Commit Graph

913377 Commits

Author SHA1 Message Date
R. Ryantm
28bb283f0c rabbitmq-server: 4.2.1 -> 4.2.2
(cherry picked from commit 8b7c2c79a8)
2026-05-29 09:51:28 +00:00
Thomas Gerbet
9b13fccc93 [25.11] coredns: 1.13.2 -> 1.14.3 (#521975) 2026-05-29 08:57:48 +00:00
Thomas Gerbet
d73e6d6015 [Backport release-25.11] fastnetmon: 2.0.372 -> 2.0.380 (#524877) 2026-05-29 08:42:19 +00:00
Florian Klink
c171c7e29b python3Packages.authlib: 1.6.11 -> 1.6.12 (#525380) 2026-05-29 06:42:53 +00:00
nixpkgs-ci[bot]
c1a577a526 [Backport release-25.11] wivrn: wrap dashboard with adb for wired functions (#525438) 2026-05-29 06:37:06 +00:00
Lyna
168bfc1046 wivrn: wrap server with adb for wired functionality
(cherry picked from commit c1b7cc0456)
2026-05-29 06:16:18 +00:00
Martin Weinelt
5fc22307ff [Backport release-25.11] thunderbird-esr: 140.7.2esr -> 140.11.1esr (#524920) 2026-05-29 00:36:52 +00:00
Emily
6583af8c67 [Backport release-25.11] ungoogled-chromium: 148.0.7778.178-1 -> 148.0.7778.215-1 (#525401) 2026-05-29 00:28:55 +00:00
networkException
a762478177 ungoogled-chromium: 148.0.7778.178-1 -> 148.0.7778.215-1
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html

This update includes 151 security fixes.

CVEs:
CVE-2026-9872 CVE-2026-9873 CVE-2026-9874 CVE-2026-9875 CVE-2026-9876
CVE-2026-9877 CVE-2026-9878 CVE-2026-9879 CVE-2026-9880 CVE-2026-9881
CVE-2026-9882 CVE-2026-9883 CVE-2026-9884 CVE-2026-9885 CVE-2026-9886
CVE-2026-9887 CVE-2026-9888 CVE-2026-9889 CVE-2026-9890 CVE-2026-9891
CVE-2026-9892 CVE-2026-9893 CVE-2026-9894 CVE-2026-9895 CVE-2026-9896
CVE-2026-9897 CVE-2026-9898 CVE-2026-9899 CVE-2026-9900 CVE-2026-9901
CVE-2026-9902 CVE-2026-9903 CVE-2026-9904 CVE-2026-9905 CVE-2026-9906
CVE-2026-9907 CVE-2026-9908 CVE-2026-9909 CVE-2026-9910 CVE-2026-9911
CVE-2026-9912 CVE-2026-9913 CVE-2026-9914 CVE-2026-9915 CVE-2026-9916
CVE-2026-9917 CVE-2026-9918 CVE-2026-9919 CVE-2026-9920 CVE-2026-9921
CVE-2026-9922 CVE-2026-9923 CVE-2026-9924 CVE-2026-9925 CVE-2026-9926
CVE-2026-9927 CVE-2026-9928 CVE-2026-9929 CVE-2026-9930 CVE-2026-9931
CVE-2026-9932 CVE-2026-9933 CVE-2026-9934 CVE-2026-9935 CVE-2026-9936
CVE-2026-9937 CVE-2026-9938 CVE-2026-9939 CVE-2026-9940 CVE-2026-9941
CVE-2026-9942 CVE-2026-9943 CVE-2026-9944 CVE-2026-9945 CVE-2026-9946
CVE-2026-9947 CVE-2026-9948 CVE-2026-9949 CVE-2026-9950 CVE-2026-9951
CVE-2026-9952 CVE-2026-9953 CVE-2026-9954 CVE-2026-9955 CVE-2026-9956
CVE-2026-9957 CVE-2026-9958 CVE-2026-9959 CVE-2026-9960 CVE-2026-9961
CVE-2026-9962 CVE-2026-9963 CVE-2026-9964 CVE-2026-9965 CVE-2026-9966
CVE-2026-9967 CVE-2026-9968 CVE-2026-9969 CVE-2026-9970 CVE-2026-9971
CVE-2026-9972 CVE-2026-9973 CVE-2026-9974 CVE-2026-9975 CVE-2026-9976
CVE-2026-9977 CVE-2026-9978 CVE-2026-9979 CVE-2026-9980 CVE-2026-9981
CVE-2026-9982 CVE-2026-9983 CVE-2026-9984 CVE-2026-9985 CVE-2026-9986
CVE-2026-9987 CVE-2026-9988 CVE-2026-9989 CVE-2026-9990 CVE-2026-9991
CVE-2026-9992 CVE-2026-9993 CVE-2026-9994 CVE-2026-9995 CVE-2026-9996
CVE-2026-9997 CVE-2026-9998 CVE-2026-9999 CVE-2026-10000 CVE-2026-10001
CVE-2026-10002 CVE-2026-10003 CVE-2026-10004 CVE-2026-10005
CVE-2026-10006 CVE-2026-10007 CVE-2026-10008 CVE-2026-10009
CVE-2026-10010 CVE-2026-10011 CVE-2026-10012 CVE-2026-10013
CVE-2026-10014 CVE-2026-10015 CVE-2026-10016 CVE-2026-10017
CVE-2026-10018 CVE-2026-10019 CVE-2026-10020 CVE-2026-10021
CVE-2026-10022

(cherry picked from commit 86522e097a)
2026-05-29 00:19:07 +00:00
Thomas Gerbet
ba14f8964c [Backport release-25.11] wireshark{,-cli}: 4.6.5 -> 4.6.6 (#525372) 2026-05-28 23:19:59 +00:00
Thomas Gerbet
260f6d3429 [Backport release-25.11] distribution: 3.0.0 -> 3.1.0 (#523325) 2026-05-28 23:14:06 +00:00
Robert Schütz
353c774912 python3Packages.authlib: 1.6.11 -> 1.6.12
Diff: https://github.com/lepture/authlib/compare/v1.6.11...v1.6.12

Changelog: https://github.com/lepture/authlib/blob/v1.6.12/docs/changelog.rst
2026-05-28 15:59:42 -07:00
Thomas Gerbet
1e108cb439 [Backport release-25.11] warpgate: 0.18.0 -> 0.23.4 (#520399) 2026-05-28 22:32:43 +00:00
Gaétan Lepage
fb55d4c723 [Backport release-25.11] python3Packages.vllm: mark insecure (#525145) 2026-05-28 22:15:28 +00:00
Ryan Omasta
cfb6193746 wireshark{,-cli}: 4.6.5 -> 4.6.6
https://www.wireshark.org/docs/relnotes/wireshark-4.6.6.html
Diff: https://gitlab.com/wireshark/wireshark/-/compare/v4.6.5...v4.6.6
(cherry picked from commit 1c88add0ef)
2026-05-28 22:15:09 +00:00
Thomas Gerbet
31e9aeaf5d [25.11] libsolv: 0.7.35 -> 0.7.37 (#523789) 2026-05-28 21:45:37 +00:00
Michael Daniels
9ccbaff36b [Backport release-25.11] gh: 2.83.2 ->2.93.0 (#525068) 2026-05-28 21:03:01 +00:00
Leona Maroni
6a56c55837 [Backport release-25.11] gitlab: 18.11.3 -> 18.11.4 (#525229) 2026-05-28 21:00:46 +00:00
Jhonas Wernery
523fd44e8f [Backport release-25.11] docker: 29.5.1 -> 29.5.2 (#525319) 2026-05-28 20:49:56 +00:00
Thomas Gerbet
978ec369f9 [25.11] gitoxide: 0.45.0 -> 0.54.0 (#524891) 2026-05-28 20:36:55 +00:00
R. Ryantm
469854aaee docker: 29.5.1 -> 29.5.2
(cherry picked from commit e5b4a4fa18)
2026-05-28 18:58:02 +00:00
Jhonas Wernery
bb6c2fc65d [Backport release-25.11] penpot-desktop: 0.23.0 -> 0.23.1 (#525161) 2026-05-28 18:48:36 +00:00
Jhonas Wernery
19bbb48fdf [25.11] electron-source.electron_39: remove, electron_39-bin: mark as insecure (#525204) 2026-05-28 18:42:52 +00:00
nixpkgs-ci[bot]
3e45202cfe [Backport release-25.11] karakeep: 0.31.0 -> 0.32.0 (#525040) 2026-05-28 18:39:39 +00:00
Emily
335a142912 [Backport release-25.11] chromium,chromedriver: 148.0.7778.178 -> 148.0.7778.216 (#525233) 2026-05-28 17:50:19 +00:00
emilylange
14c799ab61 chromium,chromedriver: 148.0.7778.178 -> 148.0.7778.216
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html
(cherry picked from commit ffc6db2fe6)
2026-05-28 14:59:17 +00:00
yaya
7ec241eecf gitlab: 18.11.3 -> 18.11.4
https://gitlab.com/gitlab-org/gitlab/-/blob/v18.11.4-ee/CHANGELOG.md
(cherry picked from commit cec4baa1d7)
2026-05-28 14:38:30 +00:00
nixpkgs-ci[bot]
4d66785aca [Backport release-25.11] git-absorb: install nushell completion (#525196) 2026-05-28 13:46:15 +00:00
teutat3s
7632d65175 electron_39-bin: mark as insecure
(cherry picked from commit 4e2f3b4904)
2026-05-28 14:42:38 +02:00
teutat3s
c1c813b80d electron-source.electron_39: remove
(cherry picked from commit 65b67d5ec1)
2026-05-28 14:42:35 +02:00
Kristoffer Plagborg Bak Sørensen
ca49d349d8 git-absorb: install nushell completion
(cherry picked from commit 4b43c64139)
2026-05-28 12:24:24 +00:00
yaya
d3de62524a [Backport release-25.11] liferea: 1.16.9 -> 1.16.10 (#525171) 2026-05-28 11:25:01 +00:00
Sergei Trofimovich
2f31d1a645 liferea: 1.16.9 -> 1.16.10
Changes: https://github.com/lwindolf/liferea/releases/tag/v1.16.10
(cherry picked from commit 7a5669f0f2)
2026-05-28 11:02:45 +00:00
Jhonas Wernery
982bae1fbe [Backport release-25.11] matrix-authentication-service: 1.16.0 -> 1.17.0 (#524994) 2026-05-28 10:41:42 +00:00
NTBBloodbath
29f7f59f23 penpot-desktop: 0.23.0 -> 0.23.1
(cherry picked from commit 599cef92f5)
2026-05-28 10:28:21 +00:00
Jhonas Wernery
b7cde3237b [Backport release-25.11] docker_25: 25.0.13 -> 25.0.16 (#524110) 2026-05-28 10:19:32 +00:00
Robert Schütz
67b1d435f3 python3Packages.vllm: mark insecure
(cherry picked from commit 1d8573f85c)
2026-05-28 09:13:42 +00:00
Martin Weinelt
f5190b6928 libredwg: 0.13.3 -> 0.13.4.8200 [backport release-25.11] (#525062) 2026-05-28 03:00:49 +02:00
Martin Weinelt
f52c223fcf [release-25.11] samba: 4.22.6 -> 4.22.10 (#525060) 2026-05-27 23:30:23 +00:00
Thorsten Weber
85ca4154fd libredwg: 0.13.4 -> 0.13.4.8200
Update to latest pre-release to fix multiple security vulnerabilities:

- CVE-2026-9500: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9501: heap-buffer-overflow in decode.c (read_2004_compressed_section)
- CVE-2026-9502: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9503: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9504: null pointer dereference in dwggrep.c (main)
- CVE-2026-9529: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9530: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9605: heap-buffer-overflow in decode.c (decompress_R2004_section)

Individual backports were not feasible as the decompressor was significantly
refactored on upstream's main branch between 0.13.4 and the fixes.

(cherry picked from commit b27ee09e7d)
2026-05-28 01:28:39 +02:00
R. Ryantm
0269512e78 libredwg: 0.13.3 -> 0.13.4
(cherry picked from commit 34faa0cb06)
2026-05-28 01:28:26 +02:00
Martin Weinelt
11c8668ea4 samba: 4.22.6 -> 4.22.10
https://www.samba.org/samba/history/samba-4.22.7.html
https://www.samba.org/samba/history/samba-4.22.8.html
https://www.samba.org/samba/history/samba-4.22.9.html
https://www.samba.org/samba/history/samba-4.22.10.html

Fixes:
CVE-2026-1933, CVE-2026-2340, CVE-2026-3012, CVE-2026-3238,
CVE-2026-4408, CVE-2026-4480
2026-05-28 01:20:46 +02:00
Michael Daniels
8ce8853ff1 gh: 2.92.0 -> 2.93.0
Diff: https://github.com/cli/cli/compare/v2.92.0...v2.93.0

Changelog: https://github.com/cli/cli/releases/tag/v2.93.0
(cherry picked from commit 3b0e4f9cbd)
2026-05-27 18:55:28 -04:00
Marie Ramlow
bd623dbb5e gh: use --set-default for GH_TELEMETRY env var
(cherry picked from commit b120931e57)
2026-05-27 18:55:27 -04:00
2kybe3
d954bef262 gh: 2.91.0 -> 2.92.0
Diff: https://github.com/cli/cli/compare/v2.91.0...v2.92.0
Changelog: https://github.com/cli/cli/releases/tag/v2.92.0
(cherry picked from commit 5437e4e349)
2026-05-27 18:55:27 -04:00
Benedikt Ritter
c33441ba73 gh: opt out of telemetry collection by default
Starting with release 2.91.0 gh sends pseudonymized telemetry data to
GitHub. Disabling it requires and explicit opt-out.

Context: https://github.blog/changelog/2026-04-22-github-cli-opt-out-usage-telemetry/

This changes makes telemetry collection opt in. If users really want to
share data with GitHub, they can `overrideAttrs` and explicitly set the
new `enableTelemetry` parameter to `true`.

(cherry picked from commit ec7f8fa480)
2026-05-27 18:55:27 -04:00
Michael Daniels
848cbe5f0a gh: 2.90.0 -> 2.91.0
Diff: https://github.com/cli/cli/compare/v2.90.0...v2.91.0

Changelog: https://github.com/cli/cli/releases/tag/v2.91.0
(cherry picked from commit e13ba8eaf2)
2026-05-27 18:55:27 -04:00
R. Ryantm
2dc04799ed gh: 2.89.0 -> 2.90.0
(cherry picked from commit 35174fd4ed)
2026-05-27 18:55:27 -04:00
R. Ryantm
d3b4bee0a5 gh: 2.88.1 -> 2.89.0
(cherry picked from commit f33adc6b7b)
2026-05-27 18:55:25 -04:00
Sav Tripodi
89eeb0b04b gh: add maintainer savtrip
(cherry picked from commit 7901d8a6cf)
2026-05-27 18:46:23 -04:00