Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: grav_2

Found 103 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-62232
9.1 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Grav < 2.0.4 2FA Bypass via Secret Regeneration

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know the victim's password can call this task without a CSRF nonce to overwrite the 2FA secret with an attacker-chosen value, compute a valid TOTP code, and complete authentication while reducing 2FA to password-only protection.

Affected products

grav
  • <2.0.4
  • ==2.0.4

Matching in nixpkgs

pkgs.grav

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.grav_2

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
    • nixos-unstable-small 2.1.8

pkgs.gravit

Beautiful OpenGL-based gravity simulator

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.antigravity

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-acp

Google's AI coding agent. Official ACP server powered by Antigravity

  • nixos-unstable -
    • nixos-unstable-small 1.1.1

pkgs.antigravity-cli

Google's Go-based terminal user interface (TUI) agent client

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.antigravity-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-hub

Desktop environment for managing multiple autonomous agents across independent projects

  • nixos-unstable -

pkgs.antigravity-ide

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.antigravity-ide-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.stardust-xr-gravity

Utility to launch apps and stardust clients at an offset

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bulwark-plugins.gravatar

Resolves Gravatar profile pictures for email contacts via the avatar transform hook

  • nixos-unstable -
    • nixos-unstable-small 1.3.1

pkgs.gnomeExtensions.gravatar

Synchronize GNOME Shell user icon with an avatar service, one of Gravatar or Libravatar.

  • nixos-unstable -
    • nixos-unstable-small 10
  • nixos-26.05 -
    • nixos-26.05-small 10

pkgs.porting-advisor-for-graviton

AWS Porting Advisor for Graviton helps customers assess and prepare their applications for migration to AWS Graviton processors

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
Untriaged
Permalink CVE-2026-62235
2.3 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Grav Flex-Objects < 1.4.3 Authorization Bypass via API

Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. Attackers with api.access credentials can create, read, update, delete, and export objects from any directory lacking an explicit permissions configuration, bypassing intended authorization controls.

Affected products

grav
  • ==1.4.3
  • <1.4.3

Matching in nixpkgs

pkgs.grav

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.grav_2

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
    • nixos-unstable-small 2.1.8

pkgs.gravit

Beautiful OpenGL-based gravity simulator

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.antigravity

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-acp

Google's AI coding agent. Official ACP server powered by Antigravity

  • nixos-unstable -
    • nixos-unstable-small 1.1.1

pkgs.antigravity-cli

Google's Go-based terminal user interface (TUI) agent client

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.antigravity-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-hub

Desktop environment for managing multiple autonomous agents across independent projects

  • nixos-unstable -

pkgs.antigravity-ide

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.antigravity-ide-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.stardust-xr-gravity

Utility to launch apps and stardust clients at an offset

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bulwark-plugins.gravatar

Resolves Gravatar profile pictures for email contacts via the avatar transform hook

  • nixos-unstable -
    • nixos-unstable-small 1.3.1

pkgs.gnomeExtensions.gravatar

Synchronize GNOME Shell user icon with an avatar service, one of Gravatar or Libravatar.

  • nixos-unstable -
    • nixos-unstable-small 10
  • nixos-26.05 -
    • nixos-26.05-small 10

pkgs.porting-advisor-for-graviton

AWS Porting Advisor for Graviton helps customers assess and prepare their applications for migration to AWS Graviton processors

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
Untriaged
Permalink CVE-2026-58655
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Grav Flex Objects - Server-Side Template Injection via Dynamic Titles

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values (page.header.flex.collection.title or page.header.flex.object.title) to Twig's template_from_string(), causing them to be evaluated as Twig code rather than treated as text. This path bypasses Grav's Security::cleanDangerousTwig() sanitization. An attacker who can control the title frontmatter of a publicly reachable Flex Objects page can achieve arbitrary Twig execution and escalate to remote command execution via access to internal Grav services such as the scheduler.

Affected products

grav
  • ==1.4.0
  • <1.4.0

Matching in nixpkgs

pkgs.grav

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.grav_2

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
    • nixos-unstable-small 2.1.8

pkgs.gravit

Beautiful OpenGL-based gravity simulator

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.antigravity

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-acp

Google's AI coding agent. Official ACP server powered by Antigravity

  • nixos-unstable -
    • nixos-unstable-small 1.1.1

pkgs.antigravity-cli

Google's Go-based terminal user interface (TUI) agent client

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.antigravity-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-hub

Desktop environment for managing multiple autonomous agents across independent projects

  • nixos-unstable -

pkgs.antigravity-ide

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.antigravity-ide-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.stardust-xr-gravity

Utility to launch apps and stardust clients at an offset

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bulwark-plugins.gravatar

Resolves Gravatar profile pictures for email contacts via the avatar transform hook

  • nixos-unstable -
    • nixos-unstable-small 1.3.1

pkgs.gnomeExtensions.gravatar

Synchronize GNOME Shell user icon with an avatar service, one of Gravatar or Libravatar.

  • nixos-unstable -
    • nixos-unstable-small 10
  • nixos-26.05 -
    • nixos-26.05-small 10

pkgs.porting-advisor-for-graviton

AWS Porting Advisor for Graviton helps customers assess and prepare their applications for migration to AWS Graviton processors

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
Untriaged
Permalink CVE-2026-61451
9.4 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): High (H)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url

The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http/https and never verifies the host against the server's own origin, so an attacker can supply an arbitrary host. As a result, an unauthenticated attacker can cause the password reset email sent to a victim to contain a reset link pointing at an attacker-controlled server; when the victim follows the link, the valid reset token is disclosed to the attacker, enabling full account takeover. The vulnerable base URL can also be influenced via the Referer or Origin headers.

Affected products

grav
  • ==1.0.4
  • <1.0.4

Matching in nixpkgs

pkgs.grav

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.grav_2

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
    • nixos-unstable-small 2.1.8

pkgs.gravit

Beautiful OpenGL-based gravity simulator

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.antigravity

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-acp

Google's AI coding agent. Official ACP server powered by Antigravity

  • nixos-unstable -
    • nixos-unstable-small 1.1.1

pkgs.antigravity-cli

Google's Go-based terminal user interface (TUI) agent client

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.antigravity-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-hub

Desktop environment for managing multiple autonomous agents across independent projects

  • nixos-unstable -

pkgs.antigravity-ide

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.antigravity-ide-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.stardust-xr-gravity

Utility to launch apps and stardust clients at an offset

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bulwark-plugins.gravatar

Resolves Gravatar profile pictures for email contacts via the avatar transform hook

  • nixos-unstable -
    • nixos-unstable-small 1.3.1

pkgs.gnomeExtensions.gravatar

Synchronize GNOME Shell user icon with an avatar service, one of Gravatar or Libravatar.

  • nixos-unstable -
    • nixos-unstable-small 10
  • nixos-26.05 -
    • nixos-26.05-small 10

pkgs.porting-advisor-for-graviton

AWS Porting Advisor for Graviton helps customers assess and prepare their applications for migration to AWS Graviton processors

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
Untriaged
Permalink CVE-2026-61449
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Grav before 2.0.2 Decompression Bomb via Forged ZIP Size

Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']) and rejects archives exceeding system.gpm.archive.max_uncompressed_size before extraction. Because this declared size is attacker-forgeable and is not cross-checked against the actual inflated stream, a crafted archive declaring tiny per-entry sizes passes the cap while extractTo() writes the real, much larger content, filling disk or exhausting inodes. The archive must be supplied by a package source or admin upload (admin/operator trust). Fixed in 2.0.2. This is an incomplete fix for GHSA-928x-9mpw-8h56.

Affected products

grav
  • ==2.0.2
  • <2.0.2

Matching in nixpkgs

pkgs.grav

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.grav_2

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
    • nixos-unstable-small 2.1.8

pkgs.gravit

Beautiful OpenGL-based gravity simulator

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.antigravity

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-acp

Google's AI coding agent. Official ACP server powered by Antigravity

  • nixos-unstable -
    • nixos-unstable-small 1.1.1

pkgs.antigravity-cli

Google's Go-based terminal user interface (TUI) agent client

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.antigravity-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-hub

Desktop environment for managing multiple autonomous agents across independent projects

  • nixos-unstable -

pkgs.antigravity-ide

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.antigravity-ide-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.stardust-xr-gravity

Utility to launch apps and stardust clients at an offset

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bulwark-plugins.gravatar

Resolves Gravatar profile pictures for email contacts via the avatar transform hook

  • nixos-unstable -
    • nixos-unstable-small 1.3.1

pkgs.gnomeExtensions.gravatar

Synchronize GNOME Shell user icon with an avatar service, one of Gravatar or Libravatar.

  • nixos-unstable -
    • nixos-unstable-small 10
  • nixos-26.05 -
    • nixos-26.05-small 10

pkgs.porting-advisor-for-graviton

AWS Porting Advisor for Graviton helps customers assess and prepare their applications for migration to AWS Graviton processors

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
Untriaged
Permalink CVE-2026-61457
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypass

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension via pathinfo($filename, PATHINFO_EXTENSION), so a user with api.media.write permission can upload a file with a double extension such as shell.php.jpg to bypass the dangerous extensions blocklist. The web server may then execute the file as PHP, resulting in remote code execution.

Affected products

grav
  • <1.0.3
  • ==1.0.3

Matching in nixpkgs

pkgs.grav

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.grav_2

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
    • nixos-unstable-small 2.1.8

pkgs.gravit

Beautiful OpenGL-based gravity simulator

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.antigravity

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-acp

Google's AI coding agent. Official ACP server powered by Antigravity

  • nixos-unstable -
    • nixos-unstable-small 1.1.1

pkgs.antigravity-cli

Google's Go-based terminal user interface (TUI) agent client

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.antigravity-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-hub

Desktop environment for managing multiple autonomous agents across independent projects

  • nixos-unstable -

pkgs.antigravity-ide

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.antigravity-ide-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.stardust-xr-gravity

Utility to launch apps and stardust clients at an offset

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bulwark-plugins.gravatar

Resolves Gravatar profile pictures for email contacts via the avatar transform hook

  • nixos-unstable -
    • nixos-unstable-small 1.3.1

pkgs.gnomeExtensions.gravatar

Synchronize GNOME Shell user icon with an avatar service, one of Gravatar or Libravatar.

  • nixos-unstable -
    • nixos-unstable-small 10
  • nixos-26.05 -
    • nixos-26.05-small 10

pkgs.porting-advisor-for-graviton

AWS Porting Advisor for Graviton helps customers assess and prepare their applications for migration to AWS Graviton processors

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
Untriaged
Permalink CVE-2026-61452
6.9 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens

The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, access tokens remain valid for their full lifetime (default 1 hour) regardless of logout, password change, new token issuance, or account disablement. An attacker who has stolen an access token retains full API access until the token naturally expires.

Affected products

grav
  • <2.0.4
  • ==2.0.4

Matching in nixpkgs

pkgs.grav

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.grav_2

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
    • nixos-unstable-small 2.1.8

pkgs.gravit

Beautiful OpenGL-based gravity simulator

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.antigravity

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-acp

Google's AI coding agent. Official ACP server powered by Antigravity

  • nixos-unstable -
    • nixos-unstable-small 1.1.1

pkgs.antigravity-cli

Google's Go-based terminal user interface (TUI) agent client

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.antigravity-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-hub

Desktop environment for managing multiple autonomous agents across independent projects

  • nixos-unstable -

pkgs.antigravity-ide

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.antigravity-ide-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.stardust-xr-gravity

Utility to launch apps and stardust clients at an offset

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bulwark-plugins.gravatar

Resolves Gravatar profile pictures for email contacts via the avatar transform hook

  • nixos-unstable -
    • nixos-unstable-small 1.3.1

pkgs.gnomeExtensions.gravatar

Synchronize GNOME Shell user icon with an avatar service, one of Gravatar or Libravatar.

  • nixos-unstable -
    • nixos-unstable-small 10
  • nixos-26.05 -
    • nixos-26.05-small 10

pkgs.porting-advisor-for-graviton

AWS Porting Advisor for Graviton helps customers assess and prepare their applications for migration to AWS Graviton processors

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
Untriaged
Permalink CVE-2026-61453
5.1 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Active (A)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Active (A)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Grav before 2.0.1 XSS via Twig String Concatenation

Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig content processing is enabled (twig_content.process_enabled: true), an attacker with page-write API permission can use Twig's string concatenation operator (~) to dynamically construct event handler names, dangerous tag names, or dangerous protocols at render time (e.g. {% set x = "on" ~ "error" %}). The validator sees only the harmless Twig expression and allows the content, but after Twig rendering the output (rendered via {{ page.content|raw }}) contains an active payload such as <img src=1 onerror=alert(1)>, executing arbitrary JavaScript in visitors' browsers.

Affected products

grav
  • ==2.0.1
  • <2.0.1

Matching in nixpkgs

pkgs.grav

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.grav_2

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
    • nixos-unstable-small 2.1.8

pkgs.gravit

Beautiful OpenGL-based gravity simulator

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.antigravity

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-acp

Google's AI coding agent. Official ACP server powered by Antigravity

  • nixos-unstable -
    • nixos-unstable-small 1.1.1

pkgs.antigravity-cli

Google's Go-based terminal user interface (TUI) agent client

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.antigravity-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-hub

Desktop environment for managing multiple autonomous agents across independent projects

  • nixos-unstable -

pkgs.antigravity-ide

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.antigravity-ide-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.stardust-xr-gravity

Utility to launch apps and stardust clients at an offset

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bulwark-plugins.gravatar

Resolves Gravatar profile pictures for email contacts via the avatar transform hook

  • nixos-unstable -
    • nixos-unstable-small 1.3.1

pkgs.gnomeExtensions.gravatar

Synchronize GNOME Shell user icon with an avatar service, one of Gravatar or Libravatar.

  • nixos-unstable -
    • nixos-unstable-small 10
  • nixos-26.05 -
    • nixos-26.05-small 10

pkgs.porting-advisor-for-graviton

AWS Porting Advisor for Graviton helps customers assess and prepare their applications for migration to AWS Graviton processors

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
Untriaged
Permalink CVE-2026-61873
7.2 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename

Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form data containing path traversal sequences that are processed through Twig templates, allowing them to write arbitrary files including PHP webshells to the web root or other sensitive directories.

Affected products

grav
  • <9.1.8
  • ==9.1.8

Matching in nixpkgs

pkgs.grav

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.grav_2

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
    • nixos-unstable-small 2.1.8

pkgs.gravit

Beautiful OpenGL-based gravity simulator

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.antigravity

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-acp

Google's AI coding agent. Official ACP server powered by Antigravity

  • nixos-unstable -
    • nixos-unstable-small 1.1.1

pkgs.antigravity-cli

Google's Go-based terminal user interface (TUI) agent client

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.antigravity-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-hub

Desktop environment for managing multiple autonomous agents across independent projects

  • nixos-unstable -

pkgs.antigravity-ide

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.antigravity-ide-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.stardust-xr-gravity

Utility to launch apps and stardust clients at an offset

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bulwark-plugins.gravatar

Resolves Gravatar profile pictures for email contacts via the avatar transform hook

  • nixos-unstable -
    • nixos-unstable-small 1.3.1

pkgs.gnomeExtensions.gravatar

Synchronize GNOME Shell user icon with an avatar service, one of Gravatar or Libravatar.

  • nixos-unstable -
    • nixos-unstable-small 10
  • nixos-26.05 -
    • nixos-26.05-small 10

pkgs.porting-advisor-for-graviton

AWS Porting Advisor for Graviton helps customers assess and prepare their applications for migration to AWS Graviton processors

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
Untriaged
Permalink CVE-2026-55890
4.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 2 months, 1 week ago Activity log
  • Created suggestion
Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style()

Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media attribute action (CVE-2026-42841) leaves the sibling MediaObjectTrait::style method reachable through the same Markdown excerpt-action pipeline, allowing an editor to save Markdown image style parameters that are written into the rendered img style attribute without sanitization. This issue is fixed in version 2.0.0-rc.9.

Affected products

grav
  • ==< 2.0.0-rc.9

Matching in nixpkgs

pkgs.grav

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
  • nixos-26.05 -

pkgs.grav_2

Fast, simple, and flexible, file-based web platform

  • nixos-unstable -
    • nixos-unstable-small 2.1.8

pkgs.gravit

Beautiful OpenGL-based gravity simulator

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.antigravity

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-acp

Google's AI coding agent. Official ACP server powered by Antigravity

  • nixos-unstable -
    • nixos-unstable-small 1.1.1

pkgs.antigravity-cli

Google's Go-based terminal user interface (TUI) agent client

  • nixos-unstable -
    • nixos-unstable-small 1.2.3

pkgs.antigravity-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5
  • nixos-26.05 -

pkgs.antigravity-hub

Desktop environment for managing multiple autonomous agents across independent projects

  • nixos-unstable -

pkgs.antigravity-ide

Agentic development platform, evolving the IDE into the agent-first era

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.antigravity-ide-fhs

Wrapped variant of antigravity-ide which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications

  • nixos-unstable -
    • nixos-unstable-small 2.5.5

pkgs.stardust-xr-gravity

Utility to launch apps and stardust clients at an offset

  • nixos-unstable -
  • nixos-26.05 -

pkgs.bulwark-plugins.gravatar

Resolves Gravatar profile pictures for email contacts via the avatar transform hook

  • nixos-unstable -
    • nixos-unstable-small 1.3.1

pkgs.gnomeExtensions.gravatar

Synchronize GNOME Shell user icon with an avatar service, one of Gravatar or Libravatar.

  • nixos-unstable -
    • nixos-unstable-small 10
  • nixos-26.05 -
    • nixos-26.05-small 10

pkgs.porting-advisor-for-graviton

AWS Porting Advisor for Graviton helps customers assess and prepare their applications for migration to AWS Graviton processors

  • nixos-unstable -
    • nixos-unstable-small 1.1.1