Commit Graph

557968 Commits

Author SHA1 Message Date
Robert Scott
4702e63ea9 Merge pull request #306066 from LeSuisse/vault-CVE-2024-2660-knownvuln-23.11
[23.11] vault, vault-bin: add CVE-2024-2660 to the knownVulnerabilities
2024-04-23 20:07:44 +01:00
Gutyina Gergő
9f528619cd spamassassin: 4.0.0 -> 4.0.1
(cherry picked from commit e6cd455773)
2024-04-23 21:03:01 +02:00
Leona Maroni
f59828987d Merge pull request #306332 from NixOS/backport-306326-to-release-23.11
[Backport release-23.11] matrix-synapse: 1.105.0 -> 1.105.1
2024-04-23 20:03:17 +02:00
teutat3s
6a838a12d5 matrix-synapse: 1.105.0 -> 1.105.1
https://github.com/element-hq/synapse/releases/tag/v1.105.1
(cherry picked from commit 3257ce1b86)
2024-04-23 17:37:39 +00:00
Nick Cao
7bc17193af Merge pull request #306269 from NixOS/backport-305731-to-release-23.11
[Backport release-23.11] stats: 2.10.7 -> 2.10.10
2024-04-23 09:38:23 -04:00
DontEatOreo
a15d3e9b8f stats: 2.10.7 -> 2.10.10
Diff: https://github.com/exelban/stats/compare/v2.10.7...v2.10.10
Changelog: https://github.com/exelban/stats/releases/tag/v2.10.10
(cherry picked from commit 34604d4149)
2024-04-23 11:58:39 +00:00
Jörg Thalheim
c8e8655c2e Merge pull request #306219 from NixOS/backport-305945-to-release-23.11
[Backport release-23.11] glasskube: 0.1.0 -> 0.2.0
2024-04-23 12:17:54 +02:00
Emily
8c91cd60f4 Merge pull request #306152 from NixOS/backport-306062-to-release-23.11
[Backport release-23.11] ungoogled-chromium: 123.0.6312.122-1 -> 124.0.6367.60-1
2024-04-23 10:54:07 +02:00
Jakuzure Nonon
59f2563a01 glasskube: 0.1.0 -> 0.2.0
(cherry picked from commit 9bf5100f71)
2024-04-23 08:39:09 +00:00
networkException
eb6dcc782b ungoogled-chromium: 123.0.6312.122-1 -> 124.0.6367.60-1
https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_16.html

This update includes 23 security fixes.

CVEs:
CVE-2024-3832 CVE-2024-3833 CVE-2024-3914 CVE-2024-3834 CVE-2024-3837
CVE-2024-3838 CVE-2024-3839 CVE-2024-3840 CVE-2024-3841 CVE-2024-3843
CVE-2024-3844 CVE-2024-3845 CVE-2024-3846 CVE-2024-3847

(cherry picked from commit cbe2cb9d6f)
2024-04-23 01:38:27 +00:00
Martin Weinelt
b500489fd3 Merge pull request #306102 from NixOS/backport-306019-to-release-23.11
[Backport release-23.11] Firefox: 125.0.1 -> 125.0.2
2024-04-23 01:29:01 +02:00
Jade Lovelace
09d2826438 Merge pull request #305937 from NixOS/backport-304213-to-release-23.11
[Backport release-23.11] stdenv: make inputDerivation never fixed-output
2024-04-22 14:25:40 -07:00
Martin Weinelt
07d5dd5c8d firefox-bin-unwrapped: 125.0.1 -> 125.0.2
https://www.mozilla.org/en-US/firefox/125.0.2/releasenotes/
(cherry picked from commit adb839a9ac)
2024-04-22 20:54:07 +00:00
Martin Weinelt
784caeda53 firefox-unwrapped: 125.0.1 -> 125.0.2
https://www.mozilla.org/en-US/firefox/125.0.2/releasenotes/
(cherry picked from commit 21498067f7)
2024-04-22 20:54:07 +00:00
Matthias Beyer
e9e8cbde26 Merge pull request #306089 from NixOS/backport-306063-to-release-23.11
[Backport release-23.11] cargo-semver-checks: 0.30.0 -> 0.31.0
2024-04-22 22:13:36 +02:00
R. Ryantm
57ae1f9298 cargo-semver-checks: 0.30.0 -> 0.31.0
(cherry picked from commit e4285fcc4d)
2024-04-22 19:09:20 +00:00
Matthias Beyer
8f409d8d82 Merge pull request #298312 from matthiasbeyer/backport-cargo-tools-updates-with-newer-rustc
[Backport release-23.11]: cargo-* tools updates with newer rustPlatform
2024-04-22 21:02:54 +02:00
Thomas Gerbet
d34bd5b51f vault, vault-bin: add CVE-2024-2660 to the knownVulnerabilities
Ideally we would upgrade but in this specific instance the fixed
versions (and the patch for the issue) have been relicensed under
the Business Source License which is unfree.

Tagging the packages with `knownVulnerabilities` seems to be our least
worse solution. If someone care enough I'm guessing the unfree versions
could be backported under a different names in 23.11.
2024-04-22 19:36:31 +02:00
Adam C. Stephens
202bdec8a8 Merge pull request #306041 from katexochen/envoy/1-27-5-release
envoy: 1.27.4 -> 1.27.5
2024-04-22 13:20:44 -04:00
Rick van Schijndel
bc413ca725 Merge pull request #306018 from helsinki-systems/fix/cve-2024-32657-backport
[23.11] hydra_unstable: Fix CVE-2024-32657
2024-04-22 18:56:53 +02:00
Artturi
a69432f36a Merge pull request #305998 from NixOS/backport-305758-to-release-23.11
[Backport release-23.11] discord updates
2024-04-22 18:10:56 +03:00
Janne Heß
81ae6d3689 hydra_unstable: Fix CVE-2024-32657 2024-04-22 16:45:36 +02:00
Paul Meyer
fc3602b7e2 envoy: unpin Go version
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2024-04-22 16:34:38 +02:00
Paul Meyer
9d94470bd0 envoy: 1.27.4 -> 1.27.5
Co-authored-by: Malte Poll <1780588+malt3@users.noreply.github.com>
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2024-04-22 16:33:54 +02:00
Artturin
bfc11101dd pkgsCross.aarch64-darwin.discord-canary: 0.0.468 -> 0.0.477
(cherry picked from commit eb11fbdab7)
2024-04-22 12:59:07 +00:00
Artturin
0d4cb79189 pkgsCross.aarch64-darwin.discord-ptb: 0.0.107 -> 0.0.109
(cherry picked from commit 38876bf2d7)
2024-04-22 12:59:07 +00:00
Artturin
90ff44f3f3 pkgsCross.aarch64-darwin.discord: 0.0.300 -> 0.0.301
(cherry picked from commit a324761827)
2024-04-22 12:59:07 +00:00
Artturin
77ef3070ea discord-canary: 0.0.346 -> 0.0.357
(cherry picked from commit 9e35527f8d)
2024-04-22 12:59:07 +00:00
Artturin
f82fa90a18 discord-ptb: 0.0.78 -> 0.0.80
(cherry picked from commit 89b8f2e298)
2024-04-22 12:59:07 +00:00
Artturin
03f703b305 discord: 0.0.49 -> 0.0.50
(cherry picked from commit 08cf70ce5a)
2024-04-22 12:59:07 +00:00
R. RyanTM
d4df7c26d0 linuxPackages.vhba: 20211218 -> 20240202
(cherry picked from commit 4084ca6c21)
2024-04-22 14:03:18 +02:00
Jade Lovelace
5dde1d006e stdenv: make inputDerivation never fixed-output
This fixes using inputDerivation on derivations that are fixed-output.

Previously:

```
nix-repl> drv = runCommand "huh" { outputHash = "sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU="; outputHashAlgo = "sha256"; outputHashType = "flat"; } "touch $out"

nix-repl> drv.inputDerivation
«derivation /nix/store/d8mjs6cmmvsr1fv7psm6imis5pmh9bcs-huh.drv»

nix-repl> :b drv.inputDerivation
error: fixed output derivation 'huh' is not allowed to refer to other store paths.
       You may need to use the 'unsafeDiscardReferences' derivation attribute, see the manual for more details.
```

Fixes: https://github.com/NixOS/nixpkgs/issues/304209
(cherry picked from commit 78945a827c)
2024-04-22 07:29:57 +00:00
Peder Bergebakken Sundt
9547e21b2e Merge pull request #305798 from NixOS/backport-289525-to-release-23.11
[Backport release-23.11] lbd: init at 0-unstable-2024-02-17
2024-04-21 21:48:43 +02:00
Tobias Mayer
a5e4bbcb47 slack: fix screen sharing on wayland
Slack blacklists the electron feature to allow screen capture via
Pipewire for unknown reasons. This change applies the same workaround
as the unofficial slack flatpack to get it working again.

(cherry picked from commit 5f6b9d7b7d)
2024-04-21 20:47:39 +02:00
D3vil0p3r
106d74cccb lbd: init at 0-unstable-2024-02-17
(cherry picked from commit 4f38e4136c)
2024-04-21 17:26:04 +00:00
superherointj
cb4064c4d6 Merge pull request #305671 from NixOS/vce_nixfmt_rfc
[Backport release-23.11] vscode-extensions: format using nixfmt-rfc-style
2024-04-21 11:31:31 -03:00
Sebastian Sellmeier
833f116f2f vscode-extensions: format using nixfmt-rfc-style 2024-04-21 15:55:57 +02:00
Sebastian Sellmeier
6cec7d924c vscode-extensions: sort arguments 2024-04-21 15:55:56 +02:00
Matthias Beyer
7daf65af3f Revert "cargo-modules: Build with rustPackages_1_76"
This reverts commit 7d28858258.
2024-04-21 14:54:47 +02:00
Matthias Beyer
a446bd881c Revert "cargo-modules: 0.11.2 -> 0.15.5"
This reverts commit ce53412a5f.
2024-04-21 14:54:44 +02:00
superherointj
8468b0786c Merge pull request #305291 from superherointj/backport-vscode-extensions-hash
[Backport release-23.11] vscode-utils: allow `hash` to be used in mktplcRef
2024-04-21 09:45:11 -03:00
aktaboot
ce53412a5f cargo-modules: 0.11.2 -> 0.15.5
skip failing tests

(cherry picked from commit 821fa71ddf)
Signed-off-by: Matthias Beyer <mail@beyermatthias.de>
2024-04-21 14:39:33 +02:00
Matthias Beyer
7d28858258 cargo-modules: Build with rustPackages_1_76
Signed-off-by: Matthias Beyer <mail@beyermatthias.de>
2024-04-21 14:38:25 +02:00
Pol Dellaiera
674372ad22 Merge pull request #305687 from NixOS/backport-305647-to-release-23.11
[Backport release-23.11] phpPackages.composer: 2.7.2 -> 2.7.3
2024-04-21 10:37:33 +02:00
Thomas Gerbet
c0454d6d68 phpPackages.composer: 2.7.2 -> 2.7.3
Changes:
https://github.com/composer/composer/releases/tag/2.7.3
(cherry picked from commit f30d13d04a)
2024-04-21 07:39:36 +00:00
Pol Dellaiera
71210116ac Merge pull request #305680 from NixOS/backport-295156-to-release-23.11
[Backport release-23.11] phpPackages.composer: 2.7.1 -> 2.7.2
2024-04-21 09:38:39 +02:00
Thomas Gerbet
f0bb439861 phpPackages.composer: 2.7.1 -> 2.7.2
Changes:
https://github.com/composer/composer/releases/tag/2.7.2
(cherry picked from commit b80593840b)
2024-04-21 07:02:41 +00:00
Bjørn Forsman
74574c3857 nixos/deconz: fix curl redirect option in postStart
It should be curl -L (follow redirects), not curl -l (FTP directory
listing option). I know because it's my mistake.

Fixes: d4b989cafc ("nixos/deconz: delay signalling service readiness until it's actually up")
(cherry picked from commit 30a62716b5)
2024-04-20 20:36:29 +02:00
Bjørn Forsman
0162798a2d nixos/deconz: delay signalling service readiness until it's actually up
Fixes test flakiness (`nix-build -A nixosTests.deconz`).

(cherry picked from commit e99ef7b970)
2024-04-20 20:25:50 +02:00
superherointj
404c2a2350 Merge pull request #304076 from NixOS/backport-304053-to-release-23.11
[Backport release-23.11] raycast: fix passthru.updateScript
2024-04-20 13:47:31 -03:00