1
0

Compare commits

..

89 Commits

Author SHA256 Message Date
AutoGits PR Review Bot
1efd26d095 auto-created for python-Django
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/python-Django!5
2026-02-04 13:30:54 +00:00
AutoGits PR Review Bot
f520bda79f auto-created for python-Django
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/python-Django!5
2026-02-04 11:08:34 +00:00
254469484a Merge pull request '0Backports: disabled some maintenace bits until maintenance mode and add no_product_provides to build options' (#390) from maxlin_factory/PackageHub:disable_maintenance_bits into leap-16.1
Reviewed-on: products/PackageHub#390
Reviewed-by: autogits_obs_staging_bot <autogits_obs_staging_bot@noreply.src.opensuse.org>
2026-02-04 11:05:19 +01:00
8d8f81784b 0Backports: add no_product_provides to build options 2026-02-04 16:18:19 +08:00
74d275a2ca 0Backports: disabled some maintenace bits until maintenance mode 2026-02-04 16:04:11 +08:00
834a5fdfd5 Merge pull request 'Do not rebuild product-composer but use product-composer from SLFO' (#385) from maxlin_factory/PackageHub:removing_dup_slfo_pkgs_20260203_2 into leap-16.1
Reviewed-on: products/PackageHub#385
Reviewed-by: autogits_obs_staging_bot <autogits_obs_staging_bot@noreply.src.opensuse.org>
2026-02-03 15:43:08 +01:00
1f9443a567 Do not rebuild product-composer but use product-composer from SLFO 2026-02-03 19:19:39 +08:00
e569013d41 Merge pull request 'Remove duplicate package which does existing in SLFO' (#384) from maxlin_factory/PackageHub:removing_dup_slfo_pkgs_20260203 into leap-16.1
Reviewed-on: products/PackageHub#384
Reviewed-by: autogits_obs_staging_bot <autogits_obs_staging_bot@noreply.src.opensuse.org>
2026-02-03 10:53:53 +01:00
0cb38f6960 0Backports: add more unneeded 32bit packages to backports_unneeded 2026-02-03 16:12:09 +08:00
906ad5f554 Remove duplicate package which does existing in SLFO 2026-02-03 15:43:17 +08:00
AutoGits PR Review Bot
3cfdd77699 Merging
PR: products/PackageHub!352
2026-01-29 09:48:51 +00:00
AutoGits PR Review Bot
8c1c9552ca Merging
PR: products/PackageHub!349
2026-01-29 09:47:33 +00:00
AutoGits PR Review Bot
dec70c26a8 Merging
PR: products/PackageHub!351
2026-01-29 08:43:03 +00:00
AutoGits PR Review Bot
97eae99a93 Merging
PR: products/PackageHub!346
2026-01-29 08:24:59 +00:00
AutoGits PR Review Bot
109f34d250 Merging
PR: products/PackageHub!331
2026-01-27 09:05:51 +00:00
AutoGits PR Review Bot
fb2c4e14d0 Merging
PR: products/PackageHub!336
2026-01-27 09:04:10 +00:00
13fd694237 Merge pull request 'Remove xen related packages (bsc#1253226)' (#330) from bigironman/PackageHub:leap-16.1 into leap-16.1
Reviewed-on: products/PackageHub#330
Reviewed-by: autogits_obs_staging_bot <autogits_obs_staging_bot@noreply.src.opensuse.org>
Reviewed-by: Yuchen Lin <maxlin_factory@noreply.src.opensuse.org>
2026-01-27 09:50:28 +01:00
AutoGits PR Review Bot
5caf7d046b auto-created for hauler
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/hauler!4
2026-01-26 12:49:53 +00:00
AutoGits PR Review Bot
9fe91808d8 auto-created for wine
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/wine!1
2026-01-25 09:43:14 +00:00
AutoGits PR Review Bot
d1de390de9 Merging
PR: products/PackageHub!295
2026-01-23 11:17:25 +00:00
AutoGits PR Review Bot
e23d4c1af1 Merging
PR: products/PackageHub!298
2026-01-23 11:16:09 +00:00
AutoGits PR Review Bot
16fb939497 Merging
PR: products/PackageHub!315
2026-01-23 11:14:52 +00:00
AutoGits PR Review Bot
af117deaba Merging
PR: products/PackageHub!316
2026-01-23 11:13:07 +00:00
AutoGits PR Review Bot
4f6c2c7a68 Merging
PR: products/PackageHub!325
2026-01-23 11:11:20 +00:00
AutoGits PR Review Bot
e26304b918 Merging
PR: products/PackageHub!328
2026-01-23 11:09:30 +00:00
AutoGits PR Review Bot
0a1949910f Merging
PR: products/PackageHub!276
2026-01-23 11:03:58 +00:00
AutoGits PR Review Bot
f143c02b59 Merging
PR: products/PackageHub!218
2026-01-23 10:21:56 +00:00
AutoGits PR Review Bot
b209e429f4 Merging
PR: products/PackageHub!248
2026-01-23 10:20:58 +00:00
AutoGits PR Review Bot
11c70dfa25 Merging
PR: products/PackageHub!292
2026-01-23 10:20:07 +00:00
AutoGits PR Review Bot
db35e9b0be Merging
PR: products/PackageHub!296
2026-01-23 10:18:20 +00:00
AutoGits PR Review Bot
455b693b03 Merging
PR: products/PackageHub!271
2026-01-23 10:13:58 +00:00
AutoGits PR Review Bot
56a87e3a00 auto-created for sbctl
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/sbctl!2
2026-01-22 08:36:18 +00:00
AutoGits PR Review Bot
a44cd4bb4c auto-created for helmfile
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/helmfile!7
2026-01-21 10:48:43 +00:00
AutoGits PR Review Bot
de6006976c auto-created for chromium
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/chromium!26
2026-01-21 00:38:01 +00:00
AutoGits PR Review Bot
224ab7e8f7 auto-created for gimp
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/gimp!1
2026-01-20 20:34:08 +00:00
AutoGits PR Review Bot
d856252976 auto-created for chromium
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/chromium!26
2026-01-20 14:14:04 +00:00
AutoGits PR Review Bot
0bfdcfa6fd auto-created for minisign
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/minisign!2
2026-01-19 19:32:49 +00:00
AutoGits PR Review Bot
1cdaa904d4 auto-created for hauler
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/hauler!1
2026-01-19 12:51:30 +00:00
AutoGits PR Review Bot
abc8a79783 auto-created for ffmpeg-4
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/ffmpeg-4!3
2026-01-19 03:17:25 +00:00
5667abb95d Remove xen related packages (bsc#1253226) 2026-01-16 16:53:17 +01:00
AutoGits PR Review Bot
17397c4bfb auto-created for go-sendxmpp
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/go-sendxmpp!2
2026-01-16 06:13:05 +00:00
AutoGits PR Review Bot
95fb4e05d2 auto-created for alsa-tools
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/alsa-tools!1
2026-01-15 10:39:18 +00:00
AutoGits PR Review Bot
dbef934cbe auto-created for wicked
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/wicked!2
2026-01-14 16:15:02 +00:00
AutoGits PR Review Bot
a1a456015c auto-created for chromium
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/chromium!26
2026-01-14 11:21:05 +00:00
AutoGits PR Review Bot
e7f6eb5176 auto-created for gimp
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/gimp!1
2026-01-13 02:40:57 +00:00
AutoGits PR Review Bot
04ce2105ab Merging
PR: products/PackageHub!288
2026-01-12 10:08:55 +00:00
AutoGits PR Review Bot
645b8a076b Merging
PR: products/PackageHub!268
2026-01-12 10:05:08 +00:00
AutoGits PR Review Bot
a024d1ea9d Merging
PR: products/PackageHub!269
2026-01-12 10:04:20 +00:00
AutoGits PR Review Bot
06e2767220 Merging
PR: products/PackageHub!270
2026-01-12 10:03:32 +00:00
AutoGits PR Review Bot
e03bbc4b91 auto-created for chromium
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/chromium!23
2026-01-06 20:29:36 +00:00
AutoGits PR Review Bot
e2883b15e7 auto-created for bird3
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/bird3!5
2026-01-05 11:07:13 +00:00
AutoGits PR Review Bot
f7bb084f03 auto-created for matio
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/matio!2
2026-01-01 18:53:37 +00:00
AutoGits PR Review Bot
ec63373895 auto-created for trivy
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/trivy!29
2025-12-29 15:07:34 +00:00
AutoGits PR Review Bot
6c1f37e6f6 auto-created for chromium
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/chromium!23
2025-12-28 08:22:58 +00:00
AutoGits PR Review Bot
8c41fb5882 auto-created for apache2-mod_wsgi
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/apache2-mod_wsgi!1
2025-12-23 10:20:36 +00:00
AutoGits PR Review Bot
657dd22773 auto-created for chromium
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/chromium!23
2025-12-19 22:26:32 +00:00
AutoGits PR Review Bot
ae501ca692 auto-created for chromium
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/chromium!23
2025-12-17 16:52:02 +00:00
Elisei Roca
c78d1d0c0f Add rawtherapee from factory 2025-12-10 17:11:35 +01:00
AutoGits PR Review Bot
a65bd0dd9c Merging
PR: products/PackageHub!252
2025-12-10 09:41:40 +00:00
AutoGits PR Review Bot
8353a5399e Merging
PR: products/PackageHub!254
2025-12-10 09:33:14 +00:00
AutoGits PR Review Bot
3db77b31a7 Merging
PR: products/PackageHub!262
2025-12-10 09:31:38 +00:00
AutoGits PR Review Bot
c8fc0a1e14 Merging
PR: products/PackageHub!231
2025-12-10 09:23:29 +00:00
AutoGits PR Review Bot
04f92b9f4a Merging
PR: products/PackageHub!233
2025-12-10 09:21:36 +00:00
AutoGits PR Review Bot
f473a26ed8 Merging
PR: products/PackageHub!228
2025-12-10 09:01:06 +00:00
AutoGits PR Review Bot
982be17fb4 Merging
PR: products/PackageHub!223
2025-12-10 08:40:36 +00:00
AutoGits PR Review Bot
0e5ce19d7c auto-created for virtme
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/virtme!3
2025-12-10 08:16:15 +00:00
AutoGits PR Review Bot
0adbd7e7c3 auto-created for exim
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/exim!3
2025-12-09 15:48:27 +00:00
AutoGits PR Review Bot
1f51ea99d3 auto-created for icinga-php-thirdparty
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/icinga-php-thirdparty!2
2025-12-08 16:10:25 +00:00
AutoGits PR Review Bot
93c0cfa368 auto-created for icinga-php-library
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/icinga-php-library!2
2025-12-08 16:09:59 +00:00
AutoGits PR Review Bot
8d4727e994 auto-created for icingaweb2
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/icingaweb2!2
2025-12-08 16:08:59 +00:00
AutoGits PR Review Bot
9a38628fc6 auto-created for trivy
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/trivy!26
2025-12-03 10:44:12 +00:00
AutoGits PR Review Bot
c2fe26d1c5 auto-created for trivy
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/trivy!26
2025-12-03 10:43:21 +00:00
AutoGits PR Review Bot
28f8f95561 auto-created for virtme
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/virtme!3
2025-12-02 19:22:59 +00:00
AutoGits PR Review Bot
d266b74103 auto-created for git-bug
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/git-bug!9
2025-12-01 11:52:11 +00:00
AutoGits PR Review Bot
a84202fbe0 auto-created for git-bug
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/git-bug!9
2025-12-01 11:14:10 +00:00
AutoGits PR Review Bot
1a04a936cf auto-created for hauler
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/hauler!1
2025-11-30 22:41:11 +00:00
a15935da4f Merge pull request 'Switch to version 16.1' (#209) from bigironman/PackageHub:leap-16.1 into leap-16.1
Reviewed-on: products/PackageHub#209
Reviewed-by: autogits_obs_staging_bot <autogits_obs_staging_bot@noreply.src.opensuse.org>
2025-11-26 11:37:17 +01:00
AutoGits PR Review Bot
45b5bbd033 auto-created for pnpm
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/pnpm!1
2025-11-25 09:48:16 +00:00
AutoGits PR Review Bot
a66d3eb230 auto-created for gitea-tea
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/gitea-tea!2
2025-11-21 11:21:57 +00:00
AutoGits PR Review Bot
de956160ff auto-created for evolution
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/evolution!1
2025-11-18 11:46:32 +00:00
AutoGits PR Review Bot
7e78a71c08 auto-created for synce4l
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/synce4l!2
2025-11-17 13:53:51 +00:00
AutoGits PR Review Bot
d819af25d8 auto-created for gimp
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/gimp!1
2025-11-14 22:03:13 +00:00
b9312ef3d1 Switch to version 16.1 2025-11-11 09:49:28 +01:00
172d5d28b3 Merge pull request 'Reset every bits in the PacakgeHub 16.1' (#205) from maxlin_factory/PackageHub:161_delete_patchinfo_package into leap-16.1
Reviewed-on: products/PackageHub#205
2025-11-04 09:49:36 +01:00
3499ed9954 Reset workflow configurations 2025-11-04 16:44:02 +08:00
cfd8745f1b Adjust project config for the 16.1 2025-11-04 16:43:49 +08:00
d4d13f2589 Deleted patchinfo packages
These patchinfo packages is mistakenly fork to leap-16.1 branch since
leap-16.0 is on maintnenace mode
2025-11-04 16:41:33 +08:00
aea01eb697 Branching Leap-16.1 2025-10-29 08:10:37 +01:00
ca4d1ccdb2 melange: Fix referenced submodule
last commit was not pointing to an accesable commit
2025-10-28 15:23:37 +01:00
68 changed files with 6632 additions and 33043 deletions

13090
.gitmodules vendored

File diff suppressed because it is too large Load Diff

View File

@@ -1,3 +1,49 @@
-------------------------------------------------------------------
Wed Feb 4 08:02:50 UTC 2026 - Yuchen Lin <mlin+factory@suse.de>
- Backports.productcompose:
+ disabled some settings for maintenance, will re-enabling it once
maintenance mode
+ add no_product_provides to build options
-------------------------------------------------------------------
Tue Feb 3 08:08:54 UTC 2026 - Yuchen Lin <mlin+factory@suse.de>
- Backports.productcompose:
+ add to backports_unneeded, cleanup more unneeded 32bit packages
libluajit-5_1-2-32bit
libmariadb3-32bit
libtss2-esys0-32bit
libtss2-mu0-32bit
libtss2-policy0-32bit
libtss2-rc0-32bit
libtss2-sys1-32bit
libtss2-tcti-cmd0-32bit
libtss2-tcti-device0-32bit
libtss2-tcti-mssim0-32bit
libtss2-tcti-spi-helper0-32bit
libtss2-tcti-swtpm0-32bit
libtss2-tctildr0-32bit
-------------------------------------------------------------------
Fri Jan 16 15:51:12 UTC 2026 - Wolfgang Engel <wolfgang.engel@suse.com>
- Backports.productcompose:
+ add to backports_unneeded, remove xen related packages (bsc#1253226)
xen
xen-devel
xen-libs
xen-doc-html
xen-tools
xen-tools-domU
xen-tools-xendomains-wait-disk
-------------------------------------------------------------------
Tue Nov 11 08:48:51 UTC 2025 - Wolfgang Engel <wolfgang.engel@suse.com>
- Backports.productcompose:
- switch to version 16.1
-------------------------------------------------------------------
Fri Oct 10 07:19:41 UTC 2025 - Wolfgang Engel <wolfgang.engel@suse.com>

View File

@@ -3,19 +3,20 @@ product_compose_schema: 0.2
vendor: openSUSE
name: Backports
version: 16
update: "16.0"
# update: "16.1"
product-type: module
summary: openSUSE Backports
scc:
description: >
Leap ftp tree, also known as POOL.
PackageHub ftp tree, also known as POOL.
Used for GA and maintenance update afterwards.
build_options:
### For maintenance, otherwise only "the best" version of each package is picked:
- take_all_available_versions
# - take_all_available_versions
- hide_flavor_in_product_directory_name
- no_product_provides
### Since the Backports product build is not self-contained in a single repository,
### the installcheck results at build-time are not useful. (As currently implemented,
@@ -33,7 +34,7 @@ repodata: all
# has only an effect during maintenance:
set_updateinfo_from: maintenance@opensuse.org
set_updateinfo_id_prefix: SUSE-PackageHub-16.0-
# set_updateinfo_id_prefix: SUSE-PackageHub-16.1-
flavors:
backports_aarch64:
@@ -173,7 +174,9 @@ packagesets:
- libgusb2-32bit
- libinput10-32bit
- liblirc_driver0-32bit
- libluajit-5_1-2-32bit
- libmanette-0_2-0-32bit
- libmariadb3-32bit
- libpcap1-32bit
- libpcap-devel-32bit
- libpolkit-agent-1-0-32bit
@@ -187,7 +190,18 @@ packagesets:
# - libsybdb5-32bit
- libsystemd0-mini
# - libtdsodbc0-32bit
- libtss2-esys0-32bit
- libtss2-fapi1-32bit
- libtss2-mu0-32bit
- libtss2-policy0-32bit
- libtss2-rc0-32bit
- libtss2-sys1-32bit
- libtss2-tcti-cmd0-32bit
- libtss2-tcti-device0-32bit
- libtss2-tcti-mssim0-32bit
- libtss2-tcti-spi-helper0-32bit
- libtss2-tcti-swtpm0-32bit
- libtss2-tctildr0-32bit
- libudev-mini1
- libunbound-devel-mini
- libusb-1_0-0-32bit
@@ -271,6 +285,13 @@ packagesets:
- update-test-retracted
- update-test-security
- update-test-trivial
- xen
- xen-devel
- xen-libs
- xen-doc-html
- xen-tools
- xen-tools-domU
- xen-tools-xendomains-wait-disk
- yum-utils
# TODO: unneeded Leap package per architecture

1
SDL3

Submodule SDL3 deleted from 7e274255d0

15
_config
View File

@@ -1,7 +1,7 @@
%if 0%{?is_stage_project}
Release: <CI_CNT>.<B_CNT> spec:bp160.999999.<CI_CNT>.<B_CNT>
Release: <CI_CNT>.<B_CNT> spec:bp161.999999.<CI_CNT>.<B_CNT>
%else
Release: <CI_CNT>.<B_CNT> spec:bp160.<CI_CNT>.<B_CNT>
Release: <CI_CNT>.<B_CNT> spec:bp161.<CI_CNT>.<B_CNT>
%endif
# 000productcompose experiment
@@ -129,15 +129,6 @@ Macros:
%ffmpeg_pref ffmpeg-7
:Macros
# BEGIN GIMP STUFF - remove this section when gimp3 is ready
# %if "%_project" == "openSUSE:Backports:SLE-16.0"
# Macros:
# Do not build python plugin in gimp2
# %_without_python_plugin 1
# :Macros
# %endif
# END GIMP STUFF
# openSUSE -> SLE magic BuildRequires can work then
Substitute: desktop-data-openSUSE-extra desktop-data-SLE-extra
Substitute: desktop-data-openSUSE desktop-data-SLE
@@ -168,7 +159,7 @@ Macros:
# Leap specific package list, the same list with excludebuild must add to Backports project
# Most of package should be built in Backports
%if "%_project" == "openSUSE:Backports:SLE-16.0"
%if "%_project" == "openSUSE:Backports:SLE-16.1"
# we build ffado:ffado-mixer for openSUSE, the main one is built in SLFO
BuildFlags: excludebuild:ffado
# build gpgme:qt flavor for qt5 support

View File

@@ -1,3 +1,3 @@
{
"": ["maintenance-release-review"]
"": ["packagehub-review"]
}

2
amarok

Submodule amarok updated: 2a1b2d88df...e1886b2904

2
bird3

Submodule bird3 updated: 8a14f83ff5...b7a81cd647

1
eigen3

Submodule eigen3 deleted from 9d3090997a

2
exim

Submodule exim updated: 9f3f61dcb2...aa2daa7cec

Submodule fprintd deleted from 3d1b159ec5

2
gimp

Submodule gimp updated: aab3634bba...539373922d

Submodule git-bug updated: 22bb247e73...2390ae6cee

2
hauler

Submodule hauler updated: 9084f004c1...69ca5e4eea

Submodule ibus-kkc deleted from 42c900194c

Submodule ibus-skk deleted from 70ee289573

Submodule ibus-unikey deleted from 700ff22649

Submodule jaxb-api deleted from e10ae3f0fc

Submodule libabigail deleted from b36b134271

1
libkkc

Submodule libkkc deleted from 13a5c11a94

1
libskk

Submodule libskk deleted from df54637cb8

2
matio

Submodule matio updated: a301162ce9...cab79b5274

Submodule nghttp3 deleted from ba31af5d60

1
ngtcp2

Submodule ngtcp2 deleted from f5554cdc0e

2
openQA

Submodule openQA updated: d4fcc3820c...04be1d7de7

View File

@@ -1,66 +0,0 @@
<patchinfo incident="packagehub-1">
<issue tracker="bnc" id="1251334">VUL-0: chromium: release 141.0.7390.65</issue>
<issue tracker="cve" id="2025-11213">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-11216">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-11207">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-11211">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-11212">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-11210">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="bnc" id="1250780">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-11208">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-10890">VUL-0: chromium: release 140.0.7339.207</issue>
<issue tracker="cve" id="2025-11206">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-11460">VUL-0: chromium: release 141.0.7390.65</issue>
<issue tracker="cve" id="2025-11219">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="bnc" id="1250472">VUL-0: chromium: release 140.0.7339.207</issue>
<issue tracker="cve" id="2025-11205">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-10891">VUL-0: chromium: release 140.0.7339.207</issue>
<issue tracker="cve" id="2025-11458"/>
<issue tracker="cve" id="2025-11215">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-11209">VUL-0: chromium: release 141.0.7390.54</issue>
<issue tracker="cve" id="2025-10892">VUL-0: chromium: release 140.0.7339.207</issue>
<packager>AndreasStieger</packager>
<rating>critical</rating>
<category>security</category>
<summary>Security update for chromium</summary>
<description>This update for chromium fixes the following issues:
Chromium 141.0.7390.76:
* Do not send URLs as AIM input. This is to resolve a privacy
concern, around passing urls to AI Mode.
Chromium 141.0.7390.65 (boo#1251334):
* CVE-2025-11458: Heap buffer overflow in Sync
* CVE-2025-11460: Use after free in Storage
* CVE-2025-11211: Out of bounds read in WebCodecs
Chromium 141.0.7390.54 (stable released 2025-09-30) (boo#1250780)
* CVE-2025-11205: Heap buffer overflow in WebGPU
* CVE-2025-11206: Heap buffer overflow in Video
* CVE-2025-11207: Side-channel information leakage in Storage
* CVE-2025-11208: Inappropriate implementation in Media
* CVE-2025-11209: Inappropriate implementation in Omnibox
* CVE-2025-11210: Side-channel information leakage in Tab
* CVE-2025-11211: Out of bounds read in Media
* CVE-2025-11212: Inappropriate implementation in Media
* CVE-2025-11213: Inappropriate implementation in Omnibox
* CVE-2025-11215: Off by one error in V8
* CVE-2025-11216: Inappropriate implementation in Storage
* CVE-2025-11219: Use after free in V8
* Various fixes from internal audits, fuzzing and other initiatives
Chromium 141.0.7390.37 (beta released 2025-09-24)
Chromium 140.0.7339.207 (boo#1250472)
* CVE-2025-10890: Side-channel information leakage in V8
* CVE-2025-10891: Integer overflow in V8
* CVE-2025-10892: Integer overflow in V8
</description>
<package>chromium</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,17 +0,0 @@
<patchinfo incident="packagehub-3">
<issue tracker="bnc" id="1252013">VUL-0: CVE-2025-11756: chromium: Use after free in Safe Browsing</issue>
<issue tracker="cve" id="2025-11756"/>
<packager>AndreasStieger</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for chromium</summary>
<description>This update for chromium fixes the following issues:
Chromium 141.0.7390.107:
* CVE-2025-11756: Use after free in Safe Browsing (boo#1252013)
</description>
<package>chromium</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,17 +0,0 @@
<patchinfo incident="packagehub-11">
<issue tracker="bnc" id="1250487">VUL-0: CVE-2025-59682: python-Django,python-Django4: Potential partial directory-traversal via archive.extract()</issue>
<issue tracker="cve" id="2025-59682">VUL-0: CVE-2025-59682: python-Django,python-Django4: Potential partial directory-traversal via archive.extract()</issue>
<issue tracker="cve" id="2025-59681"/>
<issue tracker="bnc" id="1250485">VUL-0: CVE-2025-59681: python-Django,python-Django4: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB</issue>
<packager>mcalabkova</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for python-Django</summary>
<description>This update for python-Django fixes the following issues:
- CVE-2025-59681: Fixed a potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB (boo#1250485)
- CVE-2025-59682: Fixed a potential partial directory-traversal via archive.extract() (boo#1250487)
</description>
<package>python-Django</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,103 +0,0 @@
<patchinfo incident="packagehub-4">
<packager>dheidler</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for opi</summary>
<description>This update for opi fixes the following issues:
- Version 5.8.8
* Fix adding openh264 repo on leap 16.0
This update for opi fixes the following issues:
- Version 5.8.7
* Fix ocenaudio url
* Add LocalSend plugin
* Run all tests in verbose mode
* Print written repo files in verbose mode
* Increase timeouts in test/06_install_non_interactive.py
* Remove DNF references from README.md
This update for opi fixes the following issues:
- Version 5.8.5
* add librewolf plugin (#205)
* Install .NET 9
* Add verbose mode
* Change the order of the process in the github module
* Add rustdesk plugin
This update for opi fixes the following issues:
- Version 5.8.4
* Use arm64 rpm for libation on aarch64
This update for opi fixes the following issues:
- Version 5.8.3
* Install dependencies rpm-build and squashfs at runtime if needed
* Drop DNF support
This update for opi fixes the following issues:
- Version 5.8.2
* Warn about adding staging repos
* Gracefully handle zypper exit code 106 (repos without cache present)
This update for opi fixes the following issues:
- Version 5.8.1
* Fix SyntaxWarning: invalid escape sequence '\s'
This update for opi fixes the following issues:
- Version 5.8.0
* Add mullvad-brower
This update for opi fixes the following issues:
- Version 5.7.0
* Add leap-only plugin to install zellij from github release
* Don't use subprocess.run user kwarg on 15.6
* Fix tests: Use helloworld-opi-tests instead of zfs
* Perform search despite locked rpmdb
* Simplify backend code
This update for opi fixes the following issues:
- Use no macros in url in .spec for packtrack
This update for opi fixes the following issues:
- Version 5.6.0
* Add plugin to install vagrant from hashicorp repo
This update for opi fixes the following issues:
- Version 5.5.0
* Update opi/plugins/collabora.py
* add collabora office desktop
* Omit unsupported cli args on leap in 99_install_opi.py
* Switch to PEP517 install
* Fix 09_install_with_multi_repos_in_single_file_non_interactive.py
* Fix 07_install_multiple.py on tumbleweed
* Fix test suite on tumbleweed
* Update available apps in opi - README.md
This update for opi fixes the following issues:
- Version 5.4.0
* Show key ID when importing or deleting package signing keys
* Add option to install google-chrome-canary
This update for opi fixes the following issues:
- Version 5.3.0
* Fix tests for new zypper version
* fix doblue slash in packman repo url
* Add Plugin to install Libation
</description>
<package>opi</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,17 +0,0 @@
<patchinfo incident="packagehub-5">
<packager>michals</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for virtme</summary>
<description>This update for virtme fixes the following issues:
- Update to 1.38:
* Fix the infamous Stale file handle (ESTALE) errors with virtiofsd
* Fix for systemctl daemon-reload when systemd support is enabled
* Fix for a kernel symlink issue affecting openSUSE/SLE
* README/docs improvements
* Various coding style cleanups
</description>
<package>virtme</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,55 +0,0 @@
<patchinfo incident="packagehub-6">
<issue tracker="bnc" id="1206292">[SELinux] Wine/Proton not working reliably with default SELinux configuration</issue>
<packager>regularhunter</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for lutris</summary>
<description>This update for lutris fixes the following issues:
- Move selinux dependency
- Fix gaming under selinux (bsc#1206292)
- Fix wrong placement of lang_package macro in spec file
- Update to 0.5.19:
* Fix Proton integration bugs so Proton-fixes are applied
* Do not offer DXVK, VKD3D, D3D Extras or DDXVK-NVAPI on Proton versions;
Proton will handle these.
* The "Enable Esync" and "Enable Fsync" settings are now passed on to Proton
* DXVK's integrated D8VK will be enabled in Proton
* Emulator BIOS file location (used by libretro) may be set in Preferences
* Obtain the release year from GOG and Itch.io.
* MAME Machine setting uses a searchable entry for its enourmous list
* Support for importing Commodore 64 ROMs
- Add BuildRequires apparmor-abstractions, apparmor-rpm-macros for
Leap, fix for build error: directories not owned by a package:
/etc/apparmor.d
- update to 0.5.18:
* Lutris downloads the latest GE-Proton build for Wine if any Wine version is installed
* Use dark theme by default
* Display cover-art rather than banners by default
* Add 'Uncategorized' view to sidebar
* Preference options that do not work on Wayland will be hidden when on Wayland
* Game searches can now use fancy tags like 'installed:yes' or 'source:gog', with explanatory tool-tip
* A new filter button on the search box can build many of these fancy tags for you
* Runner searches can use 'installed:yes' as well, but no other fancy searches or anything
* Updated the Flathub and Amazon source to new APIs, restoring integration
* Itch.io source integration will load a collection named 'Lutris' if present
* GOG and Itch.io sources can now offer Linux and Windows installers for the same game
* Added support for the 'foot' terminal
* Support for DirectX 8 in DXVK v2.4
* Support for Ayatana Application Indicators
* Additional options for Ruffle runner
* Updated download links for the Atari800 and MicroM8 runners
* No longer re-download cached installation files even when some are missing
* Lutris log is included in the 'System' tab of the Preferences window
* Improved error reporting, with the Lutris log included in the error details
* Add AppArmor profile for Ubuntu versions &gt;= 23.10
* Add Duckstation runner
</description>
<package>lutris</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,16 +0,0 @@
<patchinfo incident="packagehub-8">
<issue tracker="cve" id="2025-12036">VUL-0: CVE-2025-12036: chromium: Inappropriate implementation in V8</issue>
<issue tracker="bnc" id="1252402">VUL-0: CVE-2025-12036: chromium: Inappropriate implementation in V8</issue>
<packager>AndreasStieger</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for chromium</summary>
<description>This update for chromium fixes the following issues:
Chromium 141.0.7390.122:
* CVE-2025-12036: Inappropriate implementation in V8 (boo#1252402)
</description>
<package>chromium</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,57 +0,0 @@
<patchinfo incident="packagehub-7">
<issue tracker="bnc" id="1248768">[warewulf, REGRESSION] None of the disk/partition/filesystem Options to `wwctl profile set` appear to do anything</issue>
<issue tracker="bnc" id="1227465">[warewulf, kernel] After updating the Kernel in the Container Image 'wwctl container list' still shows old</issue>
<issue tracker="bnc" id="1246082">warewulf4-slurm suggest slurm only</issue>
<issue tracker="bnc" id="1248906">VUL-0: CVE-2025-58058: warewulf4: github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory</issue>
<issue tracker="bnc" id="1227686">[warewulf, kernel] Feature: Allow to determine the Kernel to boot - with none set, take latest</issue>
<issue tracker="cve" id="2025-58058">cve#2025-58058 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-58058</issue>
<packager>mslacken</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for warewulf4</summary>
<description>This update for warewulf4 fixes the following issues:
Changes in warewulf4:
- Update to version 4.6.4:
* v4.6.4 release updates
* Convert disk booleans from wwbool to *bool which allows bools in
disk to be set to false via command line (bsc#1248768)
* Update NetworkManager Overlay
* Disable ipv4 in NetworkManager if no address or route is specified
* fix(wwctl): Create overlay edit tempfile in tmpdir
* Add default for systemd name for warewulf in warewulf.conf
* Atomic overlay file application in wwclient
* Simpler names for overlay methods
* Fix warewulfd api behavior when deleting distribution overlay
- Update to version 4.6.3:
* v4.6.3 release
* IPv6 iPXE support
* Fix a syntax error in the RPM specfile
* Fix a race condition in wwctl overlay edit
* Fixed handling of comma-separated mount options in `fstab` and `ignition` overlays
* Move reexec.Init() to beginning of wwctl
* Add documentation for using tmpfs to distribute across numa nodes
* added warewuld configure option
* Fix wwctl upgrade nodes to handle kernel argument lists (bsc#1227686 bsc#1227465)
* Address copilot review from #1945
* Refactor wwapi tests for proper isolation
* Bugfix: cloning a site overlay when parent dir does not exist
* Clone to a site overlay when adding files in wwapi
* Consolidated createOverlayFile and updateOverlayFile to addOverlayFile
* Support for creating and updating overlay file in wwapi
* Only return overlay files that refer to a path within the overlay
* add overlay file deletion support
* DELETE /api/overlays/{id}?force=true can delete overlays in use
* Restore idempotency of PUT /api/nodes/{id}
* Simplify overlay mtime api and add tests
* add node overlay buildtime
* Improved netplan support
* Rebuild overlays for discovered nodes
* Restrict userdocs from building during pr when not modified
* Update to v4.6.2 GitHub release notes
</description>
<package>warewulf4</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,11 +0,0 @@
<patchinfo incident="packagehub-9">
<packager>dgarcia</packager>
<rating>moderate</rating>
<category>optional</category>
<summary>Optional update for fprintd</summary>
<description>
This update ships fprintd 1.94.4 to openSUSE Leap 16.0 and SLES Package Hub 16.0
</description>
<package>fprintd</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,129 +0,0 @@
<patchinfo incident="packagehub-13">
<packager>os-autoinst-obs-workflow</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for openQA, os-autoinst</summary>
<description>This update for openQA, os-autoinst fixes the following issues:
Changes in openQA:
- Update to version 5.1761296552.ae7c17aa:
* Add tests for file_security_policy
* Pass parameter $is_userfile to log_url
* Remove redirect and serve files as attachments if necessary
* Serve files uploaded by tests via asset domain
* Use direct link to subdomain for the test assets
* Revert "Don't redirect to asset domain via /needles/ID/(image|json) route"
* Revert "Don't redirect screenshots, thumbs and needles to files_domain"
- Update to version 5.1761228068.a3a7f84d:
* Dependency cron 2025-10-23
- Update to version 5.1761037330.ad78558e:
* Avoid needless check for number of clones
* Avoid creation of `git_clone` tasks for jobs with empty `DISTRI`
- Update to version 5.1760515610.a802d1dd:
* Lower the prio of archiving jobs to avoid piling up finalize jobs
* Add signatures in Schema::Result::ApiKeys
- Update to version 5.1760245411.e3aeaaec:
* Dependency cron 2025-10-12
- Update to version 5.1760108577.fd2f2a48:
* Log unavailability due to high load only as warning
* Filter job stats of scheduled products also by arch and build
* Document how to disable image optimizations
* Make image optimization errors stop the job producing an incomplete job
* Improve wording in description about job stats API
* Run `optipng` for real and handle errors if it fails
- Update to version 5.1759912962.689b31ed:
* Avoid failing `obs_rsync_run` jobs when restarting `openqa-gru.service`
- Update to version 5.1759834744.06a7028a:
* parser: ktap: Return earlier if subtest result is SKIP
* parser: ktap: Fallback to subtest index if name is not available
- Update to version 5.1759440640.bb989cab:
* Don't redirect to asset domain via /needles/ID/(image|json) route
- Update to version 5.1759402042.49e912c3:
* Introduce array job settings
* Retry `obs_rsync_update_*` tasks if Gru service terminates
- Update to version 5.1759329378.3b8e8685:
* Reduce the number of required checks for Mergify again
* Ensure a failing cache service is seen as such by the worker/scheduler
- Update to version 5.1759248257.70b23b32:
* Increase number of successful checks in Mergify config again
* Disable Helm Chart CI checks temporarily
* Consider all jobs for cleanup, not just jobs that were executed
* Verify job deletion when dependent job present
- Update to version 5.1759149505.49c40b0b:
* Use always the latest PostgreSQL image in Compose and documentation
* Update the PostgreSQL version in the contributing documentation
* Update PostgreSQL data path in Docker Compose file after updating to v18
* Specify PostgreSQL version in Docker Compose configuration explicitly
* mergify: Allow more time for dependabot update reaction
* Remove version property from docker-compose
* README: Fix openQA badge after switch to UEFI
* build(deps-dev): bump eslint from 9.35.0 to 9.36.0
- Update to version 5.1758910696.7549bb98:
* Replace argument assignment with signatures on ObsRsync/Task
* Enable automatic dependabot updates again after improvements
* docs: Add instructions for a continuous dashboard setup
* Replace argument assignment with signatures Folders package
* Fully cover WebAPI::Plugin::ObsRsync::Controller::Folders
* script: Also use OPENQA_WEBUI_MODE for related services
- Update to version 5.1758814503.03d923a4:
* Use Mojo::File in Worker for is_qemu_running
* Use Mojo::File in Worker for meminfo
* Document archiving of important jobs
- Update to version 5.1758729450.b88c0b40:
* Reject jobs if worker is broken when receiving a new job
- Update to version 5.1758711845.e5c02221:
* script: Allow to configure openQA mode
* t: run at least once Memorylimit register with max_rss_limit &gt; 0
* Replace argument assignation with signatures on MemoryLimit
Changes in os-autoinst:
- Update to version 5.1761036042.c43e4ab:
* Update perltidy
* Allow redirects in needle NeedleDownloader
* Don't overwrite firewall xml
* Add UEFI support for ipxe kernel boot
* os-autoinst-setup-multi-machine: Simplify determine_ethernet_interface
- Update to version 5.1759328765.e7438f7:
* Allow redirects in needle NeedleDownloader
* Don't overwrite firewall xml
* Add UEFI support for ipxe kernel boot
* t: Use consistent Mojo::File in 08-autotest as well
* os-autoinst-setup-multi-machine: Simplify determine_ethernet_interface
- Update to version 5.1759134946.e08d7c7:
* Add UEFI support for ipxe kernel boot
* t: Use consistent Mojo::File in 08-autotest as well
* os-autoinst-setup-multi-machine: Simplify determine_ethernet_interface
* os-autoinst-setup-multi-machine: Only call zypper when necessary
* os-autoinst-setup-multi-machine: Improve network interface check
</description>
<package>openQA</package>
<package>openQA:openQA-devel-test</package>
<package>openQA:openQA-test</package>
<package>openQA:openQA-worker-test</package>
<package>openQA:openQA-client-test</package>
<package>os-autoinst</package>
<package>os-autoinst:os-autoinst-test</package>
<package>os-autoinst:os-autoinst-devel-test</package>
<package>os-autoinst:os-autoinst-openvswitch-test</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,28 +0,0 @@
<patchinfo>
<packager>jsulig</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for amarok</summary>
<description>This update for amarok fixes the following issues:
Changes in amarok:
- Update to version 3.3.1
* Enable saving and loading script console items, autocompletion
in script console, and re-enable some more scripting functionality
* Convert the remaining main UI toolbuttons to use icons from theme
* Clear out remnants of the now-discontinued MusicDNS service
* Fix example permission grant command in database settings (kde#386004)
* Fix equalizer gains not updating when selecting some presets (kde#463908)
* Fix continuing playback after timecoded tracks (cue files etc, (kde#270003)
* Fix MusicBrainz search
* Properly start CD playback if Amarok is not already running (kde#503310)
* Also transmit embedded cover art through MPRIS (kde#357620)
* Don't show transcoding dialog after canceling download (kde#275840)
* Load network information earlier to avoid crashes on startup (kde#507497)
* Try to export as-compatible-as-possible playlist files (kde#507329)
* Fix some random crashes during playback
</description>
<package>amarok</package>
</patchinfo>

View File

@@ -1,48 +0,0 @@
<patchinfo incident="packagehub-10">
<issue tracker="cve" id="2025-10527">This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3.</issue>
<issue tracker="cve" id="2025-10536">This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3.</issue>
<issue tracker="cve" id="2025-10528">This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3.</issue>
<issue tracker="cve" id="2025-10537">Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3.</issue>
<issue tracker="cve" id="2025-10529">This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3.</issue>
<issue tracker="cve" id="2025-10532">This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3.</issue>
<issue tracker="cve" id="2025-10533">This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 115.28, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3.</issue>
<issue tracker="bnc" id="1249391">VUL-0: MozillaFirefox / MozillaThunderbird: update to 143.0 and 140.3esr</issue>
<packager>Yoshio_Sato</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for MozillaThunderbird</summary>
<description>This update for MozillaThunderbird fixes the following issues:
Changes in MozillaThunderbird:
Mozilla Thunderbird 140.3.0 ESR:
* Right-clicking 'List-ID' -&gt; 'Unsubscribe' created double encoded
draft subject
* Thunderbird could crash on startup
* Thunderbird could crash when importing mail
* Opening Website header link in RSS feed incorrectly re-encoded
URL parameters
MFSA 2025-78 (bsc#1249391)
* CVE-2025-10527
Sandbox escape due to use-after-free in the Graphics:
Canvas2D component
* CVE-2025-10528
Sandbox escape due to undefined behavior, invalid pointer in
the Graphics: Canvas2D component
* CVE-2025-10529
Same-origin policy bypass in the Layout component
* CVE-2025-10532
Incorrect boundary conditions in the JavaScript: GC component
* CVE-2025-10533
Integer overflow in the SVG component
* CVE-2025-10536
Information disclosure in the Networking: Cache component
* CVE-2025-10537
Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird
ESR 140.3, Firefox 143 and Thunderbird 143
</description>
<package>MozillaThunderbird</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,56 +0,0 @@
<patchinfo incident="packagehub-12">
<issue tracker="cve" id="2025-12441"/>
<issue tracker="cve" id="2025-12429"/>
<issue tracker="cve" id="2025-12431"/>
<issue tracker="cve" id="2025-12444"/>
<issue tracker="cve" id="2025-12428"/>
<issue tracker="cve" id="2025-12438"/>
<issue tracker="cve" id="2025-12435"/>
<issue tracker="cve" id="2025-12437"/>
<issue tracker="cve" id="2025-12443"/>
<issue tracker="cve" id="2025-12430"/>
<issue tracker="cve" id="2025-12440"/>
<issue tracker="cve" id="2025-12445"/>
<issue tracker="cve" id="2025-12446"/>
<issue tracker="cve" id="2025-12432"/>
<issue tracker="cve" id="2025-12436"/>
<issue tracker="cve" id="2025-12434"/>
<issue tracker="cve" id="2025-54874">VUL-0: CVE-2025-54874: TRACKERBUG: openjpeg: missing error check can lead to the use of an uninitialized pointer and cause an out-of-bounds heap</issue>
<issue tracker="cve" id="2025-12433"/>
<issue tracker="bnc" id="1252881">VUL-0: chromium: release 142.0.7444.59</issue>
<issue tracker="cve" id="2025-12439"/>
<issue tracker="cve" id="2025-12447"/>
<packager>AndreasStieger</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for chromium</summary>
<description>This update for chromium fixes the following issues:
Chromium 142.0.7444.59, the stable channel promotion of 142.
Security fixes (boo#1252881):
* CVE-2025-12428: Type Confusion in V8
* CVE-2025-12429: Inappropriate implementation in V8
* CVE-2025-12430: Object lifecycle issue in Media
* CVE-2025-12431: Inappropriate implementation in Extensions
* CVE-2025-12432: Race in V8
* CVE-2025-12433: Inappropriate implementation in V8
* CVE-2025-12434: Race in Storage
* CVE-2025-12435: Incorrect security UI in Omnibox
* CVE-2025-12436: Policy bypass in Extensions
* CVE-2025-12437: Use after free in PageInfo
* CVE-2025-12438: Use after free in Ozone
* CVE-2025-12439: Inappropriate implementation in App-Bound Encryption
* CVE-2025-12440: Inappropriate implementation in Autofill
* CVE-2025-12441: Out of bounds read in V8
* CVE-2025-12443: Out of bounds read in WebXR
* CVE-2025-12444: Incorrect security UI in Fullscreen UI
* CVE-2025-12445: Policy bypass in Extensions
* CVE-2025-12446: Incorrect security UI in SplitView
* CVE-2025-12447: Incorrect security UI in Omnibox
</description>
<package>chromium</package>
<seperate_build_arch/>
</patchinfo>

View File

@@ -1,24 +0,0 @@
<patchinfo incident="packagehub-14">
<packager>adrianSuSE</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for product-composer</summary>
<description>This update for product-composer fixes the following issues:
Update to version 0.6.16:
- merge updateinfo's with same id into one
- error out on updateinfo with same id, but non-mergable content
Update to version 0.6.15:
* Support updateinfo handling in arch specific meta data
Update to version 0.6.14:
* option to disable joliet extensions on media
* no joliet extensions on source and debug media anymore
</description>
<package>product-composer</package>
<seperate_build_arch/>
</patchinfo>

File diff suppressed because it is too large Load Diff

2
pnpm

Submodule pnpm updated: 94b9cc28e1...4d55e02518

Submodule product-composer deleted from 559d03e1cf

1
rawtherapee Submodule

Submodule rawtherapee added at f30f9d1b49

2
sbctl

Submodule sbctl updated: c8315ff856...ff582da4e2

View File

@@ -1,10 +1,4 @@
{
"ObsProject": "openSUSE:Backports:SLE-16.0",
"StagingProject": "openSUSE:Backports:SLE-16.0:PullRequest",
"QA": [
{
"Name": "Leap",
"Origin": "openSUSE:Leap:16.0:Products"
},
]
"ObsProject": "openSUSE:Backports:SLE-16.1",
"StagingProject": "openSUSE:Backports:SLE-16.1:PullRequest"
}

Submodule suitesparse deleted from 4935ce8780

Submodule synce4l updated: 3d3b1d48af...b86ac19f62

1
tbb

Submodule tbb deleted from 04b04da22c

2
trivy

Submodule trivy updated: cb29203387...a60b48a3ec

2
virtme

Submodule virtme updated: 547b3766fe...c43731f405

2
wicked

Submodule wicked updated: d61f1b645c...0ca44956ef

2
wine

Submodule wine updated: 5c12d35680...399f3278a3

View File

@@ -1,74 +1,23 @@
{
"Workflows": ["pr"],
"GitProjectName": "products/PackageHub#leap-16.0",
"GitProjectName": "products/PackageHub#leap-16.1",
"Organization": "pool",
"Branch": "leap-16.0",
"Branch": "leap-16.1",
"ManualMergeProject": true,
"NoProjectGitPR": true,
"Reviewers": [
"-maintenance-release-review",
"*opensuse-review",
"*packagehub-review",
"+legaldb",
"-autogits_obs_staging_bot",
"-qam-openqa-review"
],
"ReviewGroups": [
{
"Name": "maintenance-release-review",
"Name": "packagehub-review",
"Reviewers": [
"abergmann",
"amattiazzo",
"bfilho",
"cmatos",
"crazybyte",
"emanuelecappello",
"gsonnu",
"maintenance-robot",
"mauriziogalli",
"mbozicevic",
"mimi_vx",
"mschnitzer",
"msmeissn",
"pluskalm",
"rfrohl",
"slemke"
],
"Silent": true
},
{
"Name": "opensuse-review",
"Reviewers": [
"alarrosa",
"anag",
"atartamo",
"bigironman",
"darix",
"dimstar",
"dmach",
"eroca",
"jdsn",
"jengelh",
"mcalabkova",
"mstrigl",
"nkrapp",
"oertel",
"RBrownSUSE",
"simotek",
"lkocman-factory",
"maxlin_factory",
"smithfarm"
],
"Silent": true
},
{
"Name": "qam-openqa-review",
"Reviewers": [
"mimi_vx",
"mschnitzer",
"msmeissn",
"openqa-maintenance",
"foursixnine-openqa",
"szarate"
],
"Silent": true
]
}
]
}