1
0

Compare commits

...

45 Commits

Author SHA256 Message Date
af7f85adff Add cni and cni-plugins 2026-01-28 21:26:48 +01:00
5d50eb34d9 Update patchinfo incident numbers [skip actions] 2026-01-28 11:16:08 +00:00
AutoGits PR Review Bot
1eafc739de Merging
PR: products/PackageHub!364
2026-01-28 11:15:03 +00:00
535c096bc0 Update patchinfo incident numbers [skip actions] 2026-01-27 17:16:50 +00:00
AutoGits PR Review Bot
afb140f57e Merging
PR: products/PackageHub!358
2026-01-27 17:16:25 +00:00
f4475fce7e Update patchinfo incident numbers [skip actions] 2026-01-27 17:10:10 +00:00
AutoGits PR Review Bot
49e2d8e3ee Merging
PR: products/PackageHub!363
2026-01-27 17:09:47 +00:00
8bd7a26bb0 Update patchinfo incident numbers [skip actions] 2026-01-27 17:07:36 +00:00
AutoGits PR Review Bot
1a78353635 Merging
PR: products/PackageHub!341
2026-01-27 17:07:15 +00:00
bcee9abfe3 Update patchinfo incident numbers [skip actions] 2026-01-27 17:06:32 +00:00
AutoGits PR Review Bot
79365ff72b Merging
PR: products/PackageHub!359
2026-01-27 17:06:10 +00:00
39e5061531 Update submodules from pool/tryton#2, pool/trytond#1, pool/gnuhealth#2, pool/trytond_account#1, pool/gnuhealth-client#1, pool/proteus#1, pool/python-PyWebDAV3-GNUHealth#1, pool/trytond_account_invoice#1, pool/trytond_party#1, pool/trytond_product#1, pool/trytond_purchase#1, pool/trytond_stock#1, pool/trytond_stock_lot#1, pool/trytond_stock_supply#1 and create patchinfo.20260127144808374981.93181000773252/_patchinfo 2026-01-27 15:48:29 +01:00
664d2ab261 Update submodules from pool/os-autoinst-distri-opensuse-deps#1 and create patchinfo.20260127134511833854.93181000773252/_patchinfo 2026-01-27 14:45:26 +01:00
af95a954f4 Update submodules from pool/OpenBoard#1 and create patchinfo.20260127091626750054.93181000773252/_patchinfo 2026-01-27 10:16:56 +01:00
e96e6d61ee Update submodules from pool/openQA#19, pool/os-autoinst#11, pool/openQA-devel-container#8 and create patchinfo.20260127091248188902.93181000773252/_patchinfo 2026-01-27 10:13:26 +01:00
41f701dcc1 Update patchinfo.20260120155333040130.93181000773252/_patchinfo
fix indentation
2026-01-26 14:01:10 +01:00
3c13caa4c0 Update patchinfo.20260120155333040130.93181000773252/_patchinfo
Extend patchinfo for version 1.4.1 details
2026-01-26 13:58:34 +01:00
AutoGits PR Review Bot
7b4b273e45 auto-created for hauler
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/hauler!3
2026-01-26 12:55:04 +00:00
0305bdaf8d Update patchinfo incident numbers [skip actions] 2026-01-23 16:54:17 +00:00
AutoGits PR Review Bot
04a5237bbe Merging
PR: products/PackageHub!334
2026-01-23 16:53:52 +00:00
9e102a1492 Update patchinfo incident numbers [skip actions] 2026-01-23 09:52:14 +00:00
AutoGits PR Review Bot
191235d1f9 Merging
PR: products/PackageHub!344
2026-01-23 09:51:50 +00:00
AutoGits PR Review Bot
3bd6ac96e5 Merging
PR: products/PackageHub!350
2026-01-23 09:51:21 +00:00
1a1de1b2d9 Update patchinfo incident numbers [skip actions] 2026-01-22 13:48:23 +00:00
AutoGits PR Review Bot
bb3aba861c Merging
PR: products/PackageHub!343
2026-01-22 13:47:55 +00:00
af029e918c Update submodules from pool/sbctl#1 and create patchinfo.20260122121240008027.93181000773252/_patchinfo 2026-01-22 13:13:25 +01:00
fa3f4c5576 Update patchinfo incident numbers [skip actions] 2026-01-22 10:33:11 +00:00
AutoGits PR Review Bot
6440255204 Merging
PR: products/PackageHub!333
2026-01-22 10:32:44 +00:00
AutoGits PR Review Bot
796b04d33b auto-created for micro-editor
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/micro-editor!3
2026-01-21 16:29:00 +00:00
8f2f9d86b0 Update patchinfo incident numbers [skip actions] 2026-01-21 14:40:26 +00:00
AutoGits PR Review Bot
2fd56b30d4 Merging
PR: products/PackageHub!347
2026-01-21 14:40:04 +00:00
63082ba7c7 Update patchinfo incident numbers [skip actions] 2026-01-21 13:06:57 +00:00
AutoGits PR Review Bot
958cec1a14 Merging
PR: products/PackageHub!345
2026-01-21 13:06:34 +00:00
e52b646803 Update submodules from pool/helmfile#6 and create patchinfo.20260121120556714095.93181000773252/_patchinfo 2026-01-21 13:06:19 +01:00
4f34e4bea2 Update patchinfo incident numbers [skip actions] 2026-01-21 09:11:10 +00:00
AutoGits PR Review Bot
42e7a03923 Merging
PR: products/PackageHub!340
2026-01-21 09:10:50 +00:00
6814660c4a Update submodules from pool/gimp#4 and create patchinfo.20260121084821180176.93181000773252/_patchinfo 2026-01-21 09:50:36 +01:00
190d66cdae Update submodules from pool/minisign#1 and create patchinfo.20260121084629327942.93181000773252/_patchinfo 2026-01-21 09:46:54 +01:00
d47e73860e Update submodules from pool/chromium#27 and create patchinfo.20260121084311542237.93181000773252/_patchinfo 2026-01-21 09:43:47 +01:00
ce46c687b7 Update patchinfo incident numbers [skip actions] 2026-01-20 23:32:38 +00:00
AutoGits PR Review Bot
913979831f Merging
PR: products/PackageHub!338
2026-01-20 23:32:15 +00:00
95ca3e6bac Update submodules from pool/hauler#3 and create patchinfo.20260120155333040130.93181000773252/_patchinfo 2026-01-20 16:53:46 +01:00
201936805e Update submodules from pool/python-weasyprint#1 and create patchinfo.20260120143234408409.93181000773252/_patchinfo 2026-01-20 15:33:11 +01:00
5104c42303 Update submodules from pool/openQA#18, pool/os-autoinst#10, pool/openQA-devel-container#7 and create patchinfo.20260119135010553480.93181000773252/_patchinfo 2026-01-19 14:50:19 +01:00
075b076300 Update submodules from pool/micro-editor#3 and create patchinfo.20260119134919947913.93181000773252/_patchinfo 2026-01-19 14:49:31 +01:00
45 changed files with 713 additions and 29 deletions

8
.gitmodules vendored
View File

@@ -2290,6 +2290,14 @@
path = cmus
url = ../../pool/cmus
branch = leap-16.0
[submodule "cni"]
path = cni
url = ../../pool/cni
branch = leap-16.0
[submodule "cni-plugins"]
path = cni-plugins
url = ../../pool/cni-plugins
branch = leap-16.0
[submodule "cntlm"]
path = cntlm
url = ../../pool/cntlm

1
cni Submodule

Submodule cni added at 44ad00e51b

1
cni-plugins Submodule

Submodule cni-plugins added at fe94e351ce

2
gimp

Submodule gimp updated: fa630de895...539373922d

2
hauler

Submodule hauler updated: 4061841edd...69ca5e4eea

2
openQA

Submodule openQA updated: 3a65228a89...6e8fa2da1d

View File

@@ -0,0 +1,79 @@
<patchinfo incident="packagehub-90">
<packager>gbazzotti</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for micro-editor</summary>
<description>This update for micro-editor fixes the following issues:
Changes in micro-editor:
- Update to version 2.0.15:
* truecolor (supersedes the MICRO_TRUECOLOR environment variable)
* showchars (deprecates indentchar)
* lockbindings for completely disallowing plugins to modify keybindings
* helpsplit for changing default split type for the help command
* pageoverlap for setting number of lines kept during page up/page down
* Added FirstTab, LastTab, FirstSplit and LastSplit commands
* SkipMultiCursorBack as a counterpart to SkipMultiCursor
* CursorToViewTop, CursorToViewCenter, CursorToViewBottom
* Duplicate for duplicating the selection only, not the whole line
* Plugins never write to settings.json or bindings.json anymore
* Add onBufferOptionChanged callback
* Add SpawnCursorAtLoc()
* Expose bufpane's DoubleClick and TripleClick to plugins
* Pass mouse info to {on,pre}MouseXXX callbacks
* Support goto statement from Lua 5.2
* Various Syntax Highlighting improvements
- Update to version 2.0.14:
* matchbracestyle to choose whether to underline or highlight matching braces
* matchbraceleft to choose whether to match brace to the left of the cursor
* hltrailingws to highlight trailing whitespace
* hltaberrors to highlight tab vs space inconsistencies
* Add jump command to perform a relative goto
* Add sub-word movement actions and improve word movements
* Add paragraph selection actions and improve paragraph movements
* Make Shift-PageUp/Down the default keybindings for SelectPageUp/Down
* Add signatures support to improve filetype detection in ambiguous cases
* Provide default.yaml for default syntax highlighting
* Improvements in syntax highlighting for various languages
* More generic support for mouse events handling
* Add mouse release and mouse drag events
* Make MouseMultiCursor toggle cursors
* Better support for handling mouse events in lua
* Better API for lua timers
* Add onAnyEvent callback
* Allow colorschemes to include other colorschemes
* Give user's files in ~/.config/micro/ precedence over micro's built-in
files
* Respect umask when creating files
* Smarter smartpaste
* Make default fileformat value suited to the OS
* Improve buffer view relocation after jumping to a far-away location
* Improve return values of some actions for better action chaining
* Autocomplete filetypes
* Allow raw escape sequence to be bound with bind
* Various small improvements
* Fix various crashes
* Fix micro killed by SIGINT sent to its shell job
* Various fixes for setting local options
* Various fixes for reloading settings via reload command
* Various fixes for updating settings after changing filetype
* Fix unneeded rewriting of settings.json
* Fix overwriting persistent non-default settings in settings.json with
temporary default settings
* Don't apply rmtrailingws on autosave
* Don't autosave unmodified buffer
* Properly update autosave timer when the autosave option value changes
* Fix opening filenames including colons with parsecursor
* Fix replace to be able to insert '$'
* Fix cursor moving to an unexpected location after a redo
* Make cursor movements after selection consistent
* Fix incorrect buffer view after reloading file
* Fix lost mouse release events in case the pane becomes inactive
* Add proper locking to LineArray to fix potential races
* Cleanup indentation and trailing whitespace
* Improve plugin documentation
</description>
<package>micro-editor</package>
</patchinfo>

View File

@@ -0,0 +1,43 @@
<patchinfo incident="packagehub-94">
<packager>os-autoinst-obs-workflow</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for openQA, os-autoinst, openQA-devel-container</summary>
<description>This update for openQA, os-autoinst, openQA-devel-container fixes the following issues:
Changes in openQA:
Fri Jan 16 20:30:53 UTC 2026 - okurz@suse.com
- Update to version 5.1768564451.45d5d5b2:
* feat: optionally configure fake auth key+secret+expiration
* OpenSuseIssueReporter: Avoid multiple push calls
* unit_tests: Add unit tests for OpenSuseBugzillaUtils
* unit_tests: Adapt the UI tests to the new kernel bug button
* plugins: Introduce OpenSuseIssueReporter for external issue reporting
Changes in os-autoinst:
Fri Jan 16 20:43:12 UTC 2026 - okurz@suse.com
- Update to version 5.1768577300.b85e486:
* fix(dist): provide proper copyright headers in all spec-files
* fix(dist): try to fix os-autoinst-obs-auto-submit reverting content
Changes in openQA-devel-container:
Fri Jan 16 20:41:22 UTC 2026 - okurz@suse.de
- Update to version 5.1768564451.45d5d5b2e:
* Update to latest openQA version
</description>
<package>openQA</package>
<package>openQA:openQA-devel-test</package>
<package>openQA:openQA-test</package>
<package>openQA:openQA-worker-test</package>
<package>openQA:openQA-client-test</package>
<package>os-autoinst</package>
<package>os-autoinst:os-autoinst-test</package>
<package>os-autoinst:os-autoinst-devel-test</package>
<package>os-autoinst:os-autoinst-openvswitch-test</package>
<package>openQA-devel-container</package>
</patchinfo>

View File

@@ -0,0 +1,15 @@
<patchinfo incident="packagehub-86">
<issue tracker="cve" id="2025-68616">VUL-0: CVE-2025-68616: python-weasyprint: server-side request forgery (SSRF) protection bypass via HTTP redirects allows access to internal network resources</issue>
<issue tracker="bnc" id="1256936">VUL-0: CVE-2025-68616: python-weasyprint: server-side request forgery (SSRF) protection bypass via HTTP redirects allows access to internal network resources</issue>
<packager>dgarcia</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for python-weasyprint</summary>
<description>This update for python-weasyprint fixes the following issues:
Changes in python-weasyprint:
- CVE-2025-68616: Fixed a server-side request forgery in default fetcher (boo#1256936).
</description>
<package>python-weasyprint</package>
</patchinfo>

View File

@@ -1,4 +1,4 @@
<patchinfo>
<patchinfo incident="packagehub-87">
<issue tracker="cve" id="2025-68156"/>
<issue tracker="cve" id="2025-68161"/>
<issue tracker="cve" id="2024-51744"/>
@@ -219,4 +219,4 @@ Changes in coredns:
* fix TestCorefile1 panic for nil handling (#6802)
</description>
<package>coredns</package>
</patchinfo>
</patchinfo>

View File

@@ -0,0 +1,32 @@
<patchinfo incident="packagehub-96">
<issue tracker="cve" id="2026-22772"/>
<issue tracker="bnc" id="1256546">VUL-0: CVE-2025-47911: TRACKERBUG: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
<packager>dirkmueller</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for hauler</summary>
<description>This update for hauler fixes the following issues:
Changes in hauler:
- Update to version 1.4.1 (bsc#1256546, CVE-2026-22772):
* fixed typos for containerd imports (#493)
* fix and support containerd imports of `hauls` (#492)
* bump github.com/sigstore/fulcio (#489)
- Update to version 1.4.0:
* added/updated logging for `serve` and `remove` (#487)
* added/fixed helm chart images/dependencies features (#485)
* more experimental feature updates (#486)
* add experimental notes (#483)
* updated tempdir flag to store persistent flags (#484)
* delete artifacts from store (#473)
* path rewrites (#475)
* updated/fixed workflow dependency versions (#478)
- Update to version 1.3.2:
* bump to latest cosign fork release (#481)
* Bump golang.org/x/crypto in the go_modules group across 1 directory (#476)
</description>
<package>hauler</package>
</patchinfo>

View File

@@ -0,0 +1,19 @@
<patchinfo incident="packagehub-91">
<issue tracker="cve" id="2026-1220"/>
<issue tracker="bnc" id="1257011">VUL-0: CVE-2026-1220: chromium: Race in V8 (update to 144.0.7559.96)</issue>
<issue tracker="bnc" id="1256938">Chromium icon missing in Gnome on Leap 16</issue>
<packager>AndreasStieger</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for chromium</summary>
<description>This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 144.0.7559.96 (boo#1257011)
* CVE-2026-1220: Race in V8
- update INSTALL.sh to handle the addded tags in the desktop file (boo#1256938)
</description>
<package>chromium</package>
</patchinfo>

View File

@@ -0,0 +1,28 @@
<patchinfo incident="packagehub-92">
<packager>AndreasStieger</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for minisign</summary>
<description>This update for minisign fixes the following issues:
Changes in minisign:
- Bugfix:
* bugfix: duplicate command-line arguments [7dfdb3c]
- Security fix: [gpg.fail/trustcomment]
* Trusted comment injection (minisign) [6c59875]
* trim(): only trim trailing \r\n, reject straight \r characters
- Security fix: [gpg.fail/minisign]
* Trusted comment injection (minisign) [a10dc92]
* Bail out if the signature file contains unprintable characters
- Update to version 0.12
* Libsodium is now an optional dependency. When using the Zig
toolchain to compile Minisign, you can specify the
-Dwithout-libsodium flag to build and run without libsodium.
* Key identifiers are now zero-padded when printed.
</description>
<package>minisign</package>
</patchinfo>

View File

@@ -0,0 +1,24 @@
<patchinfo incident="packagehub-88">
<issue tracker="cve" id="2025-14422"/>
<issue tracker="cve" id="2025-14423"/>
<issue tracker="bnc" id="1255293">VUL-0: CVE-2025-14422: gimp: PNM File Parsing Integer Overflow Remote Code Execution Vulnerability</issue>
<issue tracker="bnc" id="1255296">VUL-0: CVE-2025-14425: gimp: JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</issue>
<issue tracker="cve" id="2025-14425"/>
<issue tracker="bnc" id="1255295">VUL-0: CVE-2025-14424: gimp: XCF File Parsing Use-After-Free Remote Code Execution Vulnerability</issue>
<issue tracker="bnc" id="1255294">VUL-0: CVE-2025-14423: gimp: LBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</issue>
<issue tracker="cve" id="2025-14424"/>
<packager>mgorse</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for gimp</summary>
<description>This update for gimp fixes the following issues:
Changes in gimp:
- CVE-2025-14422: Fixed PNM File Parsing Integer Overflow (bsc#1255293)
- CVE-2025-14423: Fixed LBM File Parsing Stack-based Buffer Overflow (bsc#1255294)
- CVE-2025-14424: Fixed XCF File Parsing Use-After-Free (bsc#1255295)
- CVE-2025-14425: Fixed JP2 File Parsing Heap-based Buffer Overflow(bsc#1255296)
</description>
<package>gimp</package>
</patchinfo>

View File

@@ -0,0 +1,132 @@
<patchinfo incident="packagehub-89">
<packager>manfred-h</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for helmfile</summary>
<description>This update for helmfile fixes the following issues:
Changes in helmfile:
- Update to version 1.2.3:
* build(deps): bump github.com/aws/aws-sdk-go-v2/config from
1.32.2 to 1.32.3 by @dependabot[bot] in #2308
* build(deps): bump github.com/spf13/cobra from 1.10.1 to 1.10.2
by @dependabot[bot] in #2310
* build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from
1.92.1 to 1.93.0 by @dependabot[bot] in #2307
* Add parameter to render helmfile as go template without .gotmpl
extension by @ronaldour in #2312
* build(deps): bump golang.org/x/sync from 0.18.0 to 0.19.0 by
@dependabot[bot] in #2315
* build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from
1.93.0 to 1.93.2 by @dependabot[bot] in #2323
* build(deps): bump k8s.io/apimachinery from 0.34.2 to 0.34.3
by @dependabot[bot] in #2322
* build(deps): bump golang.org/x/term from 0.37.0 to 0.38.0 by
@dependabot[bot] in #2317
* build(deps): bump k8s.io/client-go from 0.34.2 to 0.34.3 by
@dependabot[bot] in #2321
* build(deps): bump github.com/aws/aws-sdk-go-v2/config from
1.32.3 to 1.32.5 by @dependabot[bot] in #2320
* build(deps): bump helm.sh/helm/v3 from 3.19.2 to 3.19.3 by
@dependabot[bot] in #2325
* build(deps): bump helm.sh/helm/v4 from 4.0.1 to 4.0.2 by
@dependabot[bot] in #2326
* build(deps): bump actions/upload-artifact from 5 to 6 by
@dependabot[bot] in #2331
* build(deps): bump helm.sh/helm/v3 from 3.19.3 to 3.19.4 by
@dependabot[bot] in #2328
* build(deps): bump actions/download-artifact from 6 to 7 by
@dependabot[bot] in #2332
* build(deps): bump dessant/lock-threads from 5 to 6 by
@dependabot[bot] in #2330
* build(deps): bump helm.sh/helm/v4 from 4.0.3 to 4.0.4 by
@dependabot[bot] in #2329
* build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3
from 1.93.2 to 1.94.0 by @dependabot[bot] in #2333
* bump helm version to 4.0.4 by @yxxhero in #2335
* build(deps): bump github.com/aws/aws-sdk-go-v2/config from
1.32.5 to 1.32.6 by @dependabot[bot] in #2336
* build(deps): bump github.com/zclconf/go-cty-yaml from 1.1.0
to 1.2.0 by @dependabot[bot] in #2340
* build(deps): bump k8s.io/client-go from 0.34.3 to 0.35.0 by
@dependabot[bot] in #2338
* fix: rewrite relative file:// chart dependencies to absolute
paths by @sstarcher in #2334
- Update to version 1.2.2:
* Fix AWS SDK debug logging by making it configurable (issue
#2270) by @aditmeno in #2290
* test: add integration test for issue #2291 (CRD preservation
with strategicMergePatches) by @aditmeno in #2292
* build(deps): bump github.com/aws/aws-sdk-go-v2/config from
1.32.1 to 1.32.2 by @dependabot[bot] in #2300
* build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3
from 1.92.0 to 1.92.1 by @dependabot[bot] in #2299
* fix: resolve issues #2295, #2296, and #2297 by @aditmeno
in #2298
* build(deps): update Helm v4 to 4.0.1 and helm-secrets to
4.7.4 by @aditmeno in #2304
* feat: add print-env command by @dschmidt in #2279
- Update to version 1.2.1:
* build(deps): bump azure/setup-helm from 4.3.0 to 4.3.1 by
@dependabot[bot] in #2274
* build(deps): bump github.com/helmfile/vals from 0.42.4 to
0.42.5 by @dependabot[bot] in #2272
* build(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0
by @dependabot[bot] in #2277
* build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from
1.90.2 to 1.91.1 by @dependabot[bot] in #2284
* Fix four critical issues: environment merging, kubeVersion
detection, lookup() with kustomize, and Helm 4 color flags by
@aditmeno in #2276
* build(deps): bump go.uber.org/zap from 1.27.0 to 1.27.1 by
@dependabot[bot] in #2283
* build(deps): bump github.com/aws/aws-sdk-go-v2/config from
1.31.20 to 1.32.0 by @dependabot[bot] in #2282
* build(deps): bump actions/checkout from 5 to 6 by
@dependabot[bot] in #2287
* build(deps): bump k8s.io/client-go from 0.34.1 to 0.34.2 by
@dependabot[bot] in #2285
* Fix four critical bugs: array merging (#2281), AWS SDK logging
(#2270), helmDefaults skip flags (#2269), and OCI chart versions
(#2247) by @aditmeno in #2288
* build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from
1.91.1 to 1.92.0 by @dependabot[bot] in #2286
- Update to version 1.2.0:
* build(deps): bump github.com/aws/aws-sdk-go-v2/config from
1.31.15 to 1.31.16 by @dependabot[bot] in #2242
* build(deps): bump github.com/hashicorp/go-getter from 1.8.2
to 1.8.3 by @dependabot[bot] in #2241
* build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from
1.89.0 to 1.89.1 by @dependabot[bot] in #2240
* build(deps): bump github.com/containerd/containerd from 1.7.28
to 1.7.29 by @dependabot[bot] in #2249
* build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from
1.89.1 to 1.90.0 by @dependabot[bot] in #2248
* build(deps): bump github.com/aws/aws-sdk-go-v2/config from
1.31.16 to 1.31.17 by @dependabot[bot] in #2245
* build(deps): bump golang.org/x/sync from 0.17.0 to 0.18.0 by
@dependabot[bot] in #2251
* build(deps): bump golangci/golangci-lint-action from 8 to 9 by
@dependabot[bot] in #2250
* build(deps): bump github.com/aws/aws-sdk-go-v2/config from
1.31.17 to 1.31.18 by @dependabot[bot] in #2253
* build(deps): bump golang.org/x/term from 0.36.0 to 0.37.0 by
@dependabot[bot] in #2256
* build(deps): bump github.com/aws/aws-sdk-go-v2/config from
1.31.18 to 1.31.20 by @dependabot[bot] in #2259
* perf(app): Parallelize helmfile.d rendering and eliminate chdir
race conditions by @aditmeno in #2261
* build(deps): bump k8s.io/apimachinery from 0.34.1 to 0.34.2 by
@dependabot[bot] in #2264
* Issue-1883 fix by @zhaque44 in #2058
* feat: add Helm 4 support while maintaining Helm 3 compatibility
by @aditmeno in #2262
* build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from
1.90.0 to 1.90.2 by @dependabot[bot] in #2258
</description>
<package>helmfile</package>
</patchinfo>

View File

@@ -0,0 +1,72 @@
<patchinfo incident="packagehub-93">
<issue tracker="cve" id="2025-58058"/>
<issue tracker="cve" id="2025-47911"/>
<issue tracker="cve" id="2025-58190"/>
<issue tracker="bnc" id="1251399">VUL-0: CVE-2025-47911: sbctl: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
<issue tracker="bnc" id="1251609">VUL-0: CVE-2025-58190: sbctl: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input</issue>
<issue tracker="bnc" id="1248949">VUL-0: CVE-2025-58058: sbctl: github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory</issue>
<packager>jubalh</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for sbctl</summary>
<description>This update for sbctl fixes the following issues:
Changes in sbctl:
- Upgrade the embedded golang.org/x/net to 0.46.0
* Fixes: bsc#1251399, CVE-2025-47911: various algorithms with
quadratic complexity when parsing HTML documents
* Fixes: bsc#1251609, CVE-2025-58190: excessive memory consumption
by 'html.ParseFragment' when processing specially crafted input
- Update to version 0.18:
* logging: fixup new go vet warning
* workflows: add cc for cross compile
* workflow: add sudo to apt
* workflow: add pcsclite to ci
* workflow: try enable cgo
* go.mod: update golang.org/x/ dependencies
* fix: avoid adding bogus Country attribute to subject DNs
* sbctl: only store file if we did actually sign the file
* installkernel: add post install hook for Debian's traditional installkernel
* CI: missing libpcsclite pkg
* workflows: add missing depends and new pattern keyword
* Add yubikey example for create keys to the README
* Initial yubikey backend keytype support
* verify: ensure we pass args in correct order
- bsc#1248949 (CVE-2025-58058):
Bump xz to 0.5.14
- Update to version 0.17:
* Ensure we don't wrongly compare input/output files when signing
* Added --json supprt to sbctl verify
* Ensure sbctl setup with no arguments returns a helpful output
* Import latest Microsoft keys for KEK and db databases
* Ensure we print the path of the file when encountering an invalid PE file
* Misc fixups in tests
* Misc typo fixes in prints
- Update to version 0.16:
* Ensure sbctl reads --config even if /etc/sbctl/sbctl.conf is
present
* Fixed a bug where sbctl would abort if the TPM eventlog
contains the same byte multiple times
* Fixed a landlock bug where enroll-keys --export did not work
* Fixed a bug where an ESP mounted to multiple paths would not be
detected
* Exporting keys without efivars present work again
* sbctl sign will now use the saved output path if the signed
file is enrolled
* enroll-keys --append will now work without --force.
- Updates from version 0.15.4:
* Fixed an issue where sign-all did not report a non-zero exit
code when something failed
* Fixed and issue where we couldn't write to a file with landlock
* Fixed an issue where --json would print the human readable
output and the json
* Fixes landlock for UKI/bundles by disabling the sandbox feature
* Some doc fixups that mentioned /usr/share/
</description>
<package>sbctl</package>
</patchinfo>

View File

@@ -0,0 +1,63 @@
<patchinfo incident="packagehub-98">
<packager>os-autoinst-obs-workflow</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for openQA, os-autoinst, openQA-devel-container</summary>
<description>This update for openQA, os-autoinst, openQA-devel-container fixes the following issues:
Changes in openQA:
- Update to version 5.1769068942.639067ee:
* Dependency cron 2026-01-22
* feat: Show limits on "Next &amp; Previous" tab within table
- Update to version 5.1768996386.e3f58202:
* fix: Avoid Perl warning if product spec contains undef values
* GenericBug: Add [QE] to the subject
* doc: Mention version lookup of mediums and special value `*`
* doc: Wrap section about medium types consistently at 80 characters
* doc: Remove surplus white-space
* chore: Improve indentation/wrapping of comment
* feat: Improve error message when product contains no templates
* tests: Improve/add tests for "no products found" case
* KernelBug: Extend the kernel bug template
* feat: Improve error message when falling back to version `*`
- Update to version 5.1768856318.847e4fc7:
* fix(systemd): prevent openqa-gru starting while mounts are unavailable
* fix(systemd): try restarts on failure to be more resilient
* feat: Show when "Next &amp; Previous" jobs are limited
* refactor: Format SQL code for "Next &amp; Previous" jobs more nicely
* refactor: Simplify determining latest job in "Next &amp; Previous" list
- Update to version 5.1768402729.462b3957:
* feat: optionally configure fake auth key+secret+expiration
Changes in os-autoinst:
- Update to version 5.1769153586.72cabd0:
* Replace remaining functions with subroutine signatures in 18-qemu.t
* Fix snapshot overlay mechanism to avoid duplication
* fix(dist): provide proper copyright headers in all spec-files
* fix(dist): try to fix os-autoinst-obs-auto-submit reverting content
* fix(dist): exclude unstable t/28-signalblocker.t in OBS checks
* Add documentation of APPEND variable
* Add undocumented KERNEL/INITRD to the supported variables
* os-autoinst-generate-needle-preview: Embed PNG
Changes in openQA-devel-container:
- Update to version 5.1769167363.fd9ad8d88:
* Update to latest openQA version
</description>
<package>openQA</package>
<package>openQA:openQA-devel-test</package>
<package>openQA:openQA-test</package>
<package>openQA:openQA-worker-test</package>
<package>openQA:openQA-client-test</package>
<package>os-autoinst</package>
<package>os-autoinst:os-autoinst-test</package>
<package>os-autoinst:os-autoinst-devel-test</package>
<package>os-autoinst:os-autoinst-openvswitch-test</package>
<package>openQA-devel-container</package>
</patchinfo>

View File

@@ -0,0 +1,13 @@
<patchinfo incident="packagehub-95">
<packager>letsfindaway</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for OpenBoard</summary>
<description>This update for OpenBoard fixes the following issues:
Changes in OpenBoard:
- update to release version 1.7.4
</description>
<package>OpenBoard</package>
</patchinfo>

View File

@@ -0,0 +1,16 @@
<patchinfo incident="packagehub-97">
<packager>os-autoinst-obs-workflow</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for os-autoinst-distri-opensuse-deps</summary>
<description>This update for os-autoinst-distri-opensuse-deps fixes the following issues:
Changes in os-autoinst-distri-opensuse-deps:
- Added dependency perl(Inline::Python)
- Added dependency mkisofs
- Added dependency jq
- Added dependency gzip
</description>
<package>os-autoinst-distri-opensuse-deps</package>
</patchinfo>

View File

@@ -0,0 +1,126 @@
<patchinfo incident="packagehub-99">
<packager>DocB</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for tryton, trytond, gnuhealth, trytond_account, gnuhealth-client, proteus, python-PyWebDAV3-GNUHealth, trytond_account_invoice, trytond_party, trytond_product, trytond_purchase, trytond_stock, trytond_stock_lot, trytond_stock_supply</summary>
<description>This update for tryton, trytond, gnuhealth, trytond_account, gnuhealth-client, proteus, python-PyWebDAV3-GNUHealth, trytond_account_invoice, trytond_party, trytond_product, trytond_purchase, trytond_stock, trytond_stock_lot, trytond_stock_supply fixes the following issues:
Changes in tryton:
- Version 7.0.31 - Bugfix Release
- Version 7.0.29 - Bugfix Release
Changes in trytond:
- Version 7.0.44 - Bugfix Release
- Version 7.0.43 - Bugfix Release
- Version 7.0.42 - Bugfix Release
- Version 7.0.40 - Bugfix Release
- Version 7.0.38 - Bugfix Release
- Version 7.0.37 - Bugfix Release
- Version 7.0.36 - Security Release for issue #14220
- Version 7.0.35 - Bugfix Release
- Version 7.0.34 - Bugfix Release
- Version 7.0.33 - Bugfix Release
Changes in gnuhealth:
- version 5.0.5
* optimizations to language files
* various fixes
* install_demo_database.sh added
- version 5.0.2
* inconsistent naming of package and directories, switch to local copy
* gnuhealth.keyring removed due to local copy
* Remove unused dependencies from health module
* Wrong cursor field teeth (dentistry module)
* remove pillow dependency from lab and dentistry
Changes in trytond_account:
- Version 7.0.23 - Bugfix Release
- Version 7.0.22 - Bugfix Release
- Version 7.0.21 - Bugfix Release
Changes in gnuhealth-client:
- version 5.0.1
* Fix issue #11. default settings for federation.gnhealth.org not working
* allow Python 3.14
Changes in proteus:
- Version 7.0.3 - Bugfix Release
- Version 7.0.2 - Bugfix Release
Changes in python-PyWebDAV3-GNUHealth:
- version 0.13.0
* no changelog provided
* source file renamed
Changes in trytond_account_invoice:
- Version 7.0.14 - Bugfix Release
Changes in trytond_party:
- Version 7.0.7 - Bugfix Release
Changes in trytond_product:
- Version 7.0.3 - Bugfix Release
Changes in trytond_purchase:
- Version 7.0.16 - Bugfix Release
- Version 7.0.15 - Bugfix Release
Changes in trytond_stock:
- Version 7.0.16 - Bugfix Release
- Version 7.0.15 - Bugfix Release
- Version 7.0.14 - Bugfix Release
Changes in trytond_stock_lot:
- Version 7.0.5 - Bugfix Release
- Version 7.0.4 - Bugfix Release
Changes in trytond_stock_supply:
- Version 7.0.5 - Bugfix Release
</description>
<package>tryton</package>
<package>trytond</package>
<package>gnuhealth</package>
<package>trytond_account</package>
<package>gnuhealth-client</package>
<package>proteus</package>
<package>python-PyWebDAV3-GNUHealth</package>
<package>trytond_account_invoice</package>
<package>trytond_party</package>
<package>trytond_product</package>
<package>trytond_purchase</package>
<package>trytond_stock</package>
<package>trytond_stock_lot</package>
<package>trytond_stock_supply</package>
</patchinfo>

View File

@@ -0,0 +1,12 @@
<patchinfo>
<packager>eroca</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for cni, cni-plugins</summary>
<description>This update for cni, cni-plugins fixes the following issues:
Introduce cni and cni-plugins.
</description>
<package>cni</package>
<package>cni-plugins</package>
</patchinfo>

Submodule proteus updated: 138e8be577...5ce25694d3

2
sbctl

Submodule sbctl updated: c8315ff856...ff582da4e2

2
tryton

Submodule tryton updated: 9fb234c6f1...264bba7ff6

Submodule trytond updated: f23469c42b...7ff787f96e