Heya folks! It's sync day, and that means it's time for the weekly Solus roundup! It's a little early this week to give more time for testing Plasma 6.4.2.
We now have separate packages for the LTS and latest release of .NET (dotnet
). The latest release is .NET 9, which focuses on cloud-native performance, shipping with major runtime speed improvements, and a new feature switch model. Libraries add LINQβs CountBy
/AggregateBy
, upgrades to System.Text.Json
, and new cryptography APIs. The full release notes can be found here. Note: Upgrading may cause moved file warnings in eopkg
. This is normal, harmless, and expected.
OpenXR has been added to the repository this week. It is the go-to open standard when it comes to VR. OpenVR is already in the repositories and is used for SteamVR; the addition of OpenXR will give users an option to use alternatives such as monado
.
Lastly, neohtop
is now in the repository. neohtop
is a modern system monitor built on top of Svelte, Tauri, and π¦ RUST π¦.
Security updates
We have a bunch of security updates this week, some of them fixing some nasty exploits. Be sure to install updates to get the latest protections.
- deno was updated to 2.4.1-20 (@algent-al). Includes security fixes for CVE-2025-48888, CVE-2025-48934.
- dotnet was updated to 9.0.6-11 (@nelsontkq, @nelsontkq). Includes security fixes for CVE-2025-21171, CVE-2025-21172, CVE-2025-24070, CVE-2025-21173, CVE-2024-43499, CVE-2024-43498, CVE-2025-26682, CVE-2025-21176, CVE-2025-26646, CVE-2025-30399.
- dotnet-8 was updated to 8.0.17-2 (@nelsontkq, @nelsontkq). Includes security fixes for CVE-2025-21172, CVE-2025-24070, CVE-2025-21173, CVE-2025-26682, CVE-2025-21176, CVE-2025-26646, CVE-2025-30399.
- git was updated to 2.49.1-137 (@silkeh). Includes security fixes for CVE-2025-46835, CVE-2025-48384, CVE-2025-27614, CVE-2025-48386, CVE-2025-46334, CVE-2025-27613, CVE-2025-48385.
- golang was updated to 1.24.5-129 (@silkeh). Includes security fixes for CVE-2025-4674.
- nodejs-20 was updated to 20.19.2-5 (@silkeh). Includes security fixes for CVE-2025-23165, CVE-2025-23167, CVE-2025-23166.
- nodejs-22 was updated to 22.15.1-6 (@silkeh). Includes security fixes for CVE-2025-23165, CVE-2025-23166.
- valkey was updated to 8.1.3-6 (@androidnisse). Includes security fixes for CVE-2025-32023, CVE-2025-48367.
General updates
The full list of updated packages can be found here.
For the list of currently known issues, see the dedicated thread for it. If you begin experiencing a bug, please look for an issue on our issue tracker, and open a new one if one does not exist.
Thatβs all for this week, folks! We'll be here same time, same place next week for another roundup of the news!