forked from products/PackageHub
Compare commits
36 Commits
hide-java-
...
leap-16.0
| Author | SHA256 | Date | |
|---|---|---|---|
| 272e6df8eb | |||
|
|
27989672d0 | ||
| 464de639b5 | |||
|
|
f54fe69075 | ||
| 61765b6b59 | |||
|
|
1852c8a8ce | ||
| dfe0ef234b | |||
|
|
99dd857c9a | ||
| c90e774192 | |||
|
|
873c5fa4c1 | ||
| 23baf9f465 | |||
|
|
d40fc7ab20 | ||
| cf34c8859c | |||
|
|
07aabbdaf8 | ||
|
|
5f7c1b8f9d | ||
| ff4dacc9ba | |||
| d0432c612a | |||
| fe1490e4c7 | |||
| 6156889504 | |||
| 3324d45f45 | |||
| cb7dba8325 | |||
|
|
f528a0f52a | ||
|
|
f3c5c2bccf | ||
| 7cda1fc03b | |||
| aee60a7699 | |||
|
|
1b6dba3cd1 | ||
| 146b6deca8 | |||
|
|
a8c4523f73 | ||
| d264abcae0 | |||
|
|
662471de4f | ||
|
|
779f4f8aa0 | ||
| 5cbea7b736 | |||
| 4acf9d3745 | |||
|
f893d406a8
|
|||
| 40dc8cadfe | |||
| 26275cf377 |
8
.gitmodules
vendored
8
.gitmodules
vendored
@@ -17562,10 +17562,6 @@
|
||||
path = rlwrap
|
||||
url = ../../pool/rlwrap
|
||||
branch = leap-16.0
|
||||
[submodule "rmt-server"]
|
||||
path = rmt-server
|
||||
url = ../../pool/rmt-server
|
||||
branch = leap-16.0
|
||||
[submodule "rmw"]
|
||||
path = rmw
|
||||
url = ../../pool/rmw
|
||||
@@ -26134,3 +26130,7 @@
|
||||
path = python-pyRFC3339
|
||||
url = ../../pool/python-pyRFC3339
|
||||
branch = leap-16.0
|
||||
[submodule "openQA-devel-container"]
|
||||
path = openQA-devel-container
|
||||
url = ../../pool/openQA-devel-container
|
||||
branch = leap-16.0
|
||||
|
||||
2
act
2
act
Submodule act updated: ed079edc0d...8bfe9d9547
Submodule bash-git-prompt updated: 422b159da2...9bd39c9f5d
2
chromium
2
chromium
Submodule chromium updated: 6685801dcd...f6c3bfa54e
2
git-bug
2
git-bug
Submodule git-bug updated: 22bb247e73...2390ae6cee
Submodule gitea-tea updated: 91324b6042...143cd92098
Submodule gnome-browser-connector updated: 7efed54b43...630cfb02e2
2
openQA
2
openQA
Submodule openQA updated: d4fcc3820c...e091086774
1
openQA-devel-container
Submodule
1
openQA-devel-container
Submodule
Submodule openQA-devel-container added at 2af23581fe
Submodule os-autoinst updated: 54674dc3b7...caad282598
13
patchinfo.20251127113212085239.93181000773252/_patchinfo
Normal file
13
patchinfo.20251127113212085239.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,13 @@
|
||||
<patchinfo incident="packagehub-40">
|
||||
<issue tracker="cve" id="2025-61659"/>
|
||||
<issue tracker="bnc" id="1247489">VUL-0: CVE-2025-61659: bash-git-prompt: uses predictable file in /tmp for a copy of the git index</issue>
|
||||
<packager>michals</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for bash-git-prompt</summary>
|
||||
<description>This update for bash-git-prompt fixes the following issues:
|
||||
|
||||
- CVE-2025-61659: Fixed an issue where predictable files in /tmp were used for a copy of the git index (bsc#1247489)
|
||||
</description>
|
||||
<package>bash-git-prompt</package>
|
||||
</patchinfo>
|
||||
65
patchinfo.20251127122850445245.93181000773252/_patchinfo
Normal file
65
patchinfo.20251127122850445245.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,65 @@
|
||||
<patchinfo incident="packagehub-38">
|
||||
<issue tracker="bnc" id="1243954">VUL-0: CVE-2025-29785: shadowsocks-v2ray-plugin: github.com/quic-go/quic-go/internal/ackhandler: loss recovery logic for path probe packets can be used by a malicious QUIC client to trigger a null pointer dereference</issue>
|
||||
<issue tracker="cve" id="2025-47911">cve#2025-47911 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-47911</issue>
|
||||
<issue tracker="bnc" id="1243946">VUL-0: CVE-2025-29785: v2ray-core: github.com/quic-go/quic-go/internal/ackhandler: loss recovery logic for path probe packets can be used by a malicious QUIC client to trigger a null pointer dereference</issue>
|
||||
<issue tracker="cve" id="2025-297850">cve#2025-297850 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-297850</issue>
|
||||
<issue tracker="bnc" id="1251404">VUL-0: CVE-2025-47911: v2ray-core: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<issue tracker="bnc" id="1235164">VUL-0: CVE-2023-49295: v2ray-core: github.com/quic-go/quic-go: memory exhaustion attack against QUIC's path validation mechanism</issue>
|
||||
<packager>hillwood</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for shadowsocks-v2ray-plugin, v2ray-core</summary>
|
||||
<description>This update for shadowsocks-v2ray-plugin, v2ray-core fixes the following issues:
|
||||
|
||||
Changes in shadowsocks-v2ray-plugin:
|
||||
|
||||
- Update version to 5.25.0
|
||||
* Update v2ray-core to v5.25.0
|
||||
- Add update-vendor.patch, update v2ray-core to v5.33.0 (boo#1243954 and CVE-2025-297850)
|
||||
|
||||
Changes in v2ray-core:
|
||||
|
||||
- Fix CVE-2025-47911 and boo#1251404
|
||||
* Add fix-CVE-2025-47911.patch
|
||||
* Update golang.org/x/net to 0.45.0 in vendor
|
||||
|
||||
- Update version to 5.38.0
|
||||
* TLSMirror Connection Enrollment System
|
||||
* Add TLSMirror Sequence Watermarking
|
||||
* LSMirror developer preview protocol is now a part of mainline V2Ray
|
||||
* proxy dns with NOTIMP error
|
||||
* Add TLSMirror looks like TLS censorship resistant transport protocol
|
||||
as a developer preview transport
|
||||
* proxy dns with NOTIMP error
|
||||
* fix false success from SOCKS server when Dispatch() fails
|
||||
* HTTP inbound: Directly forward plain HTTP 1xx response header
|
||||
* add a option to override domain used to query https record
|
||||
* Fix bugs
|
||||
* Update vendor
|
||||
|
||||
- Update version to 5.33.0
|
||||
* bump github.com/quic-go/quic-go from 0.51.0 to 0.52.0(boo#1243946 and CVE-2025-297850)
|
||||
* Update other vendor source
|
||||
|
||||
- Update version to 5.31.0
|
||||
* Add Dns Proxy Response TTL Control
|
||||
* Fix call newError Base with a nil value error
|
||||
* Update vendor (boo#1235164)
|
||||
|
||||
- Update version to 5.29.3
|
||||
* Enable restricted mode load for http protocol client
|
||||
* Correctly implement QUIC sniffer when handling multiple initial packets
|
||||
* Fix unreleased cache buffer in QUIC sniffing
|
||||
* A temporary testing fix for the buffer corruption issue
|
||||
* QUIC Sniffer Restructure
|
||||
|
||||
- Update version to 5.22.0
|
||||
* Add packetEncoding for Hysteria
|
||||
* Add ECH Client Support
|
||||
* Add support for parsing some shadowsocks links
|
||||
* Add Mekya Transport
|
||||
* Fix bugs
|
||||
</description>
|
||||
<package>shadowsocks-v2ray-plugin</package>
|
||||
<package>v2ray-core</package>
|
||||
</patchinfo>
|
||||
90
patchinfo.20251127153254678434.93181000773252/_patchinfo
Normal file
90
patchinfo.20251127153254678434.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,90 @@
|
||||
<patchinfo incident="packagehub-39">
|
||||
<packager>os-autoinst-obs-workflow</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for openQA, os-autoinst, openQA-devel-container</summary>
|
||||
<description>This update for openQA, os-autoinst, openQA-devel-container fixes the following issues:
|
||||
|
||||
Changes in openQA:
|
||||
|
||||
- Update to version 5.1763743683.1da97aa2:
|
||||
* Optimize Job Group dropdown database query
|
||||
* Split dependency handling out of create_from_settings
|
||||
* Give jobs with high MAX_JOB_TIME a priority malus
|
||||
* Make the number of builds per group on the front page configurable
|
||||
* docs: Feature auto-generated deepwiki less prominently
|
||||
* apparmor: Additional perms for tests in osado to run
|
||||
|
||||
- Update to version 5.1763153079.b36ac754:
|
||||
* Skip a build if there are no jobs
|
||||
* Remove unused variable
|
||||
|
||||
- Update to version 5.1762879267.52145e9a:
|
||||
* Avoid installing unwanted package versions
|
||||
* Fix check in git_clone for dirty git dir
|
||||
* Prevent `t/24-worker-webui-connection.t` from running into timeout
|
||||
* Be explicit about certain aspects of archiving in the documentation
|
||||
* Fix sporadic failures in `t/ui/10-tests_overview.t`
|
||||
* Adapt os-autoinst-scripts reference after rename
|
||||
* Properly conclude scheduling if there are no jobs
|
||||
|
||||
- Update to version 5.1762193001.2f6e71ca:
|
||||
* Potentially improve stability of `t/ui/16-tests_job_next_previous.t`
|
||||
* Avoid failing check in `t/16-utils-runcmd.t`
|
||||
* README: Add deepwiki badge
|
||||
* Dependency cron 2025-10-27
|
||||
* Retry image optimizations
|
||||
|
||||
Changes in os-autoinst:
|
||||
|
||||
- Update to version 5.1763561851.03e049d:
|
||||
* Avoid `Can't exec "ffmpeg"` if ffmpeg isn't present
|
||||
* Fix syntax errors in nft due to multiple interfaces in $ethernet
|
||||
* README: Feature auto-generated deepwiki less prominently
|
||||
* Install NetworkManager-ovs in os-autoinst-setup-multi-machine
|
||||
* Add disconnect_usb (qemu only, for now)
|
||||
|
||||
- Update to version 5.1763048144.30f43a0:
|
||||
* Configure ftables in os-autoinst-setup-multi-machine
|
||||
* Makefile: Fix reruns on incomplete build dir generations
|
||||
* Propagate C++ exceptions to Perl in image write function
|
||||
* Add support NICPCIADDR variable to QEMU backend
|
||||
* Remove test which causes unhandled output
|
||||
* Improve includes in tinycv library
|
||||
* Handle OpenCV exceptions when writing an image
|
||||
* Avoid ignoring errors silently when writing images
|
||||
* Avoid saving test results referring to non-existent screenshots
|
||||
|
||||
- Update to version 5.1762250353.5150272:
|
||||
* Makefile: Fix reruns on incomplete build dir generations
|
||||
* Propagate C++ exceptions to Perl in image write function
|
||||
* Add support NICPCIADDR variable to QEMU backend
|
||||
* Remove test which causes unhandled output
|
||||
* Allow array keys like `ISSUES[]` as introduced in openQA commit a53b19b
|
||||
* Improve includes in tinycv library
|
||||
|
||||
- Update to version 5.1761723693.2b88807:
|
||||
* Propagate C++ exceptions to Perl in image write function
|
||||
* Add support NICPCIADDR variable to QEMU backend
|
||||
* Remove test which causes unhandled output
|
||||
* Allow array keys like `ISSUES[]` as introduced in openQA commit a53b19b
|
||||
* Improve includes in tinycv library
|
||||
* Handle OpenCV exceptions when writing an image
|
||||
* Avoid ignoring errors silently when writing images
|
||||
|
||||
Changes in openQA-devel-container:
|
||||
|
||||
- Update to version 5.1763743683.1da97aa28:
|
||||
* Update to latest openQA version
|
||||
</description>
|
||||
<package>openQA</package>
|
||||
<package>openQA:openQA-devel-test</package>
|
||||
<package>openQA:openQA-test</package>
|
||||
<package>openQA:openQA-worker-test</package>
|
||||
<package>openQA:openQA-client-test</package>
|
||||
<package>os-autoinst</package>
|
||||
<package>os-autoinst:os-autoinst-test</package>
|
||||
<package>os-autoinst:os-autoinst-devel-test</package>
|
||||
<package>os-autoinst:os-autoinst-openvswitch-test</package>
|
||||
<package>openQA-devel-container</package>
|
||||
</patchinfo>
|
||||
15
patchinfo.20251201094854511762.93181000773252/_patchinfo
Normal file
15
patchinfo.20251201094854511762.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,15 @@
|
||||
<patchinfo incident="packagehub-41">
|
||||
<issue tracker="bnc" id="1253608">VUL-0: CVE-2025-47913: act: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request</issue>
|
||||
<issue tracker="cve" id="2025-47913">cve#2025-47913 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-47913</issue>
|
||||
<packager>elimat</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for act</summary>
|
||||
<description>This update for act fixes the following issues:
|
||||
|
||||
- CVE-2025-47913: Prevent panic in embedded golang.org/x/crypto/ssh/agent client when
|
||||
receiving unexpected message types for key listing or signing requests (boo#1253608)
|
||||
</description>
|
||||
<package>act</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
56
patchinfo.20251201095419906173.93181000773252/_patchinfo
Normal file
56
patchinfo.20251201095419906173.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,56 @@
|
||||
<patchinfo incident="packagehub-42">
|
||||
<packager>os-autoinst-obs-workflow</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for openQA, os-autoinst, openQA-devel-container</summary>
|
||||
<description>This update for openQA, os-autoinst, openQA-devel-container fixes the following issues:
|
||||
|
||||
Changes in openQA:
|
||||
|
||||
- Update to version 5.1764349525.ffb59486:
|
||||
* Also use TIMEOUT_SCALE for priority malus calculation
|
||||
* docs: Fix wrapping and typo
|
||||
* Document multi machine ovs flow setup and IPv6 usage
|
||||
* Avoid computing time constraint for scheduled product cleanup in Perl
|
||||
* rpm: Move `…-enqueue-needle-ref-cleanup` to other `…-enqueue-…` scripts
|
||||
* Add task to limit scheduled products similar to audit events
|
||||
* Extract generic parts from audit event cleanup task into generic task
|
||||
* parser: ktap: Show full output by default if no line was parsed
|
||||
* Ignore npm scripts also via `.npmrc` to make bare npm calls more secure
|
||||
* Avoid repeating `MAIN_SETTINGS` in various places
|
||||
* Fix possibly excessive memory use when computer test result overview
|
||||
* Fix typo in `_prepare_complex_query_search_args`
|
||||
* Fix indentation in `overview.html.ep`
|
||||
* Prevent logging AMQP credentials in debug output
|
||||
* Make restart_openqa_job emit proper event payload
|
||||
* Enable gru tasks to emit AMQP messages
|
||||
* Remove explicit loading AMQP plugin in Gru plugin
|
||||
* Emit restart events when job restarted automatically
|
||||
* Add debug message about priority malus
|
||||
* Fix ordering of job groups after 2ad929ceca43d
|
||||
|
||||
Changes in os-autoinst:
|
||||
|
||||
- Update to version 5.1764330105.c5cfd48:
|
||||
* Add port forwarding example for NICTYPE_USER_OPTIONS
|
||||
* Fix regression from abcaa66b by disabling virtio-keyboard by default
|
||||
* Add IPv6 support for multi machine tests
|
||||
* distribution: Add "disable_key_repeat"
|
||||
* Use 'virtio-keyboard' by default to allow fixing key repetition errors
|
||||
|
||||
Changes in openQA-devel-container:
|
||||
|
||||
- Update to version 5.1764349525.ffb594867:
|
||||
</description>
|
||||
<package>openQA</package>
|
||||
<package>openQA:openQA-devel-test</package>
|
||||
<package>openQA:openQA-test</package>
|
||||
<package>openQA:openQA-worker-test</package>
|
||||
<package>openQA:openQA-client-test</package>
|
||||
<package>os-autoinst</package>
|
||||
<package>os-autoinst:os-autoinst-test</package>
|
||||
<package>os-autoinst:os-autoinst-devel-test</package>
|
||||
<package>os-autoinst:os-autoinst-openvswitch-test</package>
|
||||
<package>openQA-devel-container</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
43
patchinfo.20251203090122170457.187004354831441/_patchinfo
Normal file
43
patchinfo.20251203090122170457.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,43 @@
|
||||
<patchinfo incident="packagehub-43">
|
||||
<issue tracker="bnc" id="1254429">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13632">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13636">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13720">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13721">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13637">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13639">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13640">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13635">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13633">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13638">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13630">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13634">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13631">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<packager>AndreasStieger</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for chromium</summary>
|
||||
<description>This update for chromium fixes the following issues:
|
||||
|
||||
Changes in chromium:
|
||||
|
||||
Chromium 143.0.7499.40 (boo#1254429):
|
||||
|
||||
* CVE-2025-13630: Type Confusion in V8
|
||||
* CVE-2025-13631: Inappropriate implementation in Google Updater
|
||||
* CVE-2025-13632: Inappropriate implementation in DevTools
|
||||
* CVE-2025-13633: Use after free in Digital Credentials
|
||||
* CVE-2025-13634: Inappropriate implementation in Downloads
|
||||
* CVE-2025-13720: Bad cast in Loader
|
||||
* CVE-2025-13721: Race in v8
|
||||
* CVE-2025-13635: Inappropriate implementation in Downloads
|
||||
* CVE-2025-13636: Inappropriate implementation in Split View
|
||||
* CVE-2025-13637: Inappropriate implementation in Downloads
|
||||
* CVE-2025-13638: Use after free in Media Stream
|
||||
* CVE-2025-13639: Inappropriate implementation in WebRTC
|
||||
* CVE-2025-13640: Inappropriate implementation in Passwords
|
||||
|
||||
</description>
|
||||
<package>chromium</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
43
patchinfo.20251203090149653113.187004354831441/_patchinfo
Normal file
43
patchinfo.20251203090149653113.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,43 @@
|
||||
<patchinfo incident="packagehub-44">
|
||||
<packager>michals</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for virtme</summary>
|
||||
<description>This update for virtme fixes the following issues:
|
||||
|
||||
Changes in virtme:
|
||||
|
||||
Update to 1.39:
|
||||
|
||||
* The most noticeable change in this release is the new Model Context
|
||||
Protocol (MCP) server. This feature lets you connect with AI
|
||||
assistants such as Claude, Cursor, etc., and use natural human
|
||||
language to automate kernel development tasks.
|
||||
In this way, AI agents can automatically configure kernels, apply
|
||||
patches from lore.kernel.org, and run commands within recompiled
|
||||
kernels. You can even have the AI agent perform bug bisection for
|
||||
you and run specific commands/scripts inside each recompiled
|
||||
version to determine whether the kernel is good or bad.
|
||||
* An additional feature is vCPU pinning (using the --pin CPU_LIST option),
|
||||
which enables binding virtual CPUs to particular physical host CPUs.
|
||||
This ensures more consistent performance testing within the vng guest
|
||||
environment.
|
||||
* The release also adds support for memoryless NUMA nodes,
|
||||
enablingusers to specify size=0 with the --numa argument to create
|
||||
NUMA nodes without memory. This capability can be useful for simulating
|
||||
heterogeneous architectures, where devices like GPUs are represented
|
||||
as memoryless NUMA nodes to model their CPU locality relationships.
|
||||
* Last, but not least, there's a new --shell BINARY option which lets
|
||||
users choose a different shell to use within the vng session, rather
|
||||
than using their system's default shell and a new --empty-password
|
||||
option that creates empty passwords in the vng guest, instead of
|
||||
blocking login for other users, enabling easier debugging and SSH
|
||||
access during testing.
|
||||
* Updated Python versions in CI (dropped EOL 3.8 and 3.9)
|
||||
* Various bug fixes in virtme-init
|
||||
* Enhanced documentation and README updates
|
||||
* Improved error handling and validation
|
||||
</description>
|
||||
<package>virtme</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
14
patchinfo.20251203090209179395.187004354831441/_patchinfo
Normal file
14
patchinfo.20251203090209179395.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,14 @@
|
||||
<patchinfo incident="packagehub-45">
|
||||
<packager>michals</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for gitea-tea</summary>
|
||||
<description>This update for gitea-tea fixes the following issues:
|
||||
|
||||
Changes in gitea-tea:
|
||||
|
||||
- Do not make config file group-readable.
|
||||
</description>
|
||||
<package>gitea-tea</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
106
patchinfo.20251203090227587250.187004354831441/_patchinfo
Normal file
106
patchinfo.20251203090227587250.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,106 @@
|
||||
<patchinfo incident="packagehub-46">
|
||||
<issue tracker="bnc" id="1253506">VUL-0: CVE-2025-47913: TRACKERBUG: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or</issue>
|
||||
<issue tracker="cve" id="2025-47913">VUL-0: CVE-2025-47913: TRACKERBUG: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or</issue>
|
||||
<issue tracker="bnc" id="1251463">VUL-0: CVE-2025-47911: git-bug: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<issue tracker="bnc" id="1254084">VUL-0: CVE-2025-47914: git-bug: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read</issue>
|
||||
<issue tracker="cve" id="2025-58190"/>
|
||||
<issue tracker="cve" id="2025-22869">VUL-0: CVE-2025-22869: TRACKERBUG: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh</issue>
|
||||
<issue tracker="bnc" id="1234565">VUL-0: CVE-2024-45337: git-bug: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto</issue>
|
||||
<issue tracker="cve" id="2025-47914">VUL-0: CVE-2025-47914: TRACKERBUG: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read</issue>
|
||||
<issue tracker="bnc" id="1251664">VUL-0: CVE-2025-58190: git-bug: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input</issue>
|
||||
<issue tracker="bnc" id="1239494">VUL-0: CVE-2025-22869: git-bug: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh</issue>
|
||||
<issue tracker="cve" id="2024-45337">VUL-0: CVE-2024-45337: TRACKERBUG: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto</issue>
|
||||
<issue tracker="cve" id="2025-47911">VUL-0: CVE-2025-47911: TRACKERBUG: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<issue tracker="cve" id="2025-58181">VUL-0: CVE-2025-58181: TRACKERBUG: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption</issue>
|
||||
<issue tracker="bnc" id="1253930">VUL-0: CVE-2025-58181: git-bug: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption</issue>
|
||||
<packager>mcepl</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for git-bug</summary>
|
||||
<description>This update for git-bug fixes the following issues:
|
||||
|
||||
Changes in git-bug:
|
||||
|
||||
- Revendor to include fixed version of depending libraries:
|
||||
- GO-2025-4116 (CVE-2025-47913, bsc#1253506) upgrade
|
||||
golang.org/x/crypto to v0.43.0
|
||||
- GO-2025-3900 (GHSA-2464-8j7c-4cjm) upgrade
|
||||
github.com/go-viper/mapstructure/v2 to v2.4.0
|
||||
- GO-2025-3787 (GHSA-fv92-fjc5-jj9h) included in the previous
|
||||
- GO-2025-3754 (GHSA-2x5j-vhc8-9cwm) upgrade
|
||||
github.com/cloudflare/circl to v1.6.1
|
||||
- GO-2025-4134 (CVE-2025-58181, bsc#1253930) upgrade
|
||||
golang.org/x/crypto/ssh to v0.45.0
|
||||
- GO-2025-4135 (CVE-2025-47914, bsc#1254084) upgrade
|
||||
golang.org/x/crypto/ssh/agent to v0.45.0
|
||||
|
||||
- Revendor to include golang.org/x/net/html v 0.45.0 to prevent
|
||||
possible DoS by various algorithms with quadratic complexity
|
||||
when parsing HTML documents (bsc#1251463, CVE-2025-47911 and
|
||||
bsc#1251664, CVE-2025-58190).
|
||||
|
||||
Update to version 0.10.1:
|
||||
|
||||
- cli: ignore missing sections when removing configuration (ddb22a2f)
|
||||
|
||||
Update to version 0.10.0:
|
||||
|
||||
- bridge: correct command used to create a new bridge (9942337b)
|
||||
- web: simplify header navigation (7e95b169)
|
||||
- webui: remark upgrade + gfm + syntax highlighting (6ee47b96)
|
||||
- BREAKING CHANGE: dev-infra: remove gokart (89b880bd)
|
||||
|
||||
Update to version 0.10.0:
|
||||
|
||||
- bridge: correct command used to create a new bridge (9942337b)
|
||||
- web: simplify header navigation (7e95b169)
|
||||
- web: remark upgrade + gfm + syntax highlighting (6ee47b96)
|
||||
|
||||
Update to version 0.9.0:
|
||||
|
||||
- completion: remove errata from string literal (aa102c91)
|
||||
- tui: improve readability of the help bar (23be684a)
|
||||
|
||||
Update to version 0.8.1+git.1746484874.96c7a111:
|
||||
|
||||
* docs: update install, contrib, and usage documentation (#1222)
|
||||
* fix: resolve the remote URI using url.*.insteadOf (#1394)
|
||||
* build(deps): bump the go_modules group across 1 directory with 3 updates (#1376)
|
||||
* chore: gofmt simplify gitlab/export_test.go (#1392)
|
||||
* fix: checkout repo before setting up go environment (#1390)
|
||||
* feat: bump to go v1.24.2 (#1389)
|
||||
* chore: update golang.org/x/net (#1379)
|
||||
* fix: use -0700 when formatting time (#1388)
|
||||
* fix: use correct url for gitlab PATs (#1384)
|
||||
* refactor: remove depdendency on pnpm for auto-label action (#1383)
|
||||
* feat: add action: auto-label (#1380)
|
||||
* feat: remove lifecycle/frozen (#1377)
|
||||
* build(deps): bump the npm_and_yarn group across 1 directory with 12 updates (#1378)
|
||||
* feat: support new exclusion label: lifecycle/pinned (#1375)
|
||||
* fix: refactor how gitlab title changes are detected (#1370)
|
||||
* revert: "Create Dependabot config file" (#1374)
|
||||
* refactor: rename //:git-bug.go to //:main.go (#1373)
|
||||
* build(deps): bump github.com/vektah/gqlparser/v2 from 2.5.16 to 2.5.25 (#1361)
|
||||
* fix: set GitLastTag to an empty string when git-describe errors (#1355)
|
||||
* chore: update go-git to v5@masterupdate_mods (#1284)
|
||||
* refactor: Directly swap two variables to optimize code (#1272)
|
||||
* Update README.md Matrix link to new room (#1275)
|
||||
|
||||
- Update to version 0.8.0+git.1742269202.0ab94c9:
|
||||
* deps(crypto): bump golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for CVE-2024-45337) (#1312)
|
||||
|
||||
- Update golang.org/x/crypto/ssh to v0.35.0 (bsc#1239494,
|
||||
CVE-2025-22869).
|
||||
|
||||
- Add missing Requires to completion subpackages.
|
||||
|
||||
Update to version 0.8.0+git.1733745604.d499b6e:
|
||||
|
||||
* fix typos in docs (#1266)
|
||||
* build(deps): bump github.com/go-git/go-billy/v5 from 5.5.0 to 5.6.0 (#1289)
|
||||
|
||||
- bump golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for CVE-2024-45337, bsc#1234565).
|
||||
</description>
|
||||
<package>git-bug</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
23
patchinfo.20251203090353000871.187004354831441/_patchinfo
Normal file
23
patchinfo.20251203090353000871.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,23 @@
|
||||
<patchinfo incident="packagehub-47">
|
||||
<packager>regularhunter</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for weechat</summary>
|
||||
<description>This update for weechat fixes the following issues:
|
||||
|
||||
Changes in weechat:
|
||||
|
||||
Update to 4.7.2:
|
||||
|
||||
Fixed:
|
||||
|
||||
* api: fix file descriptor leak in hook_url when a timeout occurs
|
||||
or if the hook is removed during the transfer (#2284)
|
||||
* irc: fix colors in messages 367 (ban mask), 728 (quiet mask) and
|
||||
MODE (#2286)
|
||||
* irc: fix reset of color when multiple modes are set with
|
||||
command /mode
|
||||
</description>
|
||||
<package>weechat</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
15
patchinfo.20251203090415508822.187004354831441/_patchinfo
Normal file
15
patchinfo.20251203090415508822.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,15 @@
|
||||
<patchinfo incident="packagehub-48">
|
||||
<packager>rrahl0</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for gnome-browser-connector</summary>
|
||||
<description>This update for gnome-browser-connector fixes the following issues:
|
||||
|
||||
Changes in gnome-browser-connector:
|
||||
|
||||
- add unzip as a requires, otherwise the extensions can't get
|
||||
extracted
|
||||
</description>
|
||||
<package>gnome-browser-connector</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
Submodule rmt-server deleted from 4c6de7905a
Submodule shadowsocks-v2ray-plugin updated: afc77cc246...bd1c15af81
Submodule v2ray-core updated: 41d60a58bb...8335900c7d
2
virtme
2
virtme
Submodule virtme updated: 547b3766fe...b4dd61c394
2
weechat
2
weechat
Submodule weechat updated: d04e3da8e5...850136ea31
Reference in New Issue
Block a user