Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
178 commits
Select commit Hold shift + click to select a range
73e1a9d
libcamera: 0.5.2 -> 0.6.0
r-burns Dec 12, 2025
fb77441
imagemagick: 7.1.2-10 -> 7.1.2-11
dotlambda Dec 18, 2025
bd688bf
wolfssl: 5.8.2 -> 5.8.4
LeSuisse Dec 13, 2025
2b76e8b
systemd: 258.2 -> 258.3
arianvp Dec 18, 2025
01eefe7
systemd: remove systemd-initrd-luks-unl0kr from passthru
arianvp Dec 25, 2025
e2fd562
nixos/tests/systemd-boot: only run tests on x86_64-linux
arianvp Dec 25, 2025
27dcf5b
mpg123: 1.33.3 -> 1.33.4
trofi Dec 21, 2025
511b1d9
[Backport staging-25.11] systemd: 258.2 -> 258.3 (#474788)
arianvp Dec 28, 2025
e58b5e2
[Backport staging-25.11] wolfssl: 5.8.2 -> 5.8.4 (#474708)
mdaniels5757 Dec 28, 2025
db7e488
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Dec 29, 2025
0167d92
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Dec 30, 2025
cbf2733
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Dec 30, 2025
d37e76e
tzdata: 2025b -> 2025c
ajs124 Dec 11, 2025
0548fe7
[Backport staging-25.11] libcamera: 0.5.2 -> 0.6.0 (#471900)
r-burns Dec 30, 2025
5d709e8
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Dec 31, 2025
995223f
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 1, 2026
1b856e3
publicsuffix-list: 0-unstable-2025-10-08 -> 0-unstable-2025-11-14
r-ryantm Nov 16, 2025
25ed659
[Backport staging-25.11] publicsuffix-list: 0-unstable-2025-10-08 -> …
jopejoe1 Jan 1, 2026
787c83a
publicsuffix-list: 0-unstable-2025-11-14 -> 0-unstable-2025-12-28
r-ryantm Dec 31, 2025
a2864cb
[Backport staging-25.11] publicsuffix-list: 0-unstable-2025-11-14 -> …
jopejoe1 Jan 1, 2026
a549a25
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 2, 2026
3f9883c
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 3, 2026
7c94d17
libsodium: add mdaniels5757 as co-maintainer
mdaniels5757 Jan 2, 2026
f8afb5c
libsodium: 1.0.20 -> 1.0.20-unstable-2025-12-31; use GitHub for relea…
mdaniels5757 Jan 2, 2026
88ade8c
python3Packages.pynacl: 1.6.0 -> 1.6.2
mdaniels5757 Jan 2, 2026
116ff43
[Backport staging-25.11] python3Packages.pynacl: 1.6.0 -> 1.6.2; libs…
7c6f434c Jan 3, 2026
1d0ab97
systemd: accept more symlink patterns for /etc/localtime
rhelmot Dec 31, 2025
9199c10
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 4, 2026
d052b5f
[Backport staging-25.11] systemd: accept more symlink patterns for /e…
rhelmot Jan 4, 2026
305af14
xorg.xorgserver: 21.1.20 -> 21.1.21
LeSuisse Jan 4, 2026
a3b37e9
xdg-user-dirs: 0.18 -> 0.19
limwa Jan 3, 2026
eed4fdf
[Backport staging-25.11] xdg-user-dirs: 0.18 -> 0.19 (#476969)
drupol Jan 4, 2026
c55d829
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 5, 2026
6715d38
[Backport staging-25.11] tzdata: 2025b -> 2025c (#475342)
fabianhjr Jan 5, 2026
7b14335
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 6, 2026
61fa018
[Backport staging-25.11] mpg123: 1.33.3 -> 1.33.4 (#474803)
fabianhjr Jan 6, 2026
8c0288d
libpcap: 1.10.5 -> 1.10.6
r-ryantm Dec 31, 2025
4071fc5
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 7, 2026
99b3cac
xdg-user-dirs-gtk: 0.14 -> 0.16
limwa Jan 3, 2026
3de28d7
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 8, 2026
aa1adb7
python3Packages.aiohttp: 3.13.2 -> 3.13.3
dotlambda Jan 5, 2026
6ebc844
python3Packages.brotlicffi: 1.1.0.0 -> 1.2.0.0
dotlambda Jan 8, 2026
e863dca
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 9, 2026
0400740
[Backport staging-25.11] xdg-user-dirs-gtk: 0.14 -> 0.16 (#477856)
jtojnar Jan 9, 2026
fcea730
nixos/gnome: install xdg-user-dirs{,-gtk} systemd units
limwa Jan 4, 2026
b1bcdca
libtasn1: 4.20.0 -> 4.21.0
mweinelt Jan 8, 2026
549e3d4
[Backport staging-25.11] libtasn1: 4.20.0 -> 4.21.0 (#478523)
mweinelt Jan 9, 2026
0ef3de8
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 10, 2026
5e0055f
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 10, 2026
5ebb35d
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 10, 2026
37ee180
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 11, 2026
876d12f
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 11, 2026
303a026
sdl3: fix dynamic loading of vulkan
marcin-serwin Jan 11, 2026
c47e88b
Merge branch 'release-25.11' into staging-next-25.11
vcunat Jan 11, 2026
1e8a587
[Backport staging-25.11] sdl3: fix dynamic loading of vulkan (#479065)
emilazy Jan 11, 2026
058d1cc
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 12, 2026
1f8e19b
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 12, 2026
f644307
harfbuzz: apply patch for CVE-2026-22693
LeSuisse Jan 11, 2026
9a6aa4d
[Backport staging-25.11] harfbuzz: apply patch for CVE-2026-22693 (#4…
nixpkgs-ci[bot] Jan 12, 2026
d9e8f19
[Backport staging-25.11] nixos/gnome: install xdg-user-dirs{,-gtk} sy…
jtojnar Jan 12, 2026
ccf3049
[Backport staging-25.11] python3Packages.aiohttp: 3.13.2 -> 3.13.3 (#…
dotlambda Jan 12, 2026
f60fae5
[Backport staging-25.11] python3Packages.brotlicffi: 1.1.0.0 -> 1.2.0…
dotlambda Jan 12, 2026
4710458
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 13, 2026
2a739c1
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 13, 2026
df791a9
[Backport staging-25.11] libpcap: 1.10.5 -> 1.10.6 (#477475)
fabianhjr Jan 13, 2026
e222eb9
fontforge: apply patches for CVE-2025-15279, CVE-2025-15275 and CVE-2…
LeSuisse Jan 10, 2026
daaae42
[Backport staging-25.11] fontforge: apply patches for CVE-2025-15279,…
philiptaron Jan 13, 2026
4c5920d
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 14, 2026
2e710b4
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 14, 2026
f05b9a4
nodejs_22: 22.21.1 -> 22.22.0
aduh95 Jan 13, 2026
59be4bc
[Backport staging-25.11] nodejs_22: 22.21.1 -> 22.22.0 (#479976)
aduh95 Jan 14, 2026
7049e41
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 15, 2026
3bc25b4
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 15, 2026
902976c
llvmPackages.libllvm: clean up rebuild avoidance
emilazy Jan 10, 2026
2876e53
[Backport staging-25.11] llvmPackages.libllvm: clean up rebuild avoid…
alyssais Jan 15, 2026
00b64b4
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 16, 2026
7ee868a
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 16, 2026
153d30f
curl: 8.17.0 -> 8.18.0
Scrumplex Jan 7, 2026
1fd45bc
go_1_25: 1.25.5 -> 1.25.6
herbetom Jan 15, 2026
847025b
[Backport staging-25.11] go_1_25: 1.25.5 -> 1.25.6 (#480621)
katexochen Jan 16, 2026
96faca6
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 17, 2026
9b9c479
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 17, 2026
3525256
glibc: 2.40-142 -> 2.40-217, fixes CVE-2026-0915, CVE-2026-0861
Ma27 Jan 17, 2026
335ac82
[25.11] xorg.xorgserver: 21.1.20 -> 21.1.21 (#476958)
jopejoe1 Jan 17, 2026
b3e46e0
libpng: 1.6.52 -> 1.6.53
jasi2 Jan 6, 2026
6075009
libpng: 1.6.53 -> 1.6.54
vcunat Jan 17, 2026
54d4656
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 18, 2026
33aa422
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 18, 2026
a2a9a25
python3Packages.filelock: 3.20.1 -> 3.20.3
mdaniels5757 Jan 12, 2026
a1cf2e1
[Backport staging-25.11] python3Packages.filelock: 3.20.1 -> 3.20.3 (…
mdaniels5757 Jan 18, 2026
e4de4f0
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 19, 2026
3e143d9
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 19, 2026
faeb318
[25.11] glibc: 2.40-142 -> 2.40-217, fixes CVE-2026-0915, CVE-2026-08…
Ma27 Jan 19, 2026
dced89f
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 20, 2026
4b294fa
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 20, 2026
f0fb2fc
[Backport staging-25.11] libpng: 1.6.52 -> 1.6.54 (#481051)
vcunat Jan 20, 2026
ebde88d
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 21, 2026
fb945de
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 21, 2026
fc582b1
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 22, 2026
63b1069
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 22, 2026
29b651a
python3Packages.tinycss2: 1.4.0 -> 1.5.1
DutchGerman Jan 20, 2026
ad25589
python3Packages.pillow: 12.0.0 -> 12.1.0
mweinelt Jan 2, 2026
a5e3f67
python3Packages.weasyprint: 66.0 -> 68.0
DutchGerman Jan 20, 2026
f602fcb
glibc: 2.40-217 -> 2.40-218, fixes CVE-2025-15281
Ma27 Jan 22, 2026
86f9b23
libheif: finalAttrs
kuflierl Jan 22, 2026
1778575
libheif: backport fix for CVE-2025-68431
kuflierl Jan 22, 2026
6719fb9
[Backport staging-25.11] libheif: backport fix for CVE-2025-68431, fi…
nixpkgs-ci[bot] Jan 22, 2026
5b19532
[25.11] glibc: 2.40-217 -> 2.40-218, fixes CVE-2025-15281 (#482623)
Ma27 Jan 22, 2026
d4f33d8
[Backport staging-25.11] curl: 8.17.0 -> 8.18.0 (#480594)
vcunat Jan 22, 2026
a08315e
libcdio: 2.2.0 -> 2.3.0
r-ryantm Dec 25, 2025
7cacd10
[Backport staging-25.11] imagemagick: 7.1.2-10 -> 7.1.2-11 (#472465)
vcunat Jan 22, 2026
2100a5a
[Backport staging-25.11] libcdio: 2.2.0 -> 2.3.0 (#482730)
fabianhjr Jan 22, 2026
363d1e7
python3Packages.pyasn1: 0.6.1 -> 0.6.2
LeSuisse Jan 17, 2026
c4e85fd
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 23, 2026
fcd9297
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 23, 2026
e614b13
tcl: fix static builds
alyssais Jan 21, 2026
1c8c470
[25.11] python3Packages.weasyprint: 66.0 -> 68.0 (#482601)
wolfgangwalther Jan 23, 2026
11d261b
[Backport staging-25.11] tcl: fix static builds (#482960)
alyssais Jan 23, 2026
ef9b542
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 24, 2026
d7c1aed
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 24, 2026
3b5f55c
[Backport staging-25.11] python3Packages.pyasn1: 0.6.1 -> 0.6.2 (#482…
vcunat Jan 24, 2026
53d609e
javaPackages.compiler.openjdk21: 21.0.9+10 -> 21.0.10+7
r-ryantm Jan 23, 2026
68f0bc4
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 24, 2026
949fb32
Merge staging-next-25.11 into staging-25.11
nixpkgs-ci[bot] Jan 24, 2026
d50d56f
inetutils: 2.6 -> 2.7, apply patches for CVE-2026-24061
LeSuisse Jan 21, 2026
d7c2feb
[Backport staging-25.11] inetutils: 2.6 -> 2.7, apply patches for CVE…
vcunat Jan 25, 2026
534ba16
libxml2_13: 2.13.8 -> 2.13.9
gepbird Jan 16, 2026
8a2decc
libxml2: fix CVE-2026-0990
gepbird Jan 17, 2026
531bb4b
libxml2: fix CVE-2026-0992
gepbird Jan 17, 2026
edfa05a
libxml2: fix CVE-2026-0989
gepbird Jan 17, 2026
c05a51d
libxml2_13: fix CVE-2026-0990
gepbird Jan 17, 2026
3200685
libxml2_13: fix CVE-2026-0992
gepbird Jan 17, 2026
056cdba
libxml2_13: fix CVE-2026-0989
gepbird Jan 17, 2026
b13ff83
libxml2: fix a typo in comment
vcunat Jan 25, 2026
7ee67b1
[Backport staging-25.11] libxml2{,_13}: fix 3 CVEs (#483591)
vcunat Jan 25, 2026
0deedc5
Merge branch 'staging-25.11' into staging-next-25.11
vcunat Jan 25, 2026
830942e
[Backport staging-25.11] javaPackages.compiler.openjdk21: 21.0.9+10 -…
FliegendeWurst Jan 25, 2026
ab72171
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 26, 2026
61cdaea
bind: 9.20.15 -> 9.20.16
trofi Nov 19, 2025
e672a4b
bind: 9.20.16 -> 9.20.17
trofi Dec 20, 2025
52c3700
bind: 9.20.17 -> 9.20.18
LeSuisse Jan 21, 2026
4223533
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 27, 2026
ac98040
Merge (older) branch 'staging-25.11' into staging-next-25.11
vcunat Jan 27, 2026
3381470
openssl: 3.6.0 -> 3.6.1
vcunat Jan 27, 2026
8a376e9
imagemagick: 7.1.2-11 -> 7.1.2-12
dotlambda Dec 30, 2025
df93562
imagemagick: 7.1.2-12 -> 7.1.2-13
faukah Jan 21, 2026
3cb0648
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 28, 2026
7e06922
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 29, 2026
84434a6
[25.11] bind: 9.20.15 -> 9.20.18 (#484012)
vcunat Jan 29, 2026
e1c54bd
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 30, 2026
610f414
python3Package.django_4: disable on 3.13 and newer
mweinelt Dec 18, 2025
579e439
grub2: apply November security fixes
LeSuisse Nov 19, 2025
676d4f1
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Jan 31, 2026
fd88953
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Feb 1, 2026
4ab1e6d
python3Packages.jupyter-server: 2.16.0 -> 2.17.0
dotlambda Nov 22, 2025
9c76ecd
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Feb 2, 2026
aefe04b
python3Packages.pypdf: 6.1.0 -> 6.3.0
r-ryantm Nov 21, 2025
1d4a8c3
python3Packages.pypdf: 6.3.0 -> 6.4.0
r-ryantm Nov 28, 2025
a5f62df
python3Packages.pypdf: 6.4.0 -> 6.4.2
r-ryantm Dec 17, 2025
1782ab4
python3Packages.pypdf: 6.4.2 -> 6.6.0
r-ryantm Jan 11, 2026
98c6b73
python3Packages.pypdf: 6.1.0 -> 6.6.0
vcunat Feb 2, 2026
86ecf49
[Backport staging-next-25.11] grub2: apply November security fixes (#…
vcunat Feb 2, 2026
7acd5bd
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Feb 3, 2026
806d802
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Feb 4, 2026
6b95051
python3Packages.term-image: disable warnings
ambroisie Jan 30, 2026
d36923f
python3Packages.pycdio: disables tests that have problems with python…
xsteadfastx Jan 26, 2026
ced0d23
python3Packages.pycdio: fix test for fs,read
Sigmanificient Jan 26, 2026
3b615f9
knot-resolver-manager_6: 6.1.0 -> 6.2.0
vcunat Feb 3, 2026
be7ab87
Revert "python3Package.django_4: disable on 3.13 and newer"
mweinelt Feb 4, 2026
857330d
python3Packages.django_4: 4.2.27 -> 4.2.28
mweinelt Feb 3, 2026
5f02556
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Feb 5, 2026
4bb246e
python3Packages.bleach: relax tinycss2 constraint
mweinelt Feb 5, 2026
6b2dab4
Merge branch 'release-25.11' into staging-next-25.11
vcunat Feb 5, 2026
dc81370
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Feb 6, 2026
1e6c61a
texlive: force rebuild of core binaries on aarch64-darwin
vcunat Feb 6, 2026
157d6f9
amazon-ssm-agent: stop running tests
arianvp Jan 21, 2026
0f68507
[Backport release-25.11] knot-resolver-manager_6: 6.1.0 -> 6.2.0 (#48…
vcunat Feb 6, 2026
b9b68ae
Merge release-25.11 into staging-next-25.11
nixpkgs-ci[bot] Feb 7, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions nixos/modules/services/desktop-managers/gnome.nix
Original file line number Diff line number Diff line change
Expand Up @@ -390,6 +390,10 @@ in
systemd.packages = [
pkgs.gnome-session
pkgs.gnome-shell
]
++ removeExcluded [
pkgs.xdg-user-dirs # Update user dirs as described in https://freedesktop.org/wiki/Software/xdg-user-dirs/
pkgs.xdg-user-dirs-gtk # Used to create the default bookmarks
];

services.udev.packages = [
Expand Down
9 changes: 6 additions & 3 deletions nixos/tests/systemd-boot.nix
Original file line number Diff line number Diff line change
Expand Up @@ -158,7 +158,8 @@ in
}
);

basicXbootldr = runTest (
# TODO: Fix on aarch64-linux
basicXbootldr = runTestOn [ "x86_64-linux" ] (
{ lib, ... }:
{
name = "systemd-boot-xbootldr";
Expand Down Expand Up @@ -282,7 +283,8 @@ in
}
);

update = runTest (
# TODO: Fix on aarch64-linux
update = runTestOn [ "x86_64-linux" ] (
{ lib, ... }:
{
name = "systemd-boot-update";
Expand Down Expand Up @@ -457,7 +459,8 @@ in
}
);

entryFilenameXbootldr = runTest (
# TODO: Fix on aarch64-linux
entryFilenameXbootldr = runTestOn [ "x86_64-linux" ] (
{ lib, ... }:
{
name = "systemd-boot-entry-filename-xbootldr";
Expand Down
4 changes: 2 additions & 2 deletions pkgs/applications/audio/mpg123/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -21,11 +21,11 @@ assert withConplay -> !libOnly;

stdenv.mkDerivation rec {
pname = "${lib.optionalString libOnly "lib"}mpg123";
version = "1.33.3";
version = "1.33.4";

src = fetchurl {
url = "mirror://sourceforge/mpg123/mpg123-${version}.tar.bz2";
hash = "sha256-agxkct0VbiE8IGj0ARXru3OXjC2HPma64qJQ4tIZjSY=";
hash = "sha256-OujJ/4Cpe/wOIuifvNdGh+yk/B2zFbEmB/J/ActaR9k=";
};

outputs = [
Expand Down
4 changes: 2 additions & 2 deletions pkgs/applications/graphics/ImageMagick/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -85,13 +85,13 @@ in

stdenv.mkDerivation (finalAttrs: {
pname = "imagemagick";
version = "7.1.2-10";
version = "7.1.2-13";

src = fetchFromGitHub {
owner = "ImageMagick";
repo = "ImageMagick";
tag = finalAttrs.version;
hash = "sha256-96lhd0B4yV2s/zVazKrqAcDZvn+yIiXxp8fqyKSfxLc=";
hash = "sha256-meADRjoV1c48laD35TuWAwuE95L90agROuuKBd++Kn8=";
};

outputs = [
Expand Down
10 changes: 1 addition & 9 deletions pkgs/by-name/am/amazon-ssm-agent/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -107,10 +107,6 @@ buildGoModule rec {
'';

preBuild = ''
# Note: if this step fails, please patch the code to fix it! Please only skip
# tests if it is not feasible for the test to pass in a sandbox.
make quick-integtest

make pre-release
make pre-build
'';
Expand Down Expand Up @@ -143,11 +139,7 @@ buildGoModule rec {
runHook postInstall
'';

checkFlags = [
# Skip time dependent/flaky test
"-skip=TestSendStreamDataMessageWithStreamDataSequenceNumberMutexLocked"
"-skip=TestParallelAccessOfQueue"
];
doCheck = false;

postFixup = ''
wrapProgram $out/bin/amazon-ssm-agent \
Expand Down
4 changes: 2 additions & 2 deletions pkgs/by-name/bi/bind/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -29,11 +29,11 @@

stdenv.mkDerivation (finalAttrs: {
pname = "bind";
version = "9.20.15";
version = "9.20.18";

src = fetchurl {
url = "https://downloads.isc.org/isc/bind9/${finalAttrs.version}/bind-${finalAttrs.version}.tar.xz";
hash = "sha256-1is4+uSLqD/KYYERLQxxAY2LDyzihdx53GoDZ3Isyrs=";
hash = "sha256-38VGyZCsRRVSnNRcTdmVhisYrootDLKSCOiJal0yUzE=";
};

outputs = [
Expand Down
4 changes: 2 additions & 2 deletions pkgs/by-name/cu/curlMinimal/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ assert

stdenv.mkDerivation (finalAttrs: {
pname = "curl";
version = "8.17.0";
version = "8.18.0";

src = fetchurl {
urls = [
Expand All @@ -95,7 +95,7 @@ stdenv.mkDerivation (finalAttrs: {
builtins.replaceStrings [ "." ] [ "_" ] finalAttrs.version
}/curl-${finalAttrs.version}.tar.xz"
];
hash = "sha256-lV9ucprWs1ZiYOj+9oYg52ujwxrPChhSRBahhaz3eZI=";
hash = "sha256-QN95Fm50qiAUk2XhHuTHmKRq1Xw05PaP0TEA4smpGUY=";
};

# this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion
Expand Down
21 changes: 21 additions & 0 deletions pkgs/by-name/fo/fontforge/package.nix
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
{
stdenv,
fetchFromGitHub,
fetchpatch,
lib,
replaceVars,
cmake,
Expand Down Expand Up @@ -48,6 +49,26 @@ stdenv.mkDerivation (finalAttrs: {
patches = [
# Provide a Nix-controlled location for the initial `sys.path` entry.
(replaceVars ./set-python-sys-path.patch { python = "${py}/${py.sitePackages}"; })
(fetchpatch {
name = "CVE-2025-15279_1.patch";
url = "https://github.com/fontforge/fontforge/commit/7d67700cf8888e0bb37b453ad54ed932c8587073.patch";
hash = "sha256-AqixWSgMc75qkgO30nWnI9NKLRtVwCDR+uSEiwMtFKg=";
})
(fetchpatch {
name = "CVE-2025-15279_2.patch";
url = "https://github.com/fontforge/fontforge/commit/720ea95020c964202928afd2e93b0f5fac11027e.patch";
hash = "sha256-DsP2fDTZlTtg8MXcnsuGQ4PFPOVp56Jm95gq877PLlE=";
})
(fetchpatch {
name = "CVE-2025-15275.patch";
url = "https://github.com/fontforge/fontforge/commit/7195402701ace7783753ef9424153eff48c9af44.patch";
hash = "sha256-NHgKUvHF389z7PRqaDj3IWLSLijlSw0F3UYcMjLxKvE=";
})
(fetchpatch {
name = "CVE-2025-15269.patch";
url = "https://github.com/fontforge/fontforge/commit/6aea6db5da332d8ac94e3501bb83c1b21f52074d.patch";
hash = "sha256-3KsWSXVRpPJbytVmzjExCGw6IaCgcrKwqQGRKpQAOiY=";
})
];

# use $SOURCE_DATE_EPOCH instead of non-deterministic timestamps
Expand Down
10 changes: 10 additions & 0 deletions pkgs/by-name/ha/harfbuzz/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
lib,
stdenv,
fetchurl,
fetchpatch,
pkg-config,
glib,
freetype,
Expand Down Expand Up @@ -41,6 +42,15 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-5cgbf24LEC37AAz6QkU4uOiWq3ii9Lil7IyuYqtDNp4=";
};

patches = [
(fetchpatch {
# https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-xvjr-f2r9-c7ww
name = "CVE-2026-22693.patch";
url = "https://github.com/harfbuzz/harfbuzz/commit/1265ff8d990284f04d8768f35b0e20ae5f60daae.patch";
hash = "sha256-mdgIhp1ndPSfzplBRB7s+BN2T5Z9dEYZ0bAmSDCUPSE=";
})
];

postPatch = ''
patchShebangs src/*.py test
''
Expand Down
18 changes: 15 additions & 3 deletions pkgs/by-name/in/inetutils/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
stdenv,
lib,
fetchurl,
fetchpatch,
ncurses,
perl,
help2man,
Expand All @@ -12,11 +13,11 @@

stdenv.mkDerivation rec {
pname = "inetutils";
version = "2.6";
version = "2.7";

src = fetchurl {
url = "mirror://gnu/${pname}/${pname}-${version}.tar.xz";
hash = "sha256-aL7b/q9z99hr4qfZm8+9QJPYKfUncIk5Ga4XTAsjV8o=";
url = "mirror://gnu/${pname}/${pname}-${version}.tar.gz";
hash = "sha256-oVa+HN48XA/+/CYhgNk2mmBIQIeQeqVUxieH0vQOwIY=";
};

outputs = [
Expand All @@ -29,6 +30,17 @@ stdenv.mkDerivation rec {
./inetutils-1_9-PATH_PROCNET_DEV.patch

./tests-libls.sh.patch

(fetchpatch {
name = "CVE-2026-24061_1.patch";
url = "https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7b.patch";
hash = "sha256-d/FdQyLD0gYr+erFqKDr8Okf04DFXknFaN03ls2aonQ=";
})
(fetchpatch {
name = "CVE-2026-24061_2.patch";
url = "https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc.patch";
hash = "sha256-ws+ed5vb7kVMHEbqK7yj6FUT355pTv2RZEYuXs5M7Io=";
})
];

strictDeps = true;
Expand Down
11 changes: 7 additions & 4 deletions pkgs/by-name/kn/knot-resolver_6/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -15,13 +15,15 @@
libuv,
gnutls,
lmdb,
# optionals, in principle
jemalloc,
systemdMinimal,
libcap_ng,
dns-root-data,
nghttp2, # optionals, in principle
nghttp2,
ngtcp2-gnutls,
fstrm,
protobufc, # more optionals
protobufc,
# test-only deps.
cmocka,
which,
Expand All @@ -34,11 +36,11 @@ let
# TODO: we could cut the `let` short here, but it would de-indent everything.
unwrapped = stdenv.mkDerivation (finalAttrs: {
pname = "knot-resolver_6";
version = "6.1.0";
version = "6.2.0";

src = fetchurl {
url = "https://secure.nic.cz/files/knot-resolver/knot-resolver-${finalAttrs.version}.tar.xz";
hash = "sha256-eSHfdQcobZBXS79a5mSopTeAXOQLX6ixX10NM+LEONA=";
hash = "sha256-tEYzvIQxgMC8fHfPexX+VxJDrpkrTdt0r97kz6gDcBs=";
};

outputs = [
Expand Down Expand Up @@ -92,6 +94,7 @@ let
++ [
jemalloc
nghttp2
ngtcp2-gnutls
# dnstap support
fstrm
protobufc
Expand Down
5 changes: 3 additions & 2 deletions pkgs/by-name/li/libcamera/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -27,12 +27,12 @@

stdenv.mkDerivation rec {
pname = "libcamera";
version = "0.5.2";
version = "0.6.0";

src = fetchgit {
url = "https://git.libcamera.org/libcamera/libcamera.git";
rev = "v${version}";
hash = "sha256-nr1LmnedZMGBWLf2i5uw4E/OMeXObEKgjuO+PUx/GDY=";
hash = "sha256-zGcbzL1Q2hUaj/s9NjBlp7hVjmSFb0GF8CnCoDS82Tw=";
};

outputs = [
Expand Down Expand Up @@ -112,6 +112,7 @@ stdenv.mkDerivation rec {
"-Dv4l2=true"
(lib.mesonEnable "tracing" withTracing)
(lib.mesonEnable "qcam" withQcam)
"-Dlibunwind=disabled"
"-Dlc-compliance=disabled" # tries unconditionally to download gtest when enabled
# Avoid blanket -Werror to evade build failures on less
# tested compilers.
Expand Down
4 changes: 2 additions & 2 deletions pkgs/by-name/li/libcdio/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -16,13 +16,13 @@

stdenv.mkDerivation (finalAttrs: {
pname = "libcdio";
version = "2.2.0";
version = "2.3.0";

src = fetchFromGitHub {
owner = "libcdio";
repo = "libcdio";
tag = finalAttrs.version;
hash = "sha256-izjZk2kz9PkLm9+INUdl1e7jMz3nUsQKdplKI9Io+CM=";
hash = "sha256-NZj6sMIhBORh2ZBs/WGI4BYri1REog4ovUug1t5p8Y8=";
};

env = lib.optionalAttrs stdenv.hostPlatform.is32bit {
Expand Down
16 changes: 13 additions & 3 deletions pkgs/by-name/li/libheif/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
lib,
stdenv,
fetchFromGitHub,
fetchpatch,
cmake,
pkg-config,
dav1d,
Expand All @@ -22,7 +23,7 @@
vips,
}:

stdenv.mkDerivation rec {
stdenv.mkDerivation (finalAttrs: {
pname = "libheif";
version = "1.20.2";

Expand All @@ -37,10 +38,19 @@ stdenv.mkDerivation rec {
src = fetchFromGitHub {
owner = "strukturag";
repo = "libheif";
rev = "v${version}";
rev = "v${finalAttrs.version}";
hash = "sha256-PVfdX3/Oe3DXpYU5WMnCSi2p9X4fPszq2X3uuyh8RVU=";
};

patches = [
# CVE-2025-68431 (https://github.com/strukturag/libheif/security/advisories/GHSA-j87x-4gmq-cqfq)
(fetchpatch {
name = "001-fix-wrong-copy-width-in-overlay-images.patch";
url = "https://github.com/strukturag/libheif/commit/b8c12a7b70f46c9516711a988483bed377b78d46.patch";
hash = "sha256-PzGfcbdWAPdfExbSrPQwpk4v++TcNCXOhtwhgLGM13c=";
})
];

nativeBuildInputs = [
pkg-config
cmake
Expand Down Expand Up @@ -90,4 +100,4 @@ stdenv.mkDerivation rec {
platforms = lib.platforms.unix;
maintainers = with lib.maintainers; [ kuflierl ];
};
}
})
4 changes: 2 additions & 2 deletions pkgs/by-name/li/libpcap/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -26,13 +26,13 @@

stdenv.mkDerivation rec {
pname = "libpcap";
version = "1.10.5";
version = "1.10.6";

__structuredAttrs = true;

src = fetchurl {
url = "https://www.tcpdump.org/release/${pname}-${version}.tar.gz";
hash = "sha256-N87ZChmjAqfzLkWCJKAMNlwReQXCzTWsVEtogKgUiPA=";
hash = "sha256-hy3REzf+GrAq2dT+4EfJ2iRNaVxt3zTi67cz79Ttiqk=";
};

outputs = [
Expand Down
Loading
Loading