Note that the impact is reduced by the behavior of not building branches from forks. This update is important if you have automation that pushes untrustworthy expressions, or if you build untrustworthy derivations using any means.
๐ข Update your Nix installation, and refrain from building untrustworthy derivations until done.
https://t.co/mr2Kin8ht5
Hercules CI Agent uses the running nix daemon, so updating your system Nix is sufficient.
Just created a @hercules_ci effect to capture the graphical rendering pipeline for StardustXR and post to Discord. It spawns #gnome#stardustxr#monado in a #QEMU VM. It does this on every single git commit, thanks to Nix. Plus, the image gets uploaded to IPFS instead of Discord.