This release (and previous releases) includes Nix versions that are vulnerable to CVE-2024-27297. The current default Nix version, 2.19.3, is not vulnerable. If you select another Nix version you should use your own judgement to decide if CVE-2024-27297 is applicable to your usage of Nix in your GitHub Actions workflow.
The following Nix versions that are packaged with this action are not vulnerable:
2.19.3 (the default version)
2.18.1
2.3.17
The above versions have been explicitly patched by the nixpkgs maintainers.
The rest of the Nix versions provided by this action are vulnerable to CVE-2024-27297.
In the next release of this action (v28), all vulnerable Nix versions will be removed.
This release (and previous releases) includes Nix versions that are vulnerable to CVE-2024-27297. The current default Nix version, 2.19.3, is not vulnerable. If you select another Nix version you should use your own judgement to decide if CVE-2024-27297 is applicable to your usage of Nix in your GitHub Actions workflow.
The following Nix versions that are packaged with this action are not vulnerable:
2.19.3 (the default version)
2.18.1
2.3.17
The above versions have been explicitly patched by the nixpkgs maintainers.
The rest of the Nix versions provided by this action are vulnerable to CVE-2024-27297.
In the next release of this action (v28), all vulnerable Nix versions will be removed.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps nixbuild/nix-quick-install-action from 26 to 27.
Release notes
Sourced from nixbuild/nix-quick-install-action's releases.
... (truncated)
Changelog
Sourced from nixbuild/nix-quick-install-action's changelog.
Commits
d02dd28
Release v27123ee16
Fix variable nameb35ae20
Retry if db registration fails483e6ef
Bump nixpkgs revisions to get patches for CVE-2024-27297eac9523
Bump default Nix version from 2.16.2 to 2.19.3e6c4065
Revert "Add Nix 2.20.5 and 2.21.0"b83db0f
Add Nix 2.20.5 and 2.21.0896e438
Merge pull request #41 from deemp/master0e337be
fix(cicd): bump nix versiona17089e
chore: update nix versionsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show