nongnu: firefox-esr: Update to 140.7.0esr [security fixes].

Fixes CVE-2025-14327, CVE-2026-0877, CVE-2026-0878, CVE-2026-0879,
CVE-2026-0880, CVE-2026-0882, CVE-2026-0883, CVE-2026-0884,
CVE-2026-0885, CVE-2026-0886, CVE-2026-0887, CVE-2026-0890,
CVE-2026-0891.

* nongnu/packages/mozilla.scm (firefox-esr): Update to 140.7.0esr.

Signed-off-by: John Kehayias <john.kehayias@protonmail.com>
This commit is contained in:
Tomas Volf 2026-01-13 21:14:31 +01:00 committed by John Kehayias
parent 9b811605fb
commit 2b33a49a61
No known key found for this signature in database
GPG key ID: 499097AE5EA815D9

View file

@ -87,19 +87,19 @@
;; Update this id with every firefox update to its release date. ;; Update this id with every firefox update to its release date.
;; It's used for cache validation and therefore can lead to strange bugs. ;; It's used for cache validation and therefore can lead to strange bugs.
(define %firefox-esr-build-id "20251208132959") (define %firefox-esr-build-id "20260112140008")
(define-public firefox-esr (define-public firefox-esr
(package (package
(name "firefox-esr") (name "firefox-esr")
(version "140.6.0esr") (version "140.7.0esr")
(source (source
(origin (origin
(method url-fetch) (method url-fetch)
(uri (string-append "https://archive.mozilla.org/pub/firefox/releases/" (uri (string-append "https://archive.mozilla.org/pub/firefox/releases/"
version "/source/firefox-" version ".source.tar.xz")) version "/source/firefox-" version ".source.tar.xz"))
(sha256 (sha256
(base32 "1jadc0ynq49zcqd7ix9nxlrqy5gfhm61p7yliwy068bma2mwjdbc")) (base32 "0a8mrc4pja4cjhayg4af5lsfrf7161gfq03idwik0vvjf68772k0"))
(patches (patches
(map (lambda (patch) (map (lambda (patch)
(search-path (search-path