Running nixpkgs-update (https://nix-community.org/update-bot/) with UPDATE_INFO: checkov 3.3.9 -> 3.3.15 https://github.com/bridgecrewio/checkov/releases attrpath: checkov Checking auto update branch... [version] [version] generic version rewriter does not support multiple hashes [rustCrateVersion] [rustCrateVersion] No cargoHash found [golangModuleVersion] [golangModuleVersion] Not a buildGoModule package with vendorHash [npmDepsVersion] [npmDepsVersion] No npmDepsHash [updateScript] [updateScript] Success [updateScript] this derivation will be built: /nix/store/ck4azjp5mgvfv55y76js3n0c42mhp8jd-packages.json.drv building '/nix/store/ck4azjp5mgvfv55y76js3n0c42mhp8jd-packages.json.drv'... Going to be running update for following packages: - checkov-3.3.9 Press Enter key to continue... Running update for: Enqueuing group of 1 packages - checkov-3.3.9: UPDATING ... - checkov-3.3.9: DONE. Packages updated! Diff after rewrites: diff --git a/pkgs/by-name/ch/checkov/package.nix b/pkgs/by-name/ch/checkov/package.nix index d359fb3b638a..ecbd89e37e8e 100644 --- a/pkgs/by-name/ch/checkov/package.nix +++ b/pkgs/by-name/ch/checkov/package.nix @@ -35,14 +35,14 @@ let in python3.pkgs.buildPythonApplication (finalAttrs: { pname = "checkov"; - version = "3.3.9"; + version = "3.3.15"; pyproject = true; src = fetchFromGitHub { owner = "bridgecrewio"; repo = "checkov"; tag = finalAttrs.version; - hash = "sha256-XbfuMOXpG1sQgqiq42kJB3zmcKrBGhgLaopvSV0fFVY="; + hash = "sha256-OAr4/ir9Yc87j9/27C3nbNC4bkYX5SBm5+qTFD78f1U="; }; pythonRelaxDeps = [ No auto update branch exists Received ExitFailure 1 when running Raw command: nix-build --option sandbox true --arg config "{ allowUnfree = true; allowAliases = false; }" --arg overlays "[ ]" -A checkov Received ExitFailure 1 when running Raw command: nix --extra-experimental-features nix-command log -f . checkov --arg config "{ allowUnfree = true; allowAliases = false; }" --arg overlays "[ ]" Standard output: error: … while evaluating the attribute 'drvPath' at /var/cache/nixpkgs-update/worker/worktree/checkov/lib/customisation.nix:416:11: 415| // { 416| drvPath = | ^ 417| assert condition; … while calling the 'derivationStrict' builtin at «nix-internal»/derivation-internal.nix:37:12: 36| 37| strict = derivationStrict drvAttrs; | ^ 38| (stack trace truncated; use '--show-trace' to show the full, detailed trace) error: Refusing to evaluate package 'python3.14-ecdsa-0.19.2' in /var/cache/nixpkgs-update/worker/worktree/checkov/pkgs/development/python-modules/ecdsa/default.nix:50 because it is marked as insecure Known issues: - CVE-2024-23342 You can install it anyway by allowing this package, using the following methods: a) To temporarily allow all insecure packages, you can use an environment variable for a single invocation of the nix tools: $ export NIXPKGS_ALLOW_INSECURE=1 Note: When using `nix shell`, `nix build`, `nix develop`, etc with a flake, then pass `--impure` in order to allow use of environment variables. b) for `nixos-rebuild` you can add ‘python3.14-ecdsa-0.19.2’ to `nixpkgs.config.permittedInsecurePackages` in the configuration.nix, like so: { nixpkgs.config.permittedInsecurePackages = [ "python3.14-ecdsa-0.19.2" ]; } c) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add ‘python3.14-ecdsa-0.19.2’ to `permittedInsecurePackages` in ~/.config/nixpkgs/config.nix, like so: { permittedInsecurePackages = [ "python3.14-ecdsa-0.19.2" ]; }