./mail/thunderbird, Organize, secure and customize your mail

[ CVSweb ] [ Homepage ] [ RSS ] [ Required by ]


Branch: CURRENT, Version: 151.0.1nb2, Package name: thunderbird-151.0.1nb2, Maintainer: pkgsrc-users

Thunderbird is a free email, news, and chat application with support for
add-ons, derived from the Mozilla Firefox web browser.


Required to run:
[chat/libotr] [sysutils/dbus-glib] [textproc/icu] [graphics/MesaLib] [net/libIDL] [devel/nspr] [devel/libffi] [devel/nss] [x11/gtk2] [x11/pixman] [x11/gtk3] [graphics/libwebp] [multimedia/ffmpeg4]

Required to build:
[pkgtools/x11-links] [x11/xcb-proto] [lang/clang] [lang/rust] [x11/xorgproto] [devel/lld] [lang/wasi-compiler-rt] [lang/wasi-libc] [lang/wasi-libcxx]

Package options: dbus

Master sites:

Filesize: 895756.977 KB

Version history: (Expand)


CVS history: (Expand)


   2026-07-13 06:36:42 by Thomas Klausner | Files touched by this commit (846)
Log message:
*: recursive bump for libmpg123 dependency in lame
   2026-06-11 09:18:01 by Thomas Klausner | Files touched by this commit (788)
Log message:
gtk3: bump PKGREVISION for wayland option default change

Recursive bump to hopefully fix bulk build fallout due to the
unversioned change.
   2026-06-06 16:51:30 by Ryo ONODERA | Files touched by this commit (9) | Package updated
Log message:
mail/thunderbird: Update to 151.0.1

Changelog:
151.0.1:
Fixed
Forwarding/Redirecting Exchange messages failed with NS_ERROR_OUT_OF_MEMORY

151.0:
What's New
new
Enable Thundermail OAuth sign-in with account auto-configuration

new
Enable users to override OAuth provider details for EWS accounts

new
Tasks can be sorted by created or modified date

What's Changed
changed
Reinstated default application check when Thunderbird starts

changed
OpenPGP public key no longer attached by default in signed-only messages

What's Fixed
fixed
Thunderbird could crash when processing message headers

fixed
Thunderbird could crash on startup

fixed
Calendar view tabs were not properly keyboard accessible

fixed
Thunderbird could crash when processing new incoming messages

fixed
On macOS, dragging attachments out of Thunderbird created multiple copies

fixed
Cancelling a newsgroup posting was not possible

fixed
Some IMAP emails showed current time instead of correct received date

fixed
Search result count was missing when using 'Find in Message' or Ctrl+F

fixed
Search results showed older irrelevant emails before newer exact matches

fixed
Reply with selected text lost formatting for HTML messages containing </pre>

fixed
Multipart/related attachments were not preserved when editing or forwarding

fixed
Forwarded malformed MIME email had empty body and extra attachment

fixed
OWL add-on description was not visible in Account Hub for non-en-US locales

fixed
Account Hub prompted for password after OAuth login, causing Outlook setup
failure

fixed
Auto-discovered Account Hub values were not preserved for manual editing

fixed

Account Hub links for encryption and signature opened the wrong account

fixed
Virtual folders did not update correctly for filtered POP3 messages

fixed
Thunderbird could crash in spam filtering

fixed
Using thunderbird -compose with double quotes made last email address invalid

fixed
With auto-mark-read disabled, large mail still marked as read during load delay

fixed
It was not possible to create date-only all-day tasks

fixed
Task context menu (right-click) had several disabled menu items

fixed
'Current Tasks' view showed past and finished tasks instead of only unfinished

fixed
Visual and UX improvements

fixed
Security fixes

Security fixes:
Mozilla Foundation Security Advisory 2026-50
#CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs
 component
#CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component
#CVE-2026-8948: Same-origin policy bypass in the DOM: Networking component
#CVE-2026-8949: Integer overflow in the Widget: Win32 component
#CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component
#CVE-2026-8952: Privilege escalation in the Application Update component
#CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access
 APIs component
#CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/
 Video component
#CVE-2026-8955: Privilege escalation in the DOM: Workers component
#CVE-2026-8956: Integer overflow in the Networking: JAR component
#CVE-2026-8957: Privilege escalation in the Enterprise Policies component
#CVE-2026-8958: Information disclosure, sandbox escape in the Security: Process
 Sandboxing component
#CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the
 Widget: Win32 component
#CVE-2026-8960: Spoofing issue in WebExtensions
#CVE-2026-8961: Spoofing issue in the Form Autofill component
#CVE-2026-8962: Mitigation bypass in the DOM: Security component
#CVE-2026-8963: Spoofing issue in the Web Speech component
#CVE-2026-8964: Spoofing issue in the Popup Blocker component
#CVE-2026-8965: Information disclosure in the DOM: Security component
#CVE-2026-8966: Information disclosure in the IP Protection component
#CVE-2026-8967: Information disclosure in the Graphics: WebGPU component
#CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video:
 Web Codecs component
#CVE-2026-8969: Mitigation bypass in the DOM: Security component
#CVE-2026-8970: Privilege escalation in the Security component
#CVE-2026-8971: Same-origin policy bypass in the Networking: JAR component
#CVE-2026-8972: Privilege escalation in the WebRTC: Audio/Video component
#CVE-2026-8973: Memory safety bugs fixed in Thunderbird 151
#CVE-2026-8974: Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird
 151
#CVE-2026-8975: Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird
 151
   2026-02-26 14:38:44 by Ryo ONODERA | Files touched by this commit (3)
Log message:
mail/thunderbird: Update to 148.0

* Use nodejs* in the standard way.

Changelog:
148.0:
What's New

new
Accessiblity is improved in various tree views

new
'Favorites' added as destination for 'Move To' and 'File' buttons

new
Add mail.openpgp.load_untested_gpgme_version to load untested GPGME version

new
NTLM is exposed as an available authentication method for EWS accounts

What's Changed

changed
Read folders are now removed from Unread Folders view

changed
Yahoo, AT&T, AOL accounts are switched to PKCE, a more secure auth protocol

What's Fixed

fixed
Periodic new mail checks silently stopped after sleep or network outages

fixed
Donation banner stole focus when Thunderbird was running in the background

fixed
   2026-02-01 08:01:19 by Ryo ONODERA | Files touched by this commit (2)
Log message:
mail/thunderbird: Update to 147.0.1

Changelog:
147.0.1:
What's Fixed

fixed
Thunderbird crashed during search, even when not actively searching

fixed
Security fixes

Security fixes:
Mozilla Foundation Security Advisory 2026-07
#CVE-2026-0818: CSS-based exfiltration of the content from partially encrypted
 emails when allowing remote content
   2026-01-27 09:41:10 by Thomas Klausner | Files touched by this commit (1344)
Log message:
*: recursive bump for removal of cairo's xcb option
   2026-01-22 20:41:09 by Ryo ONODERA | Files touched by this commit (11)
Log message:
mail/thunderbird: Update to 147.0

Changelog:
147.0:
What's New

new
Add "Show Full Path" folder pane option for compact view modes

new
Add `mail.useLocalizedFolderNames' to toggle special folder name localization

What's Changed

changed
Special folders are now localized based on a restricted set of names

What's Fixed

fixed
Selected status and priority was not displayed in search widgets

fixed
Compacting multiple folders failed and did not compact

fixed
Resetting manual folder sorting did not work for sub folders

fixed
Unified archive subfolders could show wrong names and no messages

fixed
Folders with deep hierarchy and long folder names could fail to display

fixed
Moving saved search/virtual folder under IMAP could fail

fixed
"Open and Show" for OpenPGP-signed message (.eml) did not work

fixed
"Search Messages" search did not finish due to unparsable local folders

fixed
Compose command line flag no longer worked correctly

fixed
Search for "Attachment" in Settings menu did not find "Files and \ 
Attachments"

fixed
Account Hub did not show error message on failure when creating OAuth2 EWS
account

fixed
Thunderbird could crash during exchange address account setup

fixed
Japanese locale users could not create message filters

fixed
Moving virtual folder within maildir based IMAP or local folder could fail

fixed
Thunderbird could crash when marking all messages as read

fixed
Startup could be slow with large number of folders not using subscriptions

fixed
EWS message send that required a password errored instead of prompting

fixed
EWS HTTP 500 backoff errors were not handled gracefully

fixed
SMTP sending could hang when when multiple messages queued for sending

fixed
Thunderbird could crash when emptying EWS trash

fixed
Broken feed icon could prevent updating of feeds

fixed
Calendar did not alert user for connection issues

fixed
Creation of tasks with Start or Due date was not possible

fixed
Visual and UX improvements

fixed
Security fixes

Security fixes:
Mozilla Foundation Security Advisory 2026-04
#CVE-2026-0877: Mitigation bypass in the DOM: Security component
#CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in the
 Graphics: CanvasWebGL component
#CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in the
 Graphics component
#CVE-2026-0880: Sandbox escape due to integer overflow in the Graphics
 component
#CVE-2026-0881: Sandbox escape in the Messaging System component
#CVE-2026-0882: Use-after-free in the IPC component
#CVE-2026-0883: Information disclosure in the Networking component
#CVE-2026-0884: Use-after-free in the JavaScript Engine component
#CVE-2026-0885: Use-after-free in the JavaScript: GC component
#CVE-2026-0886: Incorrect boundary conditions in the Graphics component
#CVE-2026-0887: Clickjacking issue, information disclosure in the PDF Viewer
 component
#CVE-2026-0888: Information disclosure in the XML component
#CVE-2026-0889: Denial-of-service in the DOM: Service Workers component
#CVE-2026-0890: Spoofing issue in the DOM: Copy & Paste and Drag & Drop
 component
#CVE-2026-0891: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR
 140.7, Firefox 147 and Thunderbird 147
#CVE-2026-0892: Memory safety bugs fixed in Firefox 147 and Thunderbird 147
   2026-01-07 09:49:50 by Thomas Klausner | Files touched by this commit (2525)
Log message:
*: recursive bump for icu 78.1