Subject: CVS commit: pkgsrc/www/firefox
From: Ryo ONODERA
Date: 2024-10-01 14:47:19
Message id: 20241001124719.9CBF6FC74@cvs.NetBSD.org

Log Message:
www/firefox: Update to 130.0.1

Changelog:
130.0.1:
Fixed

  * Fixed a recent regression causing some UI elements to be rendered as
    left-to-right instead of right-to-left for users of our Saraiki
    localization. (Bug 1917175)

  * Linux: Fixed black rendering of AVIF images when Firefox is built with GCC.
    (Bug 1916038)

130.0:
New

  * Firefox now allows translating selected text portions to different
    languages after a full-page translation.

  * Firefox now offers an easy way to try experimental features with a new
    Firefox Labs page in Settings.

      + AI Chatbot feature lets you add the chatbot of your choice to the
        sidebar, for quick access as you browse.
      + Picture-in-Picture auto-open experiment enables PiP on active videos
        when switching tabs.

  * Overscroll animations are now enabled as the default behavior for
    scrollable areas on Linux.

  * Users in the United States and Canada can view local weather directly on
    the new tab page. Additionally, they have the option to select a specific
    location to see current weather conditions.

Fixed

  * Various security fixes.

  * Fixed an issue where Copy and Paste context menu items intermittently were
    not enabled when expected.

Mozilla Foundation Security Advisory 2024-39
#CVE-2024-8385: WASM type confusion involving ArrayTypes
#CVE-2024-8381: Type confusion when looking up a property name in a "with"
 block
#CVE-2024-8388: Fullscreen notice on Android could be hidden under various
 panels and OS prompts
#CVE-2024-8382: Internal event interfaces were exposed to web content when
 browser EventHandler listener callbacks ran
#CVE-2024-8383: Firefox did not ask before openings news: links in an external
 application
#CVE-2024-8384: Garbage collection could mis-color cross-compartment objects in
 OOM conditions
#CVE-2024-8386: SelectElements could be shown over another site if popups are
 allowed
#CVE-2024-8387: Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2, and
 Thunderbird 128.2
#CVE-2024-8389: Memory safety bugs fixed in Firefox 130

Files:
RevisionActionfile
1.609modifypkgsrc/www/firefox/Makefile
1.541modifypkgsrc/www/firefox/distinfo
1.287modifypkgsrc/www/firefox/mozilla-common.mk
1.76modifypkgsrc/www/firefox/options.mk
1.22modifypkgsrc/www/firefox/files/node-wrapper.sh
1.2modifypkgsrc/www/firefox/patches/patch-js_src_vm_TypedArrayObject-inl.h
1.2modifypkgsrc/www/firefox/patches/patch-python_mozbuild_mozbuild_backend_recursivemake.py
1.4removepkgsrc/www/firefox/patches/patch-media_libtheora_lib_info.c
1.3removepkgsrc/www/firefox/patches/patch-servo_components_style__traits_values.rs
1.1removepkgsrc/www/firefox/patches/patch-servo_ports_geckolib_cbindgen.toml