Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to Nix 2.23.1 (CVE-2024-38531) #1022

Merged
merged 7 commits into from
Jun 27, 2024
Merged

Upgrade to Nix 2.23.1 (CVE-2024-38531) #1022

merged 7 commits into from
Jun 27, 2024

Conversation

cole-h
Copy link
Member

@cole-h cole-h commented Jun 27, 2024

Description
Checklist
  • Formatted with cargo fmt
  • Built with nix build
  • Ran flake checks with nix flake check
  • Added or updated relevant tests (leave unchecked if not applicable)
  • Added or updated relevant documentation (leave unchecked if not applicable)
  • Linked to related issues (leave unchecked if not applicable)
Validating with install.determinate.systems

If a maintainer has added the upload to s3 label to this PR, it will become available for installation via install.determinate.systems:

curl --proto '=https' --tlsv1.2 -sSf -L https://install.determinate.systems/nix/pr/$PR_NUMBER | sh -s -- install

cole-h added 7 commits June 27, 2024 10:33
Flake lock file updates:

• Updated input 'nix':
    'https://api.flakehub.com/f/pinned/DeterminateSystems/nix/2.21.2/018ef218-45b2-731b-8c3b-a9fc57c55fd1/source.tar.gz?narHash=sha256-HNt%2BocnqVlwGzYx%2B3DQRlfv06iSv2I7Ch5kuRH7W7m4%3D' (2024-04-18)
  → 'https://api.flakehub.com/f/pinned/DeterminateSystems/nix/2.23.1/01905aba-7c85-727f-ab95-e78f10889dd3/source.tar.gz?narHash=sha256-FiQVX3mwExssB1JwqdW48cPBXJ2V%2BiXYKOtsqTkPlVw%3D' (2024-06-27)
• Updated input 'nix/nix':
    'https://api.flakehub.com/f/pinned/NixOS/nix/2.21.2/018eaedc-df49-7da8-8007-06186938ee08/source.tar.gz?narHash=sha256-ObaVDDPtnOeIE0t7m4OVk5G%2BOS6d9qYh%2BktK67Fe/zE%3D' (2024-04-03)
  → 'https://api.flakehub.com/f/pinned/NixOS/nix/2.23.1/01905a9c-511f-7df0-910f-096ac5276124/source.tar.gz?narHash=sha256-US%2BUsPhFeYoJH0ncjERRtVD1U20JtVtjsG%2BxhZqr/nY%3D' (2024-06-26)
• Added input 'nix/nix/flake-parts':
    'github:hercules-ci/flake-parts/2a55567fcf15b1b1c7ed712a2c6fadaec7412ea8?narHash=sha256-iKzJcpdXih14qYVcZ9QC9XuZYnPc6T8YImb6dX166kw%3D' (2024-06-01)
• Added input 'nix/nix/flake-parts/nixpkgs-lib':
    follows 'nix/nix/nixpkgs'
• Added input 'nix/nix/pre-commit-hooks':
    'github:cachix/pre-commit-hooks.nix/0ff4381bbb8f7a52ca4a851660fc7a437a4c6e07?narHash=sha256-F1h%2BXIsGKT9TkGO3omxDLEb/9jOOsI6NnzsXFsZhry4%3D' (2024-06-24)
• Added input 'nix/nix/pre-commit-hooks/flake-compat':
    follows 'nix/nix'
• Added input 'nix/nix/pre-commit-hooks/gitignore':
    follows 'nix/nix'
• Added input 'nix/nix/pre-commit-hooks/nixpkgs':
    follows 'nix/nix/nixpkgs'
• Added input 'nix/nix/pre-commit-hooks/nixpkgs-stable':
    follows 'nix/nix/nixpkgs'
It was removed in 2.22.0 (and its functionality folded into the flakes
feature).
As of the previous commit, we just read it from the Cargo.toml directly.
@cole-h cole-h enabled auto-merge (rebase) June 27, 2024 18:20
Copy link
Member

@colemickens colemickens left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

don't have 100% context, but it looks fine.

@cole-h cole-h disabled auto-merge June 27, 2024 18:31
@cole-h cole-h enabled auto-merge (rebase) June 27, 2024 18:31
@cole-h cole-h merged commit ae04722 into main Jun 27, 2024
16 checks passed
@cole-h cole-h deleted the update-nix branch June 27, 2024 18:36
@cole-h cole-h added this to the 0.20.0 milestone Jun 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants