Commit Graph

636251 Commits

Author SHA1 Message Date
K900
1d8758c4c5
[Backport release-24.05] xorg.*: update (#352310) 2024-10-30 11:02:34 +03:00
Nick Cao
8312bb0b55 xorg.bdftopcf: 1.1.1 -> 1.1.2
Diff: https://gitlab.freedesktop.org/xorg/util/bdftopcf/-/compare/bdftopcf-1.1.1...bdftopcf-1.1.2
(cherry picked from commit 2e85991f1e)
2024-10-30 08:00:03 +00:00
Nick Cao
a24bbc04f8 xorg.xf86videor128: 6.12.1 -> 6.13.0
Diff: https://gitlab.freedesktop.org/xorg/driver/xf86-video-r128/-/compare/xf86-video-r128-6.12.1...xf86-video-r128-6.13.0
(cherry picked from commit 3848778b3c)
2024-10-30 08:00:03 +00:00
Nick Cao
4a2eb2b757 xorg.xf86videomga: 2.0.1 -> 2.1.0
Diff: https://gitlab.freedesktop.org/xorg/driver/xf86-video-mga/-/compare/xf86-video-mga-2.0.1...xf86-video-mga-2.1.0
(cherry picked from commit 225baa68da)
2024-10-30 08:00:03 +00:00
Nick Cao
2e76155f6f xorg.xf86inputlibinput: 1.4.0 -> 1.5.0
Diff: https://gitlab.freedesktop.org/xorg/driver/xf86-input-libinput/-/compare/xf86-input-libinput-1.4.0...xf86-input-libinput-1.5.0
(cherry picked from commit f72f6d9aa3)
2024-10-30 08:00:03 +00:00
Nick Cao
938e375cf9 xorg.xf86inputevdev: 2.10.6 -> 2.11.0
Diff: https://gitlab.freedesktop.org/xorg/driver/xf86-input-evdev/-/compare/xf86-input-evdev-2.10.6...xf86-input-evdev-2.11.0
(cherry picked from commit 27cb8fcb92)
2024-10-30 08:00:03 +00:00
Nick Cao
cf87a4623e xorg.xwud: 1.0.6 -> 1.0.7
Diff: https://gitlab.freedesktop.org/xorg/app/xwud/-/compare/xwud-1.0.6...xwud-1.0.7
(cherry picked from commit 24bf2d3abd)
2024-10-30 08:00:03 +00:00
Nick Cao
272d2b64b6 xorg.xmag: 1.0.7 -> 1.0.8
Diff: https://gitlab.freedesktop.org/xorg/app/xmag/-/compare/xmag-1.0.7...xmag-1.0.8
(cherry picked from commit 7bdc8a8cba)
2024-10-30 08:00:03 +00:00
Nick Cao
87b457a378 xorg.xkbprint: 1.0.6 -> 1.0.7
Diff: https://gitlab.freedesktop.org/xorg/app/xkbprint/-/compare/xkbprint-1.0.6...xkbprint-1.0.7
(cherry picked from commit 3e78b5176e)
2024-10-30 08:00:03 +00:00
Nick Cao
12d4c3341e xorg.xcmsdb: 1.0.6 -> 1.0.7
Diff: https://gitlab.freedesktop.org/xorg/app/xcmsdb/-/compare/xcmsdb-1.0.6...xcmsdb-1.0.7
(cherry picked from commit e2a90034e4)
2024-10-30 08:00:02 +00:00
Nick Cao
3ac9886509 xorg.fonttosfnt: 1.2.3 -> 1.2.4
Diff: https://gitlab.freedesktop.org/xorg/app/fonttosfnt/-/compare/fonttosfnt-1.2.3...fonttosfnt-1.2.4
(cherry picked from commit 3bb3955022)
2024-10-30 08:00:02 +00:00
Tomo
0446c3c20d
[Backport release-24.05] gradle_6: mark very insecure (#352278) 2024-10-29 21:48:53 -07:00
Tomo
060cec2851
[Backport release-24.05] summoning-pixel-dungeon: use default gradle (#352279) 2024-10-29 21:48:29 -07:00
Tomo
e4472d9e6a summoning-pixel-dungeon: use default gradle
Upstream has made it possible to use a recent version of Gradle,
thanks to some patches:
* "1.2.6: changed JVM args to be compatible with Java 17"
    -> This is not directly applied, as it fails to apply cleanly; we use substituteInPlace instead
    -> c8a6fdd57c

* "1.2.6: updated desktop build script for Gradle 7.0+"
    -> 5610142126

Additionally, allows this package to keep working after #352236

(cherry picked from commit 6854e017bf)
2024-10-30 04:48:10 +00:00
Tomo
7640c69805 gradle_6: mark very insecure
v6 is vulnerable to a number of vulnerabiliites:
* CVE-2021-29429, affecting confidentiality
* CVE-2021-29427, affecting confidentiality and can lead to dependency poisoning
* CVE-2021-29428, a privilege escalation involving the temp dir
* CVE-2021-32751, arbitrary code execution

(cherry picked from commit 161e9a32c9)
2024-10-30 04:47:52 +00:00
Masum Reza
2bb5ad7215
[Backport release-24.05] libinput-gestures: fix rev link (#352268) 2024-10-30 09:07:06 +05:30
NovaViper
d68e4cd123 libinput-gestures: fix rev link
Previous commit forgot an `s` in `refs`, making the link 404

Co-authored-by: Eman Resu <78693624+llakala@users.noreply.github.com>
(cherry picked from commit 7294f7567a)
2024-10-30 03:36:34 +00:00
Masum Reza
55e691a21e
[Backport release-24.05] libinput-gestures: 2.76 -> 2.77 (#351818) 2024-10-30 09:05:57 +05:30
Nick Cao
f958a52026
[Backport release-24.05] powerpipe: 0.4.3 -> 0.4.4 (#352119) 2024-10-29 15:16:38 -04:00
Adam C. Stephens
1a45f6a33c
[Backport release-24.05] forgejo: 7.0.9 -> 7.0.10 (#351932) 2024-10-29 12:29:27 -04:00
R. Ryantm
e75c44d6af powerpipe: 0.4.3 -> 0.4.4
(cherry picked from commit 8b44ec3fac)
2024-10-29 14:17:23 +00:00
Marie Ramlow
d0f1128dfe forgejo: 7.0.9 -> 7.0.10
(cherry picked from commit 0e158f7f9d)
2024-10-29 14:10:43 +01:00
Sefa Eyeoglu
6aa8749b51
[Backport release-24.05] envision: init at 0-unstable-2024-06-23 (#339599) 2024-10-29 09:13:26 +01:00
Christina Sørensen
827dd72e6f
[Backport release-24.05] guix: backport build user takeover commits (#351910) 2024-10-29 07:58:22 +01:00
Luke Granger-Brown
a196affc89
[Backport release-24.05] factorio 1.1.107 -> 1.1.110 (#350682) 2024-10-29 05:35:15 +00:00
Sandro
91a2191a5a
[Backport release-24.05] mozillavpn: 2.24.0 → 2.24.1, add updateScript (#346510) 2024-10-29 02:34:10 +01:00
Nick Cao
dd6d18bf8d
[Backport release-24.05] stats: 2.11.14 -> 2.11.16 (#351878) 2024-10-28 15:12:37 -04:00
Masum Reza
64b80bfb31
[Backport release-24.05] google-chrome: 130.0.6723.{58,59} -> 130.0.6723.{69,70} (#351926) 2024-10-28 23:17:05 +05:30
Thomas Gerbet
b580496414 google-chrome: 130.0.6723.{58,59} -> 130.0.6723.{69,70}
Fixes CVE-2024-10229, CVE-2024-10230 and CVE-2024-10231.
https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_22.html

(cherry picked from commit ed24e9e893)
2024-10-28 16:16:41 +00:00
Hendrik Sokolowski
92ad245496 sysstat: add iostat as mainProgram
(cherry picked from commit f251273e41)
2024-10-28 17:10:18 +01:00
Hendrik Sokolowski
9fe0825aff sysstat: adopt
(cherry picked from commit 3db1263401)
2024-10-28 17:10:18 +01:00
Hendrik Sokolowski
1aa3b5d751 maintainers: add hensoko
(cherry picked from commit f40c74785c)
2024-10-28 17:10:18 +01:00
Pavol Rusnak
6e45ae4299
[24.05] micropython: 1.22.2 -> 1.24.0 (#351871) 2024-10-28 17:02:51 +01:00
Christina Sørensen
0ab5170991 guix: build user takeover patch
guix has recently announced a security vulnerability that allows
local users to gain priveleges of build users, and further manipulate
output of any build (including with setguid).

This commit fixes the issue by backporting the remediation commits pushed to
guix main to 1.4.0 as a patch.

Users will still have to reboot and follow other remediation steps as
described in the guix blogpost.

Refs: https://guix.gnu.org/en/blog/2024/build-user-takeover-vulnerability/
Signed-off-by: Christina Sørensen <christina@cafkafk.com>
(cherry picked from commit 633a3b8f19)
2024-10-28 15:57:06 +01:00
Christina Sørensen
4fbe49d384 guix: format with rfc-style
Signed-off-by: Christina Sørensen <christina@cafkafk.com>
(cherry picked from commit 42fee36c0b)
2024-10-28 15:56:10 +01:00
DontEatOreo
fea7bbc03b stats: 2.11.14 -> 2.11.16
Changelog: https://github.com/exelban/stats/releases/tag/v2.11.16
Diff: https://github.com/exelban/stats/compare/v2.11.14...v2.11.16
(cherry picked from commit d41e41bed3)
2024-10-28 13:15:39 +00:00
Aleksana
d30a86d3f0
[24.05] furmark: add an icon (#344948) 2024-10-28 20:59:50 +08:00
Jordan Williams
e9e07262f4
micropython: 1.23.0 -> 1.24.0
(cherry picked from commit ece2d90480)
2024-10-28 12:58:05 +01:00
R. Ryantm
184cc0e6ba
micropython: 1.22.2 -> 1.23.0
(cherry picked from commit 9784118a2f)
2024-10-28 12:52:21 +01:00
teutat3s
bf4de27fa4 element-desktop: 1.11.81 -> 1.11.82
https://github.com/element-hq/element-desktop/releases/tag/v1.11.82
(cherry picked from commit 8991fdb136)
2024-10-28 08:37:21 +01:00
John Titor
372bc515b8 libinput-gestures: nixfmt-rfc-style
replace -> replace-fail in substituteInPlace

rec -> finalAttrs

(cherry picked from commit b5ef9e4762)
2024-10-28 06:50:23 +00:00
guttermonk
a18232138f libinput-gestures: 2.76 -> 2.77
(cherry picked from commit b24c50ea7a)
2024-10-28 06:50:23 +00:00
Artturin
9b9516e15a
[Backport release-24.05] pyhton3Packages.databricks-sql-connector: Fix broken (#331732) 2024-10-28 07:05:32 +02:00
Artturin
87fc112445
[Backport release-24.05] qq: 3.2.12-2024.9.27 -> 3.2.13-2024.10.23 (#351621) 2024-10-28 06:50:06 +02:00
Emily
e17a214fdb
[Backport release-24.05] {ungoogled-,}chromium,chromedriver: 130.0.6723.58 -> 130.0.6723.69 (#351722) 2024-10-28 03:19:43 +01:00
Masum Reza
ef498e16f8
[Backport release-24.05] nixos/sway: workaround idle inhibit not working in Firefox (#350955) 2024-10-28 03:25:05 +05:30
Sefa Eyeoglu
576ee82325
[Backport release 24.05] vencord: 1.10.2 -> 1.10.5 (#351216) 2024-10-27 21:19:00 +01:00
Emily
2473202c97
[Backport release-24.05] teams-for-linux: 1.9.5 -> 1.11.2; electron 30 -> 32 (#351714) 2024-10-27 19:42:17 +00:00
Masum Reza
59a210b624
[Backport release-24.05] minidjvu: mark as vulnerable (#351644) 2024-10-27 23:40:52 +05:30
Austin Horstman
e8ab03fe9c
teams-for-linux: electron 30 -> electron 32
Looks like upstream bumped electron version, already.

(cherry picked from commit 0cf4af9081)
2024-10-27 13:10:41 -05:00