forked from products/PackageHub
Compare commits
112 Commits
workflow
...
maintenanc
| Author | SHA256 | Date | |
|---|---|---|---|
|
|
796b04d33b | ||
| 075b076300 | |||
| 42dde2bc32 | |||
|
|
514563e7f0 | ||
| e8877b6ba2 | |||
|
|
c66beb0d25 | ||
| 1bdb50141a | |||
|
|
f800ffa7eb | ||
| b6af3723b0 | |||
|
|
b904da424b | ||
| 0947d4913f | |||
|
|
f4138e1df0 | ||
| 9d66dd1eb7 | |||
|
|
b5b24a0ee5 | ||
| 215370317f | |||
|
|
e228bcc8b9 | ||
| fa31f94741 | |||
|
|
4b6c93eadf | ||
| 5ee4ff0cd1 | |||
|
|
2ab47ea154 | ||
| 7235f54cc8 | |||
|
|
5e576a9153 | ||
| 84518d8e92 | |||
|
|
de34c0d616 | ||
| 226e10c5ec | |||
| 8bf48c68fd | |||
| cde390ad2c | |||
|
|
57a2fdfcc0 | ||
| dd9b463f6b | |||
|
|
f731b8a87b | ||
| 446f67e6f6 | |||
| 472b5c129b | |||
|
|
fa1b7c2bce | ||
| 772f149974 | |||
| 8df3cece7b | |||
| aa703fe4c3 | |||
| ab59478311 | |||
|
|
7efb8b8dfc | ||
|
|
27eb5ea6c4 | ||
| 8b9ebf531e | |||
|
|
e3ff226e50 | ||
| 0ac9782d12 | |||
|
|
57a31c3244 | ||
| 15d9d81592 | |||
| 5dd827894a | |||
| c10f377714 | |||
| 2db914151f | |||
| 3103a9e8e0 | |||
| afaaa39260 | |||
| 258b2add24 | |||
|
|
a03abce98c | ||
| e69231e6ff | |||
|
|
d417b180e3 | ||
|
|
f4b954b258 | ||
|
|
76cec69059 | ||
| ebcf91f4fb | |||
|
|
be71c72197 | ||
| 120471f77e | |||
|
|
db9c364b31 | ||
| 3929c52614 | |||
| d5e75ef24a | |||
|
|
46ad282010 | ||
| 70aa830096 | |||
|
|
432b6015b9 | ||
| d0ef9928a7 | |||
| bbd772aebb | |||
| 8fac4ab323 | |||
| 8028c9ecf0 | |||
| 12a7def9e2 | |||
| 24d02629f1 | |||
|
|
95edc64165 | ||
| 85d2d64fc0 | |||
| 41d505f4ab | |||
| b1b229353f | |||
|
|
cb67484fd4 | ||
| 7de4d17bb6 | |||
|
|
a24445cff8 | ||
| 262eddbb2e | |||
| fc7baf3c8d | |||
| 9c3b6c187d | |||
| e01601e63c | |||
| aeb1f73847 | |||
| a47a0255a4 | |||
|
|
d08e2827bb | ||
| bc7de0e7cc | |||
|
|
8439743814 | ||
|
|
76091026db | ||
|
|
fc03ed1327 | ||
| b96a953188 | |||
| 6ae24600c5 | |||
| d1a0631733 | |||
|
|
51ad92059e | ||
| 3aae949b7a | |||
| 158832bfe1 | |||
|
|
a7ed1a773d | ||
|
|
6b53d9f452 | ||
| 7cf3e1410d | |||
|
|
9d8b838644 | ||
| 3c973dcf63 | |||
| fb57ec8f31 | |||
|
|
bbb50fccd1 | ||
| 792ee49a40 | |||
|
|
cd1bed3528 | ||
|
|
c8f2353703 | ||
| 4022efbf5d | |||
| a85d786d1d | |||
|
|
a177c0193e | ||
| ca5de1dd3f | |||
| af2e21625e | |||
| dec6c20720 | |||
| 886d7ce9da | |||
| 16bbbb752c |
104
.gitmodules
vendored
104
.gitmodules
vendored
@@ -290,6 +290,10 @@
|
||||
path = PrusaSlicer
|
||||
url = ../../pool/PrusaSlicer
|
||||
branch = leap-16.0
|
||||
[submodule "dehydrated"]
|
||||
path = dehydrated
|
||||
url = ../../pool/dehydrated
|
||||
branch = leap-16.0
|
||||
[submodule "QR-Code-generator"]
|
||||
path = QR-Code-generator
|
||||
url = ../../pool/QR-Code-generator
|
||||
@@ -26134,6 +26138,106 @@
|
||||
path = python-pyRFC3339
|
||||
url = ../../pool/python-pyRFC3339
|
||||
branch = leap-16.0
|
||||
[submodule "certbot-systemd-timer"]
|
||||
path = certbot-systemd-timer
|
||||
url = ../../pool/certbot-systemd-timer
|
||||
branch = leap-16.0
|
||||
[submodule "python-augeas"]
|
||||
path = python-augeas
|
||||
url = ../../pool/python-augeas
|
||||
branch = leap-16.0
|
||||
[submodule "python-bson"]
|
||||
path = python-bson
|
||||
url = ../../pool/python-bson
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-apache"]
|
||||
path = python-certbot-apache
|
||||
url = ../../pool/python-certbot-apache
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-cloudflare"]
|
||||
path = python-certbot-dns-cloudflare
|
||||
url = ../../pool/python-certbot-dns-cloudflare
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-digitalocean"]
|
||||
path = python-certbot-dns-digitalocean
|
||||
url = ../../pool/python-certbot-dns-digitalocean
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-dnsimple"]
|
||||
path = python-certbot-dns-dnsimple
|
||||
url = ../../pool/python-certbot-dns-dnsimple
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-dnsmadeeasy"]
|
||||
path = python-certbot-dns-dnsmadeeasy
|
||||
url = ../../pool/python-certbot-dns-dnsmadeeasy
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-linode"]
|
||||
path = python-certbot-dns-linode
|
||||
url = ../../pool/python-certbot-dns-linode
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-luadns"]
|
||||
path = python-certbot-dns-luadns
|
||||
url = ../../pool/python-certbot-dns-luadns
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-nsone"]
|
||||
path = python-certbot-dns-nsone
|
||||
url = ../../pool/python-certbot-dns-nsone
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-ovh"]
|
||||
path = python-certbot-dns-ovh
|
||||
url = ../../pool/python-certbot-dns-ovh
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-rfc2136"]
|
||||
path = python-certbot-dns-rfc2136
|
||||
url = ../../pool/python-certbot-dns-rfc2136
|
||||
branch = leap-16.0
|
||||
[submodule "python-certbot-dns-route53"]
|
||||
path = python-certbot-dns-route53
|
||||
url = ../../pool/python-certbot-dns-route53
|
||||
branch = leap-16.0
|
||||
[submodule "python-cloudflare"]
|
||||
path = python-cloudflare
|
||||
url = ../../pool/python-cloudflare
|
||||
branch = leap-16.0
|
||||
[submodule "python-digitalocean"]
|
||||
path = python-digitalocean
|
||||
url = ../../pool/python-digitalocean
|
||||
branch = leap-16.0
|
||||
[submodule "python-dns-lexicon"]
|
||||
path = python-dns-lexicon
|
||||
url = ../../pool/python-dns-lexicon
|
||||
branch = leap-16.0
|
||||
[submodule "python-jsonlines"]
|
||||
path = python-jsonlines
|
||||
url = ../../pool/python-jsonlines
|
||||
branch = leap-16.0
|
||||
[submodule "python-jsonpickle"]
|
||||
path = python-jsonpickle
|
||||
url = ../../pool/python-jsonpickle
|
||||
branch = leap-16.0
|
||||
[submodule "python-localzone"]
|
||||
path = python-localzone
|
||||
url = ../../pool/python-localzone
|
||||
branch = leap-16.0
|
||||
[submodule "python-pytest-httpx"]
|
||||
path = python-pytest-httpx
|
||||
url = ../../pool/python-pytest-httpx
|
||||
branch = leap-16.0
|
||||
[submodule "python-requests-file"]
|
||||
path = python-requests-file
|
||||
url = ../../pool/python-requests-file
|
||||
branch = leap-16.0
|
||||
[submodule "python-softlayer"]
|
||||
path = python-softlayer
|
||||
url = ../../pool/python-softlayer
|
||||
branch = leap-16.0
|
||||
[submodule "python-softlayer-zeep"]
|
||||
path = python-softlayer-zeep
|
||||
url = ../../pool/python-softlayer-zeep
|
||||
branch = leap-16.0
|
||||
[submodule "python-tldextract"]
|
||||
path = python-tldextract
|
||||
url = ../../pool/python-tldextract
|
||||
branch = leap-16.0
|
||||
[submodule "openQA-devel-container"]
|
||||
path = openQA-devel-container
|
||||
url = ../../pool/openQA-devel-container
|
||||
|
||||
@@ -1,3 +1,10 @@
|
||||
-------------------------------------------------------------------
|
||||
Mon Jan 5 10:38:32 UTC 2026 - Wolfgang Engel <wolfgang.engel@suse.com>
|
||||
|
||||
- Backports.productcompose:
|
||||
+ add to backports_unneeded, remove xen related packages (bsc#1253226)
|
||||
xen-tools-xendomains-wait-disk
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Fri Oct 10 07:19:41 UTC 2025 - Wolfgang Engel <wolfgang.engel@suse.com>
|
||||
|
||||
|
||||
@@ -281,6 +281,7 @@ packagesets:
|
||||
- xen-doc-html
|
||||
- xen-tools
|
||||
- xen-tools-domU
|
||||
- xen-tools-xendomains-wait-disk
|
||||
- yum-utils
|
||||
|
||||
# TODO: unneeded Leap package per architecture
|
||||
@@ -701,6 +702,9 @@ packagesets:
|
||||
- cargo-packaging
|
||||
- cargo1.87
|
||||
- cargo1.88
|
||||
- cargo1.89
|
||||
- cargo1.90
|
||||
- cargo1.91
|
||||
- catatonit
|
||||
- cblas-devel
|
||||
- cblas-devel-static
|
||||
@@ -1408,7 +1412,6 @@ packagesets:
|
||||
- gobject-introspection-devel
|
||||
- golang-github-cpuguy83-go-md2man
|
||||
- golang-github-google-jsonnet
|
||||
- golang-github-prometheus-prometheus
|
||||
- golang-github-prometheus-promu
|
||||
- golang-packaging
|
||||
- google-errorprone-annotation
|
||||
@@ -6796,6 +6799,9 @@ packagesets:
|
||||
- rhino-engine
|
||||
- rhino-javadoc
|
||||
- rhino-runtime
|
||||
- rmt-server
|
||||
- rmt-server-config
|
||||
- rmt-server-pubcloud
|
||||
- rollback-helper
|
||||
- rootlesskit
|
||||
- rp-pppoe
|
||||
@@ -6852,6 +6858,9 @@ packagesets:
|
||||
- rust-keylime
|
||||
- rust1.87
|
||||
- rust1.88
|
||||
- rust1.89
|
||||
- rust1.90
|
||||
- rust1.91
|
||||
- samba
|
||||
- samba-ad-dc
|
||||
- samba-ad-dc-libs
|
||||
@@ -7080,7 +7089,6 @@ packagesets:
|
||||
- system-user-news
|
||||
- system-user-nobody
|
||||
- system-user-ntp
|
||||
- system-user-prometheus
|
||||
- system-user-pulse
|
||||
- system-user-qemu
|
||||
- system-user-root
|
||||
|
||||
Submodule MozillaThunderbird updated: 0027b98838...4fb117d27d
2
_config
2
_config
@@ -168,7 +168,7 @@ Macros:
|
||||
|
||||
# Leap specific package list, the same list with excludebuild must add to Backports project
|
||||
# Most of package should be built in Backports
|
||||
%if "%_project" == "openSUSE:Backports:SLE-16.0"
|
||||
%if 0%{?_is_in_project}
|
||||
# we build ffado:ffado-mixer for openSUSE, the main one is built in SLFO
|
||||
BuildFlags: excludebuild:ffado
|
||||
# build gpgme:qt flavor for qt5 support
|
||||
|
||||
Submodule ansible-sap-launchpad updated: 000a0fa833...c0088ff952
Submodule apache2-mod_wsgi updated: 3509105fad...c8dbdeec72
2
cddlib
2
cddlib
Submodule cddlib updated: f0f0c4f64c...20da620429
1
certbot-systemd-timer
Submodule
1
certbot-systemd-timer
Submodule
Submodule certbot-systemd-timer added at b7f55a0d65
2
cheat
2
cheat
Submodule cheat updated: 27656594fe...e8f7ed9227
2
chromium
2
chromium
Submodule chromium updated: 63710dd6ca...b03ba53280
1
dehydrated
Submodule
1
dehydrated
Submodule
Submodule dehydrated added at 67698c18b1
2
fcitx5
2
fcitx5
Submodule fcitx5 updated: 5ca142210a...7957ae0538
2
flint
2
flint
Submodule flint updated: 71e720ca64...47c6375582
2
gimp
2
gimp
Submodule gimp updated: aab3634bba...fa630de895
Submodule go-sendxmpp updated: 3ac86d2091...a7e7d705d1
Submodule grub2-compat-ia32 updated: 75de02f7e5...1dbc6bcb1a
Submodule icinga-php-library updated: 2adfe405c4...dcb9868560
Submodule icinga-php-thirdparty updated: 045c6cef83...83db62c3c8
Submodule icingaweb2 updated: 3772b35d84...640fad7a20
2
knot
2
knot
Submodule knot updated: 41bb945764...d98a3c5e64
2
matio
2
matio
Submodule matio updated: a301162ce9...cab79b5274
Submodule micro-editor updated: 14dead0bee...493acf5fad
2
openQA
2
openQA
Submodule openQA updated: e091086774...3a65228a89
Submodule openQA-devel-container updated: 2af23581fe...ec89d608df
Submodule os-autoinst updated: caad282598...c341c75fb2
14
patchinfo.20251027101540783529.187004354831441/_patchinfo
Normal file
14
patchinfo.20251027101540783529.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,14 @@
|
||||
<patchinfo incident="packagehub-67">
|
||||
<packager>lkocman</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for grub2-compat-ia32</summary>
|
||||
<description>This update for grub2-compat-ia32 fixes the following issues:
|
||||
|
||||
- Drop update-bootloader --get as it returns 0
|
||||
even if the variable is unset
|
||||
- Add update-bootloader also into post and postun Requires
|
||||
</description>
|
||||
<package>grub2-compat-ia32</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
236
patchinfo.20251117131718442159.187004354831441/_patchinfo
Normal file
236
patchinfo.20251117131718442159.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,236 @@
|
||||
<patchinfo incident="packagehub-81">
|
||||
<issue tracker="bnc" id="1250499">VUL-0: CVE-2025-10924: gimp: GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="bnc" id="1250497">VUL-0: CVE-2025-10922: gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="cve" id="2025-10922">VUL-0: CVE-2025-10922: gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="cve" id="2025-2760">VUL-0: CVE-2025-2760: gimp: integer overflow may lead to remote code execution</issue>
|
||||
<issue tracker="bnc" id="1250501">VUL-0: CVE-2025-10925: gimp: GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="bnc" id="1241690">VUL-0: CVE-2025-2760: gimp: integer overflow may lead to remote code execution</issue>
|
||||
<issue tracker="bnc" id="1250495">VUL-0: CVE-2025-10920: gimp: GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="cve" id="2025-10920">VUL-0: CVE-2025-10920: gimp: GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="cve" id="2025-10924">VUL-0: CVE-2025-10924: gimp: GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<issue tracker="cve" id="2025-10925">VUL-0: CVE-2025-10925: gimp: GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</issue>
|
||||
<packager>mgorse</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for gimp</summary>
|
||||
<description>This update for gimp fixes the following issues:
|
||||
|
||||
Changes in gimp:
|
||||
|
||||
Update to 3.0.6:
|
||||
|
||||
- Security:
|
||||
|
||||
- During development, we received reports from the Zero Day
|
||||
Initiative of potential security issues with some of our file
|
||||
import plug-ins. While these issues are very unlikely to
|
||||
occur with real files, developers like Jacob Boerema and Alx
|
||||
Sa proactively improved security for those imports.
|
||||
The resolved reports are:
|
||||
- ZDI-CAN-27793
|
||||
- ZDI-CAN-27823
|
||||
- ZDI-CAN-27836
|
||||
- ZDI-CAN-27878
|
||||
- ZDI-CAN-27863
|
||||
- ZDI-CAN-27684
|
||||
|
||||
- Core:
|
||||
|
||||
- Many false-positive build warnings have been cleaned out (and
|
||||
proper issues fixed).
|
||||
- Various crashes fixed.
|
||||
- When creating a layer mask from the layer's alpha, but the
|
||||
layer has no alpha, simply fill the mask with complete
|
||||
opacity instead of a completely transparent layer.
|
||||
- Various core infrastructure code reviewed, cleaned up,
|
||||
refactored and improved, in drawable, layer and filter
|
||||
handling code, tree view code, and more.
|
||||
- GIMP_ICONS_LIKE_A_BOSS environment variable is not working
|
||||
anymore (because "gtk-menu-images" and "gtk-button-images"
|
||||
have been deprecated in GTK3 and removed in GTK4) and was
|
||||
therefore removed.
|
||||
- Lock Content now shows as an undo step.
|
||||
- Add alpha channel for certain transforms.
|
||||
- Add alpha channel on filter merge, when necessary.
|
||||
- Filters can now be applied non-destructively on channels.
|
||||
- Improved Photoshop brush support.
|
||||
- After deleting a palette entry, the next entry is
|
||||
automatically selected. This allows easily deleting several
|
||||
entries in a row, among other usage.
|
||||
- Resize image to layers irrespective to selections.
|
||||
- Improved in-GUI release notes' demo script language:
|
||||
|
||||
- We can now set a button value to click it: "toolbox:text,
|
||||
tool-options:outline=1, tool-options:outline-direction"
|
||||
- Color selector's module names can be used as identifiers:
|
||||
"color-editor,color-editor:CMYK=1,color-editor:total-ink-coverage"
|
||||
|
||||
- Fixed Alpha to Selection on single layers with no
|
||||
transparency.
|
||||
- Various code is slowly ported to newer code, preparing for
|
||||
GTK4 port (in an unplanned future step):
|
||||
|
||||
- Using g_set_str() (optionally redefining it in our core
|
||||
code to avoid bumping the GLib minimum requirement).
|
||||
- Start using GListModel in various pieces of code, in
|
||||
particular getting rid of more and more usage of
|
||||
GtkTreeView when possible (as it will be deprecated with
|
||||
GTK4).
|
||||
- New GimpRow class for all future row widgets.
|
||||
- Use more of G_DECLARE_DERIVABLE_TYPE and
|
||||
G_DECLARE_FINAL_TYPE where relevant.
|
||||
- New GimpContainerListView using a GtkListBox.
|
||||
- New GimpRowSeparator, GimpRowSettings, GimpRowFilter and
|
||||
GimpRowDrawableFilter widgets.
|
||||
|
||||
- (Experimental) GEX Format was updated.
|
||||
- Palette import:
|
||||
|
||||
- Set alpha value for image palette imports.
|
||||
- Fix Lab & CMYK ACB palette import.
|
||||
- Add palette format filters to import dialog, making it more
|
||||
apparent what palette formats are supported, and giving the
|
||||
ability to hide irrelevant files.
|
||||
|
||||
- Improved filter actions' sensitivity to make sure they are
|
||||
set insensitive when relevant. In particular filters which
|
||||
cannot be run non-destructively (e.g. filters with aux
|
||||
inputs, non-interactive filters and GEGL Graph) must be
|
||||
insensitive when trying to run them on group layers.
|
||||
- Fix bad axis centering on zoom out.
|
||||
- Export better SVG when exporting paths.
|
||||
|
||||
- Tools:
|
||||
|
||||
- Text tool: make sure the default color is only changed when
|
||||
the user confirms the color change.
|
||||
- Foreground Selection tool: do not create a selection when no
|
||||
strokes has been made. In particular this removes the
|
||||
unnecessary delay which happened when switching to another
|
||||
tool without actually stroking anything.
|
||||
- All Transform tools: transform boundaries for preview is now
|
||||
multi-layers aware.
|
||||
- (Experimental) Seamless Clone tool: made to work again,
|
||||
though it is still too slow to get out of Playground.
|
||||
|
||||
- Graphical User Interface:
|
||||
|
||||
- Various improvements to window management:
|
||||
|
||||
- Keep-Above windows are set with the Utility hint.
|
||||
- Utility windows are not made transient to a parent.
|
||||
- Transient factory dialogs follow the active display,
|
||||
ensuring that new image windows would not hide your toolbox
|
||||
and dock windows.
|
||||
|
||||
- Various CSS improvements for styling of the interface. Some
|
||||
theme leaks were also fixed.
|
||||
- New toggle button in Brushes and Fonts dockable, allowing
|
||||
brush and font previews to optionally follow the color theme.
|
||||
For instance, when using a dark theme, the brush and font
|
||||
previews could be drawn on the theme background, using the
|
||||
theme foreground colors. By default, these data previews are
|
||||
still drawn as black on white.
|
||||
- Palette grid is now drawn with the theme's background color.
|
||||
- Consistent naming patterns on human-facing options (first
|
||||
word only capitalized).
|
||||
- About dialog:
|
||||
|
||||
- We will now display the date and time of the last check in
|
||||
a "Up to date as of <date> at <time>" string, differing
|
||||
from the "Last checked on <date> at <time>" string. The
|
||||
former will be used to indicate that GIMP is indeed
|
||||
up-to-date whereas the latter when a new version was
|
||||
released and that you should update.
|
||||
- We now respect the system time/date format on macOS and
|
||||
Windows.
|
||||
|
||||
- The search popup won't pop up without an image.
|
||||
- Better zoom step algorithm for data previews in container
|
||||
popup (e.g. the brush popup in paint Tool Options).
|
||||
- Disable animation in the Input Controller, Preferences and
|
||||
Welcome dialogs for stack transition when animation are
|
||||
disabled in system settings.
|
||||
- Fixed crosshair hotspot on Windows (crosshair cursor for
|
||||
brushes was offset with a non-100% display scale factor).
|
||||
- Debug/CRITICAL dialog:
|
||||
|
||||
- Make sure it is non-modal.
|
||||
- Follow the theme mode under Windows.
|
||||
|
||||
- While loading images, all widgets in the file dialog are made
|
||||
insensitive, except for the Cancel button and the progress
|
||||
bar.
|
||||
- Both grid and list views can now zoom via scroll and zoom
|
||||
gestures (it used to only work in list views).
|
||||
- Pop an error message up on startup when GIO modules to read
|
||||
HTTPS links are not found and that we therefore fail to load
|
||||
the remote gimp_versions.json file. With the AppImage package
|
||||
in particular, we depend on an environment daemon which
|
||||
cannot be shipped in the package. So the next best thing is
|
||||
to warn people and tell them what they should install to get
|
||||
version checks.
|
||||
- Welcome dialog:
|
||||
|
||||
- The "Community Tutorials" link is now shown after the
|
||||
"Documentation" link.
|
||||
- The "Learn more" link in Release Notes tab leads to the
|
||||
actual release news for this version.
|
||||
|
||||
- Plug-ins:
|
||||
|
||||
- PDF export: do not draw disabled layer masks.
|
||||
- Jigsaw: the plug-in can now draw on transparent layers.
|
||||
- Various file format fixes and improvements: JPEG 2000 import,
|
||||
TIFF import, DDS import, SVG import, PSP import, FITS export,
|
||||
ICNS import, Dicom import, WBMP import, Farbfeld import, XWD
|
||||
import, ILBM import.
|
||||
- Sphere Designer: use spin scale instead of spin entries (the
|
||||
latter is unusable with little horizontal space).
|
||||
- Animation Play: frames are shown again in the playback
|
||||
progress bar.
|
||||
- Vala Goat Exercise: ignoring C warning in this Vala plug-in
|
||||
as it is generated code and we cannot control it.
|
||||
- file-gih: brush pipe selection modes now have nice,
|
||||
translatable names.
|
||||
- Metadata viewer: port from GtkTreeView to GtkListBox.
|
||||
- File Raw Data: reduce Raw Data load dialogue height by moving
|
||||
to a 2-column layout.
|
||||
- SVG import: it is now possible to break aspect ratio with
|
||||
specific width/height arguments, when calling the PDB
|
||||
procedure non-interactively (from other plug-ins).
|
||||
- Print: when run through a portal print dialog, the "Image
|
||||
Settings" will be exposed as a secondary dialog, outputted
|
||||
after the portal dialog, instead of a tab on the main print
|
||||
dialog (because it is not possible to tweak the print dialog
|
||||
when it is created by a portal). This will bring back usable
|
||||
workflow of printing with GIMP when run in a sandbox (e.g.
|
||||
Flatpak or Snap).
|
||||
- Recompose: fixed for YCbCr decomposed images.
|
||||
- Fixed vulnerabilities: ZDI-CAN-27684, ZDI-CAN-27863,
|
||||
ZDI-CAN-27878, ZDI-CAN-27836, ZDI-CAN-27823, ZDI-CAN-27793.
|
||||
- C Source and HTML export can now be run non-interactively too
|
||||
(e.g. from other plug-ins).
|
||||
- Map Object: fix missing spin boxes.
|
||||
- Small Tiles: fix display lag.
|
||||
|
||||
- CVE-2025-10925: Fix GIMP ILBM file parsing stack-based buffer overflow remote code
|
||||
execution vulnerability. (ZDI-25-914, ZDI-CAN-27793, bsc#1250501)
|
||||
|
||||
- CVE-2025-10922: Fix GIMP DCM file parsing heap-based buffer overflow remote code
|
||||
execution vulnerability. (ZDI-25-911, ZDI-CAN-27863, bsc#1250497)
|
||||
|
||||
- CVE-2025-10920: Prevent overflow attack by checking if output >= max, not just
|
||||
output > max. (ZDI-25-909, ZDI-CAN-27684, bsc#1250495)
|
||||
|
||||
- CVE-2025-10924: Fix integer overflow while parsing FF files. (bsc#1250499)
|
||||
|
||||
- CVE-2025-2760: A vulnerability allows remote attackers to execute arbitrary
|
||||
code on affected installations of GIMP. The specific flaw exists
|
||||
within parsing of XWD files. An integer overflow happens before
|
||||
allocating a buffer. This fixed in GIMP 3.0.0.
|
||||
https://www.gimp.org/news/2025/03/16/gimp-3-0-released
|
||||
(bsc#1241690)
|
||||
</description>
|
||||
<package>gimp</package>
|
||||
</patchinfo>
|
||||
63
patchinfo.20251208143300643166.187004354831441/_patchinfo
Normal file
63
patchinfo.20251208143300643166.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,63 @@
|
||||
<patchinfo incident="packagehub-61">
|
||||
<packager>bigironman</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for icinga-php-thirdparty, icinga-php-library, icingaweb2</summary>
|
||||
<description>This update for icinga-php-thirdparty, icinga-php-library, icingaweb2 fixes the following issues:
|
||||
|
||||
Changes in icinga-php-thirdparty:
|
||||
|
||||
- Update to 0.13.1
|
||||
|
||||
- No changelog from upstream.
|
||||
|
||||
- Update to 0.12.1
|
||||
|
||||
- No changelog from upstream.
|
||||
|
||||
Changes in icinga-php-library:
|
||||
|
||||
- Update to 1.17.0
|
||||
|
||||
- No changelog from upstream.
|
||||
|
||||
Changes in icingaweb2:
|
||||
|
||||
- Update to 2.12.6
|
||||
|
||||
- Search box shows many magnifying glasses for some community themes #5395
|
||||
- Authentication hooks are not called with external backends #5415
|
||||
- Improve Minimal layout #5386
|
||||
|
||||
- Update to 2.12.5
|
||||
|
||||
* PHP 8.4 Support
|
||||
We're again a little behind schedule, but now we support PHP 8.4!
|
||||
This means that installations on Ubuntu 25.04 and Fedora 42+ can
|
||||
now install Icinga Web without worrying about PHP related
|
||||
incompatibilities. Icinga packages will be available in the
|
||||
next few days.
|
||||
* Good Things Take Time
|
||||
There's only a single (notable) recent issue that is fixed
|
||||
with this release. All the others are a bit older.
|
||||
- External URLs set up as dashlets are not embedded the same
|
||||
as navigation items #5346
|
||||
* But the team sat together a few weeks ago and fixed a bug here
|
||||
and there. And of course, also in Icinga Web!
|
||||
- Users who are not allowed to change the theme, cannot change
|
||||
the theme mode either #5385
|
||||
- Improved compatibility with several SSO authentication
|
||||
providers #5000, #5227
|
||||
- Filtering for older-than events with relative time does not
|
||||
work #5263
|
||||
- Empty values are NULL in CSV exports #5350
|
||||
* Breaking, Somewhat
|
||||
This is mainly for developers.
|
||||
With the support of PHP 8.4, we introduced a new environment
|
||||
variable, ICINGAWEB_ENVIRONMENT. Unless set to dev, Icinga Web
|
||||
will not show nor log deprecation notices anymore.
|
||||
</description>
|
||||
<package>icinga-php-thirdparty</package>
|
||||
<package>icinga-php-library</package>
|
||||
<package>icingaweb2</package>
|
||||
</patchinfo>
|
||||
65
patchinfo.20251217091639760898.93181000773252/_patchinfo
Normal file
65
patchinfo.20251217091639760898.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,65 @@
|
||||
<patchinfo incident="packagehub-59">
|
||||
<issue tracker="cve" id="2025-21614">CVE-2025-21614 go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies</issue>
|
||||
<issue tracker="bnc" id="1247629">VUL-0: CVE-2025-21613: cheat: github.com/go-git/go-git/v5: argument injection via the URL field</issue>
|
||||
<issue tracker="cve" id="2025-58181">VUL-0: CVE-2025-58181: TRACKERBUG: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption</issue>
|
||||
<issue tracker="cve" id="2025-21613">VUL-0: CVE-2025-21613: TRACKERBUG: github.com/go-git/go-git/v5: argument injection via the URL field</issue>
|
||||
<issue tracker="cve" id="2025-47913">VUL-0: CVE-2025-47913: TRACKERBUG: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or</issue>
|
||||
<issue tracker="bnc" id="1253922">VUL-0: CVE-2025-58181: cheat: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption</issue>
|
||||
<issue tracker="cve" id="2025-47914">VUL-0: CVE-2025-47914: TRACKERBUG: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read</issue>
|
||||
<issue tracker="cve" id="2025-22870">VUL-0: CVE-2025-22870: TRACKERBUG: golang.org/net/http, golang.org/x/net/proxy, golang.org/x/net/http/httpproxy: proxy bypass using IPv6 zone IDs</issue>
|
||||
<issue tracker="cve" id="2023-48795">VUL-0: CVE-2023-48795: openssh: prefix truncation breaking ssh channel integrity aka Terrapin Attack</issue>
|
||||
<issue tracker="bnc" id="1254051">VUL-0: CVE-2025-47914: cheat: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read</issue>
|
||||
<issue tracker="bnc" id="1253593">VUL-0: CVE-2025-47913: cheat: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request</issue>
|
||||
<issue tracker="cve" id="2025-22869">VUL-0: CVE-2025-22869: TRACKERBUG: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh</issue>
|
||||
<packager>witekbedyk</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for cheat</summary>
|
||||
<description>This update for cheat fixes the following issues:
|
||||
|
||||
- Security:
|
||||
* CVE-2025-47913: Fix client process termination (bsc#1253593)
|
||||
* CVE-2025-58181: Fix potential unbounded memory consumption (bsc#1253922)
|
||||
* CVE-2025-47914: Fix panic due to an out of bounds read (bsc#1254051)
|
||||
* Replace golang.org/x/crypto=golang.org/x/crypto@v0.45.0
|
||||
* Replace golang.org/x/net=golang.org/x/net@v0.47.0
|
||||
* Replace golang.org/x/sys=golang.org/x/sys@v0.38.0
|
||||
|
||||
- Packaging improvements:
|
||||
* Drop Requires: golang-packaging. The recommended Go toolchain
|
||||
dependency expression is BuildRequires: golang(API) >= 1.x or
|
||||
optionally the metapackage BuildRequires: go
|
||||
* Use BuildRequires: golang(API) >= 1.19 matching go.mod
|
||||
* Build PIE with pattern that may become recommended procedure:
|
||||
%%ifnarch ppc64 GOFLAGS="-buildmode=pie" %%endif go build
|
||||
A go toolchain buildmode default config would be preferable
|
||||
but none exist at this time.
|
||||
* Drop mod=vendor, go1.14+ will detect vendor dir and auto-enable
|
||||
* Remove go build -o output binary location and name. Default
|
||||
binary has the same name as package of func main() and is
|
||||
placed in the top level of the build directory.
|
||||
* Add basic %check to execute binary --help
|
||||
|
||||
- Packaging improvements:
|
||||
* Service go_modules replace dependencies with CVEs
|
||||
* Replace github.com/cloudflare/circl=github.com/cloudflare/circl@v1.6.1
|
||||
Fix GO-2025-3754 GHSA-2x5j-vhc8-9cwm
|
||||
* Replace golang.org/x/net=golang.org/x/net@v0.36.0
|
||||
Fixes GO-2025-3503 CVE-2025-22870
|
||||
* Replace golang.org/x/crypto=golang.org/x/crypto@v0.35.0
|
||||
Fixes GO-2023-2402 CVE-2023-48795 GHSA-45x7-px36-x8w8
|
||||
Fixes GO-2025-3487 CVE-2025-22869
|
||||
* Replace github.com/go-git/go-git/v5=github.com/go-git/go-git/v5@v5.13.0
|
||||
Fixes GO-2025-3367 CVE-2025-21614 GHSA-r9px-m959-cxf4
|
||||
Fixes GO-2025-3368 CVE-2025-21613 GHSA-v725-9546-7q7m
|
||||
* Service tar_scm set mode manual from disabled
|
||||
* Service tar_scm create archive from git so we can exclude
|
||||
vendor directory upstream committed to git. Committed vendor
|
||||
directory contents have build issues even after go mod tidy.
|
||||
* Service tar_scm exclude dir vendor
|
||||
* Service set_version set mode manual from disabled
|
||||
* Service set_version remove param basename not needed
|
||||
</description>
|
||||
<package>cheat</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
21
patchinfo.20251218074156387460.187004354831441/_patchinfo
Normal file
21
patchinfo.20251218074156387460.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,21 @@
|
||||
<patchinfo incident="packagehub-60">
|
||||
<issue tracker="cve" id="2025-14766">VUL-0: chromium: release 143.0.7499.146</issue>
|
||||
<issue tracker="cve" id="2025-14174">Google Chrome: chromium: Out of bounds memory access via crafted HTML page</issue>
|
||||
<issue tracker="bnc" id="1255115">VUL-0: chromium: release 143.0.7499.146</issue>
|
||||
<issue tracker="cve" id="2025-14765">VUL-0: chromium: release 143.0.7499.146</issue>
|
||||
<packager>oertel</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for chromium</summary>
|
||||
<description>This update for chromium fixes the following issues:
|
||||
|
||||
Changes in chromium:
|
||||
|
||||
Chromium 143.0.7499.146 (boo#1255115):
|
||||
|
||||
* CVE-2025-14765: Use after free in WebGPU
|
||||
* CVE-2025-14766: Out of bounds read and write in V8
|
||||
* CVE-2025-14174: Out of bounds memory access in ANGLE
|
||||
</description>
|
||||
<package>chromium</package>
|
||||
</patchinfo>
|
||||
123
patchinfo.20251218142204589141.93181000773252/_patchinfo
Normal file
123
patchinfo.20251218142204589141.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,123 @@
|
||||
<patchinfo incident="packagehub-62">
|
||||
<packager>os-autoinst-obs-workflow</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for openQA, os-autoinst, openQA-devel-container</summary>
|
||||
<description>This update for openQA, os-autoinst, openQA-devel-container fixes the following issues:
|
||||
|
||||
Changes in openQA:
|
||||
|
||||
Thu Dec 18 03:54:10 UTC 2025 - okurz@suse.com
|
||||
|
||||
- Update to version 5.1766014013.377e64fe:
|
||||
* feat(Needle::Save): Adapt to new error handling
|
||||
* feat(OpenQA::Git): Make error handling more flexible with exceptions
|
||||
|
||||
- Update to version 5.1765887110.8fc02990:
|
||||
* Avoid partial deletion of a screenshot if Minion job is aborted
|
||||
* Add `SignalBlocker` to delay signal handling during critical sections
|
||||
|
||||
- Update to version 5.1765805960.2112d43d:
|
||||
* fix(codecov): Fix wrong casing for 'fully_covered' entries
|
||||
|
||||
- Update to version 5.1765535865.b566a24c:
|
||||
* fix(codecov): Be strict about coverage thresholds
|
||||
* Show jobs that have been cloned when `t` parameter is used on overview
|
||||
|
||||
- Update to version 5.1765469360.5c0525b5:
|
||||
* worker: Add coverage for OVS DBus checks
|
||||
* Fix overview when filtering by test and module result at the same time
|
||||
* Return signal as part of run_cmd result
|
||||
* Add scanner for untracked screenshots
|
||||
* KTAP: Properly hide details of a skipped subtest
|
||||
* docs: Restory logic of the sentence about NFT vs firewalld
|
||||
* docs: Clarify DHCP/RA availability on MM networks
|
||||
* feat: Allow to configure key+secret with env variables
|
||||
|
||||
- Update to version 5.1765286149.3debb8ea:
|
||||
* KTAP: Don't increment parsed_lines_count in "SKIP" lines
|
||||
* KTAP: Define unparsed_lines and parsed_lines_count
|
||||
|
||||
- Update to version 5.1765217707.d6e697fd:
|
||||
* Test commenting on overview page together with TODO filter
|
||||
* Fix job IDs that are considered for mass-commenting on overview page
|
||||
|
||||
- Update to version 5.1765009312.be30f6e0:
|
||||
* README: Remove left-over empty badge reference
|
||||
|
||||
Changes in os-autoinst:
|
||||
|
||||
- Update to version 5.1767623406.688dd0e:
|
||||
* os-autoinst-generate-needle-preview: Embed PNG
|
||||
* Tweak curl call not to hang
|
||||
* Fix opencv dependency due to upstream changes
|
||||
* Restore package builds on older openSUSE versions
|
||||
* Remove `ShellCheck` from devel dependencies on s390x
|
||||
|
||||
- Update to version 5.1766037062.44c7d2a:
|
||||
* Tweak curl call not to hang
|
||||
* Fix opencv dependency due to upstream changes
|
||||
* Restore package builds on older openSUSE versions
|
||||
* Remove `ShellCheck` from devel dependencies on s390x
|
||||
* Remove obsolete 'bin/' folder
|
||||
|
||||
- Update to version 5.1765976654.0026f92:
|
||||
* Fix opencv dependency due to upstream changes
|
||||
* Restore package builds on older openSUSE versions
|
||||
* Remove `ShellCheck` from devel dependencies on s390x
|
||||
* Remove obsolete 'bin/' folder
|
||||
* Improve documentation strings for get/check_var
|
||||
|
||||
- Update to version 5.1765808557.b89e9b4:
|
||||
* Restore package builds on older openSUSE versions
|
||||
* Remove `ShellCheck` from devel dependencies on s390x
|
||||
* Remove obsolete 'bin/' folder
|
||||
* Simplify the code to increment the counter
|
||||
* audio: Allow for multiple audio recordings per test
|
||||
|
||||
- Update to version 5.1765804109.1e7c99a:
|
||||
* Remove `ShellCheck` from devel dependencies on s390x
|
||||
* Remove obsolete 'bin/' folder
|
||||
* Simplify the code to increment the counter
|
||||
* audio: Allow for multiple audio recordings per test
|
||||
* Improve documentation strings for get/check_var
|
||||
|
||||
- Update to version 5.1765533145.a82864c:
|
||||
* Remove obsolete 'bin/' folder
|
||||
* Simplify the code to increment the counter
|
||||
* audio: Allow for multiple audio recordings per test
|
||||
* Improve documentation strings for get/check_var
|
||||
* Add port forwarding example for NICTYPE_USER_OPTIONS
|
||||
|
||||
- Update to version 5.1765450253.f16e6ac:
|
||||
* Simplify the code to increment the counter
|
||||
* audio: Allow for multiple audio recordings per test
|
||||
* Improve documentation strings for get/check_var
|
||||
* Add port forwarding example for NICTYPE_USER_OPTIONS
|
||||
* Fix regression from abcaa66b by disabling virtio-keyboard by default
|
||||
* distribution: Add "disable_key_repeat"
|
||||
* Use 'virtio-keyboard' by default to allow fixing key repetition errors
|
||||
|
||||
- Update to version 5.1765311639.7e3a762:
|
||||
* Simplify the code to increment the counter
|
||||
* audio: Allow for multiple audio recordings per test
|
||||
* Add port forwarding example for NICTYPE_USER_OPTIONS
|
||||
* Fix regression from abcaa66b by disabling virtio-keyboard by default
|
||||
* Add IPv6 support for multi machine tests
|
||||
|
||||
Changes in openQA-devel-container:
|
||||
|
||||
- Update to version 5.1766014013.377e64fe9:
|
||||
* Update to latest openQA version
|
||||
</description>
|
||||
<package>openQA</package>
|
||||
<package>openQA:openQA-devel-test</package>
|
||||
<package>openQA:openQA-test</package>
|
||||
<package>openQA:openQA-worker-test</package>
|
||||
<package>openQA:openQA-client-test</package>
|
||||
<package>os-autoinst</package>
|
||||
<package>os-autoinst:os-autoinst-test</package>
|
||||
<package>os-autoinst:os-autoinst-devel-test</package>
|
||||
<package>os-autoinst:os-autoinst-openvswitch-test</package>
|
||||
<package>openQA-devel-container</package>
|
||||
</patchinfo>
|
||||
33
patchinfo.20251227105430923343.187004354831441/_patchinfo
Normal file
33
patchinfo.20251227105430923343.187004354831441/_patchinfo
Normal file
@@ -0,0 +1,33 @@
|
||||
<patchinfo incident="packagehub-73">
|
||||
<packager>pgajdos</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for apache2-mod_wsgi</summary>
|
||||
<description>This update for apache2-mod_wsgi fixes the following issues:
|
||||
|
||||
Changes in apache2-mod_wsgi:
|
||||
|
||||
- Don't enable the module by default. Instead, include instructions in the
|
||||
description, consistent with other comparable modules, such as
|
||||
apache2-mod_fcgid, apache2-mod_jk and apache2-mod_mono. If a reverse
|
||||
dependency of this module requires it, that package may execute
|
||||
`a2enmod wsgi`.
|
||||
|
||||
Update to 5.0.2 includes changes from 5.0.1:
|
||||
|
||||
* Eliminate noise in logs under Python 3.13 when Python garbage collection
|
||||
decides to delay destruction of objects until a second phase, resulting in
|
||||
the wsgi.errors log object being accessed after the request had been
|
||||
completed and the log object marked as invalid. This resulted due to changes
|
||||
in garbage collection behaviour in Python 3.13.
|
||||
* Internally, when using Python 3.8 or newer, the PyConfig API will now be
|
||||
used due to deprecation and future removal of older C API alternatives.
|
||||
This was required to support Python 3.13.
|
||||
* Fix issue which could result in process crashing when values were supplied
|
||||
for user/password/realm of HTTP basic authentication which weren’t
|
||||
compliant with UTF-8 encoding format.
|
||||
* Fix memory leak in check_password() authentication hook handler.
|
||||
* Change use of deprecated thread.setDaemon to thread.daemon.
|
||||
</description>
|
||||
<package>apache2-mod_wsgi</package>
|
||||
</patchinfo>
|
||||
24
patchinfo.20260106100749431638.93181000773252/_patchinfo
Normal file
24
patchinfo.20260106100749431638.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,24 @@
|
||||
<patchinfo incident="packagehub-63">
|
||||
<issue tracker="cve" id="2025-58181"/>
|
||||
<issue tracker="cve" id="2025-47913"/>
|
||||
<issue tracker="cve" id="2025-58190"/>
|
||||
<issue tracker="cve" id="2025-47914"/>
|
||||
<issue tracker="cve" id="2025-47911"/>
|
||||
<issue tracker="bnc" id="1253512">VUL-0: CVE-2025-47913: trivy: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request</issue>
|
||||
<issue tracker="bnc" id="1253977">VUL-0: CVE-2025-47914: trivy: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read</issue>
|
||||
<issue tracker="bnc" id="1251547">VUL-0: CVE-2025-58190: trivy: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input</issue>
|
||||
<issue tracker="bnc" id="1251363">VUL-0: CVE-2025-47911: trivy: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<issue tracker="bnc" id="1253786">VUL-0: CVE-2025-58181: trivy: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption</issue>
|
||||
<packager>dirkmueller</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for trivy</summary>
|
||||
<description>This update for trivy fixes the following issues:
|
||||
|
||||
- Update to version 0.68.2:
|
||||
* release: v0.68.2 [release/v0.68] (#9950)
|
||||
* fix(deps): bump alpine from `3.22.1` to `3.23.0` [backport: release/v0.68] (#9949)
|
||||
* ci: enable `check-latest` for `setup-go` [backport: release/v0.68] (#9946)
|
||||
</description>
|
||||
<package>trivy</package>
|
||||
</patchinfo>
|
||||
33
patchinfo.20260106101959221503.93181000773252/_patchinfo
Normal file
33
patchinfo.20260106101959221503.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,33 @@
|
||||
<patchinfo incident="packagehub-66">
|
||||
<issue tracker="bnc" id="1239678">VUL-0: CVE-2025-2337: matio: heap buffer overflow in function Mat_VarPrint of file src/mat.c</issue>
|
||||
<issue tracker="cve" id="2025-2337">VUL-0: CVE-2025-2337: matio: heap buffer overflow in function Mat_VarPrint of file src/mat.c</issue>
|
||||
<issue tracker="cve" id="2025-2338">VUL-0: CVE-2025-2338: matio: heap buffer overflow in function strdup_vprintf of file src/io.c</issue>
|
||||
<issue tracker="bnc" id="1239677">VUL-0: CVE-2025-2338: matio: heap buffer overflow in function strdup_vprintf of file src/io.c</issue>
|
||||
<packager>AndreasStieger</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for matio</summary>
|
||||
<description>This update for matio fixes the following issues:
|
||||
|
||||
- update to version 1.5.29:
|
||||
* Fix printing rank-1-variable in Mat_VarPrint
|
||||
* Fix array index out of bounds in Mat_VarPrint when printing
|
||||
UTF-8 character data (boo#1239678, CVE-2025-2337)
|
||||
* Fix heap-based buffer overflow in strdup_vprintf
|
||||
(boo#1239677, CVE-2025-2338)
|
||||
* Changed Mat_VarPrint to print all values of rank-2-variable
|
||||
* Several other fixes, for example for access violations in
|
||||
Mat_VarPrint
|
||||
|
||||
- Update to version 1.5.28:
|
||||
* Fixed bug writing MAT_T_INT8/MAT_T_UINT8 encoded character
|
||||
array to compressed v5 MAT file (regression of v1.5.12).
|
||||
* Fixed bug reading all-zero sparse array of v4 MAT file
|
||||
(regression of v1.5.18).
|
||||
* Updated C99 snprintf.c.
|
||||
* CMake: Enabled testing.
|
||||
* Several other fixes, for example for access violations in
|
||||
Mat_VarPrint.
|
||||
</description>
|
||||
<package>matio</package>
|
||||
</patchinfo>
|
||||
12
patchinfo.20260106152652552214.93181000773252/_patchinfo
Normal file
12
patchinfo.20260106152652552214.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,12 @@
|
||||
<patchinfo incident="packagehub-71">
|
||||
<packager>miska</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for knot</summary>
|
||||
<description>This update for knot fixes the following issues:
|
||||
|
||||
- update to version 3.5.2, see
|
||||
https://www.knot-dns.cz/2025-11-28-version-352.html
|
||||
</description>
|
||||
<package>knot</package>
|
||||
</patchinfo>
|
||||
76
patchinfo.20260107170113751929.93181000773252/_patchinfo
Normal file
76
patchinfo.20260107170113751929.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,76 @@
|
||||
<patchinfo incident="packagehub-65">
|
||||
<packager>sbradnick</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for ranger</summary>
|
||||
<description>This update for ranger fixes the following issues:
|
||||
|
||||
- Update to version 1.9.4+git20250910.3f7a3546:
|
||||
* img_display: Avoid unicode escape sequences for Ueberzug input
|
||||
* man: fix documentation of which license ranger uses exactly
|
||||
* rifle: fixed+clarified usage string
|
||||
|
||||
- Update to version 1.9.4+git20250604.7e38143:
|
||||
* fixed bug with command info staying
|
||||
* Revert "fixed open_with bugginess"
|
||||
* fixed open_with bugginess
|
||||
* commands: Reword comment for brevity and accuracy
|
||||
* GHActions: Pass config_files rather than boolean to flake8
|
||||
* commands: Disable invalid-name and too-many-lines pylints
|
||||
* Pylint: Disable invalid-name and too-many-lines for commands.py
|
||||
* add :unnarrow to disable :narrow mode
|
||||
* rifle: Update version
|
||||
|
||||
- Update to version 1.9.4+git20250305.7ad50fa:
|
||||
* 7-zip now has an official Linux version (7zz)
|
||||
* add: support for tilde in bookmarks
|
||||
* img_display: address PR feedback
|
||||
* docs: kitty image previews are supported in other terminals now
|
||||
* img_display: auto-detect support for kitty image previews
|
||||
* rifle(terminals): support auto-detecting ghostty terminal emulator
|
||||
* Modified order of expantions in peview_script
|
||||
* Add GNOME papers to document viewers
|
||||
* Added ability to use environmental variables in preview_script option
|
||||
* doc: Regenerate man pages to have the proper version
|
||||
* Makefile: Update version Grep since adding logo to README
|
||||
* ranger/__init__: Caught another unbumped version
|
||||
* mime.types: Add .nim extension for text/plain
|
||||
* Fixed mistooks of nim scripts as a video aNIMations in rifle.conf
|
||||
* GHActions: Pypy don't run old Flake8/Pylint
|
||||
* GHActions: Use Pypy 3.10
|
||||
* actions: Use keywords for rifle.execute
|
||||
* runner: Allow action as positional argument
|
||||
* ui: Refresh window in initialize
|
||||
* ui: endwin already sets cursor to normal visibility
|
||||
* requirements: Add setuptools
|
||||
* img_display: Silence no-member false positive
|
||||
* core/main: Drop unused variable prefix_length
|
||||
* core,ext: Avoid return in finally shadowing return value
|
||||
* test_py2_compat: Prevent use of yield from
|
||||
* core,ext: Reduce positional arguments where possible
|
||||
* pager,history: Replace branch with min/max builtins
|
||||
* Pylint: Update custom checker for compatibility with 3.3.1
|
||||
* GHActions: Bump action versions
|
||||
* README: Use forge-agnostic URL
|
||||
* README: Capitalize ranger
|
||||
* README: Bump version
|
||||
* README: Replace Travis with GHActions badge
|
||||
* README: Center header
|
||||
* make logo in readme wider
|
||||
* move the ranger logo to the very top
|
||||
* Add option confirm_on_trash
|
||||
* Fix typos
|
||||
* Add IINA to rifle.conf
|
||||
* browsercolumn: ANSI escape codes support
|
||||
* #1182: Fix signals for OS X
|
||||
|
||||
- Update to version 1.9.3+git20240801.bd9b37f:
|
||||
* properly decode file:// urls given to ranger as argument (fixes #2900)
|
||||
* fix #2873 WM_NAME now shows "not accessible" in non-existent directories
|
||||
* Fixed inconsistency in ranger documentation where it was stated that commanding 'linemode humanreadablesizemtime' changed the linemode to display human readable modification time and file size, but the correct command for this is 'linemode sizehumanreadablemtime'
|
||||
* README: fix link formatting on github's markdown renderer
|
||||
* README: add liberapay badge
|
||||
* Mention viewmode key binding in man
|
||||
</description>
|
||||
<package>ranger</package>
|
||||
</patchinfo>
|
||||
19
patchinfo.20260108114750488113.93181000773252/_patchinfo
Normal file
19
patchinfo.20260108114750488113.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,19 @@
|
||||
<patchinfo incident="packagehub-64">
|
||||
<issue tracker="cve" id="2026-0628">VUL-0: CVE-2026-0628: chromium: Insufficient policy enforcement in WebView tag fixed in 143.0.7499.192</issue>
|
||||
<issue tracker="bnc" id="1256067">VUL-0: CVE-2026-0628: chromium: Insufficient policy enforcement in WebView tag fixed in 143.0.7499.192</issue>
|
||||
<packager>AndreasStieger</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for chromium</summary>
|
||||
<description>This update for chromium fixes the following issues:
|
||||
|
||||
Changes in chromium:
|
||||
|
||||
- Chromium 143.0.7499.192 (boo#1256067):
|
||||
* CVE-2026-0628: Insufficient policy enforcement in WebView tag
|
||||
|
||||
- Chromium 143.0.7499.169 (stable released 2025-12-18)
|
||||
* no cve listed yet
|
||||
</description>
|
||||
<package>chromium</package>
|
||||
</patchinfo>
|
||||
35
patchinfo.20260112114750488113.93181000773252/_patchinfo
Normal file
35
patchinfo.20260112114750488113.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,35 @@
|
||||
<patchinfo incident="packagehub-68">
|
||||
<packager>mcalabkova</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>optional</category>
|
||||
<summary>Optional update for certbot</summary>
|
||||
<description>This update for certbot fixes the following issues:
|
||||
|
||||
Various certbot packages and dependencies are being added.
|
||||
</description>
|
||||
<package>certbot-systemd-timer</package>
|
||||
<package>python-augeas</package>
|
||||
<package>python-bson</package>
|
||||
<package>python-certbot-apache</package>
|
||||
<package>python-certbot-dns-cloudflare</package>
|
||||
<package>python-certbot-dns-digitalocean</package>
|
||||
<package>python-certbot-dns-dnsimple</package>
|
||||
<package>python-certbot-dns-dnsmadeeasy</package>
|
||||
<package>python-certbot-dns-linode</package>
|
||||
<package>python-certbot-dns-luadns</package>
|
||||
<package>python-certbot-dns-nsone</package>
|
||||
<package>python-certbot-dns-ovh</package>
|
||||
<package>python-certbot-dns-rfc2136</package>
|
||||
<package>python-certbot-dns-route53</package>
|
||||
<package>python-cloudflare</package>
|
||||
<package>python-digitalocean</package>
|
||||
<package>python-dns-lexicon</package>
|
||||
<package>python-jsonlines</package>
|
||||
<package>python-jsonpickle</package>
|
||||
<package>python-localzone</package>
|
||||
<package>python-pytest-httpx</package>
|
||||
<package>python-requests-file</package>
|
||||
<package>python-softlayer</package>
|
||||
<package>python-softlayer-zeep</package>
|
||||
<package>python-tldextract</package>
|
||||
</patchinfo>
|
||||
47
patchinfo.20260113100304813079.93181000773252/_patchinfo
Normal file
47
patchinfo.20260113100304813079.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,47 @@
|
||||
<patchinfo incident="packagehub-72">
|
||||
<issue tracker="cve" id="2025-14325">firefox: JIT miscompilation in the JavaScript Engine: JIT component</issue>
|
||||
<issue tracker="cve" id="2025-14321">firefox: Use-after-free in the WebRTC: Signaling component</issue>
|
||||
<issue tracker="cve" id="2025-14328">firefox: Privilege escalation in the Netmonitor component</issue>
|
||||
<issue tracker="cve" id="2025-14323">firefox: Privilege escalation in the DOM: Notifications component</issue>
|
||||
<issue tracker="cve" id="2025-14322">firefox: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component</issue>
|
||||
<issue tracker="bnc" id="1254551">VUL-0: MozillaFirefox / MozillaThunderbird: update to 146.0 and 140.6esr</issue>
|
||||
<issue tracker="cve" id="2025-14324">firefox: JIT miscompilation in the JavaScript Engine: JIT component</issue>
|
||||
<issue tracker="cve" id="2025-14330">firefox: JIT miscompilation in the JavaScript Engine: JIT component</issue>
|
||||
<issue tracker="cve" id="2025-14329">firefox: Privilege escalation in the Netmonitor component</issue>
|
||||
<issue tracker="cve" id="2025-14331">firefox: Same-origin policy bypass in the Request Handling component</issue>
|
||||
<issue tracker="cve" id="2025-14333">firefox: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146</issue>
|
||||
<packager>Yoshio_Sato</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for MozillaThunderbird</summary>
|
||||
<description>This update for MozillaThunderbird fixes the following issues:
|
||||
|
||||
Changes in MozillaThunderbird:
|
||||
|
||||
- Mozilla Thunderbird 140.6.0 ESR
|
||||
MFSA 2025-96 (bsc#1254551)
|
||||
* CVE-2025-14321 (bmo#1992760)
|
||||
Use-after-free in the WebRTC: Signaling component
|
||||
* CVE-2025-14322 (bmo#1996473)
|
||||
Sandbox escape due to incorrect boundary conditions in the
|
||||
Graphics: CanvasWebGL component
|
||||
* CVE-2025-14323 (bmo#1996555)
|
||||
Privilege escalation in the DOM: Notifications component
|
||||
* CVE-2025-14324 (bmo#1996840)
|
||||
JIT miscompilation in the JavaScript Engine: JIT component
|
||||
* CVE-2025-14325 (bmo#1998050)
|
||||
JIT miscompilation in the JavaScript Engine: JIT component
|
||||
* CVE-2025-14328 (bmo#1996761)
|
||||
Privilege escalation in the Netmonitor component
|
||||
* CVE-2025-14329 (bmo#1997018)
|
||||
Privilege escalation in the Netmonitor component
|
||||
* CVE-2025-14330 (bmo#1997503)
|
||||
JIT miscompilation in the JavaScript Engine: JIT component
|
||||
* CVE-2025-14331 (bmo#2000218)
|
||||
Same-origin policy bypass in the Request Handling component
|
||||
* CVE-2025-14333 (bmo#1966501, bmo#1997639)
|
||||
Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird
|
||||
ESR 140.6, Firefox 146 and Thunderbird 146
|
||||
</description>
|
||||
<package>MozillaThunderbird</package>
|
||||
</patchinfo>
|
||||
45
patchinfo.20260113100344517680.93181000773252/_patchinfo
Normal file
45
patchinfo.20260113100344517680.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,45 @@
|
||||
<patchinfo incident="packagehub-70">
|
||||
<issue tracker="cve" id="2025-69195"/>
|
||||
<issue tracker="bnc" id="1255729">VUL-0: CVE-2025-69195: wget2: memory corruption and crash via filename sanitization logic with attacker-controlled URLs</issue>
|
||||
<issue tracker="cve" id="2025-69194"/>
|
||||
<issue tracker="bnc" id="1255728">VUL-0: CVE-2025-69194: wget2: arbitrary file write via Metalink path traversal</issue>
|
||||
<packager>jengelh</packager>
|
||||
<rating>important</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for wget2</summary>
|
||||
<description>This update for wget2 fixes the following issues:
|
||||
|
||||
Changes in wget2:
|
||||
|
||||
- Update to release 2.2.1
|
||||
* Fix file overwrite issue with metalink [CVE-2025-69194 bsc#1255728]
|
||||
* Fix remote buffer overflow in get_local_filename_real()
|
||||
[CVE-2025-69195 bsc#1255729]
|
||||
* Fix a redirect/mirror regression from 400713ca
|
||||
* Use the local system timestamp when requested via
|
||||
--no-use-server-timestamps
|
||||
* Prevent file truncation with --no-clobber
|
||||
* Improve messages about why URLs are not being followed
|
||||
* Fix metalink with -O/--output-document
|
||||
* Fix sorting of metalink mirrors by priority
|
||||
* Add --show-progress to improve backwards compatibility to wget
|
||||
* Fix buffer overflow in wget_iri_clone() after
|
||||
wget_iri_set_scheme()
|
||||
* Allow 'no_' prefix in config options
|
||||
* Use libnghttp2 for HTTP/2 testing
|
||||
* Set exit status to 8 on 403 response code
|
||||
* Fix convert-links
|
||||
* Fix --server-response for HTTP/1.1
|
||||
|
||||
- Update to release 2.2.0
|
||||
* Don't truncate file when -c and -O are combined
|
||||
* Don't log URI userinfo to logs
|
||||
* Fix downloading multiple files via HTTP/2
|
||||
* Support connecting with HTTP/1.0 proxies
|
||||
* Ignore 1xx HTTP responses for HTTP/1.1
|
||||
* Disable TCP Fast Open by default
|
||||
* Fix segfault when OCSP response is missing
|
||||
* Add libproxy support
|
||||
</description>
|
||||
<package>wget2</package>
|
||||
</patchinfo>
|
||||
45
patchinfo.20260113125217848639.93181000773252/_patchinfo
Normal file
45
patchinfo.20260113125217848639.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,45 @@
|
||||
<patchinfo incident="packagehub-69">
|
||||
<packager>os-autoinst-obs-workflow</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for openQA, os-autoinst, openQA-devel-container</summary>
|
||||
<description>This update for openQA, os-autoinst, openQA-devel-container fixes the following issues:
|
||||
|
||||
Changes in openQA:
|
||||
|
||||
Thu Jan 08 10:09:35 UTC 2026 - okurz@suse.com
|
||||
- Update to version 5.1767864265.63cd20df:
|
||||
* Skip caching for KERNEL and INITRD variables
|
||||
|
||||
- Update to version 5.1766150951.2799046e:
|
||||
* Coverage of openQA: add folder Client/ in codecov.yaml
|
||||
* Improve openQA coverage of _download_handler in Archive.pm
|
||||
|
||||
- Update to version 5.1766053374.57cdeee3:
|
||||
* fix(docs): Fix indentation in job template examples
|
||||
|
||||
Changes in os-autoinst:
|
||||
|
||||
- Update to version 5.1767893100.fd5003c:
|
||||
* Add documentation of APPEND variable
|
||||
* Add undocumented KERNEL/INITRD to the supported variables
|
||||
* os-autoinst-generate-needle-preview: Embed PNG
|
||||
* Tweak curl call not to hang
|
||||
* Fix opencv dependency due to upstream changes
|
||||
|
||||
Changes in openQA-devel-container:
|
||||
|
||||
- Update to version 5.1767864265.63cd20dfc:
|
||||
* Update to latest openQA version
|
||||
</description>
|
||||
<package>openQA</package>
|
||||
<package>openQA:openQA-devel-test</package>
|
||||
<package>openQA:openQA-test</package>
|
||||
<package>openQA:openQA-worker-test</package>
|
||||
<package>openQA:openQA-client-test</package>
|
||||
<package>os-autoinst</package>
|
||||
<package>os-autoinst:os-autoinst-test</package>
|
||||
<package>os-autoinst:os-autoinst-devel-test</package>
|
||||
<package>os-autoinst:os-autoinst-openvswitch-test</package>
|
||||
<package>openQA-devel-container</package>
|
||||
</patchinfo>
|
||||
14
patchinfo.20260113130548514612.93181000773252/_patchinfo
Normal file
14
patchinfo.20260113130548514612.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,14 @@
|
||||
<patchinfo incident="packagehub-74">
|
||||
<issue tracker="bnc" id="1255237">scripts it $XDG_CONFIG_DIRS/plasma-workspace/env stop working after ibus update</issue>
|
||||
<packager>ftake</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for fcitx5</summary>
|
||||
<description>This update for fcitx5 fixes the following issues:
|
||||
|
||||
|
||||
- Use return instead of exit in 20-fcitx-plasma-setup.sh (boo#1255237)
|
||||
- Replace "IBus" with "Fcitx" in a log message
|
||||
</description>
|
||||
<package>fcitx5</package>
|
||||
</patchinfo>
|
||||
35
patchinfo.20260115100809875766.93181000773252/_patchinfo
Normal file
35
patchinfo.20260115100809875766.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,35 @@
|
||||
<patchinfo incident="packagehub-80">
|
||||
<issue tracker="cve" id="2026-0907">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<issue tracker="cve" id="2026-0908">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<issue tracker="cve" id="2026-0901">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<issue tracker="cve" id="2026-0902">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<issue tracker="cve" id="2026-0906">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<issue tracker="cve" id="2026-0903">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<issue tracker="cve" id="2026-0905">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<issue tracker="cve" id="2026-0900">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<issue tracker="cve" id="2026-0904">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<issue tracker="cve" id="2026-0899">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<issue tracker="bnc" id="1256614">VUL-0: chromium: release 144.0.7559.59</issue>
|
||||
<packager>oertel</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for chromium</summary>
|
||||
<description>This update for chromium fixes the following issues:
|
||||
|
||||
Changes in chromium:
|
||||
|
||||
- Chromium 144.0.7559.59 (boo#1256614)
|
||||
* CVE-2026-0899: Out of bounds memory access in V8
|
||||
* CVE-2026-0900: Inappropriate implementation in V8
|
||||
* CVE-2026-0901: Inappropriate implementation in Blink
|
||||
* CVE-2026-0902: Inappropriate implementation in V8
|
||||
* CVE-2026-0903: Insufficient validation of untrusted input in Downloads
|
||||
* CVE-2026-0904: Incorrect security UI in Digital Credentials
|
||||
* CVE-2026-0905: Insufficient policy enforcement in Network
|
||||
* CVE-2026-0906: Incorrect security UI
|
||||
* CVE-2026-0907: Incorrect security UI in Split View
|
||||
* CVE-2026-0908: Use after free in ANGLE
|
||||
- use noopenh264 where available
|
||||
</description>
|
||||
<package>chromium</package>
|
||||
</patchinfo>
|
||||
55
patchinfo.20260115100949201882.93181000773252/_patchinfo
Normal file
55
patchinfo.20260115100949201882.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,55 @@
|
||||
<patchinfo incident="packagehub-79">
|
||||
<packager>os-autoinst-obs-workflow</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for openQA, os-autoinst, openQA-devel-container</summary>
|
||||
<description>This update for openQA, os-autoinst, openQA-devel-container fixes the following issues:
|
||||
|
||||
Changes in openQA:
|
||||
|
||||
- Update to version 5.1768323619.9a70ab91:
|
||||
* refactor: Extend tests of df-based cleanup
|
||||
* fix: Avoid wrong deletion of archived jobs in df-based cleanup
|
||||
* refactor: Move logic for validating percentage into helper
|
||||
* refactor: Clarify wording in comment regarding job cleanup
|
||||
* Use template literals in certain JavaScript code
|
||||
* Retry delete_needles job on server restart
|
||||
* Add test for _delete_needles
|
||||
* feat(OpenQA::Git): Cleanup git dir in commit() on shutdown
|
||||
* feat: Improve rendering results on the scheduled product page
|
||||
|
||||
- Update to version 5.1768209690.f34c2973:
|
||||
* feat(scheduled-products): Allow adding note to result data
|
||||
* docs: Use node_modules target
|
||||
* docs: Mention minimum PostgreSQL version
|
||||
* ci: Update PostgreSQL in CI/packaging to at least 14
|
||||
* Revert "Add MCP tool annotations for Claude connector compliance"
|
||||
|
||||
- Update to version 5.1767868268.dacbd3f7:
|
||||
* Add MCP tool annotations for Claude connector compliance
|
||||
|
||||
Changes in os-autoinst:
|
||||
|
||||
- Update to version 5.1768317525.86a9a7f:
|
||||
* fix(dist): exclude unstable t/28-signalblocker.t in OBS checks
|
||||
* Remove deprecated BIOS and UEFI_PFLASH variables
|
||||
* Add documentation of APPEND variable
|
||||
* Add undocumented KERNEL/INITRD to the supported variables
|
||||
* os-autoinst-generate-needle-preview: Embed PNG
|
||||
|
||||
Changes in openQA-devel-container:
|
||||
|
||||
- Update to version 5.1768323619.9a70ab916:
|
||||
* Update to latest openQA version
|
||||
</description>
|
||||
<package>openQA</package>
|
||||
<package>openQA:openQA-devel-test</package>
|
||||
<package>openQA:openQA-test</package>
|
||||
<package>openQA:openQA-worker-test</package>
|
||||
<package>openQA:openQA-client-test</package>
|
||||
<package>os-autoinst</package>
|
||||
<package>os-autoinst:os-autoinst-test</package>
|
||||
<package>os-autoinst:os-autoinst-devel-test</package>
|
||||
<package>os-autoinst:os-autoinst-openvswitch-test</package>
|
||||
<package>openQA-devel-container</package>
|
||||
</patchinfo>
|
||||
22
patchinfo.20260115101101937926.93181000773252/_patchinfo
Normal file
22
patchinfo.20260115101101937926.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,22 @@
|
||||
<patchinfo incident="packagehub-83">
|
||||
<issue tracker="jsc" id="PED-1942">feature request for adding ipvlan support to wicked for SLES15</issue>
|
||||
<packager>cfconrad</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for wicked</summary>
|
||||
<description>This update for wicked fixes the following issues:
|
||||
|
||||
Changes in wicked:
|
||||
|
||||
- Update to version 0.6.78
|
||||
- man: small fixes in wireless manpage (gh#opensuse/wicked#1053)
|
||||
- rtnetlink: fix RTM_NEWLINK name resolution in debug (gh#opensuse/wicked#1052)
|
||||
- Add support for IPVLAN/IPVTAP (jsc#PED-1942, gh#opensuse/wicked#1050, gh#opensuse/wicked#1051)
|
||||
- fsm: remove children reference array from worker (gh#opensuse/wicked#1049)
|
||||
- ifxml: migrate and generate lower configs/policies (gh#opensuse/wicked#1048)
|
||||
- fsm: use refcount and array macros in worker and policy (gh#opensuse/wicked#1047)
|
||||
- route: use refcounted array and fix error leaks (gh#opensuse/wicked#1046)
|
||||
- utils: add support for refcounted objects in generic array (gh#openSUSE/wicked#1045)
|
||||
</description>
|
||||
<package>wicked</package>
|
||||
</patchinfo>
|
||||
14
patchinfo.20260115101600453573.93181000773252/_patchinfo
Normal file
14
patchinfo.20260115101600453573.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,14 @@
|
||||
<patchinfo incident="packagehub-75">
|
||||
<packager>jengelh</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for flint</summary>
|
||||
<description>This update for flint fixes the following issues:
|
||||
|
||||
Changes in flint:
|
||||
|
||||
- Fixed a compile error for downstream users when using -std=c23 or
|
||||
a newer GCC which defaults to such.
|
||||
</description>
|
||||
<package>flint</package>
|
||||
</patchinfo>
|
||||
11
patchinfo.20260115114750488113.93181000773252/_patchinfo
Normal file
11
patchinfo.20260115114750488113.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,11 @@
|
||||
<patchinfo incident="packagehub-76">
|
||||
<packager>pgajdos</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>optional</category>
|
||||
<summary>Optional update for dehydrated</summary>
|
||||
<description>This update for dehydrated fixes the following issues:
|
||||
|
||||
Adds dehydrated to PackageHub / Leap 16.0.
|
||||
</description>
|
||||
<package>dehydrated</package>
|
||||
</patchinfo>
|
||||
41
patchinfo.20260115143001930772.93181000773252/_patchinfo
Normal file
41
patchinfo.20260115143001930772.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,41 @@
|
||||
<patchinfo incident="packagehub-77">
|
||||
<issue tracker="bnc" id="1256453">polymake-devel unusable</issue>
|
||||
<packager>jengelh</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for polymake, cddlib</summary>
|
||||
<description>This update for polymake, cddlib fixes the following issues:
|
||||
|
||||
Changes in polymake:
|
||||
|
||||
- Enable polydb for Tumbleweed / suse_version >=1690
|
||||
|
||||
- Reenable callable library mode [boo#1256453]
|
||||
|
||||
- Update to release 4.15
|
||||
* graph: graphviz: use PDF instead of PS
|
||||
* polytope: MILP: allow non-rational coordinates
|
||||
* Some bugfixes
|
||||
|
||||
- Update to release 4.14
|
||||
* tropical: cone: refactoring and fixes for DOME, COVECTORs and
|
||||
PSEUDOVERTICES
|
||||
* tropical: polytope: fix vertices computation
|
||||
* tropical: hypersurface: fixes for monomials and binomials
|
||||
|
||||
- Update to release 4.13
|
||||
* Support for Perl 5.40 and -std=c++20 builds
|
||||
|
||||
Changes in cddlib:
|
||||
|
||||
- Update to release 0.94n
|
||||
* Fixed a potential dd_MatrixCanonicalize segfault.
|
||||
* cddlib.pc file now points to the non-GMP version, and
|
||||
cddgmp.pc has been added for the GMP version.
|
||||
* Copy certificate and handle errors correctly in dd_SRedundant
|
||||
for the V-representation code path.
|
||||
* cddlib is now thread-safe.
|
||||
</description>
|
||||
<package>polymake</package>
|
||||
<package>cddlib</package>
|
||||
</patchinfo>
|
||||
25
patchinfo.20260115164300444802.93181000773252/_patchinfo
Normal file
25
patchinfo.20260115164300444802.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,25 @@
|
||||
<patchinfo incident="packagehub-78">
|
||||
<packager>mmamula</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for ansible-sap-launchpad</summary>
|
||||
<description>This update for ansible-sap-launchpad fixes the following issues:
|
||||
|
||||
Changes in ansible-sap-launchpad:
|
||||
|
||||
- Refactor Ansible Modules and adjust for ansible-core 2.19.
|
||||
|
||||
- 1.3.1
|
||||
- Bugfixes:
|
||||
- collection: Add ansible-test sanity workflow and fix sanity errors
|
||||
|
||||
- 1.3.0
|
||||
- Changes:
|
||||
- collection: Refactor all Ansible Modules
|
||||
- sap_software_download: Update for ansible-core 2.19
|
||||
- Bugfixes:
|
||||
- sap_software_download: Fix for failed checksums not correctly retrying
|
||||
|
||||
</description>
|
||||
<package>ansible-sap-launchpad</package>
|
||||
</patchinfo>
|
||||
95
patchinfo.20260116150132416590.93181000773252/_patchinfo
Normal file
95
patchinfo.20260116150132416590.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,95 @@
|
||||
<patchinfo incident="packagehub-82">
|
||||
<issue tracker="cve" id="2025-58190"/>
|
||||
<issue tracker="bnc" id="1241814">VUL-0: CVE-2025-22872: go-sendxmpp: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction</issue>
|
||||
<issue tracker="cve" id="2025-22872">VUL-0: CVE-2025-22872: TRACKERBUG: golang.org/x/net/html: tags incorrectly interpreted by tokenizer can lead to content being placed in the wrong scope during</issue>
|
||||
<issue tracker="bnc" id="1251677">VUL-0: CVE-2025-58190: go-sendxmpp: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input</issue>
|
||||
<issue tracker="bnc" id="1251461">VUL-0: CVE-2025-47911: go-sendxmpp: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<issue tracker="cve" id="2025-47911">VUL-0: CVE-2025-47911: TRACKERBUG: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents</issue>
|
||||
<packager>fstrba</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>security</category>
|
||||
<summary>Security update for go-sendxmpp</summary>
|
||||
<description>This update for go-sendxmpp fixes the following issues:
|
||||
|
||||
Changes in go-sendxmpp:
|
||||
|
||||
- Update to 0.15.1:
|
||||
Added
|
||||
* Add XEP-0359 Origin-ID to messages (requires go-xmpp >= v0.2.18).
|
||||
Changed
|
||||
* HTTP upload: Ignore timeouts on disco IQs as some components do
|
||||
not reply.
|
||||
- Upgrades the embedded golang.org/x/net to 0.46.0
|
||||
* Fixes: bsc#1251461, CVE-2025-47911: various algorithms with
|
||||
quadratic complexity when parsing HTML documents
|
||||
* Fixes: bsc#1251677, CVE-2025-58190: excessive memory consumption
|
||||
by 'html.ParseFragment' when processing specially crafted input
|
||||
|
||||
- Update to 0.15.0:
|
||||
Added:
|
||||
* Add flag --verbose to show debug information.
|
||||
* Add flag --recipients to specify recipients by file.
|
||||
* Add flag --retry-connect to try after a waiting time if the connection fails.
|
||||
* Add flag --retry-connect-max to specify the amount of retry attempts.
|
||||
* Add flag --legacy-pgp for using XEP-0027 PGP encryption with Ox keys.
|
||||
* Add support for punycode domains.
|
||||
Changed:
|
||||
* Update gopenpgp library to v3.
|
||||
* Improve error detection for MUC joins.
|
||||
* Don't try to connect to other SRV record targets if error contains 'auth-failure'.
|
||||
* Remove support for old SSDP version (via go-xmpp v0.2.15).
|
||||
* Http-upload: Stop checking other disco items after finding upload component.
|
||||
* Increase default TLS version to 1.3.
|
||||
- bsc#1241814 (CVE-2025-22872): This update includes golang.org/x/net/html 0.43.0
|
||||
|
||||
- Update to 0.14.1:
|
||||
* Use prettier date format for error messages.
|
||||
* Update XEP-0474 to version 0.4.0 (requires go-xmpp >= 0.2.10).
|
||||
|
||||
- Update to 0.14.0:
|
||||
Added:
|
||||
* Add --fast-invalidate to allow invalidating the FAST token.
|
||||
Changed:
|
||||
* Don't create legacy Ox private key directory in ~/.local/share/go-sendxmpp/oxprivkeys.
|
||||
* Delete legacy Ox private key directory if it's empty.
|
||||
* Show proper error if saved FAST mechanism isn't usable with current TLS version (requires go-xmpp >= 0.2.9).
|
||||
* Print debug output to stdout, not stderr (requires go-xmpp >= 0.2.9).
|
||||
* Show RECV: and SEND: prefix for debug output (requires go-xmpp >= 0.2.9).
|
||||
* Delete stored fast token if --fast-invalidate and --fast-off are set.
|
||||
* Show error when FAST creds are stored but non-FAST mechanism is requested.
|
||||
|
||||
- Update to 0.13.0:
|
||||
Added:
|
||||
* Add --anonymous to support anonymous authentication (requires go-xmpp >= 0.2.8).
|
||||
* Add XEP-0480: SASL Upgrade Tasks support (requires go-xmpp >= 0.2.8).
|
||||
* Add support for see-other-host stream error (requires go-xmpp >= 0.2.8).
|
||||
Changed:
|
||||
* Don't automatically try other auth mechanisms if FAST authentication fails.
|
||||
|
||||
- Update to 0.12.1:
|
||||
Changed:
|
||||
* Print error instead of quitting if a message of type error is received.
|
||||
* Allow upload of multiple files.
|
||||
Added:
|
||||
* Add flag --suppress-root-warning to suppress the warning when go-sendxmpp is used by the root user.
|
||||
|
||||
- Update to 0.12.0:
|
||||
Added:
|
||||
* Add possibility to look up direct TLS connection endpoint via hostmeta2 (requires xmppsrv >= 0.3.3).
|
||||
* Add flag --allow-plain to allow PLAIN authentication (requires go-xmpp >= 0.2.5).
|
||||
Changed:
|
||||
* Disable PLAIN authentication per default.
|
||||
* Disable PLAIN authentication after first use of a SCRAM auth mechanism (overrides --allow-plain) (requires
|
||||
go-xmpp >= 0.2.5).
|
||||
|
||||
- Update to 0.11.4:
|
||||
* Fix bug in SCRAM-SHA-256-PLUS (via go-xmpp >= 0.2.4).
|
||||
|
||||
- Update to 0.11.3:
|
||||
* Add go-xmpp library version to --version output (requires go-xmpp >= 0.2.2).
|
||||
* Fix XEP-0474: SASL SCRAM Downgrade Protection hash calculation bug (via go-xmpp >= v0.2.3).
|
||||
* [gocritic]: Improve code quality.
|
||||
</description>
|
||||
<package>go-sendxmpp</package>
|
||||
<seperate_build_arch/>
|
||||
</patchinfo>
|
||||
79
patchinfo.20260119134919947913.93181000773252/_patchinfo
Normal file
79
patchinfo.20260119134919947913.93181000773252/_patchinfo
Normal file
@@ -0,0 +1,79 @@
|
||||
<patchinfo>
|
||||
<packager>gbazzotti</packager>
|
||||
<rating>moderate</rating>
|
||||
<category>recommended</category>
|
||||
<summary>Recommended update for micro-editor</summary>
|
||||
<description>This update for micro-editor fixes the following issues:
|
||||
|
||||
Changes in micro-editor:
|
||||
|
||||
- Update to version 2.0.15:
|
||||
* truecolor (supersedes the MICRO_TRUECOLOR environment variable)
|
||||
* showchars (deprecates indentchar)
|
||||
* lockbindings for completely disallowing plugins to modify keybindings
|
||||
* helpsplit for changing default split type for the help command
|
||||
* pageoverlap for setting number of lines kept during page up/page down
|
||||
* Added FirstTab, LastTab, FirstSplit and LastSplit commands
|
||||
* SkipMultiCursorBack as a counterpart to SkipMultiCursor
|
||||
* CursorToViewTop, CursorToViewCenter, CursorToViewBottom
|
||||
* Duplicate for duplicating the selection only, not the whole line
|
||||
* Plugins never write to settings.json or bindings.json anymore
|
||||
* Add onBufferOptionChanged callback
|
||||
* Add SpawnCursorAtLoc()
|
||||
* Expose bufpane's DoubleClick and TripleClick to plugins
|
||||
* Pass mouse info to {on,pre}MouseXXX callbacks
|
||||
* Support goto statement from Lua 5.2
|
||||
* Various Syntax Highlighting improvements
|
||||
|
||||
- Update to version 2.0.14:
|
||||
* matchbracestyle to choose whether to underline or highlight matching braces
|
||||
* matchbraceleft to choose whether to match brace to the left of the cursor
|
||||
* hltrailingws to highlight trailing whitespace
|
||||
* hltaberrors to highlight tab vs space inconsistencies
|
||||
* Add jump command to perform a relative goto
|
||||
* Add sub-word movement actions and improve word movements
|
||||
* Add paragraph selection actions and improve paragraph movements
|
||||
* Make Shift-PageUp/Down the default keybindings for SelectPageUp/Down
|
||||
* Add signatures support to improve filetype detection in ambiguous cases
|
||||
* Provide default.yaml for default syntax highlighting
|
||||
* Improvements in syntax highlighting for various languages
|
||||
* More generic support for mouse events handling
|
||||
* Add mouse release and mouse drag events
|
||||
* Make MouseMultiCursor toggle cursors
|
||||
* Better support for handling mouse events in lua
|
||||
* Better API for lua timers
|
||||
* Add onAnyEvent callback
|
||||
* Allow colorschemes to include other colorschemes
|
||||
* Give user's files in ~/.config/micro/ precedence over micro's built-in
|
||||
files
|
||||
* Respect umask when creating files
|
||||
* Smarter smartpaste
|
||||
* Make default fileformat value suited to the OS
|
||||
* Improve buffer view relocation after jumping to a far-away location
|
||||
* Improve return values of some actions for better action chaining
|
||||
* Autocomplete filetypes
|
||||
* Allow raw escape sequence to be bound with bind
|
||||
* Various small improvements
|
||||
* Fix various crashes
|
||||
* Fix micro killed by SIGINT sent to its shell job
|
||||
* Various fixes for setting local options
|
||||
* Various fixes for reloading settings via reload command
|
||||
* Various fixes for updating settings after changing filetype
|
||||
* Fix unneeded rewriting of settings.json
|
||||
* Fix overwriting persistent non-default settings in settings.json with
|
||||
temporary default settings
|
||||
* Don't apply rmtrailingws on autosave
|
||||
* Don't autosave unmodified buffer
|
||||
* Properly update autosave timer when the autosave option value changes
|
||||
* Fix opening filenames including colons with parsecursor
|
||||
* Fix replace to be able to insert '$'
|
||||
* Fix cursor moving to an unexpected location after a redo
|
||||
* Make cursor movements after selection consistent
|
||||
* Fix incorrect buffer view after reloading file
|
||||
* Fix lost mouse release events in case the pane becomes inactive
|
||||
* Add proper locking to LineArray to fix potential races
|
||||
* Cleanup indentation and trailing whitespace
|
||||
* Improve plugin documentation
|
||||
</description>
|
||||
<package>micro-editor</package>
|
||||
</patchinfo>
|
||||
2
polymake
2
polymake
Submodule polymake updated: 83d3dd6e6a...7829f5e5e7
1
python-augeas
Submodule
1
python-augeas
Submodule
Submodule python-augeas added at edad9ed486
1
python-bson
Submodule
1
python-bson
Submodule
Submodule python-bson added at 8ac5655845
1
python-certbot-apache
Submodule
1
python-certbot-apache
Submodule
Submodule python-certbot-apache added at 494a1b647e
1
python-certbot-dns-cloudflare
Submodule
1
python-certbot-dns-cloudflare
Submodule
Submodule python-certbot-dns-cloudflare added at 2c421bc1e2
1
python-certbot-dns-digitalocean
Submodule
1
python-certbot-dns-digitalocean
Submodule
Submodule python-certbot-dns-digitalocean added at f5dbdff0ae
1
python-certbot-dns-dnsimple
Submodule
1
python-certbot-dns-dnsimple
Submodule
Submodule python-certbot-dns-dnsimple added at d61bee3e05
1
python-certbot-dns-dnsmadeeasy
Submodule
1
python-certbot-dns-dnsmadeeasy
Submodule
Submodule python-certbot-dns-dnsmadeeasy added at d27a1b8b10
1
python-certbot-dns-linode
Submodule
1
python-certbot-dns-linode
Submodule
Submodule python-certbot-dns-linode added at 2724dcf39b
1
python-certbot-dns-luadns
Submodule
1
python-certbot-dns-luadns
Submodule
Submodule python-certbot-dns-luadns added at 99f5dd27f8
1
python-certbot-dns-nsone
Submodule
1
python-certbot-dns-nsone
Submodule
Submodule python-certbot-dns-nsone added at 87233eaf9d
1
python-certbot-dns-ovh
Submodule
1
python-certbot-dns-ovh
Submodule
Submodule python-certbot-dns-ovh added at feaf7e1a31
1
python-certbot-dns-rfc2136
Submodule
1
python-certbot-dns-rfc2136
Submodule
Submodule python-certbot-dns-rfc2136 added at 1925c5a1c0
1
python-certbot-dns-route53
Submodule
1
python-certbot-dns-route53
Submodule
Submodule python-certbot-dns-route53 added at bccfbc92c0
1
python-cloudflare
Submodule
1
python-cloudflare
Submodule
Submodule python-cloudflare added at 5eb0366ea9
1
python-digitalocean
Submodule
1
python-digitalocean
Submodule
Submodule python-digitalocean added at d6a3534a6d
1
python-dns-lexicon
Submodule
1
python-dns-lexicon
Submodule
Submodule python-dns-lexicon added at 4879af3946
1
python-jsonlines
Submodule
1
python-jsonlines
Submodule
Submodule python-jsonlines added at 71ed37f7af
1
python-jsonpickle
Submodule
1
python-jsonpickle
Submodule
Submodule python-jsonpickle added at f00ff57fde
1
python-localzone
Submodule
1
python-localzone
Submodule
Submodule python-localzone added at 9542dae7a4
1
python-pytest-httpx
Submodule
1
python-pytest-httpx
Submodule
Submodule python-pytest-httpx added at 133221a192
1
python-requests-file
Submodule
1
python-requests-file
Submodule
Submodule python-requests-file added at 585632624f
1
python-softlayer
Submodule
1
python-softlayer
Submodule
Submodule python-softlayer added at 6ff6f97894
1
python-softlayer-zeep
Submodule
1
python-softlayer-zeep
Submodule
Submodule python-softlayer-zeep added at 4cb1f222a3
1
python-tldextract
Submodule
1
python-tldextract
Submodule
Submodule python-tldextract added at 716c699b9c
2
ranger
2
ranger
Submodule ranger updated: b2aa5fe5f7...4d06d462ce
2
trivy
2
trivy
Submodule trivy updated: cdbf0f01cd...1901ecd770
2
wget2
2
wget2
Submodule wget2 updated: f4e4440ab0...a444330efc
2
wicked
2
wicked
Submodule wicked updated: d61f1b645c...0ca44956ef
Reference in New Issue
Block a user