Commit Graph

708922 Commits

Author SHA1 Message Date
Adam C. Stephens
48d0b9dd10
[Backport release-24.11] nixos/kanidm: add provisioning secret directories to BindReadOnlyPaths (#357915) 2024-11-21 11:48:55 -05:00
Sandro
d74abb1d11
[Backport release-24.11] searxng: 0-unstable-2024-10-05 -> 0-unstable-2024-11-17 (#357918) 2024-11-21 17:14:04 +01:00
Sandro
66206bb85c
[Backport release-24.11] nixos/opendkim: modernize, add expandable settings option, put config file under standard location (#357396) 2024-11-21 15:57:24 +01:00
Sandro
f5e19b9e24
[Backport release-24.11] nixos/arp-scan: init, nixos/tcpdump: init (#357214) 2024-11-21 15:56:54 +01:00
⛧-440729 [sophie]
56a9afecff searxng: 0-unstable-2024-10-05 -> 0-unstable-2024-11-17
(cherry picked from commit ef02dff02c)
2024-11-21 14:53:37 +00:00
oddlama
48be85e7c7 nixos/kanidm: add provisioning secret directories to BindReadOnlyPaths
(cherry picked from commit 3e29e0560d)
2024-11-21 14:47:12 +00:00
Aleksana
b9dc4f3cfc
[Backport release-24.11] p4: fix darwin build (#357910) 2024-11-21 21:47:39 +08:00
David McFarland
8668fe0371 p4: fix darwin build
(cherry picked from commit 0a54d674cb)
2024-11-21 13:46:04 +00:00
Aleksana
5d0d706904
[Backport release-24.11] jami: 20240823 -> 20241031.0; fix build with libgit2 1.8.4 (#357909) 2024-11-21 21:46:02 +08:00
Sandro
d390a72bf8
[Backport release-24.11] yt-dlp: 2024.11.4 -> 2024.11.18 (#357891) 2024-11-21 14:45:45 +01:00
linsui
0aaaeb9dd3 jami: 20240823 -> 20241031.0
(cherry picked from commit 13a26c516c)
2024-11-21 13:43:38 +00:00
linsui
05469c7903 jami: fix build with libgit2 1.8.4
(cherry picked from commit 6b4dfe7199)
2024-11-21 13:43:38 +00:00
Aleksana
f148723f71
[Backport release-24.11] opensc: fix darwin build (#357908) 2024-11-21 21:43:37 +08:00
Michael Adler
a8c339fe13 opensc: fix darwin build
Closes #357432

(cherry picked from commit 304d33e04d)
2024-11-21 13:42:37 +00:00
Aleksana
96dcda230c
[Backport release-24.11] doc: change allowInsecurePredicate example to a useful one (#357899) 2024-11-21 21:07:42 +08:00
Sandro
2cfbf28a89 doc: change allowInsecurePredicate example to a useful one
(cherry picked from commit 73b6567c41)
2024-11-21 13:07:05 +00:00
Aleksana
30e58f7357
[Backport release-24.11] nixos/tabby: fix typo (#357896) 2024-11-21 21:03:56 +08:00
Ughur Alakbarov
9746c8b7ee nixos/tabby: fix typo
(cherry picked from commit f21d3a0f07)
2024-11-21 13:02:20 +00:00
Sandro Jäckel
6aeb89826c yt-dlp: 2024.11.4 -> 2024.11.18
Changelog: https://github.com/yt-dlp/yt-dlp/blob/HEAD/Changelog.md
(cherry picked from commit 2162745225)
2024-11-21 12:56:07 +00:00
Aleksana
82ce4b96e3
[Backport release-24.11] doc/stdenv: fix a typo (#357888) 2024-11-21 20:54:48 +08:00
Kenichi Kamiya
113c61683b doc/stdenv: fix a typo
(cherry picked from commit 2d4dfc04b4)
2024-11-21 12:51:41 +00:00
Florian Klink
b8769f901d
[Backport release-24.11] qdigidoc: fix TSL loading (#357534) 2024-11-21 13:50:53 +02:00
Emily
b92a8e9e6f
[Backport release-24.11] ungoogled-chromium: 131.0.6778.69-1 -> 131.0.6778.85-1 (#357862) 2024-11-21 12:01:47 +01:00
Franz Pletz
8e948b37fb
[Backport release-24.11] urh: add wrapGAppsHook3 (#357845) 2024-11-21 11:46:19 +01:00
networkException
4a21ed568a ungoogled-chromium: 131.0.6778.69-1 -> 131.0.6778.85-1
https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_19.html

This update includes 3 security fixes.

CVEs:
CVE-2024-11395

(cherry picked from commit bd84f1c657)
2024-11-21 10:35:45 +00:00
networkException
439ec33ea7 chromium: use cached dependencies from other attributes in update script
This patch extends the caching mechanism of the chromium
update scripts to use cached dependencies of all attributes
in the lockfile.

When updating ungoogled-chromium for example, the update script
will now use cached dependencies from vanilla chromium, usually
meaning that no additional fetching has to be done.

(cherry picked from commit 68d51619a2)
2024-11-21 10:35:45 +00:00
Emily
28626e01c5
[Backport release-24.11] chromium: fetch src from git instead of using release tarball, {ungoogled-,}chromium,chromedriver: 130.0.6723.116 -> 131.0.6778.69/85 (#357678) 2024-11-21 11:34:40 +01:00
Aleksana
991904fa88
[Backport release-24.11] git-smash: init at 0.1.1 (#357810) 2024-11-21 18:28:36 +08:00
Atemu
6490cdc578
[Backport release-24.11] linux_xanmod, linux_xanmod_latest: 2024-11-17 (#357564) 2024-11-21 10:58:13 +01:00
Paw Møller
94389bb1ff urh: add wrapGAppsHook3 (#357400)
(cherry picked from commit 96ae446175)
2024-11-21 09:54:59 +00:00
Franz Pletz
aea647643b
[Backport release-24.11] wget: 1.24.5 -> 1.25.0 (#357202) 2024-11-21 10:37:21 +01:00
Jon Seager
138a472850
[Backport release-24.11] google-chrome: 131.0.6778.69 -> 131.0.6778.85 (#357821) 2024-11-21 09:09:59 +00:00
John Titor
0016cd3dff google-chrome: 131.0.6778.69 -> 131.0.6778.85
(cherry picked from commit bd6d61f02d)
2024-11-21 08:35:42 +00:00
Bazyli Cyran
bceb563011 git-smash: init at 0.1.1
(cherry picked from commit 63cc45e9ea)
2024-11-21 08:22:03 +00:00
Aleksana
a5a963c1a2
[Backport release-24.11] upscaler: init at 1.4.0 (#357475) 2024-11-21 16:18:54 +08:00
Aleksana
1f7fe81f2e
[Backport release-24.11] snipaste: add desktop entries (#357806) 2024-11-21 16:14:28 +08:00
panda2134
4784023f58 snipaste: add desktop entries
(cherry picked from commit f56bbed24b)
2024-11-21 08:13:28 +00:00
Naïm Camille Favier
f17a91f464
[Backport release-24.11] nixos/libreswan: use environment.etc."ipsec.secrets".text (#357775) 2024-11-21 08:19:13 +01:00
Naïm Favier
65933c9eb9 nixos/libreswan: use environment.etc."ipsec.secrets".text
This is to ensure compatibility with the networkmanager module, which
uses the `text` option.

(cherry picked from commit b294762bb9)
2024-11-21 07:18:48 +00:00
José Romildo Malaquias
ed0df42190
[Backport release-24.11] ibm-plex: 6.4.0 -> 1.1.0, add @ryanccn as maintainer (#357741) 2024-11-20 23:35:03 -03:00
Ryan Cao
99a571aea7 ibm-plex: add @ryanccn as maintainer
(cherry picked from commit da4a805906)
2024-11-21 01:45:45 +00:00
Ryan Cao
e6db7d6820 ibm-plex: 6.4.0 -> 1.1.0
(cherry picked from commit 18ad5961d2)
2024-11-21 01:45:45 +00:00
Yt
8b31f63a2b
[Backport release-24.11] meilisearch: migrate to the new macOS SDK (#357349) 2024-11-20 18:48:52 -05:00
Nick Cao
fd3a0748f0
[Backport release-24.11] alembic: fix hash (#357637) 2024-11-20 17:17:00 -05:00
Gaétan Lepage
4cb4d316e6
[Backport release-24.11] mission-center: use RUSTFLAGS to link libGL and libvulkan; adopt (#357509) 2024-11-20 23:09:46 +01:00
emilylange
7b74a044f9 chromium,chromedriver: 131.0.6778.69 -> 131.0.6778.85
https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_19.html

This update includes 3 security fixes.

CVEs:
CVE-2024-11395

(cherry picked from commit eaa1bb9980)
2024-11-20 21:48:11 +00:00
emilylange
03b6fa3e21 ungoogled-chromium: 130.0.6723.116-1 -> 131.0.6778.69-1
https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html

This update includes 12 security fixes.

CVEs:
CVE-2024-11110 CVE-2024-11111 CVE-2024-11112 CVE-2024-11113
CVE-2024-11114 CVE-2024-11115 CVE-2024-11116 CVE-2024-11117

(cherry picked from commit 54d69a3c79)
2024-11-20 21:48:11 +00:00
emilylange
ebd96b1e40 chromium,chromedriver: 130.0.6723.116 -> 131.0.6778.69
https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html

This update includes 12 security fixes.

CVEs:
CVE-2024-11110 CVE-2024-11111 CVE-2024-11112 CVE-2024-11113
CVE-2024-11114 CVE-2024-11115 CVE-2024-11116 CVE-2024-11117

(cherry picked from commit 875ae81fe5)
2024-11-20 21:48:11 +00:00
emilylange
7f0b52f1aa chromium: fetch src from git instead of using release tarball
This builds upon Yureka's work to build electron from source.
A lot of the newly introduced changes to the chromium derivation and
update script are 1-to-1 copies or slight derivates of that work.

Especially the newly added depot_tools.py to resolve the DEPS files does
most of the heavy lifting and is an ever so slightly modified version of
that section Yureka implemented in electron's update.py.

Some coordination between the chromium and electron maintainers should
allow us to deduplicate a lot of the duplicated code fairly easily in
the future.

That just wasn't a goal with this commit, due to time constraints and
the urgency to switch away from the release tarballs.

Instead of taking just a few hours for a tarball to be available for
download after a release, it now takes multiple days at least.

At the time of writing, roughly a week after M131 was released, the
tarball is still not available. It's unclear if it will ever be.

Reason for this are CI issues on Google's side.

Note that virtually every release contains some security critical fixes.

Also note that this commit is written with a lot of conditionals so the
electron derivation doesn't change (just yet).

The new update.mjs update script is still very much work-in-progress but
gets the job done.

Co-Authored-By: Yureka <yuka@yuka.dev>
(cherry picked from commit 8dd2f1add9)
2024-11-20 21:48:11 +00:00
emilylange
27a9cb1168 chromium: remove "channel" argument
This is no longer used as we only differentiate between stable and
ungoogled-chromium, which we already track in the "ungoogled" boolean.

Beta and dev channels are gone for good.
It's been a year since their removal in 59719f787e.

There is, however, an additional channel mapping in nixos/tests/chromium
but that one is independent from this one here.

(cherry picked from commit ebb40bd5c2)
2024-11-20 21:48:11 +00:00