R. Ryantm
28bb283f0c
rabbitmq-server: 4.2.1 -> 4.2.2
...
(cherry picked from commit 8b7c2c79a8 )
2026-05-29 09:51:28 +00:00
Thomas Gerbet
9b13fccc93
[25.11] coredns: 1.13.2 -> 1.14.3 ( #521975 )
2026-05-29 08:57:48 +00:00
Thomas Gerbet
d73e6d6015
[Backport release-25.11] fastnetmon: 2.0.372 -> 2.0.380 ( #524877 )
2026-05-29 08:42:19 +00:00
Florian Klink
c171c7e29b
python3Packages.authlib: 1.6.11 -> 1.6.12 ( #525380 )
2026-05-29 06:42:53 +00:00
nixpkgs-ci[bot]
c1a577a526
[Backport release-25.11] wivrn: wrap dashboard with adb for wired functions ( #525438 )
2026-05-29 06:37:06 +00:00
Lyna
168bfc1046
wivrn: wrap server with adb for wired functionality
...
(cherry picked from commit c1b7cc0456 )
2026-05-29 06:16:18 +00:00
Martin Weinelt
5fc22307ff
[Backport release-25.11] thunderbird-esr: 140.7.2esr -> 140.11.1esr ( #524920 )
2026-05-29 00:36:52 +00:00
Emily
6583af8c67
[Backport release-25.11] ungoogled-chromium: 148.0.7778.178-1 -> 148.0.7778.215-1 ( #525401 )
2026-05-29 00:28:55 +00:00
networkException
a762478177
ungoogled-chromium: 148.0.7778.178-1 -> 148.0.7778.215-1
...
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html
This update includes 151 security fixes.
CVEs:
CVE-2026-9872 CVE-2026-9873 CVE-2026-9874 CVE-2026-9875 CVE-2026-9876
CVE-2026-9877 CVE-2026-9878 CVE-2026-9879 CVE-2026-9880 CVE-2026-9881
CVE-2026-9882 CVE-2026-9883 CVE-2026-9884 CVE-2026-9885 CVE-2026-9886
CVE-2026-9887 CVE-2026-9888 CVE-2026-9889 CVE-2026-9890 CVE-2026-9891
CVE-2026-9892 CVE-2026-9893 CVE-2026-9894 CVE-2026-9895 CVE-2026-9896
CVE-2026-9897 CVE-2026-9898 CVE-2026-9899 CVE-2026-9900 CVE-2026-9901
CVE-2026-9902 CVE-2026-9903 CVE-2026-9904 CVE-2026-9905 CVE-2026-9906
CVE-2026-9907 CVE-2026-9908 CVE-2026-9909 CVE-2026-9910 CVE-2026-9911
CVE-2026-9912 CVE-2026-9913 CVE-2026-9914 CVE-2026-9915 CVE-2026-9916
CVE-2026-9917 CVE-2026-9918 CVE-2026-9919 CVE-2026-9920 CVE-2026-9921
CVE-2026-9922 CVE-2026-9923 CVE-2026-9924 CVE-2026-9925 CVE-2026-9926
CVE-2026-9927 CVE-2026-9928 CVE-2026-9929 CVE-2026-9930 CVE-2026-9931
CVE-2026-9932 CVE-2026-9933 CVE-2026-9934 CVE-2026-9935 CVE-2026-9936
CVE-2026-9937 CVE-2026-9938 CVE-2026-9939 CVE-2026-9940 CVE-2026-9941
CVE-2026-9942 CVE-2026-9943 CVE-2026-9944 CVE-2026-9945 CVE-2026-9946
CVE-2026-9947 CVE-2026-9948 CVE-2026-9949 CVE-2026-9950 CVE-2026-9951
CVE-2026-9952 CVE-2026-9953 CVE-2026-9954 CVE-2026-9955 CVE-2026-9956
CVE-2026-9957 CVE-2026-9958 CVE-2026-9959 CVE-2026-9960 CVE-2026-9961
CVE-2026-9962 CVE-2026-9963 CVE-2026-9964 CVE-2026-9965 CVE-2026-9966
CVE-2026-9967 CVE-2026-9968 CVE-2026-9969 CVE-2026-9970 CVE-2026-9971
CVE-2026-9972 CVE-2026-9973 CVE-2026-9974 CVE-2026-9975 CVE-2026-9976
CVE-2026-9977 CVE-2026-9978 CVE-2026-9979 CVE-2026-9980 CVE-2026-9981
CVE-2026-9982 CVE-2026-9983 CVE-2026-9984 CVE-2026-9985 CVE-2026-9986
CVE-2026-9987 CVE-2026-9988 CVE-2026-9989 CVE-2026-9990 CVE-2026-9991
CVE-2026-9992 CVE-2026-9993 CVE-2026-9994 CVE-2026-9995 CVE-2026-9996
CVE-2026-9997 CVE-2026-9998 CVE-2026-9999 CVE-2026-10000 CVE-2026-10001
CVE-2026-10002 CVE-2026-10003 CVE-2026-10004 CVE-2026-10005
CVE-2026-10006 CVE-2026-10007 CVE-2026-10008 CVE-2026-10009
CVE-2026-10010 CVE-2026-10011 CVE-2026-10012 CVE-2026-10013
CVE-2026-10014 CVE-2026-10015 CVE-2026-10016 CVE-2026-10017
CVE-2026-10018 CVE-2026-10019 CVE-2026-10020 CVE-2026-10021
CVE-2026-10022
(cherry picked from commit 86522e097a )
2026-05-29 00:19:07 +00:00
Thomas Gerbet
ba14f8964c
[Backport release-25.11] wireshark{,-cli}: 4.6.5 -> 4.6.6 ( #525372 )
2026-05-28 23:19:59 +00:00
Thomas Gerbet
260f6d3429
[Backport release-25.11] distribution: 3.0.0 -> 3.1.0 ( #523325 )
2026-05-28 23:14:06 +00:00
Robert Schütz
353c774912
python3Packages.authlib: 1.6.11 -> 1.6.12
...
Diff: https://github.com/lepture/authlib/compare/v1.6.11...v1.6.12
Changelog: https://github.com/lepture/authlib/blob/v1.6.12/docs/changelog.rst
2026-05-28 15:59:42 -07:00
Thomas Gerbet
1e108cb439
[Backport release-25.11] warpgate: 0.18.0 -> 0.23.4 ( #520399 )
2026-05-28 22:32:43 +00:00
Gaétan Lepage
fb55d4c723
[Backport release-25.11] python3Packages.vllm: mark insecure ( #525145 )
2026-05-28 22:15:28 +00:00
Ryan Omasta
cfb6193746
wireshark{,-cli}: 4.6.5 -> 4.6.6
...
https://www.wireshark.org/docs/relnotes/wireshark-4.6.6.html
Diff: https://gitlab.com/wireshark/wireshark/-/compare/v4.6.5...v4.6.6
(cherry picked from commit 1c88add0ef )
2026-05-28 22:15:09 +00:00
Thomas Gerbet
31e9aeaf5d
[25.11] libsolv: 0.7.35 -> 0.7.37 ( #523789 )
2026-05-28 21:45:37 +00:00
Michael Daniels
9ccbaff36b
[Backport release-25.11] gh: 2.83.2 ->2.93.0 ( #525068 )
2026-05-28 21:03:01 +00:00
Leona Maroni
6a56c55837
[Backport release-25.11] gitlab: 18.11.3 -> 18.11.4 ( #525229 )
2026-05-28 21:00:46 +00:00
Jhonas Wernery
523fd44e8f
[Backport release-25.11] docker: 29.5.1 -> 29.5.2 ( #525319 )
2026-05-28 20:49:56 +00:00
Thomas Gerbet
978ec369f9
[25.11] gitoxide: 0.45.0 -> 0.54.0 ( #524891 )
2026-05-28 20:36:55 +00:00
R. Ryantm
469854aaee
docker: 29.5.1 -> 29.5.2
...
(cherry picked from commit e5b4a4fa18 )
2026-05-28 18:58:02 +00:00
Jhonas Wernery
bb6c2fc65d
[Backport release-25.11] penpot-desktop: 0.23.0 -> 0.23.1 ( #525161 )
2026-05-28 18:48:36 +00:00
Jhonas Wernery
19bbb48fdf
[25.11] electron-source.electron_39: remove, electron_39-bin: mark as insecure ( #525204 )
2026-05-28 18:42:52 +00:00
nixpkgs-ci[bot]
3e45202cfe
[Backport release-25.11] karakeep: 0.31.0 -> 0.32.0 ( #525040 )
2026-05-28 18:39:39 +00:00
Emily
335a142912
[Backport release-25.11] chromium,chromedriver: 148.0.7778.178 -> 148.0.7778.216 ( #525233 )
2026-05-28 17:50:19 +00:00
emilylange
14c799ab61
chromium,chromedriver: 148.0.7778.178 -> 148.0.7778.216
...
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html
(cherry picked from commit ffc6db2fe6 )
2026-05-28 14:59:17 +00:00
yaya
7ec241eecf
gitlab: 18.11.3 -> 18.11.4
...
https://gitlab.com/gitlab-org/gitlab/-/blob/v18.11.4-ee/CHANGELOG.md
(cherry picked from commit cec4baa1d7 )
2026-05-28 14:38:30 +00:00
nixpkgs-ci[bot]
4d66785aca
[Backport release-25.11] git-absorb: install nushell completion ( #525196 )
2026-05-28 13:46:15 +00:00
teutat3s
7632d65175
electron_39-bin: mark as insecure
...
(cherry picked from commit 4e2f3b4904 )
2026-05-28 14:42:38 +02:00
teutat3s
c1c813b80d
electron-source.electron_39: remove
...
(cherry picked from commit 65b67d5ec1 )
2026-05-28 14:42:35 +02:00
Kristoffer Plagborg Bak Sørensen
ca49d349d8
git-absorb: install nushell completion
...
(cherry picked from commit 4b43c64139 )
2026-05-28 12:24:24 +00:00
yaya
d3de62524a
[Backport release-25.11] liferea: 1.16.9 -> 1.16.10 ( #525171 )
2026-05-28 11:25:01 +00:00
Sergei Trofimovich
2f31d1a645
liferea: 1.16.9 -> 1.16.10
...
Changes: https://github.com/lwindolf/liferea/releases/tag/v1.16.10
(cherry picked from commit 7a5669f0f2 )
2026-05-28 11:02:45 +00:00
Jhonas Wernery
982bae1fbe
[Backport release-25.11] matrix-authentication-service: 1.16.0 -> 1.17.0 ( #524994 )
2026-05-28 10:41:42 +00:00
NTBBloodbath
29f7f59f23
penpot-desktop: 0.23.0 -> 0.23.1
...
(cherry picked from commit 599cef92f5 )
2026-05-28 10:28:21 +00:00
Jhonas Wernery
b7cde3237b
[Backport release-25.11] docker_25: 25.0.13 -> 25.0.16 ( #524110 )
2026-05-28 10:19:32 +00:00
Robert Schütz
67b1d435f3
python3Packages.vllm: mark insecure
...
(cherry picked from commit 1d8573f85c )
2026-05-28 09:13:42 +00:00
Martin Weinelt
f5190b6928
libredwg: 0.13.3 -> 0.13.4.8200 [backport release-25.11] ( #525062 )
2026-05-28 03:00:49 +02:00
Martin Weinelt
f52c223fcf
[release-25.11] samba: 4.22.6 -> 4.22.10 ( #525060 )
2026-05-27 23:30:23 +00:00
Thorsten Weber
85ca4154fd
libredwg: 0.13.4 -> 0.13.4.8200
...
Update to latest pre-release to fix multiple security vulnerabilities:
- CVE-2026-9500: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9501: heap-buffer-overflow in decode.c (read_2004_compressed_section)
- CVE-2026-9502: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9503: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9504: null pointer dereference in dwggrep.c (main)
- CVE-2026-9529: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9530: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9605: heap-buffer-overflow in decode.c (decompress_R2004_section)
Individual backports were not feasible as the decompressor was significantly
refactored on upstream's main branch between 0.13.4 and the fixes.
(cherry picked from commit b27ee09e7d )
2026-05-28 01:28:39 +02:00
R. Ryantm
0269512e78
libredwg: 0.13.3 -> 0.13.4
...
(cherry picked from commit 34faa0cb06 )
2026-05-28 01:28:26 +02:00
Martin Weinelt
11c8668ea4
samba: 4.22.6 -> 4.22.10
...
https://www.samba.org/samba/history/samba-4.22.7.html
https://www.samba.org/samba/history/samba-4.22.8.html
https://www.samba.org/samba/history/samba-4.22.9.html
https://www.samba.org/samba/history/samba-4.22.10.html
Fixes:
CVE-2026-1933, CVE-2026-2340, CVE-2026-3012, CVE-2026-3238,
CVE-2026-4408, CVE-2026-4480
2026-05-28 01:20:46 +02:00
Michael Daniels
8ce8853ff1
gh: 2.92.0 -> 2.93.0
...
Diff: https://github.com/cli/cli/compare/v2.92.0...v2.93.0
Changelog: https://github.com/cli/cli/releases/tag/v2.93.0
(cherry picked from commit 3b0e4f9cbd )
2026-05-27 18:55:28 -04:00
Marie Ramlow
bd623dbb5e
gh: use --set-default for GH_TELEMETRY env var
...
(cherry picked from commit b120931e57 )
2026-05-27 18:55:27 -04:00
2kybe3
d954bef262
gh: 2.91.0 -> 2.92.0
...
Diff: https://github.com/cli/cli/compare/v2.91.0...v2.92.0
Changelog: https://github.com/cli/cli/releases/tag/v2.92.0
(cherry picked from commit 5437e4e349 )
2026-05-27 18:55:27 -04:00
Benedikt Ritter
c33441ba73
gh: opt out of telemetry collection by default
...
Starting with release 2.91.0 gh sends pseudonymized telemetry data to
GitHub. Disabling it requires and explicit opt-out.
Context: https://github.blog/changelog/2026-04-22-github-cli-opt-out-usage-telemetry/
This changes makes telemetry collection opt in. If users really want to
share data with GitHub, they can `overrideAttrs` and explicitly set the
new `enableTelemetry` parameter to `true`.
(cherry picked from commit ec7f8fa480 )
2026-05-27 18:55:27 -04:00
Michael Daniels
848cbe5f0a
gh: 2.90.0 -> 2.91.0
...
Diff: https://github.com/cli/cli/compare/v2.90.0...v2.91.0
Changelog: https://github.com/cli/cli/releases/tag/v2.91.0
(cherry picked from commit e13ba8eaf2 )
2026-05-27 18:55:27 -04:00
R. Ryantm
2dc04799ed
gh: 2.89.0 -> 2.90.0
...
(cherry picked from commit 35174fd4ed )
2026-05-27 18:55:27 -04:00
R. Ryantm
d3b4bee0a5
gh: 2.88.1 -> 2.89.0
...
(cherry picked from commit f33adc6b7b )
2026-05-27 18:55:25 -04:00
Sav Tripodi
89eeb0b04b
gh: add maintainer savtrip
...
(cherry picked from commit 7901d8a6cf )
2026-05-27 18:46:23 -04:00