From ddd8723888786a64e5b5ff1ef2f5d20dad5f2a84cb88227f2977d8530ee25424 Mon Sep 17 00:00:00 2001 From: Dominik Heidler Date: Tue, 27 Sep 2022 21:28:47 +0000 Subject: [PATCH 1/4] - Version 1.11.6 OBS-URL: https://build.opensuse.org/package/show/devel:languages:nodejs/element-web?expand=0&rev=15 --- element-web-1.11.5.tar.gz | 3 --- element-web-1.11.6.tar.gz | 3 +++ element-web.changes | 35 +++++++++++++++++++++++++++++++ element-web.spec | 2 +- npm-packages-offline-cache.tar.gz | 4 ++-- prepare.sh | 6 +++++- 6 files changed, 46 insertions(+), 7 deletions(-) delete mode 100644 element-web-1.11.5.tar.gz create mode 100644 element-web-1.11.6.tar.gz diff --git a/element-web-1.11.5.tar.gz b/element-web-1.11.5.tar.gz deleted file mode 100644 index 2d2ee2d..0000000 --- a/element-web-1.11.5.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:08cd5542f7c9e9bb479b27fcf16247e75dfc80cdee5b0e3ee7c11a7fbe27d4a7 -size 1459602 diff --git a/element-web-1.11.6.tar.gz b/element-web-1.11.6.tar.gz new file mode 100644 index 0000000..7bdcae2 --- /dev/null +++ b/element-web-1.11.6.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:ee2eea6bd1390fa267b36a225eae8af6525d81bd5ccac595784c0da84dbfe841 +size 1463486 diff --git a/element-web.changes b/element-web.changes index 70735c1..51ed7fc 100644 --- a/element-web.changes +++ b/element-web.changes @@ -1,3 +1,38 @@ +------------------------------------------------------------------- +Tue Sep 27 21:25:44 UTC 2022 - Dominik Heidler + +- Version 1.11.6 +## ✨ Features + * Element Call video rooms ([\#9267](https://github.com/matrix-org/matrix-react-sdk/pull/9267)). + * Device manager - rename session ([\#9282](https://github.com/matrix-org/matrix-react-sdk/pull/9282)). + * Allow widgets to read related events ([\#9210](https://github.com/matrix-org/matrix-react-sdk/pull/9210)). Contributed by @dhenneke. + * Device manager - logout of other session ([\#9280](https://github.com/matrix-org/matrix-react-sdk/pull/9280)). + * Device manager - logout current session ([\#9275](https://github.com/matrix-org/matrix-react-sdk/pull/9275)). + * Device manager - verify other devices ([\#9274](https://github.com/matrix-org/matrix-react-sdk/pull/9274)). + * Allow integration managers to remove users ([\#9211](https://github.com/matrix-org/matrix-react-sdk/pull/9211)). + * Device manager - add verify current session button ([\#9252](https://github.com/matrix-org/matrix-react-sdk/pull/9252)). + * Add NotifPanel dot back. ([\#9242](https://github.com/matrix-org/matrix-react-sdk/pull/9242)). Fixes #17641. + * Implement MSC3575: Sliding Sync ([\#8328](https://github.com/matrix-org/matrix-react-sdk/pull/8328)). + * Add the clipboard read permission for widgets ([\#9250](https://github.com/matrix-org/matrix-react-sdk/pull/9250)). Contributed by @stefanmuhle. + +## 🐛 Bug Fixes + * Make autocomplete pop-up wider in thread view ([\#9289](https://github.com/matrix-org/matrix-react-sdk/pull/9289)). + * Fix soft crash around inviting invalid MXIDs in start DM on first message flow ([\#9281](https://github.com/matrix-org/matrix-react-sdk/pull/9281)). Fixes matrix-org/element-web-rageshakes#15060 and matrix-org/element-web-rageshakes#15140. + * Fix in-reply-to previews not disappearing when swapping rooms ([\#9278](https://github.com/matrix-org/matrix-react-sdk/pull/9278)). + * Fix invalid instanceof operand window.OffscreenCanvas ([\#9276](https://github.com/matrix-org/matrix-react-sdk/pull/9276)). Fixes #23275. + * Fix memory leak caused by unremoved listener ([\#9273](https://github.com/matrix-org/matrix-react-sdk/pull/9273)). + * Fix thumbnail generation when offscreen canvas fails ([\#9272](https://github.com/matrix-org/matrix-react-sdk/pull/9272)). Fixes #23265. + * Prevent sliding sync from showing a room under multiple sublists ([\#9266](https://github.com/matrix-org/matrix-react-sdk/pull/9266)). + * Fix tile crash around tooltipify links ([\#9270](https://github.com/matrix-org/matrix-react-sdk/pull/9270)). Fixes #23253. + * Device manager - filter out nulled metadatas in device tile properly ([\#9251](https://github.com/matrix-org/matrix-react-sdk/pull/9251)). + * Fix a sliding sync bug which could cause rooms to loop ([\#9268](https://github.com/matrix-org/matrix-react-sdk/pull/9268)). + * Remove the grey gradient on images in bubbles in the timeline ([\#9241](https://github.com/matrix-org/matrix-react-sdk/pull/9241)). Fixes #21651. + * Fix html export not including images ([\#9260](https://github.com/matrix-org/matrix-react-sdk/pull/9260)). Fixes #22059. + * Fix possible soft crash from a race condition in space hierarchies ([\#9254](https://github.com/matrix-org/matrix-react-sdk/pull/9254)). Fixes matrix-org/element-web-rageshakes#15225. + * Disable all types of autocorrect, -complete, -capitalize, etc on Spotlight's search field ([\#9259](https://github.com/matrix-org/matrix-react-sdk/pull/9259)). + * Handle M_INVALID_USERNAME on /register/available ([\#9237](https://github.com/matrix-org/matrix-react-sdk/pull/9237)). Fixes #23161. + * Fix issue with quiet zone around QR code ([\#9243](https://github.com/matrix-org/matrix-react-sdk/pull/9243)). Fixes #23199. + ------------------------------------------------------------------- Wed Sep 14 09:12:15 UTC 2022 - Dominik Heidler diff --git a/element-web.spec b/element-web.spec index dc0c8a2..648c0e7 100644 --- a/element-web.spec +++ b/element-web.spec @@ -17,7 +17,7 @@ Name: element-web -Version: 1.11.5 +Version: 1.11.6 Release: 0 Summary: A glossy Matrix collaboration client - web files License: Apache-2.0 diff --git a/npm-packages-offline-cache.tar.gz b/npm-packages-offline-cache.tar.gz index fd74993..2e3a68c 100644 --- a/npm-packages-offline-cache.tar.gz +++ b/npm-packages-offline-cache.tar.gz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:41cfbd35a2e89a07e84a46ace1b1af7a8465c0c3322f6d50e64523f648d9c7b5 -size 90709387 +oid sha256:6301f2403af64a821f297a7f7133816ee9f9c6d7b38bb36aba3637551e0197ea +size 94640255 diff --git a/prepare.sh b/prepare.sh index 3ae9b05..8cb8317 100644 --- a/prepare.sh +++ b/prepare.sh @@ -19,10 +19,12 @@ wget -c https://github.com/vector-im/element-web/archive/v${version}.tar.gz -O e tar xzvf element-web-${version}.tar.gz cd element-web-${version} +changes=$(grep "^=============" -B10000 -m2 CHANGELOG.md | head -n -3 | tail -n +4) + echo 'yarn-offline-mirror "./npm-packages-offline-cache"' > .yarnrc yarn cache clean rm -rf node_modules/ -yarn install --pure-lockfile || : # this will download tha packages into the offline cache +yarn install --pure-lockfile --ignore-engines || : # this will download tha packages into the offline cache # download some additional dependencie that slips through this earlier method cd ./npm-packages-offline-cache/ @@ -57,6 +59,8 @@ echo rm -rf "$tmpdir" echo -e "\n\nDONE creating npm dependency offline cache file 'npm-packages-offline-cache.tar.gz'" +read -p "Write changes?" +osc vc -m "Version ${version}\n${changes}" element-web.changes #DIST_VERSION=$version ./scripts/package.sh # From 37ef9cf712ae255da78614c5963fd70815d1a0b2a28cb48284b9d2514ec2cbee Mon Sep 17 00:00:00 2001 From: Dominik Heidler Date: Wed, 28 Sep 2022 13:01:04 +0000 Subject: [PATCH 2/4] - Security fix for: * CVE-2022-39249 * CVE-2022-39250 * CVE-2022-39251 * CVE-2022-39236 OBS-URL: https://build.opensuse.org/package/show/devel:languages:nodejs/element-web?expand=0&rev=16 --- element-web-1.11.6.tar.gz | 4 ++-- element-web.changes | 9 +++++++++ npm-packages-offline-cache.tar.gz | 4 ++-- 3 files changed, 13 insertions(+), 4 deletions(-) diff --git a/element-web-1.11.6.tar.gz b/element-web-1.11.6.tar.gz index 7bdcae2..d94ccb9 100644 --- a/element-web-1.11.6.tar.gz +++ b/element-web-1.11.6.tar.gz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:ee2eea6bd1390fa267b36a225eae8af6525d81bd5ccac595784c0da84dbfe841 -size 1463486 +oid sha256:daa2f3a32987342018a2e52665d4f46852c0bae2b089cb5353d53dcd75c8305e +size 1463346 diff --git a/element-web.changes b/element-web.changes index 51ed7fc..f7eb321 100644 --- a/element-web.changes +++ b/element-web.changes @@ -1,3 +1,12 @@ +------------------------------------------------------------------- +Wed Sep 28 09:25:30 UTC 2022 - Dominik Heidler + +- Security fix for: + * CVE-2022-39249 + * CVE-2022-39250 + * CVE-2022-39251 + * CVE-2022-39236 + ------------------------------------------------------------------- Tue Sep 27 21:25:44 UTC 2022 - Dominik Heidler diff --git a/npm-packages-offline-cache.tar.gz b/npm-packages-offline-cache.tar.gz index 2e3a68c..1b6fe9f 100644 --- a/npm-packages-offline-cache.tar.gz +++ b/npm-packages-offline-cache.tar.gz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:6301f2403af64a821f297a7f7133816ee9f9c6d7b38bb36aba3637551e0197ea -size 94640255 +oid sha256:7657ed9923e19f3d2d2464bc1fb7b632789cad09d791f0d0d886c3fa91f9f214 +size 95095224 From 085a1f6684f41bddd9b56d829d9d489dc78d19de1d1b3c9843c5446fe0ff4a00 Mon Sep 17 00:00:00 2001 From: Dominik Heidler Date: Wed, 28 Sep 2022 13:58:15 +0000 Subject: [PATCH 3/4] =?UTF-8?q?-=20Version=201.11.7=20##=20=F0=9F=94=92=20?= =?UTF-8?q?Security=20*=20Fix=20for=20[CVE-2022-39249](https://cve.mitre.o?= =?UTF-8?q?rg/cgi-bin/cvekey.cgi=3Fkeyword=3DCVE%2D2022%2D39249)=20*=20Fix?= =?UTF-8?q?=20for=20[CVE-2022-39250](https://cve.mitre.org/cgi-bin/cvekey.?= =?UTF-8?q?cgi=3Fkeyword=3DCVE%2D2022%2D39250)=20*=20Fix=20for=20[CVE-2022?= =?UTF-8?q?-39251](https://cve.mitre.org/cgi-bin/cvekey.cgi=3Fkeyword=3DCV?= =?UTF-8?q?E%2D2022%2D39251)=20*=20Fix=20for=20[CVE-2022-39236](https://cv?= =?UTF-8?q?e.mitre.org/cgi-bin/cvekey.cgi=3Fkeyword=3DCVE%2D2022%2D39236)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit OBS-URL: https://build.opensuse.org/package/show/devel:languages:nodejs/element-web?expand=0&rev=17 --- element-web-1.11.6.tar.gz | 3 --- element-web-1.11.7.tar.gz | 3 +++ element-web.changes | 13 +++++++------ element-web.spec | 2 +- npm-packages-offline-cache.tar.gz | 4 ++-- 5 files changed, 13 insertions(+), 12 deletions(-) delete mode 100644 element-web-1.11.6.tar.gz create mode 100644 element-web-1.11.7.tar.gz diff --git a/element-web-1.11.6.tar.gz b/element-web-1.11.6.tar.gz deleted file mode 100644 index d94ccb9..0000000 --- a/element-web-1.11.6.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:daa2f3a32987342018a2e52665d4f46852c0bae2b089cb5353d53dcd75c8305e -size 1463346 diff --git a/element-web-1.11.7.tar.gz b/element-web-1.11.7.tar.gz new file mode 100644 index 0000000..29bb8bf --- /dev/null +++ b/element-web-1.11.7.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:7963049d21621b7998d85b87844f0c000647159d50da45f1e3a8409e804c0070 +size 1463523 diff --git a/element-web.changes b/element-web.changes index f7eb321..068e7c0 100644 --- a/element-web.changes +++ b/element-web.changes @@ -1,11 +1,12 @@ ------------------------------------------------------------------- -Wed Sep 28 09:25:30 UTC 2022 - Dominik Heidler +Wed Sep 28 13:56:17 UTC 2022 - Dominik Heidler -- Security fix for: - * CVE-2022-39249 - * CVE-2022-39250 - * CVE-2022-39251 - * CVE-2022-39236 +- Version 1.11.7 +## 🔒 Security +* Fix for [CVE-2022-39249](https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=CVE%2D2022%2D39249) +* Fix for [CVE-2022-39250](https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=CVE%2D2022%2D39250) +* Fix for [CVE-2022-39251](https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=CVE%2D2022%2D39251) +* Fix for [CVE-2022-39236](https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=CVE%2D2022%2D39236) ------------------------------------------------------------------- Tue Sep 27 21:25:44 UTC 2022 - Dominik Heidler diff --git a/element-web.spec b/element-web.spec index 648c0e7..565124d 100644 --- a/element-web.spec +++ b/element-web.spec @@ -17,7 +17,7 @@ Name: element-web -Version: 1.11.6 +Version: 1.11.7 Release: 0 Summary: A glossy Matrix collaboration client - web files License: Apache-2.0 diff --git a/npm-packages-offline-cache.tar.gz b/npm-packages-offline-cache.tar.gz index 1b6fe9f..86a2e36 100644 --- a/npm-packages-offline-cache.tar.gz +++ b/npm-packages-offline-cache.tar.gz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:7657ed9923e19f3d2d2464bc1fb7b632789cad09d791f0d0d886c3fa91f9f214 -size 95095224 +oid sha256:fc6cc838a2f114c880c62b5d9e01406236728fc32e003a4814c100100716e04b +size 94662834 From 0669eca14f164a3167a3e94d3a540b6e801f6bf3fdd6e25d3f28677f13f5154d Mon Sep 17 00:00:00 2001 From: Dominik Heidler Date: Wed, 28 Sep 2022 16:18:55 +0000 Subject: [PATCH 4/4] =?UTF-8?q?-=20Version=201.11.8=20##=20=F0=9F=90=9B=20?= =?UTF-8?q?Bug=20Fixes=20=20*=20Bump=20IDB=20crypto=20store=20version=20([?= =?UTF-8?q?\#2705](https://github.com/matrix-org/matrix-js-sdk/pull/2705))?= =?UTF-8?q?.?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit OBS-URL: https://build.opensuse.org/package/show/devel:languages:nodejs/element-web?expand=0&rev=18 --- element-web-1.11.7.tar.gz | 3 --- element-web-1.11.8.tar.gz | 3 +++ element-web.changes | 7 +++++++ element-web.spec | 2 +- npm-packages-offline-cache.tar.gz | 4 ++-- 5 files changed, 13 insertions(+), 6 deletions(-) delete mode 100644 element-web-1.11.7.tar.gz create mode 100644 element-web-1.11.8.tar.gz diff --git a/element-web-1.11.7.tar.gz b/element-web-1.11.7.tar.gz deleted file mode 100644 index 29bb8bf..0000000 --- a/element-web-1.11.7.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:7963049d21621b7998d85b87844f0c000647159d50da45f1e3a8409e804c0070 -size 1463523 diff --git a/element-web-1.11.8.tar.gz b/element-web-1.11.8.tar.gz new file mode 100644 index 0000000..96cb90a --- /dev/null +++ b/element-web-1.11.8.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:9d9bb42a3d004ab4659d2945e6752aa278c59bc3b7f75919ce076bf3fb2b5f73 +size 1463533 diff --git a/element-web.changes b/element-web.changes index 068e7c0..63f1f64 100644 --- a/element-web.changes +++ b/element-web.changes @@ -1,3 +1,10 @@ +------------------------------------------------------------------- +Wed Sep 28 16:14:03 UTC 2022 - Dominik Heidler + +- Version 1.11.8 +## 🐛 Bug Fixes + * Bump IDB crypto store version ([\#2705](https://github.com/matrix-org/matrix-js-sdk/pull/2705)). + ------------------------------------------------------------------- Wed Sep 28 13:56:17 UTC 2022 - Dominik Heidler diff --git a/element-web.spec b/element-web.spec index 565124d..cc687ea 100644 --- a/element-web.spec +++ b/element-web.spec @@ -17,7 +17,7 @@ Name: element-web -Version: 1.11.7 +Version: 1.11.8 Release: 0 Summary: A glossy Matrix collaboration client - web files License: Apache-2.0 diff --git a/npm-packages-offline-cache.tar.gz b/npm-packages-offline-cache.tar.gz index 86a2e36..3c69440 100644 --- a/npm-packages-offline-cache.tar.gz +++ b/npm-packages-offline-cache.tar.gz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:fc6cc838a2f114c880c62b5d9e01406236728fc32e003a4814c100100716e04b -size 94662834 +oid sha256:08b6f9d1783b1a73bfff3d73577510fe74e7bfc7f5e6c122b9270ce4f61f5062 +size 94670293