Running nixpkgs-update (https://nix-community.org/update-bot/) with UPDATE_INFO: bitwarden-desktop 0 -> 1 attrpath: bitwarden-desktop Checking auto update branch... [version] [version] generic version rewriter does not support multiple hashes [rustCrateVersion] [rustCrateVersion] No cargoHash found [golangModuleVersion] [golangModuleVersion] Not a buildGoModule package with vendorHash [npmDepsVersion] [npmDepsVersion] skipping because derivation has updateScript [updateScript] [updateScript] Success [updateScript] this derivation will be built: /nix/store/plbdywfiqn7rk3y8skj22ma7yfipwapn-packages.json.drv building '/nix/store/plbdywfiqn7rk3y8skj22ma7yfipwapn-packages.json.drv'... Going to be running update for following packages: - bitwarden-desktop-2026.3.1 Press Enter key to continue... Running update for: Enqueuing group of 1 packages - bitwarden-desktop-2026.3.1: UPDATING ... - bitwarden-desktop-2026.3.1: DONE. Packages updated! Diff after rewrites: diff --git a/pkgs/by-name/bi/bitwarden-desktop/package.nix b/pkgs/by-name/bi/bitwarden-desktop/package.nix index 625f84e55eff..dec25773ddc9 100644 --- a/pkgs/by-name/bi/bitwarden-desktop/package.nix +++ b/pkgs/by-name/bi/bitwarden-desktop/package.nix @@ -33,13 +33,13 @@ let in buildNpmPackage' rec { pname = "bitwarden-desktop"; - version = "2026.3.1"; + version = "2026.5.0"; src = fetchFromGitHub { owner = "bitwarden"; repo = "clients"; rev = "desktop-v${version}"; - hash = "sha256-ecaCHk04N9h0RP8gK0o+MLgYS6Linsqi7AaC86hwQ3U="; + hash = "sha256-R00wt5W4kKmFIODEaGoUqDwfGyHH/2PpiRaC8Gq3d88="; }; patches = [ @@ -85,7 +85,7 @@ buildNpmPackage' rec { npmWorkspace = "apps/desktop"; npmDepsFetcherVersion = 2; - npmDepsHash = "sha256-1t4CSd1NDC1medTTFHSzX9ZkgHqPG2L//yjaloH47z0="; + npmDepsHash = "sha256-xmb3zwE8/nWpRlUOgTz2UhNRaUA8KW9sHQHA97pjjfg="; cargoDeps = rustPlatform.fetchCargoVendor { inherit @@ -95,7 +95,7 @@ buildNpmPackage' rec { cargoRoot patches ; - hash = "sha256-d9Iv7OekHOteH1lyAuyj/EzfU/KSCW6ATx83foOW3IE="; + hash = "sha256-phvk4t1JKfSYGzm/vm1rT8A0fACHJF/C0WiZ2Lk3cV0="; }; cargoRoot = "apps/desktop/desktop_native"; An auto update branch exists with message `bitwarden-desktop: 2026.3.1 -> 2026.4.0`. New version is 2026.5.0. The auto update branch does not match or exceed the new version. Old version 2026.3.1" not present in master derivation file with contents: { lib, buildNpmPackage, cargo, copyDesktopItems, dart-sass, darwin, electron_39, fetchFromGitHub, gnome-keyring, jq, llvmPackages_18, makeDesktopItem, makeWrapper, nix-update-script, nodejs_22, pkg-config, rustc, rustPlatform, stdenv, xcbuild, }: let description = "Secure and free password manager for all of your devices"; icon = "bitwarden"; electron = electron_39; # argon2 npm dependency is using `std::basic_string`, which is no longer allowed in LLVM 19 buildNpmPackage' = buildNpmPackage.override { stdenv = if stdenv.hostPlatform.isDarwin then llvmPackages_18.stdenv else stdenv; }; in buildNpmPackage' rec { pname = "bitwarden-desktop"; version = "2026.5.0"; src = fetchFromGitHub { owner = "bitwarden"; repo = "clients"; rev = "desktop-v${version}"; hash = "sha256-R00wt5W4kKmFIODEaGoUqDwfGyHH/2PpiRaC8Gq3d88="; }; patches = [ ./electron-builder-package-lock.patch ./dont-auto-setup-biometrics.patch # ensures `app.getPath("exe")` returns our wrapper, not ${electron}/bin/electron ./set-exe-path.patch # ensure that the desktop proxy is correctly located in libexec ./set-desktop-proxy-path.patch # on linux: don't flip fuses, don't create wrapper script, on darwin: don't try copying safari extensions, don't try re-signing app ./skip-afterpack-and-aftersign.patch ]; postPatch = '' # https://github.com/bitwarden/clients/pull/20480 substituteInPlace package-lock.json apps/desktop/desktop_native/napi/package.json \ --replace-fail '"@napi-rs/cli": "3.5.1"' '"@napi-rs/cli": "3.2.0"' # remove code under unfree license rm -r bitwarden_license substituteInPlace apps/desktop/src/main.ts --replace-fail '%%exePath%%' "$out/bin/bitwarden" substituteInPlace apps/desktop/src/main/native-messaging.main.ts \ --replace-fail '%%desktopProxyPath%%' "$out/libexec/desktop_proxy" # force canUpdate to false # will open releases page instead of trying to update files substituteInPlace apps/desktop/src/main/updater.main.ts \ --replace-fail 'this.canUpdate =' 'this.canUpdate = false; let _dummy =' # unneeded for desktop, and causes errors rm -r apps/cli ''; nodejs = nodejs_22; makeCacheWritable = true; npmFlags = [ "--engine-strict" "--legacy-peer-deps" ]; npmWorkspace = "apps/desktop"; npmDepsFetcherVersion = 2; npmDepsHash = "sha256-xmb3zwE8/nWpRlUOgTz2UhNRaUA8KW9sHQHA97pjjfg="; cargoDeps = rustPlatform.fetchCargoVendor { inherit pname version src cargoRoot patches ; hash = "sha256-phvk4t1JKfSYGzm/vm1rT8A0fACHJF/C0WiZ2Lk3cV0="; }; cargoRoot = "apps/desktop/desktop_native"; env.ELECTRON_SKIP_BINARY_DOWNLOAD = "1"; # make electron-builder not attempt to codesign the app on darwin env.CSC_IDENTITY_AUTO_DISCOVERY = "false"; nativeBuildInputs = [ cargo dart-sass jq makeWrapper pkg-config rustc rustPlatform.cargoCheckHook rustPlatform.cargoSetupHook ] ++ lib.optionals stdenv.hostPlatform.isLinux [ copyDesktopItems ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ xcbuild darwin.autoSignDarwinBinariesHook ]; preBuild = '' if [[ $(jq --raw-output '.devDependencies.electron' < package.json | grep -E --only-matching '^[0-9]+') != ${lib.escapeShellArg (lib.versions.major electron.version)} ]]; then echo 'ERROR: electron version mismatch' exit 1 fi # force our dart-sass executable echo "export const compilerCommand = ['dart-sass'];" > node_modules/sass-embedded/dist/lib/src/compiler-path.js # needed so that the napi executable actually is usable patchShebangs apps/desktop/node_modules pushd apps/desktop/desktop_native/napi npm run build -- --release popd pushd apps/desktop/desktop_native/proxy cargo build --bin desktop_proxy --release -j $NIX_BUILD_CORES --offline popd ''; postBuild = '' pushd apps/desktop # electron-dist needs to be writable on darwin or when using fuses cp -r ${electron.dist} electron-dist chmod -R u+w electron-dist npm exec electron-builder -- \ --dir \ -c.electronDist=electron-dist \ -c.electronVersion=${electron.version} popd ''; # there seem to be issues with missing libs on darwin when running tests doCheck = !stdenv.hostPlatform.isDarwin; nativeCheckInputs = lib.optionals stdenv.hostPlatform.isLinux [ (gnome-keyring.override { useWrappedDaemon = false; }) ]; checkFlags = [ # fails in zbus "--skip=password::password::tests::test" # requires some debug feature to be enabled "--skip=storage::serialization::tests::test_keydata_from_corrupted_bytes" "--skip=storage::serialization::tests::test_keydata_from_empty_bytes" ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ "--skip=clipboard::tests::test_write_read" ]; preCheck = '' pushd ${cargoRoot} cargoCheckType=release HOME=$(mktemp -d) ''; postCheck = '' popd ''; installPhase = '' runHook preInstall install -Dm755 -t $out/libexec apps/desktop/desktop_native/target/release/desktop_proxy '' + lib.optionalString stdenv.hostPlatform.isDarwin '' mkdir -p $out/Applications cp -r apps/desktop/dist/mac*/Bitwarden.app $out/Applications makeWrapper $out/Applications/Bitwarden.app/Contents/MacOS/Bitwarden $out/bin/bitwarden '' + lib.optionalString stdenv.hostPlatform.isLinux '' mkdir -p $out/opt/Bitwarden cp -r apps/desktop/dist/linux-*unpacked/{locales,resources{,.pak}} $out/opt/Bitwarden makeWrapper '${lib.getExe electron}' "$out/bin/bitwarden" \ --run "ulimit -c 0" \ --add-flags $out/opt/Bitwarden/resources/app.asar \ --add-flags "\''${NIXOS_OZONE_WL:+\''${WAYLAND_DISPLAY:+--ozone-platform-hint=auto --enable-features=WaylandWindowDecorations --enable-wayland-ime=true}}" \ --set-default ELECTRON_IS_DEV 0 \ --inherit-argv0 # Extract the polkit policy file from the multiline string in the source code. # This may break in the future but its better than copy-pasting it manually. mkdir -p $out/share/polkit-1/actions/ pushd apps/desktop/src/key-management/biometrics awk '/const polkitPolicy = `/{gsub(/^.*`/, ""); print; str=1; next} str{if (/`;/) str=0; gsub(/`;/, ""); print}' os-biometrics-linux.service.ts > $out/share/polkit-1/actions/com.bitwarden.Bitwarden.policy popd pushd apps/desktop/resources/icons for icon in *.png; do dir=$out/share/icons/hicolor/"''${icon%.png}"/apps mkdir -p "$dir" cp "$icon" "$dir"/${icon}.png done popd '' + '' runHook postInstall ''; desktopItems = [ (makeDesktopItem { name = "bitwarden"; exec = "bitwarden %U"; inherit icon; comment = description; desktopName = "Bitwarden"; categories = [ "Utility" ]; mimeTypes = [ "x-scheme-handler/bitwarden" ]; }) ]; passthru = { updateScript = nix-update-script { extraArgs = [ "--version=stable" "--version-regex=^desktop-v(.*)$" ]; }; }; meta = { changelog = "https://github.com/bitwarden/clients/releases/tag/${src.rev}"; inherit description; homepage = "https://bitwarden.com"; license = lib.licenses.gpl3; maintainers = with lib.maintainers; [ amarshall ]; platforms = [ "x86_64-linux" "aarch64-linux" "x86_64-darwin" "aarch64-darwin" ]; mainProgram = "bitwarden"; }; }