- Scheme 75.9%
- Tree-sitter Query 21.4%
- C++ 1.2%
- Shell 0.7%
- Makefile 0.4%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
Firefox 157.0 contains fixes for:
CVE-2026-100756: Incorrect boundary conditions in the Audio/Video:
Playback component
CVE-2026-100757: Use-after-free in the Widget component
CVE-2026-100758: Sandbox escape in the DOM: Navigation component
CVE-2026-100759: Uninitialized memory in the Storage: Quota Manager
component
CVE-2026-100760: Sandbox escape in the Security: Process Sandboxing
component
CVE-2026-100761: Privilege escalation due to use-after-free in the
Graphics: WebGPU component
CVE-2026-100762: Sandbox escape due to use-after-free in the DOM:
Content Processes component
CVE-2026-100763: Incorrect boundary conditions in the Graphics: WebGPU
component
CVE-2026-100764: Privilege escalation due to incorrect boundary
conditions in the Graphics: WebGPU component
CVE-2026-100765: Use-after-free in the JavaScript: WebAssembly
component
CVE-2026-100766: Information disclosure in the Networking: JAR
component
CVE-2026-100767: Use-after-free in the Networking: Cache component
CVE-2026-100768: Use-after-free in the Graphics: WebGPU component
CVE-2026-100769: Use-after-free in the JavaScript: WebAssembly
component
CVE-2026-100770: Sandbox escape due to use-after-free in the DOM:
Content Processes component
CVE-2026-100771: Undefined behavior in the DOM: Streams component
CVE-2026-100772: Use-after-free in the DOM: Core & HTML component
CVE-2026-100773: Use-after-free in the Storage: IndexedDB component
CVE-2026-100774: Use-after-free in the DOM: Core & HTML component
CVE-2026-100775: Sandbox escape in the Graphics component
CVE-2026-100776: Use-after-free in the JavaScript: WebAssembly
component
CVE-2026-100777: Use-after-free in the Graphics: Canvas2D component
CVE-2026-100778: Sandbox escape due to use-after-free in the DOM: Core
& HTML component
CVE-2026-100779: Use-after-free in the XSLT component
CVE-2026-100780: Use-after-free in the DOM: Core & HTML component
CVE-2026-100781: Sandbox escape due to incorrect boundary conditions
in the Graphics: WebRender component
CVE-2026-100782: Privilege escalation due to incorrect boundary
conditions in the Graphics component
CVE-2026-100783: Uninitialized memory in the Audio/Video component
CVE-2026-100784: Use-after-free in the Layout: Text and Fonts
component
CVE-2026-100785: Use-after-free in the DOM: Core & HTML component
CVE-2026-100786: Sandbox escape due to use-after-free in the Graphics
component
CVE-2026-100787: Sandbox escape in the XUL component
CVE-2026-100788: Invalid pointer in the JavaScript: WebAssembly
component
CVE-2026-100789: Use-after-free in the Graphics: Canvas2D component
CVE-2026-100790: Use-after-free in the XSLT component
CVE-2026-100791: Use-after-free in the DOM: Core & HTML component
CVE-2026-100792: JIT miscompilation in the JavaScript: WebAssembly
component
CVE-2026-100793: JIT miscompilation in the JavaScript Engine component
CVE-2026-100794: Sandbox escape due to incorrect boundary conditions
in the Internationalization component
CVE-2026-96869: Information disclosure in the Networking component
CVE-2026-100795: Denial-of-service in the Networking component
CVE-2026-100796: Use-after-free in the JavaScript: WebAssembly
component
CVE-2026-100797: Privilege escalation due to use-after-free in the
Graphics: WebRender component
CVE-2026-100798: Cryptography misuse in Storage: Quota Manager
component
CVE-2026-100799: Uninitialized memory in the Graphics: WebGPU
component
CVE-2026-100800: Sandbox escape due to use-after-free in the
Disability Access APIs component
CVE-2026-100801: Privilege escalation in the DLL Services component
CVE-2026-100802: Uninitialized memory in the Graphics: WebGPU
component
CVE-2026-100803: Same-origin policy bypass in the WebExtensions
component
CVE-2026-100804: Sandbox escape due to use-after-free in the
Preferences: Backend component
CVE-2026-100805: Race condition, use-after-free in the Audio/Video
component
CVE-2026-100806: Uninitialized memory in the Graphics: WebGPU
component
CVE-2026-100807: Privilege escalation in the DOM: Service Workers
component
CVE-2026-100808: Mitigation bypass in the DOM: Service Workers
component
CVE-2026-100809: Same-origin policy bypass in the DevTools component
CVE-2026-100810: Other issue in the DevTools component
CVE-2026-100811: Sandbox escape due to use-after-free in the DOM: Core
& HTML component
CVE-2026-100812: Denial-of-service in the Graphics component
CVE-2026-100813: Invalid pointer in the JavaScript Engine: JIT
component
CVE-2026-100814: Incorrect boundary conditions in the JavaScript
Engine: JIT component
CVE-2026-100815: Use-after-free in the CSS Parsing and Computation
component
CVE-2026-100816: Site isolation issue in the DOM: Networking component
CVE-2026-100817: Other issue in the JavaScript: WebAssembly component
CVE-2026-100818: Sandbox escape due to use-after-free in the Widget:
Gtk component
CVE-2026-100819: Sandbox escape due to incorrect boundary conditions
in the XPCOM component
CVE-2026-100820: Privilege escalation in the Address Bar component
CVE-2026-100821: Site isolation issue in the Panning and Zooming
component
CVE-2026-100822: Spoofing issue in the Networking: HTTP component
CVE-2026-100823: Spoofing issue in the Downloads component in Firefox
for Android
CVE-2026-100824: Privilege escalation in the Places component
CVE-2026-100825: Use-after-free in the JavaScript Engine: JIT
component
CVE-2026-100826: Denial-of-service in the Storage: StorageManager
component
CVE-2026-100828: Mitigation bypass in the Bookmarks & History
component
CVE-2026-100829: Mitigation bypass in the DOM: Security component
CVE-2026-100830: Mitigation bypass in the DOM: Navigation component
CVE-2026-100831: Use-after-free in the DOM: UI Events & Focus Handling
component
* gnu/packages/librewolf.scm (librewolf): Update to 157.0-1.
(firefox-l10n): Update to 1ccd8a9a31a6c858f281798805b92b609b22b55b.
Merges: https://codeberg.org/guix/guix/pulls/11634
Reviewed-by: moksh <mysticmoksh@riseup.net>
Signed-off-by: Nguyễn Gia Phong <cnx@loang.net>
|
||
| .forgejo | ||
| build-aux | ||
| doc | ||
| etc | ||
| gnu | ||
| guix | ||
| m4 | ||
| nix | ||
| po | ||
| scripts | ||
| tests | ||
| .codespellrc | ||
| .dir-locals.el | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .guix-authorizations | ||
| .guix-channel | ||
| .mailmap | ||
| AUTHORS | ||
| bootstrap | ||
| ChangeLog | ||
| CODE-OF-CONDUCT | ||
| CODEOWNERS | ||
| config-daemon.ac | ||
| configure.ac | ||
| COPYING | ||
| gnu.scm | ||
| guix.scm | ||
| HACKING | ||
| Makefile.am | ||
| manifest.scm | ||
| NEWS | ||
| README | ||
| README.org | ||
| ROADMAP | ||
| THANKS | ||
| TODO | ||
- Requirements
- Installation
- Building from Git
- How It Works
- Contact
- Guix & Nix
- Related software
- Copyright Notices
-- mode: org --
GNU Guix (IPA: ɡiːks) is a purely functional package manager, and associated free software distribution, for the GNU system. In addition to standard package management features, Guix supports transactional upgrades and roll-backs, unprivileged package management, per-user profiles, and garbage collection.
It provides Guile Scheme APIs, including a high-level embedded domain-specific languages (EDSLs) to describe how packages are to be built and composed.
GNU Guix can be used on top of an already-installed GNU/Linux distribution, or it can be used standalone (we call that “Guix System”).
Guix is based on the Nix package manager.
Requirements
If you are building Guix from source, please see the manual for build instructions and requirements, either by running:
info -f doc/guix.info "Requirements"
or by checking the web copy of the manual.
Installation
See the manual for the installation instructions, either by running
info -f doc/guix.info "Installation"
or by checking the web copy of the manual.
Building from Git
For information on building Guix from a Git checkout, please see the relevant section in the manual, either by running
info -f doc/guix.info "Building from Git"
or by checking the web_copy of the manual.
How It Works
Guix does the high-level preparation of a derivation. A derivation is
the promise of a build; it is stored as a text file under
/gnu/store/xxx.drv. The (guix derivations) module provides the
`derivation' primitive, as well as higher-level wrappers such as
`build-expression->derivation'.
Guix does remote procedure calls (RPCs) to the build daemon (the guix-daemon
command), which in turn performs builds and accesses to the store on its
behalf. The RPCs are implemented in the (guix store) module.
Contact
GNU Guix is hosted at https://codeberg.org/guix/guix/.
Please email mailto:help-guix@gnu.org for questions. Bug reports should be submitted via https://codeberg.org/guix/guix/issues/. Email mailto:gnu-system-discuss@gnu.org for general issues regarding the GNU system.
Join #guix on irc.libera.chat.
Guix & Nix
GNU Guix is based on the Nix package manager. It implements the same package deployment paradigm, and in fact it reuses some of its code. Yet, different engineering decisions were made for Guix, as described below.
Nix is really two things: a package build tool, implemented by a library and daemon, and a special-purpose programming language. GNU Guix relies on the former, but uses Scheme as a replacement for the latter.
Using Scheme instead of a specific language allows us to get all the features and tooling that come with Guile (compiler, debugger, REPL, Unicode, libraries, etc.) And it means that we have a general-purpose language, on top of which we can have embedded domain-specific languages (EDSLs), such as the one used to define packages. This broadens what can be done in package recipes themselves, and what can be done around them.
Technically, Guix makes remote procedure calls to the ‘nix-worker’ daemon to perform operations on the store. At the lowest level, Nix “derivations” represent promises of a build, stored in ‘.drv’ files in the store. Guix produces such derivations, which are then interpreted by the daemon to perform the build. Thus, Guix derivations can use derivations produced by Nix (and vice versa).
With Nix and the Nixpkgs distribution, package composition happens at the Nix language level, but builders are usually written in Bash. Conversely, Guix encourages the use of Scheme for both package composition and builders. Likewise, the core functionality of Nix is written in C++ and Perl; Guix relies on some of the original C++ code, but exposes all the API as Scheme.
Related software
- Nix, Nixpkgs, and NixOS, functional package manager and associated software distribution, are the inspiration of Guix
- GNU Stow builds around the idea of one directory per prefix, and a symlink tree to create user environments
- STORE shares the same idea
- GNOME's OSTree allows bootable system images to be built from a specified set of packages
- The GNU Source Release Collection (GSRC) is a user-land software distribution; unlike Guix, it relies on core tools available on the host system
Copyright Notices
GNU Guix is made available under the GNU GPL version 3 or later license, and authors retain their copyright. For copyright notices, we adhere to the guidance documented in (info "(maintain) Copyright Notices"), and explicitly allow ranges instead of individual years. Here's an example of the preferred style used for copyright notices in source file headers:
Copyright © 2019-2023, 2025 Your Name <your@email.com>
Meaning there were copyright-able changes made for the years 2019, 2020, 2021, 2022, 2023 and 2025.