Commit Graph

35 Commits

Author SHA1 Message Date
Leona Maroni
94585324b2 nginxStable: 1.30.3 -> 1.30.4
https://github.com/nginx/nginx/releases/tag/release-1.30.4

fixes:
- CVE-2026-42533
- CVE-2026-60005
- CVE-2026-56434
2026-07-15 22:32:56 +02:00
Mynacol
ff3edfc4db nginx: 1.30.2 -> 1.30.3; nginxMainline: 1.31.1 -> 1.31.2 2026-06-18 15:26:52 +00:00
whispers
308c3c352c nginx: 1.30.1 -> 1.30.2
Changelog: https://nginx.org/en/CHANGES-1.30
Advisory: https://my.f5.com/manage/s/article/K000161377

Fixes: CVE-2026-9256
2026-05-22 23:04:34 -04:00
Sandro Jäckel
562cb7f3e8 nginx: 1.30.0 -> 1.30.1 2026-05-13 21:36:55 +02:00
Thomas Gerbet
1cdef430f7 nginx: 1.28.3 -> 1.30.0
https://nginx.org/en/CHANGES-1.30

The build now uses OpenSSL 4.0 to allow usage of ECH
https://blog.nginx.org/blog/encrypted-client-hello-comes-to-nginx
2026-04-22 09:44:27 +02:00
Leona Maroni
4c0833faf6 nginx: 1.28.2 -> 1.28.3
https://github.com/nginx/nginx/releases/tag/release-1.28.3
https://nginx.org/en/CHANGES-1.28

fixes:
  - CVE-2026-27654
  - CVE-2026-27784
  - CVE-2026-32647
  - CVE-2026-27651
  - CVE-2026-28753
  - CVE-2026-28755
2026-03-24 21:03:59 +01:00
Joachim Ernst
a71a5c9f29 nginxStable: 1.28.0 -> 1.28.2 2026-02-05 11:46:50 +01:00
Thomas Gerbet
bfd9268302 nginxMainline: 1.27.5 -> 1.29.1
This change was already accepted in #433600 but reverted in
106b1418bc.

Changes:
```
Changes with nginx 1.29.1                                        13 Aug 2025

    *) Security: processing of a specially crafted login/password when using
       the "none" authentication method in the ngx_mail_smtp_module might
       cause worker process memory disclosure to the authentication server
       (CVE-2025-53859).

    *) Change: now TLSv1.3 certificate compression is disabled by default.

    *) Feature: the "ssl_certificate_compression" directive.

    *) Feature: support for 0-RTT in QUIC when using OpenSSL 3.5.1 or newer.

    *) Bugfix: the 103 response might be buffered when using HTTP/2 and the
       "early_hints" directive.

    *) Bugfix: in handling "Host" and ":authority" header lines with equal
       values when using HTTP/2; the bug had appeared in 1.17.9.

    *) Bugfix: in handling "Host" header lines with a port when using
       HTTP/3.

    *) Bugfix: nginx could not be built on NetBSD 10.0.

    *) Bugfix: in the "none" parameter of the "smtp_auth" directive.

Changes with nginx 1.29.0                                        24 Jun 2025

    *) Feature: support for response code 103 from proxy and gRPC backends;
       the "early_hints" directive.

    *) Feature: loading of secret keys from hardware tokens with OpenSSL
       provider.

    *) Feature: support for the "so_keepalive" parameter of the "listen"
       directive on macOS.

    *) Change: the logging level of SSL errors in a QUIC handshake has been
       changed from "error" to "crit" for critical errors, and to "info" for
       the rest; the logging level of unsupported QUIC transport parameters
       has been lowered from "info" to "debug".

    *) Change: the native nginx/Windows binary release is now built using
       Windows SDK 10.

    *) Bugfix: nginx could not be built by gcc 15 if ngx_http_v2_module or
       ngx_http_v3_module modules were used.

    *) Bugfix: nginx might not be built by gcc 14 or newer with -O3 -flto
       optimization if ngx_http_v3_module was used.

    *) Bugfixes and improvements in HTTP/3.
```
2025-08-23 11:03:51 +02:00
Thomas Gerbet
9422c3c214 nginx: 1.26.3 -> 1.28.0
https://nginx.org/en/CHANGES-1.28
2025-04-24 11:57:59 +02:00
Raito Bezarius
9490b4e085 nginxStable: 1.26.2 -> 1.26.3
Due to https://www.openwall.com/lists/oss-security/2025/02/05/8.

Fix CVE-2025-23419.

Change-Id: I2a341a55467ee67f77f0b133a8e9d3e6243249eb
Signed-off-by: Raito Bezarius <masterancpp@gmail.com>
2025-02-11 02:53:54 +01:00
Silvan Mosberger
4f0dadbf38 treewide: format all inactive Nix files
After final improvements to the official formatter implementation,
this commit now performs the first treewide reformat of Nix files using it.
This is part of the implementation of RFC 166.

Only "inactive" files are reformatted, meaning only files that
aren't being touched by any PR with activity in the past 2 months.
This is to avoid conflicts for PRs that might soon be merged.
Later we can do a full treewide reformat to get the rest,
which should not cause as many conflicts.

A CI check has already been running for some time to ensure that new and
already-formatted files are formatted, so the files being reformatted here
should also stay formatted.

This commit was automatically created and can be verified using

    nix-build a08b3a4d19.tar.gz \
      --argstr baseRev b32a094368
    result/bin/apply-formatting $NIXPKGS_PATH
2024-12-10 20:26:33 +01:00
Thomas Gerbet
a46766ea91 nginx: 1.26.1 -> 1.26.2
Fixes CVE-2024-7347

Changes:
https://nginx.org/en/CHANGES-1.26
2024-08-15 19:53:39 +02:00
Thomas Gerbet
25e4a15f2a nginx: 1.26.0 -> 1.26.1
Fixes CVE-2024-32760, CVE-2024-31079, CVE-2024-35200 and CVE-2024-34161.
Note that the `nginxQuic` derivation rely on `nginxMainline`.

Changes:
```
Changes with nginx 1.26.1                                        29 May 2024

    *) Security: when using HTTP/3, processing of a specially crafted QUIC
       session might cause a worker process crash, worker process memory
       disclosure on systems with MTU larger than 4096 bytes, or might have
       potential other impact (CVE-2024-32760, CVE-2024-31079,
       CVE-2024-35200, CVE-2024-34161).
       Thanks to Nils Bars of CISPA.

    *) Bugfix: reduced memory consumption for long-lived requests if "gzip",
       "gunzip", "ssi", "sub_filter", or "grpc_pass" directives are used.

    *) Bugfix: nginx could not be built by gcc 14 if the --with-atomic
       option was used.
       Thanks to Edgar Bonet.

    *) Bugfix: in HTTP/3.

```
2024-05-31 11:30:28 +02:00
Thomas Gerbet
73d98d9b4a nginxStable: 1.24.0 -> 1.26.0
Changes
http://nginx.org/en/CHANGES-1.26

The 1.24.x branch is now considered EOL.
2024-04-26 23:10:10 +02:00
ajs124
58cb284c0e nginxStable: 1.22.1 -> 1.24.0 2023-04-11 22:11:07 +02:00
ajs124
8be794b197 nginx: sha256 -> hash 2023-04-03 12:40:49 +02:00
Izorkin
2392241c0b nginxStable: 1.22.0 -> 1.22.1 2022-10-20 22:05:06 +03:00
ajs124
14ef375cf0 nginxStable: 1.20.2 -> 1.22.0 2022-05-30 11:58:28 +02:00
Robert Scott
6951ba02f4 nginxStable: add patch for CVE-2021-3618 2022-04-16 17:18:05 +01:00
ajs124
1fc113f0df nginxStable: 1.20.1 -> 1.20.2 2021-11-16 17:17:12 +01:00
Izorkin
919dd5497a nginxStable: 1.20.0 -> 1.20.1 2021-05-25 19:53:58 +03:00
Izorkin
f4b6314e60 nginxStable: 1.18.0 -> 1.20.0 2021-04-21 00:10:28 +03:00
Izorkin
2e6cd807d7 nginxStable: 1.16.1 -> 1.18.0 2020-04-23 14:34:13 +03:00
Emily
6d046e1079 openresty: rebase on top of nginx package
The primary motivation of this change was to allow third-party modules
to be used with OpenResty, but it also results in a significant
reduction of code duplication.
2020-02-04 19:30:40 -06:00
Izorkin
aec55db737 nginxStable: 1.16.0 -> 1.16.1 2019-08-13 21:30:08 +03:00
Izorkin
65a736064a nginxStable: 1.14.2 -> 1.16.0 2019-04-30 07:56:23 +03:00
Alyssa Ross
703827f36c nginx: 1.14.1 -> 1.14.2 2018-12-05 10:56:06 -06:00
Alyssa Ross
1908322d10 nginxStable: 1.14.0 -> 1.14.1
CVE-2018-16843, CVE-2018-16844

https://nginx.org/en/security_advisories.html
2018-11-15 17:51:51 +00:00
Michael Raskin
36f9b216eb nginxStable: 1.12.2 -> 1.14.0 2018-05-02 02:46:52 +02:00
Franz Pletz
0f0fcf84ce nginx: 1.12.1 -> 1.12.2 2017-10-24 16:06:51 +02:00
Franz Pletz
6e1aaeacfc nginx: 1.12.0 -> 1.12.1 for CVE-2017-7529 2017-07-14 00:03:41 +02:00
Robin Gloster
4a83c099e1 nginx: 1.10.3 -> 1.12.0 2017-05-23 11:37:57 +02:00
Michael Raskin
846007b8db nginx: 1.10.2 -> 1.10.3 2017-02-01 19:28:45 +01:00
Franz Pletz
4ae2189d8c nginx: 1.10.1 -> 1.10.2 2016-10-24 18:10:14 +02:00
Franz Pletz
b5daad4268 nginx: refactor and add mainline version
Upstream calls the unstable version mainline.
2016-07-19 01:20:49 +02:00