Running nixpkgs-update (https://nix-community.org/update-bot/) with UPDATE_INFO: cacert 0 -> 1
attrpath: cacert
Checking auto update branch...
[version]
[version] skipping because derivation has updateScript
[rustCrateVersion]
[rustCrateVersion] No cargoHash found
[golangModuleVersion]
[golangModuleVersion] Not a buildGoModule package with vendorHash
[npmDepsVersion]
[npmDepsVersion] No npmDepsHash
[updateScript]
[updateScript] Success
[updateScript] this derivation will be built:
/nix/store/y1846ljlvzarm323wj3gdjpbgnpkwfc6-packages.json.drv
building '/nix/store/y1846ljlvzarm323wj3gdjpbgnpkwfc6-packages.json.drv'...
Going to be running update for following packages:
- nss-cacert-3.117
Press Enter key to continue...
Running update for:
Enqueuing group of 1 packages
- nss-cacert-3.117: UPDATING ...
- nss-cacert-3.117: DONE.
Packages updated!
Diff after rewrites:
diff --git a/pkgs/by-name/ca/cacert/package.nix b/pkgs/by-name/ca/cacert/package.nix
index e92080542def..ccfb2b777d96 100644
--- a/pkgs/by-name/ca/cacert/package.nix
+++ b/pkgs/by-name/ca/cacert/package.nix
@@ -23,7 +23,7 @@ let
lib.concatStringsSep "\n\n" extraCertificateStrings
);
- srcVersion = "3.117";
+ srcVersion = "3.119.1";
version = if nssOverride != null then nssOverride.version else srcVersion;
meta = {
homepage = "https://curl.haxx.se/docs/caextract.html";
@@ -47,7 +47,7 @@ let
owner = "nss-dev";
repo = "nss";
rev = "NSS_${lib.replaceStrings [ "." ] [ "_" ] version}_RTM";
- hash = "sha256-sAs0TiV3TK/WtgHvEjl2KFAgebyWZYmcRcmxjpn2AME=";
+ hash = "sha256-GxLTqHcVWGiFezcwdctXJ8k9wqizVJPHyLBPZzphLro=";
};
dontBuild = true;
No auto update branch exists
Successfully finished processing
Automatic update generated by [nixpkgs-update](https://github.com/nix-community/nixpkgs-update) tools. This update was made based on information from passthru.updateScript.
meta.description for cacert is: Bundle of X.509 certificates of public Certificate Authorities (CA)
meta.homepage for cacert is: https://curl.haxx.se/docs/caextract.html
###### Updates performed
- Ran passthru.UpdateScript
###### To inspect upstream changes
###### Impact
Checks done
---
- built on NixOS
- The tests defined in `passthru.tests`, if any, passed
- found 3.119.1 in filename of file in /nix/store/vmy0pxnjxcywnfxad672mkl80kwh96n9-nss-cacert-3.119.1
---
Rebuild report (if merged into master) (click to expand)
```
42783 total rebuild path(s)
42783 package rebuild(s)
First fifty rebuilds by attrpath
ArchiSteamFarm
CuboCore.coreaction
CuboCore.corearchiver
CuboCore.corefm
CuboCore.coregarage
CuboCore.corehunt
CuboCore.coreimage
CuboCore.coreinfo
CuboCore.corekeyboard
CuboCore.corepad
CuboCore.corepaint
CuboCore.corepdf
CuboCore.corepins
CuboCore.corerenamer
CuboCore.coreshot
CuboCore.corestats
CuboCore.corestuff
CuboCore.coreterminal
CuboCore.coretime
CuboCore.coretoppings
CuboCore.coreuniverse
CuboCore.libcprime
CuboCore.libcsys
DisnixWebService
Fabric
LycheeSlicer
MMA
OVMF
OVMF-cloud-hypervisor
OVMFFull
R
SDL
SDL2
SDL2_Pango
SDL2_gfx
SDL2_image
SDL2_mixer
SDL2_net
SDL2_sound
SDL2_ttf
SDL_Pango
SDL_audiolib
SDL_compat
SDL_gfx
SDL_image
SDL_mixer
SDL_net
SDL_sound
SDL_stretch
```
Instructions to test this update (click to expand)
---
Either **download from the cache**:
```
nix-store -r /nix/store/vmy0pxnjxcywnfxad672mkl80kwh96n9-nss-cacert-3.119.1 \
--option binary-caches 'https://cache.nixos.org/ https://nixpkgs-update-cache.nix-community.org/' \
--option trusted-public-keys '
nixpkgs-update-cache.nix-community.org-1:U8d6wiQecHUPJFSqHN9GSSmNkmdiFW7GW7WNAnHW0SM=
cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=
'
```
(The nixpkgs-update cache is only trusted for this store-path realization.)
For the cached download to work, your user must be in the `trusted-users` list or you can use `sudo` since root is effectively trusted.
Or, **build yourself**:
```
nix-build -A cacert https://github.com/r-ryantm/nixpkgs/archive/30ddbcaf2f4f51d4676e5cd644a3e088e5f6a57e.tar.gz
```
Or:
```
nix build github:r-ryantm/nixpkgs/30ddbcaf2f4f51d4676e5cd644a3e088e5f6a57e#cacert
```
After you've downloaded or built it, look at the files and if there are any, run the binaries:
```
ls -la /nix/store/vmy0pxnjxcywnfxad672mkl80kwh96n9-nss-cacert-3.119.1
ls -la /nix/store/vmy0pxnjxcywnfxad672mkl80kwh96n9-nss-cacert-3.119.1/bin
```
---
### Pre-merge build results
Nixpkgs review skipped
---
###### Maintainer pings
cc @fpletz @lukegb for [testing](https://github.com/nix-community/nixpkgs-update/blob/main/doc/nixpkgs-maintainer-faq.md#r-ryantm-opened-a-pr-for-my-package-what-do-i-do).
> [!TIP]
> As a maintainer, if your package is located under `pkgs/by-name/*`, you can comment **`@NixOS/nixpkgs-merge-bot merge`** to automatically merge this update using the [`nixpkgs-merge-bot`](https://github.com/NixOS/nixpkgs/blob/master/ci/README.md#nixpkgs-merge-bot).
---
Add a :+1: [reaction] to [pull requests you find important].
[reaction]: https://github.blog/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/
[pull requests you find important]: https://github.com/NixOS/nixpkgs/pulls?q=is%3Aopen+sort%3Areactions-%2B1-desc
https://api.github.com/repos/NixOS/nixpkgs/pulls/476646