From patchwork Mon Sep 18 10:58:26 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Dr. Arne Babenhauserheide" X-Patchwork-Id: 54020 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 295E727BBEA; Mon, 18 Sep 2023 12:01:36 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-2.7 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,FREEMAIL_FROM,MAILING_LIST_MULTI,SPF_HELO_PASS, URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 0711627BBE2 for ; Mon, 18 Sep 2023 12:01:35 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1qiC06-0001NC-1b; Mon, 18 Sep 2023 07:01:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1qiBzq-0001Jv-4b for guix-patches@gnu.org; Mon, 18 Sep 2023 07:00:55 -0400 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1qiBzp-0001oR-Si for guix-patches@gnu.org; Mon, 18 Sep 2023 07:00:53 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1qiBzy-0008JX-0Y for guix-patches@gnu.org; Mon, 18 Sep 2023 07:01:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#66069] Update Icecat to FF 102.15.1 to fix mfsa2023-40 Resent-From: "Dr. Arne Babenhauserheide" Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Mon, 18 Sep 2023 11:01:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 66069 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: To: 66069@debbugs.gnu.org X-Debbugs-Original-To: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.169503484131922 (code B ref -1); Mon, 18 Sep 2023 11:01:01 +0000 Received: (at submit) by debbugs.gnu.org; 18 Sep 2023 11:00:41 +0000 Received: from localhost ([127.0.0.1]:52193 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1qiBzd-0008Io-9H for submit@debbugs.gnu.org; Mon, 18 Sep 2023 07:00:41 -0400 Received: from lists.gnu.org ([2001:470:142::17]:43038) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1qiBzY-0008IV-IY for submit@debbugs.gnu.org; Mon, 18 Sep 2023 07:00:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1qiBzI-0001AO-Ub for guix-patches@gnu.org; Mon, 18 Sep 2023 07:00:20 -0400 Received: from mout.web.de ([212.227.15.4]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1qiBzG-0001Ta-8A for guix-patches@gnu.org; Mon, 18 Sep 2023 07:00:20 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=web.de; s=s29768273; t=1695034814; x=1695639614; i=arne_bab@web.de; bh=vl3AX+pugG69irLXpzaBj1Mc8f/F7aFgvYGfid6ZFBM=; h=X-UI-Sender-Class:From:To:Subject:Date; b=JWHUowesj6whtSZ42Ui/xpjldp5DoAQYLfaKUtWWNZsMinh4MGCmiXRiJo+C3LEmllPlQQJ7AbJ CksRqeMSaIt3evBfp20CsmF7rrbT5yON/LJHhJ1DHApSCf+bQW1RCSP2a3wdOosPgK73pO2e+bVWq txbWjGCHIIklOlaUdlgjbG0nOU/kdaCzFnKDr4fjh73JyL/yOXVDPdOfq59kGMNpXUt6LS7nsMKeR 0JWz6WIrjYyajtrsMh9YwTCO9shvzl7fg2oFizg+bfcMxkh2RYllyoTqvdeipXMofbRPp2g7E+jPF 8Qk1xNnL2V/SszP2NoHu4kF8gNW+/bfdV/dg== X-UI-Sender-Class: 814a7b36-bfc1-4dae-8640-3722d8ec6cd6 Received: from fluss ([80.136.25.224]) by smtp.web.de (mrweb006 [213.165.67.108]) with ESMTPSA (Nemesis) id 1Melaj-1rIteF0nqf-00aWXz; Mon, 18 Sep 2023 13:00:14 +0200 User-agent: mu4e 1.10.5; emacs 29.0.92 From: "Dr. Arne Babenhauserheide" Date: Mon, 18 Sep 2023 12:58:26 +0200 Message-ID: <877conrbk2.fsf@web.de> MIME-Version: 1.0 X-Provags-ID: V03:K1:iekzZ7G/riLYhyFj4mV2NTywHoFbI1hagu2mCRXPij2jiszYwRb Wqo+KXn27MX9iOhDnEbzm8c0MBVnBXwPDqCDApQUpQS4bzXIKfHKtZ+G4joasKNoD35m//I OU8G8PdbRQ4fm5/xnsIeQYiiUTHc6lVp3kDsfncm7ZP3wHfIec0BcnljfJfMOMUfb4v+//w LqDb0tjBW8FTLmFP03B2Q== UI-OutboundReport: notjunk:1;M01:P0:xaLQoHANOQw=;M77dE7qqhB33tFpCwitVYWRnTEL xkvPaAUGIEILRJEWP9cWh+2HIGAVUbyqmeHe4t4iPFyPGQHHfFZwmBPyw+U3irLTf9h65k0Lv bGYm7L2itqwD2JlhDw1lgMZbaOPZS4phT+HU73HGyHuDtVGiRihecHr6fR4iPvk7FP+qEvVib xn1iQ8w8hVsMLHqIVh99wJiwMINOU6/Q7yL6JbzTgmww4JVOtuclHR2721cri+/EiHpR+1aG8 7BE74aso0xLtofTAYb1D68rwUMTQ+6ttar1wxfLJ5QgP6Cjg/3ZkN8THVAEvRfybKKHCPNSFf eGLKgPJZBdACyr0khXXm6NP4VqrO6pZYuPCGuKIb7SUuNOCxrIELkuQi2EJL7940tlBU2t8SX SPTmvMLYGM3cTmON48TKEXPcDTn9lTYcWJ3c9llO6ZmS7hI3jwy43i5e94remHGFsD/FaqUT3 6mch5rE0mgGoO3XjpXgcCsWc9KfLfYAya8nFx6W7GQ8z5rAhe733cg73Ne/0fy5yyzgYL+Bx0 ABqkGicTlUOrNjwCdwynEGgcw2orBwCwCRr1nbqftEDGP0iuJUu5B0Nqk6Dbr7FXU8oLn8MFT OTRwAqbmiKp2e1ztQYoaHmgFFgUyEArl6itprnb+JDhsyl9ztdSA3XYuhghOoGeqWwJJxPUzJ ohMOwkjAkKODKcJk1NYesdVwagp5IQYLWeFU03PRdbYuhIIIcldH/VLz6Dq7ngvH8onkqvbRg lCSus/v0Vyp2PPjWvODm6OUUH+ArVu/0U7kMkrj7+Op99F4LVhXNMBvP+z/E5tykV/HkDp4O3 wr1hNzNKSLO5D35/I/slW6hWh84GzXO194hyCB+zZtDLL2CBbW93MpkPwLEyOjHG1yweO6aEb 35iSpvJhwMGtSbEeehBSYcN5IfHy1Qypi2NkYvJGtCg+uIqzUGICEis9vZyCmtoW/7MldR39Z TRyN3Sb5zUWyqo0nzas3gdHcBUE= Received-SPF: pass client-ip=212.227.15.4; envelope-from=arne_bab@web.de; helo=mout.web.de X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches Hi, the attached patch updates the base version of icecat to 102.15.1 to get the fix of the critical webp vulnerability in Firefox (and every other browser out there). Best wishes, Arne From 21a46f22b9b0d49e5d556e296716fc3b6db6b2e0 Mon Sep 17 00:00:00 2001 Message-ID: <21a46f22b9b0d49e5d556e296716fc3b6db6b2e0.1695034689.git.arne_bab@web.de> From: Arne Babenhauserheide Date: Mon, 18 Sep 2023 12:56:18 +0200 Subject: [PATCH] Update icecat to FF 102.15.1 to fix mfsa2023-40 * gnu/packages/gnuzilla.scm (%icecat-base-version): update to 102.15.1 to fix https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/ * gnu/packages/gnuzilla.scm (icecat-source): update upstream hash to 102.15.1 --- gnu/packages/gnuzilla.scm | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/gnu/packages/gnuzilla.scm b/gnu/packages/gnuzilla.scm index 6e2f9729cf..e700931d28 100644 --- a/gnu/packages/gnuzilla.scm +++ b/gnu/packages/gnuzilla.scm @@ -518,7 +518,7 @@ (define all-mozilla-locales ;; XXXX: Workaround 'snippet' limitations. (define computed-origin-method (@@ (guix packages) computed-origin-method)) -(define %icecat-base-version "102.15.0") +(define %icecat-base-version "102.15.1") (define %icecat-version (string-append %icecat-base-version "-guix0-preview1")) (define %icecat-build-id "20230829000000") ;must be of the form YYYYMMDDhhmmss @@ -540,7 +540,7 @@ (define icecat-source "firefox-" upstream-firefox-version ".source.tar.xz")) (sha256 (base32 - "1bs6hxfsb77cbi238wvizq2iw4mlgz29m0sd027sz8zm1025kyl1")))) + "04q1fjninm9lw721xgv0c2fknicc24s8iaimkabwcfwmcnvly689")))) ;; The upstream-icecat-base-version may be older than the ;; %icecat-base-version. base-commit: e2a7c227dea5b361e2ebdbba24b923d1922a79d0 prerequisite-patch-id: e26acb8280f31db9b663b6fc444a2229fc5b588e prerequisite-patch-id: db5cc62f7d04f3ed3014ae984fe732f3b6db8d17 prerequisite-patch-id: 3a0bf9ef6f27f1d92537c5e9ee5c38c7d6ced99e prerequisite-patch-id: 088a72da8c11e5d1c7087b4a5e8bb9c4a3b9b2af prerequisite-patch-id: 1b4787e17ec6ab62978615e1d3804a1024c5e1a0 prerequisite-patch-id: f814d9756faa5d91a68b81654606c66b4cf389e5 prerequisite-patch-id: f2dbed3e6da49472bd141c9fa40de2d2208130fb prerequisite-patch-id: 2dbf557994da4a264566b67294f7f3f8e2931f5f prerequisite-patch-id: 912a76fac540b98d5683ba1886a7d62f0963cd9f prerequisite-patch-id: f6a9bfd16b8952c73b7a6d97be70013a290815d7 prerequisite-patch-id: e50c1aaa1d401bba32a49d2e1fb1661746543d09 prerequisite-patch-id: 1f63cb516bc5c9772ae808371528006fca20dcad prerequisite-patch-id: 1ac04f0120fb6c4f106d05bee88103debb815b41 prerequisite-patch-id: eeff242fb5e41c8c83b3daadd0965e58eb6670ba prerequisite-patch-id: 3812c9ac1252d9d20e8485462be155156f302a54 prerequisite-patch-id: 9d3dd155c91ab334999c03fefab04f361ea4d8b5 prerequisite-patch-id: f5b09b934b65fe45bdfd1273baa3bb949ed52cca prerequisite-patch-id: 61a9b3943bdbe5cb6a4aa978888ceb64088f9a14 prerequisite-patch-id: 3f9d50361fb537607c33d09115366aec05160688 prerequisite-patch-id: 765c77b7c31f24491149665a066d2906f8da8d33 prerequisite-patch-id: 2b92c37e3aa74152a7aa226e1fbd5f2735037dc0 prerequisite-patch-id: 2a3123ab0786108f26e25c45fc4c545b99b6dd27 prerequisite-patch-id: 891a2458a90ea90113c576df5029514f5143366e prerequisite-patch-id: 1a08957a2fd3e3637ed7f3cf3f44c9f8194d6668 prerequisite-patch-id: d382210c915c0a809cb709cba45a4542d60c4d20 prerequisite-patch-id: d424ad2c4c4bf14becb025c67757f48d4a6ae6b5 prerequisite-patch-id: 07e1c90231819e0b963645b041522e53891fd344 prerequisite-patch-id: 124009dec6dad63add19bf258f71bdb127078ecb prerequisite-patch-id: 0afa33c8e0e2aca07da2782e04d259d3f8c498c5 prerequisite-patch-id: 205bb6c05a145eb9137e8623687418089351e73e prerequisite-patch-id: 7138f72403701b9749a0a587f1807030d730c00d prerequisite-patch-id: 39bd665160a5e62aaa4ea94ad2e3ca30f31e2127 prerequisite-patch-id: d5d0cdab2914d5d4b80f7e9e541c8f76b6e313d6 prerequisite-patch-id: 9b22cdb1bd10f6f0231168f7223d5b700830ad48 prerequisite-patch-id: cd1ddd3e6d24b1488271cfbdc28dc6619552306e prerequisite-patch-id: 8b5cef14cf4c6b27783c8f5ed9b8802bf11b15c5 -- 2.41.0