Synch with factory #2

Manually merged
anag_factory merged 14 commits from mgorse/gimp:leap-16.0 into leap-16.0 2026-01-16 16:55:31 +01:00
Contributor

CVE fixes

CVE fixes
mgorse added 8 commits 2025-11-14 23:04:13 +01:00
OBS-URL: https://build.opensuse.org/package/show/graphics/gimp?expand=0&rev=93
OBS-URL: https://build.opensuse.org/request/show/1300479
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/gimp?expand=0&rev=155
FF files. (CVE-2025-10924, bsc#1250499)

OBS-URL: https://build.opensuse.org/package/show/graphics/gimp?expand=0&rev=94
1, Add gimp-CVE-2025-10925.patch: Fix GIMP ILBM file parsing stack-based buffer overflow remote code execution vulnerability. (CVE-2025-10925, ZDI-25-914, ZDI-CAN-27793, bsc#1250501); 2, Add gimp-CVE-2025-10922.patch: Fix GIMP DCM file parsing heap-based buffer overflow remote code execution vulnerability. (CVE-2025-10922, ZDI-25-911, ZDI-CAN-27863, bsc#1250497); 3, Add gimp-CVE-2025-10920.patch: Prevent overflow attack by checking if output >= max, not just output > max. (CVE-2025-10920, ZDI-25-909, ZDI-CAN-27684, bsc#1250495)

OBS-URL: https://build.opensuse.org/request/show/1307522
OBS-URL: https://build.opensuse.org/package/show/graphics/gimp?expand=0&rev=95
OBS-URL: https://build.opensuse.org/request/show/1307201
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/gimp?expand=0&rev=156
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1309048
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/gimp?expand=0&rev=157
OBS-URL: https://build.opensuse.org/package/show/graphics/gimp?expand=0&rev=96
- Update to 3.0.6

OBS-URL: https://build.opensuse.org/request/show/1309404
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/gimp?expand=0&rev=158
autogits_workflow_pr_bot requested review from legaldb 2025-11-14 23:04:42 +01:00
autogits_workflow_pr_bot requested review from maintenance-release-review 2025-11-14 23:04:42 +01:00
autogits_workflow_pr_bot requested review from opensuse-review 2025-11-14 23:04:43 +01:00
First-time contributor

Review by maintenance-release-review represents a group of reviewers: abergmann, amattiazzo, bfilho, cmatos, crazybyte, emanuelecappello, gsonnu, maintenance-robot, mauriziogalli, mbozicevic, mimi_vx, mschnitzer, msmeissn, pluskalm, rfrohl, slemke .

Do not use standard review interface to review on behalf of the group.
To accept the review on behalf of the group, create the following comment: @maintenance-release-review: approve.
To request changes on behalf of the group, create the following comment: @maintenance-release-review: decline followed with lines justifying the decision.
Future edits of the comments are ignored, a new comment is required to change the review state.

Review by maintenance-release-review represents a group of reviewers: abergmann, amattiazzo, bfilho, cmatos, crazybyte, emanuelecappello, gsonnu, maintenance-robot, mauriziogalli, mbozicevic, mimi_vx, mschnitzer, msmeissn, pluskalm, rfrohl, slemke . Do **not** use standard review interface to review on behalf of the group. To accept the review on behalf of the group, create the following comment: `@maintenance-release-review: approve`. To request changes on behalf of the group, create the following comment: `@maintenance-release-review: decline` followed with lines justifying the decision. Future edits of the comments are ignored, a new comment is required to change the review state.

Review by opensuse-review represents a group of reviewers: alarrosa, anag, atartamo, bigironman, darix, dimstar, dmach, eroca, jdsn, jengelh, mcalabkova, mstrigl, nkrapp, oertel, RBrownSUSE, simotek, smithfarm .

Do not use standard review interface to review on behalf of the group.
To accept the review on behalf of the group, create the following comment: @opensuse-review: approve.
To request changes on behalf of the group, create the following comment: @opensuse-review: decline followed with lines justifying the decision.
Future edits of the comments are ignored, a new comment is required to change the review state.

Review by opensuse-review represents a group of reviewers: alarrosa, anag, atartamo, bigironman, darix, dimstar, dmach, eroca, jdsn, jengelh, mcalabkova, mstrigl, nkrapp, oertel, RBrownSUSE, simotek, smithfarm . Do **not** use standard review interface to review on behalf of the group. To accept the review on behalf of the group, create the following comment: `@opensuse-review: approve`. To request changes on behalf of the group, create the following comment: `@opensuse-review: decline` followed with lines justifying the decision. Future edits of the comments are ignored, a new comment is required to change the review state.
Member

Legal reviewed as acceptable:

Accepted because previously reviewed under the same license (470261)
Legal reviewed as [acceptable](https://legaldb.suse.de/reviews/details/489403): ``` Accepted because previously reviewed under the same license (470261) ```
2.1 KiB
legaldb approved these changes 2025-11-14 23:20:12 +01:00
Dismissed
First-time contributor

fwiw does not build on slfo 1.2, gtk3 too old.

fwiw does not build on slfo 1.2, gtk3 too old.
Author
Contributor

Oh, sorry--I just assumed that the update would be safe. It shouldn't really require 3.24.51; I'll update the factory package so that it builds on SLFO and adjust the PR.

Oh, sorry--I just assumed that the update would be safe. It shouldn't really require 3.24.51; I'll update the factory package so that it builds on SLFO and adjust the PR.
mgorse changed title from Synch with factory to WIP: Synch with factory 2025-11-17 16:24:08 +01:00
First-time contributor

ping .. any update here ?

ping .. any update here ?
Author
Contributor

Thanks for the reminder. The factory version should build now, since the gtk3 requirement has been relaxed. But I see that Xiaoguang has a pr open that just adds a patch, so it would conflict with this one. I'll talk with him tonight and decide what to do.

Thanks for the reminder. The factory version should build now, since the gtk3 requirement has been relaxed. But I see that Xiaoguang has a pr open that just adds a patch, so it would conflict with this one. I'll talk with him tonight and decide what to do.
mgorse added 6 commits 2026-01-13 03:40:54 +01:00
mgorse dismissed legaldb's review 2026-01-13 03:40:54 +01:00
Reason:

New commits pushed, approval review dismissed automatically according to repository settings

autogits_workflow_pr_bot requested review from legaldb 2026-01-13 03:41:02 +01:00
First-time contributor

Review by maintenance-release-review represents a group of reviewers: abergmann, amattiazzo, bfilho, cmatos, crazybyte, emanuelecappello, gsonnu, maintenance-robot, mauriziogalli, mbozicevic, mimi_vx, mschnitzer, msmeissn, pluskalm, rfrohl, slemke .

Do not use standard review interface to review on behalf of the group.
To accept the review on behalf of the group, create the following comment: @maintenance-release-review: approve.
To request changes on behalf of the group, create the following comment: @maintenance-release-review: decline followed with lines justifying the decision.
Future edits of the comments are ignored, a new comment is required to change the review state.

Review by maintenance-release-review represents a group of reviewers: abergmann, amattiazzo, bfilho, cmatos, crazybyte, emanuelecappello, gsonnu, maintenance-robot, mauriziogalli, mbozicevic, mimi_vx, mschnitzer, msmeissn, pluskalm, rfrohl, slemke . Do **not** use standard review interface to review on behalf of the group. To accept the review on behalf of the group, create the following comment: `@maintenance-release-review: approve`. To request changes on behalf of the group, create the following comment: `@maintenance-release-review: decline` followed with lines justifying the decision. Future edits of the comments are ignored, a new comment is required to change the review state.
mgorse changed title from WIP: Synch with factory to Synch with factory 2026-01-13 03:42:31 +01:00
Author
Contributor

Okay, I pinged Xiaoguang on slack, and he doesn't object to updating to the factory version, so I've updated my PRs.

Okay, I pinged Xiaoguang on slack, and he doesn't object to updating to the factory version, so I've updated my PRs.

Review by opensuse-review represents a group of reviewers: alarrosa, anag, atartamo, bigironman, darix, dimstar, dmach, eroca, jdsn, jengelh, mcalabkova, mstrigl, nkrapp, oertel, RBrownSUSE, simotek, smithfarm .

Do not use standard review interface to review on behalf of the group.
To accept the review on behalf of the group, create the following comment: @opensuse-review: approve.
To request changes on behalf of the group, create the following comment: @opensuse-review: decline followed with lines justifying the decision.
Future edits of the comments are ignored, a new comment is required to change the review state.

Review by opensuse-review represents a group of reviewers: alarrosa, anag, atartamo, bigironman, darix, dimstar, dmach, eroca, jdsn, jengelh, mcalabkova, mstrigl, nkrapp, oertel, RBrownSUSE, simotek, smithfarm . Do **not** use standard review interface to review on behalf of the group. To accept the review on behalf of the group, create the following comment: `@opensuse-review: approve`. To request changes on behalf of the group, create the following comment: `@opensuse-review: decline` followed with lines justifying the decision. Future edits of the comments are ignored, a new comment is required to change the review state.
Member

Legal reviewed as acceptable:

Accepted because of no significant difference (496445)
Legal reviewed as [acceptable](https://legaldb.suse.de/reviews/details/497350): ``` Accepted because of no significant difference (496445) ```
2.3 KiB
legaldb approved these changes 2026-01-13 04:00:27 +01:00
First-time contributor

@opensuse-review : approve

LGTM

@opensuse-review : approve LGTM
First-time contributor

merge ok

merge ok
opensuse-review approved these changes 2026-01-13 17:41:05 +01:00
opensuse-review left a comment
Member

oertel approved a review on behalf of opensuse-review

oertel approved a review on behalf of opensuse-review
First-time contributor
@maintenance-release-review: approve
maintenance-release-review approved these changes 2026-01-16 16:33:15 +01:00
First-time contributor

rfrohl approved a review on behalf of maintenance-release-review

rfrohl approved a review on behalf of maintenance-release-review
anag_factory manually merged commit fa630de895 into leap-16.0 2026-01-16 16:55:31 +01:00
Sign in to join this conversation.