4 Commits

Author SHA256 Message Date
Alexander Graul
ec1df51782 Add fixes for several security vulnerabilities
- Add minimum_auth_version to enforce security (CVE-2025-62349)
- Backport security fixes for vendored tornado
  * BDSA-2024-3438
  * BDSA-2024-3439
  * BDSA-2024-9026
- Junos module yaml loader fix (CVE-2025-62348)
2025-11-26 11:58:50 +01:00
02bd353512 fix requires 2025-11-13 15:07:24 +01:00
1aa96b2910 Fix chlog 2025-11-12 13:25:46 +01:00
b79fb92f33 Prepare for release 2025-11-12 09:20:44 +01:00

View File

@@ -1,5 +1,5 @@
-------------------------------------------------------------------
Wed Nov 26 10:48:08 UTC 2025 - Alexander Graul <alexander.graul@suse.com>
Wed Nov 26 10:58:23 UTC 2025 - Alexander Graul <alexander.graul@suse.com>
- Add minimum_auth_version to enforce security (CVE-2025-62349)
- Backport security fixes for vendored tornado
@@ -12,12 +12,12 @@ Wed Nov 26 10:48:08 UTC 2025 - Alexander Graul <alexander.graul@suse.com>
* backport-3006.17-security-fixes-739.patch
-------------------------------------------------------------------
Thu Nov 13 14:04:05 UTC 2025 - Marek Czernek <marek.czernek@suse.com>
Thu Nov 13 14:06:48 UTC 2025 - Marek Czernek <marek.czernek@suse.com>
- Require Python dependencies only for used Python version
-------------------------------------------------------------------
Tue Nov 11 16:14:31 UTC 2025 - Marek Czernek <marek.czernek@suse.com>
Tue Nov 11 16:11:17 UTC 2025 - Marek Czernek <marek.czernek@suse.com>
- Fix TLS and x509 modules for OSes with older cryptography module
- Require python-legacy-cgi only for Python > 3.12