Running nixpkgs-update (https://nix-community.org/update-bot/) with UPDATE_INFO: firezone-gui-client 0 -> 1 attrpath: firezone-gui-client Checking auto update branch... [version] [version] generic version rewriter does not support multiple hashes [rustCrateVersion] [rustCrateVersion] skipping because derivation has updateScript [golangModuleVersion] [golangModuleVersion] Not a buildGoModule package with vendorHash [npmDepsVersion] [npmDepsVersion] No npmDepsHash [updateScript] [updateScript] Success [updateScript] this derivation will be built: /nix/store/nkz0yj11vj4g8irnfqvkan2d8g7wm8j7-packages.json.drv building '/nix/store/nkz0yj11vj4g8irnfqvkan2d8g7wm8j7-packages.json.drv'... Going to be running update for following packages: - firezone-gui-client-1.5.1 Press Enter key to continue... Running update for: Enqueuing group of 1 packages - firezone-gui-client-1.5.1: UPDATING ... - firezone-gui-client-1.5.1: DONE. Packages updated! Diff after rewrites: diff --git a/pkgs/by-name/fi/firezone-gui-client/package.nix b/pkgs/by-name/fi/firezone-gui-client/package.nix index 4a5530b6878a..15a9b32ba260 100644 --- a/pkgs/by-name/fi/firezone-gui-client/package.nix +++ b/pkgs/by-name/fi/firezone-gui-client/package.nix @@ -27,12 +27,12 @@ copyDesktopItems, }: let - version = "1.5.1"; + version = "1.5.15"; src = fetchFromGitHub { owner = "firezone"; repo = "firezone"; tag = "gui-client-${version}"; - hash = "sha256-KozSy44Opx6cukA0QTXeMpI3fP49iyabFzPLIJckOZ4="; + hash = "sha256-cjPKu3IHaTs38Wja1BT57SoK5v4EiJRLsxtnXoUKIQo="; }; frontend = stdenvNoCC.mkDerivation rec { @@ -79,7 +79,7 @@ rustPlatform.buildRustPackage rec { pname = "firezone-gui-client"; inherit version src; - cargoHash = "sha256-TDP1Z4MeQaSER8MGnCEQfIhRsakaSCeJ7boUMBYkkI0="; + cargoHash = "sha256-IUELCciBLAygMW/5rhNwMFkYqwDompKgHwHIAy03254="; sourceRoot = "${src.name}/rust"; buildAndTestSubdir = "gui-client"; env.RUSTFLAGS = "--cfg system_certs"; No auto update branch exists Received ExitFailure 1 when running Raw command: nix-build --option sandbox true --arg config "{ allowUnfree = true; allowAliases = false; }" --arg overlays "[ ]" -A firezone-gui-client Received ExitFailure 1 when running Raw command: nix --extra-experimental-features nix-command log -f . firezone-gui-client --arg config "{ allowUnfree = true; allowAliases = false; }" --arg overlays "[ ]" Standard output: error: … while calling the 'derivationStrict' builtin at «nix-internal»/derivation-internal.nix:37:12: 36| 37| strict = derivationStrict drvAttrs; | ^ 38| … while evaluating derivation 'firezone-gui-client-1.5.15' whose name attribute is located at /var/cache/nixpkgs-update/worker/worktree/firezone-gui-client/pkgs/stdenv/generic/make-derivation.nix:651:11 … while evaluating attribute 'postPatch' of derivation 'firezone-gui-client-1.5.15' at /var/cache/nixpkgs-update/worker/worktree/firezone-gui-client/pkgs/by-name/fi/firezone-gui-client/package.nix:108:3: 107| # Required to remove profiling arguments which conflict with this builder 108| postPatch = '' | ^ 109| rm .cargo/config.toml (stack trace truncated; use '--show-trace' to show the full, detailed trace) error: Refusing to evaluate package 'pnpm-9.15.9' in /var/cache/nixpkgs-update/worker/worktree/firezone-gui-client/pkgs/development/tools/pnpm/generic.nix:164 because it is marked as insecure Known issues: - CVE-2026-48995 - CVE-2026-50014 - CVE-2026-50015 - CVE-2026-50016 - CVE-2026-50017 - CVE-2026-50573 - CVE-2026-55699 You can install it anyway by allowing this package, using the following methods: a) To temporarily allow all insecure packages, you can use an environment variable for a single invocation of the nix tools: $ export NIXPKGS_ALLOW_INSECURE=1 Note: When using `nix shell`, `nix build`, `nix develop`, etc with a flake, then pass `--impure` in order to allow use of environment variables. b) for `nixos-rebuild` you can add ‘pnpm-9.15.9’ to `nixpkgs.config.permittedInsecurePackages` in the configuration.nix, like so: { nixpkgs.config.permittedInsecurePackages = [ "pnpm-9.15.9" ]; } c) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add ‘pnpm-9.15.9’ to `permittedInsecurePackages` in ~/.config/nixpkgs/config.nix, like so: { permittedInsecurePackages = [ "pnpm-9.15.9" ]; }