9893 Commits
Author SHA1 Message Date
Martin WeineltandGitHub de27c67ec4 firefox-unwrapped: 153.0.1 -> 153.0.3 (#548984) 2026-08-04 12:54:43 +00:00
Martin Weinelt ece3a41047 firefox-bin-unwrapped: 153.0.1 -> 153.0.3
https://www.firefox.com/en-US/firefox/153.0.3/releasenotes/
2026-08-04 02:39:08 +02:00
Martin Weinelt 911fe98de2 firefox-unwrapped: 153.0.1 -> 153.0.3
https://www.firefox.com/en-US/firefox/153.0.3/releasenotes/
2026-08-04 02:33:47 +02:00
Jack Boykin e7e521c4f9 firefox: use ffmpeg 8 for browsers that support it
Assisted-by: Claude Code (Claude Fable 5)
2026-08-03 12:58:20 -05:00
Steven Allen 2341bac551 brave, brave-origin: 1.92.144 -> 1.93.129
Changelog: https://community.brave.app/t/release-channel-1-93-129/656295
2026-08-01 09:36:48 -07:00
JoandGitHub b6a278d4bf firefox-devedition-unwrapped: 153.0b13 -> 154.0b4 (#547743) 2026-07-31 15:29:12 +00:00
R. Ryantm 336f08a733 firefox-devedition-unwrapped: 153.0b13 -> 154.0b4 2026-07-31 12:32:33 +00:00
emilylange ec0552d1d2 ungoogled-chromium: 150.0.7871.186-1 -> 151.0.7922.71-1
https://developer.chrome.com/blog/new-in-chrome-151

https://developer.chrome.com/release-notes/151

https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html

This update includes 370 security fixes.
2026-07-31 14:04:10 +02:00
EmilyandGitHub c07a713595 chromium,chromedriver: 150.0.7871.186 -> 151.0.7922.71 (#547085) 2026-07-30 13:28:38 +00:00
André SilvaandGitHub a892960fd4 brave, brave-origin: fix overriding (#545834) 2026-07-30 08:53:29 +00:00
emilylange dc83067caa chromium,chromedriver: 150.0.7871.186 -> 151.0.7922.71
https://developer.chrome.com/blog/new-in-chrome-151

https://developer.chrome.com/release-notes/151

https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html

This update includes 370 security fixes.
2026-07-30 02:49:47 +02:00
EmilyandGitHub a2c76aa3a1 chromium: remove no longer needed version conditionals, remove warnObsoleteVersionConditional (#544281) 2026-07-29 11:15:03 +00:00
Martin Weinelt 0e54aaa7db firefox-bin-unwrapped: 153.0 -> 153.0.1
https://www.firefox.com/en-US/firefox/153.0.1/releasenotes/
2026-07-28 17:25:04 +02:00
Martin Weinelt e8dfe47956 firefox-unwrapped: 153.0 -> 153.0.1
https://www.firefox.com/en-US/firefox/153.0.1/releasenotes/
2026-07-28 17:23:44 +02:00
Steven Allen 37004cbc02 brave, brave-origin: fix overriding
Previously, the `callPackage ./make-brave.nix { }` call produced a
function that was immediately evaluated to produce a package.
Unfortunately, because callPackage did not directly produce the package,
the final package wasn't overridable (no `.override` function).

This patch instead evaluates the brave/brave-origin function first to
produce the "package" function, then calls callPackage on the resulting
package function.
2026-07-25 20:49:21 -07:00
EmilyandGitHub a4d98e40c7 chromium: remove broken pulseSupport = false; override (#540868) 2026-07-25 23:18:16 +00:00
Rachala Rajandbuckley310 a16f93f8da brave, brave-origin: extract shared builder, init at 1.92.144
Introduce brave-origin variant and extract a shared builder for Brave.

- brave: 1.92.144
- brave-origin: new, 1.92.144

Brave Origin is a stripped-down build that drops non-privacy extras
(rewards, wallet, AI, etc.) while keeping Shields and the Chromium engine.

The shared builder lives outside pkgs/by-name/ because by-name forbids
cross-directory file references. Layout follows the firefox pattern.

Co-authored-by: buckley310 <buckley310@users.noreply.github.com>
2026-07-25 07:41:08 +05:30
networkException ca3cf20814 ungoogled-chromium: 150.0.7871.181-1 -> 150.0.7871.186-1
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html

This update includes 4 security fixes.

CVEs:
CVE-2026-16807 CVE-2026-16806 CVE-2026-16805 CVE-2026-16804
2026-07-24 22:07:01 +02:00
emilylange 36e02b4b99 chromium,chromedriver: 150.0.7871.181 -> 150.0.7871.186
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html

This update includes 4 security fixes.

CVEs:
CVE-2026-16807 CVE-2026-16806 CVE-2026-16805 CVE-2026-16804
2026-07-24 00:05:15 +02:00
networkException 0337b01dec ungoogled-chromium: 150.0.7871.128-1 -> 150.0.7871.181-1
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html

This update includes 12 security fixes.

CVEs:
CVE-2026-16420 CVE-2026-16421 CVE-2026-16413 CVE-2026-16414
CVE-2026-16415 CVE-2026-16416 CVE-2026-16417 CVE-2026-16418
CVE-2026-16419 CVE-2026-16422 CVE-2026-16423 CVE-2026-16424
2026-07-23 16:50:36 +02:00
emilylange eab52df279 chromium,chromedriver: 150.0.7871.128 -> 150.0.7871.181
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html

This update includes 12 security fixes.

CVEs:
CVE-2026-16420 CVE-2026-16421 CVE-2026-16413 CVE-2026-16414
CVE-2026-16415 CVE-2026-16416 CVE-2026-16417 CVE-2026-16418
CVE-2026-16419 CVE-2026-16422 CVE-2026-16423 CVE-2026-16424
2026-07-22 16:24:12 +02:00
Ihar HrachyshkaandGitHub 928e9dcf55 firefox: fix flaky dylib check due to SIGPIPE race (#540753) 2026-07-20 23:22:12 +00:00
Martin Weinelt a918775d8e firefox-esr-153-unwrapped: init at 153.0esr
https://www.firefox.com/en-US/firefox/153.0esr/releasenotes/
2026-07-20 14:32:12 +02:00
Martin Weinelt eca1c79425 firefox-esr-140-unwrapped: 140.12.0esr -> 140.13.0esr
https://www.firefox.com/en-US/firefox/140.13.0/releasenotes/
2026-07-20 12:35:09 +02:00
Martin Weinelt ef18f798a5 firefox-bin-unwrapped: 152.0.6 -> 153.0
https://www.firefox.com/en-US/firefox/153.0/releasenotes/
2026-07-20 12:34:41 +02:00
Martin Weinelt 8777b26d00 firefox-unwrapped: 152.0.6 -> 153.0
https://www.firefox.com/en-US/firefox/153.0/releasenotes/
2026-07-20 12:33:55 +02:00
Ben SiraphobandGitHub eeefc5b648 firefox-esr: build on 32-bit (#542781) 2026-07-18 17:30:55 +00:00
networkException a077c7d5a2 ungoogled-chromium: 150.0.7871.124-1 -> 150.0.7871.128-1
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html

This update includes 7 security fixes.

CVEs:
CVE-2026-15899 CVE-2026-15900 CVE-2026-15901 CVE-2026-15902
CVE-2026-15903 CVE-2026-15904 CVE-2026-15905
2026-07-17 12:57:53 +02:00
Ryan HendricksonandGitHub 0a3b3cb71b firefox-beta-unwrapped: 152.0b10 -> 153.0b13; firefox-devedition-unwrapped: 153.0b11 -> 153.0b13 (#537915) 2026-07-17 05:37:58 +00:00
emilylange 86292d1b1a chromium,chromedriver: 150.0.7871.124 -> 150.0.7871.128
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html

This update includes 7 security fixes.

CVEs:
CVE-2026-15899 CVE-2026-15900 CVE-2026-15901 CVE-2026-15902
CVE-2026-15903 CVE-2026-15904 CVE-2026-15905
2026-07-17 01:44:18 +02:00
Tol Wassman ffb5b4b000 firefox-devedition-unwrapped: 153.0b11 -> 153.0b13 2026-07-16 21:19:20 +00:00
Tol Wassman 38de0900df firefox-beta-unwrapped: 152.0b10 -> 153.0b13 2026-07-16 21:19:19 +00:00
Ben Siraphob 3be9b65683 firefox-esr: build on 32-bit 2026-07-16 13:52:45 -07:00
zowoqandGitHub e07740f898 treewide: drop x86_64-darwin from update scripts (#541166) 2026-07-16 01:27:09 +00:00
Heitor AugustoandGitHub d59516748c various: clean up after x86_64-darwin drop (#541168) 2026-07-15 20:27:20 +00:00
networkException c187e9f688 ungoogled-chromium: 150.0.7871.114-1 -> 150.0.7871.124-1
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html

This update includes 15 security fixes.

CVEs:
CVE-2026-15764 CVE-2026-15765 CVE-2026-15766 CVE-2026-15767
CVE-2026-15768 CVE-2026-15769 CVE-2026-15770 CVE-2026-15771
CVE-2026-15772 CVE-2026-15773 CVE-2026-15774 CVE-2026-15775
CVE-2026-15776 CVE-2026-15777 CVE-2026-15778
2026-07-15 20:48:01 +02:00
emilylange 2213bc070c chromium: remove warnObsoleteVersionConditional
It's been 5 years[^1] since this feature has been added and 1 year[^2]
since it has been muted by default.

I don't think we need this anymore. This rather simple implementation
has some deficiencies with more complex conditionals, and it is also
just surprisingly easy to run into infinite recursions caused by it.

And while I can only really speculate what the motivation behind its
addition was, the maintainer situation has drastically changed since
then, and it's just not that useful anymore.

[^1]: eb335f697e
[^2]: 8f16c0955e
2026-07-15 18:30:46 +02:00
emilylange 74444fb4e5 chromium: remove no longer needed version conditionals
The minimum versions for both chromium and electron-source are higher
than the version bounds of those conditionals.
As such, they can be safely removed.

This is a no-op.
2026-07-15 18:30:44 +02:00
Emily ec11a3817c chromedriver: drop x86_64-darwin from update script 2026-07-15 03:59:21 +01:00
Emily 993791272b firefox-bin: clean up after x86_64-darwin drop 2026-07-15 03:58:17 +01:00
Emily fdb820602b treewide: drop simple x86_64-darwin mentions
To reproduce:

    $ nix run nixpkgs/3b32825de172d0bc85664f495edb096b10862524#ast-grep \
        -- scan --update-all --inline-rules '
          id: nix-x86_64-darwin
          language: nix
          rule:
            any:
              - pattern: "\"x86_64-darwin\""
                kind: list_expression > string_expression
              - pattern:
                  context: "{ \"x86_64-darwin\" = $EXPR; }"
                  selector: binding
              - pattern:
                  context: "{ x86_64-darwin = $EXPR; }"
                  selector: binding
          fix:
            template: ""
        ' pkgs
    $ nix run nixpkgs/3b32825de172d0bc85664f495edb096b10862524#ast-grep \
        -- scan --update-all --inline-rules '
          id: json-first-x86_64-darwin
          language: json
          rule:
            kind: object > pair:nth-child(1)
            has:
              pattern: "\"x86_64-darwin\""
              field: key
          fix:
            template: ""
            expandEnd: { regex: "," }
        ' pkgs
    $ nix run nixpkgs/3b32825de172d0bc85664f495edb096b10862524#ast-grep \
        -- scan --update-all --inline-rules '
          id: json-x86_64-darwin
          language: json
          rule:
            kind: object > pair
            has:
              pattern: "\"x86_64-darwin\""
              field: key
          fix:
            template: ""
            expandStart: { regex: "," }
        ' pkgs
    $ git restore pkgs/by-name/om/omnix/package.nix
    $ git diff --name-only -z \
        | nix shell nixpkgs/3b32825de172d0bc85664f495edb096b10862524#gnused \
            -c xargs -0 sed -i '/^$/N; /^\n\? \+$/d'
    $ treefmt
2026-07-15 03:58:16 +01:00
emilylange c22f438f9d chromium,chromedriver: 150.0.7871.114 -> 150.0.7871.124
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html

This update includes 15 security fixes.

CVEs:
CVE-2026-15764 CVE-2026-15765 CVE-2026-15766 CVE-2026-15767
CVE-2026-15768 CVE-2026-15769 CVE-2026-15770 CVE-2026-15771
CVE-2026-15772 CVE-2026-15773 CVE-2026-15774 CVE-2026-15775
CVE-2026-15776 CVE-2026-15777 CVE-2026-15778
2026-07-15 00:30:26 +02:00
Martin Weinelt 7aee77157e firefox-bin-unwrapped: 152.0.5 -> 152.0.6
https://www.firefox.com/en-US/firefox/152.0.6/releasenotes/
2026-07-14 10:54:42 +02:00
Martin Weinelt 1b031faf6c firefox-unwrapped: 152.0.5 -> 152.0.6
https://www.firefox.com/en-US/firefox/152.0.6/releasenotes/
2026-07-14 10:53:38 +02:00
Felix BargfeldtandGitHub 062bfcb574 firefox/wrapper: enable strictDeps (#540042) 2026-07-12 22:16:36 +00:00
Ryan Hendrickson 37a224dda7 firefox-devedition-unwrapped: 152.0b3 -> 153.0b11 2026-07-11 19:20:50 -04:00
emilylange bb50b6eb9d chromium: remove broken pulseSupport = false; override
As far as I can tell, this override broke almost 10 years ago in
8391241e0c.

When trying to build the fixup commit that followed immediately after
that (5f53fddf1e) the build fails with the
following error:

~~~
[11704/21910] CXX obj/media/media/vp9_compressed_header_parser.o
[11705/>
FAILED: obj/media/audio/audio/audio_manager_alsa.o
g++ -MMD -MF obj/media/audio/audio/audio_manager_alsa.o.d [...]
In file included from ../../media/audio/alsa/audio_manager_alsa.cc:28:0:
../../media/audio/pulse/audio_manager_pulse.h:8:30: fatal error: pulse/pulseaudio.h: No such file or directory
compilation terminated.
ninja: build stopped: subcommand failed.
~~~

And the same happens when trying to build chromium with
`pulseSupport = false;` and picking random releases between 17.03 and
now.

I don't think there is a good reason to keep this, especially since no
one bothered to test this in almost a decade. The chromium derivation is
a mess, so let's run with this rather small win and remove this broken,
mostly useless, obscure and untested permutation.
2026-07-11 23:35:23 +02:00
Ihar Hrachyshka c0cc2fda70 firefox: fix flaky dylib check due to SIGPIPE race
The `otool ... | grep -q ...` pipeline sometimes fails with
PIPESTATUS=141 because of SIGPIPE race.

It happens because `grep -q` doesn't drain the pipe but exits on first
match. If it exists before `otool` writes its last line to stdout,
`otool` fails on write. It makes the whole dylib check fail. This
results in a symlink left pointing to a dylib file instead of copying
it, which may break the app.

The solution is to drain the pipeline with `grep -F`.
2026-07-11 09:26:47 -04:00
networkException f73f96fed5 ungoogled-chromium: 150.0.7871.100-1 -> 150.0.7871.114-1
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html

This update includes 27 security fixes.

CVEs:
CVE-2026-15112 CVE-2026-15129 CVE-2026-15132 CVE-2026-15133
CVE-2026-15108 CVE-2026-15109 CVE-2026-15110 CVE-2026-15111
CVE-2026-15113 CVE-2026-15114 CVE-2026-15115 CVE-2026-15116
CVE-2026-15117 CVE-2026-15118 CVE-2026-15119 CVE-2026-15120
CVE-2026-15121 CVE-2026-15122 CVE-2026-15123 CVE-2026-15124
CVE-2026-15125 CVE-2026-15126 CVE-2026-15127 CVE-2026-15128
CVE-2026-15130 CVE-2026-15107 CVE-2026-15131
2026-07-10 00:32:26 +02:00
emilylange 9168fb05e6 chromium,chromedriver: 150.0.7871.100 -> 150.0.7871.114
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html

This update includes 27 security fixes.

CVEs:
CVE-2026-15112 CVE-2026-15129 CVE-2026-15132 CVE-2026-15133
CVE-2026-15108 CVE-2026-15109 CVE-2026-15110 CVE-2026-15111
CVE-2026-15113 CVE-2026-15114 CVE-2026-15115 CVE-2026-15116
CVE-2026-15117 CVE-2026-15118 CVE-2026-15119 CVE-2026-15120
CVE-2026-15121 CVE-2026-15122 CVE-2026-15123 CVE-2026-15124
CVE-2026-15125 CVE-2026-15126 CVE-2026-15127 CVE-2026-15128
CVE-2026-15130 CVE-2026-15107 CVE-2026-15131
2026-07-09 22:40:16 +02:00