Commit Graph

35643 Commits

Author SHA1 Message Date
terru
8108373f5f
mattermost: 9.5.4 → 9.5.6 (#318000)
this is a security release. announcement & changelog by upstream:
https://mattermost.com/blog/mattermost-security-updates-9-8-1-9-7-5-9-6-3-9-5-6-esr-released/

(cherry picked from commit 8f596b0585)
2024-06-08 08:32:12 +02:00
Malte Poll
64a0b92356 envoy: 1.30.1 -> 1.30.2
Contains security fixes for:
- [CVE-2024-34362: Crash (use-after-free) in EnvoyQuicServerStream](GHSA-hww5-43gv-35jv)
- [CVE-2024-34363: Crash due to uncaught nlohmann JSON exception](GHSA-g979-ph9j-5gg4)
- [CVE-2024-34364: Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response, and other components](GHSA-xcj3-h7vf-fw26)
- [CVE-2024-32974: Crash in EnvoyQuicServerStream::OnInitialHeadersComplete()](GHSA-mgxp-7hhp-8299)
- [CVE-2024-32975: Crash in QuicheDataReader::PeekVarInt62Length()](GHSA-g9mq-6v96-cpqc)
- [CVE-2024-32976: Endless loop while decompressing Brotli data with extra input](GHSA-7wp5-c2vq-4f8m)
- [CVE-2024-23326: Envoy incorrectly accepts HTTP 200 response for entering upgrade mode](GHSA-vcf8-7238-v74c)

(cherry picked from commit 7e537acfea)
2024-06-05 19:30:12 +00:00
Nick Cao
812a26a921
Merge pull request #317318 from NixOS/backport-317208-to-release-24.05
[Backport release-24.05] keycloak: 24.0.4 -> 24.0.5
2024-06-05 14:55:07 -04:00
Sandro
8202acc7e9
Merge pull request #316740 from NixOS/backport-316581-to-release-24.05 2024-06-05 12:17:41 +02:00
Sandro
27a48a8e16
Merge pull request #316124 from NixOS/backport-315880-to-release-24.05 2024-06-05 11:17:45 +02:00
Leona Maroni
bcb634b9bc keycloak: 24.0.4 -> 24.0.5
Diff: https://github.com/keycloak/keycloak/compare/24.0.4...24.0.5
Changelog: https://github.com/keycloak/keycloak/releases/tag/24.0.5
(cherry picked from commit 0cc8886079)
2024-06-04 23:44:54 +00:00
Izorkin
1c1cf8246a angie: 1.5.1 -> 1.5.2
(cherry picked from commit a79f4a9161)
2024-06-04 07:56:23 +00:00
tcmal
7727292568 akkoma: 3.13.1 -> 3.13.2
(cherry picked from commit 05a94bb1ad)
2024-06-04 01:14:04 +02:00
R. Ryantm
026bbe43fa angie: 1.4.1 -> 1.5.1
(cherry picked from commit 510ea77aea)
2024-06-03 19:32:08 +00:00
Robert Schütz
0bc6b82217 nextcloud-notify_push: 0.6.11 -> 0.6.12
Diff: https://github.com/nextcloud/notify_push/compare/v0.6.11...v0.6.12

Changelog: https://github.com/nextcloud/notify_push/releases/tag/v0.6.12
(cherry picked from commit 3039b5ddef)
2024-06-02 21:19:31 +00:00
Robert Schütz
f0ec8c7c6c nextcloudPackages: update
(cherry picked from commit 80c129e782)
2024-06-02 21:19:31 +00:00
Robert Schütz
8faf3d123f nextcloud27: 27.1.9 -> 27.1.10
Changelog: https://nextcloud.com/changelog/#27-1-10
(cherry picked from commit 28b2e9ac03)
2024-06-02 21:19:31 +00:00
John Titor
6b98d222fe agate: cleanup
format with nixfmt-rfc-style
use `lib.` explicitly

update changelog url

(cherry picked from commit efd4ac1194)
2024-06-02 16:50:10 +00:00
John Titor
be59aadee1 agate: 3.3.4 -> 3.3.7
add new dependency openssl
add nix update script

(cherry picked from commit 01eec1f849)
2024-06-02 16:50:10 +00:00
Franz Pletz
8cfcfb6836
Merge pull request #316281 from NixOS/backport-316104-to-release-24.05
[Backport release-24.05] nginxMainline: 1.25.4 -> 1.27.0, nginx: 1.26.0 -> 1.26.1
2024-06-02 17:33:26 +02:00
Nick Cao
3492c064a3
Merge pull request #316480 from NixOS/backport-316432-to-release-24.05
[Backport release-24.05] maintainers: add teutat3s to matrix team + several packages
2024-06-02 10:10:11 -04:00
Emmanuel Rosa
69ce9702ff jetty: 12.0.8 -> 12.0.9
(cherry picked from commit 6c62ac1bef)
2024-06-02 11:55:08 +00:00
teutat3s
9c7405e7ce sensu-go-backend: add teutat3s to maintainers
(cherry picked from commit 9d7201ea55)
2024-06-01 18:05:50 +00:00
R. Ryantm
9f54a39ed8 db-rest: 6.0.4 -> 6.0.5
(cherry picked from commit f28c234b08)
2024-06-01 13:48:17 +00:00
Nick Cao
73a35e849d
Merge pull request #316227 from NixOS/backport-315709-to-release-24.05
[Backport release-24.05] evcc: 0.126.4 -> 0.126.5
2024-06-01 09:40:46 -04:00
Thomas Gerbet
693e9a5b33 nginxMainline: 1.25.4 -> 1.27.0
Fixes CVE-2024-32760, CVE-2024-31079, CVE-2024-35200 and CVE-2024-34161.

Changes:
```

Changes with nginx 1.27.0                                        29 May 2024

    *) Security: when using HTTP/3, processing of a specially crafted QUIC
       session might cause a worker process crash, worker process memory
       disclosure on systems with MTU larger than 4096 bytes, or might have
       potential other impact (CVE-2024-32760, CVE-2024-31079,
       CVE-2024-35200, CVE-2024-34161).
       Thanks to Nils Bars of CISPA.

    *) Feature: variables support in the "proxy_limit_rate",
       "fastcgi_limit_rate", "scgi_limit_rate", and "uwsgi_limit_rate"
       directives.

    *) Bugfix: reduced memory consumption for long-lived requests if "gzip",
       "gunzip", "ssi", "sub_filter", or "grpc_pass" directives are used.

    *) Bugfix: nginx could not be built by gcc 14 if the --with-atomic
       option was used.
       Thanks to Edgar Bonet.

    *) Bugfixes in HTTP/3.

Changes with nginx 1.25.5                                        16 Apr 2024

    *) Feature: virtual servers in the stream module.

    *) Feature: the ngx_stream_pass_module.

    *) Feature: the "deferred", "accept_filter", and "setfib" parameters of
       the "listen" directive in the stream module.

    *) Feature: cache line size detection for some architectures.
       Thanks to Piotr Sikora.

    *) Feature: support for Homebrew on Apple Silicon.
       Thanks to Piotr Sikora.

    *) Bugfix: Windows cross-compilation bugfixes and improvements.
       Thanks to Piotr Sikora.

    *) Bugfix: unexpected connection closure while using 0-RTT in QUIC.
       Thanks to Vladimir Khomutov.
```

(cherry picked from commit 35c696f49f)
2024-05-31 23:05:17 +00:00
Thomas Gerbet
cbfa794ed5 nginx: 1.26.0 -> 1.26.1
Fixes CVE-2024-32760, CVE-2024-31079, CVE-2024-35200 and CVE-2024-34161.
Note that the `nginxQuic` derivation rely on `nginxMainline`.

Changes:
```
Changes with nginx 1.26.1                                        29 May 2024

    *) Security: when using HTTP/3, processing of a specially crafted QUIC
       session might cause a worker process crash, worker process memory
       disclosure on systems with MTU larger than 4096 bytes, or might have
       potential other impact (CVE-2024-32760, CVE-2024-31079,
       CVE-2024-35200, CVE-2024-34161).
       Thanks to Nils Bars of CISPA.

    *) Bugfix: reduced memory consumption for long-lived requests if "gzip",
       "gunzip", "ssi", "sub_filter", or "grpc_pass" directives are used.

    *) Bugfix: nginx could not be built by gcc 14 if the --with-atomic
       option was used.
       Thanks to Edgar Bonet.

    *) Bugfix: in HTTP/3.

```

(cherry picked from commit 25e4a15f2a)
2024-05-31 23:05:17 +00:00
R. Ryantm
542c85a805 pdns: 4.9.0 -> 4.9.1
(cherry picked from commit 4dd185ece5)
2024-05-31 22:47:18 +00:00
Nikita Uvarov
480f868002 home-assistant: pin pymelcloud at 2.5.9
(cherry picked from commit 37733ad1ba)
2024-05-31 22:28:52 +00:00
Martin Weinelt
9ccd5056af evcc: 0.126.4 -> 0.126.5
https://github.com/evcc-io/evcc/releases/tag/0.126.5
(cherry picked from commit f315095bd6)
2024-05-31 18:39:55 +00:00
gaykitty
28a856c728 stargazer: 1.1.0 -> 1.2.1
(cherry picked from commit 43b1df204b)
2024-05-31 10:57:39 +00:00
Vladimír Čunát
0190ac4988 knot-resolver: 5.7.2 -> 5.7.3
https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.3
(cherry picked from commit 5024fba1b3)
2024-05-31 10:36:34 +00:00
Kerstin Humm
33d8e27657 mastodon: 4.2.8 -> 4.2.9
(cherry picked from commit b5fe321055)
2024-05-30 17:12:04 +00:00
Kerstin Humm
be15fecdbb mastodon: remove outdated override for openssl 3 support
(cherry picked from commit c42df26a93)
2024-05-30 17:12:04 +00:00
Martin Weinelt
ee71dc410c evcc: 0.126.3 -> 0.126.4
https://github.com/evcc-io/evcc/releases/tag/0.126.4
(cherry picked from commit 2eaea7071a)
2024-05-29 19:35:31 +00:00
Guanran Wang
1a307bb870 matrix-synapse-unwrapped: 1.107.0 -> 1.108.0
Diff: https://github.com/element-hq/synapse/compare/v1.107.0...v1.108.0

Changelog: https://github.com/element-hq/synapse/releases/tag/v1.108.0
(cherry picked from commit b2b2a2d085)
2024-05-29 13:33:52 +00:00
TomaSajt
770d2011f1 photofield: add patch for Go 1.22 support
(cherry picked from commit c4252653c1)
2024-05-28 20:04:13 +00:00
Nick Cao
1c9af90d8b
Merge pull request #315272 from NixOS/backport-314775-to-release-24.05
[Backport release-24.05] jellyfin, jellyfin-web: 10.9.1 -> 10.9.3, 10.9.2 -> 10.9.3
2024-05-28 15:20:51 -04:00
Sandro Jäckel
7f2547a15b tailscale: fix tailscale ssh
Closes #310950

(cherry picked from commit d2eeeb450a)
2024-05-28 09:04:24 +00:00
Nano Twerpus
62f30688dc jellyfin-web: add assert version == jellyfin.version to src
(cherry picked from commit 30dac56dab)
2024-05-28 07:05:39 +00:00
Nano Twerpus
0ef09bf23d jellyfin-web: 10.9.2 -> 10.9.3
(cherry picked from commit 5cd7bbe6fe)
2024-05-28 07:05:39 +00:00
Nano Twerpus
e5c147151a jellyfin: 10.9.1 -> 10.9.3
The `default.nix` was also formatted with `nixfmt-rfc-style` to be `RFC 166`-compliant.

(cherry picked from commit a7441feb23)
2024-05-28 07:05:38 +00:00
Robert Scott
42e3277186
Merge pull request #315182 from justinas/24-05-backport-314573
[24.05]  teleport_13: remove
2024-05-27 22:00:26 +01:00
Justinas Stankevicius
dac0b86b6a teleport_13: remove 2024-05-27 23:14:53 +03:00
Martin Weinelt
55ee801174 discourse: build discourseAllPlugins in passthru.tests.
Useful to reveal failing plugin builds.

(cherry picked from commit 898d023384)
2024-05-27 19:32:18 +00:00
Martin Weinelt
432e435a69 discourse: update plugins
(cherry picked from commit 1d2d14cc1f)
2024-05-27 19:32:18 +00:00
Atemu
c5ddb6cbc7
Merge pull request #314815 from NixOS/backport-314337-to-release-24.05
[Backport release-24.05] nextcloudPackages.richdocuments: init
2024-05-27 19:44:48 +02:00
Maximilian Bosch
1df68e31d2
Merge pull request #315098 from NixOS/backport-314939-to-release-24.05
[Backport release-24.05] grafana-image-renderer: 3.10.2 -> 3.10.5
2024-05-27 16:16:46 +00:00
Maximilian Bosch
818e481946 grafana-image-renderer: 3.10.2 -> 3.10.5
ChangeLogs:
* https://github.com/grafana/grafana-image-renderer/releases/tag/v3.10.3
* https://github.com/grafana/grafana-image-renderer/releases/tag/v3.10.4
* https://github.com/grafana/grafana-image-renderer/releases/tag/v3.10.5

(cherry picked from commit 8dd0b1d0ab)
2024-05-27 14:14:49 +00:00
Martin Weinelt
4d2a8b2c58 discourse: 3.1.0 -> 3.2.2
https://meta.discourse.org/t/3-1-1-security-and-bug-fix-release/278760
https://meta.discourse.org/t/3-1-2-security-and-bug-fix-release/282427
https://meta.discourse.org/t/3-1-3-security-and-bug-fix-release/284973
https://meta.discourse.org/t/3-1-4-security-and-bug-fix-release/290939
https://blog.discourse.org/2024/01/celebrating-discourse-3-2/
https://meta.discourse.org/t/3-2-1-security-and-bug-fix-release/298237
https://meta.discourse.org/t/3-2-2-bug-fix-release/307780

Co-Authored-By: Christian Albrecht <christian.albrecht@mayflower.de>
Fixes: CVE-2023-38706, CVE-2023-40588, CVE-2023-41043, CVE-2023-41042,
       CVE-2023-44388, CVE-2023-43814, CVE-2023-45147, CVE-2023-43659,
       CVE-2023-44391, CVE-2023-45131, CVE-2023-47120, CVE-2023-45816,
       CVE-2023-46130, CVE-2023-47119, CVE-2023-47121, CVE-2023-45806,
       CVE-2023-49099, CVE-2024-21655, CVE-2024-21655, CVE-2023-48297,
       CVE-2024-24748, CVE-2024-24827, CVE-2024-27085, CVE-2024-27100,
       CVE-2024-28242
(cherry picked from commit 25755c0d20)
2024-05-27 13:56:11 +00:00
Martin Weinelt
427bdcc885 discourse: strip markers from plugin compat spec
The plugin updater would previously stumble over compat spec version
entries that begin with angled brackets.

````
< 3.3.0.beta1-dev: 56b0de3896361b6a87523537c8f5b450d2fe0807
3.2.0: 33c43ca51ac7b7baa8a309a269dcf8685b8bd638
< 3.2.0.beta2-dev: ac930c509e2a5b0c37b84bcea28d332e686add95
3.1.999: a304cd2028ccf1f5b00f5137633aa7027a1fd334
3.1.0.beta3: 9c270cac9abc1c2b30574d8c655fb3a90546236b
[...]
````

(cherry picked from commit 5cf005119a)
2024-05-27 13:56:11 +00:00
Martin Weinelt
54f359612f discourse: rely on packaging module for version comparison
The distutils module is deprecated and was removed in Python 3.12, which
would eventually break this updater.

(cherry picked from commit 3106519f14)
2024-05-27 13:56:11 +00:00
Maximilian Bosch
3f3c03a9b6
grafana: 10.4.2 -> 10.4.3
ChangeLog: https://github.com/grafana/grafana/releases/tag/v10.4.3
2024-05-26 23:05:17 +02:00
Maximilian Bosch
1c63eb563d
Merge pull request #314782 from NixOS/backport-314096-to-release-24.05
[Backport release-24.05] nextcloud28: 28.0.5 -> 28.0.6, nextcloud29: 29.0.0 -> 29.0.1
2024-05-26 15:51:38 +00:00
Martin Weinelt
4e6eae43a4 python312Packages.homeassistant-stubs: 2024.5.4 -> 2024.5.5
https://github.com/KapJI/homeassistant-stubs/releases/tag/2024.5.5
(cherry picked from commit fe41047e4c)
2024-05-26 13:44:50 +00:00