From e0a1ee72af2796ba37c4b6f82664f6294f150665 Mon Sep 17 00:00:00 2001 From: Nidhish Chauhan Date: Tue, 19 May 2026 00:24:42 +0530 Subject: [PATCH 01/17] maintainers: add castorNova2 --- maintainers/maintainer-list.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index cb8b35d2f483..bda71b2ca18a 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -4542,6 +4542,12 @@ githubId = 53847249; name = "Casey Avila"; }; + castorNova2 = { + email = "solemnsquire@gmail.com"; + github = "castorNova2"; + githubId = 84083897; + name = "Nidhish Chauhan"; + }; catap = { email = "kirill@korins.ky"; github = "catap"; From bf3ce8baf29430988fb6076af8e40fb1f80d9c3b Mon Sep 17 00:00:00 2001 From: Ross Smyth <18294397+RossSmyth@users.noreply.github.com> Date: Sat, 23 May 2026 21:24:04 -0400 Subject: [PATCH 02/17] wild-unwrapped: rename github owner from david to wild-linker --- pkgs/by-name/wi/wild-unwrapped/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/wi/wild-unwrapped/package.nix b/pkgs/by-name/wi/wild-unwrapped/package.nix index acd36edcea45..7e387dd30d8a 100644 --- a/pkgs/by-name/wi/wild-unwrapped/package.nix +++ b/pkgs/by-name/wi/wild-unwrapped/package.nix @@ -13,7 +13,7 @@ rustPlatform.buildRustPackage (finalAttrs: { version = "0.8.0"; src = fetchFromGitHub { - owner = "davidlattimore"; + owner = "wild-linker"; repo = "wild"; tag = finalAttrs.version; hash = "sha256-E5cmZuOtF+MNTPyalKjnguhin70zqtDDB0D71ZpeE48="; @@ -46,8 +46,8 @@ rustPlatform.buildRustPackage (finalAttrs: { meta = { description = "Very fast linker for Linux"; - homepage = "https://github.com/davidlattimore/wild"; - changelog = "https://github.com/davidlattimore/wild/blob/${finalAttrs.version}/CHANGELOG.md"; + homepage = "https://github.com/wild-linker/wild"; + changelog = "https://github.com/wild-linker/wild/blob/${finalAttrs.version}/CHANGELOG.md"; license = [ lib.licenses.asl20 # or lib.licenses.mit From 313fc8e682ab219c8e22dd702a1fc1927f134b82 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Sun, 24 May 2026 12:27:42 +1000 Subject: [PATCH 03/17] hydra: 0-unstable-2026-03-13 -> 0-unstable-2026-03-16 Diff: https://github.com/NixOS/hydra/compare/5decc46ce66335b225c1504a509fefa0f804436f...a40d42862da88cce78a27dd594e1484a034aac4d --- pkgs/by-name/hy/hydra/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/hy/hydra/package.nix b/pkgs/by-name/hy/hydra/package.nix index e5ac3a58ab4c..8093f597f589 100644 --- a/pkgs/by-name/hy/hydra/package.nix +++ b/pkgs/by-name/hy/hydra/package.nix @@ -132,14 +132,14 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "hydra"; - version = "0-unstable-2026-03-13"; + version = "0-unstable-2026-03-16"; # nixpkgs-update: no auto update src = fetchFromGitHub { owner = "NixOS"; repo = "hydra"; - rev = "5decc46ce66335b225c1504a509fefa0f804436f"; - hash = "sha256-wBVp3TDCBKyqyWbMlya+egjhSN7R067v20pUZINSF0g="; + rev = "a40d42862da88cce78a27dd594e1484a034aac4d"; + hash = "sha256-8pttLK/JQiUL6EXJfjBtBggiLw+769JdQGrpM7klXdg="; }; outputs = [ From 7dfad65ff7b47b3eb0282593da7f67a5625e5895 Mon Sep 17 00:00:00 2001 From: transcaffeine Date: Mon, 25 May 2026 15:54:41 +0200 Subject: [PATCH 04/17] victoriametrics: 1.143.0 -> 1.144.0 Release notes: https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.144.0 Full changelog: https://github.com/VictoriaMetrics/VictoriaMetrics/compare/v1.143.0...v1.144.0 --- pkgs/by-name/vi/victoriametrics/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vi/victoriametrics/package.nix b/pkgs/by-name/vi/victoriametrics/package.nix index 0e65b7c55092..3c091d8e69b8 100644 --- a/pkgs/by-name/vi/victoriametrics/package.nix +++ b/pkgs/by-name/vi/victoriametrics/package.nix @@ -14,13 +14,13 @@ buildGoModule (finalAttrs: { pname = "VictoriaMetrics"; - version = "1.143.0"; + version = "1.144.0"; src = fetchFromGitHub { owner = "VictoriaMetrics"; repo = "VictoriaMetrics"; tag = "v${finalAttrs.version}"; - hash = "sha256-K5NsQQ+r1XoOCfeYzZP3+2wdDpGNqWZLpe1hGqx11jA="; + hash = "sha256-K8RCFHVL+E8w0webp6Bg3dma7I32iGXx9gCKnFp4d0g="; }; vendorHash = null; From 94a36f74d0d78bcf7392157bea7bda12f941fdb1 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Wed, 27 May 2026 03:19:26 +0200 Subject: [PATCH 05/17] nixos/dhparams: remove This module was deprecated in 26.05 and is being removed in 26.11. Generating your own dhparams has been obsoleted by RFC 7919 (2016). DHE itself has been obsoleted by ECHDE (RFC8422, 2018) and Hybrid PQ (draft-ietf-tls-ecdhe-mlkem, 2026) key exchanges. TLS 1.3 (RFC8446, 2018) stopped defining any DHE cipher suites and lists this as a major difference from TLS 1.2. --- nixos/modules/module-list.nix | 1 - nixos/modules/rename.nix | 3 + nixos/modules/security/dhparams.nix | 223 ---------------------------- nixos/tests/all-tests.nix | 1 - nixos/tests/dhparams.nix | 143 ------------------ 5 files changed, 3 insertions(+), 368 deletions(-) delete mode 100644 nixos/modules/security/dhparams.nix delete mode 100644 nixos/tests/dhparams.nix diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index c57b627e875c..2778c6f295ce 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -394,7 +394,6 @@ ./security/ca.nix ./security/chromium-suid-sandbox.nix ./security/default.nix - ./security/dhparams.nix ./security/doas.nix ./security/duosec.nix ./security/google_oslogin.nix diff --git a/nixos/modules/rename.nix b/nixos/modules/rename.nix index 4bca9ffcaaa0..bacb7275cea0 100644 --- a/nixos/modules/rename.nix +++ b/nixos/modules/rename.nix @@ -125,6 +125,9 @@ in (mkRemovedOptionModule [ "programs" "yabar" ] "programs.yabar has been removed from NixOS. This is because the yabar repository has been archived upstream." ) + (mkRemovedOptionModule [ "security" "dhparams" ] '' + The security.dhparams module has been removed as RFC 7919 has shown that generating your own params is problematic. + '') (mkRemovedOptionModule [ "security" "hideProcessInformation" ] '' The hidepid module was removed, since the underlying machinery is broken when using cgroups-v2. diff --git a/nixos/modules/security/dhparams.nix b/nixos/modules/security/dhparams.nix deleted file mode 100644 index a18af9f85ae7..000000000000 --- a/nixos/modules/security/dhparams.nix +++ /dev/null @@ -1,223 +0,0 @@ -{ - config, - lib, - options, - pkgs, - ... -}: - -let - inherit (lib) literalExpression mkOption types; - cfg = config.security.dhparams; - opt = options.security.dhparams; - - bitType = types.addCheck types.int (b: b >= 16) // { - name = "bits"; - description = "integer of at least 16 bits"; - }; - - paramsSubmodule = - { name, config, ... }: - { - options.bits = mkOption { - type = bitType; - default = cfg.defaultBitSize; - defaultText = literalExpression "config.${opt.defaultBitSize}"; - description = '' - The bit size for the prime that is used during a Diffie-Hellman - key exchange. - ''; - }; - - options.path = mkOption { - type = types.path; - readOnly = true; - description = '' - The resulting path of the generated Diffie-Hellman parameters - file for other services to reference. This could be either a - store path or a file inside the directory specified by - {option}`security.dhparams.path`. - ''; - }; - - config.path = - let - generated = pkgs.runCommand "dhparams-${name}.pem" { - nativeBuildInputs = [ pkgs.openssl ]; - } "openssl dhparam -out \"$out\" ${toString config.bits}"; - in - if cfg.stateful then "${cfg.path}/${name}.pem" else generated; - }; - -in -{ - options = { - security.dhparams = { - enable = mkOption { - type = types.bool; - default = false; - description = '' - Whether to generate new DH params and clean up old DH params. - ''; - }; - - params = mkOption { - type = - with types; - let - coerce = bits: { inherit bits; }; - in - attrsOf (coercedTo int coerce (submodule paramsSubmodule)); - default = { }; - example = lib.literalExpression "{ nginx.bits = 3072; }"; - description = '' - Diffie-Hellman parameters to generate. - - The value is the size (in bits) of the DH params to generate. The - generated DH params path can be found in - `config.security.dhparams.params.«name».path`. - - ::: {.note} - The name of the DH params is taken as being the name of - the service it serves and the params will be generated before the - said service is started. - ::: - - ::: {.warning} - If you are removing all dhparams from this list, you - have to leave {option}`security.dhparams.enable` for at - least one activation in order to have them be cleaned up. This also - means if you rollback to a version without any dhparams the - existing ones won't be cleaned up. Of course this only applies if - {option}`security.dhparams.stateful` is - `true`. - ::: - - ::: {.note} - **For module implementers:** It's recommended - to not set a specific bit size here, so that users can easily - override this by setting - {option}`security.dhparams.defaultBitSize`. - ::: - ''; - }; - - stateful = mkOption { - type = types.bool; - default = true; - description = '' - Whether generation of Diffie-Hellman parameters should be stateful or - not. If this is enabled, PEM-encoded files for Diffie-Hellman - parameters are placed in the directory specified by - {option}`security.dhparams.path`. Otherwise the files are - created within the Nix store. - - ::: {.note} - If this is `false` the resulting store - path will be non-deterministic and will be rebuilt every time the - `openssl` package changes. - ::: - ''; - }; - - defaultBitSize = mkOption { - type = bitType; - default = 2048; - description = '' - This allows to override the default bit size for all of the - Diffie-Hellman parameters set in - {option}`security.dhparams.params`. - ''; - }; - - path = mkOption { - type = types.str; - default = "/var/lib/dhparams"; - description = '' - Path to the directory in which Diffie-Hellman parameters will be - stored. This only is relevant if - {option}`security.dhparams.stateful` is - `true`. - ''; - }; - }; - }; - - config = lib.mkMerge [ - (lib.mkIf cfg.enable { - warnings = [ - '' - The `security.dhparams` module is deprecated and scheduled for removal in NixOS 26.11. - Generating your own params has been shown to be problematic in RFC 7919 (2016). - - Remove any uses of DHE and migrate to ECDHE (RFC 8422, 2018) and - Hybrid PQ (draft-ietf-tls-ecdhe-mlkem, 2026) key exchange algorithms. - '' - ]; - }) - (lib.mkIf (cfg.enable && cfg.stateful) { - systemd.services = { - dhparams-init = { - description = "Clean Up Old Diffie-Hellman Parameters"; - - # Clean up even when no DH params is set - wantedBy = [ "multi-user.target" ]; - - serviceConfig.RemainAfterExit = true; - serviceConfig.Type = "oneshot"; - - script = '' - if [ ! -d ${cfg.path} ]; then - mkdir -p ${cfg.path} - fi - - # Remove old dhparams - for file in ${cfg.path}/*; do - if [ ! -f "$file" ]; then - continue - fi - ${lib.concatStrings ( - lib.mapAttrsToList ( - name: - { bits, path, ... }: - '' - if [ "$file" = ${lib.escapeShellArg path} ] && \ - ${pkgs.openssl}/bin/openssl dhparam -in "$file" -text \ - | head -n 1 | grep "(${toString bits} bit)" > /dev/null; then - continue - fi - '' - ) cfg.params - )} - rm "$file" - done - - # TODO: Ideally this would be removing the *former* cfg.path, though - # this does not seem really important as changes to it are quite - # unlikely - rmdir --ignore-fail-on-non-empty ${cfg.path} - ''; - }; - } - // lib.mapAttrs' ( - name: - { bits, path, ... }: - lib.nameValuePair "dhparams-gen-${name}" { - description = "Generate Diffie-Hellman Parameters for ${name}"; - after = [ "dhparams-init.service" ]; - before = [ "${name}.service" ]; - requiredBy = [ "${name}.service" ]; - wantedBy = [ "multi-user.target" ]; - unitConfig.ConditionPathExists = "!${path}"; - serviceConfig.Type = "oneshot"; - script = '' - mkdir -p ${lib.escapeShellArg cfg.path} - ${pkgs.openssl}/bin/openssl dhparam -out ${lib.escapeShellArg path} \ - ${toString bits} - ''; - } - ) cfg.params; - }) - ]; - -} diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index f9ecf72845ed..edd511c2bbd3 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -455,7 +455,6 @@ in dependency-track = runTest ./dependency-track.nix; devpi-server = runTest ./devpi-server.nix; dex-oidc = runTest ./dex-oidc.nix; - dhparams = runTest ./dhparams.nix; dictd = runTest ./dictd.nix; disable-installer-tools = runTest ./disable-installer-tools.nix; discourse = runTest { diff --git a/nixos/tests/dhparams.nix b/nixos/tests/dhparams.nix deleted file mode 100644 index 89df5b1a0154..000000000000 --- a/nixos/tests/dhparams.nix +++ /dev/null @@ -1,143 +0,0 @@ -{ - name = "dhparams"; - - nodes.machine = - { pkgs, ... }: - { - security.dhparams.enable = true; - environment.systemPackages = [ pkgs.openssl ]; - - specialisation = { - gen1.configuration = - { config, ... }: - { - security.dhparams.params = { - # Use low values here because we don't want the test to run for ages. - foo.bits = 1024; - # Also use the old format to make sure the type is coerced in the right - # way. - bar = 1025; - }; - - systemd.services.foo = { - description = "Check systemd Ordering"; - wantedBy = [ "multi-user.target" ]; - before = [ "shutdown.target" ]; - conflicts = [ "shutdown.target" ]; - unitConfig = { - # This is to make sure that the dhparams generation of foo occurs - # before this service so we need this service to start as early as - # possible to provoke a race condition. - DefaultDependencies = false; - - # We check later whether the service has been started or not. - ConditionPathExists = config.security.dhparams.params.foo.path; - }; - serviceConfig.Type = "oneshot"; - serviceConfig.RemainAfterExit = true; - # The reason we only provide an ExecStop here is to ensure that we don't - # accidentally trigger an error because a file system is not yet ready - # during very early startup (we might not even have the Nix store - # available, for example if future changes in NixOS use systemd mount - # units to do early file system initialisation). - serviceConfig.ExecStop = "${pkgs.coreutils}/bin/true"; - }; - }; - gen2.configuration = { - security.dhparams.params.foo.bits = 1026; - }; - gen3.configuration = { }; - gen4.configuration = { - security.dhparams.stateful = false; - security.dhparams.params.foo2.bits = 1027; - security.dhparams.params.bar2.bits = 1028; - }; - gen5.configuration = { - security.dhparams.defaultBitSize = 1029; - security.dhparams.params.foo3 = { }; - security.dhparams.params.bar3 = { }; - }; - }; - }; - - testScript = - { nodes, ... }: - let - getParamPath = - gen: name: - let - node = "gen${toString gen}"; - in - nodes.machine.config.specialisation.${node}.configuration.security.dhparams.params.${name}.path; - - switchToGeneration = - gen: - let - switchCmd = "${nodes.machine.config.system.build.toplevel}/specialisation/gen${toString gen}/bin/switch-to-configuration test"; - in - '' - with machine.nested("switch to generation ${toString gen}"): - machine.succeed("${switchCmd}") - ''; - - in - '' - import re - - - def assert_param_bits(path, bits): - with machine.nested(f"check bit size of {path}"): - output = machine.succeed(f"openssl dhparam -in {path} -text") - pattern = re.compile(r"^\s*DH Parameters:\s+\((\d+)\s+bit\)\s*$", re.M) - match = pattern.match(output) - if match is None: - raise Exception("bla") - if match[1] != str(bits): - raise Exception(f"bit size should be {bits} but it is {match[1]} instead.") - - machine.wait_for_unit("multi-user.target") - ${switchToGeneration 1} - - with subtest("verify startup order"): - machine.succeed("systemctl is-active foo.service") - - with subtest("check bit sizes of dhparam files"): - assert_param_bits("${getParamPath 1 "foo"}", 1024) - assert_param_bits("${getParamPath 1 "bar"}", 1025) - - ${switchToGeneration 2} - - with subtest("check whether bit size has changed"): - assert_param_bits("${getParamPath 2 "foo"}", 1026) - - with subtest("ensure that dhparams file for 'bar' was deleted"): - machine.fail("test -e ${getParamPath 1 "bar"}") - - ${switchToGeneration 3} - - with subtest("ensure that 'security.dhparams.path' has been deleted"): - machine.fail("test -e ${nodes.machine.config.specialisation.gen3.configuration.security.dhparams.path}") - - ${switchToGeneration 4} - - with subtest("check bit sizes dhparam files"): - assert_param_bits( - "${getParamPath 4 "foo2"}", 1027 - ) - assert_param_bits( - "${getParamPath 4 "bar2"}", 1028 - ) - - with subtest("check whether dhparam files are in the Nix store"): - machine.succeed( - "expr match ${getParamPath 4 "foo2"} ${builtins.storeDir}", - "expr match ${getParamPath 4 "bar2"} ${builtins.storeDir}", - ) - - ${switchToGeneration 5} - - with subtest("check whether defaultBitSize works as intended"): - assert_param_bits("${getParamPath 5 "foo3"}", 1029) - assert_param_bits("${getParamPath 5 "bar3"}", 1029) - ''; -} From f02afd724b76be0135501aeb661a32e3e3a18ab4 Mon Sep 17 00:00:00 2001 From: Ross Smyth <18294397+RossSmyth@users.noreply.github.com> Date: Sat, 23 May 2026 21:24:52 -0400 Subject: [PATCH 06/17] wild-unwrapped: 0.8.0 -> 0.9.0 --- .../by-name/wi/wild-unwrapped/adapterTest.nix | 5 +++++ pkgs/by-name/wi/wild-unwrapped/package.nix | 19 +++++++++++++------ 2 files changed, 18 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/wi/wild-unwrapped/adapterTest.nix b/pkgs/by-name/wi/wild-unwrapped/adapterTest.nix index aaa578b97857..74b61d82632e 100644 --- a/pkgs/by-name/wi/wild-unwrapped/adapterTest.nix +++ b/pkgs/by-name/wi/wild-unwrapped/adapterTest.nix @@ -14,6 +14,7 @@ clang-tools, useWildLinker, hello, + taplo, }: let # These wrappers are REQUIRED for the Wild test suite to pass @@ -103,6 +104,10 @@ in stdenv.cc.libc.static ]; + nativeCheckInputs = [ + taplo + ]; + # https://github.com/davidlattimore/wild/discussions/832#discussioncomment-14482948 checkFlags = lib.optionals stdenv.hostPlatform.isAarch64 [ "--skip=integration_test::program_name_71___unresolved_symbols_object_c__" diff --git a/pkgs/by-name/wi/wild-unwrapped/package.nix b/pkgs/by-name/wi/wild-unwrapped/package.nix index 7e387dd30d8a..6a83893c4a32 100644 --- a/pkgs/by-name/wi/wild-unwrapped/package.nix +++ b/pkgs/by-name/wi/wild-unwrapped/package.nix @@ -1,5 +1,6 @@ { lib, + stdenv, fetchFromGitHub, callPackage, versionCheckHook, @@ -10,20 +11,24 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "wild-unwrapped"; - version = "0.8.0"; + version = "0.9.0"; src = fetchFromGitHub { owner = "wild-linker"; repo = "wild"; tag = finalAttrs.version; - hash = "sha256-E5cmZuOtF+MNTPyalKjnguhin70zqtDDB0D71ZpeE48="; + hash = "sha256-v4lPgZDPvRTAekkU9Vku9llgpOsaVtKt91VFUGrEeKw="; }; - cargoHash = "sha256-r0r7sN1SW5TIybHORfzJkN51Y0REEC2/h7q71GxUgAM="; + __structuredAttrs = true; - cargoBuildFlags = [ "-p wild-linker" ]; + cargoHash = "sha256-ADJLtTRXcVWcbvgwXvCs0wxcGp2XP1LZJUJ4hpuzVHQ="; + + cargoBuildFlags = [ + "-p" + "wild-linker" + ]; - strictDeps = true; nativeBuildInputs = [ pkg-config ]; @@ -54,6 +59,8 @@ rustPlatform.buildRustPackage (finalAttrs: { ]; mainProgram = "wild"; maintainers = with lib.maintainers; [ RossSmyth ]; - platforms = lib.platforms.linux; + # Wild can run on Linux and Darwin, but can only target ELF platforms. + # On linux this is native, on Darwin this is cross (or emulated) + platforms = with lib.platforms; lib.optionals (stdenv.targetPlatform.isElf) (linux ++ darwin); }; }) From 481f8049a7e8843231fe60fc33d58900620d7b6e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 29 May 2026 21:48:59 +0000 Subject: [PATCH 07/17] kubefwd: 1.25.14 -> 1.25.15 --- pkgs/by-name/ku/kubefwd/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ku/kubefwd/package.nix b/pkgs/by-name/ku/kubefwd/package.nix index 449db34605ee..6c965e3bf2d0 100644 --- a/pkgs/by-name/ku/kubefwd/package.nix +++ b/pkgs/by-name/ku/kubefwd/package.nix @@ -6,16 +6,16 @@ buildGoModule (finalAttrs: { pname = "kubefwd"; - version = "1.25.14"; + version = "1.25.15"; src = fetchFromGitHub { owner = "txn2"; repo = "kubefwd"; tag = "v${finalAttrs.version}"; - hash = "sha256-fxwUolGn55gf4voGT3noz44aNMSkxZiHD6OLADJ8aGg="; + hash = "sha256-OlmaKXw3SRa+7wXGBD6hEjdccBbdUXp67SM9bHduNEs="; }; - vendorHash = "sha256-UL9i81ez937u2sn4ZGY89eXfTplB0LVkeuLigc0BM5Y="; + vendorHash = "sha256-t6JaUKHpNrf9E8NTFFWwrJJI9b0HyYNQeUoV7II2ocQ="; subPackages = [ "cmd/kubefwd" ]; From 2cc9d939c73137efd6b6c3b79f4887991031be8d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 30 May 2026 07:41:41 +0000 Subject: [PATCH 08/17] devin-cli: 2026.5.6-10 -> 2026.5.26-2 --- pkgs/by-name/de/devin-cli/package.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/de/devin-cli/package.nix b/pkgs/by-name/de/devin-cli/package.nix index a1b9c72e6509..bfa58bd3a255 100644 --- a/pkgs/by-name/de/devin-cli/package.nix +++ b/pkgs/by-name/de/devin-cli/package.nix @@ -7,29 +7,29 @@ }: let - version = "2026.5.6-10"; + version = "2026.5.26-2"; throwSystem = throw "Unsupported system: ${stdenvNoCC.hostPlatform.system}"; srcs = { x86_64-linux = fetchurl { url = "https://static.devin.ai/cli/${version}/devin-${version}-x86_64-unknown-linux.tar.gz"; - hash = "sha256-X3Pua8lBRojFgB5uAQ4Px/cVq79saQV7b2JN8NBvXLE="; + hash = "sha256-5647gIz60Dj/mZ4bALJsWnAyWfXQO33vG6kqy2hHp84="; }; aarch64-linux = fetchurl { url = "https://static.devin.ai/cli/${version}/devin-${version}-aarch64-unknown-linux.tar.gz"; - hash = "sha256-wWY07anOf1e64XyxuPxWO1Qf6sVW7JHDIeJw/o59GSE="; + hash = "sha256-8D61SCYC3VMbSwgRpWm8IKD1PQwbKT/EMejSFq5qsds="; }; aarch64-darwin = fetchurl { url = "https://static.devin.ai/cli/${version}/devin-${version}-aarch64-apple-darwin.tar.gz"; - hash = "sha256-5vlVs1AQ/ZbhF25hkKqBSTjAwYA/uOJY+S+jyMEgjRk="; + hash = "sha256-1MRFAWZKPCMfEm1zPGDHBoq4zAYXsIGTlrXwTkZH9c0="; }; x86_64-darwin = fetchurl { url = "https://static.devin.ai/cli/${version}/devin-${version}-x86_64-apple-darwin.tar.gz"; - hash = "sha256-T/0apTBEdpOnT/W13zB1Nis1kRghODHiR5yOj8gQuuY="; + hash = "sha256-B3LsnLXyExTagVC7UibsQTxk5u6KmYzgr2LtAJemSyo="; }; }; From 7638e54a40064a0185b4e505a9347b2d5d010abe Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 30 May 2026 14:49:24 +0000 Subject: [PATCH 09/17] python3Packages.urllib3-future: 2.20.906 -> 2.21.900 --- pkgs/development/python-modules/urllib3-future/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/urllib3-future/default.nix b/pkgs/development/python-modules/urllib3-future/default.nix index 7e4dad81d0d6..311b0f7db021 100644 --- a/pkgs/development/python-modules/urllib3-future/default.nix +++ b/pkgs/development/python-modules/urllib3-future/default.nix @@ -25,14 +25,14 @@ buildPythonPackage rec { pname = "urllib3-future"; - version = "2.20.906"; + version = "2.21.900"; pyproject = true; src = fetchFromGitHub { owner = "jawah"; repo = "urllib3.future"; tag = version; - hash = "sha256-XYZsnvFe4WNOAGN0TJuJiVVOHh5wElfngTPe6EfVJsE="; + hash = "sha256-7GfUKhJ8hjO93IRhzmt2WbUckh4W2RCblPCMuV3JWzs="; }; postPatch = '' From b95f99b7511e9db52d2d540b3765a2ad7c789a17 Mon Sep 17 00:00:00 2001 From: Nidhish Chauhan Date: Tue, 19 May 2026 00:25:02 +0530 Subject: [PATCH 10/17] zztgo: init at 0-unstable-2020-05-29 --- pkgs/by-name/zz/zztgo/package.nix | 42 +++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 pkgs/by-name/zz/zztgo/package.nix diff --git a/pkgs/by-name/zz/zztgo/package.nix b/pkgs/by-name/zz/zztgo/package.nix new file mode 100644 index 000000000000..98afbef2a7a8 --- /dev/null +++ b/pkgs/by-name/zz/zztgo/package.nix @@ -0,0 +1,42 @@ +{ + lib, + fetchFromGitHub, + buildGoModule, + makeWrapper, +}: + +buildGoModule { + pname = "zztgo"; + version = "0-unstable-2020-05-29"; + + __structuredAttrs = true; + strictDeps = true; + + src = fetchFromGitHub { + owner = "benhoyt"; + repo = "zztgo"; + rev = "9edb1452d887852c5c68cae0a91a6227cd4ef7a9"; + hash = "sha256-Wz9xAcsT27scuR78X6+17l0RExpmh0uTQUOcQ9lHIkI="; + }; + + vendorHash = "sha256-0hOXo7Ww34yI5yrz4CDMuFZjPj9CqtmWxQoc9aEBFOs="; + + nativeBuildInputs = [ makeWrapper ]; + + postInstall = '' + install -Dm644 TOWN.ZZT $out/share/zztgo/TOWN.ZZT + install -Dm644 zzt.terminal $out/share/zztgo/zzt.terminal + + wrapProgram $out/bin/zztgo \ + --chdir $out/share/zztgo + ''; + + meta = { + description = "Port of ZZT to Go"; + homepage = "https://github.com/benhoyt/zztgo"; + mainProgram = "zztgo"; + license = lib.licenses.mit; + platforms = lib.platforms.unix; + maintainers = with lib.maintainers; [ castorNova2 ]; + }; +} From ada6b0da22c7a5ed4ab179d7ffa0f8996ed3936e Mon Sep 17 00:00:00 2001 From: Nidhish Chauhan Date: Mon, 18 May 2026 23:38:55 +0530 Subject: [PATCH 11/17] berk76-tetris: init at 1.1.0 --- pkgs/by-name/be/berk76-tetris/package.nix | 48 +++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 pkgs/by-name/be/berk76-tetris/package.nix diff --git a/pkgs/by-name/be/berk76-tetris/package.nix b/pkgs/by-name/be/berk76-tetris/package.nix new file mode 100644 index 000000000000..625c7f1df09c --- /dev/null +++ b/pkgs/by-name/be/berk76-tetris/package.nix @@ -0,0 +1,48 @@ +{ + lib, + stdenv, + fetchFromGitHub, + ncurses, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "berk76-tetris"; + version = "1.1.0-unstable-2024-11-24"; + + src = fetchFromGitHub { + owner = "oldcompcz"; + repo = "tetris"; + rev = "31d441a840dff7ad3839087b9a5a594250841342"; + hash = "sha256-B5IYXT6Z3zbeG9lG7rflQvFnvOI/vse6L2Orv5dWlHg="; + }; + + strictDeps = true; + __structuredAttrs = true; + + buildInputs = [ ncurses ]; + + buildPhase = '' + runHook preBuild + + make -f Makefile.con + + runHook postBuild + ''; + + installPhase = '' + runHook preInstall + + install -Dm755 Tetris $out/bin/tetris + + runHook postInstall + ''; + + meta = { + description = "ASCII Art Tetris"; + homepage = "https://github.com/oldcompcz/tetris"; + mainProgram = "tetris"; + license = lib.licenses.gpl3Only; + platforms = lib.platforms.unix; + maintainers = with lib.maintainers; [ castorNova2 ]; + }; +}) From e537b593f6e25c2e1b705a4c0fdde31283e30e82 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 30 May 2026 22:55:08 +0000 Subject: [PATCH 12/17] firefox-gnome-theme: 149.1 -> 150 --- pkgs/by-name/fi/firefox-gnome-theme/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/fi/firefox-gnome-theme/package.nix b/pkgs/by-name/fi/firefox-gnome-theme/package.nix index 602933889502..8dfd36de3e72 100644 --- a/pkgs/by-name/fi/firefox-gnome-theme/package.nix +++ b/pkgs/by-name/fi/firefox-gnome-theme/package.nix @@ -7,13 +7,13 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "firefox-gnome-theme"; - version = "149.1"; + version = "150"; src = fetchFromGitHub { owner = "rafaelmardojai"; repo = "firefox-gnome-theme"; tag = "v${finalAttrs.version}"; - hash = "sha256-QFY6Eu0kmaWl8W76bXs5K2BVtTh+Md+1rGba1WiTYxU="; + hash = "sha256-UdfMivNMwCCqQsYDg5pSz8X2IOaOrIZLIIy+Bg3CO2o="; }; dontConfigure = true; From 8837c8d1b57890154b59905c14a181fb269648ac Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 31 May 2026 01:00:38 +0000 Subject: [PATCH 13/17] octave: 11.1.0 -> 11.2.0 --- pkgs/development/interpreters/octave/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/octave/default.nix b/pkgs/development/interpreters/octave/default.nix index 3d5a697f35d3..19a3314a36e9 100644 --- a/pkgs/development/interpreters/octave/default.nix +++ b/pkgs/development/interpreters/octave/default.nix @@ -100,12 +100,12 @@ let allPkgs = pkgs; in stdenv.mkDerivation (finalAttrs: { - version = "11.1.0"; + version = "11.2.0"; pname = "octave"; src = fetchurl { url = "mirror://gnu/octave/octave-${finalAttrs.version}.tar.gz"; - sha256 = "sha256-wOfiyRvFcyVkMbLMmJKQub0ThR263VnQrHRxTxM0sOY="; + sha256 = "sha256-zV0nMbYchh/yDKMN3ezrNmREuRjHoulZmG8DrsNuT6I="; }; postPatch = '' From 434503630c87444ec340360759d9ea6e7fc1cedd Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 31 May 2026 01:28:55 +0000 Subject: [PATCH 14/17] gotenberg: 8.32.0 -> 8.33.0 --- pkgs/by-name/go/gotenberg/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/go/gotenberg/package.nix b/pkgs/by-name/go/gotenberg/package.nix index 18c8991f7cf8..45dd66b54510 100644 --- a/pkgs/by-name/go/gotenberg/package.nix +++ b/pkgs/by-name/go/gotenberg/package.nix @@ -24,7 +24,7 @@ let in buildGo126Module (finalAttrs: { pname = "gotenberg"; - version = "8.32.0"; + version = "8.33.0"; outputs = [ "out" @@ -35,10 +35,10 @@ buildGo126Module (finalAttrs: { owner = "gotenberg"; repo = "gotenberg"; tag = "v${finalAttrs.version}"; - hash = "sha256-o29kpKVAlKu6ER7b6ni9DMN3kGzEUnoqvHETXBNhJVs="; + hash = "sha256-hTG2O8F/0FdKVKHQsFf027OJU60moey4qkMHUwIQ8xM="; }; - vendorHash = "sha256-kHNjWq53uCVOP3JGc57MK2FKjtlqZpJz7Za+wTb/F1U="; + vendorHash = "sha256-E0PVPuSxXtacxaFLrrIVFEre5C/woj3VUckLIdrQWoI="; postPatch = '' find ./pkg -name '*_test.go' -exec sed -i -e 's#/tests#${finalAttrs.src}#g' {} \; From bc1322ea191fe90b222af7675792cc5b418c2b53 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 31 May 2026 02:05:24 +0000 Subject: [PATCH 15/17] taze: 19.13.0 -> 19.14.1 --- pkgs/by-name/ta/taze/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ta/taze/package.nix b/pkgs/by-name/ta/taze/package.nix index f5d602e33bec..3c0d016a86c7 100644 --- a/pkgs/by-name/ta/taze/package.nix +++ b/pkgs/by-name/ta/taze/package.nix @@ -12,20 +12,20 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "taze"; - version = "19.13.0"; + version = "19.14.1"; src = fetchFromGitHub { owner = "antfu-collective"; repo = "taze"; tag = "v${finalAttrs.version}"; - hash = "sha256-EUfZ8Qh/g4t5R5leMP67ReWapp5hkcjwt+0VLI+ezTs="; + hash = "sha256-tcyZ4nbMw+RjASQKOiMDUCYNSWBeJ0u/rQ9Dq81HA7Y="; }; pnpmDeps = fetchPnpmDeps { inherit (finalAttrs) pname version src; pnpm = pnpm_9; fetcherVersion = 3; - hash = "sha256-4ZTdSEjxu6+q3LZ6bUykqsSEgzQAN/IGkPhpKx+DwDg="; + hash = "sha256-c2jBLdxQuIw028xo9cGhLykxARlOjK/R4e63U2UsXCQ="; }; nativeBuildInputs = [ From 7767e8e6f6da8726b4b879608e2727cf578e6648 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 31 May 2026 02:17:50 +0000 Subject: [PATCH 16/17] dblab: 0.39.0 -> 0.40.1 --- pkgs/by-name/db/dblab/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/db/dblab/package.nix b/pkgs/by-name/db/dblab/package.nix index 8fbe4a6ff541..5891750e6734 100644 --- a/pkgs/by-name/db/dblab/package.nix +++ b/pkgs/by-name/db/dblab/package.nix @@ -7,16 +7,16 @@ buildGoModule (finalAttrs: { pname = "dblab"; - version = "0.39.0"; + version = "0.40.1"; src = fetchFromGitHub { owner = "danvergara"; repo = "dblab"; tag = "v${finalAttrs.version}"; - hash = "sha256-tiB1nX3sm/pZpOFgNyhgxDsEzk0QcJQjwTLYx17LQMI="; + hash = "sha256-pDtiLKsAvV3k7sN5dnO0g03gxbs4WeCseadWKXh9DHM="; }; - vendorHash = "sha256-UGnbXjXnZ3EVcAk0ZTaV2wWWXv5nsbyNlTv8PMl2rP4="; + vendorHash = "sha256-T1y0ALF4s3T8ZaTqj2jUdnezVRmpegKnabahiQ3CgzA="; # Fix case-insensitive conflicts producing platform-dependent checksums # https://github.com/microsoft/go-mssqldb/issues/234 proxyVendor = true; From a44891042f07b3a87188cd4990a931519da75274 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 31 May 2026 03:20:25 +0000 Subject: [PATCH 17/17] amazon-cloudwatch-agent: 1.300066.0 -> 1.300069.0 --- pkgs/by-name/am/amazon-cloudwatch-agent/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/am/amazon-cloudwatch-agent/package.nix b/pkgs/by-name/am/amazon-cloudwatch-agent/package.nix index b26f6dc35210..12d808516bca 100644 --- a/pkgs/by-name/am/amazon-cloudwatch-agent/package.nix +++ b/pkgs/by-name/am/amazon-cloudwatch-agent/package.nix @@ -11,16 +11,16 @@ buildGoModule (finalAttrs: { pname = "amazon-cloudwatch-agent"; - version = "1.300066.0"; + version = "1.300069.0"; src = fetchFromGitHub { owner = "aws"; repo = "amazon-cloudwatch-agent"; tag = "v${finalAttrs.version}"; - hash = "sha256-cN1wxJKijx5P3JvtH+WX+3SYfar7xmM6XK2JABg+3lo="; + hash = "sha256-A9UASdKERo/vg3K8EDu//r6SqQjskhmVKeBlbqqpdDM="; }; - vendorHash = "sha256-W+DEQAX6BP6xwucE0mciQ4wzsIlF1b7d2Y+dyN43Lnw="; + vendorHash = "sha256-Qlwy0wz79TgYlBcsdHLzZA3OWbSIg6reK6KGSKsMlzI="; # See the list in https://github.com/aws/amazon-cloudwatch-agent/blob/v1.300049.1/Makefile#L68-L77. subPackages = [