mr. m
a4f0d01a88
no-bug: Sign mars after building them (gh-13213)
2026-04-11 16:45:24 +02:00
JDX50S
76b7bc96ef
gh-10746: Fix SMAuthorizedClients wrong Team ID (gh-13191)
2026-04-11 12:39:44 +02:00
mr. m
fd8308fcb1
Revert "no-bug: Individually download each artifact on release" (gh-13211)
...
Reverts zen-browser/desktop#13199
---------
Signed-off-by: mr. m <91018726+mr-cheffy@users.noreply.github.com >
2026-04-11 12:03:04 +02:00
mr. m
97451e23c8
no-bug: Individually download each artifact on release (gh-13199)
2026-04-10 17:17:52 +02:00
JDX50S
11cf410f87
no-bug: fix SIGNMAR path in Sign MAR step to point at binary not directory (gh-13193)
2026-04-10 12:25:16 +02:00
dependabot[bot]
000098adb1
no-bug: bump axios from 1.13.6 to 1.15.0 in the npm_and_yarn group across 1 directory (gh-13187)
...
Bumps the npm_and_yarn group with 1 update in the / directory:
[axios](https://github.com/axios/axios ).
Updates `axios` from 1.13.6 to 1.15.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/releases ">axios's
releases</a>.</em></p>
<blockquote>
<h2>v1.15.0</h2>
<p>This release delivers two critical security patches, adds runtime
support for Deno and Bun, and includes significant CI hardening,
documentation improvements, and routine dependency updates.</p>
<h2>⚠️ Important Changes</h2>
<ul>
<li><strong>Deprecation:</strong> <code>url.parse()</code> usage has
been replaced to address Node.js deprecation warnings. If you are on a
recent version of Node.js, this resolves console warnings you may have
been seeing. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10625 ">#10625</a></strong>)</li>
</ul>
<h2>🔒 Security Fixes</h2>
<ul>
<li><strong>Proxy Handling:</strong> Fixed a <code>no_proxy</code>
hostname normalisation bypass that could lead to Server-Side Request
Forgery (SSRF). (<strong><a
href="https://redirect.github.com/axios/axios/issues/10661 ">#10661</a></strong>)</li>
<li><strong>Header Injection:</strong> Fixed an unrestricted cloud
metadata exfiltration vulnerability via a header injection chain.
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10660 ">#10660</a></strong>)</li>
</ul>
<h2>🚀 New Features</h2>
<ul>
<li><strong>Runtime Support:</strong> Added compatibility checks and
documentation for Deno and Bun environments. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10652 ">#10652</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10653 ">#10653</a></strong>)</li>
</ul>
<h2>🔧 Maintenance & Chores</h2>
<ul>
<li><strong>CI Security:</strong> Hardened workflow permissions to least
privilege, added the <code>zizmor</code> security scanner, pinned action
versions, and gated npm publishing with OIDC and environment protection.
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10618 ">#10618</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10619 ">#10619</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10627 ">#10627</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10637 ">#10637</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10666 ">#10666</a></strong>)</li>
<li><strong>Dependencies:</strong> Bumped
<code>serialize-javascript</code>, <code>handlebars</code>,
<code>picomatch</code>, <code>vite</code>, and
<code>denoland/setup-deno</code> to latest versions. Added a 7-day
Dependabot cooldown period. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10574 ">#10574</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10572 ">#10572</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10568 ">#10568</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10663 ">#10663</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10664 ">#10664</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10665 ">#10665</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10669 ">#10669</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10670 ">#10670</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10616 ">#10616</a></strong>)</li>
<li><strong>Documentation:</strong> Unified docs, improved
<code>beforeRedirect</code> credential leakage example, clarified
<code>withCredentials</code>/<code>withXSRFToken</code> behaviour,
HTTP/2 support notes, async/await timeout error handling, header case
preservation, and various typo fixes. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10649 ">#10649</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10624 ">#10624</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/7452 ">#7452</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/7471 ">#7471</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10654 ">#10654</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10644 ">#10644</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10589 ">#10589</a></strong>)</li>
<li><strong>Housekeeping:</strong> Removed stale files, regenerated
lockfile, and updated sponsor scripts and blocks. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10584 ">#10584</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10650 ">#10650</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10582 ">#10582</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10640 ">#10640</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10659 ">#10659</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10668 ">#10668</a></strong>)</li>
<li><strong>Tests:</strong> Added regression coverage for urlencoded
<code>Content-Type</code> casing. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10573 ">#10573</a></strong>)</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve Axios:</p>
<ul>
<li><strong><a
href="https://github.com/raashish1601 "><code>@raashish1601</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10573 ">#10573</a></strong>)</li>
<li><strong><a
href="https://github.com/Kilros0817 "><code>@Kilros0817</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10625 ">#10625</a></strong>)</li>
<li><strong><a
href="https://github.com/ashstrc "><code>@ashstrc</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10624 ">#10624</a></strong>)</li>
<li><strong><a
href="https://github.com/Abhi3975 "><code>@Abhi3975</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10589 ">#10589</a></strong>)</li>
<li><strong><a
href="https://github.com/theamodhshetty "><code>@theamodhshetty</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/7452 ">#7452</a></strong>)</li>
</ul>
<h2>v1.14.0</h2>
<p>This release focuses on compatibility fixes, adapter stability
improvements, and test/tooling modernisation.</p>
<h2>⚠️ Important Changes</h2>
<ul>
<li><strong>Breaking Changes:</strong> None identified in this
release.</li>
<li><strong>Action Required:</strong> If you rely on env-based proxy
behaviour or CJS resolution edge-cases, validate your integration after
upgrade (notably <code>proxy-from-env</code> v2 alignment and
<code>main</code> entry compatibility fix).</li>
</ul>
<h2>🚀 New Features</h2>
<ul>
<li><strong>Runtime Features:</strong> No new end-user features were
introduced in this release.</li>
<li><strong>Test Coverage Expansion:</strong> Added broader smoke/module
test coverage for CJS and ESM package usage. (<a
href="https://redirect.github.com/axios/axios/pull/7510 ">#7510</a>)</li>
</ul>
<h2>🐛 Bug Fixes</h2>
<ul>
<li><strong>Headers:</strong> Trim trailing CRLF in normalised header
values. (<a
href="https://redirect.github.com/axios/axios/pull/7456 ">#7456</a>)</li>
<li><strong>HTTP/2:</strong> Close detached HTTP/2 sessions on timeout
to avoid lingering sessions. (<a
href="https://redirect.github.com/axios/axios/pull/7457 ">#7457</a>)</li>
<li><strong>Fetch Adapter:</strong> Cancel <code>ReadableStream</code>
created during request-stream capability probing to prevent async
resource leaks. (<a
href="https://redirect.github.com/axios/axios/pull/7515 ">#7515</a>)</li>
<li><strong>Proxy Handling:</strong> Fixed env proxy behavior with
<code>proxy-from-env</code> v2 usage. (<a
href="https://redirect.github.com/axios/axios/pull/7499 ">#7499</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/blob/v1.x/CHANGELOG.md ">axios's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2><a
href="https://github.com/axios/axios/compare/v1.13.2...v1.13.3 ">1.13.3</a>
(2026-01-20)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>http2:</strong> Use port 443 for HTTPS connections by
default. (<a
href="https://redirect.github.com/axios/axios/issues/7256 ">#7256</a>)
(<a
href="d7e6065346 ">d7e6065</a>)</li>
<li><strong>interceptor:</strong> handle the error in the same
interceptor (<a
href="https://redirect.github.com/axios/axios/issues/6269 ">#6269</a>)
(<a
href="5945e40bb1 ">5945e40</a>)</li>
<li>main field in package.json should correspond to cjs artifacts (<a
href="https://redirect.github.com/axios/axios/issues/5756 ">#5756</a>)
(<a
href="7373fbff24 ">7373fbf</a>)</li>
<li><strong>package.json:</strong> add 'bun' package.json 'exports'
condition. Load the Node.js build in Bun instead of the browser build
(<a
href="https://redirect.github.com/axios/axios/issues/5754 ">#5754</a>)
(<a
href="b89217e3e9 ">b89217e</a>)</li>
<li>silentJSONParsing=false should throw on invalid JSON (<a
href="https://redirect.github.com/axios/axios/issues/7253 ">#7253</a>)
(<a
href="https://redirect.github.com/axios/axios/issues/7257 ">#7257</a>)
(<a
href="7d19335e43 ">7d19335</a>)</li>
<li>turn AxiosError into a native error (<a
href="https://redirect.github.com/axios/axios/issues/5394 ">#5394</a>)
(<a
href="https://redirect.github.com/axios/axios/issues/5558 ">#5558</a>)
(<a
href="1c6a86dd2c ">1c6a86d</a>)</li>
<li><strong>types:</strong> add handlers to AxiosInterceptorManager
interface (<a
href="https://redirect.github.com/axios/axios/issues/5551 ">#5551</a>)
(<a
href="8d1271b49f ">8d1271b</a>)</li>
<li><strong>types:</strong> restore AxiosError.cause type from unknown
to Error (<a
href="https://redirect.github.com/axios/axios/issues/7327 ">#7327</a>)
(<a
href="d8233d9e8e ">d8233d9</a>)</li>
<li>unclear error message is thrown when specifying an empty proxy
authorization (<a
href="https://redirect.github.com/axios/axios/issues/6314 ">#6314</a>)
(<a
href="6ef867e684 ">6ef867e</a>)</li>
</ul>
<h3>Features</h3>
<ul>
<li>add <code>undefined</code> as a value in AxiosRequestConfig (<a
href="https://redirect.github.com/axios/axios/issues/5560 ">#5560</a>)
(<a
href="095033c626 ">095033c</a>)</li>
<li>add automatic minor and patch upgrades to dependabot (<a
href="https://redirect.github.com/axios/axios/issues/6053 ">#6053</a>)
(<a
href="65a7584eda ">65a7584</a>)</li>
<li>add Node.js coverage script using c8 (closes <a
href="https://redirect.github.com/axios/axios/issues/7289 ">#7289</a>)
(<a
href="https://redirect.github.com/axios/axios/issues/7294 ">#7294</a>)
(<a
href="ec9d94e9f8 ">ec9d94e</a>)</li>
<li>added copilot instructions (<a
href="3f83143bfe ">3f83143</a>)</li>
<li>compatibility with frozen prototypes (<a
href="https://redirect.github.com/axios/axios/issues/6265 ">#6265</a>)
(<a
href="860e03396a ">860e033</a>)</li>
<li>enhance pipeFileToResponse with error handling (<a
href="https://redirect.github.com/axios/axios/issues/7169 ">#7169</a>)
(<a
href="88d7884254 ">88d7884</a>)</li>
<li><strong>types:</strong> Intellisense for string literals in a
widened union (<a
href="https://redirect.github.com/axios/axios/issues/6134 ">#6134</a>)
(<a
href="f73474d02c ">f73474d</a>),
closes <a
href="https://redirect.github.com//redirect.github.com/microsoft/TypeScript/issues/33471/issues/issuecomment-1376364329 ">microsoft/TypeScript#33471</a></li>
</ul>
<h3>Reverts</h3>
<ul>
<li>Revert "fix: silentJSONParsing=false should throw on invalid
JSON (<a
href="https://redirect.github.com/axios/axios/issues/7253 ">#7253</a>)
(<a
href="https://redirect.github.com/axios/axios/issues/7 ">#7</a>…"
(<a
href="https://redirect.github.com/axios/axios/issues/7298 ">#7298</a>)
(<a
href="a4230f5581 ">a4230f5</a>),
closes <a
href="https://redirect.github.com/axios/axios/issues/7253 ">#7253</a> <a
href="https://redirect.github.com/axios/axios/issues/7 ">#7</a> <a
href="https://redirect.github.com/axios/axios/issues/7298 ">#7298</a></li>
<li><strong>deps:</strong> bump peter-evans/create-pull-request from 7
to 8 in the github-actions group (<a
href="https://redirect.github.com/axios/axios/issues/7334 ">#7334</a>)
(<a
href="2d6ad5e48b ">2d6ad5e</a>)</li>
</ul>
<h3>Contributors to this release</h3>
<ul>
<li><!-- raw HTML omitted --> <a href="https://github.com/ashvin2005 "
title="+1752/-4 ([#7218 ](https://github.com/axios/axios/issues/7218 )
[#7218 ](https://github.com/axios/axios/issues/7218 ) )">Ashvin
Tiwari</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/mochinikunj "
title="+940/-12 ([#7294 ](https://github.com/axios/axios/issues/7294 )
[#7294 ](https://github.com/axios/axios/issues/7294 ) )">Nikunj
Mochi</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/imanchalsingh "
title="+544/-102 ([#7169 ](https://github.com/axios/axios/issues/7169 )
[#7185 ](https://github.com/axios/axios/issues/7185 ) )">Anchal
Singh</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/jasonsaayman "
title="+317/-73 ([#7334 ](https://github.com/axios/axios/issues/7334 )
[#7298 ](https://github.com/axios/axios/issues/7298 )
)">jasonsaayman</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/brodo "
title="+99/-120 ([#5558 ](https://github.com/axios/axios/issues/5558 )
)">Julian Dax</a></li>
<li><!-- raw HTML omitted --> <a
href="https://github.com/AKASHDHARDUBEY " title="+167/-0
([#7287 ](https://github.com/axios/axios/issues/7287 )
[#7288 ](https://github.com/axios/axios/issues/7288 ) )">Akash Dhar
Dubey</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/madhumitaaa "
title="+20/-68 ([#7198 ](https://github.com/axios/axios/issues/7198 )
)">Madhumita</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/Tackoil "
title="+80/-2 ([#6269 ](https://github.com/axios/axios/issues/6269 )
)">Tackoil</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/justindhillon "
title="+41/-41 ([#6324 ](https://github.com/axios/axios/issues/6324 )
[#6315 ](https://github.com/axios/axios/issues/6315 ) )">Justin
Dhillon</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/Rudrxxx "
title="+71/-2 ([#7257 ](https://github.com/axios/axios/issues/7257 )
)">Rudransh</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/WuMingDao "
title="+36/-36 ([#7215 ](https://github.com/axios/axios/issues/7215 )
)">WuMingDao</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/codenomnom "
title="+70/-0 ([#7201 ](https://github.com/axios/axios/issues/7201 )
[#7201 ](https://github.com/axios/axios/issues/7201 )
)">codenomnom</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/Nandann018-ux "
title="+60/-10 ([#7272 ](https://github.com/axios/axios/issues/7272 )
)">Nandan Acharya</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/KernelDeimos "
title="+22/-40 ([#7042 ](https://github.com/axios/axios/issues/7042 )
)">Eric Dubé</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/tiborpilz "
title="+40/-4 ([#5551 ](https://github.com/axios/axios/issues/5551 )
)">Tibor Pilz</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/joaoGabriel55 "
title="+31/-4 ([#6314 ](https://github.com/axios/axios/issues/6314 )
)">Gabriel Quaresma</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/turadg "
title="+23/-6 ([#6265 ](https://github.com/axios/axios/issues/6265 )
)">Turadg Aleahmad</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="772a4e54ec "><code>772a4e5</code></a>
chore(release): prepare release 1.15.0 (<a
href="https://redirect.github.com/axios/axios/issues/10671 ">#10671</a>)</li>
<li><a
href="4b071371be "><code>4b07137</code></a>
chore(deps-dev): bump vite from 8.0.0 to 8.0.5 in /tests/smoke/esm (<a
href="https://redirect.github.com/axios/axios/issues/10663 ">#10663</a>)</li>
<li><a
href="51e57b39db "><code>51e57b3</code></a>
chore(deps-dev): bump vite from 8.0.2 to 8.0.5 (<a
href="https://redirect.github.com/axios/axios/issues/10664 ">#10664</a>)</li>
<li><a
href="fba1a77930 "><code>fba1a77</code></a>
chore(deps-dev): bump vite from 8.0.2 to 8.0.5 in /tests/module/esm (<a
href="https://redirect.github.com/axios/axios/issues/10665 ">#10665</a>)</li>
<li><a
href="0bf6e28eac "><code>0bf6e28</code></a>
chore(deps): bump denoland/setup-deno in the github-actions group (<a
href="https://redirect.github.com/axios/axios/issues/10669 ">#10669</a>)</li>
<li><a
href="8107157c57 "><code>8107157</code></a>
chore(deps-dev): bump the development_dependencies group with 4 updates
(<a
href="https://redirect.github.com/axios/axios/issues/10670 ">#10670</a>)</li>
<li><a
href="e66530e330 "><code>e66530e</code></a>
ci: require npm-publish environment for releases (<a
href="https://redirect.github.com/axios/axios/issues/10666 ">#10666</a>)</li>
<li><a
href="49f23cbfe4 "><code>49f23cb</code></a>
chore(sponsor): update sponsor block (<a
href="https://redirect.github.com/axios/axios/issues/10668 ">#10668</a>)</li>
<li><a
href="363185461b "><code>3631854</code></a>
fix: unrestricted cloud metadata exfiltration via header injection chain
(<a
href="https://redirect.github.com/axios/axios/issues/10 ">#10</a>...</li>
<li><a
href="fb3befb6da "><code>fb3befb</code></a>
fix: no_proxy hostname normalization bypass leads to ssrf (<a
href="https://redirect.github.com/axios/axios/issues/10661 ">#10661</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/axios/axios/compare/v1.13.6...v1.15.0 ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Install script changes</summary>
<p>This version modifies <code>prepare</code> script that runs during
installation. Review the package contents before updating.</p>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/zen-browser/desktop/network/alerts ).
</details>
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 23:40:53 +02:00
DQSS
dfc47ee5d7
gh-12241: fix skip startup bookmark invalidation when no workspace bookmarks exist (gh-13168)
2026-04-09 22:51:24 +02:00
CosmoCreeper
4add28d3c0
no-bug: Remove non-existent hooks property (gh-13160)
...
Co-authored-by: mr. m <91018726+mr-cheffy@users.noreply.github.com >
2026-04-09 22:46:47 +02:00
mr. m
0a7e81f532
gh-8932: Add more PGO instrumentation (gh-13158)
2026-04-09 22:41:27 +02:00
mr. m
fc2eb5a20b
no-bug: Re-enable maintenance service (gh-13186)
2026-04-09 22:40:38 +02:00
Slowlife
a2a64cec6a
gh-13085: add support for new gh pull request dashboard (gh-13090)
2026-04-09 20:22:06 +02:00
mr. m
4ca83bfe33
no-bug: remove unnecessary verification option from build configuration (gh-13182)
2026-04-09 20:06:27 +02:00
mr. m
5163cf68d6
no-bug: update script execution to use bash for mar_sign.sh (gh-13181)
2026-04-09 19:57:59 +02:00
JDX50S
270db6d671
Merge commit from fork
...
* security: enable MAR signature verification for updates
Remove `--enable-unverified-updates` from the common mozconfig. This flag
was disabling all MAR (Mozilla ARchive) signature verification in the
updater binary, meaning update packages were applied without any
cryptographic authenticity check.
With this flag removed, the Mozilla build system will:
- Link NSS and signmar into the updater binary
- Enable SecVerifyTransformCreate-based signature verification on macOS
- Require MAR files to contain valid signatures before applying
REQUIRED FOLLOW-UP (maintainer action):
1. Generate a Zen-specific MAR signing keypair (RSA-PKCS1-SHA384)
See: https://firefox-source-docs.mozilla.org/build/buildsystem/mar.html
2. Place the public key DER file(s) in the source tree at
toolkit/mozapps/update/updater/release_primary.der
3. Sign MAR files during the release build with the private key
4. Set ACCEPTED_MAR_CHANNEL_IDS in update-settings.ini to restrict
which update channels the updater will accept
Ref: GHSA-qpj9-m8jc-mw6q
* no-bug: Added signature steps
* no-bug: Export browser/installer/package-manifest.in
---------
Co-authored-by: Maliq Barnard <maliqbarnard@Maliqs-MacBook-Air.local >
Co-authored-by: Mr. M <mr.m@tuta.com >
2026-04-09 19:28:31 +02:00
Afeefur
8b9f449f95
no-bug: added tests for unloading all other workspaces (gh-13100)
1.19.8b
2026-04-09 01:36:37 +02:00
mr. m
9433b8a8f0
gh-13121: Fixed top bar not showing when urlbar is focused (gh-13150)
2026-04-08 20:51:30 +02:00
mr. m
561a03421f
gh-13121: Fixed compact mode not hiding with translations (gh-13143)
2026-04-08 17:04:48 +02:00
mr. m
73ae2fa258
gh-13140: Fixed some items not respecting reduce motion (gh-13141)
2026-04-08 14:08:47 +02:00
Afeefur
28fcaf94a3
gh-13133: Add Duplicate tab keyboard shortcut (gh-13123)
...
Co-authored-by: mr. m <91018726+mr-cheffy@users.noreply.github.com >
1.19.7b
2026-04-07 19:48:36 +02:00
mr. m
8d646b3e41
gh-13131: Sync upstream Firefox to version 149.0.2 (gh-13129)
2026-04-07 19:43:49 +02:00
mr. m
f8efd2c22a
no-bug: New Crowdin updates (gh-13132)
2026-04-07 18:43:06 +02:00
mr. m
5ae688819e
gh-13119: Revert :is -> :where compact mode selectors (gh-13124)
2026-04-07 09:35:55 +02:00
reizumi
631fb9fc3b
no-bug: optimize icons and replace existing icons (gh-13113)
2026-04-06 19:05:34 +02:00
Tito Oliveira
640561ab19
gh-13114: Remove 'slots filled' message in tab context (gh-13102)
2026-04-06 19:03:12 +02:00
mr. m
c0c957cbff
gh-11667: Fixed unable to install addons in compact mode (gh-13097)
2026-04-05 20:38:04 +02:00
mr. m
16d7caa98f
gh-13093: Fixed double seperator lines in context menu (gh-13094)
2026-04-05 10:54:15 +02:00
mr. m
8333c34124
gh-13077: Fixed ctrl+W closing window when splitting tabs (gh-13083)
2026-04-04 20:50:25 +02:00
Chris McLaughlin
d9e03e8b83
gh-13081: focus URL bar on new blank tab in single-toolbar mode (gh-13082)
...
Co-authored-by: mr. m <mr.m@tuta.com >
2026-04-04 20:42:57 +02:00
Chris McLaughlin
bbaf7279ed
gh-12112: auto-focus URL bar when replace-newtab is disabled (gh-13080)
...
Co-authored-by: mr. m <mr.m@tuta.com >
2026-04-04 19:54:13 +02:00
mr. m
6ffeecad3a
gh-10687: Space switching should ignore system prefs (gh-13079)
2026-04-04 14:03:59 +02:00
mr. m
db3eea65b7
gh-13060: Fixed collapsed pins not marked as active (gh-13061)
1.19.6b
2026-04-03 00:00:22 +02:00
mr. m
b55358b9ab
gh-12979: Import compositor patches from upstream (gh-13054)
2026-04-02 17:17:08 +02:00
mr. m
dba5a0402c
no-bug: Dont animate glance image preview opacity (gh-13055)
2026-04-02 17:15:47 +02:00
mr. m
92eb6b07c3
gh-12985: Disable new firefox search widget (gh-13052)
2026-04-02 16:12:24 +02:00
mr. m
36aa7b0a20
gh-13038: Fixed trying to swap browsers that dont exist (gh-13051)
2026-04-02 16:10:18 +02:00
Hythera
0619d3d8de
no-bug: remove obsolete patch from Firefox 149.0 (gh-13049)
2026-04-02 14:30:52 +02:00
mr. m
6b5f6c7b9d
no-bug: Properly align identity box icon (gh-13035)
2026-04-01 13:07:10 +02:00
mr. m
69e3a995ae
gh-13024: Fixed restoring tab state also taking into account scroll (gh-13034)
2026-04-01 12:56:05 +02:00
mr. m
e32ff53d2d
gh-13030: Fixed unsplit tab item showing when it shouldn't (gh-13033)
2026-04-01 12:20:25 +02:00
Zack Koppert
ba593a19dc
no-bug: update OSPO action references to canonical org path (gh-13028)
2026-03-31 21:57:06 +02:00
mr. m
f40a7aaee1
gh-13016: Fixed pinned tabs not being able to collapse (gh-13018)
2026-03-31 14:46:32 +02:00
mr. m
62286a2758
gh-13015: Fixed tablist scroll beibg occasionally stuck (gh-13017)
2026-03-31 13:46:03 +02:00
Tyson Cung
067b8244ec
gh-12966: rename split view tab labels for clarity (gh-12983)
...
Co-authored-by: Tyson Cung <tysoncung@example.com >
2026-03-30 17:42:00 +02:00
mr. m
be9928beda
no-bug: Prevent focusing the urlbar on tab switch (gh-13002)
2026-03-30 17:34:32 +02:00
Davide Taffarello
742a1e6882
gh-12730: conflict keybord shortcut name always shows "Escape" (gh-12993)
...
Co-authored-by: mr. m <91018726+mr-cheffy@users.noreply.github.com >
2026-03-30 14:15:25 +02:00
mr. m
a2796d7af0
gh-9600: Fixed text being unreadable with some themes (gh-12998)
2026-03-30 14:14:23 +02:00
mr. m
2d6f2cbbde
gh-12994: Fixed adress bar not being aligned with the container (gh-12997)
2026-03-30 13:26:34 +02:00
mr. m
3fd89a93f5
no-bug: Move live folder context menu item to the toolbar menu (gh-12991)
2026-03-29 19:20:11 +02:00
mr. m
595f236a7a
gh-12989: Make split command use context tabs (gh-12990)
2026-03-29 18:59:15 +02:00
Rugved_018
8fec3702f4
gh-12104: Fix notification tabs overlap (gh-12965)
...
Co-authored-by: mr. m <mr.m@tuta.com >
2026-03-29 15:44:03 +02:00