Commit Graph

  • d4bc099dd3 Fix CVE-2025-58181, bsc#1253904 slfo-1.2 vlefebvre 2026-02-04 17:37:07 +01:00
  • 8424502df6 Fix CVE-2025-58181, bsc#1253904 slfo-main vlefebvre 2026-02-04 17:37:07 +01:00
  • cab94f9484 daemon.json: add --selinux-enabled to default config Aleksa Sarai 2025-10-29 18:28:00 +11:00
  • cffcf5c8a1 docker: update to 28.5.1 Aleksa Sarai 2025-10-22 15:40:57 +11:00
  • aad2c78a7e Accepting request 1320422 from Virtualization:containers factory Ana Guerrero 2025-11-28 15:50:49 +00:00
  • bf00f331e9 Accepting request 1320420 from home:cyphar:docker Aleksa Sarai 2025-11-28 08:20:05 +00:00
  • d3e4c59936 Accepting request 1314276 from Virtualization:containers Ana Guerrero 2025-10-29 20:04:16 +00:00
  • d56192ab10 daemon.json: add --selinux-enabled to default config Aleksa Sarai 2025-10-29 18:28:00 +11:00
  • 12fd86a2d0 Accepting request 1314273 from home:cyphar:docker Aleksa Sarai 2025-10-29 07:18:59 +00:00
  • 4c9bf25f0c docker: update to 28.5.1 Aleksa Sarai 2025-10-22 15:40:57 +11:00
  • c5859e69dc Accepting request 1310597 from Virtualization:containers Dominique Leuenberger 2025-10-11 20:48:31 +00:00
  • b52fc778f0 Accepting request 1309833 from home:cyphar:docker Aleksa Sarai 2025-10-10 14:04:31 +00:00
  • 1b8a58b06f Accepting request 1308807 from Virtualization:containers Dominique Leuenberger 2025-10-04 16:50:38 +00:00
  • 90f08e4cc6 Accepting request 1308812 from home:cyphar:docker Aleksa Sarai 2025-10-03 07:59:22 +00:00
  • 38fda79cc6 Accepting request 1308806 from home:cyphar:docker Aleksa Sarai 2025-10-03 07:51:54 +00:00
  • 3a09a978f0 Accepting request 1308443 from Virtualization:containers Ana Guerrero 2025-10-02 17:18:56 +00:00
  • 9495c47e86 Accepting request 1307756 from home:dimstar:Factory Aleksa Sarai 2025-10-01 16:10:28 +00:00
  • 082d79235d Accepting request 1307636 from Virtualization:containers Ana Guerrero 2025-09-30 15:34:26 +00:00
  • fe09deec84 Accepting request 1307634 from home:cyphar:docker Aleksa Sarai 2025-09-29 05:43:51 +00:00
  • 6eda0d7e41 Accepting request 1305058 from Virtualization:containers Ana Guerrero 2025-09-16 16:18:50 +00:00
  • dcfaed394f Accepting request 1305056 from home:cyphar:docker Aleksa Sarai 2025-09-16 03:06:10 +00:00
  • 55fb67e584 Accepting request 1302771 from Virtualization:containers Ana Guerrero 2025-09-05 19:42:22 +00:00
  • ef3c1ad420 Accepting request 1302770 from home:cyphar:docker Aleksa Sarai 2025-09-04 15:40:43 +00:00
  • 92b7ecdb31 Accepting request 1302695 from home:cyphar:docker Aleksa Sarai 2025-09-04 15:30:45 +00:00
  • 8214eaf0d2 Accepting request 1302148 from Virtualization:containers Ana Guerrero 2025-09-01 15:16:51 +00:00
  • d9f0fe29f2 Accepting request 1302147 from home:cyphar:docker Aleksa Sarai 2025-09-01 06:21:40 +00:00
  • 31e7c5fe4f Accepting request 1302133 from home:cyphar:docker Aleksa Sarai 2025-09-01 06:00:17 +00:00
  • eeada403cb Accepting request 1297919 from Virtualization:containers Dominique Leuenberger 2025-08-06 16:41:23 +00:00
  • 1ff6936e55 Accepting request 1296345 from Virtualization:containers Dominique Leuenberger 2025-07-30 09:42:08 +00:00
  • e18cb9c41f Accepting request 1296528 from home:cyphar:docker Aleksa Sarai 2025-07-30 09:36:22 +00:00
  • 4a5475e14c Accepting request 1296343 from home:cyphar:docker Aleksa Sarai 2025-07-29 14:52:57 +00:00
  • f5e379332d Accepting request 1295197 from Virtualization:containers Dominique Leuenberger 2025-07-24 16:34:40 +00:00
  • 45e055bc74 Accepting request 1295196 from home:cyphar:docker Aleksa Sarai 2025-07-23 04:33:16 +00:00
  • 3177dadb1d Accepting request 1294744 from Virtualization:containers Ana Guerrero 2025-07-21 18:00:26 +00:00
  • 12e7e222a3 Accepting request 1294744 from Virtualization:containers Ana Guerrero 2025-07-21 18:00:26 +00:00
  • a9817d2f90 Add bsc#1246556 reference. Aleksa Sarai 2025-07-21 06:09:47 +00:00
  • 46a688f4bc Accepting request 1294743 from home:cyphar:docker Aleksa Sarai 2025-07-21 06:09:47 +00:00
  • 323e2d4ca9 Accepting request 1293990 from Virtualization:containers Ana Guerrero 2025-07-18 13:57:38 +00:00
  • ae6e7586c3 Accepting request 1293990 from Virtualization:containers Ana Guerrero 2025-07-18 13:57:38 +00:00
  • 487c67f1de - Update to Go 1.24 for builds, to match upstream. Aleksa Sarai 2025-07-17 04:34:00 +00:00
  • 2c6df7a6a2 Accepting request 1293989 from home:cyphar:docker Aleksa Sarai 2025-07-17 04:34:00 +00:00
  • 406a71b522 Accepting request 1293103 from Virtualization:containers Ana Guerrero 2025-07-15 14:42:02 +00:00
  • 23f69f8e21 Accepting request 1293103 from Virtualization:containers Ana Guerrero 2025-07-15 14:42:02 +00:00
  • ddbb0cf9b0 - Update to Docker 28.3.2-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2832> Dirk Mueller 2025-07-14 10:23:10 +00:00
  • 3faa576164 Accepting request 1291560 from home:cyphar:docker Dirk Mueller 2025-07-14 10:23:10 +00:00
  • d7c9b3e5f2 Accepting request 1290059 from Virtualization:containers Ana Guerrero 2025-07-06 14:59:38 +00:00
  • 8cd6e4c033 Accepting request 1290059 from Virtualization:containers Ana Guerrero 2025-07-06 14:59:38 +00:00
  • 8beeee3eda - Update to Docker 28.3.1-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2831> Aleksa Sarai 2025-07-03 02:34:03 +00:00
  • 507530fa54 Accepting request 1290058 from home:cyphar:docker Aleksa Sarai 2025-07-03 02:34:03 +00:00
  • 4f26a3a4f8 Accepting request 1288579 from Virtualization:containers Ana Guerrero 2025-06-26 12:05:40 +00:00
  • 9860da1f77 Accepting request 1288579 from Virtualization:containers Ana Guerrero 2025-06-26 12:05:40 +00:00
  • 7944c3c06a - Update to Docker 28.3.0-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2830> - Rebase patches: * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch Aleksa Sarai 2025-06-25 15:46:10 +00:00
  • 2b3fce4ad6 Accepting request 1288577 from home:cyphar:docker Aleksa Sarai 2025-06-25 15:46:10 +00:00
  • 02b514011a Accepting request 1287937 from Virtualization:containers Ana Guerrero 2025-06-24 18:46:07 +00:00
  • 0c3afe9bcd Accepting request 1287937 from Virtualization:containers Ana Guerrero 2025-06-24 18:46:07 +00:00
  • e65290c603 Fix SUSEConnect patch build. Aleksa Sarai 2025-06-23 13:07:50 +00:00
  • 1cbf22ed24 Accepting request 1287936 from home:cyphar:docker Aleksa Sarai 2025-06-23 13:07:50 +00:00
  • 4f0ef3de34 [ This update is a no-op, only needed to work around unfortunate automated packaging script behaviour on SLES. ] Aleksa Sarai 2025-06-23 12:56:51 +00:00
  • bd87ff5b8b Accepting request 1287934 from home:cyphar:docker Aleksa Sarai 2025-06-23 12:56:51 +00:00
  • ed61589e0d Accepting request 1283419 from Virtualization:containers Ana Guerrero 2025-06-10 06:57:46 +00:00
  • 92ea9832f7 Accepting request 1283419 from Virtualization:containers Ana Guerrero 2025-06-10 06:57:46 +00:00
  • cc421e65c3 fix pkg/errors import Aleksa Sarai 2025-06-05 16:36:19 +00:00
  • 9b075b3cfb Accepting request 1283418 from home:cyphar:docker Aleksa Sarai 2025-06-05 16:36:19 +00:00
  • e827a6b7ca Improve patchset changes. Aleksa Sarai 2025-06-05 16:34:25 +00:00
  • 6a7742a591 Accepting request 1283414 from home:cyphar:docker Aleksa Sarai 2025-06-05 16:34:25 +00:00
  • 1f58d49808 - Do not try to inject SUSEConnect secrets when in Rootless Docker mode, as Docker does not have permission to access the host zypper credentials in this mode (and unprivileged users cannot disable the feature using /etc/docker/suse-secrets-enable.) bsc#1240150 Aleksa Sarai 2025-06-05 16:19:52 +00:00
  • 74aa876e7f Accepting request 1283412 from home:cyphar:docker Aleksa Sarai 2025-06-05 16:19:52 +00:00
  • cb1fadaa4b - Always clear SUSEConnect suse_* secrets when starting containers regardless of whether the daemon was built with SUSEConnect support. Not doing this causes containers from SUSEConnect-enabled daemons to fail to start when running with SUSEConnect-disabled (i.e. upstream) daemons. Aleksa Sarai 2025-06-04 06:14:23 +00:00
  • 2c75c396ba Accepting request 1282502 from home:cyphar:docker Aleksa Sarai 2025-06-04 06:14:23 +00:00
  • 69630be04c Accepting request 1281542 from Virtualization:containers Ana Guerrero 2025-06-02 19:59:08 +00:00
  • 646f517b6a Accepting request 1281542 from Virtualization:containers Ana Guerrero 2025-06-02 19:59:08 +00:00
  • 37241ca5cc - Update to Docker 28.2.2-ce. See upstream changelog online at <https://github.com/moby/moby/releases/tag/v28.2.2> - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch Aleksa Sarai 2025-05-30 17:59:48 +00:00
  • c48f9ef5ad Accepting request 1281540 from home:cyphar:docker Aleksa Sarai 2025-05-30 17:59:48 +00:00
  • 3f2382a8b2 - Update to Docker 28.2.1-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2820> bsc#1243833 - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch - Update to docker-buildx v0.24.0. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.24.0> Aleksa Sarai 2025-05-30 09:46:29 +00:00
  • 1d9af5c3dd Accepting request 1281342 from home:cyphar:docker Aleksa Sarai 2025-05-30 09:46:29 +00:00
  • 8371f55e1e Accepting request 1273868 from Virtualization:containers Dominique Leuenberger 2025-05-02 12:56:14 +00:00
  • 2b1f1d4d7a Accepting request 1273868 from Virtualization:containers Dominique Leuenberger 2025-05-02 12:56:14 +00:00
  • ba29e28bc2 - Update to Docker 28.1.1-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2811> bsc#1242114 Includes upstream fixes: - CVE-2025-22872 bsc#1241830 - Remove long-outdated build handling for deprecated and unsupported devicemapper and AUFS storage drivers. AUFS was removed in v24, and devicemapper was removed in v25. <https://docs.docker.com/engine/deprecated/#aufs-storage-driver> - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch - Remove upstreamed patches: - 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch - 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch - cli-0001-docs-include-required-tools-in-source-tree.patch - Update to docker-buildx v0.23.0. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.23.0> Aleksa Sarai 2025-05-01 17:17:53 +00:00
  • 3d62bf805d Accepting request 1273867 from home:cyphar:docker Aleksa Sarai 2025-05-01 17:17:53 +00:00
  • d1bd3c357c Accepting request 1268264 from Virtualization:containers Ana Guerrero 2025-04-11 14:45:32 +00:00
  • a45689df88 Accepting request 1268264 from Virtualization:containers Ana Guerrero 2025-04-11 14:45:32 +00:00
  • 212e67e0d3 - Update to docker-buildx v0.22.0. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.22.0> * Includes fixes for CVE-2025-0495. bsc#1239765 - Disable transparent SUSEConnect support for SLE-16. PED-12534 When this patchset was first added in 2013 (and rewritten over the years), there was no upstream way to easily provide SLE customers with a way to build container images based on SLE using the host subscription. However, with docker-buildx you can now define secrets for builds (this is not entirely transparent, but we can easily document this new requirement for SLE-16). Users should use RUN --mount=type=secret,id=SCCcredentials zypper -n ... in their Dockerfiles, and docker buildx build --secret id=SCCcredentials,src=/etc/zypp/credentials.d/SCCcredentials,type=file . when doing their builds. - Now that the only blocker for docker-buildx support was removed for SLE-16, enable docker-buildx for SLE-16 as well. PED-8905 Aleksa Sarai 2025-04-10 03:37:01 +00:00
  • 3b9cf36d33 Accepting request 1268262 from home:cyphar:docker Aleksa Sarai 2025-04-10 03:37:01 +00:00
  • cffd8cbd08 - Don't use the new container-selinux conditional requires on SLE-12, as the RPM version there doesn't support it. Arguably the change itself is a bit suspect but we can fix that later. bsc#1237367 Aleksa Sarai 2025-03-26 02:43:19 +00:00
  • 3629cc6207 Accepting request 1256098 from home:cyphar:docker Aleksa Sarai 2025-03-26 02:43:19 +00:00
  • 836cda6985 - Add backport for golang.org/x/oauth2 CVE-2025-22868 fix. bsc#1239185 + 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch - Add backport for golang.org/x/crypto CVE-2025-22869 fix. bsc#1239322 + 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch - Refresh patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch - Add backport for golang.org/x/oauth2 CVE-2025-22868 fix. bsc#1239185 + 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch - Add backport for golang.org/x/crypto CVE-2025-22869 fix. bsc#1239322 + 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch - Refresh patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch Aleksa Sarai 2025-03-25 04:21:54 +00:00
  • d12ec55a21 Accepting request 1255776 from home:cyphar:docker Aleksa Sarai 2025-03-25 04:21:54 +00:00
  • 2d61de33db Accepting request 1254953 from Virtualization:containers Ana Guerrero 2025-03-21 19:21:51 +00:00
  • 3efb193537 Accepting request 1254953 from Virtualization:containers Ana Guerrero 2025-03-21 19:21:51 +00:00
  • 2ca7ac0f0f - Make container-selinux requirement conditional on selinux-policy (bsc#1237367) Dan Čermák 2025-03-21 09:06:19 +00:00
  • 92ee03f64e Accepting request 1254783 from home:favogt:branches:Virtualization:containers Dan Čermák 2025-03-21 09:06:19 +00:00
  • efef872286 Accepting request 1246830 from Virtualization:containers Ana Guerrero 2025-02-20 15:27:07 +00:00
  • dacb82e3d7 Accepting request 1246830 from Virtualization:containers Ana Guerrero 2025-02-20 15:27:07 +00:00
  • f02cd51b7d Accepting request 1246829 from home:cyphar:docker Aleksa Sarai 2025-02-19 04:52:58 +00:00
  • 0998c57831 Accepting request 1246829 from home:cyphar:docker Aleksa Sarai 2025-02-19 04:52:58 +00:00
  • 93f33fbbcb Accepting request 1231895 from Virtualization:containers Ana Guerrero 2024-12-18 19:09:12 +00:00
  • 6f1e1c3bfa Accepting request 1231895 from Virtualization:containers Ana Guerrero 2024-12-18 19:09:12 +00:00
  • 22827cbc1b - Update to Docker 27.4.1-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/27/#2741> - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch * cli-0001-docs-include-required-tools-in-source-tree.patch Aleksa Sarai 2024-12-18 13:03:50 +00:00
  • 2e6f25dd36 Accepting request 1231894 from home:cyphar:docker Aleksa Sarai 2024-12-18 13:03:50 +00:00
  • d69d01a8db Add bsc#1234089 CVE-2024-29018 reference. Aleksa Sarai 2024-12-18 06:26:28 +00:00