./mail/thunderbird, Organize, secure and customize your mail

[ CVSweb ] [ Homepage ] [ RSS ] [ Required by ] [ Add to tracker ]


Branch: CURRENT, Version: 146.0.1nb1, Package name: thunderbird-146.0.1nb1, Maintainer: pkgsrc-users

Thunderbird is a free email, news, and chat application with support for
add-ons, derived from the Mozilla Firefox web browser.


Required to run:
[chat/libotr] [sysutils/dbus-glib] [textproc/icu] [graphics/MesaLib] [net/libIDL] [devel/nspr] [devel/libffi] [devel/nss] [x11/gtk2] [x11/pixman] [x11/gtk3] [graphics/libwebp] [multimedia/ffmpeg4]

Required to build:
[pkgtools/x11-links] [x11/xcb-proto] [lang/clang] [lang/rust] [x11/xorgproto] [devel/lld] [lang/wasi-compiler-rt] [lang/wasi-libc] [lang/wasi-libcxx]

Package options: dbus

Master sites:

Filesize: 763470.32 KB

Version history: (Expand)


CVS history: (Expand)


   2026-01-07 09:49:50 by Thomas Klausner | Files touched by this commit (2525)
Log message:
*: recursive bump for icu 78.1
   2025-12-24 17:47:38 by Ryo ONODERA | Files touched by this commit (13)
Log message:
mail/thunderbird: Update to 146.0.1

Changelog:
146.0.1:
What's Fixed

fixed
Reverted fix that localized consistent special folder names in server's language

146.0:
What's New

new
Enabled configuration of preferred OpenPGP keyserver via the UI

What's Changed

changed
Existing logins are migrated to make use of more modern AES cryptography

What's Fixed

fixed
Memory was not cleaned up after opening New Window from folder pane context
menu

fixed
Thunderbird could crash in server subscription logic

fixed
Importing a vCard only displayed VCF files in the file picker

fixed
Could not distinguish folders with same name in 'Recent Destinations' and
'Favorites'

fixed
Could not compose new message if the folder pane was empty

fixed
'Delete' was missing from context menu when multiple IMAP folders were selected

fixed
'Delete' button in unified toolbar could delete attachments instead of message

fixed
Servers lacking localization showed special folder names in server??s language

fixed
'Recent destinations' submenu was not sorted by time of modification

fixed
Account column could display incorrect account name

fixed
'Tag' submenu of mail context menu could be populated incorrectly

fixed
Extending the expiration date of OpenPGP key set incorrect date

fixed
Could not sign/encrypt (PGP) when using -compose and Thunderbird was not
running

fixed
Account Hub email success messages were not always accurate about config source

fixed
Account Hub advanced config setup did not include default outgoing config

fixed
Account Hub local address book creation could continue with blank name

fixed
Detailed security exception dialog was not shown when adding certificate
exception

fixed
The default account could be reset after restart if uninitialized

fixed
Opening a vCard (.vcf) from file manager or CLI did not work in some cases

fixed
Dragging attachments on macOS to folder or desktop no longer worked

fixed
EWS folder properties "Select this folder for offline use" did not work

fixed
Thunderbird could crash when mail folder was renamed or moved

fixed
Account Hub could fail when manually creating EWS account

fixed
'Offline' folder flag for EWS folders was reset on restart

fixed
'Open with' of Microsoft Office attachment did not mark file with MOTW label

fixed
Visual and UX improvements

fixed
Security fixes

Security fixes:
Mozilla Foundation Security Advisory 2025-95
#CVE-2025-14321: Use-after-free in the WebRTC: Signaling component
#CVE-2025-14322: Sandbox escape due to incorrect boundary conditions in the
 Graphics: CanvasWebGL component
#CVE-2025-14323: Privilege escalation in the DOM: Notifications component
#CVE-2025-14324: JIT miscompilation in the JavaScript Engine: JIT component
#CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT component
#CVE-2025-14326: Use-after-free in the Audio/Video: GMP component
#CVE-2025-14327: Spoofing issue in the Downloads Panel component
#CVE-2025-14328: Privilege escalation in the Netmonitor component
#CVE-2025-14329: Privilege escalation in the Netmonitor component
#CVE-2025-14330: JIT miscompilation in the JavaScript Engine: JIT component
#CVE-2025-14331: Same-origin policy bypass in the Request Handling component
#CVE-2025-14332: Memory safety bugs fixed in Firefox 146 and Thunderbird 146
#CVE-2025-14333: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR
 140.6, Firefox 146 and Thunderbird 146
   2025-12-22 07:08:18 by Adam Ciarcinski | Files touched by this commit (128)
Log message:
revbump for x264
   2025-11-28 15:47:05 by Ryo ONODERA | Files touched by this commit (3)
Log message:
mail/thunderbird: Fix build under x86 architecture without AVX/AVX512

* Bump PKGREVISION.
   2025-11-22 02:07:07 by Ryo ONODERA | Files touched by this commit (3)
Log message:
mail/thunderbird: Fix build under NetBSD 10 at least

* Internal botan-3.8.1 requires GCC 11. Bump GCC_REQD again.
  Fix my build under NetBSD/amd64 10.
   2025-11-14 18:28:39 by Ryo ONODERA | Files touched by this commit (10)
Log message:
mail/thunderbird: Update to 145.0

Changelog:
145.0:
What's New

new
Enable support for DNS over HTTPS

new
Account Hub email manual config option added

new
Add manual configuration to EWS account creation

new
Enable support for Microsoft Exchange via Exchange Web Services

What's Changed

changed
Skype has been retired and therefore dropped from Address book IM selection

changed
Removed pref default_supports_diskspace.{HOST}

changed
Removed pref default_offline_support_level.{HOST}

changed
Use of the string "Junk" has been replaced with "Spam"

changed
Stop shipping 32-bit Linux x86 binaries

What's Fixed

fixed
'Save All' attachments with same names overwrote existing files without warning

fixed
Message headers were re-downloaded at every startup

fixed
Could not drag and drop ICS file to Today Pane

fixed
'Show remote content' did not display remote content for EML message

fixed
Emoji sequences were not properly handled in subject lines

fixed
Unified toolbar Spam button did not switch to "Not Spam" when spam message
selected

fixed
Upgrading Thunderbird hid the Menu bar

fixed
When configuring external GnuPG, user was not promted to import public key

fixed
Message compose window could incorrectly disappear from Task Bar on Windows

fixed
Add-on account creation did not work with Account Hub

fixed
Owl install did not show link to website in Account Hub

fixed
Username field did not appear in Account Hub when exchange authentication
failed

fixed
Disabled inputs could be toggled in Account Hub address book

fixed
Manual account setup in Account Hub defaulted Connection Security to None

fixed
Close button from Account Hub was not narrated

fixed
Account Hub email creation error notifications were not narrated

fixed
Users could not disable spinning overlay in Account Hub for email

fixed
Deleted account data remained in "Export to mobile device" menu

fixed
'Sent' and 'Spam' folders were not always created when setting up new IMAP
accounts

fixed
Some third-party hosted accounts could not be created in Account Hub

fixed
Account Hub allowed keyboard shortcuts to be executed in background screen

fixed
Spam was not checked with mail.server.default.check_all_folders_for_new on

fixed
Upgrade from 128.x->140.x broke authentication for @att.net using Yahoo backend

fixed
Task reminders could fail for tasks without end dates or with shifted due dates

fixed
Visual and UX improvements

fixed
Security fixes

Security fixes:
Mozilla Foundation Security Advisory 2025-90
#CVE-2025-13021: Incorrect boundary conditions in the Graphics: WebGPU
 component
#CVE-2025-13022: Incorrect boundary conditions in the Graphics: WebGPU
 component
#CVE-2025-13012: Race condition in the Graphics component
#CVE-2025-13023: Sandbox escape due to incorrect boundary conditions in the
 Graphics: WebGPU component
#CVE-2025-13016: Incorrect boundary conditions in the JavaScript: WebAssembly
 component
#CVE-2025-13024: JIT miscompilation in the JavaScript Engine: JIT component
#CVE-2025-13025: Incorrect boundary conditions in the Graphics: WebGPU
 component
#CVE-2025-13026: Sandbox escape due to incorrect boundary conditions in the
 Graphics: WebGPU component
#CVE-2025-13017: Same-origin policy bypass in the DOM: Notifications component
#CVE-2025-13018: Mitigation bypass in the DOM: Security component
#CVE-2025-13019: Same-origin policy bypass in the DOM: Workers component
#CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component
#CVE-2025-13020: Use-after-free in the WebRTC: Audio/Video component
#CVE-2025-13014: Use-after-free in the Audio/Video component
#CVE-2025-13015: Spoofing issue in Thunderbird
#CVE-2025-13027: Memory safety bugs fixed in Firefox 145 and Thunderbird 145
   2025-11-04 18:24:34 by Ryo ONODERA | Files touched by this commit (8) | Package updated
Log message:
mail/thunderbird: Update to 144.0.1

Changelog:
144.0.1:
fixed
Message compose window was removed from Task Bar after saving as draft or
template

144.0:
changed
Flatpak runtime has been updated to Freedesktop SDK 24.08

fixed
Copying text from some error alerts was not possible

fixed
Fastmail CalDAV app password access failed due to forced OAuth regression

fixed
Delete key failed to prevent deleting attachments in OpenPGP messages

fixed
Newly created folder was missing under "Recent" when moving a message

fixed
Sender avatar displayed incorrectly for 'Name' via address sender format

fixed
Sorting by threads only brought threads with unread top messages to the top

fixed
News message marked read after NNTP error prevented retrieval from server

fixed
Inbox 'Location' column was not translated in French locale installation

fixed
Not all headers were signed when creating digitally signed OpenPGP email

fixed
Users could not read mail signed with OpenPGP v6 and PQC keys

fixed
Testing a configured personal S/MIME certificate for a sub-identity did not
work

fixed
Testing an S/MIME certificate did not work for an old invalid certificate

fixed
Changing identity in compose window caused modified draft not to be saved

fixed
Shift-click 'Compose Message To' on 'mailto' link did not open in plain text

fixed
Image preview in Insert Image dialog failed with CSP error for web resources

fixed
Thunderbird could crash in various scenarios

fixed
'Copy Message to' action in a newsgroup filter did not work

fixed
Thunderbird could not import profile located at the top level of zip file

fixed
Thunderbird did not clearly fail when importing profile from a bad source

fixed
No way to distinguish between Thunderbird Release/ESR in Windows registry

fixed
Multi-attachment delete/detach confirmation only cited first attachment

fixed
Thunderbird hung when auto-checking multiple accounts for new messages

fixed
Reply All button was missing when using a Microsoft Exchange account

fixed
Sending emails via servers with self-signed certificate did not work

fixed
Task reminders could fail for tasks without end dates or with shifted due dates

fixed
Could not copy an event in multiweek or month view by drag-and-drop

fixed
Calendar discovery with certificate error displayed multiple exceptions

fixed
Visual and UX improvements

fixed
Security fixes

Security fixes:
Mozilla Foundation Security Advisory 2025-84
#CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance()
#CVE-2025-11709: Out of bounds read/write in a privileged process triggered by
 WebGL textures
#CVE-2025-11710: Cross-process information leaked due to malicious IPC messages
#CVE-2025-11711: Some non-writable Object properties could be modified
#CVE-2025-11716: Sandboxed iframes allowed links to open in external apps
 (Android only)
#CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior on web
 resources without a content-type
#CVE-2025-11713: Potential user-assisted code execution in ??Copy as cURL??
 command
#CVE-2025-11719: Use-after-free caused by the native messaging web extension
 API on Windows
#CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR
 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
#CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR
 140.4, Firefox 144 and Thunderbird 144
#CVE-2025-11721: Memory safety bug fixed in Firefox 144 and Thunderbird 144
   2025-10-23 22:40:24 by Thomas Klausner | Files touched by this commit (2999)
Log message:
*: recursive bump for pcre2

Running an old binary against the new pcre doesn't work:
/usr/pkg/lib/libpcre2-8.so.0: version PCRE2_10.47 required by \ 
/usr/pkg/lib/libglib-2.0.so.0 not defined