!FBuJyWXTGcGtHTPphC:nixos.org

Nix Rust

679 Members
Rust154 Servers

Load older messages


SenderMessageTime
25 Mar 2025
@emilazy:matrix.orgemilywe already removed tons of packages for that12:43:10
@emilazy:matrix.orgemilyare the remaining ones that important?12:43:20
@emilazy:matrix.orgemilykubernix looks like something that probably won't even work any more and that is likely using ancient/insecure versions if it does12:44:25
@tomasajt:matrix.orgTomaokay, I don't really care if it doesn't get merged, the main thing is that the PR exists so in case someone really wants it they can take the changes12:46:13
@k900:0upti.meK900What's the packages?12:46:44
@k900:0upti.meK900Do we have a list?12:46:52
@tomasajt:matrix.orgTomasee the linked issue12:46:51
@k900:0upti.meK900https://github.com/yxdunc/lipl has a v3 lockfile in master and hasn't been touched in 3 years otherwise12:47:56
@k900:0upti.meK900kubernix author is also its maintainer in nixpkgs12:48:40
@k900:0upti.meK900We can probably ask for a tag?12:48:43
@k900:0upti.meK900system-syzygy has a 1.0.2 tag with a v3 lockfile12:49:29
@k900:0upti.meK900I feel like we can just bump the two and ask the author about the third one 12:50:53
@k900:0upti.meK900And never have this problem again 12:51:01
@tomasajt:matrix.orgToma I guess
also, since importCargoLock supports v1 anyways, weird old software can fall back to that
12:51:50
@k900:0upti.meK900Oh let's rip that out too lol12:52:12
@tomasajt:matrix.orgTomaI don't really agree: it's very simple to support because importCargoLock is written in nix and can use laziness12:54:33
@k900:0upti.meK900I'm not thinking about it in terms of difficulty to support tbh 12:55:04
@k900:0upti.meK900I'm thinking about it in terms of policy 12:55:11
@k900:0upti.meK900Any software that still has a pre-v3 lockfile hasn't been touched since what, 2020?12:55:33
@k900:0upti.meK900We probably don't want to be shipping that12:55:44
@k900:0upti.meK900 Even if we technically can + 12:55:51
@k900:0upti.meK900* Even if we technically can12:56:01
@emilazy:matrix.orgemilyAlyssa removed like 50 packages for having old lock file versions13:16:42
@emilazy:matrix.orgemilyso it seems a bit late to start caring about :P13:16:47
@emilazy:matrix.orgemilywe can just bump to HEAD13:17:56
@k900:0upti.meK900Yeah that's what I'm saying13:18:08
@emilazy:matrix.orgemilyI really do not think we want to ship a tool using pinned Kubernetes dependencies from 2019. https://github.com/saschagrunert/kubernix#what-is-inside13:18:36
@emilazy:matrix.orgemilylike even if this does still function with current Nixpkgs which I am somewhat sceptical about, it's plain dangerous13:18:55
@emilazy:matrix.orgemilyhttps://github.com/saschagrunert/kubernix/issues/1204 declared unmaintained upstream13:19:19
@emilazy:matrix.orgemilyrelease version is apparently broken: https://github.com/saschagrunert/kubernix/issues/72013:20:01

Show newer messages


Back to Room ListRoom Version: 6