| 4 Feb 2025 |
Pol |
- Checkout the PR
- Build a couple of PHP derivations
- Test them
- Check if the changes are OK
| 19:45:57 |
w | OK | 19:47:15 |
| 7 Feb 2025 |
piotrkwiecinski | We have 5 packages left using buildComposerProject. In their current form they move some files from $out/share/php/pname to $out. This doesn't work with buildComposerProject2. Any suggestion how we could solve it?
Here is an example: https://github.com/NixOS/nixpkgs/blob/91b02440a51ceea54ee5ca61b2d018f41c22695f/pkgs/by-name/da/davis/package.nix#L21-L27 | 14:01:37 |
piotrkwiecinski | https://github.com/search?q=repo%3ANixOS%2Fnixpkgs+%22buildComposerProject+%28%22&type=code | 14:03:42 |
piotrkwiecinski | https://github.com/NixOS/nixpkgs/blob/91b02440a51ceea54ee5ca61b2d018f41c22695f/pkgs/servers/nextcloud/packages/apps/hmr_enabler.nix#L25 uses chmod -R u+w $out/share which seems to solve a problem for building davis is this correct ok? | 14:08:22 |
| 8 Feb 2025 |
piotrkwiecinski | We don't have any packages using buildComposerProject. Is it worth deprecating it? | 12:57:34 |
| 9 Feb 2025 |
Pol | yes ! | 16:59:15 |
Pol | massive :) | 16:59:21 |
| 10 Feb 2025 |
piotrkwiecinski | Pol: in v1 we still have mkComposerRepository and buildComposerWithPlugin are we going to leave them as they are? | 21:01:16 |
| 13 Feb 2025 |
Pol | piotrkwiecinski: I want to get rid of them actually. | 21:38:50 |
| 15 Feb 2025 |
| BenjB83 joined the room. | 10:19:45 |
| BenjB83 changed their display name from Benjamín Buske to BenjB83. | 10:43:03 |
| 22 Feb 2025 |
w | I wasn't able to try that yet - But I am setting-up a new box this weekend and Iĺl try | 13:15:04 |
| 27 Feb 2025 |
| w changed their display name from w to w - out for 🚬. | 18:33:51 |
| w changed their display name from w - out for 🚬 to w. | 19:25:13 |
| 28 Feb 2025 |
Pol | Wondering if implementing lib.extendMkDerivation for PHP Builder is a good idea. | 12:33:10 |
Pol | Context: https://github.com/NixOS/nixpkgs/pull/234651 | 12:33:16 |
Pol | Something like this: https://github.com/NixOS/nixpkgs/pull/385830 | 16:15:15 |
Pol | On another note, I wrote this post on Mastodon: https://main.elk.zone/mathstodon.xyz/@Pol/114081643763526228 Feel free to boost it. | 16:28:16 |
| 2 Mar 2025 |
| @patka_123:matrix.org left the room. | 15:51:07 |
| 4 Mar 2025 |
Pol | Updated the PR @ https://github.com/NixOS/nixpkgs/pull/386757 | 10:53:07 |
| 10 Mar 2025 |
hexa |
CVE-2024-13918: Laravel 11.9.0-11.35.1 Reflected XSS via Request Parameter in Debug-Mode Error Page
| 15:13:19 |
hexa | how many laravel versions do we vendor? | 15:13:30 |
patka | The only one I can find is in Bookstack (pkgs/servers/web-apps/bookstack/php-packages.nix), which is EOL and out of the security update window.
(my search was quick and probably not exhaustive)
| 15:40:29 |
patka | I tried to use the included update script but that blows up horribly (besides that it uses composer2nix that I've seen for the first time now and is horribly unmaintained). I don't have the time to sort this out and get Bookstack updated, sorry | 15:57:53 |
tgerbet | Likely also Pixel fed, snipe-it and agorakit (and Pest but if you expose that publicly you have other issues…) | 15:59:36 |
| 11 Mar 2025 |
Genghiz | Is bookstack actively maintained? | 16:09:11 |
Genghiz | Let me rephrase. Is the maintainer active? | 16:09:23 |
Genghiz | I can update it to use the same style as firefly-iii, which is also RFC 42 styled. | 16:11:00 |
nebucatnetzer13 | He replies to mails this much I can say. | 16:57:11 |