Skip to content

flake.lock: Update#50

Merged
e1mo merged 3 commits intomainfrom
flake-update
Apr 7, 2025
Merged

flake.lock: Update#50
e1mo merged 3 commits intomainfrom
flake-update

Conversation

@e1mo
Copy link
Copy Markdown
Member

@e1mo e1mo commented Mar 28, 2025

pysaml2 is broken due to changes pyopenssl: NixOS/nixpkgs#367976
Since we use SAML for authentication, we are not able to update matrix synapse. In order to be able to do that, this PR uses a patch for pysaml2 that switches to cryptography: IdentityPython/pysaml2#977

The PR has not been reviewed by upstream, so there is a chance of something being not right. However, the tests pass. However, given that this allows us to update matrix synapse (which has had fixes for very real CVEs in a recent release). Thus this seems like a decent tradeoff.

Flake lock file updates:

• Updated input 'flake-utils':
    'github:numtide/flake-utils/c1dfcf08411b08f6b8615f7d8971a2bfa81d5e8a' (2024-09-17)
  → 'github:numtide/flake-utils/11707dc2f618dd54ca8739b309ec4fc024de578b' (2024-11-13)
• Updated input 'freescout-nix':
    'gitlab:e1mo/freescout-nix-flake/7e35a8d1f507ea3d6b6be54edc3a83f48f3dd140' (2024-05-11)
  → 'gitlab:e1mo/freescout-nix-flake/2019d91ac06a3581143d4ae2d54643bc7fa0cc7a' (2025-03-09)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/f6f24b0bbb0461887719d10c77c9fe81e7bea37d' (2024-10-08)
  → 'github:NixOS/nixpkgs/360e0a6013f94d32ea86050d3646e3ccba1c2667' (2025-03-28)
• Updated input 'sops-nix':
    'github:Mic92/sops-nix/06535d0e3d0201e6a8080dd32dbfde339b94f01b' (2024-10-08)
  → 'github:Mic92/sops-nix/67566fe68a8bed2a7b1175fdfb0697ed22ae8852' (2025-03-23)
• Removed input 'sops-nix/nixpkgs-stable'

@Proliecan
Copy link
Copy Markdown
Member

Thanks for taking care of this @e1mo !
Sadly I don't feel qualified to comment on the subject, but it's great people like you keep us running! 🥇

@e1mo e1mo marked this pull request as ready for review April 5, 2025 06:20
@e1mo e1mo requested a review from a team as a code owner April 5, 2025 06:20
@e1mo e1mo requested review from gametabe and ruru4143 April 5, 2025 06:20
e1mo added 3 commits April 5, 2025 14:43
Flake lock file updates:

• Updated input 'flake-utils':
    'github:numtide/flake-utils/c1dfcf08411b08f6b8615f7d8971a2bfa81d5e8a' (2024-09-17)
  → 'github:numtide/flake-utils/11707dc2f618dd54ca8739b309ec4fc024de578b' (2024-11-13)
• Updated input 'freescout-nix':
    'gitlab:e1mo/freescout-nix-flake/7e35a8d1f507ea3d6b6be54edc3a83f48f3dd140' (2024-05-11)
  → 'gitlab:e1mo/freescout-nix-flake/2b5bcee06a673c13c5b5a62b4f4dd1300ce85903' (2025-04-05)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/f6f24b0bbb0461887719d10c77c9fe81e7bea37d' (2024-10-08)
  → 'github:NixOS/nixpkgs/250b695f41e0e2f5afbf15c6b12480de1fe0001b' (2025-04-05)
• Updated input 'sops-nix':
    'github:Mic92/sops-nix/06535d0e3d0201e6a8080dd32dbfde339b94f01b' (2024-10-08)
  → 'github:Mic92/sops-nix/cff8437c5fe8c68fc3a840a21bf1f4dc801da40d' (2025-04-04)
• Removed input 'sops-nix/nixpkgs-stable'
Apply the patch from the PR that replaces pyopenssl with cryptography.
The PR has not been reviewed by upstream, so there is a chance of
something being not right. However, the tests pass. So it should
probably be allright?

(And in turn we can finally update matrix and the rest of our services
and close some very real CVEs)
@e1mo e1mo merged commit 8eb0222 into main Apr 7, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants