!bxVOQwsVoHhZcmNDGw:nixos.org

Nix + dotnet

127 Members
24 Servers

Load older messages


SenderMessageTime
17 Dec 2024
@gggkiller:matrix.orgGGGHaving a key to specify which platforms you download that package for and then we filter it based on targetPlatform22:42:26
@gggkiller:matrix.orgGGG
In reply to @6pak:matrix.org
GenerateRestoreGraphFile looked like it had everything we need
Does it have the hashes for the packages in a format we can consume for the lockfile as well? Never heard of that
22:42:52
@6pak:matrix.org6pak

Never heard of that

I don't think it's documented, but nothing in msbuild land ever is ;p

22:43:22
@gggkiller:matrix.orgGGGYeah, fair enough22:43:35
@gggkiller:matrix.orgGGGNixpkgs has been the only reason I've ever looked into these build specific .net internals22:43:54
@6pak:matrix.org6pakit doesn't have hashes annoyingly, even though it could22:43:56
@6pak:matrix.org6pakwe can always grab it from the nuget server though22:44:20
@corngood:corngood.comCorngoodThat would be great, but there are a lot of annoying edge cases to test.22:45:35
@6pak:matrix.org6pakthe big exception are the nuget msbuild sdks which bypass the regular resolving22:47:06
@gggkiller:matrix.orgGGGthere are also some packages which download packages outside of the restore target iirc22:47:39
@corngood:corngood.comCorngoodSorry if I missed the context above, but is the problem just that it's on an EOL SDK? I personally would just allow the insecure dependency and continue to use it as is.22:47:40
@gggkiller:matrix.orgGGG or that don't use PackageReference and instead do something else 22:48:10
@gggkiller:matrix.orgGGGwe'd also need to guarantee it works with paket and et. all22:48:22
@corngood:corngood.comCorngoodyeah, tools and paket are the ones that come to mind. also some explicit downloads in msbuild, etc22:48:25
@6pak:matrix.org6pak and imo it's fair to not handle it in the generic msbuild tooling 22:48:24
@whovian9369:matrix.orgWhovian9369That context sums it up well -- I don't really like the idea of using the insecure allowance but it may just be what I end up doing. Thanks for the thoughts!22:48:40
@corngood:corngood.comCorngoodThat's understandable. Has the upstream project considered this? Providing an LTS build that's not on a supported platform seems odd.22:49:38
@gggkiller:matrix.orgGGGupstream seems abandoned from what I saw22:49:54
@gggkiller:matrix.orgGGGlast release 2 years ago22:49:55
@gggkiller:matrix.orgGGGthey have some commits but no releases in the interim22:50:36
@gggkiller:matrix.orgGGGthere's a commit updating to .NET 9 rc2 but idk how stable that is22:50:45
@whovian9369:matrix.orgWhovian9369Pre-Release was ~1yr ago22:51:02
@gggkiller:matrix.orgGGGboth releases are from 2022, which is 2 years ago22:51:31
@whovian9369:matrix.orgWhovian9369I misread the year, apologies.22:51:42
@corngood:corngood.comCorngoodI actually think dotnet 6 is so widely use that I'm not worried about it being EOL. There are tons of things that are less likely to get security fixes that aren't marked insecure in nixpkgs.22:51:47
@gggkiller:matrix.orgGGG you could risk building from the latest commit from the main branch 22:51:52
@corngood:corngood.comCorngood* I actually think dotnet 6 is so widely used that I'm not worried about it being EOL. There are tons of things that are less likely to get security fixes that aren't marked insecure in nixpkgs.22:52:09
@whovian9369:matrix.orgWhovian9369Honestly I'd say that the dev is just busy, but I don't quite know what else to say or do about it as I figure the response I'd get would be "PR it then." but... 🤷22:52:24
@gggkiller:matrix.orgGGGit is widely used but won't be getting any security updates even if something does happen though22:52:26
@gggkiller:matrix.orgGGG* it is widely used but won't be getting any security updates even if something does happen though, nor will anyone report it as a security issue because it's been abandoned22:52:43

Show newer messages


Back to Room ListRoom Version: 9