Running nixpkgs-update (https://nix-community.org/update-bot/) with UPDATE_INFO: djv 3.1.1 -> 3.4.2 https://github.com/darbyjohnston/djv/releases attrpath: djv Checking auto update branch... No auto update branch exists [version] [version] updated version and sha256 [rustCrateVersion] [rustCrateVersion] No cargoHash found [golangModuleVersion] [golangModuleVersion] Not a buildGoModule package with vendorHash [npmDepsVersion] [npmDepsVersion] No npmDepsHash [updateScript] [updateScript] skipping because derivation has no updateScript Diff after rewrites: diff --git a/pkgs/by-name/dj/djv/package.nix b/pkgs/by-name/dj/djv/package.nix index e7f2da7adcc9..40dc1511f20a 100644 --- a/pkgs/by-name/dj/djv/package.nix +++ b/pkgs/by-name/dj/djv/package.nix @@ -32,13 +32,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "djv"; - version = "3.1.1"; + version = "3.4.2"; src = fetchFromGitHub { owner = "darbyjohnston"; repo = "djv"; tag = finalAttrs.version; - hash = "sha256-/SakJ23mi/dz8eUt2UtcgfLtFZiCHy1ME+jWdNS8+Fw="; + hash = "sha256-QVWT0HDzwt1koM0h7//2+xsSt6+qJ3y6uAQb2Cv/Zks="; }; postPatch = '' Received ExitFailure 1 when running Raw command: nix-build --option sandbox true --arg config "{ allowUnfree = true; allowAliases = false; }" --arg overlays "[ ]" -A djv Received ExitFailure 1 when running Raw command: nix --extra-experimental-features nix-command log -f . djv --arg config "{ allowUnfree = true; allowAliases = false; }" --arg overlays "[ ]" Standard output: error: … while calling the 'derivationStrict' builtin at «nix-internal»/derivation-internal.nix:37:12: 36| 37| strict = derivationStrict drvAttrs; | ^ 38| … while evaluating derivation 'djv-3.4.2' whose name attribute is located at /var/cache/nixpkgs-update/worker/worktree/djv/pkgs/stdenv/generic/make-derivation.nix:535:11 … while evaluating attribute 'buildInputs' of derivation 'djv-3.4.2' at /var/cache/nixpkgs-update/worker/worktree/djv/pkgs/stdenv/generic/make-derivation.nix:587:11: 586| depsHostHost = hostHostOutputs; 587| buildInputs = hostTargetOutputs; | ^ 588| depsTargetTarget = targetTargetOutputs; (stack trace truncated; use '--show-trace' to show the full, detailed trace) error: Refusing to evaluate package 'openexr-2.5.10' in /var/cache/nixpkgs-update/worker/worktree/djv/pkgs/development/libraries/openexr/2.nix:83 because it is marked as insecure Known issues: - CVE-2021-3598: ImfDeepScanLineInputFile Out-of-Bounds Read - CVE-2021-3605: rleUncompress Out-of-Bounds Read - CVE-2021-3933: Integer Overflow Vulnerability in File Processing on 32-bit Systems - CVE-2021-23169: copyIntoFrameBuffer Heap Buffer Overflow Leading to Arbitrary Code Execution - CVE-2021-23215: DwaCompressor Integer Overflow Leads to Heap Buffer Overflow - CVE-2021-26260: DwaCompressor Integer Overflow Leading to Heap Buffer Overflow - CVE-2021-26945: Integer Overflow Leading to Heap Buffer Overflow - CVE-2023-5841: Heap Overflow in Scanline Deep Data Parsing - CVE-2024-31047: convert Function Denial of Service - CVE-2025-12495: EXR File Parsing Heap-based Buffer Overflow Remote Code Execution - CVE-2025-12839: EXR File Parsing Heap-based Buffer Overflow Remote Code Execution - CVE-2025-12840: EXR File Parsing Heap-based Buffer Overflow Remote Code Execution - CVE-2026-27622: CompositeDeepScanLine integer-overflow leads to heap OOB write You can install it anyway by allowing this package, using the following methods: a) To temporarily allow all insecure packages, you can use an environment variable for a single invocation of the nix tools: $ export NIXPKGS_ALLOW_INSECURE=1 Note: When using `nix shell`, `nix build`, `nix develop`, etc with a flake, then pass `--impure` in order to allow use of environment variables. b) for `nixos-rebuild` you can add ‘openexr-2.5.10’ to `nixpkgs.config.permittedInsecurePackages` in the configuration.nix, like so: { nixpkgs.config.permittedInsecurePackages = [ "openexr-2.5.10" ]; } c) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add ‘openexr-2.5.10’ to `permittedInsecurePackages` in ~/.config/nixpkgs/config.nix, like so: { permittedInsecurePackages = [ "openexr-2.5.10" ]; }