Running nixpkgs-update (https://nix-community.org/update-bot/) with UPDATE_INFO: clipgrab 3.9.7 -> 3.9.16 https://repology.org/project/clipgrab/versions attrpath: clipgrab Checking auto update branch... No auto update branch exists [version] stderr did not split as expected full stderr was: warning: ignoring the client-specified setting 'sandbox', because it is a restricted setting and you are not a trusted user this derivation will be built: /nix/store/93y01lh4xz0y5ppsb7b5zmrkfb276cik-clipgrab-3.9.16.tar.gz.drv building '/nix/store/93y01lh4xz0y5ppsb7b5zmrkfb276cik-clipgrab-3.9.16.tar.gz.drv'... structuredAttrs is enabled trying https://download.clipgrab.org/clipgrab-3.9.16.tar.gz % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 curl: (22) The requested URL returned error: 404 Warning: Problem (retrying all errors). Will retry in 1 second. 3 retries left. 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 curl: (22) The requested URL returned error: 404 Warning: Problem (retrying all errors). Will retry in 2 seconds. 2 retries Warning: left. 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 curl: (22) The requested URL returned error: 404 Warning: Problem (retrying all errors). Will retry in 4 seconds. 1 retry left. 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 curl: (22) The requested URL returned error: 404 error: cannot download clipgrab-3.9.16.tar.gz from any mirror error: Cannot build '/nix/store/93y01lh4xz0y5ppsb7b5zmrkfb276cik-clipgrab-3.9.16.tar.gz.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/abyg20whjic3n4zfk9m3m934cflqyrhi-clipgrab-3.9.16.tar.gz Last 18 log lines: > structuredAttrs is enabled > > trying https://download.clipgrab.org/clipgrab-3.9.16.tar.gz > % Total % Received % Xferd Average Speed Time Time Time Current > Dload Upload Total Spent Left Speed > 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 > curl: (22) The requested URL returned error: 404 > Warning: Problem (retrying all errors). Will retry in 1 second. 3 retries left. > 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 > curl: (22) The requested URL returned error: 404 > Warning: Problem (retrying all errors). Will retry in 2 seconds. 2 retries > Warning: left. > 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 > curl: (22) The requested URL returned error: 404 > Warning: Problem (retrying all errors). Will retry in 4 seconds. 1 retry left. > 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 > curl: (22) The requested URL returned error: 404 > error: cannot download clipgrab-3.9.16.tar.gz from any mirror For full logs, run: nix log /nix/store/93y01lh4xz0y5ppsb7b5zmrkfb276cik-clipgrab-3.9.16.tar.gz.drv stderr did not split as expected full stderr was: warning: ignoring the client-specified setting 'sandbox', because it is a restricted setting and you are not a trusted user error: attribute 'originalSrc' in selection path 'clipgrab.originalSrc' not found stderr did not split as expected full stderr was: warning: ignoring the client-specified setting 'sandbox', because it is a restricted setting and you are not a trusted user error: … while calling the 'derivationStrict' builtin at :37:12: 36| 37| strict = derivationStrict drvAttrs; | ^ 38| … while evaluating derivation 'clipgrab-3.9.16' whose name attribute is located at /var/cache/nixpkgs-update/worker/worktree/clipgrab/pkgs/stdenv/generic/make-derivation.nix:541:13 … while evaluating attribute 'buildInputs' of derivation 'clipgrab-3.9.16' at /var/cache/nixpkgs-update/worker/worktree/clipgrab/pkgs/stdenv/generic/make-derivation.nix:593:13: 592| depsHostHost = elemAt (elemAt dependencies 1) 0; 593| buildInputs = elemAt (elemAt dependencies 1) 1; | ^ 594| depsTargetTarget = elemAt (elemAt dependencies 2) 0; (stack trace truncated; use '--show-trace' to show the full, detailed trace) error: Package ‘qtwebengine-5.15.19’ in /var/cache/nixpkgs-update/worker/worktree/clipgrab/pkgs/development/libraries/qt-5/modules/qtwebengine.nix:442 is marked as insecure, refusing to evaluate. Known issues: - qt5 qtwebengine is unmaintained upstream since april 2025. It is based on chromium 87.0.4280.144, and supposedly patched up to 135.0.7049.95 which is outdated. Security issues are frequently discovered in chromium. The following list of CVEs was fixed in the life cycle of chromium 138 and likely also affects qtwebengine: - CVE-2025-8879 - CVE-2025-8880 - CVE-2025-8901 - CVE-2025-8881 - CVE-2025-8882 - CVE-2025-8576 - CVE-2025-8577 - CVE-2025-8578 - CVE-2025-8579 - CVE-2025-8580 - CVE-2025-8581 - CVE-2025-8582 - CVE-2025-8583 - CVE-2025-8292 - CVE-2025-8010 - CVE-2025-8011 - CVE-2025-7656 - CVE-2025-6558 (known to be exploited in the wild) - CVE-2025-7657 - CVE-2025-6554 - CVE-2025-6555 - CVE-2025-6556 - CVE-2025-6557 The actual list of CVEs affecting qtwebengine is likely much longer, as this list is missing issues fixed in chromium 136/137 and even more issues are continuously discovered and lack upstream fixes in qtwebengine. You can install it anyway by allowing this package, using the following methods: a) To temporarily allow all insecure packages, you can use an environment variable for a single invocation of the nix tools: $ export NIXPKGS_ALLOW_INSECURE=1 Note: When using `nix shell`, `nix build`, `nix develop`, etc with a flake, then pass `--impure` in order to allow use of environment variables. b) for `nixos-rebuild` you can add ‘qtwebengine-5.15.19’ to `nixpkgs.config.permittedInsecurePackages` in the configuration.nix, like so: { nixpkgs.config.permittedInsecurePackages = [ "qtwebengine-5.15.19" ]; } c) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add ‘qtwebengine-5.15.19’ to `permittedInsecurePackages` in ~/.config/nixpkgs/config.nix, like so: { permittedInsecurePackages = [ "qtwebengine-5.15.19" ]; }