Files
request-tracker/request-tracker-rpmlintrc

46 lines
3.1 KiB
Plaintext
Raw Permalink Normal View History

# make testdeps is pre configure as it just tests needed dependencies
addFilter("make-check-outside-check-section.*make testdeps")
# use an own user:group for RT tasks
addFilter("non-standard-uid /var/run/request-tracker rt");
- update to 4.4.4: Security Updates + One of RT's dependencies, the Perl module Email::Address, has a denial of service vulnerability which could induce a denial of service of RT itself. We recommend updating to Email::Address version 1.912 or later. The Email::Address vulnerabilities are assigned CVE-2015-7686 and CVE-2015-12558. CVE-2015-7686 was addressed in RT with a previous update. Email::Address version 1.912 addresses both of these CVEs with updates directly in the source module. + One of RT's dependencies, the Perl module Email::Address::List, relies on and operates similarly to Email::Address and therefore also has potential denial of service vulnerabilities. These vulnerabilities are assigned CVE-2018-18898. We recommend administrators install Email::Address::List version 0.06 or later. + An optional RT dependency, HTML::Gumbo, incorrectly escaped HTML in some cases. Since RT relies on this module to escape HTML content, it's possible this issue could allow malicious HTML to be displayed in RT. For RT's using this optional module, we recommend administrators install HTML::Gumbo version 0.18 or later. * The version of jQuery used in RT 4.2 and 4.4 has a Cross-site Scripting (XSS) vulnerability when using cross-domain Ajax requests. This vulnerability is assigned CVE-2015-9251. RT does not use this jQuery feature so it is not directly vulnerable. jQuery version 1.12 no longer receives official updates, however a fix was posted with recommendations for applications to patch locally, so RT will follow this recommendation and ship with a patched version. EU General Data Protection Regulation (GDPR) Several new features were added to support GDPR compliance and are summarized here. OBS-URL: https://build.opensuse.org/package/show/devel:languages:perl/request-tracker?expand=0&rev=61
2019-03-14 13:50:49 +00:00
addFilter("non-standard-uid /var/cache/request-tracker.* rt");
addFilter("non-standard-uid /var/log/request-tracker rt");
- update to 4.4.4: Security Updates + One of RT's dependencies, the Perl module Email::Address, has a denial of service vulnerability which could induce a denial of service of RT itself. We recommend updating to Email::Address version 1.912 or later. The Email::Address vulnerabilities are assigned CVE-2015-7686 and CVE-2015-12558. CVE-2015-7686 was addressed in RT with a previous update. Email::Address version 1.912 addresses both of these CVEs with updates directly in the source module. + One of RT's dependencies, the Perl module Email::Address::List, relies on and operates similarly to Email::Address and therefore also has potential denial of service vulnerabilities. These vulnerabilities are assigned CVE-2018-18898. We recommend administrators install Email::Address::List version 0.06 or later. + An optional RT dependency, HTML::Gumbo, incorrectly escaped HTML in some cases. Since RT relies on this module to escape HTML content, it's possible this issue could allow malicious HTML to be displayed in RT. For RT's using this optional module, we recommend administrators install HTML::Gumbo version 0.18 or later. * The version of jQuery used in RT 4.2 and 4.4 has a Cross-site Scripting (XSS) vulnerability when using cross-domain Ajax requests. This vulnerability is assigned CVE-2015-9251. RT does not use this jQuery feature so it is not directly vulnerable. jQuery version 1.12 no longer receives official updates, however a fix was posted with recommendations for applications to patch locally, so RT will follow this recommendation and ship with a patched version. EU General Data Protection Regulation (GDPR) Several new features were added to support GDPR compliance and are summarized here. OBS-URL: https://build.opensuse.org/package/show/devel:languages:perl/request-tracker?expand=0&rev=61
2019-03-14 13:50:49 +00:00
addFilter("non-standard-uid /var/lib/request-tracker rt");
addFilter("non-standard-gid /var/lib/request-tracker rt");
# RT::Shredder:ScripCondition is currently part of RT itself -
# wait for Upstream to do the split
addFilter("perl5-naming-policy-not-applied.*/usr/lib/perl.*/RT/Shredder/ScripCondition.pm");
# Duplicate files - we ignore them for now
addFilter("files-duplicate.*/usr/sbin/rt-server.*/usr/sbin/standalone_httpd:/usr/sbin/rt-server.fcgi");
addFilter("files-duplicate.*/usr/share/doc/packages/request-tracker/README.*/usr/share/request-tracker/doc/README");
- update to 4.0.4: This release contains a number of bugfixes and small improvements since the 4.0.2 release; a few of the more notable ones include: + Due to a change in RT 3.8.9, which also affected RT 4.0.0 and higher, TransactionBatch scrips were run twice; this has now been fixed. + A new toggle has been added to expand all quote folding in a ticket's transaction history. + New "On Forward", "On Forward Transaction" and "On Forward Ticket" conditions have been added. + Ticket searches no longer forget which saved search they were loaded from when being updated. + A new "make jsmin" target has been added to aid in downloading, compiling, and installing jsmin. + Improved threading for automatically generated emails concerning a ticket. + Improved detection of Outlook-style message fowarding headers. + No longer error when a user has supplied a non-existant RT style; instead, fall back to the default. This is particularly relevant for users coming RT 3.8 with the 3.6 stylesheet applied, which no longer exists in 4.0. + Improved handling of files named "0", and Unicode filenames, in file uploads. + Tickets can no longer be linked to deleted tickets. + Restore missing menus on simple search result pages. + Fix support for perl 5.12 and later by removing a deprecated use of "defined %hash". - install rcrequest-tracker symlink - fix FSF address in init script - ignore the init-script-without-%restart_on_update-postun warning from rpmlint: the init script just creates missing directories OBS-URL: https://build.opensuse.org/package/show/devel:languages:perl/request-tracker?expand=0&rev=3
2011-12-30 10:57:16 +00:00
# the init script just creates missing directories on start, no need to restart the "application"
addFilter("init-script-without-%restart_on_update-postun.*/etc/init.d/request-tracker");
- update to 4.4.4: Security Updates + One of RT's dependencies, the Perl module Email::Address, has a denial of service vulnerability which could induce a denial of service of RT itself. We recommend updating to Email::Address version 1.912 or later. The Email::Address vulnerabilities are assigned CVE-2015-7686 and CVE-2015-12558. CVE-2015-7686 was addressed in RT with a previous update. Email::Address version 1.912 addresses both of these CVEs with updates directly in the source module. + One of RT's dependencies, the Perl module Email::Address::List, relies on and operates similarly to Email::Address and therefore also has potential denial of service vulnerabilities. These vulnerabilities are assigned CVE-2018-18898. We recommend administrators install Email::Address::List version 0.06 or later. + An optional RT dependency, HTML::Gumbo, incorrectly escaped HTML in some cases. Since RT relies on this module to escape HTML content, it's possible this issue could allow malicious HTML to be displayed in RT. For RT's using this optional module, we recommend administrators install HTML::Gumbo version 0.18 or later. * The version of jQuery used in RT 4.2 and 4.4 has a Cross-site Scripting (XSS) vulnerability when using cross-domain Ajax requests. This vulnerability is assigned CVE-2015-9251. RT does not use this jQuery feature so it is not directly vulnerable. jQuery version 1.12 no longer receives official updates, however a fix was posted with recommendations for applications to patch locally, so RT will follow this recommendation and ship with a patched version. EU General Data Protection Regulation (GDPR) Several new features were added to support GDPR compliance and are summarized here. OBS-URL: https://build.opensuse.org/package/show/devel:languages:perl/request-tracker?expand=0&rev=61
2019-03-14 13:50:49 +00:00
# the RT module is the main part of the Request Tracker application - don't split it out into a dedicated perl-RT module for now
addFilter("perl5-naming-policy-not-applied /usr/lib/perl5/vendor_perl/.*/RT");
# no rc-links for timer services
addFilter("suse-missing-rclink.*rt-email-dashboard");
addFilter("suse-missing-rclink.*rt-email-digest-daily");
addFilter("suse-missing-rclink.*rt-email-digest-weekly");
# according to https://en.opensuse.org/openSUSE:Systemd_packaging_guidelines#Packaging_of_the_systemd_timers
# it's enough to handle the timer files and not the service files
addFilter("systemd-service-without-service_add_post.*rt-email-dashboard.service");
addFilter("systemd-service-without-service_add_post.*rt-email-digest-daily.service");
addFilter("systemd-service-without-service_add_post.*rt-email-digest-weekly.service");
addFilter("systemd-service-without-service_add_pre.*rt-email-dashboard.service");
addFilter("systemd-service-without-service_add_pre.*rt-email-digest-daily.service");
addFilter("systemd-service-without-service_add_pre.*rt-email-digest-weekly.service");
addFilter("systemd-service-without-service_del_postun.*rt-email-dashboard.service");
addFilter("systemd-service-without-service_del_postun.*rt-email-digest-daily.service");
addFilter("systemd-service-without-service_del_postun.*rt-email-digest-weekly.service");
addFilter("systemd-service-without-service_del_preun.*rt-email-dashboard.service");
addFilter("systemd-service-without-service_del_preun.*rt-email-digest-daily.service");
addFilter("systemd-service-without-service_del_preun.*rt-email-digest-weekly.service");
# directories for the GnuPG and SMIME keys
addFilter("non-standard-gid.*/var/lib/request-tracker/data rt");
addFilter("non-standard-gid.*/var/lib/request-tracker/data/gpg rt");
addFilter("non-standard-gid.*/var/lib/request-tracker/data/smime rt");
addFilter("non-standard-uid.*/var/lib/request-tracker/data rt");
addFilter("non-standard-uid.*/var/lib/request-tracker/data/gpg rt");
addFilter("non-standard-uid.*/var/lib/request-tracker/data/smime rt");