Allow insecure openssl_1_1 at flake nixpkgs config level

This commit is contained in:
Hermes
2026-08-08 09:46:31 +00:00
parent ba1652dab4
commit afc9ae8cc5
2 changed files with 10 additions and 6 deletions
+10 -1
View File
@@ -24,7 +24,16 @@
flake-utils.lib.eachDefaultSystem (
system:
let
pkgs = nixpkgs.legacyPackages.${system};
pkgs = nixpkgs.legacyPackages.${system}.extend (
final: prev: {
config = prev.config // {
permittedInsecurePackages = (prev.config.permittedInsecurePackages or [ ]) ++ [
# openssl_1_1 is EOL but needed to link vibe-d 0.9.8 TLS
"openssl-1.1.1w"
];
};
}
);
in
{
packages = import ./pkgs {
-5
View File
@@ -19,11 +19,6 @@ buildDubPackage rec {
dubLock = ./dub-lock.json;
# openssl_1_1 is EOL and marked insecure in nixpkgs, but it's only a
# build-time link dependency (vibe-d 0.9.8 TLS needs symbols removed in
# OpenSSL 3). The resulting binary statically links it.
permittedInsecurePackages = [ "openssl-1.1.1w" ];
buildInputs = [ zlib openssl_1_1 ];
meta = {