Pier Angelo Vendrame pushed to branch maint-15.0 at The Tor Project / Applications / tor-browser-build
Commits:
-
0b8cdd78
by Pier Angelo Vendrame at 2026-09-14T18:07:38+02:00
7 changed files:
- projects/browser/Bundle-Data/Docs-MB/ChangeLog.txt
- projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt
- projects/browser/config
- projects/firefox/config
- projects/geckoview/config
- projects/translation/config
- rbm.conf
Changes:
| 1 | +Mullvad Browser 15.0.23 - September 15 2026
|
|
| 2 | + * All Platforms
|
|
| 3 | + * Updated Firefox to 140.16.0esr
|
|
| 4 | + * Updated NoScript to 13.6.33.1984
|
|
| 5 | + * Bug 577: Rebase Mullvad Browser stable onto 140.16.0esr [mullvad-browser]
|
|
| 6 | + * Bug 45296: (H1) SharedWorker Identity Mismatch allows WebAssembly execution at Safer [tor-browser]
|
|
| 7 | + * Bug 45297: (H1) Missing setHTMLUnsafe hook leaves a permanent WebAssembly-capable child realm at Safer [tor-browser]
|
|
| 8 | + * Bug 45299: Backport Security Fixes from Firefox 156 [tor-browser]
|
|
| 9 | + |
|
| 1 | 10 | Mullvad Browser 15.0.21 - September 01 2026
|
| 2 | 11 | * All Platforms
|
| 3 | 12 | * Updated Firefox to 140.15.0esr
|
| 1 | +Tor Browser 15.0.23 - September 15 2026
|
|
| 2 | + * All Platforms
|
|
| 3 | + * Updated NoScript to 13.6.33.1984
|
|
| 4 | + * Bug 45296: (H1) SharedWorker Identity Mismatch allows WebAssembly execution at Safer [tor-browser]
|
|
| 5 | + * Bug 45297: (H1) Missing setHTMLUnsafe hook leaves a permanent WebAssembly-capable child realm at Safer [tor-browser]
|
|
| 6 | + * Bug 45299: Backport Security Fixes from Firefox 156 [tor-browser]
|
|
| 7 | + * Bug 45303: Rebase Tor Browser stable onto 140.16.0esr [tor-browser]
|
|
| 8 | + * Bug 41875: Update relprep.py for the new versions.ini URL [tor-browser-build]
|
|
| 9 | + * Windows + macOS + Linux
|
|
| 10 | + * Updated Firefox to 140.16.0esr
|
|
| 11 | + * Linux
|
|
| 12 | + * Bug 44996: Change the 32-bit linux message to the expired version for the final 15.0 release [tor-browser]
|
|
| 13 | + * Android
|
|
| 14 | + * Updated GeckoView to 140.16.0esr
|
|
| 15 | + * Build System
|
|
| 16 | + * All Platforms
|
|
| 17 | + * Bug 41871: Update downloads repository references in relprep templates [tor-browser-build]
|
|
| 18 | + |
|
| 1 | 19 | Tor Browser 15.0.22 - September 09 2026
|
| 2 | 20 | * All Platforms
|
| 3 | 21 | * Updated Tor to 0.4.9.12
|
| ... | ... | @@ -114,12 +114,12 @@ input_files: |
| 114 | 114 | - filename: dmg-root
|
| 115 | 115 | enable: '[% ! c("var/android") %]'
|
| 116 | 116 | - name: fenix-nightly-apk
|
| 117 | - URL: https://ftp.mozilla.org/pub/fenix/nightly/2026/09/2026-09-08-04-21-39-fenix-157.0a1-android-arm64-v8a/fenix-157.0a1.multi.android-arm64-v8a.apk
|
|
| 117 | + URL: https://ftp.mozilla.org/pub/fenix/nightly/2026/09/2026-09-13-21-24-39-fenix-158.0a1-android-arm64-v8a/fenix-158.0a1.multi.android-arm64-v8a.apk
|
|
| 118 | 118 | enable: '[% c("var/android") %]'
|
| 119 | - sha256sum: 86af54073920df74060f57f892384f523295ddee4c762054b692449b19f047c6
|
|
| 120 | - - URL: https://dist.torproject.org/torbrowser/noscript/noscript-13.6.32.1984.xpi
|
|
| 119 | + sha256sum: fdb4e2eceee55a0410f6ec1cf9fee0487b6fc44abe5f00ccde4a4def1ceb5bbc
|
|
| 120 | + - URL: https://dist.torproject.org/torbrowser/noscript/noscript-13.6.33.1984.xpi
|
|
| 121 | 121 | name: noscript
|
| 122 | - sha256sum: 05713eb71e43bee5a78c16c4a1e5c750b755a637c01ef1810e71f518d38fdb25
|
|
| 122 | + sha256sum: 1e4e7a1a45b2b2826688c072a35d366610312237778835ce07c8b5179a4cb7e4
|
|
| 123 | 123 | - URL: https://addons.mozilla.org/firefox/downloads/file/4981431/ublock_origin-1.74.0.xpi
|
| 124 | 124 | name: ublock-origin
|
| 125 | 125 | sha256sum: 175756d74468c9ba45863f7fc333d3be670f82d5b066314e915814dd547d1652
|
| ... | ... | @@ -18,7 +18,7 @@ container: |
| 18 | 18 | use_container: 1
|
| 19 | 19 | |
| 20 | 20 | var:
|
| 21 | - firefox_platform_version: '140.15.0'
|
|
| 21 | + firefox_platform_version: '140.16.0'
|
|
| 22 | 22 | firefox_version: '[% c("var/firefox_platform_version") %]esr'
|
| 23 | 23 | browser_series: '15.0'
|
| 24 | 24 | browser_rebase: 1
|
| ... | ... | @@ -20,7 +20,7 @@ container: |
| 20 | 20 | build_apk: 1
|
| 21 | 21 | |
| 22 | 22 | var:
|
| 23 | - firefox_platform_version: '140.15.0'
|
|
| 23 | + firefox_platform_version: '140.16.0'
|
|
| 24 | 24 | geckoview_version: '[% c("var/firefox_platform_version") %]esr'
|
| 25 | 25 | browser_series: '15.0'
|
| 26 | 26 | browser_rebase: 1
|
| ... | ... | @@ -12,19 +12,19 @@ compress_tar: 'gz' |
| 12 | 12 | steps:
|
| 13 | 13 | base-browser:
|
| 14 | 14 | base-browser: '[% INCLUDE build %]'
|
| 15 | - git_hash: 530070e3a5fbe2dce823b5ac4d7b937e887b5c8b
|
|
| 15 | + git_hash: 42c240fa39334d44b52a082ece7ea992ce4ff03c
|
|
| 16 | 16 | targets:
|
| 17 | 17 | nightly:
|
| 18 | 18 | git_hash: 'base-browser'
|
| 19 | 19 | tor-browser:
|
| 20 | 20 | tor-browser: '[% INCLUDE build %]'
|
| 21 | - git_hash: cfeef0986124ecc811f607c207f22e0f285a8c0e
|
|
| 21 | + git_hash: b43f67013b014d128543404f8e159dd51250da8f
|
|
| 22 | 22 | targets:
|
| 23 | 23 | nightly:
|
| 24 | 24 | git_hash: 'tor-browser'
|
| 25 | 25 | mullvad-browser:
|
| 26 | 26 | mullvad-browser: '[% INCLUDE build %]'
|
| 27 | - git_hash: 4bf1989120841478aa114b1bf4efefe78cdaf8ee
|
|
| 27 | + git_hash: 7ccb76bc67daa5d88da4a1e3ae0021b19bc55c4b
|
|
| 28 | 28 | targets:
|
| 29 | 29 | nightly:
|
| 30 | 30 | git_hash: 'mullvad-browser'
|
| ... | ... | @@ -32,7 +32,7 @@ steps: |
| 32 | 32 | fenix: '[% INCLUDE build %]'
|
| 33 | 33 | # We need to bump the commit before releasing but just pointing to a branch
|
| 34 | 34 | # might cause too much rebuidling of the Firefox part.
|
| 35 | - git_hash: 8163f5d46d50c48c63513ed86e3db0df721520e6
|
|
| 35 | + git_hash: 086dbaa310f8aa50530f28d68c937d378208a1ad
|
|
| 36 | 36 | compress_tar: 'zst'
|
| 37 | 37 | targets:
|
| 38 | 38 | nightly:
|
| ... | ... | @@ -74,11 +74,11 @@ buildconf: |
| 74 | 74 | git_signtag_opt: '-s'
|
| 75 | 75 | |
| 76 | 76 | var:
|
| 77 | - torbrowser_version: '15.0.22'
|
|
| 77 | + torbrowser_version: '15.0.23'
|
|
| 78 | 78 | torbrowser_build: 'build1'
|
| 79 | 79 | # This should be the date of when the build is started. For the build
|
| 80 | 80 | # to be reproducible, browser_release_date should always be in the past.
|
| 81 | - browser_release_date: '2026/09/08 15:30:00'
|
|
| 81 | + browser_release_date: '2026/09/14 10:00:00'
|
|
| 82 | 82 | browser_release_date_timestamp: '[% USE date; date.format(c("var/browser_release_date"), "%s") %]'
|
| 83 | 83 | browser_default_channel: release
|
| 84 | 84 | browser_platforms:
|
| ... | ... | @@ -128,9 +128,10 @@ var: |
| 128 | 128 | updater_enabled: 1
|
| 129 | 129 | build_mar: 1
|
| 130 | 130 | torbrowser_incremental_from:
|
| 131 | + - '[% IF c("var/tor-browser") %]15.0.22[% END %]'
|
|
| 131 | 132 | - 15.0.21
|
| 132 | 133 | - 15.0.20
|
| 133 | - - 15.0.19
|
|
| 134 | + - '[% IF c("var/mullvad-browser") %]15.0.19[% END %]'
|
|
| 134 | 135 | mar_channel_id: '[% c("var/projectname") %]-torproject-[% c("var/channel") %]'
|
| 135 | 136 | |
| 136 | 137 | # By default, we sort the list of installed packages. This allows sharing
|