Commit Graph
964619 Commits
Author SHA1 Message Date
SandroandGitHub d481030eff steelix: init at 25.07-unstable-2026-03-01 (#493073) 2026-03-17 16:30:29 +00:00
K900andGitHub 21617e6de4 kdePackages: Plasma 6.6.2 -> 6.6.3 (#500761) 2026-03-17 16:30:12 +00:00
SandroandGitHub e04db598df gnome-manuals: init at 49.0 (#497761) 2026-03-17 16:28:23 +00:00
SandroandGitHub 800ca7a530 node-red: 4.1.2 -> 4.1.7 (#497694) 2026-03-17 16:25:59 +00:00
SandroandGitHub a1ce4e69ac tetrio-desktop: add darwin support (#493450) 2026-03-17 16:19:26 +00:00
K900 5b33be1427 kdePackages: Plasma 6.6.2 -> 6.6.3 2026-03-17 19:18:26 +03:00
SandroandGitHub 31db9cdf0d keycloak.plugins.keycloak-discord: 0.6.1 -> 1.3.1, migrate to iForged fork (#493214) 2026-03-17 16:17:16 +00:00
nixpkgs-ci[bot]andGitHub dbac689a85 tutanota-desktop: 332.260303.0 -> 336.260316.0 (#500695) 2026-03-17 16:16:06 +00:00
nixpkgs-ci[bot]andGitHub ff4915eace rinf_cli: 8.9.1 -> 8.10.0 (#500689) 2026-03-17 16:15:58 +00:00
nixpkgs-ci[bot]andGitHub be80397636 postmoogle: 0.9.28 -> 0.9.29 (#500335) 2026-03-17 16:15:56 +00:00
nixpkgs-ci[bot]andGitHub 21f0842a15 easyeffects: 8.1.2 -> 8.1.4 (#500310) 2026-03-17 16:15:52 +00:00
SandroandGitHub 97f9ae06c2 cliamp: init at 1.20.1 (#497321) 2026-03-17 16:14:54 +00:00
SandroandGitHub 66766a23ad scopehal-apps: 0.1 -> 0.1.1 (#496526) 2026-03-17 16:14:29 +00:00
SandroandGitHub 889adedeb2 librewolf-unwrapped: 148.0-1 -> 148.0.2-2 (#498625) 2026-03-17 16:14:15 +00:00
SandroandGitHub 1f90f69d7e python3Packages.nlpo3: 1.4.0-unstable-2024-11-11 -> 1.4.0 (#497958) 2026-03-17 16:13:44 +00:00
SandroandGitHub 19775bf4aa cmc: init at 1.2.2 (#486472) 2026-03-17 16:12:57 +00:00
SandroandGitHub 117d600efa mangayomi: 0.7.0 -> 0.7.2 (#498760) 2026-03-17 16:11:07 +00:00
SandroandGitHub 81e7be721d casilda: 1.0.0 -> 1.2.0 (#498759) 2026-03-17 16:10:13 +00:00
SandroandGitHub 8d4df5819f wamrc: 2.3.1 -> 2.4.4 (#470333) 2026-03-17 16:07:01 +00:00
SandroandGitHub 1d636bd469 server-box: 1.0.1316 -> 1.0.1331 (#498944) 2026-03-17 16:01:48 +00:00
SandroandGitHub 7408cd58bd phira-mp: init at 0.1.0-unstable-2025-06-10 (#428178) 2026-03-17 15:54:40 +00:00
André SilvaandGitHub a909cee899 enpass: 6.11.6.1833 -> 6.11.13.1957 (#499541) 2026-03-17 15:43:33 +00:00
SandroandGitHub eaeded1f53 cinny-{unwrapped,desktop}: 4.10.5 -> 4.11.1 (#498877) 2026-03-17 15:43:02 +00:00
SandroandGitHub bea7c51519 modrinth-app-unwrapped: 0.10.30 -> 0.12.4 (#496103) 2026-03-17 15:41:39 +00:00
SandroandGitHub c764e81fd5 python3Packages.py-netgear-plus: init at 0.4.7 (#496282) 2026-03-17 15:41:08 +00:00
SandroandGitHub df9cca310f grocy: 4.5.0 -> 4.6.0 (#497612) 2026-03-17 15:39:22 +00:00
Martin WeineltandGitHub 784d11dcb7 home-assistant-custom-components.gtfs-realtime: init at 0.3.2 (#498348) 2026-03-17 15:02:20 +00:00
Peder Bergebakken SundtandGitHub b655a33768 flexget: 3.19.0 -> 3.19.2 (#500094) 2026-03-17 14:51:35 +00:00
Ulrik StridandGitHub ab0fff8ae6 gemini-cli: 0.31.0 -> 0.33.0 (#498937) 2026-03-17 14:47:32 +00:00
AtemuandGitHub ae0c0756cc jpegli: init at 0-unstable-2025-02-11 (#462987) 2026-03-17 14:46:18 +00:00
Ulrik Strid 1e6600e2e3 vscode-extensions.Google.gemini-cli-vscode-ide-companion: fix install 2026-03-17 15:33:33 +01:00
dotlambdaandGitHub 8d12ecb291 python3Packages.elevenlabs: 2.38.1 -> 2.39.1 (#500700) 2026-03-17 14:11:13 +00:00
Damien CassouandGitHub 732a7e5ea6 lint-staged: 16.3.2 -> 16.4.0 (#500464) 2026-03-17 14:06:15 +00:00
Fernando RodriguesandGitHub b0eddce0fd xen: patch with XSA-480 and XSA-481 (#500711) 2026-03-17 14:05:34 +00:00
nixpkgs-ci[bot]andGitHub 6fd329b2ad bento: 1.15.1 -> 1.15.2 (#500666) 2026-03-17 13:46:24 +00:00
nixpkgs-ci[bot]andGitHub 1fe306e29f cargo-shear: 1.9.1 -> 1.11.2 (#500646) 2026-03-17 13:46:23 +00:00
7c6f434candGitHub c3070a298a texlive.bin: inherit arguments from texlive (#499903) 2026-03-17 13:20:24 +00:00
Yohann BonifaceandGitHub 6a5a68e0d1 python3Packages.sphinx-markdown-builder: 0.6.9 -> 0.6.10 (#500585) 2026-03-17 13:10:34 +00:00
nixpkgs-ci[bot]andGitHub f787c2f87f clojure: 1.12.4.1602 -> 1.12.4.1618 (#497373) 2026-03-17 13:04:50 +00:00
nixpkgs-ci[bot]andGitHub 7e0dc3c775 gomplate: 4.3.3 -> 5.0.0 (#494244) 2026-03-17 13:04:46 +00:00
nixpkgs-ci[bot]andGitHub 1cd60bbc08 clj-kondo: 2025.10.23 -> 2026.01.19 (#483214) 2026-03-17 13:04:46 +00:00
Yifei Sun ce0d6e4b39 home-assistant-custom-components.gtfs-realtime: init at 0.3.2 2026-03-17 13:43:54 +01:00
Yifei Sun e154d10561 python3Packages.gtfs-station-stop: init at 0.11.7 2026-03-17 13:43:54 +01:00
nixpkgs-ci[bot]andGitHub bdc04b6b10 swaynotificationcenter: 0.12.3 -> 0.12.5 (#485461) 2026-03-17 12:35:37 +00:00
Vincent LaporteandGitHub f2498f1a86 rocqPackages.mathcomp-analysis: init at 1.16.0 (#500659) 2026-03-17 12:26:28 +00:00
Fernando Rodrigues d8ad1e5a71 xen: patch with XSA-481
Xen Security Advisory CVE-2026-23555 / XSA-481
                               version 2

                 Xenstored DoS by unprivileged domain

Any guest issuing a Xenstore command accessing a node using the
(illegal) node path "/local/domain/", will crash xenstored due to a
clobbered error indicator in xenstored when verifying the node path.

Note that the crash is forced via a failing assert() statement in
xenstored. In case xenstored is being built with NDEBUG #defined,
an unprivileged guest trying to access the node path "/local/domain/"
will result in it no longer being serviced by xenstored, other guests
(including dom0) will still be serviced, but xenstored will use up
all cpu time it can get.

Any unprivileged domain can cause xenstored to crash, causing a
DoS (denial of service) for any Xenstore action. This will result
in an inability to perform further domain administration on the host.

In case xenstored has been built with NDEBUG defined, an unprivileged
domain can force xenstored to be 100% busy, but without harming
xenstored functionality for other guests otherwise.

Signed-off-by: Fernando Rodrigues <alpha@sigmasquadron.net>
2026-03-17 23:11:48 +11:00
Fernando Rodrigues a8cdacffc2 xen: patch with XSA-480
Xen Security Advisory CVE-2026-23554 / XSA-480
                               version 3

              Use after free of paging structures in EPT

The Intel EPT paging code uses an optimization to defer flushing of any cached
EPT state until the p2m lock is dropped, so that multiple modifications done
under the same locked region only issue a single flush.

Freeing of paging structures however is not deferred until the flushing is
done, and can result in freed pages transiently being present in cached state.
Such stale entries can point to memory ranges not owned by the guest, thus
allowing access to unintended memory regions.

Privilege escalation, Denial of Service (DoS) affecting the entire host,
and information leaks are possible impacts of this vulnerability.

Signed-off-by: Fernando Rodrigues <alpha@sigmasquadron.net>
2026-03-17 23:11:48 +11:00
nixpkgs-ci[bot]andGitHub 35740f0044 fabric-ai: 1.4.433 -> 1.4.437 (#500607) 2026-03-17 11:50:11 +00:00
Sarah BrofeldtandGitHub cee3d0e872 apacheKafka: 4_2: init at 4.2.0 (#499402) 2026-03-17 11:26:46 +00:00
Johannes KirschbauerandGitHub e513b3c1e9 lib.types: use isType for optionType (#499943) 2026-03-17 11:15:25 +00:00