From 4828c40ef4d331ad55a000a177d54ff18eb1b06e Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Sun, 6 Apr 2025 12:56:01 +0200 Subject: [PATCH] vyper: 0.4.0 -> 0.4.1 Fixes CVE-2025-21607, CVE-2025-27105, CVE-2025-26622 and CVE-2025-27104. https://github.com/vyperlang/vyper/releases/tag/v0.4.1 --- pkgs/development/compilers/vyper/default.nix | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/pkgs/development/compilers/vyper/default.nix b/pkgs/development/compilers/vyper/default.nix index 8f523f14735b..011675a1f31b 100644 --- a/pkgs/development/compilers/vyper/default.nix +++ b/pkgs/development/compilers/vyper/default.nix @@ -1,5 +1,6 @@ { lib, + lark, asttokens, buildPythonPackage, cbor2, @@ -28,21 +29,20 @@ let in buildPythonPackage rec { pname = "vyper"; - version = "0.4.0"; + version = "0.4.1"; pyproject = true; disabled = pythonOlder "3.10"; src = fetchPypi { inherit pname version; - hash = "sha256-locUXGoL9C3lLpIgLOmpE2SNPGV6yOXPubNaEA3EfjQ="; + hash = "sha256-KiGbiVybWtanEjem+30DpuzKqAD6owujJBiEfjUKleM="; }; postPatch = '' # pythonRelaxDeps doesn't work substituteInPlace setup.py \ - --replace-fail "setuptools_scm>=7.1.0,<8.0.0" "setuptools_scm>=7.1.0" \ - --replace-fail '"pytest-runner",' "" + --replace-fail "setuptools_scm>=7.1.0,<8.0.0" "setuptools_scm>=7.1.0" ''; nativeBuildInputs = [ @@ -59,6 +59,7 @@ buildPythonPackage rec { ]; propagatedBuildInputs = [ + lark asttokens cbor2 importlib-metadata