| Age | Commit message (Expand) | Author |
| 2025-08-21 | nongnu: firefox-esr: Update to 140.2.0esr [security fixes].•••Fixes CVE-2025-9179, CVE-2025-9180, CVE-2025-9181, CVE-2025-9182,
CVE-2025-9183, CVE-2025-9184, CVE-2025-9185.
* nongnu/packages/mozilla.scm (firefox-esr): Update to 140.2.0esr.
Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
| Tomas Volf |
| 2025-08-21 | nongnu: firefox: Update to 142.0 [security fixes].•••Fixes CVE-2025-9179, CVE-2025-9180, CVE-2025-9181, CVE-2025-9182,
CVE-2025-9183, CVE-2025-9184, CVE-2025-9185, CVE-2025-9186,
CVE-2025-9187.
* nongnu/packages/mozilla.scm (firefox): Update to 142.0.
Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
| Tomas Volf |
| 2025-08-18 | nongnu: firefox-esr: No longer hardcode nspr version.•••Nspr version 4.32 was removed in Guix
https://codeberg.org/guix/guix/commit/4d7692adc58effb97b82c4144efef8a28802da9b.
The issue that required this version specifically has also since been resolved
and thus a specific version of nspr is no longer required:
https://bugs.gnu.org/32833#28.
* nongnu/packages/mozilla.scm (firefox-esr) [inputs] Replace nspr-4.32 with
nspr.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| caem |
| 2025-08-13 | nongnu: Remove (gnu packages crates-io) module import.•••* nongnu/packages/mozilla.scm (nongnu): Remove module import of
(gnu packages crates-io).
| Hilton Chain |
| 2025-08-10 | nongnu: firefox: Update to 141.0.3.•••* nongnu/packages/mozilla.scm (firefox): Update to 141.0.3.
Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
| Tomas Volf |
| 2025-07-23 | nongnu: firefox-esr: Update to 140.1.0esr [security fixes].•••Fixes CVE-2025-8027, CVE-2025-8028, CVE-2025-8029, CVE-2025-8030,
CVE-2025-8031, CVE-2025-8032, CVE-2025-8033, CVE-2025-8034,
CVE-2025-8035, CVE-2025-8036, CVE-2025-8037, CVE-2025-8038,
CVE-2025-8039, CVE-2025-8040.
* nongnu/packages/mozilla.scm (firefox-esr): Update to 140.1.0esr.
Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
| Tomas Volf |
| 2025-07-23 | nongnu: firefox: Update to 141.0 [security fixes].•••Fixes CVE-2025-8027, CVE-2025-8028, CVE-2025-8029, CVE-2025-8030,
CVE-2025-8031, CVE-2025-8032, CVE-2025-8033, CVE-2025-8034,
CVE-2025-8035, CVE-2025-8036, CVE-2025-8037, CVE-2025-8038,
CVE-2025-8039, CVE-2025-8040, CVE-2025-8041, CVE-2025-8042,
CVE-2025-8043, CVE-2025-8044.
* nongnu/packages/mozilla.scm (firefox): Update to 141.0.
Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
| Tomas Volf |
| 2025-07-10 | nongnu: firefox: Update to 140.0.4.•••* nongnu/packages/mozilla.scm (firefox): Update to 140.0.4.
Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
| Tomas Volf |
| 2025-06-28 | nongnu: firefox: Remove obsolete phase.•••* nongnu/packages/mozilla.scm (firefox)[arguments]<#:phases>: Remome
'patch-icu-lookup.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-06-28 | nongnu: firefox-esr: Update to 140.0esr.•••* nongnu/packages/mozilla.scm (firefox-esr): Update to 140.0esr.
[source]<patches>: Add firefox-restore-desktop-files.patch. Use >=138 version
of path comparison patch.
[inputs]: Use icu4c-76.
[native-inputs]: Use rust-cbindgen-0.28.
(firefox)[inputs]: Drop.
[native-inputs]: Do not replace rust-cbindgen.
* nongnu/packages/patches/firefox-esr-add-store-to-rdd-allowlist.patch: Update
to new version. No functional changes.
* nongnu/packages/patches/firefox-esr-use-system-wide-dir.patch: Same.
* nongnu/packages/patches/firefox-esr-compare-paths.patch: Delete file.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-06-25 | nongnu: firefox-esr: Update to 128.12.0esr [security fixes].•••Fixes CVE-2025-6424, CVE-2025-6425, CVE-2025-6426, CVE-2025-6429,
CVE-2025-6430.
* nongnu/packages/mozilla.scm (firefox-esr): Update to 128.12.0esr.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-06-25 | nongnu: firefox: Update to 140.0 [security fixes].•••Fixes CVE-2025-6424, CVE-2025-6425, CVE-2025-6426, CVE-2025-6427,
CVE-2025-6428, CVE-2025-6429, CVE-2025-6430, CVE-2025-6431,
CVE-2025-6432, CVE-2025-6433, CVE-2025-6434, CVE-2025-6435,
CVE-2025-6436.
* nongnu/packages/mozilla.scm (firefox): Update to 140.0.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-06-25 | nongnu: firefox: Fix GPU decoding.•••* nongnu/packages/patches/firefox-esr-add-store-to-rdd-allowlist.patch: New
file.
* nongnu/packages/mozilla.scm (firefox-esr)[source]<patches>: Add it.
[#:phases]<wrap-glxtest>: New phase ported from Guix's librewolf package.
<wrap-program>: Remove whitelist manipulation.
[inputs]: Add pciutils.
* nongnu/packages/patches/firefox-add-store-to-rdd-allowlist.patch: New file.
* nongnu/packages/mozilla.scm (firefox)[source]<patches>: Add it.
Fixes: https://gitlab.com/nonguix/nonguix/-/issues/389
Signed-off-by: Hilton Chain <hako@ultrarare.space>
Modified-by: Hilton Chain <hako@ultrarare.space>
| Brice Waegeneire |
| 2025-06-12 | nongnu: firefox: Update to 139.0.4 [security fixes].•••Fixes CVE-2025-49709, CVE-2025-49710.
* nongnu/packages/mozilla.scm (firefox): Update to 139.0.4.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-06-12 | nongnu: firefox, firefox-esr: Delete testing/web-platform.•••* nongnu/packages/mozilla.scm (firefox, firefox-esr)[source]: Delete
testing/web-platform to allow build with 1G less RAM.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Nicolas Graves |
| 2025-05-28 | nongnu: firefox: Update to 139.0 [security fixes].•••Fixes CVE-2025-5262, CVE-2025-5263, CVE-2025-5264, CVE-2025-5265,
CVE-2025-5266, CVE-2025-5267, CVE-2025-5268, CVE-2025-5270,
CVE-2025-5271, CVE-2025-5272.
* nongnu/packages/mozilla.scm (firefox): Update to 139.0.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-05-28 | nongnu: firefox-esr: Update to 128.11.0esr [security fixes].•••Fixes CVE-2025-5262, CVE-2025-5263, CVE-2025-5264, CVE-2025-5265,
CVE-2025-5266, CVE-2025-5267, CVE-2025-5268, CVE-2025-5269.
* nongnu/packages/mozilla.scm (firefox-esr): Update to 128.11.0esr.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-05-18 | nongnu: firefox-esr: Update to 128.10.1esr [security fixes].•••Fixes CVE-2025-4920, CVE-2025-4921.
* nongnu/packages/mozilla.scm (firefox-esr): Update to 128.10.1esr.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-05-18 | nongnu: firefox: Update to 138.0.4 [security fixes].•••Fixes CVE-2025-4920, CVE-2025-4921.
* nongnu/packages/mozilla.scm (firefox): Update to 138.0.4.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-05-14 | nongnu: firefox: Update to 138.0.3.•••* nongnu/packages/mozilla.scm (firefox): Update to 138.0.3.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-05-04 | nongnu: firefox: Update to 138.0 [security fixes].•••Fixes CVE-2025-2817, CVE-2025-4082, CVE-2025-4083, CVE-2025-4085,
CVE-2025-4086, CVE-2025-4087, CVE-2025-4088, CVE-2025-4089,
CVE-2025-4090, CVE-2025-4091, CVE-2025-4092.
* nongnu/packages/patches/firefox-ge-138-compare-paths.patch: New file.
* nongnu/packages/mozilla.scm (firefox): Update to 138.0.
[source]: Use the new patch.
[native-inputs]: Replace rust-cbindgen with rust-cbindgen-0.28.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-04-30 | nongnu: firefox-esr: Update to 128.10.0esr [security fixes].•••Fixes CVE-2025-2817, CVE-2025-4082, CVE-2025-4083, CVE-2025-4084,
CVE-2025-4087, CVE-2025-4091, CVE-2025-4093.
* nongnu/packages/mozilla.scm (firefox-esr): Update to 128.10.0esr.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-04-17 | nongnu: firefox: Update to 137.0.2 [security fixes].•••Fixes CVE-2025-3608.
* nongnu/packages/mozilla.scm (firefox): Update to 137.0.2.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-04-11 | nongnu: firefox: Create lib/icecat so that ICECAT_SYSTEM_DIR is set.•••Adapted from <https://issues.guix.gnu.org/77677>.
* nongnu/packages/mozilla.scm (firefox-esr)
[arguments]<#:phases>: Add 'mkdir-lib-icecat'.
Fixes: https://gitlab.com/nonguix/nonguix/-/issues/368
Reported-by: Katherine Cox-Buday <cox.katherine.e@gmail.com>
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Clement Lassieur |
| 2025-04-10 | nongnu: firefox: Update to 137.0.1.•••* nongnu/packages/mozilla.scm (firefox): Update to 137.0.1.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-04-10 | nongnu: Deprecate firefox-esr-wayland.•••Since Firefox ESR has already been above version 121, this variable can be
deprecated.
* nongnu/packages/mozilla.scm (firefox-esr/wayland): Deprecated by
firefox-esr.
| Hilton Chain |
| 2025-04-07 | nongnu: firefox: Fix video decoding/acceleration.•••Fixes #386.
As of Firefox 137, VA-API video acceleration is enabled by default. This
would fail due to not finding libpciaccess. This is an indirect dependency,
through libdrm (that mesa and libva depend on). It would be best to have our
runpaths-of-input work recursively to catch this (so it can be in the RDD
sandbox used by Firefox here). In the meantime, add libpciaccess explicitly
to fix this issue.
* nongnu/packages/mozilla.scm (firefox-esr)[arguments]<#:phases>: In the
wrap-program phase, add the libpciaccess library path, used in
LD_LIBRARY_PATH. Add a comment for future work on rdd-whitelist.
[inputs]: Add libpciaccess.
| John Kehayias |
| 2025-04-03 | nongnu: firefox: Update to 137.0 [security fixes].•••Fixes CVE-2025-2857, CVE-2025-3028, CVE-2025-3029, CVE-2025-3030,
CVE-2025-3031, CVE-2025-3032, CVE-2025-3033, CVE-2025-3034,
CVE-2025-3035.
* nongnu/packages/mozilla.scm (firefox): Update to 137.0.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-04-03 | nongnu: firefox-esr: Update to 128.9.0esr [security fixes].•••Fixes CVE-2025-2857, CVE-2025-3028, CVE-2025-3029, CVE-2025-3030.
* nongnu/packages/mozilla.scm (firefox-esr): Update to 128.9.0esr.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-03-19 | nongnu: firefox: Update to 136.0.2.•••* nongnu/packages/mozilla.scm (firefox): Update to 136.0.2.
Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
| Tomas Volf |
| 2025-03-12 | nongnu: firefox: Update to 136.0.1.•••* nongnu/packages/mozilla.scm (firefox): Update to 136.0.1.
Signed-off-by: Jonathan Brielmaier <jonathan.brielmaier@web.de>
| Tomas Volf |
| 2025-03-12 | nongnu: firefox-esr: Use current rust.•••* nongnu/packages/mozilla.scm (rust-firefox-esr): Set to `rust'.
Signed-off-by: Jonathan Brielmaier <jonathan.brielmaier@web.de>
| Tomas Volf |
| 2025-03-12 | nongnu: firefox: Use current rust.•••* nongnu/packages/mozilla.scm (rust-firefox): Set to `rust'.
Signed-off-by: Jonathan Brielmaier <jonathan.brielmaier@web.de>
| Tomas Volf |
| 2025-03-06 | nongnu: firefox: Update to 136.0 [security fixes].•••Fixes CVE-2024-9956, CVE-2025-1930, CVE-2025-1931, CVE-2025-1932,
CVE-2025-1933, CVE-2025-1934, CVE-2025-1935, CVE-2025-1936,
CVE-2025-1937, CVE-2025-1938, CVE-2025-1939, CVE-2025-1940,
CVE-2025-1941, CVE-2025-1942, CVE-2025-1943.
* nongnu/packages/mozilla.scm (firefox): Update to 136.0.
[inputs]: Use icu4c-76.
[arguments]<#:phases>: Add 'patch-icu-lookup.
Signed-off-by: Jelle Licht <jlicht@fsfe.org>
| Tomas Volf |
| 2025-03-05 | nongnu: firefox-esr: Update to 128.8.0esr [security fixes].•••Fixes CVE-2024-43097, CVE-2025-1930, CVE-2025-1931, CVE-2025-1932,
CVE-2025-1933, CVE-2025-1934, CVE-2025-1935, CVE-2025-1936,
CVE-2025-1937, CVE-2025-1938.
* nongnu/packages/mozilla.scm (firefox-esr): Update to 128.8.0esr.
Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
| Tomas Volf |
| 2025-03-02 | nongnu: firefox-esr: Rename icu4c-73 to icu4c.•••* nongnu/packages/mozilla.scm (firefox-esr)[inputs]: Rename icu4c-73 to
icu4c. On gnome-team icu4c was updated to version 73.
| Jelle Licht |
| 2025-02-24 | nongnu: firefox: Use key for beaconDB API.•••This was proposed by Joel (beaconDB founder) at their Matrix chat room.
* nongnu/packages/mozilla.scm (firefox-esr)[arguments]: Set a key for
beaconDB API.
Co-authored-by: Tomas Volf <wolf@wolfsden.cz>
Signed-off-by: Jonathan Brielmaier <jonathan.brielmaier@web.de>
| Jonathan Brielmaier |
| 2025-02-24 | nongnu: firefox: Honor --cores build argument.•••* nongnu/packages/mozilla.scm (firefox)[arguments]{phases}: Honor
--cores build argument in 'build phase. Also removing comments that
are outdated by this change.
Signed-off-by: Jonathan Brielmaier <jonathan.brielmaier@web.de>
| Nicolas Graves |
| 2025-02-24 | nongnu: firefox: Update to 135.0.1 [security fixes].•••Fixes CVE-2025-1414.
* nongnu/packages/mozilla.scm (firefox): Update to 135.0.1.
Signed-off-by: Jonathan Brielmaier <jonathan.brielmaier@web.de>
| Tomas Volf |
| 2025-02-06 | nongnu: firefox: Update to 135.0 [security fixes].•••Fixes CVE-2025-1009, CVE-2025-1010, CVE-2025-1011, CVE-2025-1012,
CVE-2025-1013, CVE-2025-1014, CVE-2025-1016, CVE-2025-1017,
CVE-2025-1018, CVE-2025-1019, CVE-2025-1020.
* nongnu/packages/mozilla.scm (firefox): Update to 135.0.
Signed-off-by: Jonathan Brielmaier <jonathan.brielmaier@web.de>
| Tomas Volf |
| 2025-02-06 | nongnu: firefox-esr: Update to 128.7.0esr [security fixes].•••Fixes CVE-2024-11704, CVE-2025-1009, CVE-2025-1010, CVE-2025-1011,
CVE-2025-1012, CVE-2025-1013, CVE-2025-1014, CVE-2025-1016,
CVE-2025-1017.
* nongnu/packages/mozilla.scm (firefox-esr): Update to 128.7.0esr.
Signed-off-by: Jonathan Brielmaier <jonathan.brielmaier@web.de>
| Tomas Volf |
| 2025-02-06 | nongnu: firefox-esr: Use beaconDB as geolocation provider.•••* nongnu/packages/mozilla.scm (firefox-esr)[arguments]: Set beaconDB as
geolocation provider in 'fix-preferences phase.
| Jonathan Brielmaier |
| 2025-01-22 | nongnu: firefox: Update to 134.0.2.•••* nongnu/packages/mozilla.scm (firefox): Update to 134.0.2.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-01-16 | nongnu: firefox: Update to 134.0.1.•••* nongnu/packages/mozilla.scm (firefox): Update to 134.0.1.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2025-01-08 | nongnu: firefox: Update to 134.0 [security fixes].•••Fixes CVE-2025-0237, CVE-2025-0238, CVE-2025-0239, CVE-2025-0240,
CVE-2025-0241, CVE-2025-0242, CVE-2025-0243, CVE-2025-0244,
CVE-2025-0245, CVE-2025-0246, CVE-2025-0247.
* nongnu/packages/mozilla.scm (firefox): Update to 134.0.
[inputs]: Replace icu4c with icu4c-75.
Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
| Tomas Volf |
| 2025-01-08 | nongnu: firefox-esr: Update to 128.6.0esr [security fixes].•••Fixes CVE-2025-0237, CVE-2025-0238, CVE-2025-0239, CVE-2025-0240,
CVE-2025-0241, CVE-2025-0242, CVE-2025-0243.
* nongnu/packages/mozilla.scm (firefox-esr): Update to 128.6.0esr.
Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
| Tomas Volf |
| 2024-12-13 | nongnu: firefox-esr: Update to 128.5.2esr.•••* nongnu/packages/mozilla.scm (firefox-esr): Update to 128.5.2esr.
Signed-off-by: Hilton Chain <hako@ultrarare.space>
| Tomas Volf |
| 2024-12-13 | nongnu: firefox: Support Guix icecat browser extensions.•••* nongnu/packages/patches/firefox-use-system-wide-dir.patch: New file.
* nongnu/packages/mozilla.scm (firefox)[source]: Add it along with
firefox-esr-compare-paths.patch.
| Hilton Chain |
| 2024-12-13 | nongnu: firefox-esr: Support Guix icecat browser extensions.•••* nongnu/packages/patches/firefox-esr-compare-paths.patch: New file.
* nongnu/packages/patches/firefox-esr-use-system-wide-dir.patch: New file.
* nongnu/packages/mozilla.scm (firefox-esr)[source]: Add them.
[arguments]<#:configure-flags>: Allow unsigned system addons.
[native-search-paths]: Add ICECAT_SYSTEM_DIR.
| Hilton Chain |
| 2024-12-11 | nongnu: firefox: Update to 133.0.3.•••* nongnu/packages/mozilla.scm (firefox): Update to 133.0.3.
| Tomas Volf |