Skip to content

Update DeterminateSystems/determinate-nix-action action to v3.22.5 - #171

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/determinatesystems-determinate-nix-action-3.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/determinatesystems-determinate-nix-action-3.x

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending
DeterminateSystems/determinate-nix-action action patch v3.22.3 → v3.22.5 v3.23.1 (+1)

Release Notes

DeterminateSystems/determinate-nix-action (DeterminateSystems/determinate-nix-action)

v3.22.5

Compare Source

What's Changed

Full Changelog: DeterminateSystems/determinate-nix-action@v3.22.4...v3.22.5

v3.22.4

Compare Source

What's Changed

Full Changelog: DeterminateSystems/determinate-nix-action@v3.22.3...v3.22.4


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "after 2am and before 8am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the renovate Renovate dependency updates label Oct 5, 2026
@renovate
renovate Bot force-pushed the renovate/determinatesystems-determinate-nix-action-3.x branch from 2d883a1 to f198e50 Compare October 5, 2026 09:02
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

DeterminateSystems/determinate-nix-action (github-action) v3.22.3 -> v3.22.5

Risk: 🟢 Safe

The Deep Dive

Update Scope

Moves the SHA pin of DeterminateSystems/determinate-nix-action from 021c8a1 (v3.22.3) to 8d87e8d (v3.22.5). The pin appears in one place: the Install Nix step of .github/workflows/renovate-lint-fix.yaml. That workflow runs only on Renovate PRs, on macos-26, and only when lintable files change. The action is a generated wrapper (v3.22.3...v3.22.5 compare), so the bump changes two things:

  • Determinate Nix / nix-installer source-tag default: v3.22.3 → v3.22.5. All three are still based on upstream Nix 2.35.2.
  • Inner DeterminateSystems/nix-installer-action revision: b67ad2f → 3138316. This is 22 commits (compare) and includes the move to detsys-ts 2.x with OpenTelemetry.

Unchanged: the other four Nix-installing workflows (ci.yaml, flake-builds.yaml, update-flake-lock.yaml, update-flake-versions.yaml) use cachix/install-nix-action v31 and are not touched. The step passes no with: inputs, and the repo's own flake, home.nix, and cachix/cachix-action v17 are also unchanged.

Performance & Stability

Two Determinate Nix patch releases, both performance-only:

  • Faster tarball cache in v3.22.4 (nix-src PR 627). This applies to the nix develop evaluation that the lint step runs. The effect is small for a one-off CI job.
  • Zero-copy copy_file_range for file-source → fd copies in v3.22.5 (nix-src PR 630). This is a small I/O gain.
  • Install time unchanged in practice: this PR's own Reconcile PR artifacts run took ~71 s from step start to "Nix was installed successfully". A same-day run still on v3.22.3 (run 37286415792) also took ~71 s.

Security

The update resolves one low-severity, build-time advisory and introduces none. Net effect: slightly positive, nothing new to weigh against it.

  • Resolved: GHSA-g7r4-m6w7-qqqr. This is a GHSA with no CVE ID, rated low (CVSS 2.5): arbitrary file read via the esbuild development server on Windows. It affects esbuild >= 0.27.3, < 0.28.1. The inner nix-installer-action lockfile moves esbuild from 0.27.7 (affected) to 0.28.2 (patched) (PR 283). esbuild is not in the shipped dist/index.js bundle; the only string matches are an undici esbuildDetection guard and a vitest comment. It is also never run as a dev server, so the advisory was not reachable on this macos-26 runner before or after. The fix is hygiene only.
  • No advisories on the Determinate repos (determinate-nix-action, nix-installer-action, nix-installer, nix-src), and no CVEs in the range.
  • Runtime and toolchain unchanged:
    • Node: the inner action declares runs.using: node24 at both revisions, and that runtime is provided by the runner, not by the action.
    • Rust: the nix-installer binary is built with crane from nixpkgs 26.05. That pin moves a311611 → 4c78701, but pkgs/development/compilers/rust/1_95.nix, 1_97.nix and default.nix have identical blob SHAs in both revisions (default rust = rust_1_95). No toolchain advisory is introduced or resolved.
  • The telemetry change is a data-flow change, not a vulnerability; see Hazards.

Key Fixes

  • Fewer false telemetry errors: a runner without a determinate-nixd socket no longer records an error span (PR 289), and a runner without sudo no longer counts as a failed run (detsys-ts PR 233). These only change telemetry status; install behaviour is the same.
  • Git fetcher fixes not reached: Determinate Nix v3.22.4 fixes rev-pinned fetches from bucketed refs (#628) and the pre-2.20 NAR hash fallback for inputs with submodules (#624). Both are in the git fetcher. Every node in this repo's flake.lock is type: github, which uses the tarball fetcher, and no input sets submodules. The nix develop call in the lint step never goes through either code path, so these fixes do not affect this repo.

Newer Versions

v3.23.0, released 2026-10-02, is pending. It only bumps the source-tag default to Determinate Nix 3.23.0. That release is a minor version that adds Nix-level OpenTelemetry, experimental nix flake bake, and builtins.wasm improvements. The inner nix-installer-action revision stays at 3138316.

Hazards & Risks

No hazards that need action. One default behaviour changes:

The action's own telemetry now goes to a new OpenTelemetry endpoint, with plaintext repo metadata

  • What merging does: the bundled nix-installer-action switches to detsys-ts 2.x (detsys-ts PR 208, PR 277). Instead of the old PostHog-style diagnostics POST to install.determinate.systems, it exports OTLP traces and logs to https://otel.determinate.systems using a built-in public ingest token (telemetry.ts).
  • Sent before (detsys-ts v1):
    • Plaintext: the owner name (claytono, via $groupidentify); the action ref and repo, event name, runner OS and arch; and Nix and source facts.
    • Hashed only: repository, workflow, job and run identity (github_repository_hash, github_workflow_hash, github_workflow_job_hash and run hashes in correlation.ts).
    • On failure: daemon.log was attached.
  • Newly sent in plaintext: the repository name and URL, head and base branch names and SHAs, the PR number, the workflow and job names, the run ID and URL, and the runner name (github-semconv.ts).
  • Unchanged: the vendor, telemetry being on by default, the owner name, OS/arch facts, and the daemon.log attachment on failure.
  • The opt-out changes too: diagnostic-endpoint: "" used to disable the action's diagnostics. It now only covers the child installer binary. Disabling the action's own export needs OTEL_SDK_DISABLED=true or an empty OTEL_EXPORTER_OTLP_ENDPOINT. A consumer who had opted out through diagnostic-endpoint would silently start exporting again.
  • What the repo evidence shows:
    • This workflow sets no diagnostic-endpoint or OTEL_* (grep of .github/: no matches), and its run log shows diagnostic-endpoint: -, the default. No existing opt-out is being bypassed.
    • claytono/dotfiles is public, so every newly plaintext field is already publicly visible on GitHub.
    • The OTLP variables are not exported to later steps; the pre-commit step env in this PR's run has no OTEL_*.
    • The step gets no repository secrets; the default github.token goes into nix.conf, not into the telemetry attributes.
  • Net impact: Determinate Systems can now link these CI runs to this repo by name instead of by hash. The repo is public and never opted out, so nothing private is exposed and no configured preference is overridden. Opting out would mean adding OTEL_SDK_DISABLED: true to the step's env:.

Sources


🟢 Verdict: Safe

This is a patch bump of a CI-only Nix installer, used by one Renovate-only workflow. It brings only performance and fix-level Determinate Nix changes, introduces no advisories, and already installed and linted successfully on this PR's own run. The switch of the inner action's telemetry to OpenTelemetry is worth knowing about, but this public repo already had default-on telemetry and never opted out, so no action is needed.

@renovate
renovate Bot force-pushed the renovate/determinatesystems-determinate-nix-action-3.x branch 2 times, most recently from a98206d to 4828ac6 Compare October 5, 2026 16:03
@renovate
renovate Bot force-pushed the renovate/determinatesystems-determinate-nix-action-3.x branch from 4828ac6 to d5e96f3 Compare October 6, 2026 16:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants