Commit Graph

1607 Commits

Author SHA1 Message Date
Leona Maroni
de20c77eaa discourse.plugins: update
(cherry picked from commit 2b0b37048c)
2024-10-25 16:53:18 +00:00
Leona Maroni
f01bb94314 discourse-mail-receiver: 4.0.7 -> 4.1.0
(cherry picked from commit d642a421cb)
2024-10-25 16:53:18 +00:00
Leona Maroni
6bcdcaf38e discourse: 3.2.5 -> 3.3.2
https://meta.discourse.org/t/3-3-0-major-release/316353
https://meta.discourse.org/t/3-3-1-bug-fix-release/322330
https://meta.discourse.org/t/3-3-2-security-and-maintenance-release/329341
(cherry picked from commit 6a5e0f7dac)
2024-10-25 16:53:18 +00:00
Maximilian Bosch
e135afca60 wiki-js: unpack into source
We effectively copy everything into `$out` (but this isn't using
`buildCommand` to allow applying custom patches). However, this had the
effect that `env-vars` was also copied into `$out` retaining a reference
to the source tarball.

Removing that reduces the closure size from 765.5M to 388.8M, i.e. by
about 50.7%.

(cherry picked from commit 3dc2d95972)
2024-10-19 06:02:33 +00:00
Maximilian Bosch
2e8d92a721 wiki-js: 2.5.304 -> 2.5.305
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.305
(cherry picked from commit e0f63ad971)
2024-10-19 06:02:33 +00:00
Martin Weinelt
8b57afd0f3 discourse: mark as known vulnerable
There is no maintenance happening on this package and I can't keep doing
security updates for it, when the build changes on every minor release.

(cherry picked from commit 492050c0d3)
2024-10-17 14:26:33 +00:00
Martin Weinelt
c0327d885b
mediawiki: 1.41.3 -> 1.41.4
https://www.mediawiki.org/wiki/Release_notes/1.41#MediaWiki_1.41.4
2024-10-14 22:01:35 +02:00
Thomas Gerbet
0947890f63 mediawiki: 1.41.1 -> 1.41.3
Fixes CVE-2024-47913 (impacts the AbuseFilter extension).

Changes:
https://www.mediawiki.org/wiki/Release_notes/1.41#MediaWiki_1.41.3
2024-10-08 22:42:47 +02:00
h7x4
61dfc4309b
[Backport release-24.05] slskd: 0.21.1 -> 0.21.3 (#334090) 2024-10-01 19:33:34 +02:00
R. Ryantm
fbab02e64d outline: 0.79.0 -> 0.80.2
(cherry picked from commit 01525c4d97)
2024-09-30 03:54:19 +00:00
Maximilian Bosch
4de78af3ba
Merge: [Backport release-24.05] wiki-js: 2.5.303 -> 2.5.304, fix CVE-2024-45298 (#343754) 2024-09-22 21:50:14 +02:00
Weijia Wang
4b20ad9d1e
[Backport release-24.05] wordpress: 6.5.4 -> 6.5.5 (#332652) 2024-09-22 20:58:17 +02:00
Maximilian Bosch
56acf92e3d wiki-js: 2.5.303 -> 2.5.304, fix CVE-2024-45298
ChangeLog: https://github.com/requarks/wiki/releases/tag/v2.5.304
(cherry picked from commit 149ed25fc2)
2024-09-22 16:07:24 +00:00
Sandro Jäckel
edd84626d1
hedgedoc: 1.9.9 -> 1.10.0
Changelog: https://github.com/hedgedoc/hedgedoc/releases/tag/1.10.0
Fixes: https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-pjf2-269h-cx7p
(cherry picked from commit 7e7df1ade9)
2024-09-10 06:51:38 +02:00
github-actions[bot]
7411580f18
[Backport release-24.05] outline: 0.78.0 -> 0.79.0 (#340143)
outline: 0.78.0 -> 0.79.0

(cherry picked from commit fec686e486)

Co-authored-by: R. Ryantm <ryantm-bot@ryantm.com>
2024-09-08 21:21:26 +04:00
Emily
cbff61b225
[24.05] olm: mark as vulnerable (#335189) 2024-09-02 03:41:40 +01:00
laalsaas
1e88a008ba matomo_5: 5.1.0 -> 5.1.1
(cherry picked from commit ed48acbc06)
2024-08-30 11:07:38 +00:00
laalsaas
d09ca3c2a2 matomo_5: 5.0.2 -> 5.1.0
(cherry picked from commit cf642a11d3)
2024-08-30 11:07:38 +00:00
Emily
56e4b26ab1 {cinny,fluffychat,jitsi-meet}: inherit vulnerabilities from olm
These vendor the libolm code.

(cherry picked from commit bbfd5d1085)
2024-08-16 20:25:35 +01:00
e1mo
0160c36e94 dokuwiki: add e1mo as maintainer
(cherry picked from commit e94d59e8e2)
2024-08-16 15:00:28 +00:00
e1mo
1dddb06662 dokuwiki: 2023-04-04a -> 2023-04-04b
Fixes an XSS Vulnerability reported in
https://github.com/dokuwiki/dokuwiki/issues/4305

(cherry picked from commit 0d80a75fb3)
2024-08-16 15:00:28 +00:00
melvyn
aea895e058 slskd: 0.21.1 -> 0.21.3
(cherry picked from commit 90de5096f6)
2024-08-12 08:56:05 +00:00
R. Ryantm
dac84a19e2 wordpress: 6.5.4 -> 6.5.5
(cherry picked from commit 817323b8b7)
2024-08-06 07:35:58 +00:00
Martin Weinelt
f1ed5c49cb discourse: update plugins
(cherry picked from commit 12bf120747)
2024-07-30 17:22:23 +00:00
Martin Weinelt
c7abff0f2e discourse: 3.2.4 -> 3.2.5
https://meta.discourse.org/t/3-2-5-security-and-bug-fix-release/316349/1

Fixes: CVE-2024-37165, CVE-2024-39320, CVE-2024-37299
(cherry picked from commit 326c87902e)
2024-07-30 17:22:23 +00:00
Alexander Sieg
9b9690d7ae outline: 0.77.2 -> 0.78.0 and set updateScript
(cherry picked from commit cde84f1d5d)
2024-07-22 08:36:17 +00:00
melvyn
0207576d61 slskd: 0.19.5 -> 0.21.1
(cherry picked from commit c5b8ea1af7)
2024-07-18 20:33:18 +00:00
Martin Weinelt
8004217c28 discourse: update plugins
(cherry picked from commit 7a6af82358)
2024-07-15 23:00:36 +00:00
Martin Weinelt
dd41579ef2 discourse: 3.2.3 -> 3.2.4
https://meta.discourse.org/t/3-2-4-security-and-bug-fix-release/315984

Fixes: CVE-2024-38360
(cherry picked from commit 078b2393fd)
2024-07-15 23:00:36 +00:00
Martin Weinelt
ea7110d77a discourse: fix nix-shell package order
The python environment needs to come early, or else we're getting another
python, that does not have the bundled dependencies.

(cherry picked from commit ece092568a)
2024-07-15 23:00:36 +00:00
Martin Weinelt
898c75df00 discourse.plugins.discourse-migratepassword: 1.16.3 -> 1.17.0
(cherry picked from commit c8c381efaf)
2024-07-04 16:00:22 +00:00
Martin Weinelt
afbd4aecbb discourse: 3.2.2 -> 3.2.3
https://meta.discourse.org/t/3-2-3-security-and-bug-fix-release/313392

Fixes: CVE-2024-35227, CVE-2024-35234, CVE-2024-36113, CVE-2024-36122,
       CVE-2024-37157
(cherry picked from commit b212150fa2)
2024-07-04 16:00:22 +00:00
Martin Weinelt
9ddbc87291 discourse: fix update script after nix-universal-prefetch removal
Replaces nix-universal-prefetch with nurl.

(cherry picked from commit 10a6847471)
2024-07-04 16:00:22 +00:00
Weijia Wang
0ae435eda5
Merge pull request #320701 from NixOS/backport-318898-to-release-24.05
[Backport release-24.05] wordpress: 6.5.2 -> 6.5.4
2024-06-20 10:18:41 +02:00
Alexander Sieg
e50be7be1b outline: 0.77.1 -> 0.77.2
(cherry picked from commit 5840285b38)
2024-06-18 13:12:12 +00:00
Alexander Sieg
d74a936c02 outline: 0.76.1 -> 0.77.1
Changelog:
- https://github.com/outline/outline/releases/tag/v0.77.0
- https://github.com/outline/outline/releases/tag/v0.77.1

(cherry picked from commit fae942daaf)
2024-06-18 10:11:34 +00:00
Weijia Wang
e0bfd6e51b wordpress: update plugins
(cherry picked from commit d229aeec6b)
2024-06-18 06:41:18 +00:00
Weijia Wang
f3d5a72f0a wordpress: 6.5.2 -> 6.5.4
(cherry picked from commit 66e95dd167)
2024-06-18 06:41:18 +00:00
Weijia Wang
6337853053 wordpress: fix update script
(cherry picked from commit 873856ba1f)
2024-06-18 06:41:18 +00:00
Martin Weinelt
55ee801174 discourse: build discourseAllPlugins in passthru.tests.
Useful to reveal failing plugin builds.

(cherry picked from commit 898d023384)
2024-05-27 19:32:18 +00:00
Martin Weinelt
432e435a69 discourse: update plugins
(cherry picked from commit 1d2d14cc1f)
2024-05-27 19:32:18 +00:00
Martin Weinelt
4d2a8b2c58 discourse: 3.1.0 -> 3.2.2
https://meta.discourse.org/t/3-1-1-security-and-bug-fix-release/278760
https://meta.discourse.org/t/3-1-2-security-and-bug-fix-release/282427
https://meta.discourse.org/t/3-1-3-security-and-bug-fix-release/284973
https://meta.discourse.org/t/3-1-4-security-and-bug-fix-release/290939
https://blog.discourse.org/2024/01/celebrating-discourse-3-2/
https://meta.discourse.org/t/3-2-1-security-and-bug-fix-release/298237
https://meta.discourse.org/t/3-2-2-bug-fix-release/307780

Co-Authored-By: Christian Albrecht <christian.albrecht@mayflower.de>
Fixes: CVE-2023-38706, CVE-2023-40588, CVE-2023-41043, CVE-2023-41042,
       CVE-2023-44388, CVE-2023-43814, CVE-2023-45147, CVE-2023-43659,
       CVE-2023-44391, CVE-2023-45131, CVE-2023-47120, CVE-2023-45816,
       CVE-2023-46130, CVE-2023-47119, CVE-2023-47121, CVE-2023-45806,
       CVE-2023-49099, CVE-2024-21655, CVE-2024-21655, CVE-2023-48297,
       CVE-2024-24748, CVE-2024-24827, CVE-2024-27085, CVE-2024-27100,
       CVE-2024-28242
(cherry picked from commit 25755c0d20)
2024-05-27 13:56:11 +00:00
Martin Weinelt
427bdcc885 discourse: strip markers from plugin compat spec
The plugin updater would previously stumble over compat spec version
entries that begin with angled brackets.

````
< 3.3.0.beta1-dev: 56b0de3896361b6a87523537c8f5b450d2fe0807
3.2.0: 33c43ca51ac7b7baa8a309a269dcf8685b8bd638
< 3.2.0.beta2-dev: ac930c509e2a5b0c37b84bcea28d332e686add95
3.1.999: a304cd2028ccf1f5b00f5137633aa7027a1fd334
3.1.0.beta3: 9c270cac9abc1c2b30574d8c655fb3a90546236b
[...]
````

(cherry picked from commit 5cf005119a)
2024-05-27 13:56:11 +00:00
Martin Weinelt
54f359612f discourse: rely on packaging module for version comparison
The distutils module is deprecated and was removed in Python 3.12, which
would eventually break this updater.

(cherry picked from commit 3106519f14)
2024-05-27 13:56:11 +00:00
Aleksana
21f02582dc
Merge pull request #313957 from NixOS/backport-312495-to-release-24.05
[Backport release-24.05] hedgedoc: fix executing scripts
2024-05-25 13:08:56 +08:00
Olivér Falvai
15f3844c0c lemmy-server: fix darwin build
(cherry picked from commit 0fc86c4a7a)
2024-05-24 21:08:48 +00:00
Jonas Heinrich
9043a9df41 wordpressPackages.themes.proton: init at 1.0.1
(cherry picked from commit ef13f279d1)
2024-05-24 11:41:56 +00:00
Sandro Jäckel
aa465c1950 hedgedoc: fix executing scripts, delete unused setup script
(cherry picked from commit 10cadef027)
2024-05-23 11:06:54 +00:00
R. Ryantm
9121844bf7 wiki-js: 2.5.302 -> 2.5.303 2024-05-20 08:00:50 +00:00
Pol Dellaiera
831dced72e
Merge pull request #300228 from davidkna/kavita-fix-migrations
kavita: restore db migrations
2024-05-14 21:14:52 +02:00