1
0

Compare commits

...

31 Commits

Author SHA256 Message Date
Marcus Meissner
17e4e99ab5 filter out xen bsc#1253226 2025-11-17 16:30:01 +00:00
AutoGits PR Review Bot
d9ad5b0d95 Merging
PR: products/PackageHub!211
2025-11-14 09:57:31 +00:00
52f1c10e67 Update patchinfo incident numbers [skip actions] 2025-11-13 15:20:09 +00:00
AutoGits PR Review Bot
b95f5de289 Merging
PR: products/PackageHub!212
2025-11-13 15:19:32 +00:00
fccc06cc6f Update submodules from pool/chromium#16 and create patchinfo.20251112154630847363.187004354831441/_patchinfo 2025-11-12 16:46:43 +01:00
Markéta Machová
5e88777506 add certbot stack to PackageHub 2025-11-12 11:39:26 +01:00
b3eb0849c8 Update patchinfo incident numbers [skip actions] 2025-11-11 16:48:59 +00:00
AutoGits PR Review Bot
b52f6924a4 Merging
PR: products/PackageHub!210
2025-11-11 16:48:33 +00:00
54b6eca2a4 Update submodules from pool/product-composer#7 and create patchinfo.20251111094408723997.187004354831441/_patchinfo 2025-11-11 10:44:19 +01:00
1d731ee42f Update patchinfo incident numbers [skip actions] 2025-11-10 17:16:28 +00:00
AutoGits PR Review Bot
7862ce5600 Merging
PR: products/PackageHub!207
2025-11-10 17:16:10 +00:00
148e498d69 Update patchinfo incident numbers [skip actions] 2025-11-10 15:41:42 +00:00
AutoGits PR Review Bot
4f2851fe76 Merging
PR: products/PackageHub!193
2025-11-10 15:41:26 +00:00
162506107e Update patchinfo incident numbers [skip actions] 2025-11-10 15:40:56 +00:00
AutoGits PR Review Bot
7863330b11 Merging
PR: products/PackageHub!197
2025-11-10 15:40:39 +00:00
fb0e75d1b4 Update patchinfo incident numbers [skip actions] 2025-11-10 15:40:17 +00:00
AutoGits PR Review Bot
7aa51378b7 Merging
PR: products/PackageHub!195
2025-11-10 15:39:51 +00:00
AutoGits PR Review Bot
8d87e747e8 Merging
PR: products/PackageHub!208
2025-11-07 15:01:00 +00:00
Marcus Meissner
1b0f0f0118 remove product again, we do not need it currently 2025-11-07 10:23:59 +00:00
46d712de4f Update patchinfo incident numbers [skip actions] 2025-11-07 08:49:01 +00:00
AutoGits PR Review Bot
5003a51c3b Merging
PR: products/PackageHub!206
2025-11-07 08:48:34 +00:00
92d66f0b6b Update submodules from pool/chromium#15 and create patchinfo.20251106083153138720.187004354831441/_patchinfo 2025-11-06 09:32:10 +01:00
351a05e702 Update patchinfo.20251025182836794674.93181000773252/_patchinfo
removed  <seperate_build_arch/>
2025-11-05 10:56:13 +01:00
52ba298c89 Update patchinfo.20251027103924170417.187004354831441/_patchinfo
remove sdeperate build arch
2025-11-05 10:53:07 +01:00
dc8c823d25 Update patchinfo.20251104153107003768.187004354831441/_patchinfo
remove seperate buiild arch
2025-11-05 10:52:05 +01:00
c662779915 Update submodules from pool/MozillaThunderbird#6 and create patchinfo.20251104153107003768.187004354831441/_patchinfo 2025-11-04 16:32:07 +01:00
b125d840e4 Merge branch 'leap-16.0' into maintenance-update-1761561563 2025-11-03 15:55:44 +01:00
caf037d873 Merge branch 'leap-16.0' into maintenance-update-1761416916 2025-11-03 15:54:28 +01:00
1f1551b5ed Add new line 2025-11-03 15:45:13 +01:00
7f9822480c Update submodules from pool/micropython#2 and create patchinfo.20251027103924170417.187004354831441/_patchinfo 2025-10-27 11:39:35 +01:00
aa01d6bd01 Update submodules from pool/amarok!1 and create patchinfo.20251025182836794674.93181000773252/_patchinfo 2025-10-25 20:29:27 +02:00
21 changed files with 214 additions and 13 deletions

24
.gitmodules vendored
View File

@@ -26110,3 +26110,27 @@
path = fprintd
url = ../../pool/fprintd
branch = leap-16.0
[submodule "python-acme"]
path = python-acme
url = ../../pool/python-acme
branch = leap-16.0
[submodule "python-certbot"]
path = python-certbot
url = ../../pool/python-certbot
branch = leap-16.0
[submodule "python-certbot-nginx"]
path = python-certbot-nginx
url = ../../pool/python-certbot-nginx
branch = leap-16.0
[submodule "python-ConfigArgParse"]
path = python-ConfigArgParse
url = ../../pool/python-ConfigArgParse
branch = leap-16.0
[submodule "python-josepy"]
path = python-josepy
url = ../../pool/python-josepy
branch = leap-16.0
[submodule "python-pyRFC3339"]
path = python-pyRFC3339
url = ../../pool/python-pyRFC3339
branch = leap-16.0

View File

@@ -271,6 +271,12 @@ packagesets:
- update-test-retracted
- update-test-security
- update-test-trivial
- xen
- xen-devel
- xen-libs
- xen-doc-html
- xen-tools
- xen-tools-domU
- yum-utils
# TODO: unneeded Leap package per architecture

2
amarok

Submodule amarok updated: e1886b2904...2a1b2d88df

View File

@@ -0,0 +1,28 @@
<patchinfo incident="packagehub-18">
<packager>jsulig</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for amarok</summary>
<description>This update for amarok fixes the following issues:
Changes in amarok:
- Update to version 3.3.1
* Enable saving and loading script console items, autocompletion
in script console, and re-enable some more scripting functionality
* Convert the remaining main UI toolbuttons to use icons from theme
* Clear out remnants of the now-discontinued MusicDNS service
* Fix example permission grant command in database settings (kde#386004)
* Fix equalizer gains not updating when selecting some presets (kde#463908)
* Fix continuing playback after timecoded tracks (cue files etc, (kde#270003)
* Fix MusicBrainz search
* Properly start CD playback if Amarok is not already running (kde#503310)
* Also transmit embedded cover art through MPRIS (kde#357620)
* Don't show transcoding dialog after canceling download (kde#275840)
* Load network information earlier to avoid crashes on startup (kde#507497)
* Try to export as-compatible-as-possible playlist files (kde#507329)
* Fix some random crashes during playback
</description>
<package>amarok</package>
</patchinfo>

View File

@@ -1,4 +1,4 @@
<patchinfo>
<patchinfo incident="packagehub-16">
<packager>miska</packager>
<rating>moderate</rating>
<category>recommended</category>
@@ -29,4 +29,4 @@ update to version 3.4.7, see
https://www.knot-dns.cz/2025-06-04-version-347.html
</description>
<package>knot</package>
</patchinfo>
</patchinfo>

View File

@@ -0,0 +1,27 @@
<patchinfo incident="packagehub-17">
<issue tracker="cve" id="2025-59438">VUL-0: CVE-2025-59438: TRACKERBUG: mbedtls: padding oracle attack possible through timing of cipher error reporting</issue>
<packager>dheidler</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for micropython</summary>
<description>This update for micropython fixes the following issues:
Changes in micropython:
- Build with mbedtls-3.6.5 instead of bundled 3.6.2 to fix CVE-2025-59438
Version 1.26.0:
* Added machine.I2CTarget for creating I2C target devices on multiple ports.
* New MCU support: STM32N6xx (800 MHz, ML accel) &amp; ESP32-C2 (WiFi + BLE).
* Major float accuracy boost (~28% → ~98%), constant folding in compiler.
* Optimized native/Viper emitters; reduced heap use for slices.
* Time functions standardized (19702099); new boards across ESP32, SAMD, STM32, Zephyr.
* ESP32: ESP-IDF 5.4.2, flash auto-detect, PCNT class, LAN8670 PHY.
* RP2: compressed errors, better lightsleep, hard IRQ timers.
* Zephyr v4.0.0: PWM, SoftI2C/SPI, BLE runtime services, boot.py/main.py support.
* mpremote adds fs tree, improved df, portable config paths.
* Updated lwIP, LittleFS, libhydrogen, stm32lib; expanded hardware/CI tests.
</description>
<package>micropython</package>
</patchinfo>

View File

@@ -0,0 +1,63 @@
<patchinfo incident="packagehub-15">
<issue tracker="cve" id="2025-11710"/>
<issue tracker="cve" id="2025-11709"/>
<issue tracker="cve" id="2025-11715"/>
<issue tracker="bnc" id="1247774">[SLFO:Main] [SLES16.0] MozillaFirefox fails to build on s390x</issue>
<issue tracker="cve" id="2025-11712"/>
<issue tracker="cve" id="2025-11708"/>
<issue tracker="cve" id="2025-11714"/>
<issue tracker="cve" id="2025-11713"/>
<issue tracker="cve" id="2025-11711"/>
<issue tracker="bnc" id="1251263">VUL-0: MozillaFirefox / MozillaThunderbird: update to 144.0 and 140.4esr</issue>
<packager>MSirringhaus</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for MozillaThunderbird</summary>
<description>This update for MozillaThunderbird fixes the following issues:
Mozilla Thunderbird 140.4:
* changed: Account Hub is now disabled by default for second
email account
* changed: Flatpak runtime has been updated to Freedesktop SDK
24.08
* fixed: Users could not read mail signed with OpenPGP v6 and
PQC keys
* fixed: Image preview in Insert Image dialog failed with CSP
error for web resources
* fixed: Emptying trash on exit did not work with some
providers
* fixed: Thunderbird could crash when applying filters
* fixed: Users were unable to override expired mail server
certificate
* fixed: Opening Website header link in RSS feed incorrectly
re-encoded URL parameters
* fixed: Security fixes
MFSA 2025-85 (bsc#1251263):
* CVE-2025-11708
Use-after-free in MediaTrackGraphImpl::GetInstance()
* CVE-2025-11709
Out of bounds read/write in a privileged process triggered by
WebGL textures
* CVE-2025-11710
Cross-process information leaked due to malicious IPC
messages
* CVE-2025-11711
Some non-writable Object properties could be modified
* CVE-2025-11712
An OBJECT tag type attribute overrode browser behavior on web
resources without a content-type
* CVE-2025-11713
Potential user-assisted code execution in “Copy as cURL”
command
* CVE-2025-11714
Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR
140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
* CVE-2025-11715
Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird
ESR 140.4, Firefox 144 and Thunderbird 144
</description>
<package>MozillaThunderbird</package>
</patchinfo>

View File

@@ -0,0 +1,23 @@
<patchinfo incident="packagehub-19">
<issue tracker="bnc" id="1253089">VUL-0: chromium: release 142.0.7444.134</issue>
<issue tracker="cve" id="2025-12727"/>
<issue tracker="cve" id="2025-12725"/>
<issue tracker="cve" id="2025-12729">VUL-0: chromium: release 142.0.7444.134</issue>
<issue tracker="cve" id="2025-12728"/>
<issue tracker="cve" id="2025-12726"/>
<packager>AndreasStieger</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for chromium</summary>
<description>This update for chromium fixes the following issues:
Chromium 142.0.7444.134 (boo#1253089):
* CVE-2025-12725: Out of bounds write in WebGPU
* CVE-2025-12726: Inappropriate implementation in Views
* CVE-2025-12727: Inappropriate implementation in V8
* CVE-2025-12728: Inappropriate implementation in Omnibox
* CVE-2025-12729: Inappropriate implementation in Omnibox
</description>
<package>chromium</package>
</patchinfo>

View File

@@ -0,0 +1,14 @@
<patchinfo incident="packagehub-20">
<packager>adrianSuSE</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for product-composer</summary>
<description>This update for product-composer fixes the following issues:
Update to version 0.6.17:
- fix multiarch media handling of updateinfo id's
</description>
<package>product-composer</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -0,0 +1,16 @@
<patchinfo incident="packagehub-21">
<issue tracker="bnc" id="1253267">VUL-0: chromium: release 142.0.7444.162</issue>
<issue tracker="cve" id="2025-13042">VUL-0: chromium: release 142.0.7444.162</issue>
<packager>AndreasStieger</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for chromium</summary>
<description>This update for chromium fixes the following issues:
Chromium 142.0.7444.162 (boo#1253267):
* CVE-2025-13042: Inappropriate implementation in V8
</description>
<package>chromium</package>
<seperate_build_arch/>
</patchinfo>

1
python-ConfigArgParse Submodule

Submodule python-ConfigArgParse added at 5c3cff44d9

1
python-acme Submodule

Submodule python-acme added at 27b3328397

1
python-certbot Submodule

Submodule python-certbot added at f9b56088c8

1
python-certbot-nginx Submodule

Submodule python-certbot-nginx added at 64e5a394f6

1
python-josepy Submodule

Submodule python-josepy added at 921f2778a2

1
python-pyRFC3339 Submodule

Submodule python-pyRFC3339 added at d5107ae95b

View File

@@ -1,10 +1,4 @@
{
"ObsProject": "openSUSE:Backports:SLE-16.0",
"StagingProject": "openSUSE:Backports:SLE-16.0:PullRequest",
"QA": [
{
"Name": "Leap",
"Origin": "openSUSE:Leap:16.0:Products"
},
]
}