summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* python312Packages.manifestoo-core: 1.6 -> 1.7•••(cherry picked from commit d92dd651b4ad5aae9f34962bb311c711bd32b865) origin/backport-327536-to-release-24.05R. Ryantm2024-07-291-2/+2
* Merge pull request #330727 from NixOS/backport-330701-to-release-24.05•••[Backport release-24.05] google-chrome: 126.0.6478.182 -> 127.0.6533.72Masum Reza2024-07-291-2/+3
|\
| * google-chrome: add changelog link to make it easier for reviewers•••Look for Chrome Desktop Stable update in the posts to see the changelog (cherry picked from commit 117a1c494c62d4f0ab486b136c3b7bb598e20490) John Titor2024-07-281-0/+1
| * google-chrome: 126.0.6478.182 -> 127.0.6533.72•••This update includes 22 security fixes. [$11000][349198731] High CVE-2024-6988: Use after free in Downloads. Reported by lime(@limeSec_) from TIANGONG Team of Legendsec at QI-ANXIN Group on 2024-06-25 [$8000][349342289] High CVE-2024-6989: Use after free in Loader. Reported by Anonymous on 2024-06-25 [TBD][346618785] High CVE-2024-6991: Use after free in Dawn. Reported by wgslfuzz on 2024-06-12 [$8000][339686368] Medium CVE-2024-6994: Heap buffer overflow in Layout. Reported by Huang Xilin of Ant Group Light-Year Security Lab on 2024-05-10 [$6000][343938078] Medium CVE-2024-6995: Inappropriate implementation in Fullscreen. Reported by Alesandro Ortiz on 2024-06-01 [$5000][333708039] Medium CVE-2024-6996: Race in Frames. Reported by Louis Jannett (Ruhr University Bochum) on 2024-04-10 [$3000][325293263] Medium CVE-2024-6997: Use after free in Tabs. Reported by Sven Dysthe (@svn-dys) on 2024-02-15 [$2000][340098902] Medium CVE-2024-6998: Use after free in User Education. Reported by Sven Dysthe (@svn-dys) on 2024-05-13 [$2000][340893685] Medium CVE-2024-6999: Inappropriate implementation in FedCM. Reported by Alesandro Ortiz on 2024-05-15 [$500][339877158] Medium CVE-2024-7000: Use after free in CSS. Reported by Anonymous on 2024-05-11 [TBD][347509736] Medium CVE-2024-7001: Inappropriate implementation in HTML. Reported by Jake Archibald on 2024-06-17 [$2000][338233148] Low CVE-2024-7003: Inappropriate implementation in FedCM. Reported by Alesandro Ortiz on 2024-05-01 [TBD][40063014] Low CVE-2024-7004: Insufficient validation of untrusted input in Safe Browsing. Reported by Anonymous on 2023-02-10 [TBD][40068800] Low CVE-2024-7005: Insufficient validation of untrusted input in Safe Browsing. Reported by Umar Farooq on 2023-08-04 (cherry picked from commit 98dc7a18aa9f391f410317b5d97a96bc04b4a02d) John Titor2024-07-281-2/+2
* | sapling: 0.2.202401116 -> 0.2.20240718•••(cherry picked from commit 860120afe4a56687e069af33f265beeb303de048) Shadaj Laddad2024-07-283-1036/+1698
|/
* Merge pull request #330671 from NixOS/backport-330610-to-release-24.05•••[Backport release-24.05] ungoogled-chromium: 126.0.6478.182-1 -> 127.0.6533.72-1Emily2024-07-282-8/+11
|\
| * ungoogled-chromium: 126.0.6478.182-1 -> 127.0.6533.72-1•••https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html This update includes 22 security fixes. CVEs: CVE-2024-6988 CVE-2024-6989 CVE-2024-6991 CVE-2024-6994 CVE-2024-6995 CVE-2024-6996 CVE-2024-6997 CVE-2024-6998 CVE-2024-6999 CVE-2024-7000 CVE-2024-7001 CVE-2024-7003 CVE-2024-7004 CVE-2024-7005 The ungoogled-chromium binary pruning list got updated to include the path to a node binary previously not included in the chromium source tarball. We already did link the binary from our node package into place, however as we were running the pruning script after the linking the binary would get removed, causing the build to fail. Co-authored-by: emilylange <git@emilylange.de> (cherry picked from commit bb19f848aed45c5769d148854776e85352d039bf) networkException2024-07-282-8/+11
|/
* Merge pull request #330428 from risicle/ris-cri-o-1.30.1-r24.05•••[24.05] cri-o: 1.30.0 -> 1.30.1❄️2024-07-281-2/+2
|\
| * cri-o-unwrapped: 1.30.0 -> 1.30.1•••(cherry picked from commit 10b1cee6ca731dd6537bbed1282c52b087aec686) R. Ryantm2024-07-271-2/+2
* | Merge pull request #330462 from risicle/ris-argocd-2.11.3-r24.05•••[24.05] argocd: 2.11.0 -> 2.11.3 ❄️2024-07-281-3/+3
|\ \
| * | argocd: 2.11.2 -> 2.11.3•••(cherry picked from commit 474318f944ef74aec40ccb49d36ffd372707f669) R. Ryantm2024-07-271-2/+2
| * | argocd: 2.11.1 -> 2.11.2•••(cherry picked from commit 1fffe13b2fa3f9bbabf66d9e8528ad7e89303d50) R. Ryantm2024-07-271-3/+3
| * | argocd: 2.11.0 -> 2.11.1•••(cherry picked from commit 7d7251c9b07cfb1e3e3af2eba09c2f6d83245605) R. Ryantm2024-07-271-3/+3
| |/
* | Merge pull request #330554 from NixOS/backport-329912-to-release-24.05•••[Backport release-24.05] linuxKernel.kernels.linux_zen: 6.9.8-zen1 -> 6.10.1-zen1 ; linuxKernel.kernels.linux_lqx: 6.9.8-lqx1 -> 6.9.11-lqx1Atemu2024-07-281-4/+4
|\ \
| * | linuxKernel.kernels.linux_zen: 6.9.8-lqx1 -> 6.9.11-lqx1•••(cherry picked from commit 0961f648facaf8bdbf193a1bd141248fe1e22e28) JerrySM642024-07-281-2/+2
| * | linuxKernel.kernels.linux_zen: 6.9.8-zen1 -> 6.10.1-zen1•••(cherry picked from commit 83431a5831471e975c4db5a3b30b530a7191795c) JerrySM642024-07-281-2/+2
* | | Merge pull request #330403 from risicle/ris-libvpx_1_8-known-vulnerabilities-...•••[24.05] libvpx_1_8: mark with knownVulnerabilitiesEmily2024-07-281-0/+5
|\ \ \
| * | | libvpx_1_8: mark with knownVulnerabilities•••CVE-2023-6349 CVE-2023-44488 CVE-2024-5197 Robert Scott2024-07-271-0/+5
| | |/ | |/|
* | | Merge pull request #330425 from risicle/ris-wagtail-6.0.5-r24.05•••[24.05] python311Packages.wagtail: 6.0.2 -> 6.0.5Robert Scott2024-07-281-2/+2
|\ \ \
| * | | python311Packages.wagtail: 6.0.2 -> 6.0.5Robert Scott2024-07-271-2/+2
| |/ /
* | | Merge pull request #330365 from matthiasbeyer/backport-cargo-tools-updates•••[Backport 24.05]: cargo tools updatesMatthias Beyer2024-07-2812-35/+35
|\ \ \
| * | | cargo-tally: 1.0.47 -> 1.0.48•••(cherry picked from commit a2788c5179e345493daa7a1e4295f9122bde5acf) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-component: 0.13.2 -> 0.14.0•••(cherry picked from commit 14d7585308265f14af7059c3f96339a92a5f2435) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-deny: 0.14.24 -> 0.15.0•••(cherry picked from commit db232207fee11b770b9d53ce99412129ac1c2096) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-workspaces: 0.3.2 -> 0.3.5•••(cherry picked from commit c315b7bb99e22a8c94497fefd523de3c5d8e86fa) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-workspaces: 0.3.1 -> 0.3.2•••(cherry picked from commit 8d305db7375072a6b63fff7db666cc89c8381acd) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-llvm-cov: 0.6.10 -> 0.6.11•••(cherry picked from commit c07cdd34decacb4cac467962b20c94b3670d89a0) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> Charles Hall2024-07-271-4/+4
| * | | cargo-hack: 0.6.29 -> 0.6.30•••(cherry picked from commit 80f1af4dc0969a8b4b0761f8d08ac9e77a53fe15) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-hack: 0.6.28 -> 0.6.29•••(cherry picked from commit 322904529793414be7343e37ade4229b77072123) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-udeps: 0.1.47 -> 0.1.49•••(cherry picked from commit 8a7f972fdaa8c74d84ea83118a1df307ed2c2400) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-dist: 0.18.0 -> 0.19.1•••(cherry picked from commit 93682f498bf33b27fee7523b2a814cf82c4b7a8c) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-dist: 0.17.0 -> 0.18.0•••(cherry picked from commit 1a33b22222169e2e3341c2f01eca60b67007d726) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> Misty De Méo2024-07-271-3/+3
| * | | cargo-dist: 0.16.0 -> 0.17.0•••(cherry picked from commit 04234384079f08ee932c9962b0b7e3b30e0885fd) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> Misty De Méo2024-07-271-3/+3
| * | | cargo-zigbuild: 0.19.0 -> 0.19.1•••(cherry picked from commit 509de8578d3085d346685872690b712a620648a8) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-zigbuild: use zig from buildPackages•••(cherry picked from commit f22a643625e9f42883c602e26f470cb5a95a4191) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> Nick Cao2024-07-271-1/+1
| * | | cargo-zigbuild: 0.18.4 -> 0.19.0•••(cherry picked from commit af7995aa159dead11d8bd826035a028fa96ca876) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-tauri: 1.6.8 -> 1.7.1•••(cherry picked from commit d2ef3b395999a5d14a295cf30be3fbdad9873e15) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
| * | | cargo-semver-checks: 0.32.0 -> 0.33.0•••(cherry picked from commit 2f5fb56cb33f1c0a58fd2fe23c5bd0e8bf922835) Signed-off-by: Matthias Beyer <mail@beyermatthias.de> R. Ryantm2024-07-271-3/+3
* | | | Merge #329971: thunderbird-128: 128.0esr -> 128.0.1esr•••...into release-24.05 Vladimír Čunát2024-07-281-2/+2
|\ \ \ \
| * | | | thunderbirdPackages.thunderbird-128: 128.0esr -> 128.0.1esr•••(cherry picked from commit 577df53830c838391df4a0159baf88a655970378) R. Ryantm2024-07-251-2/+2
* | | | | Merge pull request #327459 from NixOS/backport-324969-to-release-24.05•••[Backport release-24.05] gnucash: 5.6 -> 5.8tomberek2024-07-281-10/+3
|\ \ \ \ \
| * | | | | gnucash: 5.6 -> 5.8•••Diff: https://github.com/Gnucash/gnucash/compare/5.6...5.8 (cherry picked from commit 8eb0fc8d1b11abfc8934b4ffffd4c5c2a274fa2b) Yongun Seong2024-07-151-10/+3
* | | | | | Merge pull request #330273 from emilylange/backport-330023-to-release-24.05•••[Backport release-24.05] chromium,chromedriver: 126.0.6478.182 -> 127.0.6533.72Emily2024-07-285-15/+29
|\ \ \ \ \ \ | |_|_|_|_|/ |/| | | | |
| * | | | | chromium,chromedriver: 126.0.6478.182 -> 127.0.6533.72•••https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html This update includes 22 security fixes. CVEs: CVE-2024-6988 CVE-2024-6989 CVE-2024-6991 CVE-2024-6994 CVE-2024-6995 CVE-2024-6996 CVE-2024-6997 CVE-2024-6998 CVE-2024-6999 CVE-2024-7000 CVE-2024-7001 CVE-2024-7003 CVE-2024-7004 CVE-2024-7005 (cherry picked from commit 432cb6b1bbf4510c899474c4a1bdf9c7c966adfd) emilylange2024-07-271-9/+9
| * | | | | chromium: prepare for M127•••(cherry picked from commit b80f73df94770c316b206ac221215b464377c3ee) emilylange2024-07-273-3/+17
| * | | | | chromium: fix `update.py` python3.12 compat•••(cherry picked from commit 793613662146fe14937e8b42e083733bbe663428) emilylange2024-07-261-3/+3
* | | | | | Merge pull request #330531 from NixOS/backport-330435-to-release-24.05•••[Backport release-24.05] Kernel updates for 2024-07-27K9002024-07-283-29/+29
|\ \ \ \ \ \
| * | | | | | linux-rt_5_15: 5.15.160-rt77 -> 5.15.163-rt78•••(cherry picked from commit 1e5a635100917cd2cdafc2a932dd0b716beb7eaa) K9002024-07-271-3/+3
| * | | | | | linux_4_19: 4.19.318 -> 4.19.319•••(cherry picked from commit db09f89018e38b432418b938d8dc534847256527) K9002024-07-271-2/+2
| * | | | | | linux_5_4: 5.4.280 -> 5.4.281•••(cherry picked from commit 4ab6a7935deec4f6c37e44bf34ad4ffb4bf6dd01) K9002024-07-271-2/+2