teutat3s
c1c813b80d
electron-source.electron_39: remove
...
(cherry picked from commit 65b67d5ec1 )
2026-05-28 14:42:35 +02:00
yaya
d3de62524a
[Backport release-25.11] liferea: 1.16.9 -> 1.16.10 ( #525171 )
2026-05-28 11:25:01 +00:00
Sergei Trofimovich
2f31d1a645
liferea: 1.16.9 -> 1.16.10
...
Changes: https://github.com/lwindolf/liferea/releases/tag/v1.16.10
(cherry picked from commit 7a5669f0f2 )
2026-05-28 11:02:45 +00:00
Jhonas Wernery
982bae1fbe
[Backport release-25.11] matrix-authentication-service: 1.16.0 -> 1.17.0 ( #524994 )
2026-05-28 10:41:42 +00:00
Jhonas Wernery
b7cde3237b
[Backport release-25.11] docker_25: 25.0.13 -> 25.0.16 ( #524110 )
2026-05-28 10:19:32 +00:00
Martin Weinelt
f5190b6928
libredwg: 0.13.3 -> 0.13.4.8200 [backport release-25.11] ( #525062 )
2026-05-28 03:00:49 +02:00
Martin Weinelt
f52c223fcf
[release-25.11] samba: 4.22.6 -> 4.22.10 ( #525060 )
2026-05-27 23:30:23 +00:00
Thorsten Weber
85ca4154fd
libredwg: 0.13.4 -> 0.13.4.8200
...
Update to latest pre-release to fix multiple security vulnerabilities:
- CVE-2026-9500: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9501: heap-buffer-overflow in decode.c (read_2004_compressed_section)
- CVE-2026-9502: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9503: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9504: null pointer dereference in dwggrep.c (main)
- CVE-2026-9529: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9530: heap-buffer-overflow in decode.c (decompress_R2004_section)
- CVE-2026-9605: heap-buffer-overflow in decode.c (decompress_R2004_section)
Individual backports were not feasible as the decompressor was significantly
refactored on upstream's main branch between 0.13.4 and the fixes.
(cherry picked from commit b27ee09e7d )
2026-05-28 01:28:39 +02:00
R. Ryantm
0269512e78
libredwg: 0.13.3 -> 0.13.4
...
(cherry picked from commit 34faa0cb06 )
2026-05-28 01:28:26 +02:00
Martin Weinelt
11c8668ea4
samba: 4.22.6 -> 4.22.10
...
https://www.samba.org/samba/history/samba-4.22.7.html
https://www.samba.org/samba/history/samba-4.22.8.html
https://www.samba.org/samba/history/samba-4.22.9.html
https://www.samba.org/samba/history/samba-4.22.10.html
Fixes:
CVE-2026-1933, CVE-2026-2340, CVE-2026-3012, CVE-2026-3238,
CVE-2026-4408, CVE-2026-4480
2026-05-28 01:20:46 +02:00
Michael Daniels
88298d6346
[Backport release-25.11] google-chrome: 148.0.7778.178 -> 148.0.7778.215 ( #525032 )
2026-05-27 22:42:42 +00:00
Michael Daniels
287d3dc160
google-chrome: 148.0.7778.178 -> 148.0.7778.215
...
(cherry picked from commit 2c044ef431 )
2026-05-27 22:02:25 +00:00
R. Ryantm
ed94b9f746
matrix-authentication-service: 1.16.0 -> 1.17.0
...
(cherry picked from commit e5d373f0e5 )
2026-05-27 20:27:11 +00:00
Philip Taron
c767db50e2
[Backport release-25.11] rustPlatform.importCargoLock: download crates from static.crates.io ( #524988 )
2026-05-27 20:09:08 +00:00
Philip Taron
7218b61388
rustPlatform.importCargoLock: download crates from static.crates.io
...
The crates.io API server's 1 req/sec rate limit currently surfaces as
intermittent HTTP 403 errors when vendoring lockfiles. Switch to the CDN
endpoint as recommended by upstream (rust-lang/crates.io#13482), mirroring
the fix already applied to fetchCargoVendor in #512735 .
fetchurl is content-addressed by sha256, so the URL change does not affect
any downstream store paths.
Fixes #524979
(cherry picked from commit f830e6112b )
2026-05-27 20:04:11 +00:00
Martin Weinelt
5e44c82aee
pretix: patch CVE-2026-9712 ( #524971 )
2026-05-27 19:22:45 +00:00
Martin Weinelt
72e4093b08
pretix: patch CVE-2026-9712
...
https://pretix.eu/about/en/blog/20260527-release-2026-4-2/
2026-05-27 21:16:47 +02:00
nixpkgs-ci[bot]
662e5a54f7
[Backport release-25.11] html2pdf: add versionCheckHook ( #524910 )
2026-05-27 18:28:56 +00:00
dotlambda
dd796aa746
[Backport release-25.11] perlPackages.Imager: 1.025 -> 1.031 ( #524896 )
2026-05-27 17:24:45 +00:00
Kenichi Kamiya
dec6653a77
html2pdf: add versionCheckHook
...
version flag is available in 0.8.3:
4886ded651
(cherry picked from commit 8c7c19f27a )
2026-05-27 16:26:29 +00:00
Robert Schütz
3f11b9c009
perlPackages.Imager: 1.025 -> 1.031
...
Changelog: https://metacpan.org/release/TONYC/Imager-1.031/source/Changes
(cherry picked from commit 8c5161adf0 )
2026-05-27 15:28:41 +00:00
Martin Weinelt
e60871b207
[Backport release-25.11] firefox/wrapper: better way to disable update checks ( #524821 )
2026-05-27 13:13:25 +00:00
K900
ac6e1fae6e
firefox/wrapper: better way to disable update checks
...
See https://bugzilla.mozilla.org/show_bug.cgi?id=2042197
(cherry picked from commit 1da3ca7373 )
2026-05-27 12:26:16 +00:00
nixpkgs-ci[bot]
1e31450425
[Backport release-25.11] jackett: 0.24.1879 -> 0.24.1954 ( #524730 )
2026-05-27 11:02:09 +00:00
Vladimír Čunát
e19a38a2cc
ceph: pyopenssl CVE fixes ( #523433 )
2026-05-27 10:21:12 +00:00
R. Ryantm
fe6a949cd0
jackett: 0.24.1879 -> 0.24.1954
...
(cherry picked from commit 629f87d2bd )
2026-05-27 08:22:25 +00:00
Vincent Laporte
1f1acd5f23
[Backport release-25.11] hol_light: fix ( #524648 )
2026-05-27 06:46:37 +00:00
nixpkgs-ci[bot]
32cf083116
[Backport release-25.11] unityhub: 3.16.2 -> 3.16.3 ( #504363 )
2026-05-27 05:25:47 +00:00
Martin Weinelt
726e534b73
[Backport release-25.11] Thunderbird: 150.0.2 -> 151.0.1 ( #524616 )
2026-05-27 01:53:22 +00:00
Felix Bargfeldt
809ac9decc
[Backport release-25.11] kdlfmt: 0.1.6 -> 0.1.7 ( #524636 )
2026-05-27 01:37:34 +00:00
Vincent Laporte
8bcdbf7529
hol_light: fix
...
(cherry picked from commit 823a2a5430 )
2026-05-27 02:33:44 +02:00
R. Ryantm
532adf42f4
kdlfmt: 0.1.6 -> 0.1.7
...
(cherry picked from commit dd5e5a35e8 )
2026-05-26 23:49:33 +00:00
Michael Daniels
a4060a48e9
[25.11] roundcube: 1.6.15 -> 1.6.16 ( #523953 )
2026-05-26 23:23:27 +00:00
Martin Weinelt
ad59befbf3
thunderbird-unwrapped: 150.0.2 -> 151.0.1
...
https://www.thunderbird.net/en-US/thunderbird/151.0/releasenotes/
https://www.thunderbird.net/en-US/thunderbird/151.0.1/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-50/
Fixes:
CVE-2026-8946, CVE-2026-8947, CVE-2026-8948, CVE-2026-8950,
CVE-2026-8952, CVE-2026-8953, CVE-2026-8954, CVE-2026-8955,
CVE-2026-8956, CVE-2026-8957, CVE-2026-8958, CVE-2026-8960,
CVE-2026-8961, CVE-2026-8962, CVE-2026-8963, CVE-2026-8964,
CVE-2026-8965, CVE-2026-8966, CVE-2026-8967, CVE-2026-8968,
CVE-2026-8969, CVE-2026-8970, CVE-2026-8971, CVE-2026-8972,
CVE-2026-8973, CVE-2026-8974, CVE-2026-8975
(cherry picked from commit 6327c29984 )
2026-05-26 22:33:48 +00:00
dotlambda
3eba1dac2e
[25.11] postfix: 3.10.7 -> 3.10.10 ( #523681 )
2026-05-26 21:41:27 +00:00
nixpkgs-ci[bot]
43f2881438
[Backport release-25.11] bird2: 2.18.1 -> 2.19.0; bird3: 3.2.1 -> 3.3.0 ( #524568 )
2026-05-26 21:29:39 +00:00
Tom Herbers
42b31385aa
bird3: 3.2.1 -> 3.3.0
...
Diff: https://gitlab.nic.cz/labs/bird/-/compare/v3.2.1...v3.3.0
Changelog: https://gitlab.nic.cz/labs/bird/-/blob/v3.3.0/NEWS
(cherry picked from commit 2ee9c5f475 )
2026-05-26 19:58:18 +00:00
Tom Herbers
6c41d212d9
bird2: 2.18.1 -> 2.19.0
...
Diff: https://gitlab.nic.cz/labs/bird/-/compare/v2.18.1...v2.19.0
Changelog: https://gitlab.nic.cz/labs/bird/-/blob/v2.19.0/NEWS
(cherry picked from commit 197d3402b3 )
2026-05-26 19:58:18 +00:00
Niklas Hambüchen
283ec1093a
[Backport release-25.11] llama-cpp: Use runtime instruction dispatch for massive speedups ( #524150 )
2026-05-26 16:43:34 +00:00
yaya
bcd7933568
[Backport release-25.11] gitlab-runner: 18.11.2 -> 18.11.3 ( #524432 )
2026-05-26 14:51:10 +00:00
yaya
916604a40a
gitlab-runner: add meta.changelog
...
(cherry picked from commit 1309675d1c )
2026-05-26 12:56:26 +00:00
yaya
8e90818e9b
gitlab-runner: 18.11.2 -> 18.11.3
...
- Changelog: https://gitlab.com/gitlab-org/gitlab-runner/blob/v18.11.3/CHANGELOG.md
- Diff: https://gitlab.com/gitlab-org/gitlab-runner/-/compare/v18.11.2...v18.11.3
(cherry picked from commit 0050e4fdae )
2026-05-26 12:56:26 +00:00
Martin Weinelt
25f5383063
[Backport release-25.11] Firefox: 151.0.1 -> 151.0.2 ( #524336 )
2026-05-26 13:57:21 +02:00
Felix Bargfeldt
de2f0530f6
[25.11] zipline: 4.5.3 -> 4.6.1 ( #524402 )
2026-05-26 10:28:17 +00:00
R. Ryantm
a7f58c32ff
zipline: 4.6.0 -> 4.6.1
...
(cherry picked from commit 7e694d8797 )
2026-05-26 12:23:10 +02:00
R. Ryantm
dea21382eb
zipline: 4.5.3 -> 4.6.0
...
(cherry picked from commit 95c4d71846 )
2026-05-26 12:23:10 +02:00
Martin Weinelt
f6a538e454
firefox-bin-unwrapped: 151.0.1 -> 151.0.2
...
https://www.firefox.com/en-US/firefox/151.0.2/releasenotes/
(cherry picked from commit a8ec6de44b )
2026-05-26 06:48:26 +00:00
Martin Weinelt
ad11919836
firefox-unwrapped: 151.0.1 -> 151.0.2
...
https://www.firefox.com/en-US/firefox/151.0.2/releasenotes/
(cherry picked from commit 1c2cf917ce )
2026-05-26 06:48:26 +00:00
nixpkgs-ci[bot]
d60e39a68a
[Backport release-25.11] shogihome: 1.27.2 -> 1.27.3 ( #524293 )
2026-05-26 05:00:57 +00:00
R. Ryantm
f7fe4eb2c6
shogihome: 1.27.2 -> 1.27.3
...
(cherry picked from commit 086e5644a0 )
2026-05-26 03:38:54 +00:00