forked from products/PackageHub
Compare commits
333 Commits
maintenanc
...
move_virtu
| Author | SHA256 | Date | |
|---|---|---|---|
| 2a6a020bcb | |||
| 10a68d97df | |||
|
|
ec0534f072 | ||
| 34b7a87191 | |||
|
|
5bd774a842 | ||
| 6947388c96 | |||
|
|
72ab7c49e3 | ||
| 7116f72f90 | |||
|
|
bed70f4c1a | ||
| 3a049c72be | |||
| 5bf44d3a0a | |||
|
|
953a26826f | ||
| 97d37c1171 | |||
|
|
55b48f8078 | ||
| 4291ac9678 | |||
|
|
d7cb9b9687 | ||
| 524ac41579 | |||
| 4a3eb4b09d | |||
|
|
6fee663212 | ||
| c3e3984357 | |||
| d8b82440d2 | |||
| 36b9de3803 | |||
|
|
599cd78130 | ||
| d696ced100 | |||
|
|
43918c1781 | ||
| fdc2e6920a | |||
|
|
5f3a2ca4f5 | ||
| e02931c376 | |||
|
|
e86e27c0ee | ||
|
|
861976ffaa | ||
| 62c3a6df17 | |||
| dc70bd8a7d | |||
| 203c9ebc1c | |||
|
|
5ce11d2031 | ||
| 4a8a71cfaa | |||
|
|
5e193e7b0c | ||
| 2ba789da73 | |||
|
|
5d155cfc8e | ||
| 3215b683bb | |||
| f0fd57da25 | |||
| a75756a1dd | |||
| a5e36132b4 | |||
|
|
93d5c851b6 | ||
| 735cc2c65c | |||
|
|
50931b6594 | ||
| bad747d321 | |||
| f0977f2467 | |||
|
|
c7f5c5003b | ||
|
|
1c6a2a337d | ||
| 32bc2761d5 | |||
|
|
255b0dece9 | ||
| eb62b13642 | |||
|
|
8c4efc438b | ||
| b2bd4b1f94 | |||
| c0469b3a59 | |||
| df53e25b6e | |||
|
|
4cfc011cfb | ||
| c10ac83930 | |||
| b4cc334ca3 | |||
| b32cb083da | |||
| fae13248f7 | |||
| 23516a9114 | |||
|
|
7543ea3cc3 | ||
| 32aca2e338 | |||
|
|
f36dfbd3f4 | ||
| c03172bbca | |||
|
|
92dadc23e7 | ||
| fd82b347f4 | |||
| 4d24c64542 | |||
|
|
0270ebc4a5 | ||
| 4fc2a1bb69 | |||
| e669a65e98 | |||
|
|
bd24e5011e | ||
| 5ad185879e | |||
|
|
6fedcd6d2c | ||
| 7043e32e83 | |||
|
|
9316aa7ce5 | ||
| 94bea3e342 | |||
|
|
08450cd470 | ||
| ed9758ae15 | |||
|
|
3bad3c5f46 | ||
| bc63d065c9 | |||
|
|
cf8e9e1dee | ||
| 6c1722de12 | |||
| e487856041 | |||
| deeaf745bd | |||
| 81aa423ed5 | |||
|
|
5d785c8e63 | ||
| 97a20f7e72 | |||
| f52d4e66c2 | |||
| 58d4cec34c | |||
| b4cde53f22 | |||
| 48e68291d4 | |||
| 5d50eb34d9 | |||
|
|
1eafc739de | ||
| 1b5478f24d | |||
| 535c096bc0 | |||
|
|
afb140f57e | ||
| f4475fce7e | |||
|
|
49e2d8e3ee | ||
| 8bd7a26bb0 | |||
|
|
1a78353635 | ||
| bcee9abfe3 | |||
|
|
79365ff72b | ||
| 39e5061531 | |||
| 664d2ab261 | |||
| 6d86a654c2 | |||
| af95a954f4 | |||
| e96e6d61ee | |||
| 41f701dcc1 | |||
| 3c13caa4c0 | |||
|
|
7b4b273e45 | ||
| 0305bdaf8d | |||
|
|
04a5237bbe | ||
| 9e102a1492 | |||
|
|
191235d1f9 | ||
|
|
3bd6ac96e5 | ||
| 1a1de1b2d9 | |||
|
|
bb3aba861c | ||
| af029e918c | |||
| fa3f4c5576 | |||
|
|
6440255204 | ||
|
|
796b04d33b | ||
| 8f2f9d86b0 | |||
|
|
2fd56b30d4 | ||
| 63082ba7c7 | |||
|
|
958cec1a14 | ||
| e52b646803 | |||
| 4f34e4bea2 | |||
|
|
42e7a03923 | ||
| 6814660c4a | |||
| 190d66cdae | |||
| d47e73860e | |||
| ce46c687b7 | |||
|
|
913979831f | ||
| 95ca3e6bac | |||
| fdbe485ba9 | |||
| 201936805e | |||
| ee96dd430d | |||
|
|
e4c18f1b17 | ||
| 7484b999ac | |||
|
|
87019a2c96 | ||
| 5104c42303 | |||
| 075b076300 | |||
| 42dde2bc32 | |||
|
|
514563e7f0 | ||
| 5f13a6d6a2 | |||
| e8877b6ba2 | |||
|
|
c66beb0d25 | ||
| 1bdb50141a | |||
|
|
f800ffa7eb | ||
| b6af3723b0 | |||
|
|
b904da424b | ||
| 0947d4913f | |||
|
|
f4138e1df0 | ||
| 9d66dd1eb7 | |||
|
|
b5b24a0ee5 | ||
| 215370317f | |||
|
|
e228bcc8b9 | ||
| fa31f94741 | |||
|
|
4b6c93eadf | ||
| 5ee4ff0cd1 | |||
|
|
2ab47ea154 | ||
| 7235f54cc8 | |||
|
|
5e576a9153 | ||
| 84518d8e92 | |||
|
|
de34c0d616 | ||
| 226e10c5ec | |||
| 8bf48c68fd | |||
| cde390ad2c | |||
|
|
57a2fdfcc0 | ||
| dd9b463f6b | |||
|
|
f731b8a87b | ||
| 446f67e6f6 | |||
| 472b5c129b | |||
|
|
fa1b7c2bce | ||
| 772f149974 | |||
| 8df3cece7b | |||
| aa703fe4c3 | |||
| ab59478311 | |||
|
|
7efb8b8dfc | ||
|
|
27eb5ea6c4 | ||
| 8b9ebf531e | |||
|
|
e3ff226e50 | ||
| 0ac9782d12 | |||
|
|
57a31c3244 | ||
| 15d9d81592 | |||
| 5dd827894a | |||
| c10f377714 | |||
| 2db914151f | |||
| 3103a9e8e0 | |||
| afaaa39260 | |||
| 258b2add24 | |||
|
|
a03abce98c | ||
| e69231e6ff | |||
|
|
d417b180e3 | ||
|
|
f4b954b258 | ||
|
|
76cec69059 | ||
| ebcf91f4fb | |||
|
|
be71c72197 | ||
| 120471f77e | |||
|
|
db9c364b31 | ||
| 3929c52614 | |||
| d5e75ef24a | |||
|
|
46ad282010 | ||
| 70aa830096 | |||
|
|
432b6015b9 | ||
| d0ef9928a7 | |||
| bbd772aebb | |||
| 8fac4ab323 | |||
| 8028c9ecf0 | |||
| 132621a397 | |||
| 12a7def9e2 | |||
| 24d02629f1 | |||
|
|
95edc64165 | ||
| 85d2d64fc0 | |||
| 41d505f4ab | |||
| d6d7a39cb4 | |||
| b1b229353f | |||
|
|
cb67484fd4 | ||
| 7de4d17bb6 | |||
|
|
a24445cff8 | ||
| 262eddbb2e | |||
| fc7baf3c8d | |||
| 9c3b6c187d | |||
| e01601e63c | |||
| aeb1f73847 | |||
| a47a0255a4 | |||
|
|
d08e2827bb | ||
| bc7de0e7cc | |||
|
|
8439743814 | ||
|
|
76091026db | ||
|
|
fc03ed1327 | ||
| b96a953188 | |||
| 6ae24600c5 | |||
| d1a0631733 | |||
|
|
51ad92059e | ||
| 3aae949b7a | |||
| 158832bfe1 | |||
|
|
a7ed1a773d | ||
|
|
6b53d9f452 | ||
| 7cf3e1410d | |||
|
|
9d8b838644 | ||
|
747469b4bf
|
|||
| 3c973dcf63 | |||
| 80fe33645a | |||
|
|
2176ab50a4 | ||
|
|
158a277d59 | ||
| fb57ec8f31 | |||
|
|
bbb50fccd1 | ||
| 89bd7827cb | |||
|
|
cb8920ffd6 | ||
| 46f285f4b7 | |||
| d38e304ad2 | |||
|
|
6411d5ea23 | ||
| c3d432dd34 | |||
|
|
d433f344c3 | ||
| ee207a2ab3 | |||
| 792ee49a40 | |||
|
|
cd1bed3528 | ||
| 7d490f401a | |||
|
|
0673a0497c | ||
|
|
9423c5c9b7 | ||
| 927e99a69e | |||
|
|
7114ff5a64 | ||
|
|
c8f2353703 | ||
| 5996407142 | |||
| 55f7b884a6 | |||
| 01348e5949 | |||
|
|
1e27862c42 | ||
| 46e4106db3 | |||
|
|
764328e284 | ||
| 4022efbf5d | |||
| feedd4ca39 | |||
| 79e36c0fe2 | |||
| 021c63e2c2 | |||
|
|
eaf12474ff | ||
| 19e2bfc867 | |||
| 9d5e502d5d | |||
|
|
92c12b23ba | ||
| a85d786d1d | |||
| 0da9f5542f | |||
| 74b322a7d3 | |||
| 272e6df8eb | |||
|
|
27989672d0 | ||
| 464de639b5 | |||
|
|
f54fe69075 | ||
| 61765b6b59 | |||
|
|
1852c8a8ce | ||
| dfe0ef234b | |||
|
|
99dd857c9a | ||
| c90e774192 | |||
|
|
873c5fa4c1 | ||
| 23baf9f465 | |||
|
|
d40fc7ab20 | ||
| cf34c8859c | |||
|
|
07aabbdaf8 | ||
|
|
5f7c1b8f9d | ||
| ff4dacc9ba | |||
| d0432c612a | |||
| fe1490e4c7 | |||
| 6156889504 | |||
| 3324d45f45 | |||
| cb7dba8325 | |||
|
|
f528a0f52a | ||
|
|
f3c5c2bccf | ||
| 7cda1fc03b | |||
| 142516cf54 | |||
| aee60a7699 | |||
|
|
1b6dba3cd1 | ||
| 146b6deca8 | |||
|
|
a8c4523f73 | ||
| d264abcae0 | |||
|
|
662471de4f | ||
|
|
779f4f8aa0 | ||
|
|
f82b6807a3 | ||
| dae02011d2 | |||
|
|
b1b5c5f7fd | ||
| ba6df4c406 | |||
| 5cbea7b736 | |||
| 4acf9d3745 | |||
|
f893d406a8
|
|||
|
|
a177c0193e | ||
| ca5de1dd3f | |||
| 40dc8cadfe | |||
| 26275cf377 | |||
| 60e7b0a97e | |||
| af2e21625e | |||
| c8a509cefa | |||
| 6a6ae3204b | |||
| dec6c20720 | |||
| 886d7ce9da | |||
| 16bbbb752c |
148
.gitmodules
vendored
148
.gitmodules
vendored
@@ -258,6 +258,10 @@
|
||||
path = OpenShadingLanguage
|
||||
url = ../../pool/OpenShadingLanguage
|
||||
branch = leap-16.0
|
||||
[submodule "OpenSMTPD"]
|
||||
path = OpenSMTPD
|
||||
url = ../../pool/OpenSMTPD
|
||||
branch = leap-16.0
|
||||
[submodule "OpenSubdiv"]
|
||||
path = OpenSubdiv
|
||||
url = ../../pool/opensubdiv
|
||||
@@ -290,6 +294,10 @@
|
||||
path = PrusaSlicer
|
||||
url = ../../pool/PrusaSlicer
|
||||
branch = leap-16.0
|
||||
[submodule "dehydrated"]
|
||||
path = dehydrated
|
||||
url = ../../pool/dehydrated
|
||||
branch = leap-16.0
|
||||
[submodule "QR-Code-generator"]
|
||||
path = QR-Code-generator
|
||||
url = ../../pool/QR-Code-generator
|
||||
@@ -3066,6 +3074,10 @@
|
||||
path = dom2-core-tests
|
||||
url = ../../pool/dom2-core-tests
|
||||
branch = leap-16.0
|
||||
[submodule "doomsday"]
|
||||
path = doomsday
|
||||
url = ../../pool/doomsday
|
||||
branch = leap-16.0
|
||||
[submodule "dosbox"]
|
||||
path = dosbox
|
||||
url = ../../pool/dosbox
|
||||
@@ -7170,6 +7182,10 @@
|
||||
path = gnu_ddrescue
|
||||
url = ../../pool/gnu_ddrescue
|
||||
branch = leap-16.0
|
||||
[submodule "gnucobol"]
|
||||
path = gnucobol
|
||||
url = ../../pool/gnucobol
|
||||
branch = leap-16.0
|
||||
[submodule "gnuastro"]
|
||||
path = gnuastro
|
||||
url = ../../pool/gnuastro
|
||||
@@ -10590,6 +10606,10 @@
|
||||
path = most
|
||||
url = ../../pool/most
|
||||
branch = leap-16.0
|
||||
[submodule "motif"]
|
||||
path = motif
|
||||
url = ../../pool/motif
|
||||
branch = leap-16.0
|
||||
[submodule "motion"]
|
||||
path = motion
|
||||
url = ../../pool/motion
|
||||
@@ -12962,6 +12982,10 @@
|
||||
path = perl-Data-Visitor
|
||||
url = ../../pool/perl-Data-Visitor
|
||||
branch = leap-16.0
|
||||
[submodule "perl-Date-Manip"]
|
||||
path = perl-Date-Manip
|
||||
url = ../../pool/perl-Date-Manip
|
||||
branch = leap-16.0
|
||||
[submodule "perl-DateTime-Calendar-Mayan"]
|
||||
path = perl-DateTime-Calendar-Mayan
|
||||
url = ../../pool/perl-DateTime-Calendar-Mayan
|
||||
@@ -13746,6 +13770,10 @@
|
||||
path = perl-Mojolicious-Plugin-OAuth2
|
||||
url = ../../pool/perl-Mojolicious-Plugin-OAuth2
|
||||
branch = leap-16.0
|
||||
[submodule "perl-Mojolicious-Plugin-OpenAPI"]
|
||||
path = perl-Mojolicious-Plugin-OpenAPI
|
||||
url = ../../pool/perl-Mojolicious-Plugin-OpenAPI
|
||||
branch = leap-16.0
|
||||
[submodule "perl-Mojolicious-Plugin-Webpack"]
|
||||
path = perl-Mojolicious-Plugin-Webpack
|
||||
url = ../../pool/perl-Mojolicious-Plugin-Webpack
|
||||
@@ -14342,6 +14370,10 @@
|
||||
path = perl-TAP-Formatter-GitHubActions
|
||||
url = ../../pool/perl-TAP-Formatter-GitHubActions
|
||||
branch = leap-16.0
|
||||
[submodule "perl-TAP-Harness-JUnit"]
|
||||
path = perl-TAP-Harness-JUnit
|
||||
url = ../../pool/perl-TAP-Harness-JUnit
|
||||
branch = leap-16.0
|
||||
[submodule "perl-Task-Weaken"]
|
||||
path = perl-Task-Weaken
|
||||
url = ../../pool/perl-Task-Weaken
|
||||
@@ -14702,6 +14734,10 @@
|
||||
path = phoronix-test-suite
|
||||
url = ../../pool/phoronix-test-suite
|
||||
branch = leap-16.0
|
||||
[submodule "php-APCu"]
|
||||
path = php-APCu
|
||||
url = ../../pool/php-APCu
|
||||
branch = leap-16.0
|
||||
[submodule "php-pear-Auth_SASL"]
|
||||
path = php-pear-Auth_SASL
|
||||
url = ../../pool/php-pear-Auth_SASL
|
||||
@@ -17350,6 +17386,10 @@
|
||||
path = rasqal
|
||||
url = ../../pool/rasqal
|
||||
branch = leap-16.0
|
||||
[submodule "rawtherapee"]
|
||||
path = rawtherapee
|
||||
url = ../../pool/rawtherapee
|
||||
branch = leap-16.0
|
||||
[submodule "raw-thumbnailer"]
|
||||
path = raw-thumbnailer
|
||||
url = ../../pool/raw-thumbnailer
|
||||
@@ -17562,10 +17602,6 @@
|
||||
path = rlwrap
|
||||
url = ../../pool/rlwrap
|
||||
branch = leap-16.0
|
||||
[submodule "rmt-server"]
|
||||
path = rmt-server
|
||||
url = ../../pool/rmt-server
|
||||
branch = leap-16.0
|
||||
[submodule "rmw"]
|
||||
path = rmw
|
||||
url = ../../pool/rmw
|
||||
@@ -26134,3 +26170,107 @@
|
||||
path = python-pyRFC3339
|
||||
url = ../../pool/python-pyRFC3339
|
||||
branch = leap-16.0
|
||||
[submodule "certbot-systemd-timer"]
|
||||
path = certbot-systemd-timer
|
||||
url = ../../pool/certbot-systemd-timer
|
||||
branch = leap-16.0
|
||||
[submodule "python-augeas"]
|
||||
path = python-augeas
|
||||
url = ../../pool/python-augeas
|
||||
branch = leap-16.0
|
||||
[submodule "python-bson"]
|
||||
path = python-bson
|
||||
url = ../../pool/python-bson
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-apache"]
|
||||
path = python-certbot-apache
|
||||
url = ../../pool/python-certbot-apache
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-cloudflare"]
|
||||
path = python-certbot-dns-cloudflare
|
||||
url = ../../pool/python-certbot-dns-cloudflare
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-digitalocean"]
|
||||
path = python-certbot-dns-digitalocean
|
||||
url = ../../pool/python-certbot-dns-digitalocean
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-dnsimple"]
|
||||
path = python-certbot-dns-dnsimple
|
||||
url = ../../pool/python-certbot-dns-dnsimple
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-dnsmadeeasy"]
|
||||
path = python-certbot-dns-dnsmadeeasy
|
||||
url = ../../pool/python-certbot-dns-dnsmadeeasy
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-linode"]
|
||||
path = python-certbot-dns-linode
|
||||
url = ../../pool/python-certbot-dns-linode
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-luadns"]
|
||||
path = python-certbot-dns-luadns
|
||||
url = ../../pool/python-certbot-dns-luadns
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-nsone"]
|
||||
path = python-certbot-dns-nsone
|
||||
url = ../../pool/python-certbot-dns-nsone
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-ovh"]
|
||||
path = python-certbot-dns-ovh
|
||||
url = ../../pool/python-certbot-dns-ovh
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-rfc2136"]
|
||||
path = python-certbot-dns-rfc2136
|
||||
url = ../../pool/python-certbot-dns-rfc2136
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-route53"]
|
||||
path = python-certbot-dns-route53
|
||||
url = ../../pool/python-certbot-dns-route53
|
||||
branch = leap-16.0
|
||||
[submodule "python-cloudflare"]
|
||||
path = python-cloudflare
|
||||
url = ../../pool/python-cloudflare
|
||||
branch = leap-16.0
|
||||
[submodule "python-digitalocean"]
|
||||
path = python-digitalocean
|
||||
url = ../../pool/python-digitalocean
|
||||
branch = leap-16.0
|
||||
[submodule "python-dns-lexicon"]
|
||||
path = python-dns-lexicon
|
||||
url = ../../pool/python-dns-lexicon
|
||||
branch = leap-16.0
|
||||
[submodule "python-jsonlines"]
|
||||
path = python-jsonlines
|
||||
url = ../../pool/python-jsonlines
|
||||
branch = leap-16.0
|
||||
[submodule "python-jsonpickle"]
|
||||
path = python-jsonpickle
|
||||
url = ../../pool/python-jsonpickle
|
||||
branch = leap-16.0
|
||||
[submodule "python-localzone"]
|
||||
path = python-localzone
|
||||
url = ../../pool/python-localzone
|
||||
branch = leap-16.0
|
||||
[submodule "python-pytest-httpx"]
|
||||
path = python-pytest-httpx
|
||||
url = ../../pool/python-pytest-httpx
|
||||
branch = leap-16.0
|
||||
[submodule "python-requests-file"]
|
||||
path = python-requests-file
|
||||
url = ../../pool/python-requests-file
|
||||
branch = leap-16.0
|
||||
[submodule "python-softlayer"]
|
||||
path = python-softlayer
|
||||
url = ../../pool/python-softlayer
|
||||
branch = leap-16.0
|
||||
[submodule "python-softlayer-zeep"]
|
||||
path = python-softlayer-zeep
|
||||
url = ../../pool/python-softlayer-zeep
|
||||
branch = leap-16.0
|
||||
[submodule "python-tldextract"]
|
||||
path = python-tldextract
|
||||
url = ../../pool/python-tldextract
|
||||
branch = leap-16.0
|
||||
[submodule "openQA-devel-container"]
|
||||
path = openQA-devel-container
|
||||
url = ../../pool/openQA-devel-container
|
||||
branch = leap-16.0
|
||||
|
||||
@@ -1,3 +1,10 @@
|
||||
-------------------------------------------------------------------
|
||||
Mon Jan 5 10:38:32 UTC 2026 - Wolfgang Engel <wolfgang.engel@suse.com>
|
||||
|
||||
- Backports.productcompose:
|
||||
+ add to backports_unneeded, remove xen related packages (bsc#1253226)
|
||||
xen-tools-xendomains-wait-disk
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Fri Oct 10 07:19:41 UTC 2025 - Wolfgang Engel <wolfgang.engel@suse.com>
|
||||
|
||||
|
||||
@@ -140,6 +140,7 @@ packagesets:
|
||||
- geoipupdate-legacy
|
||||
- geolite2legacy
|
||||
- gio-branding-upstream
|
||||
- glibc-livepatches
|
||||
- grpc-source
|
||||
- kernel-azure-livepatch-devel
|
||||
- kernel-default-livepatch-devel
|
||||
@@ -149,6 +150,12 @@ packagesets:
|
||||
- kernel-livepatch-6_12_0-160000_5-rt
|
||||
- kernel-livepatch-6_12_0-160000_6-default
|
||||
- kernel-livepatch-6_12_0-160000_6-rt
|
||||
- kernel-livepatch-6_12_0-160000_7-default
|
||||
- kernel-livepatch-6_12_0-160000_7-rt
|
||||
- kernel-livepatch-6_12_0-160000_8-default
|
||||
- kernel-livepatch-6_12_0-160000_8-rt
|
||||
- kernel-livepatch-6_12_0-160000_9-default
|
||||
- kernel-livepatch-6_12_0-160000_9-rt
|
||||
- kernel-rt-livepatch
|
||||
- kernel-rt-livepatch-devel
|
||||
- krb5-mini
|
||||
@@ -203,6 +210,7 @@ packagesets:
|
||||
- ocfs2-kmp-default
|
||||
- ocfs2-kmp-rt
|
||||
- openssl_tpm2
|
||||
- openssl-3-livepatches
|
||||
- pam-extra-32bit
|
||||
- patterns-base-kernel_livepatching
|
||||
- patterns-base-transactional_base
|
||||
@@ -224,6 +232,7 @@ packagesets:
|
||||
- patterns-base-update_test
|
||||
- plymouth-branding-upstream
|
||||
- postgresql17-devel-mini
|
||||
- postgresql18-devel-mini
|
||||
- protobuf21-source
|
||||
- reproducible-faketools
|
||||
- reproducible-faketools-ant
|
||||
@@ -279,6 +288,7 @@ packagesets:
|
||||
- xen-doc-html
|
||||
- xen-tools
|
||||
- xen-tools-domU
|
||||
- xen-tools-xendomains-wait-disk
|
||||
- yum-utils
|
||||
|
||||
# TODO: unneeded Leap package per architecture
|
||||
@@ -699,6 +709,9 @@ packagesets:
|
||||
- cargo-packaging
|
||||
- cargo1.87
|
||||
- cargo1.88
|
||||
- cargo1.89
|
||||
- cargo1.90
|
||||
- cargo1.91
|
||||
- catatonit
|
||||
- cblas-devel
|
||||
- cblas-devel-static
|
||||
@@ -1406,7 +1419,6 @@ packagesets:
|
||||
- gobject-introspection-devel
|
||||
- golang-github-cpuguy83-go-md2man
|
||||
- golang-github-google-jsonnet
|
||||
- golang-github-prometheus-prometheus
|
||||
- golang-github-prometheus-promu
|
||||
- golang-packaging
|
||||
- google-errorprone-annotation
|
||||
@@ -1922,6 +1934,27 @@ packagesets:
|
||||
- java-21-openjdk-javadoc
|
||||
- java-21-openjdk-jmods
|
||||
- java-21-openjdk-src
|
||||
- java-22-openjdk
|
||||
- java-22-openjdk-demo
|
||||
- java-22-openjdk-devel
|
||||
- java-22-openjdk-headless
|
||||
- java-22-openjdk-javadoc
|
||||
- java-22-openjdk-jmods
|
||||
- java-22-openjdk-src
|
||||
- java-23-openjdk
|
||||
- java-23-openjdk-demo
|
||||
- java-23-openjdk-devel
|
||||
- java-23-openjdk-headless
|
||||
- java-23-openjdk-javadoc
|
||||
- java-23-openjdk-jmods
|
||||
- java-23-openjdk-src
|
||||
- java-24-openjdk
|
||||
- java-24-openjdk-demo
|
||||
- java-24-openjdk-devel
|
||||
- java-24-openjdk-headless
|
||||
- java-24-openjdk-javadoc
|
||||
- java-24-openjdk-jmods
|
||||
- java-24-openjdk-src
|
||||
- java-cup
|
||||
- java-cup-manual
|
||||
- javacc
|
||||
@@ -5490,6 +5523,17 @@ packagesets:
|
||||
- postgresql17-pltcl
|
||||
- postgresql17-server
|
||||
- postgresql17-server-devel
|
||||
- postgresql18
|
||||
- postgresql18-contrib
|
||||
- postgresql18-devel
|
||||
- postgresql18-docs
|
||||
- postgresql18-pgaudit
|
||||
- postgresql18-pgvector
|
||||
- postgresql18-plperl
|
||||
- postgresql18-plpython
|
||||
- postgresql18-pltcl
|
||||
- postgresql18-server
|
||||
- postgresql18-server-devel
|
||||
- powerman
|
||||
- powerman-devel
|
||||
- powertop
|
||||
@@ -6773,6 +6817,9 @@ packagesets:
|
||||
- rhino-engine
|
||||
- rhino-javadoc
|
||||
- rhino-runtime
|
||||
- rmt-server
|
||||
- rmt-server-config
|
||||
- rmt-server-pubcloud
|
||||
- rollback-helper
|
||||
- rootlesskit
|
||||
- rp-pppoe
|
||||
@@ -6829,6 +6876,9 @@ packagesets:
|
||||
- rust-keylime
|
||||
- rust1.87
|
||||
- rust1.88
|
||||
- rust1.89
|
||||
- rust1.90
|
||||
- rust1.91
|
||||
- samba
|
||||
- samba-ad-dc
|
||||
- samba-ad-dc-libs
|
||||
@@ -7057,7 +7107,6 @@ packagesets:
|
||||
- system-user-news
|
||||
- system-user-nobody
|
||||
- system-user-ntp
|
||||
- system-user-prometheus
|
||||
- system-user-pulse
|
||||
- system-user-qemu
|
||||
- system-user-root
|
||||
@@ -7932,6 +7981,8 @@ packagesets:
|
||||
- kernel-kvmsmall
|
||||
- kernel-kvmsmall-devel
|
||||
- kernel-livepatch-6_12_0-160000_5-default
|
||||
- kernel-livepatch-6_12_0-160000_6-default
|
||||
- kernel-livepatch-6_12_0-160000_7-default
|
||||
- libLLVMSPIRVLib19
|
||||
- libatopology2
|
||||
- libdpdk-25
|
||||
@@ -8043,6 +8094,8 @@ packagesets:
|
||||
- grub2-s390x-emu
|
||||
- kernel-default-livepatch
|
||||
- kernel-livepatch-6_12_0-160000_5-default
|
||||
- kernel-livepatch-6_12_0-160000_6-default
|
||||
- kernel-livepatch-6_12_0-160000_7-default
|
||||
- kernel-zfcpdump
|
||||
- kiwi-settings
|
||||
- libHBAAPI2
|
||||
@@ -8182,6 +8235,8 @@ packagesets:
|
||||
- kernel-kvmsmall-devel
|
||||
- kernel-kvmsmall-vdso
|
||||
- kernel-livepatch-6_12_0-160000_5-default
|
||||
- kernel-livepatch-6_12_0-160000_6-default
|
||||
- kernel-livepatch-6_12_0-160000_7-default
|
||||
- kiwi-pxeboot
|
||||
- kubevirt-virtctl
|
||||
- libFLAC++10-x86-64-v3
|
||||
|
||||
Submodule MozillaThunderbird updated: 0027b98838...4fb117d27d
Submodule OpenBoard updated: e1d590bc01...b998a303e8
1
OpenSMTPD
Submodule
1
OpenSMTPD
Submodule
Submodule OpenSMTPD added at cc881e3c77
2
_config
2
_config
@@ -168,7 +168,7 @@ Macros:
|
||||
|
||||
# Leap specific package list, the same list with excludebuild must add to Backports project
|
||||
# Most of package should be built in Backports
|
||||
%if "%_project" == "openSUSE:Backports:SLE-16.0"
|
||||
%if 0%{?_is_in_project}
|
||||
# we build ffado:ffado-mixer for openSUSE, the main one is built in SLFO
|
||||
BuildFlags: excludebuild:ffado
|
||||
# build gpgme:qt flavor for qt5 support
|
||||
|
||||
2
act
2
act
Submodule act updated: ed079edc0d...8bfe9d9547
Submodule ansible-sap-launchpad updated: 000a0fa833...c0088ff952
Submodule apache2-mod_wsgi updated: 3509105fad...c8dbdeec72
Submodule bash-git-prompt updated: 422b159da2...9bd39c9f5d
2
cddlib
2
cddlib
Submodule cddlib updated: f0f0c4f64c...20da620429
1
certbot-systemd-timer
Submodule
1
certbot-systemd-timer
Submodule
Submodule certbot-systemd-timer added at b7f55a0d65
2
cheat
2
cheat
Submodule cheat updated: 27656594fe...e8f7ed9227
2
chromium
2
chromium
Submodule chromium updated: 6685801dcd...ff3414e963
Submodule cmake-extras updated: d3c9c9090d...ff796226d9
2
coredns
2
coredns
Submodule coredns updated: c75b9e7492...8273aa64e4
1
dehydrated
Submodule
1
dehydrated
Submodule
Submodule dehydrated added at 67698c18b1
1
doomsday
Submodule
1
doomsday
Submodule
Submodule doomsday added at 259fda21db
Submodule evolution updated: 5caf1853e4...49eb134ec6
2
exim
2
exim
Submodule exim updated: 9f3f61dcb2...aa2daa7cec
2
fcitx5
2
fcitx5
Submodule fcitx5 updated: 5ca142210a...7957ae0538
2
ffmpeg-4
2
ffmpeg-4
Submodule ffmpeg-4 updated: 5d7becce29...185351b606
2
flint
2
flint
Submodule flint updated: 71e720ca64...47c6375582
2
gdcm
2
gdcm
Submodule gdcm updated: bedf8333a7...be46bd0032
2
gimp
2
gimp
Submodule gimp updated: aab3634bba...d7bae19de0
2
git-bug
2
git-bug
Submodule git-bug updated: 22bb247e73...2390ae6cee
Submodule gitea-tea updated: 91324b6042...143cd92098
2
gn
2
gn
Submodule gn updated: 140cfd7fc8...10a6ded157
Submodule gnome-browser-connector updated: 7efed54b43...630cfb02e2
1
gnucobol
Submodule
1
gnucobol
Submodule
Submodule gnucobol added at 30352791a2
Submodule gnuhealth updated: dbcd0306a3...6e5edb6ab0
Submodule gnuhealth-client updated: fd6315ff20...c790d4b1d8
Submodule go-sendxmpp updated: 3ac86d2091...a7e7d705d1
Submodule grub2-compat-ia32 updated: 75de02f7e5...1dbc6bcb1a
2
hauler
2
hauler
Submodule hauler updated: 9084f004c1...69ca5e4eea
2
helmfile
2
helmfile
Submodule helmfile updated: 6bf0433278...5670b579cc
Submodule icinga-php-library updated: 2adfe405c4...dcb9868560
Submodule icinga-php-thirdparty updated: 045c6cef83...83db62c3c8
Submodule icingaweb2 updated: 3772b35d84...640fad7a20
2
kbuild
2
kbuild
Submodule kbuild updated: 245dba4a3f...26142e2c7d
2
knot
2
knot
Submodule knot updated: 41bb945764...d98a3c5e64
2
labwc
2
labwc
Submodule labwc updated: 3ff4d66043...54ed9a7fa2
2
matio
2
matio
Submodule matio updated: a301162ce9...cab79b5274
Submodule messagelib updated: 7866487643...20ebf1a5d2
Submodule micro-editor updated: 14dead0bee...493acf5fad
Submodule micropython updated: a2de50f788...1a105a4362
2
minisign
2
minisign
Submodule minisign updated: 0120e9a39f...e3f15b140a
1
motif
Submodule
1
motif
Submodule
Submodule motif added at 618168fbeb
2
myrlyn
2
myrlyn
Submodule myrlyn updated: 3086a75932...3528003dd4
2
niri
2
niri
Submodule niri updated: de5c060c81...d66708d6ef
2
openQA
2
openQA
Submodule openQA updated: d4fcc3820c...68075a67b6
1
openQA-devel-container
Submodule
1
openQA-devel-container
Submodule
Submodule openQA-devel-container added at a6ab86b7ea
2
orthanc
2
orthanc
Submodule orthanc updated: 12a313f754...b1faeb6d03
Submodule orthanc-authorization updated: 1775daa8d2...f76b8b7d8c
Submodule orthanc-dicomweb updated: 76735708d6...43ded30b6e
Submodule orthanc-gdcm updated: 4cd29ae1d8...6bd78f0f67
Submodule orthanc-indexer updated: cd8eb0df05...e85b09b660
Submodule orthanc-mysql updated: c3f53cb55c...332c40656c
Submodule orthanc-neuro updated: c1ebe82b72...ce09ff7baa
Submodule orthanc-postgresql updated: 58dee52dbf...424752aeb5
Submodule orthanc-python updated: cff0c7c264...7415055070
Submodule orthanc-stl updated: a6937cc2bc...47cf97af1d
Submodule orthanc-tcia updated: 356ba251d2...bc37602553
Submodule orthanc-wsi updated: a0c624caf6...428762710d
Submodule os-autoinst updated: 54674dc3b7...c267795e7d
Submodule os-autoinst-distri-opensuse-deps updated: 224b171c8f...de9efe473a
14
patchinfo.20251027101540783529.187004354831441/_patchinfo
Normal file
14
patchinfo.20251027101540783529.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,14 @@
|
||||
<patchinfo incident="packagehub-67">
|
||||
<packager>lkocman</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for grub2-compat-ia32</summary>
|
||||
<description>This update for grub2-compat-ia32 fixes the following issues:
|
||||
|
||||
- Drop update-bootloader --get as it returns 0
|
||||
even if the variable is unset
|
||||
- Add update-bootloader also into post and postun Requires
|
||||
</description>
|
||||
<package>grub2-compat-ia32</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
236
patchinfo.20251117131718442159.187004354831441/_patchinfo
Normal file
236
patchinfo.20251117131718442159.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,236 @@
|
||||
<patchinfo incident="packagehub-81">
|
||||
<issue tracker="bnc" id="1250499">VUL-0: CVE-2025-10924: gimp: GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="bnc" id="1250497">VUL-0: CVE-2025-10922: gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="cve" id="2025-10922">VUL-0: CVE-2025-10922: gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="cve" id="2025-2760">VUL-0: CVE-2025-2760: gimp: integer overflow may lead to remote code execution</issue>
|
||||
<issue tracker="bnc" id="1250501">VUL-0: CVE-2025-10925: gimp: GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="bnc" id="1241690">VUL-0: CVE-2025-2760: gimp: integer overflow may lead to remote code execution</issue>
|
||||
<issue tracker="bnc" id="1250495">VUL-0: CVE-2025-10920: gimp: GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="cve" id="2025-10920">VUL-0: CVE-2025-10920: gimp: GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="cve" id="2025-10924">VUL-0: CVE-2025-10924: gimp: GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="cve" id="2025-10925">VUL-0: CVE-2025-10925: gimp: GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<packager>mgorse</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for gimp</summary>
|
||||
<description>This update for gimp fixes the following issues:
|
||||
|
||||
Changes in gimp:
|
||||
|
||||
Update to 3.0.6:
|
||||
|
||||
- Security:
|
||||
|
||||
- During development, we received reports from the Zero Day
|
||||
Initiative of potential security issues with some of our file
|
||||
import plug-ins. While these issues are very unlikely to
|
||||
occur with real files, developers like Jacob Boerema and Alx
|
||||
Sa proactively improved security for those imports.
|
||||
The resolved reports are:
|
||||
- ZDI-CAN-27793
|
||||
- ZDI-CAN-27823
|
||||
- ZDI-CAN-27836
|
||||
- ZDI-CAN-27878
|
||||
- ZDI-CAN-27863
|
||||
- ZDI-CAN-27684
|
||||
|
||||
- Core:
|
||||
|
||||
- Many false-positive build warnings have been cleaned out (and
|
||||
proper issues fixed).
|
||||
- Various crashes fixed.
|
||||
- When creating a layer mask from the layer's alpha, but the
|
||||
layer has no alpha, simply fill the mask with complete
|
||||
opacity instead of a completely transparent layer.
|
||||
- Various core infrastructure code reviewed, cleaned up,
|
||||
refactored and improved, in drawable, layer and filter
|
||||
handling code, tree view code, and more.
|
||||
- GIMP_ICONS_LIKE_A_BOSS environment variable is not working
|
||||
anymore (because "gtk-menu-images" and "gtk-button-images"
|
||||
have been deprecated in GTK3 and removed in GTK4) and was
|
||||
therefore removed.
|
||||
- Lock Content now shows as an undo step.
|
||||
- Add alpha channel for certain transforms.
|
||||
- Add alpha channel on filter merge, when necessary.
|
||||
- Filters can now be applied non-destructively on channels.
|
||||
- Improved Photoshop brush support.
|
||||
- After deleting a palette entry, the next entry is
|
||||
automatically selected. This allows easily deleting several
|
||||
entries in a row, among other usage.
|
||||
- Resize image to layers irrespective to selections.
|
||||
- Improved in-GUI release notes' demo script language:
|
||||
|
||||
- We can now set a button value to click it: "toolbox:text,
|
||||
tool-options:outline=1, tool-options:outline-direction"
|
||||
- Color selector's module names can be used as identifiers:
|
||||
"color-editor,color-editor:CMYK=1,color-editor:total-ink-coverage"
|
||||
|
||||
- Fixed Alpha to Selection on single layers with no
|
||||
transparency.
|
||||
- Various code is slowly ported to newer code, preparing for
|
||||
GTK4 port (in an unplanned future step):
|
||||
|
||||
- Using g_set_str() (optionally redefining it in our core
|
||||
code to avoid bumping the GLib minimum requirement).
|
||||
- Start using GListModel in various pieces of code, in
|
||||
particular getting rid of more and more usage of
|
||||
GtkTreeView when possible (as it will be deprecated with
|
||||
GTK4).
|
||||
- New GimpRow class for all future row widgets.
|
||||
- Use more of G_DECLARE_DERIVABLE_TYPE and
|
||||
G_DECLARE_FINAL_TYPE where relevant.
|
||||
- New GimpContainerListView using a GtkListBox.
|
||||
- New GimpRowSeparator, GimpRowSettings, GimpRowFilter and
|
||||
GimpRowDrawableFilter widgets.
|
||||
|
||||
- (Experimental) GEX Format was updated.
|
||||
- Palette import:
|
||||
|
||||
- Set alpha value for image palette imports.
|
||||
- Fix Lab & CMYK ACB palette import.
|
||||
- Add palette format filters to import dialog, making it more
|
||||
apparent what palette formats are supported, and giving the
|
||||
ability to hide irrelevant files.
|
||||
|
||||
- Improved filter actions' sensitivity to make sure they are
|
||||
set insensitive when relevant. In particular filters which
|
||||
cannot be run non-destructively (e.g. filters with aux
|
||||
inputs, non-interactive filters and GEGL Graph) must be
|
||||
insensitive when trying to run them on group layers.
|
||||
- Fix bad axis centering on zoom out.
|
||||
- Export better SVG when exporting paths.
|
||||
|
||||
- Tools:
|
||||
|
||||
- Text tool: make sure the default color is only changed when
|
||||
the user confirms the color change.
|
||||
- Foreground Selection tool: do not create a selection when no
|
||||
strokes has been made. In particular this removes the
|
||||
unnecessary delay which happened when switching to another
|
||||
tool without actually stroking anything.
|
||||
- All Transform tools: transform boundaries for preview is now
|
||||
multi-layers aware.
|
||||
- (Experimental) Seamless Clone tool: made to work again,
|
||||
though it is still too slow to get out of Playground.
|
||||
|
||||
- Graphical User Interface:
|
||||
|
||||
- Various improvements to window management:
|
||||
|
||||
- Keep-Above windows are set with the Utility hint.
|
||||
- Utility windows are not made transient to a parent.
|
||||
- Transient factory dialogs follow the active display,
|
||||
ensuring that new image windows would not hide your toolbox
|
||||
and dock windows.
|
||||
|
||||
- Various CSS improvements for styling of the interface. Some
|
||||
theme leaks were also fixed.
|
||||
- New toggle button in Brushes and Fonts dockable, allowing
|
||||
brush and font previews to optionally follow the color theme.
|
||||
For instance, when using a dark theme, the brush and font
|
||||
previews could be drawn on the theme background, using the
|
||||
theme foreground colors. By default, these data previews are
|
||||
still drawn as black on white.
|
||||
- Palette grid is now drawn with the theme's background color.
|
||||
- Consistent naming patterns on human-facing options (first
|
||||
word only capitalized).
|
||||
- About dialog:
|
||||
|
||||
- We will now display the date and time of the last check in
|
||||
a "Up to date as of <date> at <time>" string, differing
|
||||
from the "Last checked on <date> at <time>" string. The
|
||||
former will be used to indicate that GIMP is indeed
|
||||
up-to-date whereas the latter when a new version was
|
||||
released and that you should update.
|
||||
- We now respect the system time/date format on macOS and
|
||||
Windows.
|
||||
|
||||
- The search popup won't pop up without an image.
|
||||
- Better zoom step algorithm for data previews in container
|
||||
popup (e.g. the brush popup in paint Tool Options).
|
||||
- Disable animation in the Input Controller, Preferences and
|
||||
Welcome dialogs for stack transition when animation are
|
||||
disabled in system settings.
|
||||
- Fixed crosshair hotspot on Windows (crosshair cursor for
|
||||
brushes was offset with a non-100% display scale factor).
|
||||
- Debug/CRITICAL dialog:
|
||||
|
||||
- Make sure it is non-modal.
|
||||
- Follow the theme mode under Windows.
|
||||
|
||||
- While loading images, all widgets in the file dialog are made
|
||||
insensitive, except for the Cancel button and the progress
|
||||
bar.
|
||||
- Both grid and list views can now zoom via scroll and zoom
|
||||
gestures (it used to only work in list views).
|
||||
- Pop an error message up on startup when GIO modules to read
|
||||
HTTPS links are not found and that we therefore fail to load
|
||||
the remote gimp_versions.json file. With the AppImage package
|
||||
in particular, we depend on an environment daemon which
|
||||
cannot be shipped in the package. So the next best thing is
|
||||
to warn people and tell them what they should install to get
|
||||
version checks.
|
||||
- Welcome dialog:
|
||||
|
||||
- The "Community Tutorials" link is now shown after the
|
||||
"Documentation" link.
|
||||
- The "Learn more" link in Release Notes tab leads to the
|
||||
actual release news for this version.
|
||||
|
||||
- Plug-ins:
|
||||
|
||||
- PDF export: do not draw disabled layer masks.
|
||||
- Jigsaw: the plug-in can now draw on transparent layers.
|
||||
- Various file format fixes and improvements: JPEG 2000 import,
|
||||
TIFF import, DDS import, SVG import, PSP import, FITS export,
|
||||
ICNS import, Dicom import, WBMP import, Farbfeld import, XWD
|
||||
import, ILBM import.
|
||||
- Sphere Designer: use spin scale instead of spin entries (the
|
||||
latter is unusable with little horizontal space).
|
||||
- Animation Play: frames are shown again in the playback
|
||||
progress bar.
|
||||
- Vala Goat Exercise: ignoring C warning in this Vala plug-in
|
||||
as it is generated code and we cannot control it.
|
||||
- file-gih: brush pipe selection modes now have nice,
|
||||
translatable names.
|
||||
- Metadata viewer: port from GtkTreeView to GtkListBox.
|
||||
- File Raw Data: reduce Raw Data load dialogue height by moving
|
||||
to a 2-column layout.
|
||||
- SVG import: it is now possible to break aspect ratio with
|
||||
specific width/height arguments, when calling the PDB
|
||||
procedure non-interactively (from other plug-ins).
|
||||
- Print: when run through a portal print dialog, the "Image
|
||||
Settings" will be exposed as a secondary dialog, outputted
|
||||
after the portal dialog, instead of a tab on the main print
|
||||
dialog (because it is not possible to tweak the print dialog
|
||||
when it is created by a portal). This will bring back usable
|
||||
workflow of printing with GIMP when run in a sandbox (e.g.
|
||||
Flatpak or Snap).
|
||||
- Recompose: fixed for YCbCr decomposed images.
|
||||
- Fixed vulnerabilities: ZDI-CAN-27684, ZDI-CAN-27863,
|
||||
ZDI-CAN-27878, ZDI-CAN-27836, ZDI-CAN-27823, ZDI-CAN-27793.
|
||||
- C Source and HTML export can now be run non-interactively too
|
||||
(e.g. from other plug-ins).
|
||||
- Map Object: fix missing spin boxes.
|
||||
- Small Tiles: fix display lag.
|
||||
|
||||
- CVE-2025-10925: Fix GIMP ILBM file parsing stack-based buffer overflow remote code
|
||||
execution vulnerability. (ZDI-25-914, ZDI-CAN-27793, bsc#1250501)
|
||||
|
||||
- CVE-2025-10922: Fix GIMP DCM file parsing heap-based buffer overflow remote code
|
||||
execution vulnerability. (ZDI-25-911, ZDI-CAN-27863, bsc#1250497)
|
||||
|
||||
- CVE-2025-10920: Prevent overflow attack by checking if output >= max, not just
|
||||
output > max. (ZDI-25-909, ZDI-CAN-27684, bsc#1250495)
|
||||
|
||||
- CVE-2025-10924: Fix integer overflow while parsing FF files. (bsc#1250499)
|
||||
|
||||
- CVE-2025-2760: A vulnerability allows remote attackers to execute arbitrary
|
||||
code on affected installations of GIMP. The specific flaw exists
|
||||
within parsing of XWD files. An integer overflow happens before
|
||||
allocating a buffer. This fixed in GIMP 3.0.0.
|
||||
https://www.gimp.org/news/2025/03/16/gimp-3-0-released
|
||||
(bsc#1241690)
|
||||
</description>
|
||||
<package>gimp</package>
|
||||
</patchinfo>
|
||||
14
patchinfo.20251117132509463589.187004354831441/_patchinfo
Normal file
14
patchinfo.20251117132509463589.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,14 @@
|
||||
<patchinfo incident="packagehub-49">
|
||||
<packager>okurz</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for perl-Mojolicious-Plugin-Webpack</summary>
|
||||
<description>This update for perl-Mojolicious-Plugin-Webpack fixes the following issues:
|
||||
|
||||
Changes in perl-Mojolicious-Plugin-Webpack:
|
||||
|
||||
- See https://github.com/jhthorsen/mojolicious-plugin-webpack/pull/17
|
||||
</description>
|
||||
<package>perl-Mojolicious-Plugin-Webpack</package>
|
||||
|
||||
</patchinfo>
|
||||
62
patchinfo.20251126120323268597.93181000773252/_patchinfo
Normal file
62
patchinfo.20251126120323268597.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,62 @@
|
||||
<patchinfo incident="packagehub-37">
|
||||
<issue tracker="cve" id="2025-46817">cve#2025-46817 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-46817</issue>
|
||||
<issue tracker="cve" id="2025-62507">cve#2025-62507 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-62507</issue>
|
||||
<issue tracker="cve" id="2025-49844">cve#2025-49844 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-49844</issue>
|
||||
<issue tracker="cve" id="2025-46818">cve#2025-46818 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-46818</issue>
|
||||
<issue tracker="bnc" id="1250995">VUL-0: CVE-2025-49844,CVE-2025-46817,CVE-2025-46818,CVE-2025-46819: valkey,redis,redis7: multiple LUA issues</issue>
|
||||
<issue tracker="bnc" id="1252996">VUL-0: CVE-2025-62507: redis,redis7,valkey: XACKDEL - potential stack overflow and RCE</issue>
|
||||
<issue tracker="cve" id="2025-46819">cve#2025-46819 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-46819</issue>
|
||||
<packager>ateixeira</packager>
|
||||
<rating>critical</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for redis</summary>
|
||||
<description>This update for redis fixes the following issues:
|
||||
|
||||
- Updated to 8.2.3 (boo#1252996 CVE-2025-62507)
|
||||
* https://github.com/redis/redis/releases/tag/8.2.3
|
||||
- Security fixes
|
||||
- (CVE-2025-62507) Bug in `XACKDEL` may lead to stack overflow
|
||||
and potential RCE
|
||||
- Bug fixes
|
||||
- `HGETEX`: A missing `numfields` argument when `FIELDS` is
|
||||
used can lead to Redis crash
|
||||
- An overflow in `HyperLogLog` with 2GB+ entries may result in
|
||||
a Redis crash
|
||||
- Cuckoo filter - Division by zero in Cuckoo filter insertion
|
||||
- Cuckoo filter - Counter overflow
|
||||
- Bloom filter - Arbitrary memory read/write with invalid
|
||||
filter
|
||||
- Bloom filter - Out-of-bounds access with empty chain
|
||||
- Top-k - Out-of-bounds access
|
||||
- Bloom filter - Restore invalid filter [We thank AWS security
|
||||
for responsibly disclosing the security bug]
|
||||
|
||||
- Updated to 8.2.2 (boo#1250995)
|
||||
* https://github.com/redis/redis/releases/tag/8.2.2
|
||||
* Fixed Lua script may lead to remote code execution (CVE-2025-49844).
|
||||
* Fixed Lua script may lead to integer overflow (CVE-2025-46817).
|
||||
* Fixed Lua script can be executed in the context of another user
|
||||
(CVE-2025-46818).
|
||||
* Fixed LUA out-of-bound read (CVE-2025-46819).
|
||||
* Fixed potential crash on Lua script or streams and HFE defrag.
|
||||
* Fixed potential crash when using ACL rules.
|
||||
* Added VSIM: new EPSILON argument to specify maximum distance.
|
||||
* Added SVS-VAMANA: allow use of BUILD_INTEL_SVS_OPT flag.
|
||||
* Added RESP3 serialization performance.
|
||||
* Added INFO SEARCH: new SVS-VAMANA metrics.
|
||||
|
||||
- Updated to 8.2.1
|
||||
* https://github.com/redis/redis/releases/tag/8.2.1
|
||||
- Bug fixes
|
||||
* #14240 INFO KEYSIZES - potential incorrect histogram updates
|
||||
on cluster mode with modules
|
||||
* #14274 Disable Active Defrag during flushing replica
|
||||
* #14276 XADD or XTRIM can crash the server after loading RDB
|
||||
* #Q6601 Potential crash when running FLUSHDB (MOD-10681)
|
||||
* Performance and resource utilization
|
||||
* Query Engine - LeanVec and LVQ proprietary Intel
|
||||
optimizations were removed from Redis Open Source
|
||||
* #Q6621 Fix regression in INFO (MOD-10779)
|
||||
</description>
|
||||
<package>redis</package>
|
||||
</patchinfo>
|
||||
13
patchinfo.20251127113212085239.93181000773252/_patchinfo
Normal file
13
patchinfo.20251127113212085239.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,13 @@
|
||||
<patchinfo incident="packagehub-40">
|
||||
<issue tracker="cve" id="2025-61659"/>
|
||||
<issue tracker="bnc" id="1247489">VUL-0: CVE-2025-61659: bash-git-prompt: uses predictable file in /tmp for a copy of the git index</issue>
|
||||
<packager>michals</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for bash-git-prompt</summary>
|
||||
<description>This update for bash-git-prompt fixes the following issues:
|
||||
|
||||
- CVE-2025-61659: Fixed an issue where predictable files in /tmp were used for a copy of the git index (bsc#1247489)
|
||||
</description>
|
||||
<package>bash-git-prompt</package>
|
||||
</patchinfo>
|
||||
65
patchinfo.20251127122850445245.93181000773252/_patchinfo
Normal file
65
patchinfo.20251127122850445245.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,65 @@
|
||||
<patchinfo incident="packagehub-38">
|
||||
<issue tracker="bnc" id="1243954">VUL-0: CVE-2025-29785: shadowsocks-v2ray-plugin: github.com/quic-go/quic-go/internal/ackhandler: loss recovery logic for path probe packets can be used by a malicious QUIC client to trigger a null pointer dereference</issue>
|
||||
<issue tracker="cve" id="2025-47911">cve#2025-47911 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-47911</issue>
|
||||
<issue tracker="bnc" id="1243946">VUL-0: CVE-2025-29785: v2ray-core: github.com/quic-go/quic-go/internal/ackhandler: loss recovery logic for path probe packets can be used by a malicious QUIC client to trigger a null pointer dereference</issue>
|
||||
<issue tracker="cve" id="2025-297850">cve#2025-297850 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-297850</issue>
|
||||
<issue tracker="bnc" id="1251404">VUL-0: CVE-2025-47911: v2ray-core: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<issue tracker="bnc" id="1235164">VUL-0: CVE-2023-49295: v2ray-core: github.com/quic-go/quic-go: memory exhaustion attack against QUIC's path validation mechanism</issue>
|
||||
<packager>hillwood</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for shadowsocks-v2ray-plugin, v2ray-core</summary>
|
||||
<description>This update for shadowsocks-v2ray-plugin, v2ray-core fixes the following issues:
|
||||
|
||||
Changes in shadowsocks-v2ray-plugin:
|
||||
|
||||
- Update version to 5.25.0
|
||||
* Update v2ray-core to v5.25.0
|
||||
- Add update-vendor.patch, update v2ray-core to v5.33.0 (boo#1243954 and CVE-2025-297850)
|
||||
|
||||
Changes in v2ray-core:
|
||||
|
||||
- Fix CVE-2025-47911 and boo#1251404
|
||||
* Add fix-CVE-2025-47911.patch
|
||||
* Update golang.org/x/net to 0.45.0 in vendor
|
||||
|
||||
- Update version to 5.38.0
|
||||
* TLSMirror Connection Enrollment System
|
||||
* Add TLSMirror Sequence Watermarking
|
||||
* LSMirror developer preview protocol is now a part of mainline V2Ray
|
||||
* proxy dns with NOTIMP error
|
||||
* Add TLSMirror looks like TLS censorship resistant transport protocol
|
||||
as a developer preview transport
|
||||
* proxy dns with NOTIMP error
|
||||
* fix false success from SOCKS server when Dispatch() fails
|
||||
* HTTP inbound: Directly forward plain HTTP 1xx response header
|
||||
* add a option to override domain used to query https record
|
||||
* Fix bugs
|
||||
* Update vendor
|
||||
|
||||
- Update version to 5.33.0
|
||||
* bump github.com/quic-go/quic-go from 0.51.0 to 0.52.0(boo#1243946 and CVE-2025-297850)
|
||||
* Update other vendor source
|
||||
|
||||
- Update version to 5.31.0
|
||||
* Add Dns Proxy Response TTL Control
|
||||
* Fix call newError Base with a nil value error
|
||||
* Update vendor (boo#1235164)
|
||||
|
||||
- Update version to 5.29.3
|
||||
* Enable restricted mode load for http protocol client
|
||||
* Correctly implement QUIC sniffer when handling multiple initial packets
|
||||
* Fix unreleased cache buffer in QUIC sniffing
|
||||
* A temporary testing fix for the buffer corruption issue
|
||||
* QUIC Sniffer Restructure
|
||||
|
||||
- Update version to 5.22.0
|
||||
* Add packetEncoding for Hysteria
|
||||
* Add ECH Client Support
|
||||
* Add support for parsing some shadowsocks links
|
||||
* Add Mekya Transport
|
||||
* Fix bugs
|
||||
</description>
|
||||
<package>shadowsocks-v2ray-plugin</package>
|
||||
<package>v2ray-core</package>
|
||||
</patchinfo>
|
||||
90
patchinfo.20251127153254678434.93181000773252/_patchinfo
Normal file
90
patchinfo.20251127153254678434.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,90 @@
|
||||
<patchinfo incident="packagehub-39">
|
||||
<packager>os-autoinst-obs-workflow</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for openQA, os-autoinst, openQA-devel-container</summary>
|
||||
<description>This update for openQA, os-autoinst, openQA-devel-container fixes the following issues:
|
||||
|
||||
Changes in openQA:
|
||||
|
||||
- Update to version 5.1763743683.1da97aa2:
|
||||
* Optimize Job Group dropdown database query
|
||||
* Split dependency handling out of create_from_settings
|
||||
* Give jobs with high MAX_JOB_TIME a priority malus
|
||||
* Make the number of builds per group on the front page configurable
|
||||
* docs: Feature auto-generated deepwiki less prominently
|
||||
* apparmor: Additional perms for tests in osado to run
|
||||
|
||||
- Update to version 5.1763153079.b36ac754:
|
||||
* Skip a build if there are no jobs
|
||||
* Remove unused variable
|
||||
|
||||
- Update to version 5.1762879267.52145e9a:
|
||||
* Avoid installing unwanted package versions
|
||||
* Fix check in git_clone for dirty git dir
|
||||
* Prevent `t/24-worker-webui-connection.t` from running into timeout
|
||||
* Be explicit about certain aspects of archiving in the documentation
|
||||
* Fix sporadic failures in `t/ui/10-tests_overview.t`
|
||||
* Adapt os-autoinst-scripts reference after rename
|
||||
* Properly conclude scheduling if there are no jobs
|
||||
|
||||
- Update to version 5.1762193001.2f6e71ca:
|
||||
* Potentially improve stability of `t/ui/16-tests_job_next_previous.t`
|
||||
* Avoid failing check in `t/16-utils-runcmd.t`
|
||||
* README: Add deepwiki badge
|
||||
* Dependency cron 2025-10-27
|
||||
* Retry image optimizations
|
||||
|
||||
Changes in os-autoinst:
|
||||
|
||||
- Update to version 5.1763561851.03e049d:
|
||||
* Avoid `Can't exec "ffmpeg"` if ffmpeg isn't present
|
||||
* Fix syntax errors in nft due to multiple interfaces in $ethernet
|
||||
* README: Feature auto-generated deepwiki less prominently
|
||||
* Install NetworkManager-ovs in os-autoinst-setup-multi-machine
|
||||
* Add disconnect_usb (qemu only, for now)
|
||||
|
||||
- Update to version 5.1763048144.30f43a0:
|
||||
* Configure ftables in os-autoinst-setup-multi-machine
|
||||
* Makefile: Fix reruns on incomplete build dir generations
|
||||
* Propagate C++ exceptions to Perl in image write function
|
||||
* Add support NICPCIADDR variable to QEMU backend
|
||||
* Remove test which causes unhandled output
|
||||
* Improve includes in tinycv library
|
||||
* Handle OpenCV exceptions when writing an image
|
||||
* Avoid ignoring errors silently when writing images
|
||||
* Avoid saving test results referring to non-existent screenshots
|
||||
|
||||
- Update to version 5.1762250353.5150272:
|
||||
* Makefile: Fix reruns on incomplete build dir generations
|
||||
* Propagate C++ exceptions to Perl in image write function
|
||||
* Add support NICPCIADDR variable to QEMU backend
|
||||
* Remove test which causes unhandled output
|
||||
* Allow array keys like `ISSUES[]` as introduced in openQA commit a53b19b
|
||||
* Improve includes in tinycv library
|
||||
|
||||
- Update to version 5.1761723693.2b88807:
|
||||
* Propagate C++ exceptions to Perl in image write function
|
||||
* Add support NICPCIADDR variable to QEMU backend
|
||||
* Remove test which causes unhandled output
|
||||
* Allow array keys like `ISSUES[]` as introduced in openQA commit a53b19b
|
||||
* Improve includes in tinycv library
|
||||
* Handle OpenCV exceptions when writing an image
|
||||
* Avoid ignoring errors silently when writing images
|
||||
|
||||
Changes in openQA-devel-container:
|
||||
|
||||
- Update to version 5.1763743683.1da97aa28:
|
||||
* Update to latest openQA version
|
||||
</description>
|
||||
<package>openQA</package>
|
||||
<package>openQA:openQA-devel-test</package>
|
||||
<package>openQA:openQA-test</package>
|
||||
<package>openQA:openQA-worker-test</package>
|
||||
<package>openQA:openQA-client-test</package>
|
||||
<package>os-autoinst</package>
|
||||
<package>os-autoinst:os-autoinst-test</package>
|
||||
<package>os-autoinst:os-autoinst-devel-test</package>
|
||||
<package>os-autoinst:os-autoinst-openvswitch-test</package>
|
||||
<package>openQA-devel-container</package>
|
||||
</patchinfo>
|
||||
15
patchinfo.20251201094854511762.93181000773252/_patchinfo
Normal file
15
patchinfo.20251201094854511762.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,15 @@
|
||||
<patchinfo incident="packagehub-41">
|
||||
<issue tracker="bnc" id="1253608">VUL-0: CVE-2025-47913: act: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request</issue>
|
||||
<issue tracker="cve" id="2025-47913">cve#2025-47913 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-47913</issue>
|
||||
<packager>elimat</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for act</summary>
|
||||
<description>This update for act fixes the following issues:
|
||||
|
||||
- CVE-2025-47913: Prevent panic in embedded golang.org/x/crypto/ssh/agent client when
|
||||
receiving unexpected message types for key listing or signing requests (boo#1253608)
|
||||
</description>
|
||||
<package>act</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
209
patchinfo.20251201094954024941.93181000773252/_patchinfo
Normal file
209
patchinfo.20251201094954024941.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,209 @@
|
||||
<patchinfo incident="packagehub-54">
|
||||
<issue tracker="bnc" id="1251651">VUL-0: CVE-2025-58190: hauler: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input</issue>
|
||||
<issue tracker="cve" id="2025-22872">cve#2025-22872 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-22872</issue>
|
||||
<issue tracker="cve" id="2025-58058">cve#2025-58058 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-58058</issue>
|
||||
<issue tracker="cve" id="2024-45338">cve#2024-45338 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2024-45338</issue>
|
||||
<issue tracker="bnc" id="1241184">VUL-0: CVE-2024-0406: hauler: mholt/archiver: access to restricted files or directories when unpacking specially crafted tar file</issue>
|
||||
<issue tracker="bnc" id="1235332">VUL-0: CVE-2024-45338: hauler: golang.org/x/net/html: denial of service due to non-linear parsing of case-insensitive content</issue>
|
||||
<issue tracker="cve" id="2025-11579">cve#2025-11579 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-11579</issue>
|
||||
<issue tracker="cve" id="2024-0406">cve#2024-0406 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2024-0406</issue>
|
||||
<issue tracker="cve" id="2025-47911">cve#2025-47911 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-47911</issue>
|
||||
<issue tracker="cve" id="2025-46569">cve#2025-46569 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-46569</issue>
|
||||
<issue tracker="bnc" id="1246722">VUL-0: CVE-2025-46569: hauler: github.com/open-policy-agent/opa: HTTP request path can be crafted to inject Rego code into a constructed query when a virtual document is requested through the Data API</issue>
|
||||
<issue tracker="bnc" id="1248937">VUL-0: CVE-2025-58058: hauler: github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory</issue>
|
||||
<issue tracker="bnc" id="1241804">VUL-0: CVE-2025-22872: hauler: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction</issue>
|
||||
<issue tracker="bnc" id="1251516">VUL-0: CVE-2025-47911: hauler: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<issue tracker="cve" id="2025-58190">cve#2025-58190 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-58190</issue>
|
||||
<issue tracker="bnc" id="1251891">VUL-0: CVE-2025-11579: hauler: github.com/nwaples/rardecode: failure to restrict the dictionary size when processing RAR files allows for excessive memory consumpti</issue>
|
||||
<packager>dirkmueller</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for hauler</summary>
|
||||
<description>This update for hauler fixes the following issues:
|
||||
|
||||
- Update to version 1.3.1 (bsc#1251516, CVE-2025-47911,
|
||||
bsc#1251891, CVE-2025-11579, bsc#1251651, CVE-2025-58190,
|
||||
bsc#1248937, CVE-2025-58058):
|
||||
* bump github.com/containerd/containerd (#474)
|
||||
* another fix to tests for new tests (#472)
|
||||
* fixed typo in testdata (#471)
|
||||
* fixed/cleaned new tests (#470)
|
||||
* trying a new way for hauler testing (#467)
|
||||
* update for cosign v3 verify (#469)
|
||||
* added digests view to info (#465)
|
||||
* bump github.com/nwaples/rardecode/v2 from 2.1.1 to 2.2.0 in the go_modules group across 1 directory (#457)
|
||||
* update oras-go to v1.2.7 for security patches (#464)
|
||||
* update cosign to v3.0.2+hauler.1 (#463)
|
||||
* fixed homebrew directory deprecation (#462)
|
||||
* add registry logout command (#460)
|
||||
|
||||
- Update to version 1.3.0:
|
||||
* bump the go_modules group across 1 directory with 2 updates (#455)
|
||||
* upgraded versions/dependencies/deprecations (#454)
|
||||
* allow loading of docker tarballs (#452)
|
||||
* bump the go_modules group across 1 directory with 2 updates (#449)
|
||||
|
||||
- update to 1.2.5 (bsc#1246722, CVE-2025-46569):
|
||||
* Bump github.com/open-policy-agent/opa from 1.1.0 to 1.4.0 in
|
||||
the go_modules group across 1 directory (CVE-2025-46569)
|
||||
* deprecate auth from hauler store copy
|
||||
* Bump github.com/cloudflare/circl from 1.3.7 to 1.6.1 in the
|
||||
go_modules group across 1 directory
|
||||
* Bump github.com/go-viper/mapstructure/v2 from 2.2.1 to 2.3.0
|
||||
in the go_modules group across 1 directory
|
||||
* upgraded go and dependencies versions
|
||||
|
||||
- Update to version 1.2.5:
|
||||
* upgraded go and dependencies versions (#444)
|
||||
* Bump github.com/go-viper/mapstructure/v2 (#442)
|
||||
* bump github.com/cloudflare/circl (#441)
|
||||
* deprecate auth from hauler store copy (#440)
|
||||
* Bump github.com/open-policy-agent/opa (#438)
|
||||
|
||||
- update to 1.2.4 (CVE-2025-22872, bsc#1241804):
|
||||
* Bump golang.org/x/net from 0.37.0 to 0.38.0 in the go_modules
|
||||
group across 1 directory
|
||||
* minor tests updates
|
||||
|
||||
- Update to version 1.2.3:
|
||||
* formatting and flag text updates
|
||||
* add keyless signature verification (#434)
|
||||
* bump helm.sh/helm/v3 in the go_modules group across 1 directory (#430)
|
||||
* add --only flag to hauler store copy (for images) (#429)
|
||||
* fix tlog verification error/warning output (#428)
|
||||
|
||||
- Update to version 1.2.2 (bsc#1241184, CVE-2024-0406):
|
||||
* cleanup new tlog flag typos and add shorthand (#426)
|
||||
* default public transparency log verification to false to be airgap friendly but allow override (#425)
|
||||
* bump github.com/golang-jwt/jwt/v4 (#423)
|
||||
* bump the go_modules group across 1 directory with 2 updates (#422)
|
||||
* bump github.com/go-jose/go-jose/v3 (#417)
|
||||
* bump github.com/go-jose/go-jose/v4 (#415)
|
||||
* clear default manifest name if product flag used with sync (#412)
|
||||
* updates for v1.2.0 (#408)
|
||||
* fixed remote code (#407)
|
||||
* added remote file fetch to load (#406)
|
||||
* added remote and multiple file fetch to sync (#405)
|
||||
* updated save flag and related logs (#404)
|
||||
* updated load flag and related logs [breaking change] (#403)
|
||||
* updated sync flag and related logs [breaking change] (#402)
|
||||
* upgraded api update to v1/updated dependencies (#400)
|
||||
* fixed consts for oci declarations (#398)
|
||||
* fix for correctly grabbing platform post cosign 2.4 updates (#393)
|
||||
* use cosign v2.4.1+carbide.2 to address containerd annotation in index.json (#390)
|
||||
* Bump the go_modules group across 1 directory with 2 updates (#385)
|
||||
* replace mholt/archiver with mholt/archives (#384)
|
||||
* forked cosign bump to 2.4.1 and use as a library vs embedded binary (#383)
|
||||
* cleaned up registry and improved logging (#378)
|
||||
* Bump golang.org/x/crypto in the go_modules group across 1 directory (#377)
|
||||
- bump net/html dependencies (bsc#1235332, CVE-2024-45338)
|
||||
|
||||
- Update to version 1.1.1:
|
||||
* fixed cli desc for store env var (#374)
|
||||
* updated versions for go/k8s/helm (#373)
|
||||
* updated version flag to internal/flags (#369)
|
||||
* renamed incorrectly named consts (#371)
|
||||
* added store env var (#370)
|
||||
* adding ignore errors and retries for continue on error/fail on error (#368)
|
||||
* updated/fixed hauler directory (#354)
|
||||
* standardize consts (#353)
|
||||
* removed cachedir code (#355)
|
||||
* removed k3s code (#352)
|
||||
* updated dependencies for go, helm, and k8s (#351)
|
||||
* [feature] build with boring crypto where available (#344)
|
||||
* updated workflow to goreleaser builds (#341)
|
||||
* added timeout to goreleaser workflow (#340)
|
||||
* trying new workflow build processes (#337)
|
||||
* improved workflow performance (#336)
|
||||
* have extract use proper ref (#335)
|
||||
* yet another workflow goreleaser fix (#334)
|
||||
* even more workflow fixes (#333)
|
||||
* added more fixes to github workflow (#332)
|
||||
* fixed typo in hauler store save (#331)
|
||||
* updates to fix build processes (#330)
|
||||
* added integration tests for non hauler tarballs (#325)
|
||||
* bump: golang >= 1.23.1 (#328)
|
||||
* add platform flag to store save (#329)
|
||||
* Update feature_request.md
|
||||
* updated/standardize command descriptions (#313)
|
||||
* use new annotation for 'store save' manifest.json (#324)
|
||||
* enable docker load for hauler tarballs (#320)
|
||||
* bump to cosign v2.2.3-carbide.3 for new annotation (#322)
|
||||
* continue on error when adding images to store (#317)
|
||||
* Update README.md (#318)
|
||||
* fixed completion commands (#312)
|
||||
* github.com/rancherfederal/hauler => hauler.dev/go/hauler (#311)
|
||||
* pages: enable go install hauler.dev/go/hauler (#310)
|
||||
* Create CNAME
|
||||
* pages: initial workflow (#309)
|
||||
* testing and linting updates (#305)
|
||||
* feat-273: TLS Flags (#303)
|
||||
* added list-repos flag (#298)
|
||||
* fixed hauler login typo (#299)
|
||||
* updated cobra function for shell completion (#304)
|
||||
* updated install.sh to remove github api (#293)
|
||||
* fix image ref keys getting squashed when containing sigs/atts (#291)
|
||||
* fix missing versin info in release build (#283)
|
||||
* bump github.com/docker/docker in the go_modules group across 1 directory (#281)
|
||||
* updated install script (`install.sh`) (#280)
|
||||
* fix digest images being lost on load of hauls (Signed). (#259)
|
||||
* feat: add readonly flag (#277)
|
||||
* fixed makefile for goreleaser v2 changes (#278)
|
||||
* updated goreleaser versioning defaults (#279)
|
||||
* update feature_request.md (#274)
|
||||
* updated old references
|
||||
* updated actions workflow user
|
||||
* added dockerhub to github actions workflow
|
||||
* removed helm chart
|
||||
* added debug container and workflow
|
||||
* updated products flag description
|
||||
* updated chart for release
|
||||
* fixed workflow errors/warnings
|
||||
* fixed permissions on testdata
|
||||
* updated chart versions (will need to update again)
|
||||
* last bit of fixes to workflow
|
||||
* updated unit test workflow
|
||||
* updated goreleaser deprecations
|
||||
* added helm chart release job
|
||||
* updated github template names
|
||||
* updated imports (and go fmt)
|
||||
* formatted gitignore to match dockerignore
|
||||
* formatted all code (go fmt)
|
||||
* updated chart tests for new features
|
||||
* Adding the timeout flag for fileserver command
|
||||
* Configure chart commands to use helm clients for OCI and private registry support
|
||||
* Added some documentation text to sync command
|
||||
* Bump golang.org/x/net from 0.17.0 to 0.23.0
|
||||
* fix for dup digest smashing in cosign
|
||||
* removed vagrant scripts
|
||||
* last bit of updates and formatting of chart
|
||||
* updated hauler testdata
|
||||
* adding functionality and cleaning up
|
||||
* added initial helm chart
|
||||
* removed tag in release workflow
|
||||
* updated/fixed image ref in release workflow
|
||||
* updated/fixed platforms in release workflow
|
||||
* updated/cleaned github actions (#222)
|
||||
* Make Product Registry configurable (#194)
|
||||
* updated fileserver directory name (#219)
|
||||
* fix logging for files
|
||||
* add extra info for the tempdir override flag
|
||||
* tempdir override flag for load
|
||||
* deprecate the cache flag instead of remove
|
||||
* switch to using bci-golang as builder image
|
||||
* fix: ensure /tmp for hauler store load
|
||||
* added the copy back for now
|
||||
* remove copy at the image sync not needed with cosign update
|
||||
* removed misleading cache flag
|
||||
* better logging when adding to store
|
||||
* update to v2.2.3 of our cosign fork
|
||||
* add: dockerignore
|
||||
* add: Dockerfile
|
||||
* Bump google.golang.org/protobuf from 1.31.0 to 1.33.0
|
||||
* Bump github.com/docker/docker
|
||||
* updated and added new logos
|
||||
* updated github files
|
||||
</description>
|
||||
<package>hauler</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
56
patchinfo.20251201095419906173.93181000773252/_patchinfo
Normal file
56
patchinfo.20251201095419906173.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,56 @@
|
||||
<patchinfo incident="packagehub-42">
|
||||
<packager>os-autoinst-obs-workflow</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for openQA, os-autoinst, openQA-devel-container</summary>
|
||||
<description>This update for openQA, os-autoinst, openQA-devel-container fixes the following issues:
|
||||
|
||||
Changes in openQA:
|
||||
|
||||
- Update to version 5.1764349525.ffb59486:
|
||||
* Also use TIMEOUT_SCALE for priority malus calculation
|
||||
* docs: Fix wrapping and typo
|
||||
* Document multi machine ovs flow setup and IPv6 usage
|
||||
* Avoid computing time constraint for scheduled product cleanup in Perl
|
||||
* rpm: Move `…-enqueue-needle-ref-cleanup` to other `…-enqueue-…` scripts
|
||||
* Add task to limit scheduled products similar to audit events
|
||||
* Extract generic parts from audit event cleanup task into generic task
|
||||
* parser: ktap: Show full output by default if no line was parsed
|
||||
* Ignore npm scripts also via `.npmrc` to make bare npm calls more secure
|
||||
* Avoid repeating `MAIN_SETTINGS` in various places
|
||||
* Fix possibly excessive memory use when computer test result overview
|
||||
* Fix typo in `_prepare_complex_query_search_args`
|
||||
* Fix indentation in `overview.html.ep`
|
||||
* Prevent logging AMQP credentials in debug output
|
||||
* Make restart_openqa_job emit proper event payload
|
||||
* Enable gru tasks to emit AMQP messages
|
||||
* Remove explicit loading AMQP plugin in Gru plugin
|
||||
* Emit restart events when job restarted automatically
|
||||
* Add debug message about priority malus
|
||||
* Fix ordering of job groups after 2ad929ceca43d
|
||||
|
||||
Changes in os-autoinst:
|
||||
|
||||
- Update to version 5.1764330105.c5cfd48:
|
||||
* Add port forwarding example for NICTYPE_USER_OPTIONS
|
||||
* Fix regression from abcaa66b by disabling virtio-keyboard by default
|
||||
* Add IPv6 support for multi machine tests
|
||||
* distribution: Add "disable_key_repeat"
|
||||
* Use 'virtio-keyboard' by default to allow fixing key repetition errors
|
||||
|
||||
Changes in openQA-devel-container:
|
||||
|
||||
- Update to version 5.1764349525.ffb594867:
|
||||
</description>
|
||||
<package>openQA</package>
|
||||
<package>openQA:openQA-devel-test</package>
|
||||
<package>openQA:openQA-test</package>
|
||||
<package>openQA:openQA-worker-test</package>
|
||||
<package>openQA:openQA-client-test</package>
|
||||
<package>os-autoinst</package>
|
||||
<package>os-autoinst:os-autoinst-test</package>
|
||||
<package>os-autoinst:os-autoinst-devel-test</package>
|
||||
<package>os-autoinst:os-autoinst-openvswitch-test</package>
|
||||
<package>openQA-devel-container</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
43
patchinfo.20251203090122170457.187004354831441/_patchinfo
Normal file
43
patchinfo.20251203090122170457.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,43 @@
|
||||
<patchinfo incident="packagehub-43">
|
||||
<issue tracker="bnc" id="1254429">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13632">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13636">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13720">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13721">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13637">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13639">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13640">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13635">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13633">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13638">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13630">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13634">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<issue tracker="cve" id="2025-13631">VUL-0: chromium: release 143.0.7499.40):</issue>
|
||||
<packager>AndreasStieger</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for chromium</summary>
|
||||
<description>This update for chromium fixes the following issues:
|
||||
|
||||
Changes in chromium:
|
||||
|
||||
Chromium 143.0.7499.40 (boo#1254429):
|
||||
|
||||
* CVE-2025-13630: Type Confusion in V8
|
||||
* CVE-2025-13631: Inappropriate implementation in Google Updater
|
||||
* CVE-2025-13632: Inappropriate implementation in DevTools
|
||||
* CVE-2025-13633: Use after free in Digital Credentials
|
||||
* CVE-2025-13634: Inappropriate implementation in Downloads
|
||||
* CVE-2025-13720: Bad cast in Loader
|
||||
* CVE-2025-13721: Race in v8
|
||||
* CVE-2025-13635: Inappropriate implementation in Downloads
|
||||
* CVE-2025-13636: Inappropriate implementation in Split View
|
||||
* CVE-2025-13637: Inappropriate implementation in Downloads
|
||||
* CVE-2025-13638: Use after free in Media Stream
|
||||
* CVE-2025-13639: Inappropriate implementation in WebRTC
|
||||
* CVE-2025-13640: Inappropriate implementation in Passwords
|
||||
|
||||
</description>
|
||||
<package>chromium</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
43
patchinfo.20251203090149653113.187004354831441/_patchinfo
Normal file
43
patchinfo.20251203090149653113.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,43 @@
|
||||
<patchinfo incident="packagehub-44">
|
||||
<packager>michals</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for virtme</summary>
|
||||
<description>This update for virtme fixes the following issues:
|
||||
|
||||
Changes in virtme:
|
||||
|
||||
Update to 1.39:
|
||||
|
||||
* The most noticeable change in this release is the new Model Context
|
||||
Protocol (MCP) server. This feature lets you connect with AI
|
||||
assistants such as Claude, Cursor, etc., and use natural human
|
||||
language to automate kernel development tasks.
|
||||
In this way, AI agents can automatically configure kernels, apply
|
||||
patches from lore.kernel.org, and run commands within recompiled
|
||||
kernels. You can even have the AI agent perform bug bisection for
|
||||
you and run specific commands/scripts inside each recompiled
|
||||
version to determine whether the kernel is good or bad.
|
||||
* An additional feature is vCPU pinning (using the --pin CPU_LIST option),
|
||||
which enables binding virtual CPUs to particular physical host CPUs.
|
||||
This ensures more consistent performance testing within the vng guest
|
||||
environment.
|
||||
* The release also adds support for memoryless NUMA nodes,
|
||||
enablingusers to specify size=0 with the --numa argument to create
|
||||
NUMA nodes without memory. This capability can be useful for simulating
|
||||
heterogeneous architectures, where devices like GPUs are represented
|
||||
as memoryless NUMA nodes to model their CPU locality relationships.
|
||||
* Last, but not least, there's a new --shell BINARY option which lets
|
||||
users choose a different shell to use within the vng session, rather
|
||||
than using their system's default shell and a new --empty-password
|
||||
option that creates empty passwords in the vng guest, instead of
|
||||
blocking login for other users, enabling easier debugging and SSH
|
||||
access during testing.
|
||||
* Updated Python versions in CI (dropped EOL 3.8 and 3.9)
|
||||
* Various bug fixes in virtme-init
|
||||
* Enhanced documentation and README updates
|
||||
* Improved error handling and validation
|
||||
</description>
|
||||
<package>virtme</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
14
patchinfo.20251203090209179395.187004354831441/_patchinfo
Normal file
14
patchinfo.20251203090209179395.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,14 @@
|
||||
<patchinfo incident="packagehub-45">
|
||||
<packager>michals</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for gitea-tea</summary>
|
||||
<description>This update for gitea-tea fixes the following issues:
|
||||
|
||||
Changes in gitea-tea:
|
||||
|
||||
- Do not make config file group-readable.
|
||||
</description>
|
||||
<package>gitea-tea</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
106
patchinfo.20251203090227587250.187004354831441/_patchinfo
Normal file
106
patchinfo.20251203090227587250.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,106 @@
|
||||
<patchinfo incident="packagehub-46">
|
||||
<issue tracker="bnc" id="1253506">VUL-0: CVE-2025-47913: TRACKERBUG: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or</issue>
|
||||
<issue tracker="cve" id="2025-47913">VUL-0: CVE-2025-47913: TRACKERBUG: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or</issue>
|
||||
<issue tracker="bnc" id="1251463">VUL-0: CVE-2025-47911: git-bug: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<issue tracker="bnc" id="1254084">VUL-0: CVE-2025-47914: git-bug: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read</issue>
|
||||
<issue tracker="cve" id="2025-58190"/>
|
||||
<issue tracker="cve" id="2025-22869">VUL-0: CVE-2025-22869: TRACKERBUG: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh</issue>
|
||||
<issue tracker="bnc" id="1234565">VUL-0: CVE-2024-45337: git-bug: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto</issue>
|
||||
<issue tracker="cve" id="2025-47914">VUL-0: CVE-2025-47914: TRACKERBUG: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read</issue>
|
||||
<issue tracker="bnc" id="1251664">VUL-0: CVE-2025-58190: git-bug: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input</issue>
|
||||
<issue tracker="bnc" id="1239494">VUL-0: CVE-2025-22869: git-bug: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh</issue>
|
||||
<issue tracker="cve" id="2024-45337">VUL-0: CVE-2024-45337: TRACKERBUG: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto</issue>
|
||||
<issue tracker="cve" id="2025-47911">VUL-0: CVE-2025-47911: TRACKERBUG: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<issue tracker="cve" id="2025-58181">VUL-0: CVE-2025-58181: TRACKERBUG: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption</issue>
|
||||
<issue tracker="bnc" id="1253930">VUL-0: CVE-2025-58181: git-bug: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption</issue>
|
||||
<packager>mcepl</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for git-bug</summary>
|
||||
<description>This update for git-bug fixes the following issues:
|
||||
|
||||
Changes in git-bug:
|
||||
|
||||
- Revendor to include fixed version of depending libraries:
|
||||
- GO-2025-4116 (CVE-2025-47913, bsc#1253506) upgrade
|
||||
golang.org/x/crypto to v0.43.0
|
||||
- GO-2025-3900 (GHSA-2464-8j7c-4cjm) upgrade
|
||||
github.com/go-viper/mapstructure/v2 to v2.4.0
|
||||
- GO-2025-3787 (GHSA-fv92-fjc5-jj9h) included in the previous
|
||||
- GO-2025-3754 (GHSA-2x5j-vhc8-9cwm) upgrade
|
||||
github.com/cloudflare/circl to v1.6.1
|
||||
- GO-2025-4134 (CVE-2025-58181, bsc#1253930) upgrade
|
||||
golang.org/x/crypto/ssh to v0.45.0
|
||||
- GO-2025-4135 (CVE-2025-47914, bsc#1254084) upgrade
|
||||
golang.org/x/crypto/ssh/agent to v0.45.0
|
||||
|
||||
- Revendor to include golang.org/x/net/html v 0.45.0 to prevent
|
||||
possible DoS by various algorithms with quadratic complexity
|
||||
when parsing HTML documents (bsc#1251463, CVE-2025-47911 and
|
||||
bsc#1251664, CVE-2025-58190).
|
||||
|
||||
Update to version 0.10.1:
|
||||
|
||||
- cli: ignore missing sections when removing configuration (ddb22a2f)
|
||||
|
||||
Update to version 0.10.0:
|
||||
|
||||
- bridge: correct command used to create a new bridge (9942337b)
|
||||
- web: simplify header navigation (7e95b169)
|
||||
- webui: remark upgrade + gfm + syntax highlighting (6ee47b96)
|
||||
- BREAKING CHANGE: dev-infra: remove gokart (89b880bd)
|
||||
|
||||
Update to version 0.10.0:
|
||||
|
||||
- bridge: correct command used to create a new bridge (9942337b)
|
||||
- web: simplify header navigation (7e95b169)
|
||||
- web: remark upgrade + gfm + syntax highlighting (6ee47b96)
|
||||
|
||||
Update to version 0.9.0:
|
||||
|
||||
- completion: remove errata from string literal (aa102c91)
|
||||
- tui: improve readability of the help bar (23be684a)
|
||||
|
||||
Update to version 0.8.1+git.1746484874.96c7a111:
|
||||
|
||||
* docs: update install, contrib, and usage documentation (#1222)
|
||||
* fix: resolve the remote URI using url.*.insteadOf (#1394)
|
||||
* build(deps): bump the go_modules group across 1 directory with 3 updates (#1376)
|
||||
* chore: gofmt simplify gitlab/export_test.go (#1392)
|
||||
* fix: checkout repo before setting up go environment (#1390)
|
||||
* feat: bump to go v1.24.2 (#1389)
|
||||
* chore: update golang.org/x/net (#1379)
|
||||
* fix: use -0700 when formatting time (#1388)
|
||||
* fix: use correct url for gitlab PATs (#1384)
|
||||
* refactor: remove depdendency on pnpm for auto-label action (#1383)
|
||||
* feat: add action: auto-label (#1380)
|
||||
* feat: remove lifecycle/frozen (#1377)
|
||||
* build(deps): bump the npm_and_yarn group across 1 directory with 12 updates (#1378)
|
||||
* feat: support new exclusion label: lifecycle/pinned (#1375)
|
||||
* fix: refactor how gitlab title changes are detected (#1370)
|
||||
* revert: "Create Dependabot config file" (#1374)
|
||||
* refactor: rename //:git-bug.go to //:main.go (#1373)
|
||||
* build(deps): bump github.com/vektah/gqlparser/v2 from 2.5.16 to 2.5.25 (#1361)
|
||||
* fix: set GitLastTag to an empty string when git-describe errors (#1355)
|
||||
* chore: update go-git to v5@masterupdate_mods (#1284)
|
||||
* refactor: Directly swap two variables to optimize code (#1272)
|
||||
* Update README.md Matrix link to new room (#1275)
|
||||
|
||||
- Update to version 0.8.0+git.1742269202.0ab94c9:
|
||||
* deps(crypto): bump golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for CVE-2024-45337) (#1312)
|
||||
|
||||
- Update golang.org/x/crypto/ssh to v0.35.0 (bsc#1239494,
|
||||
CVE-2025-22869).
|
||||
|
||||
- Add missing Requires to completion subpackages.
|
||||
|
||||
Update to version 0.8.0+git.1733745604.d499b6e:
|
||||
|
||||
* fix typos in docs (#1266)
|
||||
* build(deps): bump github.com/go-git/go-billy/v5 from 5.5.0 to 5.6.0 (#1289)
|
||||
|
||||
- bump golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for CVE-2024-45337, bsc#1234565).
|
||||
</description>
|
||||
<package>git-bug</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
23
patchinfo.20251203090353000871.187004354831441/_patchinfo
Normal file
23
patchinfo.20251203090353000871.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,23 @@
|
||||
<patchinfo incident="packagehub-47">
|
||||
<packager>regularhunter</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for weechat</summary>
|
||||
<description>This update for weechat fixes the following issues:
|
||||
|
||||
Changes in weechat:
|
||||
|
||||
Update to 4.7.2:
|
||||
|
||||
Fixed:
|
||||
|
||||
* api: fix file descriptor leak in hook_url when a timeout occurs
|
||||
or if the hook is removed during the transfer (#2284)
|
||||
* irc: fix colors in messages 367 (ban mask), 728 (quiet mask) and
|
||||
MODE (#2286)
|
||||
* irc: fix reset of color when multiple modes are set with
|
||||
command /mode
|
||||
</description>
|
||||
<package>weechat</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
15
patchinfo.20251203090415508822.187004354831441/_patchinfo
Normal file
15
patchinfo.20251203090415508822.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,15 @@
|
||||
<patchinfo incident="packagehub-48">
|
||||
<packager>rrahl0</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for gnome-browser-connector</summary>
|
||||
<description>This update for gnome-browser-connector fixes the following issues:
|
||||
|
||||
Changes in gnome-browser-connector:
|
||||
|
||||
- add unzip as a requires, otherwise the extensions can't get
|
||||
extracted
|
||||
</description>
|
||||
<package>gnome-browser-connector</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
127
patchinfo.20251205103932570835.187004354831441/_patchinfo
Normal file
127
patchinfo.20251205103932570835.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,127 @@
|
||||
<patchinfo incident="packagehub-51">
|
||||
<packager>dirkmueller</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for trivy</summary>
|
||||
<description>This update for trivy fixes the following issues:
|
||||
|
||||
Changes in trivy:
|
||||
|
||||
Update to version 0.68.1:
|
||||
|
||||
* fix: update cosing settings for GoReleaser after bumping cosing to v3 (#9863)
|
||||
* chore(deps): bump the testcontainers group with 2 updates (#9506)
|
||||
* feat(aws): Add support for dualstack ECR endpoints (#9862)
|
||||
* fix(vex): use a separate `visited` set for each DFS path (#9760)
|
||||
* docs: catch some missed docs -> guide (#9850)
|
||||
* refactor(misconf): parse azure_policy_enabled to addonprofile.azurepolicy.enabled (#9851)
|
||||
* chore(cli): Remove Trivy Cloud (#9847)
|
||||
* fix(misconf): ensure value used as ignore marker is non-null and known (#9835)
|
||||
* fix(misconf): map healthcheck start period flag to --start-period instead of --startPeriod (#9837)
|
||||
* chore(deps): bump the docker group with 3 updates (#9776)
|
||||
* chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#9827)
|
||||
* chore(deps): bump the common group across 1 directory with 20 updates (#9840)
|
||||
* feat(image): add Sigstore bundle SBOM support (#9516)
|
||||
* chore(deps): bump the aws group with 7 updates (#9691)
|
||||
* test(k8s): update k8s integrtion test (#9725)
|
||||
* chore(deps): bump github.com/containerd/containerd from 1.7.28 to 1.7.29 (#9764)
|
||||
* feat(sbom): add support for SPDX attestations (#9829)
|
||||
* docs(misconf): Remove duplicate sections (#9819)
|
||||
* feat(misconf): Update Azure network schema for new checks (#9791)
|
||||
* feat(misconf): Update AppService schema (#9792)
|
||||
* fix(misconf): ensure boolean metadata values are correctly interpreted (#9770)
|
||||
* feat(misconf): support https_traffic_only_enabled in Az storage account (#9784)
|
||||
* docs: restructure docs for new hosting (#9799)
|
||||
* docs(server): fix info about scanning licenses on the client side. (#9805)
|
||||
* ci: remove unused preinstalled software/images for build tests to free up disk space. (#9814)
|
||||
* feat(report): add fingerprint generation for vulnerabilities (#9794)
|
||||
* chore: trigger the trivy-www workflow (#9737)
|
||||
* fix: update all documentation links (#9777)
|
||||
* feat(suse): Add new openSUSE, Micro and SLES releases end of life dates (#9788)
|
||||
* test(go): set `GOPATH` for tests (#9785)
|
||||
* feat(flag): add `--cacert` flag (#9781)
|
||||
* fix(misconf): handle unsupported experimental flags in Dockerfile (#9769)
|
||||
* test(go): refactor mod_test.go to use txtar format (#9775)
|
||||
* docs: Fix typos and linguistic errors in documentation / hacktoberfest (#9586)
|
||||
* chore(deps): bump github.com/opencontainers/selinux from 1.12.0 to 1.13.0 (#9778)
|
||||
* chore(deps): bump github.com/containerd/containerd/v2 from 2.1.4 to 2.1.5 (#9763)
|
||||
* fix(java): use `true` as default value for Repository Release|Snapshot Enabled in pom.xml and settings.xml files (#9751)
|
||||
* docs: add info that `SSL_CERT_FILE` works on `Unix systems other than macOS` only (#9772)
|
||||
* docs: change SecObserve URLs in documentatio (#9771)
|
||||
* feat(db): enable concurrent access to vulnerability database (#9750)
|
||||
* feat(misconf): add agentpools to azure container schema (#9714)
|
||||
* feat(report): switch ReportID from UUIDv4 to UUIDv7 (#9749)
|
||||
* feat(misconf): Update Azure Compute schema (#9675)
|
||||
* feat(misconf): Update azure storage schema (#9728)
|
||||
* feat(misconf): Update SecurityCenter schema (#9674)
|
||||
* feat(image): pass global context to docker/podman image save func (#9733)
|
||||
* chore(deps): bump the github-actions group with 4 updates (#9739)
|
||||
* fix(flag): remove viper.SetDefault to fix IsSet() for config-only flags (#9732)
|
||||
* feat(license): use separate SPDX ids to ignore SPDX expressions (#9087)
|
||||
* feat(dotnet): add dependency graph support for .deps.json files (#9726)
|
||||
* feat(misconf): Add support for configurable Rego error limit (#9657)
|
||||
* feat(misconf): Add RoleAssignments attribute (#9396)
|
||||
* feat(report): add image reference to report metadata (#9729)
|
||||
* fix(os): Add photon 5.0 in supported OS (#9724)
|
||||
* fix(license): handle SPDX WITH exceptions as single license in category detection (#9380)
|
||||
* refactor: add case-insensitive string set implementation (#9720)
|
||||
* feat: include registry and repository in artifact ID calculation (#9689)
|
||||
* feat(java): add support remote repositories from settings.xml files (#9708)
|
||||
* fix(sbom): don’t panic on SBOM format if scanned CycloneDX file has empty metadata (#9562)
|
||||
* docs: update vulnerability reporting guidelines in SECURITY.md (#9395)
|
||||
* docs: add info about `java-db` subdir (#9706)
|
||||
* fix(report): correct field order in SARIF license results (#9712)
|
||||
* test: improve golden file management in integration tests (#9699)
|
||||
* ci: get base_sha using base.ref (#9704)
|
||||
* refactor(misconf): mark AVDID fields as deprecated and use ID internally (#9576)
|
||||
* fix(nodejs): fix npmjs parser.pkgNameFromPath() panic issue (#9688)
|
||||
* fix: close all opened resources if an error occurs (#9665)
|
||||
* refactor(misconf): type-safe parser results in generic scanner (#9685)
|
||||
* feat(image): add RepoTags support for Docker archives (#9690)
|
||||
* chore(deps): bump github.com/quic-go/quic-go from 0.52.0 to 0.54.1 (#9694)
|
||||
* feat(misconf): Update Azure Container Schema (#9673)
|
||||
* ci: use merge commit for apidiff to avoid false positives (#9622)
|
||||
* feat(misconf): include map key in manifest snippet for diagnostics (#9681)
|
||||
* refactor(misconf): add ManifestFromYAML for unified manifest parsing (#9680)
|
||||
* test: update golden files for TestRepository* integration tests (#9684)
|
||||
* refactor(cli): Update the cloud config command (#9676)
|
||||
* fix(sbom): add `buildInfo` info as properties (#9683)
|
||||
* feat: add ReportID field to scan reports (#9670)
|
||||
* docs: add vulnerability database contribution guide (#9667)
|
||||
* feat(cli): Add trivy cloud suppport (#9637)
|
||||
* feat: add ArtifactID field to uniquely identify scan targets (#9663)
|
||||
* fix(nodejs): use the default ID format to match licenses in pnpm packages. (#9661)
|
||||
* feat(sbom): use SPDX license IDs list to validate SPDX IDs (#9569)
|
||||
* fix: use context for analyzers (#9538)
|
||||
* chore(deps): bump the docker group with 3 updates (#9545)
|
||||
* chore(deps): bump the aws group with 6 updates (#9547)
|
||||
* ci(helm): bump Trivy version to 0.67.2 for Trivy Helm Chart 0.19.1 (#9641)
|
||||
* test(helm): bump up Yamale dependency for Helm chart-testing-action (#9653)
|
||||
* fix: Trim the end-of-range suffix (#9618)
|
||||
* test(k8s): use a specific bundle for k8s misconfig scan (#9633)
|
||||
* fix: Use `fetch-level: 1` to check out trivy-repo in the release workflow (#9636)
|
||||
* refactor: move the aws config (#9617)
|
||||
* fix(license): don't normalize `unlicensed` licenses into `unlicense` (#9611)
|
||||
* fix: using SrcVersion instead of Version for echo detector (#9552)
|
||||
* feat(fs): change artifact type to repository when git info is detected (#9613)
|
||||
* fix: add `buildInfo` for `BlobInfo` in `rpc` package (#9608)
|
||||
* fix(vex): don't use reused BOM (#9604)
|
||||
* ci: use pull_request_target for apidiff workflow to support fork PRs (#9605)
|
||||
* fix: restore compatibility for google.protobuf.Value (#9559)
|
||||
* ci: add API diff workflow (#9600)
|
||||
* chore(deps): update to module-compatible docker-credential-gcr/v2 (#9591)
|
||||
* docs: improve documentation for scanning raw IaC configurations (#9571)
|
||||
* feat: allow ignoring findings by type in Rego (#9578)
|
||||
* docs: bump pygments from 2.18.0 to 2.19.2 (#9596)
|
||||
* refactor(misconf): add ID to scan.Rule (#9573)
|
||||
* fix(java): update order for resolving package fields from multiple demManagement (#9575)
|
||||
* chore(deps): bump the github-actions group across 1 directory with 9 updates (#9563)
|
||||
* chore(deps): bump the common group across 1 directory with 7 updates (#9590)
|
||||
* chore(deps): Switch to go-viper/mapstructure (#9579)
|
||||
* chore: add context to the cache interface (#9565)
|
||||
* ci(helm): bump Trivy version to 0.67.0 for Trivy Helm Chart 0.19.0 (#9554)
|
||||
* fix: validate backport branch name (#9548)
|
||||
</description>
|
||||
<package>trivy</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
18
patchinfo.20251208125318499450.93181000773252/_patchinfo
Normal file
18
patchinfo.20251208125318499450.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,18 @@
|
||||
<patchinfo incident="packagehub-50">
|
||||
<issue tracker="bnc" id="1254437">VUL-0: CVE-2025-64460,CVE-2025-13372: python-Django: Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion</issue>
|
||||
<issue tracker="bnc" id="1252926">VUL-0: CVE-2025-64459: python-Django,python-Django4: Potential SQL injection via `_connector` keyword argument in `QuerySet` and `Q` objects</issue>
|
||||
<issue tracker="cve" id="2025-13372">cve#2025-13372 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-13372</issue>
|
||||
<issue tracker="cve" id="2025-64460">cve#2025-64460 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-64460</issue>
|
||||
<issue tracker="cve" id="2025-64459">cve#2025-64459 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-64459</issue>
|
||||
<packager>mcalabkova</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for python-Django</summary>
|
||||
<description>This update for python-Django fixes the following issues:
|
||||
|
||||
- CVE-2025-64459: Fixed a potential SQL injection via `_connector` keyword argument in `QuerySet` and `Q` objects (bsc#1252926)
|
||||
- CVE-2025-13372,CVE-2025-64460: Fixed Denial of Service in 'django.core.serializers.xml_serializer.getInnerText()' (bsc#1254437)
|
||||
</description>
|
||||
<package>python-Django</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
63
patchinfo.20251208143300643166.187004354831441/_patchinfo
Normal file
63
patchinfo.20251208143300643166.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,63 @@
|
||||
<patchinfo incident="packagehub-61">
|
||||
<packager>bigironman</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for icinga-php-thirdparty, icinga-php-library, icingaweb2</summary>
|
||||
<description>This update for icinga-php-thirdparty, icinga-php-library, icingaweb2 fixes the following issues:
|
||||
|
||||
Changes in icinga-php-thirdparty:
|
||||
|
||||
- Update to 0.13.1
|
||||
|
||||
- No changelog from upstream.
|
||||
|
||||
- Update to 0.12.1
|
||||
|
||||
- No changelog from upstream.
|
||||
|
||||
Changes in icinga-php-library:
|
||||
|
||||
- Update to 1.17.0
|
||||
|
||||
- No changelog from upstream.
|
||||
|
||||
Changes in icingaweb2:
|
||||
|
||||
- Update to 2.12.6
|
||||
|
||||
- Search box shows many magnifying glasses for some community themes #5395
|
||||
- Authentication hooks are not called with external backends #5415
|
||||
- Improve Minimal layout #5386
|
||||
|
||||
- Update to 2.12.5
|
||||
|
||||
* PHP 8.4 Support
|
||||
We're again a little behind schedule, but now we support PHP 8.4!
|
||||
This means that installations on Ubuntu 25.04 and Fedora 42+ can
|
||||
now install Icinga Web without worrying about PHP related
|
||||
incompatibilities. Icinga packages will be available in the
|
||||
next few days.
|
||||
* Good Things Take Time
|
||||
There's only a single (notable) recent issue that is fixed
|
||||
with this release. All the others are a bit older.
|
||||
- External URLs set up as dashlets are not embedded the same
|
||||
as navigation items #5346
|
||||
* But the team sat together a few weeks ago and fixed a bug here
|
||||
and there. And of course, also in Icinga Web!
|
||||
- Users who are not allowed to change the theme, cannot change
|
||||
the theme mode either #5385
|
||||
- Improved compatibility with several SSO authentication
|
||||
providers #5000, #5227
|
||||
- Filtering for older-than events with relative time does not
|
||||
work #5263
|
||||
- Empty values are NULL in CSV exports #5350
|
||||
* Breaking, Somewhat
|
||||
This is mainly for developers.
|
||||
With the support of PHP 8.4, we introduced a new environment
|
||||
variable, ICINGAWEB_ENVIRONMENT. Unless set to dev, Icinga Web
|
||||
will not show nor log deprecation notices anymore.
|
||||
</description>
|
||||
<package>icinga-php-thirdparty</package>
|
||||
<package>icinga-php-library</package>
|
||||
<package>icingaweb2</package>
|
||||
</patchinfo>
|
||||
13
patchinfo.20251209165835367165.93181000773252/_patchinfo
Normal file
13
patchinfo.20251209165835367165.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,13 @@
|
||||
<patchinfo incident="packagehub-52">
|
||||
<issue tracker="cve" id="2025-53881">cve#2025-53881 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-53881</issue>
|
||||
<issue tracker="bnc" id="1246457">VUL-0: CVE-2025-53881: exim: SUSE-specific logrotate configuration allows escalation from mail user/group to root</issue>
|
||||
<packager>bigironman</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for exim</summary>
|
||||
<description>This update for exim fixes the following issues:
|
||||
|
||||
- CVE-2025-53881: Fixed a potential security issue with logfile rotation (bsc#1246457)
|
||||
</description>
|
||||
<package>exim</package>
|
||||
</patchinfo>
|
||||
18
patchinfo.20251210101443200408.93181000773252/_patchinfo
Normal file
18
patchinfo.20251210101443200408.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,18 @@
|
||||
<patchinfo incident="packagehub-53">
|
||||
<packager>michals</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for virtme</summary>
|
||||
<description>This update for virtme fixes the following issues:
|
||||
|
||||
- Update to 1.40:
|
||||
* No significant change, this is just a very small hotfix release
|
||||
to solve a packaging problem introduced by a conflict with the
|
||||
new vng-mcp tool.
|
||||
* While at it, there're also some small improved hints in the MCP
|
||||
server, so that AI agents can better understand how to build
|
||||
the kernel using vng --build.
|
||||
</description>
|
||||
<package>virtme</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
20
patchinfo.20251210102155991569.93181000773252/_patchinfo
Normal file
20
patchinfo.20251210102155991569.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,20 @@
|
||||
<patchinfo incident="packagehub-57">
|
||||
<issue tracker="bnc" id="1254531">cmake-extras: Could not locate qmlplugindump</issue>
|
||||
<issue tracker="bnc" id="1239788">cmake4: build failure tracker bug.</issue>
|
||||
<packager>hillwood</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for cmake-extras</summary>
|
||||
<description>This update for cmake-extras fixes the following issues:
|
||||
|
||||
- Support both qmlplugindump-qt5 and qmlplugindump-qt6 (boo#1254531)
|
||||
- Fix filename and path of qmlplugindump-qt5 for openSUSE
|
||||
- Update to 1.9
|
||||
* add support for CMake 4.0
|
||||
- Update to 1.8
|
||||
* GMock: wire dependencies between GMock step and library files
|
||||
* QmlPlugins: Crude support for qt6
|
||||
</description>
|
||||
<package>cmake-extras</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
11
patchinfo.20251210175743200408.93181000773252/_patchinfo
Normal file
11
patchinfo.20251210175743200408.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,11 @@
|
||||
<patchinfo incident="packagehub-58">
|
||||
<packager>pgajdos</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>optional</category>
|
||||
<summary>Optional update for rawtherapee</summary>
|
||||
<description>This update for rawtherapee fixes the following issues:
|
||||
|
||||
Ship rawtherapee image editor.
|
||||
</description>
|
||||
<package>rawtherapee</package>
|
||||
</patchinfo>
|
||||
17
patchinfo.20251211092111744764.93181000773252/_patchinfo
Normal file
17
patchinfo.20251211092111744764.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,17 @@
|
||||
<patchinfo incident="packagehub-55">
|
||||
<issue tracker="cve" id="2025-14372">cve#2025-14372 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-14372</issue>
|
||||
<issue tracker="bnc" id="1254776">VUL-0: chromium: release 143.0.7499.109</issue>
|
||||
<issue tracker="cve" id="2025-14373">cve#2025-14373 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-14373</issue>
|
||||
<packager>AndreasStieger</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for chromium</summary>
|
||||
<description>This update for chromium fixes the following issues:
|
||||
|
||||
- Chromium 143.0.7499.109 (boo#1254776):
|
||||
* CVE-2025-14372: Use after free in Password Manager
|
||||
* CVE-2025-14373: Inappropriate implementation in Toolbar
|
||||
* third issue with an exploit is known to exist in the wild
|
||||
</description>
|
||||
<package>chromium</package>
|
||||
</patchinfo>
|
||||
15
patchinfo.20251214181248399975.93181000773252/_patchinfo
Normal file
15
patchinfo.20251214181248399975.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,15 @@
|
||||
<patchinfo incident="packagehub-56">
|
||||
<issue tracker="bnc" id="1254386">labwc crashes when turning display off with wlr-randr (fixed in upstream and Factory)</issue>
|
||||
<packager>lucsansag</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for labwc</summary>
|
||||
<description>This update for labwc fixes the following issues:
|
||||
|
||||
Changes in labwc:
|
||||
|
||||
- Fixed layershell unmap segfault when no outputs left (boo#1254386)
|
||||
</description>
|
||||
<package>labwc</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
65
patchinfo.20251217091639760898.93181000773252/_patchinfo
Normal file
65
patchinfo.20251217091639760898.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,65 @@
|
||||
<patchinfo incident="packagehub-59">
|
||||
<issue tracker="cve" id="2025-21614">CVE-2025-21614 go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies</issue>
|
||||
<issue tracker="bnc" id="1247629">VUL-0: CVE-2025-21613: cheat: github.com/go-git/go-git/v5: argument injection via the URL field</issue>
|
||||
<issue tracker="cve" id="2025-58181">VUL-0: CVE-2025-58181: TRACKERBUG: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption</issue>
|
||||
<issue tracker="cve" id="2025-21613">VUL-0: CVE-2025-21613: TRACKERBUG: github.com/go-git/go-git/v5: argument injection via the URL field</issue>
|
||||
<issue tracker="cve" id="2025-47913">VUL-0: CVE-2025-47913: TRACKERBUG: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or</issue>
|
||||
<issue tracker="bnc" id="1253922">VUL-0: CVE-2025-58181: cheat: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption</issue>
|
||||
<issue tracker="cve" id="2025-47914">VUL-0: CVE-2025-47914: TRACKERBUG: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read</issue>
|
||||
<issue tracker="cve" id="2025-22870">VUL-0: CVE-2025-22870: TRACKERBUG: golang.org/net/http, golang.org/x/net/proxy, golang.org/x/net/http/httpproxy: proxy bypass using IPv6 zone IDs</issue>
|
||||
<issue tracker="cve" id="2023-48795">VUL-0: CVE-2023-48795: openssh: prefix truncation breaking ssh channel integrity aka Terrapin Attack</issue>
|
||||
<issue tracker="bnc" id="1254051">VUL-0: CVE-2025-47914: cheat: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read</issue>
|
||||
<issue tracker="bnc" id="1253593">VUL-0: CVE-2025-47913: cheat: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request</issue>
|
||||
<issue tracker="cve" id="2025-22869">VUL-0: CVE-2025-22869: TRACKERBUG: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh</issue>
|
||||
<packager>witekbedyk</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for cheat</summary>
|
||||
<description>This update for cheat fixes the following issues:
|
||||
|
||||
- Security:
|
||||
* CVE-2025-47913: Fix client process termination (bsc#1253593)
|
||||
* CVE-2025-58181: Fix potential unbounded memory consumption (bsc#1253922)
|
||||
* CVE-2025-47914: Fix panic due to an out of bounds read (bsc#1254051)
|
||||
* Replace golang.org/x/crypto=golang.org/x/crypto@v0.45.0
|
||||
* Replace golang.org/x/net=golang.org/x/net@v0.47.0
|
||||
* Replace golang.org/x/sys=golang.org/x/sys@v0.38.0
|
||||
|
||||
- Packaging improvements:
|
||||
* Drop Requires: golang-packaging. The recommended Go toolchain
|
||||
dependency expression is BuildRequires: golang(API) >= 1.x or
|
||||
optionally the metapackage BuildRequires: go
|
||||
* Use BuildRequires: golang(API) >= 1.19 matching go.mod
|
||||
* Build PIE with pattern that may become recommended procedure:
|
||||
%%ifnarch ppc64 GOFLAGS="-buildmode=pie" %%endif go build
|
||||
A go toolchain buildmode default config would be preferable
|
||||
but none exist at this time.
|
||||
* Drop mod=vendor, go1.14+ will detect vendor dir and auto-enable
|
||||
* Remove go build -o output binary location and name. Default
|
||||
binary has the same name as package of func main() and is
|
||||
placed in the top level of the build directory.
|
||||
* Add basic %check to execute binary --help
|
||||
|
||||
- Packaging improvements:
|
||||
* Service go_modules replace dependencies with CVEs
|
||||
* Replace github.com/cloudflare/circl=github.com/cloudflare/circl@v1.6.1
|
||||
Fix GO-2025-3754 GHSA-2x5j-vhc8-9cwm
|
||||
* Replace golang.org/x/net=golang.org/x/net@v0.36.0
|
||||
Fixes GO-2025-3503 CVE-2025-22870
|
||||
* Replace golang.org/x/crypto=golang.org/x/crypto@v0.35.0
|
||||
Fixes GO-2023-2402 CVE-2023-48795 GHSA-45x7-px36-x8w8
|
||||
Fixes GO-2025-3487 CVE-2025-22869
|
||||
* Replace github.com/go-git/go-git/v5=github.com/go-git/go-git/v5@v5.13.0
|
||||
Fixes GO-2025-3367 CVE-2025-21614 GHSA-r9px-m959-cxf4
|
||||
Fixes GO-2025-3368 CVE-2025-21613 GHSA-v725-9546-7q7m
|
||||
* Service tar_scm set mode manual from disabled
|
||||
* Service tar_scm create archive from git so we can exclude
|
||||
vendor directory upstream committed to git. Committed vendor
|
||||
directory contents have build issues even after go mod tidy.
|
||||
* Service tar_scm exclude dir vendor
|
||||
* Service set_version set mode manual from disabled
|
||||
* Service set_version remove param basename not needed
|
||||
</description>
|
||||
<package>cheat</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
21
patchinfo.20251218074156387460.187004354831441/_patchinfo
Normal file
21
patchinfo.20251218074156387460.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,21 @@
|
||||
<patchinfo incident="packagehub-60">
|
||||
<issue tracker="cve" id="2025-14766">VUL-0: chromium: release 143.0.7499.146</issue>
|
||||
<issue tracker="cve" id="2025-14174">Google Chrome: chromium: Out of bounds memory access via crafted HTML page</issue>
|
||||
<issue tracker="bnc" id="1255115">VUL-0: chromium: release 143.0.7499.146</issue>
|
||||
<issue tracker="cve" id="2025-14765">VUL-0: chromium: release 143.0.7499.146</issue>
|
||||
<packager>oertel</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for chromium</summary>
|
||||
<description>This update for chromium fixes the following issues:
|
||||
|
||||
Changes in chromium:
|
||||
|
||||
Chromium 143.0.7499.146 (boo#1255115):
|
||||
|
||||
* CVE-2025-14765: Use after free in WebGPU
|
||||
* CVE-2025-14766: Out of bounds read and write in V8
|
||||
* CVE-2025-14174: Out of bounds memory access in ANGLE
|
||||
</description>
|
||||
<package>chromium</package>
|
||||
</patchinfo>
|
||||
123
patchinfo.20251218142204589141.93181000773252/_patchinfo
Normal file
123
patchinfo.20251218142204589141.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,123 @@
|
||||
<patchinfo incident="packagehub-62">
|
||||
<packager>os-autoinst-obs-workflow</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for openQA, os-autoinst, openQA-devel-container</summary>
|
||||
<description>This update for openQA, os-autoinst, openQA-devel-container fixes the following issues:
|
||||
|
||||
Changes in openQA:
|
||||
|
||||
Thu Dec 18 03:54:10 UTC 2025 - okurz@suse.com
|
||||
|
||||
- Update to version 5.1766014013.377e64fe:
|
||||
* feat(Needle::Save): Adapt to new error handling
|
||||
* feat(OpenQA::Git): Make error handling more flexible with exceptions
|
||||
|
||||
- Update to version 5.1765887110.8fc02990:
|
||||
* Avoid partial deletion of a screenshot if Minion job is aborted
|
||||
* Add `SignalBlocker` to delay signal handling during critical sections
|
||||
|
||||
- Update to version 5.1765805960.2112d43d:
|
||||
* fix(codecov): Fix wrong casing for 'fully_covered' entries
|
||||
|
||||
- Update to version 5.1765535865.b566a24c:
|
||||
* fix(codecov): Be strict about coverage thresholds
|
||||
* Show jobs that have been cloned when `t` parameter is used on overview
|
||||
|
||||
- Update to version 5.1765469360.5c0525b5:
|
||||
* worker: Add coverage for OVS DBus checks
|
||||
* Fix overview when filtering by test and module result at the same time
|
||||
* Return signal as part of run_cmd result
|
||||
* Add scanner for untracked screenshots
|
||||
* KTAP: Properly hide details of a skipped subtest
|
||||
* docs: Restory logic of the sentence about NFT vs firewalld
|
||||
* docs: Clarify DHCP/RA availability on MM networks
|
||||
* feat: Allow to configure key+secret with env variables
|
||||
|
||||
- Update to version 5.1765286149.3debb8ea:
|
||||
* KTAP: Don't increment parsed_lines_count in "SKIP" lines
|
||||
* KTAP: Define unparsed_lines and parsed_lines_count
|
||||
|
||||
- Update to version 5.1765217707.d6e697fd:
|
||||
* Test commenting on overview page together with TODO filter
|
||||
* Fix job IDs that are considered for mass-commenting on overview page
|
||||
|
||||
- Update to version 5.1765009312.be30f6e0:
|
||||
* README: Remove left-over empty badge reference
|
||||
|
||||
Changes in os-autoinst:
|
||||
|
||||
- Update to version 5.1767623406.688dd0e:
|
||||
* os-autoinst-generate-needle-preview: Embed PNG
|
||||
* Tweak curl call not to hang
|
||||
* Fix opencv dependency due to upstream changes
|
||||
* Restore package builds on older openSUSE versions
|
||||
* Remove `ShellCheck` from devel dependencies on s390x
|
||||
|
||||
- Update to version 5.1766037062.44c7d2a:
|
||||
* Tweak curl call not to hang
|
||||
* Fix opencv dependency due to upstream changes
|
||||
* Restore package builds on older openSUSE versions
|
||||
* Remove `ShellCheck` from devel dependencies on s390x
|
||||
* Remove obsolete 'bin/' folder
|
||||
|
||||
- Update to version 5.1765976654.0026f92:
|
||||
* Fix opencv dependency due to upstream changes
|
||||
* Restore package builds on older openSUSE versions
|
||||
* Remove `ShellCheck` from devel dependencies on s390x
|
||||
* Remove obsolete 'bin/' folder
|
||||
* Improve documentation strings for get/check_var
|
||||
|
||||
- Update to version 5.1765808557.b89e9b4:
|
||||
* Restore package builds on older openSUSE versions
|
||||
* Remove `ShellCheck` from devel dependencies on s390x
|
||||
* Remove obsolete 'bin/' folder
|
||||
* Simplify the code to increment the counter
|
||||
* audio: Allow for multiple audio recordings per test
|
||||
|
||||
- Update to version 5.1765804109.1e7c99a:
|
||||
* Remove `ShellCheck` from devel dependencies on s390x
|
||||
* Remove obsolete 'bin/' folder
|
||||
* Simplify the code to increment the counter
|
||||
* audio: Allow for multiple audio recordings per test
|
||||
* Improve documentation strings for get/check_var
|
||||
|
||||
- Update to version 5.1765533145.a82864c:
|
||||
* Remove obsolete 'bin/' folder
|
||||
* Simplify the code to increment the counter
|
||||
* audio: Allow for multiple audio recordings per test
|
||||
* Improve documentation strings for get/check_var
|
||||
* Add port forwarding example for NICTYPE_USER_OPTIONS
|
||||
|
||||
- Update to version 5.1765450253.f16e6ac:
|
||||
* Simplify the code to increment the counter
|
||||
* audio: Allow for multiple audio recordings per test
|
||||
* Improve documentation strings for get/check_var
|
||||
* Add port forwarding example for NICTYPE_USER_OPTIONS
|
||||
* Fix regression from abcaa66b by disabling virtio-keyboard by default
|
||||
* distribution: Add "disable_key_repeat"
|
||||
* Use 'virtio-keyboard' by default to allow fixing key repetition errors
|
||||
|
||||
- Update to version 5.1765311639.7e3a762:
|
||||
* Simplify the code to increment the counter
|
||||
* audio: Allow for multiple audio recordings per test
|
||||
* Add port forwarding example for NICTYPE_USER_OPTIONS
|
||||
* Fix regression from abcaa66b by disabling virtio-keyboard by default
|
||||
* Add IPv6 support for multi machine tests
|
||||
|
||||
Changes in openQA-devel-container:
|
||||
|
||||
- Update to version 5.1766014013.377e64fe9:
|
||||
* Update to latest openQA version
|
||||
</description>
|
||||
<package>openQA</package>
|
||||
<package>openQA:openQA-devel-test</package>
|
||||
<package>openQA:openQA-test</package>
|
||||
<package>openQA:openQA-worker-test</package>
|
||||
<package>openQA:openQA-client-test</package>
|
||||
<package>os-autoinst</package>
|
||||
<package>os-autoinst:os-autoinst-test</package>
|
||||
<package>os-autoinst:os-autoinst-devel-test</package>
|
||||
<package>os-autoinst:os-autoinst-openvswitch-test</package>
|
||||
<package>openQA-devel-container</package>
|
||||
</patchinfo>
|
||||
33
patchinfo.20251227105430923343.187004354831441/_patchinfo
Normal file
33
patchinfo.20251227105430923343.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,33 @@
|
||||
<patchinfo incident="packagehub-73">
|
||||
<packager>pgajdos</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for apache2-mod_wsgi</summary>
|
||||
<description>This update for apache2-mod_wsgi fixes the following issues:
|
||||
|
||||
Changes in apache2-mod_wsgi:
|
||||
|
||||
- Don't enable the module by default. Instead, include instructions in the
|
||||
description, consistent with other comparable modules, such as
|
||||
apache2-mod_fcgid, apache2-mod_jk and apache2-mod_mono. If a reverse
|
||||
dependency of this module requires it, that package may execute
|
||||
`a2enmod wsgi`.
|
||||
|
||||
Update to 5.0.2 includes changes from 5.0.1:
|
||||
|
||||
* Eliminate noise in logs under Python 3.13 when Python garbage collection
|
||||
decides to delay destruction of objects until a second phase, resulting in
|
||||
the wsgi.errors log object being accessed after the request had been
|
||||
completed and the log object marked as invalid. This resulted due to changes
|
||||
in garbage collection behaviour in Python 3.13.
|
||||
* Internally, when using Python 3.8 or newer, the PyConfig API will now be
|
||||
used due to deprecation and future removal of older C API alternatives.
|
||||
This was required to support Python 3.13.
|
||||
* Fix issue which could result in process crashing when values were supplied
|
||||
for user/password/realm of HTTP basic authentication which weren’t
|
||||
compliant with UTF-8 encoding format.
|
||||
* Fix memory leak in check_password() authentication hook handler.
|
||||
* Change use of deprecated thread.setDaemon to thread.daemon.
|
||||
</description>
|
||||
<package>apache2-mod_wsgi</package>
|
||||
</patchinfo>
|
||||
24
patchinfo.20260106100749431638.93181000773252/_patchinfo
Normal file
24
patchinfo.20260106100749431638.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,24 @@
|
||||
<patchinfo incident="packagehub-63">
|
||||
<issue tracker="cve" id="2025-58181"/>
|
||||
<issue tracker="cve" id="2025-47913"/>
|
||||
<issue tracker="cve" id="2025-58190"/>
|
||||
<issue tracker="cve" id="2025-47914"/>
|
||||
<issue tracker="cve" id="2025-47911"/>
|
||||
<issue tracker="bnc" id="1253512">VUL-0: CVE-2025-47913: trivy: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request</issue>
|
||||
<issue tracker="bnc" id="1253977">VUL-0: CVE-2025-47914: trivy: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read</issue>
|
||||
<issue tracker="bnc" id="1251547">VUL-0: CVE-2025-58190: trivy: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input</issue>
|
||||
<issue tracker="bnc" id="1251363">VUL-0: CVE-2025-47911: trivy: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<issue tracker="bnc" id="1253786">VUL-0: CVE-2025-58181: trivy: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption</issue>
|
||||
<packager>dirkmueller</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for trivy</summary>
|
||||
<description>This update for trivy fixes the following issues:
|
||||
|
||||
- Update to version 0.68.2:
|
||||
* release: v0.68.2 [release/v0.68] (#9950)
|
||||
* fix(deps): bump alpine from `3.22.1` to `3.23.0` [backport: release/v0.68] (#9949)
|
||||
* ci: enable `check-latest` for `setup-go` [backport: release/v0.68] (#9946)
|
||||
</description>
|
||||
<package>trivy</package>
|
||||
</patchinfo>
|
||||
33
patchinfo.20260106101959221503.93181000773252/_patchinfo
Normal file
33
patchinfo.20260106101959221503.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,33 @@
|
||||
<patchinfo incident="packagehub-66">
|
||||
<issue tracker="bnc" id="1239678">VUL-0: CVE-2025-2337: matio: heap buffer overflow in function Mat_VarPrint of file src/mat.c</issue>
|
||||
<issue tracker="cve" id="2025-2337">VUL-0: CVE-2025-2337: matio: heap buffer overflow in function Mat_VarPrint of file src/mat.c</issue>
|
||||
<issue tracker="cve" id="2025-2338">VUL-0: CVE-2025-2338: matio: heap buffer overflow in function strdup_vprintf of file src/io.c</issue>
|
||||
<issue tracker="bnc" id="1239677">VUL-0: CVE-2025-2338: matio: heap buffer overflow in function strdup_vprintf of file src/io.c</issue>
|
||||
<packager>AndreasStieger</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for matio</summary>
|
||||
<description>This update for matio fixes the following issues:
|
||||
|
||||
- update to version 1.5.29:
|
||||
* Fix printing rank-1-variable in Mat_VarPrint
|
||||
* Fix array index out of bounds in Mat_VarPrint when printing
|
||||
UTF-8 character data (boo#1239678, CVE-2025-2337)
|
||||
* Fix heap-based buffer overflow in strdup_vprintf
|
||||
(boo#1239677, CVE-2025-2338)
|
||||
* Changed Mat_VarPrint to print all values of rank-2-variable
|
||||
* Several other fixes, for example for access violations in
|
||||
Mat_VarPrint
|
||||
|
||||
- Update to version 1.5.28:
|
||||
* Fixed bug writing MAT_T_INT8/MAT_T_UINT8 encoded character
|
||||
array to compressed v5 MAT file (regression of v1.5.12).
|
||||
* Fixed bug reading all-zero sparse array of v4 MAT file
|
||||
(regression of v1.5.18).
|
||||
* Updated C99 snprintf.c.
|
||||
* CMake: Enabled testing.
|
||||
* Several other fixes, for example for access violations in
|
||||
Mat_VarPrint.
|
||||
</description>
|
||||
<package>matio</package>
|
||||
</patchinfo>
|
||||
12
patchinfo.20260106152652552214.93181000773252/_patchinfo
Normal file
12
patchinfo.20260106152652552214.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,12 @@
|
||||
<patchinfo incident="packagehub-71">
|
||||
<packager>miska</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for knot</summary>
|
||||
<description>This update for knot fixes the following issues:
|
||||
|
||||
- update to version 3.5.2, see
|
||||
https://www.knot-dns.cz/2025-11-28-version-352.html
|
||||
</description>
|
||||
<package>knot</package>
|
||||
</patchinfo>
|
||||
12
patchinfo.20260106152825813077.93181000773252/_patchinfo
Normal file
12
patchinfo.20260106152825813077.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,12 @@
|
||||
<patchinfo incident="packagehub-85">
|
||||
<issue tracker="bnc" id="1254975">niri doesn't set the right portal notification proxy</issue>
|
||||
<packager>mantarimay</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for niri</summary>
|
||||
<description>This update for niri fixes the following issues:
|
||||
|
||||
- Fixed portal notification proxy (boo#1254975)
|
||||
</description>
|
||||
<package>niri</package>
|
||||
</patchinfo>
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user