xmlgraphics-batik/xmlgraphics-batik.changes

330 lines
12 KiB
Plaintext

-------------------------------------------------------------------
Fri Mar 1 19:02:03 UTC 2024 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 1.17
* BATIK-1346: Allow configuration of rhino whitelist
* BATIK-1347: Switch to empty whitelist for rhino (CVE-2022-44730)
* BATIK-1349: Block loading external resource by default
(CVE-2022-44729)
- Upgrade to version 1.16
* Java 8 or later is minimum runtime required
* BATIK-1338: Block loading jar inside svg (CVE-2022-41704,
bsc#1204704)
* BATIK-1345: Restrict what java classes can be run thru rhino
(CVE-2022-42890, bsc#1204709)
- Removed patch:
* xmlgraphics-batik-nosourcetarget.patch
+ not needed since Java 8 compatibility is now the default
-------------------------------------------------------------------
Thu Feb 29 07:18:22 UTC 2024 - Fridrich Strba <fstrba@suse.com>
- Allow building with this spec-file on systems that don't have the
mvn_install_pom macros defined and release version requirement
of javapackages-local
- Require the xmlgraphics-commons, xml-commons-apis a rhino by their
names, since they are on the classpath by their location in the
scripts. Require them in the subpackages that contain the scripts.
- Require javapackages-tools in subpackages that contain scripts
created by jpackage_script macro. The scripts need functions from
javapackages-tools
-------------------------------------------------------------------
Wed Feb 21 10:55:53 UTC 2024 - Gus Kenion <gus.kenion@suse.com>
- Use %patch -P N instead of deprecated %patchN.
-------------------------------------------------------------------
Wed Oct 25 15:07:46 UTC 2023 - Fridrich Strba <fstrba@suse.com>
- Build with source and target levels 8
- Added patch:
* xmlgraphics-batik-nosourcetarget.patch
+ do not hardcode source/target 1.7
-------------------------------------------------------------------
Wed Jun 28 14:27:24 UTC 2023 - Fridrich Strba <fstrba@suse.com>
- Remove the optional dependency on jython
* fixes new build cycles
-------------------------------------------------------------------
Fri Sep 23 07:28:24 UTC 2022 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 1.15
* BATIK-1260: Java 11 module error
* BATIK-1321: Remove Xerces
* BATIK-1299: Batik-all jar has all classes so should not pull
other jars also
* BATIK-1329: Remove xalan
* BATIK-1331, bsc#1203674, CVE-2022-38398: Jar url should be
blocked by DefaultExternalResourceSecurity
* BATIK-1333, bsc#1203673, CVE-2022-38648: Block external resource
before calling fop
* BATIK-1335, bsc#1203672, CVE-2022-40146: Jar url should be
blocked by DefaultScriptSecurity
-------------------------------------------------------------------
Sun Mar 20 07:25:00 UTC 2022 - Fridrich Strba <fstrba@suse.com>
- Build with source/target levels 8
-------------------------------------------------------------------
Tue Feb 2 17:56:50 UTC 2021 - Jan Engelhardt <jengelh@inai.de>
- Set buildshell to bash for "<<<".
-------------------------------------------------------------------
Sun Jan 24 17:54:37 UTC 2021 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 1.14
* Fixes bsc#1182748, CVE-2020-11987
* BATIK-1284: Dont load DTDs in NodePickerPanel
* BATIK-1292: Remove console message "About to transcoder source
of type: ..."
-------------------------------------------------------------------
Tue Jun 16 13:00:51 UTC 2020 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 1.13
* Fixes bsc#1172961, CVE-2019-17566
* BATIK-1276: Allow blocking of external resources
* BATIK-1275: Refactor shared resources.
-------------------------------------------------------------------
Fri Apr 3 09:26:49 UTC 2020 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 1.12
* Java 7 or later is minimum runtime required
* BATIK-1203: ImageTagRegistry forgets to reinitialize cache
* BATIK-1251: Correct policy file in Squiggle
* BATIK-1253: build.sh referenced from build.xml
* BATIK-1257: Rasterizer - insufficient permissions when
transcoding to PDF
* BATIK-1272: Update Xerces to 2.12
* BATIK-1232: Zip release should use mvn jars
* BATIK-1233: Add policy file for batik-rasterizer
* BATIK-1234: Tools cannot be run using java -jar xxx.jar when
built with Maven
* BATIK-1240: Java 11 compile error
* BATIK-1249: Fix Java 11 module error
- Remove the *.script files and generate the scripts using the
%%jpackage_script macro
- Generate an ant build system from the maven poms and use it for
the first phase build
- Removed patches:
* xmlgraphics-batik-manifests.patch
+ The manifests are now generated in the first phase build
* xmlgraphics-batik-policy.patch
+ We override the policy setting by granting all rights to
svgbrowser and to rasterizer
* xmlgraphics-batik-securitymanager.patch
+ Integrated upstream
-------------------------------------------------------------------
Mon Mar 16 13:43:43 UTC 2020 - Fridrich Strba <fstrba@suse.com>
- Modified patch:
* xmlgraphics-batik-manifests.patch
+ Extend the bundle manifest so that it is useful for eclipse
-------------------------------------------------------------------
Sun Jan 20 20:35:14 UTC 2019 - Fridrich Strba <fstrba@suse.com>
- Upgrade to version 1.10
* BATIK-906: Should never use Error to report runtime errors
* BATIK-1123: Missing import of ImportInfo class
* BATIK-1125: Rasterizer fails with base64 embedded png
* BATIK-1140: Show line numbers on exception
* BATIK-1142: Remove e.printStackTrace for BridgeException in
SVGAbstractTranscoder
* BATIK-1157: Wrong value for default JPEG quality in
documentation
* BATIK-1170: Incorrect ColorConvertOp alpha handling breaks
masking
* BATIK-1196: Run batik tests from junit
* BATIK-1197: Make jython and rhino optional
* BATIK-1198: TIFF transcoder looks for invalid class name for its
WriteAdapter
* BATIK-1200: ImagingOpException: Unable to transform src image
* BATIK-1204: Remove hashtable
* BATIK-1212: Show real error on URL failure
* BATIK-1216: Compile error on Java 10
* BATIK-1222: Only call DOMImplementation in deserialization
- Split the css-jar into a separate package
- Install maven pom files.
- Added patches:
* 0001-Fix-imageio-codec-lookup.patch
+ PNG transcoder looks for invalid class name for its
WriteAdapter
* xmlgraphics-batik-nolinksinjavadoc.patch
+ Fix javadoc generation by not loading URL links.
- Modified patch:
* xmlgraphics-batik-manifests.patch
+ Add Bundle-SymbolicName and Bundle-Version manifest entries
+ Add targets for jar files produced by maven build and not
produced by the ant one. Produce them when target jars is
called.
-------------------------------------------------------------------
Wed Nov 7 20:47:58 UTC 2018 - Fridrich Strba <fstrba@suse.com>
- Do not depend on a particular xml-commons-apis provider.
-------------------------------------------------------------------
Wed Jul 11 10:21:58 UTC 2018 - fstrba@suse.com
- Added patch:
* xmlgraphics-batik-securitymanager.patch
+ Fix build with jdk11
+ Replace use of SecurityManager::checkSystemClipboardAccess
by check for AWTPermission("accessClipboard")
- Run fdupes on relevant directories
-------------------------------------------------------------------
Fri May 19 15:45:22 UTC 2017 - tchvatal@suse.com
- Version update to batik 1.9:
* No obvious upstream changelog
- Refresh patch xmlgraphics-batik-manifests.patch
- Refresh patch xmlgraphics-batik-policy.patch
-------------------------------------------------------------------
Fri May 19 11:09:42 UTC 2017 - vsistek@suse.com
- Add BuildRequires: javapackages-local (for maven conversions)
-------------------------------------------------------------------
Mon Mar 20 15:16:57 UTC 2017 - sknorr@suse.com
- Needed as a dependency for FOP 2.1 (FATE#322405)
-------------------------------------------------------------------
Fri Mar 4 14:05:13 UTC 2016 - fvogt@suse.com
- Update to batik-1.8:
batik-src-1.7.zip -> batik-src-1.8.tar.gz
- Update xmlgraphics-batik-manifests.patch
- Refresh xmlgraphics-batik-policy.patch
-------------------------------------------------------------------
Mon Dec 8 13:03:34 UTC 2014 - tchvatal@suse.com
- spec-cleanify
-------------------------------------------------------------------
Fri Dec 5 12:39:52 UTC 2014 - p.drouand@gmail.com
- Use javapackages-tools instead of java-devel
-------------------------------------------------------------------
Fri Jun 27 11:17:48 UTC 2014 - tchvatal@suse.com
- Specify targets to build on sle11.
-------------------------------------------------------------------
Thu Sep 12 19:08:45 UTC 2013 - tchvatal@suse.com
- Kill javadoc to remove unresolvables.
-------------------------------------------------------------------
Mon Sep 9 11:06:29 UTC 2013 - tchvatal@suse.com
- Move from jpackage-utils to javapackage-tools
-------------------------------------------------------------------
Fri Apr 5 09:00:58 UTC 2013 - idonmez@suse.com
- Add Source URL, see https://en.opensuse.org/SourceUrls
-------------------------------------------------------------------
Wed Nov 3 08:56:40 UTC 2010 - mvyskocil@suse.cz
- merge with xmlgraphics-batik-1.7-5.jpp5.src.rpm
-------------------------------------------------------------------
Tue Mar 30 11:20:58 UTC 2010 - mvyskocil@suse.cz
- enable batik-all.jar to ensure swingx (-> netbeans) build
-------------------------------------------------------------------
Tue Nov 3 19:09:07 UTC 2009 - coolo@novell.com
- updated patches to apply with fuzz=0
-------------------------------------------------------------------
Mon Aug 31 15:08:12 CEST 2009 - ro@suse.de
- fix archive compression
-------------------------------------------------------------------
Wed May 15 08:33:00 CET 2008 - toms@suse.de
- Fixed errors in build by correction build.xml.patch:
Replaced target="1.5" with target="1.4"
- Cleaned up SPEC file a bit
-------------------------------------------------------------------
Wed Mar 5 12:05:40 CET 2008 - toms@suse.de
- Fixed BuildRequires
-------------------------------------------------------------------
Fri Feb 29 09:20:30 CET 2008 - toms@suse.de
- Removed from samples/tests/spec/fonts/ directory due to license issues:
fontAltGlyph.svg, fontAltGlyph3.svg, fontChoice.svg, fontDecorations.svg,
fontGlyphChoice.svg, fontGlyphsBoth.svg, fontGlyphsChildSVG.svg,
fontGlyphsD.svg, fontKerning.svg, fontStyling.svg and
samples/tests/spec/scripting/textcontent/missing-glpyh.svg
-------------------------------------------------------------------
Tue Jan 29 15:13:23 CET 2008 - toms@suse.de
- Added additional source and created subpackage -javadoc
-------------------------------------------------------------------
Mon Jan 28 08:33:41 CET 2008 - toms@suse.de
- Reorganised installation directory: Installed all jar files under
%{_javadir} and created link from %{_datadir}/%{name}
- Corrected *sh.in files
-------------------------------------------------------------------
Wed Aug 29 14:54:05 CEST 2007 - toms@suse.de
- Removed samples/tests/spec/scripting/textcontent/missing-glpyh.svg
due to license issues
-------------------------------------------------------------------
Tue Aug 21 13:35:07 CEST 2007 - toms@suse.de
- Updated to version 1.7
Removed samples/fonts directory
-------------------------------------------------------------------
Wed May 23 16:42:59 CEST 2007 - toms@suse.de
- Corrected sh files (missing #), improved SPEC file
-------------------------------------------------------------------
Fri Mar 30 14:49:53 CEST 2007 - toms@suse.de
- Removed samples subdirectory
-------------------------------------------------------------------
Fri Mar 30 11:01:57 CEST 2007 - toms@suse.de
- Added unzip to BuildRequires
-------------------------------------------------------------------
Thu Mar 29 16:37:26 CEST 2007 - toms@suse.de
- Corrected *-sh files
-------------------------------------------------------------------
Thu Mar 29 15:38:02 CEST 2007 - toms@suse.de
- First inital version of 1.6