Commit Graph

2474 Commits

Author SHA1 Message Date
R. Ryantm
407a72068d tomcat9: 9.0.108 -> 9.0.109 2025-09-07 05:22:20 +00:00
R. Ryantm
a77e6da395 tomcat: 11.0.10 -> 11.0.11 2025-09-05 21:27:25 +00:00
dish
ec9857885d jetty: 12.0.25 -> 12.1.0 (#437398) 2025-08-28 22:59:15 -04:00
R. Ryantm
1d5f62e366 jetty: 12.0.25 -> 12.1.0 2025-08-27 05:08:41 +00:00
dish
4acde7282a couchdb: use quickjs instead of spidermonkey
Allows us to drop spidermonkey_91, which reached EOL years ago. We won't
switch to the latest supported spidermonkey version for couchdb(128)
because as of commit its support ends in 3 weeks, so there would be no
use trying to update it again after this. Better to just switch now and
avoid pain in the future.
2025-08-25 19:29:13 -04:00
Thomas Gerbet
bfd9268302 nginxMainline: 1.27.5 -> 1.29.1
This change was already accepted in #433600 but reverted in
106b1418bc.

Changes:
```
Changes with nginx 1.29.1                                        13 Aug 2025

    *) Security: processing of a specially crafted login/password when using
       the "none" authentication method in the ngx_mail_smtp_module might
       cause worker process memory disclosure to the authentication server
       (CVE-2025-53859).

    *) Change: now TLSv1.3 certificate compression is disabled by default.

    *) Feature: the "ssl_certificate_compression" directive.

    *) Feature: support for 0-RTT in QUIC when using OpenSSL 3.5.1 or newer.

    *) Bugfix: the 103 response might be buffered when using HTTP/2 and the
       "early_hints" directive.

    *) Bugfix: in handling "Host" and ":authority" header lines with equal
       values when using HTTP/2; the bug had appeared in 1.17.9.

    *) Bugfix: in handling "Host" header lines with a port when using
       HTTP/3.

    *) Bugfix: nginx could not be built on NetBSD 10.0.

    *) Bugfix: in the "none" parameter of the "smtp_auth" directive.

Changes with nginx 1.29.0                                        24 Jun 2025

    *) Feature: support for response code 103 from proxy and gRPC backends;
       the "early_hints" directive.

    *) Feature: loading of secret keys from hardware tokens with OpenSSL
       provider.

    *) Feature: support for the "so_keepalive" parameter of the "listen"
       directive on macOS.

    *) Change: the logging level of SSL errors in a QUIC handshake has been
       changed from "error" to "crit" for critical errors, and to "info" for
       the rest; the logging level of unsupported QUIC transport parameters
       has been lowered from "info" to "debug".

    *) Change: the native nginx/Windows binary release is now built using
       Windows SDK 10.

    *) Bugfix: nginx could not be built by gcc 15 if ngx_http_v2_module or
       ngx_http_v3_module modules were used.

    *) Bugfix: nginx might not be built by gcc 14 or newer with -O3 -flto
       optimization if ngx_http_v3_module was used.

    *) Bugfixes and improvements in HTTP/3.
```
2025-08-23 11:03:51 +02:00
K900
e9a7500b70 Merge remote-tracking branch 'origin/master' into staging-next 2025-08-23 09:24:59 +03:00
R. Ryantm
b36e2faecb angie: 1.10.1 -> 1.10.2 2025-08-22 13:07:17 +00:00
K900
041aa01117 Merge remote-tracking branch 'origin/master' into staging-next 2025-08-21 15:22:18 +03:00
Thomas Gerbet
30ba499421 jetty_12: 12.0.23 -> 12.0.25
Fixes CVE-2025-5115 / https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h

Changes:
https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.25
https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.24
2025-08-21 14:18:48 +02:00
nixpkgs-ci[bot]
fd41c5f912 Merge master into staging-next 2025-08-17 00:19:15 +00:00
R. Ryantm
31bd086141 jetty_11: 11.0.25 -> 11.0.26 2025-08-16 21:09:51 +02:00
Martin Weinelt
106b1418bc Revert "Merge remote-tracking branch 'origin/master' into staging-next"
This reverts commit 28cafe5795, reversing
changes made to 281c9189d4.

Broken merge due to mergiraf removing many newlines from
python-packages.nix.
2025-08-15 13:58:54 +02:00
Franz Pletz
2e118025da nginxMainline: 1.27.5 -> 1.29.1 (#433600) 2025-08-15 10:49:55 +02:00
Franz Pletz
fbf7c69d78 nginx: apply patch for CVE-2025-53859 (#433604) 2025-08-14 23:55:12 +02:00
Thomas Gerbet
cca6e62d32 nginx: apply patch for CVE-2025-53859
https://www.openwall.com/lists/oss-security/2025/08/13/5
2025-08-14 11:10:10 +02:00
Thomas Gerbet
a93581ee44 nginxMainline: 1.27.5 -> 1.29.1
Fixes CVE-2025-53859

Changes:
```
Changes with nginx 1.29.1                                        13 Aug 2025

    *) Security: processing of a specially crafted login/password when using
       the "none" authentication method in the ngx_mail_smtp_module might
       cause worker process memory disclosure to the authentication server
       (CVE-2025-53859).

    *) Change: now TLSv1.3 certificate compression is disabled by default.

    *) Feature: the "ssl_certificate_compression" directive.

    *) Feature: support for 0-RTT in QUIC when using OpenSSL 3.5.1 or newer.

    *) Bugfix: the 103 response might be buffered when using HTTP/2 and the
       "early_hints" directive.

    *) Bugfix: in handling "Host" and ":authority" header lines with equal
       values when using HTTP/2; the bug had appeared in 1.17.9.

    *) Bugfix: in handling "Host" header lines with a port when using
       HTTP/3.

    *) Bugfix: nginx could not be built on NetBSD 10.0.

    *) Bugfix: in the "none" parameter of the "smtp_auth" directive.

Changes with nginx 1.29.0                                        24 Jun 2025

    *) Feature: support for response code 103 from proxy and gRPC backends;
       the "early_hints" directive.

    *) Feature: loading of secret keys from hardware tokens with OpenSSL
       provider.

    *) Feature: support for the "so_keepalive" parameter of the "listen"
       directive on macOS.

    *) Change: the logging level of SSL errors in a QUIC handshake has been
       changed from "error" to "crit" for critical errors, and to "info" for
       the rest; the logging level of unsupported QUIC transport parameters
       has been lowered from "info" to "debug".

    *) Change: the native nginx/Windows binary release is now built using
       Windows SDK 10.

    *) Bugfix: nginx could not be built by gcc 15 if ngx_http_v2_module or
       ngx_http_v3_module modules were used.

    *) Bugfix: nginx might not be built by gcc 14 or newer with -O3 -flto
       optimization if ngx_http_v3_module was used.

    *) Bugfixes and improvements in HTTP/3.
```
2025-08-14 10:48:12 +02:00
R. Ryantm
83432fe506 tomcat10: 10.1.43 -> 10.1.44 2025-08-10 10:26:17 +00:00
R. Ryantm
a58f01c29f tomcat9: 9.0.107 -> 9.0.108 2025-08-09 13:29:16 +02:00
Yohann Boniface
9f95d354f7 tomcat: 11.0.9 -> 11.0.10 (#431904) 2025-08-08 21:58:00 +02:00
Vladimír Čunát
38638f66c2 apacheHttpd: 2.6.62 -> 2.6.65 (#424369) 2025-08-08 09:29:17 +02:00
R. Ryantm
0d90820359 tomcat: 11.0.9 -> 11.0.10 2025-08-08 01:32:35 +00:00
Weijia Wang
0cbce5bea9 angie: 1.9.1 -> 1.10.1 (#422574) 2025-08-03 16:10:29 -06:00
Wolfgang Walther
5a0711127c treewide: run nixfmt 1.0.0 2025-07-24 13:55:40 +02:00
Thomas Gerbet
29b0c59178 apacheHttpd: 2.6.62 -> 2.6.65
Fixes CVE-2025-53020, CVE-2025-49812, CVE-2025-49630, CVE-2025-23048, CVE-2024-47252,
CVE-2024-43204 and CVE-2024-42516.

https://dlcdn.apache.org/httpd/CHANGES_2.4.64
https://dlcdn.apache.org/httpd/CHANGES_2.4.65
2025-07-24 08:27:11 +02:00
Thomas Gerbet
82aed1e3a4 tomcat11: 11.0.8 -> 11.0.9
Fixes CVE-2025-52520 and CVE-2025-53506.

https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.9
2025-07-23 21:21:15 +02:00
Thomas Gerbet
d1173a321f tomcat9: 9.0.106 -> 9.0.107
Fixes CVE-2025-52434, CVE-2025-52520 and CVE-2025-53506.

https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.107
2025-07-23 21:21:15 +02:00
mivorasu
ca35bb6872 treewide: trim whitespace in description strings 2025-07-22 23:41:42 +00:00
R. Ryantm
531ddd0ad9 angie: 1.9.1 -> 1.10.1 2025-07-22 21:00:02 +00:00
mivorasu
1e377fedf7 treewide: strip trailing punctuation from description strings 2025-07-22 19:09:42 +00:00
Paul Meyer
d312580bc9 angie-console-light: 1.4.0 -> 1.8.0 (#424037) 2025-07-14 10:27:32 +02:00
Wolfgang Walther
21e07192a5 tomcat10: 10.1.42 -> 10.1.43 (#422810) 2025-07-11 18:28:55 +00:00
R. Ryantm
b2a9f72158 angie-console-light: 1.4.0 -> 1.8.0 2025-07-10 12:30:11 +00:00
R. Ryantm
0bb47a6a7d tomcat10: 10.1.42 -> 10.1.43 2025-07-05 22:53:03 +00:00
R. Ryantm
931288980e jetty: 12.0.22 -> 12.0.23 2025-07-05 06:11:10 +00:00
Peder Bergebakken Sundt
75cf8aea64 apacheHttpdPackages.mod_python: mark broken on darwin 2025-06-27 09:31:14 +02:00
Martin Weinelt
ba16255219 nginxModules.vod: fix libxml 2.14 compat
The recovery attribute of the struct has been made deprecated.
2025-06-25 04:32:31 +02:00
Thomas Gerbet
59f474b329 tomcat9: 9.0.105 -> 9.0.106 (#417071) 2025-06-21 15:16:43 +02:00
Thomas Gerbet
8e7eb731b2 tomcat10: 10.1.41 -> 10.1.42 (#417470) 2025-06-21 15:14:42 +02:00
Thomas Gerbet
52b4f2d27c tomcat: 11.0.7 -> 11.0.8 (#416816) 2025-06-21 15:13:13 +02:00
R. Ryantm
d309d42fd5 tomcat10: 10.1.41 -> 10.1.42 2025-06-17 07:54:11 +00:00
Peder Bergebakken Sundt
8940949306 apacheHttpdPackages_2_4.mod_timestamp: fix build with gcc 14 (#415590) 2025-06-17 03:51:01 +02:00
R. Ryantm
b21c137548 tomcat9: 9.0.105 -> 9.0.106 2025-06-15 21:42:24 +00:00
R. Ryantm
77cf08ad3e tomcat: 11.0.7 -> 11.0.8 2025-06-14 22:46:13 +00:00
jopejoe1
f7cb9cf2f9 angie: 1.9.0 -> 1.9.1 (#414232) 2025-06-11 14:08:08 +02:00
Michael Daniels
f83566ac82 apacheHttpdPackages_2_4.mod_timestamp: fix build with gcc 14 2025-06-10 10:14:27 -04:00
R. Ryantm
e613166d54 jetty: 12.0.21 -> 12.0.22 2025-06-06 11:16:19 +00:00
R. Ryantm
7537804387 angie: 1.9.0 -> 1.9.1 2025-06-05 12:36:13 +00:00
Aaron Andersen
b89155042c tomcat-native: 2.0.8 -> 2.0.9 (#412788) 2025-06-02 22:57:16 -04:00
Wolfgang Walther
00b09ef1fc couchdb3: 3.4.3 -> 3.5.0 (#404787) 2025-06-01 10:17:14 +00:00