20
0

leap-16.0 code-o-o#leap/features#240 #1

Closed
lkocman wants to merge 23 commits from lkocman/MozillaThunderbird:leap-16.0 into leap-16.0
13 changed files with 1101 additions and 309 deletions

View File

@@ -1,3 +1,233 @@
-------------------------------------------------------------------
Tue Aug 5 19:36:55 UTC 2025 - Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Thunderbird ESR 140.1.1
Fixed
* Users with attachments open in tabs saw an error on Thunderbird restart
* Sending from unified or local folder failed if no default account was set
* Delete button could remove attachment instead of message
* Message list scrolled back when returning to mail tab after opening a message
-------------------------------------------------------------------
Sat Jul 26 08:58:28 UTC 2025 - Andreas Schwab <schwab@suse.de>
- Update memory constraints
-------------------------------------------------------------------
Sat Jul 19 06:05:52 UTC 2025 - Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Thunderbird ESR 140.1.0
* New folders were not added alphabetically if folders manually
reordered beforehand
* Message archive folder creation could silently stop during async
folder creation
MFSA 2025-63 (bsc#1246664)
* CVE-2025-8027 (bmo#1968423)
JavaScript engine only wrote partial return value to stack
* CVE-2025-8028 (bmo#1971581)
Large branch table could lead to truncated instruction
* CVE-2025-8029 (bmo#1928021)
javascript: URLs executed on object and embed tags
* CVE-2025-8036 (bmo#1960834)
DNS rebinding circumvents CORS
* CVE-2025-8037 (bmo#1964767)
Nameless cookies shadow secure cookies
* CVE-2025-8030 (bmo#1968414)
Potential user-assisted code execution in “Copy as cURL” command
* CVE-2025-8031 (bmo#1971719)
Incorrect URL stripping in CSP reports
* CVE-2025-8032 (bmo#1974407)
XSLT documents could bypass CSP
* CVE-2025-8038 (bmo#1808979)
CSP frame-src was not correctly enforced for paths
* CVE-2025-8039 (bmo#1970997)
Search terms persisted in URL bar
* CVE-2025-8033 (bmo#1973990)
Incorrect JavaScript state machine for generators
* CVE-2025-8034 (bmo#1970422, bmo#1970422, bmo#1970422, bmo#1970422)
Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR
128.13, Thunderbird ESR 128.13, Firefox ESR 140.1,
Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
* CVE-2025-8040 (bmo#1975058, bmo#1975058, bmo#1975998, bmo#1975998)
Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird
ESR 140.1, Firefox 141 and Thunderbird 141
* CVE-2025-8035 (bmo#1975961, bmo#1975961, bmo#1975961)
Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird
ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox
141 and Thunderbird 141
-------------------------------------------------------------------
Mon Jul 15 04:38:05 UTC 2025 - Tristan Miller <psychonaut@nothingisreal.com>
- Mozilla Thunderbird ESR 140.0.1
MFSA 2025-54
* CVE-2025-6424 (bmo#1966423)
Use-after-free in FontFaceSet
* CVE-2025-6425 (bmo#1717672)
The WebCompat WebExtension shipped exposed a persistent UUID
* CVE-2025-6426 (bmo#1964385)
No warning when opening executable terminal files on macOS
* CVE-2025-6427 (bmo#1966927)
connect-src Content Security Policy restriction could be
bypassed
* CVE-2025-6429 (bmo#1970658)
Incorrect parsing of URLs could have allowed embedding of
youtube.com
* CVE-2025-6430 (bmo#1971140)
Content-Disposition header ignored when a file is included in
an embed or object tag
* CVE-2025-6432 (bmo#1943804)
DNS Requests leaked outside of a configured SOCKS proxy
* CVE-2025-6433 (bmo#1954033)
WebAuthn would allow a user to sign a challenge on a webpage
with an invalid TLS certificate
* CVE-2025-6434 (bmo#1955182)
HTTPS-Only exception screen lacked anti-clickjacking delay
* CVE-2025-6435 (bmo#1961777 bmo#1950056)
Save as in Devtools could download files without sanitizing
the extension
* CVE-2025-6436 (bmo#1941377 bmo#1960948 bmo#1966187 bmo#1966505
bmo#1970764)
Memory safety bugs fixed in Firefox 140 and Thunderbird 140
- adapt mozilla-ntlm-full-path.patch for Thunderbird 140.0.1
- adapt mozilla-silence-no-return-type.patch for Thunderbird
140.0.1
-------------------------------------------------------------------
Sun Jun 29 06:49:01 UTC 2025 - Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Thunderbird ESR 128.12.0
MFSA 2025-55 (bsc#1244670)
* CVE-2025-6424 (bmo#1966423)
Use-after-free in FontFaceSet
* CVE-2025-6425 (bmo#1717672)
The WebCompat WebExtension shipped exposed a persistent UUID
* CVE-2025-6426 (bmo#1964385)
No warning when opening executable terminal files on macOS
* CVE-2025-6429 (bmo#1970658)
Incorrect parsing of URLs could have allowed embedding of
youtube.com
* CVE-2025-6430 (bmo#1971140)
Content-Disposition header ignored when a file is included in
an embed or object tag
-------------------------------------------------------------------
Tue Jun 17 08:18:37 UTC 2025 - Manfred Hollstein <manfred.h@gmx.net>
- Use these tools/versions unconditionally, package won't build on
Tumbleweed with new gcc15 otherwise:
gcc14, gcc14-c++, cargo1.84, rust1.84
-------------------------------------------------------------------
Mon Jun 9 11:46:34 UTC 2025 - Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Thunderbird ESR 128.11.1
MFSA 2025-49
* CVE-2025-5986 (bmo#1958580, bmo#1968012)
Unsolicited File Download, Disk Space Exhaustion, and Credential
Leakage via mailbox:/// Links
-------------------------------------------------------------------
Sun Jun 8 14:58:03 UTC 2025 - Bernhard Wiedemann <bwiedemann@suse.com>
- Replace usage of %jobs for reproducible builds (boo#1237231)
-------------------------------------------------------------------
Mon May 26 16:54:33 UTC 2025 - Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Thunderbird ESR 128.11.0
MFSA 2025-46 (boo#1243353)
* CVE-2025-5262 (bmo#1962421)
Double-free in libvpx encoder
* CVE-2025-5263 (bmo#1960745)
Error handling for script execution was incorrectly isolated
from web content
* CVE-2025-5264 (bmo#1950001)
Potential local code execution in “Copy as cURL” command
* CVE-2025-5265 (bmo#1962301)
Potential local code execution in “Copy as cURL” command
* CVE-2025-5266 (bmo#1965628)
Script element events leaked cross-origin resource status
* CVE-2025-5267 (bmo#1954137)
Clickjacking vulnerability could have led to leaking saved
payment card details
* CVE-2025-5268 (bmo#1950136, bmo#1958121, bmo#1960499,
bmo#1962634)
Memory safety bugs fixed in Firefox 139, Thunderbird 139,
Firefox ESR 128.11, and Thunderbird 128.11
* CVE-2025-5269 (bmo#1924108)
Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird
128.11
* fixed: Thunderbird could crash if message copying to Sent
folder was interrupted (bmo#1965304)
-------------------------------------------------------------------
Wed May 21 05:23:25 UTC 2025 - Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Thunderbird ESR 128.10.2
MFSA 2025-40 (boo#1243303)
* CVE-2025-4918 (bmo#1966612)
Out-of-bounds access when resolving Promise objects
* CVE-2025-4919 (bmo#1966614)
Out-of-bounds access when optimizing linear sums
* Messages could not be viewed if the profile used a UNC path
* Visual and UX improvements
-------------------------------------------------------------------
Thu May 15 17:11:50 UTC 2025 - Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Thunderbird ESR 128.10.1:
MFSA 2025-34 (boo#1243216)
* CVE-2025-3875 (bmo#1950629)
Sender Spoofing via Malformed From Header in Thunderbird
* CVE-2025-3877 (bmo#1958580)
Unsolicited File Download, Disk Space Exhaustion, and
Credential Leakage via mailbox:/// Links
* CVE-2025-3909 (bmo#1958376)
JavaScript Execution via Spoofed PDF Attachment and file:///
Link
* CVE-2025-3932 (bmo#1960412)
Tracking Links in Attachments Bypassed Remote Content
Blocking
* fixed: Standalone message windows/tabs no longer responded
after folder compaction (bmo#1960349)
* fixed: Thunderbird could crash when importing Outlook
messages (bmo#1851297)
* fixed: Visual and UX improvements (bmo#1960861)
-------------------------------------------------------------------
Sun May 11 09:44:51 UTC 2025 - Christian Boltz <suse-beta@cboltz.de>
- build on s390x needs 17G memory - adjust _constraints
-------------------------------------------------------------------
Tue Apr 29 20:33:16 UTC 2025 - Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Thunderbird ESR 128.10.0
* Changed color override defaults with high contrast mode on
macOS and Linux
* Using Delete column in "Search Messages..." window could delete
other messages
MFSA 2025-32 (bsc#1241621)
* CVE-2025-2817 (bmo#1917536)
Privilege escalation in Thunderbird Updater
* CVE-2025-4082 (bmo#1937097)
WebGL shader attribute memory corruption in Thunderbird for
macOS
* CVE-2025-4083 (bmo#1958350)
Process isolation bypass using "javascript:" URI links in
cross-origin frames
* CVE-2025-4084 (bmo#1949994, bmo#1956698, bmo#1960198)
Potential local code execution in "copy as cURL" command
* CVE-2025-4087 (bmo#1952465)
Unsafe attribute access during XPath parsing
* CVE-2025-4091 (bmo#1951161, bmo#1952105)
Memory safety bugs fixed in Firefox 138, Thunderbird 138,
Firefox ESR 128.10, and Thunderbird 128.10
* CVE-2025-4093 (bmo#1894100)
Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird
128.10
-------------------------------------------------------------------
Tue Apr 15 20:16:38 UTC 2025 - Wolfgang Rosenauer <wr@rosenauer.org>

View File

@@ -1,8 +1,9 @@
#
# spec file for package MozillaThunderbird
#
# Copyright (c) 2025 SUSE LLC
# Copyright (c) 2025 SUSE LLC and contributors
# Copyright (c) 2006-2025 Wolfgang Rosenauer <wr@rosenauer.org>
# Copyright (c) 2025 Tristan Miller <psychonaut@nothingisreal.com>
#
# All modifications and additions to the file contributed by third parties
# remain the property of their copyright owners, unless otherwise agreed
@@ -28,9 +29,9 @@
# orig_suffix b3 (or esr)
# major 69
# mainver %%major.99
%define major 128
%define mainver %major.9.2
%define orig_version 128.9.2
%define major 140
%define mainver %major.1.1
%define orig_version 140.1.1
%define orig_suffix esr
%define update_channel esr
%define source_prefix thunderbird-%{orig_version}
@@ -92,18 +93,14 @@ Name: %{pkgname}
BuildRequires: Mesa-devel
BuildRequires: alsa-devel
BuildRequires: autoconf213
BuildRequires: cargo1.84
BuildRequires: dbus-1-glib-devel
BuildRequires: dejavu-fonts
BuildRequires: fdupes
BuildRequires: gcc14
BuildRequires: gcc14-c++
BuildRequires: memory-constraints
%if 0%{?suse_version} < 1550 && 0%{?sle_version} <= 150600
BuildRequires: gcc13
BuildRequires: gcc13-c++
%else
BuildRequires: gcc-c++
%endif
BuildRequires: cargo1.78
BuildRequires: rust1.78
BuildRequires: rust1.84
%if 0%{useccache} != 0
BuildRequires: ccache
%endif
@@ -133,7 +130,7 @@ BuildRequires: python3-curses
BuildRequires: python3-devel
%endif
%endif
BuildRequires: rust-cbindgen >= 0.26
BuildRequires: rust-cbindgen >= 0.27
BuildRequires: unzip
BuildRequires: update-desktop-files
BuildRequires: xorg-x11-libXt-devel
@@ -312,7 +309,7 @@ echo "" > .obsenv.sh
cat >> .obsenv.sh <<EOF
export CARGO_HOME=${RPM_BUILD_DIR}/%{srcname}-%{orig_version}/.cargo
export MOZ_SOURCE_CHANGESET=\$RELEASE_TAG
#export MOZ_SOURCE_CHANGESET=\$RELEASE_TAG
export SOURCE_REPO=\$RELEASE_REPO
export source_repo=\$RELEASE_REPO
export MOZ_SOURCE_REPO=\$RELEASE_REPO
@@ -322,14 +319,9 @@ export BUILD_OFFICIAL=1
export MOZ_TELEMETRY_REPORTING=1
export MACH_BUILD_PYTHON_NATIVE_PACKAGE_SOURCE=system
export CFLAGS="%{optflags}"
%if 0%{?suse_version} < 1550 && 0%{?sle_version} <= 150600
export CC=gcc-13
export CXX=g++-13
%else
%if 0%{?clang_build} == 0
export CC=gcc
export CXX=g++
%endif
export CC=gcc-14
export CXX=g++-14
%endif
%ifarch %arm %ix86
### NOTE: these sections are not required anymore. Alson --no-keep-memory + -Wl,-z,pack-relative-relocs causes
@@ -359,7 +351,7 @@ source ./.obsenv.sh
cat << EOF > $MOZCONFIG
mk_add_options MOZILLA_OFFICIAL=1
mk_add_options BUILD_OFFICIAL=1
mk_add_options MOZ_MAKE_FLAGS=%{?jobs:-j%jobs}
mk_add_options MOZ_MAKE_FLAGS=%{?_smp_mflags}
mk_add_options MOZ_OBJDIR=@TOPSRCDIR@/../obj
ac_add_options --disable-bootstrap
ac_add_options --prefix=%{_prefix}
@@ -470,7 +462,7 @@ ac_add_options --without-wasm-sandboxed-libraries
ac_add_options --enable-official-branding
EOF
#%%define njobs 0%{?jobs:%jobs}
#%%define njobs 0%{?jobs:%%jobs}
# Weird race condition when building langpacks which comes and goes in OBS/IBS is hitting heavy with TB 128
# so we have to build it sequentially, sadly.
%define njobs 1
@@ -617,8 +609,9 @@ exit 0
%{progdir}/thunderbird-bin
# crashreporter files
%if %crashreporter
%{progdir}/crashhelper
%{progdir}/crashreporter
%{progdir}/minidump-analyzer
#%%{progdir}/minidump-analyzer
%endif
%dir %{progdir}/chrome/
%{progdir}/chrome/icons/

View File

@@ -47,6 +47,16 @@
</memoryperjob>
</hardware>
</overwrite>
<overwrite>
<conditions>
<arch>s390x</arch>
</conditions>
<hardware>
<memory>
<size unit="G">17</size>
</memory>
</hardware>
</overwrite>
<overwrite>
<conditions>
<arch>x86_64</arch>
@@ -57,4 +67,14 @@
</memory>
</hardware>
</overwrite>
<overwrite>
<conditions>
<arch>riscv64</arch>
</conditions>
<hardware>
<memory>
<size unit="G">28</size>
</memory>
</hardware>
</overwrite>
</constraints>

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:c51b9bbfb8b29d31b42475bb6db78742f3afdd1c31085621ffea909320e8f23c
size 30352232

3
l10n-140.1.1esr.tar.xz Normal file
View File

@@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:3d1d482a383d9349a05e261282be243872f2097edb5d45b235651e6180ce65e2
size 33282056

View File

@@ -1,18 +1,14 @@
# HG changeset patch
# User Petr Cerny <pcerny@novell.com>
# Parent 7308e4a7c1f769f4bbbc90870b849cadd99495a6
# Parent 1c6a565013e4c5f3494f964269783939cd5ed0b8
Bug 634334 - call to the ntlm_auth helper fails
diff --git a/extensions/auth/nsAuthSambaNTLM.cpp b/extensions/auth/nsAuthSambaNTLM.cpp
--- a/extensions/auth/nsAuthSambaNTLM.cpp
+++ b/extensions/auth/nsAuthSambaNTLM.cpp
@@ -160,7 +160,7 @@ nsresult nsAuthSambaNTLM::SpawnNTLMAuthH
const char* username = PR_GetEnv("USER");
if (!username) return NS_ERROR_FAILURE;
diff -ru thunderbird-140.0.1.old/extensions/auth/nsAuthSambaNTLM.cpp thunderbird-140.0.1/extensions/auth/nsAuthSambaNTLM.cpp
--- thunderbird-140.0.1.old/extensions/auth/nsAuthSambaNTLM.cpp 2025-07-09 19:15:12.000000000 -0500
+++ thunderbird-140.0.1/extensions/auth/nsAuthSambaNTLM.cpp 2025-07-14 23:33:57.065780950 -0500
@@ -153,7 +153,7 @@
options.fds_to_remap.push_back(
std::pair{fromChildPipeWrite.get(), STDOUT_FILENO});
- std::vector<std::string> argvVec{"ntlm_auth", "--helper-protocol",
+ std::vector<std::string> argvVec{"/usr/bin/ntlm_auth", "--helper-protocol",
"ntlmssp-client-1", "--use-cached-creds",
"--username", username};
- const char* const args[] = {"ntlm_auth",
+ const char* const args[] = {"/usr/bin/ntlm_auth",
"--helper-protocol",
"ntlmssp-client-1",
"--use-cached-creds",

File diff suppressed because it is too large Load Diff

View File

@@ -2,19 +2,20 @@ This file contains the public PGP key that is used to sign builds and
artifacts of Mozilla projects (such as Firefox and Thunderbird).
Please realize that this file itself or the public key servers may be
compromised. You are encouraged to validate the authenticity of these keys in
an out-of-band manner.
compromised. You are encouraged to validate the authenticity of these
keys in an out-of-band manner.
Mozilla users: pgp < KEY
gpg --show-keys < KEY
pub rsa4096 2015-07-17 [SC]
14F26682D0916CDD81E37B6D61B7B526D98F0353
uid [ full ] Mozilla Software Releases <release@mozilla.com>
uid Mozilla Software Releases <release@mozilla.com>
sub rsa4096 2021-05-17 [S] [expired: 2023-05-17]
sub rsa4096 2015-07-17 [S] [expired: 2017-07-16]
sub rsa4096 2017-06-22 [S] [expired: 2019-06-22]
sub rsa4096 2019-05-30 [S] [expired: 2021-05-29]
sub rsa4096 2021-05-17 [S] [expired: 2023-05-17]
sub rsa4096 2023-05-05 [S] [expires: 2025-05-04]
sub rsa4096 2025-03-13 [S] [expires: 2027-03-13]
-----BEGIN PGP PUBLIC KEY BLOCK-----
@@ -400,6 +401,41 @@ W81ABx4ASBktXAf1IweRbbxqW8OgMhG6xHTeiEjjav7SmlD0XVOxjhI+qBoNPovW
lChqONxablBkuh0Jd6kdNiaSEM9cd60kK3GT/dBMyv0yVhhLci6HQZ+Mf4cbn0Kt
ayzuQLOcdRCN3FF/JNQH3v6LA1MdRfmJlgC4UdiepBb1uCgtVIPizRuXWDjyjzeP
ZRN/AqaUbEoNBHhIz0nKhQGDbst4ugIzJWIX+6UokwPC3jvJqQQttccjAy6kXBmx
fxyRMB5BEeLY0+qVPyvOxpXEGnlSHYmdIS4=
=ZEQW
fxyRMB5BEeLY0+qVPyvOxpXEGnlSHYmdIS65Ag0EZ9KQfQEQAOVIyh0sZPPFLWxo
FT0WhPzHw8BhgnCBNdZAh9+SM0Apq2VcQKSjBjKiterOTtc6EVh0K2ikbGKHQ1Sv
wNdsYL01cSkJSJORig/1Du1eh+2nlo8nut7xT//V+2FQyWFCLDeQvLlAs3QHMrMY
xTcwNk3qi/z1Z5Q4e6Re2aKRU00LtSomD6CKWy9nAaqTRNzzdndJwIyCyshX4bbU
zAzE7Wbgh/E0/FgBGw87LYITqyU6US4lvoUXB+89XxwMxO9I74L118gXEyybz+JN
0/w87hXAKnaKjasSvobKE4mau8SXqmOO66MxiMaF4Xsmr3oIwo8q9W5d+hA+t225
ipq2rZZErmPL44deMCeKmepjLTa9CoxX2oVpDWGOYFRyJRkLDyyH4O3gCo/5qv4r
OTJqPFfKPtrjWFJKGf4P4UD0GSBX2Q+mOf2XHWsMJE4t8T7jxQCSAQUMwt6M18h1
auIqcfkuNvdJhcl2GvJyCMIbkA3AoiuKaSPgoVCmJdbc6Ao9ydmMUB5Q1rYpMNKC
MsuVP9OcX8FoHEVMXOvr0f6Wfj+iHytfO2VTqrw/cqoCyuPoSrgxjs1/cRSz5g9f
Z0zrOtQyNB5yJ3YPTG3va1/XLflrjPcT4ZUkej9nkFpCNWdEZVWD/z3vXBGSV11N
9Cdy60QbD4yZvDjV2GQ+dwAF1o1BABEBAAGJBHIEGAEKACYWIQQU8maC0JFs3YHj
e21ht7Um2Y8DUwUCZ9KQfQIbAgUJA8JnAAJACRBht7Um2Y8DU8F0IAQZAQoAHRYh
BAm+7WPzRiot/6s7h17LZJfBogJWBQJn0pB9AAoJEF7LZJfBogJW9I4QAJbv4Rhb
4x6Jl75x2Lfp46/e3fZVDhzUdLjK8A/acRF7JRBuJVJRaijJ5tngdknmlmbzfqly
zsMWUciAwVJRvijNFDeicet5zJpBRsXEUAug3iVCD1KlVvLzjCi9Eb9s6xCQjSJ8
DZE020s41wdqtb1nziDASAkg+YH2DzpTEaZVNM39uNDKbaJLYIjKA9MV1YHArqUl
dFsoofBe4zIZRFyvMD7Gmr7Xm0IWYLrfmnenm1JJYIkvGUeVoP8dEonAVhLVwvww
ufobV0qdtMfhZsgFwf1XSHI9MtD4yAVtBqBTkfFeRLnBjJK/ywYxGqbadt1b57I4
ywTQ16oXNrlTF1Su0I8i/fo0i/9ohNl3opN3LbaEbhT37M4xpy4MgL2Fthddc2gW
vF/8TFRaXw7LaLSR7HwO+Y0CpOtV/Ct4RzKEulY5DpV9b1JQJhpLcjMz+pBDAM3K
JuiV6Bcfoz5PZowFy74UmE02Vzk/oyuI/o4KMihy0UzWQVkOZTTu4eONktgGiZOn
RFdiLKVgeLEDXTLdhbuwGS2+wX3I7lLP9AWpK8Ahc81eUwU6MwdbfwfJ1ELtKaa/
JmMjaWkr5aGrp88d8ePR9jYA47Z2q0esB67pRJVe0McVJlu9GQGq05S7lZKs6mi9
dHTzeHwua//IXHMK0s3WhMU7vGwJ3E2+pTstf8AQALSwkezD3QchPV+5CAUYY7Cm
MXB6zzIU18wCS61Y8QdDvqmtWHdMVTp4xT14fS6cvB4uFzacGQJ7CVIWeZgwEFzZ
iev3dKpnUOGg0WQSwmQQA0JCg6/qS0AeUPINjhWtNcR7voCqAYeRcjo47UJclD/K
KNTCn27btHRaEmpTdTtC6sxiVElFObb3a9tHXqwLWp8gJ+NZ+6mlrvvH2hm1CAyQ
TDRYC7nN69QJrKHR8HA3AeR5figQHLwvmfQlV2erZE17GT+L5t0HxX/HKZCim91P
Apqa+7iY0eKPAG5iacABrBi9zzh/ex0ovvuxsBDKUFCSu7HIivnAVrdS/kbO1qJ5
I3MBMp0dlQ6PS6LeZIRhxts0aPPZedsXytoL7kFLISfJ55AuhJpskz+55uviJhp/
H3zNBYtQ+dmFmp4RRk/Nvu0zv6OGtaZy6M5X24Pbzb/OApBML84cEmb3iZie9J2Z
YW68/D96sP09x6GItCJlCIdQZkRcwmkQwgtq9sJDw92/vSGeYdRn+oCAxJ14eObC
sVwcfJARLt45btEnx+zRCAHAHQHpV6qTGT6nqg57XuM9iNNdyTGKRU+Iklgb9LRx
VAQfbn5uXYb5j2ox5pjxtbXTf9Lbo7RkygcWSKZPWmYgGsKS6jmXkDa/TyOlPxkb
aknpPbYMBztRT4Ju0VU4
=4Dnl
-----END PGP PUBLIC KEY BLOCK-----

View File

@@ -1,10 +1,10 @@
PRODUCT="thunderbird"
CHANNEL="esr128"
VERSION="128.9.2"
CHANNEL="esr140"
VERSION="140.1.1"
VERSION_SUFFIX="esr"
REV_VERSION="128.9.1"
REV_VERSION="140.1.0"
PREV_VERSION_SUFFIX="esr"
#SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation
RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr128"
RELEASE_TAG="3dc116e792891bdcfaaa36232ed71fb2a79ed570"
RELEASE_TIMESTAMP="20250415075302"
RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr140"
RELEASE_TAG="c2cef707a311a491572603b9902681f654964f08"
RELEASE_TIMESTAMP="20250805025534"

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:21cbdc12fd2a5c79ce3ae3f23b5c334160b4380858aaa8a92fc1d9c9acfdd5fb
size 674861236

View File

@@ -1,16 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEErdcHlHlwDcrf3VM34207E/PZMnQFAmf+NL8ACgkQ4207E/PZ
MnQC3xAAnuM8XgSk1ntr6xuPTs0PtiOVn4SsM3i47Cfdi/ZbOye3Gr4FeW2KcHLO
I9jpFZv84lxCAi7IOG01tHIGehmKMBIl+y31oh+ECTxftghtlYtE2FR4s00rAkdt
1n6Vrht/R0HPW1Shi6pf/qK01pOL8OQG1bGvOtJdZWCiQv3BZPGJblOC32d8E5Tg
3nBl2YEO2l01G6J3cNxQRgGnWW2UM8n61Uha/5LKWU/yvv9390Pj1BItziOBD5L4
52xmQKyGcNUOZ2br7wO4nGf05er2aOFJPyYPuRLpuTd85MMA1yL99gjEoROXqo2o
fxS8se/otNNMujdfFwoyGldg0PJpWCCW54WGTeT7aRVP0+jhC0S/HD+At0NeABhL
a1B74NqP5O/v9KjOQpUNPGBmoCbq/+VqIkfmDZF2D7wTLyVHfGySLi5sTuNjvpNj
Vq1XyGty2hGXMmJ2rHshVCK1MphEwibK4f2P3pBYWblEuN/tcYZaO2KQPh0GlH3I
/UhzV5Iv+6mL2H78qOkBsWwjxHeSCd64UZi0BdemtFjVOXYCXenRC7ywnG/q+xxD
N+jlhAqiMvWyZLVMhPASK+ih8ascUMTOifV48xh6s0WYzzgc810wwUiH5XLl+8Oh
oXmxT2R4wgsq3pw10eDCbjMl8tqOVyfA97y3HmGkO2x89OqyIGk=
=pPx+
-----END PGP SIGNATURE-----

View File

@@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:136b160954abe2426ab26e46d35d946207ab5e217ac72d3ff5cb1b87680d4fcd
size 753445400

View File

@@ -0,0 +1,16 @@
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEECb7tY/NGKi3/qzuHXstkl8GiAlYFAmiRqcYACgkQXstkl8Gi
AlZscRAAuYghAziF92noBbHIfY1LZ21FdYuZuq058k8sgWkd6gdQ/Q+Vk4nfOFIn
zrl76a2o8qRzkhhOPkRDQoYkdy2cmVTMANqF8mp3hE+LLOTmb9x5G9BgUDsWbIUd
E3mcGRJ6LAfZeBjFJNKMTw94Vr4TOSWgS4KqEwo2RnL+1w65eCWTMnIRvcs1mYJD
iLtZUvdLACx499ZY0vvzraCtVQFJ6+m8uzf+FXfIgJDL6XRV3H4rDPSjamgBuIKv
QfL/toEGW+ZtqAr88u5gCLOfXNXziIk0TgLm5Wd0rnseGODQTSr/wLdEr6BROBle
HU0CtxN15PVTTwZV1KH0mSgvEMlfi461Ii3Ct+HdF6i6HAbMORsfKlQPPn4JGiZT
B4QXIohr0FTp73PH83nDCk1YvRl0kSHCUMjrTdchFVkOXTIW58eWTUA2zT6sFaMQ
+NLA0xaKGVFBTD7NWgSbMGIgsZPDhnhJlpnGR4K9YuE1+F5hL7AMmAqkb/tGslAz
LMOL6CiOSuOYckOan6uGtxCmb2h3FbCyjfRMtQbvT3V116ZBDle462gDo79pAJwC
1CyF9RGnvDx9m4+N2NR8b9YZxyBdyVciEnzmf+KqOlj6hGPR4dPeizEzEIQK2ZXD
ixScReBjDyyaTLivq7RBha4nHPVfWzYicA5CmWUxMGXmibW3NfM=
=ccda
-----END PGP SIGNATURE-----