Skip to content

Conversation

@mweinelt
Copy link
Member

@mweinelt mweinelt commented Jan 1, 2026

https://meta.discourse.org/t/release-v3-5-3-security-and-maintenance-release/392357

Fixes: CVE-2025-64528
(cherry picked from commit af6946f)

Backports #475361

Things done

  • Built on platform:
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • Tested, as applicable:
  • Ran nixpkgs-review on this PR. See nixpkgs-review usage.
  • Tested basic functionality of all binary files, usually in ./result/bin/.
  • Nixpkgs Release Notes
    • Package update: when the change is major or breaking.
  • NixOS Release Notes
    • Module addition: when adding a new NixOS module.
    • Module update: when the change is significant.
  • Fits CONTRIBUTING.md, pkgs/README.md, maintainers/README.md and other READMEs.

Add a 👍 reaction to pull requests you find important.

@mweinelt mweinelt added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Jan 1, 2026
@mweinelt mweinelt requested review from leona-ya and talyz and removed request for talyz January 1, 2026 15:45
@nixpkgs-ci nixpkgs-ci bot added 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux. 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. 4.workflow: backport This targets a stable branch labels Jan 1, 2026
@leona-ya
Copy link
Member

leona-ya commented Jan 2, 2026

This will again break in the same way as #469624. I didn't anticipate another release in the 3.5.x block. I can provide a change to the update script tomorrow.

@mweinelt
Copy link
Member Author

mweinelt commented Jan 2, 2026

Awh, sorry. Thanks for noticing.

@leona-ya
Copy link
Member

leona-ya commented Jan 5, 2026

#477161. I tried now a bit to fix the master build, but wasn't able to :/

@mweinelt
Copy link
Member Author

mweinelt commented Jan 5, 2026

Looks like a gcc15 regression at first glance.

@leona-ya leona-ya added this pull request to the merge queue Jan 9, 2026
Merged via the queue into NixOS:release-25.11 with commit 15921bb Jan 9, 2026
32 of 34 checks passed
@mweinelt mweinelt deleted the nixos-25.11-discourse-3.5.3 branch January 9, 2026 11:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1.severity: security Issues which raise a security issue, or PRs that fix one 4.workflow: backport This targets a stable branch 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants