Running nixpkgs-update (https://nix-community.org/update-bot/) with UPDATE_INFO: azure-cli-extensions.confcom 0 -> 1 attrpath: azure-cli-extensions.confcom Checking auto update branch... [version] [version] generic version rewriter does not support multiple hashes [rustCrateVersion] [rustCrateVersion] No cargoHash found [golangModuleVersion] [golangModuleVersion] Not a buildGoModule package with vendorHash [npmDepsVersion] [npmDepsVersion] No npmDepsHash [updateScript] [updateScript] Success [updateScript] this derivation will be built: /nix/store/xkn4cg6sd8jjld5g0wknb9z0avqkq5kp-packages.json.drv building '/nix/store/xkn4cg6sd8jjld5g0wknb9z0avqkq5kp-packages.json.drv'... Going to be running update for following packages: - python3.13-confcom-1.2.6 Press Enter key to continue... Running update for: Enqueuing group of 1 packages - python3.13-confcom-1.2.6: UPDATING ... - python3.13-confcom-1.2.6: DONE. Packages updated! Diff after rewrites: diff --git a/pkgs/by-name/az/azure-cli/extensions-manual.nix b/pkgs/by-name/az/azure-cli/extensions-manual.nix index 84f7ec3ae088..b8be1f927571 100644 --- a/pkgs/by-name/az/azure-cli/extensions-manual.nix +++ b/pkgs/by-name/az/azure-cli/extensions-manual.nix @@ -173,9 +173,9 @@ confcom = mkAzExtension rec { pname = "confcom"; - version = "1.2.6"; + version = "1.5.0"; url = "https://azcliprod.blob.core.windows.net/cli-extensions/confcom-${version}-py3-none-any.whl"; - hash = "sha256-kyJ4AkPcpP/10nf4whJiuraC7hn0E6iBkhRIn43E9J0="; + hash = "sha256-b+NRDdjT/tZNDtKTG30/O1jrob/l0estNRDzQNVMXtM="; description = "Microsoft Azure Command-Line Tools Confidential Container Security Policy Generator Extension"; nativeBuildInputs = [ autoPatchelfHook ]; buildInputs = [ openssl_1_1 ]; No auto update branch exists Received ExitFailure 1 when running Raw command: nix-build --option sandbox true --arg config "{ allowUnfree = true; allowAliases = false; }" --arg overlays "[ ]" -A azure-cli-extensions.confcom Received ExitFailure 1 when running Raw command: nix --extra-experimental-features nix-command log -f . azure-cli-extensions.confcom --arg config "{ allowUnfree = true; allowAliases = false; }" --arg overlays "[ ]" Standard output: error: … while evaluating the attribute 'drvPath' at /var/cache/nixpkgs-update/worker/worktree/azure-cli-extensions.confcom/lib/customisation.nix:446:7: 445| // { 446| drvPath = | ^ 447| assert condition; … while calling the 'derivationStrict' builtin at :37:12: 36| 37| strict = derivationStrict drvAttrs; | ^ 38| (stack trace truncated; use '--show-trace' to show the full, detailed trace) error: Package ‘openssl-1.1.1w’ in /var/cache/nixpkgs-update/worker/worktree/azure-cli-extensions.confcom/pkgs/development/libraries/openssl/default.nix:384 is marked as insecure, refusing to evaluate. Known issues: - OpenSSL 1.1 is reaching its end of life on 2023/09/11 and cannot be supported through the NixOS 23.11 release cycle. https://www.openssl.org/blog/blog/2023/03/28/1.1.1-EOL/ You can install it anyway by allowing this package, using the following methods: a) To temporarily allow all insecure packages, you can use an environment variable for a single invocation of the nix tools: $ export NIXPKGS_ALLOW_INSECURE=1 Note: When using `nix shell`, `nix build`, `nix develop`, etc with a flake, then pass `--impure` in order to allow use of environment variables. b) for `nixos-rebuild` you can add ‘openssl-1.1.1w’ to `nixpkgs.config.permittedInsecurePackages` in the configuration.nix, like so: { nixpkgs.config.permittedInsecurePackages = [ "openssl-1.1.1w" ]; } c) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add ‘openssl-1.1.1w’ to `permittedInsecurePackages` in ~/.config/nixpkgs/config.nix, like so: { permittedInsecurePackages = [ "openssl-1.1.1w" ]; }