BLUE
Profile banner
DS
Determinate Systems
@determinate.systems
Bringing Nix ❄️ to the enterprise to empower fearless software delivery 💪 determinate.systems
108 followers61 following28 posts
DSdeterminate.systems

Throw out your manual provisioning runbook: fully automated Nix installation on macOS comes to AWS. Autoscale and deploy Apple hardware without logging in graphically to allow Full Disk Access with the latest Determinate Nix Installer. Check out the blog post for details:

Fully automated Nix installation for macOS on AWS EC2
Fully automated Nix installation for macOS on AWS EC2

Skip the unskippable: eliminate the macOS Full Disk Access approval on AWS EC2 with Determinate.

0
DSdeterminate.systems

Has your build ended with "error: Nix daemon disconnected unexpectedly (maybe it crashed?)"? Good news: Nix 2.24.9 is phasing in through all Determinate channels, improving the reliability and fixing this issue. See:

HttpBinaryCacheStore::getFile(): Fix uncaught exception by edolstra · Pull Request #11600 · NixOS/nix
HttpBinaryCacheStore::getFile(): Fix uncaught exception by edolstra · Pull Request #11600 · NixOS/nix

Motivation This method is marked as noexcept, but enqueueFileTransfer() can throw Interrupted if the user has hit Ctrl-C or if the ThreadPool that the thread is a part of is shutting down. Should f...

0
DSdeterminate.systems

Corporate Nix user? Determinate automatically handles Zscaler and other MITM proxies for you. Check out our blog post on solving enterprise TLS certificates for Nix on macOS: https://buff.ly/4eHFTAf

0
DSdeterminate.systems

NixOS users can determine if CUPS is enabled, and their machine may be impacted by the recent CUPS vulnerabilities via: nix eval .#nixosConfigurations.YOURMACHINENAME.config.services.printing.enable The machine is not affected if nix eval prints "false".

0
DSdeterminate.systems

The primary risk is leaking of netrc credentials through a crafted derivation plus an attacker-in-the-middle. Users of the experimental feature `impure-derivations` are at greater risk. FlakeHub Cache users and users of impure derivations should upgrade as soon as possible.

0
DSdeterminate.systems

builtin:fetchurl is a builtin derivation that requires an output hash, and is not the same as `builtins.fetchUrl`, which does not. `builtins.fetchUrl` is not affected.

1
DSdeterminate.systems

Nix 2.24.8 is currently phasing in through all Determinate distribution channels. This release improves the security of Nix's builtin:fetchurl builder by validating TLS certificates against the system's certificate store. Note: builtin:fetchurl is not builtins.fetchUrl...

1
DSdeterminate.systems

Excited for macOS Sequoia? Make the upgrade seamless by preparing your Nix installation first. Our latest Determinate Nix Installer release includes a repair tool to make any existing installation compatible.

Prepare Nix for macOS Sequoia
Prepare Nix for macOS Sequoia

Nix fully supports the upcoming macOS Sequoia, but you'll have to repair the build users first.

0
DSdeterminate.systems

Nix 2.24.6 is now available through all Determinate channels, resolving last night's security vuln. Users can get our supported Nix via our Nix flake: https://buff.ly/47jg5Ig. Other users can update Nix via `nix upgrade-nix` see the below link. Details:

Uncoordinated disclosure of a Nix 2.24 privilege escalation vulnerability
Uncoordinated disclosure of a Nix 2.24 privilege escalation vulnerability

Determinate's Status Page - Uncoordinated disclosure of a Nix 2.24 privilege escalation vulnerability.

0
DSdeterminate.systems

A vuln in Nix versions 2.24.{0-5} was disclosed without a coordinated Nix release. Affected versions are yanked from the DeterminateSystems/nix flake, and Determinate Nix Installer is rolled back to 2.23.3. See: https://buff.ly/4cXEMv9https://buff.ly/3MEIXRO

0
Profile banner
DS
Determinate Systems
@determinate.systems
Bringing Nix ❄️ to the enterprise to empower fearless software delivery 💪 determinate.systems
108 followers61 following28 posts