Fabian Affolter
7d4f096a7b python3Packages.gevent: 26.5.0 -> 26.8.0 2026-08-24 09:30:06 +02:00
Fabian Affolter
0935c8e495 python3Packages.cffi: migrate to finalAttrs 2026-08-24 09:30:06 +02:00
Fabian Affolter
930c8e9e26 python3Packages.cffi: 2.1.0 -> 2.1.1
Diff: https://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1

Changelog: https://github.com/python-cffi/cffi/releases/tag/v2.1.1
2026-08-24 09:30:05 +02:00
Michael Daniels
7d5dbca098 python3Packages.mkdocs-embed-file-plugin: unbreak by adding pyprojectVersionPatchHook (#555811) 2026-08-23 14:24:04 -04:00
Ryan Omasta
9d44cfba88 python3Packages.pymdown-extensions: 11.0.1 -> 11.0.2 (#555556)
https://github.com/facelessuser/pymdown-extensions/releases/tag/11.0.2
Diff: https://github.com/facelessuser/pymdown-extensions/compare/11.0.1...11.0.2
2026-08-23 13:55:55 -04:00
Michael Daniels
84969077c1 python3Packages.rich: fix compat with pygments 2.21.0 (#555486)
See https://github.com/Textualize/rich/issues/4209
2026-08-23 00:02:24 -04:00
Michael Daniels
642695ad83 python3Packages.sphinx: fix compat with pygments 2.21.0 (#555485)
See https://github.com/sphinx-doc/sphinx/pull/14611
2026-08-23 00:02:23 -04:00
Ryan Omasta
4ad3307df7 python3Packages.mako: fix compat with pygments 2.21.0 (#555561) 2026-08-22 23:28:08 -04:00
Fabian Affolter
18677e9005 fixup! python3Packages.argcomplete: 3.6.3 -> 3.7.2 2026-08-22 02:16:54 +02:00
Fabian Affolter
26f6991cfc python3Packages.asteval: 1.0.9 -> 1.0.10
Diff: https://github.com/lmfit/asteval/compare/1.0.9...1.0.10

Changelog: https://github.com/lmfit/asteval/releases/tag/1.0.10
2026-08-22 01:54:30 +02:00
Fabian Affolter
418eb2c39d python3Packages.django-types: 0.22.0 -> 0.24.0
Changelog: https://github.com/sbdchd/django-types/blob/main/CHANGELOG.md
2026-08-22 01:51:11 +02:00
Fabian Affolter
4fb106f289 python3Packages.types-webencodings: 0.5.0.20260408 -> 0.6.0.20260821 2026-08-22 01:48:01 +02:00
Fabian Affolter
52397d834f python3Packages.types-setuptools: 80.9.0.20251223 -> 84.0.0.20260812 2026-08-22 01:47:12 +02:00
Fabian Affolter
bf398265a0 python3Packages.types-requests: 2.32.4.20260107 -> 2.33.0.20260712 2026-08-22 01:46:57 +02:00
Fabian Affolter
19e416de15 python3Packages.types-pyyaml: 6.0.12.20250915 -> 6.0.12.20260815 2026-08-22 01:46:41 +02:00
Fabian Affolter
eb901e94ce python3Packages.types-pytz: 2026.1.1.20260304 -> 2026.3.1.20260727 2026-08-22 01:46:27 +02:00
Fabian Affolter
71d4a58a41 python3Packages.types-python-dateutil: 2.9.0.20251115 -> 2.9.0.20260807 2026-08-22 01:46:13 +02:00
Fabian Affolter
01723ab80a python3Packages.types-psycopg2: 2.9.21.20251012 -> 2.9.21.20260724 2026-08-22 01:45:54 +02:00
Fabian Affolter
5925682b6f python3Packages.types-psutil: 7.2.1.20260116 -> 7.2.2.20260518 2026-08-22 01:42:01 +02:00
Fabian Affolter
1f97a2fd4a python3Packages.types-docutils: 0.22.3.20260712 -> 0.22.3.20260724 2026-08-22 01:36:56 +02:00
Fabian Affolter
2e96796e37 python3Packages.types-deprecated: 1.3.1.20260520 -> 1.3.1.20260728 2026-08-22 01:36:41 +02:00
Fabian Affolter
97597dff04 python3Packages.sse-starlette: migrate to finalAttrs 2026-08-22 00:48:55 +02:00
Fabian Affolter
b56a009699 python3Packages.sse-starlette: 3.2.0 -> 3.4.5
Diff: https://github.com/sysid/sse-starlette/compare/v3.2.0...v3.4.5

Changelog: https://github.com/sysid/sse-starlette/blob/v3.4.5/CHANGELOG.md
2026-08-22 00:48:55 +02:00
Fabian Affolter
7a7f5fc993 python3Packages.platformdirs: migrate to finalAttrs 2026-08-21 09:12:16 +02:00
Fabian Affolter
f3c2483e0a python3Packages.platformdirs: 4.10.0 -> 4.11.3
Diff: https://github.com/tox-dev/platformdirs/compare/4.10.0...4.11.3

Changelog: https://github.com/tox-dev/platformdirs/releases/tag/4.11.3
2026-08-21 09:08:34 +02:00
Fabian Affolter
a68bcae7ee python3Packages.tuf: 6.0.0 -> 7.0.0
Diff: https://github.com/theupdateframework/python-tuf/compare/v6.0.0...v7.0.0

Changelog: https://github.com/theupdateframework/python-tuf/blob/v7.0.0/docs/CHANGELOG.md
2026-08-20 11:13:51 +02:00
Fabian Affolter
9e685a1586 python3Packages.mako: 1.3.12 -> 1.4.1
Changelog: https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_1
2026-08-20 01:01:29 +02:00
Fabian Affolter
fb1b7e0c3e python3Packages.orjson: 3.11.9 -> 3.12.0
Diff: https://github.com/ijl/orjson/compare/3.11.9...3.12.0

Changelog: https://github.com/ijl/orjson/blob/3.12.0/CHANGELOG.md
2026-08-20 00:41:21 +02:00
Fabian Affolter
a795a02721 python3Packages.marshmallow: 4.3.0 -> 4.3.1
Diff: https://github.com/marshmallow-code/marshmallow/compare/4.3.0...4.3.1

Changelog: https://github.com/marshmallow-code/marshmallow/blob/4.3.1/CHANGELOG.rst
2026-08-20 00:32:25 +02:00
Fabian Affolter
03820fd8ab python3Packages.click: 8.3.3 -> 8.4.2
Diff: https://github.com/pallets/click/compare/8.3.3...8.4.2

Changelog: https://github.com/pallets/click/blob/8.4.2/CHANGES.rst
2026-08-20 00:10:21 +02:00
Fabian Affolter
c74a434f78 python3Packages.certifi: 2026.06.17 -> 2026.07.22
Diff: https://github.com/certifi/python-certifi/compare/2026.06.17...2026.07.22
2026-08-20 00:01:36 +02:00
Fabian Affolter
01f25a11a1 python3Packages.cbor2: 6.1.3 -> 6.1.4
Diff: https://github.com/agronholm/cbor2/compare/6.1.3...6.1.4

Changelog: https://github.com/agronholm/cbor2/releases/tag/6.1.4
2026-08-19 23:59:02 +02:00
Fabian Affolter
675324c7eb python3Packages.airportsdata: 20251008 -> 20260803
Diff: https://github.com/mborsetti/airportsdata/compare/v20251008...v20260803

Changelog: https://github.com/mborsetti/airportsdata/releases/tag/v20260803
2026-08-19 23:54:19 +02:00
Fabian Affolter
bdd1e3b62f python3Packages.argcomplete: 3.6.3 -> 3.7.2
Diff: https://github.com/kislyuk/argcomplete/compare/v3.6.3...v3.7.2

Changelog: https://github.com/kislyuk/argcomplete/blob/v3.7.2/Changes.rst
2026-08-19 23:53:26 +02:00
Fabian Affolter
0a4e563665 python3Packages.cachetools: 7.1.4 -> 7.1.7
Diff: https://github.com/tkem/cachetools/compare/v7.1.4...v7.1.7

Changelog: https://github.com/tkem/cachetools/blob/v7.1.7/CHANGELOG.rst
2026-08-19 20:56:05 +02:00
Fabian Affolter
570eb566b4 python3Packages.pytest-httpserver: 1.1.3 -> 1.1.5
Diff: https://github.com/csernazs/pytest-httpserver/compare/1.1.3...1.1.5

Changelog: https://github.com/csernazs/pytest-httpserver/blob/1.1.5/CHANGES.rst
2026-08-19 20:50:25 +02:00
Fabian Affolter
72a971ab03 python313Packages.id: migrate to finalAttrs 2026-08-19 20:42:24 +02:00
Fabian Affolter
8d7caaea50 python313Packages.id: 1.5.0 -> 1.6.1
Diff: https://github.com/di/id/compare/v1.5.0...v1.6.1

Changelog: https://github.com/di/id/blob/1.6.1/CHANGELOG.md
2026-08-19 20:42:24 +02:00
Fabian Affolter
7db9c7ebeb python3Packages.debtcollector: 3.0.0 -> 3.1.0 2026-08-19 20:41:20 +02:00
Fabian Affolter
fbd0a0633c python3Packages.wrapt: 1.17.2 -> 2.1.2
Changelog: https://github.com/GrahamDumpleton/wrapt/releases/tag/2.1.2
2026-08-19 20:41:20 +02:00
Fabian Affolter
60ce0f7db6 python3Packages.brotlicffi: 1.2.0.0 -> 1.2.0.1
Diff: https://github.com/python-hyper/brotlicffi/compare/v1.2.0.0...v1.2.0.1

Changelog: https://github.com/python-hyper/brotlicffi/blob/v1.2.0.1/HISTORY.rst
2026-08-19 20:34:30 +02:00
Fabian Affolter
8e5cbfaf7b python3Packages.readme-renderer: migrate to finalAttrs 2026-08-19 20:33:34 +02:00
Fabian Affolter
ed06a13e39 python3Packages.readme-renderer: 44.0 -> 45.0
Changelog: https://github.com/pypa/readme_renderer/releases/tag/45.0
2026-08-19 20:33:34 +02:00
Fabian Affolter
21b180eb4b python3Packages.sentry-sdk: 2.66.0 -> 2.67.1
Diff: https://github.com/getsentry/sentry-python/compare/2.66.0...2.67.1

Changelog: https://github.com/getsentry/sentry-python/blob/2.67.1/CHANGELOG.md
2026-08-19 20:32:47 +02:00
Fabian Affolter
64bf2cc093 python3Packages.json5: migrate to finalAttrs 2026-08-19 20:32:29 +02:00
Fabian Affolter
0ee5d59d1f python3Packages.json5: 0.13.0 -> 0.15.0
Diff: https://github.com/dpranke/pyjson5/compare/v0.13.0...v0.15.0

Changelog: https://github.com/dpranke/pyjson5/releases/tag/v0.15.0
2026-08-19 20:32:29 +02:00
Fabian Affolter
729fcd8f10 python3Packages.oras: 0.2.42 -> 0.2.43
Diff: https://github.com/oras-project/oras-py/compare/0.2.42...0.2.43

Changelog: https://github.com/oras-project/oras-py/blob/0.2.43/CHANGELOG.md
2026-08-19 20:31:50 +02:00
Fabian Affolter
6db1e0933c python3Packages.jwcrypto: 1.5.6 -> 1.5.8
Changelog: https://github.com/latchset/jwcrypto/releases/tag/1.5.8
2026-08-19 20:31:20 +02:00
Fabian Affolter
6dc31cd4da python3Packages.joserfc: migrate to finalAttrs 2026-08-19 20:29:41 +02:00
Fabian Affolter
5f30573fb4 python3Packages.joserfc: 1.6.9 -> 1.7.4
Diff: https://github.com/authlib/joserfc/compare/1.6.9...1.7.4

Changelog: https://github.com/authlib/joserfc/blob/1.7.4/docs/changelog.rst
2026-08-19 20:29:40 +02:00
Fabian Affolter
0c2e350997 python3Packages.charset-normalizer: 3.4.9 -> 3.5.1
Changelog: https://github.com/jawah/charset_normalizer/blob/3.5.1/CHANGELOG.md
2026-08-19 20:28:48 +02:00
dotlambda
fcef5e359b python3Packages.shtab: 1.9.2 -> 1.11.0 (#553026) 2026-08-19 03:50:59 -07:00
dotlambda
df3ff49869 python3Packages.anyio: Fetch patch for test_keyboard_interrupt_does_not_resume_test timeout (#553146) 2026-08-18 19:13:28 -07:00
Robert Schütz
1c04b95b22 python3Packages.uv-dynamic-versioning: add gitMinimal to nativeCheckInputs
This wasn't needed before because gitpython previously propagated it.
2026-08-18 19:03:53 -07:00
Michael Daniels
c6065371e2 python3Packages.shtab: use versionCheckHook 2026-08-18 17:15:54 -04:00
Michael Daniels
5df83b898c python3Packages.shtab: install completions for shtab command
Co-authored-by: dotlambda <github@dotlambda.de>
2026-08-18 17:15:48 -04:00
Ryan Omasta
eab3108172 python3Packages.pygments: 2.20.0 -> 2.21.0
https://github.com/pygments/pygments/releases/tag/2.21.0
Diff: https://github.com/pygments/pygments/compare/2.20.0...2.21.0
2026-08-18 22:14:12 +02:00
dotlambda
d6fdead0f3 python3Packages.tqdm: 4.68.4 -> 4.70.0 (#554032) 2026-08-18 12:44:34 -07:00
Robert Schütz
4808572dcf python3Packages.tqdm: 4.68.4 -> 4.70.0
Diff: https://github.com/tqdm/tqdm/compare/v4.68.4...v4.70.0

Changelog: https://tqdm.github.io/releases/
2026-08-18 12:32:03 -07:00
dotlambda
0b59eab01f python3Packages.buildPythonPackage: default to __structuredAttrs = true (#543976) 2026-08-18 12:24:00 -07:00
dotlambda
3103284e5a python3Packages.pytest-rerunfailures: 16.3 → 16.4 (#538766) 2026-08-18 12:18:13 -07:00
dotlambda
85e756065e python3Packages.vulture: 2.14 -> 2.16 (#538412) 2026-08-18 12:17:12 -07:00
dotlambda
72422068fd python3Packages.distutils: use standard zlib (#536823) 2026-08-18 12:15:17 -07:00
dotlambda
8c3cd1a2c2 python3Packages.libcst: 1.8.6 -> 1.9.0 (#547519) 2026-08-18 12:08:19 -07:00
dotlambda
9d00d91c87 python3Packages.redis: 8.0.1 -> 8.1.0 (#547590) 2026-08-18 12:08:08 -07:00
dotlambda
f2a5ca8a20 python3Packages.pikepdf: 10.10.0 -> 10.11.0 (#547824) 2026-08-18 12:07:59 -07:00
dotlambda
c9638bd7c9 python3Packages.markdown: 3.10.2 -> 3.10.3 (#547860) 2026-08-18 12:07:54 -07:00
dotlambda
b573b7b695 python3Packages.faust-cchardet: 2.1.20 -> 2.2.1 (#548451) 2026-08-18 12:07:49 -07:00
dotlambda
c6fce33b87 python3Packages.pydantic-settings: 2.12.0 -> 2.14.2 (#548921) 2026-08-18 12:07:41 -07:00
dotlambda
ebc38fa795 python3Packages.gitpython: don't propagate gitMinimal (#549279) 2026-08-18 12:07:29 -07:00
dotlambda
a1a232b471 mpython3Packages.pybind11: 3.0.4 -> 3.1.0 (#550949) 2026-08-18 12:07:23 -07:00
dotlambda
9522bf9d6c python3Packages.pytest-forked: 1.6.0 -> 1.7.5 (#551671) 2026-08-18 12:07:20 -07:00
dotlambda
564da11dd4 python313Packages.backports-zstd: 1.6.0 -> 1.7.0 (#553363) 2026-08-18 12:07:13 -07:00
dotlambda
ef0f2bf210 python3Packages.libvalkey: 4.0.1 -> 4.1.0 (#553371) 2026-08-18 12:07:04 -07:00
dotlambda
52a58e6465 python3Packages.tomlkit: 0.15.0 -> 0.15.1 (#547205) 2026-08-18 12:06:45 -07:00
dotlambda
b59a36d874 python3Packages.pythonMetadataCheckHook: improve (#546373) 2026-08-18 12:06:37 -07:00
Robert Schütz
9d99444486 python3Packages.buildPythonPackage: default to __structuredAttrs = true 2026-08-18 12:06:07 -07:00
Robert Schütz
a910fbf5ed python3Packages.libvalkey: 4.0.1 -> 4.1.0
Diff: https://github.com/valkey-io/libvalkey-py/compare/v4.0.1...v4.1.0

Changelog: https://github.com/valkey-io/libvalkey-py/releases/tag/v4.1.0
2026-08-16 09:37:42 -07:00
Robert Schütz
62b5ec0cef python313Packages.backports-zstd: 1.6.0 -> 1.7.0
Diff: https://github.com/rogdham/backports.zstd/compare/v1.6.0...v1.7.0

Changelog: https://github.com/rogdham/backports.zstd/blob/v1.7.0/CHANGELOG.md
2026-08-16 09:06:47 -07:00
Michael Daniels
f5073d3a8a python3Packages.shtab: test with fish and zsh too 2026-08-15 21:52:31 -04:00
Michael Daniels
a084ca2557 python3Packages.shtab: remove unused pytest-timeout dep 2026-08-15 21:52:31 -04:00
Michael Daniels
ae380da2fc python3Packages.shtab: 1.9.2 -> 1.11.0
Diff: https://github.com/tqdm/shtab/compare/v1.9.2...v1.11.0

Release note for v1.9.3: https://github.com/tqdm/shtab/releases/tag/v1.9.3
Release note for v1.10.0: https://github.com/tqdm/shtab/releases/tag/v1.10.0
Release note for v1.11.0: https://github.com/tqdm/shtab/releases/tag/v1.11.0
2026-08-15 21:51:57 -04:00
OPNA2608
27f0b4544f python3Packages.anyio: Fetch patch for test_keyboard_interrupt_does_not_resume_test timeout 2026-08-16 00:56:18 +02:00
Robert Schütz
30d64aed75 python3Packages.pytest-forked: 1.6.0 -> 1.7.5
Diff: https://github.com/pytest-dev/pytest-forked/compare/v1.6.0...v1.7.5

Changelog: https://github.com/pytest-dev/pytest-forked/blob/refs/tags/v1.7.5/CHANGELOG.rst
2026-08-11 16:35:24 -07:00
Robert Schütz
313c73971c python3Packages.pybind11: 3.0.4 -> 3.1.0
Diff: https://github.com/pybind/pybind11/compare/v3.0.4...v3.1.0

Changelog: https://github.com/pybind/pybind11/blob/v3.1.0/docs/changelog.md
2026-08-09 16:48:39 -07:00
Robert Schütz
7f5d8d1888 python3Packages.gitpython: don't propagate gitMinimal 2026-08-04 13:22:33 -07:00
Robert Schütz
10705c93fd python3Packages.pydantic-settings: 2.12.0 -> 2.14.2
Diff: https://github.com/pydantic/pydantic-settings/compare/v2.12.0...v2.14.2
2026-08-03 13:40:22 -07:00
Robert Schütz
4899257e7a python3Packages.faust-cchardet: 2.1.20 -> 2.2.1
Diff: https://github.com/faust-streaming/cChardet/compare/v2.1.20...v2.2.1

Changelog: https://github.com/faust-streaming/cChardet/blob/v2.2.1/CHANGES.rst
2026-08-02 08:19:54 -07:00
Robert Schütz
38691da286 python3Packages.markdown: use finalAttrs 2026-07-31 11:21:52 -07:00
Robert Schütz
36d4dc7578 python3Packages.markdown: 3.10.2 -> 3.10.3
Diff: https://github.com/Python-Markdown/markdown/compare/3.10.2...3.10.3

Changelog: https://github.com/Python-Markdown/markdown/blob/3.10.3/docs/changelog.md
2026-07-31 11:20:43 -07:00
Robert Schütz
0fe60f516e python3Packages.pikepdf: 10.10.0 -> 10.11.0
Diff: https://github.com/pikepdf/pikepdf/compare/v10.10.0...v10.11.0

Changelog: https://github.com/pikepdf/pikepdf/blob/v10.11.0/docs/releasenotes/version10.md
2026-07-31 09:45:01 -07:00
Robert Schütz
1df6920fa9 python3Packages.fakeredis: 2.36.2 -> 2.37.0
Diff: https://github.com/cunla/fakeredis-py/compare/v2.36.2...v2.37.0

Changelog: https://github.com/cunla/fakeredis-py/releases/tag/v2.37.0
2026-07-30 16:57:20 -07:00
Robert Schütz
6f9e207dc9 python3Packages.redis: 8.0.1 -> 8.1.0
Diff: https://github.com/redis/redis-py/compare/v8.0.1...v8.1.0

Changelog: https://github.com/redis/redis-py/releases/tag/v8.1.0
2026-07-30 16:57:20 -07:00
Robert Schütz
a79457f0e9 python3Packages.libcst: 1.8.6 -> 1.9.0
Diff: https://github.com/Instagram/LibCST/compare/v1.8.6...v1.9.0

Changelog: https://github.com/Instagram/LibCST/blob/v1.9.0/CHANGELOG.md
2026-07-30 13:12:02 -07:00
Robert Schütz
13d2ccfaaf python3Packages.tomlkit: 0.15.0 -> 0.15.1
Diff: https://github.com/python-poetry/tomlkit/compare/0.15.0...0.15.1

Changelog: https://github.com/python-poetry/tomlkit/blob/0.15.1/CHANGELOG.md
2026-07-29 13:46:21 -07:00
Robert Schütz
6612bf03f4 python3Packages.pythonMetadataCheckHook: skip only version comparison for unstable version
This way we still compare the pname to the name in METADATA.
2026-07-27 14:10:08 -07:00
Robert Schütz
b40c514e9a python3Packages.pythonMetadataCheckHook: rewrite comparison in Python 2026-07-27 14:10:07 -07:00
Robert Schütz
d3731cb537 python3Packages.pythonMetadataCheckHook: improve error message for mismatched pname 2026-07-27 13:47:57 -07:00
Raphael Borun Das Gupta
3bb433eb16 python3Packages.pytest-rerunfailures: 16.3 → 16.4
upstream diff: https://github.com/pytest-dev/pytest-rerunfailures/compare/16.3...16.4

upstream changelog: https://github.com/pytest-dev/pytest-rerunfailures/blob/16.4/CHANGES.rst#164-2026-07-01
2026-07-05 21:53:44 +02:00
Fabian Affolter
dd909fe254 python3Packages.vulture: migrate to finalAttrs 2026-07-04 17:38:10 +02:00
Fabian Affolter
bdd04fd7e8 python3Packages.vulture: 2.14 -> 2.16
Changelog: https://github.com/jendrikseipp/vulture/releases/tag/v2.16
2026-07-04 17:31:31 +02:00
Elliot Cameron
afd722eb9e python3Packages.distutils: use standard zlib
Use standard zlib instead instead of sortix libz. Python itself depends
on zlib so this dependency added a *different* version of the "z"
library to the closures of all Python packages dependeng on distutils.
2026-06-29 18:19:42 -04:00
2504 changed files with 27024 additions and 41899 deletions

View File

@@ -79,7 +79,7 @@ indent_size = unset
trim_trailing_whitespace = true
# binaries
[*.{nib,torrent}]
[*.nib]
end_of_line = unset
insert_final_newline = unset
trim_trailing_whitespace = unset

3
.gitattributes vendored
View File

@@ -62,6 +62,3 @@ ci/OWNERS linguist-language=CODEOWNERS
# patching CRLF line endings from an upstream source package.
*.diff !text !eol
*.patch !text !eol
# Torrent files are binary files and should not be re-encoded.
*.torrent !text !eol

View File

@@ -59,7 +59,7 @@ jobs:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
target-as-trusted-at: ${{ inputs.targetSha }}
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
with:
# Sandbox is disabled on MacOS by default.
extra_nix_config: sandbox = true

View File

@@ -134,35 +134,6 @@ jobs:
GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }}
run: gh api /rate_limit | jq
github-script:
runs-on: ubuntu-24.04-arm
timeout-minutes: 5
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
sparse-checkout: .github/actions
- name: Checkout merge and target commits
uses: ./.github/actions/checkout
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
target-as-trusted-at: ${{ inputs.targetSha }}
- name: Install dependencies to trusted/
run: |
npm ci --package-lock-only=false
echo "$PWD/node_modules/.bin" >> "$GITHUB_PATH"
working-directory: nixpkgs/trusted/ci/github-script
- name: Link trusted/ dependencies to untrusted/
run: ln -s "$PWD/trusted/ci/github-script/node_modules" untrusted/ci/github-script/node_modules
working-directory: nixpkgs
- name: Type-check ci/github-script
run: tsc --build
working-directory: nixpkgs/untrusted/ci/github-script
owners:
runs-on: ubuntu-24.04-arm
timeout-minutes: 5
@@ -171,14 +142,13 @@ jobs:
with:
persist-credentials: false
sparse-checkout: .github/actions
- name: Checkout merge and target commits
uses: ./.github/actions/checkout
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
target-as-trusted-at: ${{ inputs.targetSha }}
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
continue-on-error: true

View File

@@ -139,7 +139,7 @@ jobs:
core.info(`Found pinned.json commit: ${ciPinBumpCommit}`)
- name: Install Nix
uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
- name: Load supported versions
id: versions
@@ -187,7 +187,7 @@ jobs:
target-as-trusted-at: ${{ inputs.targetSha }}
- name: Install Nix
uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
continue-on-error: true
@@ -277,7 +277,7 @@ jobs:
merge-multiple: true
- name: Install Nix
uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
- name: Combine all output paths and eval stats
run: |
@@ -486,7 +486,7 @@ jobs:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
- name: Install Nix
uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
- name: Ensure flake outputs on all systems still evaluate
run: nix flake check --all-systems --no-build './nixpkgs/untrusted?shallow=1'

View File

@@ -35,7 +35,7 @@ jobs:
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
# TODO: Figure out how to best enable caching for the treefmt job. Cachix won't work well,
# because the cache would be invalidated on every commit - treefmt checks every file.
@@ -70,7 +70,7 @@ jobs:
with:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
continue-on-error: true
@@ -100,7 +100,7 @@ jobs:
merged-as-untrusted-at: ${{ inputs.mergedSha }}
target-as-trusted-at: ${{ inputs.targetSha }}
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
continue-on-error: true

View File

@@ -6,7 +6,6 @@ Christina Sørensen <christina@cafkafk.com> <christinaafk@gmail.com>
Christina Sørensen <christina@cafkafk.com> <89321978+cafkafk@users.noreply.github.com>
Daniel Løvbrøtte Olsen <me@dandellion.xyz> <daniel.olsen99@gmail.com>
Ethan Carter Edwards <ethan@ethancedwards.com> Ethan Edwards <ethancarteredwards@gmail.com>
Ethan Carter Edwards <ethan@ethancedwards.com> <ethancedwards8@users.noreply.github.com>
Fabian Affolter <mail@fabian-affolter.ch> <fabian@affolter-engineering.ch>
Fiona Behrens <me@kloenk.dev>
Fiona Behrens <me@kloenk.dev> <me@kloenk.de>

View File

@@ -957,6 +957,7 @@ The following situations are fully or partially exempt:
If you believe that someone is using automation without appropriate disclosure and review, you can politely ask them if thats the case and point them to this policy as appropriate.
Please assume good faith and remain civil; its not always possible to determine, and it is more likely that someone overlooked this policy than deliberately violated it.
If you think someone is continuing to break the policy after this, please escalate to the [Nixpkgs core team](https://nixos.org/community/teams/nixpkgs-core/) rather than fighting over it.
If a contribution is clearly in violation of the policy (e.g. the contributor admits it was not followed, or there are AI tool attributions that do not meet our required format), it can be closed or hidden, preferably after informing the contributor of the policy and giving them a chance to address the violations.
Deliberate violations of this policy are considered to break the [Code of Conduct](https://github.com/NixOS/.github/blob/master/CODE_OF_CONDUCT.md) clause against “Wasting other peoples time with low quality contributions, including but not limited to LLM and bot spam”.

View File

@@ -361,10 +361,7 @@ pkgs/development/python-modules/buildcatrust/ @ajs124 @lukegb @mweinelt
/pkgs/applications/editors/kakoune @philiptaron
# LuaPackages
/pkgs/development/interpreters/lua-5 @NixOS/lua
/pkgs/development/interpreters/luajit @NixOS/lua
/pkgs/development/lua-modules @NixOS/lua
/pkgs/top-level/lua-packages.nix @NixOS/lua
# Neovim
/pkgs/applications/editors/neovim @NixOS/neovim

View File

@@ -2,4 +2,3 @@ comparison
comparison.zip
node_modules
step-summary.md
*.tsbuildinfo

View File

@@ -988,20 +988,6 @@ fetchRadiclePatch {
}
```
## `fetchFromTangled` {#fetchfromtangled}
This is to be used with tangled repositories. `fetchFromTangled` works with
very similar arguments to `fetchFromGithub`. However, instead of a `owner` and
`repo`, a `did` argument is expected.
```nix
fetchFromTangled {
did = "did:plc:jj6ajj6duxnlthwtnob4qyuv"; # tranquil.farm/tranquil-pds
tag = "v6.6.0";
hash = "sha256-cfTsjmK/IMqT5kMKOGpwwWbBlvtrCDOerUJJ8AVI3kY=";
}
```
## `requireFile` {#requirefile}
`requireFile` allows requesting files that cannot be fetched automatically, but whose content is known.

3
doc/hooks/ghc.section.md Normal file
View File

@@ -0,0 +1,3 @@
# GHC {#ghc}
Creates a temporary package database and registers every Haskell build input in it (TODO: how?).

View File

@@ -17,6 +17,7 @@ check-phase-thread-limit-hook.section.md
cmake.section.md
desktop-file-utils.section.md
gdk-pixbuf.section.md
ghc.section.md
gnome.section.md
haredo.section.md
installShellFiles.section.md

View File

@@ -34,21 +34,17 @@ Inside each package set are:
- builders: mixRelease, buildRebar3, etc
- hooks: for composing builders and packages
The package set is the only place Erlang and Elixir versions are chosen. Builders such as `mixRelease`, `fetchMixDeps` and `buildMix` take them from the set they are called from, and do not accept `erlang`, `elixir` or `hex` arguments.
To use a non-default Elixir, derive a new set with `overrideScope`. This keeps the rest of the set consistent, so every builder picks up the overridden Elixir:
To use a non-default Elixir it's important to keep the rest of the package set consistent, so it's recommended to use `.extend`. This ensures that builders like `mixRelease`, `fetchMixDeps`, and `buildMix` all pick up the overridden Elixir:
```nix
let
beamPackages = beam27Packages.overrideScope (final: prev: { elixir = final.elixir_1_18; });
beamPackages = beam27Packages.extend (self: super: { elixir = self.elixir_1_18; });
in
beamPackages.mixRelease {
# ...
}
```
`erlang` can be replaced the same way, which is useful for a patched OTP. Every member of the set is built from the set's own `erlang`, so overriding it rebuilds Elixir, Rebar3 and the rest against it.
## Build Tools {#beam-build-tools}
### Rebar3 {#beam-build-tools-rebar3}
@@ -336,8 +332,8 @@ Usually, we need to create a `shell.nix` file and do our development inside the
with pkgs;
let
# pin OTP via beam27Packages/beam28Packages/... and Elixir via overrideScope
beamPackages = beam27Packages.overrideScope (final: prev: { elixir = final.elixir_1_18; });
# pin OTP via beam27Packages/beam28Packages/... and Elixir via .extend
beamPackages = beam27Packages.extend (self: super: { elixir = self.elixir_1_18; });
in
mkShell { buildInputs = [ beamPackages.elixir ]; }
```
@@ -372,8 +368,8 @@ Here is an example `shell.nix`.
with import <nixpkgs> { };
let
# pin OTP via beam27Packages/beam28Packages/... and Elixir via overrideScope
beamPackages = beam27Packages.overrideScope (final: prev: { elixir = final.elixir_1_18; });
# pin OTP via beam27Packages/beam28Packages/... and Elixir via .extend
beamPackages = beam27Packages.extend (self: super: { elixir = self.elixir_1_18; });
# define packages to install
basePackages = [

View File

@@ -1,30 +1,49 @@
# JavaScript {#language-javascript}
# Javascript {#language-javascript}
## Introduction {#javascript-introduction}
Package JavaScript applications with the tools below.
This contains instructions on how to package JavaScript applications.
The various tools available will be listed in the [tools-overview](#javascript-tools-overview).
Some general principles for packaging will follow.
Finally, some tool-specific instructions will be given.
## Getting unstuck / finding code examples {#javascript-finding-examples}
If you find you are lacking inspiration for packaging JavaScript applications, the links below might prove useful.
Searching online for prior art can be helpful if you are running into solved problems.
### Github {#javascript-finding-examples-github}
- Searching Nix files for `yarnConfigHook`: <https://github.com/search?q=yarnConfigHook+language%3ANix&type=code>
- Searching just `flake.nix` files for `yarnConfigHook`: <https://github.com/search?q=yarnConfigHook+path%3A**%2Fflake.nix&type=code>
### Gitlab {#javascript-finding-examples-gitlab}
- Searching Nix files for `yarnConfigHook`: <https://gitlab.com/search?scope=blobs&search=yarnConfigHook+extension%3Anix>
- Searching just `flake.nix` files for `yarnConfigHook`: <https://gitlab.com/search?scope=blobs&search=yarnConfigHook+filename%3Aflake.nix>
## Tools overview {#javascript-tools-overview}
## General principles {#javascript-general-principles}
The principles below are ordered by importance.
The following principles are given in order of importance with potential exceptions.
### Use the project's Node.js version {#javascript-upstream-node-version}
### Try to use the same node version used upstream {#javascript-upstream-node-version}
It is often not documented which Node.js version the project uses, but if it is, use the same version when packaging.
It is often not documented which node version is used upstream, but if it is, try to use the same version when packaging.
This can be a problem if the project uses the latest and greatest and you are trying to use an earlier version of Node.js.
This can be a problem if upstream is using the latest and greatest and you are trying to use an earlier version of node.
Some cryptic errors regarding V8 may appear.
### Use the project's package manager and lock file {#javascript-upstream-package-manager}
### Try to respect the package manager originally used by upstream (and use the upstream lock file) {#javascript-upstream-package-manager}
A lock file (package-lock.json, yarn.lock...) is supposed to make reproducible installations of `node_modules` for each tool.
Package manager guidelines recommend committing those lock files to the repository.
If a particular lock file is present, it is a strong indication of which package manager the project uses.
Guidelines of package managers, recommend to commit those lock files to the repos.
If a particular lock file is present, it is a strong indication of which package manager is used upstream.
Use a Nix tool that understands the lock file.
It's better to try to use a Nix tool that understands the lock file.
Using a different tool might give you a hard-to-understand error because different packages have been installed.
Using a different tool forces you to commit a lock file to the repository.
@@ -32,16 +51,16 @@ These files are fairly large, so when packaging for nixpkgs, this approach does
Exceptions to this rule are:
- When you encounter one of the bugs from a Nix tool. In each of the tool-specific instructions, known problems are detailed. If a tool has a problem, try another. You may have to re-create a lock file and commit it to Nixpkgs.
- Some lock files contain a particular version of a package that has been pulled off npm for some reason. In that case, you can recreate the lock file (by removing the original and running `npm install`, `yarn`, etc.) and commit this to Nixpkgs.
- When you encounter one of the bugs from a Nix tool. In each of the tool-specific instructions, known problems will be detailed. If you have a problem with a particular tool, then it's best to try another tool, even if this means you will have to re-create a lock file and commit it to Nixpkgs.
- Some lock files contain particular version of a package that has been pulled off npm for some reason. In that case, you can recreate upstream lock (by removing the original and `npm install`, `yarn`, ...) and commit this to nixpkgs.
### Use the project's `package.json` {#javascript-upstream-package-json}
### Try to use upstream package.json {#javascript-upstream-package-json}
Exceptions to this rule are:
- Sometimes the project assumes some dependencies are installed globally. Add them to the `package.json` manually (`yarn add xxx` or `npm install xxx`). Run locally installed CLI tools with `npx`, for example `npx postcss`. That is how you call them in the phases.
- Sometimes the upstream repo assumes some dependencies should be installed globally. In that case, you can add them manually to the upstream `package.json` (`yarn add xxx` or `npm install xxx`, ...). Dependencies that are installed locally can be executed with `npx` for CLI tools (e.g. `npx postcss ...`, this is how you can call those dependencies in the phases).
- Sometimes there is a version conflict between some dependency requirements. In that case you can fix a version by removing the `^`.
- Sometimes a script in `package.json` does not work as is. It might call a CLI tool that is not available, or `cd` into a directory with a different `package.json`, which is common with workspaces. Read what the script does. Reproduce it in the build phases. For example, a `build` script may call `build:ui` and `build:server` in turn. If one fails, split them into separate steps.
- Sometimes the script defined in the package.json does not work as is. Some scripts for example use CLI tools that might not be available, or cd in directory with a different package.json (for workspaces notably). In that case, it's perfectly fine to look at what the particular script is doing and break this down in the phases. In the build script you can see `build:*` calling in turns several other build scripts like `build:ui` or `build:server`. If one of those fails, you can try to separate those into,
```sh
yarn build:ui
@@ -51,7 +70,7 @@ Exceptions to this rule are:
npm run build:server
```
When you need to override `package.json`, it is best to use the one from the project and make explicit overrides. Here is an example:
when you need to override a package.json. It's nice to use the one from the upstream source and do some explicit override. Here is an example:
```nix
{
@@ -63,22 +82,22 @@ Exceptions to this rule are:
}
```
You still need to commit the modified version of the lock files, but at least the overrides are explicit for everyone to see.
You will still need to commit the modified version of the lock files, but at least the overrides are explicit for everyone to see.
### Use `node_modules` directly {#javascript-using-node_modules}
### Using node_modules directly {#javascript-using-node_modules}
Each tool has an abstraction to build the node_modules (dependencies) directory.
Each tool has an abstraction to just build the node_modules (dependencies) directory.
You can always use the `stdenv.mkDerivation` with the node_modules to build the package (symlink the node_modules directory and then use the package build command).
The `node_modules` abstraction can also be used to build some web framework frontends.
For an example of this, see how [plausible](https://github.com/NixOS/nixpkgs/blob/master/pkgs/by-name/pl/plausible/package.nix) is built.
Then, when building the frontend, you can symlink the `node_modules` directory.
The node_modules abstraction can be also used to build some web framework frontends.
For an example of this see how [plausible](https://github.com/NixOS/nixpkgs/blob/master/pkgs/by-name/pl/plausible/package.nix) is built.
Then when building the frontend you can just symlink the node_modules directory.
## Tool-specific instructions {#javascript-tool-specific}
### buildNpmPackage {#javascript-buildNpmPackage}
`buildNpmPackage` packages npm-based projects in Nixpkgs without the use of an auto-generated dependencies file.
It uses npm's cache. It builds a reproducible cache of the project's dependencies and points npm at it.
`buildNpmPackage` allows you to package npm-based projects in Nixpkgs without the use of an auto-generated dependencies file.
It works by utilizing npm's cache functionality -- creating a reproducible cache that contains the dependencies of a project, and pointing npm to it.
Here's an example:
@@ -116,9 +135,9 @@ buildNpmPackage (finalAttrs: {
})
```
In the default `installPhase` set by `buildNpmPackage`, it uses `npm pack --json --dry-run` to decide what files to install. They go in `$out/lib/node_modules/$name/`, where `$name` is the `name` string in the package's `package.json`.
In the default `installPhase` set by `buildNpmPackage`, it uses `npm pack --json --dry-run` to decide what files to install in `$out/lib/node_modules/$name/`, where `$name` is the `name` string defined in the package's `package.json`.
Additionally, the `bin` and `man` keys in the source's `package.json` are used to decide what binaries and manpages are supposed to be installed.
If these are not defined, `npm pack` may miss some files, and no binaries are produced.
If these are not defined, `npm pack` may miss some files, and no binaries will be produced.
#### Arguments {#javascript-buildNpmPackage-arguments}
@@ -153,8 +172,8 @@ sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=
`fetchNpmDeps` is a Nix function that requires the following mandatory arguments:
- `src`: A directory or tarball with a `package-lock.json` file
- `hash`: The output hash of the dependencies defined in `package-lock.json`.
- `src`: A directory / tarball with `package-lock.json` file
- `hash`: The output hash of the node dependencies defined in `package-lock.json`.
It returns a derivation with all `package-lock.json` dependencies downloaded into `$out/`, usable as an npm cache.
@@ -168,7 +187,7 @@ There is no need to specify a `hash`, since it relies entirely on the integrity
##### Inputs {#javascript-buildNpmPackage-inputs}
- `npmRoot`: Path to the package directory containing the source tree.
- `npmRoot`: Path to package directory containing the source tree.
If this is omitted, the `package` and `packageLock` arguments must be specified instead.
- `package`: Parsed contents of `package.json`
- `packageLock`: Parsed contents of `package-lock.json`
@@ -176,7 +195,7 @@ There is no need to specify a `hash`, since it relies entirely on the integrity
- `version`: Package version
- `fetcherOpts`: An attribute set of arguments forwarded to the underlying fetcher.
It returns a derivation with a patched `package.json` and `package-lock.json` with all dependencies resolved to Nix store paths.
It returns a derivation with a patched `package.json` & `package-lock.json` with all dependencies resolved to Nix store paths.
:::{.note}
`npmHooks.npmConfigHook` cannot be used with `importNpmLock`.
@@ -238,18 +257,18 @@ buildNpmPackage {
`importNpmLock.buildNodeModules` returns a derivation with a pre-built `node_modules` directory, as imported by `importNpmLock`.
This is to be used together with `importNpmLock.hooks.linkNodeModulesHook` to support `nix-shell`/`nix develop` development workflows.
This is to be used together with `importNpmLock.hooks.linkNodeModulesHook` to facilitate `nix-shell`/`nix develop` based development workflows.
It accepts an argument with the following attributes:
`npmRoot` (Path; optional)
: Path to the package directory containing the source tree. If not specified, the `package` and `packageLock` arguments must both be specified.
: Path to package directory containing the source tree. If not specified, the `package` and `packageLock` arguments must both be specified.
`package` (Attrset; optional)
: Parsed contents of `package.json`, as returned by `lib.importJSON ./my-package.json`. If not specified, the `package.json` in `npmRoot` is used.
`packageLock` (Attrset; optional)
: Parsed contents of `package-lock.json`, as returned by `lib.importJSON ./my-package-lock.json`. If not specified, the `package-lock.json` in `npmRoot` is used.
: Parsed contents of `package-lock.json`, as returned `lib.importJSON ./my-package-lock.json`. If not specified, the `package-lock.json` in `npmRoot` is used.
`derivationArgs` (`mkDerivation` attrset; optional)
: Arguments passed to `stdenv.mkDerivation`
@@ -269,26 +288,26 @@ pkgs.mkShell {
};
}
```
creates a development shell where a `node_modules` directory is created and packages are symlinked to the Nix store when activated.
will create a development shell where a `node_modules` directory is created & packages symlinked to the Nix store when activated.
:::{.note}
Commands like `npm install` and `npm add` that write packages and executables need to be used with `--package-lock-only`.
Commands like `npm install` & `npm add` that write packages & executables need to be used with `--package-lock-only`.
This means `npm` installs dependencies by writing into `package-lock.json` without modifying the `node_modules` folder. It installs by reloading the devShell.
This gives the `nix shell` near-exclusive ownership over your `node_modules` folder.
This means `npm` installs dependencies by writing into `package-lock.json` without modifying the `node_modules` folder. Installation happens through reloading the devShell.
This might be best practice since it gives the `nix shell` virtually exclusive ownership over your `node_modules` folder.
Set `package-lock-only = true` in your project-local [`.npmrc`](https://docs.npmjs.com/cli/v11/configuring-npm/npmrc).
It's recommended to set `package-lock-only = true` in your project-local [`.npmrc`](https://docs.npmjs.com/cli/v11/configuring-npm/npmrc).
:::
### corepack {#javascript-corepack}
This package puts the corepack wrappers for pnpm and yarn in your PATH, and they honor the `packageManager` setting in the `package.json`.
This package puts the corepack wrappers for pnpm and yarn in your PATH, and they will honor the `packageManager` setting in the `package.json`.
### pnpm {#javascript-pnpm}
pnpm is available as the top-level package `pnpm`. Additionally, there are variants pinned to certain major versions, like `pnpm_9`, `pnpm_10`, `pnpm_10_29_2` and `pnpm_11`, which support different sets of lock file versions.
When packaging an application that includes a `pnpm-lock.yaml`, you need to fetch the pnpm store for that project using a fixed-output-derivation. The function `fetchPnpmDeps` can create this pnpm store derivation. In conjunction, the setup hook `pnpmConfigHook` prepares the build environment to install the pre-fetched dependencies store. The example below uses the fetcher and setup hook for a package that has `package.json` and `pnpm-lock.yaml`:
When packaging an application that includes a `pnpm-lock.yaml`, you need to fetch the pnpm store for that project using a fixed-output-derivation. The function `fetchPnpmDeps` can create this pnpm store derivation. In conjunction, the setup hook `pnpmConfigHook` will prepare the build environment to install the pre-fetched dependencies store. Here is an example for a package that contains `package.json` and a `pnpm-lock.yaml` files using the fetcher and setup hook above:
There is also the [`pnpmBuildHook`](#pnpm-build-hook) for building packages with `pnpm`, as seen in [](#ex-pnpm-build-hook).
@@ -331,7 +350,7 @@ stdenv.mkDerivation (finalAttrs: {
})
```
Use a pinned version of pnpm (for example `pnpm_9` or `pnpm_10`) to increase reproducibility. An older version may be required if the package needs a certain lock file version. To do so, pass the `pnpm` argument to `fetchPnpmDeps`. Then override the `pnpm` arg in `pnpmConfigHook`. Here are the changes in the example above to use a pinned pnpm version:
It is highly recommended to use a pinned version of pnpm (i.e., `pnpm_9` or `pnpm_10`), to increase future reproducibility. It might also be required to use an older version if the package needs support for a certain lock file version. To do so, you can pass the `pnpm` argument to `fetchPnpmDeps` and override the `pnpm` arg in `pnpmConfigHook`. Here are the changes in the example above to use a pinned pnpm version:
<!-- TODO: Does splicing still work when overriding in nativeBuildInputs here? -->
@@ -373,7 +392,7 @@ Use a pinned version of pnpm (for example `pnpm_9` or `pnpm_10`) to increase rep
})
```
In case you are patching `package.json` or `pnpm-lock.yaml`, make sure to pass `finalAttrs.patches` to the function as well (i.e., `inherit (finalAttrs) patches`).
In case you are patching `package.json` or `pnpm-lock.yaml`, make sure to pass `finalAttrs.patches` to the function as well (i.e., `inherit (finalAttrs) patches`.
`pnpmConfigHook` supports adding additional `pnpm install` flags via `pnpmInstallFlags` which can be set to a Nix string array:
@@ -389,14 +408,14 @@ In case you are patching `package.json` or `pnpm-lock.yaml`, make sure to pass `
}
```
If needed, set `dontPnpmConfigure = true;` to fully disable `pnpmConfigHook` without removing it from inputs manually.
If needed, `dontPnpmConfigure = true;` can be used to fully disable `pnpmConfigHook` without manually removing it from inputs.
#### Dealing with `sourceRoot` {#javascript-pnpm-sourceRoot}
If the pnpm project is in a subdirectory, you can define `sourceRoot` or `setSourceRoot` for `fetchPnpmDeps`.
If `sourceRoot` is different between the parent derivation and `fetchPnpmDeps`, you have to set `pnpmRoot` to effectively be the same location as it is in `fetchPnpmDeps`.
If the pnpm project is in a subdirectory, you can just define `sourceRoot` or `setSourceRoot` for `fetchPnpmDeps`.
If `sourceRoot` is different between the parent derivation and `fetchPnpmDeps`, you will have to set `pnpmRoot` to effectively be the same location as it is in `fetchPnpmDeps`.
Assuming the directory structure below, you can define `sourceRoot` and `pnpmRoot`:
Assuming the following directory structure, we can define `sourceRoot` and `pnpmRoot` as follows:
```
.
@@ -420,9 +439,10 @@ Assuming the directory structure below, you can define `sourceRoot` and `pnpmRoo
}
```
#### pnpm workspaces {#javascript-pnpm-workspaces}
#### PNPM Workspaces {#javascript-pnpm-workspaces}
For a pnpm workspace, set `pnpmWorkspaces = [ "<workspace project name 1>" "<workspace project name 2>" ]` in your `fetchPnpmDeps` call. pnpm then installs only the dependencies for those workspace packages.
If you need to use a PNPM workspace for your project, then set `pnpmWorkspaces = [ "<workspace project name 1>" "<workspace project name 2>" ]`, etc, in your `fetchPnpmDeps` call,
which will make PNPM only install dependencies for those workspace packages.
For example:
@@ -438,9 +458,9 @@ For example:
```
The above would make `fetchPnpmDeps` call only install dependencies for the `@astrojs/language-server` workspace package.
You do not need to set `sourceRoot` to make this work.
Note that you do not need to set `sourceRoot` to make this work.
For these projects, build with `pnpm --filter=<pnpm workspace name> build`, because `npmHooks.npmBuildHook` may not work. The example below fits most workspace projects:
Usually, in such cases, you'd want to use `pnpm --filter=<pnpm workspace name> build` to build your project, as `npmHooks.npmBuildHook` probably won't work. A `buildPhase` based on the following example will probably fit most workspace projects:
```nix
{
@@ -454,9 +474,9 @@ For these projects, build with `pnpm --filter=<pnpm workspace name> build`, beca
}
```
#### Additional pnpm commands and settings {#javascript-pnpm-extraCommands}
#### Additional PNPM Commands and settings {#javascript-pnpm-extraCommands}
If you require setting an additional pnpm configuration setting (such as `dedupe-peer-dependents` or similar),
If you require setting an additional PNPM configuration setting (such as `dedupe-peer-dependents` or similar),
set `prePnpmInstall` to the right commands to run. For example:
```nix
@@ -471,11 +491,11 @@ set `prePnpmInstall` to the right commands to run. For example:
}
```
In this example, `prePnpmInstall` runs in both `pnpmConfigHook` and the `fetchPnpmDeps` builder.
In this example, `prePnpmInstall` will be run by both `pnpmConfigHook` and by the `fetchPnpmDeps` builder.
#### pnpm `fetcherVersion` {#javascript-pnpm-fetcherVersion}
This is the version of the output of `fetchPnpmDeps`. Use `4` for new packages:
This is the version of the output of `fetchPnpmDeps`. New packages should use `4`:
```nix
{
@@ -491,7 +511,7 @@ This is the version of the output of `fetchPnpmDeps`. Use `4` for new packages:
When upgrading to a newer `fetcherVersion`, you need to regenerate the hash.
This variable ensures that we can make changes to the output of `fetchPnpmDeps` without breaking existing hashes.
Changes can include workarounds or bug fixes to existing pnpm issues.
Changes can include workarounds or bug fixes to existing PNPM issues.
##### Version history {#javascript-pnpm-fetcherVersion-versionHistory}
@@ -504,9 +524,9 @@ Version 3 is the minimum supported value. Versions 1 and 2 were removed in the 2
### Yarn {#javascript-yarn}
Yarn-based projects use a `yarn.lock` file instead of a `package-lock.json` to pin dependencies.
Yarn based projects use a `yarn.lock` file instead of a `package-lock.json` to pin dependencies.
To package Yarn-based applications, you need to distinguish by the version pointers in the `yarn.lock` file. See the following sections.
To package yarn-based applications, you need to distinguish by the version pointers in the `yarn.lock` file. See the following sections.
#### Yarn v1 {#javascript-yarn-v1}
@@ -575,12 +595,12 @@ This script by default runs `yarn --offline build`, and it relies upon the proje
##### `yarnInstallHook` arguments {#javascript-yarninstallhook}
To install the package, `yarnInstallHook` uses both `npm` and `yarn` to clean up project files and dependencies. To disable this phase, you can set `dontYarnInstall = true` or override the `installPhase`. Below is a list of additional `mkDerivation` arguments read by this hook:
To install the package `yarnInstallHook` uses both `npm` and `yarn` to cleanup project files and dependencies. To disable this phase, you can set `dontYarnInstall = true` or override the `installPhase`. Below is a list of additional `mkDerivation` arguments read by this hook:
- `yarnKeepDevDeps`: Disables the removal of devDependencies from `node_modules` before installation.
#### Yarn Berry v3/v4 {#javascript-yarn-v3-v4}
Yarn Berry (v3 / v4) versions have similar formats. They start with blocks like these:
Yarn Berry (v3 / v4) have similar formats, they start with blocks like these:
```yaml
__metadata:
@@ -600,7 +620,7 @@ For these packages, we have some helpers exposed under the respective `yarn-berr
- `fetchYarnBerryDeps`
- `yarnBerryConfigHook`
Explicitly pin the major version. For example, capture the `yarn-berry_Xn` argument and re-define it as a `yarn-berry` `let` binding.
It's recommended to ensure you're explicitly pinning the major version used, for example by capturing the `yarn-berry_Xn` argument and then re-defining it as a `yarn-berry` `let` binding.
```nix
{
@@ -636,26 +656,26 @@ stdenv.mkDerivation (finalAttrs: {
##### `yarn-berry_X.fetchYarnBerryDeps` {#javascript-fetchYarnBerryDeps}
`fetchYarnBerryDeps` runs `yarn-berry-fetcher fetch` in a fixed-output-derivation. It is a custom fetcher designed to reproducibly download all files in the `yarn.lock` file, validating their hashes in the process. For git dependencies, it creates a checkout at `${offlineCache}/checkouts/<40-character-commit-hash>` (relying on the git commit hash to describe the contents of the checkout).
To produce the `hash` argument for the `fetchYarnBerryDeps` call, run `yarn-berry-fetcher prefetch`:
To produce the `hash` argument for `fetchYarnBerryDeps` function call, the `yarn-berry-fetcher prefetch` command can be used:
```console
$ yarn-berry-fetcher prefetch </path/to/yarn.lock> [/path/to/missing-hashes.json]
```
This prints the hash to stdout. Use it in update scripts to recalculate the hash for a new `yarn.lock`.
This prints the hash to stdout and can be used in update scripts to recalculate the hash for a new version of `yarn.lock`.
##### `yarn-berry_X.yarnBerryConfigHook` {#javascript-yarnBerryConfigHook}
`yarnBerryConfigHook` uses the store path `offlineCache` points to, to run a `yarn install` during the build, producing a usable `node_modules` directory from the downloaded dependencies.
Internally, this uses a patched version of Yarn to ensure git dependencies are re-packed and any attempted downloads fail immediately.
##### Patching the project's `package.json` or `yarn.lock` files {#javascript-yarnBerry-patching}
In case patching the project's `package.json` or `yarn.lock` is needed, it's important to pass `finalAttrs.patches` to `fetchYarnBerryDeps` as well, so the patched variants are picked up (i.e., `inherit (finalAttrs) patches`).
##### Patching upstream `package.json` or `yarn.lock` files {#javascript-yarnBerry-patching}
In case patching the upstream `package.json` or `yarn.lock` is needed, it's important to pass `finalAttrs.patches` to `fetchYarnBerryDeps` as well, so the patched variants are picked up (i.e., `inherit (finalAttrs) patches`.
##### Missing hashes in the `yarn.lock` file {#javascript-yarnBerry-missing-hashes}
Unfortunately, `yarn.lock` files do not include hashes for optional/platform-specific dependencies. This is [by design](https://github.com/yarnpkg/berry/issues/6759).
To compensate for this, run the `yarn-berry-fetcher missing-hashes` subcommand to produce all missing hashes. These are stored in a `missing-hashes.json` file, which needs to be passed to both the build itself, as well as the `fetchYarnBerryDeps` helper:
To compensate for this, the `yarn-berry-fetcher missing-hashes` subcommand can be used to produce all missing hashes. These are usually stored in a `missing-hashes.json` file, which needs to be passed to both the build itself, as well as the `fetchYarnBerryDeps` helper:
```nix
{
@@ -698,7 +718,7 @@ If you are packaging something outside Nixpkgs, consider the following:
### npmlock2nix {#javascript-npmlock2nix}
[npmlock2nix](https://github.com/nix-community/npmlock2nix) aims at building `node_modules` without code generation. It hasn't reached v1 yet; the API may change.
[npmlock2nix](https://github.com/nix-community/npmlock2nix) aims at building `node_modules` without code generation. It hasn't reached v1 yet, the API might be subject to change.
#### Pitfalls {#javascript-npmlock2nix-pitfalls}
@@ -706,7 +726,7 @@ There are some [problems with npm v7](https://github.com/tweag/npmlock2nix/issue
### nix-npm-buildpackage {#javascript-nix-npm-buildpackage}
[nix-npm-buildpackage](https://github.com/serokell/nix-npm-buildpackage) aims at building `node_modules` without code generation. It hasn't reached v1 yet; the API may change. It supports both `package-lock.json` and yarn.lock.
[nix-npm-buildpackage](https://github.com/serokell/nix-npm-buildpackage) aims at building `node_modules` without code generation. It hasn't reached v1 yet, the API might change. It supports both `package-lock.json` and yarn.lock.
#### Pitfalls {#javascript-nix-npm-buildpackage-pitfalls}

View File

@@ -143,9 +143,6 @@
"ex-writeShellApplication": [
"index.html#ex-writeShellApplication"
],
"fetchfromtangled": [
"index.html#fetchfromtangled"
],
"first-package-go": [
"index.html#first-package-go"
],
@@ -2801,6 +2798,9 @@
"glycin-dont-wrap": [
"index.html#glycin-dont-wrap"
],
"ghc": [
"index.html#ghc"
],
"gnome-platform": [
"index.html#gnome-platform"
],
@@ -3648,8 +3648,7 @@
"index.html#hareHook-cross-compilation"
],
"haskell": [
"index.html#haskell",
"index.html#ghc"
"index.html#haskell"
],
"haskell-available-packages": [
"index.html#haskell-available-packages"
@@ -3778,9 +3777,15 @@
"index.html#language-javascript"
],
"javascript-introduction": [
"index.html#javascript-introduction",
"index.html#javascript-finding-examples",
"index.html#javascript-finding-examples-github",
"index.html#javascript-introduction"
],
"javascript-finding-examples": [
"index.html#javascript-finding-examples"
],
"javascript-finding-examples-github": [
"index.html#javascript-finding-examples-github"
],
"javascript-finding-examples-gitlab": [
"index.html#javascript-finding-examples-gitlab"
],
"javascript-tools-overview": [

View File

@@ -72,8 +72,6 @@
- `alps` has been rewritten upstream, see [upstream repository](https://github.com/migadu/alps) for documentation.
- `writers.makeDataWriter` has been removed. It has been deprecated since 2023. Use `pkgs.writeTextFile` instead.
- `bosun` has been removed as it is no longer maintained upstream. the corresponding monitoring options has been removed.
- `uhttpmock` providing 0.0 ABI was removed. `uhttpmock_1_0` providing 1.0 ABI was renamed to `uhttpmock` and `uhttpmock_1_0` was kept as an alias.
@@ -84,6 +82,8 @@
- `nix-serve-ng` (and `haskellPackages.nix-serve-ng`) is now built against Lix instead of CppNix, following upstream which has switched to Lix as its supported Nix implementation.
- `buildPythonPackage` and `buildPythonApplication` now set `__structuredAttrs = true` by default. You can explicitly set `__structuredAttrs = false` in packages broken by this change.
- Linux kernel configuration has been moved out of the `linux-kernel` field of the platform structure into the kernel builders:
- `linux-kernel.name` has been removed.
- `linux-kernel.target` is available as the `target` parameter and passthru attribute on the kernel builders.
@@ -101,8 +101,6 @@
- `pdns` has been updated from `5.0.x` to `5.1.x`. Please be sure to review the [Upgrade Notes](https://doc.powerdns.com/authoritative/upgrading.html#to-5-1-0) before upgrading. Namely LUA record updates are no longer allowed by default, and the embedded webserver no longer includes a `access-control-allow-origin: *` header by default.
- LibreOffice upstream switched from Fresh/Still stable branches to a single Stable branch; `libreoffice` and `libreoffice-qt` work as before, but more specific aliases like `libreoffice-fresh` should be replaced.
- `davmail` no longer supports building with GTK 2, and the `preferGtk3` override flag has been removed as GTK 3 is always used.
- Support for the legacy UBoot image format has been removed from the Linux kernel builders, as it is deprecated upstream and no longer used by any platform in Nixpkgs.
@@ -163,8 +161,6 @@
- `buildFHSEnv`, `appimageTools.wrapAppImage`, and `appimageTools.wrapType2` now support the `finalAttrs` pattern. When using `wrapAppImage`, it is now recommended to pass the extracted AppImage to the `contents` attribute (instead of `src`), to avoid shadowing `src`. Passing the extracted contents to `src` is now deprecated and will be removed in a future release.
- All databases of the MySQL family `mysql`, `mariadb` and `percona` now provide a client-only package `client` sub-attribute. Use the `<dbname>.client` package if the server components are not needed. The main package continues to ship the client binaries as well.
- Package-URL (PURL, https://github.com/package-url/purl-spec) metadata identifier has been added for `fetchgit`, `fetchpypi` and `fetchFromGithub` fetchers.
`mkDerivation` has been adjusted to reuse this information.
Package-URLs allow reliably identifying and locating software packages.

View File

@@ -508,7 +508,6 @@ A number between 0 and 7 indicating how much information to log. If set to 1 or
#### `enableParallelBuilding` {#var-stdenv-enableParallelBuilding}
If set to `true`, `stdenv` will pass specific flags to `make` and other build tools to enable parallel building with up to `build-cores` workers.
Can be overridden for a specific phase using `enableParallelInstalling` or `enableParallelChecking`.
Unless set to `false`, some build systems with good support for parallel building including `cmake`, `meson`, and `qmake` will set it to `true`.

View File

@@ -283,12 +283,6 @@ lib.mapAttrs mkLicense (
fullName = "BSD 3-Clause Tso variant";
};
bsdAskToEndorse = {
#spdxId = "BSD-ask-to-endorse"; # Accepted to SPDX waiting on next SPDX release
fullName = "BSD - ask to endorse";
url = "https://github.com/sudo-project/sudo/blob/c1307ea9ff340ce0538779f8e456501461fc44b7/plugins/sudoers/redblack.c#L24-L43";
};
bsdAxisNoDisclaimerUnmodified = {
fullName = "BSD-Axis without Warranty Disclaimer with Unmodified requirement";
url = "https://scancode-licensedb.aboutcode.org/bsd-no-disclaimer-unmodified.html";
@@ -715,11 +709,6 @@ lib.mapAttrs mkLicense (
url = "https://geant4.web.cern.ch/geant4/license/LICENSE.html";
};
gccException20 = {
spdxId = "GCC-exception-2.0";
fullName = "GCC Runtime Library exception 2.0";
};
gccException31 = {
spdxId = "GCC-exception-3.1";
fullName = "GCC Runtime Library exception 3.1";
@@ -1295,11 +1284,6 @@ lib.mapAttrs mkLicense (
fullName = "Open Data Commons Open Database License v1.0";
};
ofl10 = {
spdxId = "OFL-1.0";
fullName = "SIL Open Font License 1.0";
};
ofl = {
spdxId = "OFL-1.1";
fullName = "SIL Open Font License 1.1";
@@ -1486,6 +1470,12 @@ lib.mapAttrs mkLicense (
fullName = "MIT-STK License";
};
sudo = {
shortName = "sudo";
fullName = "Sudo License (ISC-style)";
url = "https://www.sudo.ws/about/license/";
};
sustainableUse = {
spdxId = "SUL-1.0";
fullName = "Sustainable Use License";
@@ -1653,8 +1643,6 @@ lib.mapAttrs mkLicense (
vol-sl = {
fullName = "Volatility Software License, Version 1.0";
url = "https://www.volatilityfoundation.org/license/vsl-v1.0";
free = false;
redistributable = true;
};
vsl10 = {

View File

@@ -161,12 +161,14 @@ let
(with final; isWindows && isAarch64);
# Use the split GCC package set (`gccNGPackages`) instead of the
# monolithic `gcc`.
# monolithic `gcc`. No platform selects it yet; it is opt-in, set
# explicitly on a platform spec, so that the split set can be exercised
# before anything depends on it.
#
# I (@Ericson2314) plan on making more obscure low-tier
# platforms (e.g. NetBSD) use it soon, so we can dogfood GCC NG
# and thereby iron out its bugs.
useGccNG = final.isCygwin;
# I (@Ericson2314) plan on making obscure low-tier platforms (e.g.
# NetBSD) use it soon, so we can dogfood GCC NG and thereby iron out its
# bugs.
useGccNG = false;
libc =
if final.isDarwin then

View File

@@ -262,7 +262,6 @@
"stephenstubbs": 18033664,
"t-monaghan": 62273348,
"thefloweringash": 42933,
"thtrf": 82712122,
"tricktron": 16036882,
"uncenter": 47499684,
"usertam": 22500027,
@@ -658,6 +657,7 @@
"djacu": 7043297
},
"members": {
"Sigmanificient": 53050011,
"flyfloh": 74379,
"thilobillerbeck": 7442383
},
@@ -694,8 +694,8 @@
"eclairevoyant": 848000
},
"members": {
"daylinmorgan": 47667941,
"eveeifyeve": 88671402
"Eveeifyeve": 88671402,
"daylinmorgan": 47667941
},
"name": "nim"
},
@@ -788,11 +788,10 @@
"description": "Maintain Pantheon desktop environment and platform",
"id": 4786995,
"maintainers": {
"bobby285271": 20080233,
"davidak": 91113
},
"members": {
"amz-x": 18249234
"bobby285271": 20080233
},
"name": "Pantheon"
},
@@ -856,7 +855,6 @@
"lorenzleutgeb": 542154
},
"members": {
"Mic92": 96200,
"ju1m": 21160136,
"matthiasbeyer": 427866
},
@@ -897,6 +895,7 @@
"0x4A6F": 9675338
},
"members": {
"DarkKirb": 23011243,
"dramforever": 2818072,
"fgaz": 8182846,
"jonhermansen": 660911

View File

@@ -3694,6 +3694,13 @@
githubId = 185443;
name = "Alexey Lebedeff";
};
binary-eater = {
email = "sergeantsagara@protonmail.com";
github = "Binary-Eater";
githubId = 10691440;
name = "Rahul Rameshbabu";
keys = [ { fingerprint = "678A 8DF1 D9F2 B51B 7110 BE53 FF24 7B3E 5411 387B"; } ];
};
binarycat = {
email = "binarycat@envs.net";
github = "lolbinarycat";
@@ -4878,12 +4885,6 @@
githubId = 543423;
name = "Alex Wied";
};
ceridwen15 = {
email = "me@cdwn.gay";
github = "NonsensicalNickname";
githubId = 118519066;
name = "Ceridwen Weaving";
};
cfouche = {
email = "chaddai.fouche@gmail.com";
github = "Chaddai";
@@ -5424,12 +5425,6 @@
githubId = 69784758;
matrix = "@clot27:matrix.org";
};
cloudglides = {
name = "Cloud";
email = "cloudglides@proton.me";
github = "cloudglides";
githubId = 111557161;
};
cloudripper = {
email = "dev+nixpkgs@cldrpr.com";
github = "cloudripper";
@@ -5622,12 +5617,6 @@
githubId = 327028;
name = "Cole Mickens";
};
colepearson27 = {
name = "Cole Pearson";
email = "colepearson27@gmail.com";
github = "colepearson27";
githubId = 113060096;
};
colescott = {
email = "colescottsf@gmail.com";
github = "colescott";
@@ -8028,12 +8017,6 @@
githubId = 63352906;
keys = [ { fingerprint = "922F CA48 5FDB 20B1 ED1B A61F 284D 11D3 33C4 D21B"; } ];
};
edgarpost = {
name = "Edgar Post-Buijs";
email = "github@edgarpost.com";
github = "EdgarPost";
githubId = 488221;
};
edlimerkaj = {
name = "Edli Merkaj";
email = "edli.merkaj@identinet.io";
@@ -8725,11 +8708,6 @@
{ fingerprint = "2E51 F618 39D1 FA94 7A73 00C2 34C0 4305 D581 DBFE"; }
];
};
ethanthoma = {
name = "Ethan Thoma";
github = "ethanthoma";
githubId = 4424467;
};
ethindp = {
name = "Ethin Probst";
email = "harlydavidsen@gmail.com";
@@ -10435,12 +10413,6 @@
github = "gkleen";
githubId = 20089782;
};
gl1tchxd = {
name = "Felix Buchsteiner";
github = "gl1tchxd-git";
githubId = 92686452;
email = "contact@gl1tchxd.at";
};
gleber = {
email = "gleber.p@gmail.com";
github = "gleber";
@@ -11083,12 +11055,6 @@
githubId = 79340822;
keys = [ { fingerprint = "3582 5B85 66C8 4F36 45C7 EC42 809F 7938 9CB1 8650"; } ];
};
havunen = {
name = "Sampo Kivistö";
email = "sampo.kivisto@live.fi";
github = "havunen";
githubId = 2021355;
};
hawkw = {
email = "eliza@elizas.website";
github = "hawkw";
@@ -11713,12 +11679,6 @@
github = "I-Al-Istannen";
githubId = 20284688;
};
i-love-lean = {
name = "i-love-lean";
github = "i-love-lean";
githubId = 170473930;
email = "nixpkgs@unnamed.website";
};
i01011001 = {
email = "yugen.m7@gmail.com";
github = "i01011001";
@@ -17040,12 +17000,6 @@
}
];
};
lunitur = {
email = "karlo.puselj@gmail.com";
github = "Lunitur";
githubId = 8092435;
name = "Karlo Pušelj";
};
lunkentuss = {
email = "peter.hansson17@gmail.com";
matrix = "@lunkentuss:matrix.org";
@@ -17799,11 +17753,6 @@
githubId = 29855073;
name = "Michael Colicchia";
};
Masrepus = {
github = "Masrepus";
githubId = 6538121;
name = "Samuel Hopstock";
};
masrlinu = {
github = "masrlinu";
githubId = 5259918;
@@ -18823,12 +18772,6 @@
githubId = 1387206;
name = "Mike Sperber";
};
mikilio = {
email = "kilian.mio@mikilio.com";
github = "Mikilio";
githubId = 86004375;
name = "Kilian Mio";
};
mikoim = {
email = "ek@esh.ink";
github = "mikoim";
@@ -19173,12 +19116,6 @@
githubId = 104795;
name = "Marek Mahut";
};
mmclinton = {
email = "nixpkg.concur071@simplelogin.com";
github = "mmclinton";
githubId = 96266047;
name = "Miller Clinton";
};
mmesch = {
github = "MMesch";
githubId = 2597803;
@@ -19501,12 +19438,6 @@
githubId = 15896005;
name = "Vladyslav Burzakovskyy";
};
mroboff = {
email = "mark.roboff@bluecircuit.ai";
github = "mroboff";
githubId = 81203001;
name = "Mark Roboff";
};
mrsmoer = {
email = "mrsmoer@protonmail.com";
github = "MrSmoer";
@@ -20941,12 +20872,6 @@
githubId = 41154684;
name = "nokazn";
};
nolight132 = {
email = "contact@nolight.dev";
github = "nolight132";
githubId = 71591964;
name = "Pavel Olizko";
};
nolith = {
github = "nolith";
githubId = 78752;
@@ -27446,18 +27371,18 @@
name = "Steven Allen";
keys = [ { fingerprint = "327B 20CE 21EA 68CF A774 8675 7C92 3221 5899 410C"; } ];
};
steeleduncan = {
email = "steeleduncan@hotmail.com";
github = "steeleduncan";
githubId = 866573;
name = "Duncan Steele";
};
steell = {
email = "steve@steellworks.com";
github = "Steell";
githubId = 1699155;
name = "Steve Elliott";
};
stefanboca = {
email = "stefan.r.boca@gmail.com";
github = "stefanboca";
githubId = 45266795;
name = "Stefan Boca";
};
stefanfehrenbach = {
email = "stefan.fehrenbach@gmail.com";
github = "fehrenbach";
@@ -27576,12 +27501,6 @@
githubId = 4340859;
name = "Stian Lågstad";
};
stig = {
email = "stig@circleci.com";
github = "stig";
githubId = 45407;
name = "Stig Brautaset";
};
StijnDW = {
email = "nixdev@rinsa.eu";
github = "Stekke";
@@ -29369,11 +29288,6 @@
githubId = 47905926;
name = "toyboot4e";
};
tpansino = {
name = "Tom Pansino";
github = "tpansino";
githubId = 2768420;
};
tphanir = {
github = "tphanir";
name = "phani";
@@ -29785,11 +29699,6 @@
githubId = 12422133;
name = "Chromo-residuum-opec";
};
ui-1 = {
name = "ui-1";
github = "ui-1";
githubId = 134524800;
};
uku3lig = {
name = "uku";
email = "hi@uku.moe";
@@ -32207,11 +32116,6 @@
githubId = 39456023;
name = "Mike Yim";
};
zeusec = {
name = "Cole";
github = "zeusec";
githubId = 65095161;
};
zevisert = {
email = "dev@zevisert.ca";
github = "zevisert";

View File

@@ -25,11 +25,6 @@ for k in "${!sources[@]}"; do
mkdir "$TMPDIR/$k"
tar -C "$TMPDIR/$k" -xf "${sources[$k]}"
if [ "$k" == "kdenlive" ]; then
echo "[kdenlive] Applying horrible hack"
rm -rf "$TMPDIR/$k/"*"/data/lumas"
fi
(cd "$TMPDIR/$k"; reuse lint --json) | jq --arg name "$k" '{$name: .summary.used_licenses | sort}' -c > "$TMPDIR/$k.json"
done

View File

@@ -91,13 +91,13 @@ class KDERepoMetadata:
return {p.name: p for p in self.projects}
@functools.cached_property
def projects_by_repo(self):
return {p.repo_path: p for p in self.projects}
def projects_by_path(self):
return {p.project_path: p for p in self.projects}
def try_lookup_package(self, path):
if path in IGNORE:
return None
project = self.projects_by_repo.get(path)
project = self.projects_by_path.get(path)
if project is None and path not in WARNED:
WARNED.add(path)
print(f"Warning: unknown project {path}")
@@ -109,7 +109,7 @@ class KDERepoMetadata:
Project.from_yaml(metadata_file)
for metadata_file in repo_metadata.glob("projects-invent/**/metadata.yaml")
] + [
Project(id, None, project_path, project_path)
Project(id, None, project_path, None)
for project_path, id in THIRD_PARTY.items()
]
@@ -125,11 +125,11 @@ class KDERepoMetadata:
dep_graph = collections.defaultdict(set)
if unstable:
spec_name = "kde-dependencies-latest-kf6"
spec_name = "dependency-data-kf6-qt6"
else:
spec_name = "kde-dependencies-stable-kf6"
spec_name = "dependency-data-stable-kf6-qt6"
spec_path = repo_metadata / "kde-dependencies" / spec_name
spec_path = repo_metadata / "dependencies" / spec_name
for line in spec_path.open():
line = line.strip()
if line.startswith("#"):

View File

@@ -59,6 +59,6 @@ To make this path available, set the following option:
```nix
{
nix.settings.extra-sandbox-paths = [ "/dev/net" ];
nix.settings.sandbox-paths = [ "/dev/net" ];
}
```

View File

@@ -291,17 +291,10 @@ have a predefined type and string generator already declared under
and returning a set with JSON-specific attributes `type` and
`generate` as specified [below](#pkgs-formats-result).
`pkgs.formats.yaml` { *`tags`* ? false }
`pkgs.formats.yaml` { }
: A function taking an attribute set with values
`tags`
: A boolean for controlling whether YAML tags can be generated.
If set, attribute sets with a single key that starts with a "!"
will be interpreted as a YAML tag.
It returns a set with YAML-specific attributes `type` and
: A function taking an empty attribute set (for future extensibility)
and returning a set with YAML-specific attributes `type` and
`generate` as specified [below](#pkgs-formats-result).
`pkgs.formats.ini` { *`listsAsDuplicateKeys`* ? false, *`listToValue`* ? null, \.\.\. }

View File

@@ -464,7 +464,7 @@
- `services.pds` has been renamed to `services.bluesky-pds`.
- `services.pfix-srsd` now automatically integrates with the local Postfix instance, when enabled. This behavior can disabled using the `services.pfix-srsd.configurePostfix` option.
- `services.pfix-srsd` now automatically integrates with the local Postfix instance, when enabled. This behavior can disabled using the [services.pfix-srsd.configurePostfix](#opt-services.pfix-srsd.configurePostfix) option.
- `services.postsrsd` now automatically integrates with the local Postfix instance, when enabled. This behavior can disabled using the [services.postsrsd.configurePostfix](#opt-services.postsrsd.configurePostfix) option.

View File

@@ -38,8 +38,6 @@
- [Moonlight Qt](https://moonlight-stream.org/), a client for playing your PC games on almost any device. Available as [programs.moonlight-qt](#opt-programs.moonlight-qt.enable).
- [udp514-journal](https://github.com/eworm-de/udp514-journal), a service to forward remote syslog messages to systemd-journal. Available as [services.udp514-journal](#opt-services.udp514-journal.enable).
- [RomM](https://romm.app/), a self-hosted ROM manager and player. Available as [services.romm](#opt-services.romm.enable).
- [scx_loader](https://github.com/sched-ext/scx-loader), a system daemon and DBus-based loader for sched_ext schedulers. `scxctl` is the command-line client for interacting with the loader, allowing users to switch schedulers, modes, and arguments dynamically. Available as [services.scx-loader](#opt-services.scx-loader.enable)
@@ -86,14 +84,10 @@
- [Krill](https://nlnetlabs.nl/projects/krill/about), RPKI CA and Publication Server written in Rust. Available as [services.krill](#opt-services.krill.enable).
- [vellum](https://github.com/greyxp1/vellum) is a live screen annotation overlay for Wayland. Available as [programs.vellum](#opt-programs.vellum.enable).
- [stash-clipboard](https://github.com/NotAShelf/stash), a Wayland clipboard "manager" with fast persistent history and multi-media support. Available as [services.stash-clipboard](#opt-services.stash-clipboard.enable).
- [OO7](https://github.com/linux-credentials/oo7) is a desktop-agnostic Secret Service provider. Available as [services.oo7](#opt-services.oo7.enable)
- [rosec](https://github.com/jmylchreest/rosec), a secrets daemon implementing the freedesktop.org Secret Service API with modular backend providers. It can automatically unlock the user's vault on login via PAM. Available as [services.rosec](#opt-services.rosec.enable).
- [NordVPN](https://github.com/NordSecurity/nordvpn-linux), a NordVPN client for linux. Available as [services.nordvpn](options.html#opt-services.nordvpn.enable).
- [RNSD](https://reticulum.network/), the Reticulum Network Stack Daemon. It provides a secure and efficient way to communicate over the Reticulum Network. Available as [services.rnsd](#opt-services.rnsd.enable).
@@ -106,10 +100,6 @@
- [kvrocks_exporter](https://github.com/RocksLabs/kvrocks_exporter), a Prometheus exporter for Kvrocks metrics. Available as [services.prometheus.exporters.kvrocks](#opt-services.prometheus.exporters.kvrocks.enable).
- [Umbriel](https://docs.noctalia.dev/umbriel/), a Wayland compositor built on wlroots and SceneFX. Available as [programs.umbriel](#opt-programs.umbriel.enable).
- [Rundeck](https://www.rundeck.com), Self-Service Operations [services.rundeck](#opt-services.rundeck.enable).
## Backward Incompatibilities {#sec-release-26.11-incompatibilities}
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
@@ -188,33 +178,18 @@
- `services.firezone.server.provision` has been removed due to it being unmaintanable. Remove all uses of provisioning and use the WebUI to configure firezone.
- `security.unprivilegedUsernsClone` has been removed. The option controls a sysctl only provided by the removed -hardened kernels. The removal should only affect users running custom hardened kernels.
Disabling user-namespace is possible by setting `boot.kernel.sysctl."user.max_user_namespaces"` to zero, but not generally advised, as browsers, like firefox and chrome, and many other user tools use namespaces for sandboxing.
- The `services.syncthing` module now updates the Syncthing REST API using partial updates (`PATCH`) instead of full replacements (`PUT`) for general settings. Updating these settings was broken and prone to errors after updates, see [#428808](https://github.com/NixOS/nixpkgs/issues/428808) and [#528889](https://github.com/NixOS/nixpkgs/issues/528889). As a result, settings modified manually through the Syncthing Web UI that are not explicitly defined in your Nix configuration will now persist across rebuilds.
- `services.plantuml-server.packages.jetty` now supports `jetty_12`, it no longer supports `jetty_11`.
- `services.komodo-periphery` has been updated to support version 2.0.0. Some options have been renamed to match the new configuration structure; compatibility aliases are provided for the renamed options. The `passkeys` and `outbound.onboardingKey` options have been removed; use `passkeyFiles`, `auth.privateKey`/`auth.corePublicKeys`, or `outbound.onboardingKeyFile` instead. New outbound mode configuration is available under `outbound.*`.
- `services.pfix-srsd` and the supporting `pfixtools` package have been removed, as the project is dormant and does not support pcre2. `services.postsrsd` is the recommended replacement for Sender Rewriting Scheme support with Postfix.
- `services.quake3-server.port` has been removed in favor of the structured [](#opt-services.quake3-server.settings.net_port) option. Use `services.quake3-server.settings.net_port` to set any custom UDP port directly.
- Package `overseerr` has been removed as the `overseerr` and `jellyseerr` projects were merged under `seerr`.
- The papra NixOS module is now hardening the systemd unit by default. If this breaks any of the configured directories, please reconfigure them through `services.papra.environment` to enable sandbox passthrough.
- `slskd` has been updated to v0.25.0, which renames the `global` option to `transfers`. Please review the [changelog](https://github.com/slskd/slskd/releases#release-0.25.0).
- [firefox-syncserver.database.type](#opt-services.firefox-syncserver.database.type) no longer defaults to `"mysql"`. You must now explicitly choose between `"mysql"` and `"postgresql"`. New deployments should prefer PostgreSQL.
- `chatgpt` has been retargeted to OpenAI's new ChatGPT desktop app, while the previous app has been renamed to `chatgpt-classic`.
- NetBox was updated to `>= 4.6.8`. Have a look at the breaking changes
of the [4.6 release](https://github.com/netbox-community/netbox/releases/tag/v4.6.0),
make the required changes to your database, if needed, then upgrade by setting `services.netbox.package = pkgs.netbox_4_6;` in your configuration.
## Other Notable Changes {#sec-release-26.11-notable-changes}
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
@@ -258,8 +233,6 @@
- `services.nginx` gained a [`lua`](#opt-services.nginx.lua.enable) option to enable Lua scripting via OpenResty's lua-nginx-module on a stock nginx, configuring `lua_package_path`/`lua_package_cpath` from the packages listed in [`services.nginx.lua.extraPackages`](#opt-services.nginx.lua.extraPackages). Use this to add Lua to a regular nginx; for the full OpenResty platform (libraries that rely on its bundled lualib, such as `lua-resty-openidc`), set `services.nginx.package` to `pkgs.openresty` instead — the option configures the Lua search path for it too.
- `services.nginx.virtualHosts.<name>.locations.<name>` gained a new `useGrpcErrorPages` option. If enabled, it sets up error pages that are valid gRPC messages. This is useful if you proxy gRPC and want to emit errors from nginx, for example when adding authentication on top.
- `security.polkit.settings` added for RFC42 style configuration of the polkitd daemon.
- `boot.supportedFilesystems.ntfs` installs `ntfsprogs-plus` instead of `ntfs3g` on kernel version 7.1 and later, unless `boot.supportedFilesystems.ntfs-3g` is explicitly enabled.
@@ -274,9 +247,7 @@
- `services.gitlab.registry` now uses PostgreSQL as database storage for new installations and supports old installations that use the filesystem as metadata storage. It creates the required PostgreSQL database and user. Users can manually migrate their filesystem based metadata storage. See [GitLab Container Registry Migration to database metadata store](#module-services-gitlab-registry-database-migration).
- `services.fail2ban` now supports systemd socket activation via `fail2ban.socket`
- Enabling [`services.userborn`](#opt-services.userborn.enable) on a system that was previously managed by the default `update-users-groups.pl` script now imports the legacy state from `/var/lib/nixos/` on the first switch. Locked stub entries are added to `/etc/passwd` and `/etc/group` for every name recorded in `uid-map`/`gid-map` that no longer has a live entry, so a previously-used UID/GID cannot be reassigned to a different user. Subordinate id ranges recorded in `auto-subuid-map` are seeded into the subid files as well. If the import fails, userborn does not start and the user database is left untouched. Inspect `journalctl -u userborn-import-legacy.service`, fix or remove the legacy state, and switch again. The import can be skipped entirely with [`services.userborn.importLegacyState`](#opt-services.userborn.importLegacyState)` = false`.
- Enabling [`services.userborn`](#opt-services.userborn.enable) on a system that was previously managed by the default `update-users-groups.pl` script now imports the legacy state from `/var/lib/nixos/` on the first switch. Locked stub entries are added to `/etc/passwd` and `/etc/group` for every name recorded in `uid-map`/`gid-map` that no longer has a live entry, so a previously-used UID/GID cannot be reassigned to a different user. If the import fails, userborn does not start and the user database is left untouched. Inspect `journalctl -u userborn-import-legacy.service`, fix or remove the legacy state, and switch again. The import can be skipped entirely with [`services.userborn.importLegacyState`](#opt-services.userborn.importLegacyState)` = false`.
- The `newuidmap` and `newgidmap` security wrappers are now installed with `cap_setuid`/`cap_setgid` file capabilities instead of the setuid-root bit, matching shadow's `--with-fcaps` install mode and other major distributions. Rootless containers (podman, docker-rootless, unprivileged user namespaces) are unaffected. The only behavioural change is that mapping host uid 0 via `/etc/subuid` (which NixOS never configures by default) additionally requires `cap_setfcap`; users who explicitly grant uid 0 in a subuid range can restore the previous behaviour with `security.wrappers.newuidmap.capabilities = lib.mkForce "cap_setuid,cap_setfcap+ep";`.

View File

@@ -1809,16 +1809,15 @@ class NspawnMachine(BaseMachine):
# 1. Wait for the directory to actually be created by the container
self.log(f"Waiting for journal at {journal_path}...")
warn_after = 10
max_attempts = 10
attempts = 0
while not journal_path.exists():
if proc.poll() is not None:
self.log(f"Error: Journal directory {journal_path} never appeared.")
return
while not journal_path.exists() and attempts < max_attempts:
time.sleep(1)
attempts += 1
if attempts == warn_after:
self.log(f"Still waiting for journal at {journal_path}...")
if not journal_path.exists():
self.log(f"Error: Journal directory {journal_path} never appeared.")
return
# 2. Start the journalctl process
# Using a loop here handles cases where journalctl might exit unexpectedly

View File

@@ -1,9 +1,4 @@
{
config,
lib,
options,
...
}:
{ lib, options, ... }:
let
inherit (lib) types mkOption literalMD;
@@ -31,7 +26,7 @@ in
'';
apply = lib.filterAttrs (k: v: v != null);
type = types.submodule (
{ options, ... }:
{ options, config, ... }:
{
options = {
maintainers = mkOption {
@@ -76,10 +71,7 @@ in
};
platforms = mkOption {
type = types.listOf types.raw;
default = lib.platforms.linux ++ lib.optionals (config.containers == { }) lib.platforms.darwin;
defaultText = literalMD ''
`lib.platforms.linux ++ lib.platforms.darwin` when no containers are configured; otherwise `lib.platforms.linux`.
'';
default = lib.platforms.linux ++ lib.platforms.darwin;
description = ''
Sets the [`meta.platforms`](https://nixos.org/manual/nixpkgs/stable/#var-meta-platforms) attribute on the [{option}`test`](#test-opt-test) derivation.
'';

View File

@@ -35,7 +35,8 @@ let
options = {
devnet = mkOption {
type = types.bool;
default = containers != { } && nodes != { };
default =
builtins.length (lib.attrNames containers) > 0 && builtins.length (lib.attrNames nodes) > 0;
defaultText = lib.literalMD "`true` if both VMs and containers are present.";
description = ''
This heuristic setting that assumes that the majority of tests requires VMs and containers
@@ -51,14 +52,14 @@ let
};
uid-range = mkOption {
type = types.bool;
default = containers != { };
default = builtins.length (lib.attrNames containers) > 0;
defaultText = lib.literalMD "`true` if containers are present.";
description = "Containers use systemd-nspawn, which requires pid 0 inside of the sandbox. `uid-range` enables that.";
};
kvm = mkOption {
type = types.bool;
default = isLinux && nodes != { };
defaultText = lib.literalMD "`true` if built to run on Linux and any virtual machines are specified.";
default = isLinux;
defaultText = lib.literalMD "`true` if built to run on Linux.";
description = "Whether Linux KVM virtualization is required when running this test. Can be disabled to allow emulated execution.";
};
apple-virt = mkOption {

View File

@@ -7,15 +7,20 @@ testModuleArgs@{
...
}:
let
inherit (lib) mkOption types const;
inherit (types) coercedTo lines functionTo;
inherit (lib) mkOption types;
inherit (types) either lines functionTo;
in
{
options = {
testScript = mkOption {
type = coercedTo lines const (functionTo lines);
# Only pass args the testScript function expects.
apply = v: args: v (builtins.intersectAttrs (lib.functionArgs v) args);
type = either lines (functionTo lines);
apply =
v:
if lib.isFunction v then
# Only pass args the testScript function expects.
args: v (builtins.intersectAttrs (lib.functionArgs v) args)
else
v;
description = ''
A series of python declarations and statements that you write to perform
the test.
@@ -45,19 +50,23 @@ in
withoutTestScriptReferences.includeTestScriptReferences = false;
withoutTestScriptReferences.testScript = lib.mkForce "testscript omitted";
testScriptString = config.testScript {
nodes = lib.mapAttrs (
k: v:
if v.virtualisation.useNixStoreImage then
# prevent infinite recursion when testScript would
# reference v's toplevel
config.withoutTestScriptReferences.nodesCompat.${k}
else
# reuse memoized config
v
) config.nodesCompat;
containers = config.containers;
};
testScriptString =
if lib.isFunction config.testScript then
config.testScript {
nodes = lib.mapAttrs (
k: v:
if v.virtualisation.useNixStoreImage then
# prevent infinite recursion when testScript would
# reference v's toplevel
config.withoutTestScriptReferences.nodesCompat.${k}
else
# reuse memoized config
v
) config.nodesCompat;
containers = config.containers;
}
else
config.testScript;
nodeDefaults =
{ config, name, ... }:

View File

@@ -842,7 +842,7 @@ in
users.users = {
root = {
uid = ids.uids.root;
description = mkDefault "System administrator";
description = "System administrator";
home = "/root";
shell = mkDefault cfg.defaultUserShell;
group = "root";
@@ -850,7 +850,7 @@ in
nobody = {
uid = ids.uids.nobody;
isSystemUser = true;
description = mkDefault "Unprivileged account (don't use!)";
description = "Unprivileged account (don't use!)";
group = "nogroup";
};
};

View File

@@ -9,16 +9,6 @@ let
cfg = imcfg.fcitx5;
fcitx5Package = pkgs.qt6Packages.fcitx5-with-addons.override { inherit (cfg) addons; };
settingsFormat = pkgs.formats.ini { };
mkKeyValue = lib.generators.mkKeyValueDefault {
mkValueString =
v:
if true == v then
"True"
else if false == v then
"False"
else
lib.generators.mkValueStringDefault { } v;
} "=";
in
{
options = {
@@ -141,13 +131,10 @@ in
};
in
lib.attrsets.mergeAttrsList [
(optionalFile "config" (lib.generators.toINI { inherit mkKeyValue; }) cfg.settings.globalOptions)
(optionalFile "profile" (lib.generators.toINI { inherit mkKeyValue; }) cfg.settings.inputMethod)
(optionalFile "config" (lib.generators.toINI { }) cfg.settings.globalOptions)
(optionalFile "profile" (lib.generators.toINI { }) cfg.settings.inputMethod)
(lib.concatMapAttrs (
name: value:
optionalFile "conf/${name}.conf" (lib.generators.toINIWithGlobalSection {
inherit mkKeyValue;
}) value
name: value: optionalFile "conf/${name}.conf" (lib.generators.toINIWithGlobalSection { }) value
) cfg.settings.addons)
];

View File

@@ -352,7 +352,6 @@
./programs/udevil.nix
./programs/upki.nix
./programs/usbtop.nix
./programs/vellum.nix
./programs/vim.nix
./programs/virt-manager.nix
./programs/vivid.nix
@@ -372,7 +371,6 @@
./programs/wayland/pinnacle.nix
./programs/wayland/river.nix
./programs/wayland/sway.nix
./programs/wayland/umbriel.nix
./programs/wayland/uwsm.nix
./programs/wayland/waybar.nix
./programs/wayland/wayfire.nix
@@ -784,7 +782,6 @@
./services/logging/syslog-ng.nix
./services/logging/syslogd.nix
./services/logging/SystemdJournal2Gelf.nix
./services/logging/udp514-journal.nix
./services/logging/ulogd.nix
./services/logging/vector.nix
./services/mail/automx2.nix
@@ -807,6 +804,7 @@
./services/mail/offlineimap.nix
./services/mail/opendkim.nix
./services/mail/opensmtpd.nix
./services/mail/pfix-srsd.nix
./services/mail/postfix-tlspol.nix
./services/mail/postfix.nix
./services/mail/postgrey.nix
@@ -1321,7 +1319,6 @@
./services/networking/mmsd.nix
./services/networking/modemmanager.nix
./services/networking/monero.nix
./services/networking/moonshine.nix
./services/networking/mosquitto.nix
./services/networking/mozillavpn.nix
./services/networking/mptcpd.nix
@@ -1577,7 +1574,6 @@
./services/security/physlock.nix
./services/security/pocket-id.nix
./services/security/reaction.nix
./services/security/rosec.nix
./services/security/shibboleth-sp.nix
./services/security/sks.nix
./services/security/spire/agent.nix
@@ -1824,7 +1820,6 @@
./services/web-apps/romm.nix
./services/web-apps/rss-bridge.nix
./services/web-apps/rsshub.nix
./services/web-apps/rundeck.nix
./services/web-apps/rustical.nix
./services/web-apps/rutorrent.nix
./services/web-apps/screego.nix

View File

@@ -60,7 +60,7 @@ in
description = ''
Configuration written to {file}`/etc/atuin/config.toml`.
See <https://docs.atuin.sh/latest/configuration/config/> for the full list
See <https://docs.atuin.sh/configuration/config/> for the full list
of options.
'';
};
@@ -99,7 +99,7 @@ in
{file}`/etc/atuin/themes/theme-name.toml`
where the name of each attribute is the theme-name
See <https://docs.atuin.sh/latest/guide/theming/> for the full list
See <https://docs.atuin.sh/guide/theming/> for the full list
of options.
'';
default = { };

View File

@@ -86,6 +86,9 @@ in
programs = {
cpu-energy-meter.enable = lib.mkDefault true;
};
# See <https://github.com/sosy-lab/benchexec/blob/3.18/doc/INSTALL.md#kernel-requirements>.
security.unprivilegedUsernsClone = true;
};
meta.maintainers = with lib.maintainers; [ lorenzleutgeb ];

View File

@@ -1,81 +0,0 @@
{
config,
lib,
pkgs,
...
}:
let
cfg = config.programs.vellum;
inherit (lib)
getExe
literalExpression
mkEnableOption
mkIf
mkOption
mkPackageOption
;
inherit (lib.types) separatedString;
toml = pkgs.formats.toml { };
in
{
options.programs.vellum = {
enable = mkEnableOption "vellum, a live screen annotation overlay for Wayland";
package = mkPackageOption pkgs "vellum" { };
settings = mkOption {
inherit (toml) type;
default = { };
description = ''
Configuration options for vellum.
See available options at <https://github.com/greyxp1/vellum/blob/master/docs/configuration.md>.
'';
example = literalExpression ''
{
default_tool = "arrow";
remember_last_tool = false;
feedback_duration_ms = 250;
}
'';
};
extraOptions = mkOption {
type = separatedString " ";
default = "";
description = ''
Extra command-line options to pass to
the {command}`vellum` daemon.
'';
example = "--force-backend vulkan";
};
};
config = mkIf cfg.enable {
environment = {
systemPackages = [ cfg.package ];
etc."xdg/vellum/config.toml" = mkIf (cfg.settings != { }) {
source = toml.generate "vellum-config.toml" cfg.settings;
};
};
systemd.user.services.vellum = {
description = "Vellum screen annotation overlay";
after = [ "graphical-session.target" ];
partOf = [ "graphical-session.target" ];
wantedBy = [ "graphical-session.target" ];
restartTriggers = [ config.environment.etc."xdg/vellum/config.toml".source ];
serviceConfig = {
ExecStart = "${getExe cfg.package} ${cfg.extraOptions}";
Restart = "on-failure";
};
};
};
meta = {
maintainers = with lib.maintainers; [ poz ];
};
}

View File

@@ -1,48 +0,0 @@
{
config,
lib,
pkgs,
...
}:
let
cfg = config.programs.umbriel;
in
{
options.programs.umbriel = {
enable = lib.mkEnableOption "Umbriel, a Wayland compositor built on wlroots and SceneFX";
package = lib.mkPackageOption pkgs "umbriel" { };
portalPackage = lib.mkPackageOption pkgs "xdg-desktop-portal-umbriel" { };
};
config = lib.mkIf cfg.enable (
lib.mkMerge [
{
environment.systemPackages = [ cfg.package ];
services.displayManager.sessionPackages = [ cfg.package ];
systemd.packages = [ cfg.package ];
systemd.user.services.umbriel = {
restartIfChanged = false;
enableDefaultPath = false;
};
xdg.portal = {
enable = lib.mkDefault true;
extraPortals = [ cfg.portalPackage ];
configPackages = [ cfg.portalPackage ];
};
}
(import ./wayland-session.nix {
inherit lib pkgs;
enableXWayland = false;
enableWlrPortal = false;
})
]
);
meta.maintainers = with lib.maintainers; [
samiser
pyrox0
];
}

View File

@@ -320,9 +320,6 @@ in
The Javascript version of Parsoid configured through this module does not work with modern MediaWiki versions,
and has been deprecated by upstream, so it has been removed. MediaWiki comes with a new PHP-based parser built-in, so there is no need for this module.
'')
(mkRemovedOptionModule [ "services" "pfix-srsd" ] ''
The pfixtools project is dormant and does not support pcre2. `services.postsrsd` is the recommended replacement for Sender Rewriting Scheme support with Postfix.
'')
(mkRemovedOptionModule [ "services" "pingvin-share" ] ''
The `pingvin-share.backend` package was broken and the project was archived upstream, so it was removed from nixpkgs.
'')

View File

@@ -772,7 +772,7 @@ let
description = ''
Key type to use for private keys.
For an up to date list of supported values check the --key-type option
at <https://go-acme.github.io/lego/references/ref-flags/index.html#options>.
at <https://go-acme.github.io/lego/usage/cli/options/>.
'';
};
@@ -833,7 +833,7 @@ let
'';
example = lib.literalExpression ''
{
"DNSUPDATE_TSIG_SECRET_FILE" = "/run/secrets/tsig-secret-example.org";
"RFC2136_TSIG_SECRET_FILE" = "/run/secrets/tsig-secret-example.org";
}
'';
};
@@ -852,9 +852,8 @@ let
inherit (defaultAndText "ocspMustStaple" false) default defaultText;
description = ''
Turns on the OCSP Must-Staple TLS extension.
Make sure you know what you're doing!
OCSP Must-Staple can be considered a legacy feature, that is no longer superted by Let's Encrypt. See:
- <https://letsencrypt.org/2024/12/05/ending-ocsp>
Make sure you know what you're doing! See:
- <https://blog.apnic.net/2019/01/15/is-the-web-ready-for-ocsp-must-staple/>
- <https://blog.hboeck.de/archives/886-The-Problem-with-OCSP-Stapling-and-Must-Staple-and-why-Certificate-Revocation-is-still-broken.html>
'';

View File

@@ -9,16 +9,6 @@
[ "security" "virtualization" "flushL1DataCache" ]
[ "security" "virtualisation" "flushL1DataCache" ]
)
(lib.mkRemovedOptionModule
[
"security"
"unprivilegedUsernsClone"
]
''
to disable or enable unprivileged user namespaces please use
the sysctl "user.max_user_namespaces".
''
)
];
options = {
@@ -41,6 +31,16 @@
'';
};
security.unprivilegedUsernsClone = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
When disabled, unprivileged users will not be able to create new namespaces.
By default unprivileged user namespaces are disabled.
This option only works in a hardened profile.
'';
};
security.protectKernelImage = lib.mkOption {
type = lib.types.bool;
default = false;
@@ -121,6 +121,10 @@
];
})
(lib.mkIf config.security.unprivilegedUsernsClone {
boot.kernel.sysctl."kernel.unprivileged_userns_clone" = lib.mkDefault true;
})
(lib.mkIf config.security.protectKernelImage {
# Disable hibernation (allows replacing the running kernel)
boot.kernelParams = [ "nohibernate" ];

View File

@@ -686,18 +686,6 @@ let
'';
};
rosec = {
enable = lib.mkOption {
default = false;
type = lib.types.bool;
description = ''
If enabled, pam_rosec will attempt to automatically unlock the
user's rosec vault upon login. If the user login password does not
match their vault password, rosec will prompt separately after login.
'';
};
};
enableUMask = lib.mkOption {
default = config.security.pam.enableUMask;
defaultText = lib.literalExpression "config.security.pam.enableUMask";
@@ -1221,7 +1209,6 @@ let
|| cfg.kwallet.enable
|| cfg.enableGnomeKeyring
|| cfg.oo7.enable
|| cfg.rosec.enable
|| config.services.intune.enable
|| cfg.googleAuthenticator.enable
|| cfg.gnupg.enable
@@ -1291,12 +1278,6 @@ let
control = "optional";
modulePath = "${pkgs.oo7-pam}/lib/security/pam_oo7.so";
}
{
name = "rosec";
enable = cfg.rosec.enable;
control = "optional";
modulePath = "${pkgs.rosec}/lib/security/pam_rosec.so";
}
{
name = "intune";
enable = config.services.intune.enable;
@@ -1518,12 +1499,6 @@ let
control = "optional";
modulePath = "${pkgs.oo7-pam}/lib/security/pam_oo7.so";
}
{
name = "rosec";
enable = cfg.rosec.enable;
control = "optional";
modulePath = "${pkgs.rosec}/lib/security/pam_rosec.so";
}
];
session = utils.pam.autoOrderRules [
@@ -1751,12 +1726,6 @@ let
auto_start = true;
};
}
{
name = "rosec";
enable = cfg.rosec.enable;
control = "optional";
modulePath = "${pkgs.rosec}/lib/security/pam_rosec.so";
}
{
name = "gnupg";
enable = cfg.gnupg.enable;

View File

@@ -59,9 +59,6 @@ So the raw tpm character device, the kernel RM, and `tabrmd` are all "TCTIs".
The ESAPI library speaks the client side of the TCTI protocol, and can be connected to any server TCTI.
All of the other libraries or programs that work with TPM all use ESAPI under the hood, and so a common characteristic among all these libraries is that you will find you need to configure them in some way as to which TCTI they should be talking to.
A TPM-enabled system should choose to enable either the Linux kernel resource manager or the `tabrmd` resource manager. The tpm2-software group does not have absolute guidance on this, but the userspace resource manager supports an anti-contention feature known as session un-gapping but has not seen recent development.
The kernel resource manager has seen more active development and is the resource manager of choice in immutable distributions such as Fedora Silverblue.
#### Higher Level Interfaces {#module-security-tpm2-introduction-hli}
As alluded to previously, there are a number of ways of speaking the client side TCTI that all amount to wrappers around ESAPI. They include:
@@ -76,16 +73,6 @@ As alluded to previously, there are a number of ways of speaking the client side
A typical configuration is:
```
security.tpm2 = {
enable = true;
pkcs11.enable = true;
tctiEnvironment.enable = true;
}
```
Or to use the `tpm2-abrmd` resource manager:
```
security.tpm2 = {
enable = true;
abrmd.enable = true;
@@ -98,6 +85,7 @@ security.tpm2 = {
`enable = true;` is required for any tpm functionality other than the raw character device and kernel resource manager to be available.
`abrmd.enable = true;` causes the tpm2-abrmd program (the user-space resource manager) to run as a systemd service.
Generally you want this because the user-space resource manager gets more frequent updates than the kernel-space RM, and there aren't any kernel RM features that are unavailable in the user-space RM.
`pkcs11.enable = true;` makes the PKCS11 tool and libraries available in the system path.
Generally you want this because it's unlikely to cause problems and it's required by one of the more common TPM use cases, which is protecting an ssh key using the TPM.

View File

@@ -27,7 +27,7 @@ in
options = {
services.chromadb = {
enable = mkEnableOption "ChromaDB, an open-source AI application database";
enable = mkEnableOption "ChromaDB, an open-source AI application database.";
package = mkPackageOption pkgs [ "python3Packages" "chromadb" ] { };

View File

@@ -213,7 +213,7 @@ in
initialScript = lib.mkOption {
type = lib.types.nullOr lib.types.path;
default = null;
description = "A file containing SQL statements to be executed on the first startup. Can be used for granting certain permissions on the database. Run as superuser.";
description = "A file containing SQL statements to be executed on the first startup. Can be used for granting certain permissions on the database.";
};
ensureDatabases = lib.mkOption {

View File

@@ -15,16 +15,9 @@ let
;
cfg = config.services.quake3-server;
toQuake3Value = value: if lib.isBool value then (if value then "1" else "0") else toString value;
toQuake3Config =
settings:
lib.concatStrings (
lib.mapAttrsToList (name: value: ''seta ${name} "${toQuake3Value value}"'' + "\n") settings
);
configFile = pkgs.writeText "q3ds-extra.cfg" ''
${toQuake3Config cfg.settings}
set net_port ${toString cfg.port}
${cfg.extraConfig}
'';
@@ -57,19 +50,19 @@ let
'';
in
{
imports = [
(lib.mkRenamedOptionModule
[ "services" "quake3-server" "port" ]
[ "services" "quake3-server" "settings" "net_port" ]
)
];
options = {
services.quake3-server = {
enable = mkEnableOption "Quake 3 dedicated server";
package = lib.mkPackageOption pkgs "ioquake3" { };
port = mkOption {
type = types.port;
default = 27960;
description = ''
UDP Port the server should listen on.
'';
};
openFirewall = mkOption {
type = types.bool;
default = false;
@@ -78,59 +71,16 @@ in
'';
};
settings = mkOption {
type = types.submodule {
freeformType = types.attrsOf (
types.nullOr (
types.oneOf [
types.str
types.bool
types.int
types.float
types.port
]
)
);
options = {
net_port = lib.mkOption {
type = lib.types.port;
default = 27960;
description = "UDP port for the dedicated server to bind to.";
};
};
};
default = { };
example = {
sv_hostname = "My Quake 3 server";
g_gametype = 0;
sv_pure = true;
};
description = ''
Quake 3 cvars set via `seta` on server start (i.e. persisted,
archive-flagged cvars the vast majority of server settings).
Note that options changed via RCON will not be persisted. To list
all possible options, use "cvarlist 1" via RCON.
'';
};
extraConfig = mkOption {
type = types.lines;
default = "";
example = ''
// map rotation and other things that don't map onto plain cvars
set d1 "map q3dm1 ; set nextmap vstr d2"
set d2 "map q3dm7 ; set nextmap vstr d1"
vstr d1
// rarely needed: cvars with a non-seta flag
sets sv_privatePassword "hidden"
seta rconPassword "superSecret" // sets RCON password for remote console
seta sv_hostname "My Quake 3 server" // name that appears in server list
'';
description = ''
Extra configuration lines appended after `settings`, for anything
that isn't a plain persisted cvar: map-rotation scripts, `exec`,
`vstr`, aliases, or cvars that need `set`/`sets`/`sett`/`setu`
instead of `seta`. Note that options changed via RCON will not be
persisted. To list all possible options, use "cvarlist 1" via RCON.
Extra configuration options. Note that options changed via RCON will not be persisted. To list all possible
options, use "cvarlist 1" via RCON.
'';
};
@@ -153,7 +103,7 @@ in
baseq3InStore = builtins.typeOf cfg.baseq3 == "set";
in
mkIf cfg.enable {
networking.firewall.allowedUDPPorts = mkIf cfg.openFirewall [ cfg.settings.net_port ];
networking.firewall.allowedUDPPorts = mkIf cfg.openFirewall [ cfg.port ];
systemd.services.q3ds = {
description = "Quake 3 dedicated server";
@@ -165,7 +115,7 @@ in
serviceConfig = with lib; {
Restart = "always";
DynamicUser = true;
WorkingDirectory = if baseq3InStore then home else cfg.baseq3;
WorkingDirectory = home;
# It is possible to alter configuration files via RCON. To ensure reproducibility we have to prevent this
ReadOnlyPaths = if baseq3InStore then home else cfg.baseq3;

View File

@@ -1,95 +0,0 @@
{
config,
lib,
pkgs,
...
}:
let
cfg = config.services.udp514-journal;
description = "Forward syslog from network (udp/514) to journal";
in
{
options = {
services.udp514-journal = {
enable = lib.mkEnableOption "the udp514-journal systemd socket/service";
openFirewall = lib.mkEnableOption "" // {
description = "Whether to open the port in the firewall.";
};
port = lib.mkOption {
type = lib.types.port;
default = 514;
description = "Port to listen on";
};
package = lib.mkPackageOption pkgs "udp514-journal" { };
};
};
config = lib.mkIf cfg.enable {
systemd.sockets.udp514-journal = {
enable = true;
name = "udp514-journal.socket";
inherit description;
listenDatagrams = [ (builtins.toString cfg.port) ];
wantedBy = [ "sockets.target" ];
};
systemd.services.udp514-journal = {
enable = true;
name = "udp514-journal.service";
inherit description;
requires = [
"systemd-journald.socket"
"udp514-journal.socket"
];
serviceConfig = {
Type = "notify";
Restart = "always";
ExecStart = "${cfg.package}/bin/udp514-journal";
DynamicUser = "on";
CapabilityBoundingSet = "";
AmbientCapabilities = "";
ProtectSystem = "strict";
ProtectHome = "on";
PrivateDevices = "on";
PrivateTmp = true;
PrivateUsers = "self";
PrivateNetwork = "on";
RestrictAddressFamilies = [ "AF_UNIX" ];
RestrictNamespaces = true;
RestrictSUIDSGID = true;
RestrictRealtime = true;
LockPersonality = true;
SystemCallArchitectures = "native";
SystemCallFilter = [
"@system-service"
"~@privileged"
"~@resources"
];
ProtectClock = true;
ProtectHostname = true;
ProtectKernelLogs = true;
ProtectKernelModules = true;
ProtectKernelTunables = "on";
ProtectControlGroups = "strict";
ProtectProc = "noaccess";
ProcSubset = "pid";
MemoryDenyWriteExecute = true;
NoNewPrivileges = true;
MemoryMax = "5M";
UMask = "0077";
};
confinement = {
enable = true;
binSh = null;
};
};
networking.firewall.allowedUDPPorts = lib.mkIf cfg.openFirewall [ cfg.port ];
};
meta.maintainers = with lib.maintainers; [ usovalx ];
}

View File

@@ -0,0 +1,81 @@
{
config,
lib,
pkgs,
...
}:
let
cfg = config.services.pfix-srsd;
in
{
###### interface
options = {
services.pfix-srsd = {
enable = lib.mkOption {
default = false;
type = lib.types.bool;
description = "Whether to run the postfix sender rewriting scheme daemon.";
};
domain = lib.mkOption {
description = "The domain for which to enable srs";
type = lib.types.str;
example = "example.com";
};
secretsFile = lib.mkOption {
description = ''
The secret data used to encode the SRS address.
to generate, use a command like:
`for n in $(seq 5); do dd if=/dev/urandom count=1 bs=1024 status=none | sha256sum | sed 's/ -$//' | sed 's/^/ /'; done`
'';
type = lib.types.path;
default = "/var/lib/pfix-srsd/secrets";
};
configurePostfix = lib.mkOption {
type = lib.types.bool;
default = true;
description = ''
Whether to configure the required settings to use pfix-srsd in the local Postfix instance.
'';
};
};
};
###### implementation
config = lib.mkMerge [
(lib.mkIf (cfg.enable && cfg.configurePostfix && config.services.postfix.enable) {
services.postfix.settings.main = {
sender_canonical_maps = [ "tcp:127.0.0.1:10001" ];
sender_canonical_classes = [ "envelope_sender" ];
recipient_canonical_maps = [ "tcp:127.0.0.1:10002" ];
recipient_canonical_classes = [ "envelope_recipient" ];
};
})
(lib.mkIf cfg.enable {
environment = {
systemPackages = [ pkgs.pfixtools ];
};
systemd.services.pfix-srsd = {
description = "Postfix sender rewriting scheme daemon";
before = [ "postfix.service" ];
#note that we use requires rather than wants because postfix
#is unable to process (almost) all mail without srsd
requiredBy = [ "postfix.service" ];
serviceConfig = {
Type = "forking";
PIDFile = "/run/pfix-srsd.pid";
ExecStart = "${pkgs.pfixtools}/bin/pfix-srsd -p /run/pfix-srsd.pid -I ${config.services.pfix-srsd.domain} ${config.services.pfix-srsd.secretsFile}";
};
};
})
];
}

View File

@@ -1296,5 +1296,6 @@ in
[ "services" "postfix" "settings" "main" "smtp_tls_security_level" ]
(config: lib.mkIf config.services.postfix.useDane "dane")
)
(lib.mkRenamedOptionModule [ "services" "postfix" "useSrs" ] [ "services" "pfix-srsd" "enable" ])
];
}

View File

@@ -74,7 +74,7 @@ in
default = null;
description = ''
Environment file, used to set any secret ATUIN_* environment variables, such as ATUIN_DB_URI containing a password.
See <https://docs.atuin.sh/latest/self-hosting/server-setup/#configuration> for available environment variables.
See https://docs.atuin.sh/cli/self-hosting/server-setup/#configuration for available environment variables.
'';
};
};

View File

@@ -6,6 +6,7 @@
}:
let
cfg = config.services.portunus;
in
{
options.services.portunus = {
@@ -78,15 +79,9 @@ in
type = lib.types.listOf (
lib.types.submodule {
options = {
redirectURIs = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [ ];
description = "URLs where the OIDC client should redirect";
};
callbackURL = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = "URL where the OIDC client should redirect (deprecated, use redirectURIs)";
type = lib.types.str;
description = "URL where the OIDC client should redirect";
};
id = lib.mkOption {
type = lib.types.str;
@@ -98,7 +93,7 @@ in
default = [ ];
example = [
{
redirectURIs = [ "https://example.com/client/oidc/callback" ];
callbackURL = "https://example.com/client/oidc/callback";
id = "service";
}
];
@@ -232,7 +227,7 @@ in
staticClients = lib.forEach cfg.dex.oidcClients (client: {
inherit (client) id;
redirectURIs = client.redirectURIs ++ lib.optional (client.callbackURL != null) client.callbackURL;
redirectURIs = [ client.callbackURL ];
name = "OIDC for ${client.id}";
secretEnv = "DEX_CLIENT_${client.id}";
});

View File

@@ -71,7 +71,7 @@ in
serviceConfig = {
ExecStartPre = [
"${cfg.package}/bin/beszel-hub migrate up"
"${cfg.package}/bin/beszel-hub migrate history-sync"
"${cfg.package}/bin/beszel-hub history-sync"
];
ExecStart = ''
${cfg.package}/bin/beszel-hub serve --http='${cfg.host}:${toString cfg.port}'

View File

@@ -2090,6 +2090,7 @@ in
serviceConfig = {
ExecStartPre = [
"${lib.getExe' pkgs.coreutils "ln"} -fs ${cfg.package}/share/grafana/conf ${cfg.dataDir}"
"${lib.getExe' pkgs.coreutils "ln"} -fs ${cfg.package}/share/grafana/tools ${cfg.dataDir}"
];
ExecStart = "${lib.getExe cfg.package} server -homepath ${cfg.dataDir} -config ${configFile}";

View File

@@ -20,7 +20,8 @@ let
settings =
if (cfg.settings != null) then
lib.recursiveUpdate cfg.settings (
cfg.settings
// (
if cfg.settings.schema_version < 23 then
{
bind_host = cfg.host;
@@ -191,9 +192,8 @@ in
# Note: --check-config has the side effect of modifying the file at rest!
${lib.getExe cfg.package} -c "$STATE_DIRECTORY/AdGuardHome.yaml" --check-config
# sed operation needed to fix protection_disabled_until value changed by yaml-merge
${lib.getExe pkgs.yaml-merge} "$STATE_DIRECTORY/AdGuardHome.yaml" "${configFile}" \
| sed -E "s/(protection_disabled_until: [0-9]{4}-[0-9]{2}-[0-9]{2}) /\1T/" > "$STATE_DIRECTORY/AdGuardHome.yaml.tmp"
# Writing directly to AdGuardHome.yaml results in empty file
${lib.getExe pkgs.yaml-merge} "$STATE_DIRECTORY/AdGuardHome.yaml" "${configFile}" > "$STATE_DIRECTORY/AdGuardHome.yaml.tmp"
mv "$STATE_DIRECTORY/AdGuardHome.yaml.tmp" "$STATE_DIRECTORY/AdGuardHome.yaml"
else
${installFresh}

View File

@@ -35,12 +35,6 @@ in
package = lib.mkPackageOption pkgs "crab-hole" { };
openFirewall = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Open ports in the firewall for crab-hole's DNS server.";
};
supplementaryGroups = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [ ];
@@ -176,11 +170,6 @@ in
RestartSec = 1;
};
};
networking.firewall = lib.mkIf cfg.openFirewall {
allowedUDPPorts = [ 53 ];
allowedTCPPorts = [ 53 ];
};
};
meta.maintainers = [

View File

@@ -1,188 +0,0 @@
{
config,
lib,
pkgs,
...
}:
let
cfg = config.services.moonshine;
tomlFormat = pkgs.formats.toml { };
configFile = tomlFormat.generate "moonshine-config.toml" cfg.settings;
runScript = pkgs.writeShellScriptBin "moonshine-server" ''
export XDG_RUNTIME_DIR="''${XDG_RUNTIME_DIR:-/run/user/$(${lib.getExe' pkgs.coreutils "id"} -u)}"
export DBUS_SESSION_BUS_ADDRESS="''${DBUS_SESSION_BUS_ADDRESS:-unix:path=$XDG_RUNTIME_DIR/bus}"
exec ${lib.getExe cfg.package} ${configFile} "$@"
'';
in
{
options.services.moonshine = {
enable = lib.mkEnableOption "Moonshine, a headless game streaming server for Moonlight clients";
package = lib.mkPackageOption pkgs "moonshine" { };
user = lib.mkOption {
type = lib.types.nonEmptyStr;
example = "alice";
description = ''
User under which to run Moonshine. The user must be declared separately
in {option}`users.users`. Lingering is enabled automatically so the
server can run without an active login session.
'';
};
settings = lib.mkOption {
type = tomlFormat.type;
default = { };
example = lib.literalExpression ''
{
name = "my-desktop";
address = "0.0.0.0";
application = [
{
title = "Steam";
command = [ "steam" "steam://open/bigpicture" ];
}
];
application_scanner = [
{
type = "steam";
library = "$HOME/.local/share/Steam";
command = [ "steam" "-bigpicture" "steam://rungameid/{game_id}" ];
}
];
}
'';
description = ''
Moonshine configuration, generated as a TOML file in the Nix store.
See <https://github.com/hgaiser/moonshine/blob/main/moonshine-core/src/config.rs>
for the available settings and <https://github.com/hgaiser/moonshine#configuration> for some examples.
Do not leave this option empty: Moonshine's upstream defaults configure
Steam at {file}`/usr/bin/steam`, which does not exist on NixOS. Define
at least `application` with an executable in the Nix store, as shown in
the example. Setting `application` explicitly is sufficient;
`application_scanners` may be omitted.
Moonshine stores {file}`cert.pem` and {file}`key.pem` in
{file}`~/.config/moonshine/`, and paired-client state in
{file}`~/.local/share/moonshine/state.toml` for the configured user.
Since the service runs without a desktop session, its notification
action cannot reliably open the pairing page. Pair clients by visiting
{file}`http://<host>:47989/pin` in a browser instead.
'';
};
extraPackages = lib.mkOption {
type = lib.types.listOf lib.types.package;
default = [ ];
example = lib.literalExpression "[ pkgs.steam ]";
description = ''
Packages added to the service's {env}`PATH` for applications launched
by Moonshine.
'';
};
environment = lib.mkOption {
type = lib.types.attrsOf lib.types.str;
default = { };
example = {
MESA_VK_DEVICE_SELECT = "10de:25a2!";
};
description = ''
Environment variables set for Moonshine.
::: {.note}
Those are not inherited by launched applications.
:::
'';
};
firewallInterfaces = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [ ];
example = [
"tailscale0"
"wg0"
];
description = ''
Network interfaces on which to open the Moonlight/GameStream ports.
The ports are not opened when this list is empty.
Moonshine is not designed for use on public networks. Do not expose Moonshine ports directly to the internet. See https://github.com/hgaiser/moonshine#security
'';
};
};
config = lib.mkIf cfg.enable {
assertions = [
{
assertion = lib.hasAttr cfg.user config.users.users;
message = "services.moonshine.user refers to undeclared user '${cfg.user}'.";
}
];
boot.kernelModules = [
"uinput"
"uhid"
];
environment.systemPackages = [ cfg.package ];
# Make the implicit WSI Vulkan layer available to launched applications.
hardware.graphics = {
enable = true;
extraPackages = [ cfg.package ];
};
networking.firewall.interfaces = lib.genAttrs cfg.firewallInterfaces (_: {
allowedTCPPorts = [
(cfg.settings.webserver.port_https or 47984)
(cfg.settings.webserver.port or 47989)
(cfg.settings.stream.port or 48010)
];
allowedUDPPorts = [
5353 # moonshine has an embedded mDNS responder that does not conflict with avahi
(cfg.settings.stream.video.port or 47998)
(cfg.settings.stream.control.port or 47999)
(cfg.settings.stream.audio.port or 48000)
];
});
services.udev.packages = [ cfg.package ];
systemd.services.moonshine = {
description = "Streaming server using the NVIDIA GameStream / Moonlight protocol.";
wantedBy = [ "multi-user.target" ];
after = [ "network.target" ];
path = [ pkgs.xwayland ] ++ cfg.extraPackages;
environment = {
MOONSHINE_LOG = "moonshine=info";
}
// cfg.environment;
serviceConfig = {
User = cfg.user;
SupplementaryGroups = [ "moonshine" ];
ExecStart = lib.getExe runScript;
Restart = "on-failure";
RestartSec = 5;
DeviceAllow = [
"/dev/uinput rw"
"/dev/uhid rw"
"char-drm rw"
"char-nvidia rw"
"char-nvidia-uvm rw"
];
};
};
users = {
groups.moonshine = { };
users.${cfg.user} = {
linger = true;
extraGroups = [ "input" ];
};
};
};
}

View File

@@ -1049,7 +1049,7 @@ in
};
syncthing-init = lib.mkIf (cleanedConfig != { }) {
description = "Syncthing configuration updater";
requires = [ "syncthing.service" ];
requisite = [ "syncthing.service" ];
after = [ "syncthing.service" ];
wantedBy = [ "multi-user.target" ];

View File

@@ -825,7 +825,6 @@ in
RestrictSUIDSGID = true;
ExecReload = [
" " # This is needed to clear the ExecReload definitions from upstream
"${lib.getExe' pkgs.util-linux "kill"} -HUP $MAINPID"
];
ExecStart = [
" " # This is needed to clear the ExecStart definitions from upstream

View File

@@ -400,8 +400,12 @@ in
# Security
NoNewPrivileges = true;
# Directory
RuntimeDirectory = "fail2ban";
RuntimeDirectoryMode = "0750";
StateDirectory = "fail2ban";
StateDirectoryMode = "0750";
LogsDirectory = "fail2ban";
LogsDirectoryMode = "0750";
# Sandboxing
ProtectSystem = "strict";
ProtectHome = true;
@@ -413,10 +417,6 @@ in
ProtectControlGroups = true;
};
};
systemd.sockets.fail2ban.wantedBy = [
"sockets.target"
"fail2ban.service"
];
# Defaults for the daemon settings
services.fail2ban.daemonSettings.Definition = {

View File

@@ -1,50 +0,0 @@
{
config,
lib,
pkgs,
...
}:
let
cfg = config.services.rosec;
in
{
options.services.rosec = {
enable = lib.mkEnableOption "rosec, a secrets daemon implementing the freedesktop.org Secret Service API";
package = lib.mkPackageOption pkgs "rosec" { };
pam = {
enable = lib.mkEnableOption "PAM integration to automatically unlock the rosec vault on login";
services = lib.mkOption {
type = with lib.types; listOf str;
default = [ "login" ];
example = [
"login"
"greetd"
];
description = ''
List of PAM services for which to enable rosec automatic unlock.
'';
};
};
};
config = lib.mkIf cfg.enable {
environment.systemPackages = [ cfg.package ];
services.dbus.packages = [ cfg.package ];
systemd.packages = [ cfg.package ];
xdg.portal.extraPortals = [ cfg.package ];
security.pam.services = lib.mkIf cfg.pam.enable (
lib.genAttrs cfg.pam.services (_: {
rosec.enable = true;
})
);
};
meta.maintainers = with lib.maintainers; [ mikilio ];
}

View File

@@ -149,11 +149,6 @@ in
default = "tinyauth";
description = "Group account under which Tinyauth runs.";
};
enableUnixSocket = mkEnableOption (
"a UNIX domain socket at `/run/tinyauth/tinyauth.sock`"
+ " instead of listening on an IP address and port."
);
};
config = mkIf cfg.enable {
@@ -179,7 +174,6 @@ in
GIN_MODE = "release";
TINYAUTH_DATABASE_PATH = "${cfg.dataDir}/tinyauth.db";
TINYAUTH_RESOURCES_PATH = "${cfg.dataDir}/resources";
TINYAUTH_SERVER_SOCKETPATH = mkIf cfg.enableUnixSocket "%t/tinyauth/tinyauth.sock";
};
serviceConfig = {
@@ -187,8 +181,6 @@ in
User = cfg.user;
Group = cfg.group;
WorkingDirectory = cfg.dataDir;
RuntimeDirectory = mkIf cfg.enableUnixSocket "tinyauth";
RuntimeDirectoryMode = mkIf cfg.enableUnixSocket "750";
ExecStart = getExe cfg.package;
Restart = "always";
@@ -232,7 +224,7 @@ in
"~@privileged"
"~@resources"
];
UMask = if cfg.enableUnixSocket then "0007" else "0077";
UMask = "0077";
};
};

View File

@@ -31,15 +31,6 @@ let
;
isNormal = opts.isNormalUser;
shell = utils.toShellPath opts.shell;
autoSubIdRange = opts.autoSubUidGidRange;
subUidRanges = map (r: {
start = r.startUid;
inherit (r) count;
}) opts.subUidRanges;
subGidRanges = map (r: {
start = r.startGid;
inherit (r) count;
}) opts.subGidRanges;
}) (lib.filterAttrs (_: u: u.enable) config.users.users);
};
@@ -56,19 +47,12 @@ let
previousConfigPath = "/var/lib/userborn/previous-userborn.json";
immutableEtc = config.system.etc.overlay.enable && !config.system.etc.overlay.mutable;
# The files live outside /etc and need to be linked or bind-mounted there.
filesOutsideEtc = !cfg.static && cfg.passwordFilesLocation != "/etc";
# The filenames created by userborn.
passwordFiles = [
"group"
"passwd"
"shadow"
];
# newuidmap opens these with O_NOFOLLOW, no symlinks in /etc.
subIdFiles = [
"subuid"
"subgid"
];
in
{
@@ -109,9 +93,6 @@ in
write the files directly to `/etc`.
However this can also serve other use cases, e.g. when `/etc` is on a `tmpfs`.
The subid files are an exception: `newuidmap` rejects symlinks, so
they are bind-mounted into `/etc` instead of being symlinked.
'';
};
@@ -247,16 +228,13 @@ in
# Make the source files writable before executing userborn.
(lib.mkIf (!userCfg.mutableUsers) (
lib.map (file: "-${pkgs.util-linux}/bin/umount ${cfg.passwordFilesLocation}/${file}") (
passwordFiles ++ subIdFiles
)
lib.map (file: "-${pkgs.util-linux}/bin/umount ${cfg.passwordFilesLocation}/${file}") passwordFiles
))
];
ExecStartPost =
if userCfg.mutableUsers then
# Store the config so the next run can tell declarative changes
# from manual edits (see USERBORN_PREVIOUS_CONFIG).
# Store the config somewhere for the next invocation
[
"${pkgs.coreutils}/bin/ln -sf ${userbornConfigJson} ${previousConfigPath}"
]
@@ -265,33 +243,9 @@ in
(lib.map (
file:
"${pkgs.util-linux}/bin/mount --bind -o ro ${cfg.passwordFilesLocation}/${file} ${cfg.passwordFilesLocation}/${file}"
) (passwordFiles ++ subIdFiles));
) passwordFiles);
};
};
# Bind-mount the subid files into /etc when they live elsewhere,
# newuidmap rejects symlinks.
mounts = lib.mkIf filesOutsideEtc (
map (file: {
what = "${cfg.passwordFilesLocation}/${file}";
where = "/etc/${file}";
type = "none";
options = "bind";
after = [ "userborn.service" ];
requires = [ "userborn.service" ];
wantedBy = [ "sysinit.target" ];
requiredBy = [ "sysinit-reactivation.target" ];
before = [
"sysinit.target"
"sysinit-reactivation.target"
"shutdown.target"
];
conflicts = [ "shutdown.target" ];
# Re-mount after userborn's atomic rename replaces the inode.
restartTriggers = [ userbornConfigJson ];
unitConfig.DefaultDependencies = false;
}) subIdFiles
);
};
environment.etc = lib.mkMerge [
@@ -304,11 +258,11 @@ in
source = "${userbornStaticFiles}/${file}";
mode = if file == "shadow" then "0000" else "0644";
}
) (passwordFiles ++ subIdFiles)
) passwordFiles
)
))
(lib.mkIf filesOutsideEtc (
(lib.mkIf (!cfg.static && cfg.passwordFilesLocation != "/etc") (
# Statically create the symlinks to passwordFilesLocation when they're not
# inside /etc because we will not be able to do it at runtime in case of a
# (non-static) immutable /etc!
@@ -322,19 +276,6 @@ in
) passwordFiles
)
))
(lib.mkIf filesOutsideEtc (
# Placeholder mount points for the subid bind mounts.
lib.listToAttrs (
lib.map (
file:
lib.nameValuePair file {
text = "";
mode = "0644";
}
) subIdFiles
)
))
];
};

View File

@@ -160,10 +160,6 @@ in
);
environment.systemPackages = [ cfg.package ];
# Install at least one monospace font, as otherwise the fallback is DejaVu Sans, a non-monospace font
fonts.packages = [ pkgs.hack-font ];
systemd.packages = [ cfg.package ];
systemd.services."kmsconvt@" = {

View File

@@ -787,7 +787,6 @@ in
# Caches
PrivateTmp = true;
TemporaryFileSystem = "/dev/shm:mode=1777,nosuid,nodev";
CacheDirectory = [
"frigate"
# https://github.com/blakeblackshear/frigate/discussions/18129

View File

@@ -342,17 +342,10 @@ in
'';
};
};
virtualHosts.${domainFor "albums"} = {
forceSSL = mkDefault true;
locations."/" = {
root = webPackage "albums";
tryFiles = "$uri $uri.html /index.html";
extraConfig = ''
add_header Access-Control-Allow-Origin 'https://${cfgWeb.domains.api}';
'';
};
};
virtualHosts.${domainFor "photos"} = {
serverAliases = [
(domainFor "albums") # the albums app is shared with the photos frontend
];
forceSSL = mkDefault true;
locations."/" = {
root = webPackage "photos";

View File

@@ -137,15 +137,7 @@ in
host = mkOption {
type = types.str;
default = "localhost";
example = ""; # all interfaces
# hint: the use of "" for IMMICH_HOST is not documented
# see https://docs.immich.app/install/environment-variables/#ports
# or https://github.com/immich-app/immich/blob/767caf9bfec2ec74ebdef6f58643ee9505da8550/docs/docs/install/environment-variables.md?plain=1#L70
# impl: https://github.com/immich-app/immich/blob/60f4dedb2991c8356d2977f1dc9cfa2cf666788c/server/src/app.common.ts#L90
description = ''
The host that immich will listen on.
Set to an empty string (`""`) to listen on all interfaces.
'';
description = "The host that immich will listen on.";
};
port = mkOption {
type = types.port;

View File

@@ -109,12 +109,12 @@ let
'';
dbAddr =
if cfg.database.type == "postgres" then
(if cfg.database.socket == null then cfg.database.host else cfg.database.socket)
else if cfg.database.socket == null then
if cfg.database.socket == null then
"${cfg.database.host}:${toString cfg.database.port}"
else if cfg.database.type == "mysql" then
"${cfg.database.host}:${cfg.database.socket}"
else if cfg.database.type == "postgres" then
"${cfg.database.socket}"
else
throw "Unsupported database type: ${cfg.database.type} for socket: ${cfg.database.socket}";

View File

@@ -434,12 +434,11 @@ in
package = lib.mkOption {
type = types.package;
default =
if lib.versionAtLeast config.system.stateVersion "26.11" then pkgs.netbox_4_6 else pkgs.netbox_4_5;
if lib.versionAtLeast config.system.stateVersion "26.05" then pkgs.netbox_4_5 else pkgs.netbox_4_4;
defaultText = lib.literalExpression ''
if lib.versionAtLeast config.system.stateVersion "26.11" then
pkgs.netbox_4_6
else
pkgs.netbox_4_5;
if lib.versionAtLeast config.system.stateVersion "26.05"
then pkgs.netbox_4_5
else pkgs.netbox_4_4;
'';
description = ''
NetBox package to use.

View File

@@ -8,22 +8,14 @@ let
cfg = config.services.papra;
defaultUser = "papra";
defaultGroup = "papra";
defaultEnv = {
SERVER_SERVE_PUBLIC_DIR = true;
PORT = 1221;
DATABASE_URL = "file:/var/lib/papra/db.sqlite";
DOCUMENT_STORAGE_FILESYSTEM_ROOT = "/var/lib/papra/local-documents";
};
in
{
imports = [
(lib.mkChangedOptionModule
[ "services" "papra" "environmentFile" ]
[ "services" "papra" "environmentFiles" ]
(
config:
let
value = lib.getAttrFromPath [ "services" "papra" "environmentFile" ] config;
in
if value == null then [ ] else [ value ]
)
)
];
options = {
services.papra = {
enable = lib.mkEnableOption "Papra";
@@ -45,103 +37,31 @@ in
package = lib.mkPackageOption pkgs "papra" { };
openFirewall = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
Whether to open the firewall for Papra.
'';
};
environment = lib.mkOption {
type = lib.types.submodule {
freeformType =
with lib.types;
attrsOf (oneOf [
str
int
float
bool
path
package
]);
options = {
PORT = lib.mkOption {
type = lib.types.port;
default = 1221;
description = ''
The port on which Papra listens.
See <https://docs.papra.app/self-hosting/configuration/#port> for more information.
'';
};
DATABASE_URL = lib.mkOption {
type = lib.types.str;
default = "file:/var/lib/papra/db.sqlite";
description = ''
The URL of the database.
See <https://docs.papra.app/self-hosting/configuration/#database_url> for more information.
::: {.note}
When specifying a `file:` URL with an absolute path through this option,
the database's parent directory is automatically added to the systemd
service's `ReadWritePaths`. Other local database paths, including paths
specified through `environmentFiles`, may need to be added to `ReadWritePaths` manually.
:::
'';
};
INGESTION_FOLDER_ROOT_PATH = lib.mkOption {
type = lib.types.path;
default = "/var/lib/papra/ingestion";
description = ''
The root directory in which ingestion folders for each organization are stored.
The parent directory must already exist if using a custom path.
See <https://docs.papra.app/self-hosting/configuration/#ingestion_folder_root_path> for more information.
'';
};
DOCUMENT_STORAGE_FILESYSTEM_ROOT = lib.mkOption {
type = lib.types.path;
default = "/var/lib/papra/local-documents";
description = ''
The root directory to store documents in.
The parent directory must already exist if using a custom path.
See <https://docs.papra.app/self-hosting/configuration/#document_storage_filesystem_root> for more information.
'';
};
SERVER_SERVE_PUBLIC_DIR = lib.mkOption {
type = lib.types.bool;
default = true;
description = ''
Whether to serve the public directory.
See <https://docs.papra.app/self-hosting/configuration/#server_serve_public_dir> for more information.
'';
};
};
type =
with lib.types;
attrsOf (oneOf [
str
int
float
bool
path
package
]);
default = defaultEnv;
example = {
PORT = 1221;
};
default = { };
description = ''
Environment variables to pass to Papra.
See <https://docs.papra.app/self-hosting/configuration/#configuration-variables> for more information.
'';
description = "Environment variables to set for the service.";
};
environmentFiles = lib.mkOption {
type = with lib.types; listOf path;
default = [ ];
example = [ "/run/secrets/papra.env" ];
description = ''
Files to load environment variables from in addition to [](#opt-services.papra.environment).
This is useful to avoid putting secrets into the nix store.
See <https://docs.papra.app/self-hosting/configuration/#configuration-variables> for more information.
'';
environmentFile = lib.mkOption {
type = with lib.types; nullOr path;
default = null;
description = "Environment file, usefult to provide secrets to the service";
};
};
};
config = lib.mkIf cfg.enable {
users = {
users = lib.optionalAttrs (cfg.user == defaultUser) {
@@ -156,18 +76,6 @@ in
};
};
systemd.tmpfiles.settings."10-papra" = {
"${cfg.environment.DOCUMENT_STORAGE_FILESYSTEM_ROOT}".d = {
mode = "0700";
inherit (cfg) user group;
};
"${cfg.environment.INGESTION_FOLDER_ROOT_PATH}".d = {
mode = "0770";
inherit (cfg) user group;
};
};
systemd.services.papra = {
wantedBy = [ "multi-user.target" ];
serviceConfig = {
@@ -177,58 +85,15 @@ in
User = cfg.user;
Group = cfg.group;
StateDirectory = "papra";
StateDirectoryMode = "0700";
EnvironmentFile = cfg.environmentFiles;
ReadWritePaths = lib.unique (
[
cfg.environment.DOCUMENT_STORAGE_FILESYSTEM_ROOT
cfg.environment.INGESTION_FOLDER_ROOT_PATH
]
++ lib.optional (lib.hasPrefix "file:/" cfg.environment.DATABASE_URL) (
dirOf (lib.removePrefix "file:" cfg.environment.DATABASE_URL)
)
);
# Hardening
CapabilityBoundingSet = "";
NoNewPrivileges = true;
LockPersonality = true;
PrivateDevices = true;
PrivateTmp = true;
ProcSubset = "pid";
ProtectClock = true;
ProtectControlGroups = true;
ProtectHome = true;
ProtectHostname = true;
ProtectKernelLogs = true;
ProtectKernelModules = true;
ProtectKernelTunables = true;
ProtectProc = "invisible";
ProtectSystem = "strict";
RemoveIPC = true;
RestrictAddressFamilies = [
"AF_UNIX"
"AF_INET"
"AF_INET6"
];
RestrictNamespaces = true;
RestrictRealtime = true;
RestrictSUIDSGID = true;
SystemCallArchitectures = "native";
SystemCallFilter = [
"@system-service"
"~@privileged"
"~@resources"
];
UMask = "0007";
EnvironmentFile = cfg.environmentFile;
};
environment = lib.mapAttrs (
_: s: if lib.isBool s then lib.boolToString s else toString s
) cfg.environment;
};
networking.firewall = lib.mkIf cfg.openFirewall {
allowedTCPPorts = [ cfg.environment.PORT ];
environment =
let
environmentwithDefaults = defaultEnv // cfg.environment;
in
(lib.mapAttrs (
_: s: if lib.isBool s then lib.boolToString s else toString s
) environmentwithDefaults);
};
};

View File

@@ -1,651 +0,0 @@
{
config,
lib,
pkgs,
...
}:
let
cfg = config.services.rundeck;
settingsFormat = pkgs.formats.javaProperties { };
effectivePort = if cfg.ssl.enable then cfg.ssl.port else cfg.serverPort;
scheme = if cfg.ssl.enable then "https" else "http";
configFile = settingsFormat.generate "rundeck-config.properties" cfg.settings;
frameworkFile = settingsFormat.generate "framework.properties" cfg.frameworkSettings;
realmFile = pkgs.writeText "realm.properties" ''
${cfg.adminUser}:@ADMIN_PASSWORD@,user,admin
'';
replaceSecret =
placeholder: file: target:
"replace-secret ${
lib.escapeShellArgs [
placeholder
file
target
]
}";
rundeckStartScript = pkgs.writeShellScript "start-rundeck" ''
# Generate SSH
if [ ! -f ${cfg.dataDir}/.ssh/id_${cfg.sshKeyType} ]; then
umask 0077
${lib.getExe' pkgs.openssh "ssh-keygen"} -t ${cfg.sshKeyType} ${
lib.optionalString (cfg.sshKeyType == "rsa") "-b 4096"
} -N "" -f ${cfg.dataDir}/.ssh/id_${cfg.sshKeyType}
chmod 644 ${cfg.dataDir}/.ssh/id_${cfg.sshKeyType}.pub
chown ${cfg.user}:${cfg.group} ${cfg.dataDir}/.ssh/id_${cfg.sshKeyType} ${cfg.dataDir}/.ssh/id_${cfg.sshKeyType}.pub
fi
${lib.getExe cfg.package} \
--skipinstall \
-b ${cfg.dataDir} \
-c ${cfg.configDir} \
-p ${cfg.dataDir}/projects
'';
in
{
options = {
services.rundeck = {
enable = lib.mkEnableOption "Rundeck service";
package = lib.mkPackageOption pkgs "rundeck" { };
adminUser = lib.mkOption {
type = lib.types.str;
default = "admin";
description = "Username for the Rundeck admin user";
example = "rundeck-admin";
};
adminPasswordFile = lib.mkOption {
type = lib.types.path;
description = "Path to a file containing the admin password";
example = "/run/secrets/rundeck-admin-password";
};
user = lib.mkOption {
type = lib.types.str;
default = "rundeck";
description = "User account under which Rundeck runs";
};
group = lib.mkOption {
type = lib.types.str;
default = "rundeck";
description = "Group account under which Rundeck runs";
};
serverHostname = lib.mkOption {
type = lib.types.str;
default = "localhost";
description = "Hostname for the Rundeck server";
};
serverURL = lib.mkOption {
type = lib.types.str;
default = "${scheme}://${cfg.serverHostname}:${toString effectivePort}";
defaultText = lib.literalMD ''
`<scheme>://<serverHostname>:<port>`, where scheme is `https` when
`ssl.enable` else `http`, and port is `ssl.port` when `ssl.enable`
else `serverPort`.
'';
description = "Complete Grails server URL";
example = "https://myhost:4443/rundeck";
};
serverPort = lib.mkOption {
type = lib.types.port;
default = 4440;
description = "Port on which Rundeck will listen";
};
serverUUID = lib.mkOption {
type = lib.types.str;
default = "";
description = "UUID for the Rundeck server (automatically generated if not specified)";
};
dataDir = lib.mkOption {
type = lib.types.path;
default = "/var/lib/rundeck";
description = "Directory for Rundeck runtime data (RDECK_BASE)";
};
configDir = lib.mkOption {
type = lib.types.path;
default = "/etc/rundeck";
description = "Directory for Rundeck configuration files";
};
javaOpts = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [
"-Xmx1024m"
"-Xms256m"
"-XX:MaxMetaspaceSize=256m"
"-server"
];
description = "Additional Java options for Rundeck";
};
aclPolicies = lib.mkOption {
type = lib.types.attrsOf lib.types.str;
default = { };
description = "ACL policies for Rundeck, where the attribute name is the filename and the value is the policy content";
example = lib.literalExpression ''
{
"admin.aclpolicy" = '''
description: Admin access for administrators
context:
project: '.*'
for:
resource:
- allow: '*'
job:
- allow: '*'
node:
- allow: '*'
by:
group: admin
---
description: Admin access in application scope
context:
application: 'rundeck'
for:
resource:
- allow: '*'
project:
- allow: '*'
by:
group: admin
''';
}
'';
};
sshKeyType = lib.mkOption {
type = lib.types.enum [
"rsa"
"ed25519"
];
default = "rsa";
description = "Type of SSH key to generate (rsa for compatibility, ed25519 for better security)";
};
openFirewall = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Whether to open the Rundeck port in the firewall";
};
startTimeout = lib.mkOption {
type = lib.types.int;
default = 180;
description = "Timeout in seconds before systemd considers the service startup as failed";
example = 120;
};
database = {
type = lib.mkOption {
type = lib.types.enum [
"h2"
"postgresql"
"mysql"
];
default = "h2";
description = "Database type to use (h2, postgresql, or mysql)";
};
host = lib.mkOption {
type = lib.types.str;
default = "localhost";
description = "Database host";
};
port = lib.mkOption {
type = lib.types.nullOr lib.types.port;
default =
if cfg.database.type == "postgresql" then
5432
else if cfg.database.type == "mysql" then
3306
else
null;
defaultText = lib.literalExpression ''
if config.services.rundeck.database.type == "postgresql" then
5432
else if config.services.rundeck.database.type == "mysql" then
3306
else
null
'';
description = "Database port (defaults: PostgreSQL: 5432, MySQL: 3306)";
};
name = lib.mkOption {
type = lib.types.str;
default = "rundeck";
description = "Database name";
};
username = lib.mkOption {
type = lib.types.str;
default = "rundeck";
description = "Database username";
};
passwordFile = lib.mkOption {
type = lib.types.nullOr lib.types.path;
default = null;
description = "Path to a file containing the database password";
example = "/run/secrets/rundeck-db-password";
};
};
settings = lib.mkOption {
type = lib.types.submodule {
freeformType = settingsFormat.type;
};
default = { };
description = ''
Configuration written to `rundeck-config.properties`.
See <https://docs.rundeck.com/docs/administration/configuration/config-file-reference.html>
for available options.
Secrets must not be set here, as this ends up world-readable in the Nix
store. Use the dedicated `*File` options instead.
'';
example = lib.literalExpression ''
{
"rundeck.feature.repository.enabled" = "true";
"rundeck.projectsStorageType" = "db";
"rundeck.gui.title" = "My Rundeck Instance";
"rdeck.security.useHMacRequestTokens" = "true";
"rundeck.web.jetty.servlet.MaxFormKeys" = "2000";
}
'';
};
frameworkSettings = lib.mkOption {
type = lib.types.submodule {
freeformType = settingsFormat.type;
};
default = { };
description = ''
Configuration written to `framework.properties`.
See <https://docs.rundeck.com/docs/administration/configuration/config-file-reference.html>
for available options.
'';
example = lib.literalExpression ''
{
"framework.ssh.timeout" = "120";
"framework.ssh.user" = "deploy";
}
'';
};
ssl = {
enable = lib.mkEnableOption "SSL support";
port = lib.mkOption {
type = lib.types.port;
default = 4443;
description = "Port on which Rundeck will listen for HTTPS when ssl.enable is true";
};
keyStore = lib.mkOption {
type = lib.types.path;
example = "/etc/rundeck/ssl/keystore";
description = "Path to the keystore containing the SSL certificate";
};
keyStorePasswordFile = lib.mkOption {
type = lib.types.path;
description = "Path to a file containing the SSL keystore password";
example = "/run/secrets/rundeck-keystore-password";
};
};
};
};
config = lib.mkIf cfg.enable {
assertions = [
{
assertion =
cfg.database.type == "h2"
|| (cfg.database.host != "" && cfg.database.username != "" && cfg.database.passwordFile != null);
message = "When using external database (PostgreSQL/MySQL), host, username, and passwordFile must be provided";
}
{
assertion = cfg.database.type == "h2" || cfg.database.port != null;
message = "Database port must be set when using an external database";
}
];
services.rundeck.settings = {
"server.address" = lib.mkDefault "0.0.0.0";
"server.port" = lib.mkDefault (toString cfg.serverPort);
"grails.serverURL" = lib.mkDefault cfg.serverURL;
"logging.config" = lib.mkDefault "${cfg.configDir}/log4j2.properties";
"dataSource.url" = lib.mkDefault (
if cfg.database.type == "h2" then
"jdbc:h2:file:${cfg.dataDir}/data/rundeckdb;DB_CLOSE_ON_EXIT=FALSE;NON_KEYWORDS=MONTH,HOUR,MINUTE,YEAR,SECONDS"
else if cfg.database.type == "postgresql" then
"jdbc:postgresql://${cfg.database.host}:${toString cfg.database.port}/${cfg.database.name}"
else
"jdbc:mysql://${cfg.database.host}:${toString cfg.database.port}/${cfg.database.name}?autoReconnect=true&useSSL=false"
);
"dataSource.driverClassName" = lib.mkDefault (
if cfg.database.type == "h2" then
"org.h2.Driver"
else if cfg.database.type == "postgresql" then
"org.postgresql.Driver"
else
"org.mariadb.jdbc.Driver"
);
"dataSource.username" = lib.mkDefault cfg.database.username;
}
// lib.optionalAttrs (cfg.database.passwordFile != null) {
"dataSource.password" = lib.mkDefault "@DB_PASSWORD@";
}
// lib.optionalAttrs (cfg.database.type == "h2") {
"dataSource.dialect" = lib.mkDefault "org.hibernate.dialect.H2Dialect";
}
// lib.optionalAttrs (cfg.database.type == "mysql") {
"dataSource.dialect" = lib.mkDefault "org.hibernate.dialect.MariaDB103Dialect";
}
// lib.optionalAttrs cfg.ssl.enable {
"server.https.port" = lib.mkDefault (toString cfg.ssl.port);
"server.ssl.keyStore" = lib.mkDefault (toString cfg.ssl.keyStore);
"server.ssl.keyStorePassword" = lib.mkDefault "@KEYSTORE_PASSWORD@";
};
services.rundeck.frameworkSettings = {
"framework.server.name" = lib.mkDefault cfg.serverHostname;
"framework.server.hostname" = lib.mkDefault cfg.serverHostname;
"framework.server.port" = lib.mkDefault (toString effectivePort);
"framework.server.url" = lib.mkDefault cfg.serverURL;
"framework.ssh.keypath" = lib.mkDefault "${cfg.dataDir}/.ssh/id_${cfg.sshKeyType}";
"framework.ssh.user" = lib.mkDefault cfg.user;
"framework.ssh.timeout" = lib.mkDefault "60";
"rdeck.base" = cfg.dataDir;
"framework.projects.dir" = "${cfg.dataDir}/projects";
"framework.etc.dir" = toString cfg.configDir;
"framework.var.dir" = "${cfg.dataDir}/var";
"framework.tmp.dir" = "${cfg.dataDir}/var/tmp";
"framework.logs.dir" = "${cfg.dataDir}/var/logs";
"framework.libext.dir" = "${cfg.dataDir}/libext";
"rundeck.server.uuid" = if cfg.serverUUID != "" then cfg.serverUUID else "@SERVER_UUID@";
};
users.users.${cfg.user} = {
isSystemUser = true;
group = cfg.group;
home = cfg.dataDir;
createHome = true;
};
users.groups.${cfg.group} = { };
systemd.tmpfiles.settings."10-rundeck" = {
"${cfg.dataDir}" = {
d = {
mode = "0750";
user = cfg.user;
group = cfg.group;
};
};
"${cfg.dataDir}/etc" = {
d = {
mode = "0750";
user = cfg.user;
group = cfg.group;
};
};
"${cfg.dataDir}/data" = {
d = {
mode = "0750";
user = cfg.user;
group = cfg.group;
};
};
"${cfg.dataDir}/projects" = {
d = {
mode = "0750";
user = cfg.user;
group = cfg.group;
};
};
"${cfg.dataDir}/libext" = {
d = {
mode = "0750";
user = cfg.user;
group = cfg.group;
};
};
"${cfg.dataDir}/var" = {
d = {
mode = "0750";
user = cfg.user;
group = cfg.group;
};
};
"${cfg.dataDir}/var/logs" = {
d = {
mode = "0750";
user = cfg.user;
group = cfg.group;
};
};
"${cfg.dataDir}/var/tmp" = {
d = {
mode = "0750";
user = cfg.user;
group = cfg.group;
};
};
"${cfg.dataDir}/.ssh" = {
d = {
mode = "0700";
user = cfg.user;
group = cfg.group;
};
};
"${cfg.configDir}" = {
d = {
mode = "0750";
user = cfg.user;
group = cfg.group;
};
};
"${cfg.configDir}/ssl" = {
d = {
mode = "0750";
user = cfg.user;
group = cfg.group;
};
};
"/var/log/rundeck" = {
L = {
argument = "${cfg.dataDir}/var/logs";
};
};
};
environment.etc."rundeck/jaas-loginmodule.conf" = {
mode = "0640";
user = cfg.user;
group = cfg.group;
text = ''
RDpropertyfilelogin {
org.eclipse.jetty.jaas.spi.PropertyFileLoginModule required
debug="true"
file="/etc/rundeck/realm.properties";
};
'';
};
environment.etc."rundeck/log4j2.properties" = {
mode = "0640";
user = cfg.user;
group = cfg.group;
text = ''
status = info
name = RundeckPro
appender.console.type = Console
appender.console.name = STDOUT
appender.console.layout.type = PatternLayout
appender.console.layout.pattern = %d{DEFAULT} %-5p %c{1} - %m%n
appender.file.type = RollingFile
appender.file.name = FILE
appender.file.fileName = ${cfg.dataDir}/var/logs/rundeck.log
appender.file.filePattern = ${cfg.dataDir}/var/logs/rundeck.%d{yyyy-MM-dd}.log
appender.file.layout.type = PatternLayout
appender.file.layout.pattern = %d{DEFAULT} [%t] %-5p %c{1} - %m%n
appender.file.policies.type = Policies
appender.file.policies.time.type = TimeBasedTriggeringPolicy
appender.file.policies.time.interval = 1
appender.file.policies.time.modulate = true
rootLogger.level = info
rootLogger.appenderRef.stdout.ref = STDOUT
rootLogger.appenderRef.file.ref = FILE
logger.hibernate.name = org.hibernate
logger.hibernate.level = ERROR
'';
};
systemd.services.rundeck = {
description = "Rundeck Service";
wantedBy = [ "multi-user.target" ];
after = [
"network.target"
]
++ lib.optional (cfg.database.type == "mysql") "mysql.service"
++ lib.optional (cfg.database.type == "postgresql") "postgresql.service";
wants =
lib.optional (cfg.database.type == "mysql") "mysql.service"
++ lib.optional (cfg.database.type == "postgresql") "postgresql.service";
environment = {
RDECK_BASE = cfg.dataDir;
RUNDECK_CONFIG_DIR = cfg.configDir;
JAVA_OPTS = lib.concatStringsSep " " cfg.javaOpts;
};
path = [ pkgs.replace-secret ];
serviceConfig = {
User = cfg.user;
Group = cfg.group;
ExecStart = rundeckStartScript;
WorkingDirectory = cfg.dataDir;
RuntimeDirectory = "rundeck";
RuntimeDirectoryMode = "0750";
UMask = "0027";
LimitNOFILE = 65536;
ReadWritePaths = [
cfg.dataDir
cfg.configDir
];
RestartSec = "10s";
Restart = "always";
TimeoutStartSec = "${toString cfg.startTimeout}s";
CapabilityBoundingSet = [ "CAP_SYS_ADMIN" ];
AmbientCapabilities = [ "CAP_SYS_ADMIN" ];
LimitCORE = 0;
LockPersonality = true;
MemorySwapMax = 0;
MemoryZSwapMax = 0;
PrivateDevices = true;
PrivateTmp = true;
ProtectClock = true;
ProtectControlGroups = true;
ProtectHome = true;
ProtectHostname = true;
ProtectKernelLogs = true;
ProtectKernelModules = true;
ProtectKernelTunables = true;
ProtectProc = "invisible";
RemoveIPC = true;
RestrictAddressFamilies = [
"AF_UNIX"
"AF_INET"
"AF_INET6"
"AF_NETLINK"
];
RestrictNamespaces = true;
RestrictRealtime = true;
RestrictSUIDSGID = true;
SystemCallArchitectures = "native";
};
preStart = ''
${lib.optionalString (cfg.serverUUID == "") ''
# Generate UUID
UUID_FILE="${cfg.dataDir}/.uuid"
if [ ! -f "$UUID_FILE" ]; then
umask 0137
${lib.getExe' pkgs.util-linux "uuidgen"} > "$UUID_FILE"
fi
''}
install -m 0640 ${configFile} ${cfg.configDir}/rundeck-config.properties
install -m 0640 ${frameworkFile} ${cfg.configDir}/framework.properties
install -m 0600 ${realmFile} ${cfg.configDir}/realm.properties
${replaceSecret "@ADMIN_PASSWORD@" cfg.adminPasswordFile "${cfg.configDir}/realm.properties"}
${lib.optionalString (cfg.database.passwordFile != null) (
replaceSecret "@DB_PASSWORD@" cfg.database.passwordFile "${cfg.configDir}/rundeck-config.properties"
)}
${lib.optionalString cfg.ssl.enable (
replaceSecret "@KEYSTORE_PASSWORD@" cfg.ssl.keyStorePasswordFile
"${cfg.configDir}/rundeck-config.properties"
)}
${lib.optionalString (cfg.serverUUID == "") (
replaceSecret "@SERVER_UUID@" "${cfg.dataDir}/.uuid" "${cfg.configDir}/framework.properties"
)}
if [ -f ${cfg.dataDir}/etc/framework.properties ]; then
install -m 0640 ${cfg.configDir}/framework.properties ${cfg.dataDir}/etc/framework.properties
fi
${lib.concatStringsSep "\n" (
lib.mapAttrsToList (
name: content:
"install -m 0640 ${pkgs.writeText "rundeck-${name}" content} ${cfg.dataDir}/etc/${name}"
) cfg.aclPolicies
)}
'';
};
networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [
(if cfg.ssl.enable then cfg.ssl.port else cfg.serverPort)
];
};
}

View File

@@ -145,7 +145,7 @@ in
serviceConfig = {
DynamicUser = true;
ExecStart = "${lib.getExe cfg.package} serve";
ExecStart = lib.getExe cfg.package;
EnvironmentFile = cfg.environmentFiles;
Restart = "on-failure";
StateDirectory = "rustical";

View File

@@ -398,11 +398,6 @@ let
hostListen = if vhost.forceSSL then filter (x: x.ssl) defaultListen else defaultListen;
# If there's any location setting `useGrpcErrorPages`, we need to add the location blocks.
locationsWantGrpcErrorPages = builtins.any (location: location.useGrpcErrorPages) (
attrValues vhost.locations
);
listenString =
{
addr,
@@ -520,10 +515,6 @@ let
${mkBasicAuth vhostName vhost}
${optionalString locationsWantGrpcErrorPages ''
include ${./grpc-locations.conf};
''}
${optionalString (vhost.root != null) "root ${vhost.root};"}
${optionalString (vhost.globalRedirect != null) ''
@@ -568,9 +559,6 @@ let
optionalAttrs (config.fastcgiParams != { }) (defaultFastcgiParams // config.fastcgiParams)
)
)}
${optionalString config.useGrpcErrorPages ''
include ${./grpc-error-pages.conf};
''}
${optionalString (config.index != null) "index ${config.index};"}
${optionalString (config.tryFiles != null) "try_files ${config.tryFiles};"}
${optionalString (config.root != null) "root ${config.root};"}

View File

@@ -1,22 +0,0 @@
error_page 400 = @grpc_internal;
error_page 401 = @grpc_unauthenticated;
error_page 403 = @grpc_permission_denied;
error_page 404 = @grpc_unimplemented;
error_page 429 = @grpc_unavailable;
error_page 502 = @grpc_unavailable;
error_page 503 = @grpc_unavailable;
error_page 504 = @grpc_unavailable;
# NGINX-to-gRPC status code mappings
# Ref: https://github.com/grpc/grpc/blob/master/doc/statuscodes.md
#
error_page 405 = @grpc_internal; # Method not allowed
error_page 408 = @grpc_deadline_exceeded; # Request timeout
error_page 413 = @grpc_resource_exhausted; # Payload too large
error_page 414 = @grpc_resource_exhausted; # Request URI too large
error_page 415 = @grpc_internal; # Unsupported media type;
error_page 426 = @grpc_internal; # HTTP request was sent to HTTPS port
error_page 495 = @grpc_unauthenticated; # Client certificate authentication error
error_page 496 = @grpc_unauthenticated; # Client certificate not presented
error_page 497 = @grpc_internal; # HTTP request was sent to mutual TLS port
error_page 500 = @grpc_internal; # Server error
error_page 501 = @grpc_internal; # Not implemented

View File

@@ -1,46 +0,0 @@
# gRPC error responses
# Ref: https://github.com/grpc/grpc-go/blob/master/codes/codes.go
# Ref: https://grpc.io/docs/guides/wire
#
location @grpc_deadline_exceeded {
add_header grpc-status 4;
add_header grpc-message 'deadline exceeded';
default_type application/grpc;
return 200;
}
location @grpc_permission_denied {
add_header grpc-status 7;
add_header grpc-message 'permission denied';
default_type application/grpc;
return 200;
}
location @grpc_resource_exhausted {
add_header grpc-status 8;
add_header grpc-message 'resource exhausted';
default_type application/grpc;
return 200;
}
location @grpc_unimplemented {
add_header grpc-status 12;
add_header grpc-message unimplemented;
default_type application/grpc;
return 200;
}
location @grpc_internal {
add_header grpc-status 13;
add_header grpc-message 'internal error';
default_type application/grpc;
return 200;
}
location @grpc_unavailable {
add_header grpc-status 14;
add_header grpc-message unavailable;
default_type application/grpc;
return 200;
}
location @grpc_unauthenticated {
add_header grpc-status 16;
add_header grpc-message unauthenticated;
default_type application/grpc;
return 200;
}

View File

@@ -158,17 +158,5 @@ with lib;
Enable recommended uwsgi settings.
'';
};
useGrpcErrorPages = mkOption {
type = types.bool;
default = false;
description = ''
Whether to configure error codes to be emitted as gRPC-compatible errors.
Should be set when proxying gRPC, and returning responses from nginx (like when adding authentication).
This defines a few `@grpc-*` locations inside the containing vhost.
'';
};
};
}

View File

@@ -200,7 +200,6 @@ in
AmbientCapabilities = "cap_net_bind_service";
NoNewPrivileges = true;
LimitNOFILE = 131072;
LimitMEMLOCK = "infinity";
};
};

View File

@@ -55,14 +55,10 @@ let
"LinkJournal"
"Ephemeral"
"AmbientCapability"
"SuppressSync"
"PrivateUsersDelegate"
"RestrictAddressFamilies"
])
(assertValueOneOf "Boot" boolValues)
(assertValueOneOf "ProcessTwo" boolValues)
(assertValueOneOf "NotifyReady" boolValues)
(assertValueOneOf "SuppressSync" boolValues)
];
checkFiles = checkUnitConfig "Files" [
@@ -78,7 +74,6 @@ let
"BindUser"
"Inaccessible"
"PrivateUsersOwnership"
"BindUserShell"
])
(assertValueOneOf "ReadOnly" boolValues)
(assertValueOneOf "Volatile" (boolValues ++ [ "state" ]))
@@ -102,7 +97,6 @@ let
"Bridge"
"Zone"
"Port"
"NamespacePath"
])
(assertValueOneOf "Private" boolValues)
(assertValueOneOf "VirtualEthernet" boolValues)

View File

@@ -322,7 +322,7 @@ in
ln -s "${systemd}/example/tmpfiles.d/credstore.conf"
ln -s "${systemd}/example/tmpfiles.d/home.conf"
ln -s "${systemd}/example/tmpfiles.d/journal-nocow.conf"
${optionalString systemd.withPortabled ''ln -s "${systemd}/example/tmpfiles.d/portables.conf"''}
ln -s "${systemd}/example/tmpfiles.d/portables.conf"
ln -s "${systemd}/example/tmpfiles.d/static-nodes-permissions.conf"
ln -s "${systemd}/example/tmpfiles.d/systemd.conf"
ln -s "${systemd}/example/tmpfiles.d/systemd-nologin.conf"

View File

@@ -78,7 +78,7 @@ in
description = ''
List of repositories to search.
Deprecated, examine {option}`virtualisation.containers.registries.settings` instead.
Deprecated, examine {option}`virtualisation.registries.settings` instead.
'';
};
@@ -89,7 +89,7 @@ in
description = ''
List of insecure repositories.
Deprecated, examine {option}`virtualisation.containers.registries.settings` instead.
Deprecated, examine {option}`virtualisation.registries.settings` instead.
'';
};
@@ -100,7 +100,7 @@ in
description = ''
List of blocked repositories.
Deprecated, examine {option}`virtualisation.containers.registries.settings` instead.
Deprecated, examine {option}`virtualisation.registries.settings` instead.
'';
};
@@ -145,7 +145,7 @@ in
};
config = lib.mkIf cfg.enable {
warnings = lib.optional oldRegistriesOptionsUsed "the options virtualisation.containers.registries.search / insecure / block are deprecated. See virtualisation.containers.registries.settings instead.";
warnings = lib.optional oldRegistriesOptionsUsed "the options virtualisation.registries.search / insecure / block are deprecated. See virtualisation.registries.settings instead.";
virtualisation.containers.registries.settings = lib.mkIf oldRegistriesOptionsUsed {
registries = {

View File

@@ -526,7 +526,7 @@ let
# Parses an IP address with an optional prefix
ipFromString =
str: defaultPrefix:
str:
let
segments = lib.splitString "/" str;
prefix = lib.elemAt segments 1;
@@ -534,7 +534,7 @@ let
in
{
address = lib.head segments;
prefixLength = if hasPrefix then builtins.fromJSON prefix else defaultPrefix;
prefixLength = if hasPrefix then builtins.fromJSON prefix else 32;
};
in
@@ -610,10 +610,10 @@ in
networking.interfaces = lib.mkIf config.privateNetwork (
lib.mkMerge [
(lib.mkIf (config.localAddress != null) {
eth0.ipv4.addresses = [ (ipFromString config.localAddress 32) ];
eth0.ipv4.addresses = [ (ipFromString config.localAddress) ];
})
(lib.mkIf (config.localAddress6 != null) {
eth0.ipv6.addresses = [ (ipFromString config.localAddress6 128) ];
eth0.ipv6.addresses = [ (ipFromString config.localAddress6) ];
})
]
);

View File

@@ -3,13 +3,13 @@
name = "actual";
meta.maintainers = [ lib.maintainers.oddlama ];
containers.machine =
nodes.machine =
{ ... }:
{
services.actual.enable = true;
};
containers.machine2 =
nodes.machine2 =
{ ... }:
{
services.actual = {

View File

@@ -20,20 +20,16 @@ let
isFunction
mapAttrs
elem
meta
recurseIntoAttrs
;
callSupportedTest =
test: if meta.availableOn pkgs.stdenv.hostPlatform test then callTest test else { };
# TODO: remove when handleTest is gone (make sure nixosTests and nixos/release.nix#tests are unaffected)
# TODO: when removing, also deprecate `test` attribute in ../lib/testing/run.nix
discoverTests =
val:
if isAttrs val then
if (val ? test) then
callSupportedTest val
callTest val
else
mapAttrs (n: s: if n == "passthru" then s else discoverTests s) val
else if isFunction val then
@@ -124,7 +120,7 @@ let
if tree ? recurseForDerivations && tree.recurseForDerivations then
mapAttrs (k: findTests) (removeAttrs tree [ "recurseForDerivations" ])
else
callSupportedTest tree;
callTest tree;
runTest =
arg:
@@ -694,10 +690,7 @@ in
ghostunnel = runTest ./ghostunnel.nix;
ghostunnel-modular = runTest ./ghostunnel-modular.nix;
gitdaemon = runTest ./gitdaemon.nix;
gitea = import ./gitea.nix {
inherit pkgs runTest;
inherit (pkgs) lib;
};
gitea = handleTest ./gitea.nix { giteaPackage = pkgs.gitea; };
github-runner = runTest ./github-runner.nix;
gitlab = import ./gitlab {
inherit runTest;
@@ -802,7 +795,7 @@ in
systemdStage1 = true;
};
hister = runTest ./hister.nix;
hitch = runTest ./hitch;
hitch = handleTest ./hitch { };
hledger-web = runTest ./hledger-web.nix;
hockeypuck = runTest ./hockeypuck.nix;
holo-daemon-modular-service = runTest ./holo-daemon-modular.nix;
@@ -813,10 +806,7 @@ in
homer = handleTest ./homer { };
honk = runTest ./honk.nix;
hoogle = runTest ./hoogle.nix;
hostname = import ./hostname.nix {
inherit pkgs runTest;
inherit (pkgs) lib;
};
hostname = handleTest ./hostname.nix { };
hound = runTest ./hound.nix;
hub = runTest ./git/hub.nix;
hydra = runTest ./hydra;
@@ -912,14 +902,8 @@ in
keter = runTest ./keter.nix;
kexec = runTest ./kexec.nix;
keycloak = discoverTests (import ./keycloak.nix);
keyd = import ./keyd.nix {
inherit pkgs runTest;
inherit (pkgs) lib;
};
keymap = import ./keymap.nix {
inherit pkgs runTest;
inherit (pkgs) lib;
};
keyd = handleTest ./keyd.nix { };
keymap = handleTest ./keymap.nix { };
kimai = runTest ./kimai.nix;
kismet = runTest ./kismet.nix;
kiwix-serve = runTest ./kiwix-serve;
@@ -1013,7 +997,7 @@ in
lomiri-mediaplayer-app = runTest ./lomiri-mediaplayer-app.nix;
lomiri-music-app = runTest ./lomiri-music-app.nix;
lomiri-system-settings = runTest ./lomiri-system-settings.nix;
lorri = runTest ./lorri/default.nix;
lorri = handleTest ./lorri/default.nix { };
luks = runTest ./luks.nix;
luks-suspend = runTest ./luks-suspend.nix;
lvm2 = import ./lvm2 { inherit pkgs runTest; };
@@ -1162,7 +1146,6 @@ in
netbox-upgrade = runTest ./web-apps/netbox-upgrade.nix;
netbox_4_4 = handleTest ./web-apps/netbox/default.nix { netbox = pkgs.netbox_4_4; };
netbox_4_5 = handleTest ./web-apps/netbox/default.nix { netbox = pkgs.netbox_4_5; };
netbox_4_6 = handleTest ./web-apps/netbox/default.nix { netbox = pkgs.netbox_4_6; };
netdata = runTest ./netdata.nix;
netfoil = runTest ./netfoil.nix;
netplan = runTest ./netplan.nix;
@@ -1185,7 +1168,6 @@ in
nginx-etag = runTest ./nginx-etag.nix;
nginx-etag-compression = runTest ./nginx-etag-compression.nix;
nginx-globalredirect = runTest ./nginx-globalredirect.nix;
nginx-grpc-error-pages = runTest ./nginx-grpc-error-pages.nix;
nginx-http3 = import ./nginx-http3.nix { inherit pkgs runTest; };
nginx-lua = runTest ./nginx-lua.nix;
nginx-mime = runTest ./nginx-mime.nix;
@@ -1542,7 +1524,6 @@ in
rnsd = runTest ./networking/rnsd.nix;
robustirc-bridge = runTest ./robustirc-bridge.nix;
romm = runTest ./romm.nix;
rosec = runTest ./rosec.nix;
rosenpass = runTest ./rosenpass.nix;
roundcube = runTest ./roundcube.nix;
routinator = handleTest ./routinator.nix { };
@@ -1560,7 +1541,6 @@ in
rsyslogd = handleTest ./rsyslogd.nix { };
rtkit = runTest ./rtkit.nix;
rtorrent = runTest ./rtorrent.nix;
rundeck = runTest ./rundeck.nix;
rush = runTest ./rush.nix;
rustfs = runTest ./rustfs.nix;
rustical = runTest ./web-apps/rustical.nix;
@@ -1795,7 +1775,7 @@ in
terminal-emulators = handleTest ./terminal-emulators.nix { };
test-containers-bittorrent = runTest ./test-containers-bittorrent.nix;
thanos = runTest ./thanos.nix;
thelounge = runTest ./thelounge.nix;
thelounge = handleTest ./thelounge.nix { };
tiddlywiki = runTest ./tiddlywiki.nix;
tigervnc = handleTest ./tigervnc.nix { };
tika = runTest ./tika.nix;
@@ -1844,7 +1824,6 @@ in
ucarp = runTest ./ucarp.nix;
udisks2 = runTest ./udisks2.nix;
udp-over-tcp = runTest ./udp-over-tcp.nix;
udp514-journal = runTest ./udp514-journal.nix;
ulogd = runTest ./ulogd/ulogd.nix;
umami = runTest ./web-apps/umami.nix;
umurmur = runTest ./umurmur.nix;
@@ -1870,9 +1849,6 @@ in
userborn-mutable-etc = runTest ./userborn-mutable-etc.nix;
userborn-mutable-users = runTest ./userborn-mutable-users.nix;
userborn-static = runTest ./userborn-static.nix;
userborn-subids = runTest ./userborn-subids.nix;
userborn-subids-immutable-etc = runTest ./userborn-subids-immutable-etc.nix;
userborn-subids-mutable-etc = runTest ./userborn-subids-mutable-etc.nix;
ustreamer = runTest ./ustreamer.nix;
utils = pkgs.callPackage ./utils { inherit runTest; };
utmp = runTest ./utmp.nix;
@@ -1926,10 +1902,7 @@ in
inherit pkgs runTest;
inherit (pkgs) lib;
};
wine = import ./wine.nix {
inherit pkgs runTest;
inherit (pkgs) lib;
};
wine = handleTest ./wine.nix { };
wireguard = import ./wireguard {
inherit pkgs runTest;
inherit (pkgs) lib;

View File

@@ -1,7 +1,7 @@
{
name = "blocky";
containers = {
nodes = {
server =
{ pkgs, ... }:
{

View File

@@ -1,7 +1,7 @@
{ pkgs, ... }:
{
name = "cloudlog";
containers = {
nodes = {
machine = {
services.mysql.package = pkgs.mariadb;
services.cloudlog.enable = true;

View File

@@ -9,7 +9,7 @@
2. Spins up an nghttpd2 server to test client HTTP/2 headers against
known-good headers
See https://github.com/lexiforest/curl-impersonate/tree/main/tests/signatures
See https://github.com/lwthiker/curl-impersonate/tree/main/tests/signatures
for details.
Notes:
@@ -22,20 +22,18 @@
- We started skipping the test_http2_headers test due to log format differences
between the nghttpd2 version in nixpkgs and the outdated one curl-impersonate
uses upstream for its tests.
- test_http3_fingerprint is skipped because it requires connecting to
third-party endpoint (fp.impersonate.pro) which isn't reachable from the test VM
*/
{ config, lib, ... }:
let
pkgs = config.node.pkgs;
{ pkgs, lib, ... }:
let
# Update with domains in TestImpersonate.TEST_URLS if needed from:
# https://github.com/lexiforest/curl-impersonate/blob/main/tests/test_impersonate.py
# https://github.com/lwthiker/curl-impersonate/blob/main/tests/test_impersonate.py
domains = [
"www.wikimedia.org"
"www.wikipedia.org"
"www.mozilla.org"
"www.apache.org"
"www.kernel.org"
"git-scm.com"
];
@@ -94,12 +92,7 @@ let
}
''
mkdir -p $out/bin
sed -e 's/opts->local_port_end - opts->local_port_start);/(long)(opts->local_port_end - opts->local_port_start));/' \
-e 's/^\( *\)opts->local_port_start);/\1(long)opts->local_port_start);/' \
-e 's/CURLOPT_SSL_VERIFYPEER, 0)/CURLOPT_SSL_VERIFYPEER, 0L)/' \
-e 's/CURLOPT_SSL_VERIFYHOST, 0)/CURLOPT_SSL_VERIFYHOST, 0L)/' \
${pkgs.curl-impersonate.src}/tests/minicurl.c > minicurl.c
$CC -Wall -Werror -o $out/bin/minicurl minicurl.c `curl-config --libs`
$CC -Wall -Werror -o $out/bin/minicurl ${pkgs.curl-impersonate.src}/tests/minicurl.c `curl-config --libs`
'';
in
pkgs.writeShellScript "curl-impersonate-test" ''
@@ -134,42 +127,50 @@ let
# Run tests
cd tests
pytest . --install-dir ../usr --capture-interface eth1 --exitfirst -k 'not test_http2_headers and not test_http3_fingerprint'
pytest . --install-dir ../usr --capture-interface eth1 --exitfirst -k 'not test_http2_headers'
'';
in
{
name = "curl-impersonate";
meta = {
maintainers = with lib.maintainers; [
ui-1
];
maintainers = [ ];
};
nodes = {
web = { ... }: {
networking.firewall.allowedTCPPorts = [
80
443
];
web =
{
nodes,
pkgs,
lib,
config,
...
}:
{
networking.firewall.allowedTCPPorts = [
80
443
];
services = {
nginx = {
enable = true;
virtualHosts."curl-impersonate.nixos.test" = {
default = true;
addSSL = true;
sslCertificate = "${tls-certs}/cert.pem";
sslCertificateKey = "${tls-certs}/key.pem";
services = {
nginx = {
enable = true;
virtualHosts."curl-impersonate.nixos.test" = {
default = true;
addSSL = true;
sslCertificate = "${tls-certs}/cert.pem";
sslCertificateKey = "${tls-certs}/key.pem";
};
};
};
};
};
curl =
{
nodes,
pkgs,
lib,
config,
...
}:
{
@@ -181,20 +182,22 @@ in
};
};
testScript = { ... }: ''
start_all()
testScript =
{ nodes, ... }:
''
start_all()
with subtest("Wait for network"):
web.systemctl("start network-online.target")
curl.systemctl("start network-online.target")
web.wait_for_unit("network-online.target")
curl.wait_for_unit("network-online.target")
with subtest("Wait for network"):
web.systemctl("start network-online.target")
curl.systemctl("start network-online.target")
web.wait_for_unit("network-online.target")
curl.wait_for_unit("network-online.target")
with subtest("Wait for web server"):
web.wait_for_unit("nginx.service")
web.wait_for_open_port(443)
with subtest("Wait for web server"):
web.wait_for_unit("nginx.service")
web.wait_for_open_port(443)
with subtest("Run curl-impersonate tests"):
curl.succeed("${curl-impersonate-test}")
'';
with subtest("Run curl-impersonate tests"):
curl.succeed("${curl-impersonate-test}")
'';
}

View File

@@ -2,7 +2,7 @@
{
name = "fail2ban";
nodes.machine = { ... }: {
nodes.machine = _: {
services.fail2ban = {
enable = true;
bantime-increment.enable = true;
@@ -11,7 +11,7 @@
networking.nftables.enable = true;
};
nodes.client = { pkgs, ... }: {
nodes.client = _: {
environment.systemPackages = [
pkgs.sshpass
pkgs.netcat
@@ -31,41 +31,16 @@
client_addr = "2001:db8:1::1"
machine_addr = "2001:db8:1::2"
# Verify that querying the version works
clientVersion = machine.succeed("fail2ban-client -V").rstrip()
t.assertEqual(clientVersion, "${pkgs.fail2ban.version}")
serverVersion = machine.succeed("fail2ban-server -V").rstrip()
t.assertEqual(serverVersion, "${pkgs.fail2ban.version}")
# Verify that fail2ban-client can communicate with the server
machine.succeed("fail2ban-client ping")
# Verify there is not ban and the port is reachable from the client.
machine.succeed(f"test 0 -eq $(fail2ban-client get sshd banned {client_addr})")
client.succeed(f"nc -w3 -z {machine_addr} 22")
# Cause authentication failure log entries (detach second command since ban may cause timeout).
client.fail(f"sshpass -p 'wrongpassword' ssh -o StrictHostKeyChecking=no {machine_addr}")
client.execute(f"sshpass -p 'wrongpassword' ssh -o StrictHostKeyChecking=no {machine_addr} >&2 &")
# Cause authentication failure log entries.
for _ in range(2):
client.fail(f"sshpass -p 'wrongpassword' ssh -o StrictHostKeyChecking=no {machine_addr}")
# Verify there is a ban and the port is unreachable from the client.
machine.wait_until_succeeds(f"test 1 -eq $(fail2ban-client get sshd banned {client_addr})")
client.fail(f"nc -w3 -z {machine_addr} 22")
# Verify that unbanning works
machine.succeed(f"fail2ban-client unban {client_addr}")
client.succeed(f"nc -w3 -z {machine_addr} 22")
# Verify that fail2ban-regex works
regex = r"^matching log entry: <HOST>$"
line = "matching log entry: 1.2.3.4"
matches = machine.succeed(f"fail2ban-regex -o matches '{line}' '{regex}'")
t.assertIn(line, matches)
# Verify that socket activation works
machine.succeed("systemctl stop fail2ban.service")
machine.fail("systemctl --quiet is-active fail2ban.service")
machine.succeed("fail2ban-client ping")
machine.succeed("systemctl --quiet is-active fail2ban.service")
'';
}

View File

@@ -37,7 +37,7 @@
];
fcitx5.settings = {
globalOptions = {
"Hotkey"."EnumerateSkipFirst" = false;
"Hotkey"."EnumerateSkipFirst" = "False";
"Hotkey/TriggerKeys"."0" = "Control+space";
"Hotkey/EnumerateForwardKeys"."0" = "Alt+Shift_L";
"Hotkey/EnumerateBackwardKeys"."0" = "Alt+Shift_R";

View File

@@ -1,11 +1,12 @@
{
pkgs,
lib,
runTest,
...
system ? builtins.currentSystem,
config ? { },
giteaPackage ? pkgs.gitea,
pkgs ? import ../.. { inherit system config; },
}:
with lib;
with import ../lib/testing-python.nix { inherit system pkgs; };
with pkgs.lib;
let
## gpg --faked-system-time='20230301T010000!' --quick-generate-key snakeoil ed25519 sign
@@ -30,8 +31,8 @@ let
];
makeGiteaTest =
type:
nameValuePair type (runTest {
name = "${pkgs.gitea.pname}-${type}";
nameValuePair type (makeTest {
name = "${giteaPackage.pname}-${type}";
meta.maintainers = with maintainers; [
aanderse
kolaente
@@ -45,7 +46,7 @@ let
services.gitea = {
enable = true;
database = { inherit type; };
package = pkgs.gitea;
package = giteaPackage;
metricsTokenFile = (pkgs.writeText "metrics_secret" "fakesecret").outPath;
settings.service.DISABLE_REGISTRATION = true;
settings."repository.signing".SIGNING_KEY = signingPrivateKeyId;
@@ -53,7 +54,7 @@ let
settings.metrics.ENABLED = true;
};
environment.systemPackages = [
pkgs.gitea
giteaPackage
pkgs.gnupg
pkgs.jq
];

View File

@@ -1,34 +1,36 @@
{ pkgs, ... }:
{
name = "hitch";
meta = with pkgs.lib.maintainers; {
maintainers = [ jflanglois ];
};
nodes.machine =
{ pkgs, ... }:
{
environment.systemPackages = [ pkgs.curl ];
services.hitch = {
enable = true;
backend = "[127.0.0.1]:80";
pem-files = [
./example.pem
];
};
services.httpd = {
enable = true;
virtualHosts.localhost.documentRoot = ./example;
adminAddr = "noone@testing.nowhere";
};
import ../make-test-python.nix (
{ pkgs, ... }:
{
name = "hitch";
meta = with pkgs.lib.maintainers; {
maintainers = [ jflanglois ];
};
nodes.machine =
{ pkgs, ... }:
{
environment.systemPackages = [ pkgs.curl ];
services.hitch = {
enable = true;
backend = "[127.0.0.1]:80";
pem-files = [
./example.pem
];
};
testScript = ''
start_all()
services.httpd = {
enable = true;
virtualHosts.localhost.documentRoot = ./example;
adminAddr = "noone@testing.nowhere";
};
};
machine.wait_for_unit("multi-user.target")
machine.wait_for_unit("hitch.service")
machine.wait_for_open_port(443)
assert "We are all good!" in machine.succeed("curl -fk https://localhost:443/index.txt")
'';
}
testScript = ''
start_all()
machine.wait_for_unit("multi-user.target")
machine.wait_for_unit("hitch.service")
machine.wait_for_open_port(443)
assert "We are all good!" in machine.succeed("curl -fk https://localhost:443/index.txt")
'';
}
)

View File

@@ -1,10 +1,11 @@
{
pkgs,
runTest,
lib,
system ? builtins.currentSystem,
config ? { },
pkgs ? import ../.. { inherit system config; },
}:
with lib;
with import ../lib/testing-python.nix { inherit system pkgs; };
with pkgs.lib;
let
makeHostNameTest =
@@ -18,7 +19,7 @@ let
in
if (res.success && res.value != null) then res.value else "null";
in
runTest {
makeTest {
name = "hostname-${fqdn}";
meta = with pkgs.lib.maintainers; {
maintainers = [

View File

@@ -71,7 +71,6 @@ in
];
};
boot.kernelPackages = pkgs.linuxPackages_latest;
networking.jool.enable = true;
networking.jool.siit.default.global.pool6 = "fd::/96";
};
@@ -192,7 +191,6 @@ in
];
};
boot.kernelPackages = pkgs.linuxPackages_latest;
networking.jool.enable = true;
networking.jool.nat64.default = {
bib = [
@@ -208,17 +206,17 @@ in
{
protocol = "TCP";
prefix = "203.0.113.1/32";
"port range" = "20000-29999";
"port range" = "40001-65535";
}
{
protocol = "UDP";
prefix = "203.0.113.1/32";
"port range" = "20000-29999";
"port range" = "40001-65535";
}
{
protocol = "ICMP";
prefix = "203.0.113.1/32";
"port range" = "20000-29999";
"port range" = "40001-65535";
}
# Ports for static BIB entries
{

View File

@@ -1,10 +1,12 @@
# The test template is taken from the `./keymap.nix`
{
pkgs,
runTest,
lib,
system ? builtins.currentSystem,
config ? { },
pkgs ? import ../.. { inherit system config; },
}:
with import ../lib/testing-python.nix { inherit system pkgs; };
let
readyFile = "/tmp/readerReady";
resultFile = "/tmp/readerResult";
@@ -27,8 +29,8 @@ let
mkKeyboardTest =
name:
{ default, test }:
runTest {
with pkgs.lib;
makeTest {
inherit name;
nodes.machine = {
@@ -70,7 +72,7 @@ let
};
in
lib.mapAttrs mkKeyboardTest {
pkgs.lib.mapAttrs mkKeyboardTest {
swap-ab_and_ctrl-as-shift = {
test.press = [
"a"

View File

@@ -1,9 +1,11 @@
{
pkgs,
runTest,
lib,
system ? builtins.currentSystem,
config ? { },
pkgs ? import ../.. { inherit system config; },
}:
with import ../lib/testing-python.nix { inherit system pkgs; };
let
readyFile = "/tmp/readerReady";
resultFile = "/tmp/readerResult";
@@ -30,8 +32,8 @@ let
extraConfig ? { },
tests,
}:
with lib;
runTest {
with pkgs.lib;
makeTest {
name = "keymap-${layout}";
nodes.machine.console.keyMap = mkOverride 900 layout;
@@ -103,7 +105,7 @@ let
};
in
lib.mapAttrs mkKeyboardTest {
pkgs.lib.mapAttrs mkKeyboardTest {
azerty = {
tests = {
azqw.qwerty = [

View File

@@ -1,4 +1,4 @@
{
import ../make-test-python.nix {
name = "lorri";
nodes.machine =

View File

@@ -118,7 +118,7 @@ in
(pkgs.writers.writePython3Bin "create_management_room_and_invite_mjolnir"
{
libraries = with pkgs.python3Packages; [
(matrix-nio.override { withVodozemac = true; })
(matrix-nio.override { withOlm = true; })
];
}
''

View File

@@ -4,16 +4,16 @@ let
shared =
{ pkgs, ... }:
{
services.mediawiki = {
enable = true;
httpd.virtualHost = {
hostName = "localhost";
adminAddr = "root@example.com";
};
passwordFile = pkgs.writeText "password" "correcthorsebatterystaple";
extensions = {
ParserFunctions = null;
services.mediawiki.enable = true;
services.mediawiki.httpd.virtualHost.hostName = "localhost";
services.mediawiki.httpd.virtualHost.adminAddr = "root@example.com";
services.mediawiki.passwordFile = pkgs.writeText "password" "correcthorsebatterystaple";
services.mediawiki.extensions = {
Matomo = pkgs.fetchzip {
url = "https://github.com/DaSchTour/matomo-mediawiki-extension/archive/v4.0.1.tar.gz";
sha256 = "0g5rd3zp0avwlmqagc59cg9bbkn3r7wx7p6yr80s644mj6dlvs1b";
};
ParserFunctions = null;
};
};
@@ -21,7 +21,7 @@ let
t:
runTest {
imports = [
{ containers.machine.imports = [ shared ]; }
{ nodes.machine.imports = [ shared ]; }
t
];
};
@@ -29,7 +29,7 @@ in
{
mysql = makeTest {
name = "mediawiki-mysql";
containers.machine = {
nodes.machine = {
services.mediawiki.database.type = "mysql";
};
testScript = ''
@@ -44,7 +44,7 @@ in
postgresql = makeTest {
name = "mediawiki-postgres";
containers.machine = {
nodes.machine = {
services.mediawiki.database.type = "postgres";
};
testScript = ''
@@ -59,7 +59,7 @@ in
sqlite = makeTest {
name = "mediawiki-sqlite";
containers.machine = {
nodes.machine = {
services.mediawiki.database.type = "sqlite";
};
testScript = ''
@@ -74,29 +74,29 @@ in
nohttpd = makeTest {
name = "mediawiki-nohttpd";
containers.machine = {
nodes.machine = {
services.mediawiki.webserver = "none";
};
testScript =
{ containers, ... }:
{ nodes, ... }:
''
start_all()
machine.wait_for_unit("phpfpm-mediawiki.service")
env = (
"SCRIPT_NAME=/index.php",
"SCRIPT_FILENAME=${containers.machine.services.mediawiki.finalPackage}/share/mediawiki/index.php",
"SCRIPT_FILENAME=${nodes.machine.services.mediawiki.finalPackage}/share/mediawiki/index.php",
"REMOTE_ADDR=127.0.0.1",
'QUERY_STRING=title=Main_Page',
"REQUEST_METHOD=GET",
);
page = machine.succeed(f"{' '.join(env)} ${lib.getExe containers.machine.nixpkgs.pkgs.fcgi} -bind -connect ${containers.machine.services.phpfpm.pools.mediawiki.socket}")
page = machine.succeed(f"{' '.join(env)} ${lib.getExe nodes.machine.nixpkgs.pkgs.fcgi} -bind -connect ${nodes.machine.services.phpfpm.pools.mediawiki.socket}")
assert "MediaWiki has been installed" in page, f"no 'MediaWiki has been installed' in:\n{page}"
'';
};
nginx = makeTest {
name = "mediawiki-nginx";
containers.machine = {
nodes.machine = {
services.mediawiki.webserver = "nginx";
};
testScript = ''

View File

@@ -10,8 +10,5 @@
inherit (pkgs) percona-server_8_4;
};
mkTestName =
pkg:
"${builtins.replaceStrings [ "-" ] [ "_" ] pkg.pname}_${
builtins.replaceStrings [ "." ] [ "" ] (lib.versions.majorMinor pkg.version)
}";
pkg: "mariadb_${builtins.replaceStrings [ "." ] [ "" ] (lib.versions.majorMinor pkg.version)}";
}

View File

@@ -33,7 +33,7 @@ let
nodes = {
${name} =
{ pkgs, config, ... }:
{ pkgs, ... }:
{
users = {
@@ -61,18 +61,18 @@ let
# note that using pkgs.writeText here is generally not a good idea,
# as it will store the password in world-readable /nix/store ;)
initialScript = pkgs.writeText "mysql-init.sql" (
if config.services.mysql.package.pname == "mariadb" then
if (!useSocketAuth) then
''
CREATE USER 'testuser3'@'localhost' IDENTIFIED BY 'secure';
GRANT ALL PRIVILEGES ON testdb3.* TO 'testuser3'@'localhost';
''
else
''
ALTER USER root@localhost IDENTIFIED WITH unix_socket;
DELETE FROM mysql.user WHERE password = ''' AND plugin = ''';
DELETE FROM mysql.user WHERE user = ''';
FLUSH PRIVILEGES;
''
else
# just some smoketest initial script sql statement
''
SELECT * FROM mysql.user;
''
);
ensureDatabases = [
@@ -104,66 +104,61 @@ let
};
};
testScript =
{ nodes, ... }:
let
mysqlClient = lib.getExe nodes.${name}.services.mysql.package.client;
in
''
start_all()
testScript = ''
start_all()
machine = ${name}
machine.wait_for_unit("mysql")
machine = ${name}
machine.wait_for_unit("mysql")
machine.succeed(
"echo 'use testdb; create table tests (test_id INT, PRIMARY KEY (test_id));' | sudo -u testuser mysql -u testuser"
)
machine.succeed(
"echo 'use testdb; insert into tests values (42);' | sudo -u testuser mysql -u testuser"
)
# Ensure testuser2 is not able to insert into testdb as mysql testuser2
machine.fail(
"echo 'use testdb; insert into tests values (23);' | sudo -u testuser2 mysql -u testuser2"
)
# Ensure testuser2 is not able to authenticate as mysql testuser
machine.fail(
"echo 'use testdb; insert into tests values (23);' | sudo -u testuser2 mysql -u testuser"
)
machine.succeed(
"echo 'use testdb; select test_id from tests;' | sudo -u testuser mysql -u testuser -N | grep 42"
)
${lib.optionalString hasMroonga ''
# Check if Mroonga plugin works
machine.succeed(
"echo 'use testdb; create table tests (test_id INT, PRIMARY KEY (test_id));' | sudo -u testuser ${mysqlClient} -u testuser"
"echo 'use testdb; create table mroongadb (test_id INT, PRIMARY KEY (test_id)) ENGINE = Mroonga;' | sudo -u testuser mysql -u testuser"
)
machine.succeed(
"echo 'use testdb; insert into tests values (42);' | sudo -u testuser ${mysqlClient} -u testuser"
)
# Ensure testuser2 is not able to insert into testdb as mysql testuser2
machine.fail(
"echo 'use testdb; insert into tests values (23);' | sudo -u testuser2 ${mysqlClient} -u testuser2"
)
# Ensure testuser2 is not able to authenticate as mysql testuser
machine.fail(
"echo 'use testdb; insert into tests values (23);' | sudo -u testuser2 ${mysqlClient} -u testuser"
"echo 'use testdb; insert into mroongadb values (25);' | sudo -u testuser mysql -u testuser"
)
machine.succeed(
"echo 'use testdb; select test_id from tests;' | sudo -u testuser ${mysqlClient} -u testuser -N | grep 42"
"echo 'use testdb; select test_id from mroongadb;' | sudo -u testuser mysql -u testuser -N | grep 25"
)
machine.succeed(
"echo 'use testdb; drop table mroongadb;' | sudo -u testuser mysql -u testuser"
)
''}
${lib.optionalString hasMroonga ''
# Check if Mroonga plugin works
machine.succeed(
"echo 'use testdb; create table mroongadb (test_id INT, PRIMARY KEY (test_id)) ENGINE = Mroonga;' | sudo -u testuser ${mysqlClient} -u testuser"
)
machine.succeed(
"echo 'use testdb; insert into mroongadb values (25);' | sudo -u testuser ${mysqlClient} -u testuser"
)
machine.succeed(
"echo 'use testdb; select test_id from mroongadb;' | sudo -u testuser ${mysqlClient} -u testuser -N | grep 25"
)
machine.succeed(
"echo 'use testdb; drop table mroongadb;' | sudo -u testuser ${mysqlClient} -u testuser"
)
''}
${lib.optionalString hasRocksDB ''
# Check if RocksDB plugin works
machine.succeed(
"echo 'use testdb; create table rocksdb (test_id INT, PRIMARY KEY (test_id)) ENGINE = RocksDB;' | sudo -u testuser ${mysqlClient} -u testuser"
)
machine.succeed(
"echo 'use testdb; insert into rocksdb values (28);' | sudo -u testuser ${mysqlClient} -u testuser"
)
machine.succeed(
"echo 'use testdb; select test_id from rocksdb;' | sudo -u testuser ${mysqlClient} -u testuser -N | grep 28"
)
machine.succeed(
"echo 'use testdb; drop table rocksdb;' | sudo -u testuser ${mysqlClient} -u testuser"
)
''}
'';
${lib.optionalString hasRocksDB ''
# Check if RocksDB plugin works
machine.succeed(
"echo 'use testdb; create table rocksdb (test_id INT, PRIMARY KEY (test_id)) ENGINE = RocksDB;' | sudo -u testuser mysql -u testuser"
)
machine.succeed(
"echo 'use testdb; insert into rocksdb values (28);' | sudo -u testuser mysql -u testuser"
)
machine.succeed(
"echo 'use testdb; select test_id from rocksdb;' | sudo -u testuser mysql -u testuser -N | grep 28"
)
machine.succeed(
"echo 'use testdb; drop table rocksdb;' | sudo -u testuser mysql -u testuser"
)
''}
'';
};
in
lib.mapAttrs (
@@ -185,6 +180,7 @@ lib.mapAttrs (
_: package:
makeMySQLTest {
inherit package;
name = builtins.replaceStrings [ "-" ] [ "_" ] package.pname;
hasMroonga = false;
useSocketAuth = false;
}

View File

@@ -1,40 +0,0 @@
{ ... }:
{
name = "nginx-grpc-error-pages";
containers = {
webserver =
{ pkgs, ... }:
{
services.nginx = {
enable = true;
virtualHosts.test = {
locations = {
"=/".return = "200 blub";
"/grpc.reflection.v1.ServerReflection" = {
useGrpcErrorPages = true;
extraConfig = ''
grpc_pass unix:/run/some-service.sock;
# Let's pretend there was a more sophisticated check here
return 401;
'';
};
};
};
};
};
};
testScript = ''
webserver.wait_for_unit("nginx")
webserver.wait_for_open_port(80)
# regular HTTP requests should behave normally
webserver.succeed("curl --fail http://localhost")
t.assertEqual(webserver.succeed("curl -s -o /dev/null -w '%{http_code}' http://localhost/404").strip(), "404")
# a gRPC 401 becomes HTTP code 2xx, with grpc-message and grpc-status headers set.
t.assertEqual(webserver.succeed("curl -s -o /dev/null --fail -w '%header{grpc-status}_%header{grpc-message}' http://localhost/grpc.reflection.v1.ServerReflection").strip(), "16_unauthenticated")
'';
}

Some files were not shown because too many files have changed in this diff Show More