openSUSE-2025-181 Recommended update for ollama moderate openSUSE Backports SLE-15-SP7 Update This update for ollama fixes the following issues: Introduce version 0.7.0: * Ollama now supports multimodal models via Ollama's new engine, starting with new vision multimodal models: ~ Meta Llama 4 ~ Google Gemma 3 ~ Qwen 2.5 VL ~ Qwen 2.5 VL * Ollama now supports providing WebP images as input to multimodal models * Improved performance of importing safetensors models via ollama create * Various bug fixes and performance enhancements ollama-0.7.0-bp157.2.1.src.rpm ollama-0.7.0-bp157.2.1.x86_64.rpm ollama-0.7.0-bp157.2.1.aarch64.rpm ollama-0.7.0-bp157.2.1.ppc64le.rpm ollama-0.7.0-bp157.2.1.s390x.rpm openSUSE-2025-182 Security update for afterburn moderate openSUSE Backports SLE-15-SP7 Update This update for afterburn fixes the following issues: - Update to version 5.8.2: * cargo: Afterburn release 5.8.2 * docs/release-notes: update for release 5.8.2 * cargo: update dependencies * cargo: Afterburn release 5.8.1 * cargo: Afterburn release 5.8.0 * docs/release-notes: update for release 5.8.0 * cargo: update dependencies * packit: add initial support - Update to version 5.7.0.git103.bae893c: * Sync repo templates * build(deps): bump crossbeam-channel from 0.5.13 to 0.5.15 * build(deps): bump tokio from 1.40.0 to 1.44.2 * build(deps): bump openssl from 0.10.71 to 0.10.72 fixes RUSTSEC-2025-0022 AKA CVE-2025-3416 * build(deps): bump zbus from 4.4.0 to 5.5.0 * mod.rs: Fix clippy lint errors * release-notes.md: add release notes for rust version update * Cargo.toml: bump MSRV to 1.84.1 * Fix clippy lint issues * Sync repo templates * build(deps): bump mockito from 1.6.1 to 1.7.0 * build(deps): bump serde_json from 1.0.139 to 1.0.140 * build(deps): bump tempfile from 3.17.1 to 3.19.1 * build(deps): bump clap from 4.5.31 to 4.5.35 * build(deps): bump reqwest from 0.12.12 to 0.12.15 * Update release notes. * proxmoxve: Add more context to log messages. * proxmoxve: Remove unneeded fields * proxmoxve: Add tests for static network configuration from cloud-init. * proxmoxve: Add support for static network configuration from cloud-init. * build(deps): bump mailparse from 0.15.0 to 0.16.1 * Sync repo templates * build(deps): bump ring from 0.17.8 to 0.17.13 * build(deps): bump anyhow from 1.0.95 to 1.0.96 * release notes: add notes for tempfile bump from 3.16.0 to 3.17.1 * build(deps): bump serde from 1.0.217 to 1.0.218 * build(deps): bump openssl from 0.10.70 to 0.10.71 * build(deps): bump tempfile from 3.16.0 to 3.17.1 * build(deps): bump serde_json from 1.0.138 to 1.0.139 * build(deps): bump clap from 4.5.27 to 4.5.31 * add makefile targets for fmt,lint and test * providers/openstack: ignore ec2 metadata if not present * build(deps): bump openssl from 0.10.66 to 0.10.70 * build(deps): bump serde_json from 1.0.137 to 1.0.138 * build(deps): bump tempfile from 3.14.0 to 3.16.0 * build(deps): bump openssl from 0.10.66 to 0.10.69 * build(deps): bump ipnetwork from 0.20.0 to 0.21.1 * build(deps): bump serde from 1.0.215 to 1.0.217 * build(deps): bump serde_json from 1.0.133 to 1.0.137 * build(deps): bump anyhow from 1.0.93 to 1.0.95 * build(deps): bump clap from 4.5.21 to 4.5.27 * build(deps): bump reqwest from 0.12.7 to 0.12.12 * Sync repo templates * build(deps): bump mockito from 1.5.0 to 1.6.1 * build(deps): bump serde_json from 1.0.128 to 1.0.133 * build(deps): bump clap from 4.5.17 to 4.5.21 * build(deps): bump tempfile from 3.12.0 to 3.14.0 * build(deps): bump anyhow from 1.0.89 to 1.0.93 * build(deps): bump serde from 1.0.210 to 1.0.215 * docs: add changelog entry * proxmox: use noop provider if no configdrive * add noop provider * release-notes: remove "upcoming" - Update to version 5.7.0: * cargo: Afterburn release 5.7.0 * docs/release-notes: update for release 5.7.0 * cargo: update dependencies * dhcp: replace dbus_proxy with proxy, and zbus traits * build(deps): bump zbus from 3.15.2 to 4.4.0 * build(deps): bump tempfile from 3.10.1 to 3.12.0 * build(deps): bump serde from 1.0.205 to 1.0.210 * build(deps): bump serde_json from 1.0.121 to 1.0.127 * build(deps): bump reqwest from 0.12.5 to 0.12.7 * build(deps): bump uzers from 0.12.0 to 0.12.1 * build(deps): bump clap from 4.5.13 to 4.5.16 * build(deps): bump serde from 1.0.203 to 1.0.205 * build(deps): bump serde_json from 1.0.119 to 1.0.121 * build(deps): bump mockito from 1.4.0 to 1.5.0 * build(deps): bump openssh-keys from 0.6.3 to 0.6.4 * build(deps): bump clap from 4.5.8 to 4.5.13 * build(deps): bump openssl from 0.10.64 to 0.10.66 * providers/hetzner: private ipv4 addresses in attributes * openstack: Document the two platforms * build(deps): bump zerovec-derive from 0.10.2 to 0.10.3 * build(deps): bump zerovec from 0.10.2 to 0.10.4 * build(deps): bump nix from 0.27.1 to 0.29.0 * build(deps): bump clap from 4.5.7 to 4.5.8 * build(deps): bump serde_json from 1.0.117 to 1.0.119 * microsoft/azure: allow empty certificate chain in PKCS12 file * proxmoxve: implement proxmoxve provider * providers/hetzner: fix duplicate attribute prefix * build(deps): bump pnet_base from 0.34.0 to 0.35.0 * cargo: Afterburn release 5.6.0 * docs/release-notes: update for release 5.6.0 * cargo: update dependencies * build(deps): bump libflate from 1.4.0 to 2.1.0 * build(deps): bump base64 from 0.21.7 to 0.22.1 * build(deps): bump uzers from 0.11.3 to 0.12.0 * build(deps): bump pnet_datalink from 0.34.0 to 0.35.0 * build(deps): bump nix from 0.28.0 to 0.29.0 * lint: silence deadcode warnings * lint: address latest lint's from msrv update * workflows/rust: directly update toolchain to 1.75.0 * cargo: update msrv to 1.75 * Sync repo templates * build(deps): bump reqwest from 0.12.2 to 0.12.4 * build(deps): bump serde from 1.0.197 to 1.0.200 * build(deps): bump anyhow from 1.0.81 to 1.0.82 * build(deps): bump mailparse from 0.14.1 to 0.15.0 * build(deps): bump serde_json from 1.0.115 to 1.0.116 * providers: Add "akamai" provider * build(deps): bump h2 from 0.3.24 to 0.3.26 * build(deps): bump anyhow from 1.0.79 to 1.0.81 * build(deps): bump serde_json from 1.0.113 to 1.0.115 * build(deps): bump reqwest from 0.11.24 to 0.12.2 * build(deps): bump serde_yaml from 0.9.32 to 0.9.34+deprecated * build(deps): bump mio from 0.8.10 to 0.8.11 * build(deps): bump mailparse from 0.14.0 to 0.14.1 * build(deps): bump openssl from 0.10.62 to 0.10.64 * build(deps): bump nix from 0.27.1 to 0.28.0 * build(deps): bump mockito from 1.2.0 to 1.4.0 * build(deps): bump tempfile from 3.9.0 to 3.10.1 * build(deps): bump serde_yaml from 0.9.31 to 0.9.32 * build(deps): bump serde from 1.0.195 to 1.0.197 * build(deps): bump h2 from 0.3.23 to 0.3.24 * build(deps): bump slog-term from 2.9.0 to 2.9.1 * build(deps): bump serde_yaml from 0.9.30 to 0.9.31 * build(deps): bump serde_json from 1.0.111 to 1.0.113 * build(deps): bump clap from 4.4.16 to 4.4.18 * build(deps): bump reqwest from 0.11.23 to 0.11.24 * cargo: Afterburn release 5.5.1 * docs/release-notes: update for release 5.5.1 * cargo: update dependencies * build(deps): bump anyhow from 1.0.75 to 1.0.78 * build(deps): bump serde_yaml from 0.9.27 to 0.9.29 * build(deps): bump reqwest from 0.11.22 to 0.11.23 * build(deps): bump serde_json from 1.0.108 to 1.0.109 * build(deps): bump openssl from 0.10.60 to 0.10.62 * build(deps): bump tempfile from 3.8.1 to 3.9.0 * build(deps): bump clap from 4.4.10 to 4.4.12 * build(deps): bump unsafe-libyaml from 0.2.9 to 0.2.10 * providers/vmware: add missing public functions for non-amd64 * build(deps): bump clap from 4.4.8 to 4.4.10 * cargo: Afterburn release 5.5.0 * build(deps): bump openssl from 0.10.59 to 0.10.60 * docs/release-notes: update for release 5.5.0 * cargo: update dependencies * ci: cancel previous build on PR update * build(deps): allow building with libsystemd 0.7.0 * providers/vmware: Process guestinfo.metadata netplan configuration * kubevirt: Run afterburn-hostname service * build(deps): bump reqwest from 0.11.20 to 0.11.22 * build(deps): bump tempfile from 3.8.0 to 3.8.1 * build(deps): bump clap from 4.4.6 to 4.4.7 * build(deps): bump serde_json from 1.0.107 to 1.0.108 * build(deps): bump serde_yaml from 0.9.25 to 0.9.27 * build(deps): bump rustix from 0.37.19 to 0.37.25 * build(deps): bump clap from 4.4.2 to 4.4.6 * build(deps): bump serde_json from 1.0.105 to 1.0.107 * build(deps): bump mockito from 1.1.0 to 1.2.0 * providers: add support for scaleway * Move away from deprecated `users` to `uzers` * providers/hetzner: add support for Hetzner Cloud * build(deps): bump clap from 4.4.1 to 4.4.2 * cargo: update MSRV to 1.71 * build(deps): bump clap from 4.3.19 to 4.4.1 * chore: Get rid of Clippy warnings * cargo: specify required features for nix dependency * build(deps): bump nix from 0.26.2 to 0.27.1 * build(deps): bump slog-async from 2.7.0 to 2.8.0 * build(deps): bump openssl from 0.10.56 to 0.10.57 * build(deps): bump reqwest from 0.11.18 to 0.11.20 * build(deps): bump serde from 1.0.185 to 1.0.188 * build(deps): bump tempfile from 3.7.1 to 3.8.0 * build(deps): bump serde from 1.0.183 to 1.0.185 * build(deps): bump anyhow from 1.0.72 to 1.0.75 * build(deps): bump serde_json from 1.0.104 to 1.0.105 * build(deps): bump openssl from 0.10.55 to 0.10.56 * build(deps): bump tempfile from 3.7.0 to 3.7.1 * build(deps): bump serde from 1.0.180 to 1.0.183 * Sync repo templates * build(deps): bump serde from 1.0.179 to 1.0.180 * build(deps): bump serde_json from 1.0.103 to 1.0.104 * build(deps): bump serde from 1.0.175 to 1.0.179 * build(deps): bump pnet_datalink from 0.33.0 to 0.34.0 * build(deps): bump serde from 1.0.171 to 1.0.175 * build(deps): bump clap from 4.3.14 to 4.3.19 * build(deps): bump pnet_base from 0.33.0 to 0.34.0 * build(deps): bump serde_yaml from 0.9.23 to 0.9.25 * build(deps): bump tempfile from 3.6.0 to 3.7.0 * build(deps): bump clap from 4.3.11 to 4.3.14 * build(deps): bump serde_yaml from 0.9.22 to 0.9.23 * build(deps): bump anyhow from 1.0.71 to 1.0.72 * build(deps): bump serde_json from 1.0.100 to 1.0.103 * build(deps): bump clap from 4.3.10 to 4.3.11 * build(deps): bump serde_json from 1.0.99 to 1.0.100 * build(deps): bump openssh-keys from 0.6.1 to 0.6.2 * build(deps): bump zbus from 3.13.1 to 3.14.1 * build(deps): bump clap from 4.3.8 to 4.3.10 * build(deps): bump serde from 1.0.164 to 1.0.165 * build(deps): bump serde_json from 1.0.96 to 1.0.99 * build(deps): bump clap from 4.3.3 to 4.3.8 * build(deps): bump serde_yaml from 0.9.21 to 0.9.22 * build(deps): bump openssl from 0.10.54 to 0.10.55 * build(deps): bump mockito from 1.0.2 to 1.1.0 * openstack: Add attribute OPENSTACK_INSTANCE_UUID * build(deps): bump serde from 1.0.163 to 1.0.164 * build(deps): bump clap from 4.3.2 to 4.3.3 * build(deps): bump tempfile from 3.5.0 to 3.6.0 * cargo: Afterburn release 5.4.3 * docs/release-notes: update for release 5.4.3 * cargo: update dependencies * cargo: allow openssl 0.10.46 * build(deps): bump openssl from 0.10.52 to 0.10.54 * build(deps): bump openssh-keys from 0.6.0 to 0.6.1 * build(deps): bump vmw_backdoor from 0.2.3 to 0.2.4 * ci: strip debug symbols * build-sys: Use new tier = 2 for cargo-vendor-filterer * build(deps): bump reqwest from 0.11.17 to 0.11.18 * cargo: Afterburn release 5.4.2 * docs/release-notes: update for release * docs/release-notes: note Azure SSH regression fix with new openssl * cargo: fix minimum version of openssl crate * build(deps): bump serde from 1.0.162 to 1.0.163 * build(deps): bump zbus from 3.12.0 to 3.13.1 * build(deps): bump serde from 1.0.160 to 1.0.162 * build(deps): bump anyhow from 1.0.70 to 1.0.71 * build(deps): bump openssl from 0.10.51 to 0.10.52 * build(deps): bump reqwest from 0.11.16 to 0.11.17 * build(deps): bump openssl from 0.10.50 to 0.10.51 * build(deps): bump enumflags2 from 0.7.5 to 0.7.7 * build(deps): bump openssl from 0.10.48 to 0.10.50 * build(deps): bump zbus from 3.11.1 to 3.12.0 * build(deps): bump serde_json from 1.0.95 to 1.0.96 * build(deps): bump h2 from 0.3.15 to 0.3.17 * build(deps): bump openssl from 0.10.47 to 0.10.48 * microsoft/crypto/mod: replace deprecated function `parse` with `parse2` * build(deps): bump serde from 1.0.159 to 1.0.160 * build(deps): bump serde_yaml from 0.9.19 to 0.9.21 * build(deps): bump tempfile from 3.4.0 to 3.5.0 * build(deps): bump serde from 1.0.158 to 1.0.159 * build(deps): bump mockito from 1.0.1 to 1.0.2 * Update mockito to 1.0.1 * build(deps): bump reqwest from 0.11.15 to 0.11.16 * build(deps): bump serde_json from 1.0.94 to 1.0.95 * cli: switch to clap derive * cli: add descriptive value names for option arguments in --help * build(deps): bump zbus from 3.11.0 to 3.11.1 * build(deps): bump openssl from 0.10.45 to 0.10.47 * build(deps): bump reqwest from 0.11.14 to 0.11.15 * build(deps): bump serde from 1.0.155 to 1.0.158 * build(deps): bump anyhow from 1.0.69 to 1.0.70 * cli: have clap require exactly one of --cmdline/--provider * providers/*: move endpoint mocking into retry::Client * retry/client: move URL parsing into helper function * providers/microsoft: import crate::retry * providers/microsoft: use stored client for all fetches * providers/packet: use stored client for boot checkin * build(deps): bump zbus from 3.10.0 to 3.11.0 * build(deps): bump serde from 1.0.152 to 1.0.155 * docs: Use upstream theme and update to 0.4.1 * build(deps): bump serde_json from 1.0.93 to 1.0.94 * build(deps): bump serde_yaml from 0.9.17 to 0.9.19 * build(deps): bump mockito from 0.32.3 to 0.32.4 * build(deps): bump tempfile from 3.3.0 to 3.4.0 * initrd: remember to write trailing newline to network kargs file * util: drop obsolete "OEM" terminology * Update to clap 4 * build(deps): bump mockito from 0.31.1 to 0.32.3 * workflows: update clippy to 1.67 * Fix clippy lints * Inline variables into format strings * build(deps): bump zbus from 3.9.0 to 3.10.0 * build(deps): bump serde_json from 1.0.92 to 1.0.93 afterburn-5.8.2-bp157.2.3.1.src.rpm afterburn-5.8.2-bp157.2.3.1.x86_64.rpm afterburn-dracut-5.8.2-bp157.2.3.1.noarch.rpm afterburn-5.8.2-bp157.2.3.1.i586.rpm afterburn-5.8.2-bp157.2.3.1.aarch64.rpm afterburn-5.8.2-bp157.2.3.1.ppc64le.rpm afterburn-5.8.2-bp157.2.3.1.s390x.rpm openSUSE-2025-175 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Update to version 137.0.7151.55 (stable release 2025-05-27) (boo#1243741) - CVE-2025-5063: Use after free in Compositing - CVE-2025-5280: Out of bounds write in V8 - CVE-2025-5064: Inappropriate implementation in Background Fetch API - CVE-2025-5065: Inappropriate implementation in FileSystemAccess API - CVE-2025-5066: Inappropriate implementation in Messages - CVE-2025-5281: Inappropriate implementation in BFCache - CVE-2025-5283: Use after free in libvpx - CVE-2025-5067: Inappropriate implementation in Tab Strip chromedriver-137.0.7151.55-bp157.2.3.2.x86_64.rpm chromium-137.0.7151.55-bp157.2.3.2.src.rpm chromium-137.0.7151.55-bp157.2.3.2.x86_64.rpm chromedriver-137.0.7151.55-bp157.2.3.2.aarch64.rpm chromium-137.0.7151.55-bp157.2.3.2.aarch64.rpm openSUSE-2025-180 Security update for varnish important openSUSE Backports SLE-15-SP7 Update This update for varnish fixes the following issues: - Update to release 7.7.1 * VSV-16: Resolve request smuggling attack - Update to release 7.7.0 * The `linux` jail gained control of transparent huge pages settings. * An issue has been fixed which could cause a crash when varnishd receives an invalid Content-Range header from a backend. * Timestamping for HTTP/2 requests (when idle period begins) has been switched to be more in line with HTTP/1. * VSV-15: The client connection is now always closed when a malformed request is received. [CVE-2025-30346, boo#1239892] - Update to release 7.6.0 * The Varnish Delivery Processor (VDP) filter API has been generalized to also accommodate future use for backend request bodies. * VDPs with no vdp_bytes_f function are now supported if the vdp_init_f returns a value greater than zero to signify that the filter is not to be added to the chain. This is useful to support VDPs which only need to work on headers. * The epoll and kqueue waiters have been improved to correctly report WAITER_REMCLOSE, which increases the WAITER.*.remclose counter. * varnishtest now supports the shutdown command corresponding to the shutdown(2) standard C library call. * VSC counters for waiters have been added: * conns to count waits on idle connections * remclose to count idle connections closed by the peer * timeout to count idle connections which timed out in the waiter * action to count idle connections which resulted in a read * The port of a listen_endpoint given with the -a argument to varnishd can now also be a numerical port range like "80-89". * The warning "mlock() of VSM failed" message is now emitted when locking of shared memory segments (via mlock(2)) fails. * A bug has been fixed where string comparisons in VCL could fail with the nonsensical error message "Comparison of different types: STRING '==' STRING". * An issue has been addressed in the builtin.vcl where backend responses would fail if they contained a Content-Range header when no range was requested. * Additional SessError VSL events are now generated for various HTTP/2 protocol errors. * A new Linux jail has been added which is now the default on Linux. For now, it is almost identical to the Unix jail with one addition: * When the new Linux jail is used, the working directory not mounted on tmpfs partition. * A race condition with VCL temperature transitions has been addressed. * Internal management of probes has been reworked to address race conditions. * Backend tasks can now be instructed to queue if the backend has reached its max_connections. * The size of the buffer to hold panic messages is now tunable through the new panic_buffer parameter. * The Varnish Shared Memory (VSM) and Varnish Shared Counters (VSC) consumer implementation in libvarnishapi have been improved for stability and performance. * An issue has been fixed where Varnish Shared Log (VSL) queries (for example using ``varnishlog -q``) with numerical values would fail in unexpected ways due to truncation. * The ``ObjWaitExtend()`` Object API function gained a statep argument to optionally return the busy object state consistent with the current extension. A NULL value may be passed if the caller does not require it. * For backends using the ``.via`` attribute to connect through a proxy, the connect_timeout, ``first_byte_timeout`` and ``between_bytes_timeout`` attributes are now inherited from proxy unless explicitly given. * varnishd now creates a worker_tmpdir which can be used by VMODs for temporary files. The VMOD developer documentation has details. * The environment variable VARNISH_DEFAULT_N now provides the default "varnish name" / "workdir" as otherwise specified by the ``-n`` argument to varnishd and varnish* utilities except varnishtest. * A glitch with TTL comparisons has been fixed which could, for example, lead to unexpected behavior with purge.soft(). - Update to release 7.5.0 * Resolved CVE-2023-44487, CVE-2024-30156 [boo#1221942] * The default value of cli_limit has been increased from 48KB to 64KB. * A new ``pipe_task_deadline`` directive specifies the maximum duration of a pipe transaction. * All the timeout parameters that can be disabled accept the "never" value. * Added parameters to control the HTTP/2 Rapid Reset attach. - update to 7.4.2 (boo#1216123, CVE-2023-44487): * The ``vcl_req_reset`` feature (controllable through the ``feature`` parameter, see `varnishd(1)`) has been added and enabled by default to terminate client side VCL processing early when the client is gone. *req_reset* events trigger a VCL failure and are reported to `vsl(7)` as ``Timestamp: Reset`` and accounted to ``main.req_reset`` in `vsc` as visible through ``varnishstat(1)``. In particular, this feature is used to reduce resource consumption of HTTP/2 "rapid reset" attacks (see below). Note that *req_reset* events may lead to client tasks for which no VCL is called ever. Presumably, this is thus the first time that valid `vcl(7)` client transactions may not contain any ``VCL_call`` records. * Added mitigation options and visibility for HTTP/2 "rapid reset" attacks Global rate limit controls have been added as parameters, which can be overridden per HTTP/2 session from VCL using the new vmod ``h2``: * The ``h2_rapid_reset`` parameter and ``h2.rapid_reset()`` function define a threshold duration for an ``RST_STREAM`` to be classified as "rapid": If an ``RST_STREAM`` frame is parsed sooner than this duration after a ``HEADERS`` frame, it is accounted against the rate limit described below. * The ``h2_rapid_reset_limit`` parameter and ``h2.rapid_reset_limit()`` function define how many "rapid" resets may be received during the time span defined by the ``h2_rapid_reset_period`` parameter / ``h2.rapid_reset_period()`` function before the HTTP/2 connection is forcibly closed with a ``GOAWAY`` and all ongoing VCL client tasks of the connection are aborted. The defaults are 100 and 60 seconds, corresponding to an allowance of 100 "rapid" resets per minute. * The ``h2.rapid_reset_budget()`` function can be used to query the number of currently allowed "rapid" resets. * Sessions closed due to rapid reset rate limiting are reported as ``SessClose RAPID_RESET`` in `vsl(7)` and accounted to ``main.sc_rapid_reset`` in `vsc` as visible through ``varnishstat(1)``. * The ``cli_limit`` parameter default has been increased from 48KB to 64KB. * ``VSUB_closefrom()`` now falls back to the base implementation not only if ``close_range()`` was determined to be unusable at compile time, but also at run time. That is to say, even if ``close_range()`` is compiled in, the fallback to the naive implementation remains. libvarnishapi3-7.7.1-bp157.2.3.1.x86_64.rpm varnish-7.7.1-bp157.2.3.1.src.rpm varnish-7.7.1-bp157.2.3.1.x86_64.rpm varnish-devel-7.7.1-bp157.2.3.1.x86_64.rpm libvarnishapi3-7.7.1-bp157.2.3.1.i586.rpm varnish-7.7.1-bp157.2.3.1.i586.rpm varnish-devel-7.7.1-bp157.2.3.1.i586.rpm libvarnishapi3-7.7.1-bp157.2.3.1.aarch64.rpm varnish-7.7.1-bp157.2.3.1.aarch64.rpm varnish-devel-7.7.1-bp157.2.3.1.aarch64.rpm libvarnishapi3-7.7.1-bp157.2.3.1.ppc64le.rpm varnish-7.7.1-bp157.2.3.1.ppc64le.rpm varnish-devel-7.7.1-bp157.2.3.1.ppc64le.rpm libvarnishapi3-7.7.1-bp157.2.3.1.s390x.rpm varnish-7.7.1-bp157.2.3.1.s390x.rpm varnish-devel-7.7.1-bp157.2.3.1.s390x.rpm openSUSE-2025-191 Recommended update for micropython, micropython-lib, webrepl moderate openSUSE Backports SLE-15-SP7 Update This update for micropython, micropython-lib, webrepl fixes the following issues: This update ships micropython in version 1.25.0. micropython-lib-1.25.0-bp157.2.1.noarch.rpm micropython-lib-1.25.0-bp157.2.1.src.rpm micropython-1.25.0-bp157.2.1.src.rpm micropython-1.25.0-bp157.2.1.x86_64.rpm mpremote-1.25.0-bp157.2.1.noarch.rpm mpy-tools-1.25.0-bp157.2.1.x86_64.rpm webrepl-20221108.1e09d9a-bp157.2.1.noarch.rpm webrepl-20221108.1e09d9a-bp157.2.1.src.rpm micropython-1.25.0-bp157.2.1.aarch64.rpm mpy-tools-1.25.0-bp157.2.1.aarch64.rpm micropython-1.25.0-bp157.2.1.s390x.rpm mpy-tools-1.25.0-bp157.2.1.s390x.rpm openSUSE-2025-189 Recommended update for opi moderate openSUSE Backports SLE-15-SP7 Update This update for opi fixes the following issues: Version 5.8.5: * add librewolf plugin (#205) * Install .NET 9 * Add verbose mode * Change the order of the process in the github module * Add rustdesk plugin Version 5.8.4; * Use arm64 rpm for libation on aarch64 Version 5.8.3: * Install dependencies rpm-build and squashfs at runtime if needed * Drop DNF support Version 5.8.2: * Warn about adding staging repos * Gracefully handle zypper exit code 106 (repos without cache present) Version 5.8.1: * Fix SyntaxWarning: invalid escape sequence '\s' Version 5.8.0: * Add mullvad-brower opi-5.8.5-bp157.2.3.1.noarch.rpm opi-5.8.5-bp157.2.3.1.src.rpm openSUSE-2025-194 Recommended update for virtme moderate openSUSE Backports SLE-15-SP7 Update This update for virtme fixes the following issues: Update to version 1.36: * vng: Fix remote build * virtme_ng: run: --exec and positional arguments are mutually exclusive * virtme-ng: run: Fix quoting * virtme_ng: run: Fix `vng -- ''` virtme-1.36-bp157.2.3.1.noarch.rpm virtme-1.36-bp157.2.3.1.src.rpm openSUSE-2025-196 Recommended update for claws-mail moderate openSUSE Backports SLE-15-SP7 Update This update for claws-mail fixes the following issues: - Update to 4.3.1: * The configuration option, "Don't popup error dialog on receive error" has been changed to "Show error dialog on receive error". Your previous choice will be automatically changed to the new format. * The option "Warn when pasting files as attachments" has been added to the Compose/Writing preferences page. This option was previously hidden. * chmod 0600 is now set on *history files in the configuration directory. * A new preference has been added to enable setting the chmod value of saved attachments: "Save attachments with chmod [ ]", found on the Other/Miscelleanous preferences page. The default value is 600. * The creation and updating of .mh_sequences files in MH mailbox folders is now optional and disabled by default. This is controlled by a new hidden preference, mh_compat_mode. If you were previously relying on this feature, set mh_compat_mode=1 in clawsrc before running this version. * A new hidden preference has been added, passphrase_dialog_msg_title_switch. This switches the placement of the dialogue message with the dialogue title in the passphrase dialogue. This can be useful for interacting with third-party programs such as KeePassXC. * The top-level 'Mark' menu item has been renamed to 'Marks'. If you have set custom hotkeys for any items in this menu you will need to re-set them. * New accounts now have all secure options activated by default, including TLS connections and SMTP AUTH. * The option to accept valid TLS certificates is now activated by default on new accounts. * Notification plugin: support for Ayatana indicator has been added. * PDF Viewer plugin: support for image/x-eps (encapsulated postscript) images has been added. * Libravatar plugin: the https URL, https://seccdn.libravatar.org/avatar, is now used by default. * vCalendar plugin: CREATED/LAST_MODIFIED are correctly handled, and the VTIMEZONE component is used when present * Various code cleanups. * The English, Spanish and French manuals have been updated. * Updated translations: Albanian, Brazilian Portuguese, British English, Catalan, Czech, Dutch, French, Polish, Portuguese, Romanian, Russian, Simplified Chinese, Slovak, Spanish, Swedish, Turkish. * bug fixes: * bug 3964, 'Attachment icon doesn't show in message list unless the message is clicked and then disappears later' * bug 4658, 'Headers unfolded incorrectly in message view' * bug 4817, 'Edit button in Messages view->Text settings not translatable' * bug 4818, 'Your Claws Mail configuration is from a newer...' dialog is shown more than once' * bug 4819, 'Text wrapping broken when text contains an URL' * bug 4821, 'If the Mail folder is on another partition, folder chmod settings are not applied to draft and queue' * bug 4824, 'No syntax highlighting after exiting external editor' * bug 4828, '"Mark" not translated anymore' * bug 4835, 'Disallow a forward slash in (IMAP) account names' * bug 4840, 'core dump unsubscribing from newsgroups' * CID 1491093: attrib leaked if attvalue is null * CID 1491370: unchecked return value. * archive plugin build in debug mode. * keep newsgroup subscription window on top when 'subscribe to newsgroup...' fails and newsgroup list can't be retrieved * don't silently fail to save a sent msg * IMAP: show the clip icon in the message list as soon as possible * stop needlessly checking which folders want sycnhronising every time we select a msg in an MH mailbox - Update to 4.3.0: * Compose window: when the focus is in the message text, copied files can be pasted as attachments using /Edit/paste or Ctrl+V. (The context menu's Paste will still insert the list of files into the message body.) * '/Mark/Mark all read in folder' and 'Mark/Mark all unread in folder' have been re-added to the Message List context menu. * It is now possible to use '/Tools/Remove references' when forwarding mail. * Keyboard shortcuts: The "Choose preset keyboard shortcuts" selector has been integrated into the main preferences page. When 'Current' is the selected preset, Apply/OK will keep the existing settings. * An MBOX file can now be imported from the command line using `claws-mail --import-mbox %f` where %f is the full path to the MBOX file. * OAUTH2 support for Microsoft 365 GCC High has been added. * LiteHTML Viewer plugin: Updated to LiteHTML 0.9. * The menurc file is now backed-up on startup. * Removed support for the obsolete Avant Window Navigator. * Various code cleanups. * The manual has been updated. * New translation: Albanian. * Updated translations: Catalan, Czech, French, Hungarian, Indonesian, Polish, Romanian, Slovak, Spanish, Swedish, Turkish. * bug 4668, 'Sometimes, at program start, message list takes all the vertical space' * bug 4720, 'matcher: release regex_t in matcherprop_string_match' * bug 4724, 'set proper availability status to sign/encrypt toolbar buttons' * bug 4725, 'oauth2: remove trailing zero from transmit buffer in oauth2_contact_server' * bug 4728, 'socket: handle GNUTLS_E_PREMATURE_TERMINATION in ssl_read' * bug 4730, 'oauth2: fix string handling in oauth2_contact_server' * bug 4733, 'Line breaks lost in headers' * bug 4734, 'ssl_certificate: remove unhelpful warnings from certificate check' * bug 4746, 'matcher: remove incorrect condition in matcherprop_free' * bug 4747, 'matcher: simplify matcherprop_new' * bug 4749, 'release regex_t in summary_compile_simplify_regexp' * bug 4750, 'remove regcomp wrapper and call regcomp directly' * bug 4752, 'Adjust incorrect debug_printf call in pgp plugins' * bug 4754, 'text/enriched literal less-than sign sequence handled incorrectly * bug 4757, 'remove AX_FUNC_MKDIR' * bug 4758, 'remove unused check for bind_textdomain_codeset' * bug 4759, 'remove unused function checks from AC_CHECK_FUNCS' * bug 4760, 'use correct type for move_bar_id' * bug 4762, 'oauth2: preserve an existing refresh token' * bug 4765, 'only store smtp auth if authorization method is OAUTH2' * bug 4766, 'preserve the expiry value of SMTP auth type is not OAUTH2' * bug 4768, 'Adjust logic while evaluating enable_avatars' * bug 4770, 'remove intl from list of include directories' * bug 4773, 'remove obsolescent AC_C_CONST' * bug 4780, 'use proper prototype for two archiver functions' * bug 4781, 'use correct prototype for privacy_free_signature_data' * bug 4782, 'use correct prototype for stop_archiving' * bug 4786, 'remove type confusion in getsockopt call in sock_connect_async_cb' * bug 4787, 'Use correct function for memory transfer in crypt_cfb_buf' * bug 4788, '"Change primary passphrase" disabled status handling' * bug 4790, 'widget spacing in "Changing primary passphrase" dialog' * bug 4791, 'remove obsolete glib version check' * bug 4795, 'Please remove -no-cpp-precomp flag for Apple' * bug 4796, 'URL with wide character doesn't work' * bug 4798, 'Quoting wrong when format=flowed and respect_flowed_format is set' * CIDs 1220325, 1491306 and 1491315, 'Explicit null dereferenced (FORWARD_NULL)' * CIDs 1491064, 1491074, 1491211, 1491105, 1491139, 1491164, 1491166, 1491168, 1491169, 1491178, 1491232, 1491242, 1492281 and 1591844 'Use after free (USE_AFTER_FREE)' * CID 1491137 'Out-of-bounds access (OVERRUN)' * CID 1591952 values overwritten before being used * CID 1596594 (CHECKED_RETURN) * CID 1596595 'Resource leak' * errors caused by invalid MIME viewer command-line * building on non-X11 systems * Use CFLAGS provided by nettle.pc * Fancy plugin, recognise mid and data embedded images claws-mail-4.3.1-bp157.2.3.1.src.rpm claws-mail-4.3.1-bp157.2.3.1.x86_64.rpm claws-mail-devel-4.3.1-bp157.2.3.1.x86_64.rpm claws-mail-lang-4.3.1-bp157.2.3.1.noarch.rpm claws-mail-4.3.1-bp157.2.3.1.aarch64.rpm claws-mail-devel-4.3.1-bp157.2.3.1.aarch64.rpm claws-mail-4.3.1-bp157.2.3.1.ppc64le.rpm claws-mail-devel-4.3.1-bp157.2.3.1.ppc64le.rpm claws-mail-4.3.1-bp157.2.3.1.s390x.rpm claws-mail-devel-4.3.1-bp157.2.3.1.s390x.rpm openSUSE-2025-188 Security update for chromium important openSUSE Backports SLE-15-SP7 Update Chromium was updated to 137.0.7151.68 (stable release 2025-06-03) (boo#1244019) * CVE-2025-5419: Out of bounds read and write in V8 * CVE-2025-5068: Use after free in Blink - Google is aware that an exploit for CVE-2025-5419 exists in the wild. chromedriver-137.0.7151.68-bp157.2.6.2.x86_64.rpm chromium-137.0.7151.68-bp157.2.6.2.src.rpm chromium-137.0.7151.68-bp157.2.6.2.x86_64.rpm chromedriver-137.0.7151.68-bp157.2.6.2.aarch64.rpm chromium-137.0.7151.68-bp157.2.6.2.aarch64.rpm openSUSE-2025-204 Security update for atop low openSUSE Backports SLE-15-SP7 Update This update for atop fixes the following issues: - Update to 2.11.1: * Atop will not connect to the TCP port of 'atopgpud' daemon any more by default. The flag -k can be used explicitly when 'atopgpud' is active. Also the code to parse the received strings is improved to avoid future issues with heap corruption. * The flag -K has been implemented to connect to netatop/netatop-bpf. * Fix CVE-2025-31160 (boo#1240393) - Update to 2.11.0: * Cgroups (version 2) support. Show the hierarchical structure of cgroups and the related metrics with key/option 'G', and define the cgroup depth with the keys/options 2 till 7. Key/option 8 also shows the processes per cgroup level, except the kernel processes in the root cgroup. Key/option 9 shows the related processes per cgroup level including the kernel processes in the root cgroup. With key/option 'C' the output is sorted on CPU consumption (default), with key/option 'M' on memory consumption, and with key/option 'D' (requires root privileges) on disk utilization. Note: The collection of cgroup information per process is not supported any more. * Twin mode: live measurement with review option. In twin mode atop spawns into a lower level process that gathers the counters and writes them to a temporary raw file, and an upper level process that reads the counters from the temporary raw file and presents them to the user. The reading of the upper level process keeps in pace with the written samples of the lower level process for live measurements. However, when pressing the 'r' (reset to measurement begin), the 'b' (branch to time stamp), or the 'T' (previous sample), the upper level process implicitly pauses with the possibility to review previous samples. The 'z' (explicit pause) can also be used to pause the live measurement. When pressing the 'z' again (continue after pause) viewing of the live measurement will be continued. * Various corrections related to JSON output. * Improved gathering of current CPU frequency. * Support more than 500 CPUs. * The format of the raw file is incompatible with previous versions. Raw files from previous versions can be converted to the new layout with the atopconvert command. - Update to 2.10.0: * Additional memory statistics on system level: amount of available memory, amount of memory used for Transparant Huge Pages, amount of memory used by two categories of static huge pages (usually 2MiB and 1GiB), and the number of pages transferred to/from zswap. * Additional counters for the number of idle threads on system level and process level. * Refined view of memory bar graph, including free static huge pages. * Generic way to determine the container id or pod name for containerized processes. * Support for a BPF-based alternative[1] for the netatop kernel module to gather network statistics per process/thread. * Use the -z flag followed by a regex to prepend matching environment variables to the full command line that is shown per process (with key 'c'). * Various bugfixes (like memory leak when switching to bar graph mode) and minor improvements. * Bugfix: failing malloc while starting atopsar (unprivileged) for a live measurement. * The program atophide can be used to make an extraction from an input raw log to an output raw log, optionally specifying a begin time and/or an end time. The output raw log can be anonymized, i.e. the hostname will be replaced, command names of non-standard commands will be replaced, all command arguments will be wiped, logical volume names will be replaced and NFS mounted volume names will be replaced. * The format of the raw file is incompatible with previous versions. Raw files from previous versions can be converted to the new layout with the atopconvert command. - Update to 2.9.0: * Avoid compiler warning by limiting PSI average * Install cleanup function to avoid termination of parent process * add man for PAG steal * Oomkills event should not remain orange after boot values * Clarified atop man page * Closing bracket missing in synopsis * Add highlight concerning bar graph mode * Introduce bar graph mode Besides all detailed information that is supplied by atop on system and process level, a (character-based) bar graph can be shown about the utilization of the most critical system resources * Freeing ethlink should depend of ifdef * Added reset to indicate shadow file to be closed * fix atopacctd.c: failed to start atopacct.service * acctatop: reacquire acctfd to collect nprocexit for some bad cases * Calibrate nprocexit to avoid atop coredumps unexpectedly * json.c: fix avque counters output * Resolve compiler warnings from latest versions of GCC * Added versdate.h to make clean target * Revert "Added versdate.h to make clean target" * Added versdate.h to make clean target * fix calculation for scan and steal * only call str.decode if nvml returned bytes * Add exit epoch to parseable output PRG (solves issue #242) * Minor correction in man page for NVCSW/NIVCSW * Context switches (voluntary and involuntary) on process level incorrect * Various modifications releated to (non)voluntary context switches * Add nvcsw and nivcsw for each process * ifprop.c: Fix possible memory leak * Code cleanup and prototype additions * Consistency check on number of threads (solves issue #232) * atop-rotate.service: use restart instead of try-restart * Add link to atophttpd atop-2.11.1-bp157.2.3.1.src.rpm atop-2.11.1-bp157.2.3.1.x86_64.rpm atop-daemon-2.11.1-bp157.2.3.1.x86_64.rpm atop-daemon-debuginfo-2.11.1-bp157.2.3.1.x86_64.rpm atop-debuginfo-2.11.1-bp157.2.3.1.x86_64.rpm atop-debugsource-2.11.1-bp157.2.3.1.x86_64.rpm atop-2.11.1-bp157.2.3.1.i586.rpm atop-daemon-2.11.1-bp157.2.3.1.i586.rpm atop-daemon-debuginfo-2.11.1-bp157.2.3.1.i586.rpm atop-debuginfo-2.11.1-bp157.2.3.1.i586.rpm atop-debugsource-2.11.1-bp157.2.3.1.i586.rpm atop-2.11.1-bp157.2.3.1.aarch64.rpm atop-daemon-2.11.1-bp157.2.3.1.aarch64.rpm atop-daemon-debuginfo-2.11.1-bp157.2.3.1.aarch64.rpm atop-debuginfo-2.11.1-bp157.2.3.1.aarch64.rpm atop-debugsource-2.11.1-bp157.2.3.1.aarch64.rpm atop-2.11.1-bp157.2.3.1.ppc64le.rpm atop-daemon-2.11.1-bp157.2.3.1.ppc64le.rpm atop-daemon-debuginfo-2.11.1-bp157.2.3.1.ppc64le.rpm atop-debuginfo-2.11.1-bp157.2.3.1.ppc64le.rpm atop-debugsource-2.11.1-bp157.2.3.1.ppc64le.rpm atop-2.11.1-bp157.2.3.1.s390x.rpm atop-daemon-2.11.1-bp157.2.3.1.s390x.rpm atop-daemon-debuginfo-2.11.1-bp157.2.3.1.s390x.rpm atop-debuginfo-2.11.1-bp157.2.3.1.s390x.rpm atop-debugsource-2.11.1-bp157.2.3.1.s390x.rpm openSUSE-2025-200 Recommended update for for orafce, timescaledb important openSUSE Backports SLE-15-SP7 Update This update for orafce and timescaledb rebuilds them against current postgresql. postgresql12-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.src.rpm postgresql12-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql12-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql12-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql13-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.src.rpm postgresql13-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql13-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql13-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql14-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.src.rpm postgresql14-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql14-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql14-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql15-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.src.rpm postgresql15-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql15-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql15-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql16-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.src.rpm postgresql16-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql16-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql16-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql17-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.src.rpm postgresql17-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql17-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql17-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.x86_64.rpm postgresql14-timescaledb-2.17.1-bp157.2.2.1.src.rpm postgresql14-timescaledb-2.17.1-bp157.2.2.1.x86_64.rpm postgresql15-timescaledb-2.17.1-bp157.2.2.1.src.rpm postgresql15-timescaledb-2.17.1-bp157.2.2.1.x86_64.rpm postgresql16-timescaledb-2.17.1-bp157.2.2.1.src.rpm postgresql16-timescaledb-2.17.1-bp157.2.2.1.x86_64.rpm postgresql17-timescaledb-2.17.1-bp157.2.2.1.src.rpm postgresql17-timescaledb-2.17.1-bp157.2.2.1.x86_64.rpm postgresql12-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql12-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql12-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql13-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql13-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql13-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql14-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql14-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql14-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql15-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql15-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql15-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql16-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql16-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql16-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql17-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql17-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql17-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.i586.rpm postgresql14-timescaledb-2.17.1-bp157.2.2.1.i586.rpm postgresql15-timescaledb-2.17.1-bp157.2.2.1.i586.rpm postgresql16-timescaledb-2.17.1-bp157.2.2.1.i586.rpm postgresql17-timescaledb-2.17.1-bp157.2.2.1.i586.rpm postgresql12-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql12-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql12-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql13-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql13-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql13-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql14-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql14-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql14-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql15-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql15-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql15-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql16-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql16-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql16-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql17-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql17-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql17-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.aarch64.rpm postgresql14-timescaledb-2.17.1-bp157.2.2.1.aarch64.rpm postgresql15-timescaledb-2.17.1-bp157.2.2.1.aarch64.rpm postgresql16-timescaledb-2.17.1-bp157.2.2.1.aarch64.rpm postgresql17-timescaledb-2.17.1-bp157.2.2.1.aarch64.rpm postgresql12-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql12-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql12-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql13-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql13-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql13-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql14-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql14-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql14-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql15-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql15-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql15-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql16-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql16-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql16-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql17-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql17-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql17-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.ppc64le.rpm postgresql14-timescaledb-2.17.1-bp157.2.2.1.ppc64le.rpm postgresql15-timescaledb-2.17.1-bp157.2.2.1.ppc64le.rpm postgresql16-timescaledb-2.17.1-bp157.2.2.1.ppc64le.rpm postgresql17-timescaledb-2.17.1-bp157.2.2.1.ppc64le.rpm postgresql12-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql12-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql12-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql13-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql13-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql13-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql14-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql14-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql14-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql15-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql15-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql15-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql16-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql16-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql16-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql17-orafce-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql17-orafce-debuginfo-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql17-orafce-debugsource-4.14.1+git0.48e67e7-bp157.2.2.1.s390x.rpm postgresql14-timescaledb-2.17.1-bp157.2.2.1.s390x.rpm postgresql15-timescaledb-2.17.1-bp157.2.2.1.s390x.rpm postgresql16-timescaledb-2.17.1-bp157.2.2.1.s390x.rpm postgresql17-timescaledb-2.17.1-bp157.2.2.1.s390x.rpm openSUSE-2025-201 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 137.0.7151.103 (stable release 2025-06-10) (boo#1244452) - CVE-2025-5958: Use after free in Media - CVE-2025-5959: Type Confusion in V8 chromedriver-137.0.7151.103-bp157.2.9.1.x86_64.rpm chromium-137.0.7151.103-bp157.2.9.1.src.rpm chromium-137.0.7151.103-bp157.2.9.1.x86_64.rpm chromedriver-137.0.7151.103-bp157.2.9.1.aarch64.rpm chromium-137.0.7151.103-bp157.2.9.1.aarch64.rpm openSUSE-2025-206 Security update for konsole important openSUSE Backports SLE-15-SP7 Update This update for konsole fixes the following issues: - CVE-2025-49091: Fixed potential remote code execution in a certain scenario with url open (boo#1244569) konsole-23.08.5-bp157.2.3.1.src.rpm konsole-23.08.5-bp157.2.3.1.x86_64.rpm konsole-debuginfo-23.08.5-bp157.2.3.1.x86_64.rpm konsole-debugsource-23.08.5-bp157.2.3.1.x86_64.rpm konsole-part-23.08.5-bp157.2.3.1.x86_64.rpm konsole-part-debuginfo-23.08.5-bp157.2.3.1.x86_64.rpm konsole-part-lang-23.08.5-bp157.2.3.1.noarch.rpm konsole-zsh-completion-23.08.5-bp157.2.3.1.noarch.rpm konsole-23.08.5-bp157.2.3.1.aarch64.rpm konsole-debuginfo-23.08.5-bp157.2.3.1.aarch64.rpm konsole-debugsource-23.08.5-bp157.2.3.1.aarch64.rpm konsole-part-23.08.5-bp157.2.3.1.aarch64.rpm konsole-part-debuginfo-23.08.5-bp157.2.3.1.aarch64.rpm konsole-23.08.5-bp157.2.3.1.ppc64le.rpm konsole-debuginfo-23.08.5-bp157.2.3.1.ppc64le.rpm konsole-debugsource-23.08.5-bp157.2.3.1.ppc64le.rpm konsole-part-23.08.5-bp157.2.3.1.ppc64le.rpm konsole-part-debuginfo-23.08.5-bp157.2.3.1.ppc64le.rpm konsole-23.08.5-bp157.2.3.1.s390x.rpm konsole-debuginfo-23.08.5-bp157.2.3.1.s390x.rpm konsole-debugsource-23.08.5-bp157.2.3.1.s390x.rpm konsole-part-23.08.5-bp157.2.3.1.s390x.rpm konsole-part-debuginfo-23.08.5-bp157.2.3.1.s390x.rpm openSUSE-2025-212 Recommended update for kanidm moderate openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: kanidm was updated to version 1.6.4~git2.a4b3b0f7b: * Remove dead code * OpenSUSE build fix Update to version 1.6.4~git0.e1d26ed10: * Allow deferring spans in unixd * Dark mode improvements (#3660) * Fix SCIM filter parser for quoted values with spaces and escaped quotes (#3673) * fix: strip comments from UNIX files before parsing (#3674) * Fix healthcheck to use ENV for config path (#3656) * Investigate and reduce memory consumption of unixd (#3645) * Swap bytes mut at buffer limits (#3651) * fix: Improve unixd & unixd-tasks startup coupling (#3638) * reload schema before verify (#3643) * Defend against split_at panic (#3636) Update to version 1.6.3~git0.389493eb1: * Fix minor issue with untagged version handling (#3634) * Move shadow processing out of task event loop (#3631) * Dont specify config path in container (#3630) * Accept SSHA with different salt lengths (#3629) * Resolve flaw with ssh key parse if the key has no comment (#3628) * Indicate that this is an ip list, not a range (#3626) * Test for corrupted unicode in SSH keys, keep the key title on error/resubmit (#3618) * Reduce replication logging verbosity * cargo publish (#3613) kanidm-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.src.rpm kanidm-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.x86_64.rpm kanidm-clients-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.x86_64.rpm kanidm-clients-debuginfo-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.x86_64.rpm kanidm-debuginfo-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.x86_64.rpm kanidm-debugsource-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.x86_64.rpm kanidm-docs-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.x86_64.rpm kanidm-server-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.x86_64.rpm kanidm-server-debuginfo-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.x86_64.rpm kanidm-unixd-clients-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.x86_64.rpm kanidm-unixd-clients-debuginfo-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.x86_64.rpm kanidm-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.aarch64.rpm kanidm-clients-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.aarch64.rpm kanidm-clients-debuginfo-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.aarch64.rpm kanidm-debuginfo-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.aarch64.rpm kanidm-debugsource-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.aarch64.rpm kanidm-docs-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.aarch64.rpm kanidm-server-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.aarch64.rpm kanidm-server-debuginfo-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.aarch64.rpm kanidm-unixd-clients-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.aarch64.rpm kanidm-unixd-clients-debuginfo-1.6.4~git2.a4b3b0f7b-bp157.2.3.1.aarch64.rpm openSUSE-2025-215 Recommended update for python-certbot-dns-google, python-google-api-python-client, python-google-auth-httplib2, python-uritemplate moderate openSUSE Backports SLE-15-SP7 Update This update for python-certbot-dns-google, python-google-api-python-client, python-google-auth-httplib2, python-uritemplate fixes the following issues: Changes in python-uritemplate, python-google-auth-httplib2, python-google-api-python-client: - shipped for use by python-certbot-dns-google. Changes in python-certbot-dns-google: Update to version 2.11.0: * sync with the main certbot package Update to 2.9.0: * Support for Python 3.12 was added. * Updates `joinpath` syntax to only use one addition per call, because the multiple inputs version was causing mypy errors on Python 3.10. * Makes the `reconfigure` verb actually use the staging server for the dry run to check the new configuration. Update to version 2.7.3: * Filter zones in certbot-dns-google to avoid usage of private DNS zones to create records Update to version 2.6.0: * Support for Python 3.11 was added to Certbot and all of its components. * All Certbot components now require pytest to run tests. * Packaged tests for all Certbot components besides josepy were moved inside the _internal/tests module. * There is now a new Other annotated challenge object to allow plugins to support entirely novel challenges. * --dns-google-project optionally allows for specifying the project that the DNS zone(s) reside in, which allows for Certbot usage in scenarios where the auth credentials reside in a different project to the zone(s) that are being managed. * certbot-dns-google now loads credentials using the standard Application Default Credentials strategy, rather than explicitly requiring the Google Compute metadata server to be present if a service account is not provided using --dns-google-credentials. * --dns-google-credentials now supports additional types of file-based credential, such as External Account Credentials created by Workload Identity Federation. All file-based credentials implemented by the Google Auth library are supported. * certbot-dns-google no longer requires deprecated oauth2client library. * Certbot no longer depends on zope. Update to 1.29.0: * --allow-subset-of-names will now additionally retry in cases where domains are rejected while creating or finalizing orders. This requires subproblem support from the ACME server * The show_account subcommand now uses the "newAccount" ACME endpoint to fetch the account data, so it doesn't rely on the locally stored account URL. This fixes situations where Certbot would use old ACMEv1 registration info with non-functional account URLs. * The generated Certificate Signing Requests are now generated as version 1 instead of version 3. This resolves situations in where strict enforcement of PKCS#10 meant that CSRs that were generated as version 3 were rejected Update to version 1.26.0: * GCP Permission list for certbot-dns-google in plugin documentation python-certbot-dns-google-2.11.0-bp157.2.3.1.src.rpm python311-certbot-dns-google-2.11.0-bp157.2.3.1.noarch.rpm python-google-api-python-client-2.170.0-bp157.2.1.src.rpm python311-google-api-python-client-2.170.0-bp157.2.1.noarch.rpm python-google-auth-httplib2-0.2.0-bp157.2.1.src.rpm python311-google-auth-httplib2-0.2.0-bp157.2.1.noarch.rpm python-uritemplate-4.1.1-bp157.2.1.src.rpm python311-uritemplate-4.1.1-bp157.2.1.noarch.rpm openSUSE-2025-213 Recommended update for ollama moderate openSUSE Backports SLE-15-SP7 Update This update for ollama fixes the following issues: Update to version 0.9.0: * Ollama now has the ability to enable or disable thinking. This gives users the flexibility to choose the model’s thinking behavior for different applications and use cases. Update to version 0.8.0: * Ollama will now stream responses with tool calls * Logs will now include better memory estimate debug information when running models in Ollama's engine. Update to version 0.7.1: * Improved model memory management to allocate sufficient memory to prevent crashes when running multimodal models in certain situations * Enhanced memory estimation for models to prevent unintended memory offloading * ollama show will now show ... when data is truncated * Fixed crash that would occur with qwen2.5vl * Fixed crash on Nvidia's CUDA for llama3.2-vision * Support for Alibaba's Qwen 3 and Qwen 2 architectures in Ollama's new multimodal engine ollama-0.9.0-bp157.5.1.src.rpm ollama-0.9.0-bp157.5.1.x86_64.rpm ollama-0.9.0-bp157.5.1.aarch64.rpm ollama-0.9.0-bp157.5.1.ppc64le.rpm ollama-0.9.0-bp157.5.1.s390x.rpm openSUSE-2025-214 Recommended update for openQA moderate openSUSE Backports SLE-15-SP7 Update This update for openQA fixes the following issues: - Update to version 5.1749832158.cc746ea0: * Bump @eslint/config-helpers from 0.2.2 to 0.2.3 * Docs: Convert images/openqa-in-5-minutes.gif to webm * Add test for failing save_needle with abort call * Document considerations for zero-downtime upgrades * Bump @eslint/config-array from 0.20.0 to 0.20.1 * Bump @eslint/plugin-kit from 0.3.1 to 0.3.2 * Change `do_cleanup` definition in test using `scm git` * apparmor: Allow file lock in fixed iso/hdd images * apparmor: Allow using 'git-lfs' * Disable git_auto_update by default * Re-add git_auto_commit and improved docs for the git settings * Tweak git config access in _git_clone_all * Disentangle git_auto_clone and git_auto_update * Bump brace-expansion from 1.1.11 to 1.1.12 * Update documentation with the new postgres format * Avoid showing too much probably disturbing errors on test details page * Update deprecated postgresql repository * Print one URL per line in test settings * Bump eslint-scope from 8.3.0 to 8.4.0 * Bump espree from 10.3.0 to 10.4.0 * Verify log output when cleanup fail in _save_needles * Improve error handling when loading test module results * Simplify the `createElement()` function * Restore behavior in case of empty details JSON after ca86aec6 * Verify abort job when git is disabled and do_cleanup is 'no' * Avoid job terminated unexpectedly by add signal handler * Bump datatables.net-bs5 from 2.3.1 to 2.3.2 * Bump acorn from 8.14.1 to 8.15.0 * Use regex when checking worker config for relevant sections * Allow appending values in worker config via `+=` * Streamline coding style in `t/24-worker-settings.t` * Allow using list and range specifiers in worker config file - Update to version 5.1749214996.3536da99: * Bump @types/estree from 1.0.7 to 1.0.8 * Support sass generation in all product versions * Avoid sporadic test failures due to warning about closed ws connection * Increase chart testing verbosity for better log trace * Bump ace-builds from 1.41.0 to 1.42.0 * Bump eslint from 9.27.0 to 9.28.0 * Bump @pkgr/core from 0.2.4 to 0.2.7 * Remove nested .gitignore from openQA rpm * Add permissions to avoid the warnings in openQA build - Update to version 5.1748615746.d50d8e24: * Bump synckit from 0.11.6 to 0.11.8 * Bump eslint-plugin-prettier from 5.4.0 to 5.4.1 * Support repeated query params in filter parsing * Replace deprecated ingress class annotation with ingressClassName * CI: Update python version in check-helm-chart * Avoid database error when more than one limit parameter is specified * Use signatures in all functions of `t/ui/18-tests-details.t` * Improve details of test details test * Refactor search_args construction for multi-valued query parameters * Allow comma-separated filtering of flavor * Dependency cron 2025-05-26 * t: Test if flavor options from URL are carried over to the form * t: Add more testing of comma-separated values * t: Check URL contains single flavor * Apply macro to support upcoming opensuse/sle 16 build - Update to version 5.1748004971.d2bfe8ce: * CI: Enable Leap 16.0 OBS build checks * systemd: Increase availability of openqa-webui with ordering * systemd: Remove obsolete ordering of websockets after scheduler * Update GettingStarted.asciidoc Fedora instructions * Deprecate skip-checks and add check-repos option * Switch overly verbose "Updating seen from worker" messages to trace * t: Also use default test database in full-stack+deploy * Fix quoting issue in run-tests-within-container script * Bump eslint from 9.26.0 to 9.27.0 * Bump @modelcontextprotocol/sdk from 1.11.3 to 1.11.4 * Bump synckit from 0.11.5 to 0.11.6 * Create link to the common prove_wrapper * Avoid repeated calls to $t->app->minion * Add linear backoff in hook script * Sync the subrepo external/os-autoinst-common * Bump datatables.net-bs5 from 2.3.0 to 2.3.1 * Dependency cron 2025-05-16 * Bump @modelcontextprotocol/sdk from 1.11.2 to 1.11.3 * Bump eventsource-parser from 3.0.1 to 3.0.2 * Set TESTS_FAILED_FLAG to 1 instead of touching file * Explain container execution and CONTAINER_TEST implications * Remove section which checks unused variable * Update checkstyle invocation in run-tests-within-container script - Update to version 5.1747282262.9a4e6bb5: * load-templates: with --clean, empty job group YAML templates * Fix phrasing in jobs comment carry over unit test * Bump debug from 4.4.0 to 4.4.1 * Bump synckit from 0.11.4 to 0.11.5 * Avoid workers getting stuck with old jobs * Avoid duplicate `use Mojo::JSON` * Follow consistent database DUMP_FOLDER target directory * Create new systemd service and timer for database dump and cleanup * dump-templates: dump job groups as they exist, fix group checks * t: load-templates: check harder for what gets loaded * load-templates: job groups: simplify, don't error on group exists * load-templates: fix loading of job templates openQA-5.1749832158.cc746ea0-bp157.2.4.1.src.rpm openQA-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-auto-update-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-bootstrap-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-client-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-common-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-continuous-update-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-devel-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-doc-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-local-db-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-munin-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-python-scripts-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-single-instance-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-single-instance-nginx-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-worker-5.1749832158.cc746ea0-bp157.2.4.1.x86_64.rpm openQA-client-test-5.1749832158.cc746ea0-bp157.2.4.1.src.rpm openQA-test-5.1749832158.cc746ea0-bp157.2.4.1.src.rpm openQA-worker-test-5.1749832158.cc746ea0-bp157.2.4.1.src.rpm openQA-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-auto-update-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-bootstrap-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-client-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-common-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-continuous-update-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-devel-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-doc-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-local-db-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-munin-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-python-scripts-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-single-instance-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-single-instance-nginx-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-worker-5.1749832158.cc746ea0-bp157.2.4.1.aarch64.rpm openQA-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-auto-update-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-bootstrap-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-client-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-common-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-continuous-update-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-devel-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-doc-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-local-db-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-munin-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-python-scripts-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-single-instance-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-single-instance-nginx-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-worker-5.1749832158.cc746ea0-bp157.2.4.1.ppc64le.rpm openQA-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-auto-update-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-bootstrap-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-client-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-common-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-continuous-update-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-devel-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-doc-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-local-db-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-munin-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-python-scripts-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-single-instance-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-single-instance-nginx-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openQA-worker-5.1749832158.cc746ea0-bp157.2.4.1.s390x.rpm openSUSE-2025-210 Security update for chromium important openSUSE Backports SLE-15-SP7 Update Chromium was updated to 137.0.7151.119 (stable release 2025-06-17) (boo#1244711): * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler chromedriver-137.0.7151.119-bp157.2.12.1.x86_64.rpm chromium-137.0.7151.119-bp157.2.12.1.src.rpm chromium-137.0.7151.119-bp157.2.12.1.x86_64.rpm chromedriver-137.0.7151.119-bp157.2.12.1.aarch64.rpm chromium-137.0.7151.119-bp157.2.12.1.aarch64.rpm openSUSE-2025-217 Recommended update for python-libvirt-python moderate openSUSE Backports SLE-15-SP7 Update This update for python-libvirt-python fixes the following issues: python-libvirt-python updated to 11.0.0. python-libvirt-python-11.0.0-bp157.4.1.src.rpm python-libvirt-python-debugsource-11.0.0-bp157.4.1.x86_64.rpm python311-libvirt-python-11.0.0-bp157.4.1.x86_64.rpm python311-libvirt-python-debuginfo-11.0.0-bp157.4.1.x86_64.rpm python-libvirt-python-debugsource-11.0.0-bp157.4.1.i586.rpm python311-libvirt-python-11.0.0-bp157.4.1.i586.rpm python311-libvirt-python-debuginfo-11.0.0-bp157.4.1.i586.rpm python-libvirt-python-debugsource-11.0.0-bp157.4.1.aarch64.rpm python311-libvirt-python-11.0.0-bp157.4.1.aarch64.rpm python311-libvirt-python-debuginfo-11.0.0-bp157.4.1.aarch64.rpm python-libvirt-python-debugsource-11.0.0-bp157.4.1.ppc64le.rpm python311-libvirt-python-11.0.0-bp157.4.1.ppc64le.rpm python311-libvirt-python-debuginfo-11.0.0-bp157.4.1.ppc64le.rpm python-libvirt-python-debugsource-11.0.0-bp157.4.1.s390x.rpm python311-libvirt-python-11.0.0-bp157.4.1.s390x.rpm python311-libvirt-python-debuginfo-11.0.0-bp157.4.1.s390x.rpm openSUSE-2025-208 Security update for velociraptor important openSUSE Backports SLE-15-SP7 Update This update for velociraptor fixes the following issues: - Update to version 0.7.0.4.git152.fb24dfd: * audit: fix watch rules in artifacts * audit: update go-libaudit dependency for pcc64le arch filter fix * Use execsnoop plugin in artifacts when possible * Add execsnoop plugin to capture execve system calls * github-actions: update ubuntu runners to 22.04 * Fix failing tls unit test on new go versions - Update to version 0.7.0.4.git142.862ef23: * github: fix deprecated upload artifact again * Update npm packages Includes fixes for the following vulnerabilities: CVE-2023-45133 CVE-2023-46234 CVE-2024-55565 CVE-2024-45296 CVE-2023-44270 CVE-2024-47068 CVE-2024-23331 CVE-2024-31207 CVE-2024-45812 CVE-2024-45811 * Update go dependencies Includes fixes for the following vulnerabilities: CVE-2024-45338 CVE-2024-37298 CVE-2024-24786 CVE-2023-45683 (boo#1216310) CVE-2023-1732 * Update jwt to 4.5.1 Fixes CVE-2024-51744 (boo#1232944) * Update go-retryablehttp to 0.7.7 Fixes CVE-2024-6104 (boo#1227061) * Update go-oidc and go-jose Fixes CVE-2024-28180 (boo#1235168) * Update dompurify to 3.1.3 Fixes CVE-2024-47875 (boo#1231574) * Update package-lock.json * Update micromatch to 4.0.8 Partial fix for CVE-2024-4067 (boo#1224367) Partial fix for CVE-2024-4068 (boo#1224296) * Update axios to 1.7.9 Fixes CVE-2024-39338 (boo#1229424) * Update cross-spawn to 7.0.6 Fixes CVE-2024-21538 (boo#1233845) * Update elliptic to 6.6.1 Update contains fixes for: CVE-2024-48949 (boo#1231558) CVE-2024-48948 (boo#1231685) CVE-2024-42459 (boo#1232543) CVE-2024-42460 (boo#1232543) CVE-2024-42461 (boo#1232543) * Update follow-redirects to 1.15.6 Fixes CVE-2024-28849 (boo#1221456) * fix: gui/velociraptor/package.json to reduce vulnerabilities Fixes CVE-2022-25883 (boo#1212572) - Update to version 0.7.0.4.git126.27cfbe1: * bpf: fix plugins not stopping when context cancelled * tcpsnoop: move parsing to its own function * bpf plugins: remove depreciated libbpfgo calls * bpf plugins: add context to error logs * chattrsnoop: fix files not getting closed * chattrsnoop: move hashing from plugin to artifact * RPM artifact: start checks immediately on artifact load * rpm plugin: fix ndb magic error * audit s390x: fix arch filter rules errors * github: fix deprecated upload artifact * tcpsnoop: fix ipv6 local and remote addresses order * tcpsnoop: fix missing ipv6 outbound connections * Linux.Events.ProcessExecutions: remove parent cmdline * audit: reduce FileBufferLeaseSize to ease GC overhead * audit: fix auditBuf allocation and go vet warnings * audit: fix plugin shutdown race condition * audit: fix audit client data races * audit: fix race in subscriber * audit: prevent Windows loading audit package * sdjournal: fix package causing test failures * github: run linux unit tests - Update node modules with security fixes. * Fixes CVE-2024-39338 (boo#1229424) - Update to version 0.7.0.4.git97.675e45f9: * kafka-humio-gateway: update go version and dependency list * kafka-humio-gateway: specific mTLS cert paths in config.yml * docker-compose: set kafka replication factor and min ISRs * kafka-humio-gateway: add http post retry mechanism * kafka-humio-gateway: add pprof debugging option * kafka-humio-gateway: format with gofmt * kafka-humio-gateway: fix go-staticcheck issues * kafka-humio-gateway: fix sendEvents() never exiting * Kafka.Events.Client: Update to use new artifactset type * docker-compose: add optional Kafka cluser * kafka-humio-gateway: add mTLS support * contrib/kafka-humio-gateway: add new debug option for noisy events * contrib/kafka-humio-gateway: backoff and retry for metadata * kafka-humio-gateway: add sample config file * kafka-humio-gateway: update sarama and dependencies * Add Kafka-Humio Gateway [Depends on PR#10] (#8) * vql/server/kafka: connect sarama logging to velociraptor logging * vql/server/kafka: add exponential backoff (limited to 30s) for metadata retries * vql/server/kafka: set appropriate ClientID * Add a Kafka export plugin - Update to version 0.7.0.4.git74.3426c0a: * Fix services artifact symbol pid not found error * chattrsnoop: correct read size for flags * chattrsnoop: fix wrong FS_IOC_SETFLAGS value for ppc * chattrsnoop: fix do_vfs_ioctl kprobe failure - Update to version 0.7.0.4.git68.ad1f4e5: * Fix undefined binary.NativeEndian build errors - Add llvm16-libclang13 dependency for SLE 15 SP5 and above - Update to version 0.7.0.4.git66.eea7659: * dnssnoop: fix loading protocol from ip header on s390 * dnssnoop: fix htons() so it works on s390 too * Fix systemd Services artifact missing events * chattrsnoop: replace global variables with locals * tcpsnoop: fix garbled results on s390 * chattrsnoop: fix immutable attribute set on s390 * chattrsnoop: fix bpf_probe_read for s390 * tcpsnoop: remove unused filtering code * Add artifact to collect new files without owner * bpf plugins: set a logger callback - Update to version 0.7.0.4.git47.0f8a4de1: * Rename SUSE specific artifacts to have SUSE prefix * Add SUSE.Linux.Events.NewZeroSizeLogFile artifact * Move NewFiles artifact to SUSE * Move ImmutableFile artifact to SUSE * Make ImmutableFile artifact consistent with others * Fix absolute path case in ExecutableFiles artifact * Add client monitoring artifact for RPMs * Add artifact to collect new hidden files * Add artifact to monitor ssh authorized_keys files * Fix split_records error on older clients * Add hash fields to Linux.Events.ProcessExecutions * Add artifact to collect systemd service events * Fix SystemLogins artifacts file extensions * Add SUSE.Linux.Events.Timers artifact * Fix audit filter key typo in Linux.Events.NewFiles * Add server artifact to delete old client data on server * Add SUSE.Linux.Sys.At artifact * chattrsnoop: include full error details in logs * chattrsnoop: handle os.Stat() error properly * chattrsnoop: don't log.Fatal() on hash error * Fix Linux.Events.ImmutableFile not showing hash in GUI * SUSE.Linux.Events.Crontab: Add task execution artifacts * Raise client connection log level to ERROR * sdjournal: Correctly seek to current tail - Update to version 0.7.0.4.git6.7b40b8b: * go.mod: increase go version to 1.19 velociraptor-0.7.0.4.git152.fb24dfd-bp157.2.3.1.src.rpm velociraptor-0.7.0.4.git152.fb24dfd-bp157.2.3.1.x86_64.rpm system-user-velociraptor-1.0.0-bp157.2.3.1.noarch.rpm velociraptor-client-0.7.0.4.git152.fb24dfd-bp157.2.3.1.src.rpm velociraptor-client-0.7.0.4.git152.fb24dfd-bp157.2.3.1.x86_64.rpm velociraptor-client-0.7.0.4.git152.fb24dfd-bp157.2.3.1.aarch64.rpm velociraptor-client-0.7.0.4.git152.fb24dfd-bp157.2.3.1.ppc64le.rpm velociraptor-client-0.7.0.4.git152.fb24dfd-bp157.2.3.1.s390x.rpm openSUSE-2025-235 Recommended update for openQA-devel-container moderate openSUSE Backports SLE-15-SP7 Update This update for openQA-devel-container fixes the following issues: - Update to version 5.1749650866.7a5a615c8: * Update to latest openQA version openQA-5.1749832158.cc746ea0-bp157.2.6.1.src.rpm openQA-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-auto-update-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-bootstrap-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-client-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-common-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-continuous-update-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-devel-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-doc-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-local-db-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-munin-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-python-scripts-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-single-instance-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-single-instance-nginx-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-worker-5.1749832158.cc746ea0-bp157.2.6.1.x86_64.rpm openQA-client-test-5.1749832158.cc746ea0-bp157.2.6.1.src.rpm openQA-test-5.1749832158.cc746ea0-bp157.2.6.1.src.rpm openQA-worker-test-5.1749832158.cc746ea0-bp157.2.6.1.src.rpm openQA-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-auto-update-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-bootstrap-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-client-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-common-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-continuous-update-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-devel-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-doc-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-local-db-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-munin-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-python-scripts-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-single-instance-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-single-instance-nginx-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-worker-5.1749832158.cc746ea0-bp157.2.6.1.aarch64.rpm openQA-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-auto-update-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-bootstrap-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-client-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-common-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-continuous-update-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-devel-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-doc-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-local-db-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-munin-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-python-scripts-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-single-instance-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-single-instance-nginx-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-worker-5.1749832158.cc746ea0-bp157.2.6.1.ppc64le.rpm openQA-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-auto-update-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-bootstrap-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-client-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-common-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-continuous-update-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-devel-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-doc-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-local-db-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-munin-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-python-scripts-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-single-instance-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-single-instance-nginx-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openQA-worker-5.1749832158.cc746ea0-bp157.2.6.1.s390x.rpm openSUSE-2025-220 Security update for libetebase moderate openSUSE Backports SLE-15-SP7 Update This update for libetebase fixes the following issues: Update to version 0.5.8: * CVE-2025-3416: Fixed rust openssl: Use-After-Free in Md::fetch and Cipher::fetch in rust-openssl crate (bsc#1242638) * Deps: run cargo update. libetebase-0.5.8-bp157.2.3.1.src.rpm libetebase-devel-0.5.8-bp157.2.3.1.x86_64.rpm libetebase0-0.5.8-bp157.2.3.1.x86_64.rpm libetebase-devel-0.5.8-bp157.2.3.1.i586.rpm libetebase0-0.5.8-bp157.2.3.1.i586.rpm libetebase-devel-0.5.8-bp157.2.3.1.aarch64.rpm libetebase0-0.5.8-bp157.2.3.1.aarch64.rpm libetebase-devel-0.5.8-bp157.2.3.1.ppc64le.rpm libetebase0-0.5.8-bp157.2.3.1.ppc64le.rpm libetebase-devel-0.5.8-bp157.2.3.1.s390x.rpm libetebase0-0.5.8-bp157.2.3.1.s390x.rpm openSUSE-2025-224 Recommended update for queue moderate openSUSE Backports SLE-15-SP7 Update This update for queue fixes the following issues: Version 1.2.0: - Ignore broken pipe error (e.g. when piping to head) Version 1.2.0: - Only use dark_grey if available Version 1.1.0: - Color scheduled and running entries differently - Enable multi column limiting - Add hint about config location Version 1.3.0: - Ignore broken pipe error (e.g. when piping to head) Version 1.2.0: - Only use dark_grey if available Version 1.1.0: - Color scheduled and running entries differently - Enable multi column limiting - Add hint about config location queue-1.3.0-bp157.2.3.1.noarch.rpm queue-1.3.0-bp157.2.3.1.src.rpm openSUSE-2025-232 Security update for chromium important openSUSE Backports SLE-15-SP7 Update this update for chromium 138.0.7204.96 (stable released 2025-06-30) (boo#1245544) fixes the following issues: * cve-2025-6554: type confusion in v8 * CVE-2025-6555: Use after free in Animation * CVE-2025-6556: Insufficient policy enforcement in Loader * CVE-2025-6557: Insufficient data validation in DevTools chromedriver-138.0.7204.96-bp157.2.19.1.x86_64.rpm chromedriver-debuginfo-138.0.7204.96-bp157.2.19.1.x86_64.rpm chromium-138.0.7204.96-bp157.2.19.1.src.rpm chromium-138.0.7204.96-bp157.2.19.1.x86_64.rpm chromium-debuginfo-138.0.7204.96-bp157.2.19.1.x86_64.rpm gh-2.74.2-bp157.2.3.1.src.rpm gh-2.74.2-bp157.2.3.1.x86_64.rpm gh-bash-completion-2.74.2-bp157.2.3.1.noarch.rpm gh-debuginfo-2.74.2-bp157.2.3.1.x86_64.rpm gh-fish-completion-2.74.2-bp157.2.3.1.noarch.rpm gh-zsh-completion-2.74.2-bp157.2.3.1.noarch.rpm gn-0.20250520-bp157.2.3.1.src.rpm gn-0.20250520-bp157.2.3.1.x86_64.rpm gn-debuginfo-0.20250520-bp157.2.3.1.x86_64.rpm gn-debugsource-0.20250520-bp157.2.3.1.x86_64.rpm gh-2.74.2-bp157.2.3.1.i586.rpm gh-debuginfo-2.74.2-bp157.2.3.1.i586.rpm gn-0.20250520-bp157.2.3.1.i586.rpm gn-debuginfo-0.20250520-bp157.2.3.1.i586.rpm gn-debugsource-0.20250520-bp157.2.3.1.i586.rpm chromedriver-138.0.7204.96-bp157.2.19.1.aarch64.rpm chromedriver-debuginfo-138.0.7204.96-bp157.2.19.1.aarch64.rpm chromium-138.0.7204.96-bp157.2.19.1.aarch64.rpm chromium-debuginfo-138.0.7204.96-bp157.2.19.1.aarch64.rpm gh-2.74.2-bp157.2.3.1.aarch64.rpm gh-debuginfo-2.74.2-bp157.2.3.1.aarch64.rpm gn-0.20250520-bp157.2.3.1.aarch64.rpm gn-debuginfo-0.20250520-bp157.2.3.1.aarch64.rpm gn-debugsource-0.20250520-bp157.2.3.1.aarch64.rpm gh-2.74.2-bp157.2.3.1.ppc64le.rpm gh-debuginfo-2.74.2-bp157.2.3.1.ppc64le.rpm gn-0.20250520-bp157.2.3.1.ppc64le.rpm gn-debuginfo-0.20250520-bp157.2.3.1.ppc64le.rpm gn-debugsource-0.20250520-bp157.2.3.1.ppc64le.rpm gh-2.74.2-bp157.2.3.1.s390x.rpm gh-debuginfo-2.74.2-bp157.2.3.1.s390x.rpm gn-0.20250520-bp157.2.3.1.s390x.rpm gn-debuginfo-0.20250520-bp157.2.3.1.s390x.rpm gn-debugsource-0.20250520-bp157.2.3.1.s390x.rpm openSUSE-2025-228 Recommended update for gitea-tea moderate openSUSE Backports SLE-15-SP7 Update This update for gitea-tea fixes the following issues: - update to 0.10.1: * Update release ci * chore(deps): update crazy-max/ghaction-import-gpg action to v6 * fix(deps): update module github.com/urfave/cli/v3 to v3.3.8 - update to 0.10.0: * fix: support SSH remotes with non-standard ports * minor helper fixes * Bump Table Dep * Login via oauth2 flow * Feat: interactive issue edit command * Use flakes vs devbox * Fix helper panic * Add --note-file flag to read release notes from a file * Fix/Login Edit Use Editor Env * Gitea Actions support * Expose --labels option * Add git helper * Support auto detecting branch for PRs * context: move human readable note to stderr * Add repos rm/delete command * Release Asset Management * tea branches list/protect/unprotect * Add OTP and scopes to login * Initial CLI docs * Fix for go tools called from make * fix interactive login add * issues list can show filtered by owner/org instead of repo too * fix: non-standard ssh port URL's repo can't be recognized * updated dependencies gitea-tea-0.10.1-bp157.2.3.1.src.rpm gitea-tea-0.10.1-bp157.2.3.1.x86_64.rpm gitea-tea-bash-completion-0.10.1-bp157.2.3.1.noarch.rpm gitea-tea-zsh-completion-0.10.1-bp157.2.3.1.noarch.rpm gitea-tea-0.10.1-bp157.2.3.1.i586.rpm gitea-tea-0.10.1-bp157.2.3.1.aarch64.rpm gitea-tea-0.10.1-bp157.2.3.1.ppc64le.rpm gitea-tea-0.10.1-bp157.2.3.1.s390x.rpm openSUSE-2025-230 Security update for roundcubemail important openSUSE Backports SLE-15-SP7 Update This update for roundcubemail fixes the following issues: Update to 1.6.11: This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: * Fix Post-Auth RCE via PHP Object Deserialization reported by firs0v. - CHANGELOG * Managesieve: Fix match-type selector (remove unsupported options) in delete header action (#9610) * Improve installer to fix confusion about disabling SMTP authentication (#9801) * Fix PHP warning in index.php (#9813) * OAuth: Fix/improve token refresh * Fix dark mode bug where wrong colors were used for blockquotes in HTML mail preview (#9820) * Fix HTML message preview if it contains floating tables (#9804) * Fix removing/expiring redis/memcache records when using a key prefix * Fix bug where a wrong SPECIAL-USE folder could have been detected, if there were more than one per-type (#9781) * Fix a default value and documentation of password_ldap_encodage option (#9658) * Remove mobile/floating Create button from the list in Settings > Folders (#9661) * Fix Delete and Empty buttons state while creating a folder (#9047) * Fix connecting to LDAP using ldapi:// URI (#8990) * Fix cursor position on "below the quote" reply in HTML mode (#8700) * Fix bug where attachments with content type of application/vnd.ms-tnef were not parsed (#7119) roundcubemail-1.6.11-bp157.2.3.1.noarch.rpm roundcubemail-1.6.11-bp157.2.3.1.src.rpm openSUSE-2025-231 Security update for sslh important openSUSE Backports SLE-15-SP7 Update This update for sslh fixes the following issues: sslh was updated to 2.2.4: * Fix CVE-2025-46806 (boo#1243120) for "Misaligned Memory Accesses in `is_openvpn_protocol()`" * Fix CVE-2025-46807 (boo#1243122) for "File Descriptor Exhaustion in sslh-select and sslh-ev" * Fix potential parsing of undefined data in syslog probe (no CVE assigned) Update to 2.2.3: * Reverse older commit: version.h cannot be included without breaking the build (everything recompiles every time) and the release archive creation (which relies on git tags). Update to 2.2.2: * Fix potential vulnerability similar to CVE-2020-28935 Update to 2.2.1: * Fix compilation when libproxyprotocol is not present Update to 2.2.0: * Add a boolean setting "is_unix" for listen and protocol entries. This will use the 'host' setting as a path name to a socket file, and connections (listening or connecting) will be performed on Unix socket instead of Internet sockets. * Support HAProxy's proxyprotocol on the backend server side. * Lots of documentation about a new, simpler way to perform transparent proxying. * New "verbose" option that overrides all other verbose settings. Update to 2.1.3: * Landlock access fix Update to 2.1.2: * Fix inetd Update to 2.1.1: * Fix MacOS build error Update to 2.1.0: * Support for the Landlock LSM. After initial setup, sslh gives up all local file access rights. * Reintroduced --ssl as an alias to --tls. * Introduce autoconf to adapt to landlock presence. * Close connexion without error message if remote client forcefully closes connexion, for Windows. Update to 2.0.1: * New semver-compatible version number * New sslh-ev: this is functionaly equivalent to sslh-select (mono-process, only forks for specified protocols), but based on libev, which should make it scalable to large numbers of connections. * New log system: instead of –verbose with arbitrary levels, there are now several message classes. Each message class can be set to go to stderr, syslog, or both. Classes are documented in example.cfg. * UDP connections are now managed in a hash to avoid linear searches. The downside is that the number of UDP connections is a hard limit, configurable with the ‘udp_max_connections’, which defaults to 1024. Timeouts are managed with lists. * inetd merges stderr output to what is sent to the client, which is a security issue as it might give information to an attacker. When inetd is activated, stderr is forcibly closed. * New protocol-level option resolve_on_forward, requests that target names are resolved at each connection instead of at startup. Useful for dynamic DNS situations. sslh-2.2.4-bp157.2.3.1.src.rpm sslh-2.2.4-bp157.2.3.1.x86_64.rpm sslh-2.2.4-bp157.2.3.1.i586.rpm sslh-2.2.4-bp157.2.3.1.aarch64.rpm sslh-2.2.4-bp157.2.3.1.ppc64le.rpm sslh-2.2.4-bp157.2.3.1.s390x.rpm openSUSE-2025-237 Security update for mosquitto moderate openSUSE Backports SLE-15-SP7 Update This update for mosquitto fixes the following issues: mosquitto was update to version 2.0.21: * Broker * Fix clients sending a RESERVED packet not being quickly disconnected. * Fix bind_interface producing an error when used with an interface that has an IPv6 link-local address and no other IPv6 addresses. * Fix mismatched wrapped/unwrapped memory alloc/free in properties. * Fix allow_anonymous false not being applied in local only mode. * Add retain_expiry_interval option to fix expired retained message not being removed from memory if they are not subscribed to. * Produce an error if invalid combinations of cafile/capath/certfile/keyfile are used. * Backport keepalive checking from develop to fix problems in current implementation. * Client library * Fix potential deadlock in mosquitto_sub if -W is used. * Apps * mosquitto_ctrl dynsec now also allows -i to specify a clientid as well as -c. This matches the documentation which states -i. - systemd service: Wait till the network got setup to avoid startup failure. - Update to version 2.0.19 (CVE-2024-3935 boo#1232635, CVE-2024-10525 boo#1232636): libmosquitto1-2.0.21-bp157.2.3.1.x86_64.rpm libmosquittopp1-2.0.21-bp157.2.3.1.x86_64.rpm mosquitto-2.0.21-bp157.2.3.1.src.rpm mosquitto-2.0.21-bp157.2.3.1.x86_64.rpm mosquitto-clients-2.0.21-bp157.2.3.1.x86_64.rpm mosquitto-devel-2.0.21-bp157.2.3.1.x86_64.rpm libmosquitto1-2.0.21-bp157.2.3.1.aarch64.rpm libmosquittopp1-2.0.21-bp157.2.3.1.aarch64.rpm mosquitto-2.0.21-bp157.2.3.1.aarch64.rpm mosquitto-clients-2.0.21-bp157.2.3.1.aarch64.rpm mosquitto-devel-2.0.21-bp157.2.3.1.aarch64.rpm libmosquitto1-2.0.21-bp157.2.3.1.ppc64le.rpm libmosquittopp1-2.0.21-bp157.2.3.1.ppc64le.rpm mosquitto-2.0.21-bp157.2.3.1.ppc64le.rpm mosquitto-clients-2.0.21-bp157.2.3.1.ppc64le.rpm mosquitto-devel-2.0.21-bp157.2.3.1.ppc64le.rpm libmosquitto1-2.0.21-bp157.2.3.1.s390x.rpm libmosquittopp1-2.0.21-bp157.2.3.1.s390x.rpm mosquitto-2.0.21-bp157.2.3.1.s390x.rpm mosquitto-clients-2.0.21-bp157.2.3.1.s390x.rpm mosquitto-devel-2.0.21-bp157.2.3.1.s390x.rpm openSUSE-2025-241 Security update for spdlog moderate openSUSE Backports SLE-15-SP7 Update This update for spdlog fixes the following issues: - CVE-2025-6140: Fixed input manipulation that may lead to resource consumption (boo#1244696) libspdlog1_11-1.11.0-bp157.2.3.1.x86_64.rpm spdlog-1.11.0-bp157.2.3.1.src.rpm spdlog-devel-1.11.0-bp157.2.3.1.x86_64.rpm libspdlog1_11-1.11.0-bp157.2.3.1.aarch64.rpm libspdlog1_11-64bit-1.11.0-bp157.2.3.1.aarch64_ilp32.rpm spdlog-devel-1.11.0-bp157.2.3.1.aarch64.rpm libspdlog1_11-1.11.0-bp157.2.3.1.ppc64le.rpm spdlog-devel-1.11.0-bp157.2.3.1.ppc64le.rpm libspdlog1_11-1.11.0-bp157.2.3.1.s390x.rpm spdlog-devel-1.11.0-bp157.2.3.1.s390x.rpm openSUSE-2025-247 Recommended update for sassist moderate openSUSE Backports SLE-15-SP7 Update This update for sassist fixes the following issues: Update to 0.8.7 * sos and supportconfig fixes. * documentation updates. * update the revision in _service file sassist-0.8.7-bp157.2.3.1.noarch.rpm sassist-0.8.7-bp157.2.3.1.src.rpm openSUSE-2025-243 Security update for chmlib important openSUSE Backports SLE-15-SP7 Update This update for chmlib fixes the following issues: - CVE-2025-48172: Fixed integer overflow in _chm_decompress_block of chm_lib.c, that could lead to heap buffer overflow (boo#1245803). chmlib-0.40-bp157.2.3.1.src.rpm chmlib-devel-0.40-bp157.2.3.1.x86_64.rpm chmlib-examples-0.40-bp157.2.3.1.x86_64.rpm libchm0-0.40-bp157.2.3.1.x86_64.rpm chmlib-devel-0.40-bp157.2.3.1.i586.rpm chmlib-devel-32bit-0.40-bp157.2.3.1.x86_64.rpm chmlib-examples-0.40-bp157.2.3.1.i586.rpm libchm0-0.40-bp157.2.3.1.i586.rpm libchm0-32bit-0.40-bp157.2.3.1.x86_64.rpm chmlib-devel-0.40-bp157.2.3.1.aarch64.rpm chmlib-devel-64bit-0.40-bp157.2.3.1.aarch64_ilp32.rpm chmlib-examples-0.40-bp157.2.3.1.aarch64.rpm libchm0-0.40-bp157.2.3.1.aarch64.rpm libchm0-64bit-0.40-bp157.2.3.1.aarch64_ilp32.rpm chmlib-devel-0.40-bp157.2.3.1.ppc64le.rpm chmlib-examples-0.40-bp157.2.3.1.ppc64le.rpm libchm0-0.40-bp157.2.3.1.ppc64le.rpm chmlib-devel-0.40-bp157.2.3.1.s390x.rpm chmlib-examples-0.40-bp157.2.3.1.s390x.rpm libchm0-0.40-bp157.2.3.1.s390x.rpm openSUSE-2025-250 Security update for pdns-recursor important openSUSE Backports SLE-15-SP7 Update This update for pdns-recursor fixes the following issues: - update to 5.1.3: * Implement rfc6303 special zones (mostly v6 reverse mappings) * Distinguish OS imposed limits from app imposed limits, specifically on chains. - update to 5.1.2 (boo#1231292 CVE-2024-25590) https://doc.powerdns.com/recursor/changelog/5.1.html#change-5.1.2 - update to 5.1.1 https://doc.powerdns.com/recursor/changelog/5.1.html#change-5.1.1 https://doc.powerdns.com/recursor/changelog/5.0.html#change-5.0.8 - update to 5.0.5: * Do not count RRSIGs using unsupported algorithms toward RRSIGs limit * Correctly count NSEC3s considered when chasing the closest encloser. * Let NetmaskGroup parse dont-throttle-netmasks, allowing negations. * Fix types of two YAML settings (incoming.edns_padding_from, incoming.proxy_protocol_from) that should be sequences of subnets * Fix trace=fail regression and add regression test for it pdns-recursor-5.1.3-bp157.2.3.1.src.rpm pdns-recursor-5.1.3-bp157.2.3.1.x86_64.rpm pdns-recursor-5.1.3-bp157.2.3.1.aarch64.rpm pdns-recursor-5.1.3-bp157.2.3.1.ppc64le.rpm openSUSE-2025-254 Recommended update for icecast moderate openSUSE Backports SLE-15-SP7 Update This update for icecast fixes the following issues: - Fix logrotate configuration to set the proper owner (boo#1245967); also dropping the corresponding rpmlintrc entry - Provide user/group symbol for user created during pre. icecast-2.4.4-bp157.2.3.1.src.rpm icecast-2.4.4-bp157.2.3.1.x86_64.rpm icecast-doc-2.4.4-bp157.2.3.1.noarch.rpm icecast-2.4.4-bp157.2.3.1.i586.rpm icecast-2.4.4-bp157.2.3.1.aarch64.rpm icecast-2.4.4-bp157.2.3.1.ppc64le.rpm icecast-2.4.4-bp157.2.3.1.s390x.rpm openSUSE-2025-257 Recommended update for munin moderate openSUSE Backports SLE-15-SP7 Update This update for munin fixes the following issues: - Let munin-node use its own log and run sub-directory to avoid privilege escalation (boo#1246089) - Drop dependency on fast-cgi which was replaced in 2.0.x by munin-httpd https://guide.munin-monitoring.org/en/latest/reference/munin-httpd.html - Add /srv/www directories to filelist [boo#1231027] - Fix dependenices: the FastCGI perl module is called FCGI. - remove package name based perl requires - remove dependency on /usr/bin/python3 using %python3_fix_shebang_path macro, [boo#1212476] - Provide user(munin) and group(munin): the user and group are created during in the pre script. - Use IO::Socket::IP instead of IO::Socket::INET[6] * Remove the dependency on perl(IO::Socket::INET6) as it has been deprecated by upstream, is no longer suitable for use and its not being maintained. A compatible replacement for this package is perl(IO::Socket::IP) which is shipped by the perl-base package. * Upstream commit back-ported: https://github.com/munin-monitoring/munin/commit/012b33a7 * Add upstream munin-remove-deprecated-INET6.patch - Drop manual requires for python (boo#1210588) munin-2.0.72-bp157.2.3.1.noarch.rpm munin-2.0.72-bp157.2.3.1.src.rpm munin-node-2.0.72-bp157.2.3.1.noarch.rpm openSUSE-2025-259 Recommended update for git-credential-oauth moderate openSUSE Backports SLE-15-SP7 Update This update for git-credential-oauth fixes the following issues: Introduce version 0.15.0: git-credential-oauth-0.15.0-bp157.2.1.src.rpm git-credential-oauth-0.15.0-bp157.2.1.x86_64.rpm git-credential-oauth-0.15.0-bp157.2.1.i586.rpm git-credential-oauth-0.15.0-bp157.2.1.aarch64.rpm git-credential-oauth-0.15.0-bp157.2.1.ppc64le.rpm git-credential-oauth-0.15.0-bp157.2.1.s390x.rpm openSUSE-2025-261 Recommended update for chafa moderate openSUSE Backports SLE-15-SP7 Update This update for chafa fixes the following issues: - Update to 1.16.1: * Bug fixes: #282 Fish completion not included in release tarball #283 Piping and redirection are broken in Windows - Update to 1.16.0: * Added terminal probing. Currently we can determine geometry, colors and sixel capabilities this way. This supplements the existing heuristics. * The internal terminal database and heuristics were refactored for clarity, with new API added to simplify the configuration process. * I/O is now threaded, resulting in improved responsiveness and pipelining. * New option: --grid=WxH, --grid=[auto|on|off] or -g. This lays out multiple images in a grid for easy browsing. * New option: --label=[on|off] or -l. Labels each image with its filename. Works in both continuous and grid layouts. * New option: --probe=[auto|on|off]. Controls whether to actively probe the terminal. Can take a real number denoting how long to wait for a response. * Sixel quality improved significantly. The quantizer was reimplemented with modern algorithms (#174), and blue noise dithering was introduced (#238). * The new blue noise dithering is also available in symbols mode, and can be turned on with --dither noise. It can be turned off with --dither none. * Numerous small improvements were made to sixel handling: + Terminal cursor placement quirks are now represented and handled. + Images can now cover their cell extents completely. + Workaround for animations "walking up the screen" on quirky terminals. * The JPEG XL loader was improved with optional memory mapping and better container support * Enabled wildcard expansion in Windows builds (#266). * Added completions for the fish shell and updated those for zsh. * Bug fixes: + #111 Provide auto detection of background for perception of transparency + #228 Sixel capability not detected in foot + tmux + #236 Ghostty shows pwd/lock indicator when using Chafa + #238 Sixel image quality significantly different from img2sixel and ImageMagick + #239 Chafa leaves echo on + #245 JPEG file not recognized + #246 Examples using deprecated functions + #249 Sixel detection doesn't set default values + #254 -t 1 doesn't work with -f iterm + #255 Animations scroll/walk up the screen + #265 Enable Kitty image protocol for Warp + #266 On Windows, in a cmd.exe window, filename wildcard expansion is broken + #273 -t 1 messes up some images + #274 -f {kitty,iterm} swaps BG color channels for SVG + #278 Images not always padded to cell boundary + [unfiled] Fix broken bashisms resulting in logic failure + [unfiled] Small leak in chafa_canvas_print_rows() + [unfiled] Uninitialized histogram in nearest-neighbor interp. - Update to 1.14.5: Fixes: * Improve sixel and general terminal support inside tmux * Support JPEGs with CMYK color space * Fix --font-ratio doing nothing * Ensure CLI tool gets linked with libm. - Update to 1.14.4: * Bug fixes: #216 Dither intensity does not work properly - Update to 1.14.3: * Sixel transparency has been reenabled for still frames. Animations will be pre-composited on an opaque background to prevent flicker/glitchiness (#211) * Now supports the Ghostty terminal, defaulting to the Kitty graphics protocol there. * Bug fixes: #185 Chafa version 1.14 breaks image preview on lf. #210 Crash with -f sixels. #211 Sixels are too small in Windows Terminal. #212 Aspect-preserving calculations are off in some cases. [unfiled] Inconsistent fraction parsing in CLI arguments. [unfiled] A few small memory leaks in the JPEG XL loader. - Update to 1.14.2: * #203 Chafa 1.14.1 fails to build on i686 * #205 Symbols mode not working since 1.14.1 * #206 Crash when importing more than 32767 glyphs * Fix erroneous base64 encoding of final byte in some circumstances - Update to 1.14.1: * A JPEG XL (.jxl) loader was added using libjxl (#188). * Added detection of the Eat "Emulate a Terminal" Emacs terminal. * Symbols mode was sped up significantly on AVX2-capable platforms. * Tests: A new test driver was added. It will log the specifics of any failures, which aids debugging of CI builds. * Bug fixes: #189 Fix installation of zsh completions. #190 Fix a small memory leak in ChafaCanvas. #192 Wrong sixel padding in some circumstances. #195 tmux passthrough enabled when already set. #196 iTerm mode not enabled automatically. - Enable optional image formats * jpeg * svg * tiff * webp - Update to 1.14.0: * Removed ImageMagick loader support. Packagers can now remove this dependency * Polite mode is now off by default. The new default eliminates cursor flicker and makes the output more robust against unusual terminal settings. The old behavior can be restored with --polite on. * Added image loaders for the AVIF and QOI formats. * sRGB gamma is now handled correctly in scaling operations. * New option: --passthrough=<auto|none|screen|tmux>. This allows passing graphics protocols like Sixels, iTerm and Kitty through a terminal multiplexer. It will be enabled automatically for Kitty, and can be enabled manually for other protocols with more limited support * New option: --view-size=<WxH>. Specifies width and height of the viewport, overriding the detected terminal size * New option: --fit-width. Fits images to the width of the viewport, allowing them to be taller than the viewport's height * New option: --relative=<bool>. Enables relative cursor positioning. Useful if you've pre-positioned the cursor at a particular offset where you want frames to appear, but tends to make the output illegible in pagers, e.g. less -R * New option: --exact-size=<auto|on|off>. Preserves the input pixel size when possible. Useful to avoid artifacts caused by resampling * New symbol selector: imported. This selects glyphs loaded with --glyph-file * Fontgen: Added a BDF font writer * Fontgen: Cleanup and modernization * The help text and manual page were overhauled for readability, and the API documentation now includes symbol indexes by version and deprecation status. * Added a zsh completion script * Fix "unknown file format" when using AVIF on stdin * Fix broken linking with libwebp-1.3.1 * Fix make check with --without-tools * Fix --duration not working well with still images * Fix sixel rendering of animations * Fix operator precedence in geometry calculation chafa-1.16.1-bp157.2.3.1.src.rpm chafa-1.16.1-bp157.2.3.1.x86_64.rpm chafa-devel-1.16.1-bp157.2.3.1.x86_64.rpm chafa-doc-1.16.1-bp157.2.3.1.noarch.rpm libchafa0-1.16.1-bp157.2.3.1.x86_64.rpm chafa-1.16.1-bp157.2.3.1.i586.rpm chafa-devel-1.16.1-bp157.2.3.1.i586.rpm libchafa0-1.16.1-bp157.2.3.1.i586.rpm chafa-1.16.1-bp157.2.3.1.aarch64.rpm chafa-devel-1.16.1-bp157.2.3.1.aarch64.rpm libchafa0-1.16.1-bp157.2.3.1.aarch64.rpm chafa-1.16.1-bp157.2.3.1.ppc64le.rpm chafa-devel-1.16.1-bp157.2.3.1.ppc64le.rpm libchafa0-1.16.1-bp157.2.3.1.ppc64le.rpm chafa-1.16.1-bp157.2.3.1.s390x.rpm chafa-devel-1.16.1-bp157.2.3.1.s390x.rpm libchafa0-1.16.1-bp157.2.3.1.s390x.rpm openSUSE-2025-256 Recommended update for tinyproxy low openSUSE Backports SLE-15-SP7 Update This update for tinyproxy fixes the following issues: - Add userswitching to logrotate snippet [boo#1246092] - Replace sysvinit call in logrotate snippet by systemctl tinyproxy-1.11.2-bp157.2.3.1.src.rpm tinyproxy-1.11.2-bp157.2.3.1.x86_64.rpm tinyproxy-1.11.2-bp157.2.3.1.i586.rpm tinyproxy-1.11.2-bp157.2.3.1.aarch64.rpm tinyproxy-1.11.2-bp157.2.3.1.ppc64le.rpm tinyproxy-1.11.2-bp157.2.3.1.s390x.rpm openSUSE-2026-19 Recommended update for ansible-sap-launchpad moderate openSUSE Backports SLE-15-SP7 Update This update for ansible-sap-launchpad fixes the following issues: Update to version 1.2.1: - software_center_download: Improved logic for skipping existing files and getting valid filename - sap_software_download: Add SLES 16 python313 support and update changelog ansible-sap-launchpad-1.2.1-bp157.2.3.34.noarch.rpm ansible-sap-launchpad-1.2.1-bp157.2.3.34.src.rpm openSUSE-2025-267 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 138.0.7204.157 (boo#1246558): * CVE-2025-7656: Integer overflow in V8 * CVE-2025-6558: Incorrect validation of untrusted input in ANGLE and GPU * CVE-2025-7657: Use after free in WebRTC - Chromium 138.0.7204.100: * tweaks to the Google services settings page chromedriver-138.0.7204.157-bp157.2.22.1.x86_64.rpm chromium-138.0.7204.157-bp157.2.22.1.src.rpm chromium-138.0.7204.157-bp157.2.22.1.x86_64.rpm chromedriver-138.0.7204.157-bp157.2.22.1.aarch64.rpm chromium-138.0.7204.157-bp157.2.22.1.aarch64.rpm openSUSE-2025-269 Security update for python3-pycares moderate openSUSE Backports SLE-15-SP7 Update This update for python3-pycares fixes the following issues: - CVE-2025-48945: Fixed a use-after-free in the Channel object garbage collection (boo#1244691) python3-pycares-3.1.1-bp157.2.3.1.src.rpm python3-pycares-3.1.1-bp157.2.3.1.x86_64.rpm python3-pycares-3.1.1-bp157.2.3.1.i586.rpm python3-pycares-3.1.1-bp157.2.3.1.aarch64.rpm python3-pycares-3.1.1-bp157.2.3.1.ppc64le.rpm python3-pycares-3.1.1-bp157.2.3.1.s390x.rpm openSUSE-2025-270 Security update for xtrabackup moderate openSUSE Backports SLE-15-SP7 Update This update for xtrabackup fixes the following issues: - CVE-2025-5916: Prevented signed integer overflow while reading warcfile (boo#1244383). - CVE-2025-5917: Fixed overflow in build_ustar_entry_name() (boo#1244333). - CVE-2025-5914: Fixed double free due to an integer overflow (boo#1244389). xtrabackup-2.4.26-bp157.2.3.1.src.rpm xtrabackup-2.4.26-bp157.2.3.1.x86_64.rpm xtrabackup-test-2.4.26-bp157.2.3.1.x86_64.rpm xtrabackup-2.4.26-bp157.2.3.1.i586.rpm xtrabackup-test-2.4.26-bp157.2.3.1.i586.rpm xtrabackup-2.4.26-bp157.2.3.1.aarch64.rpm xtrabackup-test-2.4.26-bp157.2.3.1.aarch64.rpm xtrabackup-2.4.26-bp157.2.3.1.ppc64le.rpm xtrabackup-test-2.4.26-bp157.2.3.1.ppc64le.rpm xtrabackup-2.4.26-bp157.2.3.1.s390x.rpm xtrabackup-test-2.4.26-bp157.2.3.1.s390x.rpm openSUSE-2025-273 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This security update to chromium 138.0.7204.168 boo#1246902 * CVE-2025-8010: Type Confusion in V8 * CVE-2025-8011: Type Confusion in V8 * Various fixes from internal audits, fuzzing and other initiatives chromedriver-138.0.7204.168-bp157.2.25.1.x86_64.rpm chromedriver-debuginfo-138.0.7204.168-bp157.2.25.1.x86_64.rpm chromium-138.0.7204.168-bp157.2.25.1.src.rpm chromium-138.0.7204.168-bp157.2.25.1.x86_64.rpm chromium-debuginfo-138.0.7204.168-bp157.2.25.1.x86_64.rpm chromedriver-138.0.7204.168-bp157.2.25.1.aarch64.rpm chromedriver-debuginfo-138.0.7204.168-bp157.2.25.1.aarch64.rpm chromium-138.0.7204.168-bp157.2.25.1.aarch64.rpm chromium-debuginfo-138.0.7204.168-bp157.2.25.1.aarch64.rpm openSUSE-2025-276 Recommended update for gitea-tea moderate openSUSE Backports SLE-15-SP7 Update This update for gitea-tea fixes the following issues: - Fix argument parsing. gitea-tea-0.10.1-bp157.2.6.1.src.rpm gitea-tea-0.10.1-bp157.2.6.1.x86_64.rpm gitea-tea-bash-completion-0.10.1-bp157.2.6.1.noarch.rpm gitea-tea-zsh-completion-0.10.1-bp157.2.6.1.noarch.rpm gitea-tea-0.10.1-bp157.2.6.1.i586.rpm gitea-tea-0.10.1-bp157.2.6.1.aarch64.rpm gitea-tea-0.10.1-bp157.2.6.1.ppc64le.rpm gitea-tea-0.10.1-bp157.2.6.1.s390x.rpm openSUSE-2025-277 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 138.0.7204.183 (boo#1247365): - CVE-2025-8292: Use after free in Media Stream chromedriver-138.0.7204.183-bp157.2.28.1.x86_64.rpm chromium-138.0.7204.183-bp157.2.28.1.src.rpm chromium-138.0.7204.183-bp157.2.28.1.x86_64.rpm chromedriver-138.0.7204.183-bp157.2.28.1.aarch64.rpm chromium-138.0.7204.183-bp157.2.28.1.aarch64.rpm openSUSE-2025-278 Recommended update for kmozillahelper important openSUSE Backports SLE-15-SP7 Update This update for kmozillahelper fixes the following issue: - Drop the requirement on mozilla-kde4-version. It's only provided by old versions of MozillaFirefox and MozillaThunderbird, which we don't want to pull in (boo#1247369) kmozillahelper-5.0.6-bp157.2.3.1.src.rpm kmozillahelper-5.0.6-bp157.2.3.1.x86_64.rpm kmozillahelper-5.0.6-bp157.2.3.1.i586.rpm kmozillahelper-5.0.6-bp157.2.3.1.aarch64.rpm kmozillahelper-5.0.6-bp157.2.3.1.ppc64le.rpm kmozillahelper-5.0.6-bp157.2.3.1.s390x.rpm openSUSE-2025-281 Recommended update for kanidm moderate openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: - Update to version 1.7.0~git0.621ac7be0: * Release 1.7.0 * Fix a couple of commands in the OAuth2 Proxy examples (#3758) - Update to version 1.7.0-pre~git0.7d9da9dc8: * Release 1.7.0-pre * 20250729 pre release (#3756) * Helps to enable features like defer spans (#3755) * Downgrade notify-debouncer (#3747) * Reduce memory usage on unixd (#3754) * Bump the all group with 4 updates (#3753) * 20250723 application passwords again (#3748) * Docs oauth2 examples (#3750) * Groups WebUI, modify description (#3734) * Improve replication logging (#3746) * 20250711 type migrations (#3741) * Bump the all group with 3 updates (#3743) * Use constants for /etc/shadow and related paths (#3740) * fix: don't show people's whole tokens in debugs (#3742) * Updates to makefile (#3736) * Add a new paragraph in the installation quickstart for installing required client tools, and clarify the client tool setup paragraph (#3735) * Bump the all group with 4 updates (#3737) * Add ppc64le support for docker images (#3733) * Basic interface to get and regenerate the RADIUS password (#3728) * book: fix command example in pam_and_nsswitch.md (#3732) * fix docgen (#3731) * Fix for Failed to deserialize query: missing field 'state' (#3726) * Add user facing SCIM pagination / sorting (#3725) * Admin UI Group name modification (#3717) * fix typo in documentation: tls_path to tls_key (#3727) * Pre-validate and extract UAT into ClientAuthInfo (#3714) * Security policy updates (re: #3719) (#3722) * Fix using wrong template when setting POSIX password (#3719) (#3720) * Resolve startup failure with client TLS certificates (#3712) * Bump the all group with 2 updates (#3718) * Simple group list (#3713) * Update repos (#3711) * 20250621 application passwords (#3700) * Update docs, doc fmt (#3710) * Apply review feedback * Correctly log connection information * Refactor middleware/extractors * [htmx] basic profile updating (#2994) * Correct 389DS command (#3707) * Schema again (#3706) * examples: small grammar fix (#3705) * Clippy (#3702) * 20250627 update hsm crypto (#3701) * Update 389 content sync instructions (#3699) * Corrections to radius examples (#3697) * fix: wording (#3696) * Update radius.md (Explain: NAS == Network Access Server) (#3691) * updating docs around packages (#3695) * 20250618 rustls (#3687) * fix: error message that wasn't an error (#3690) * Only generate passwords on service accounts (#3688) * Add hmac 256 for cryptography operations (#3663) * Update Nextcloud example (#3683) * Bump the all group with 8 updates (#3684) * Allow deferring spans in unixd (#3680) * OpenSUSE build fix (#3681) * Dark mode improvements (#3660) * Add port examples for server.toml (#3679) * Fix SCIM filter parser for quoted values with spaces and escaped quotes (#3673) * fix: strip comments from UNIX files before parsing (#3674) * Bump the all group across 1 directory with 11 updates (#3675) * Start to implement SCIM apis (#3535) * Fix healthcheck to use ENV for config path (#3656) * maint: rewrite crypto Password::try_from (#3637) * doc(book): Add option to Nextcloud Oauth2.0 example (#3654) * Bump the all group with 4 updates (#3655) * Make it clearer that the http address section is needed (#3652) * TODO trimming (#3641) * Investigate and reduce memory consumption of unixd (#3645) * Swap bytes mut at buffer limits (#3651) * Clippy for 1.87 (#3644) * fix: Improve unixd & unixd-tasks startup coupling (#3638) * Bump the all group with 2 updates (#3648) * reload schema before verify (#3643) * Defend against split_at panic (#3636) * Fix minor issue with untagged version handling (#3634) * Move shadow processing out of task event loop (#3631) * Dont specify config path in container (#3630) * Accept SSHA with different salt lengths (#3629) * Bye poetry, hi uv for python things (#3627) * Resolve flaw with ssh key parse if the key has no comment (#3628) * Indicate that this is an ip list, not a range (#3626) * Test for corrupted unicode in SSH keys, keep the key title on error/resubmit (#3618) * Reduce replication logging verbosity * Bump the all group across 1 directory with 7 updates (#3623) * Bump the all group in /pykanidm with 2 updates (#3621) * cargo publish (#3613) * fix: clippy * maint: typo in log message * Set kid manually to prevent divergence * Order keys in application JWKS / Fix rotation bug * Fix toml issues with strings * OAuth2 Client ID's should be processed as lowercase (#3605) * Resolve reload of oauth2 on startup (#3604) * Bump petgraph from 0.7.1 to 0.8.1 in the all group (#3595) * Bump the all group in /pykanidm with 2 updates (#3596) * Avoid openssl for md4 (#3594) * Fixes #3586, inverts the navbar button color (#3593) * Update to 1.7.0-dev (#3592) kanidm-1.7.0~git0.621ac7be0-bp157.2.6.1.src.rpm kanidm-1.7.0~git0.621ac7be0-bp157.2.6.1.x86_64.rpm kanidm-clients-1.7.0~git0.621ac7be0-bp157.2.6.1.x86_64.rpm kanidm-docs-1.7.0~git0.621ac7be0-bp157.2.6.1.x86_64.rpm kanidm-server-1.7.0~git0.621ac7be0-bp157.2.6.1.x86_64.rpm kanidm-unixd-clients-1.7.0~git0.621ac7be0-bp157.2.6.1.x86_64.rpm kanidm-1.7.0~git0.621ac7be0-bp157.2.6.1.aarch64.rpm kanidm-clients-1.7.0~git0.621ac7be0-bp157.2.6.1.aarch64.rpm kanidm-docs-1.7.0~git0.621ac7be0-bp157.2.6.1.aarch64.rpm kanidm-server-1.7.0~git0.621ac7be0-bp157.2.6.1.aarch64.rpm kanidm-unixd-clients-1.7.0~git0.621ac7be0-bp157.2.6.1.aarch64.rpm openSUSE-2025-282 Recommended update for exim moderate openSUSE Backports SLE-15-SP7 Update This update for exim fixes the following issues: Exim is shipped in release 4.98.2. exim-4.98.2-bp157.2.1.src.rpm exim-4.98.2-bp157.2.1.x86_64.rpm eximon-4.98.2-bp157.2.1.x86_64.rpm eximstats-html-4.98.2-bp157.2.1.x86_64.rpm exim-4.98.2-bp157.2.1.aarch64.rpm eximon-4.98.2-bp157.2.1.aarch64.rpm eximstats-html-4.98.2-bp157.2.1.aarch64.rpm exim-4.98.2-bp157.2.1.ppc64le.rpm eximon-4.98.2-bp157.2.1.ppc64le.rpm eximstats-html-4.98.2-bp157.2.1.ppc64le.rpm exim-4.98.2-bp157.2.1.s390x.rpm eximon-4.98.2-bp157.2.1.s390x.rpm eximstats-html-4.98.2-bp157.2.1.s390x.rpm openSUSE-2025-288 Security update for kubo moderate openSUSE Backports SLE-15-SP7 Update This update for kubo fixes the following issues: - 0.35.0 * Opt-in HTTP Retrieval client * Dedicated Reprovider.Strategy for MFS * Experimental support for MFS as a FUSE mount point * Grid view in WebUI * Enhanced DAG-Shaping Controls * Datastore Metrics Now Opt-In * Improved performance of data onboarding * Optimized, dedicated queue for providing fresh CIDs * New Provider configuration options * Deprecated ipfs stats provider * New Bitswap configuration options * Bitswap.Libp2pEnabled * Bitswap.ServerEnabled * Internal.Bitswap.ProviderSearchMaxResults * New Routing configuration options * Routing.IgnoreProviders * Routing.DelegatedRouters * New Pebble database format config * New environment variables * Improved Log Output Setting * New Repo Lock Optional Wait * Updated golang.org/x/net to 0.40.0 (boo#1241776, CVE-2025-22872) - Update to 0.34.1 - for details see * https://github.com/ipfs/kubo/releases/tag/v0.34.1 * Dependency updates - Update to 0.34.0 - for details see * https://github.com/ipfs/kubo/releases/tag/v0.34.0 * AutoTLS now enabled by default for nodes with 1 hour uptime * New WebUI features: CAR file import and QR code sharing * RPC and CLI command changes ~ ipfs config is now validating json fields ~ Deprecated the bitswap reprovide command ~ The stats reprovide command now shows additional stats ~ ipfs files cp now performs basic codec check * Bitswap improvements from Boxo * IPNS publishing TTL change ~ we've lowered the default IPNS Record TTL during publishing to 5 minutes * IPFS_LOG_LEVEL deprecated * Pebble datastore format update * Badger datastore update * Datastore Implementation Updates * Datastore Implementation Updates * Fix hanging pinset operations during reprovides * Important dependency updates - Update to 0.33.1 - for details see * https://github.com/ipfs/kubo/releases/tag/v0.33.1 * Bitswap improvements from Boxo * Improved IPNS interop - Update to 0.33.0 - for details see * https://github.com/ipfs/kubo/releases/tag/v0.33.0 * Shared TCP listeners: Kubo now supports sharing the same TCP port (4001 by default) by both raw TCP and WebSockets libp2p transports. * AutoTLS takes care of Secure WebSockets setup: It is no longer necessary to manually add /tcp/../ws listeners to Addresses.Swarm when AutoTLS.Enabled is set to true. Kubo will detect if /ws listener is missing and add one on the same port as pre-existing TCP (e.g. /tcp/4001), removing the need for any extra configuration. * Bitswap improvements from Boxo * Using default libp2p_rcmgr metrics: Bespoke rcmgr metrics were removed, Kubo now exposes only the default libp2p_rcmgr metrics from go-libp2p. * Flatfs does not sync on each write: New repositories initialized with flatfs in Datastore.Spec will have sync set to false. * ipfs add --to-files no longer works with --wrap * ipfs --api supports HTTPS RPC endpoints * New options for faster writes: WriteThrough, BlockKeyCacheSize, BatchMaxNodes, BatchMaxSize * MFS stability with large number of writes * New DoH resolvers for non-ICANN DNSLinks: .eth and .crypto * Reliability improvements to the WebRTC Direct listener * Fix: Escape Redirect URL for Directory kubo-0.35.0-bp157.2.3.1.src.rpm kubo-0.35.0-bp157.2.3.1.x86_64.rpm kubo-0.35.0-bp157.2.3.1.i586.rpm kubo-0.35.0-bp157.2.3.1.aarch64.rpm kubo-0.35.0-bp157.2.3.1.ppc64le.rpm kubo-0.35.0-bp157.2.3.1.s390x.rpm openSUSE-2025-286 Security update for chromium important openSUSE Backports SLE-15-SP7 Update Chromium was updated to fix: - CVE-2025-54874 fix missing error check in openjpeg (bsc#1247661) Chromium 139.0.7258.66 (boo#1247664): * CVE-2025-8576: Use after free in Extensions * CVE-2025-8577: Inappropriate implementation in Picture In Picture * CVE-2025-8578: Use after free in Cast * CVE-2025-8579: Inappropriate implementation in Gemini Live in Chrome * CVE-2025-8580: Inappropriate implementation in Filesystems * CVE-2025-8581: Inappropriate implementation in Extensions * CVE-2025-8582: Insufficient validation of untrusted input in DOM * CVE-2025-8583: Inappropriate implementation in Permissions chromedriver-139.0.7258.66-bp157.2.31.1.x86_64.rpm chromium-139.0.7258.66-bp157.2.31.1.src.rpm chromium-139.0.7258.66-bp157.2.31.1.x86_64.rpm chromedriver-139.0.7258.66-bp157.2.31.1.aarch64.rpm chromium-139.0.7258.66-bp157.2.31.1.aarch64.rpm openSUSE-2025-290 Recommended update for kanidm moderate openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: Update to version 1.7.1~git0.130a31d29: * Release 1.7.1 * Update tracing-forest * Handle SEC1 private key (#3761) kanidm-1.7.1~git0.130a31d29-bp157.2.9.1.src.rpm kanidm-1.7.1~git0.130a31d29-bp157.2.9.1.x86_64.rpm kanidm-clients-1.7.1~git0.130a31d29-bp157.2.9.1.x86_64.rpm kanidm-docs-1.7.1~git0.130a31d29-bp157.2.9.1.x86_64.rpm kanidm-server-1.7.1~git0.130a31d29-bp157.2.9.1.x86_64.rpm kanidm-unixd-clients-1.7.1~git0.130a31d29-bp157.2.9.1.x86_64.rpm kanidm-1.7.1~git0.130a31d29-bp157.2.9.1.aarch64.rpm kanidm-clients-1.7.1~git0.130a31d29-bp157.2.9.1.aarch64.rpm kanidm-docs-1.7.1~git0.130a31d29-bp157.2.9.1.aarch64.rpm kanidm-server-1.7.1~git0.130a31d29-bp157.2.9.1.aarch64.rpm kanidm-unixd-clients-1.7.1~git0.130a31d29-bp157.2.9.1.aarch64.rpm openSUSE-2025-294 Recommended update for python-CppHeaderParser moderate openSUSE Backports SLE-15-SP7 Update This update for python-CppHeaderParser fixes the following issues: - Initial version CppHeaderParser 2.7.4 (PED#13362, PED#13381). python-CppHeaderParser-2.7.4-bp157.2.1.src.rpm python3-CppHeaderParser-2.7.4-bp157.2.1.noarch.rpm openSUSE-2025-293 Recommended update for chromium moderate openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - install libffmpeg.so if using the bundled one and block the extra dependency chromedriver-139.0.7258.66-bp157.2.34.1.x86_64.rpm chromium-139.0.7258.66-bp157.2.34.1.src.rpm chromium-139.0.7258.66-bp157.2.34.1.x86_64.rpm chromedriver-139.0.7258.66-bp157.2.34.1.aarch64.rpm chromium-139.0.7258.66-bp157.2.34.1.aarch64.rpm openSUSE-2025-298 Recommended update for virtme moderate openSUSE Backports SLE-15-SP7 Update This update for virtme fixes the following issues: Update to 1.37: The most interesting feature in this new version is the initial support for systemd. Until now, virtme-ng didn't support systemd because it relied on a custom init system (virtme-ng-init) to speed up boot time. As a result, tests requiring systemd couldn't run inside the virtme-ng session. With the new --systemd option, virtme-ng can now (optionally) boot with systemd in the virtualized environment, enabling full systemd interaction during testing. virtme-1.37-bp157.2.6.1.noarch.rpm virtme-1.37-bp157.2.6.1.src.rpm openSUSE-2025-301 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 139.0.7258.127 (boo#1247981): * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker * CVE-2025-8882: Use after free in Aura * Various fixes from internal audits, fuzzing and other initiatives chromedriver-139.0.7258.127-bp157.2.37.1.x86_64.rpm chromedriver-debuginfo-139.0.7258.127-bp157.2.37.1.x86_64.rpm chromium-139.0.7258.127-bp157.2.37.1.src.rpm chromium-139.0.7258.127-bp157.2.37.1.x86_64.rpm chromium-debuginfo-139.0.7258.127-bp157.2.37.1.x86_64.rpm chromedriver-139.0.7258.127-bp157.2.37.1.aarch64.rpm chromedriver-debuginfo-139.0.7258.127-bp157.2.37.1.aarch64.rpm chromium-139.0.7258.127-bp157.2.37.1.aarch64.rpm chromium-debuginfo-139.0.7258.127-bp157.2.37.1.aarch64.rpm chromedriver-139.0.7258.127-bp157.2.37.1.ppc64le.rpm chromedriver-debuginfo-139.0.7258.127-bp157.2.37.1.ppc64le.rpm chromium-139.0.7258.127-bp157.2.37.1.ppc64le.rpm chromium-debuginfo-139.0.7258.127-bp157.2.37.1.ppc64le.rpm openSUSE-2025-306 Recommended update for kanidm moderate openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: Update to version 1.7.2~git0.d331ea986: * Release 1.7.2 * Resolve replication show-cert issue (#3792) * Add json codec wrapper for unix integration (#3789) * Trying to clean up order of operations in kanidm_unixd_tasks (#3762) * Break-glass account disable command (#3780) * Make it clearer why the user can't login with unixd (#3778) * Improve argon2id parameter search speed (#3768) kanidm-1.7.2~git0.d331ea986-bp157.2.12.1.src.rpm kanidm-1.7.2~git0.d331ea986-bp157.2.12.1.x86_64.rpm kanidm-clients-1.7.2~git0.d331ea986-bp157.2.12.1.x86_64.rpm kanidm-docs-1.7.2~git0.d331ea986-bp157.2.12.1.x86_64.rpm kanidm-server-1.7.2~git0.d331ea986-bp157.2.12.1.x86_64.rpm kanidm-unixd-clients-1.7.2~git0.d331ea986-bp157.2.12.1.x86_64.rpm kanidm-1.7.2~git0.d331ea986-bp157.2.12.1.aarch64.rpm kanidm-clients-1.7.2~git0.d331ea986-bp157.2.12.1.aarch64.rpm kanidm-docs-1.7.2~git0.d331ea986-bp157.2.12.1.aarch64.rpm kanidm-server-1.7.2~git0.d331ea986-bp157.2.12.1.aarch64.rpm kanidm-unixd-clients-1.7.2~git0.d331ea986-bp157.2.12.1.aarch64.rpm openSUSE-2025-307 Recommended update for gh moderate openSUSE Backports SLE-15-SP7 Update This update for gh fixes the following issues: - Update to version 2.76.2: * Refactor tab completion test * Test `gh pr create --reviewer` tab completion * Include org teams for PR reviewers * docs(ci): delete obsolete comment - Update to version 2.76.1: * Updated third-party license compliance content * Add tests for reviewer team handling in PR creation * Refactor and improve RepoMetadata teams test * Refactor error assertion in Test_RepoMetadataTeams * FIX: conditionally fetching team reviewers * Add TeamReviewers flag to RepoMetadataInput * Update .github/workflows/scripts/spam-detection/generate-sys-prompt.sh * Use gh go templating for user prompt * Update eval script comments * Remove unnecessary file for heredoc * First pass to optimize and improve * Limit permissions of govulncheck workflow * Incorporate govulncheck into workflows * update ownership of pkg/cmd/release/shared/ * Run Lint and Tests on `push` to `trunk` branch * ci: echo spam detection result * ci: add `models: read` permission * ci: correct `sed` usage to remove Markdown front matter * docs: fix typo in script docs * ci: fix potentially confusing typo in system prompt * ci: use `issue.html_url` instead of `issue.url` * ci: remove unused env vars * ci: add spam issue detection workflow * ci: add spam issue detection scripts * chore(deps): bump github.com/sigstore/sigstore-go from 1.0.0 to 1.1.0 * chore(deps): bump advanced-security/filter-sarif from 1.0.0 to 1.0.1 * Improve `api` `--preview` docs * add tenancy aware for san matcher - Update to version 2.76.0: * Copilot Pro+ / Enterprise subscribers can now assign issues to Copilot during issue creation * Display immutable field in release view command * Do not fetch logs for skipped jobs * Transform extension and filename qualifiers into path qualifier for web code search - Update to version 2.75.0: * Quote Windows rsyso script global hook * test(search): verify `URL` returns quoted query * test(search): test pagination with multi-word quoted queries * fix(search): fix mutating query state fields * Add setup-go to bump-go * Update contribution design link * test(pr merge): always assert stderr * test(pr merge): verify `deleteRemoteBranch` behaviour when API returns error * fix(pr merge): ignore 404 as error when deleting remote branch * Ensure go mod tidy is run in bump-go * Inject token into bump-go workflow * Reformat gh run view help * docs(run view): explain restrictions of fallback API calls * test(run view): delete unused ZIP archive * refactor(run view): remove `Log` field from DTO types * test(run view): update tests * refactor(run view): use API as fallback to fetch job logs * test: add `BinaryResponse` helper function * Ensure bump go script has git user configured * Support --no-repos-selected on secret set * docs: consistently use apt in installation instructions * Consume dependabot minor versions for go modules * test: add test for `ParseURL` * Update microsoft dev-tunnels to v0.1.13 * Bump all dependencies except dev-tunnels * Fix inconsistent use of tabs and spaces * docs: explain PR URL parsing reason * test: improve test case to highlight host name override * test: remove references to `AssignedActorsUsed` field * test: verify providing a URL arg affects the base repo * refactor: select PR fields based on detected features * test: remove tests verifying assigne-related behaviour * fix: remove assignee-related intervention * fix: remove `AssignedActorsUsed` field * Add workflow to automate go version bumping * fix: expose `ParseURL` as a public func * Remove unused GH_TOKEN env variable from workflow * Add `workflow_dispatch` support to PR Help Wanted check (#11179) * chore: improve error message when `versioninfo.json` is not found * Fix: `gh pr create` prioritize `--title` and `--body` over `--fill` when `--web` is present (#10547) * chore: create `.syso` libs only on Windows * chore: delete `script/winres.json` * chore: add `versioninfo.template.json` * refactor: switch to `github.com/josephspurrier/goversioninfo` * chore: exclude generated `.syso` files from git repo * Ensure automation uses pinned go-licenses version * Fix missing newline in install_linux.md * Apply suggestions from code review * Update missed Go 1.23 references * chore: update Go version to 1.24 in devcontainer configuration * Use `make` for license generation and checks * Use temp directory for license checks * Update 3rd party licenses * Restored original test setup, clarified * Enhance Activetoken prioritize test * improve the description for gh release verify cmd * chore: fix function name * Push up * Use active token stubbing on auth config * refactor to simplify implementation * Primer formatting * Fix spacing * Add missing files * Rename READMEs * Initial restore of Primer CLI docs * use standardize color roles logic for the logging * moved to shared lib * moved to shared lib * update the artifact and bundle for testing * empty commit * clean the code * revert the workflow * debug windows env * debug windows env * debug windows env * chore: fix variable name casing * Avoid analyzing 3rd party license content with CodeQL * chore: ensure output path is a directory * clean the path * clean the path * Update 3rd party license information * Adopt license compliance scripts into workflows, docs * clean the path * improve test * fix test * add unit test * chore: prepare Windows resources `.syso` files before build * chore: add script to create Windows resources * Cleanup * fix: get token for active user instead of blank if possible * remove filepath test * update Sprintf * removed unused file * added the unit test * add json format * change verify-asset logic * minor fix * clean up the code * update the lng * wip * remove comment * wip * init * docs: install_linux.md: add Solus linux install instructions gh-2.76.2-bp157.2.6.1.src.rpm gh-2.76.2-bp157.2.6.1.x86_64.rpm gh-bash-completion-2.76.2-bp157.2.6.1.noarch.rpm gh-fish-completion-2.76.2-bp157.2.6.1.noarch.rpm gh-zsh-completion-2.76.2-bp157.2.6.1.noarch.rpm gh-2.76.2-bp157.2.6.1.i586.rpm gh-2.76.2-bp157.2.6.1.aarch64.rpm gh-2.76.2-bp157.2.6.1.ppc64le.rpm gh-2.76.2-bp157.2.6.1.s390x.rpm openSUSE-2025-302 Security update for trivy important openSUSE Backports SLE-15-SP7 Update This update for trivy fixes the following issues: - CVE-2025-53547: Fixed code execution in Helm Chart (boo#1246151) - Update to version 0.64.1: * release: v0.64.1 [release/v0.64] (#9122) * fix(misconf): skip rewriting expr if attr is nil [backport: release/v0.64] (#9127) * fix(cli): Add more non-sensitive flags to telemetry [backport: release/v0.64] (#9124) * fix(rootio): check full version to detect `root.io` packages [backport: release/v0.64] (#9120) * fix(alma): parse epochs from rpmqa file [backport: release/v0.64] (#9119) * release: v0.64.0 [main] (#8955) * docs(python): fix type with METADATA file name (#9090) * feat: reject unsupported artifact types in remote image retrieval (#9052) * chore(deps): bump github.com/go-viper/mapstructure/v2 from 2.2.1 to 2.3.0 (#9088) * refactor(misconf): rewrite Rego module filtering using functional filters (#9061) * feat(terraform): add partial evaluation for policy templates (#8967) * feat(vuln): add Root.io support for container image scanning (#9073) * feat(sbom): add manufacturer field to CycloneDX tools metadata (#9019) * fix(cli): add some values to the telemetry call (#9056) * feat(ubuntu): add end of life date for Ubuntu 25.04 (#9077) * refactor: centralize HTTP transport configuration (#9058) * test: include integration tests in linting and fix all issues (#9060) * chore(deps): bump the common group across 1 directory with 26 updates (#9063) * feat(java): dereference all maven settings.xml env placeholders (#9024) * fix(misconf): reduce log noise on incompatible check (#9029) * fix(misconf): .Config.User always takes precedence over USER in .History (#9050) * chore(deps): update Docker to v28.2.2 and fix compatibility issues (#9037) * docs(misconf): simplify misconfiguration docs (#9030) * fix(misconf): move disabled checks filtering after analyzer scan (#9002) * docs: add PR review policy for maintainers (#9032) * fix(sbom): remove unnecessary OS detection check in SBOM decoding (#9034) * test: improve and extend tests for iac/adapters/arm (#9028) * chore: bump up Go version to 1.24.4 (#9031) * feat(cli): add version constraints to annoucements (#9023) * fix(misconf): correct Azure value-to-time conversion in AsTimeValue (#9015) * feat(ubuntu): add eol date for 20.04-ESM (#8981) * fix(report): don't panic when report contains vulns, but doesn't contain packages for `table` format (#8549) * fix(nodejs): correctly parse `packages` array of `bun.lock` file (#8998) * refactor: use strings.SplitSeq instead of strings.Split in for-loop (#8983) * docs: change --disable-metrics to --disable-telemetry in example (#8999) (#9003) * feat(misconf): add OpenTofu file extension support (#8747) * refactor(misconf): set Trivy version by default in Rego scanner (#9001) * docs: fix assets with versioning (#8996) * docs: add partners page (#8988) * chore(alpine): add EOL date for Alpine 3.22 (#8992) * fix: don't show corrupted trivy-db warning for first run (#8991) * Update installation.md (#8979) * feat(misconf): normalize CreatedBy for buildah and legacy docker builder (#8953) * chore(k8s): update comments with deprecated command format (#8964) * chore: fix errors and typos in docs (#8963) * fix: Add missing version check flags (#8951) * feat(redhat): Add EOL date for RHEL 10. (#8910) * fix: Correctly check for semver versions for trivy version check (#8948) * refactor(server): change custom advisory and vulnerability data types fr… (#8923) * ci(helm): bump Trivy version to 0.63.0 for Trivy Helm Chart 0.15.0 (#8946) * release: v0.63.0 [main] (#8809) * fix(misconf): use argument value in WithIncludeDeprecatedChecks (#8942) * chore(deps): Bump trivy-checks (#8934) * fix(julia): add `Relationship` field support (#8939) * feat(minimos): Add support for MinimOS (#8792) * feat(alpine): add maintainer field extraction for APK packages (#8930) * feat(echo): Add Echo Support (#8833) * fix(redhat): Also try to find buildinfo in root layer (layer 0) (#8924) * fix(wolfi): support new APK database location (#8937) * feat(k8s): get components from namespaced resources (#8918) * refactor(cloudformation): remove unused ScanFile method from Scanner (#8927) * refactor(terraform): remove result sorting from scanner (#8928) * feat(misconf): Add support for `Minimum Trivy Version` (#8880) * docs: improve skipping files documentation (#8749) * feat(cli): Add available version checking (#8553) * feat(nodejs): add a bun.lock analyzer (#8897) * feat: terraform parser option to set current working directory (#8909) * perf(secret): only match secrets of meaningful length, allow example strings to not be matched (#8602) * feat(misconf): export raw Terraform data to Rego (#8741) * refactor(terraform): simplify AllReferences method signature in Attribute (#8906) * fix: check post-analyzers for StaticPaths (#8904) * feat: add Bottlerocket OS package analyzer (#8653) * feat(license): improve work text licenses with custom classification (#8888) * chore(deps): bump github.com/containerd/containerd/v2 from 2.1.0 to 2.1.1 (#8901) * chore(deps): bump the common group across 1 directory with 9 updates (#8887) * refactor(license): simplify compound license scanning (#8896) * feat(license): Support compound licenses (licenses using SPDX operators) (#8816) * fix(k8s): use in-memory cache backend during misconfig scanning (#8873) * feat(nodejs): add bun.lock parser (#8851) * feat(license): improve work with custom classification of licenses from config file (#8861) * fix(cli): disable `--skip-dir` and `--skip-files` flags for `sbom` command (#8886) * fix: julia parser panicing (#8883) * refactor(db): change logic to detect wrong DB (#8864) * fix(cli): don't use allow values for `--compliance` flag (#8881) * docs(misconf): Reorganize misconfiguration scan pages (#8206) * fix(server): add missed Relationship field for `rpc` (#8872) * feat: add JSONC support for comments and trailing commas (#8862) * fix(vex): use `lo.IsNil` to check `VEX` from OCI artifact (#8858) * feat(go): support license scanning in both GOPATH and vendor (#8843) * fix(redhat): save contentSets for OS packages in fs/vm modes (#8820) * fix: filter all files when processing files installed from package managers (#8842) * feat(misconf): add misconfiguration location to junit template (#8793) * docs(vuln): remove OSV for Python from data sources (#8841) * chore: add an issue template for maintainers (#8838) * chore: enable staticcheck (#8815) * ci(helm): bump Trivy version to 0.62.1 for Trivy Helm Chart 0.14.1 (#8836) * feat(license): scan vendor directory for license for go.mod files (#8689) * docs(java): Update info about dev deps in gradle lock (#8830) * chore(deps): bump golang.org/x/sync from 0.13.0 to 0.14.0 in the common group (#8822) * fix(java): exclude dev dependencies in gradle lockfile (#8803) * fix: octalLiteral from go-critic (#8811) * fix(redhat): trim invalid suffix from content_sets in manifest parsing (#8818) * chore(deps): bump the common group across 1 directory with 10 updates (#8817) * fix: use-any from revive (#8810) * fix: more revive rules (#8814) * docs: change in java.md: fix the Trity -to-> Trivy typo (#8813) * fix(misconf): check if for-each is known when expanding dyn block (#8808) * ci(helm): bump Trivy version to 0.62.0 for Trivy Helm Chart 0.14.0 (#8802) - Update to version 0.62.1: * release: v0.62.1 [release/v0.62] (#8825) * chore(deps): bump the common group across 1 directory with 10 updates [backport: release/v0.62] (#8831) * fix(misconf): check if for-each is known when expanding dyn block [backport: release/v0.62] (#8826) * fix(redhat): trim invalid suffix from content_sets in manifest parsing [backport: release/v0.62] (#8824) * release: v0.62.0 [main] (#8669) * feat(nodejs): add root and workspace for `yarn` packages (#8535) * fix: unused-parameter rule from revive (#8794) * chore(deps): Update trivy-checks (#8798) * fix: early-return, indent-error-flow and superfluous-else rules from revive (#8796) * fix(k8s): remove using `last-applied-configuration` (#8791) * refactor(misconf): remove unused methods from providers (#8781) * refactor(misconf): remove unused methods from iac types (#8782) * fix(misconf): filter null nodes when parsing json manifest (#8785) * fix: testifylint last issues (#8768) * fix(misconf): perform operations on attribute safely (#8774) * refactor(ubuntu): update time handling for fixing time (#8780) * chore(deps): bump golangci-lint to v2.1.2 (#8766) * feat(image): save layers metadata into report (#8394) * feat(misconf): convert AWS managed policy to document (#8757) * chore(deps): bump the docker group across 1 directory with 3 updates (#8762) * ci(helm): bump Trivy version to 0.61.1 for Trivy Helm Chart 0.13.1 (#8753) * ci(helm): create a helm branch for patches from main (#8673) * fix(terraform): hcl object expressions to return references (#8271) * chore(terraform): option to pass in instanced logger (#8738) * ci: use `Skitionek/notify-microsoft-teams` instead of `aquasecurity` fork (#8740) * chore(terraform): remove os.OpenPath call from terraform file functions (#8737) * chore(deps): bump the common group across 1 directory with 23 updates (#8733) * feat(rust): add root and workspace relationships/package for `cargo` lock files (#8676) * refactor(misconf): remove module outputs from parser.EvaluateAll (#8587) * fix(misconf): populate context correctly for module instances (#8656) * fix(misconf): check if metadata is not nil (#8647) * refactor(misconf): switch to x/json (#8719) * fix(report): clean buffer after flushing (#8725) * ci: improve PR title validation workflow (#8720) * refactor(flag): improve flag system architecture and extensibility (#8718) * fix(terraform): `evaluateStep` to correctly set `EvalContext` for multiple instances of blocks (#8555) * refactor: migrate from `github.com/aquasecurity/jfather` to `github.com/go-json-experiment/json` (#8591) * feat(misconf): support auto_provisioning_defaults in google_container_cluster (#8705) * ci: use `github.event.pull_request.user.login` for release PR check workflow (#8702) * refactor: add hook interface for extended functionality (#8585) * fix(misconf): add missing variable as unknown (#8683) * docs: Update maintainer docs (#8674) * ci(vuln): reduce github action script injection attack risk (#8610) * fix(secret): ignore .dist-info directories during secret scanning (#8646) * fix(server): fix redis key when trying to delete blob (#8649) * chore(deps): bump the testcontainers group with 2 updates (#8650) * test: use `aquasecurity` repository for test images (#8677) * chore(deps): bump the aws group across 1 directory with 5 updates (#8652) * fix(k8s): skip passed misconfigs for the summary report (#8684) * fix(k8s): correct compare artifact versions (#8682) * chore: update Docker lib (#8681) * refactor(misconf): remove unused terraform attribute methods (#8657) * feat(misconf): add option to pass Rego scanner to IaC scanner (#8369) * chore: typo fix to replace `rego` with `repo` on the RepoFlagGroup options error output (#8643) * docs: Add info about helm charts release (#8640) * ci(helm): bump Trivy version to 0.61.0 for Trivy Helm Chart 0.13.0 (#8638) - Update to version 0.61.1: * release: v0.61.1 [release/v0.61] (#8704) * fix(k8s): skip passed misconfigs for the summary report [backport: release/v0.61] (#8748) * fix(k8s): correct compare artifact versions [backport: release/v0.61] (#8699) * test: use `aquasecurity` repository for test images [backport: release/v0.61] (#8698) * release: v0.61.0 [main] (#8507) * fix(misconf): Improve logging for unsupported checks (#8634) * feat(k8s): add support for controllers (#8614) * fix(debian): don't include empty licenses for `dpkgs` (#8623) * fix(misconf): Check values wholly prior to evalution (#8604) * chore(deps): Bump trivy-checks (#8619) * fix(k8s): show report for `--report all` (#8613) * chore(deps): bump github.com/golang-jwt/jwt/v4 from 4.5.1 to 4.5.2 (#8597) * refactor: rename scanner to service (#8584) * fix(misconf): do not skip loading documents from subdirectories (#8526) * refactor(misconf): get a block or attribute without calling HasChild (#8586) * fix(misconf): identify the chart file exactly by name (#8590) * test: use table-driven tests in Helm scanner tests (#8592) * refactor(misconf): Simplify misconfig checks bundle parsing (#8533) * chore(deps): bump the common group across 1 directory with 10 updates (#8566) * fix(misconf): do not use cty.NilVal for non-nil values (#8567) * docs(cli): improve flag value display format (#8560) * fix(misconf): set default values for AWS::EKS::Cluster.ResourcesVpcConfig (#8548) * docs: remove slack (#8565) * fix: use `--file-patterns` flag for all post analyzers (#7365) * docs(python): Mention pip-compile (#8484) * feat(misconf): adapt aws_opensearch_domain (#8550) * feat(misconf): adapt AWS::EC2::VPC (#8534) * docs: fix a broken link (#8546) * fix(fs): check postAnalyzers for StaticPaths (#8543) * refactor(misconf): remove unused methods for ec2.Instance (#8536) * feat(misconf): adapt aws_default_security_group (#8538) * feat(fs): optimize scanning performance by direct file access for known paths (#8525) * feat(misconf): adapt AWS::DynamoDB::Table (#8529) * style: Fix MD syntax in self-hosting.md (#8523) * perf(misconf): retrieve check metadata from annotations once (#8478) * feat(misconf): Add support for aws_ami (#8499) * fix(misconf): skip Azure CreateUiDefinition (#8503) * refactor(misconf): use OPA v1 (#8518) * fix(misconf): add ephemeral block type to config schema (#8513) * perf(misconf): parse input for Rego once (#8483) * feat: replace TinyGo with standard Go for WebAssembly modules (#8496) * chore: replace deprecated tenv linter with usetesting (#8504) * fix(spdx): save text licenses into `otherLicenses` without normalize (#8502) * chore(deps): bump the common group across 1 directory with 13 updates (#8491) * chore: use go.mod for managing Go tools (#8493) * ci(helm): bump Trivy version to 0.60.0 for Trivy Helm Chart 0.12.0 (#8494) * release: v0.60.0 [main] (#8327) * fix(sbom): improve logic for binding direct dependency to parent component (#8489) * chore(deps): remove missed replace of `trivy-db` (#8492) * chore(deps): bump alpine from 3.21.0 to 3.21.3 in the docker group across 1 directory (#8490) * chore(deps): update Go to 1.24 and switch to go-version-file (#8388) * docs: add abbreviation list (#8453) * chore(terraform): assign *terraform.Module 'parent' field (#8444) * feat: add report summary table (#8177) * chore(deps): bump the github-actions group with 3 updates (#8473) * refactor(vex): improve SBOM reference handling with project standards (#8457) * ci: update GitHub Actions cache to v4 (#8475) * feat: add `--vuln-severity-source` flag (#8269) * fix(os): add mapping OS aliases (#8466) * chore(deps): bump the aws group across 1 directory with 7 updates (#8468) * chore(deps): Bump trivy-checks to v1.7.1 (#8467) * refactor(report): write tables after rendering all results (#8357) * docs: update VEX documentation index page (#8458) * fix(db): fix case when 2 trivy-db were copied at the same time (#8452) * feat(misconf): render causes for Terraform (#8360) * fix(misconf): fix incorrect k8s locations due to JSON to YAML conversion (#8073) * feat(cyclonedx): Add initial support for loading external VEX files from SBOM references (#8254) * chore(deps): update go-rustaudit location (#8450) * fix: update all documentation links (#8045) * chore(deps): bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 (#8443) * chore(deps): bump the common group with 6 updates (#8411) * fix(k8s): add missed option `PkgRelationships` (#8442) * fix(sbom): add SBOM file's filePath as Application FilePath if we can't detect its path (#8346) * feat(go): fix parsing main module version for go >= 1.24 (#8433) * refactor(misconf): make Rego scanner independent of config type (#7517) * fix(image): disable AVD-DS-0007 for history scanning (#8366) * fix(server): secrets inspectation for the config analyzer in client server mode (#8418) * chore: remove mockery (#8417) * test(server): replace mock driver with memory cache in server tests (#8416) * test: replace mock with memory cache and fix non-deterministic tests (#8410) * test: replace mock with memory cache in scanner tests (#8413) * test: use memory cache (#8403) * fix(spdx): init `pkgFilePaths` map for all formats (#8380) * chore(deps): bump the common group across 1 directory with 11 updates (#8381) * docs: correct Ruby documentation (#8402) * chore: bump `mockery` to update v2.52.2 version and rebuild mock files (#8390) * fix: don't use `scope` for `trivy registry login` command (#8393) * fix(go): merge nested flags into string for ldflags for Go binaries (#8368) * chore(terraform): export module path on terraform modules (#8374) * fix(terraform): apply parser options to submodule parsing (#8377) * docs: Fix typos in documentation (#8361) * docs: fix navigate links (#8336) * ci(helm): bump Trivy version to 0.59.1 for Trivy Helm Chart 0.11.1 (#8354) * ci(spdx): add `aqua-installer` step to fix `mage` error (#8353) * chore: remove debug prints (#8347) * fix(misconf): do not log scanners when misconfig scanning is disabled (#8345) * fix(report): remove html escaping for `shortDescription` and `fullDescription` fields for sarif reports (#8344) * chore(deps): bump Go to `v1.23.5` (#8341) * fix(python): add `poetry` v2 support (#8323) * chore(deps): bump the github-actions group across 1 directory with 4 updates (#8331) * fix(misconf): ecs include enhanced for container insights (#8326) * fix(sbom): preserve OS packages from multiple SBOMs (#8325) * ci(helm): bump Trivy version to 0.59.0 for Trivy Helm Chart 0.11.0 (#8311) trivy-0.64.1-bp157.2.3.1.src.rpm trivy-0.64.1-bp157.2.3.1.x86_64.rpm trivy-0.64.1-bp157.2.3.1.i586.rpm trivy-0.64.1-bp157.2.3.1.aarch64.rpm trivy-0.64.1-bp157.2.3.1.ppc64le.rpm trivy-0.64.1-bp157.2.3.1.s390x.rpm openSUSE-2025-313 Recommended update for fuc moderate openSUSE Backports SLE-15-SP7 Update This update for fuc fixes the following issues: - Update to version 3.1.1: * fix recursive copy detection for multiple directories * Upgrade deps - Update to version 3.1.0: * Support hard linking files in cpz! * Fixed bugs with --force and symlinks. * Upgrade deps - Update to version 3.0.1: * dependency bumps, including Rustix1.0 - Update to version 3.0.0: * Upgrade deps * Fix bug when trying to copy "." into a directory * Eliminate pointless statx when removing files with unknown d_type * requires Rust 2024 edition * Remove extra mkdir (push that responsibility outside the library so we don't have a ton of redundant mkdirs) * Avoid pointless copy_file_range calls that we know won't copy anything * Remember cross-device copy failures per directory * Swap binary name and arch for better sorting * Add docs on progress indicator - Update to version 2.2.0: * Stable rust patch * Upgrade deps * Add -L / --dereference option (#36) * Add NO_UNSHARE envvar support to avoid calling unshare for default docker configs which block the syscall (closes #34) * Use official cache-size version * Use my own cache-size dep to fix the build * Remove cargo warning about "no edition set" * Clarify what rmz/cpz are - Update to version 2.1.0: * Stable rust patch * Upgrade FTZZ * Add progress feature (closes #14) * Upgrade deps * Remove release_max_level_off since tracing is completely compiled out by default anyway * Add tip for merging directories * Integrate tracing - Update to version 2.0.0: * Improved handling of deeply nested folders and other IO errors * Never follow symlinks for deletion - Update to version 1.1.9: * Upgrade deps * Don't show stack traces in errors * Tweak copy error message slightly * Use better pattern matching * Fix inconsistent badge sytling * Support flipping cpz argument order * Slight efficiency improvement (at the expense of throughput in hopefully rare cases) * Update README.md fuc-3.1.1-bp157.2.3.1.src.rpm fuc-3.1.1-bp157.2.3.1.x86_64.rpm fuc-3.1.1-bp157.2.3.1.aarch64.rpm openSUSE-2025-304 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 139.0.7258.138 (boo#1248315): * CVE-2025-9132: Out of bounds write in V8 chromedriver-139.0.7258.138-bp157.2.40.1.x86_64.rpm chromium-139.0.7258.138-bp157.2.40.1.src.rpm chromium-139.0.7258.138-bp157.2.40.1.x86_64.rpm chromedriver-139.0.7258.138-bp157.2.40.1.aarch64.rpm chromium-139.0.7258.138-bp157.2.40.1.aarch64.rpm chromedriver-139.0.7258.138-bp157.2.40.1.ppc64le.rpm chromium-139.0.7258.138-bp157.2.40.1.ppc64le.rpm openSUSE-2025-321 Security update for rpi-imager moderate openSUSE Backports SLE-15-SP7 Update This update for rpi-imager fixes the following issues: - Turned off dependency vendoring, to get security fixes for libarchive and others. Includes a fix for CVE-2025-5916 (boo#1244387) rpi-imager-1.7.5-bp157.2.3.1.src.rpm rpi-imager-1.7.5-bp157.2.3.1.x86_64.rpm rpi-imager-1.7.5-bp157.2.3.1.i586.rpm rpi-imager-1.7.5-bp157.2.3.1.aarch64.rpm rpi-imager-1.7.5-bp157.2.3.1.ppc64le.rpm openSUSE-2025-315 Security update for proftpd important openSUSE Backports SLE-15-SP7 Update This update for proftpd fixes the following issues: - CVE-2024-57392: Null pointer dereference vulnerability by sending a maliciously crafted message (boo#1236889). - CVE-2024-48651: Supplemental group inheritance grants unintended access to GID 0 (boo#1233997). proftpd-1.3.8d-bp157.2.3.1.src.rpm proftpd-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-debuginfo-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-debugsource-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-devel-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-doc-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-lang-1.3.8d-bp157.2.3.1.noarch.rpm proftpd-ldap-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-ldap-debuginfo-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-mysql-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-mysql-debuginfo-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-pgsql-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-pgsql-debuginfo-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-radius-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-radius-debuginfo-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-sqlite-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-sqlite-debuginfo-1.3.8d-bp157.2.3.1.x86_64.rpm proftpd-1.3.8d-bp157.2.3.1.i586.rpm proftpd-debuginfo-1.3.8d-bp157.2.3.1.i586.rpm proftpd-debugsource-1.3.8d-bp157.2.3.1.i586.rpm proftpd-devel-1.3.8d-bp157.2.3.1.i586.rpm proftpd-doc-1.3.8d-bp157.2.3.1.i586.rpm proftpd-ldap-1.3.8d-bp157.2.3.1.i586.rpm proftpd-ldap-debuginfo-1.3.8d-bp157.2.3.1.i586.rpm proftpd-mysql-1.3.8d-bp157.2.3.1.i586.rpm proftpd-mysql-debuginfo-1.3.8d-bp157.2.3.1.i586.rpm proftpd-pgsql-1.3.8d-bp157.2.3.1.i586.rpm proftpd-pgsql-debuginfo-1.3.8d-bp157.2.3.1.i586.rpm proftpd-radius-1.3.8d-bp157.2.3.1.i586.rpm proftpd-radius-debuginfo-1.3.8d-bp157.2.3.1.i586.rpm proftpd-sqlite-1.3.8d-bp157.2.3.1.i586.rpm proftpd-sqlite-debuginfo-1.3.8d-bp157.2.3.1.i586.rpm proftpd-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-debuginfo-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-debugsource-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-devel-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-doc-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-ldap-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-ldap-debuginfo-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-mysql-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-mysql-debuginfo-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-pgsql-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-pgsql-debuginfo-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-radius-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-radius-debuginfo-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-sqlite-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-sqlite-debuginfo-1.3.8d-bp157.2.3.1.aarch64.rpm proftpd-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-debuginfo-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-debugsource-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-devel-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-doc-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-ldap-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-ldap-debuginfo-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-mysql-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-mysql-debuginfo-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-pgsql-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-pgsql-debuginfo-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-radius-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-radius-debuginfo-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-sqlite-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-sqlite-debuginfo-1.3.8d-bp157.2.3.1.ppc64le.rpm proftpd-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-debuginfo-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-debugsource-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-devel-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-doc-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-ldap-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-ldap-debuginfo-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-mysql-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-mysql-debuginfo-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-pgsql-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-pgsql-debuginfo-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-radius-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-radius-debuginfo-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-sqlite-1.3.8d-bp157.2.3.1.s390x.rpm proftpd-sqlite-debuginfo-1.3.8d-bp157.2.3.1.s390x.rpm openSUSE-2025-328 Recommended update for kanidm moderate openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: Update to version 1.7.3~git0.10847190e: * Release 1.7.3 * Make it clearer why acceptor isnt available (#3812) * Minor: reduce logging verbosity during debug (#3810) * Handle IP addresses in replication SAN field (#3811) * Update to use the codec properly (#3807) kanidm-1.7.3~git0.10847190e-bp157.2.15.1.src.rpm kanidm-1.7.3~git0.10847190e-bp157.2.15.1.x86_64.rpm kanidm-clients-1.7.3~git0.10847190e-bp157.2.15.1.x86_64.rpm kanidm-docs-1.7.3~git0.10847190e-bp157.2.15.1.x86_64.rpm kanidm-server-1.7.3~git0.10847190e-bp157.2.15.1.x86_64.rpm kanidm-unixd-clients-1.7.3~git0.10847190e-bp157.2.15.1.x86_64.rpm kanidm-1.7.3~git0.10847190e-bp157.2.15.1.aarch64.rpm kanidm-clients-1.7.3~git0.10847190e-bp157.2.15.1.aarch64.rpm kanidm-docs-1.7.3~git0.10847190e-bp157.2.15.1.aarch64.rpm kanidm-server-1.7.3~git0.10847190e-bp157.2.15.1.aarch64.rpm kanidm-unixd-clients-1.7.3~git0.10847190e-bp157.2.15.1.aarch64.rpm openSUSE-2025-317 Security update for minikube important openSUSE Backports SLE-15-SP7 Update This update for minikube fixes the following issues: - Update to version 1.36.0: * Features - Support Kubernetes version v1.33.1 #20784 - New flag "-f" to allow passing a config file for addon configure command. #20255 - vfkit: bump to Preferred driver on macOs #20808 - vfkit: new network option "--network vment-shared' for vfkit driver #20501 * Bug Fixes: - fix bootpd check on macOS >= 15 #20400 - fix bug in parsing proxies with dashes #20648 - fix waiting for all pods having specified labels to be Ready #20315 - fix: incorrect finalImg affecting downloading kic form github assets #20316 - fix: reference missing files in schema (Closes #20752) #20761 - Improvements: - Additional checks for 9p support #20288 - vfkit: Graceful shutdown on stop #20504 - vfkit: More robust state management #20506 - vfkit vmnet: support running without sudoers configuration #20719 - Revert "fix --wait's failure to work on coredns pods" #20313 * Languages: - Add Indonesian translation #20494 - Add more french translation #20361 - Add more Korean translations #20634 - Add more Chinese translations #20543#20543 - fixed minor typo in german translation #20546 - Version Updates: - Addon cloud-spanner: Update cloud-spanner-emulator/emulator image from 1.5.28 to 1.5.34 #20451 #20539 #20602#20623 #20670 #20704 #20795 - Addon headlamp: Update headlamp-k8s/headlamp image from v0.26.0 to v0.28.0 #20311 - Addon ingress: Update ingress-nginx/controller image from v1.11.3 to v1.12.2 #20789 - Addon inspektor-gadget: Update inspektor-gadget image from v0.36.0 to v0.40.0 #20325#20354#20512 #20736 - Addon kong: Update kong image from 3.8.0 to 3.9.0 #20151 #20384 #20728 - Addon kong: Update kong/kubernetes-ingress-controller image from 3.3.1 to 3.4.5 #20319#20446#20788 - Addon kubevirt: Update bitnami/kubectl image from 1.31.3 to 1.33.1 #20321#20349#20665#20731#20790 - Addon nvidia-device-plugin: Update nvidia/k8s-device-plugin image from v0.17.0 to v0.17.2 #20786#20534 - Addon registry: Update kube-registry-proxy image from 0.0.8 to 0.0.9 #20717 - Addon registry: Update registry image from 2.8.3 to 3.0.0 #20242 #20425 - Addon Volcano: Update volcano images from v1.10.0 to v1.11.2 #20318 #20616 #20697 - CNI: Update cilium from v1.17.0 to v3.30.0 #20419 #20390 #20584 #20734 #20317 #20383 #20535 #20637 #20787 - CNI: Update flannel from v0.26.2 to v0.26.7 #20385#20617 #20639 - CNI: Update kindnetd from v20241108-5c6d2daf to v20250512-df8de77b #20327#20427 #20797 - HA (multi-control plane): Update kube-vip from v0.8.10 to v0.9.1 #20638#20238#20598 #20699 - Kicbase: Bump ubuntu:jammy from 20240911.1 to 20250126 #20387 #20718 - Kicbase/ISO: Update buildroot from 2023.02.9 to 2025.2 #20720 - Kicbase/ISO: Update cni-plugins from v1.6.2 to v1.7.1 #20771 - Kicbase/ISO: Update cri-dockerd from v0.3.15 to v0.4.0 #20747 - Kicbase/ISO: Update docker from 27.4.0 to 28.0.4 #20436 #20523 #20591 - Kicbase/ISO: Update runc from v1.2.3 to v1.3.0#20433#20604 #20764 - update to 1.35.0 (boo#1234528, CVE-2024-45337): * Features: - Add support for AMD GPUs via --gpus=amd #19749 - publish & download kicbase image in github release assets #19464 - Support latest Kubernetes v1.32.0 #20091 - Adds support for kubeadm.k8s.io/v1beta4 available since k8s v1.31 #19790 * Improvements: - Merge nvidia-gpu-device-plugin and nvidia-device-plugin. #19545 - cilium: remove appArmorProfile for k8s<v1.30.0 #19888 - auto-pause: restart service after configuration #19900 - Revert "Change MINIKUBE_HOME logic" #20045 - HA (multi-control plane): Update kube-vip from v0.8.6 to v0.8.7 #20053 - don't pollute minikube profile list with errors if exitcode is absent #19728 - unified minikube cluster status query #18998 - Vfkit driver: fix TestMachineType failing on macOS #19726 - No more arch restriction on nerdctld #19730 - remove helm-tiller addon #19636 - More robust MAC address matching #19750 - Add instructions to resolve docker context error #19197 * Bug fixes: - fix --wait's failure to work on coredns pods #19748 - Fix panic when no services in namespace with --all specified #19957 - fix timeout when stopping KVM machine with CRI-O container runtime #19758 - Fix long lines in lastStart.txt not outputting in log outputs #19740 - Fix wrongly detecting kicbase arch as incorrect #19664 * Breaking Changes: - skip building kvm2-arm64 till 19959 is resolved #20062 - remove arm64 kvm #19985 * Languages: - Add more Chinese translations #19490 - Add more Chinese translations #19508 - Fix chinnese translation on wrong line #19718 - Add more chinnese translations #19962 - Add more chinnese translations #19772 - Fix french translation #19978 - Improve french translation #19654 * - Version Updates: - Please see the full changelog - https://github.com/kubernetes/minikube/releases/tag/v0.35.0 docker-machine-driver-kvm2-1.36.0-bp157.2.3.1.x86_64.rpm minikube-1.36.0-bp157.2.3.1.src.rpm minikube-1.36.0-bp157.2.3.1.x86_64.rpm minikube-bash-completion-1.36.0-bp157.2.3.1.noarch.rpm minikube-fish-completion-1.36.0-bp157.2.3.1.noarch.rpm minikube-zsh-completion-1.36.0-bp157.2.3.1.noarch.rpm minikube-1.36.0-bp157.2.3.1.i586.rpm docker-machine-driver-kvm2-1.36.0-bp157.2.3.1.aarch64.rpm minikube-1.36.0-bp157.2.3.1.aarch64.rpm openSUSE-2025-323 Security update for v2ray-core important openSUSE Backports SLE-15-SP7 Update This update for v2ray-core fixes the following issues: - Update version to 5.33.0 * bump github.com/quic-go/quic-go from 0.51.0 to 0.52.0(boo#1243946 and CVE-2025-297850) * Update other vendor source - Update version to 5.31.0 * Add Dns Proxy Response TTL Control * Fix call newError Base with a nil value error * Update vendor (boo#1235164) - Update version to 5.29.3 * Enable restricted mode load for http protocol client * Correctly implement QUIC sniffer when handling multiple initial packets * Fix unreleased cache buffer in QUIC sniffing * A temporary testing fix for the buffer corruption issue * QUIC Sniffer Restructure - Update version to 5.22.0 * Add packetEncoding for Hysteria * Add ECH Client Support * Add support for parsing some shadowsocks links * Add Mekya Transport * Fix bugs - Update version to 5.18.0 * Add timeout for http request roundtripper * Fix ss2022 auth reader size overflow * Add pie build mode to all binary builds * Support "services" root config in cfgv4 * packet_encoding for config v4 * add MPTCP support * Add (Experimental) Meyka Building Blocks to request Transport * Add timeout for http request roundtripper * Hysteria2: Add Hysteria2 Protocol * Add AllowInsecureIfPinnedPeerCertificate option to tls security * Add tls certChainHash command * add support for socket activation * Add pprof flag for debugging * Fix bugs - Update version to 5.16.1 * Add Keep-Alive to removed headers - Update version to 5.15.1 * feat: RandomStrategy AliveOnly * Improve container image tags and timestamp * Add delay_auth_write to Socks5 Client Advanced Config * Add MaxMin TLS version support in TLS Setting * feat: RandomStrategy AliveOnly * Improve container image tags and timestamp * Fixed an encrypted traffic's malleable vulnerability that allow integrity corruption by an attacker with a privileged network position to silently drop segments of traffic from an encrypted traffic stream. * Update documents * Fix bugs - Update vendor, fix CVE-2024-22189 boo#1222488 - Update version to 5.12.1 * Shadowsocks2022 Client Support * Apply DomainStrategy to outbound target * Add DomainStrategy to JSONv5 outbound * Add sniffing for TUN * Add HTTPUpgrade transport * It is a reduced version of WebSocket Transport that can pass many reverse proxies and CDNs without running a WebSocket protocol stack * TUN Support * Add uTLS support for h2 transport * Fix bugs golang-github-v2fly-v2ray-core-5.33.0-bp157.2.3.1.noarch.rpm v2ray-core-5.33.0-bp157.2.3.1.src.rpm v2ray-core-5.33.0-bp157.2.3.1.x86_64.rpm v2ray-core-5.33.0-bp157.2.3.1.i586.rpm v2ray-core-5.33.0-bp157.2.3.1.aarch64.rpm v2ray-core-5.33.0-bp157.2.3.1.ppc64le.rpm v2ray-core-5.33.0-bp157.2.3.1.s390x.rpm openSUSE-2025-324 Security update for etcd important openSUSE Backports SLE-15-SP7 Update This update for etcd fixes the following issues: - Update to version 3.6.2: * Avoid lowering revision of watchers in the future after restore * Add verification to verify the watch response have a bigger revision than minRev * Disable progress notify validation until we can guarantee response * Skip sending progress notification for watch with starting revision in the future - See upgrade guide: https://etcd.io/docs/v3.6/upgrades/upgrade_3_6/ - Update to version 3.6.1: * etcd server: - Replaced the deprecated/removed UnaryServerInterceptor and StreamServerInterceptor in otelgrpc with NewServerHandler - Add protection on PromoteMember and UpdateRaftAttributes to prevent panicking - Fix the issue that --force-new-cluster can't remove all other members in a corner case - Fix mvcc: avoid double decrement of watcher gauge on close/cancel race - Add validation to ensure there is no empty v3discovery endpoint * etcdctl: - Fix command etcdctl endpoint health doesn't work when options are set via environment variables - Update to version 3.6.0: https://github.com/etcd-io/etcd/compare/v3.5.21...v3.6.0 * Dropped flags in v3.6.0: ETCD_ENABLE_V2 ETCD_PROXY ETCD_PROXY_DIAL_TIMEOUT ETCD_PROXY_FAILURE_WAIT ETCD_PROXY_READ_TIMEOUT ETCD_PROXY_REFRESH_INTERVAL ETCD_PROXY_WRITE_TIMEOUT - Update to version 3.5.21: * bump golang.org/x/net from v0.36.0 to v0.38.0 * bump github.com/golang-jwt/jwt/v4 from 4.5.1 to 4.5.2 to address CVE-2025-30204 (boo#1240515) - Update to version 3.5.20: * Fix the issue that learner promotion command doesn't support json output * overwrite the member if already exist * add verification to check whether membership data is in sync between v2store and v3store * fix: grpcproxy can get stuck in and endless loop causing high cpu usage * perf(release3.5): use RLock in Demoted method for read-only access to expiry - Update to version 3.5.19: * Bump go toolchain to 1.23.7 * fix a compaction induce latency issue * Add learner id into log when being promoted or removed * add learner check to readyz * tools: add mixed read-write performance evaluation scripts - Update to version 3.5.18: * Ensure all goroutines created by StartEtcd to exit before closing the errc * mvcc: restore tombstone index if it's first revision * Bump go toolchain to 1.22.11 * Avoid deadlock in etcd.Close when stopping during bootstrapping * etcdutl/etcdutl: use datadir package to build wal/snapdir * Remove duplicated <-s.ReadyNotify() * Do not wait for ready notify if the server is stopping * Fix mixVersion test case: ensure a snapshot to be sent out * *: support custom content check offline in v2store * Print warning message for deprecated flags if set * fix runtime error: comparing uncomparable type * add tls min/max version to grpc proxy - Fixing a configuration data loss bug: Fillup really really wants that the template and the target file actually follow the sysconfig format. The current config and the current template do not fulfill this requirement. Move the current /etc/sysconfig/etcd to /etc/default/etcd and install a new sysconfig file which only adds the ETCD_OPTIONS option, which is actually used by the unit file. This also makes it a bit cleaner to move etcd to use --config-file in the long run. - Update etcd configuration file based on https://github.com/etcd-io/etcd/blob/v3.5.17/etcd.conf.yml.sample - Update to version 3.5.17: * fix(defrag): close temp file in case of error * Bump go toolchain to 1.22.9 * fix(defrag): handle defragdb failure * fix(defrag): handle no space left error * [3.5] Fix risk of a partial write txn being applied * [serverWatchStream] terminate recvLoop on sws.close() - Update to version 3.5.16: * Bump go toolchain to 1.22.7 * Introduce compaction sleep interval flag * Fix passing default grpc call options in Kubernetes client * Skip leadership check if the etcd instance is active processing heartbeats * Introduce Kubernetes KV interface to etcd client - Update to version 3.5.15: * Differentiate the warning message for rejected client and peer * connections * Suppress noisy basic auth token deletion log * Support multiple values for allowed client and peer TLS identities(#18015) * print error log when validation on conf change failed - Update to version 3.5.14: * etcdutl: Fix snapshot restore memory alloc issue * server: Implement WithMmapSize option for backend config * gRPC health server sets serving status to NOT_SERVING on defrag * server/mvcc: introduce compactBeforeSetFinishedCompact failpoint * Update the compaction log when bootstrap and update compact's signature * add experimental-snapshot-catchup-entries flag. * Fix retry requests when receiving ErrGPRCNotSupportedForLearner - Update to version 3.5.13: * Fix progress notification for watch that doesn't get any events * pkg/types: Support Unix sockets in NewURLS * added arguments to the grpc-proxy: dial-keepalive-time, dial-keepalive-timeout, permit-without-stream * server: fix comment to match function name * Make CGO_ENABLED configurable for etcd 3.5 * etcdserver: drain leaky goroutines before test completed etcd-3.6.2-bp157.2.3.1.src.rpm etcd-3.6.2-bp157.2.3.1.x86_64.rpm etcdctl-3.6.2-bp157.2.3.1.x86_64.rpm etcdutl-3.6.2-bp157.2.3.1.x86_64.rpm etcd-3.6.2-bp157.2.3.1.aarch64.rpm etcdctl-3.6.2-bp157.2.3.1.aarch64.rpm etcdutl-3.6.2-bp157.2.3.1.aarch64.rpm etcd-3.6.2-bp157.2.3.1.ppc64le.rpm etcdctl-3.6.2-bp157.2.3.1.ppc64le.rpm etcdutl-3.6.2-bp157.2.3.1.ppc64le.rpm etcd-3.6.2-bp157.2.3.1.s390x.rpm etcdctl-3.6.2-bp157.2.3.1.s390x.rpm etcdutl-3.6.2-bp157.2.3.1.s390x.rpm openSUSE-2025-332 Security update for go-sendxmpp moderate openSUSE Backports SLE-15-SP7 Update This update for go-sendxmpp fixes the following issues: - Update to 0.15.0: Added: * Add flag --verbose to show debug information. * Add flag --recipients to specify recipients by file. * Add flag --retry-connect to try after a waiting time if the connection fails. * Add flag --retry-connect-max to specify the amount of retry attempts. * Add flag --legacy-pgp for using XEP-0027 PGP encryption with Ox keys. * Add support for punycode domains. Changed: * Update gopenpgp library to v3. * Improve error detection for MUC joins. * Don't try to connect to other SRV record targets if error contains 'auth-failure'. * Remove support for old SSDP version (via go-xmpp v0.2.15). * Http-upload: Stop checking other disco items after finding upload component. * Increase default TLS version to 1.3. - CVE-2025-22872: Fixed golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (boo#1241814) - Update to 0.14.1: * Use prettier date format for error messages. * Update XEP-0474 to version 0.4.0 (requires go-xmpp >= 0.2.10). go-sendxmpp-0.15.0-bp157.2.3.1.src.rpm go-sendxmpp-0.15.0-bp157.2.3.1.x86_64.rpm go-sendxmpp-0.15.0-bp157.2.3.1.i586.rpm go-sendxmpp-0.15.0-bp157.2.3.1.aarch64.rpm go-sendxmpp-0.15.0-bp157.2.3.1.ppc64le.rpm go-sendxmpp-0.15.0-bp157.2.3.1.s390x.rpm openSUSE-2025-327 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 139.0.7258.154 (boo#1248769) * CVE-2025-9478: Use after free in ANGLE chromedriver-139.0.7258.154-bp157.2.43.1.x86_64.rpm chromium-139.0.7258.154-bp157.2.43.1.src.rpm chromium-139.0.7258.154-bp157.2.43.1.x86_64.rpm chromedriver-139.0.7258.154-bp157.2.43.1.aarch64.rpm chromium-139.0.7258.154-bp157.2.43.1.aarch64.rpm chromedriver-139.0.7258.154-bp157.2.43.1.ppc64le.rpm chromium-139.0.7258.154-bp157.2.43.1.ppc64le.rpm openSUSE-2025-334 Security update for dcmtk moderate openSUSE Backports SLE-15-SP7 Update This update for dcmtk fixes the following issues: - CVE-2025-9732: Fixed a memory corruption in dcm2img (boo#1248995). dcmtk-3.6.9-bp157.3.3.1.src.rpm dcmtk-3.6.9-bp157.3.3.1.x86_64.rpm dcmtk-debuginfo-3.6.9-bp157.3.3.1.x86_64.rpm dcmtk-debugsource-3.6.9-bp157.3.3.1.x86_64.rpm dcmtk-devel-3.6.9-bp157.3.3.1.x86_64.rpm libdcmtk19-3.6.9-bp157.3.3.1.x86_64.rpm libdcmtk19-debuginfo-3.6.9-bp157.3.3.1.x86_64.rpm dcmtk-3.6.9-bp157.3.3.1.i586.rpm dcmtk-debuginfo-3.6.9-bp157.3.3.1.i586.rpm dcmtk-debugsource-3.6.9-bp157.3.3.1.i586.rpm dcmtk-devel-3.6.9-bp157.3.3.1.i586.rpm libdcmtk19-3.6.9-bp157.3.3.1.i586.rpm libdcmtk19-debuginfo-3.6.9-bp157.3.3.1.i586.rpm dcmtk-3.6.9-bp157.3.3.1.aarch64.rpm dcmtk-debuginfo-3.6.9-bp157.3.3.1.aarch64.rpm dcmtk-debugsource-3.6.9-bp157.3.3.1.aarch64.rpm dcmtk-devel-3.6.9-bp157.3.3.1.aarch64.rpm libdcmtk19-3.6.9-bp157.3.3.1.aarch64.rpm libdcmtk19-debuginfo-3.6.9-bp157.3.3.1.aarch64.rpm dcmtk-3.6.9-bp157.3.3.1.ppc64le.rpm dcmtk-debuginfo-3.6.9-bp157.3.3.1.ppc64le.rpm dcmtk-debugsource-3.6.9-bp157.3.3.1.ppc64le.rpm dcmtk-devel-3.6.9-bp157.3.3.1.ppc64le.rpm libdcmtk19-3.6.9-bp157.3.3.1.ppc64le.rpm libdcmtk19-debuginfo-3.6.9-bp157.3.3.1.ppc64le.rpm dcmtk-3.6.9-bp157.3.3.1.s390x.rpm dcmtk-debuginfo-3.6.9-bp157.3.3.1.s390x.rpm dcmtk-debugsource-3.6.9-bp157.3.3.1.s390x.rpm dcmtk-devel-3.6.9-bp157.3.3.1.s390x.rpm libdcmtk19-3.6.9-bp157.3.3.1.s390x.rpm libdcmtk19-debuginfo-3.6.9-bp157.3.3.1.s390x.rpm openSUSE-2025-337 Security update for chromium, gn important openSUSE Backports SLE-15-SP7 Update This update for chromium, gn fixes the following issues: - Chromium 140.0.7339.80 (boo#1249093): * new permission prompt for local network access * CVE-2025-9864: Use after free in V8 * CVE-2025-9865: Inappropriate implementation in Toolbar * CVE-2025-9866: Inappropriate implementation in Extensions * CVE-2025-9867: Inappropriate implementation in Downloads * Various fixes from internal audits, fuzzing and other initiatives chromedriver-140.0.7339.80-bp157.2.46.1.x86_64.rpm chromium-140.0.7339.80-bp157.2.46.1.src.rpm chromium-140.0.7339.80-bp157.2.46.1.x86_64.rpm gn-0.20250619-bp157.2.6.1.src.rpm gn-0.20250619-bp157.2.6.1.x86_64.rpm gn-debuginfo-0.20250619-bp157.2.6.1.x86_64.rpm gn-debugsource-0.20250619-bp157.2.6.1.x86_64.rpm gn-0.20250619-bp157.2.6.1.i586.rpm gn-debuginfo-0.20250619-bp157.2.6.1.i586.rpm gn-debugsource-0.20250619-bp157.2.6.1.i586.rpm chromedriver-140.0.7339.80-bp157.2.46.1.aarch64.rpm chromium-140.0.7339.80-bp157.2.46.1.aarch64.rpm gn-0.20250619-bp157.2.6.1.aarch64.rpm gn-debuginfo-0.20250619-bp157.2.6.1.aarch64.rpm gn-debugsource-0.20250619-bp157.2.6.1.aarch64.rpm gn-0.20250619-bp157.2.6.1.ppc64le.rpm gn-debuginfo-0.20250619-bp157.2.6.1.ppc64le.rpm gn-debugsource-0.20250619-bp157.2.6.1.ppc64le.rpm gn-0.20250619-bp157.2.6.1.s390x.rpm gn-debuginfo-0.20250619-bp157.2.6.1.s390x.rpm gn-debugsource-0.20250619-bp157.2.6.1.s390x.rpm openSUSE-2025-338 Recommended update for opi moderate openSUSE Backports SLE-15-SP7 Update This update for opi fixes the following issues: - Version 5.8.7 * Fix ocenaudio url * Add LocalSend plugin * Run all tests in verbose mode * Print written repo files in verbose mode * Increase timeouts in test/06_install_non_interactive.py * Remove DNF references from README.md opi-5.8.7-bp157.2.6.1.noarch.rpm opi-5.8.7-bp157.2.6.1.src.rpm openSUSE-2025-345 Recommended update for gh moderate openSUSE Backports SLE-15-SP7 Update This update for gh fixes the following issues: - Update to version 2.78.0: * Add `--force` flag to `gh run cancel` (#11513) * Update third-party license versions (#11557) * chore(deps): bump github.com/go-viper/mapstructure/v2 (#11556) * Merge pull request #11536 from cli/copilot/fix-11535 * chore(deps): bump github.com/cli/go-gh/v2 from 2.12.1 to 2.12.2 * Update pkg/cmd/release/verify/verify.go * Update pkg/cmd/release/verify-asset/verify_asset.go * Hidden trusted root flag for release verify * Update Go dependencies to latest versions * chore(deps): bump actions/checkout from 4 to 5 * udpate the test * replace /git/refs/tags/ to /git/ref/tags/ * Update feature_detection.go * Update PR tests for v2 projects * Base changes for PR project items * Update `gh issue view` to show v2 projects * PR feedback from @bagtoad * Update v1 project detection logic * Update govulncheck workflow to scan source code * add test for FetchRefSHA * Apply suggestion from @Copilot * Update docs/install_windows.md * Consolidate repo profile, fix headings * chore(deps): bump google.golang.org/grpc from 1.73.0 to 1.74.2 * chore(deps): bump github.com/yuin/goldmark from 1.7.12 to 1.7.13 * Update docs on contributing new install methods * markdown lint fixes * Formatting * Initial installation doc refactor * Pushing empty commit to run CI * Bump Go to 1.24.6 * Fix linter * Update pkg/cmd/search/search.go * chore(deps): bump actions/download-artifact from 4 to 5 * Update docs/triage.md * Update docs/triage.md * Update issue triage guidelines and label usage * fix error for ErrReleaseNotFound when fetching ref * Apply suggestion from @Copilot * Update .github/workflows/scripts/spam-detection/process-issue.sh * docs(search): move search syntax note to `gh search --help` * Update spam detection to comment on and close issue * Update permissions and events for workflow * ci: use `help wanted` label link in comment * ci: anchor regexp for `help wanted` label * Improve spam detection evals (#11419) * v1 project feature detection spike using version * docs(help): rename `search-syntax` help topic * docs(search): add reference to `gh help search` * Add help topic for search syntax in gh commands * docs(search): add note for exclusion search syntax * Regenerate third-party licenses on trunk pushes * chore(deps): bump github.com/spf13/pflag from 1.0.6 to 1.0.7 gh-2.78.0-bp157.2.9.1.src.rpm gh-2.78.0-bp157.2.9.1.x86_64.rpm gh-bash-completion-2.78.0-bp157.2.9.1.noarch.rpm gh-fish-completion-2.78.0-bp157.2.9.1.noarch.rpm gh-zsh-completion-2.78.0-bp157.2.9.1.noarch.rpm gh-2.78.0-bp157.2.9.1.i586.rpm gh-2.78.0-bp157.2.9.1.aarch64.rpm gh-2.78.0-bp157.2.9.1.s390x.rpm openSUSE-2025-347 Security update for kubo moderate openSUSE Backports SLE-15-SP7 Update This update for kubo fixes the following issues: - CVE-2025-22872: Fixed golang.org/x/net/html issue where incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (boo#1241776). kubo-0.35.0-bp157.2.6.1.src.rpm kubo-0.35.0-bp157.2.6.1.x86_64.rpm kubo-0.35.0-bp157.2.6.1.i586.rpm kubo-0.35.0-bp157.2.6.1.aarch64.rpm kubo-0.35.0-bp157.2.6.1.ppc64le.rpm kubo-0.35.0-bp157.2.6.1.s390x.rpm openSUSE-2025-349 Recommended update for mkdud moderate openSUSE Backports SLE-15-SP7 Update This update for mkdud fixes the following issues: Update to version 2.0: - merge gh#openSUSE/mkdud#42 - make mkdud SLE-16 aware (jsc#PED-13262) - update man page - documentation update - adjust package dependencies mkdud-2.0-bp157.2.3.1.noarch.rpm mkdud-2.0-bp157.2.3.1.src.rpm openSUSE-2025-343 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 140.0.7339.127 (boo#1249388) * CVE-2025-10200: Use after free in Serviceworker * CVE-2025-10201: Inappropriate implementation in Mojo chromedriver-140.0.7339.127-bp157.2.49.1.x86_64.rpm chromium-140.0.7339.127-bp157.2.49.1.src.rpm chromium-140.0.7339.127-bp157.2.49.1.x86_64.rpm chromedriver-140.0.7339.127-bp157.2.49.1.aarch64.rpm chromium-140.0.7339.127-bp157.2.49.1.aarch64.rpm openSUSE-2025-352 Security update for java-11-openj9 important openSUSE Backports SLE-15-SP7 Update This update for java-11-openj9 fixes the following issues: Update to OpenJDK 11.0.28 with OpenJ9 0.53.0 virtual machine Including Oracle July 2025 CPU changes * CVE-2025-30749 (boo#1246595), CVE-2025-30754 (boo#1246598), CVE-2025-30761 (boo#1246580), CVE-2025-50059 (boo#1246575), CVE-2025-50106 (boo#1246584) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.53/ Update to OpenJDK 11.0.27 with OpenJ9 0.51.0 virtual machine Including Oracle April 2025 CPU changes * CVE-2025-21587 (boo#1241274), CVE-2025-30691 (boo#1241275), CVE-2025-30698 (boo#1241276) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.51/ java-11-openj9-11.0.28.0-bp157.2.3.1.src.rpm java-11-openj9-11.0.28.0-bp157.2.3.1.x86_64.rpm java-11-openj9-demo-11.0.28.0-bp157.2.3.1.x86_64.rpm java-11-openj9-devel-11.0.28.0-bp157.2.3.1.x86_64.rpm java-11-openj9-headless-11.0.28.0-bp157.2.3.1.x86_64.rpm java-11-openj9-javadoc-11.0.28.0-bp157.2.3.1.noarch.rpm java-11-openj9-jmods-11.0.28.0-bp157.2.3.1.x86_64.rpm java-11-openj9-src-11.0.28.0-bp157.2.3.1.x86_64.rpm java-11-openj9-11.0.28.0-bp157.2.3.1.aarch64.rpm java-11-openj9-demo-11.0.28.0-bp157.2.3.1.aarch64.rpm java-11-openj9-devel-11.0.28.0-bp157.2.3.1.aarch64.rpm java-11-openj9-headless-11.0.28.0-bp157.2.3.1.aarch64.rpm java-11-openj9-jmods-11.0.28.0-bp157.2.3.1.aarch64.rpm java-11-openj9-src-11.0.28.0-bp157.2.3.1.aarch64.rpm java-11-openj9-11.0.28.0-bp157.2.3.1.ppc64le.rpm java-11-openj9-demo-11.0.28.0-bp157.2.3.1.ppc64le.rpm java-11-openj9-devel-11.0.28.0-bp157.2.3.1.ppc64le.rpm java-11-openj9-headless-11.0.28.0-bp157.2.3.1.ppc64le.rpm java-11-openj9-jmods-11.0.28.0-bp157.2.3.1.ppc64le.rpm java-11-openj9-src-11.0.28.0-bp157.2.3.1.ppc64le.rpm java-11-openj9-11.0.28.0-bp157.2.3.1.s390x.rpm java-11-openj9-demo-11.0.28.0-bp157.2.3.1.s390x.rpm java-11-openj9-devel-11.0.28.0-bp157.2.3.1.s390x.rpm java-11-openj9-headless-11.0.28.0-bp157.2.3.1.s390x.rpm java-11-openj9-jmods-11.0.28.0-bp157.2.3.1.s390x.rpm java-11-openj9-src-11.0.28.0-bp157.2.3.1.s390x.rpm openSUSE-2025-354 Security update for java-17-openj9 important openSUSE Backports SLE-15-SP7 Update This update for java-17-openj9 fixes the following issues: Update to OpenJDK 17.0.16 with OpenJ9 0.53.0 virtual machine Including Oracle July 2025 CPU changes * CVE-2025-30749 (boo#1246595), CVE-2025-30754 (boo#1246598), CVE-2025-50059 (boo#1246575), CVE-2025-50106 (boo#1246584) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.53/ Update to OpenJDK 17.0.15 with OpenJ9 0.51.0 virtual machine Including Oracle April 2025 CPU changes * CVE-2025-21587 (boo#1241274), CVE-2025-30691 (boo#1241275), CVE-2025-30698 (boo#1241276) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.51/ java-17-openj9-17.0.16.0-bp157.2.3.1.src.rpm java-17-openj9-17.0.16.0-bp157.2.3.1.x86_64.rpm java-17-openj9-demo-17.0.16.0-bp157.2.3.1.x86_64.rpm java-17-openj9-devel-17.0.16.0-bp157.2.3.1.x86_64.rpm java-17-openj9-headless-17.0.16.0-bp157.2.3.1.x86_64.rpm java-17-openj9-javadoc-17.0.16.0-bp157.2.3.1.noarch.rpm java-17-openj9-jmods-17.0.16.0-bp157.2.3.1.x86_64.rpm java-17-openj9-src-17.0.16.0-bp157.2.3.1.x86_64.rpm java-17-openj9-17.0.16.0-bp157.2.3.1.aarch64.rpm java-17-openj9-demo-17.0.16.0-bp157.2.3.1.aarch64.rpm java-17-openj9-devel-17.0.16.0-bp157.2.3.1.aarch64.rpm java-17-openj9-headless-17.0.16.0-bp157.2.3.1.aarch64.rpm java-17-openj9-jmods-17.0.16.0-bp157.2.3.1.aarch64.rpm java-17-openj9-src-17.0.16.0-bp157.2.3.1.aarch64.rpm java-17-openj9-17.0.16.0-bp157.2.3.1.ppc64le.rpm java-17-openj9-demo-17.0.16.0-bp157.2.3.1.ppc64le.rpm java-17-openj9-devel-17.0.16.0-bp157.2.3.1.ppc64le.rpm java-17-openj9-headless-17.0.16.0-bp157.2.3.1.ppc64le.rpm java-17-openj9-jmods-17.0.16.0-bp157.2.3.1.ppc64le.rpm java-17-openj9-src-17.0.16.0-bp157.2.3.1.ppc64le.rpm java-17-openj9-17.0.16.0-bp157.2.3.1.s390x.rpm java-17-openj9-demo-17.0.16.0-bp157.2.3.1.s390x.rpm java-17-openj9-devel-17.0.16.0-bp157.2.3.1.s390x.rpm java-17-openj9-headless-17.0.16.0-bp157.2.3.1.s390x.rpm java-17-openj9-jmods-17.0.16.0-bp157.2.3.1.s390x.rpm java-17-openj9-src-17.0.16.0-bp157.2.3.1.s390x.rpm openSUSE-2025-361 Recommended update for ntpd-rs moderate openSUSE Backports SLE-15-SP7 Update This update for ntpd-rs fixes the following issues: Update to version 1.6.1 * Fixed mistake in the calculation of root dispersion used in serving and observability. Update to version 1.6.0 Added * Support draft versions of NTPv5 with configuration changes. * Allow disabling ntp versions in the server. Changed * NTPv5 draft support now targets draft 4. * Time jumps now emit warnings. * Updated dependencies. Fixed * Fixed a crash in force-sync when using many servers. * Fixed root dispersion of the server not properly updating over time. * Fixed a bug in handling unsigned ntp deny messages. Update to version 1.5.0 Added * Support for PPS based sources (this support can be disabled with a compile flag for now). * Per source configuration of poll intervals. * Allow setting a custom reference id for stratum 1 servers. Changed * Our algorithm can now handle periodic sources. * ntpd-rs runs single-threaded when only configured as a client, servers still run multithreaded. * The reference timestamp field is now set to the truncated receive timestamp instead of being zero. * Support of rustls 0.21 and 0.22 is removed. * Certificate validation is now done through rustls-platform-verifier, following platform certificate validation more closely. * Updated dependencies Fixed * Fixed parsing of IPv6 addresses. * Fixed incorrect display of date in force-sync command. * Fixed a client denial of service vulnerability with zero-sized NTS cookies. * Fixed a client denial of service vulnerability with NTS cookies that are too large. Update to version 1.4.0 Added * Support for GPS based sources via a GPSd socket. * Added a setting to allow disabling of colors in our logs (observability.ansi-colors) Changed * Fallback to V4 should V5 not work for some reason (if NTPv5 is enabled) * Make the NTP version of a source configurable. * We now support rustls from 0.21 and up, to allow compilation on more targets. Fixed * Force sync did not work when a single source was configured. * Fix incorrect indexing in decode of ReferenceIdRequest for NTPv5 messages. Update to version 1.3.1 * Updated dependencies. Includes fixes for RUSTSEC-2024-0399. Update to version 1.3.0 Added * Added force-sync command to ntp-ctl to help with getting a decent initial time if the clock is far away from reality. * Added information on NTS to the ntp-ctl status overview. Changed * Made the logs a little less chatty. * Updated dependencies. ntpd-rs-1.6.1-bp157.2.3.1.src.rpm ntpd-rs-1.6.1-bp157.2.3.1.x86_64.rpm ntpd-rs-common-1.6.1-bp157.2.3.1.noarch.rpm ntpd-rs-1.6.1-bp157.2.3.1.i586.rpm ntpd-rs-1.6.1-bp157.2.3.1.aarch64.rpm openSUSE-2025-363 Recommended update for mkdud moderate openSUSE Backports SLE-15-SP7 Update This update for mkdud fixes the following issues: Update to version 2.2: - fix "How to apply" output Update to version 2.1: - support expressing installation ISO changes in DUDs (jsc#PED-13262) - add --dracut-hook option - update documentation mkdud-2.2-bp157.2.6.1.noarch.rpm mkdud-2.2-bp157.2.6.1.src.rpm openSUSE-2025-365 Security update for shadowsocks-v2ray-plugin moderate openSUSE Backports SLE-15-SP7 Update This update for shadowsocks-v2ray-plugin fixes the following issues: Update version to 5.37.0 * Update v2ray-core to 5.37.0 * Fixed CVE-2025-29785 in dependency ackhandler (bsc#1243954) golang-github-teddysun-v2ray-plugin-5.37.0-bp157.2.3.1.noarch.rpm shadowsocks-v2ray-plugin-5.37.0-bp157.2.3.1.src.rpm shadowsocks-v2ray-plugin-5.37.0-bp157.2.3.1.x86_64.rpm shadowsocks-v2ray-plugin-5.37.0-bp157.2.3.1.i586.rpm shadowsocks-v2ray-plugin-5.37.0-bp157.2.3.1.aarch64.rpm shadowsocks-v2ray-plugin-5.37.0-bp157.2.3.1.ppc64le.rpm shadowsocks-v2ray-plugin-5.37.0-bp157.2.3.1.s390x.rpm openSUSE-2025-357 Security update for perl-JSON-XS important openSUSE Backports SLE-15-SP7 Update This update for perl-JSON-XS fixes the following issues: Updated to version 4.40.0 (4.04) - CVE-2025-40928: Fixed integer overflow in parsing (boo#1249330). perl-JSON-XS-4.40.0-bp157.2.3.1.src.rpm perl-JSON-XS-4.40.0-bp157.2.3.1.x86_64.rpm perl-JSON-XS-4.40.0-bp157.2.3.1.i586.rpm perl-JSON-XS-4.40.0-bp157.2.3.1.aarch64.rpm perl-JSON-XS-4.40.0-bp157.2.3.1.ppc64le.rpm perl-JSON-XS-4.40.0-bp157.2.3.1.s390x.rpm openSUSE-2025-367 Security update for chromium important openSUSE Backports SLE-15-SP7 Update Chromium was updated to 140.0.7339.185 (stable released 2025-09-17) boo#1249999 Security issues fixed: * CVE-2025-10585: Type Confusion in V8 * CVE-2025-10500: Use after free in Dawn * CVE-2025-10501: Use after free in WebRTC * CVE-2025-10502: Heap buffer overflow in ANGLE chromedriver-140.0.7339.185-bp157.2.52.1.x86_64.rpm chromium-140.0.7339.185-bp157.2.52.1.src.rpm chromium-140.0.7339.185-bp157.2.52.1.x86_64.rpm chromedriver-140.0.7339.185-bp157.2.52.1.aarch64.rpm chromium-140.0.7339.185-bp157.2.52.1.aarch64.rpm openSUSE-2025-373 Security update for tor moderate openSUSE Backports SLE-15-SP7 Update This update for tor fixes the following issues: - 0.4.8.18 * CVE-2025-4444: onion service descriptor resource consumption issue (boo#1250101) - 0.4.8.17 * Minor features and bugfixes * use quantum-resistant MLKEM-768 cipher - tor 0.4.8.16 * fix typo in a directory authority rule file * fix a sandbox issue for bandwidth authority and a conflux issue on the control port * client fix about relay flag usage - tor 0.4.8.14 * bugfix for onion service directory cache * test-network now unconditionally includes IPv6 * Regenerate fallback directories 2025-02-05 * Update the geoip files to 2025-02-05 * Fix a pointer free - tor 0.4.8.13 * Conflux related client circuit building performance bugfix * Fix minor memory leaks * Add STATUS TYPE=version handler for Pluggable Transport - tor 0.4.8.12 * Minor features and bugfixes * See https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.8/ReleaseNotes tor-0.4.8.18-bp157.2.3.1.src.rpm tor-0.4.8.18-bp157.2.3.1.x86_64.rpm tor-debuginfo-0.4.8.18-bp157.2.3.1.x86_64.rpm tor-debugsource-0.4.8.18-bp157.2.3.1.x86_64.rpm tor-0.4.8.18-bp157.2.3.1.aarch64.rpm tor-debuginfo-0.4.8.18-bp157.2.3.1.aarch64.rpm tor-debugsource-0.4.8.18-bp157.2.3.1.aarch64.rpm tor-0.4.8.18-bp157.2.3.1.ppc64le.rpm tor-debuginfo-0.4.8.18-bp157.2.3.1.ppc64le.rpm tor-debugsource-0.4.8.18-bp157.2.3.1.ppc64le.rpm tor-0.4.8.18-bp157.2.3.1.s390x.rpm tor-debuginfo-0.4.8.18-bp157.2.3.1.s390x.rpm tor-debugsource-0.4.8.18-bp157.2.3.1.s390x.rpm openSUSE-2025-374 Recommended update for bird moderate openSUSE Backports SLE-15-SP7 Update This update for bird fixes the following issues: - redownload sources, seem like they changed a little - Minor polishing * use %tmpfiles_create macro * use install -D instead of mkdir && install - Update to version 2.17.1 * BSD: Fix build on NetBSD * BGP: Fix crash when incoming connection for disabled protocol arrives * Documentation fixes - Drop extra spaces in sysusers file and drop explicit group creation - Use prebuild PDF documentation for the docs package - Drop explicit User & Group Provides, should be handled automatically - Drop perl dependency for docs package because: * we currently don't build the documentation * real dependencies are different anyway - Update description - Migrate user creation to sysuser-tools - Update to version 2.17 * Babel: next hop control for IPv4 * BGP: link-local next hop format configuration * TCP-AO implementation for Linux - Update to version 2.16 * BFD: Set password per session * BFD: Accept zero checksum for IPv6-UDP * BMP: Refactoring and optimizations * OSPF: Allow loopback nexthop in OSPFv3-IPv4 * RPKI: TCP-MD5 authentication option * Filters: Add enum types to filter grammar * CLI: Configurable additional control sockets * CLI: Timeformat command * CLI: Dump commands need a target file * ASPA support in filters, Static and RPKI * Formalized contributions and credits policy * Many bugfixes and improvements bird-2.17.1-bp157.2.3.1.src.rpm bird-2.17.1-bp157.2.3.1.x86_64.rpm bird-doc-2.17.1-bp157.2.3.1.noarch.rpm bird-2.17.1-bp157.2.3.1.i586.rpm bird-2.17.1-bp157.2.3.1.aarch64.rpm bird-2.17.1-bp157.2.3.1.ppc64le.rpm bird-2.17.1-bp157.2.3.1.s390x.rpm openSUSE-2025-375 Recommended update for monitoring-plugins-zypper moderate openSUSE Backports SLE-15-SP7 Update This update for monitoring-plugins-zypper fixes the following issues: - update to 1.98.12 + remove openSUSE Leap 15.4, 15.5 + add SLE-15-SP7 + add Tumbleweed 2025 - update to 1.98.11 + Update AppArmor profile to work with Tumbleweed monitoring-plugins-zypper-1.98.12-bp157.2.3.1.noarch.rpm monitoring-plugins-zypper-1.98.12-bp157.2.3.1.src.rpm openSUSE-2025-379 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 140.0.7339.207 (boo#1250472) * CVE-2025-10890: Side-channel information leakage in V8 * CVE-2025-10891: Integer overflow in V8 * CVE-2025-10892: Integer overflow in V8 chromedriver-140.0.7339.207-bp157.2.55.1.x86_64.rpm chromium-140.0.7339.207-bp157.2.55.1.src.rpm chromium-140.0.7339.207-bp157.2.55.1.x86_64.rpm chromedriver-140.0.7339.207-bp157.2.55.1.aarch64.rpm chromium-140.0.7339.207-bp157.2.55.1.aarch64.rpm openSUSE-2025-377 Security update for afterburn important openSUSE Backports SLE-15-SP7 Update This update for afterburn fixes the following issues: - Update to version 5.9.0.git21.a73f509: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS as azure stopped providing keys in the old one, fixes boo#1250471 * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates * Sync repo templates ⚙ - Update to version 5.9.0: * cargo: Afterburn release 5.9.0 * docs/release-notes: update for release 5.9.0 * cargo: update dependencies * Add TMT test structure and basic smoke test * build(deps): bump openssl from 0.10.72 to 0.10.73 * build(deps): bump reqwest from 0.12.15 to 0.12.18 * docs/release-notes: Update changelog entry * dracut: Return 255 in module-setup * oraclecloud: add release note and move base URL to constant * oraclecloud: implement oraclecloud provider * build(deps): bump nix from 0.29.0 to 0.30.1 * build(deps): bump zbus from 5.7.0 to 5.7.1 * build(deps): bump serde-xml-rs from 0.6.0 to 0.8.1 * build(deps): bump ipnetwork from 0.20.0 to 0.21.1 * build(deps): bump clap from 4.5.38 to 4.5.39 - Fix Requires in noarch package to not be arch specific (boo#1244675) afterburn-5.9.0.git21.a73f509-bp157.2.6.1.src.rpm afterburn-5.9.0.git21.a73f509-bp157.2.6.1.x86_64.rpm afterburn-dracut-5.9.0.git21.a73f509-bp157.2.6.1.noarch.rpm afterburn-5.9.0.git21.a73f509-bp157.2.6.1.i586.rpm afterburn-5.9.0.git21.a73f509-bp157.2.6.1.aarch64.rpm afterburn-5.9.0.git21.a73f509-bp157.2.6.1.ppc64le.rpm afterburn-5.9.0.git21.a73f509-bp157.2.6.1.s390x.rpm openSUSE-2025-381 Recommended update for virtme moderate openSUSE Backports SLE-15-SP7 Update This update for virtme fixes the following issues: Update to 1.38: * Fix the infamous Stale file handle (ESTALE) errors with virtiofsd * Fix for systemctl daemon-reload when systemd support is enabled * Fix for a kernel symlink issue affecting openSUSE/SLE * README/docs improvements * Various coding style cleanups virtme-1.38-bp157.2.9.1.noarch.rpm virtme-1.38-bp157.2.9.1.src.rpm openSUSE-2025-382 Recommended update for galera-4 moderate openSUSE Backports SLE-15-SP7 Update This update for galera-4 fixes the following issues: - libboost_system was removed upstream, fixes boo#1249900 Update to 26.4.22: * New feature for applications to define sequential consistency parameters for the certification process, via wsrep_certify_v1() which takes an application defined callback * Fixed assertions in report_last_committed() that could cause issues under certain thread scheduling conditions * Removed unnecessary assertions that could trigger due to normal timing variations in distributed environments * Fixed string format warnings that were appearing during builds on Debian Sid 26.4.21 changelog: * remove the dependency on openssl/engine.h - fixes codership/galera#663 * writeset serialization during IST fails because the seqno locking mechanism does not prevent underlying data stores from discarding released actions, requiring the locked seqno to be passed to stores to enforce discard limits. * fixed ssl_cipher parameter type to string * when a node progresses from JOINED to SYNCED, a race condition may prevent it from being counted in the commit cut; ensure it is included upon announcing SYNCED and delay advancing the commit cut until the node's last applied value exceeds the current commit cut. GCS protocol version bumped. * expose versions of all protocols agreed on by quorum via status call. 26.4.20 changelog: * improve error and warning messages handling in the library. System error numbers and messages are hidden from thrown exceptions, except for the cases where the exception is thrown because of error from system call. Some warning level messages in gcomm and GCS have been changed to info level in cases where the message does not require action from the administrator. Update to 26.4.19: * WSREP_KEY_SHARED key type is being phased out since it had insufficiently strict certification rules that may lead to certification test passes where it should fail. WSREP_KEY_REFERENCE fixes this, and all new writesets will be constructed using this. WSREP_KEY_SHARED is supported for backwards compatibility. * A memory leak in the commit cut action has been fixed. * Network level node isolation, which can help shut down all communication with the rest of the cluster to achieve a fail-silent crash. * GCS level protocol bumped, as error voting for joiner in the JOINED state was broken when group-wide commit cut (implied SUCCESS vote) was not taken into account when processing error vote requests from the JOINED node. - Switch to mariadb fork of galera-4. update to 26.4.18: * The garbd process hangs due to exceptions in the GCS layer not being caught within the receive loop, necessitating a forceful termination. Fixing this requires catching all exceptions within the loop, closing the connection first, and then continuing until a 'SELF-LEAVE' message ensures graceful exit. * When using SSL, crashes of garbd during graceful node shutdowns may occur, and result in the cluster becoming non-Primary; garbd now ignores the SIGPIPE signal to prevent this. * socket_ssl_compression is deprecated, now it isn't attempt to be set, and the user receives a warning if it was explicitly set. * Fixed commit cut tracking on node leave, and bumped GCS protocol version for backwards compatibility. * Executing the gcomm join process in the database server thread can lead to issues during allowlist callbacks, which should only be handled by Galera service threads. The gcomm join process is run within the gcomm service thread now. Update to 26.4.17: - "Zero-level" certification keys are implemented. Currently there are 3 levels of resource keys: schema, table, row, yet one common resource used by every writeset, a node. The key is added by default to every writeset with the default type WSREP_KEY_SHARED. Now, node-wide operations can be performed with the same semantics as regular transactions. - Non-SYNCED nodes are not counted when calculating commit cut - maximum seqno that is no longer needed in certification index; situations may arise when group commit cut is applied before all preceding events are committed on a non-SYNCED node, now drain all monitors to ensure that preceding events are committed. - Stability of node joining process for gmcast improved when new nodes are connecting concurrently as nodes previously may arrive at a different conclusion on which nodes will be blocked, however now, connections are explicitly allowed from all nodes which may be accepted as members in the next view. - Stability of node joining process for EVS improved by dropping EVS join messages without own identified in joining state, to avoid starting membership protocol before at least one of the existing nodes has seen at least one join message from a joiner. - Improve "Failed to report last committed" warning to make it more accurate and user-friendly. Update to 26.4.16: - Removed out-of-order certification for BF aborted transactions. - Better error handling when the socket is closed, also cleaned up excessive debug logging. Update to 26.4.15: - an assertion is relaxed when Galera is configured with commit order disabled - in certificate index preload, an assertion in handle_ist_trx_preload() fails if the first handled IST preload write set has failed certification, and incrementing the index position caused the certificate index to end up with the wrong position; now fixed by appending dummy writeset sequence numbers into Certification::trx_map_ - ASAN reported memory leak if gcs is closed after becoming joined but before reaching synced galera-4-26.4.22-bp157.2.3.1.src.rpm galera-4-26.4.22-bp157.2.3.1.x86_64.rpm galera-4-wsrep-provider-26.4.22-bp157.2.3.1.x86_64.rpm galera-4-26.4.22-bp157.2.3.1.i586.rpm galera-4-wsrep-provider-26.4.22-bp157.2.3.1.i586.rpm galera-4-26.4.22-bp157.2.3.1.aarch64.rpm galera-4-wsrep-provider-26.4.22-bp157.2.3.1.aarch64.rpm galera-4-26.4.22-bp157.2.3.1.ppc64le.rpm galera-4-wsrep-provider-26.4.22-bp157.2.3.1.ppc64le.rpm galera-4-26.4.22-bp157.2.3.1.s390x.rpm galera-4-wsrep-provider-26.4.22-bp157.2.3.1.s390x.rpm openSUSE-2025-387 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 141.0.7390.54 (stable released 2025-09-30) (boo#1250780) * CVE-2025-11205: Heap buffer overflow in WebGPU * CVE-2025-11206: Heap buffer overflow in Video * CVE-2025-11207: Side-channel information leakage in Storage * CVE-2025-11208: Inappropriate implementation in Media * CVE-2025-11209: Inappropriate implementation in Omnibox * CVE-2025-11210: Side-channel information leakage in Tab * CVE-2025-11211: Out of bounds read in Media * CVE-2025-11212: Inappropriate implementation in Media * CVE-2025-11213: Inappropriate implementation in Omnibox * CVE-2025-11215: Off by one error in V8 * CVE-2025-11216: Inappropriate implementation in Storage * CVE-2025-11219: Use after free in V8 * Various fixes from internal audits, fuzzing and other initiatives chromedriver-141.0.7390.54-bp157.2.58.1.x86_64.rpm chromium-141.0.7390.54-bp157.2.58.1.src.rpm chromium-141.0.7390.54-bp157.2.58.1.x86_64.rpm chromedriver-141.0.7390.54-bp157.2.58.1.aarch64.rpm chromium-141.0.7390.54-bp157.2.58.1.aarch64.rpm chromedriver-141.0.7390.54-bp157.2.58.1.ppc64le.rpm chromium-141.0.7390.54-bp157.2.58.1.ppc64le.rpm openSUSE-2025-390 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 141.0.7390.65 (boo#1251334): * CVE-2025-11458: Heap buffer overflow in Sync * CVE-2025-11460: Use after free in Storage * CVE-2025-11211: Out of bounds read in WebCodecs chromedriver-141.0.7390.65-bp157.2.61.1.x86_64.rpm chromium-141.0.7390.65-bp157.2.61.1.src.rpm chromium-141.0.7390.65-bp157.2.61.1.x86_64.rpm chromedriver-141.0.7390.65-bp157.2.61.1.aarch64.rpm chromium-141.0.7390.65-bp157.2.61.1.aarch64.rpm chromedriver-141.0.7390.65-bp157.2.61.1.ppc64le.rpm chromium-141.0.7390.65-bp157.2.61.1.ppc64le.rpm openSUSE-2025-393 Recommended update for chromium moderate openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 141.0.7390.76: * Do not send URLs as AIM input. This is to resolve a privacy concern, around passing urls to AI Mode. - exclude the main tarball from the src.rpm to reduce size (it is anyway fully referenced, so no supply chain concern) chromedriver-141.0.7390.76-bp157.2.64.1.x86_64.rpm chromium-141.0.7390.76-bp157.2.64.1.nosrc.rpm chromium-141.0.7390.76-bp157.2.64.1.x86_64.rpm chromedriver-141.0.7390.76-bp157.2.64.1.aarch64.rpm chromium-141.0.7390.76-bp157.2.64.1.aarch64.rpm chromedriver-141.0.7390.76-bp157.2.64.1.ppc64le.rpm chromium-141.0.7390.76-bp157.2.64.1.ppc64le.rpm openSUSE-2025-394 Recommended update for gh moderate openSUSE Backports SLE-15-SP7 Update This update for gh fixes the following issues: Update to version 2.81.0: * test(auth status): correctly replace JSON-escaped paths * update the description * refactor: use strings.FieldsFuncSeq to reduce memory allocations * fix(pr checkout): add alias `co` * remove hidden value for release verify cmd * fix latest tag for relase verify asset * docs(auth status): explain `--json` will always exit with zero * fix(auth status): return JSON entries under `hosts` * fixup! examples * fix error missing in json output * examples * remove showToken from authEntry * address copilot comment on parameter order * add examples * simplify exporter usage * remove includeScope * do not mutate opts.ShowToken * move displayToken to String method * move flag validation to RunE * refactor without VisitAll * introduce AddJSONFlagsWithoutShorthand * fix show token when using json * fix exit code * revert showToken change * mutually exclusive flags * flag duplicate check * add ExpectCommandToSupportJSONFields * do not export authState * handle -t conflict * do not fetch scope if not necessary * json flags * auth state enum * Refactor entry to a single type * Fix missing assertions - Packaging improvements: * Update to BuildRequires: golang(API) >= 1.24 matching go.mod Update to version 2.80.0: * chore: update third-party licenses * Add math package import to sessions.go * Add TODO for better integer handling in GetPullRequestDatabaseID * chore: update third-party licenses * update the test * Update pkg/cmd/attestation/api/client.go * add initiator_type for attestations * fix(agent-task/capi): return proper error message when resp is not a JSON * test(agent-task view): populate `Session.Name` in all test cases * fix(agent-task view): improve session overview * refactor(agent-task view): merge empty println calls with next * fix(agent-task view): re-fetch session to get all pieces of data * fix(agent-task/capi): remove fallback to viewer when user id is zero * test(agent-tassk/capi): update `ListSessionsByResourceID` tests * docs(agent-task/capi): add TODO note for dropping local ID generation * fix(agent-task/capi): fetch viewer when resource session user id is zero * fix(agent-task/capi): handle unpopulated resource session `LastUpdatedAt` * refactor(agent-task/capi): keep `resource` private * update agents resource route * fix(agent-task view): improve session error * fix(agent-task view): display session error * fix(agent-task/capi): add `WorkflowRunID` field to `Session` * refactor(agent-task/capi): remove unused slice * fix(agent-task/capi): add `Error` field to `Session` * fix(agent-task create): block empty problem statement arg * fix(agent-task create): use pager when following logs * fix(agent-task create): avoid prompting when problem statement is provided * fix(agent-task list): show capitalised session state * fix(agent-task/shared): fix session state value * docs(agent-task list): add "(preview)" note to cmd docs * chore(agent-task/shared): regenerate `LogRenderer` mock * test(agent-task/capi): assert session with zero resource ID are kept * fix(agent-task/capi): keep sessions with no resource attached * refactor(agent-task list): remove unused `BaseRepo` from `ListOptions` * docs(agent-task/capi): fix test case explanation * Fix session deduplication and add test for paging * Remove repo-scoped session listing and related code * docs(agent-task): use `heredoc.Doc` * docs(pr/shared): add a `TODO` on decoupling PR finder from IO * fix(agent-task view): display zero premium requests * fix(agent-task/shared): make capitalised status names consistent * Update pkg/cmd/agent-task/agent_task.go * Update pkg/cmd/agent-task/agent_task.go * Enhance agent-task command help and usage info * Refactor comments in stripDiffFormat function * Remove obsolete log-3 test data files * fix(agent-task view): omit session overview in log mode * fix(agent-task view): display premium requests used * fix(agent-task/capi): add `PremiumRequests` field to `Session` * fix(agent-task view): display session duration * fix(agent-task view): display completed sessions as "Ready for review" * fix(agent-task view): disable PR finder progress indicator * test(pr/shared): assert `FindOptions.DisableProgress` is respected * fix(pr/shared): add `DisableProgress` field to `FindOptions` * Refactor stripDiffFormat guard clause logic * Use filepath.Ext to detect file extension in markdown renderer * Improve log rendering error handling and test coverage * Prefix rendered shell commands with '$ ' in logs * Clarify comment on CRLF normalization in tests * Refactor generic tool call titles map to package scope * Add pager support to log output in printLogs * test(agent-task create): add test for `--follow` * docs(agent-task create): add example for `--follow` flag * feat(agent-task create): add `--follow` flag * refactor(agent-task create): extract session URL polling into a func * Add TODO for bash-related tool call details * Update comment for reasoning text formatting * Enable Bash session tool handling in log rendering * Rename testdata log files for clarity * Normalize line endings in log testdata files too * Fix line ending conversion in tests * Add note for updating testdata files in log tests * Make log tests OS-agnostic by normalizing line endings * Fix comment for GetSessionLogs method * Add and improve function documentation in log.go * Update log test expectation files * Rename renderToolCall to renderToolCallTitle * Rename relativePath to relativeFilePath in log rendering * Refactor markdown rendering helper function names * Improve log rendering and tool call handling * Refactor JSON content rendering in log entries * Various log rendering improvements * feat(agent-task view): add `--log` and `--follow` flags * feat(agent-task view): add `--log` and `--follow` flags * fix(agent-task/shared): add log renderer * feat(agent-task/capi): add `GetSessionLogs` method * Add error type assertion to createRun tests * Add test for non-interactive problem statement input * Update test to use edited task description * Remove unused stdin field from create command tests * Refactor create command tests and add base branch case * refactor(pr/shared): rename `rest` to `tail` * refactor(agent-task/shared): enhance symbol names * Update command examples for agent-task create * Refactor agent-task create to improve file input handling * fix(pr/shared): ensure `ParseURL` regexp is backward-compatible * refactor(agent-task/shared): extract uuid pattern * refactor(agent-task view): rename `resourceID` to `prID` * feat(agent-task view): support PR `/agent-sessions/*` URL as argument * fix(agent-task/shared): add `ParsePullRequestAgentSessionURL` * fix(pr/shared): add rest return value to `ParseURL` * docs(agent-task view): improve `--help` docs * refactor(agent-task create): assign `Config` at instantiation * fix(agent-task create): only prompt for problem statement if not provided * fix(agent-task view): stop progress indicator before opening browser * test(agent-task view): enhance naming and stubs * test(agent-task view): add `--web` mode tests * feat(agent-task view): add `--web` mode * refactor: move Copilot Agents home URL to capi * fix(agent-task/capi): also return PR URL from `GetPullRequestDatabaseID` * Still prompt for task desc with -F * Add interactive prompt for task description in agent-task create * Fix default value in session selection prompt * Show session name instead of ID in agent-task list * docs(agent-task view): explain test case rationale * docs(agent-task view): explain when condition is met * docs(agent-task/capi): remove redundant comment * test(agent-task/capi): fix test case args * fix(agent-task/capi): skip unpopulated resource ID when hydrating * docs(agent-task/shared): add godoc to `SessionStateString` * test(agent-task view): update tests * fix(agent-task view): use lower limit for fetching sessions * fix(agent-task view): use `CapiClient.GetPullRequestDatabaseID` * fix(agent-task/capi): add `GetPullRequestDatabaseID` to `CapiClient` interface * test(agent-task/capi): add tests for `GetPullRequestDatabaseID` * feat(agent-task/capi): add `GetPullRequestDatabaseID` method * test(agent-task/capi): add tests for `GetSessionByResourceID` * feat(agent-task view): support PR arg * fix(agent-task/shared): add `SessionSymbol` func * test(agent-task/shared): add test for `IsSessionID` * fix(agent-task/shared): add `IsSessionID` * test(pr/shared): add test for `ParseFullReference` * fix(pr/shared): add `ParseFullReference` func * feat(agent-task/capi): add `ListSessionsByResourceID` method to `CapiClient` interface * feat(agent-task/capi): add `ListSessionsByResourceID` * test(agent-task view): add tests for the `view` command * feat(agent-task view): add `view` command * test(agent-task list): remove unused `stubs` * feat(agent-task/capi): add `GetSession` method to `CapiClient` interface * test(agent-task/capi): add tests for `GetSession` * feat(agent-task/capi): add `GetSession` method * refactor(agent-task/capi): populate PRs `IsDraft` * refactor(agent-task/capi): hydrate user data * test(agent-task create): quote file paths to pass CI on Windows * refactor(agent-task list): simplify cmd initialisation * refactor(agent-task create): remove redundant `if` * test(agent-task create): use `CapiClientMock` * fix(agent-task create): simplify command initialisation * test(agent-task list): update `TestNewCmdCreate` * fix(agent-task create): allow no positional arg * test(agent-task list): apply test args anyway * test(agent-task list): use `CapiClientMock` * test(agent-task list): update `TestNewCmdList` * refactor(agent-task/capi): drop embedding of unexported struct * test(agent-task/capi): add `CapiClientMock` * test(agent-task/capi): add `go:generate` directive to gen mock * test(agent-task/capi): add tests for job-related methods * test(agent-task/capi): add tests for session-related methods * fix(agent-task/capi): handle non-JSON error response * fix(agent-task/capi): improve returned errs * refactor(agent-task/capi): improve pagination * refactor(agent-task list): use shared `CapiClientFunc` * fix(agent-task/shared): add `CapiClientFunc` helper * Improve agent-task create command help text * Refactor test case struct in create_test.go * Add base branch option to agent task creation * Support reading task description from stdin * Increase backoff timing for agent task creation * Add file input support to agent-task create command * Update error messages and test repo handling in agent-task create * Simplify error handling in CreateJob response * Simplify stdout assertion in createRun test * Improve job error handling and update tests * Use Job struct in request * Escape URL path parameters in GetJob request * Escape owner and repo in job creation URL * Escape URL path segments in agent session links * Remove nil check for job in agentSessionWebURL * Update test to expect 500 error response * Update error message in createRun test * Remove redundant 'error:' prefix from repo error * Update command usage for agent task creation * Update agent-task create command argument handling * Add agent task creation command and job API * Add pager support to agent-task list output * Replace panic with require.FailNow in test * Add test for web mode with repo flag in listRun * Add comment on web dashboard filtering limitation * Add test case for negative limit in list command * Return NoResultsError when no agent tasks found * Add comment explaining error handling in listRun * Simplify time calculation in listRun test * Simplify BaseRepo assignment in list command * Handle repo resolution errors gracefully in agent-task list * Add --web flag to agent-task list command * Show default limit in agent-task list flag help * Add limit flag to agent-task list command * Add repo-scoped agent session listing support * Refactor session state color logic to shared package * Optimize session pull request hydration logic * Refactor error handling in generatePullRequestNodeID * Update API query name for session PR fetch * Refactor variable names in ListSessionsForViewer * Remove commented-out fields from sessionPullRequest * Refactor agent-task list command client initialization * Refactor session filtering in listRun function * Fix import alias for shared package in agent-task list * Add agent task listing command and CAPI client * Refactor agent task tests into table-driven format * Refactor test to use require.Empty assertion * Show help on agent-task command execution * Add agent-task command with OAuth token validation Update to version 2.79.0: * fix(featuredetection): remove redundant `AdvancedIssueSearchWebInIssuesTab` field * docs(featuredetection): remove unknown dates * docs(search prs): mention advanced issue search syntax support * docs(search issues): mention advanced issue search syntax support * docs(pr list): mention advanced issue search syntax support * docs(issue list): mention advanced issue search syntax support * refactor(search): rename `Query.String` to `StandardSearchString` * test(search): improve test cases * chore(deps): bump actions/stale from 9 to 10 * chore(deps): bump actions/setup-go from 5 to 6 * Bump sigstore/rekor to v1.4.1 * Remove mention of public preview in trustedroot.go * docs(featuredetection): add godoc for min GHES version for advanced issue search * docs(issue pr): fix incorrect formatting * docs(issue list): fix incorrect formatting * docs: add cleanup/future TODO marks for advanced issue search changes * docs(pr list): explain use of advanced issue search syntax * docs(issue list): explain use of advanced issue search syntax * test(issue/pr list): assert integration with advanced issue search * test(pr shared): assert `ListURLWithQuery` works with advanced search syntax * refactor(issue/pr list): support advanced issue search * docs(search): improve `Searcher.URL` method docs * docs(search prs): mention advanced issue search takeover * docs(search issues): mention advanced issue search takeover * docs(search): improve docs for `Query.String` and `Query.AdvancedIssueSearchString` methods * refactor(search): improve special qualifier grouping * test(search): test advanced search support * fix(search): use advanced issue search when available * refactor: improve mock feature detector names * refactor(search): sort qualifiers in query * test(search): provide feature detection dependency * fix(search): add feature detection dependency * test(search): explain why `is:` and `in:` qualifiers used in test case * fix(search): sort qualifiers in advacned issue search syntax * test(search): add tests for `AdvancedIssueSearchString` method * fix(search): add `AdvancedIssueSearchString` method * test(featuredetection): add tests for advanced issue search detection * fix(featuredetection): add feature detection for advanced issue search * test(cache delete): combine test cases for invalid/non-existent refs * test(cache delete): replace `HTTP 204` with `200` to match API behaviour * docs(cache delete): explain different API responses * test(cache delete): add test case for key arg and `--all` * refactor(cache delete): simplify error handling * refactor(cache delete): simplify condition * fix(cache): validate `--ref` flag usage with cache ID * fix(cache): prevent using `--ref` flag with cache ID * refactor(cache): extract cache ID parsing logic * fix(cache): update error message for missing cache key with `--ref` flag * chore(cache): improve help text for `--ref` flag in cache deletion * test(cache): add tests for `--ref` flag in cache deletion * feat(cache): add support for `--ref` flag in cache deletion * refactor: use slices.Equal to simplify code (#11364) * feat: `gh auth` Automatically copy one-time OAuth code to clipboard (#11518) * docs(release create): difference `--generate-notes` and `--notes-from-tag` (#11534) * Fix pr create when branch name contains slashes gh-2.81.0-bp157.2.12.1.src.rpm gh-2.81.0-bp157.2.12.1.x86_64.rpm gh-bash-completion-2.81.0-bp157.2.12.1.noarch.rpm gh-fish-completion-2.81.0-bp157.2.12.1.noarch.rpm gh-zsh-completion-2.81.0-bp157.2.12.1.noarch.rpm gh-2.81.0-bp157.2.12.1.i586.rpm gh-2.81.0-bp157.2.12.1.aarch64.rpm gh-2.81.0-bp157.2.12.1.ppc64le.rpm gh-2.81.0-bp157.2.12.1.s390x.rpm openSUSE-2025-397 Recommended update for skanpage moderate openSUSE Backports SLE-15-SP7 Update This update for skanpage fixes the following issues: - Work around a tesseract bug which causes a crash if /usr/share/tessdata doesn't exist (but doesn't if it's empty) (boo#1243103) - Recommend installing tesseract-ocr skanpage-23.08.5-bp157.2.3.1.src.rpm skanpage-23.08.5-bp157.2.3.1.x86_64.rpm skanpage-debuginfo-23.08.5-bp157.2.3.1.x86_64.rpm skanpage-lang-23.08.5-bp157.2.3.1.noarch.rpm skanpage-23.08.5-bp157.2.3.1.aarch64.rpm skanpage-debuginfo-23.08.5-bp157.2.3.1.aarch64.rpm skanpage-23.08.5-bp157.2.3.1.ppc64le.rpm skanpage-debuginfo-23.08.5-bp157.2.3.1.ppc64le.rpm skanpage-23.08.5-bp157.2.3.1.s390x.rpm skanpage-debuginfo-23.08.5-bp157.2.3.1.s390x.rpm openSUSE-2025-399 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 141.0.7390.107: * CVE-2025-11756: Use after free in Safe Browsing (boo#1252013) chromedriver-141.0.7390.107-bp157.2.67.1.x86_64.rpm chromium-141.0.7390.107-bp157.2.67.1.nosrc.rpm chromium-141.0.7390.107-bp157.2.67.1.x86_64.rpm chromedriver-141.0.7390.107-bp157.2.67.1.aarch64.rpm chromium-141.0.7390.107-bp157.2.67.1.aarch64.rpm chromedriver-141.0.7390.107-bp157.2.67.1.ppc64le.rpm chromium-141.0.7390.107-bp157.2.67.1.ppc64le.rpm openSUSE-2025-401 Security update for coredns moderate openSUSE Backports SLE-15-SP7 Update This update for coredns fixes the following issues: - CVE-2025-58063: Fixed Lease ID Confusion (bsc#1249389) - Update to version 1.12.4: * bump deps * fix(transfer): goroutine leak on axfr err (#7516) * plugin/etcd: fix import order for ttl test (#7515) * fix(grpc): check proxy list length in policies (#7512) * fix(https): propagate HTTP request context (#7491) * fix(plugin): guard nil lookups across plugins (#7494) * lint: add missing prealloc to backend lookup test (#7510) * fix(grpc): span leak on error attempt (#7487) * test(plugin): improve backend lookup coverage (#7496) * lint: enable prealloc (#7493) * lint: enable durationcheck (#7492) * Add Sophotech to adopters list (#7495) * plugin: Use %w to wrap user error (#7489) * fix(metrics): add timeouts to metrics HTTP server (#7469) * chore(ci): restrict token permissions (#7470) * chore(ci): pin workflow dependencies (#7471) * fix(forward): use netip package for parsing (#7472) * test(plugin): improve test coverage for pprof (#7473) * build(deps): bump github.com/go-viper/mapstructure/v2 (#7468) * plugin/file: fix label offset problem in ClosestEncloser (#7465) * feat(trace): migrate dd-trace-go v1 to v2 (#7466) * test(multisocket): deflake restart by using a fresh port and coordinated cleanup (#7438) * chore: update Go version to 1.24.6 (#7437) * plugin/header: Remove deprecated syntax (#7436) * plugin/loadbalance: support prefer option (#7433) * Improve caddy.GracefulServer conformance checks (#7416) - Update to version 1.12.3: * chore: Minor changes to `Dockerfile` (#7428) * Properly create hostname from IPv6 (#7431) * Bump deps * fix: handle cached connection closure in forward plugin (#7427) * plugin/test: fix TXT record comparison for multi-chunk vs multiple records * plugin/file: preserve case in SRV record names and targets per RFC 6763 * fix(auto/file): return REFUSED when no next plugin is available (#7381) * Port to AWS Go SDK v2 (#6588) * fix(cache): data race when refreshing cached messages (#7398) * fix(cache): data race when updating the TTL of cached messages (#7397) * chore: fix docs incompatibility (#7390) * plugin/rewrite: Add EDNS0 Unset Action (#7380) * add args: startup_timeout for kubernetes plugin (#7068) * [plugin/cache] create a copy of a response to ensure original data is never modified * Add support for fallthrough to the grpc plugin (#7359) * view: Add IPv6 example match (#7355) * chore: enable more rules from revive (#7352) * chore: enable early-return and superfluous-else from revive (#7129) * test(plugin): improve tests for auto (#7348) * fix(proxy): flaky dial tests (#7349) * test: add t.Helper() calls to test helper functions (#7351) * fix(kubernetes): multicluster DNS race condition (#7350) * lint: enable wastedassign linter (#7340) * test(plugin): add tests for any (#7341) * Actually invoke make release -f Makefile.release during test (#7338) * Keep golang to 1.24.2 due to build issues in 1.24.3 (#7337) * lint: enable protogetter linter (#7336) * lint: enable nolintlint linter (#7332) * fix: missing intrange lint fix (#7333) * perf(kubernetes): optimize AutoPath slice allocation (#7323) * lint: enable intrange linter (#7331) * feat(plugin/file): fallthrough (#7327) * lint: enable canonicalheader linter (#7330) * fix(proxy): avoid Dial hang after Transport stopped (#7321) * test(plugin): add tests for pkg/rand (#7320) * test(dnsserver): add unit tests for gRPC and QUIC servers (#7319) * fix: loop variable capture and linter (#7328) * lint: enable usetesting linter (#7322) * test: skip certain network-specific tests on non-Linux (#7318) * test(dnsserver): improve core/dnsserver test coverage (#7317) * fix(metrics): preserve request size from plugins (#7313) * fix: ensure DNS query name reset in plugin.NS error path (#7142) * feat: enable plugins via environment during build (#7310) * fix(plugin/bind): remove zone for link-local IPv4 (#7295) * test(request): improve coverage across package (#7307) * test(coremain): Add unit tests (#7308) * ci(test-e2e): add Go version setup to workflow (#7309) * kubernetes: add multicluster support (#7266) * chore: Add new maintainer thevilledev (#7298) * Update golangci-lint (#7294) * feat: limit concurrent DoQ streams and goroutines (#7296) * docs: add man page for multisocket plugin (#7297) * Prepare for the k8s api upgrade (#7293) * fix(rewrite): truncated upstream response (#7277) * fix(plugin/secondary): make transfer property mandatory (#7249) * plugin/bind: remove macOS bug mention in docs (#7250) * Remove `?bla=foo:443` for `POST` DoH (#7257) * Do not interrupt querying readiness probes for plugins (#6975) * Added `SetProxyOptions` function for `forward` plugin (#7229) coredns-1.12.4-bp157.2.3.1.src.rpm coredns-1.12.4-bp157.2.3.1.x86_64.rpm coredns-extras-1.12.4-bp157.2.3.1.noarch.rpm coredns-1.12.4-bp157.2.3.1.aarch64.rpm coredns-1.12.4-bp157.2.3.1.ppc64le.rpm coredns-1.12.4-bp157.2.3.1.s390x.rpm openSUSE-2025-403 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 141.0.7390.122: * CVE-2025-12036: Inappropriate implementation in V8 (boo#1252402) chromedriver-141.0.7390.122-bp157.2.70.1.x86_64.rpm chromium-141.0.7390.122-bp157.2.70.1.nosrc.rpm chromium-141.0.7390.122-bp157.2.70.1.x86_64.rpm chromedriver-141.0.7390.122-bp157.2.70.1.aarch64.rpm chromium-141.0.7390.122-bp157.2.70.1.aarch64.rpm chromedriver-141.0.7390.122-bp157.2.70.1.ppc64le.rpm chromium-141.0.7390.122-bp157.2.70.1.ppc64le.rpm openSUSE-2025-409 Security update for exim moderate openSUSE Backports SLE-15-SP7 Update This update for exim fixes the following issues: - CVE-2025-53881: Fixed potential security issue with logfile rotation (boo#1246457). exim-4.98.2-bp157.5.1.src.rpm exim-4.98.2-bp157.5.1.x86_64.rpm eximon-4.98.2-bp157.5.1.x86_64.rpm eximstats-html-4.98.2-bp157.5.1.x86_64.rpm exim-4.98.2-bp157.5.1.aarch64.rpm eximon-4.98.2-bp157.5.1.aarch64.rpm eximstats-html-4.98.2-bp157.5.1.aarch64.rpm exim-4.98.2-bp157.5.1.ppc64le.rpm eximon-4.98.2-bp157.5.1.ppc64le.rpm eximstats-html-4.98.2-bp157.5.1.ppc64le.rpm exim-4.98.2-bp157.5.1.s390x.rpm eximon-4.98.2-bp157.5.1.s390x.rpm eximstats-html-4.98.2-bp157.5.1.s390x.rpm openSUSE-2025-410 Recommended update for etcd moderate openSUSE Backports SLE-15-SP7 Update This update for etcd fixes the following issue: - etcd 3.5.21 is provided as an intermediate version for transitioning from 3.5.x to 3.6.x. etcd-3.5.21-bp157.2.6.1.src.rpm etcd-3.5.21-bp157.2.6.1.x86_64.rpm etcdctl-3.5.21-bp157.2.6.1.x86_64.rpm etcdutl-3.5.21-bp157.2.6.1.x86_64.rpm etcd-3.5.21-bp157.2.6.1.aarch64.rpm etcdctl-3.5.21-bp157.2.6.1.aarch64.rpm etcdutl-3.5.21-bp157.2.6.1.aarch64.rpm etcd-3.5.21-bp157.2.6.1.ppc64le.rpm etcdctl-3.5.21-bp157.2.6.1.ppc64le.rpm etcdutl-3.5.21-bp157.2.6.1.ppc64le.rpm etcd-3.5.21-bp157.2.6.1.s390x.rpm etcdctl-3.5.21-bp157.2.6.1.s390x.rpm etcdutl-3.5.21-bp157.2.6.1.s390x.rpm openSUSE-2025-415 Recommended update for etcd moderate openSUSE Backports SLE-15-SP7 Update This update for etcd provides the current version 3.6.5. etcd-3.6.5-bp157.2.9.1.src.rpm etcd-3.6.5-bp157.2.9.1.x86_64.rpm etcdctl-3.6.5-bp157.2.9.1.x86_64.rpm etcdutl-3.6.5-bp157.2.9.1.x86_64.rpm etcd-3.6.5-bp157.2.9.1.aarch64.rpm etcdctl-3.6.5-bp157.2.9.1.aarch64.rpm etcdutl-3.6.5-bp157.2.9.1.aarch64.rpm etcd-3.6.5-bp157.2.9.1.ppc64le.rpm etcdctl-3.6.5-bp157.2.9.1.ppc64le.rpm etcdutl-3.6.5-bp157.2.9.1.ppc64le.rpm etcd-3.6.5-bp157.2.9.1.s390x.rpm etcdctl-3.6.5-bp157.2.9.1.s390x.rpm etcdutl-3.6.5-bp157.2.9.1.s390x.rpm openSUSE-2025-411 Security update for chromium moderate openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 142.0.7444.59 - Chromium 142.0.7444.52 chromedriver-142.0.7444.59-bp157.2.73.1.x86_64.rpm chromium-142.0.7444.59-bp157.2.73.1.nosrc.rpm chromium-142.0.7444.59-bp157.2.73.1.x86_64.rpm chromedriver-142.0.7444.59-bp157.2.73.1.aarch64.rpm chromium-142.0.7444.59-bp157.2.73.1.aarch64.rpm chromedriver-142.0.7444.59-bp157.2.73.1.ppc64le.rpm chromium-142.0.7444.59-bp157.2.73.1.ppc64le.rpm openSUSE-2025-418 Security update for git-bug moderate openSUSE Backports SLE-15-SP7 Update This update for git-bug fixes the following issues: - Revendor to include golang.org/x/net/html v 0.45.0 to prevent possible DoS by various algorithms with quadratic complexity when parsing HTML documents (boo#1251463, CVE-2025-47911 and boo#1251664, CVE-2025-58190). - Update to version 0.10.1: - cli: ignore missing sections when removing configuration (ddb22a2f) - Update to version 0.10.0: - bridge: correct command used to create a new bridge (9942337b) - web: simplify header navigation (7e95b169) - webui: remark upgrade + gfm + syntax highlighting (6ee47b96) - BREAKING CHANGE: dev-infra: remove gokart (89b880bd) - Update to version 0.10.0 - bridge: correct command used to create a new bridge (9942337b) - web: simplify header navigation (7e95b169) - web: remark upgrade + gfm + syntax highlighting (6ee47b96) - Update to version 0.9.0: - completion: remove errata from string literal (aa102c91) - tui: improve readability of the help bar (23be684a) - Update to version 0.8.1+git.1746484874.96c7a111: * docs: update install, contrib, and usage documentation (#1222) * fix: resolve the remote URI using url.*.insteadOf (#1394) * build(deps): bump the go_modules group across 1 directory with 3 updates (#1376) * chore: gofmt simplify gitlab/export_test.go (#1392) * fix: checkout repo before setting up go environment (#1390) * feat: bump to go v1.24.2 (#1389) * chore: update golang.org/x/net (#1379) * fix: use -0700 when formatting time (#1388) * fix: use correct url for gitlab PATs (#1384) * refactor: remove depdendency on pnpm for auto-label action (#1383) * feat: add action: auto-label (#1380) * feat: remove lifecycle/frozen (#1377) * build(deps): bump the npm_and_yarn group across 1 directory with 12 updates (#1378) * feat: support new exclusion label: lifecycle/pinned (#1375) * fix: refactor how gitlab title changes are detected (#1370) * revert: "Create Dependabot config file" (#1374) * refactor: rename //:git-bug.go to //:main.go (#1373) * build(deps): bump github.com/vektah/gqlparser/v2 from 2.5.16 to 2.5.25 (#1361) * fix: set GitLastTag to an empty string when git-describe errors (#1355) * chore: update go-git to v5@masterupdate_mods (#1284) * refactor: Directly swap two variables to optimize code (#1272) * Update README.md Matrix link to new room (#1275) - Update to version 0.8.0+git.1742269202.0ab94c9: * deps(crypto): bump golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for CVE-2024-45337) (#1312) git-bug-0.10.1-bp157.2.3.1.src.rpm git-bug-0.10.1-bp157.2.3.1.x86_64.rpm git-bug-bash-completion-0.10.1-bp157.2.3.1.noarch.rpm git-bug-fish-completion-0.10.1-bp157.2.3.1.noarch.rpm git-bug-zsh-completion-0.10.1-bp157.2.3.1.noarch.rpm git-bug-0.10.1-bp157.2.3.1.i586.rpm git-bug-0.10.1-bp157.2.3.1.aarch64.rpm git-bug-0.10.1-bp157.2.3.1.ppc64le.rpm git-bug-0.10.1-bp157.2.3.1.s390x.rpm openSUSE-2025-419 Recommended update for bash-git-prompt moderate openSUSE Backports SLE-15-SP7 Update This update for bash-git-prompt fixes the following issues: - Fixed insecure predictable /tmp file usage (boo#1247489). bash-git-prompt-2.7.1-bp157.2.3.1.noarch.rpm bash-git-prompt-2.7.1-bp157.2.3.1.src.rpm openSUSE-2025-414 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Security fixes (boo#1252881): * CVE-2025-12428: Type Confusion in V8 * CVE-2025-12429: Inappropriate implementation in V8 * CVE-2025-12430: Object lifecycle issue in Media * CVE-2025-12431: Inappropriate implementation in Extensions * CVE-2025-12432: Race in V8 * CVE-2025-12433: Inappropriate implementation in V8 * CVE-2025-12434: Race in Storage * CVE-2025-12435: Incorrect security UI in Omnibox * CVE-2025-12436: Policy bypass in Extensions * CVE-2025-12437: Use after free in PageInfo * CVE-2025-12438: Use after free in Ozone * CVE-2025-12439: Inappropriate implementation in App-Bound Encryption * CVE-2025-12440: Inappropriate implementation in Autofill * CVE-2025-12441: Out of bounds read in V8 * CVE-2025-12443: Out of bounds read in WebXR * CVE-2025-12444: Incorrect security UI in Fullscreen UI * CVE-2025-12445: Policy bypass in Extensions * CVE-2025-12446: Incorrect security UI in SplitView * CVE-2025-12447: Incorrect security UI in Omnibox chromedriver-142.0.7444.59-bp157.2.76.1.x86_64.rpm chromium-142.0.7444.59-bp157.2.76.1.nosrc.rpm chromium-142.0.7444.59-bp157.2.76.1.x86_64.rpm chromedriver-142.0.7444.59-bp157.2.76.1.aarch64.rpm chromium-142.0.7444.59-bp157.2.76.1.aarch64.rpm chromedriver-142.0.7444.59-bp157.2.76.1.ppc64le.rpm chromium-142.0.7444.59-bp157.2.76.1.ppc64le.rpm openSUSE-2025-424 Recommended update for catfish, elementary-xfce-icon-theme, gigolo, libxfce4ui, libxfce4windowing, menulibre, orage, parole, pragha, thunar, thunar-archive-plugin, thunar-media-tags-plugin, thunar-shares-plugin, thunar-vcs-plugin, tumbler, xfburn, xfce4-battery-plugin, xfce4-calculator-plugin, xfce4-clipman-plugin, xfce4-cpufreq-plugin, xfce4-cpugraph-plugin, xfce4-dict, xfce4-diskperf-plugin, xfce4-docklike-plugin, xfce4-eyes-plugin, xfce4-fsguard-plugin, xfce4-genmon-plugin, xfce4-mailwatch-plugin, xfce4-mount-plugin, xfce4-mpc-plugin, xfce4-netload-plugin, xfce4-notes-plugin, xfce4-panel, xfce4-panel-profiles, xfce4-places-plugin, xfce4-screenshooter, xfce4-sensors-plugin, xfce4-session, xfce4-settings, xfce4-smartbookmark-plugin, xfce4-stopwatch-plugin, xfce4-systemload-plugin, xfce4-taskmanager, xfce4-time-out-plugin, xfce4-timer-plugin, xfce4-verve-plugin, xfce4-wavelan-plugin, xfce4-weather-plugin, xfce4-whiskermenu-plugin, xfce4-xkb-plugin, xfdashboard, xfdesktop, xfmpc moderate openSUSE Backports SLE-15-SP7 Update This update for catfish, elementary-xfce-icon-theme, gigolo, libxfce4ui, libxfce4windowing, menulibre, orage, parole, pragha, thunar, thunar-archive-plugin, thunar-media-tags-plugin, thunar-shares-plugin, thunar-vcs-plugin, tumbler, xfburn, xfce4-battery-plugin, xfce4-calculator-plugin, xfce4-clipman-plugin, xfce4-cpufreq-plugin, xfce4-cpugraph-plugin, xfce4-dict, xfce4-diskperf-plugin, xfce4-docklike-plugin, xfce4-eyes-plugin, xfce4-fsguard-plugin, xfce4-genmon-plugin, xfce4-mailwatch-plugin, xfce4-mount-plugin, xfce4-mpc-plugin, xfce4-netload-plugin, xfce4-notes-plugin, xfce4-panel, xfce4-panel-profiles, xfce4-places-plugin, xfce4-screenshooter, xfce4-sensors-plugin, xfce4-session, xfce4-settings, xfce4-smartbookmark-plugin, xfce4-stopwatch-plugin, xfce4-systemload-plugin, xfce4-taskmanager, xfce4-time-out-plugin, xfce4-timer-plugin, xfce4-verve-plugin, xfce4-wavelan-plugin, xfce4-weather-plugin, xfce4-whiskermenu-plugin, xfce4-xkb-plugin, xfdashboard, xfdesktop, xfmpc fixes the following issues: Changes in catfish: - Update to version 4.20.1 - build: Require defs.py - build: Relax meson requirements - build: Document dependency version requirements - Prevent selection change on right-click - Support opening multiple files with enter key - Improve TreeView performance - Deprecated exo with libxfce4ui 4.21.0 - Update files found in real time - Display search time in status bar - Fix unintended search - Add hotkey for copy location - Add delete hotkey - Rename Files - Add a context menu option to send selected files to a folder - Complete copyright in about dialog - Translation Updates - Update to version 0.21+git12.dff5c11f with the following highlights: * Major New Feature: HiDPI Support * Application Icons: Many application icons were added or redesigned from scratch * File Type Icons (Mimetypes): icons for different file types were added or updated * System & Status Icons: A major effort was made to colorize and unify the panel and status indicator icons. * Theme Removal: The -darker and -darkest theme variants have been removed * File Deletion: A massive number of unused, duplicate, and broken symlinks were removed across all icon categories. * App Icon Removal: Icons for old or less common applications were removed to streamline the theme. * Better Standards Compliance: The theme was updated to improve compliance with the FreeDesktop.org Icon Specification. * License Update: The project's license was updated to GPLv3. Changes in gigolo: - Update to version 0.6.0 * Update README after switchover to meson * Add suport to Meson * Replace deprecated exo with libxfce4ui 4.21.0 * Translation Updates Changes in libxfce4ui: - Update to version 4.20.2 * clipboard-manager: Use GtkClipboard iff image-only format is available * I18n: Update po/LINGUAS list * clipboard-manager: Fix potential leak on targets * clipboard-manager: Use separate struct for each call to set_with_data() * clipboard-manager: Use GtkTargetList instead of manual allocation * Translation Updates Changes in libxfce4windowing: - Update to version 4.20.4 * XfwMonitorWayland: Delay monitor finalization until gdk data are set * XfwSeatWayland: Store global name for matching when seat is removed * XfwMonitorWayland: Fix release order in _global_removed() * XfwMonitorManagerWayland: Use g_hash_table_iter_remove when iterating * XfwMonitorWayland: Store global name for matching when output is removed * XfwScreenWayland: Rename id to name in registry_global(_remove)? * XfwMonitorWayland: Don't make XfwScreen emit signal with null monitor * XfwWorkspaceGroupWayland: Connect to XfwScreen::monitor-(added|removed) * Add mnemonics for workspace names in workspace menu * Revert "Update README after switchover to meson" * Update README after switchover to meson * Destroy wl_output & xdg_output together when wl_output global removed * XfwWorkspaceWayland: Fix typo * XfwWorkspace: Fix id property management * Defer binding to the workspace manager until after we have the outputs * I18n: Update po/LINGUAS list * meson-build: Add Vala language bindings option * Translation Updates - Update to version 4.20.3: - Support absolute icon paths - meson-build: Add GNU visibility files to sources - I18n: Update po/LINGUAS list - autotools-build: Search for xdt-gen-visibility also in the working tree - build: Automate copyright year management - docs: Fix warnings - XfwWindowX11: Fix memory leak - Try to match the app id in lower case to find the .desktop file - XfwWindowX11: Keep a ref on workspace - XfwWnckIcon: Fix wrong compare func - meson-build: Add missing conditional for ext-workspace - meson-build: Reintroduce tests option - meson-build: Use SPDX license expression - meson-build: Specify wayland-scanner as a native dependency - meson-build: Update debug/optimization flag management - Translation Updates Changes in menulibre: - update to version 2.4.0: * Improved desktop environment integration * The new "Exec Editor" makes editing command arguments easier * Help dialogs replace the wall-of-text tooltips * Separators are displayed in the sidebar again * Numerous UX tweaks make MenuLibre easier on the eyes Changes in orage: - Update to version 4.20.2 * Changed recurrence limits from 100 to 9999 (MR !78). * Minor cleanup of log messages. Changes in parole: - Update to version 4.12.0 * Update README after switchover to meson * build: Automate copyright year management * Add meson build * build: Use @ENUMPREFIX@ in glib-mkenums template * build: Simplify desktop file generation * build: Fix shellcheck issues in mime scripts * build: Remove clutter support * build: Replace xdt-csource with glib-compile-resources * Translation Updates Changes in pragha: - Drop rygel-devel BuildRequires, what pragha checks for is pkgconfig(rygel-server-2.6), and currently rygel-devel provides pkgconfig(rygel-server-2.8). Changes in thunar-archive-plugin: - Update to version 0.6.0 * Update README after switchover to meson * Fix -Wunterminated-string-initialization warnings with GCC 15.1 * Add Meson support * Remove deprecated and unused exo * Translation Updates Changes in thunar-media-tags-plugin: - Update to version 0.6.0: * Update README after switchover to meson * Add support to Meson * Translation Updates Changes in thunar-shares-plugin: - Update to version 0.5.0: * Update README after switchover to meson * Add support to Meson * Translation Updates Changes in thunar: - Update to 4.20.5 * Prevent GFileMonitor leak for folders (#1724) * Don't use variables for strings in ngettext (#1683) * Fix 'MOUNTED' state on file reload when unmounted * Translation Updates - Update to 4.20.5 * Update shortcut model asynchronously (#1022) * Clear selection before updating selection (#1672) * Translation Updates - Dropped git bcond as we no longer use it - Update to 4.20.4 * Improve file add/remove checks for ThunarFolder (#1649) * Properly update view after hidden file rename * Always reload ThunarFiles on change notice (#1650) * Directly notify after file reload (#1650) * Set initial state of "Restore" button (#1663) * Fix quoting when running shell scripts in a terminal (#1661) * Avoid use-after-free in rename dialog when file is changed * Fix a GFile leak in _thunar_io_jobs_rename * Fix use-after-free in thunar_renamer_dialog_response (#1458) * Fix use-after-free on exit with search tabs open (#1593) * Translation Updates - Update to 4.20.3 * Always warn user before permanent deleting files * Fix string leaks when UCAs use a submenu * Fix a potential leak in thunar_action_manager_append_custom_actions * Fix leaks with ThunarMenuX objects * Fix thunarx_menu_get_items leak when multiple UCAs share a submenu * Fix refresh on row-changed in list view (#1584) * Add missing NULL check before unref call * Fix popup position of DnD menu * UCA: Correct PWD for submenu folder items (#1615) * wayland: Fix popup menu not closing (#1592) * Check if file exists before opening its location (#1257) * Prevent popups on wrong window (#1591) * thunar-tpa: Fix libxfce4panel include * Prevent criticals when switching current view (#1344) * Fix crash when destroying folder in list view (#1330) (#1568) * Fix crash in properties dialog (#1585) * Fix invalid filenames when copying to exFAT FS (#1570) * Fix typo in preferences dialog * Hide shortcuts editor when accel map uninitialized (#1488) * Update statusbar when searching (#1560) * Always update statusbar on file changes in list view (#1560) * Fix item activation on double-click in list view (#1567) * Use 'malloc_trim' after search (#1552) * Fix missing dialog for folder errors in list view (#1538) * Fix leak on search update * Fix missing dialog window icon (#1506) * Fix leaks on "cancel search" * Properly check if a file can be trashed (#1554) * Translation Updates Changes in thunar-vcs-plugin: - Update to 0.4.0: Meson has been added as a build system in this release, and the associated archive has been generated by 'meson dist'. Although autotools has been retained for the time being and can still be used via 'autogen.sh', meson is now the preferred build system, and autotools will be removed in a future release. * Update README after switchover to meson * Fix a ThunarxMenu leak in tvp_svn_action_create_menu_item * Fix a ThunarxMenu leak in tvp_git_action_create_menu_item * Fix string leaks in git-log parser * Fix warnings * Add support to Meson * Fix a -Wunused-macros warning with GCC * Replace deprecated exo with libxfce4ui 4.21.0 * Translation Updates - Don't install the ...16x16/apps/subversion.png icon as it creates a file conflict with package kdevelop. Changes in tumbler: - Update to version 4.20.1: * Update Copyright year * gepub-thumbnailer: Get pixbuf in "area-prepared" signal handler * gst-thumbnailer: Fix TumblerThumbnailFlavor leak * ffmpeg-thumbnailer: Update mime type list from upstream desktop file * xdg-cache: Fix TumblerThumbnailFlavor leaks * cover-thumbnailer: Capture regex matchinfo for series episodes * cover-thumbnailer: Update the base URL for TMDB * cover-thumbnailer: Use correct parameter types with curl * poppler-thumbnailer: Only use embedded thumbnail if resolution suffices * gst-thumbnailer: Make mime type checking more flexible * Translation Updates - Replace packageand(package1:package2) with (package1 and package2) - tumbler-folder-thumbnailer and tumbler-webp-thumbnailer are noarch packages. Changes in xfburn: - Update to version 0.8.0 * Add support for Meson * Support large BD discs (thanks @ToddAWalter) * Check for ID_TYPE "cd/dvd" (thanks @luik) * Update xfburn.desktop.in file * Replace deprecated exo with libxfce4ui 4.21.0 * Remove dead code * I18n: Update po/LINGUAS list * Translation Updates Changes in xfce4-battery-plugin: - Update to version 1.2.0 Meson has been added as a build system in this release, and the associated archive has been generated by 'meson dist'. Although autotools has been retained for the time being and can still be used via 'autogen.sh', meson is now the preferred build system, and autotools will be removed in a future release. * Update README after switchover to meson * build: Automate copyright year management * meson-build: Use shared_module() * Replace deprecated exo with libxfce4ui 4.21.0 * meson-build: Do not install Makefile.in * build: Use VERSION_FULL instead of PACKAGE_VERSION * Add meson build * Translation Updates Changes in xfce4-calculator-plugin: - Update to version 0.8.0: Meson has been added as a build system in this release, and the associated archive has been generated by 'meson dist'. Although autotools has been retained for the time being and can still be used via 'autogen.sh', meson is now the preferred build system, and autotools will be removed in a future release. * Update README after switchover to meson * autotools-build: Explicitly require glib, gtk3 * build: Automate copyright year management * meson-build: Use shared_module() * I18n: Update po/LINGUAS list * build: Fix -Werror={missing-declarations,old-style-definition} * Add meson build * Remove generated gmon.out * tests: Use PATH to search for calctest program * I18n: Update po/LINGUAS list * Translation Updates Changes in xfce4-clipman-plugin: - Update to version 1.7.0: Meson has been added as a build system in this release, and the associated archive has been generated by 'meson dist'. Although autotools has been retained for the time being and can still be used via 'autogen.sh', meson is now the preferred build system, and autotools will be removed in a future release. * Update README after switchover to meson * build: Automate copyright year management * build: Replace xdt-csource with glib-compile-resources * meson-build: Use shared_module() * Replace deprecated exo with libxfce4ui 4.21.0 * Use HTTPS for action URLs * history: Add missing sanity checks * history: Update size when max values change at runtime * history: Fix truncation when max_images changes * collector: Avoid default clipboard restoration while waiting for image * tests: Print more test results * gcc-analyzer: Adapt regexes to meson * Add meson build * build: Add missing dep flags * Translation Updates Changes in xfce4-cpufreq-plugin: - Update to version 1.3.0: Meson has been added as a build system in this release, and the associated archive has been generated by 'meson dist'. Although autotools has been retained for the time being and can still be used via 'autogen.sh', meson is now the preferred build system, and autotools will be removed in a future release. * Update README after switchover to meson * build: Automate copyright year management * meson-build: Use shared_module() * build: Add missing check for malloc_trim * Add meson build * autotools-build: Remove gthread-2.0 dependency * autotools-build: Don't build libxfce4_pp * overview: Make cpufreq overview scrollable * I18n: Update po/LINGUAS list * Translation Updates Changes in xfce4-cpugraph-plugin: - Update to version 1.3.0 - Update README after switchover to meson - autotools-build: Explicitly require glib, gtk3, libxfce4util - build: Automate copyright year management - meson-build: Use shared_module() - cpu.h: Fix -Wundef warning - Add meson build - Translation Updates Changes in xfce4-dict: - Update to version 0.8.9 * Hide web search link in results if not set * Fix enchant binary names * autotools-build: Add missing compile flags * meson-build: Remove --manual-register flag from compile_resources() * Replace deprecated exo with libxfce4ui 4.21.0 * Meson version can be older * build: Automate copyright year management * Add suport to Meson * I18n: Update po/LINGUAS list * Remove x11 includes * Drop libx11 as dependency * Translation Updates Changes in xfce4-diskperf-plugin: - Update to version 2.8.0 - Update README after switchover to meson - autotools-build: Explicitly require glib, gtk3, libxfce4util - build: Automate copyright year management - meson-build: Use shared_module() - Add meson build - I18n: Update po/LINGUAS list - Translation Updates Changes in xfce4-docklike-plugin: - Update to version 0.5.0 - Update README after switchover to meson - Add missing files to translate and fix about dialog - Fix licensing - GroupMenuItem: Show window action menu as context menu - Group: Remove window action menu from context menu - x11: Add exceptions where instance-id should be preferred to class-id - Group: Don't show group menu when context menu is shown - Allow user to create a launcher if not found - AppInfos: Print a warning if app launch fails - cleanup: AppInfos: Use class member instead of creating new object - cleanup: AppInfos: Use naming conventions of other objects - AppInfos: Avoid using hard-coded aliases - Allow user to manually select a launcher if not found - Helpers: Extend String::pathBasename and use it everywhere - AppInfos: Extend excluded binary list and use a container - cleanup: Replace NULL/TRUE with nullptr/true - autotools-build: Explicitly require libxfce4util - build: Automate copyright year management - meson-build: Use shared_module() - Activate/minimize all group windows on left click on the group icon - Replace deprecated exo with libxfce4ui 4.21.0 - Group: Reset mTopWindowIndex when it becomes out of bounds - Revert "Group: Reset mTopWindowIndex when active window becomes inactive" - Group: Reset mTopWindowIndex when active window becomes inactive - Fix several issues with context menu for undockable apps - Fix memory leak when getting indicator color from theme - Add meson build - autotools-build: Require libXi - {State,Store}.ipp: Renamed from {State,Store}.tpp - I18n: Update po/LINGUAS list - Translation Updates Changes in xfce4-eyes-plugin: - Update to version 4.7.0 - Update README after switchover to meson - autotools-build: Explicitly require libxfce4util - build: Automate copyright year management - meson-build: Use shared_module() - Add about dialog - Add meson build - themes: Unify capitalization in file names - Translation Updates Changes in xfce4-fsguard-plugin: - Update to version 1.2.0 - Update README after switchover to meson - autotools-build: Explicitly require glib, gtk3 - build: Automate copyright year management - meson-build: Use shared_module() - Replace deprecated exo with libxfce4ui 4.21.0 - Add about dialog - Add meson build - Fix memory leak - Translation Updates Changes in xfce4-genmon-plugin: - Update to version 4.3.0 - Update README after switchover to meson - autotools-build: Explicitly require glib, gtk3 - meson-build: Use shared_module() - Replace deprecated exo with libxfce4ui 4.21.0 - build: Automate copyright year management - Add meson build - autotools-build: Explicitly require libxfce4util - Fix libxfce4panel include - Translation Updates Changes in xfce4-mailwatch-plugin: - Update to version 1.4.0 * autotools-build: Explicitly require libxfce4util * meson-build: Use shared_module() * Replace deprecated exo with libxfce4ui 4.21.0 * build: Automate copyright year management * Add meson build * Fix incomplete use of XfceTitledDialog * Translation Updates Changes in xfce4-mount-plugin: - Update to version 1.2.0 * autotools-build: Explicitly require glib, gtk3 * meson-build: Use shared_module() * Replace deprecated exo with libxfce4ui 4.21.0 * gcc-analyzer: Adapt regexes to meson * README: Remove outdated version info * build: Automate copyright year management * Add meson build * autotools-build: Explicitly require libxfce4util * Fix libxfce4panel include * Translation Updates Changes in xfce4-mpc-plugin: - Update to version 0.6.0 * autotools-build: Explicitly require glib, gtk3 * meson-build: Use shared_module() * build: Automate copyright year management * Add meson build * autotools-build: Explicitly require libxfce4util * Reapply "build: Use #ifdef instead of #if" * Only define HAVE_LIBMPD when libmpd is found * Translation Updates Changes in xfce4-netload-plugin: - Update to version 1.5.0 * meson-build: Use shared_module() * commandline: Fix -Werror={missing-declarations,suggest-attribute=noreturn} * build: Automate copyright year management * Add meson build * netload: Fix link to wiki page * autotools-build: Fix typo * autotools-build: Explicitly require glib, gtk3, libxfce4util * Translation Updates Changes in xfce4-notes-plugin: - Update to version 1.12.0 * meson-build: Use shared_module() * Replace deprecated exo with libxfce4ui 4.21.0 * build: Automate copyright year management * Add meson build * Translation Updates Changes in xfce4-panel-profiles: - Update to version 1.1.1 - build: Allow skip checking runtime dependencies - Parameterize version and copyright year in man page - Bump version in configure - Update to version 1.1.0 - Update README after switchover to meson - build: Automate copyright year management - org.xfce.PanelProfiles.desktop: Unbreak desktop-file-validate - build: Require libxfce4ui 4.16.0 - Add about dialog - Add meson build - Deprecated exo with libxfce4ui 4.21.0 - I18n: Update po/LINGUAS list - Save and restore launchers as is - Translation Updates Changes in xfce4-panel: - Update to version 4.20.5 * wayland: panel: Ensure panel window is shown at least once * panel: Don't show panel window too early * panel: Restrict X-XFCE-Unique=SCREEN to X11 * Fix string comparison when searching for plugin dirs * wayland: Support multiple workspace groups where it makes sense * tasklist: Deactivate context menu when its button is destroyed * x11: Let GtkSocket expand if possible * libxfce4panel: Restore possibility to oversize icons * wayland: autohide: Try to trigger size_allocate() more reliably * panel: Show window when new output is connected * Translation Updates Changes in xfce4-places-plugin: - Update to version 1.9.0 * Replace deprecated exo with libxfce4ui 4.21.0 * build: Require gio-unix-2.0 * build: Automate copyright year management * Add meson build * Add about dialog * I18n: Update po/LINGUAS list * Translation Updates Changes in xfce4-screenshooter: - Update to 1.11.2 * Fully free a GSList to fix a leak * Fix a string leak in screenshooter_get_filename_for_uri * Properly free a GdkPixbuf to fix a leak * meson-build: Fix manpage install dir * Improve selection background in black surfaces * Fix xfce_resource_save_location leak in main * Replace deprecated exo with libxfce4ui 4.21.0 * Remove imgur upload custom action automatically * Fix build with autotools * Drop Imgur custom action * preferences: Add link to the documentation for custom actions examples * Add support to Meson * Update xfce4-screenshooter.1 * Fix segfault in another location * Fix segfault when app command is NULL (#132) * Improved imgur upload script * Add support to WL_SHM_FORMAT_BGR888 * Check if file was correctly open before using it * Revert "Only restrict file permissions after sucessfully writing them" * Fix blurred preview images at scale >1 * Only restrict file permissions after sucessfully writing them * Translation Updates Changes in xfce4-sensors-plugin: - Update to version 1.5.0 * build: Automate copyright year management * Add meson build * autotools-build: xfce4-sensors.1.in -> xfce4-sensors.1 * autotools-build: Remove spec files * autotools-build: Make libxfce4sensors internal * autotools-build: Don't build libxfce4_pp * Fix libxfce4panel include * Translation Updates Changes in xfce4-session: - Add mic-mute and Windows-key handling for Wayland labwc (boo#1248802) - Yet more default key binding for Wayland labwc (boo#1248802) - Add more default key bindings for Wayland with labwc (boo#1248802): - Drop the previous workaround patch for wayland startup (boo#1247542): - Reduce the timeout for auto-start on Wayland (boo#1247542); This is a temporary workaround for the too slow start-up on Wayland desktop. Currently the error is ignored in anyway. - Use '?' for SUSE macro expansion, so that quilt setup works. - Update to version 4.20.3: * wayland: startxfce4: Remove definition of SDL_VIDEODRIVER variable * Add xapp for Settings in xfce-portals.conf * startxfce4: Add check for /etc/vconsole.conf * labwc: Add some default config values * xfce-portals.conf: Add wlr for ScreenCast * startxfce4: Improve keyboard layout detection on wayland * wayland: start a D-Bus session only if there isn't one already * Use syntax compatible with most sh shells. * labwc: Add window snapping range - Fix the audio mixer invocation on Wayland (boo#1247640): Changes in xfce4-settings: - Update to version 4.20.2: * display: Add/improve some debug logs * wayland: displays: Don't wl_display_roundtrip() on new output * settings-editor: Fix -Wcomma warning * common: Fix memory leak * common: Be more secure when parsing pnp.ids file * x11: display: Properly take XRRModeFlags into account * xfsettingsd: Use 2 decimals in warning about unknown mode * build: Fix resource not found at runtime * build: Automate copyright year management * build: Replace xdt-csource with glib-compile-resources * build: Define xfce4 min version >= 4.18 * display-settings: Add missing update of /ActiveProfile * Translation Updates Changes in xfce4-smartbookmark-plugin: - Update to version 0.6.0 - Update README after switchover to meson - build: Automate copyright year management - Add meson build - Add about dialog - Replace deprecated exo with libxfce4ui 4.21.0 - Translation Updates Changes in xfce4-stopwatch-plugin: - Update to 0.6.0 - Update README after switchover to meson - build: Automate copyright year management - Add meson build - Add about dialog - autotools-build: Avoid versioning libstopwatch - I18n: Update po/LINGUAS list - Translation Updates Changes in xfce4-systemload-plugin: - Update to 1.4.0 - Update README after switchover to meson - build: Automate copyright year management - Add meson build - autotools-build: Explicitly require glib, gtk3, libxfce4util - Fix libxfce4panel include - Translation Updates Changes in xfce4-taskmanager: - Update to version 1.6.0 - Update README after switchover to meson - process-window: Fix wrong use of g_signal_emit_by_name() - Fix process window being destroyed when status icon is visible - Remove manual registration of resources - Unify gresource files - Add support to Meson - build: Add missing dep flags - Translation Update Changes in xfce4-time-out-plugin: - Update to version 1.2.0 - Update README after switchover to meson - build: Automate copyright year management - Add meson build - autotools-build: Explicitly require libxfce4util - Fix libxfce4panel include - Translation Updates Changes in xfce4-timer-plugin: - Update to version 1.8.0 - Update README after switchover to meson - build: Automate copyright year management - Add meson build - Translation Updates Changes in xfce4-verve-plugin: - Update to version 2.1.0 - Update README after switchover to meson - build: Automate copyright year management - Add meson build - Add about dialog - build: Remove unused verve-dbus-service code - Replace deprecated exo with libxfce4ui 4.21.0 - Fix libxfce4panel include Changes in xfce4-wavelan-plugin: - Update to version 0.7.0 - Update README after switchover to meson - build: Automate copyright year management - Add meson build - Remove unused inline-icons.h - autotools-build: Explicitly require libxfce4util - Translation Updates Changes in xfce4-weather-plugin: - Update to 0.12.0 - Update README after switchover to meson - build: Automate copyright year management - Add meson build - build: Replace xdt-csource with glib-compile-resources - Replace deprecated exo with libxfce4ui 4.21.0 - prefs-dialog: Fix help button behavior - prefs-dialog: Fix typo - build: Bump dependency versions and fix deprecation warnings - I18n: Update po/LINGUAS list - I18n: Update po/LINGUAS list - Alignment fixes, only use single row when labels not shown - Make libsoup v3 support optional - Report UPower Glib support - libsoup: Port to libsoup-3.0 - parsers: Generalise input to array of gchar - libxfce4ui: Avoid deprecated functions - Translation Updates Changes in xfce4-whiskermenu-plugin: - Update to version 2.10.0 - Add meson build - po: Add LINGUAS and POTFILES - Remove outdated install instructions - Remove unused search flags variable - Replace deprecated exo with libxfce4ui 4.21.0 - Fix missing declaration warning - Fix shadowed variables - Fix unused lambda capture warning - Translation Updates Changes in xfce4-xkb-plugin: - Update to version 0.9.0 - Update README after switchover to meson - Remove vertical white line at left in the Mexican SVG flag (mx.svg) - Fix corrupted Argentinian SVG flag (ar.svg) - Optimize SVG flags using SVGO (https://github.com/svg/svgo) - build: Automate copyright year management - Add meson build - autotools-build: Install flags/me.svg - Fix libxfce4panel include - Translation Updates Changes in xfdashboard: - Update to 1.1.0 * Update README after switchover to meson * build: Fix -Wunused-but-set-variable * x11: Set wnck client type at the very first call * build: Fix -Werror=undef * Add meson build * build: Automate copyright year management * build: Unbreak example-search-provider * build: Install version.h * build: Drop dead code with glib 2.66 * build: Require clutter 1.24.0 * build: Require xfce 4.16.0 * build: Require gtk 3.22.0 * Replace deprecated exo with libxfce4ui 4.21.0 * I18n: Update po/LINGUAS list * I18n: Update po/LINGUAS list * I18n: Update po/LINGUAS list * I18n: Update po/LINGUAS list * xfdashboard: Fix translation in g_option_context_set_summary * build: Fix gettext warning about empty string * build: Use XDT_VERSION_INIT and get rid of configure.ac.in * build: Workaround *.theme translation * build: Switch from intltool to gettext * build: Fix deprecation warnings from glib * build: Fix redefined glib macros * build: Add new debug option to AS_CASE * Raise required minimum version of Glib 2.66 due to some functions of Glib used without #ifdef's and alternatives * Add icons at missing sizes, clean up SVG metadata * Remove ENABLE_NLS ifdefs * Post-release version bump to 1.1.0 * Translation Updates - Regenerate xfdashboard-desktop-category.diff and xfdashboard-desktopfile-without-binary.diff - Add xfdashboard-relax-some-package-versions.diff - Rewrite the "tee -a" construct to avoid compressed binary data being sent to stdout and cluttering the output - Add xfdashboard-rpmlintrc to avoid an unnecessary complex package name for libxdashboard0 - Add "-lm" to CFLAGS on Leap 15.6, because libxfdashboard0.so doesn't get automatically linked with libm. Changes in xfdesktop: - Switch to using meson for building; this allows building this package even in the upcoming development release Xfce-4.21 - Remove bcond_with git and related items - Ensure installed icon files land in _datadir/wallpapers/xfce, not in _datadir/backgrounds/xfce which is used by meson - Fix the monitor name pickup on Wayland, which resulted in broken background picture setup (boo#1247542): - Fix missing backslash for building in non-git mode Changes in xfmpc: - Update to 0.4.0 - Update README after switchover to meson - Add support to Meson - Add search shortcuts - Translation Updates catfish-4.20.1-bp157.3.3.1.noarch.rpm catfish-4.20.1-bp157.3.3.1.src.rpm catfish-lang-4.20.1-bp157.3.3.1.noarch.rpm elementary-xfce-icon-theme-0.21+git12.dff5c11f-bp157.2.3.1.noarch.rpm elementary-xfce-icon-theme-0.21+git12.dff5c11f-bp157.2.3.1.src.rpm gigolo-0.6.0-bp157.2.3.1.src.rpm gigolo-0.6.0-bp157.2.3.1.x86_64.rpm gigolo-debuginfo-0.6.0-bp157.2.3.1.x86_64.rpm gigolo-debugsource-0.6.0-bp157.2.3.1.x86_64.rpm gigolo-lang-0.6.0-bp157.2.3.1.noarch.rpm libxfce4kbd-private-3-0-4.20.2-bp157.2.3.1.x86_64.rpm libxfce4kbd-private-3-0-debuginfo-4.20.2-bp157.2.3.1.x86_64.rpm libxfce4ui-2-0-4.20.2-bp157.2.3.1.x86_64.rpm libxfce4ui-2-0-debuginfo-4.20.2-bp157.2.3.1.x86_64.rpm libxfce4ui-4.20.2-bp157.2.3.1.src.rpm libxfce4ui-branding-upstream-4.20.2-bp157.2.3.1.noarch.rpm libxfce4ui-debuginfo-4.20.2-bp157.2.3.1.x86_64.rpm libxfce4ui-debugsource-4.20.2-bp157.2.3.1.x86_64.rpm libxfce4ui-devel-4.20.2-bp157.2.3.1.x86_64.rpm libxfce4ui-devel-debuginfo-4.20.2-bp157.2.3.1.x86_64.rpm libxfce4ui-doc-4.20.2-bp157.2.3.1.noarch.rpm libxfce4ui-lang-4.20.2-bp157.2.3.1.noarch.rpm libxfce4ui-tools-4.20.2-bp157.2.3.1.x86_64.rpm libxfce4ui-tools-debuginfo-4.20.2-bp157.2.3.1.x86_64.rpm typelib-1_0-Libxfce4ui-2_0-4.20.2-bp157.2.3.1.x86_64.rpm libxfce4windowing-0-0-4.20.4-bp157.2.3.1.x86_64.rpm libxfce4windowing-0-0-debuginfo-4.20.4-bp157.2.3.1.x86_64.rpm libxfce4windowing-4.20.4-bp157.2.3.1.src.rpm libxfce4windowing-debuginfo-4.20.4-bp157.2.3.1.x86_64.rpm libxfce4windowing-debugsource-4.20.4-bp157.2.3.1.x86_64.rpm libxfce4windowing-devel-4.20.4-bp157.2.3.1.x86_64.rpm libxfce4windowing-devel-doc-4.20.4-bp157.2.3.1.noarch.rpm libxfce4windowing-lang-4.20.4-bp157.2.3.1.noarch.rpm libxfce4windowingui-0-0-4.20.4-bp157.2.3.1.x86_64.rpm libxfce4windowingui-0-0-debuginfo-4.20.4-bp157.2.3.1.x86_64.rpm typelib-1_0-Libxfce4windowing-0_0-4.20.4-bp157.2.3.1.x86_64.rpm typelib-1_0-Libxfce4windowingui-0_0-4.20.4-bp157.2.3.1.x86_64.rpm menulibre-2.4.0-bp157.3.3.1.noarch.rpm menulibre-2.4.0-bp157.3.3.1.src.rpm menulibre-lang-2.4.0-bp157.3.3.1.noarch.rpm orage-4.20.2-bp157.2.3.1.src.rpm orage-4.20.2-bp157.2.3.1.x86_64.rpm orage-debuginfo-4.20.2-bp157.2.3.1.x86_64.rpm orage-debugsource-4.20.2-bp157.2.3.1.x86_64.rpm orage-lang-4.20.2-bp157.2.3.1.noarch.rpm parole-4.20.0-bp157.2.3.1.src.rpm parole-4.20.0-bp157.2.3.1.x86_64.rpm parole-debuginfo-4.20.0-bp157.2.3.1.x86_64.rpm parole-debugsource-4.20.0-bp157.2.3.1.x86_64.rpm parole-devel-4.20.0-bp157.2.3.1.x86_64.rpm parole-lang-4.20.0-bp157.2.3.1.noarch.rpm pragha-1.3.99.1-bp157.2.3.1.src.rpm pragha-1.3.99.1-bp157.2.3.1.x86_64.rpm pragha-debuginfo-1.3.99.1-bp157.2.3.1.x86_64.rpm pragha-debugsource-1.3.99.1-bp157.2.3.1.x86_64.rpm pragha-lang-1.3.99.1-bp157.2.3.1.noarch.rpm pragha-plugins-1.3.99.1-bp157.2.3.1.x86_64.rpm pragha-plugins-debuginfo-1.3.99.1-bp157.2.3.1.x86_64.rpm pragha-plugins-devel-1.3.99.1-bp157.2.3.1.x86_64.rpm thunar-archive-plugin-0.6.0-bp157.2.3.1.src.rpm thunar-archive-plugin-0.6.0-bp157.2.3.1.x86_64.rpm thunar-archive-plugin-debuginfo-0.6.0-bp157.2.3.1.x86_64.rpm thunar-archive-plugin-debugsource-0.6.0-bp157.2.3.1.x86_64.rpm thunar-archive-plugin-lang-0.6.0-bp157.2.3.1.noarch.rpm thunar-media-tags-plugin-0.6.0-bp157.2.3.1.src.rpm thunar-media-tags-plugin-0.6.0-bp157.2.3.1.x86_64.rpm thunar-media-tags-plugin-debuginfo-0.6.0-bp157.2.3.1.x86_64.rpm thunar-media-tags-plugin-debugsource-0.6.0-bp157.2.3.1.x86_64.rpm thunar-media-tags-plugin-lang-0.6.0-bp157.2.3.1.noarch.rpm thunar-shares-plugin-0.5.0-bp157.2.3.1.src.rpm thunar-shares-plugin-0.5.0-bp157.2.3.1.x86_64.rpm thunar-shares-plugin-debuginfo-0.5.0-bp157.2.3.1.x86_64.rpm thunar-shares-plugin-debugsource-0.5.0-bp157.2.3.1.x86_64.rpm thunar-shares-plugin-lang-0.5.0-bp157.2.3.1.noarch.rpm thunar-vcs-plugin-0.4.0-bp157.2.3.1.src.rpm thunar-vcs-plugin-0.4.0-bp157.2.3.1.x86_64.rpm thunar-vcs-plugin-debuginfo-0.4.0-bp157.2.3.1.x86_64.rpm thunar-vcs-plugin-debugsource-0.4.0-bp157.2.3.1.x86_64.rpm thunar-vcs-plugin-lang-0.4.0-bp157.2.3.1.noarch.rpm libthunarx-3-0-4.20.6-bp157.2.3.2.x86_64.rpm libthunarx-3-0-debuginfo-4.20.6-bp157.2.3.2.x86_64.rpm thunar-4.20.6-bp157.2.3.2.src.rpm thunar-4.20.6-bp157.2.3.2.x86_64.rpm thunar-debuginfo-4.20.6-bp157.2.3.2.x86_64.rpm thunar-debugsource-4.20.6-bp157.2.3.2.x86_64.rpm thunar-devel-4.20.6-bp157.2.3.2.x86_64.rpm thunar-lang-4.20.6-bp157.2.3.2.noarch.rpm typelib-1_0-Thunarx-3_0-4.20.6-bp157.2.3.2.x86_64.rpm libtumbler-1-0-4.20.1-bp157.3.3.1.x86_64.rpm libtumbler-1-0-debuginfo-4.20.1-bp157.3.3.1.x86_64.rpm tumbler-4.20.1-bp157.3.3.1.src.rpm tumbler-4.20.1-bp157.3.3.1.x86_64.rpm tumbler-debuginfo-4.20.1-bp157.3.3.1.x86_64.rpm tumbler-debugsource-4.20.1-bp157.3.3.1.x86_64.rpm tumbler-devel-4.20.1-bp157.3.3.1.x86_64.rpm tumbler-doc-4.20.1-bp157.3.3.1.noarch.rpm tumbler-folder-thumbnailer-4.20.1-bp157.3.3.1.noarch.rpm tumbler-lang-4.20.1-bp157.3.3.1.noarch.rpm tumbler-webp-thumbnailer-4.20.1-bp157.3.3.1.noarch.rpm xfburn-0.8.0-bp157.2.3.1.src.rpm xfburn-0.8.0-bp157.2.3.1.x86_64.rpm xfburn-debuginfo-0.8.0-bp157.2.3.1.x86_64.rpm xfburn-debugsource-0.8.0-bp157.2.3.1.x86_64.rpm xfburn-lang-0.8.0-bp157.2.3.1.noarch.rpm xfce4-battery-plugin-1.2.0-bp157.2.3.1.src.rpm xfce4-battery-plugin-1.2.0-bp157.2.3.1.x86_64.rpm xfce4-battery-plugin-debuginfo-1.2.0-bp157.2.3.1.x86_64.rpm xfce4-battery-plugin-debugsource-1.2.0-bp157.2.3.1.x86_64.rpm xfce4-battery-plugin-lang-1.2.0-bp157.2.3.1.noarch.rpm xfce4-calculator-plugin-0.8.0-bp157.2.3.1.src.rpm xfce4-calculator-plugin-0.8.0-bp157.2.3.1.x86_64.rpm xfce4-calculator-plugin-debuginfo-0.8.0-bp157.2.3.1.x86_64.rpm xfce4-calculator-plugin-debugsource-0.8.0-bp157.2.3.1.x86_64.rpm xfce4-calculator-plugin-lang-0.8.0-bp157.2.3.1.noarch.rpm xfce4-clipman-plugin-1.7.0-bp157.2.3.1.src.rpm xfce4-clipman-plugin-1.7.0-bp157.2.3.1.x86_64.rpm xfce4-clipman-plugin-debuginfo-1.7.0-bp157.2.3.1.x86_64.rpm xfce4-clipman-plugin-debugsource-1.7.0-bp157.2.3.1.x86_64.rpm xfce4-clipman-plugin-lang-1.7.0-bp157.2.3.1.noarch.rpm xfce4-cpufreq-plugin-1.3.0-bp157.2.3.2.src.rpm xfce4-cpufreq-plugin-1.3.0-bp157.2.3.2.x86_64.rpm xfce4-cpufreq-plugin-debuginfo-1.3.0-bp157.2.3.2.x86_64.rpm xfce4-cpufreq-plugin-debugsource-1.3.0-bp157.2.3.2.x86_64.rpm xfce4-cpufreq-plugin-lang-1.3.0-bp157.2.3.2.noarch.rpm xfce4-cpugraph-plugin-1.3.0-bp157.2.3.2.src.rpm xfce4-cpugraph-plugin-1.3.0-bp157.2.3.2.x86_64.rpm xfce4-cpugraph-plugin-debuginfo-1.3.0-bp157.2.3.2.x86_64.rpm xfce4-cpugraph-plugin-debugsource-1.3.0-bp157.2.3.2.x86_64.rpm xfce4-cpugraph-plugin-lang-1.3.0-bp157.2.3.2.noarch.rpm xfce4-dict-0.8.9-bp157.2.3.1.src.rpm xfce4-dict-0.8.9-bp157.2.3.1.x86_64.rpm xfce4-dict-debuginfo-0.8.9-bp157.2.3.1.x86_64.rpm xfce4-dict-debugsource-0.8.9-bp157.2.3.1.x86_64.rpm xfce4-dict-lang-0.8.9-bp157.2.3.1.noarch.rpm xfce4-panel-plugin-dict-0.8.9-bp157.2.3.1.x86_64.rpm xfce4-panel-plugin-dict-debuginfo-0.8.9-bp157.2.3.1.x86_64.rpm xfce4-diskperf-plugin-2.8.0-bp157.2.3.2.src.rpm xfce4-diskperf-plugin-2.8.0-bp157.2.3.2.x86_64.rpm xfce4-diskperf-plugin-debuginfo-2.8.0-bp157.2.3.2.x86_64.rpm xfce4-diskperf-plugin-debugsource-2.8.0-bp157.2.3.2.x86_64.rpm xfce4-diskperf-plugin-lang-2.8.0-bp157.2.3.2.noarch.rpm xfce4-docklike-plugin-0.5.0-bp157.2.3.2.src.rpm xfce4-docklike-plugin-0.5.0-bp157.2.3.2.x86_64.rpm xfce4-docklike-plugin-debuginfo-0.5.0-bp157.2.3.2.x86_64.rpm xfce4-docklike-plugin-debugsource-0.5.0-bp157.2.3.2.x86_64.rpm xfce4-docklike-plugin-lang-0.5.0-bp157.2.3.2.noarch.rpm xfce4-eyes-plugin-4.7.0-bp157.2.3.2.src.rpm xfce4-eyes-plugin-4.7.0-bp157.2.3.2.x86_64.rpm xfce4-eyes-plugin-debuginfo-4.7.0-bp157.2.3.2.x86_64.rpm xfce4-eyes-plugin-debugsource-4.7.0-bp157.2.3.2.x86_64.rpm xfce4-eyes-plugin-lang-4.7.0-bp157.2.3.2.noarch.rpm xfce4-fsguard-plugin-1.2.0-bp157.2.3.2.src.rpm xfce4-fsguard-plugin-1.2.0-bp157.2.3.2.x86_64.rpm xfce4-fsguard-plugin-debuginfo-1.2.0-bp157.2.3.2.x86_64.rpm xfce4-fsguard-plugin-debugsource-1.2.0-bp157.2.3.2.x86_64.rpm xfce4-fsguard-plugin-lang-1.2.0-bp157.2.3.2.noarch.rpm xfce4-genmon-plugin-4.3.0-bp157.2.3.2.src.rpm xfce4-genmon-plugin-4.3.0-bp157.2.3.2.x86_64.rpm xfce4-genmon-plugin-debuginfo-4.3.0-bp157.2.3.2.x86_64.rpm xfce4-genmon-plugin-debugsource-4.3.0-bp157.2.3.2.x86_64.rpm xfce4-genmon-plugin-lang-4.3.0-bp157.2.3.2.noarch.rpm xfce4-mailwatch-plugin-1.4.0-bp157.2.3.1.src.rpm xfce4-mailwatch-plugin-1.4.0-bp157.2.3.1.x86_64.rpm xfce4-mailwatch-plugin-debuginfo-1.4.0-bp157.2.3.1.x86_64.rpm xfce4-mailwatch-plugin-debugsource-1.4.0-bp157.2.3.1.x86_64.rpm xfce4-mailwatch-plugin-lang-1.4.0-bp157.2.3.1.noarch.rpm xfce4-mount-plugin-1.2.0-bp157.2.3.2.src.rpm xfce4-mount-plugin-1.2.0-bp157.2.3.2.x86_64.rpm xfce4-mount-plugin-debuginfo-1.2.0-bp157.2.3.2.x86_64.rpm xfce4-mount-plugin-debugsource-1.2.0-bp157.2.3.2.x86_64.rpm xfce4-mount-plugin-lang-1.2.0-bp157.2.3.2.noarch.rpm xfce4-mpc-plugin-0.6.0-bp157.2.3.2.src.rpm xfce4-mpc-plugin-0.6.0-bp157.2.3.2.x86_64.rpm xfce4-mpc-plugin-debuginfo-0.6.0-bp157.2.3.2.x86_64.rpm xfce4-mpc-plugin-debugsource-0.6.0-bp157.2.3.2.x86_64.rpm xfce4-mpc-plugin-lang-0.6.0-bp157.2.3.2.noarch.rpm xfce4-netload-plugin-1.5.0-bp157.2.3.2.src.rpm xfce4-netload-plugin-1.5.0-bp157.2.3.2.x86_64.rpm xfce4-netload-plugin-debuginfo-1.5.0-bp157.2.3.2.x86_64.rpm xfce4-netload-plugin-debugsource-1.5.0-bp157.2.3.2.x86_64.rpm xfce4-netload-plugin-lang-1.5.0-bp157.2.3.2.noarch.rpm xfce4-notes-plugin-1.12.0-bp157.2.3.2.src.rpm xfce4-notes-plugin-1.12.0-bp157.2.3.2.x86_64.rpm xfce4-notes-plugin-debuginfo-1.12.0-bp157.2.3.2.x86_64.rpm xfce4-notes-plugin-debugsource-1.12.0-bp157.2.3.2.x86_64.rpm xfce4-notes-plugin-lang-1.12.0-bp157.2.3.2.noarch.rpm xfce4-panel-profiles-1.1.1-bp157.2.3.1.noarch.rpm xfce4-panel-profiles-1.1.1-bp157.2.3.1.src.rpm libxfce4panel-2_0-4-4.20.5-bp157.2.3.1.x86_64.rpm libxfce4panel-2_0-4-debuginfo-4.20.5-bp157.2.3.1.x86_64.rpm typelib-1_0-Libxfce4panel-2_0-4.20.5-bp157.2.3.1.x86_64.rpm xfce4-panel-4.20.5-bp157.2.3.1.src.rpm xfce4-panel-4.20.5-bp157.2.3.1.x86_64.rpm xfce4-panel-branding-upstream-4.20.5-bp157.2.3.1.noarch.rpm xfce4-panel-debuginfo-4.20.5-bp157.2.3.1.x86_64.rpm xfce4-panel-debugsource-4.20.5-bp157.2.3.1.x86_64.rpm xfce4-panel-devel-4.20.5-bp157.2.3.1.x86_64.rpm xfce4-panel-lang-4.20.5-bp157.2.3.1.noarch.rpm xfce4-panel-restore-defaults-4.20.5-bp157.2.3.1.x86_64.rpm xfce4-places-plugin-1.9.0-bp157.2.3.1.src.rpm xfce4-places-plugin-1.9.0-bp157.2.3.1.x86_64.rpm xfce4-places-plugin-debuginfo-1.9.0-bp157.2.3.1.x86_64.rpm xfce4-places-plugin-debugsource-1.9.0-bp157.2.3.1.x86_64.rpm xfce4-places-plugin-lang-1.9.0-bp157.2.3.1.noarch.rpm xfce4-screenshooter-1.11.2-bp157.2.3.1.src.rpm xfce4-screenshooter-1.11.2-bp157.2.3.1.x86_64.rpm xfce4-screenshooter-debuginfo-1.11.2-bp157.2.3.1.x86_64.rpm xfce4-screenshooter-debugsource-1.11.2-bp157.2.3.1.x86_64.rpm xfce4-screenshooter-lang-1.11.2-bp157.2.3.1.noarch.rpm xfce4-screenshooter-plugin-1.11.2-bp157.2.3.1.x86_64.rpm xfce4-screenshooter-plugin-debuginfo-1.11.2-bp157.2.3.1.x86_64.rpm xfce4-sensors-plugin-1.5.0-bp157.2.3.1.src.rpm xfce4-sensors-plugin-1.5.0-bp157.2.3.1.x86_64.rpm xfce4-sensors-plugin-debuginfo-1.5.0-bp157.2.3.1.x86_64.rpm xfce4-sensors-plugin-debugsource-1.5.0-bp157.2.3.1.x86_64.rpm xfce4-sensors-plugin-lang-1.5.0-bp157.2.3.1.noarch.rpm xfce4-session-4.20.3-bp157.2.3.1.src.rpm xfce4-session-4.20.3-bp157.2.3.1.x86_64.rpm xfce4-session-branding-upstream-4.20.3-bp157.2.3.1.noarch.rpm xfce4-session-debuginfo-4.20.3-bp157.2.3.1.x86_64.rpm xfce4-session-debugsource-4.20.3-bp157.2.3.1.x86_64.rpm xfce4-session-lang-4.20.3-bp157.2.3.1.noarch.rpm xfce4-settings-4.20.2-bp157.2.3.1.src.rpm xfce4-settings-4.20.2-bp157.2.3.1.x86_64.rpm xfce4-settings-branding-upstream-4.20.2-bp157.2.3.1.noarch.rpm xfce4-settings-color-4.20.2-bp157.2.3.1.x86_64.rpm xfce4-settings-color-debuginfo-4.20.2-bp157.2.3.1.x86_64.rpm xfce4-settings-debuginfo-4.20.2-bp157.2.3.1.x86_64.rpm xfce4-settings-debugsource-4.20.2-bp157.2.3.1.x86_64.rpm xfce4-settings-lang-4.20.2-bp157.2.3.1.noarch.rpm xfce4-smartbookmark-plugin-0.6.0-bp157.2.3.1.src.rpm xfce4-smartbookmark-plugin-0.6.0-bp157.2.3.1.x86_64.rpm xfce4-smartbookmark-plugin-debuginfo-0.6.0-bp157.2.3.1.x86_64.rpm xfce4-smartbookmark-plugin-debugsource-0.6.0-bp157.2.3.1.x86_64.rpm xfce4-smartbookmark-plugin-lang-0.6.0-bp157.2.3.1.noarch.rpm xfce4-stopwatch-plugin-0.6.0-bp157.2.3.1.src.rpm xfce4-stopwatch-plugin-0.6.0-bp157.2.3.1.x86_64.rpm xfce4-stopwatch-plugin-debuginfo-0.6.0-bp157.2.3.1.x86_64.rpm xfce4-stopwatch-plugin-debugsource-0.6.0-bp157.2.3.1.x86_64.rpm xfce4-stopwatch-plugin-lang-0.6.0-bp157.2.3.1.noarch.rpm xfce4-systemload-plugin-1.4.0-bp157.2.3.1.src.rpm xfce4-systemload-plugin-1.4.0-bp157.2.3.1.x86_64.rpm xfce4-systemload-plugin-debuginfo-1.4.0-bp157.2.3.1.x86_64.rpm xfce4-systemload-plugin-debugsource-1.4.0-bp157.2.3.1.x86_64.rpm xfce4-systemload-plugin-lang-1.4.0-bp157.2.3.1.noarch.rpm xfce4-taskmanager-1.6.0-bp157.2.3.1.src.rpm xfce4-taskmanager-1.6.0-bp157.2.3.1.x86_64.rpm xfce4-taskmanager-debuginfo-1.6.0-bp157.2.3.1.x86_64.rpm xfce4-taskmanager-debugsource-1.6.0-bp157.2.3.1.x86_64.rpm xfce4-taskmanager-lang-1.6.0-bp157.2.3.1.noarch.rpm xfce4-time-out-plugin-1.2.0-bp157.2.3.1.src.rpm xfce4-time-out-plugin-1.2.0-bp157.2.3.1.x86_64.rpm xfce4-time-out-plugin-debuginfo-1.2.0-bp157.2.3.1.x86_64.rpm xfce4-time-out-plugin-debugsource-1.2.0-bp157.2.3.1.x86_64.rpm xfce4-time-out-plugin-lang-1.2.0-bp157.2.3.1.noarch.rpm xfce4-timer-plugin-1.8.0-bp157.2.3.1.src.rpm xfce4-timer-plugin-1.8.0-bp157.2.3.1.x86_64.rpm xfce4-timer-plugin-debuginfo-1.8.0-bp157.2.3.1.x86_64.rpm xfce4-timer-plugin-debugsource-1.8.0-bp157.2.3.1.x86_64.rpm xfce4-timer-plugin-lang-1.8.0-bp157.2.3.1.noarch.rpm xfce4-verve-plugin-2.1.0-bp157.2.3.1.src.rpm xfce4-verve-plugin-2.1.0-bp157.2.3.1.x86_64.rpm xfce4-verve-plugin-debuginfo-2.1.0-bp157.2.3.1.x86_64.rpm xfce4-verve-plugin-debugsource-2.1.0-bp157.2.3.1.x86_64.rpm xfce4-verve-plugin-lang-2.1.0-bp157.2.3.1.noarch.rpm xfce4-wavelan-plugin-0.7.0-bp157.2.3.1.src.rpm xfce4-wavelan-plugin-0.7.0-bp157.2.3.1.x86_64.rpm xfce4-wavelan-plugin-debuginfo-0.7.0-bp157.2.3.1.x86_64.rpm xfce4-wavelan-plugin-debugsource-0.7.0-bp157.2.3.1.x86_64.rpm xfce4-wavelan-plugin-lang-0.7.0-bp157.2.3.1.noarch.rpm xfce4-weather-plugin-0.12.0-bp157.2.3.1.src.rpm xfce4-weather-plugin-0.12.0-bp157.2.3.1.x86_64.rpm xfce4-weather-plugin-debuginfo-0.12.0-bp157.2.3.1.x86_64.rpm xfce4-weather-plugin-debugsource-0.12.0-bp157.2.3.1.x86_64.rpm xfce4-weather-plugin-lang-0.12.0-bp157.2.3.1.noarch.rpm xfce4-whiskermenu-plugin-2.10.0-bp157.2.3.1.src.rpm xfce4-whiskermenu-plugin-2.10.0-bp157.2.3.1.x86_64.rpm xfce4-whiskermenu-plugin-debuginfo-2.10.0-bp157.2.3.1.x86_64.rpm xfce4-whiskermenu-plugin-debugsource-2.10.0-bp157.2.3.1.x86_64.rpm xfce4-whiskermenu-plugin-lang-2.10.0-bp157.2.3.1.noarch.rpm xfce4-xkb-plugin-0.9.0-bp157.2.3.1.src.rpm xfce4-xkb-plugin-0.9.0-bp157.2.3.1.x86_64.rpm xfce4-xkb-plugin-debuginfo-0.9.0-bp157.2.3.1.x86_64.rpm xfce4-xkb-plugin-debugsource-0.9.0-bp157.2.3.1.x86_64.rpm xfce4-xkb-plugin-lang-0.9.0-bp157.2.3.1.noarch.rpm libxfdashboard0-1.1.0-bp157.3.3.1.x86_64.rpm libxfdashboard0-debuginfo-1.1.0-bp157.3.3.1.x86_64.rpm xfdashboard-1.1.0-bp157.3.3.1.src.rpm xfdashboard-1.1.0-bp157.3.3.1.x86_64.rpm xfdashboard-debuginfo-1.1.0-bp157.3.3.1.x86_64.rpm xfdashboard-debugsource-1.1.0-bp157.3.3.1.x86_64.rpm xfdashboard-devel-1.1.0-bp157.3.3.1.x86_64.rpm xfdashboard-lang-1.1.0-bp157.3.3.1.noarch.rpm xfdashboard-themes-1.1.0-bp157.3.3.1.noarch.rpm xfdesktop-4.20.1-bp157.2.3.1.src.rpm xfdesktop-4.20.1-bp157.2.3.1.x86_64.rpm xfdesktop-branding-upstream-4.20.1-bp157.2.3.1.noarch.rpm xfdesktop-debuginfo-4.20.1-bp157.2.3.1.x86_64.rpm xfdesktop-debugsource-4.20.1-bp157.2.3.1.x86_64.rpm xfdesktop-lang-4.20.1-bp157.2.3.1.noarch.rpm xfmpc-0.4.0-bp157.2.3.1.src.rpm xfmpc-0.4.0-bp157.2.3.1.x86_64.rpm xfmpc-debuginfo-0.4.0-bp157.2.3.1.x86_64.rpm xfmpc-debugsource-0.4.0-bp157.2.3.1.x86_64.rpm xfmpc-lang-0.4.0-bp157.2.3.1.noarch.rpm gigolo-0.6.0-bp157.2.3.1.aarch64.rpm gigolo-debuginfo-0.6.0-bp157.2.3.1.aarch64.rpm gigolo-debugsource-0.6.0-bp157.2.3.1.aarch64.rpm libxfce4kbd-private-3-0-4.20.2-bp157.2.3.1.aarch64.rpm libxfce4kbd-private-3-0-debuginfo-4.20.2-bp157.2.3.1.aarch64.rpm libxfce4ui-2-0-4.20.2-bp157.2.3.1.aarch64.rpm libxfce4ui-2-0-debuginfo-4.20.2-bp157.2.3.1.aarch64.rpm libxfce4ui-debuginfo-4.20.2-bp157.2.3.1.aarch64.rpm libxfce4ui-debugsource-4.20.2-bp157.2.3.1.aarch64.rpm libxfce4ui-devel-4.20.2-bp157.2.3.1.aarch64.rpm libxfce4ui-devel-debuginfo-4.20.2-bp157.2.3.1.aarch64.rpm libxfce4ui-tools-4.20.2-bp157.2.3.1.aarch64.rpm libxfce4ui-tools-debuginfo-4.20.2-bp157.2.3.1.aarch64.rpm typelib-1_0-Libxfce4ui-2_0-4.20.2-bp157.2.3.1.aarch64.rpm libxfce4windowing-0-0-4.20.4-bp157.2.3.1.aarch64.rpm libxfce4windowing-0-0-debuginfo-4.20.4-bp157.2.3.1.aarch64.rpm libxfce4windowing-debuginfo-4.20.4-bp157.2.3.1.aarch64.rpm libxfce4windowing-debugsource-4.20.4-bp157.2.3.1.aarch64.rpm libxfce4windowing-devel-4.20.4-bp157.2.3.1.aarch64.rpm libxfce4windowingui-0-0-4.20.4-bp157.2.3.1.aarch64.rpm libxfce4windowingui-0-0-debuginfo-4.20.4-bp157.2.3.1.aarch64.rpm typelib-1_0-Libxfce4windowing-0_0-4.20.4-bp157.2.3.1.aarch64.rpm typelib-1_0-Libxfce4windowingui-0_0-4.20.4-bp157.2.3.1.aarch64.rpm orage-4.20.2-bp157.2.3.1.aarch64.rpm orage-debuginfo-4.20.2-bp157.2.3.1.aarch64.rpm orage-debugsource-4.20.2-bp157.2.3.1.aarch64.rpm parole-4.20.0-bp157.2.3.1.aarch64.rpm parole-debuginfo-4.20.0-bp157.2.3.1.aarch64.rpm parole-debugsource-4.20.0-bp157.2.3.1.aarch64.rpm parole-devel-4.20.0-bp157.2.3.1.aarch64.rpm pragha-1.3.99.1-bp157.2.3.1.aarch64.rpm pragha-debuginfo-1.3.99.1-bp157.2.3.1.aarch64.rpm pragha-debugsource-1.3.99.1-bp157.2.3.1.aarch64.rpm pragha-plugins-1.3.99.1-bp157.2.3.1.aarch64.rpm pragha-plugins-debuginfo-1.3.99.1-bp157.2.3.1.aarch64.rpm pragha-plugins-devel-1.3.99.1-bp157.2.3.1.aarch64.rpm thunar-archive-plugin-0.6.0-bp157.2.3.1.aarch64.rpm thunar-archive-plugin-debuginfo-0.6.0-bp157.2.3.1.aarch64.rpm thunar-archive-plugin-debugsource-0.6.0-bp157.2.3.1.aarch64.rpm thunar-media-tags-plugin-0.6.0-bp157.2.3.1.aarch64.rpm thunar-media-tags-plugin-debuginfo-0.6.0-bp157.2.3.1.aarch64.rpm thunar-media-tags-plugin-debugsource-0.6.0-bp157.2.3.1.aarch64.rpm thunar-shares-plugin-0.5.0-bp157.2.3.1.aarch64.rpm thunar-shares-plugin-debuginfo-0.5.0-bp157.2.3.1.aarch64.rpm thunar-shares-plugin-debugsource-0.5.0-bp157.2.3.1.aarch64.rpm thunar-vcs-plugin-0.4.0-bp157.2.3.1.aarch64.rpm thunar-vcs-plugin-debuginfo-0.4.0-bp157.2.3.1.aarch64.rpm thunar-vcs-plugin-debugsource-0.4.0-bp157.2.3.1.aarch64.rpm libthunarx-3-0-4.20.6-bp157.2.3.2.aarch64.rpm libthunarx-3-0-debuginfo-4.20.6-bp157.2.3.2.aarch64.rpm thunar-4.20.6-bp157.2.3.2.aarch64.rpm thunar-debuginfo-4.20.6-bp157.2.3.2.aarch64.rpm thunar-debugsource-4.20.6-bp157.2.3.2.aarch64.rpm thunar-devel-4.20.6-bp157.2.3.2.aarch64.rpm typelib-1_0-Thunarx-3_0-4.20.6-bp157.2.3.2.aarch64.rpm libtumbler-1-0-4.20.1-bp157.3.3.1.aarch64.rpm libtumbler-1-0-debuginfo-4.20.1-bp157.3.3.1.aarch64.rpm tumbler-4.20.1-bp157.3.3.1.aarch64.rpm tumbler-debuginfo-4.20.1-bp157.3.3.1.aarch64.rpm tumbler-debugsource-4.20.1-bp157.3.3.1.aarch64.rpm tumbler-devel-4.20.1-bp157.3.3.1.aarch64.rpm xfburn-0.8.0-bp157.2.3.1.aarch64.rpm xfburn-debuginfo-0.8.0-bp157.2.3.1.aarch64.rpm xfburn-debugsource-0.8.0-bp157.2.3.1.aarch64.rpm xfce4-battery-plugin-1.2.0-bp157.2.3.1.aarch64.rpm xfce4-battery-plugin-debuginfo-1.2.0-bp157.2.3.1.aarch64.rpm xfce4-battery-plugin-debugsource-1.2.0-bp157.2.3.1.aarch64.rpm xfce4-calculator-plugin-0.8.0-bp157.2.3.1.aarch64.rpm xfce4-calculator-plugin-debuginfo-0.8.0-bp157.2.3.1.aarch64.rpm xfce4-calculator-plugin-debugsource-0.8.0-bp157.2.3.1.aarch64.rpm xfce4-clipman-plugin-1.7.0-bp157.2.3.1.aarch64.rpm xfce4-clipman-plugin-debuginfo-1.7.0-bp157.2.3.1.aarch64.rpm xfce4-clipman-plugin-debugsource-1.7.0-bp157.2.3.1.aarch64.rpm xfce4-cpufreq-plugin-1.3.0-bp157.2.3.2.aarch64.rpm xfce4-cpufreq-plugin-debuginfo-1.3.0-bp157.2.3.2.aarch64.rpm xfce4-cpufreq-plugin-debugsource-1.3.0-bp157.2.3.2.aarch64.rpm xfce4-cpugraph-plugin-1.3.0-bp157.2.3.2.aarch64.rpm xfce4-cpugraph-plugin-debuginfo-1.3.0-bp157.2.3.2.aarch64.rpm xfce4-cpugraph-plugin-debugsource-1.3.0-bp157.2.3.2.aarch64.rpm xfce4-dict-0.8.9-bp157.2.3.1.aarch64.rpm xfce4-dict-debuginfo-0.8.9-bp157.2.3.1.aarch64.rpm xfce4-dict-debugsource-0.8.9-bp157.2.3.1.aarch64.rpm xfce4-panel-plugin-dict-0.8.9-bp157.2.3.1.aarch64.rpm xfce4-panel-plugin-dict-debuginfo-0.8.9-bp157.2.3.1.aarch64.rpm xfce4-diskperf-plugin-2.8.0-bp157.2.3.2.aarch64.rpm xfce4-diskperf-plugin-debuginfo-2.8.0-bp157.2.3.2.aarch64.rpm xfce4-diskperf-plugin-debugsource-2.8.0-bp157.2.3.2.aarch64.rpm xfce4-docklike-plugin-0.5.0-bp157.2.3.2.aarch64.rpm xfce4-docklike-plugin-debuginfo-0.5.0-bp157.2.3.2.aarch64.rpm xfce4-docklike-plugin-debugsource-0.5.0-bp157.2.3.2.aarch64.rpm xfce4-eyes-plugin-4.7.0-bp157.2.3.2.aarch64.rpm xfce4-eyes-plugin-debuginfo-4.7.0-bp157.2.3.2.aarch64.rpm xfce4-eyes-plugin-debugsource-4.7.0-bp157.2.3.2.aarch64.rpm xfce4-fsguard-plugin-1.2.0-bp157.2.3.2.aarch64.rpm xfce4-fsguard-plugin-debuginfo-1.2.0-bp157.2.3.2.aarch64.rpm xfce4-fsguard-plugin-debugsource-1.2.0-bp157.2.3.2.aarch64.rpm xfce4-genmon-plugin-4.3.0-bp157.2.3.2.aarch64.rpm xfce4-genmon-plugin-debuginfo-4.3.0-bp157.2.3.2.aarch64.rpm xfce4-genmon-plugin-debugsource-4.3.0-bp157.2.3.2.aarch64.rpm xfce4-mailwatch-plugin-1.4.0-bp157.2.3.1.aarch64.rpm xfce4-mailwatch-plugin-debuginfo-1.4.0-bp157.2.3.1.aarch64.rpm xfce4-mailwatch-plugin-debugsource-1.4.0-bp157.2.3.1.aarch64.rpm xfce4-mount-plugin-1.2.0-bp157.2.3.2.aarch64.rpm xfce4-mount-plugin-debuginfo-1.2.0-bp157.2.3.2.aarch64.rpm xfce4-mount-plugin-debugsource-1.2.0-bp157.2.3.2.aarch64.rpm xfce4-mpc-plugin-0.6.0-bp157.2.3.2.aarch64.rpm xfce4-mpc-plugin-debuginfo-0.6.0-bp157.2.3.2.aarch64.rpm xfce4-mpc-plugin-debugsource-0.6.0-bp157.2.3.2.aarch64.rpm xfce4-netload-plugin-1.5.0-bp157.2.3.2.aarch64.rpm xfce4-netload-plugin-debuginfo-1.5.0-bp157.2.3.2.aarch64.rpm xfce4-netload-plugin-debugsource-1.5.0-bp157.2.3.2.aarch64.rpm xfce4-notes-plugin-1.12.0-bp157.2.3.2.aarch64.rpm xfce4-notes-plugin-debuginfo-1.12.0-bp157.2.3.2.aarch64.rpm xfce4-notes-plugin-debugsource-1.12.0-bp157.2.3.2.aarch64.rpm libxfce4panel-2_0-4-4.20.5-bp157.2.3.1.aarch64.rpm libxfce4panel-2_0-4-debuginfo-4.20.5-bp157.2.3.1.aarch64.rpm typelib-1_0-Libxfce4panel-2_0-4.20.5-bp157.2.3.1.aarch64.rpm xfce4-panel-4.20.5-bp157.2.3.1.aarch64.rpm xfce4-panel-debuginfo-4.20.5-bp157.2.3.1.aarch64.rpm xfce4-panel-debugsource-4.20.5-bp157.2.3.1.aarch64.rpm xfce4-panel-devel-4.20.5-bp157.2.3.1.aarch64.rpm xfce4-panel-restore-defaults-4.20.5-bp157.2.3.1.aarch64.rpm xfce4-places-plugin-1.9.0-bp157.2.3.1.aarch64.rpm xfce4-places-plugin-debuginfo-1.9.0-bp157.2.3.1.aarch64.rpm xfce4-places-plugin-debugsource-1.9.0-bp157.2.3.1.aarch64.rpm xfce4-screenshooter-1.11.2-bp157.2.3.1.aarch64.rpm xfce4-screenshooter-debuginfo-1.11.2-bp157.2.3.1.aarch64.rpm xfce4-screenshooter-debugsource-1.11.2-bp157.2.3.1.aarch64.rpm xfce4-screenshooter-plugin-1.11.2-bp157.2.3.1.aarch64.rpm xfce4-screenshooter-plugin-debuginfo-1.11.2-bp157.2.3.1.aarch64.rpm xfce4-sensors-plugin-1.5.0-bp157.2.3.1.aarch64.rpm xfce4-sensors-plugin-debuginfo-1.5.0-bp157.2.3.1.aarch64.rpm xfce4-sensors-plugin-debugsource-1.5.0-bp157.2.3.1.aarch64.rpm xfce4-session-4.20.3-bp157.2.3.1.aarch64.rpm xfce4-session-debuginfo-4.20.3-bp157.2.3.1.aarch64.rpm xfce4-session-debugsource-4.20.3-bp157.2.3.1.aarch64.rpm xfce4-settings-4.20.2-bp157.2.3.1.aarch64.rpm xfce4-settings-color-4.20.2-bp157.2.3.1.aarch64.rpm xfce4-settings-color-debuginfo-4.20.2-bp157.2.3.1.aarch64.rpm xfce4-settings-debuginfo-4.20.2-bp157.2.3.1.aarch64.rpm xfce4-settings-debugsource-4.20.2-bp157.2.3.1.aarch64.rpm xfce4-smartbookmark-plugin-0.6.0-bp157.2.3.1.aarch64.rpm xfce4-smartbookmark-plugin-debuginfo-0.6.0-bp157.2.3.1.aarch64.rpm xfce4-smartbookmark-plugin-debugsource-0.6.0-bp157.2.3.1.aarch64.rpm xfce4-stopwatch-plugin-0.6.0-bp157.2.3.1.aarch64.rpm xfce4-stopwatch-plugin-debuginfo-0.6.0-bp157.2.3.1.aarch64.rpm xfce4-stopwatch-plugin-debugsource-0.6.0-bp157.2.3.1.aarch64.rpm xfce4-systemload-plugin-1.4.0-bp157.2.3.1.aarch64.rpm xfce4-systemload-plugin-debuginfo-1.4.0-bp157.2.3.1.aarch64.rpm xfce4-systemload-plugin-debugsource-1.4.0-bp157.2.3.1.aarch64.rpm xfce4-taskmanager-1.6.0-bp157.2.3.1.aarch64.rpm xfce4-taskmanager-debuginfo-1.6.0-bp157.2.3.1.aarch64.rpm xfce4-taskmanager-debugsource-1.6.0-bp157.2.3.1.aarch64.rpm xfce4-time-out-plugin-1.2.0-bp157.2.3.1.aarch64.rpm xfce4-time-out-plugin-debuginfo-1.2.0-bp157.2.3.1.aarch64.rpm xfce4-time-out-plugin-debugsource-1.2.0-bp157.2.3.1.aarch64.rpm xfce4-timer-plugin-1.8.0-bp157.2.3.1.aarch64.rpm xfce4-timer-plugin-debuginfo-1.8.0-bp157.2.3.1.aarch64.rpm xfce4-timer-plugin-debugsource-1.8.0-bp157.2.3.1.aarch64.rpm xfce4-verve-plugin-2.1.0-bp157.2.3.1.aarch64.rpm xfce4-verve-plugin-debuginfo-2.1.0-bp157.2.3.1.aarch64.rpm xfce4-verve-plugin-debugsource-2.1.0-bp157.2.3.1.aarch64.rpm xfce4-wavelan-plugin-0.7.0-bp157.2.3.1.aarch64.rpm xfce4-wavelan-plugin-debuginfo-0.7.0-bp157.2.3.1.aarch64.rpm xfce4-wavelan-plugin-debugsource-0.7.0-bp157.2.3.1.aarch64.rpm xfce4-weather-plugin-0.12.0-bp157.2.3.1.aarch64.rpm xfce4-weather-plugin-debuginfo-0.12.0-bp157.2.3.1.aarch64.rpm xfce4-weather-plugin-debugsource-0.12.0-bp157.2.3.1.aarch64.rpm xfce4-whiskermenu-plugin-2.10.0-bp157.2.3.1.aarch64.rpm xfce4-whiskermenu-plugin-debuginfo-2.10.0-bp157.2.3.1.aarch64.rpm xfce4-whiskermenu-plugin-debugsource-2.10.0-bp157.2.3.1.aarch64.rpm xfce4-xkb-plugin-0.9.0-bp157.2.3.1.aarch64.rpm xfce4-xkb-plugin-debuginfo-0.9.0-bp157.2.3.1.aarch64.rpm xfce4-xkb-plugin-debugsource-0.9.0-bp157.2.3.1.aarch64.rpm libxfdashboard0-1.1.0-bp157.3.3.1.aarch64.rpm libxfdashboard0-debuginfo-1.1.0-bp157.3.3.1.aarch64.rpm xfdashboard-1.1.0-bp157.3.3.1.aarch64.rpm xfdashboard-debuginfo-1.1.0-bp157.3.3.1.aarch64.rpm xfdashboard-debugsource-1.1.0-bp157.3.3.1.aarch64.rpm xfdashboard-devel-1.1.0-bp157.3.3.1.aarch64.rpm xfdesktop-4.20.1-bp157.2.3.1.aarch64.rpm xfdesktop-debuginfo-4.20.1-bp157.2.3.1.aarch64.rpm xfdesktop-debugsource-4.20.1-bp157.2.3.1.aarch64.rpm xfmpc-0.4.0-bp157.2.3.1.aarch64.rpm xfmpc-debuginfo-0.4.0-bp157.2.3.1.aarch64.rpm xfmpc-debugsource-0.4.0-bp157.2.3.1.aarch64.rpm gigolo-0.6.0-bp157.2.3.1.ppc64le.rpm gigolo-debuginfo-0.6.0-bp157.2.3.1.ppc64le.rpm gigolo-debugsource-0.6.0-bp157.2.3.1.ppc64le.rpm libxfce4kbd-private-3-0-4.20.2-bp157.2.3.1.ppc64le.rpm libxfce4kbd-private-3-0-debuginfo-4.20.2-bp157.2.3.1.ppc64le.rpm libxfce4ui-2-0-4.20.2-bp157.2.3.1.ppc64le.rpm libxfce4ui-2-0-debuginfo-4.20.2-bp157.2.3.1.ppc64le.rpm libxfce4ui-debuginfo-4.20.2-bp157.2.3.1.ppc64le.rpm libxfce4ui-debugsource-4.20.2-bp157.2.3.1.ppc64le.rpm libxfce4ui-devel-4.20.2-bp157.2.3.1.ppc64le.rpm libxfce4ui-devel-debuginfo-4.20.2-bp157.2.3.1.ppc64le.rpm libxfce4ui-tools-4.20.2-bp157.2.3.1.ppc64le.rpm libxfce4ui-tools-debuginfo-4.20.2-bp157.2.3.1.ppc64le.rpm typelib-1_0-Libxfce4ui-2_0-4.20.2-bp157.2.3.1.ppc64le.rpm libxfce4windowing-0-0-4.20.4-bp157.2.3.1.ppc64le.rpm libxfce4windowing-0-0-debuginfo-4.20.4-bp157.2.3.1.ppc64le.rpm libxfce4windowing-debuginfo-4.20.4-bp157.2.3.1.ppc64le.rpm libxfce4windowing-debugsource-4.20.4-bp157.2.3.1.ppc64le.rpm libxfce4windowing-devel-4.20.4-bp157.2.3.1.ppc64le.rpm libxfce4windowingui-0-0-4.20.4-bp157.2.3.1.ppc64le.rpm libxfce4windowingui-0-0-debuginfo-4.20.4-bp157.2.3.1.ppc64le.rpm typelib-1_0-Libxfce4windowing-0_0-4.20.4-bp157.2.3.1.ppc64le.rpm typelib-1_0-Libxfce4windowingui-0_0-4.20.4-bp157.2.3.1.ppc64le.rpm orage-4.20.2-bp157.2.3.1.ppc64le.rpm orage-debuginfo-4.20.2-bp157.2.3.1.ppc64le.rpm orage-debugsource-4.20.2-bp157.2.3.1.ppc64le.rpm parole-4.20.0-bp157.2.3.1.ppc64le.rpm parole-debuginfo-4.20.0-bp157.2.3.1.ppc64le.rpm parole-debugsource-4.20.0-bp157.2.3.1.ppc64le.rpm parole-devel-4.20.0-bp157.2.3.1.ppc64le.rpm pragha-1.3.99.1-bp157.2.3.1.ppc64le.rpm pragha-debuginfo-1.3.99.1-bp157.2.3.1.ppc64le.rpm pragha-debugsource-1.3.99.1-bp157.2.3.1.ppc64le.rpm pragha-plugins-1.3.99.1-bp157.2.3.1.ppc64le.rpm pragha-plugins-debuginfo-1.3.99.1-bp157.2.3.1.ppc64le.rpm pragha-plugins-devel-1.3.99.1-bp157.2.3.1.ppc64le.rpm thunar-archive-plugin-0.6.0-bp157.2.3.1.ppc64le.rpm thunar-archive-plugin-debuginfo-0.6.0-bp157.2.3.1.ppc64le.rpm thunar-archive-plugin-debugsource-0.6.0-bp157.2.3.1.ppc64le.rpm thunar-media-tags-plugin-0.6.0-bp157.2.3.1.ppc64le.rpm thunar-media-tags-plugin-debuginfo-0.6.0-bp157.2.3.1.ppc64le.rpm thunar-media-tags-plugin-debugsource-0.6.0-bp157.2.3.1.ppc64le.rpm thunar-shares-plugin-0.5.0-bp157.2.3.1.ppc64le.rpm thunar-shares-plugin-debuginfo-0.5.0-bp157.2.3.1.ppc64le.rpm thunar-shares-plugin-debugsource-0.5.0-bp157.2.3.1.ppc64le.rpm thunar-vcs-plugin-0.4.0-bp157.2.3.1.ppc64le.rpm thunar-vcs-plugin-debuginfo-0.4.0-bp157.2.3.1.ppc64le.rpm thunar-vcs-plugin-debugsource-0.4.0-bp157.2.3.1.ppc64le.rpm libthunarx-3-0-4.20.6-bp157.2.3.2.ppc64le.rpm libthunarx-3-0-debuginfo-4.20.6-bp157.2.3.2.ppc64le.rpm thunar-4.20.6-bp157.2.3.2.ppc64le.rpm thunar-debuginfo-4.20.6-bp157.2.3.2.ppc64le.rpm thunar-debugsource-4.20.6-bp157.2.3.2.ppc64le.rpm thunar-devel-4.20.6-bp157.2.3.2.ppc64le.rpm typelib-1_0-Thunarx-3_0-4.20.6-bp157.2.3.2.ppc64le.rpm libtumbler-1-0-4.20.1-bp157.3.3.1.ppc64le.rpm libtumbler-1-0-debuginfo-4.20.1-bp157.3.3.1.ppc64le.rpm tumbler-4.20.1-bp157.3.3.1.ppc64le.rpm tumbler-debuginfo-4.20.1-bp157.3.3.1.ppc64le.rpm tumbler-debugsource-4.20.1-bp157.3.3.1.ppc64le.rpm tumbler-devel-4.20.1-bp157.3.3.1.ppc64le.rpm xfburn-0.8.0-bp157.2.3.1.ppc64le.rpm xfburn-debuginfo-0.8.0-bp157.2.3.1.ppc64le.rpm xfburn-debugsource-0.8.0-bp157.2.3.1.ppc64le.rpm xfce4-battery-plugin-1.2.0-bp157.2.3.1.ppc64le.rpm xfce4-battery-plugin-debuginfo-1.2.0-bp157.2.3.1.ppc64le.rpm xfce4-battery-plugin-debugsource-1.2.0-bp157.2.3.1.ppc64le.rpm xfce4-calculator-plugin-0.8.0-bp157.2.3.1.ppc64le.rpm xfce4-calculator-plugin-debuginfo-0.8.0-bp157.2.3.1.ppc64le.rpm xfce4-calculator-plugin-debugsource-0.8.0-bp157.2.3.1.ppc64le.rpm xfce4-clipman-plugin-1.7.0-bp157.2.3.1.ppc64le.rpm xfce4-clipman-plugin-debuginfo-1.7.0-bp157.2.3.1.ppc64le.rpm xfce4-clipman-plugin-debugsource-1.7.0-bp157.2.3.1.ppc64le.rpm xfce4-cpufreq-plugin-1.3.0-bp157.2.3.2.ppc64le.rpm xfce4-cpufreq-plugin-debuginfo-1.3.0-bp157.2.3.2.ppc64le.rpm xfce4-cpufreq-plugin-debugsource-1.3.0-bp157.2.3.2.ppc64le.rpm xfce4-cpugraph-plugin-1.3.0-bp157.2.3.2.ppc64le.rpm xfce4-cpugraph-plugin-debuginfo-1.3.0-bp157.2.3.2.ppc64le.rpm xfce4-cpugraph-plugin-debugsource-1.3.0-bp157.2.3.2.ppc64le.rpm xfce4-dict-0.8.9-bp157.2.3.1.ppc64le.rpm xfce4-dict-debuginfo-0.8.9-bp157.2.3.1.ppc64le.rpm xfce4-dict-debugsource-0.8.9-bp157.2.3.1.ppc64le.rpm xfce4-panel-plugin-dict-0.8.9-bp157.2.3.1.ppc64le.rpm xfce4-panel-plugin-dict-debuginfo-0.8.9-bp157.2.3.1.ppc64le.rpm xfce4-diskperf-plugin-2.8.0-bp157.2.3.2.ppc64le.rpm xfce4-diskperf-plugin-debuginfo-2.8.0-bp157.2.3.2.ppc64le.rpm xfce4-diskperf-plugin-debugsource-2.8.0-bp157.2.3.2.ppc64le.rpm xfce4-docklike-plugin-0.5.0-bp157.2.3.2.ppc64le.rpm xfce4-docklike-plugin-debuginfo-0.5.0-bp157.2.3.2.ppc64le.rpm xfce4-docklike-plugin-debugsource-0.5.0-bp157.2.3.2.ppc64le.rpm xfce4-eyes-plugin-4.7.0-bp157.2.3.2.ppc64le.rpm xfce4-eyes-plugin-debuginfo-4.7.0-bp157.2.3.2.ppc64le.rpm xfce4-eyes-plugin-debugsource-4.7.0-bp157.2.3.2.ppc64le.rpm xfce4-fsguard-plugin-1.2.0-bp157.2.3.2.ppc64le.rpm xfce4-fsguard-plugin-debuginfo-1.2.0-bp157.2.3.2.ppc64le.rpm xfce4-fsguard-plugin-debugsource-1.2.0-bp157.2.3.2.ppc64le.rpm xfce4-genmon-plugin-4.3.0-bp157.2.3.2.ppc64le.rpm xfce4-genmon-plugin-debuginfo-4.3.0-bp157.2.3.2.ppc64le.rpm xfce4-genmon-plugin-debugsource-4.3.0-bp157.2.3.2.ppc64le.rpm xfce4-mailwatch-plugin-1.4.0-bp157.2.3.1.ppc64le.rpm xfce4-mailwatch-plugin-debuginfo-1.4.0-bp157.2.3.1.ppc64le.rpm xfce4-mailwatch-plugin-debugsource-1.4.0-bp157.2.3.1.ppc64le.rpm xfce4-mount-plugin-1.2.0-bp157.2.3.2.ppc64le.rpm xfce4-mount-plugin-debuginfo-1.2.0-bp157.2.3.2.ppc64le.rpm xfce4-mount-plugin-debugsource-1.2.0-bp157.2.3.2.ppc64le.rpm xfce4-mpc-plugin-0.6.0-bp157.2.3.2.ppc64le.rpm xfce4-mpc-plugin-debuginfo-0.6.0-bp157.2.3.2.ppc64le.rpm xfce4-mpc-plugin-debugsource-0.6.0-bp157.2.3.2.ppc64le.rpm xfce4-netload-plugin-1.5.0-bp157.2.3.2.ppc64le.rpm xfce4-netload-plugin-debuginfo-1.5.0-bp157.2.3.2.ppc64le.rpm xfce4-netload-plugin-debugsource-1.5.0-bp157.2.3.2.ppc64le.rpm xfce4-notes-plugin-1.12.0-bp157.2.3.2.ppc64le.rpm xfce4-notes-plugin-debuginfo-1.12.0-bp157.2.3.2.ppc64le.rpm xfce4-notes-plugin-debugsource-1.12.0-bp157.2.3.2.ppc64le.rpm libxfce4panel-2_0-4-4.20.5-bp157.2.3.1.ppc64le.rpm libxfce4panel-2_0-4-debuginfo-4.20.5-bp157.2.3.1.ppc64le.rpm typelib-1_0-Libxfce4panel-2_0-4.20.5-bp157.2.3.1.ppc64le.rpm xfce4-panel-4.20.5-bp157.2.3.1.ppc64le.rpm xfce4-panel-debuginfo-4.20.5-bp157.2.3.1.ppc64le.rpm xfce4-panel-debugsource-4.20.5-bp157.2.3.1.ppc64le.rpm xfce4-panel-devel-4.20.5-bp157.2.3.1.ppc64le.rpm xfce4-panel-restore-defaults-4.20.5-bp157.2.3.1.ppc64le.rpm xfce4-places-plugin-1.9.0-bp157.2.3.1.ppc64le.rpm xfce4-places-plugin-debuginfo-1.9.0-bp157.2.3.1.ppc64le.rpm xfce4-places-plugin-debugsource-1.9.0-bp157.2.3.1.ppc64le.rpm xfce4-screenshooter-1.11.2-bp157.2.3.1.ppc64le.rpm xfce4-screenshooter-debuginfo-1.11.2-bp157.2.3.1.ppc64le.rpm xfce4-screenshooter-debugsource-1.11.2-bp157.2.3.1.ppc64le.rpm xfce4-screenshooter-plugin-1.11.2-bp157.2.3.1.ppc64le.rpm xfce4-screenshooter-plugin-debuginfo-1.11.2-bp157.2.3.1.ppc64le.rpm xfce4-sensors-plugin-1.5.0-bp157.2.3.1.ppc64le.rpm xfce4-sensors-plugin-debuginfo-1.5.0-bp157.2.3.1.ppc64le.rpm xfce4-sensors-plugin-debugsource-1.5.0-bp157.2.3.1.ppc64le.rpm xfce4-session-4.20.3-bp157.2.3.1.ppc64le.rpm xfce4-session-debuginfo-4.20.3-bp157.2.3.1.ppc64le.rpm xfce4-session-debugsource-4.20.3-bp157.2.3.1.ppc64le.rpm xfce4-settings-4.20.2-bp157.2.3.1.ppc64le.rpm xfce4-settings-color-4.20.2-bp157.2.3.1.ppc64le.rpm xfce4-settings-color-debuginfo-4.20.2-bp157.2.3.1.ppc64le.rpm xfce4-settings-debuginfo-4.20.2-bp157.2.3.1.ppc64le.rpm xfce4-settings-debugsource-4.20.2-bp157.2.3.1.ppc64le.rpm xfce4-smartbookmark-plugin-0.6.0-bp157.2.3.1.ppc64le.rpm xfce4-smartbookmark-plugin-debuginfo-0.6.0-bp157.2.3.1.ppc64le.rpm xfce4-smartbookmark-plugin-debugsource-0.6.0-bp157.2.3.1.ppc64le.rpm xfce4-stopwatch-plugin-0.6.0-bp157.2.3.1.ppc64le.rpm xfce4-stopwatch-plugin-debuginfo-0.6.0-bp157.2.3.1.ppc64le.rpm xfce4-stopwatch-plugin-debugsource-0.6.0-bp157.2.3.1.ppc64le.rpm xfce4-systemload-plugin-1.4.0-bp157.2.3.1.ppc64le.rpm xfce4-systemload-plugin-debuginfo-1.4.0-bp157.2.3.1.ppc64le.rpm xfce4-systemload-plugin-debugsource-1.4.0-bp157.2.3.1.ppc64le.rpm xfce4-taskmanager-1.6.0-bp157.2.3.1.ppc64le.rpm xfce4-taskmanager-debuginfo-1.6.0-bp157.2.3.1.ppc64le.rpm xfce4-taskmanager-debugsource-1.6.0-bp157.2.3.1.ppc64le.rpm xfce4-time-out-plugin-1.2.0-bp157.2.3.1.ppc64le.rpm xfce4-time-out-plugin-debuginfo-1.2.0-bp157.2.3.1.ppc64le.rpm xfce4-time-out-plugin-debugsource-1.2.0-bp157.2.3.1.ppc64le.rpm xfce4-timer-plugin-1.8.0-bp157.2.3.1.ppc64le.rpm xfce4-timer-plugin-debuginfo-1.8.0-bp157.2.3.1.ppc64le.rpm xfce4-timer-plugin-debugsource-1.8.0-bp157.2.3.1.ppc64le.rpm xfce4-verve-plugin-2.1.0-bp157.2.3.1.ppc64le.rpm xfce4-verve-plugin-debuginfo-2.1.0-bp157.2.3.1.ppc64le.rpm xfce4-verve-plugin-debugsource-2.1.0-bp157.2.3.1.ppc64le.rpm xfce4-wavelan-plugin-0.7.0-bp157.2.3.1.ppc64le.rpm xfce4-wavelan-plugin-debuginfo-0.7.0-bp157.2.3.1.ppc64le.rpm xfce4-wavelan-plugin-debugsource-0.7.0-bp157.2.3.1.ppc64le.rpm xfce4-weather-plugin-0.12.0-bp157.2.3.1.ppc64le.rpm xfce4-weather-plugin-debuginfo-0.12.0-bp157.2.3.1.ppc64le.rpm xfce4-weather-plugin-debugsource-0.12.0-bp157.2.3.1.ppc64le.rpm xfce4-whiskermenu-plugin-2.10.0-bp157.2.3.1.ppc64le.rpm xfce4-whiskermenu-plugin-debuginfo-2.10.0-bp157.2.3.1.ppc64le.rpm xfce4-whiskermenu-plugin-debugsource-2.10.0-bp157.2.3.1.ppc64le.rpm xfce4-xkb-plugin-0.9.0-bp157.2.3.1.ppc64le.rpm xfce4-xkb-plugin-debuginfo-0.9.0-bp157.2.3.1.ppc64le.rpm xfce4-xkb-plugin-debugsource-0.9.0-bp157.2.3.1.ppc64le.rpm libxfdashboard0-1.1.0-bp157.3.3.1.ppc64le.rpm libxfdashboard0-debuginfo-1.1.0-bp157.3.3.1.ppc64le.rpm xfdashboard-1.1.0-bp157.3.3.1.ppc64le.rpm xfdashboard-debuginfo-1.1.0-bp157.3.3.1.ppc64le.rpm xfdashboard-debugsource-1.1.0-bp157.3.3.1.ppc64le.rpm xfdashboard-devel-1.1.0-bp157.3.3.1.ppc64le.rpm xfdesktop-4.20.1-bp157.2.3.1.ppc64le.rpm xfdesktop-debuginfo-4.20.1-bp157.2.3.1.ppc64le.rpm xfdesktop-debugsource-4.20.1-bp157.2.3.1.ppc64le.rpm xfmpc-0.4.0-bp157.2.3.1.ppc64le.rpm xfmpc-debuginfo-0.4.0-bp157.2.3.1.ppc64le.rpm xfmpc-debugsource-0.4.0-bp157.2.3.1.ppc64le.rpm gigolo-0.6.0-bp157.2.3.1.s390x.rpm gigolo-debuginfo-0.6.0-bp157.2.3.1.s390x.rpm gigolo-debugsource-0.6.0-bp157.2.3.1.s390x.rpm libxfce4kbd-private-3-0-4.20.2-bp157.2.3.1.s390x.rpm libxfce4kbd-private-3-0-debuginfo-4.20.2-bp157.2.3.1.s390x.rpm libxfce4ui-2-0-4.20.2-bp157.2.3.1.s390x.rpm libxfce4ui-2-0-debuginfo-4.20.2-bp157.2.3.1.s390x.rpm libxfce4ui-debuginfo-4.20.2-bp157.2.3.1.s390x.rpm libxfce4ui-debugsource-4.20.2-bp157.2.3.1.s390x.rpm libxfce4ui-devel-4.20.2-bp157.2.3.1.s390x.rpm libxfce4ui-devel-debuginfo-4.20.2-bp157.2.3.1.s390x.rpm libxfce4ui-tools-4.20.2-bp157.2.3.1.s390x.rpm libxfce4ui-tools-debuginfo-4.20.2-bp157.2.3.1.s390x.rpm typelib-1_0-Libxfce4ui-2_0-4.20.2-bp157.2.3.1.s390x.rpm libxfce4windowing-0-0-4.20.4-bp157.2.3.1.s390x.rpm libxfce4windowing-0-0-debuginfo-4.20.4-bp157.2.3.1.s390x.rpm libxfce4windowing-debuginfo-4.20.4-bp157.2.3.1.s390x.rpm libxfce4windowing-debugsource-4.20.4-bp157.2.3.1.s390x.rpm libxfce4windowing-devel-4.20.4-bp157.2.3.1.s390x.rpm libxfce4windowingui-0-0-4.20.4-bp157.2.3.1.s390x.rpm libxfce4windowingui-0-0-debuginfo-4.20.4-bp157.2.3.1.s390x.rpm typelib-1_0-Libxfce4windowing-0_0-4.20.4-bp157.2.3.1.s390x.rpm typelib-1_0-Libxfce4windowingui-0_0-4.20.4-bp157.2.3.1.s390x.rpm orage-4.20.2-bp157.2.3.1.s390x.rpm orage-debuginfo-4.20.2-bp157.2.3.1.s390x.rpm orage-debugsource-4.20.2-bp157.2.3.1.s390x.rpm parole-4.20.0-bp157.2.3.1.s390x.rpm parole-debuginfo-4.20.0-bp157.2.3.1.s390x.rpm parole-debugsource-4.20.0-bp157.2.3.1.s390x.rpm parole-devel-4.20.0-bp157.2.3.1.s390x.rpm pragha-1.3.99.1-bp157.2.3.1.s390x.rpm pragha-debuginfo-1.3.99.1-bp157.2.3.1.s390x.rpm pragha-debugsource-1.3.99.1-bp157.2.3.1.s390x.rpm pragha-plugins-1.3.99.1-bp157.2.3.1.s390x.rpm pragha-plugins-debuginfo-1.3.99.1-bp157.2.3.1.s390x.rpm pragha-plugins-devel-1.3.99.1-bp157.2.3.1.s390x.rpm thunar-archive-plugin-0.6.0-bp157.2.3.1.s390x.rpm thunar-archive-plugin-debuginfo-0.6.0-bp157.2.3.1.s390x.rpm thunar-archive-plugin-debugsource-0.6.0-bp157.2.3.1.s390x.rpm thunar-media-tags-plugin-0.6.0-bp157.2.3.1.s390x.rpm thunar-media-tags-plugin-debuginfo-0.6.0-bp157.2.3.1.s390x.rpm thunar-media-tags-plugin-debugsource-0.6.0-bp157.2.3.1.s390x.rpm thunar-shares-plugin-0.5.0-bp157.2.3.1.s390x.rpm thunar-shares-plugin-debuginfo-0.5.0-bp157.2.3.1.s390x.rpm thunar-shares-plugin-debugsource-0.5.0-bp157.2.3.1.s390x.rpm thunar-vcs-plugin-0.4.0-bp157.2.3.1.s390x.rpm thunar-vcs-plugin-debuginfo-0.4.0-bp157.2.3.1.s390x.rpm thunar-vcs-plugin-debugsource-0.4.0-bp157.2.3.1.s390x.rpm libthunarx-3-0-4.20.6-bp157.2.3.2.s390x.rpm libthunarx-3-0-debuginfo-4.20.6-bp157.2.3.2.s390x.rpm thunar-4.20.6-bp157.2.3.2.s390x.rpm thunar-debuginfo-4.20.6-bp157.2.3.2.s390x.rpm thunar-debugsource-4.20.6-bp157.2.3.2.s390x.rpm thunar-devel-4.20.6-bp157.2.3.2.s390x.rpm typelib-1_0-Thunarx-3_0-4.20.6-bp157.2.3.2.s390x.rpm libtumbler-1-0-4.20.1-bp157.3.3.1.s390x.rpm libtumbler-1-0-debuginfo-4.20.1-bp157.3.3.1.s390x.rpm tumbler-4.20.1-bp157.3.3.1.s390x.rpm tumbler-debuginfo-4.20.1-bp157.3.3.1.s390x.rpm tumbler-debugsource-4.20.1-bp157.3.3.1.s390x.rpm tumbler-devel-4.20.1-bp157.3.3.1.s390x.rpm xfburn-0.8.0-bp157.2.3.1.s390x.rpm xfburn-debuginfo-0.8.0-bp157.2.3.1.s390x.rpm xfburn-debugsource-0.8.0-bp157.2.3.1.s390x.rpm xfce4-battery-plugin-1.2.0-bp157.2.3.1.s390x.rpm xfce4-battery-plugin-debuginfo-1.2.0-bp157.2.3.1.s390x.rpm xfce4-battery-plugin-debugsource-1.2.0-bp157.2.3.1.s390x.rpm xfce4-calculator-plugin-0.8.0-bp157.2.3.1.s390x.rpm xfce4-calculator-plugin-debuginfo-0.8.0-bp157.2.3.1.s390x.rpm xfce4-calculator-plugin-debugsource-0.8.0-bp157.2.3.1.s390x.rpm xfce4-clipman-plugin-1.7.0-bp157.2.3.1.s390x.rpm xfce4-clipman-plugin-debuginfo-1.7.0-bp157.2.3.1.s390x.rpm xfce4-clipman-plugin-debugsource-1.7.0-bp157.2.3.1.s390x.rpm xfce4-cpufreq-plugin-1.3.0-bp157.2.3.2.s390x.rpm xfce4-cpufreq-plugin-debuginfo-1.3.0-bp157.2.3.2.s390x.rpm xfce4-cpufreq-plugin-debugsource-1.3.0-bp157.2.3.2.s390x.rpm xfce4-cpugraph-plugin-1.3.0-bp157.2.3.2.s390x.rpm xfce4-cpugraph-plugin-debuginfo-1.3.0-bp157.2.3.2.s390x.rpm xfce4-cpugraph-plugin-debugsource-1.3.0-bp157.2.3.2.s390x.rpm xfce4-dict-0.8.9-bp157.2.3.1.s390x.rpm xfce4-dict-debuginfo-0.8.9-bp157.2.3.1.s390x.rpm xfce4-dict-debugsource-0.8.9-bp157.2.3.1.s390x.rpm xfce4-panel-plugin-dict-0.8.9-bp157.2.3.1.s390x.rpm xfce4-panel-plugin-dict-debuginfo-0.8.9-bp157.2.3.1.s390x.rpm xfce4-diskperf-plugin-2.8.0-bp157.2.3.2.s390x.rpm xfce4-diskperf-plugin-debuginfo-2.8.0-bp157.2.3.2.s390x.rpm xfce4-diskperf-plugin-debugsource-2.8.0-bp157.2.3.2.s390x.rpm xfce4-docklike-plugin-0.5.0-bp157.2.3.2.s390x.rpm xfce4-docklike-plugin-debuginfo-0.5.0-bp157.2.3.2.s390x.rpm xfce4-docklike-plugin-debugsource-0.5.0-bp157.2.3.2.s390x.rpm xfce4-eyes-plugin-4.7.0-bp157.2.3.2.s390x.rpm xfce4-eyes-plugin-debuginfo-4.7.0-bp157.2.3.2.s390x.rpm xfce4-eyes-plugin-debugsource-4.7.0-bp157.2.3.2.s390x.rpm xfce4-fsguard-plugin-1.2.0-bp157.2.3.2.s390x.rpm xfce4-fsguard-plugin-debuginfo-1.2.0-bp157.2.3.2.s390x.rpm xfce4-fsguard-plugin-debugsource-1.2.0-bp157.2.3.2.s390x.rpm xfce4-genmon-plugin-4.3.0-bp157.2.3.2.s390x.rpm xfce4-genmon-plugin-debuginfo-4.3.0-bp157.2.3.2.s390x.rpm xfce4-genmon-plugin-debugsource-4.3.0-bp157.2.3.2.s390x.rpm xfce4-mailwatch-plugin-1.4.0-bp157.2.3.1.s390x.rpm xfce4-mailwatch-plugin-debuginfo-1.4.0-bp157.2.3.1.s390x.rpm xfce4-mailwatch-plugin-debugsource-1.4.0-bp157.2.3.1.s390x.rpm xfce4-mount-plugin-1.2.0-bp157.2.3.2.s390x.rpm xfce4-mount-plugin-debuginfo-1.2.0-bp157.2.3.2.s390x.rpm xfce4-mount-plugin-debugsource-1.2.0-bp157.2.3.2.s390x.rpm xfce4-mpc-plugin-0.6.0-bp157.2.3.2.s390x.rpm xfce4-mpc-plugin-debuginfo-0.6.0-bp157.2.3.2.s390x.rpm xfce4-mpc-plugin-debugsource-0.6.0-bp157.2.3.2.s390x.rpm xfce4-netload-plugin-1.5.0-bp157.2.3.2.s390x.rpm xfce4-netload-plugin-debuginfo-1.5.0-bp157.2.3.2.s390x.rpm xfce4-netload-plugin-debugsource-1.5.0-bp157.2.3.2.s390x.rpm xfce4-notes-plugin-1.12.0-bp157.2.3.2.s390x.rpm xfce4-notes-plugin-debuginfo-1.12.0-bp157.2.3.2.s390x.rpm xfce4-notes-plugin-debugsource-1.12.0-bp157.2.3.2.s390x.rpm libxfce4panel-2_0-4-4.20.5-bp157.2.3.1.s390x.rpm libxfce4panel-2_0-4-debuginfo-4.20.5-bp157.2.3.1.s390x.rpm typelib-1_0-Libxfce4panel-2_0-4.20.5-bp157.2.3.1.s390x.rpm xfce4-panel-4.20.5-bp157.2.3.1.s390x.rpm xfce4-panel-debuginfo-4.20.5-bp157.2.3.1.s390x.rpm xfce4-panel-debugsource-4.20.5-bp157.2.3.1.s390x.rpm xfce4-panel-devel-4.20.5-bp157.2.3.1.s390x.rpm xfce4-panel-restore-defaults-4.20.5-bp157.2.3.1.s390x.rpm xfce4-places-plugin-1.9.0-bp157.2.3.1.s390x.rpm xfce4-places-plugin-debuginfo-1.9.0-bp157.2.3.1.s390x.rpm xfce4-places-plugin-debugsource-1.9.0-bp157.2.3.1.s390x.rpm xfce4-screenshooter-1.11.2-bp157.2.3.1.s390x.rpm xfce4-screenshooter-debuginfo-1.11.2-bp157.2.3.1.s390x.rpm xfce4-screenshooter-debugsource-1.11.2-bp157.2.3.1.s390x.rpm xfce4-screenshooter-plugin-1.11.2-bp157.2.3.1.s390x.rpm xfce4-screenshooter-plugin-debuginfo-1.11.2-bp157.2.3.1.s390x.rpm xfce4-session-4.20.3-bp157.2.3.1.s390x.rpm xfce4-session-debuginfo-4.20.3-bp157.2.3.1.s390x.rpm xfce4-session-debugsource-4.20.3-bp157.2.3.1.s390x.rpm xfce4-settings-4.20.2-bp157.2.3.1.s390x.rpm xfce4-settings-color-4.20.2-bp157.2.3.1.s390x.rpm xfce4-settings-color-debuginfo-4.20.2-bp157.2.3.1.s390x.rpm xfce4-settings-debuginfo-4.20.2-bp157.2.3.1.s390x.rpm xfce4-settings-debugsource-4.20.2-bp157.2.3.1.s390x.rpm xfce4-smartbookmark-plugin-0.6.0-bp157.2.3.1.s390x.rpm xfce4-smartbookmark-plugin-debuginfo-0.6.0-bp157.2.3.1.s390x.rpm xfce4-smartbookmark-plugin-debugsource-0.6.0-bp157.2.3.1.s390x.rpm xfce4-stopwatch-plugin-0.6.0-bp157.2.3.1.s390x.rpm xfce4-stopwatch-plugin-debuginfo-0.6.0-bp157.2.3.1.s390x.rpm xfce4-stopwatch-plugin-debugsource-0.6.0-bp157.2.3.1.s390x.rpm xfce4-systemload-plugin-1.4.0-bp157.2.3.1.s390x.rpm xfce4-systemload-plugin-debuginfo-1.4.0-bp157.2.3.1.s390x.rpm xfce4-systemload-plugin-debugsource-1.4.0-bp157.2.3.1.s390x.rpm xfce4-taskmanager-1.6.0-bp157.2.3.1.s390x.rpm xfce4-taskmanager-debuginfo-1.6.0-bp157.2.3.1.s390x.rpm xfce4-taskmanager-debugsource-1.6.0-bp157.2.3.1.s390x.rpm xfce4-time-out-plugin-1.2.0-bp157.2.3.1.s390x.rpm xfce4-time-out-plugin-debuginfo-1.2.0-bp157.2.3.1.s390x.rpm xfce4-time-out-plugin-debugsource-1.2.0-bp157.2.3.1.s390x.rpm xfce4-timer-plugin-1.8.0-bp157.2.3.1.s390x.rpm xfce4-timer-plugin-debuginfo-1.8.0-bp157.2.3.1.s390x.rpm xfce4-timer-plugin-debugsource-1.8.0-bp157.2.3.1.s390x.rpm xfce4-verve-plugin-2.1.0-bp157.2.3.1.s390x.rpm xfce4-verve-plugin-debuginfo-2.1.0-bp157.2.3.1.s390x.rpm xfce4-verve-plugin-debugsource-2.1.0-bp157.2.3.1.s390x.rpm xfce4-wavelan-plugin-0.7.0-bp157.2.3.1.s390x.rpm xfce4-wavelan-plugin-debuginfo-0.7.0-bp157.2.3.1.s390x.rpm xfce4-wavelan-plugin-debugsource-0.7.0-bp157.2.3.1.s390x.rpm xfce4-weather-plugin-0.12.0-bp157.2.3.1.s390x.rpm xfce4-weather-plugin-debuginfo-0.12.0-bp157.2.3.1.s390x.rpm xfce4-weather-plugin-debugsource-0.12.0-bp157.2.3.1.s390x.rpm xfce4-whiskermenu-plugin-2.10.0-bp157.2.3.1.s390x.rpm xfce4-whiskermenu-plugin-debuginfo-2.10.0-bp157.2.3.1.s390x.rpm xfce4-whiskermenu-plugin-debugsource-2.10.0-bp157.2.3.1.s390x.rpm xfce4-xkb-plugin-0.9.0-bp157.2.3.1.s390x.rpm xfce4-xkb-plugin-debuginfo-0.9.0-bp157.2.3.1.s390x.rpm xfce4-xkb-plugin-debugsource-0.9.0-bp157.2.3.1.s390x.rpm libxfdashboard0-1.1.0-bp157.3.3.1.s390x.rpm libxfdashboard0-debuginfo-1.1.0-bp157.3.3.1.s390x.rpm xfdashboard-1.1.0-bp157.3.3.1.s390x.rpm xfdashboard-debuginfo-1.1.0-bp157.3.3.1.s390x.rpm xfdashboard-debugsource-1.1.0-bp157.3.3.1.s390x.rpm xfdashboard-devel-1.1.0-bp157.3.3.1.s390x.rpm xfdesktop-4.20.1-bp157.2.3.1.s390x.rpm xfdesktop-debuginfo-4.20.1-bp157.2.3.1.s390x.rpm xfdesktop-debugsource-4.20.1-bp157.2.3.1.s390x.rpm xfmpc-0.4.0-bp157.2.3.1.s390x.rpm xfmpc-debuginfo-0.4.0-bp157.2.3.1.s390x.rpm xfmpc-debugsource-0.4.0-bp157.2.3.1.s390x.rpm openSUSE-2025-423 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 142.0.7444.134 (boo#1253089): * CVE-2025-12725: Out of bounds write in WebGPU * CVE-2025-12726: Inappropriate implementation in Views * CVE-2025-12727: Inappropriate implementation in V8 * CVE-2025-12728: Inappropriate implementation in Omnibox * CVE-2025-12729: Inappropriate implementation in Omnibox chromedriver-142.0.7444.134-bp157.2.79.1.x86_64.rpm chromium-142.0.7444.134-bp157.2.79.1.nosrc.rpm chromium-142.0.7444.134-bp157.2.79.1.x86_64.rpm chromedriver-142.0.7444.134-bp157.2.79.1.aarch64.rpm chromium-142.0.7444.134-bp157.2.79.1.aarch64.rpm chromedriver-142.0.7444.134-bp157.2.79.1.ppc64le.rpm chromium-142.0.7444.134-bp157.2.79.1.ppc64le.rpm openSUSE-2025-428 Security update for python-pdfminer.six important openSUSE Backports SLE-15-SP7 Update This update for python-pdfminer.six fixes the following issues: - CVE-2025-64512: Fixed executing of arbitrary code from a malicious pickle file (bsc#1253228). python-pdfminer.six-20200124-bp157.2.3.1.src.rpm python3-pdfminer.six-20200124-bp157.2.3.1.noarch.rpm openSUSE-2025-430 Security update for chromium important openSUSE Backports SLE-15-SP7 Update Chromium was updated to 142.0.7444.162 (boo#1253267) to fix: * CVE-2025-13042: Inappropriate implementation in V8 chromedriver-142.0.7444.162-bp157.2.82.1.x86_64.rpm chromium-142.0.7444.162-bp157.2.82.1.nosrc.rpm chromium-142.0.7444.162-bp157.2.82.1.x86_64.rpm chromedriver-142.0.7444.162-bp157.2.82.1.aarch64.rpm chromium-142.0.7444.162-bp157.2.82.1.aarch64.rpm chromedriver-142.0.7444.162-bp157.2.82.1.ppc64le.rpm chromium-142.0.7444.162-bp157.2.82.1.ppc64le.rpm openSUSE-2025-431 Recommended update for nmon moderate openSUSE Backports SLE-15-SP7 Update This update for nmon fixes the following issues: - update to 16q: * bugfixes - update to 16p: * Small improvements to on-screen use only : + CLI -B and GUI 'B' to toggle boxes around stats. + CLI -^ and '^' to change units for Disk I/O KB/s -> MB/s -> GB/s. This happen temporarily too if the size of the statistic will not fit on-scree. * Code changed to ensure clean compile for GCC 12 HAMA servers) and small fixes snprintf/strncpy. * POWER pool_capacity now correctly divided by 100. * Online view POWER Welcome panel on POWER reports the top MHz Small changes only: mode with "-J" stats (m) * Boottime shown online in the Kernel "k" panel * Utilisation stats: /proc/stat now reports 10 Utilisation stats * Bug caused Seg Faults core dumps fixed while collecting to a * Fix: Improved memory handling for extreme numbers of processes (1000's) or rapid exec of processes (100's in a millisecond) for large Linux servers. We have examples on Intel of 80 CPU * Online Dot "." command no longer also changes what is displayed as users said it was confusing. * Minor online start-up flash screen text changes to include C concise CPU stats and U for full Utilisation stats (all 10 of them) instead of a file. * Copyright and GPL v3 notice in the code plus online "h" and * Source code re-indented. * Fixes for Welcome screen on Mainframe * Fixed for Curses handling when collecting data to file - big bug for main frame and x86. * Fixes for Welcome screen on Mainframe * Fixed for Curses handling when collecting data to file - big bug for main frame and x86. + You need a S822LC With NVIDIA GPU(s) and Nvidia Library installed libnvidia-ml.so * CPU Wide View - online view for up to 192 CPUs * CPU MHz per Core ratings for machine that allow cores with different MHz - online & saved to file * lscpu stats capture - online & to file * Z experiment mode showing CPU interrupts - Renamed U stats in version 16b - online only * Online colourising stats to aid usability - online only * Massive improvement in help information: nmon -? and nmon -h * Code change to alphabetic order for getopt() and key input * New nmon logo on flash screen - online only * Extra kernel stats - online only nmon-16q-bp157.2.3.1.src.rpm nmon-16q-bp157.2.3.1.x86_64.rpm nmon-16q-bp157.2.3.1.i586.rpm nmon-16q-bp157.2.3.1.aarch64.rpm nmon-16q-bp157.2.3.1.ppc64le.rpm nmon-16q-bp157.2.3.1.s390x.rpm openSUSE-2025-456 Optional update for rust-bindgen low openSUSE Backports SLE-15-SP7 Update This update for rust-bindgen provides version 0.72.0, a build dependency of an upcoming version of Chromium (boo#1253246). rust-bindgen-0.72.0-bp157.2.3.2.src.rpm rust-bindgen-0.72.0-bp157.2.3.2.x86_64.rpm rust-bindgen-debuginfo-0.72.0-bp157.2.3.2.x86_64.rpm rust-bindgen-debugsource-0.72.0-bp157.2.3.2.x86_64.rpm rust-bindgen-0.72.0-bp157.2.3.2.i586.rpm rust-bindgen-debuginfo-0.72.0-bp157.2.3.2.i586.rpm rust-bindgen-debugsource-0.72.0-bp157.2.3.2.i586.rpm rust-bindgen-0.72.0-bp157.2.3.2.aarch64.rpm rust-bindgen-debuginfo-0.72.0-bp157.2.3.2.aarch64.rpm rust-bindgen-debugsource-0.72.0-bp157.2.3.2.aarch64.rpm rust-bindgen-0.72.0-bp157.2.3.2.ppc64le.rpm rust-bindgen-debuginfo-0.72.0-bp157.2.3.2.ppc64le.rpm rust-bindgen-debugsource-0.72.0-bp157.2.3.2.ppc64le.rpm rust-bindgen-0.72.0-bp157.2.3.2.s390x.rpm rust-bindgen-debuginfo-0.72.0-bp157.2.3.2.s390x.rpm rust-bindgen-debugsource-0.72.0-bp157.2.3.2.s390x.rpm openSUSE-2025-434 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium 142.0.7444.175 (boo#1253698) fixes the following issues: * CVE-2025-13223: Type Confusion in V8 * CVE-2025-13224: Type Confusion in V8 chromedriver-142.0.7444.175-bp157.2.85.1.x86_64.rpm chromium-142.0.7444.175-bp157.2.85.1.nosrc.rpm chromium-142.0.7444.175-bp157.2.85.1.x86_64.rpm chromedriver-142.0.7444.175-bp157.2.85.1.aarch64.rpm chromium-142.0.7444.175-bp157.2.85.1.aarch64.rpm chromedriver-142.0.7444.175-bp157.2.85.1.ppc64le.rpm chromium-142.0.7444.175-bp157.2.85.1.ppc64le.rpm openSUSE-2025-435 Recommended update for monitoring-plugins, monitoring-plugins-smb moderate openSUSE Backports SLE-15-SP7 Update This update for monitoring-plugins, monitoring-plugins-smb fixes the following issues: monitoring-plugins is reintroduced in version 2.4.0. Changes in monitoring-plugins-smb: - Renamed package to monitoring-plugins-smb monitoring-plugins-2.4.0-bp157.2.1.src.rpm monitoring-plugins-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-all-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-breeze-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-by_ssh-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-cluster-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-common-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-cups-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-curl-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-dbi-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-dbi-mysql-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-dbi-pgsql-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-dbi-sqlite3-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-dhcp-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-dig-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-disk-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-disk_smb-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-dns-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-dummy-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-extras-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-file_age-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-flexlm-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-fping-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-hpjd-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-http-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-icmp-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-ide_smart-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-ifoperstatus-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-ifstatus-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-ircd-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-ldap-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-load-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-log-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-mailq-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-mrtg-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-mrtgtraf-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-mysql-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-nagios-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-nt-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-ntp_peer-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-ntp_time-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-nwstat-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-oracle-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-overcr-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-pgsql-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-ping-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-procs-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-radius-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-real-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-rpc-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-sensors-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-smtp-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-snmp-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-ssh-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-swap-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-tcp-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-time-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-ups-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-uptime-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-users-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-wave-2.4.0-bp157.2.1.x86_64.rpm monitoring-plugins-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-all-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-breeze-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-by_ssh-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-cluster-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-common-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-cups-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-curl-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-dbi-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-dbi-mysql-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-dbi-pgsql-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-dbi-sqlite3-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-dhcp-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-dig-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-disk-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-disk_smb-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-dns-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-dummy-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-extras-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-file_age-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-flexlm-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-fping-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-hpjd-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-http-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-icmp-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-ide_smart-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-ifoperstatus-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-ifstatus-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-ircd-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-ldap-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-load-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-log-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-mailq-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-mrtg-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-mrtgtraf-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-mysql-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-nagios-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-nt-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-ntp_peer-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-ntp_time-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-nwstat-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-oracle-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-overcr-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-pgsql-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-ping-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-procs-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-radius-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-real-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-rpc-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-sensors-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-smtp-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-snmp-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-ssh-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-swap-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-tcp-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-time-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-ups-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-uptime-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-users-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-wave-2.4.0-bp157.2.1.i586.rpm monitoring-plugins-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-all-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-breeze-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-by_ssh-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-cluster-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-common-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-cups-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-curl-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-dbi-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-dbi-mysql-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-dbi-pgsql-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-dbi-sqlite3-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-dhcp-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-dig-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-disk-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-disk_smb-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-dns-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-dummy-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-extras-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-file_age-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-flexlm-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-fping-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-hpjd-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-http-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-icmp-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-ide_smart-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-ifoperstatus-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-ifstatus-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-ircd-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-ldap-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-load-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-log-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-mailq-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-mrtg-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-mrtgtraf-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-mysql-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-nagios-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-nt-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-ntp_peer-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-ntp_time-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-nwstat-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-oracle-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-overcr-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-pgsql-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-ping-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-procs-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-radius-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-real-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-rpc-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-sensors-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-smtp-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-snmp-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-ssh-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-swap-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-tcp-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-time-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-ups-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-uptime-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-users-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-wave-2.4.0-bp157.2.1.aarch64.rpm monitoring-plugins-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-all-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-breeze-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-by_ssh-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-cluster-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-common-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-cups-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-curl-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-dbi-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-dbi-mysql-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-dbi-pgsql-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-dbi-sqlite3-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-dhcp-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-dig-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-disk-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-disk_smb-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-dns-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-dummy-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-extras-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-file_age-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-flexlm-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-fping-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-hpjd-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-http-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-icmp-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-ide_smart-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-ifoperstatus-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-ifstatus-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-ircd-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-ldap-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-load-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-log-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-mailq-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-mrtg-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-mrtgtraf-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-mysql-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-nagios-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-nt-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-ntp_peer-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-ntp_time-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-nwstat-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-oracle-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-overcr-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-pgsql-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-ping-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-procs-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-radius-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-real-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-rpc-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-sensors-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-smtp-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-snmp-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-ssh-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-swap-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-tcp-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-time-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-ups-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-uptime-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-users-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-wave-2.4.0-bp157.2.1.ppc64le.rpm monitoring-plugins-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-all-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-breeze-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-by_ssh-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-cluster-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-common-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-cups-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-curl-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-dbi-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-dbi-mysql-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-dbi-pgsql-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-dbi-sqlite3-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-dhcp-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-dig-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-disk-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-disk_smb-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-dns-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-dummy-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-extras-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-file_age-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-flexlm-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-fping-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-hpjd-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-http-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-icmp-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-ide_smart-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-ifoperstatus-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-ifstatus-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-ircd-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-ldap-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-load-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-log-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-mailq-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-mrtg-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-mrtgtraf-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-mysql-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-nagios-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-nt-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-ntp_peer-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-ntp_time-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-nwstat-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-oracle-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-overcr-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-pgsql-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-ping-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-procs-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-radius-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-real-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-rpc-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-smtp-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-snmp-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-ssh-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-swap-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-tcp-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-time-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-ups-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-uptime-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-users-2.4.0-bp157.2.1.s390x.rpm monitoring-plugins-wave-2.4.0-bp157.2.1.s390x.rpm openSUSE-2025-441 Recommended update for kanidm moderate openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: - Update to version 1.8.0~git0.42d0e864c: * Release 1.8.0 * 20251108 lld (#3944) * Improve uid/gid overlap message during IAM migration (#3943) * Release 1.8.0-pre * Release Prep (#3938) * 20251029 hmac name uniqueness (#3931) * sssshhhhh quiet there. (#3906) * Add support for proxyv1 (#3935) * 20251031 nss sync conn persist (#3921) * Improve offline authentication (#3934) * 20251005 multiple accept (#3933) * Add CSS to support forced-colors on the toggle switch (#3932) * Prevent replication certificate renewal deadlock * fix: ensure CLI exits with non-zero code on HTTP client errors (#3929) * Bump the all group with 5 updates (#3927) * 20251015 OIDC auth source (#3905) * Bump the all group with 2 updates (#3913) * Bump the all group with 2 updates (#3914) * Prevent users saving their credentials if there are none (#3805) * Fix passkey typos (#3907) * fix: Replace letter "d" by sink (#3909) * Bump the all group with 33 updates (#3898) * Fix: set OAuth2 JTI to session ID (#3901) * Open app links in new tabs (#3899) * 20251009 account/group schema changes (#3880) * [fix] Mail attribute on service accounts not accessible (#3893) * Correct RADIUS API token generation examples (#3890) * Foundations of message sending (#3878) * 20251010 drop eckeys (#3882) * Remove systemd notify-reload. (#3885) * Bump the all group with 3 updates (#3884) * 20250801 reference entries (#3863) * 20251009 3829 OIDC groups (#3879) * Bump the all group with 5 updates (#3876) * 20251003 im silly (#3874) * When no upgrade checks are performed, issue a status: PASS (#3873) * Example of ipv4 to ipv6 addr mapping. (#3871) * 20250919 csp again (#3856) * client_secret_post auth for oauth2 endpoints (#3833) * Fix some CLI things (#3870) * Bump the all group with 6 updates (#3869) * Use connection address for Proxy::Local Requests (#3868) * Dont prevalidate UAT on oauth2 routes (#3865) * Backup Compression (#3821) * fix: always throw error when pam_allowed_login_groups is empty in Kanidm unixd (#3840) * update oauth2 outline config example (#3826) * Syntax errors in openapi.json (#3859) * fix: stop duplicating logs in otel mode (#3704) * Update fedora docs, start to add authselect profile (#3806) * Document oauth2 shortnames in book (#3857) * Bump the all group with 9 updates (#3861) * fix: Revert adding fetching ui hints to the reset-credentials flow. (#3831) * 20250912 unixd performance (#3846) * Fix readme file for better readability (#3775) * Updates for rust 1.90 (#3855) * Add password check api (#3847) * Bump the all group with 3 updates (#3853) * Add form-action localhost to csp (#3849) * Bump the all group across 1 directory with 8 updates (#3845) * Bump actions/setup-python from 5 to 6 in the all group (#3842) * docs: Don't enable unixd Kanidm provider in safe default config (#3839) * Add yescrypt support (#3844) * fix: spelling (#3841) * Bump the all group with 2 updates (#3836) * Bump tracing-subscriber from 0.3.19 to 0.3.20 in the cargo group (#3832) * CLI gardening (#3819) * Bump the all group with 7 updates (#3823) * Bump actions/upload-pages-artifact from 3 to 4 in the all group (#3824) * Prevent memory exhaustion on freebsd builds (#3818) * Make it clearer why acceptor isnt available (#3812) * Minor: reduce logging verbosity during debug (#3810) * Handle IP addresses in replication SAN field (#3811) * Update to use the codec properly (#3807) * Show the admin page in the navbar when the user has experiment ui hint. (#3793) * Bump actions/checkout from 4 to 5 in the all group (#3803) * Bump the all group with 5 updates (#3804) * Update whatwg email validation regex (#3797) * Fix account recover-disable edge case (#3796) * Dynamic version for centos/fedora repository (#3794) * Resolve replication show-cert issue (#3792) * Add json codec wrapper for unix integration (#3789) * Break-glass account disable command (#3780) * Bump the all group across 1 directory with 11 updates (#3790) * Bump slab from 0.4.10 to 0.4.11 in the cargo group (#3788) * [webui] add members to group (#3786) * Bump actions/download-artifact from 4 to 5 in the all group (#3785) * Make it clearer why the user can't login with unixd (#3778) * fix: bump HSTS age to 2 years + 1 second (#3779) * updating packages (#3774) * Improve argon2id parameter search speed (#3768) * Improve error messages during server startup to identify failing cert… (#3771) * Update docs re PA and google (#3772) * Forget username if user no longer wants to be remembered (#3770) * 20250802 handle sec1 keys (#3769) * Trying to clean up order of operations in kanidm_unixd_tasks (#3762) * Bump the all group with 7 updates (#3764) * Provide correct access for RADIUS service accounts (#3759) * Fix a couple of commands in the OAuth2 Proxy examples (#3758) * Design doc for email messaging (#3729) * 20250725 unixd access token (#3751) * 20250729 dev version (#3757) kanidm-1.8.0~git0.42d0e864c-bp157.2.18.1.src.rpm kanidm-1.8.0~git0.42d0e864c-bp157.2.18.1.x86_64.rpm kanidm-clients-1.8.0~git0.42d0e864c-bp157.2.18.1.x86_64.rpm kanidm-docs-1.8.0~git0.42d0e864c-bp157.2.18.1.x86_64.rpm kanidm-server-1.8.0~git0.42d0e864c-bp157.2.18.1.x86_64.rpm kanidm-unixd-clients-1.8.0~git0.42d0e864c-bp157.2.18.1.x86_64.rpm kanidm-1.8.0~git0.42d0e864c-bp157.2.18.1.aarch64.rpm kanidm-clients-1.8.0~git0.42d0e864c-bp157.2.18.1.aarch64.rpm kanidm-docs-1.8.0~git0.42d0e864c-bp157.2.18.1.aarch64.rpm kanidm-server-1.8.0~git0.42d0e864c-bp157.2.18.1.aarch64.rpm kanidm-unixd-clients-1.8.0~git0.42d0e864c-bp157.2.18.1.aarch64.rpm openSUSE-2025-437 Security update for act important openSUSE Backports SLE-15-SP7 Update This update for act fixes the following issues: - CVE-2025-47913: Prevent panic in embedded golang.org/x/crypto/ssh/agent client when receiving unexpected message types for key listing or signing requests by returning a descriptive error instead. (boo#1253608) act-0.2.45-bp157.3.3.1.src.rpm act-0.2.45-bp157.3.3.1.x86_64.rpm act-0.2.45-bp157.3.3.1.i586.rpm act-0.2.45-bp157.3.3.1.aarch64.rpm act-0.2.45-bp157.3.3.1.ppc64le.rpm act-0.2.45-bp157.3.3.1.s390x.rpm openSUSE-2025-444 Recommended update for monitoring-plugins-smb moderate openSUSE Backports SLE-15-SP7 Update This update for monitoring-plugins-smb fixes the following issues: - Introduces monitoring-plugins-smb monitoring-plugins-smb-1.0-bp157.2.1.src.rpm monitoring-plugins-smb-1.0-bp157.2.1.x86_64.rpm monitoring-plugins-smb-1.0-bp157.2.1.i586.rpm monitoring-plugins-smb-1.0-bp157.2.1.aarch64.rpm monitoring-plugins-smb-1.0-bp157.2.1.ppc64le.rpm monitoring-plugins-smb-1.0-bp157.2.1.s390x.rpm openSUSE-2025-445 Security update for obs-service-cargo moderate openSUSE Backports SLE-15-SP7 Update This update for obs-service-cargo fixes the following issues: - Introduce obs-service-cargo version 7.2.0. obs-service-cargo-7.2.0-bp157.2.1.src.rpm obs-service-cargo-7.2.0-bp157.2.1.x86_64.rpm obs-service-cargo-7.2.0-bp157.2.1.i586.rpm obs-service-cargo-7.2.0-bp157.2.1.aarch64.rpm obs-service-cargo-7.2.0-bp157.2.1.ppc64le.rpm obs-service-cargo-7.2.0-bp157.2.1.s390x.rpm openSUSE-2025-438 Security update for libebml important openSUSE Backports SLE-15-SP7 Update This update for libebml fixes the following issues: - update to 1.4.5 (boo#1218432, CVE-2023-52339): * Fix invalid memory access (reading beyond allocated memory) due to missing integer overflow check. libebml-1.4.5-bp157.2.3.1.src.rpm libebml-debugsource-1.4.5-bp157.2.3.1.x86_64.rpm libebml-devel-1.4.5-bp157.2.3.1.x86_64.rpm libebml5-1.4.5-bp157.2.3.1.x86_64.rpm libebml5-debuginfo-1.4.5-bp157.2.3.1.x86_64.rpm libebml-debugsource-1.4.5-bp157.2.3.1.i586.rpm libebml-devel-1.4.5-bp157.2.3.1.i586.rpm libebml5-1.4.5-bp157.2.3.1.i586.rpm libebml5-32bit-1.4.5-bp157.2.3.1.x86_64.rpm libebml5-32bit-debuginfo-1.4.5-bp157.2.3.1.x86_64.rpm libebml5-debuginfo-1.4.5-bp157.2.3.1.i586.rpm libebml-debugsource-1.4.5-bp157.2.3.1.aarch64.rpm libebml-devel-1.4.5-bp157.2.3.1.aarch64.rpm libebml5-1.4.5-bp157.2.3.1.aarch64.rpm libebml5-64bit-1.4.5-bp157.2.3.1.aarch64_ilp32.rpm libebml5-64bit-debuginfo-1.4.5-bp157.2.3.1.aarch64_ilp32.rpm libebml5-debuginfo-1.4.5-bp157.2.3.1.aarch64.rpm libebml-debugsource-1.4.5-bp157.2.3.1.ppc64le.rpm libebml-devel-1.4.5-bp157.2.3.1.ppc64le.rpm libebml5-1.4.5-bp157.2.3.1.ppc64le.rpm libebml5-debuginfo-1.4.5-bp157.2.3.1.ppc64le.rpm libebml-debugsource-1.4.5-bp157.2.3.1.s390x.rpm libebml-devel-1.4.5-bp157.2.3.1.s390x.rpm libebml5-1.4.5-bp157.2.3.1.s390x.rpm libebml5-debuginfo-1.4.5-bp157.2.3.1.s390x.rpm openSUSE-2025-448 Recommended update for unison moderate openSUSE Backports SLE-15-SP7 Update This update for unison fixes the following issues: - Update to version 2.53.8 * Add ability to use reflinking instead of copying * Experimental default-off support to detect moves/renames - Update to verison 2.53.7 * Time remaining, when over 24h, shown as days and HMS instead of just HMS. * Stop using deprecated [GdkPixbuf.from_xpm_data] (avoids problems with some versions of gdkpixbuf). Attempt to avoid soundness issues with lablgtk while doing so. * Deprecation warning: support for external rsync will be removed unison-2.53.8-bp157.2.3.1.src.rpm unison-2.53.8-bp157.2.3.1.x86_64.rpm unison-text-2.53.8-bp157.2.3.1.x86_64.rpm unison-doc-2.53.8-bp157.2.3.1.src.rpm unison-doc-2.53.8-bp157.2.3.1.x86_64.rpm unison-2.53.8-bp157.2.3.1.aarch64.rpm unison-text-2.53.8-bp157.2.3.1.aarch64.rpm unison-doc-2.53.8-bp157.2.3.1.aarch64.rpm unison-2.53.8-bp157.2.3.1.ppc64le.rpm unison-text-2.53.8-bp157.2.3.1.ppc64le.rpm unison-doc-2.53.8-bp157.2.3.1.ppc64le.rpm unison-2.53.8-bp157.2.3.1.s390x.rpm unison-text-2.53.8-bp157.2.3.1.s390x.rpm unison-doc-2.53.8-bp157.2.3.1.s390x.rpm openSUSE-2025-455 Recommended update for kanidm moderate openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: - Update to version 1.8.3~git0.471c021f2: * Release 1.8.3 * Resolve infinite reauth loop - Update to version 1.8.1~git0.3d1bdfd13: * Release 1.8.1 * Small fixes (#3965) * Make log messages more verbose for issues with resources server (#3954) * unixd_tasks: update home alias symlink conditionally and atomically (#3947) * Manually handle form bytes to allow optional encoding (#3968) * Improve handling of ready event (#3967) * Fix typo in kanidm-ldap-sync (#3964) kanidm-1.8.3~git0.471c021f2-bp157.2.23.1.src.rpm kanidm-1.8.3~git0.471c021f2-bp157.2.23.1.x86_64.rpm kanidm-clients-1.8.3~git0.471c021f2-bp157.2.23.1.x86_64.rpm kanidm-clients-debuginfo-1.8.3~git0.471c021f2-bp157.2.23.1.x86_64.rpm kanidm-debugsource-1.8.3~git0.471c021f2-bp157.2.23.1.x86_64.rpm kanidm-docs-1.8.3~git0.471c021f2-bp157.2.23.1.x86_64.rpm kanidm-server-1.8.3~git0.471c021f2-bp157.2.23.1.x86_64.rpm kanidm-server-debuginfo-1.8.3~git0.471c021f2-bp157.2.23.1.x86_64.rpm kanidm-unixd-clients-1.8.3~git0.471c021f2-bp157.2.23.1.x86_64.rpm kanidm-unixd-clients-debuginfo-1.8.3~git0.471c021f2-bp157.2.23.1.x86_64.rpm kanidm-1.8.3~git0.471c021f2-bp157.2.23.1.aarch64.rpm kanidm-clients-1.8.3~git0.471c021f2-bp157.2.23.1.aarch64.rpm kanidm-clients-debuginfo-1.8.3~git0.471c021f2-bp157.2.23.1.aarch64.rpm kanidm-debuginfo-1.8.3~git0.471c021f2-bp157.2.23.1.aarch64.rpm kanidm-debugsource-1.8.3~git0.471c021f2-bp157.2.23.1.aarch64.rpm kanidm-docs-1.8.3~git0.471c021f2-bp157.2.23.1.aarch64.rpm kanidm-server-1.8.3~git0.471c021f2-bp157.2.23.1.aarch64.rpm kanidm-server-debuginfo-1.8.3~git0.471c021f2-bp157.2.23.1.aarch64.rpm kanidm-unixd-clients-1.8.3~git0.471c021f2-bp157.2.23.1.aarch64.rpm kanidm-unixd-clients-debuginfo-1.8.3~git0.471c021f2-bp157.2.23.1.aarch64.rpm openSUSE-2025-454 Security update for gitea-tea moderate openSUSE Backports SLE-15-SP7 Update This update for gitea-tea fixes the following issues: - Do not make config file group-readable. - update to 0.11.1: * 61d4e57 Fix Pr Create crash (#823) * 4f33146 add test for matching logins (#820) * 08b8398 Update README.md (#819) - CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input (boo#1251663) - CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents (boo#1251471) - update to 0.11.0: * Fix yaml output single quote (#814) * generate man page (#811) * feat: add validation for object-format flag in repo create command (#741) * Fix release version (#815) * update gitea sdk to v0.22 (#813) * don't fallback login directly (#806) * Check duplicated login name in interact mode when creating new login (#803) * Fix bug when output json with special chars (#801) * add debug mode and update readme (#805) * update go.mod to retract the wrong tag v1.3.3 (#802) * revert completion scripts removal (#808) * Remove pagination from context (#807) * Continue auth when failed to open browser (#794) * Fix bug (#793) * Fix tea login add with ssh public key bug (#789) * Add temporary authentication via environment variables (#639) * Fix attachment size (#787) * deploy image when tagging (#792) * Add Zip URL for release list (#788) * Use bubbletea instead of survey for interacting with TUI (#786) * capitalize a few items * rm out of date comparison file * README: Document logging in to gitea (#790) * remove autocomplete command (#782) * chore(deps): update ghcr.io/devcontainers/features/git-lfs docker tag to v1.2.5 (#773) * replace arch package url (#783) * fix: Reenable -p and --limit switches (#778) - Update to 0.10.1+git.1757695903.cc20b52: - feat: add validation for object-format flag in repo create command (see gh#openSUSE/openSUSE-git#60) - Fix release version - update gitea sdk to v0.22 - don't fallback login directly - Check duplicated login name in interact mode when creating new login - Fix bug when output json with special chars - add debug mode and update readme - update go.mod to retract the wrong tag v1.3.3 - revert completion scripts removal - Remove pagination from context - Continue auth when failed to open browser - Fix bug - Fix tea login add with ssh public key bug - Add temporary authentication via environment variables - Fix attachment size - deploy image when tagging - Add Zip URL for release list - Use bubbletea instead of survey for interacting with TUI - capitalize a few items - rm out of date comparison file - README: Document logging in to gitea - remove autocomplete command - chore(deps): update ghcr.io/devcontainers/features/git-lfs docker tag to v1.2.5 - replace arch package url - fix: Reenable `-p` and `--limit` switches gitea-tea-0.11.1-bp157.2.9.1.src.rpm gitea-tea-0.11.1-bp157.2.9.1.x86_64.rpm gitea-tea-bash-completion-0.11.1-bp157.2.9.1.noarch.rpm gitea-tea-zsh-completion-0.11.1-bp157.2.9.1.noarch.rpm gitea-tea-0.11.1-bp157.2.9.1.i586.rpm gitea-tea-0.11.1-bp157.2.9.1.aarch64.rpm gitea-tea-0.11.1-bp157.2.9.1.ppc64le.rpm gitea-tea-0.11.1-bp157.2.9.1.s390x.rpm openSUSE-2025-460 Security update for python-mistralclient moderate openSUSE Backports SLE-15-SP7 Update This update for python-mistralclient fixes the following issues: - CVE-2021-4472: Fixed a local file inclusion which may result in disclosure of arbitrary files content (boo#1254289) python-mistralclient-4.0.1-bp157.2.3.1.src.rpm python-mistralclient-doc-4.0.1-bp157.2.3.1.noarch.rpm python3-mistralclient-4.0.1-bp157.2.3.1.noarch.rpm openSUSE-2025-457 Security update for icinga2 important openSUSE Backports SLE-15-SP7 Update This update for icinga2 fixes the following issues: - Update to 2.14.5 * Bug Fixes - Don't close anonymous connections before sending the response for a certificate request #10337 - Performance data: Don't discard min/max values even if crit/warn thresholds aren’t given #10339 - Fix a failing test case on systems time_t is only 32 bits #10343 * Documentation - Document the -X option for the mail-host-notification and mail-service-notification commands #10335 - Include Nagios in the migration docs #10324 - Remove RHEL 7 from installation instructions #10334 - Add instructions for installing build dependencies on Windows Server #10336 - Update to 2.14.4 * Crash Fixes - Invalid DateTime#format() arguments in config and console on Windows Server 2016 and older. #10112 - Downtime scheduling at runtime with non-existent trigger. #10049 - Object creation at runtime during Icinga DB initialization. #10151 - Comment on a service of a non-existent host. #9861 * Miscellaneous Bugfixes - Lost notifications after recovery outside the notification time period. #10187 - TimePeriod/ScheduledDowntime exceeding specified date range. #9983 #10107 - Clean up failure for obsolete Downtimes. #10062 - ifw-api check command: use correct process-finished handler. #10140 - Email notification scripts: strip 0x0D (CR) for a proper Content-Type. #10061 - Several fixes and improvements of the code quality. #10066 #10214 #10254 #10263 #10264 * Cluster and API - Sync runtime objects in topological order to honor their dependencies. #10000 - Make parallel config syncs more robust. #10013 - After object creation via API fails, clean up properly for the next try. #10111 - Close HTTPS connections properly to prevent leaks. #10005 #10006 - Reduce the number of cluster messages in memory at the same time. #9991 #9999 #10210 - Once a cluster connection shall be closed, stop communicating. #10213 #10221 - Remove unnecessary blocking of semaphores. #9992 #9994 - Reduce unnecessary cluster messages setting the next check time. #10011 * Icinga DB and IDO - IDO: fix object relations after aborted synchronization. #10065 - Icinga DB, IDO: limit all timestamps to four year digits. #10058 #10059 - Icinga DB: limit execution_time and latency (milliseconds) to database schema. #10060 * Troubleshooting - Add /v1/debug/malloc_info which calls malloc_info(3) if available. #10015 - Add log messages about own network I/O. #9993 #10141 #10207 - Several fixes and improvements of log messages. #9997 #10021 #10209 * Windows - Update OpenSSL shipped on Windows to v3.0.15. #10170 - Update Boost shipped on Windows to v1.86. #10114 - Support CMake v3.29. #10037 - Don't require to build .msi as admin. #10137 - Build configuration scripts: allow custom $CMAKE_ARGS. #10312 * Documentation - Distributed Monitoring: add section "External CA/PKI". #9825 - Explain how to enable/disable debug logging on the fly. #9981 - Update supported OS versions and repository configuration. #10064 #10090 #10120 #10135 #10136 #10205 - Several fixes and improvements. #9960 #10050 #10071 #10156 #10194 - Replace broken links. #10115 #10118 #10282 - Fix typographical and similarly trivial errors. #9953 #9967 #10056 #10116 #10152 #10153 #10204 - Update to 2.14.3 - Security: fix TLS certificate validation bypass. CVE-2024-49369 (boo#1233310) - Security: update OpenSSL shipped on Windows to v3.0.15. - Windows: sign MSI packages with a certificate the OS trusts by default. - Update to 2.14.2 - InfluxDB: truncate timestamps to whole seconds to save disk space. #9969 - HttpServerConnection: log request processing time as well. #9970 - Update Boost shipped on Windows to v1.84. #9970 - Update to 2.14.1 * Security - Automatically renew own root CA and distribute it to all nodes. #9933 - Update OpenSSL shipped on Windows to v3.0.12. #9946 - Disable TLS renegotiation (handshake on existing connection). #9946 * Bugfixes - Icinga DB feature: fix crash due to missing NULL pointer check. #9946 - Icinga DB feature: fix data written into Redis crashing the Go daemon. #9946 - GelfWriter: fix deadlock on stop/reload caused by busy queue. #9947 - Don't lose notifications due to too long output, truncate it. #9947 * Enhancements - Discard duplicate problem notifications due to state filtering. #9932 - Speed up API filters targeting specific hosts/services to O(1). #9944 - POST /v1/console/*: return HTTP 503 while Icinga is reloading. #9947 - Update Boost shipped on Windows to v1.83. #9946 - Documentation: several fixes and improvements. #9921 - Update to 2.14.0 * Breaking Changes - Remove CheckResultReader (which has been deprecated since v2.9). #9714 - Remove StatusDataWriter (which has been deprecated since v2.9). #9715 - ElasticsearchWriter: drop support for Elasticsearch < v7. #9812 - Consider a checkable unreachable once one Dependency fails. Previously all of them had to fail. (Consult the upgrading docs.) #8218 - API: reject config modifications during reload with HTTP status 503. #9445 - icinga2 daemon: to reduce config load time, write file needed by icinga2 object list only if --dump-objects is given. #9586 #9591 - Default email notification scripts: link to Icinga DB Web, not the monitoring module. (Consult the upgrading docs.) #9742 #9757 - API: for security reasons hide TicketSalt in /v1/variables. #7863 * Icinga 2 Config DSL - Disallow global variable modification after config commit start (i.e. inside object/apply T "x" { ... }) to reduce config load time. #9740 - Forbid Dependency cycles at config load time. #8389 - Allow only strings in the arrays Host#groups, Service#groups and User#groups. Needed for consistency, especially by the IDO. #9057 - Disallow empty object names. (They worked only partially anyway.) #9409 * Enhancements - Significantly reduce config load time of large setups. #8118 #9555 #9557 #9572 #9577 #9603 #9608 #9627 #9648 #9657 #9662 - Allow to connect dependencies via redundancy groups. Only parents within one group are assumed to provide redundancy for each other. #8218 - Built-in check command ifw-api, communicates directly with the Icinga for Windows REST API. (Doesn't spawn a PowerShell process for that.) #9062 - JournaldLogger which logs to systemd journal. #9000 - API: POST /v1/objects: allow to discard some previously modified attributes, i.e. to restore the config files' values. #9783 - ElasticsearchWriter: support Elasticsearch v8. #9812 - Support $env.ENV_VAR_NAME$ macros. #8302 - Speed up Icinga DB config dump. #9524 - Default mail notification scripts: also print $host.notes$ and $service.notes$. #9713 - Enable built-in OpenSSL DH parameters to allow DHE TLS ciphers. #9811 - Clean up global default TLS cipher list to improve security. #9809 - Influxdb(2)Writer: write more precise timestamps (nanoseconds). #9599 * Bugfixes - Icinga DB feature: normalize several Redis data not to crash the Go daemon. #9772 #9775 #9792 #9793 #9794 #9805 - Fix parsing of perfdata across multiple lines in plugin output. #8969 - icinga check: fix last reload failure time. #8429 #9827 - Resolve macros inside custom vars of IcingaApplication. #9779 - SELinux: allow Icinga and its plugins to write to syslog. #9688 - ElasticsearchWriter: fix data buffer flush race condition during stop. #9810 - Trigger flexible downtimes not in the past if checkable is already down. #9726 - Send downtime expiration notifications immediately, not after up to a minute. #9726 * Cluster - Don't hang in timed out connection attempt. #9711 #9725 - Fix lost acknowledgements after re-connect. #9718 - cluster-zone check: don't complain about not connected other local zone members if there aren't any. #8595 - Allow agent to update executions delegated to it via /v1/actions/execute-command. #8627 * API - Disallow breaking inter-object relationships by changing relationship attributes at runtime, e.g. Service#host_name. #9407 - Correct several HTTP response status codes. #7958 #9354 - Correct Boolean field types previously reported by /v1/types as Number. #9514 * CLI - icinga2 daemon: fix -DConfiguration.Concurrency= flag which now allows to override the number of threads. #9643 - icinga2 node wizard: avoid unnecessary chown(2) which may fail and abort the wizard. #8744 - Correct several log messages. #8895 #8965 #9663 * ITL - Add linux_netdev check command. #9045 + Command Argument Changes - disk: don't pass -m (disk_megabytes) by default. #9642 - disk: pass -X fuse.portal (disk_exclude_type) by default. #9459 - http: support multiple -k (http_header) as array. #8574 - icmp: double defaults for -w (icmp_wpl) and -c (icmp_cpl). #9041 - logfiles: pass --winwarncrit (logfiles_winwarncrit) without argument. #9056 - nwc_health: pass SNMPv3-only args only when using SNMPv3. #9095 - vmware-esx-dc-runtime-tools and vmware-esx-soap-vm-runtime-tools: - rename --open-vm-tools to --open_vm_tools_ok (vmware_openvmtools). #9611 - Update to 2.13.8 * Bugfixes - Icinga DB feature: normalize several Redis data not to crash the Go daemon. #9814 - Don't hang in timed out connection attempt. #9815 - Trigger flexible downtimes not in the past if checkable is already down. #9817 - ElasticsearchWriter: fix data buffer flush race condition during stop. #9818 - SELinux: allow Icinga and its plugins to write to syslog. #9819 - Fix lost acknowledgements after re-connect. #9820 - Fix parsing of perfdata across multiple lines in plugin output. #9821 - cluster-zone check: don't complain about not connected other local zone members if there aren't any. #9822 * Updates - Update Boost shipped on Windows to v1.82. #9816 - Update OpenSSL shipped on Windows to v3.0.9. #9816 - Update vendored https://github.com/nlohmann/json to v3.9.1. #9816 - Update vendored https://github.com/nemtrif/utfcpp to v3.2.3. #9816 - Update to 2.13.7 * Security - Windows: update bundled OpenSSL to v1.1.1t. #9672 * Bugfixes - SELinux: fix user and domain creation by explicitly setting the role. #9690 - Signal handlers: don't interrupt and break plugins spawning. #9682 - Icinga DB: take check\_period into account during overdue calculation. #9679 - Avoid corrupted files: use fsync(2)/FlushFileBuffers() everywhere. #9681 - Solaris: fix compile error. #9680 * Enhancements - Windows: update bundled Boost to v1.81. #9678 - Documentation: several fixes and improvements. #9671 icinga2-2.14.5-bp157.3.3.1.src.rpm icinga2-2.14.5-bp157.3.3.1.x86_64.rpm icinga2-bin-2.14.5-bp157.3.3.1.x86_64.rpm icinga2-common-2.14.5-bp157.3.3.1.x86_64.rpm icinga2-doc-2.14.5-bp157.3.3.1.x86_64.rpm icinga2-ido-mysql-2.14.5-bp157.3.3.1.x86_64.rpm icinga2-ido-pgsql-2.14.5-bp157.3.3.1.x86_64.rpm nano-icinga2-2.14.5-bp157.3.3.1.x86_64.rpm vim-icinga2-2.14.5-bp157.3.3.1.x86_64.rpm icinga2-2.14.5-bp157.3.3.1.i586.rpm icinga2-bin-2.14.5-bp157.3.3.1.i586.rpm icinga2-common-2.14.5-bp157.3.3.1.i586.rpm icinga2-doc-2.14.5-bp157.3.3.1.i586.rpm icinga2-ido-mysql-2.14.5-bp157.3.3.1.i586.rpm icinga2-ido-pgsql-2.14.5-bp157.3.3.1.i586.rpm nano-icinga2-2.14.5-bp157.3.3.1.i586.rpm vim-icinga2-2.14.5-bp157.3.3.1.i586.rpm icinga2-2.14.5-bp157.3.3.1.aarch64.rpm icinga2-bin-2.14.5-bp157.3.3.1.aarch64.rpm icinga2-common-2.14.5-bp157.3.3.1.aarch64.rpm icinga2-doc-2.14.5-bp157.3.3.1.aarch64.rpm icinga2-ido-mysql-2.14.5-bp157.3.3.1.aarch64.rpm icinga2-ido-pgsql-2.14.5-bp157.3.3.1.aarch64.rpm nano-icinga2-2.14.5-bp157.3.3.1.aarch64.rpm vim-icinga2-2.14.5-bp157.3.3.1.aarch64.rpm openSUSE-2025-462 Recommended update for virtme moderate openSUSE Backports SLE-15-SP7 Update This update for virtme fixes the following issues: - Update to 1.39: * The most noticeable change in this release is the new Model Context Protocol (MCP) server. This feature lets you connect with AI assistants such as Claude, Cursor, etc., and use natural human language to automate kernel development tasks. In this way, AI agents can automatically configure kernels, apply patches from lore.kernel.org, and run commands within recompiled kernels. You can even have the AI agent perform bug bisection for you and run specific commands/scripts inside each recompiled version to determine whether the kernel is good or bad. * An additional feature is vCPU pinning (using the --pin CPU_LIST option), which enables binding virtual CPUs to particular physical host CPUs. This ensures more consistent performance testing within the vng guest environment. * The release also adds support for memoryless NUMA nodes, enablingusers to specify size=0 with the --numa argument to create NUMA nodes without memory. This capability can be useful for simulating heterogeneous architectures, where devices like GPUs are represented as memoryless NUMA nodes to model their CPU locality relationships. * Last, but not least, there's a new --shell BINARY option which lets users choose a different shell to use within the vng session, rather than using their system's default shell and a new --empty-password option that creates empty passwords in the vng guest, instead of blocking login for other users, enabling easier debugging and SSH access during testing. * Updated Python versions in CI (dropped EOL 3.8 and 3.9) * Various bug fixes in virtme-init * Enhanced documentation and README updates * Improved error handling and validation virtme-1.39-bp157.2.12.1.noarch.rpm virtme-1.39-bp157.2.12.1.src.rpm openSUSE-2025-458 Security update to chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 143.0.7499.40 (boo#1254429): * CVE-2025-13630: Type Confusion in V8 * CVE-2025-13631: Inappropriate implementation in Google Updater * CVE-2025-13632: Inappropriate implementation in DevTools * CVE-2025-13633: Use after free in Digital Credentials * CVE-2025-13634: Inappropriate implementation in Downloads * CVE-2025-13720: Bad cast in Loader * CVE-2025-13721: Race in v8 * CVE-2025-13635: Inappropriate implementation in Downloads * CVE-2025-13636: Inappropriate implementation in Split View * CVE-2025-13637: Inappropriate implementation in Downloads * CVE-2025-13638: Use after free in Media Stream * CVE-2025-13639: Inappropriate implementation in WebRTC * CVE-2025-13640: Inappropriate implementation in Passwords chromedriver-143.0.7499.40-bp157.2.88.1.x86_64.rpm chromium-143.0.7499.40-bp157.2.88.1.nosrc.rpm chromium-143.0.7499.40-bp157.2.88.1.x86_64.rpm chromedriver-143.0.7499.40-bp157.2.88.1.aarch64.rpm chromium-143.0.7499.40-bp157.2.88.1.aarch64.rpm chromedriver-143.0.7499.40-bp157.2.88.1.ppc64le.rpm chromium-143.0.7499.40-bp157.2.88.1.ppc64le.rpm openSUSE-2025-468 Recommended update for virtme moderate openSUSE Backports SLE-15-SP7 Update This update for virtme fixes the following issues: - Update to 1.40: * No significant change, this is just a very small hotfix release to solve a packaging problem introduced by a conflict with the new vng-mcp tool. * While at it, there're also some small improved hints in the MCP server, so that AI agents can better understand how to build the kernel using vng --build. virtme-1.40-bp157.2.15.1.noarch.rpm virtme-1.40-bp157.2.15.1.src.rpm openSUSE-2026-117 Security update for keybase-client important openSUSE Backports SLE-15-SP7 Update This update for keybase-client fixes the following issues: - CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (boo#1254023) - CVE-2025-47913: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (boo#1253563) - CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (boo#1253864) kbfs-6.2.8-bp157.2.3.15.x86_64.rpm kbfs-debuginfo-6.2.8-bp157.2.3.15.x86_64.rpm kbfs-git-6.2.8-bp157.2.3.15.x86_64.rpm kbfs-git-debuginfo-6.2.8-bp157.2.3.15.x86_64.rpm kbfs-tool-6.2.8-bp157.2.3.15.x86_64.rpm kbfs-tool-debuginfo-6.2.8-bp157.2.3.15.x86_64.rpm keybase-client-6.2.8-bp157.2.3.15.src.rpm keybase-client-6.2.8-bp157.2.3.15.x86_64.rpm keybase-client-debuginfo-6.2.8-bp157.2.3.15.x86_64.rpm kbfs-6.2.8-bp157.2.3.15.i586.rpm kbfs-debuginfo-6.2.8-bp157.2.3.15.i586.rpm kbfs-git-6.2.8-bp157.2.3.15.i586.rpm kbfs-git-debuginfo-6.2.8-bp157.2.3.15.i586.rpm kbfs-tool-6.2.8-bp157.2.3.15.i586.rpm kbfs-tool-debuginfo-6.2.8-bp157.2.3.15.i586.rpm keybase-client-6.2.8-bp157.2.3.15.i586.rpm keybase-client-debuginfo-6.2.8-bp157.2.3.15.i586.rpm kbfs-6.2.8-bp157.2.3.15.aarch64.rpm kbfs-debuginfo-6.2.8-bp157.2.3.15.aarch64.rpm kbfs-git-6.2.8-bp157.2.3.15.aarch64.rpm kbfs-git-debuginfo-6.2.8-bp157.2.3.15.aarch64.rpm kbfs-tool-6.2.8-bp157.2.3.15.aarch64.rpm kbfs-tool-debuginfo-6.2.8-bp157.2.3.15.aarch64.rpm keybase-client-6.2.8-bp157.2.3.15.aarch64.rpm keybase-client-debuginfo-6.2.8-bp157.2.3.15.aarch64.rpm kbfs-6.2.8-bp157.2.3.15.ppc64le.rpm kbfs-debuginfo-6.2.8-bp157.2.3.15.ppc64le.rpm kbfs-git-6.2.8-bp157.2.3.15.ppc64le.rpm kbfs-git-debuginfo-6.2.8-bp157.2.3.15.ppc64le.rpm kbfs-tool-6.2.8-bp157.2.3.15.ppc64le.rpm kbfs-tool-debuginfo-6.2.8-bp157.2.3.15.ppc64le.rpm keybase-client-6.2.8-bp157.2.3.15.ppc64le.rpm keybase-client-debuginfo-6.2.8-bp157.2.3.15.ppc64le.rpm kbfs-6.2.8-bp157.2.3.15.s390x.rpm kbfs-debuginfo-6.2.8-bp157.2.3.15.s390x.rpm kbfs-git-6.2.8-bp157.2.3.15.s390x.rpm kbfs-git-debuginfo-6.2.8-bp157.2.3.15.s390x.rpm kbfs-tool-6.2.8-bp157.2.3.15.s390x.rpm kbfs-tool-debuginfo-6.2.8-bp157.2.3.15.s390x.rpm keybase-client-6.2.8-bp157.2.3.15.s390x.rpm keybase-client-debuginfo-6.2.8-bp157.2.3.15.s390x.rpm openSUSE-2025-470 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 143.0.7499.109 (boo#1254776): * CVE-2025-14372: Use after free in Password Manager * CVE-2025-14373: Inappropriate implementation in Toolbar * third issue with an exploit is known to exist in the wild chromedriver-143.0.7499.109-bp157.2.91.1.x86_64.rpm chromium-143.0.7499.109-bp157.2.91.1.nosrc.rpm chromium-143.0.7499.109-bp157.2.91.1.x86_64.rpm chromedriver-143.0.7499.109-bp157.2.91.1.aarch64.rpm chromium-143.0.7499.109-bp157.2.91.1.aarch64.rpm chromedriver-143.0.7499.109-bp157.2.91.1.ppc64le.rpm chromium-143.0.7499.109-bp157.2.91.1.ppc64le.rpm openSUSE-2025-472 Recommended update for powerline moderate openSUSE Backports SLE-15-SP7 Update This update for powerline fixes the following issues: - Fix TypeError with python 3.13 in vim status line; upstream PR + test fix - Update to version 2.8.4: * Minor improvements and bug fixes. - Remove manual python script hashbangs fix, that's done now automatically by the %python_install macro. Fix problem of package requiring /usr/bin/python3.11.11 - Only recommend python311-i3ipc if i3 is installed - Make git-core a suitable alternative instead of python311-pygit2 - Fix powerline requiring both python2 and python3 * Added `output` option to i3wm.workspaces segment to filter workspaces based on powerline-2.8.4-bp157.2.3.1.src.rpm powerline-2.8.4-bp157.2.3.1.x86_64.rpm powerline-docs-2.8.4-bp157.2.3.1.noarch.rpm powerline-fonts-2.8.4-bp157.2.3.1.noarch.rpm tmux-powerline-2.8.4-bp157.2.3.1.noarch.rpm vim-plugin-powerline-2.8.4-bp157.2.3.1.noarch.rpm powerline-2.8.4-bp157.2.3.1.aarch64.rpm powerline-2.8.4-bp157.2.3.1.ppc64le.rpm powerline-2.8.4-bp157.2.3.1.s390x.rpm openSUSE-2025-473 Security update for icinga-php-library, icingaweb2 moderate openSUSE Backports SLE-15-SP7 Update This update for icinga-php-library, icingaweb2 fixes the following issues: Changes in icingaweb2: - Update to 2.12.6 - Search box shows many magnifying glasses for some community themes #5395 - Authentication hooks are not called with external backends #5415 - Improve Minimal layout #5386 - Update to 2.12.5 * PHP 8.4 Support We're again a little behind schedule, but now we support PHP 8.4! This means that installations on Ubuntu 25.04 and Fedora 42+ can now install Icinga Web without worrying about PHP related incompatibilities. Icinga packages will be available in the next few days. * Good Things Take Time There's only a single (notable) recent issue that is fixed with this release. All the others are a bit older. - External URLs set up as dashlets are not embedded the same as navigation items #5346 * But the team sat together a few weeks ago and fixed a bug here and there. And of course, also in Icinga Web! - Users who are not allowed to change the theme, cannot change the theme mode either #5385 - Improved compatibility with several SSO authentication providers #5000, #5227 - Filtering for older-than events with relative time does not work #5263 - Empty values are NULL in CSV exports #5350 * Breaking, Somewhat This is mainly for developers. With the support of PHP 8.4, we introduced a new environment variable, ICINGAWEB_ENVIRONMENT. Unless set to dev, Icinga Web will not show nor log deprecation notices anymore. - Update to 2.12.4 - Database login broken after upgrade #5343 - Update to 2.12.3 - XSS in embedded content CVE-2025-27405 - DOM-based XSS CVE-2025-27404 - Open redirect on login page CVE-2025-30164 - Reflected XSS CVE-2025-27609 - Login against Postgres DB is case-sensitive #5223 - Role list has no functioning quick search #5300 - After clicking on Check now, the page does not refresh itself #5293 - Service States display wrong since update to 2.12.2 #5290 - Set right version for icinga-php-library. - Fix usage of %requires_eq: invalid syntax previosly resulted in ignored lines and now properly returns an error. - Update to 2.12.2 - Sort by name of roles does not work properly #4789 - Settings menu flyout closes too fast / easy #5196 - CSP header is missing the script-src policy #5180 - Broken event overview due to IntlDateFormatter #5172 - Downtimes, which were started and canceled, are missing in the history #5176 - Usage of IcingaWeb2 api command returns 404, but is successful #5183 - Allow fontawesome icons as menu items #5205 - Error while opening a navigation root item #5177 - Dashlets twice in dashboard & not deletable #5203 - PluginOutputRenderer gets called twice #5271 - Graphs disappear after form controls are used #4996 - Make subgroups of custom variables fully collapsible #5256 - Provide group as required by RPM 4.19 - Update to 2.12.1 - Add PHP 8.3 support - Login Redirect Loop #5133 - UI database migration not fully compatible with PostgreSQL #5129 - Missing styles when logging out and in while CSP is enabled #5126 - Update to 2.12.0 - Support for PHP 8.2 #4918 - Support for Content-Security-Policy #4528 - Allow to initiate a refresh with __REFRESH__ #5108 - Don't refresh twice upon __CLOSE__ #5106 - Add event column-moved #5049 - Add copy-to-clipboard behavior #5041 - Access Oracle Database via tnsnames.ora / LDAP Naming Services #5062 - Reduce risk of crashing the x509 collector daemon #5115 - CSV export does not escape double quotes #4910 * Full changelog see: https://github.com/Icinga/icingaweb2/milestone/79?closed=1 - Massive changes in spec needed. - DB schema files are in schema not etc/schema in packaged tarball - Add subpackge php-fpm with php-fpm configuration. - Remove max php version restrictions for suse. - Fix rights for /etc/icingaweb2/enabledModules directory as upstream use. Changes in icinga-php-library: - Update to 1.17.0 - No changelog from upstream. - Update ot 0.14.1 - No changelog from upstream. - Remove unneded requires and buildrequires icinga-php-common. - Add missing requires. - Update to 0.13.0 - No changelog from upstream. - Update to 0.12.0 - No changelog from upstream. - Update to 0.11.0 - No changelog from upstream. icinga-php-library-0.17.0-bp157.2.3.1.noarch.rpm icinga-php-library-0.17.0-bp157.2.3.1.src.rpm icingacli-2.12.6-bp157.2.3.1.noarch.rpm icingaweb2-2.12.6-bp157.2.3.1.noarch.rpm icingaweb2-2.12.6-bp157.2.3.1.src.rpm icingaweb2-common-2.12.6-bp157.2.3.1.noarch.rpm icingaweb2-php-fpm-2.12.6-bp157.2.3.1.noarch.rpm php-icinga-2.12.6-bp157.2.3.1.noarch.rpm openSUSE-2025-474 Security update for flannel important openSUSE Backports SLE-15-SP7 Update This update for flannel fixes the following issues: - Update to version 0.27.4: * Removed PodSecurityPolicy manifest creation * Fix interface IP address detection in dual-stack mode * Fix: recreate VXLAN device (flannel.*) when external interface is deleted and re-added (#2247) * golangci-lint: fix iptables_test * firewall: add option to disable fully-random mode for MASQUERADE * Bump the tencent group with 2 updates * Bump github.com/coreos/go-systemd/v22 in the other-go-modules group * Bump golang.org/x/sys in the other-go-modules group * Bump the etcd group with 4 updates * Bump etcd version in tests * Stop using deprecated cache.NewIndexerInformer function * Bump k8s test version * Bump k8s deps to v0.31.11 * Bump the other-go-modules group with 2 updates * helm chart: add nodeSelector in the helm chart * Updated Alpine image * Added flag to enable blackhole route locally for Canal * Bump golang.org/x/sync in the other-go-modules group * make enqueueLeaseEvent context aware and prevent dangling goroutines when context is done - fixed a typo/build error * make retry interval exp backoff * cont_when_cache_not_ready configurable with fail by default * use semaphore as opposed to raw signal channel * Update pkg/subnet/kube/kube.go * Fix deadlock in startup for large clusters * enable setting resources in helm chart * capture close() err on subnet file save (#2248) * doc: document flag --iptables-forward-rules * Bump netlink to v1.3.1 * fix: clean-up rules when starting instead of shutting down * Bump k8s and sles test version * Add modprobe br_netfilter step in test workflows * test: don't run the workflows on "push" events * Update to the latest flannel cni-plugins v1.7.1 * Move to go 1.23.6 - Update to version 0.26.6: * Bump github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common * Bump the etcd group with 4 updates * Bump the tencent group with 2 updates * Organize dependabot PR's more clearly by using groups * Use peer's wireguard port, not our own * Bump to codeql v3 * Pin all GHA to a specific SHA commit * Bump github.com/golang-jwt/jwt/v4 from 4.5.1 to 4.5.2 (fix CVE-2025-30204, boo#1240516) * Bump github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common * Bump go.etcd.io/etcd/tests/v3 from 3.5.18 to 3.5.20 * add missing GH_TOKEN env var in release.yaml * Bump github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/vpc * Upload chart archive with the release files * make deps * refactor release.yaml to reduce use of potentially vulnerable GH Actions * Bump golang.org/x/net from 0.34.0 to 0.36.0 * enable setting CNI directory paths in helm chart * Added cni file configuration on the chart * Bump github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/vpc * Bump github.com/avast/retry-go/v4 from 4.6.0 to 4.6.1 - Update to version 0.26.4: * Moved to github container registry * Bump github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/vpc * Bump go.etcd.io/etcd/tests/v3 from 3.5.17 to 3.5.18 * fix: Fix high CPU usage when losing etcd connection and try to re-establish connection with exponential backoff * Bump github.com/containernetworking/plugins from 1.6.1 to 1.6.2 * Bump alpine from 20240923 to 20250108 in /images * Bump golang.org/x/net from 0.31.0 to 0.33.0 * Bump github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/vpc * Bump github.com/jonboulle/clockwork from 0.4.0 to 0.5.0 * feat: add bool to control CNI config installation using Helm * fix: add missing MY_NODE_NAME env in chart * Bump k8s deps to 0.29.12 * Don't panic upon shutdown when running in standalone mode * Bump golang.org/x/crypto from 0.29.0 to 0.31.0 * Bump alpine from 20240807 to 20240923 in /images * Bump github.com/containernetworking/plugins from 1.6.0 to 1.6.1 * Bump github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/vpc * Bump github.com/vishvananda/netns from 0.0.4 to 0.0.5 * Use the standard context library * Bump github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common * Updated flannel cni image to 1.6.0 * Updated CNI plugins version on the README * Bump sigs.k8s.io/knftables from 0.0.17 to 0.0.18 * Bump github.com/golang-jwt/jwt/v4 from 4.4.2 to 4.5.1 * Bump github.com/Microsoft/hcsshim from 0.12.8 to 0.12.9 * Added check to not check br_filter in case of windows * Bumo golangci-lint to latest version * Bump to go 1.23 * Added checks for br_netfilter module * Try not to cleanup multiple peers behind same PublicIP * fix trivy check * check that the lease includes an IP address of the requested family before configuring the flannel interface * Fixed IPv6 chosen in case of public-ipv6 configured * add timeout to e2e test pipelines * Update k8s version ine2e tests to v1.29.8 * Update netlink to v1.3.0 * Fixed values file on flannel chart * Bump k8s.io/klog/v2 from 2.120.1 to 2.130.1 * Updated Flannel chart with Netpol containter and removed clustercidr * Fix bug in hostgw-windows * Fix bug in the logic polling the interface * Added node-public-ip annotation * Try several times to contact kube-api before failing * Fixed IPv6 0 initialization * wireguard backend: avoid error message if route already exists * Bump github.com/avast/retry-go/v4 from 4.5.1 to 4.6.0 * use wait.PollUntilContextTimeout instead of deprecated wait.Poll * troubleshooting.md: add `ethtool -K flannel.1 tx-checksum-ip-generic off` for NAT * Added configuration for pulic-ip through node annotation * extension/vxlan: remove arp commands from vxlan examples * Refactor TrafficManager windows files to clarify logs * Add persistent-mac option to v6 too * fix comparison with previous networks in SetupAndEnsureMasqRules * show content of stdout and stderr when running iptables-restore returns an error * Add extra check before contacting kube-api * remove unimplemented error in windows trafficmngr * remove --dirty flags in git describe * Added leaseAttr string method with logs on VxLan * remove multiClusterCidr related-code. * Implement nftables masquerading for flannel * fix: ipv6 iptables rules were created even when IPv6 was disabled * Add tolerations to the flannel chart * Added additional check for n.spec.podCIDRs * Remove net-tools since it's an old package that we are not using * fix iptables_windows.go * Clean-up Makefile and use docker buildx locally * Use manual test to ensure iptables-* binaries are present * Bump github.com/containerd/containerd from 1.6.23 to 1.6.26 * Bump github.com/joho/godotenv * SubnetManager should use the main context * Simplify TrafficManager interface * refactor iptables package to prepare for nftables-based implementation - Update to version 0.24.2: * Prepare for v0.24.2 release * Increase the time out for interface checking in windows * Prepare for v0.24.1 release * Provide support to select the interface in Windows * Improve the log from powershell * Wait all the jobs to finish before deploy the github-page * remove remaining references to mips64le * add multi-arch dockerfile * add missing riscv64 in docker manifest create step * prepare for v0.24.0 release * Bump golang.org/x/crypto from 0.15.0 to 0.17.0 * Add the VNI to the error message in Windows * chart: add possibility for defining image pull secrets in daemonset * Remove multiclustercidr logic from code * Update opentelemetry dependencies * Bump go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc * Add riscv64 arch in GH actions * vxlan vni should not be type uint16 * Quote wireguard psk in helm chart * add riscv64 support - Update to 0.14.0: * Add tencent cloud VPC network support * moving go modules to flannel-io/flannel and updating to go 1.16 * fix(windows): nil pointer panic * Preserve environment for extension backend * Fix flannel hang if lease expired * Documentation for the Flannel upgrade/downgrade procedure * Move from glog to klog * fix(host-gw): failed to restart if gateway hnsep existed * ipsec: use well known paths of charon daemon * upgrade client-go to 1.19.4 * move from juju/errors to pkg/errors * subnets: move forward the cursor to skip illegal subnet * Fix Expired URL to Deploying Flannel with kubeadm * Modify kube-flannel.yaml to use rbac.authorization.k8s.io/v1 * preserve AccessKey & AccessKeySecret environment on sudo fix some typo in doc. * iptables: handle errors that prevent rule deletes - update to 0.13.0: * Use multi-arch Docker images in the Kubernetes manifest * Accept existing XMRF policies and update them intead of raising errors * Add --no-sanity-check to iptables-wrapper-installer.sh for architectures other than amd64 * Use "docker manifest" to publish multi-arch Docker images * Add NET_RAW capability to support cri-o * remove glide * switch to go modules * Add and implement iptables-wrapper-installer.sh from https://github.com/kubernetes-sigs/iptables-wrappers * documentation: set priorityClassName to system-node-critical * Added a hint for firewall rules * Disabling ipv6 accept_ra explicitely on the created interface * use alpine 3.12 everywhere * windows: replace old netsh (rakelkar/gonetsh) with powershell commands * fix CVE-2019-14697 * Bugfix: VtepMac would be empty when lease re-acquire for windows * Use stable os and arch label for node * doc(awsvpc): correct the required permissions - update to 0.12.0: * fix deleteLease * Use publicIP lookup iface if --public-ip indicated * kubernetes 1.16 cni error * Add cniVersion to general CNI plugin configuration. * Needs to clear NodeNetworkUnavailable flag on Kubernetes * Replaces gorillalabs go-powershell with bhendo/go-powershell * Make VXLAN device learning attribute configurable * change nodeSelector to nodeAffinity and schedule the pod to linux node * This PR adds the cni version to the cni-conf.yaml inside the kube-flannel-cfg configmap * EnableNonPersistent flag for Windows Overlay networks * snap package. * Update lease with DR Mac * main.go: add the "net-config-path" flag * Deploy Flannel with unprivileged PSP * Enable local host to local pod connectivity in Windows VXLAN * Update hcsshim for HostRoute policy in Windows VXLAN flannel-0.27.4-bp157.2.3.1.src.rpm flannel-0.27.4-bp157.2.3.1.x86_64.rpm flannel-k8s-yaml-0.27.4-bp157.2.3.1.noarch.rpm flannel-0.27.4-bp157.2.3.1.i586.rpm flannel-0.27.4-bp157.2.3.1.aarch64.rpm flannel-0.27.4-bp157.2.3.1.ppc64le.rpm flannel-0.27.4-bp157.2.3.1.s390x.rpm openSUSE-2025-479 Recommended update for kanidm moderate openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: - Update to version 1.8.4~git0.2449805e3: * Release 1.8.4 * Handle concurrent pam sessions. (#4001) * fix: correcting parsing of backup compression input (#3995) * fixing up docs builds (#4006) kanidm-1.8.4~git0.2449805e3-bp157.2.26.1.src.rpm kanidm-1.8.4~git0.2449805e3-bp157.2.26.1.x86_64.rpm kanidm-clients-1.8.4~git0.2449805e3-bp157.2.26.1.x86_64.rpm kanidm-docs-1.8.4~git0.2449805e3-bp157.2.26.1.x86_64.rpm kanidm-server-1.8.4~git0.2449805e3-bp157.2.26.1.x86_64.rpm kanidm-unixd-clients-1.8.4~git0.2449805e3-bp157.2.26.1.x86_64.rpm kanidm-1.8.4~git0.2449805e3-bp157.2.26.1.aarch64.rpm kanidm-clients-1.8.4~git0.2449805e3-bp157.2.26.1.aarch64.rpm kanidm-docs-1.8.4~git0.2449805e3-bp157.2.26.1.aarch64.rpm kanidm-server-1.8.4~git0.2449805e3-bp157.2.26.1.aarch64.rpm kanidm-unixd-clients-1.8.4~git0.2449805e3-bp157.2.26.1.aarch64.rpm openSUSE-2025-476 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 143.0.7499.146 (boo#1255115): * CVE-2025-14765: Use after free in WebGPU * CVE-2025-14766: Out of bounds read and write in V8 chromedriver-143.0.7499.146-bp157.2.94.1.x86_64.rpm chromium-143.0.7499.146-bp157.2.94.1.nosrc.rpm chromium-143.0.7499.146-bp157.2.94.1.x86_64.rpm chromedriver-143.0.7499.146-bp157.2.94.1.aarch64.rpm chromium-143.0.7499.146-bp157.2.94.1.aarch64.rpm chromedriver-143.0.7499.146-bp157.2.94.1.ppc64le.rpm chromium-143.0.7499.146-bp157.2.94.1.ppc64le.rpm openSUSE-2025-480 Recommended update for gh moderate openSUSE Backports SLE-15-SP7 Update This update for gh fixes the following issues: - Update to version 2.83.2: * Update licences * Bump dev-tunnels SDK 0.1.13 to 0.1.19 * Bump Go to 1.25.5 * Update licenses for go-containerregistry-0.20.7 bump * chore(deps): bump github.com/google/go-containerregistry * Update licenses for go-version-1.8.0 bump * chore(deps): bump github.com/hashicorp/go-version from 1.7.0 to 1.8.0 * Update licenses for tcell-2.13.1 bump * chore(deps): bump github.com/gdamore/tcell/v2 from 2.9.0 to 2.13.1 * chore: make licenses * refactor: drop multierror in favor of std * Bump Go to 1.25.4 * Update licenses for huh 0.8.0 bump * Fix accessible prompter tests with huh 0.8.0 upgrade * chore(deps): bump github.com/charmbracelet/huh from 0.7.0 to 0.8.0 * Update licenses with grpc-1.76.0 bump * chore(deps): bump google.golang.org/grpc from 1.75.0 to 1.76.0 * Update licenses for mimetype 1.4.11 bump * chore(deps): bump github.com/gabriel-vasile/mimetype * chore(deps): bump github.com/theupdateframework/go-tuf/v2 * chore(deps): bump golangci/golangci-lint-action from 9.0.0 to 9.1.0 * Update licenses for protobuf 1.36.10 bump * chore(deps): bump google.golang.org/protobuf from 1.36.9 to 1.36.10 * Error if go-licenses is not on the PATH * chore(deps): bump actions/checkout from 5 to 6 * Update licenses for crypto-0.45.0 bump * chore(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0 * Alphabetize Ubuntu section * Add Debian/Ubuntu to unofficial packages * Add PGP key rotation PoC (#12176) * refactor(pkg/search): rename `KeywordsVerbatim` to `ImmutableKeywords` * refactor(pkg/search): rewrite returns in a more verbose way * fix(pr/shared): delegate query compilation to `search` package * test(pkg/search): assert verbatim keywords are respected * fix(pkg/search): add `KeywordsVerbatim` field to `Query` type * Remove extra flag default from help usage * Refactor cfg out of CAPI Client - Update to version 2.83.1: * chore(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0 * Check user and teams nil state instead of length * Update third-party licenses and dependencies * Ensure empty arrays for reviewers in PR API calls * Update .github/workflows/lint.yml * Annotate go-licenses install with version tag * Integrate license checks back into lint workflow - Update to version 2.83.0: * chore(deps): bump github.com/cli/go-gh/v2 from 2.12.2 to 2.13.0 * Apply suggestions from code review * Add note on govulncheck source mode for Go 1.25 * docs(pkg/search): fix typo * docs(repo garden): improve func godoc * fix: ignore `nilerr` on intentionally swallowed error * fix: resolve `nilerr` issues * fix: resolve `copyloopvar` issues * fix: resolve `gocritic` issue * test(pkg/httpmock): ignore `bodyclose` on mock response value * refactor(repo garden): return pagination link instead of resp * fix: close resp body (bodyclose) * refactor: remove returned resp from `api.EndpointNeedsScopes` * refactor(pkg/search): remove passing resp for pagination * ci: enable basic linters * Update lint govulncheck to use source mode * chore: add `workflow_dispatch` to govulncheck triggers * Add example for --custom-agent usage * Update error messages in job creation tests * Update pkg/cmd/agent-task/capi/job.go * Add shorthand flag for custom-agent option * Fix: do not swallow job creation error * Clarify custom agent flag description * Add custom agent support to job creation * docs(release list): fix typo * docs(release list): reword comment * feat(release list): add `isImmutable` JSON field * fix(featuredetection): add `ReleaseFeatures` method * docs(api): add example for `--input` option * docs(api): mention use of `@<path>` and `@-` for `--field` * docs: update go version 1.25 * refactor: replace backport with `strings.CutSuffix` * chore: exclude `third-party` from Golangci-lint formatting paths * chore: bump Go in devcontainer * chore: apply `go fix` to remove deprecated `// +build` tags * fix: --interval flags docs in gh pr checks * test(gist/edit): add tests for single file edit and interactive multi-file selection * Update Go toolchain version to 1.24.9 * docs(run list): mention `pr checks` in help docs * ci: bump Golangci-lint to v2.6.0 * chore(deps): bump golang.org/x/crypto from 0.42.0 to 0.43.0 * chore(deps): bump golang.org/x/text from 0.29.0 to 0.30.0 * test(gist): fix failing tests * fix(gist): prevent fetching full content for already edited files * fix(gist): only include files that have changed in request * fix(gist): fetch full content for truncated files during editing * (repo delete) remove comprehensive assertions on check stderr output * Fix typo in comment for gh issue develop branch checkout command * (gh repo delete) Add warning when `--yes` is ignored without a repository, Closes: #12033 * chore(deps): bump github.com/rivo/tview * chore(deps): bump actions/download-artifact from 5 to 6 * chore(deps): bump actions/upload-artifact from 4 to 5 * Remove skipped tests * Make verifier choice more explicit * Return only basic pull request info when reverting a PR * chore(deps): bump mislav/bump-homebrew-formula-action from 3.4 to 3.6 * chore(deps): bump goreleaser/goreleaser-action from 6.3.0 to 6.4.0 * test fixup * Update release verify commands to use sentinel value * Initial plan * Make PGI verifier initialization non-fatal to allow GitHub attestation verification * Initial plan * improve docstring for release-create * Bump Go to 1.25.3 * Address remaining PR comments for revert implementation * Adjust PR revert based on new acceptance criteria * Return nil when err is nil * Fix revert unit tests by using renamed helper * feat: include revert PR info in message output * Undo autoformat changes * feat: implement `pr revert` * test(gist): add tests for handling truncated files in view command * test(gist): add tests for editing truncated gist files * test(gist): add tests for `GetRawGistFile` function * feat(gist): retrieve full content for truncated gist files * feat(gist): retrieve full content for truncated gist files * feat(gist): add `GetRawGistFile` function to retrieve raw gist content * feat(gist): add `RawURL` and `Truncated` fields to `GistFile` - Update to version 2.82.1: * Add test for non-interactive projects v1 unsupported * Inject Detector mock in edit command tests * Pass ProjectsV1Support to FetchOptions functions * chore(deps): bump github.com/gabriel-vasile/mimetype * Update .github/workflows/govulncheck.yml * chore(deps): bump github/codeql-action from 3 to 4 * chore(deps): Bump github.com/sigstore/sigstore-go from 1.1.0 to 1.1.3 * chore(deps): bump actions/attest-build-provenance from 2.4.0 to 3.0.0 - Update to version 2.82.0: * chore: run `go mod tidy` * refactor(auth refresh): use `PlainHttpClient` instead of zero `http.Client` * refactor(auth login): use `PlainHttpClient` for OAuth flow * refactor(authflow): receive HTTP client via args * fix(factory): add `PlainHttpClient` to factory * test(api): assert `SkipDefaultHeaders` is honoured * fix(api): expose `SkipDefaultHeaders` option * test(api): improve `NewHTTPClient` test assertions * Fix agentTaskCmd to use repoResolvingCmdFactory * Add new displaying message to test expectation * Fix --follow not killing the progress indicator * Apply suggestion from @babakks * Apply suggestion from @babakks * Fix argument order in httpStubs test functions * docs(cache delete): remove redundant comment * docs(cache delete): add godoc for `deleteCacheByKey` * Remove default empty slices in RemovePullRequestReviews * Fix typo in error message for required flags * Refactor reviewer partitioning in PR edit command * Escape repo owner and name in PR reviewer API paths * Remove unused ghIds function and githubv4 import * fix(cache): report correct deleted count for key and key+ref deletions * Refactor PR reviewer editing to use REST API and optimize team fetch gh-2.83.2-bp157.2.15.1.src.rpm gh-2.83.2-bp157.2.15.1.x86_64.rpm gh-bash-completion-2.83.2-bp157.2.15.1.noarch.rpm gh-fish-completion-2.83.2-bp157.2.15.1.noarch.rpm gh-zsh-completion-2.83.2-bp157.2.15.1.noarch.rpm gh-2.83.2-bp157.2.15.1.i586.rpm gh-2.83.2-bp157.2.15.1.aarch64.rpm gh-2.83.2-bp157.2.15.1.ppc64le.rpm gh-2.83.2-bp157.2.15.1.s390x.rpm openSUSE-2025-484 Recommended update for timescaledb moderate openSUSE Backports SLE-15-SP7 Update This update for timescaledb fixes the following issues: - postgresql18 enablement. - Update to version 2.24.0 This release contains performance improvements and bug fixes since the 2.23.1 release. We recommend that you upgrade at the next available opportunity. Highlighted features in TimescaleDB v2.24.0 - Direct Compress just got smarter and faster: it now works seamlessly with hypertables generating continuous aggregates. Invalidation ranges are computed directly in-memory based on the ingested batches and written efficiently at transaction commit. This change reduces the IO footprint drastically by removing the write amplification of the invalidation logs. - Continuous aggregates now speak UUIDv7: hypertables partitioned by UUIDv7 are fully supported through an enhanced time_bucket that accepts UUIDv7 values and returns precise, timezone-aware timestamps — unlocking powerful time-series analytics on modern UUID-driven table schemas. - Lightning-fast recompression: the new recompress := true option on the compress_chunk API enables pure in-memory recompression, delivering a 4–5× speed boost over the previous disk-based process. - ARM support for bloom filters The sparse bloom filter indexes will stop working after upgrade to 2.24. If you are affected by this problem, the warning "bloom filter sparse indexes require action to re-enable" will appear in the Postgres log during upgrade. In versions before 2.24, the hashing scheme of the bloom filter sparse indexes used to depend on the build options of the TimescaleDB executables. These options are set by the package publishers and might differ between different package sources or even versions. After upgrading to a version with different postgresql15-timescaledb-2.24.0-bp157.2.5.1.src.rpm postgresql15-timescaledb-2.24.0-bp157.2.5.1.x86_64.rpm postgresql16-timescaledb-2.24.0-bp157.2.5.1.src.rpm postgresql16-timescaledb-2.24.0-bp157.2.5.1.x86_64.rpm postgresql17-timescaledb-2.24.0-bp157.2.5.1.src.rpm postgresql17-timescaledb-2.24.0-bp157.2.5.1.x86_64.rpm postgresql18-timescaledb-2.24.0-bp157.2.5.1.src.rpm postgresql18-timescaledb-2.24.0-bp157.2.5.1.x86_64.rpm postgresql15-timescaledb-2.24.0-bp157.2.5.1.i586.rpm postgresql16-timescaledb-2.24.0-bp157.2.5.1.i586.rpm postgresql17-timescaledb-2.24.0-bp157.2.5.1.i586.rpm postgresql18-timescaledb-2.24.0-bp157.2.5.1.i586.rpm postgresql15-timescaledb-2.24.0-bp157.2.5.1.aarch64.rpm postgresql16-timescaledb-2.24.0-bp157.2.5.1.aarch64.rpm postgresql17-timescaledb-2.24.0-bp157.2.5.1.aarch64.rpm postgresql18-timescaledb-2.24.0-bp157.2.5.1.aarch64.rpm postgresql15-timescaledb-2.24.0-bp157.2.5.1.ppc64le.rpm postgresql16-timescaledb-2.24.0-bp157.2.5.1.ppc64le.rpm postgresql17-timescaledb-2.24.0-bp157.2.5.1.ppc64le.rpm postgresql18-timescaledb-2.24.0-bp157.2.5.1.ppc64le.rpm postgresql15-timescaledb-2.24.0-bp157.2.5.1.s390x.rpm postgresql16-timescaledb-2.24.0-bp157.2.5.1.s390x.rpm postgresql17-timescaledb-2.24.0-bp157.2.5.1.s390x.rpm postgresql18-timescaledb-2.24.0-bp157.2.5.1.s390x.rpm openSUSE-2025-482 Security update for cheat important openSUSE Backports SLE-15-SP7 Update This update for cheat fixes the following issues: Security: * CVE-2025-47913: Fix client process termination (boo#1253593) * CVE-2025-58181: Fix potential unbounded memory consumption (boo#1253922) * CVE-2025-47914: Fix panic due to an out of bounds read (boo#1254051) * Replace golang.org/x/crypto=golang.org/x/crypto@v0.45.0 * Replace golang.org/x/net=golang.org/x/net@v0.47.0 * Replace golang.org/x/sys=golang.org/x/sys@v0.38.0 - Packaging improvements: * Service go_modules replace dependencies with CVEs * Replace github.com/cloudflare/circl=github.com/cloudflare/circl@v1.6.1 Fix GO-2025-3754 GHSA-2x5j-vhc8-9cwm * Replace golang.org/x/net=golang.org/x/net@v0.36.0 Fixes GO-2025-3503 CVE-2025-22870 * Replace golang.org/x/crypto=golang.org/x/crypto@v0.35.0 Fixes GO-2023-2402 CVE-2023-48795 GHSA-45x7-px36-x8w8 Fixes GO-2025-3487 CVE-2025-22869 * Replace github.com/go-git/go-git/v5=github.com/go-git/go-git/v5@v5.13.0 Fixes GO-2025-3367 CVE-2025-21614 GHSA-r9px-m959-cxf4 Fixes GO-2025-3368 CVE-2025-21613 GHSA-v725-9546-7q7m * Service tar_scm set mode manual from disabled * Service tar_scm create archive from git so we can exclude vendor directory upstream committed to git. Committed vendor directory contents have build issues even after go mod tidy. * Service tar_scm exclude dir vendor * Service set_version set mode manual from disabled * Service set_version remove param basename not needed - boo#1247629 (CVE-2025-21613): * Use go-git 5.13.0 via replace in _service cheat-4.4.2-bp157.2.3.1.src.rpm cheat-4.4.2-bp157.2.3.1.x86_64.rpm cheat-4.4.2-bp157.2.3.1.i586.rpm cheat-4.4.2-bp157.2.3.1.aarch64.rpm cheat-4.4.2-bp157.2.3.1.ppc64le.rpm cheat-4.4.2-bp157.2.3.1.s390x.rpm openSUSE-2025-483 Security update for go-sendxmpp important openSUSE Backports SLE-15-SP7 Update This update for go-sendxmpp fixes the following issues: Update to 0.15.1: - Added * Add XEP-0359 Origin-ID to messages (requires go-xmpp >= v0.2.18). - Changed * HTTP upload: Ignore timeouts on disco IQs as some components do not reply. Upgrades the embedded golang.org/x/net to 0.46.0 * Fixes: boo#1251461, CVE-2025-47911: various algorithms with quadratic complexity when parsing HTML documents * Fixes: boo#1251677, CVE-2025-58190: excessive memory consumption by 'html.ParseFragment' when processing specially crafted input go-sendxmpp-0.15.1-bp157.2.6.1.src.rpm go-sendxmpp-0.15.1-bp157.2.6.1.x86_64.rpm go-sendxmpp-0.15.1-bp157.2.6.1.i586.rpm go-sendxmpp-0.15.1-bp157.2.6.1.aarch64.rpm go-sendxmpp-0.15.1-bp157.2.6.1.ppc64le.rpm go-sendxmpp-0.15.1-bp157.2.6.1.s390x.rpm openSUSE-2025-485 Recommended update for rpmrebuild moderate openSUSE Backports SLE-15-SP7 Update This update for rpmrebuild fixes the following issues: update to 2.21: * allow multiline spec changes (Michel Bourget) * fix rpm2archive syntax for rhel 9 (Blair Zajac) * skip install test for gpg-pubkey packages update to 2.20: * cpio is legacy, replace it by tar (rpm2cpio => rpm2archive) * remove warning : Explicit %attr() mode not applicable to symlink * bugfix : the comment-missing option was not working on rpm files * tests : clean generated files * tests : only use RPMREBUILD_IGNORE_FILE_ERROR if necessary * tests : add test numbers in code * fix build on fedora 41 (buildroot) * use RPMREBUILD_NOQUOTE on some distribution if filenames contains meta-car * bugfix comment missing with spec-only on rpm file * bugfix file with space update to 2.19: * Set the directory mode to '-' instead of omit (xujing) * support filetrigger (merged from github repo) * fix IsPackageInstalled code * fix trailing space (yixian) * fix backslash in filename * add rpm tag BUGURL * add rpm tag VCS * new plugin empty_section * add in specfile a guide to use rpmbuild if spec-only * new plugin replacefile * new env variable RPMREBUILD_IGNORE_FILE_ERROR (allow to work if not root) update to 2.18: * bugs fix (thanks xujing) rpmrebuild-2.21-bp157.2.3.1.noarch.rpm rpmrebuild-2.21-bp157.2.3.1.src.rpm openSUSE-2025-486 Recommended update for icinga-php-thirdparty moderate openSUSE Backports SLE-15-SP7 Update This update for icinga-php-thirdparty fixes the following issues: Update to 0.13.1 - No changelog from upstream. icinga-php-thirdparty-0.13.1-bp157.2.3.1.noarch.rpm icinga-php-thirdparty-0.13.1-bp157.2.3.1.src.rpm openSUSE-2025-487 Security update for duc moderate openSUSE Backports SLE-15-SP7 Update This update for duc fixes the following issues: Update to 1.4.6: * new: added LICENCE to 'make release' target * fix: fixed logic error in buffer_get() (boo#1254566, CVE-2025-13654) * cha: updated tests duc-1.4.6-bp157.2.3.1.src.rpm duc-1.4.6-bp157.2.3.1.x86_64.rpm duc-1.4.6-bp157.2.3.1.i586.rpm duc-1.4.6-bp157.2.3.1.aarch64.rpm duc-1.4.6-bp157.2.3.1.ppc64le.rpm duc-1.4.6-bp157.2.3.1.s390x.rpm openSUSE-2025-489 Security update for trivy important openSUSE Backports SLE-15-SP7 Update This update for trivy fixes the following issues: Update to version 0.68.2: * fix(deps): bump alpine from `3.22.1` to `3.23.0` [backport: release/v0.68] (#9949) * ci: enable `check-latest` for `setup-go` [backport: release/v0.68] (#9946) Update to version 0.68.1 (boo#1251363, CVE-2025-47911, boo#1251547, CVE-2025-58190, boo#1253512, CVE-2025-47913, boo#1253512, CVE-2025-47913, boo#1253786, CVE-2025-58181, boo#1253977, CVE-2025-47914): * fix: update cosing settings for GoReleaser after bumping cosing to v3 (#9863) * chore(deps): bump the testcontainers group with 2 updates (#9506) * feat(aws): Add support for dualstack ECR endpoints (#9862) * fix(vex): use a separate `visited` set for each DFS path (#9760) * docs: catch some missed docs -> guide (#9850) * refactor(misconf): parse azure_policy_enabled to addonprofile.azurepolicy.enabled (#9851) * chore(cli): Remove Trivy Cloud (#9847) * fix(misconf): ensure value used as ignore marker is non-null and known (#9835) * fix(misconf): map healthcheck start period flag to --start-period instead of --startPeriod (#9837) * chore(deps): bump the docker group with 3 updates (#9776) * chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#9827) * chore(deps): bump the common group across 1 directory with 20 updates (#9840) * feat(image): add Sigstore bundle SBOM support (#9516) * chore(deps): bump the aws group with 7 updates (#9691) * test(k8s): update k8s integrtion test (#9725) * chore(deps): bump github.com/containerd/containerd from 1.7.28 to 1.7.29 (#9764) * feat(sbom): add support for SPDX attestations (#9829) * docs(misconf): Remove duplicate sections (#9819) * feat(misconf): Update Azure network schema for new checks (#9791) * feat(misconf): Update AppService schema (#9792) * fix(misconf): ensure boolean metadata values are correctly interpreted (#9770) * feat(misconf): support https_traffic_only_enabled in Az storage account (#9784) * docs: restructure docs for new hosting (#9799) * docs(server): fix info about scanning licenses on the client side. (#9805) * ci: remove unused preinstalled software/images for build tests to free up disk space. (#9814) * feat(report): add fingerprint generation for vulnerabilities (#9794) * chore: trigger the trivy-www workflow (#9737) * fix: update all documentation links (#9777) * feat(suse): Add new openSUSE, Micro and SLES releases end of life dates (#9788) * test(go): set `GOPATH` for tests (#9785) * feat(flag): add `--cacert` flag (#9781) * fix(misconf): handle unsupported experimental flags in Dockerfile (#9769) * test(go): refactor mod_test.go to use txtar format (#9775) * docs: Fix typos and linguistic errors in documentation / hacktoberfest (#9586) * chore(deps): bump github.com/opencontainers/selinux from 1.12.0 to 1.13.0 (#9778) * chore(deps): bump github.com/containerd/containerd/v2 from 2.1.4 to 2.1.5 (#9763) * fix(java): use `true` as default value for Repository Release|Snapshot Enabled in pom.xml and settings.xml files (#9751) * docs: add info that `SSL_CERT_FILE` works on `Unix systems other than macOS` only (#9772) * docs: change SecObserve URLs in documentatio (#9771) * feat(db): enable concurrent access to vulnerability database (#9750) * feat(misconf): add agentpools to azure container schema (#9714) * feat(report): switch ReportID from UUIDv4 to UUIDv7 (#9749) * feat(misconf): Update Azure Compute schema (#9675) * feat(misconf): Update azure storage schema (#9728) * feat(misconf): Update SecurityCenter schema (#9674) * feat(image): pass global context to docker/podman image save func (#9733) * chore(deps): bump the github-actions group with 4 updates (#9739) * fix(flag): remove viper.SetDefault to fix IsSet() for config-only flags (#9732) * feat(license): use separate SPDX ids to ignore SPDX expressions (#9087) * feat(dotnet): add dependency graph support for .deps.json files (#9726) * feat(misconf): Add support for configurable Rego error limit (#9657) * feat(misconf): Add RoleAssignments attribute (#9396) * feat(report): add image reference to report metadata (#9729) * fix(os): Add photon 5.0 in supported OS (#9724) * fix(license): handle SPDX WITH exceptions as single license in category detection (#9380) * refactor: add case-insensitive string set implementation (#9720) * feat: include registry and repository in artifact ID calculation (#9689) * feat(java): add support remote repositories from settings.xml files (#9708) * fix(sbom): don’t panic on SBOM format if scanned CycloneDX file has empty metadata (#9562) * docs: update vulnerability reporting guidelines in SECURITY.md (#9395) * docs: add info about `java-db` subdir (#9706) * fix(report): correct field order in SARIF license results (#9712) * test: improve golden file management in integration tests (#9699) * ci: get base_sha using base.ref (#9704) * refactor(misconf): mark AVDID fields as deprecated and use ID internally (#9576) * fix(nodejs): fix npmjs parser.pkgNameFromPath() panic issue (#9688) * fix: close all opened resources if an error occurs (#9665) * refactor(misconf): type-safe parser results in generic scanner (#9685) * feat(image): add RepoTags support for Docker archives (#9690) * chore(deps): bump github.com/quic-go/quic-go from 0.52.0 to 0.54.1 (#9694) * feat(misconf): Update Azure Container Schema (#9673) * ci: use merge commit for apidiff to avoid false positives (#9622) * feat(misconf): include map key in manifest snippet for diagnostics (#9681) * refactor(misconf): add ManifestFromYAML for unified manifest parsing (#9680) * test: update golden files for TestRepository* integration tests (#9684) * refactor(cli): Update the cloud config command (#9676) * fix(sbom): add `buildInfo` info as properties (#9683) * feat: add ReportID field to scan reports (#9670) * docs: add vulnerability database contribution guide (#9667) * feat(cli): Add trivy cloud suppport (#9637) * feat: add ArtifactID field to uniquely identify scan targets (#9663) * fix(nodejs): use the default ID format to match licenses in pnpm packages. (#9661) * feat(sbom): use SPDX license IDs list to validate SPDX IDs (#9569) * fix: use context for analyzers (#9538) * chore(deps): bump the docker group with 3 updates (#9545) * chore(deps): bump the aws group with 6 updates (#9547) * ci(helm): bump Trivy version to 0.67.2 for Trivy Helm Chart 0.19.1 (#9641) * test(helm): bump up Yamale dependency for Helm chart-testing-action (#9653) * fix: Trim the end-of-range suffix (#9618) * test(k8s): use a specific bundle for k8s misconfig scan (#9633) * fix: Use `fetch-level: 1` to check out trivy-repo in the release workflow (#9636) * refactor: move the aws config (#9617) * fix(license): don't normalize `unlicensed` licenses into `unlicense` (#9611) * fix: using SrcVersion instead of Version for echo detector (#9552) * feat(fs): change artifact type to repository when git info is detected (#9613) * fix: add `buildInfo` for `BlobInfo` in `rpc` package (#9608) * fix(vex): don't use reused BOM (#9604) * ci: use pull_request_target for apidiff workflow to support fork PRs (#9605) * fix: restore compatibility for google.protobuf.Value (#9559) * ci: add API diff workflow (#9600) * chore(deps): update to module-compatible docker-credential-gcr/v2 (#9591) * docs: improve documentation for scanning raw IaC configurations (#9571) * feat: allow ignoring findings by type in Rego (#9578) * docs: bump pygments from 2.18.0 to 2.19.2 (#9596) * refactor(misconf): add ID to scan.Rule (#9573) * fix(java): update order for resolving package fields from multiple demManagement (#9575) * chore(deps): bump the github-actions group across 1 directory with 9 updates (#9563) * chore(deps): bump the common group across 1 directory with 7 updates (#9590) * chore(deps): Switch to go-viper/mapstructure (#9579) * chore: add context to the cache interface (#9565) * ci(helm): bump Trivy version to 0.67.0 for Trivy Helm Chart 0.19.0 (#9554) * fix: validate backport branch name (#9548) Update to version 0.67.2 (boo#1250625, CVE-2025-11065, boo#1248897, CVE-2025-58058): * fix: Use `fetch-level: 1` to check out trivy-repo in the release workflow [backport: release/v0.67] (#9638) * fix: restore compatibility for google.protobuf.Value [backport: release/v0.67] (#9631) * fix: using SrcVersion instead of Version for echo detector [backport: release/v0.67] (#9629) * fix: add `buildInfo` for `BlobInfo` in `rpc` package [backport: release/v0.67] (#9615) * fix(vex): don't use reused BOM [backport: release/v0.67] (#9612) * fix(vex): don't suppress vulns for packages with infinity loop (#9465) * fix(aws): use `BuildableClient` insead of `xhttp.Client` (#9436) * refactor(misconf): replace github.com/liamg/memoryfs with internal mapfs and testing/fstest (#9282) * docs: clarify inline ignore limitations for resource-less checks (#9537) * fix(k8s): disable parallel traversal with fs cache for k8s images (#9534) * fix(misconf): handle tofu files in module detection (#9486) * feat(seal): add seal support (#9370) * docs: fix modules path and update code example (#9539) * fix: close file descriptors and pipes on error paths (#9536) * feat: add documentation URL for database lock errors (#9531) * fix(db): Dowload database when missing but metadata still exists (#9393) * feat(cloudformation): support default values and list results in Fn::FindInMap (#9515) * fix(misconf): unmark cty values before access (#9495) * feat(cli): change --list-all-pkgs default to true (#9510) * fix(nodejs): parse workspaces as objects for package-lock.json files (#9518) * refactor(fs): use underlyingPath to determine virtual files more reliably (#9302) * refactor: remove google/wire dependency and implement manual DI (#9509) * chore(deps): bump the aws group with 6 updates (#9481) * chore(deps): bump the common group across 1 directory with 24 updates (#9507) * fix(misconf): wrap legacy ENV values in quotes to preserve spaces (#9497) * docs: move info about `detection priority` into coverage section (#9469) * feat(sbom): added support for CoreOS (#9448) * fix(misconf): strip build metadata suffixes from image history (#9498) * feat(cyclonedx): preserve SBOM structure when scanning SBOM files with vulnerability updates (#9439) * docs: Fix typo in terraform docs (#9492) * feat(redhat): add os-release detection for RHEL-based images (#9458) * ci(deps): add 3-day cooldown period for Dependabot updates (#9475) * refactor: migrate from go-json-experiment to encoding/json/v2 (#9422) * fix(vuln): compare `nuget` package names in lower case (#9456) * chore: Update release flow to include chocolatey (#9460) * docs: document eol supportability (#9434) * docs(report): add nuanses about secret/license scanner in summary table (#9442) * ci: use environment variables in GitHub Actions for improved security (#9433) * chore: bump Go to 1.24.7 (#9435) * fix(nodejs): use snapshot string as `Package.ID` for pnpm packages (#9330) * ci(helm): bump Trivy version to 0.66.0 for Trivy Helm Chart 0.18.0 (#9425) - Fix version number shown for 'trivy -v' Update to version 0.66.0 (boo#1248937, CVE-2025-58058): * chore(deps): bump the aws group with 7 updates (#9419) * refactor(secret): clarify secret scanner messages (#9409) * fix(cyclonedx): handle multiple license types (#9378) * fix(repo): sanitize git repo URL before inserting into report metadata (#9391) * test: add HTTP basic authentication to git test server (#9407) * fix(sbom): add support for `file` component type of `CycloneDX` (#9372) * fix(misconf): ensure module source is known (#9404) * ci: migrate GitHub Actions from version tags to SHA pinning (#9405) * fix: create temp file under composite fs dir (#9387) * chore(deps): bump github.com/ulikunitz/xz from 0.5.12 to 0.5.14 (#9403) * refactor: switch to stable azcontainerregistry SDK package (#9319) * chore(deps): bump the common group with 7 updates (#9382) * refactor(misconf): migrate from custom Azure JSON parser (#9222) * fix(repo): preserve RepoMetadata on FS cache hit (#9389) * refactor(misconf): use atomic.Int32 (#9385) * chore(deps): bump the aws group with 6 updates (#9383) * docs: Fix broken link to "Built-in Checks" (#9375) * fix(plugin): don't remove plugins when updating index.yaml file (#9358) * fix: persistent flag option typo (#9374) * chore(deps): bump the common group across 1 directory with 26 updates (#9347) * fix(image): use standardized HTTP client for ECR authentication (#9322) * refactor: export `systemFileFiltering` Post Handler (#9359) * docs: update links to Semaphore pages (#9352) * fix(conda): memory leak by adding closure method for `package.json` file (#9349) * feat: add timeout handling for cache database operations (#9307) * fix(misconf): use correct field log_bucket instead of target_bucket in gcp bucket (#9296) * fix(misconf): ensure ignore rules respect subdirectory chart paths (#9324) * chore(deps): bump alpine from 3.21.4 to 3.22.1 (#9301) * feat(terraform): use .terraform cache for remote modules in plan scanning (#9277) * chore: fix some function names in comment (#9314) * chore(deps): bump the aws group with 7 updates (#9311) * docs: add explanation for how to use non-system certificates (#9081) * chore(deps): bump the github-actions group across 1 directory with 2 updates (#8962) * fix(misconf): preserve original paths of remote submodules from .terraform (#9294) * refactor(terraform): make Scan method of Terraform plan scanner private (#9272) * fix: suppress debug log for context cancellation errors (#9298) * feat(secret): implement streaming secret scanner with byte offset tracking (#9264) * fix(python): impove package name normalization (#9290) * feat(misconf): added audit config attribute (#9249) * refactor(misconf): decouple input fs and track extracted files with fs references (#9281) * test(misconf): remove BenchmarkCalculate using outdated check metadata (#9291) * refactor: simplify Detect function signature (#9280) * ci(helm): bump Trivy version to 0.65.0 for Trivy Helm Chart 0.17.0 (#9288) * fix(fs): avoid shadowing errors in file.glob (#9286) * test(misconf): move terraform scan tests to integration tests (#9271) * test(misconf): drop gcp iam test covered by another case (#9285) * chore(deps): bump to alpine from `3.21.3` to `3.21.4` (#9283) Update to version 0.65.0: * fix(cli): ensure correct command is picked by telemetry (#9260) * feat(flag): add schema validation for `--server` flag (#9270) * chore(deps): bump github.com/docker/docker from 28.3.2+incompatible to 28.3.3+incompatible (#9274) * ci: skip undefined labels in discussion triage action (#9175) * feat(repo): add git repository metadata to reports (#9252) * fix(license): handle WITH operator for `LaxSplitLicenses` (#9232) * chore: add modernize tool integration for code modernization (#9251) * fix(secret): add UTF-8 validation in secret scanner to prevent protobuf marshalling errors (#9253) * chore: implement process-safe temp file cleanup (#9241) * fix: prevent graceful shutdown message on normal exit (#9244) * fix(misconf): correctly parse empty port ranges in google_compute_firewall (#9237) * feat: add graceful shutdown with signal handling (#9242) * chore: update template URL for brew formula (#9221) * test: add end-to-end testing framework with image scan and proxy tests (#9231) * refactor(db): use `Getter` interface with `GetParams` for trivy-db sources (#9239) * ci: specify repository for `gh cache delete` in canary worklfow (#9240) * ci: remove invalid `--confirm` flag from `gh cache delete` command in canary builds (#9236) * fix(misconf): fix log bucket in schema (#9235) * chore(deps): bump the common group across 1 directory with 24 updates (#9228) * ci: move runner.os context from job-level env to step-level in canary workflow (#9233) * chore(deps): bump up Trivy-kubernetes to v0.9.1 (#9214) * feat(misconf): added logging and versioning to the gcp storage bucket (#9226) * fix(server): add HTTP transport setup to server mode (#9217) * chore: update the rpm download Update (#9202) * feat(alma): add AlmaLinux 10 support (#9207) * fix(nodejs): don't use prerelease logic for compare npm constraints (#9208) * fix(rootio): fix severity selection (#9181) * fix(sbom): merge in-graph and out-of-graph OS packages in scan results (#9194) * fix(cli): panic: attempt to get os.Args[1] when len(os.Args) < 2 (#9206) * fix(misconf): correctly adapt azure storage account (#9138) * feat(misconf): add private ip google access attribute to subnetwork (#9199) * feat(report): add CVSS vectors in sarif report (#9157) * fix(terraform): `for_each` on a map returns a resource for every key (#9156) * fix: supporting .egg-info/METADATA in python.Packaging analyzer (#9151) * chore: migrate protoc setup from Docker to buf CLI (#9184) * ci: delete cache after artifacts upload in canary workflow (#9177) * refactor: remove aws flag helper message (#9080) * ci: use gh pr view to get PR number for forked repositories in auto-ready workflow (#9183) * ci: add auto-ready-for-review workflow (#9179) * feat(image): add Docker context resolution (#9166) * ci: optimize golangci-lint performance with cache-based strategy (#9173) * feat: add HTTP request/response tracing support (#9125) * fix(aws): update amazon linux 2 EOL date (#9176) * chore: Update release workflow to trigger version updates (#9162) * chore(deps): bump helm.sh/helm/v3 from 3.18.3 to 3.18.4 (#9164) * fix: also check `filepath` when removing duplicate packages (#9142) * chore: add debug log to show image source location (#9163) * docs: add section on customizing default check data (#9114) * chore(deps): bump the common group across 1 directory with 9 updates (#9153) * docs: partners page content updates (#9149) * chore(license): add missed spdx exceptions: (#9147) * docs: trivy partners page updates (#9133) * fix: migrate from `*.list` to `*.md5sums` files for `dpkg` (#9131) * ci(helm): bump Trivy version to 0.64.1 for Trivy Helm Chart 0.16.1 (#9135) * feat(sbom): add SHA-512 hash support for CycloneDX SBOM (#9126) * fix(misconf): skip rewriting expr if attr is nil (#9113) * fix(license): add missed `GFDL-NIV-1.1` and `GFDL-NIV-1.2` into Trivy mapping (#9116) * fix(cli): Add more non-sensitive flags to telemetry (#9110) * fix(alma): parse epochs from rpmqa file (#9101) * fix(rootio): check full version to detect `root.io` packages (#9117) * chore: drop FreeBSD 32-bit support (#9102) * fix(sbom): use correct field for licenses in CycloneDX reports (#9057) * fix(secret): fix line numbers for multiple-line secrets (#9104) * feat(license): observe pkg types option in license scanner (#9091) * ci(helm): bump Trivy version to 0.64.0 for Trivy Helm Chart 0.16.0 (#9107) - Update to version 0.64.1 (boo#1243633, CVE-2025-47291, (boo#1246730, CVE-2025-46569): - Update to version 0.62.1 (boo#1239225, CVE-2025-22868, boo#1241724, CVE-2025-22872): - Update to version 0.61.1 (boo#1239385, CVE-2025-22869, boo#1240466, CVE-2025-30204): trivy-0.68.2-bp157.2.6.1.src.rpm trivy-0.68.2-bp157.2.6.1.x86_64.rpm trivy-0.68.2-bp157.2.6.1.i586.rpm trivy-0.68.2-bp157.2.6.1.aarch64.rpm trivy-0.68.2-bp157.2.6.1.ppc64le.rpm trivy-0.68.2-bp157.2.6.1.s390x.rpm openSUSE-2026-1 Recommended update for wsdd moderate openSUSE Backports SLE-15-SP7 Update This update for wsdd fixes the following issues: - Drop rcwsdd symlink [jsc#PED-266] Update to 0.9: * Add command line argument to set source port for multicast message for better firewall interoperability * Add initial support for SunOS (#223), without dynamic address/interface monitoring. Thanks to Carsten Grzemba. * Add Socket-activated systemd service (#218). Thanks to Alessandro Astone. * Devices are now recorded based on their URI provided in the endpoint reference address, which is not neccessarily a UUID. This also affects API (see #226). * make `/etc/default/wsdd` optional for systemd (see #212) * Remove support for Python 3.7 and 3.8 in Github workflows. * Clean conection turn-down for Python pre-3.13. Thanks to Alessandro Astone * Handle TimeoutError in metadata exchange. * Proper handling of endpoint addresses as URIs, not UUIDs, see #226. Update to version 0.8: * Configuration files for firewalld added * Show device type and allow filtering in API's list command * Add option --metadata-timeout to set the timeout for the HTTP-based metadata exchange * The employed UUID is now read from /etc/{machine-id,hostid} before falling by back to the UUID derivation from the host name. * Handle addresses with zone id by ignoring the interface part * Do not crash with asyncio future error when non-existing interface is provided - Remove some bashism from wsdd-init.sh - Use the unmodified service files from wsdd for Leap 15.5 and below, else reuse ws-discovery-udp service from firewalld - remove dependency on /usr/bin/python3 using %python3_fix_shebang macro, [boo#1212476] - Fix previous change: really limit the forced change to python 3.10 on suse_version <= 1500 (up to SLE/Leap 15); newer products already use python 3.10 (or newer) as default. Update to version 0.7.1: * GitHub workflow for static analyses added (syntax, format, and type checks are performed). * Added EnvironmentFile and according example for systemd-based distros. * Make wsdd work (again) on MacOS (#139). Thanks to Eugene Gershnik. * Application profile for UFW has been added (#169) * Use of implicitly present async I/O loop instead created one for API servers. Fixes regression due to changed API in Python 3.10 (see #162) * Source code is spiced with type hints now. * man page moved to section 8. - Include ws-discovey-udp service from firewalld 1.0 as part of wsdd.xml - Add CONFIG parameter to %sysusers_generate_pre Version 0.7.0: * Using the server interface it is now possible to start and stop the host functionality (discoverable device) without terminating and restarting the daemon. * Support multiple IP addresses in 'hello' messages from other hosts (#89) * Support interfaces with IPv6-only configuration (#94) * Re-enable 'probe' command of API (#116) * Removed code marked as deprecated starting with Python 3.10. * The example systemd unit file now uses DynamicUser instead of the unsafe nobody:nobody combination. It also employs the rundir as chroot directory. * Code changed to use asyncio instead of selector-based * The server interface does not close connections after each command anymore. * For the 'list' command of the server interface, the list of discovered devices is terminated with a line containing only a single dot ('.') * Log device discovery only once per address and interface - Some systemd hardening - stop owning directories provided by filesystem rpm (boo#1184786) - Remove unneccessary (and deprecated) PermissionsStartOnly=true (boo#1184446). - Add %sysusers_requires: we are creating users in pre, thus need to ensure to have the tooling ready prior to package installation (boo#1183047). - Use sysuser-tools for creation of the wsdd user and group - Do not hijack the /run/sysconfig folder anymore - Add missing '/' - Fix a missed place for use of %{_tmpfilesdir} - Cleanup spec file * Use %{_tmpfilesdir} instead of explicit path * Fix requirements for %fillup_only - Version 0.6.4 * send proper HTTP status codes in case of server side errors * send unicast and multicast UDP traffic in a standard-compliant fashion * add -V/--version option * copyright year update - Version 0.6.3 * Skip Netlink messages smaller than 4 bytes correctly (#77, and maybe #59). * Messages are sent via the correct socket to comply with the intended/specified message flow. This also eases the firewall configuration (#72). * Include instructions for adding repository keys under Debian/Ubuntu in README. - Run spec-cleaner - Version 0.6.2 * Lowered priority of non-essential, protocol-related and internal log messages (#53). * Do not use PID in Netlink sockets in order to avoid issues with duplicated PIDs, e.g., when Docker is used. * Prevent exceptions due to invalid incoming messages. * HTTP server address family wrong when interface address is added (#62) * Fixed error when interface address is removed (#62) - Fix use of /usr/lib and /usr/libexec - Version 0.6.1 * ignore unknown interface indexes from Netlink message on Linux (caused "error in main loop") * prevent hosts from not being discovered due to misplaced socket registration at selector - Version 0.6 * new operation 'discovery' operation mode to scan for other hosts, exposed via minimalistic socket-based API * improved handling of address changes (prevents termination when system is currently starting up but no IP address has been assigned) * usage of tentative IPv6 addresses is avoided on Linux * chroot now works also an machines with international domain/host name * fixed handling of invalid messages * improved FreeBSD rc.d script * code heavily refactored - Fix handling of WSDD_WORKGROUP - Let WSDD_DOMAIN override WSDD_WORKGROUP - Use wsdd for user and group of the ghost directories - Replace wsdd-wrapper by an ExecStartPre script - Change the "WSD_" variable prefix by "WSDD_" - Run wsdd as user and group wsdd - Run wsdd in a chroot folder - Merge firewall files into one - Update to version 0.5 - Remove unneeded _service file - Remove debug output - Respect libexecdir in systemd service file - Determine domain, and/or hostname - Move wssd back to /usr/bin - Reload firewalld services - Remove fillup_prereq post requires - Initial package wsdd-0.9-bp157.2.1.noarch.rpm wsdd-0.9-bp157.2.1.src.rpm openSUSE-2026-2 Recommended update for orafce moderate openSUSE Backports SLE-15-SP7 Update This update for orafce to version 4.16.2+git0.6a3cfa5: * fix update script from 4.15-4.16 and prepare for 4.16.2 - Update to version 4.16.1+git0.3eaa566: * fix meson build + prepare for 4.16.1 - Update to version 4.16.0+git0.38f69ed: * More accurace calculating months_between when time part of input is not truncated. * fix build on pg19 - Update to version 4.14.6+git0.2b21fee: * prepare for 4.14.6 * fix build pn pg19 * remove useless usage of short life memory context * remove useless (and buggy) usage of short life memory context - enable pg 18 - Update to version 4.14.5+git0.86c6e48: * prepare for 4.14.5 * regression tests for fix oracle.replace_empty_strings and oracle.replace_null_strings * Fix in function oracle.replace_empty_strings detection of empty string of type character(n). Fix in function oracle.replace_null_strings generating empty string of type character(n). * the names of roles created by regress tests should to use prefix "regress_" * fix build on master (pg19) * fix formatting * fix formatting * post pgindent sync * pgindent formatting * typedef list for pgindent postgresql13-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.src.rpm postgresql13-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.x86_64.rpm postgresql14-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.src.rpm postgresql14-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.x86_64.rpm postgresql15-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.src.rpm postgresql15-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.x86_64.rpm postgresql16-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.src.rpm postgresql16-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.x86_64.rpm postgresql17-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.src.rpm postgresql17-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.x86_64.rpm postgresql18-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.src.rpm postgresql18-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.x86_64.rpm postgresql13-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.i586.rpm postgresql14-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.i586.rpm postgresql15-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.i586.rpm postgresql16-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.i586.rpm postgresql17-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.i586.rpm postgresql18-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.i586.rpm postgresql13-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.aarch64.rpm postgresql14-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.aarch64.rpm postgresql15-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.aarch64.rpm postgresql16-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.aarch64.rpm postgresql17-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.aarch64.rpm postgresql18-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.aarch64.rpm postgresql13-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.ppc64le.rpm postgresql14-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.ppc64le.rpm postgresql15-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.ppc64le.rpm postgresql16-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.ppc64le.rpm postgresql17-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.ppc64le.rpm postgresql18-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.ppc64le.rpm postgresql13-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.s390x.rpm postgresql14-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.s390x.rpm postgresql15-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.s390x.rpm postgresql16-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.s390x.rpm postgresql17-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.s390x.rpm postgresql18-orafce-4.16.2+git0.6a3cfa5-bp157.2.5.1.s390x.rpm openSUSE-2026-5 Security update for dcmtk moderate openSUSE Backports SLE-15-SP7 Update This update for dcmtk fixes the following issues: - Update to 3.7.0. See docs/CHANGES.370 for the full list of changes * CVE-2025-14841: invalid messages may trigger a segmentation fault due to a NULL pointer dereference (boo#1255292). * CVE-2025-14607: manipulation to component dcmdata could lead to memory corruption (boo#1255464). - Avoid unnecessary dependencies (boo#1254123): dcmtk-3.7.0-bp157.3.6.1.src.rpm dcmtk-3.7.0-bp157.3.6.1.x86_64.rpm dcmtk-debuginfo-3.7.0-bp157.3.6.1.x86_64.rpm dcmtk-debugsource-3.7.0-bp157.3.6.1.x86_64.rpm dcmtk-devel-3.7.0-bp157.3.6.1.x86_64.rpm libdcmtk20-3.7.0-bp157.3.6.1.x86_64.rpm libdcmtk20-debuginfo-3.7.0-bp157.3.6.1.x86_64.rpm dcmtk-3.7.0-bp157.3.6.1.i586.rpm dcmtk-debuginfo-3.7.0-bp157.3.6.1.i586.rpm dcmtk-debugsource-3.7.0-bp157.3.6.1.i586.rpm dcmtk-devel-3.7.0-bp157.3.6.1.i586.rpm libdcmtk20-3.7.0-bp157.3.6.1.i586.rpm libdcmtk20-debuginfo-3.7.0-bp157.3.6.1.i586.rpm dcmtk-3.7.0-bp157.3.6.1.aarch64.rpm dcmtk-debuginfo-3.7.0-bp157.3.6.1.aarch64.rpm dcmtk-debugsource-3.7.0-bp157.3.6.1.aarch64.rpm dcmtk-devel-3.7.0-bp157.3.6.1.aarch64.rpm libdcmtk20-3.7.0-bp157.3.6.1.aarch64.rpm libdcmtk20-debuginfo-3.7.0-bp157.3.6.1.aarch64.rpm dcmtk-3.7.0-bp157.3.6.1.ppc64le.rpm dcmtk-debuginfo-3.7.0-bp157.3.6.1.ppc64le.rpm dcmtk-debugsource-3.7.0-bp157.3.6.1.ppc64le.rpm dcmtk-devel-3.7.0-bp157.3.6.1.ppc64le.rpm libdcmtk20-3.7.0-bp157.3.6.1.ppc64le.rpm libdcmtk20-debuginfo-3.7.0-bp157.3.6.1.ppc64le.rpm dcmtk-3.7.0-bp157.3.6.1.s390x.rpm dcmtk-debuginfo-3.7.0-bp157.3.6.1.s390x.rpm dcmtk-debugsource-3.7.0-bp157.3.6.1.s390x.rpm dcmtk-devel-3.7.0-bp157.3.6.1.s390x.rpm libdcmtk20-3.7.0-bp157.3.6.1.s390x.rpm libdcmtk20-debuginfo-3.7.0-bp157.3.6.1.s390x.rpm openSUSE-2026-4 Security update for chromium, noopenh264 important openSUSE Backports SLE-15-SP7 Update This update for chromium, noopenh264 fixes the following issues: Changes in chromium: - Chromium 143.0.7499.192 (boo#1256067): * CVE-2026-0628: Insufficient policy enforcement in WebView tag - Chromium 143.0.7499.169 (stable released 2025-12-18) * no cve listed yet Changes in noopenh264: - Introducing the package. chromedriver-143.0.7499.192-bp157.2.97.1.x86_64.rpm chromium-143.0.7499.192-bp157.2.97.1.nosrc.rpm chromium-143.0.7499.192-bp157.2.97.1.x86_64.rpm libopenh264-8-2.6.0~noopenh264-bp157.2.1.x86_64.rpm libopenh264-8-debuginfo-2.6.0~noopenh264-bp157.2.1.x86_64.rpm libopenh264-devel-2.6.0~noopenh264-bp157.2.1.x86_64.rpm noopenh264-2.6.0~noopenh264-bp157.2.1.src.rpm noopenh264-debugsource-2.6.0~noopenh264-bp157.2.1.x86_64.rpm libopenh264-8-2.6.0~noopenh264-bp157.2.1.i586.rpm libopenh264-8-32bit-2.6.0~noopenh264-bp157.2.1.x86_64.rpm libopenh264-8-32bit-debuginfo-2.6.0~noopenh264-bp157.2.1.x86_64.rpm libopenh264-8-debuginfo-2.6.0~noopenh264-bp157.2.1.i586.rpm libopenh264-devel-2.6.0~noopenh264-bp157.2.1.i586.rpm noopenh264-debugsource-2.6.0~noopenh264-bp157.2.1.i586.rpm chromedriver-143.0.7499.192-bp157.2.97.1.aarch64.rpm chromium-143.0.7499.192-bp157.2.97.1.aarch64.rpm libopenh264-8-2.6.0~noopenh264-bp157.2.1.aarch64.rpm libopenh264-8-64bit-2.6.0~noopenh264-bp157.2.1.aarch64_ilp32.rpm libopenh264-8-64bit-debuginfo-2.6.0~noopenh264-bp157.2.1.aarch64_ilp32.rpm libopenh264-8-debuginfo-2.6.0~noopenh264-bp157.2.1.aarch64.rpm libopenh264-devel-2.6.0~noopenh264-bp157.2.1.aarch64.rpm noopenh264-debugsource-2.6.0~noopenh264-bp157.2.1.aarch64.rpm chromedriver-143.0.7499.192-bp157.2.97.1.ppc64le.rpm chromium-143.0.7499.192-bp157.2.97.1.ppc64le.rpm libopenh264-8-2.6.0~noopenh264-bp157.2.1.ppc64le.rpm libopenh264-8-debuginfo-2.6.0~noopenh264-bp157.2.1.ppc64le.rpm libopenh264-devel-2.6.0~noopenh264-bp157.2.1.ppc64le.rpm noopenh264-debugsource-2.6.0~noopenh264-bp157.2.1.ppc64le.rpm libopenh264-8-2.6.0~noopenh264-bp157.2.1.s390x.rpm libopenh264-8-debuginfo-2.6.0~noopenh264-bp157.2.1.s390x.rpm libopenh264-devel-2.6.0~noopenh264-bp157.2.1.s390x.rpm noopenh264-debugsource-2.6.0~noopenh264-bp157.2.1.s390x.rpm openSUSE-2026-7 Security update for cpp-httplib important openSUSE Backports SLE-15-SP7 Update This update for cpp-httplib fixes the following issues: - CVE-2025-53629: Fixed that a header can allocate memory arbitrarily in the server, potentially leading to its exhaustion (boo#1246471) - CVE-2025-53628: Fixed HTTP header smuggling due to insecure trailers merge (boo#1246468) - CVE-2025-52887: Fixed that the number of HTTP header fields was not limited, which can lead to potential exhaustion of system memory (boo#1245414) cpp-httplib-0.20.1-bp157.2.3.1.src.rpm cpp-httplib-devel-0.20.1-bp157.2.3.1.x86_64.rpm libcpp-httplib0_20-0.20.1-bp157.2.3.1.x86_64.rpm cpp-httplib-devel-0.20.1-bp157.2.3.1.i586.rpm libcpp-httplib0_20-0.20.1-bp157.2.3.1.i586.rpm cpp-httplib-devel-0.20.1-bp157.2.3.1.aarch64.rpm libcpp-httplib0_20-0.20.1-bp157.2.3.1.aarch64.rpm cpp-httplib-devel-0.20.1-bp157.2.3.1.ppc64le.rpm libcpp-httplib0_20-0.20.1-bp157.2.3.1.ppc64le.rpm cpp-httplib-devel-0.20.1-bp157.2.3.1.s390x.rpm libcpp-httplib0_20-0.20.1-bp157.2.3.1.s390x.rpm openSUSE-2026-9 Security update for python-cbor2 moderate openSUSE Backports SLE-15-SP7 Update This update for python-cbor2 fixes the following issues: - CVE-2025-68131: Fixed that a attacker-controlled message can read data from previously decoded messages if the decoder is reused across trust boundaries (boo#1255783) python-cbor2-5.5.1-bp157.2.3.1.src.rpm python311-cbor2-5.5.1-bp157.2.3.1.x86_64.rpm python311-cbor2-5.5.1-bp157.2.3.1.i586.rpm python311-cbor2-5.5.1-bp157.2.3.1.aarch64.rpm python311-cbor2-5.5.1-bp157.2.3.1.ppc64le.rpm python311-cbor2-5.5.1-bp157.2.3.1.s390x.rpm openSUSE-2026-32 Security update for coredns important openSUSE Backports SLE-15-SP7 Update This update for coredns fixes the following issues: - Update to version 1.14.1: * This release primarily addresses security vulnerabilities affecting Go versions prior to Go 1.25.6 and Go 1.24.12 (CVE-2025-61728, CVE-2025-61726, CVE-2025-68121, CVE-2025-61731, CVE-2025-68119). It also includes performance improvements to the proxy plugin via multiplexed connections, along with various documentation updates. - CVE-2025-68156: Fixed a denial of service due to uncontrolled recursion in expression evaluation (bsc#1255345) - Update to version 1.14.0: * core: Fix gosec G115 integer overflow warnings * core: Add regex length limit * plugin/azure: Fix slice init length * plugin/errors: Add optional show_first flag to consolidate directive * plugin/file: Fix for misleading SOA parser warnings * plugin/kubernetes: Rate limits to api server * plugin/metrics: Implement plugin chain tracking * plugin/sign: Report parser err before missing SOA * build(deps): bump github.com/expr-lang/expr from 1.17.6 to 1.17.7 - Update to version 1.13.2: * core: Add basic support for DoH3 * core: Avoid proxy unnecessary alloc in Yield * core: Fix usage of sync.Pool to save an alloc * core: Fix data race with sync.RWMutex for uniq * core: Prevent QUIC reload panic by lazily initializing the listener * core: Refactor/use reflect.TypeFor * plugin/auto: Limit regex length * plugin/cache: Remove superfluous allocations in item.toMsg * plugin/cache: Isolate metadata in prefetch goroutine * plugin/cache: Correct spelling of MaximumDefaultTTL in cache and dnsutil packages * plugin/dnstap: Better error handling (redial & logging) when Dnstap is busy * plugin/file: Performance finetuning * plugin/forward: Disallow NOERROR in failover * plugin/forward: Added support for per-nameserver TLS SNI * plugin/forward: Prevent busy loop on connection err * plugin/forward: Add max connect attempts knob * plugin/geoip: Add ASN schema support * plugin/geoip: Add support for subdivisions * plugin/kubernetes: Fix kubernetes plugin logging * plugin/multisocket: Cap num sockets to prevent OOM * plugin/nomad: Support service filtering * plugin/rewrite: Pre-compile CNAME rewrite regexp * plugin/secondary: Fix reload causing secondary plugin goroutine to leak - Update to version 1.13.1: * core: Avoid string concatenation in loops * core: Update golang to 1.25.2 and golang.org/x/net to v0.45.0 on CVE fixes * plugin/sign: Reject invalid UTF‑8 dbfile token - Update to version 1.13.0: * core: Export timeout values in dnsserver.Server * core: Fix Corefile infinite loop on unclosed braces * core: Fix Corefile related import cycle issue * core: Normalize panics on invalid origins * core: Rely on dns.Server.ShutdownContext to gracefully stop * plugin/dnstap: Add bounds for plugin args * plugin/file: Fix data race in tree Elem.Name * plugin/forward: No failover to next upstream when receiving SERVFAIL or REFUSED response codes * plugin/grpc: Enforce DNS message size limits * plugin/loop: Prevent panic when ListenHosts is empty * plugin/loop: Avoid panic on invalid server block * plugin/nomad: Add a Nomad plugin * plugin/reload: Prevent SIGTERM/reload deadlock coredns-1.14.1-bp157.2.10.1.src.rpm coredns-1.14.1-bp157.2.10.1.x86_64.rpm coredns-debuginfo-1.14.1-bp157.2.10.1.x86_64.rpm coredns-extras-1.14.1-bp157.2.10.1.noarch.rpm coredns-1.14.1-bp157.2.10.1.aarch64.rpm coredns-debuginfo-1.14.1-bp157.2.10.1.aarch64.rpm coredns-1.14.1-bp157.2.10.1.ppc64le.rpm coredns-debuginfo-1.14.1-bp157.2.10.1.ppc64le.rpm openSUSE-2026-14 Security update for fluidsynth moderate openSUSE Backports SLE-15-SP7 Update This update for fluidsynth fixes the following issues: - CVE-2025-56225: Fixed NULL pointer deference when loading and invalid MIDI file (boo#1256435). fluidsynth-2.3.4-bp157.2.3.1.src.rpm fluidsynth-2.3.4-bp157.2.3.1.x86_64.rpm fluidsynth-devel-2.3.4-bp157.2.3.1.x86_64.rpm libfluidsynth3-2.3.4-bp157.2.3.1.x86_64.rpm fluidsynth-2.3.4-bp157.2.3.1.i586.rpm fluidsynth-devel-2.3.4-bp157.2.3.1.i586.rpm libfluidsynth3-2.3.4-bp157.2.3.1.i586.rpm libfluidsynth3-32bit-2.3.4-bp157.2.3.1.x86_64.rpm fluidsynth-2.3.4-bp157.2.3.1.aarch64.rpm fluidsynth-devel-2.3.4-bp157.2.3.1.aarch64.rpm libfluidsynth3-2.3.4-bp157.2.3.1.aarch64.rpm libfluidsynth3-64bit-2.3.4-bp157.2.3.1.aarch64_ilp32.rpm fluidsynth-2.3.4-bp157.2.3.1.ppc64le.rpm fluidsynth-devel-2.3.4-bp157.2.3.1.ppc64le.rpm libfluidsynth3-2.3.4-bp157.2.3.1.ppc64le.rpm fluidsynth-2.3.4-bp157.2.3.1.s390x.rpm fluidsynth-devel-2.3.4-bp157.2.3.1.s390x.rpm libfluidsynth3-2.3.4-bp157.2.3.1.s390x.rpm openSUSE-2026-15 Recommended update for gosec moderate openSUSE Backports SLE-15-SP7 Update This update for gosec fixes the following issues: - Update to version 2.22.4: * Update to go version 1.24.3 and 1.23.9 * update: updated the build command to include version metadata * chore(deps): update all dependencies * Update the AI provider API key value when provided as an argument * chore(deps): update module google.golang.org/api to v0.230.0 * chore(deps): update module google.golang.org/api to v0.229.0 * chore(deps): update all dependencies * Comment the reason why the file can be nil when an issue is created * Handle nil file when creating a new issue * chore(deps): update all dependencies (#1333) - Update to version 2.22.3: * Update version in 'action.yml' to 2.22.3 (anticipating next version (#1332) * Update go version to 1.24.2 and 1.23.8 (#1331) * remove G113. It only affects old/unsupported versions of Go (#1328) * chore(deps): update all dependencies (#1325) * Add SSOJet (#1320) * chore(deps): update all dependencies (#1319) * Update the integrity sha for babel dependency in html report (#1316) * Add support for `//gosec:disable` directive (#1314) * chore(deps): update all dependencies (#1315) - Update to version 2.22.2: * Update to go version 1.24.1 and 1.23.7 (#1313) * chore(deps): update all dependencies (#1310) * chore(deps): update all dependencies (#1308) * Update gosec version in the GitHub action to v2.22.1 (#1307) * chore(deps): update module google.golang.org/api to v0.221.0 (#1305) - Update to version 2.22.1: * Update cosign to v2.4.2 (#1303) * Add support for go 1.24 and phased out support for go 1.22 (#1302) * chore(deps): update all dependencies (#1300) * Update to go version 1.23.6 and 1.22.12 (#1299) * chore(deps): update module google.golang.org/api to v0.219.0 (#1296) * chore(deps): update module google.golang.org/api to v0.218.0 (#1294) * Add test to conver unit parssing for G115 rule (#1293) * Update to go version 1.23.5 and 1.22.11 (#1291) * chore(deps): update all dependencies (#1290) * Update gosec in github action to 2.22.0 (#1286) gosec-2.22.4-bp157.2.3.1.src.rpm gosec-2.22.4-bp157.2.3.1.x86_64.rpm gosec-2.22.4-bp157.2.3.1.aarch64.rpm gosec-2.22.4-bp157.2.3.1.ppc64le.rpm gosec-2.22.4-bp157.2.3.1.s390x.rpm openSUSE-2026-16 Security update for zk moderate openSUSE Backports SLE-15-SP7 Update This update for zk fixes the following issues: - Update to version 0.15.2 * Find notes with missing backlinks using zk list --missing-backlink * LSP diagnostic for missing backlinks when other notes link to current note without reciprocal links * Code action to add missing backlinks * LSP diagnostic for self-referential links * Release tarballs now output the program version * Config path can be set with $ZK_CONFIG_DIR * bump deps: golang.org/x/crypto v0.45.0 fixes CVE-2025-58181 - Update to version 0.15.0 * fixed LSP crashes when editing code fences and/or working in text files with code fences * new feature to set a group path "by name", in that any directory with the same name can share the same group rules, no matter how deep in the notebook. See references below. - Update to version 0.14.2 * Path in .zk/config.toml for the default note template now accepts UNIX "~/paths" * Find notes without tags with zk list --tagless * fix: LSP ignores magnet links as links to notes * fix: Note titles with double quoted words no longer break json output * fix: Grammar in error output * fix: Group rules could not be nested - Update to version 0.14.1 * Fixed parsing large notes @khimaros in #339 * fix day range parsing (#382) by @tjex in #384 * accept tripple dash file URIs as valid links by @tjex in #391 * fix(lsp): fix trigger completion of zk LSP by @Rahlir in #397 * fix(lsp): ignore diagnostic check within code blocks by @Rahlir in #399 * allow notebook as hidden dir by @tjex in #402 * documentation fixes zk-0.15.2-bp157.2.3.1.src.rpm zk-0.15.2-bp157.2.3.1.x86_64.rpm zk-0.15.2-bp157.2.3.1.i586.rpm zk-0.15.2-bp157.2.3.1.aarch64.rpm zk-0.15.2-bp157.2.3.1.ppc64le.rpm zk-0.15.2-bp157.2.3.1.s390x.rpm openSUSE-2026-20 Recommended update for powerline moderate openSUSE Backports SLE-15-SP7 Update This update for powerline fixes the following issues: - Use %python3_fix_shebang_path to fix python binaries hashbangs (boo#1255982) powerline-2.8.4-bp157.2.6.1.src.rpm powerline-2.8.4-bp157.2.6.1.x86_64.rpm powerline-docs-2.8.4-bp157.2.6.1.noarch.rpm powerline-fonts-2.8.4-bp157.2.6.1.noarch.rpm tmux-powerline-2.8.4-bp157.2.6.1.noarch.rpm vim-plugin-powerline-2.8.4-bp157.2.6.1.noarch.rpm powerline-2.8.4-bp157.2.6.1.aarch64.rpm powerline-2.8.4-bp157.2.6.1.ppc64le.rpm powerline-2.8.4-bp157.2.6.1.s390x.rpm openSUSE-2026-22 Security update for chromium moderate openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 144.0.7559.59 (boo#1256614) * CVE-2026-0899: Out of bounds memory access in V8 * CVE-2026-0900: Inappropriate implementation in V8 * CVE-2026-0901: Inappropriate implementation in Blink * CVE-2026-0902: Inappropriate implementation in V8 * CVE-2026-0903: Insufficient validation of untrusted input in Downloads * CVE-2026-0904: Incorrect security UI in Digital Credentials * CVE-2026-0905: Insufficient policy enforcement in Network * CVE-2026-0906: Incorrect security UI * CVE-2026-0907: Incorrect security UI in Split View * CVE-2026-0908: Use after free in ANGLE - use noopenh264 where available chromedriver-144.0.7559.59-bp157.2.100.1.x86_64.rpm chromium-144.0.7559.59-bp157.2.100.1.nosrc.rpm chromium-144.0.7559.59-bp157.2.100.1.x86_64.rpm chromedriver-144.0.7559.59-bp157.2.100.1.aarch64.rpm chromium-144.0.7559.59-bp157.2.100.1.aarch64.rpm chromedriver-144.0.7559.59-bp157.2.100.1.ppc64le.rpm chromium-144.0.7559.59-bp157.2.100.1.ppc64le.rpm openSUSE-2026-24 Security update for python-weasyprint important openSUSE Backports SLE-15-SP7 Update This update for python-weasyprint fixes the following issues: - CVE-2025-68616: Fixed a server-side request forgery in default fetcher (boo#1256936). python-weasyprint-60.2-bp157.2.3.1.src.rpm python311-weasyprint-60.2-bp157.2.3.1.noarch.rpm openSUSE-2026-28 Security update for chromium moderate openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 144.0.7559.96 (boo#1257011) * CVE-2026-1220: Race in V8 - update INSTALL.sh to handle the addded tags in the desktop file (boo#1256938) chromedriver-144.0.7559.96-bp157.2.103.1.x86_64.rpm chromium-144.0.7559.96-bp157.2.103.1.nosrc.rpm chromium-144.0.7559.96-bp157.2.103.1.x86_64.rpm chromedriver-144.0.7559.96-bp157.2.103.1.aarch64.rpm chromium-144.0.7559.96-bp157.2.103.1.aarch64.rpm chromedriver-144.0.7559.96-bp157.2.103.1.ppc64le.rpm chromium-144.0.7559.96-bp157.2.103.1.ppc64le.rpm openSUSE-2026-30 Optional update adding minisign low openSUSE Backports SLE-15-SP7 Update This optional update makes available minisign. It is an implementation of a source tarball verification mechanism, alternative to OpenPGP format signatures. It is a dependency of an upcoming update to obs-source_validator. minisign-0.12-bp157.2.1.src.rpm minisign-0.12-bp157.2.1.x86_64.rpm minisign-debuginfo-0.12-bp157.2.1.x86_64.rpm minisign-debugsource-0.12-bp157.2.1.x86_64.rpm minisign-0.12-bp157.2.1.i586.rpm minisign-debuginfo-0.12-bp157.2.1.i586.rpm minisign-debugsource-0.12-bp157.2.1.i586.rpm minisign-0.12-bp157.2.1.aarch64.rpm minisign-debuginfo-0.12-bp157.2.1.aarch64.rpm minisign-debugsource-0.12-bp157.2.1.aarch64.rpm minisign-0.12-bp157.2.1.ppc64le.rpm minisign-debuginfo-0.12-bp157.2.1.ppc64le.rpm minisign-debugsource-0.12-bp157.2.1.ppc64le.rpm minisign-0.12-bp157.2.1.s390x.rpm minisign-debuginfo-0.12-bp157.2.1.s390x.rpm minisign-debugsource-0.12-bp157.2.1.s390x.rpm openSUSE-2026-40 Recommended update for vlc moderate openSUSE Backports SLE-15-SP7 Update This update for vlc fixes the following issues: - Update to version 3.0.23: + Codecs: * Fix WebVTT line positioning * Expose additional audio codec information (notably for Flac 24bit) + Demuxers: * fix some JPEG files wih JFIF headers + Security: * Fix null deref in libass, undefined shift in theora and cc-708, integer overflow in daala, Infinite loop in h264 parsing, buffer overflow in png and multiple format-overflows + Misc: * Prepare compatibility for taglib 2.0, Qt6, FFmpeg8, mingw-w64 v13 and newer versions of libplacebo and pupnp - Update to version 3.0.22: + Core: Assume subpictures are in SDR by default + Decoders: * Fix Opus channel mapping * Fix hardware decoding with VideoToolbox of XVID MPEG-4 video * Add dav1d-all-layers option * Fix DVD CEA-608 captions parsing * Fix ProRes 4:4:4:4 * Disable decoding using libdca, libmpeg2 and liba52 by default in favor of libavcodec + Demuxers: * Add support for DMX audio music (MUS) files * Handle mkv-use-chapter-codec option * Add A_ATRAC/AT1 support in matroska * Prevent FLAC seeking logic get stuck * Handle pictures in FLAC * Fix VOB/AOB LPCM/MLP detection failing occasionally * Cut QNap title on first invalid character * Fix display of certain JPEG files * Fix playback of very short ASF files (duration less than 1s) * Multiple fixes in MPEG-TS * Fix crashes in multiple demuxers (reported by rub.de, oss-fuzz and others) + Input: Fix SFTP seeking for large files on 32-bit OS + Interface: * Qt: Add option to use dark palette * Qt: Add compilation support for newer versions of Qt5 * Qt: Fix scrolling on volume slider * KDE: fix MPRIS state when started from file + Service Discovery: UPnP: remove SAT>IP channel list fallback + Video Output: * Use a better stretch mode in wingdi * Fetch missing device information when running in UWP + Video Filter: * Add AMD GPU Frame Rate Doubler (Direct3D11) * Improve visualization of low frequencies in spectrogram - Pin to ffmpeg-7; even the master branch does not yet build against ffmpeg 8. - opus_header: fix channel mapping family 1 parsing (boo#1244167). - Drop opencv sub-package, and hence no longer needed pkgconfig(opencv) libvlc5-3.0.23-bp157.2.5.1.x86_64.rpm libvlc5-debuginfo-3.0.23-bp157.2.5.1.x86_64.rpm libvlccore9-3.0.23-bp157.2.5.1.x86_64.rpm libvlccore9-debuginfo-3.0.23-bp157.2.5.1.x86_64.rpm vlc-3.0.23-bp157.2.5.1.src.rpm vlc-3.0.23-bp157.2.5.1.x86_64.rpm vlc-codec-fluidsynth-3.0.23-bp157.2.5.1.x86_64.rpm vlc-codec-fluidsynth-debuginfo-3.0.23-bp157.2.5.1.x86_64.rpm vlc-codec-gstreamer-3.0.23-bp157.2.5.1.x86_64.rpm vlc-codec-gstreamer-debuginfo-3.0.23-bp157.2.5.1.x86_64.rpm vlc-debuginfo-3.0.23-bp157.2.5.1.x86_64.rpm vlc-debugsource-3.0.23-bp157.2.5.1.x86_64.rpm vlc-devel-3.0.23-bp157.2.5.1.x86_64.rpm vlc-jack-3.0.23-bp157.2.5.1.x86_64.rpm vlc-jack-debuginfo-3.0.23-bp157.2.5.1.x86_64.rpm vlc-lang-3.0.23-bp157.2.5.1.noarch.rpm vlc-noX-3.0.23-bp157.2.5.1.x86_64.rpm vlc-noX-debuginfo-3.0.23-bp157.2.5.1.x86_64.rpm vlc-qt-3.0.23-bp157.2.5.1.x86_64.rpm vlc-qt-debuginfo-3.0.23-bp157.2.5.1.x86_64.rpm libvlc5-3.0.23-bp157.2.5.1.aarch64.rpm libvlc5-debuginfo-3.0.23-bp157.2.5.1.aarch64.rpm libvlccore9-3.0.23-bp157.2.5.1.aarch64.rpm libvlccore9-debuginfo-3.0.23-bp157.2.5.1.aarch64.rpm vlc-3.0.23-bp157.2.5.1.aarch64.rpm vlc-codec-fluidsynth-3.0.23-bp157.2.5.1.aarch64.rpm vlc-codec-fluidsynth-debuginfo-3.0.23-bp157.2.5.1.aarch64.rpm vlc-codec-gstreamer-3.0.23-bp157.2.5.1.aarch64.rpm vlc-codec-gstreamer-debuginfo-3.0.23-bp157.2.5.1.aarch64.rpm vlc-debuginfo-3.0.23-bp157.2.5.1.aarch64.rpm vlc-debugsource-3.0.23-bp157.2.5.1.aarch64.rpm vlc-devel-3.0.23-bp157.2.5.1.aarch64.rpm vlc-jack-3.0.23-bp157.2.5.1.aarch64.rpm vlc-jack-debuginfo-3.0.23-bp157.2.5.1.aarch64.rpm vlc-noX-3.0.23-bp157.2.5.1.aarch64.rpm vlc-noX-debuginfo-3.0.23-bp157.2.5.1.aarch64.rpm vlc-qt-3.0.23-bp157.2.5.1.aarch64.rpm vlc-qt-debuginfo-3.0.23-bp157.2.5.1.aarch64.rpm libvlc5-3.0.23-bp157.2.5.1.ppc64le.rpm libvlc5-debuginfo-3.0.23-bp157.2.5.1.ppc64le.rpm libvlccore9-3.0.23-bp157.2.5.1.ppc64le.rpm libvlccore9-debuginfo-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-codec-fluidsynth-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-codec-fluidsynth-debuginfo-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-codec-gstreamer-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-codec-gstreamer-debuginfo-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-debuginfo-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-debugsource-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-devel-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-jack-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-jack-debuginfo-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-noX-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-noX-debuginfo-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-qt-3.0.23-bp157.2.5.1.ppc64le.rpm vlc-qt-debuginfo-3.0.23-bp157.2.5.1.ppc64le.rpm openSUSE-2026-33 Security update for cacti, cacti-spine critical openSUSE Backports SLE-15-SP7 Update This update for cacti, cacti-spine fixes the following issues: cacti 1.2.30: - Unable to add new users - When using Automation Rules, specifying graph criteria may cause issues - When transferring a system from a backup if the poller has not run recently rrdtool issues are found - When translating, quotes may cause incorrect text to appear - When using Boost for the first time, warnings may appear - When refreshing forms, items may be checked incorrectly by xmacan cacti 1.2.29: - CVE-2025-22604 GHSA-c5j8-jxj3-hh36 - Authenticated RCE via multi-line SNMP responses (bsc#1236488) - CVE-2025-24368 GHSA-f9c7-7rc3-574c - SQL Injection vulnerability when using tree rules through Automation API (bsc#1236490) - CVE-2024-54145 GHSA-fh3x-69rr-qqpp - SQL Injection vulnerability when request automation devices (bsc#1236487) - CVE-2025-24367 GHSA-fxrq-fr7h-9rqq - Arbitrary File Creation leading to RCE (bsc#1236489) - CVE-2024-45598 GHSA-pv2c-97pp-vxwg - Local File Inclusion (LFI) Vulnerability via Poller Standard Error Log Path (bsc#1236482) - CVE-2024-54146 GHSA-vj9g-P7F2-4wqj - SQL Injection vulnerability when view host template (bsc#1236486) - issue: Temporary table names may incorrectly think they have a schema - issue: When using Preset Time to view graphs, it is using a fixed point rather than relative time - issue: Fix issue where RRA files are not automatically removed - issue: Fix invalid help link for Automation Networks - issue: Unable to disable a tree within the GUI - issue: When removing graphs, RRA files may be left behind - issue: Improve compatibility with ping under FreeBSD - issue: Improve compatibility wtih Slice RRD tool under PHP 8.x - issue: Allow IPv6 formats to use colons without port - issue: Update Fortigate, Aruba OSCX and Clearpass templates - issue: When a plugin is disabled, unable to use GUI to enable it again - issue: When upgrading, ensure that replication only runs as necessary - issue: Improve caching and syncing issues with replication - issue: Improve caching techniques for database calls - issue: Improve compatibility for Error constants under PHP 8.4 - issue: When running the upgrade database script, cursor is left in the middle of the row - issue: Guest page does not automatically refresh - issue: When installing, conversion of tables may produce collation errors - feature: Add HPE Nimble/Alletra template - feature: When installing, only convert core cacti tables - Add /srv/www directories to filelist [boo#1231027] - fix for cacti-cron.timer & cacti-cron.service failing after upgrade has already removed - replace cacti-cron.timer & cacti-cron.service with cactid.service to fix thold & other "sub poller" poller processes not running. cacti 1.2.28: - CVE-2024-43365 GHSA-49f2-hwx9-qffr: XSS vulnerability when creating external links with the consolenewsection parameter (bsc#1231372) - CVE-2024-43364 GHSA-fgc6-g8gc-wcg5: XSS vulnerability when creating external links with the title parameter (bsc#1231371) - CVE-2024-43363 GHSA-gxq4-mv8h-6qj4: RCE vulnerability can be executed via Log Poisoning (bsc#1231370) - CVE-2024-43362 GHSA-wh9c-v56x-v77c: XSS vulnerability when creating external links with the fileurl parameter - issue: When using LDAP authentication the first time, warnings may appear in logs - issue: When installing, a replication loop for plugin_realms may occur - issue: When installing, remote poller may attempt to sync with other pollers - issue: When a Data Query has a space, indexes may not be properly escaped - issue: Boost does not always order data source records properly - issue: Add IP address to the login audit for successful logins by xmacan - issue: Undefined variable error may sometimes occur when dealing with RRD output by MSS970 - issue: When export to CSV, only the first line of notes is included - issue: When rendering forms, missing default value can cause errors - issue: Allow hosted content to be executable for the links page - issue: When closing database connections, some may linger incorrectly - issue: When changing passwords, an infinite loop may occur by ddb4github - issue: When using Cacti Daemon, a "Cron out of sync" message may be reported - issue: Add ability to filter/sort users by group or last login time - issue: When using List View, unable to add Graphs to a Report - issue: When using SNMPv3, some devices may show polling issues - issue: Limit table conversion to Cacti core tables - issue: Fix issues with posix-based kills on Windows - issue: When installing, password changes may fail on new installations - issue: When using structured RRD folders, permission issues may be flagged incorrectly - issue: When unable to locate a valid theme, new default will be Modern - issue: Properly cache the data source information for dsstats processing - issue: When reindexing, verify all fields may not work as intended - feature: Add ability to log database connections/disconnections - feature: Add Ping Method where connection refused assumes host is up - feature: When displaying graphs, default end time does not show full 24 hour period - feature: Add --id to remove_device.php - feature: Add Location and Site to Graph List View - feature: Add more verbose logging to Boost - feature: Update jQuery to 3.7.1 - feature: Update jQueryUI to 1.14.0 - feature: Update Purify.js to 3.1.6 - feature: Update billboard.js to 3.13.0 - feature: Improve the performance of the repopulation of the poller cache Changes in cacti-spine: cacti-spine 1.2.30: - no changes - Bump/rebuild to match Cacti 1.2.30 cacti-spine 1.2.28: - When using Ping or SNMP Uptime, host is not always detected properly - Add Ping Method where connection refused assumes host is up cacti-spine-1.2.30-bp157.2.3.1.src.rpm cacti-spine-1.2.30-bp157.2.3.1.x86_64.rpm cacti-spine-debuginfo-1.2.30-bp157.2.3.1.x86_64.rpm cacti-spine-debugsource-1.2.30-bp157.2.3.1.x86_64.rpm cacti-spine-1.2.30-bp157.2.3.1.i586.rpm cacti-spine-debuginfo-1.2.30-bp157.2.3.1.i586.rpm cacti-spine-debugsource-1.2.30-bp157.2.3.1.i586.rpm cacti-spine-1.2.30-bp157.2.3.1.aarch64.rpm cacti-spine-debuginfo-1.2.30-bp157.2.3.1.aarch64.rpm cacti-spine-debugsource-1.2.30-bp157.2.3.1.aarch64.rpm cacti-spine-1.2.30-bp157.2.3.1.ppc64le.rpm cacti-spine-debuginfo-1.2.30-bp157.2.3.1.ppc64le.rpm cacti-spine-debugsource-1.2.30-bp157.2.3.1.ppc64le.rpm cacti-spine-1.2.30-bp157.2.3.1.s390x.rpm cacti-spine-debuginfo-1.2.30-bp157.2.3.1.s390x.rpm cacti-spine-debugsource-1.2.30-bp157.2.3.1.s390x.rpm openSUSE-2026-148 Security update for cacti, cacti-spine critical openSUSE Backports SLE-15-SP7 Update This update for cacti, cacti-spine fixes the following issues: cacti 1.2.30: - Unable to add new users - When using Automation Rules, specifying graph criteria may cause issues - When transferring a system from a backup if the poller has not run recently rrdtool issues are found - When translating, quotes may cause incorrect text to appear - When using Boost for the first time, warnings may appear - When refreshing forms, items may be checked incorrectly by xmacan cacti 1.2.29: - CVE-2025-22604 GHSA-c5j8-jxj3-hh36 - Authenticated RCE via multi-line SNMP responses (bsc#1236488) - CVE-2025-24368 GHSA-f9c7-7rc3-574c - SQL Injection vulnerability when using tree rules through Automation API (bsc#1236490) - CVE-2024-54145 GHSA-fh3x-69rr-qqpp - SQL Injection vulnerability when request automation devices (bsc#1236487) - CVE-2025-24367 GHSA-fxrq-fr7h-9rqq - Arbitrary File Creation leading to RCE (bsc#1236489) - CVE-2024-45598 GHSA-pv2c-97pp-vxwg - Local File Inclusion (LFI) Vulnerability via Poller Standard Error Log Path (bsc#1236482) - CVE-2024-54146 GHSA-vj9g-P7F2-4wqj - SQL Injection vulnerability when view host template (bsc#1236486) - issue: Temporary table names may incorrectly think they have a schema - issue: When using Preset Time to view graphs, it is using a fixed point rather than relative time - issue: Fix issue where RRA files are not automatically removed - issue: Fix invalid help link for Automation Networks - issue: Unable to disable a tree within the GUI - issue: When removing graphs, RRA files may be left behind - issue: Improve compatibility with ping under FreeBSD - issue: Improve compatibility wtih Slice RRD tool under PHP 8.x - issue: Allow IPv6 formats to use colons without port - issue: Update Fortigate, Aruba OSCX and Clearpass templates - issue: When a plugin is disabled, unable to use GUI to enable it again - issue: When upgrading, ensure that replication only runs as necessary - issue: Improve caching and syncing issues with replication - issue: Improve caching techniques for database calls - issue: Improve compatibility for Error constants under PHP 8.4 - issue: When running the upgrade database script, cursor is left in the middle of the row - issue: Guest page does not automatically refresh - issue: When installing, conversion of tables may produce collation errors - feature: Add HPE Nimble/Alletra template - feature: When installing, only convert core cacti tables - Add /srv/www directories to filelist [boo#1231027] - fix for cacti-cron.timer & cacti-cron.service failing after upgrade has already removed - replace cacti-cron.timer & cacti-cron.service with cactid.service to fix thold & other "sub poller" poller processes not running. cacti 1.2.28: - CVE-2024-43365 GHSA-49f2-hwx9-qffr: XSS vulnerability when creating external links with the consolenewsection parameter (bsc#1231372) - CVE-2024-43364 GHSA-fgc6-g8gc-wcg5: XSS vulnerability when creating external links with the title parameter (bsc#1231371) - CVE-2024-43363 GHSA-gxq4-mv8h-6qj4: RCE vulnerability can be executed via Log Poisoning (bsc#1231370) - CVE-2024-43362 GHSA-wh9c-v56x-v77c: XSS vulnerability when creating external links with the fileurl parameter - issue: When using LDAP authentication the first time, warnings may appear in logs - issue: When installing, a replication loop for plugin_realms may occur - issue: When installing, remote poller may attempt to sync with other pollers - issue: When a Data Query has a space, indexes may not be properly escaped - issue: Boost does not always order data source records properly - issue: Add IP address to the login audit for successful logins by xmacan - issue: Undefined variable error may sometimes occur when dealing with RRD output by MSS970 - issue: When export to CSV, only the first line of notes is included - issue: When rendering forms, missing default value can cause errors - issue: Allow hosted content to be executable for the links page - issue: When closing database connections, some may linger incorrectly - issue: When changing passwords, an infinite loop may occur by ddb4github - issue: When using Cacti Daemon, a "Cron out of sync" message may be reported - issue: Add ability to filter/sort users by group or last login time - issue: When using List View, unable to add Graphs to a Report - issue: When using SNMPv3, some devices may show polling issues - issue: Limit table conversion to Cacti core tables - issue: Fix issues with posix-based kills on Windows - issue: When installing, password changes may fail on new installations - issue: When using structured RRD folders, permission issues may be flagged incorrectly - issue: When unable to locate a valid theme, new default will be Modern - issue: Properly cache the data source information for dsstats processing - issue: When reindexing, verify all fields may not work as intended - feature: Add ability to log database connections/disconnections - feature: Add Ping Method where connection refused assumes host is up - feature: When displaying graphs, default end time does not show full 24 hour period - feature: Add --id to remove_device.php - feature: Add Location and Site to Graph List View - feature: Add more verbose logging to Boost - feature: Update jQuery to 3.7.1 - feature: Update jQueryUI to 1.14.0 - feature: Update Purify.js to 3.1.6 - feature: Update billboard.js to 3.13.0 - feature: Improve the performance of the repopulation of the poller cache Changes in cacti-spine: cacti-spine 1.2.30: - no changes - Bump/rebuild to match Cacti 1.2.30 cacti-spine 1.2.28: - When using Ping or SNMP Uptime, host is not always detected properly - Add Ping Method where connection refused assumes host is up cacti-1.2.30-bp157.2.3.1.noarch.rpm cacti-1.2.30-bp157.2.3.1.src.rpm openSUSE-2026-35 Security update for chromium important openSUSE Backports SLE-15-SP7 Update Chromium was updated to fix the following issues: Chromium 144.0.7559.109 (boo#1257404) * CVE-2026-1504: Inappropriate implementation in Background Fetch API chromedriver-144.0.7559.109-bp157.2.106.1.x86_64.rpm chromium-144.0.7559.109-bp157.2.106.1.nosrc.rpm chromium-144.0.7559.109-bp157.2.106.1.x86_64.rpm chromedriver-144.0.7559.109-bp157.2.106.1.aarch64.rpm chromium-144.0.7559.109-bp157.2.106.1.aarch64.rpm chromedriver-144.0.7559.109-bp157.2.106.1.ppc64le.rpm chromium-144.0.7559.109-bp157.2.106.1.ppc64le.rpm openSUSE-2026-38 Security update for python-djangorestframework moderate openSUSE Backports SLE-15-SP7 Update This update for python-djangorestframework fixes the following issues: - CVE-2024-21520: Fixed improper input sanitization before splitting and joining with 'br' tags (boo#1227077) - Tests can be run only on (newer) python311 stack - Make it at least installable on python3 stack (no guarantees for it to run) - Use sle15allpythons to get the Python 3.6 packages (jsc#PED-8919) python-djangorestframework-3.14.0-bp157.2.3.1.src.rpm python3-djangorestframework-3.14.0-bp157.2.3.1.noarch.rpm python311-djangorestframework-3.14.0-bp157.2.3.1.noarch.rpm python-djangorestframework-test-3.14.0-bp157.2.3.1.src.rpm openSUSE-2026-41 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 144.0.7559.132 (boo#1257650) * CVE-2026-1861: Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. * CVE-2026-1862: Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. chromedriver-144.0.7559.132-bp157.2.109.1.x86_64.rpm chromium-144.0.7559.132-bp157.2.109.1.nosrc.rpm chromium-144.0.7559.132-bp157.2.109.1.x86_64.rpm chromedriver-144.0.7559.132-bp157.2.109.1.aarch64.rpm chromium-144.0.7559.132-bp157.2.109.1.aarch64.rpm chromedriver-144.0.7559.132-bp157.2.109.1.ppc64le.rpm chromium-144.0.7559.132-bp157.2.109.1.ppc64le.rpm openSUSE-2026-50 Security update for micropython low openSUSE Backports SLE-15-SP7 Update This update for micropython fixes the following issues: - CVE-2026-1998: Fixed a segmentation fault in 'mp_map_lookup' via 'mp_import_all' (boo#1257803) - Version 1.26.1 * esp32: update esp_tinyusb component to v1.7.6 * tools: add an environment variable MICROPY_MAINTAINER_BUILD * esp32: add IDF Component Lockfiles to git repo * shared/tinyusb: fix hang from new tx_overwritabe_if_not_connected flag * shared/tinyusb/mp_usbd_cdc: rewrite USB CDC TX loop * tools/mpremote: don't apply Espressif DTR/RTS quirk to TinyUSB CDC dev - Fix building on single core systems * Skip tests/thread/stress_schedule.py when single core system detected - Build with mbedtls-3.6.5 instead of bundled 3.6.2 to fix CVE-2025-59438 - Version 1.26.0 * Added machine.I2CTarget for creating I2C target devices on multiple ports. * New MCU support: STM32N6xx (800 MHz, ML accel) and ESP32-C2 (WiFi + BLE). * Major float accuracy boost (~28% ~98%), constant folding in compiler. * Optimized native/Viper emitters; reduced heap use for slices. * Time functions standardized (1970 2099); new boards across ESP32, SAMD, STM32, Zephyr. * ESP32: ESP-IDF 5.4.2, flash auto-detect, PCNT class, LAN8670 PHY. * RP2: compressed errors, better lightsleep, hard IRQ timers. * Zephyr v4.0.0: PWM, SoftI2C/SPI, BLE runtime services, boot.py/main.py support. * mpremote adds fs tree, improved df, portable config paths. * Updated lwIP, LittleFS, libhydrogen, stm32lib; expanded hardware/CI tests. micropython-1.26.1-bp157.5.1.src.rpm micropython-1.26.1-bp157.5.1.x86_64.rpm mpremote-1.26.1-bp157.5.1.noarch.rpm mpy-tools-1.26.1-bp157.5.1.x86_64.rpm micropython-1.26.1-bp157.5.1.aarch64.rpm mpy-tools-1.26.1-bp157.5.1.aarch64.rpm openSUSE-2026-49 Recommended update for gn moderate openSUSE Backports SLE-15-SP7 Update This update for gn fixes the following issues: - Update to version 0.20251217: * Fix sha2 on big endian * [Windows] Reduce the number of worker threads on many-core machines * Add a sha256 hash implementation and use it for string_hash * Opt-in to the Windows SegmentHeap * Add a `module_name` flag to source_set. * Refactor module name to be dynamic. * Optimize vector creation in compile_commands_writer.cc. * Run 'tools/run_formatter.sh' * Implement `string_hash` function. * Support weak_libraries * Do not add .inputdeps paths to --ninja-outputs-file * Make clang modules output -fmodule-file=foo=<pcm>. * infra: Revert CIPD autoconf * infra: Include autoconf bin directory to PATH * infra: Fix autoconf executable path * infra: Use CIPD autoconf * Allow led access in GN via http://go/ciba * Revert "Build non-linkable deps async with Ninja's validaitons" * Upgrade linux bots from ubuntu 22.04 to ubuntu 24.04 * Use unordered_map instead of map in HeaderChecker * Add --file_relation to gn refs command * Optimize vector initialization and preallocation in desc_builder.cc. * Add `reserve` statement when vector size is known beforehand. * Refactor container update by preferring the range insert. * Handle symlinked directories correctly during gn clean on Windows. * Fix relative imports from args.gn. - Update to version 0.20250918: * update reference.md * Include -fmodule-file flags in compile_commands.json * Refactor C++ module dependency logic into a new utility * Gitiles navigation bar * Adds a len() function * Avoid clashes of include_dir in rust-project.json. * Check all targets to find duplicated outputs. * infra/config: Remove luci.recipes.use_python3 experiment * Handle empty outputs in WriteInputDepsStampOrPhonyAndGetDep * build: Propagate module dependencies through group targets * Deduplicate item in 'deps', 'sources' and related lists * infra: Update comment for macOS version used in CQ/CI * [Apple] Allow passing a manifest to the post-processing script * Update link to buganizer in README.md * [Apple] Fix `gn gen` when using swift and no_stamp_files * [Apple] Remove deprecated aliases for `post_processing_$var` * Revert "Allow newline in string literal" * Use std::ranges::all_of in parse_tree_unittest * infra: Correctly use macOS 13 instead of 11 * Update Xcode and macOS version in bots * infra: Add shadow buckets to trigger led job * Allow newline in string literal * Revert "Update macOS version to 13 used in CQ/CI" * Update macOS version to 13 used in CQ/CI * Refactor command_format.cc * Shorten targets from //path/to/foo:foo to //path/to/foo * Modernize and improve parse_tree.cc * Auto-format the codebase * Remove hardcoded -fmodules-embed-all-files flag * Reland "Use JSON escaping for JSON string output" gn-0.20251217-bp157.2.9.1.src.rpm gn-0.20251217-bp157.2.9.1.x86_64.rpm gn-0.20251217-bp157.2.9.1.i586.rpm gn-0.20251217-bp157.2.9.1.aarch64.rpm gn-0.20251217-bp157.2.9.1.ppc64le.rpm gn-0.20251217-bp157.2.9.1.s390x.rpm openSUSE-2026-44 Security update for tcpreplay important openSUSE Backports SLE-15-SP7 Update This update for tcpreplay fixes the following issues: - update to 4.5.2: * features added since 4.4.4 - fix/recalculate header checksum for ipv6-frag - IPv6 frag checksum support - AF_XDP socket support - tcpreplay -w (write into a pcap file) - tcpreaplay --fixhdrlen - --include and --exclude options - SLL2 support - Haiku support * security fixes reported for 4.4.4 fixed in 4.5.2 - CVE-2023-4256 / boo#1218249 - CVE-2023-43279 / boo#1221324 - CVE-2024-3024 / boo#1222131 (likely) - CVE-2024-22654 / boo#1243845 - CVE-2025-9157 / boo#1248322 - CVE-2025-9384 / boo#1248595 - CVE-2025-9385 / boo#1248596 - CVE-2025-9386 / boo#1248597 - CVE-2025-9649 / boo#1248964 - CVE-2025-51006 / boo#1250356 - see https://github.com/appneta/tcpreplay/compare/v4.4.4...v4.5.2 for full changelog - security fix for CVE-2025-8746 / boo#1247919 tcpreplay-4.5.2-bp157.2.3.1.src.rpm tcpreplay-4.5.2-bp157.2.3.1.x86_64.rpm tcpreplay-4.5.2-bp157.2.3.1.i586.rpm tcpreplay-4.5.2-bp157.2.3.1.aarch64.rpm tcpreplay-4.5.2-bp157.2.3.1.ppc64le.rpm tcpreplay-4.5.2-bp157.2.3.1.s390x.rpm openSUSE-2026-46 Security update for htmldoc important openSUSE Backports SLE-15-SP7 Update This update for htmldoc fixes the following issues: - CVE-2024-46478: Fixed buffer overflow when handling tabs through the parse_pre function (boo#1232380). htmldoc-1.9.16-bp157.3.3.1.src.rpm htmldoc-1.9.16-bp157.3.3.1.x86_64.rpm htmldoc-1.9.16-bp157.3.3.1.i586.rpm htmldoc-1.9.16-bp157.3.3.1.aarch64.rpm htmldoc-1.9.16-bp157.3.3.1.ppc64le.rpm htmldoc-1.9.16-bp157.3.3.1.s390x.rpm openSUSE-2026-53 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - fix INSTALL.sh again to replace the tags in desktop file, appdata and manpage (boo#1258199) - Chromium 145.0.7632.75: * CVE-2026-2441: Use after free in CSS (boo#1258185) - Chromium 145.0.7632.67: * Revert a change in url_fixer that may have caused crashes - Chromium 145.0.7632.45 (boo#1258116) * jpeg-xl support has been readded * CVE-2026-2313: Use after free in CSS * CVE-2026-2314: Heap buffer overflow in Codecs * CVE-2026-2315: Inappropriate implementation in WebGPU * CVE-2026-2316: Insufficient policy enforcement in Frames * CVE-2026-2317: Inappropriate implementation in Animation * CVE-2026-2318: Inappropriate implementation in PictureInPicture * CVE-2026-2319: Race in DevTools * CVE-2026-2320: Inappropriate implementation in File input * CVE-2026-2321: Use after free in Ozone * CVE-2026-2322: Inappropriate implementation in File input * CVE-2026-2323: Inappropriate implementation in Downloads chromedriver-145.0.7632.75-bp157.2.118.1.x86_64.rpm chromium-145.0.7632.75-bp157.2.118.1.nosrc.rpm chromium-145.0.7632.75-bp157.2.118.1.x86_64.rpm chromedriver-145.0.7632.75-bp157.2.118.1.aarch64.rpm chromium-145.0.7632.75-bp157.2.118.1.aarch64.rpm openSUSE-2026-54 Recommended update for chromium moderate openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - more fixes for desktop file, some variables were lowercased, further adaptions in INSTALL script (boo#1258199) - also copy rollup into third_party/node/node_modules - stay on llvm-10 for swiftshader but bring a similar patch - drop use of rollup binaries and use rollup-3.x which does not use prebuilt binaries (that fail at least on older ppc64le) follow the approach of the debian packaging - update/resync ppc64le patches from fedora chromedriver-145.0.7632.75-bp157.2.121.1.x86_64.rpm chromium-145.0.7632.75-bp157.2.121.1.nosrc.rpm chromium-145.0.7632.75-bp157.2.121.1.x86_64.rpm chromedriver-145.0.7632.75-bp157.2.121.1.aarch64.rpm chromium-145.0.7632.75-bp157.2.121.1.aarch64.rpm chromedriver-145.0.7632.75-bp157.2.121.1.ppc64le.rpm chromium-145.0.7632.75-bp157.2.121.1.ppc64le.rpm openSUSE-2026-59 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 145.0.7632.109 (boo#1258438): * CVE-2026-2648: Heap buffer overflow in PDFium * CVE-2026-2649: Integer overflow in V8 * CVE-2026-2650: Heap buffer overflow in Media chromedriver-145.0.7632.109-bp157.2.124.1.x86_64.rpm chromium-145.0.7632.109-bp157.2.124.1.nosrc.rpm chromium-145.0.7632.109-bp157.2.124.1.x86_64.rpm chromedriver-145.0.7632.109-bp157.2.124.1.aarch64.rpm chromium-145.0.7632.109-bp157.2.124.1.aarch64.rpm chromedriver-145.0.7632.109-bp157.2.124.1.ppc64le.rpm chromium-145.0.7632.109-bp157.2.124.1.ppc64le.rpm openSUSE-2026-56 Security update for python-nltk important openSUSE Backports SLE-15-SP7 Update This update for python-nltk fixes the following issues: - CVE-2025-14009: Fixed Secure ZIP extraction (boo#1258436) python-nltk-3.7-bp157.3.3.1.src.rpm python3-nltk-3.7-bp157.3.3.1.noarch.rpm openSUSE-2026-66 Recommended update for gitea-tea moderate openSUSE Backports SLE-15-SP7 Update This update for gitea-tea fixes the following issues: - Fixed terminal rendering errors gitea-tea-0.11.1-bp157.2.12.1.src.rpm gitea-tea-0.11.1-bp157.2.12.1.x86_64.rpm gitea-tea-bash-completion-0.11.1-bp157.2.12.1.noarch.rpm gitea-tea-zsh-completion-0.11.1-bp157.2.12.1.noarch.rpm gitea-tea-0.11.1-bp157.2.12.1.i586.rpm gitea-tea-0.11.1-bp157.2.12.1.aarch64.rpm gitea-tea-0.11.1-bp157.2.12.1.ppc64le.rpm gitea-tea-0.11.1-bp157.2.12.1.s390x.rpm openSUSE-2026-63 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 145.0.7632.116 (boo#1258733): * CVE-2026-3061: Out of bounds read in Media * CVE-2026-3062: Out of bounds read and write in Tint * CVE-2025-3063: Inappropriate implementation in DevTools chromedriver-145.0.7632.116-bp157.2.127.1.x86_64.rpm chromium-145.0.7632.116-bp157.2.127.1.nosrc.rpm chromium-145.0.7632.116-bp157.2.127.1.x86_64.rpm chromedriver-145.0.7632.116-bp157.2.127.1.aarch64.rpm chromium-145.0.7632.116-bp157.2.127.1.aarch64.rpm chromedriver-145.0.7632.116-bp157.2.127.1.ppc64le.rpm chromium-145.0.7632.116-bp157.2.127.1.ppc64le.rpm openSUSE-2026-61 Security update for phpunit important openSUSE Backports SLE-15-SP7 Update This update for phpunit fixes the following issues: version 9.6.34: - CVE-2026-24765: prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage (boo#1257381) php7-phpunit-9.6.34-bp157.2.3.1.noarch.rpm php7-phpunit-9.6.34-bp157.2.3.1.src.rpm php8-phpunit-9.6.34-bp157.2.3.1.noarch.rpm php8-phpunit-9.6.34-bp157.2.3.1.src.rpm openSUSE-2026-64 Recommended update for mosquitto important openSUSE Backports SLE-15-SP7 Update This update for mosquitto fixes the following issues: - update to 2.0.23 (boo#1258671) * Fix handling of disconnected sessions for `per_listener_settings true` * Check return values of openssl *_get_ex_data() and *_set_ex_data() to prevent possible crash. This could occur only in extremely unlikely situations * Check return value of openssl ASN1_string_[get0_]data() functions for NULL. This prevents a crash in case of incorrect certificate handling in openssl * Fix potential crash on startup if a malicious/corrupt persistence file from mosquitto 1.5 or earlier is loaded * Limit auto_id_prefix to 50 characters - Update to version 2.0.22 Broker * Bridge: Fix idle_timeout never occurring for lazy bridges. * Fix case where max_queued_messages = 0 was not treated as unlimited. * Fix --version exit code and output. * Fix crash on receiving a $CONTROL message over a bridge, if per_listener_settings is set true and the bridge is carrying out topic remapping. * Fix incorrect reference clock being selected on startup on Linux. Closes #3238. * Fix reporting of client disconnections being incorrectly attributed to "out of memory". * Fix compilation when using WITH_OLD_KEEPALIVE. * Fix problems with secure websockets. * Fix crash on exit when using WITH_EPOLL=no. * Fix clients being incorrectly expired when they have keepalive == max_keepalive. Closes #3226, #3286. Dynamic security plugin * Fix mismatch memory free when saving config which caused memory tracking to be incorrect. Client library * Fix C++ symbols being removed when compiled with link time optimisation. * TLS error handling was incorrectly setting a protocol error for non-TLS errors. This would cause the mosquitto_loop_start() thread to exit if no broker was available on the first connection attempt. This has been fixed. Closes #3258. * Fix linker errors on some architectures using cmake. libmosquitto1-2.0.23-bp157.2.6.1.x86_64.rpm libmosquittopp1-2.0.23-bp157.2.6.1.x86_64.rpm mosquitto-2.0.23-bp157.2.6.1.src.rpm mosquitto-2.0.23-bp157.2.6.1.x86_64.rpm mosquitto-clients-2.0.23-bp157.2.6.1.x86_64.rpm mosquitto-devel-2.0.23-bp157.2.6.1.x86_64.rpm libmosquitto1-2.0.23-bp157.2.6.1.aarch64.rpm libmosquittopp1-2.0.23-bp157.2.6.1.aarch64.rpm mosquitto-2.0.23-bp157.2.6.1.aarch64.rpm mosquitto-clients-2.0.23-bp157.2.6.1.aarch64.rpm mosquitto-devel-2.0.23-bp157.2.6.1.aarch64.rpm libmosquitto1-2.0.23-bp157.2.6.1.ppc64le.rpm libmosquittopp1-2.0.23-bp157.2.6.1.ppc64le.rpm mosquitto-2.0.23-bp157.2.6.1.ppc64le.rpm mosquitto-clients-2.0.23-bp157.2.6.1.ppc64le.rpm mosquitto-devel-2.0.23-bp157.2.6.1.ppc64le.rpm libmosquitto1-2.0.23-bp157.2.6.1.s390x.rpm libmosquittopp1-2.0.23-bp157.2.6.1.s390x.rpm mosquitto-2.0.23-bp157.2.6.1.s390x.rpm mosquitto-clients-2.0.23-bp157.2.6.1.s390x.rpm mosquitto-devel-2.0.23-bp157.2.6.1.s390x.rpm openSUSE-2026-72 Security update for libaec moderate openSUSE Backports SLE-15-SP7 Update This update for libaec fixes the following issues: Libaec was updated to version 1.1.6 to fix a buffer overflow [bnc#1258965]. libaec-1.1.6-bp157.2.4.1.src.rpm libaec-debugsource-1.1.6-bp157.2.4.1.x86_64.rpm libaec-devel-1.1.6-bp157.2.4.1.x86_64.rpm libaec0-1.1.6-bp157.2.4.1.x86_64.rpm libaec0-debuginfo-1.1.6-bp157.2.4.1.x86_64.rpm libsz2-1.1.6-bp157.2.4.1.x86_64.rpm libsz2-debuginfo-1.1.6-bp157.2.4.1.x86_64.rpm sz2-devel-1.1.6-bp157.2.4.1.x86_64.rpm libaec-debugsource-1.1.6-bp157.2.4.1.i586.rpm libaec-devel-1.1.6-bp157.2.4.1.i586.rpm libaec0-1.1.6-bp157.2.4.1.i586.rpm libaec0-32bit-1.1.6-bp157.2.4.1.x86_64.rpm libaec0-32bit-debuginfo-1.1.6-bp157.2.4.1.x86_64.rpm libaec0-debuginfo-1.1.6-bp157.2.4.1.i586.rpm libsz2-1.1.6-bp157.2.4.1.i586.rpm libsz2-32bit-1.1.6-bp157.2.4.1.x86_64.rpm libsz2-32bit-debuginfo-1.1.6-bp157.2.4.1.x86_64.rpm libsz2-debuginfo-1.1.6-bp157.2.4.1.i586.rpm sz2-devel-1.1.6-bp157.2.4.1.i586.rpm libaec-debugsource-1.1.6-bp157.2.4.1.aarch64.rpm libaec-devel-1.1.6-bp157.2.4.1.aarch64.rpm libaec0-1.1.6-bp157.2.4.1.aarch64.rpm libaec0-64bit-1.1.6-bp157.2.4.1.aarch64_ilp32.rpm libaec0-64bit-debuginfo-1.1.6-bp157.2.4.1.aarch64_ilp32.rpm libaec0-debuginfo-1.1.6-bp157.2.4.1.aarch64.rpm libsz2-1.1.6-bp157.2.4.1.aarch64.rpm libsz2-64bit-1.1.6-bp157.2.4.1.aarch64_ilp32.rpm libsz2-64bit-debuginfo-1.1.6-bp157.2.4.1.aarch64_ilp32.rpm libsz2-debuginfo-1.1.6-bp157.2.4.1.aarch64.rpm sz2-devel-1.1.6-bp157.2.4.1.aarch64.rpm libaec-debugsource-1.1.6-bp157.2.4.1.ppc64le.rpm libaec-devel-1.1.6-bp157.2.4.1.ppc64le.rpm libaec0-1.1.6-bp157.2.4.1.ppc64le.rpm libaec0-debuginfo-1.1.6-bp157.2.4.1.ppc64le.rpm libsz2-1.1.6-bp157.2.4.1.ppc64le.rpm libsz2-debuginfo-1.1.6-bp157.2.4.1.ppc64le.rpm sz2-devel-1.1.6-bp157.2.4.1.ppc64le.rpm libaec-debugsource-1.1.6-bp157.2.4.1.s390x.rpm libaec-devel-1.1.6-bp157.2.4.1.s390x.rpm libaec0-1.1.6-bp157.2.4.1.s390x.rpm libaec0-debuginfo-1.1.6-bp157.2.4.1.s390x.rpm libsz2-1.1.6-bp157.2.4.1.s390x.rpm libsz2-debuginfo-1.1.6-bp157.2.4.1.s390x.rpm sz2-devel-1.1.6-bp157.2.4.1.s390x.rpm openSUSE-2026-74 Security update for gitea-tea moderate openSUSE Backports SLE-15-SP7 Update This update for gitea-tea fixes the following issues: - update to 0.12.0: * New Features - Add tea actions commands for managing workflow runs and workflows in #880, #796 - Add tea api subcommand for arbitrary API calls not covered by existing commands in #879 - Add repository webhook management commands in #798 - Add JSON output support for single PR view in #864 - Add JSON output and file redirection for issue detail view in #841 - Support creating AGit flow pull requests in #867 * Bug Fixes - Fix authentication via environment variables when specifying repo argument in #809 - Fix issue detail view ignoring --owner flag in #899 - Fix PR create crash in #823 - Fix TTY prompt handling in #897 - Fix termenv OSC RGBA handling in #907 - Fix labels delete command and --id flag type in #865 - Fix delete repo command description in #858 - Fix pagination flags for secrets list, webhooks list, and pull requests list in #853, #852, - #851 - Enable git worktree support and improve PR create error handling in #850 - Only prompt for SSH passphrase when necessary in #844 - Only prompt for login confirmation when no default login is set in #839 - Skip token uniqueness check when using SSH authentication in #898 - Require non-empty token in GetLoginByToken in #895 - Fix config file permissions to remove group read/write in #856 * Improvements - Add file locking for safe concurrent access to config file in #881 - Improve error messages throughout the CLI in #871 - Send consistent HTTP request headers in #888 - Revert requiring HTTP/HTTPS login URLs; restore SSH as a login method in #891 - Refactor context into dedicated subpackages in #873, #888 - General code cleanup and improvements in #869, #870 - Add test coverage for login matching in #820 * Build & Dependencies - Build with Go 1.25 in #886 - Build for Windows aarch64 - Update Gitea SDK version in #868 - Update Nix flake in #872 - Update dependencies including lipgloss v2, urfave/cli v3.6.2, go-git v5.16.5, and various Go modules in #849, #875, #876, #878, #884, #885, #900, #901, #904, #905 - Update CI actions (checkout v6, setup-go v6) in #882, #883 gitea-tea-0.12.0-bp157.2.15.1.src.rpm gitea-tea-0.12.0-bp157.2.15.1.x86_64.rpm gitea-tea-bash-completion-0.12.0-bp157.2.15.1.noarch.rpm gitea-tea-zsh-completion-0.12.0-bp157.2.15.1.noarch.rpm gitea-tea-0.12.0-bp157.2.15.1.i586.rpm gitea-tea-0.12.0-bp157.2.15.1.aarch64.rpm gitea-tea-0.12.0-bp157.2.15.1.ppc64le.rpm gitea-tea-0.12.0-bp157.2.15.1.s390x.rpm openSUSE-2026-76 Recommended update for kanidm moderate openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: - Update to version 1.9.1~git0.36055feca: * Release 1.9.1 * 20260220 prevent migration accidents (#4156) * Alert on unsaved changes (#4155) * Warn about systemd-userdb (#4147) * Dont be as upset when migration dir doesnt exist (#4146) - Update to version 1.9.0~git0.2df2bfc4a: * Release 1.9.0 * Allow LDAP CA verification to be disabled in sync (#4133) * Add oauth2 example, fix inter-migration reference handling (#4136) * Corrected recycle_bin.md typo (#4135) * Set docker tag properly * Release "1.9.0-pre"-pre * chore: Release Notes (#4129) * Update to use hjson (#4128) * Python OpenAPI-based internals (#4119) * Allow reseting (aka clearing) softlocks (#4111) * 20260122 SCIM batch (#4088) * Improve upgrade/downgrade testing and checks (#4125) * Adding scripts for testing nginx and proxyv1 ldap, updating haproxy-protocol (#4087) * Allow extra characters in claim names (#4110) * Add ability to backup via stdout (#4114) * Remove mozilla webauthn authenticator backend (#4118) * 20260205 truncate service acct tokens (#4113) * clarify ssh_publickeys oidc claim (#4116) * Add note about building client tools locked (#4117) * add RFC8693 to features section of the book (#4112) * FIX: make tracing-forest stop panic'ing things when enabling otel (#4105) * Bump bytes from 1.11.0 to 1.11.1 (#4107) * Tweaking rm_if_exist to remove a race condition (#4103) * Set `sudo_provider = none` in sssd.conf; Update default value for LDAP_MAXIMUM_QUERYABLE_ATTRIBUTES (#4098) * Improve secure origin handling in OAuth2 (#4097) * Radius support for SAN-DN (#4094) * Bump the all group with 10 updates (#4093) * Allow UUID when Name also allowed (#4089) * Disallow methods that should not be used (#4083) * Prevent panic (#4082) * 20260116 kanidmd json mode (#4075) * Return http409 on AttrUniqueness error (#4079) * Hardening against process errors (#4061) * 20260108 sync polish (#4054) * Allow overriding css (#4077) * Bump the all group with 8 updates (#4078) * Support homeDirectory virtual attribute (#4073) * Bump the uv group across 2 directories with 3 updates (#4074) * Allow invalid passwords to be skipped (#4071) * shrinking logo.svg and re-brotli-ing others (#4069) * fallback for target_os dependency management in kanidm_tools webauthn-authenticator-rs (#4067) * allows service desk to change account validity (#4068) * kanidm-ipa-sync aws-lc-rs crypto provider fix (#4065) * 20260107 unixd documentation (#4046) * Bump the all group with 12 updates (#4059) * Bump lru from 0.16.2 to 0.16.3 (#4047) * Prevent server crashing on requests with low log level (#4039) * Correct rw flag in service account documentation (#4042) * Bump rsa from 0.9.9 to 0.9.10 (#4041) * Implement OIDC auth for service-accounts (RFC8963) (#4021) * 20251219 Uint64/Int64 syntax types (#4022) * Bump the all group across 1 directory with 16 updates (#4036) * update askama, askama_web to v0.15 (#4030) * Bump the all group with 11 updates (#4024) * Bump yescrypt from 0.1.0-rc.0 to 0.1.0-rc.1 in the all group (#4017) * Bump the all group with 2 updates (#4016) * OAuth2 CSP form-action (#4011) * Handle concurrent pam sessions. (#4001) * Bump the all group with 5 updates (#4005) * fix: correcting parsing of backup compression input (#3995) * Add a home strategy framework (#3985) * Bump the all group with 8 updates (#3996) * Resolve infinite reauth loop (#3992) * Ignore CredentialTypeMinimum during migrations (#3991) * Allow disabling OAuth2 consent prompt (#3972) * Report correct client IP in request log (#3990) * Ensure that privileged sessions expirations are synced (#3984) * Add reference to the Kanidm anthem (#3987) * Missing constraint on skip upgrade process (#3983) * Changing how we parse environment variables in kanidmd (#3977) * Document the upgrade process through versions. (#3982) * Bump actions/checkout from 5 to 6 in the all group (#3979) * Bump the all group with 8 updates (#3980) * lib crypto should not depend on proto (#3975) * Change AttributeUniqueness to yield BAD_REQUEST (#3974) * fix: kanidm_build_profiles has unwrap which can cause builds to fail (#3973) * Small fixes (#3965) * Make log messages more verbose for issues with resources server (#3954) * unixd_tasks: update home alias symlink conditionally and atomically (#3947) * Manually handle form bytes to allow optional encoding (#3968) * Improve handling of ready event (#3967) * Fix typo in kanidm-ldap-sync (#3964) * Bump the all group with 10 updates (#3963) * Bump js-yaml (#3957) * Bump the all group with 3 updates (#3948) * 20251108 lld (#3944) * Improve uid/gid overlap message during IAM migration (#3943) * 1.9.0-dev (#3939) - Enable python bindings for the primary python version on newer distributions and 3.11 on 15.x - Update to version 1.8.6~git0.268c71d0a: * Release 1.8.6 * Release 1.8.5 * OAuth2 CSP form-action (#4011) * Force webauthn 0.5.4 kanidm-1.9.1~git0.36055feca-bp157.2.29.1.src.rpm kanidm-1.9.1~git0.36055feca-bp157.2.29.1.x86_64.rpm kanidm-clients-1.9.1~git0.36055feca-bp157.2.29.1.x86_64.rpm kanidm-docs-1.9.1~git0.36055feca-bp157.2.29.1.x86_64.rpm kanidm-server-1.9.1~git0.36055feca-bp157.2.29.1.x86_64.rpm kanidm-unixd-clients-1.9.1~git0.36055feca-bp157.2.29.1.x86_64.rpm kanidm-1.9.1~git0.36055feca-bp157.2.29.1.aarch64.rpm kanidm-clients-1.9.1~git0.36055feca-bp157.2.29.1.aarch64.rpm kanidm-docs-1.9.1~git0.36055feca-bp157.2.29.1.aarch64.rpm kanidm-server-1.9.1~git0.36055feca-bp157.2.29.1.aarch64.rpm kanidm-unixd-clients-1.9.1~git0.36055feca-bp157.2.29.1.aarch64.rpm openSUSE-2026-69 Security update for python-nltk important openSUSE Backports SLE-15-SP7 Update This update for python-nltk fixes the following issues: - CVE-2026-0847: Fixed an issue where improper sanitization of file paths could lead to path traversal (boo#1259232) python-nltk-3.7-bp157.3.6.1.src.rpm python3-nltk-3.7-bp157.3.6.1.noarch.rpm openSUSE-2026-70 Security update for roundcubemail important openSUSE Backports SLE-15-SP7 Update This update for roundcubemail fixes the following issues: - update to 1.6.13 This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: + Fix CSS injection vulnerability reported by CERT Polska (boo#1258052, CVE-2026-26079). + Fix remote image blocking bypass via SVG content reported by nullcathedral (boo#1257909, CVE-2026-25916). This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating! CHANGELOG + Managesieve: Fix handling of string-list format values for date tests in Out of Office (#10075) + Fix CSS injection vulnerability reported by CERT Polska. + Fix remote image blocking bypass via SVG content reported by nullcathedral. - update to 1.6.12 This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: + Fix Cross-Site-Scripting vulnerability via SVG's animate tag reported by Valentin T., CrowdStrike (boo#1255308, CVE-2025-68461). + Fix Information Disclosure vulnerability in the HTML style sanitizer reported by somerandomdev (boo#1255306, CVE-2025-68460). This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. + Support IPv6 in database DSN (#9937) + Don't force specific error_reporting setting + Fix compatibility with PHP 8.5 regarding array_first() + Remove X-XSS-Protection example from .htaccess file (#9875) + Fix "Assign to group" action state after creation of a first group (#9889) + Fix bug where contacts search would fail if contactlist_fields contained vcard fields (#9850) + Fix bug where an mbox export file could include inconsistent message delimiters (#9879) + Fix parsing of inline styles that aren't well-formatted (#9948) + Fix Cross-Site-Scripting vulnerability via SVG's animate tag + Fix Information Disclosure vulnerability in the HTML style sanitizer roundcubemail-1.6.13-bp157.2.6.1.noarch.rpm roundcubemail-1.6.13-bp157.2.6.1.src.rpm openSUSE-2026-78 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 145.0.7632.159 (boo#1259213) * CVE-2026-3536: Integer overflow in ANGLE * CVE-2026-3537: Object lifecycle issue in PowerVR * CVE-2026-3538: Integer overflow in Skia * CVE-2026-3539: Object lifecycle issue in DevTools * CVE-2026-3540: Inappropriate implementation in WebAudio * CVE-2026-3541: Inappropriate implementation in CSS * CVE-2026-3542: Inappropriate implementation in WebAssembly * CVE-2026-3543: Inappropriate implementation in V8 * CVE-2026-3544: Heap buffer overflow in WebCodecs * CVE-2026-3545: Insufficient data validation in Navigation chromedriver-145.0.7632.159-bp157.2.130.1.x86_64.rpm chromium-145.0.7632.159-bp157.2.130.1.nosrc.rpm chromium-145.0.7632.159-bp157.2.130.1.x86_64.rpm chromedriver-145.0.7632.159-bp157.2.130.1.aarch64.rpm chromium-145.0.7632.159-bp157.2.130.1.aarch64.rpm chromedriver-145.0.7632.159-bp157.2.130.1.ppc64le.rpm chromium-145.0.7632.159-bp157.2.130.1.ppc64le.rpm openSUSE-2026-80 Security update for coredns important openSUSE Backports SLE-15-SP7 Update This update for coredns fixes the following issues: Update to version 1.14.2: - CVE-2026-26017: Fixed DNS access control bypass due to default execution order of plugins and TOCTOU flaw (bsc#1259320). - CVE-2026-26018: Fixed denial of service in the loop detection plugin due to predictable PRNG combined with fatal error handler (bsc#1259319). - CVE-2025-68156: Fixed uncontrolled recursion in expression evaluation can cause a denial of service (bsc#1255345). coredns-1.14.2-bp157.2.13.1.src.rpm coredns-1.14.2-bp157.2.13.1.x86_64.rpm coredns-extras-1.14.2-bp157.2.13.1.noarch.rpm coredns-1.14.2-bp157.2.13.1.aarch64.rpm coredns-1.14.2-bp157.2.13.1.ppc64le.rpm openSUSE-2026-92 Recommended update for keepassxc moderate openSUSE Backports SLE-15-SP7 Update This update for keepassxc fixes the following issues: - update to 2.7.12: - changes - Passkeys: Set BE and BS flags to true (NOTE: MAY BREAK EXISTING PASSKEYS) [#13042] - Support TIMEOTP autotype and entry placeholder [#13117] - Browser: Show URLs in browser access dialog [#12906] - Bitwarden Import: Add support for nested folders [#13081] - Fixes - Prevent exploits through OpenSSL configurations [#13118, #13124] - Auto-Type: Revert change that caused race condition on Linux [#12738] - Auto-Type: Fix help button enablement [#12937] - Browser: Fix showing correct checkbox value in entry Browser Integration settings [#12980] - Browser: Fix setting browser related values to customData [#13026] - Passkeys: Add publicKey to register response [#12757] - Fix main entry URL validation when using placeholders [#12964] - Fix minor font and theme issues [#12814] - Fix 'Remove' button in Plugin Data being enabled when no row is selected [#12916] - Sanitize attachment file names before saving [#13114] - update to 2.7.11: - Changes - Add image, HTML, Markdown preview, and text editing support to inline attachment viewer [#12085, #12244, #12654] - Add database merge confirmation dialog [#10173] - Add option to auto-generate a password for new entries [#12593] - Add support for group sync in KeeShare [#11593] - Add {UUID} placeholder for use in references [#12511] - Add 'Wait for Enter' search option [#12263] - Add keyboard shortcut to 'Jump to Group' from search results [#12225] - Add predefined search for TOTP entries [#12199] - Add confirmation when closing database via ESC key [#11963] - Add support for escaping placeholder expressions [#11904] - Reduce tab indentation width in notes fields [#11919] - Cap default Argon2 parallelism when creating a new database [#11853] - Database lock after inactivity now enabled by default and set to 900 seconds [#12689, #12609] - Copying TOTP now opens setup dialog if none is configured for entry [#12584] - Make double click action configurable [#12322] - Remove unused 'Last Accessed' from GUI [#12602] - Auto-Type: Add more granular confirmation settings [#12370] - Auto-Type: Add URL typing preset and add copy options to menu [#12341] - Browser: Do not allow sites automatically if entry added from browser extension [#12413] - Browser: Add options to restrict exposed groups [#9852, #12119] - Bitwarden Import: Add support for timestamps and password history [#12588] - macOS: Add Liquid Glass icon [#12642] - macOS: Remove theme-based menubar icon toggle [#12685] - macOS: Add Window and Help menus [#12357] - Windows: Add option to add KeePassXC to PATH during installation [#12171] - Fixes - Fix window geometry not being restored properly when KeePassXC starts in tray [#12683] - Fix potential database truncation when using direct write save method with YubiKeys [#11841] - Fix issue with database backup saving [#11874] - Fix UI lockups during startup with multiple tabs [#12053] - Fix keyboard shortcuts when menubar is hidden [#12431] - Fix clipboard being cleared on exit even if no password was copied [#12603] - Fix single-instance detection when username contains invalid filename characters [#12559] - Fix 'Search Wait for Enter' setting not being save [#12614] - Fix hotkey accelerators not being escaped properly on database tabs [#12630] - Fix confusing error if user cancels out of key file edit dialog [#12639] - Fix issues with saved searches and 'Press Enter to Search' option [#12314] - Fix URL wildcard matching [#12257] - Fix TOTP visibility on unlock and settings change [#12220] - Fix KeeShare entries with reference attributes not updating [#11809] - Fix sort order not being maintained when toggling filters in database reports [#11849] - Fix several UI font and layout issues [#11967, #12102] - Prevent mouse wheel scroll on edit username field [#12398] - Improve base translation consistency [#12432] - Improve inactivity timer [#12246] - Documentation improvements [#12373, #12506] - Browser: Fix ordering of clientDataJSON in Passkey response object [#12120] - Browser: Fix URL matching for additional URLs [#12196] - Browser: Fix group settings inheritance [#12368] - Browser: Allow read-only native messaging config files [#12236] - Browser: Optimise entry iteration in browser access control dialog [#11817] - Browser: Fix 'Do not ask permission for HTTP Basic Auth' option [#11871] - Browser: Fix native messaging path for Tor Browser launcher on Linux [#12005] - Auto-Type: Fix empty window behaviour [#12622] - Auto-Type: Take delays into account when typing TOTP [#12691] - SSH Agent: Fix out-of-memory crash with malformed SSH keys [#12606] - CSV Import: Fix modified and creation time import [#12379] - CSV Import: Fix duplication of root groups on import [#12240] - Proton Pass Import: Fix email addresses not being imported when no username set [#11888] - macOS: Fix secure input getting stuck [#11928] - Windows: Prevent launch as SYSTEM user from MSI installer [#12705] - Windows: Remove broken check for MSVC Redistributable from MSI installer [#11950] - Linux: Fix startup delay due to StartupNotify setting in desktop file [#12306] - Linux: Fix memory initialisation when --pw-stdin is used with a pipe [#12050] keepassxc-2.7.12-bp157.2.3.1.src.rpm keepassxc-2.7.12-bp157.2.3.1.x86_64.rpm keepassxc-debuginfo-2.7.12-bp157.2.3.1.x86_64.rpm keepassxc-debugsource-2.7.12-bp157.2.3.1.x86_64.rpm keepassxc-lang-2.7.12-bp157.2.3.1.noarch.rpm keepassxc-2.7.12-bp157.2.3.1.aarch64.rpm keepassxc-debuginfo-2.7.12-bp157.2.3.1.aarch64.rpm keepassxc-debugsource-2.7.12-bp157.2.3.1.aarch64.rpm keepassxc-2.7.12-bp157.2.3.1.ppc64le.rpm keepassxc-debuginfo-2.7.12-bp157.2.3.1.ppc64le.rpm keepassxc-debugsource-2.7.12-bp157.2.3.1.ppc64le.rpm keepassxc-2.7.12-bp157.2.3.1.s390x.rpm keepassxc-debuginfo-2.7.12-bp157.2.3.1.s390x.rpm keepassxc-debugsource-2.7.12-bp157.2.3.1.s390x.rpm openSUSE-2026-83 Recommended update for gh moderate openSUSE Backports SLE-15-SP7 Update This update for gh fixes the following issues: - Update to version 2.88.0: * fix: add if guard to no-response job to prevent running on workflow_dispatch * Add pitch surfacing workflow (monthly + manual dispatch) * fix: address review feedback on squash merge commit message * fix: gofmt alignment in test struct literals * feat(repo): add --squash-merge-commit-message flag to gh repo edit * chore(deps): bump golang.org/x/sync from 0.19.0 to 0.20.0 * refactor: change extractFileName param from []byte to string * Update Go version requirement to 1.26+ * Bump golangci-lint from v2.6.0 to v2.11.0 for Go 1.26 support * Bump Go from 1.25.7 to 1.26.1 to fix stdlib vulnerabilities * Address review comments: use actorDisplayName for Copilot author display * Show friendly display names in gh issue view * Add generic actorDisplayName for all actor display names * Show friendly Copilot (AI) name in gh pr view * fix: align example indentation with codebase convention * fix: address review feedback for --exclude flag * fix: share diffHeaderRegexp between changedFilesNames and extractFileName, fix gofmt * feat(pr diff): add --exclude flag to filter files from diff output * Fetch org teams via repository.owner inline fragment * chore(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.2 * Exclude PR author from reviewer candidates in SuggestedReviewerActors * Fix duplicate reviewers in gh pr edit by passing logins as defaults * Exclude current user from suggested reviewers in gh pr create * Replace @copilot with Copilot reviewer login in gh pr create * Add TODO requestReviewsByLoginCleanup on GHES ID-based reviewer path * Remove /slug team reviewer shorthand normalization * Add TODO requestReviewsByLoginCleanup on static reviewer MultiSelect * Check state.ActorReviewers in MetadataSurvey reviewer search gate * Label Copilot detection in SuggestedReviewerActorsForRepo as a hack * Add TODO requestReviewsByLoginCleanup in CreatePullRequest * refactor: deduplicate scope error handling between api/client.go and project queries * Fix extension install error message showing raw struct instead of owner/repo (#12836) * chore(deps): bump github.com/docker/cli * Remove StateReason feature detection for issue close * Remove unnecessary StateReasonDuplicate feature detection * docs: add examples to gh issue close help text (#12830) * Fix incorrect integer conversion from int to uint16 in port forwarder (#12831) * Combine issue feature detection into a single GraphQL query * feat(browse): add blame flag * Reword `--no-upstream` help doc * test(issue list): cover additional PR search qualifier variants * fix(issue list): reject pull request-only search qualifiers * chore(deps): bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0 * chore(deps): bump github.com/gabriel-vasile/mimetype * chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.1 * chore(deps): bump actions/attest-build-provenance from 3.2.0 to 4.1.0 * chore(deps): bump actions/download-artifact from 7 to 8 * chore(deps): bump actions/upload-artifact from 6 to 7 * Set COPILOT_GH env var when launching Copilot CLI * Simplify progress indicators in issue develop * Emit null for zero createdAt/updatedAt values * Address Copilot review feedback * Polish --json support for agent-task view * Polish --json support for agent-task list * Fix gofmt alignment in view_test.go * feat(pr): add changeType field to files JSON output * Add --duplicate-of flag and duplicate reason to gh issue close * Add --json support to `gh agent-task view` * Add --json support to `gh agent-task list` * fix(project/item-edit): preserve title/body when editing draft issue with partial flags * Add databaseId to assignees GraphQL fragment * fix(licenses): implement VCS-friendly embedding * chore(gitignore): ignore generated license files * Use pre-compiled regexp for matching Content-Type * chore(script/licenses): fix indentation * fix(script/licenses): generate licenses in separate dirs * Fix invalid ANSI SGR escape code in JSON and diff colorization * Add --no-upstream flag to gh repo clone * Clarify ReviewerCandidate relationship to AssignableActor * Move PR review queries from queries_pr.go to queries_pr_review.go * Use org/slug format in test fixtures and remove /slug normalization * Normalize /slug team shorthand to org/slug and fix docs * Include bot logins in login-based reviewer mutation guard * Skip reviewer metadata fetch when using search-based selection * Update test assertions to expect org/slug team format * Wire bot reviewer logins through CreatePullRequest * Partition bot reviewers separately for RequestReviewsByLogin * Preserve org/slug format for team reviewer slugs * Apply suggestion from @BagToad * Remove redundant comment * Don't swallow error from FD * Remove redundant comments * Fix issue develop repeated invocation with named branches * Fix redundant API call in gh issue view --comments (#12606) * Add toGitHubV4Strings helper to reduce code duplication * Address PR review comments * gh pr create: CCR and multiselectwithsearch * trigger rerun * test: TestGenerateScopeErrorForGQL and TestRequiredScopesFromServerMessage * fix: clarify scope error while creating issues for projects * fix: error when --remote flag used with repo argument * build: customizable install `prefix` - Update to version 2.87.3: * Fix project mutation query variable usage - Update to version 2.87.2: * chore(deps): bump golang.org/x/crypto from 0.47.0 to 0.48.0 * fix(agent-task/capi): fix capi API version * Remove debris licenses - Update to version 2.87.0: * Bundle licenses at release time (#12625) * Rename query for clarity * Remove pointer comments * Simplify error message * Remove DTO concept * Add `--query` flag to `project item-list` (#12696) * Clarify --clobber flag deletes assets before re-uploading * Add usage examples to gh gist edit command * Remove feedback issue template * Migrate PR triage workflows to shared workflows * Rename triage workflow to triage-discussion-label * Pass environment as input to shared triage workflow * Add missing environment and label check to triage workflow * Initial plan * fix(workflow run): bail out on feature detection error * refactor(featuredetection): remove temp in favour of early returns * docs(workflow run): improve help docs * docs(workflow run): add cleanup marker with explanation on future changes * fix(workflow run): apply `url.PathEscape` when compiling URL * refactor(workflow run): remove temp `out` * Add missing TODO comments for featuredetection if-statements * docs(featuredetection): fix typo in comment * test(featuredetection): fix test case name * test(workflow run): verify retrieval of workflow run details * feat(workflow run): retrieve workflow run if supported by the API * test(featuredetection): add tests for `ActionsFeatures` * fix(featuredetection): add `ActionsFeatures` to detect workflow dispatch features * pin REST API version to 2022-11-28 * Migrate stale workflow to shared workflow * Respect --exit-status with --log and --log-failed * document fork default branch behavior * Migrate issue triage workflows to shared workflows * fork default branch only in pr create * update third party licenses * chore(deps): bump golang.org/x/crypto from 0.46.0 to 0.47.0 * Add manual dispatch to bump-go workflow * bump go to 1.25.7 * update third party licenses * chore(deps): bump golang.org/x/term from 0.38.0 to 0.39.0 * update third party licenses * chore(deps): bump golang.org/x/text from 0.32.0 to 0.33.0 * Add toGitHubV4Strings helper to reduce code duplication * Address PR review comments * update third party licenses * chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.4 to 2.13.7 * Update third party licenses * chore(deps): bump github.com/theupdateframework/go-tuf/v2 * Update third-party licenses * Clarify comment on reviewer API behavior * Clarify assignee/reviewer fetching behavior * Clarify EditableReviewers comment * Clarify Copilot assignee comment * Use unfiltered totalCount for reviewer 'more results' display * Include name in reviewer display for existing review requests * update Go 1.25.6 * Implement cascading quota for reviewer suggestions * fix(pr edit): send empty slices to clear reviewers in replace mode * Fix return proper slug only for ReviewerTeam * Remove redundant comment * chore: update licenses * chore: bump `cli/oauth` to `v1.2.2` * Add CCR and reviewer MultiSelectWithSearch * chore(deps): bump actions/attest-build-provenance from 3.1.0 to 3.2.0 * Remove outdated comment in SuggestedAssignableActors * Apply suggestions from code review * Remove outdated TODO comments in survey.go * Remove redundant comment in editRun test * Return total assignee count in SuggestedAssignableActors * Add test for MultiSelectWithSearch error propagation * Add test for legacy assignee flow on GHES * Remove unused Viewer struct from SuggestedAssignableActors * Add comments to assigneeSearchFunc for clarity * Simplify variables map in SuggestedAssignableActors * Simplify suggested assignable actors * Fix linter and mock prompter signature * Apply suggestions from code review * Apply suggestions from code review * Clarify TODO comment for reviewer search function * Only support assignee searchfunc on GitHub.com * Update edit tests * Refactor MultiSelectWithSearch to use result struct * Add comment describing logger * Pass editable to assigneeSearchFunc and update metadata * Add dynamic assignee search to PR edit flow * MultiSelectWithSearch initial implementation * prshared: named prompt interface parameters * typo: dont to don't * chore(deps): bump goreleaser/goreleaser-action from 6.0.0 to 6.4.0 * chore: update licenses * chore(deps): bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 * chore(deps): bump github.com/theupdateframework/go-tuf/v2 * chore: update licenses * chore(deps): bump github.com/sigstore/sigstore from 1.10.0 to 1.10.4 * docs: lint source.md * fix(pr/shared): improve `ParseFullReference` error message * Fix fmt.Errorf format argument in ParseFullReference * chore(deps): bump actions/upload-artifact from 5 to 6 * chore(deps): bump actions/download-artifact from 6 to 7 - Update to version 2.86.0: * refactor: address review comments * Update contributing guidelines for clarity * test(copilot): fix windows asset URL * fix(cache delete): add unit tests and expand help doc * feat(cache delete): allow for delete all caches for a ref * Fix OS name in test archive filename to 'win32' * fix(copilot): replace `windows` with `win32` to match asset names * fix(root): avoid command name collision when registering extensions * chore(root): register `copilot` command * feat: add `copilot` command * refactor(run download): extract zip extraction func into a separate package * fix: error when head and base refs are identical in pr create - Update to version 2.85.0: * fix: simplify set-default remote parsing * Handle repo argument before remote name * chore: update licenses * chore(deps): bump github.com/yuin/goldmark from 1.7.13 to 1.7.16 * chore: update licenses using `go-licenses@v2` * chore: install `go-licenses@v2` in scripts * Update go-licenses for 1.25 * chore: update licenses * chore: bump `github.com/sigstore/sigstore-go` to `v1.1.4` * chore: remove redundant comment * ci: enable noop linters * Add shell specification for temporary tag creation * ci: shorten `run` block * ci: improve step name * ci: tag per build job * Update Azure Code Signing endpoint URL * Update Azure Code Signing client to 1.0.95 * Update actions/checkout to v6 in extension workflow templates * feat: allow git remote names in gh repo set-default * Add test to ensure null values are skipped * ci: disable create storage record for artifacts * chore(deps): bump actions/attest-build-provenance from 3.0.0 to 3.1.0 * chore: run `go mod tidy` * chore: update licenses * chore: upgrade `github.com/cli/oauth` to `v1.2.1` * fix: prevent panic when processing null project items * ci: fix binary artficat dirs used in macos job * ci: fix binary artifact dir paths used in Windows job * ci: upgrade to GoReleaser v2 CLI syntax for `--skip` * ci: limit deb/rpm packages to `linux` build * ci: replace `archives.format` with `archives.formats` array * ci: remove redundant `archives.rlcp` * ci: replace `archives.builds` with `archives.ids` * ci: quote 386 arch * ci: upgrade `.goreleaser.yml` to v2 * ci: upgrade to GoReleaser v2 * chore: update licenses * chore(deps): bump golang.org/x/crypto from 0.45.0 to 0.46.0 * chore: update licenses * chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.2 to 2.13.4 * chore(deps): bump golangci/golangci-lint-action from 9.1.0 to 9.2.0 * chore: update licenses * chore: update licenses * chore(deps): bump github.com/spf13/cobra from 1.10.1 to 1.10.2 * chore: update licenses * chore(deps): bump golang.org/x/term from 0.37.0 to 0.38.0 * chore: update licenses * chore(deps): bump golang.org/x/text from 0.31.0 to 0.32.0 * chore: update licenses * chore(deps): bump golang.org/x/sync from 0.18.0 to 0.19.0 * Fix Debian CLI package link in installation guide * Add tests of browse --actions * Add gh browse --actions flag * chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.1 to 2.13.2 gh-2.88.0-bp157.2.18.1.src.rpm gh-2.88.0-bp157.2.18.1.x86_64.rpm gh-bash-completion-2.88.0-bp157.2.18.1.noarch.rpm gh-fish-completion-2.88.0-bp157.2.18.1.noarch.rpm gh-zsh-completion-2.88.0-bp157.2.18.1.noarch.rpm gh-2.88.0-bp157.2.18.1.i586.rpm gh-2.88.0-bp157.2.18.1.aarch64.rpm gh-2.88.0-bp157.2.18.1.ppc64le.rpm gh-2.88.0-bp157.2.18.1.s390x.rpm openSUSE-2026-90 Recommended update for ansible-sap-launchpad moderate openSUSE Backports SLE-15-SP7 Update This update for ansible-sap-launchpad fixes the following issues: Refactor Ansible Modules and adjust for ansible-core 2.19. - 1.3.1 - Bugfixes: - collection: Add ansible-test sanity workflow and fix sanity errors - 1.3.0 - Changes: - collection: Refactor all Ansible Modules - sap_software_download: Update for ansible-core 2.19 - Bugfixes: - sap_software_download: Fix for failed checksums not correctly retrying ansible-sap-launchpad-1.3.1-bp157.2.6.1.noarch.rpm ansible-sap-launchpad-1.3.1-bp157.2.6.1.src.rpm openSUSE-2026-85 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 146.0.7680.80: * CVE-2026-3909: Out of bounds write in Skia (boo#1259659) - Chromium 146.0.7680.75: * CVE-2026-3910: Inappropriate implementation in V8 (boo#1259648) - Chromium 146.0.7680.71 (released 2026-03-11) (boo#1259530) * CVE-2026-3913: Heap buffer overflow in WebML * CVE-2026-3914: Integer overflow in WebML * CVE-2026-3915: Heap buffer overflow in WebML * CVE-2026-3916: Out of bounds read in Web Speech * CVE-2026-3917: Use after free in Agents * CVE-2026-3918: Use after free in WebMCP * CVE-2026-3919: Use after free in Extensions * CVE-2026-3920: Out of bounds memory access in WebML * CVE-2026-3921: Use after free in TextEncoding * CVE-2026-3922: Use after free in MediaStream * CVE-2026-3923: Use after free in WebMIDI * CVE-2026-3924: Use after free in WindowDialog * CVE-2026-3925: Incorrect security UI in LookalikeChecks * CVE-2026-3926: Out of bounds read in V8 * CVE-2026-3927: Incorrect security UI in PictureInPicture * CVE-2026-3928: Insufficient policy enforcement in Extensions * CVE-2026-3929: Side-channel information leakage in ResourceTiming * CVE-2026-3930: Unsafe navigation in Navigation * CVE-2026-3931: Heap buffer overflow in Skia * CVE-2026-3932: Insufficient policy enforcement in PDF * CVE-2026-3934: Insufficient policy enforcement in ChromeDriver * CVE-2026-3935: Incorrect security UI in WebAppInstalls * CVE-2026-3936: Use after free in WebView * CVE-2026-3937: Incorrect security UI in Downloads * CVE-2026-3938: Insufficient policy enforcement in Clipboard * CVE-2026-3939: Insufficient policy enforcement in PDF * CVE-2026-3940: Insufficient policy enforcement in DevTools * CVE-2026-3941: Insufficient policy enforcement in DevTools * CVE-2026-3942: Incorrect security UI in PictureInPicture chromedriver-146.0.7680.80-bp157.2.133.1.x86_64.rpm chromium-146.0.7680.80-bp157.2.133.1.nosrc.rpm chromium-146.0.7680.80-bp157.2.133.1.x86_64.rpm chromedriver-146.0.7680.80-bp157.2.133.1.aarch64.rpm chromium-146.0.7680.80-bp157.2.133.1.aarch64.rpm chromedriver-146.0.7680.80-bp157.2.133.1.ppc64le.rpm chromium-146.0.7680.80-bp157.2.133.1.ppc64le.rpm openSUSE-2026-87 Security update for python-simpleeval important openSUSE Backports SLE-15-SP7 Update This update for python-simpleeval fixes the following issues: - CVE-2026-32640: Objects (including modules) can leak dangerous modules through to direct access inside the sandbox (boo#1259685) python-simpleeval-0.9.13-bp157.2.3.1.src.rpm python311-simpleeval-0.9.13-bp157.2.3.1.noarch.rpm openSUSE-2026-88 Security update for krb5-appl critical openSUSE Backports SLE-15-SP7 Update This update for krb5-appl fixes the following issues: - CVE-2026-32746: Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd LINEMODE (boo#1259691) krb5-appl-1.0.3-bp157.2.3.1.src.rpm krb5-appl-clients-1.0.3-bp157.2.3.1.x86_64.rpm krb5-appl-servers-1.0.3-bp157.2.3.1.x86_64.rpm krb5-appl-clients-1.0.3-bp157.2.3.1.i586.rpm krb5-appl-servers-1.0.3-bp157.2.3.1.i586.rpm krb5-appl-clients-1.0.3-bp157.2.3.1.aarch64.rpm krb5-appl-servers-1.0.3-bp157.2.3.1.aarch64.rpm krb5-appl-clients-1.0.3-bp157.2.3.1.ppc64le.rpm krb5-appl-servers-1.0.3-bp157.2.3.1.ppc64le.rpm krb5-appl-clients-1.0.3-bp157.2.3.1.s390x.rpm krb5-appl-servers-1.0.3-bp157.2.3.1.s390x.rpm openSUSE-2026-106 Security update for libjxl moderate openSUSE Backports SLE-15-SP7 Update This update for libjxl fixes the following issues: - Update to release 0.8.5 (boo#1258090): * fix tile dimension in low memory rendering pipeline [CVE-2025-12474]. - Update to release 0.8.4 * Huffman lookup table size fix [CVE-2024-11403] * Check height limit in modular trees [CVE-2024-11498] libjxl-0.8.5-bp157.2.3.1.src.rpm libjxl-devel-0.8.5-bp157.2.3.1.x86_64.rpm libjxl-tools-0.8.5-bp157.2.3.1.x86_64.rpm libjxl0_8-0.8.5-bp157.2.3.1.x86_64.rpm gdk-pixbuf-loader-jxl-0.8.5-bp157.2.3.1.x86_64.rpm gimp-plugin-jxl-0.8.5-bp157.2.3.1.x86_64.rpm jxl-thumbnailer-0.8.5-bp157.2.3.1.noarch.rpm libjxl-gtk-0.8.5-bp157.2.3.1.src.rpm libjxl-devel-0.8.5-bp157.2.3.1.i586.rpm libjxl-tools-0.8.5-bp157.2.3.1.i586.rpm libjxl0_8-0.8.5-bp157.2.3.1.i586.rpm libjxl0_8-32bit-0.8.5-bp157.2.3.1.x86_64.rpm gdk-pixbuf-loader-jxl-0.8.5-bp157.2.3.1.i586.rpm gimp-plugin-jxl-0.8.5-bp157.2.3.1.i586.rpm libjxl-devel-0.8.5-bp157.2.3.1.aarch64.rpm libjxl-tools-0.8.5-bp157.2.3.1.aarch64.rpm libjxl0_8-0.8.5-bp157.2.3.1.aarch64.rpm libjxl0_8-64bit-0.8.5-bp157.2.3.1.aarch64_ilp32.rpm gdk-pixbuf-loader-jxl-0.8.5-bp157.2.3.1.aarch64.rpm gimp-plugin-jxl-0.8.5-bp157.2.3.1.aarch64.rpm libjxl-devel-0.8.5-bp157.2.3.1.s390x.rpm libjxl-tools-0.8.5-bp157.2.3.1.s390x.rpm libjxl0_8-0.8.5-bp157.2.3.1.s390x.rpm gdk-pixbuf-loader-jxl-0.8.5-bp157.2.3.1.s390x.rpm gimp-plugin-jxl-0.8.5-bp157.2.3.1.s390x.rpm openSUSE-2026-94 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 146.0.7680.153 (boo#1259964): * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS * CVE-2026-4443: Heap buffer overflow in WebAudio * CVE-2026-4444: Stack buffer overflow in WebRTC * CVE-2026-4445: Use after free in WebRTC * CVE-2026-4446: Use after free in WebRTC * CVE-2026-4447: Inappropriate implementation in V8 * CVE-2026-4448: Heap buffer overflow in ANGLE * CVE-2026-4449: Use after free in Blink * CVE-2026-4450: Out of bounds write in V8 * CVE-2026-4451: Insufficient validation of untrusted input in Navigation * CVE-2026-4452: Integer overflow in ANGLE * CVE-2026-4453: Integer overflow in Dawn * CVE-2026-4454: Use after free in Network * CVE-2026-4455: Heap buffer overflow in PDFium * CVE-2026-4456: Use after free in Digital Credentials API * CVE-2026-4457: Type Confusion in V8 * CVE-2026-4458: Use after free in Extensions * CVE-2026-4459: Out of bounds read and write in WebAudio * CVE-2026-4460: Out of bounds read in Skia * CVE-2026-4461: Inappropriate implementation in V8 * CVE-2026-4462: Out of bounds read in Blink * CVE-2026-4463: Heap buffer overflow in WebRTC * CVE-2026-4464: Integer overflow in ANGLE - fix INSTALL.sh (upstream changed CHANNEL to channel in wrapper) chromedriver-146.0.7680.153-bp157.2.136.1.x86_64.rpm chromium-146.0.7680.153-bp157.2.136.1.nosrc.rpm chromium-146.0.7680.153-bp157.2.136.1.x86_64.rpm chromedriver-146.0.7680.153-bp157.2.136.1.aarch64.rpm chromium-146.0.7680.153-bp157.2.136.1.aarch64.rpm chromedriver-146.0.7680.153-bp157.2.136.1.ppc64le.rpm chromium-146.0.7680.153-bp157.2.136.1.ppc64le.rpm openSUSE-2026-101 Recommended update for claws-mail moderate openSUSE Backports SLE-15-SP7 Update This update for claws-mail fixes the following issues: - Update to 4.4.0: * Several updates to strings and icons. * The word 'Write' is now used in place of 'Compose'. e.g. 'Write email'; 'Write' preferences page, etc. * Hide Message List's horizontal scrollbar by default if not using GENERIC_UMPC. * Added a new hidden preference, 'mainwin_toolbar_always_enable_actions', (turned off by default). Activating this option means that toolbar items bound to user Actions (in the main window) will be active even when no messages are selected. * Navigation using the numpad arrow keys is now possible. * A new Colour preference has been added: 'Messages marked for moving or deletion'. This is used when 'execute immediately' is switched off. * Compose window: When re-editing a drafted message, the user will now be prompted to save any changes made to the message headers. * Compose window: when the contents of a header field are cleared, the Clear button becomes a Delete button, enabling the now empty row to be removed completely. * Folder properties: two new options to handle HTML content have been added to the General page: 'Render HTML messages as text' and 'Render HTML messages with plugin if possible'. * Folder properties: a new option, 'Show tags' has been added. This controls whether any message tags are displayed at the top of the Message View. * SpamAssassin: updated third-party code to 4.0.1. * Mail Archiver: added support for Zstandard compression (zstd) (libarchive >= 3.4.0 required). * RSSyl: the default User-Agent string has been changed to ClawsMailRSSyl/$VERSION ($URL); this can be changed in the plugin's preferences, and can be further set on a per-feed basis on the 'Feed properties' page. * RSSyl: added a preference so that feeds configured for manual updates only are not updated when refreshing all feeds (recursively by the context menu, timer or at start-up, if enabled). * RSSyl: store and send ETag and Last-Modified headers. * RSSyl: postpone auto-updates if the server sends a Retry-After: header. A successful manual update clears the Retry-After value. * PGP: display a specific message, ("This key is not in your keyring") in the NoticeView area when a key is not in the keyring. * PGP: added an option to automatically locate missing keys when sending encrypted messages. * PGP: a missing key can now optionally be retrieved by clicking the NoticeView icon. * PGP: added a 'Search for PGP key' context menu item to email addresses in the Message View. * Notification: Ayatana indicator can now be configured to limit notifications to certain folders only. * Notification: added 'Open address book' entry to Ayatana indicator's tray menu. * Configuration is now stored in a dedicated file: oauth2rc, located in the configuration directory. This file allows a user to accommodate an API change by a service provider, or to add a completely new Oauth2-based email provider of their choice. Setting protected=1 within an edited or bespoke block protects it from being overwritten by a new version of Claws Mail. * GnuTLS >= 3.4.0 is now the minimum requirement. * libetpan >= 1.9.4 is now the minimum requirement. * dbus-glib support has been migrated to GDBus (GIO) >= 2.26 and D-Bus (>= 0.60). * The summary of the configure output has been completed. * A new hidden preference has been added: "show_contact_pic". When viewing a message, if the sender is in your address book and you have saved a picture for the contact there, this option will display that picture unless the Header Pane is displayed or you have chosen not to display (X-)Face or "enable_avatars" is set to '0'. If you have a large address book it is recommended that you leave this option turned off to avoid delays in displaying messages. * The wizard now uses secure defaults. * Various code cleanups, fixes, and enhancements. * The English, French and Spanish manuals have been updated. * Updated translations: British English, Catalan, Czech, Dutch, French, German, Romanian, Slovak, Spanish, Swedish, Turkish. * bug fixes: * bug 4498, 'About window resizing issues' * bug 4586, 'PDF Viewer view breaks in Three Column layout' * bug 4764, 'Wrapped UTF8 encoded subject line displayed with nonexistent quotation marks' * bug 4834, 'Long email addresses in vCalendar invites cause the attachments bar on the right side to be hidden until restart' * bug 4841, 'qutoted-printable encoding breaks text/html file with extraordinarily long lines, base64 does not' * bug 4846, 'Preferences-> Toolbars: always show icon preview on button' * bug 4848, 'The new ayatana tray icon displays no icon when there are new messages' * bug 4850, 'Show error dialog on receive error translation' * bug 4852, 'Cancel messages contain Approved-header' * bug 4854, 'auto-wrapping off not respected when using external editor' * bug 4856, 'Build fails with gettext 0.24' * bug 4863, 'Account Preferences Minor UI inconsistency' * bug 4882, 'IMAP can not use client certificate with passphrase' * bug 4887, 'Dillo processes are not killed when an HTML message is no longer being viewed' * bug 4893, 'Clamd plugin not checking any mail' * bug 4897, ''small screen' view: crash when exiting view message list after deleting all messages/mails in folder.' * bug 4898, 'When entering folder message list is not scrolling to selected message' * bug 4902, 'memory leak in the spam_report plug-in' * bug 4930, 'remove duplicate signature flag from MimeView' * bug 4931, 'avoid memory leak in summary_set_header' * fix bug where viewing msgs in the separate msg view are not marked as read when the msgview panel is hidden * litehtml plugin build failure on Windows * 'Save email as...' from the separate message view would save whatever was selected in the summaryview rather than what was open in the message view. * when message view is closed 1. select a msg; 2. hit [v] (key), 3. open the mime structure list 4. select a part in the structure tree 5. hit [v] --[crash]-- * fix header pane bug whereby a very long header value would push the mime icons panel out of the visible area. * do not attempt to delete a tag from list when the edit tag entry has focus. - Enable vcalendar plugin default - adjust gpgme dependencies for future-proofing claws-mail-4.4.0-bp157.2.6.1.src.rpm claws-mail-4.4.0-bp157.2.6.1.x86_64.rpm claws-mail-devel-4.4.0-bp157.2.6.1.x86_64.rpm claws-mail-lang-4.4.0-bp157.2.6.1.noarch.rpm claws-mail-4.4.0-bp157.2.6.1.aarch64.rpm claws-mail-devel-4.4.0-bp157.2.6.1.aarch64.rpm claws-mail-4.4.0-bp157.2.6.1.ppc64le.rpm claws-mail-devel-4.4.0-bp157.2.6.1.ppc64le.rpm claws-mail-4.4.0-bp157.2.6.1.s390x.rpm claws-mail-devel-4.4.0-bp157.2.6.1.s390x.rpm openSUSE-2026-102 Security update for python-pydicom important openSUSE Backports SLE-15-SP7 Update This update for python-pydicom fixes the following issues: - CVE-2026-32711: path traversal in FileSet/DICOMDIR ReferencedFileID can allow file access outside the File-set root (boo#1259973) python-pydicom-2.3.1-bp157.2.3.1.src.rpm python3-pydicom-2.3.1-bp157.2.3.1.noarch.rpm python311-pydicom-2.3.1-bp157.2.3.1.noarch.rpm openSUSE-2026-95 Security update for python-cbor2 important openSUSE Backports SLE-15-SP7 Update This update for python-cbor2 fixes the following issues: - CVE-2026-26209: Fixed uncontrolled recursion via crafted CBOR payloads that could cause a denial of service (boo#1260367) python-cbor2-5.5.1-bp157.2.6.1.src.rpm python311-cbor2-5.5.1-bp157.2.6.1.x86_64.rpm python311-cbor2-5.5.1-bp157.2.6.1.i586.rpm python311-cbor2-5.5.1-bp157.2.6.1.aarch64.rpm python311-cbor2-5.5.1-bp157.2.6.1.ppc64le.rpm python311-cbor2-5.5.1-bp157.2.6.1.s390x.rpm openSUSE-2026-97 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 146.0.7680.164 (boo#1260376) * CVE-2026-4673: Heap buffer overflow in WebAudio * CVE-2026-4674: Out of bounds read in CSS * CVE-2026-4675: Heap buffer overflow in WebGL * CVE-2026-4676: Use after free in Dawn * CVE-2026-4677: Out of bounds read in WebAudio * CVE-2026-4678: Use after free in WebGPU * CVE-2026-4679: Integer overflow in Fonts * CVE-2026-4680: Use after free in FedCM chromedriver-146.0.7680.164-bp157.2.139.1.x86_64.rpm chromium-146.0.7680.164-bp157.2.139.1.nosrc.rpm chromium-146.0.7680.164-bp157.2.139.1.x86_64.rpm chromedriver-146.0.7680.164-bp157.2.139.1.aarch64.rpm chromium-146.0.7680.164-bp157.2.139.1.aarch64.rpm chromedriver-146.0.7680.164-bp157.2.139.1.ppc64le.rpm chromium-146.0.7680.164-bp157.2.139.1.ppc64le.rpm openSUSE-2026-98 Security update for python-nltk important openSUSE Backports SLE-15-SP7 Update This update for python-nltk fixes the following issues: - CVE-2026-33230: reflected cross-site scripting issue in the `lookup_...` route (boo#1260066) - CVE-2026-33231: unauthenticated remote shutdown of the local WordNet Browser HTTP server when it is started in its default mode (boo#1260067) - CVE-2026-33236: Attackers can control a remote XML index server to provide malicious values containing path traversal sequences (boo#1260068) python-nltk-3.7-bp157.3.9.1.src.rpm python3-nltk-3.7-bp157.3.9.1.noarch.rpm openSUSE-2026-103 Security update for v2ray-core important openSUSE Backports SLE-15-SP7 Update This update for v2ray-core fixes the following issues: - Update version to 5.47.0 * Add sticky choice option for leastping * Add support for enrollment links in tlsmirror * Add Wireguard Outbound (unreleased) * Add sticky choice option for leastping * Generalize IP address parsing in TUN stack options * Fix bugs - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (boo#1260329) - Update version to 5.44.1 * uTLS: bundled library updated to v1.8.2 for Chrome120 imitation profile identification * Update golang toolchain to v1.25.6, which fixed an vulnerable (tls.Config).Clone function * Fix bugs - Update version to 5.42.0 * Add TLSMirror bootstrap enrollment and self enrollment feature * TLSMirror Inverse Role Request Tripper Enrollment Server Support - CVE-2025-47911: v2ray-core: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents (boo#1251404) * Update golang.org/x/net to 0.45.0 in vendor - Update version to 5.38.0 * TLSMirror Connection Enrollment System * Add TLSMirror Sequence Watermarking * LSMirror developer preview protocol is now a part of mainline V2Ray * proxy dns with NOTIMP error * Add TLSMirror looks like TLS censorship resistant transport protocol as a developer preview transport * proxy dns with NOTIMP error * fix false success from SOCKS server when Dispatch() fails * HTTP inbound: Directly forward plain HTTP 1xx response header * add a option to override domain used to query https record * Fix bugs * Update vendor golang-github-v2fly-v2ray-core-5.47.0-bp157.2.6.1.noarch.rpm v2ray-core-5.47.0-bp157.2.6.1.src.rpm v2ray-core-5.47.0-bp157.2.6.1.x86_64.rpm v2ray-core-5.47.0-bp157.2.6.1.i586.rpm v2ray-core-5.47.0-bp157.2.6.1.aarch64.rpm v2ray-core-5.47.0-bp157.2.6.1.ppc64le.rpm v2ray-core-5.47.0-bp157.2.6.1.s390x.rpm openSUSE-2026-99 Security update for glusterfs important openSUSE Backports SLE-15-SP7 Update This update for glusterfs fixes the following issues: - Update to release 11.2 * Next minor release tentative date: Release will be based on requirement only * Users are highly encouraged to upgrade to newer releases of GlusterFS. * Important fixes in this release - Regression suite tests failures are addressed - Fixed notify stack-based buffer over-read (boo#1208519, CVE-2023-26253) - Update to release 11.1 * Fix upgrade issue by reverting posix change related to storage.reserve value * Fix possible data loss during rebalance if there is any linkfile on the system - Disable IO_uring for now [boo#1210894] - Update to release 11 [boo#1208517] [boo#1208519] * Major performance impovement of ~36% with rmdir operations * Extension of ZFS support for snapshots * Qouta implimentation based on namespace * Major cleanups and readdir/readdirp improvements * Fixed use-after-free in dht_setxattr_mds_cbk (CVE-2022-48340) - Update to release 10.2 * Some 165 bugfixes with none particularly sticking out glusterfs-11.2-bp157.2.3.1.src.rpm glusterfs-11.2-bp157.2.3.1.x86_64.rpm glusterfs-devel-11.2-bp157.2.3.1.x86_64.rpm libgfapi0-11.2-bp157.2.3.1.x86_64.rpm libgfchangelog0-11.2-bp157.2.3.1.x86_64.rpm libgfrpc0-11.2-bp157.2.3.1.x86_64.rpm libgfxdr0-11.2-bp157.2.3.1.x86_64.rpm libglusterfs0-11.2-bp157.2.3.1.x86_64.rpm python3-gluster-11.2-bp157.2.3.1.noarch.rpm glusterfs-11.2-bp157.2.3.1.i586.rpm glusterfs-devel-11.2-bp157.2.3.1.i586.rpm libgfapi0-11.2-bp157.2.3.1.i586.rpm libgfchangelog0-11.2-bp157.2.3.1.i586.rpm libgfrpc0-11.2-bp157.2.3.1.i586.rpm libgfxdr0-11.2-bp157.2.3.1.i586.rpm libglusterfs0-11.2-bp157.2.3.1.i586.rpm glusterfs-11.2-bp157.2.3.1.aarch64.rpm glusterfs-devel-11.2-bp157.2.3.1.aarch64.rpm libgfapi0-11.2-bp157.2.3.1.aarch64.rpm libgfchangelog0-11.2-bp157.2.3.1.aarch64.rpm libgfrpc0-11.2-bp157.2.3.1.aarch64.rpm libgfxdr0-11.2-bp157.2.3.1.aarch64.rpm libglusterfs0-11.2-bp157.2.3.1.aarch64.rpm glusterfs-11.2-bp157.2.3.1.ppc64le.rpm glusterfs-devel-11.2-bp157.2.3.1.ppc64le.rpm libgfapi0-11.2-bp157.2.3.1.ppc64le.rpm libgfchangelog0-11.2-bp157.2.3.1.ppc64le.rpm libgfrpc0-11.2-bp157.2.3.1.ppc64le.rpm libgfxdr0-11.2-bp157.2.3.1.ppc64le.rpm libglusterfs0-11.2-bp157.2.3.1.ppc64le.rpm glusterfs-11.2-bp157.2.3.1.s390x.rpm glusterfs-devel-11.2-bp157.2.3.1.s390x.rpm libgfapi0-11.2-bp157.2.3.1.s390x.rpm libgfchangelog0-11.2-bp157.2.3.1.s390x.rpm libgfrpc0-11.2-bp157.2.3.1.s390x.rpm libgfxdr0-11.2-bp157.2.3.1.s390x.rpm libglusterfs0-11.2-bp157.2.3.1.s390x.rpm openSUSE-2026-108 Security update for obs-service-set_version moderate openSUSE Backports SLE-15-SP7 Update This update for obs-service-set_version fixes the following issues: - Update to version 0.6.6: * Hardcode "0" as release for PKGBUILD as well - expand __python3 with python3 to work outside suse rpm packaging - Update to version 0.6.5: * Update spec file to the one used in the packaging * Move revision detection into _revision_detect - Fix shebang of the script to use the explicit version of Python (boo#1212476). - Update to version 0.6.4: * Treat LegacyVersion as InvalidVersion * Add testing python 3.10 - 3.12 - Update to version 0.6.3: * [dist] import spec file from O:S:U * Mute warning about missing EMAIL env variable in unit tests * Fix unit tests * Replace invalid use of os.errno with errno module * Replace @VERSION@ placeholders in .dsc files * Remove usage of deprecated imp module with importlib * Detect revision and set pkgrel for Arch packages - add support for AL2023 - Builds on CentOS_[5678] and possibly other distros failed because their 'rpm' didn't recognize the "Recommends:" tag. I've wrapped that tag in an "%if 0%{?suse_version}" to work around it. Build is now passing on the CentOS distros. - Update to version 0.6.2: * Avoid the Flake8 warning and restore conditional import - Update to version 0.6.1: * Handle already converted versions gracefully * Flake8 fixes (missing import) * Test python3 by default - Update to version 0.6.0: * Test against Python 3.10 which is the Tumbleweed default * Remove TravisCI - we switched to GitHub Actions * handle removed packaging.version.LegacyVersion (Fixes #83) - simplifiy conditions for all rhel like distros to skip testsuite - Update to version 0.5.14: * changed debugging output to logging module * Explicitely specifying --fromfile should win over .obsinfo * Add new switch --fromfile * Add zst to recognized suffixes (zstd support) - Update to version 0.5.13: * add license file * fixing suffixes - remove backslashes * fix suffixes to begin with a dot * enhanced debug mode * tests for directory pristine-tar - Update to version 0.5.12: * debian: set script shebang to python3 * debian: add python3 as a runtime dependency * conditionally define PYTHON in Makefile * debian: use python3 for building * try to fix set_version:157:13: E117 over-indented (comment) - Modified .spec file to better suit Fedora OS (let's just assume all Fedora versions has python 3) - Update to version 0.5.11: * try to fix set_version:157:13: E117 over-indented (comment) - enable test suite by default * if it does not build, it can also not be executed on the distro - fix requires for SLE 12 distro - Changed source files to support python 3 - fix for Fedora 30/Rawhide - for now obs_scm_testsuite only for > 1315, needed python stuff not available otherwise - Update to version 0.5.11: * fix code to pass flake8 tests for python3 * fix zipfile crash also for python2.7 * avoid error with latest flake8 about unused variable * allow running tests with python3 * second place where zip file handling can crash * avoid crashes due to false is_zipfile() response * Add python-flake8 to test suite package list * Fix indentation of condition * Fix basename to match documentation (#54) - Update to version 0.5.10: * fix zipfile crash also for python2.7 - Wrap make check in bcond obs_scm_testsuite - Update to version 0.5.9: * avoid crashes due to false is_zipfile() response - enable test suite - Update to version 0.5.8: * fixes boo#1072359 * code cleanup and some refactoring * cli options --debug and --regex * new targets (test/clean) for Makefile * initial .gitignore * Mention that tests may take some time in README.md * Fix pip/zypper tests for python3 * enforce files to be decoded as UTF-8 * Don't let version check get beyond path boundary * Slightly reorganize README.md file - add requires to python3, since Leap 15.0 still does not have the fileprovides - Update to version 0.5.7: * added gitignore * added target 'clean' in Makefile * Added new target 'test' to Makefile * fix flake8 error 'do not use bare except' * Reverting patch for setlocale as it breaks in containers - Update to version 0.5.7: * workaround for python3 locale problems in factory * add a hint to flake8 * satisfy flake8 * skip also sha256sums check for Arch - switch to python3 for less ancient distros - Avoid half-converting Debian native pkgs to non-native pkgs - Simplify the pip version handling - travis: Do not use "--use-mirrors" when using pip - travis: Test python 3.6 - try to avoid python-packaging to support non-SUSE distros - Update to version 0.5.6: * strip \n from version in obsinfo - Update to version 0.5.5: * read version from .obsinfo file if available * Add support for Collax build recipes - Update to version 0.5.4: * support obscpio archives * do not strip release number in debian, but setting it back - Update to version 0.5.3: * VersionDetector._autodetect: prioritize the directory name over the file name - Update to version 0.5.3: * Don't add unconverted_version unconditionally - Update to version 0.5.3: + Use old version from testing data instead of hardcoding + Fix replacement of empty tags + Fix empty version checks for debian/changelog + fix when switching from .dev to non-dev version - Update to version 0.5.3: + Set pkgver and pkgrel for PKGBUILD files (fixes #21) + Fix python3 compat - Update to version 0.5.2: + fix it ... it only worked with "disabledrun" mode by luck - Update to version 0.5.1: + Make python-packaging runtime dep optional + Fix %setup handling for python spec files - Recommends python-packaging - Require python-packaging - Update to version 0.5.0: + Add Makefile with install target + Change debian source format to 'native' + Fix tar file detection for PKGBUILD + Add Testsuite and README.md + - empty dummy commit to test travis hook + Disable py26, enable py{33,34} for tests + Add basic test for debian changelogs + Add travis build status image to README + Also do negative test for debian/changelog + Move testdata to .json files + Move _write_tarfile() to base test class + Remove python 2.6 compat import + Reuse test data for debian changelog tests + Rewrite set_version in python + Install devscripts in travis-ci test env + Restructure version detection code + Allow files in test tarballs + Add package type detection for python + Add version converter for python packages + Run python version converter tests with dpkg + Add function to add or replace a %define + Fix problem with replacing tags in spec files + Add function to replace %{version} in %setup + Add custom line support for _write_specfile func + Finally use version conversion for python packages + Skip some tests if zypper or dpkg are unavailable + Use python binary from virtualenv - Update to version 0.4.2: + Release 0.4.2 - Update Debian changelog - Update to version 0.4.2: + the extension needs to be \. + test with defined() at ./set_version line 118. + Fix processing of --file parameter + Add support for setting the version in debian.changelog + Sort local file list based on modification time (newest first) - Update to version 0.4.1: + Add support to automatically detect version based on Debian changelog file + Initial debianization + Handle PKGBUILD files generated by services - Update to version 0.4.1: + - drop old bash version + - fix PKGBUILD version setting + fix help text + support detection from tar ball content + use warnings pragma + - replace bash script with a more secure perl version + fix urgent quoting bugs + Be more liberal in root-dir version detection - Update to version 0.4.1: + - drop old bash version + - fix PKGBUILD version setting + fix help text - Update to version 0.4.0: + support detection from tar ball content + use warnings pragma - Update to version 0.4.0: This is a rewrite in perl This fixes also a sed commandline injection (boo#866966 CVE-2014-0593) - Update to version 0.3.3: + ERROR: git log --pretty=format:%s --no-merges 4b090f0cad..4fc9fcb0c2 failed; aborting! - Update to version 0.3.3: + - drop two echo lines which can be used to run random commands - Update to version 0.3.2: + Be more liberal in root-dir version detection - Update to version 0.3.1: + Check tarball content's root-dir for version + Use a for-loop for different endings - Move service to github.com/openSUSE/obs-service-set_version - Add _service file to update package from there - Drop local sources and use tarball from source services - Take Debian version and revision number from debian.changelog file - add support for PKGBUILD aka Arch Linux files - Preserve whitespaces in Version: and Requires: lines - only change the first occurrence of Version: header - output useful info during run - when auto-detecting the version, use the newest matching file - patch License to follow spdx.org standard - add --basename to usage help text - do not delete mandriva/fedora macros in release when reset the release number - support detecting the version from *.tbz2 files - initial package of service - fix set version, when also release number is reset obs-service-set_version-0.6.6-bp157.2.1.noarch.rpm obs-service-set_version-0.6.6-bp157.2.1.src.rpm openSUSE-2026-109 Security update for obs-service-recompress, obs-service-tar_scm moderate openSUSE Backports SLE-15-SP7 Update This update for obs-service-recompress, obs-service-tar_scm fixes the following issues: Changes in obs-service-tar_scm: - Update to version 0.11.0: * Replace deprecated ConfigParser.readfp() with read_file() * Remove six from all metadata as well. * Convert all six.assertRaisesRegex to the standard library self. form. * Remove encoding of the first parameter of subprocess.Popen - Update to version 0.10.53: * Add new --extract-rename option * debian: recommend on brz instead of depending on bzr - Update to version 0.10.52: * [archive] fix include/exclude glob to regex conversion - Update to version 0.10.51: * [core] new options `--include-re/--exclude-re` * [tests] disable test_tar_exclude_re and fix warnings * [core] revert removal of fnmatch - Update to version 0.10.50: * remove check if obsinfo is None from tar service - Update to version 0.10.49: * add test case to exclude with regex * disable partial clone if started by osc * refactor TarSCM.archive to unify exclude mechanism * fix testsuite * Sync spec file with the one in package * improve doc in *.service * change python version for github workflow * fix KankuFile * disabling test cases for bzr and hg * fix excludes for obscpio * Add test for the new changes entry format * Include real name in generated changelog entries * unset git global configs * fix syntax of spec file - use the python-flavor for requires, not python3 so that build service can determine dependencies properly - Update to version 0.10.46: * [dist] fix BuildRequires for older distros like SLE12 - Update to version 0.10.45: * [dist] fix shebang substitution in spec for py2 - Update to version 0.10.44: * import submit request change * Support updating submodules to main branch * do not skip "--reference" if package-meta ... * cpio: Do not follow symlinks in 'touch' * Support URL hostname in keyring * gbp: use --git-export * Update debian/changelog for 0.10.43 * disable compile python in debian package * update dist/debian.dsc to match debian packaging * Update debian debhelper dependency * Fix description-synopsis-starts-with-article * Fix priority-extra-is-replaced-by-priority-optional * Debian compat from 8 to 10 * Debian X-Python version no longer needed * Fix Lintian error about missing python3 dep * enable the GBP service * Fixed filtering of include/exclude when topdir has escape characters. * Fix setting svn credentials in the command line - update to version 0.10.44: * Support updating submodules to main branch * Debian packaging for gbp service * do not skip "--reference" if package-meta is enabled and git's partial clone is used. * Fixed filtering of include/exclude when topdir has escape characters. * Fix setting svn credentials in the command line * cpio: Do not follow symlinks in 'touch' * Support URL hostname in keyring * debian package updates - "Downgrade" bzr, mercurial and subversion Recommends to Suggests. - Fix shebang of the script to use the explicit version of Python (boo#1212476). - Update to version 0.10.43: * Allow to use "tar" service also standalone. - add support for AL2023 - Update to version 0.10.41: * fix for python2 - Update to version 0.10.40: * [dist] updated debian changelog * Add Python 3.12 to GitHub Actions * Switch from ConfigParser.readfp to ConfigParser.read_string - Update to version 0.10.39: * Add gpg as a dependency (needed for gpg validation) - Update to version 0.10.38: * Python 2 is no longer supported by GitHub actions, stop testing it * FD leak / flake8 / py311 fixes * updated debian files * disabled pylint 'no-member' because of false positives in py311 * removed unittest2 from BuildRequires in spec * fixed fixtures and new Exception class * updated KankuFile to Tumbleweed and removed python2 tests - Update to version 0.10.36: * fix broken tar ball from 0.10.35 release - Update to version 0.10.35 * Avoid getting confused by _scmsync.obsinfo files - Update to version 0.10.34.1667392550.026bf0e: * Fix testing in GH actions * make linters happy again * new find_latest_signed_commit algorithm - Update to version 0.10.33.1664344889.48d1960: * check if lock is older than 24 hours - Update to version 0.10.32.1662712308.31d1884: * [dist] added Requires to python_path * improve tar service to handle multiple obsinfo files to create tarball from obscpio * new ENV 'TAR_SCM_SKIP_CLEANUP' to make test development/debugging easier * staple pylint version lower than 2.14 because of breaking changes in config * do not use python mock * fix pylint errors in commontests.py * Fixed testing * use extra cache dir for partial clone * fix cache update in case of partial clone * disable partial clone when subdir is set * do not set default subdir to '.' * fixes to pass pylint * enable partial clone feature in git scm * partial clone feature * simplify locking to avoid race conditions * TarSCM.cli: set some defaults to make usage in testing easier * unlink .lock file after unlocking the cache - Update to version 0.10.30.1641993356.a87e7af: * Simplifiy conditions for all rhel like distros * Changed gendered pronoun to be gender neutral - Update to version 0.10.30.1641990734.bdad8f9: * fixes for python2.7 compatibility * fix test cases * fix various linter problems with pylint 2.11.1 * disable consider-using-f-string in pylint * added TC for _stash_pop_required * assertTarIsDeeply now more verbose in case of failure * remove tearDown/Trace from testenv.py * fix regression to keep local changes when running in osc * various fixes to make linter happy * fix tests for python 2.7 - Update to version 0.10.29.1634038025.85bfc3f: * fix test cases * fix various linter problems with pylint 2.11.1 * disable consider-using-f-string in pylint * added TC for _stash_pop_required * assertTarIsDeeply now more verbose in case of failure * remove tearDown/Trace from testenv.py * fix regression to keep local changes when running in osc - Update to version 0.10.28.1632141620.a8837d3: * fix missing "checkout" when running in osc * fix breakage on version detection * change locale - Update to version 0.10.27.1626072657.0fb7a03: * [ci] enhanced github actions for multiple python versions * Create main.yml * Change date format from short to %Y%m%d. - Update to version 0.10.26.1624258505.aed4969: * almalinux in spec file * fix include filters for obscpio files * fix python interpreter for mageia 8 * TarScm: use owner/group root in .obscpio files - Update to version 0.10.26.1623775884.87f49a8: * fixed include/exclude filtering * add '--' to git log command if file/dir equal revision exists * add '--source' to git log command * disabled consider-using-with in .pylint*rc * package .gitignore files * Fix version _none_ generate tarball with '-' * Prevent KeyError in check_for_branch_request method * removed skipped test case (obsolete since 5 yrs) * testing for obscpio/obsinfo * fix regression - obsinfo included the version string * Revert "remove useless variables" * remove useless variables * added param --without-version * extracted dstname to _dstname * cleanup TarSCM/tasks.py for pylint * add date/time to logging output for better debugging * Fix typos - Update to version 0.10.22.1615538418.07a353d: * Fix filelist: align config(noreplace) usage with obs-service-download_files * Support gitlab/github merge requests - Update to version 0.10.21.1612422695.2fdf897: * fixes boo#1127353 * fixes boo#1168573 * activate pylint3.8 and fixed false positives * don`t sanitize version if versionrewrite_pattern is set - Update to version 0.10.20.1606128060.135ac94: * fix build for CentOS adn RHEL 8 * filter dirs with "include" filter option - Update to version 0.10.19.1605080719.3b79112: * [dist] prefer python3 over python2 - Update to version 0.10.18.1600256320.569e5be: * add license file (issue 257) * additional option verification * new option '--maintainers-asc' and '--last-signed-tag' * new option '--latest-signed-commit' * Remove superflous ')' in an error message. - Update to version 0.10.16.1595259906.d3308f5: * [dist] updated debian control file for use in OBS - Update to version 0.10.16.1595245235.15a0df2: * Build with python 3 for Debian and Ubuntu * [doc] added allowed urls in documentation of tar_scm.service - remove unused unittest2 dependency - Update to version 0.10.16.1590752286.5c27247: * [dist] fix for gbp/fedora (python*-base) * fix situation when revision has been modified in _service - Update to version 0.10.15.1588842879.5c43eef: * dist: Convert to multibuild; run test suite in a separate flavor - Update to version 0.10.15.1588146746.5cfeeb8: * fix #boo 1168573 (obsservicerun,obsrun) not exists in client side installation * Update debian/changelog for latest version * Helpers: when a command fail, print the command itself too with its output * git: add support for @PARENT_TAG@ in revision * Fix build on non-openSUSE distro - Update to version 0.10.14.1584435160.d912143: * [dist] don't install gbp files by default * [dist] remove python-keyring* from dependcies * [dist] make gbp switchable in spec file - Update to version 0.10.14.1583853599.ccbb399: * support server side credentials for SCM repos - Update to version 0.10.12.1582901608.a1c02c1: * simplify osc git update case a lot * fixing revision usage on a commit hash - Update to version 0.10.12.1582709176.d82a692: * fix lost commits on local run * fix breakage when working on a specific tag/commit * git-lfs should not be mandatory as tar_scm will never use it * Allow use of git-lfs only when running obs_scm * Document _none_ special version in .service * Version cleanup: don't strip hyphen when building Debian packages * Add new archive option for Debian: git-buildpackage * call git stash with LANG=C * improved comment for method get_changesrevision * Add debian package dep to git-lfs * Implement git LFS blobs retrieval - Update to version 0.10.11.1579870213.888e79c: * Add testcase for appimage with empty build section * Handle missing build entry in appimage.yml * Fix --mirror argument position for git clone * Re-enable compatibility with Python 2.6 * fix decoding for locale -a containg non-ASCII * update_cache in git now does merge * prefer local branch over remote * added UnicodeDecodeError to exeption list in archive.py * fetch rev explicitly if using CACHEDIRECTORY and rev could not be found * tar_scm.service.in: Add example to match-tag. - Fix building and installation for CentOS8, RHEL8 and RES8 - Update to version 0.10.10.1566390389.9f923f8: * Revert "Merge pull request #323 from e4t/master" * Make service 'tar' work with a cachedir as well * Fix unit tests for modified scm directory handling * Append '_service' to repository directory * separate language and encoding * git: really print the error message * tar_scm.service: fix exclude documentation * Don`t break testsuite if cwd contains colons * disabling hg tests in travis - Fixes boo#1138377 - Update to version 0.10.9.1559745964.22c86cd: * [dist] python3 for SLE12 and openSUSE 42.3 * [dist] enable python3 in SLE >= 12 * fix encoding error for surrogates * glibc-common was used up to FC23 and RHEL7 * Compile python files before install * change order in GNUMakefile to prefer python3 * More thorought spec file cleanup * predefine python version in spec file for GNUMAkefile * [dist] spec file: python3 only and multidist * Git also uses the LANGUAGE variable * centos_version and rhel_version are triple digits * Minimize diff with the version in openSUSE:Tools * Fix the logic to pick the locale package on Fedora * Forgot the guard 0 in one conditional * Require packages to get the en_US.UTF-8 locales * enforce bytes for cpio file list - Update to version 0.10.9.1559647449.d965035: * [dist] enable python3 in SLE >= 12 - Require external argparse for RHEL6 - Update to version 0.10.9.1557261720.32a1cdb: * fix encoding error for surrogates * glibc-common was used up to FC23 and RHEL7 - Update to version 0.10.8.1556896538.0693a62: * Compile python files before install * change order in GNUMakefile to prefer python3 * More thorought spec file cleanup * predefine python version in spec file for GNUMAkefile - the current guessing code is finding python2 and then uses that, because python2 still seems to be available in the build env, as we already know which python version we want we can just pass the path to make and skip the whole guessing. - Update to version 0.10.7.1556277536.7e9915a: * [dist] spec file: python3 only and multidist * Git also uses the LANGUAGE variable * centos_version and rhel_version are triple digits * Minimize diff with the version in openSUSE:Tools * Fix the logic to pick the locale package on Fedora * Forgot the guard 0 in one conditional - centos_version and rhel_version are triple digits - locally apply fixes from https://github.com/openSUSE/obs-service-tar_scm/pull/298 - Change requirement locale_package to glibc-common to fix building for CentOS6 and CentOS7 - Update to version 0.10.6.1551887937.e42c270: * Require packages to get the en_US.UTF-8 locales - Update to version 0.10.6.1551448746.2759df2: * enforce bytes for cpio file list * fixes boo#1127907 - Update to version 0.10.5.1551309990.79898c7: * Prefer UTF-8 locale as output format for changes - Update to version 0.10.4.1551193322.b7a79f4: * added KankuFile * fix problems with unicode source files * added python-six to Requires in specfile * better encoding handling - Update to version 0.10.1.1550758451.f88bd41: * fixes boo#1082696 and boo#1076410 * more fixes py3 unicode * fix unicode in containers - Update to version 0.10.0.1550647779.25999e8: * fix spec for RH/Fedora - glibc-locale -> glibc-common - Update to version 0.10.0.1550589094.e2ae17d: * move to python3 * add python 3.6 and 3.7 to testing * added logging for better debugging changesgenerate * raise exception if no changesauthor given * removed python 2.6 from travis - Update to version 0.9.5.1548407358.b62685b: * Stop using @opensuse.org addresses to indicate a missing address * move argparse dep to -common package * allow submodule and ssl options in appimage * sync spec file as used in openSUSE:Tools project - Update to version 0.9.5.1545082095.8dbc95f: * [dist] fix service files installation in Makefile - Update to version 0.9.5.1545064321.5c10ac0: * check encoding problems for svn and print proper error msg * added new param '--locale' * separate service file installation in GNUmakefile * added glibc as Recommends in spec file * cleanup for broken svn caches * another fix for unicode problem in obs_scm - Update to version 0.9.5.1544099104.f52adb7: * Final fix for unicode in filenames * Another attempt to fix unicode filenames in prep_tree_for_archive - Update to version 0.9.5.1544015491.08dd948: * Another attempt to fix unicode filenames in prep_tree_for_archive - Update to version 0.9.5.1543865445.4e2fbad: * fix bug with unicode filenames in prep_tree_for_archive * reuse _service*_servicedata/changes files from previous service runs - Update to version 0.9.5.1543588452.b19491f: * fix problems with unicode characters in commit messages for changeloggenerate - Update to version 0.9.5.1543502111.e576bd6: * fix encoding issues if commit message contains utf8 char - Update to version 0.9.5.1543424658.8740ef1: * revert encoding for old changes file - Update to version 0.9.5.1543418966.30359e4: * change pylint/flake8 back to 2.7 for now * remove hardcoded utf-8 encodings - Update to version 0.9.5.1542905297.a6e346a: * make code python3 ready * Add support for extract globbing - Update to version 0.9.4.1537959361.56833cb: * enable flake8 in hound * cleanup for pylint and flake8 * split pylint2 in GNUmakefile * fix check for "--reproducible" * create reproducible obscpio archives * fix flake warning - Update to version 0.9.3.1537869751.51a17c5: * fix regression from 44b3bee * Support also SSH urls for Git - Update to version 0.9.2.1537788075.fefaa74: * fix CVE-2018-12473 (boo#1105361) * fix CVE-2018-12474 (boo#1107507) * fix CVE-2018-12476 (boo#1107944) * check name/version option in obsinfo for slashes * check url for remote url * check symlinks in subdir parameter * check filename for slashes * disable follow_symlinks in extract feature - switch to obs_scm for this package - Update to version 0.9.1.1537341862.5348694: * run download_files in appimage and snapcraft case * check --extract file path for parent dir * Fix parameter descriptions - Update to version 0.9.1.1534504824.0732756: * changed os.removedirs -> shutil.rmtree * Adding information regarding the *package-metadata* option for the *tar* service The tar service is highly useful in combination with the *obscpio* service. After the fix for the metadata for the latter one, it is important to inform the users of the *tar* service that metadata is kept only if the flag *package-metadata* is enabled. Add the flag to the .service file for mentioning that. * Allow metadata packing for CPIO archives when desired As of now, metadata are always excluded from *obscpio* packages. This is because the *package-metadata* flag is ignored; this change (should) make *obscpio* aware of it. - Update to version 0.9.1.1530616709.1329314: * improve handling of corrupt git cache directories * only do git stash save/pop if we have a non-empty working tree (#228) * sort imports * don't allow DEBUG_TAR_SCM to change behaviour (#240) * add stub user docs in lieu of something proper (#238) * [dist] fix build for distros not yet supporting Recommends tag * Remove clone_dir if clone fails * python-unittest2 is only required for the optional make check * move python-unittest2 dep to test suite only part (submission by olh) - Update to version v0.9.0.1523267117.de861d8: * Removing redundant pass statement * fixing indentation warnings from flake8 * fixing flake8 warnings, missing imports * missing import for logging functions. * [backend] Adding http proxy support - python-unittest2 is only required for the optional make check - Update to version 0.8.0.1520581079.e26b0ae: * make installation of scm's optional * add a lot more detail to README * Git clone with --no-checkout in prepare_working_copy * Refactor and simplify git prepare_working_copy * Cleanup flake8 checks * Only use current dir if it actually looks like git (Fixes #202) * reactivate test_obscpio_extract_d * fix broken test create_archive * fix broken tests for broken-links * changed PREFIX in Gnumakefile to /usr * new cli option --skip-cleanup * fix for broken links * fix reference to snapcraft YAML file * fix docstring typo in TarSCM.scm.tar.fetch_upstream * acknowledge deficiencies in dev docs * wrap long lines in README - Update to version 0.8.0.1507129410.0cb2d44: * mention _none_ version string for people who need it for kiwi root archives for example * git: Support url change * change ordering so that latest change is on top * also override timestamps of files in cpio * Sort cpio file list * [dist] fix spec file py_compile for fedora * Sort tar file list - Update to version 0.8.0.1499787575.2419460: * [test] refactor of fake classes * [bugfix] fix UnboundLocalError: local variable 'parent_tag' - Update to version 0.8.0.1499787575.2419460: * [dist] changed to %py_compile in spec file * [bugfix] fixes issue #173 * [bugfix] Decoupled self.scm from class name in TarSCM/scm/* * [lint] make tests/unittestcases.py flake8 ready * [lint] more fixes for pylint readiness * [lint] refactor unittestcases.py * [test] increase cov for TarSCM.archive from 61% to 92% * [doc] added comment to --use-obs-scm * [test] refactor of fake classes * [bugfix] fix UnboundLocalError: local variable 'parent_tag' - hotfix runtime of obs_scm - Update to version 0.8.0.1498846582.8799787: * fix for gh issue #169 * new version placeholder for empty version string * fix for bzr locale problem in testsuite * pylint and flake8 in testsuite for better code quality * code cleanup to be more pylint and flake8 compatible - Update to version 0.7.0.1497261741.b1aa4cb: * Move spec file to git - Update to version 0.7.0.1496831936.d960322: * fix for nonexistant build section in appimage.yml * more documentation for README.md * Update control - add python-yaml for debian distros - added Requires: python2 for Fedora >= 25 - Only BuildRequire packages needed for testsuite if the testsuite is enabled - Update to version 0.7.0.1492101301.747de50: * skip broken tests temporarily - Update to version 0.7.0.1492095435.eda090e: * revision, repodir and repocachedir as attribute for TarSCM.<scm> * new class TarSCM.cli to make testing easier * testing script name more reliable * fixed arguments for singletask in case of snapcraft * refactored snapcraft code + first tests for snapcraft * added testcase for snapcraft finalize * split classes into several files * track module dependencies in requirements.txt * use unittest2 in Python 2.6 * more testing for TarSCM.tasks * clone_dir/repodir/arch_dir(tar_dir)/args now attributes of scm objects * test case for save_run * major refactor of git cache handling * consolidation of archive.obscpio and archive.tar parameters * next test cases * unset CACHEDIRECTORY env variable in unit tests * update atime/mtime of repocachedir if already exists * prevent key errors when $HOME is not set * fix PEP8 problems and reenable PEP8 testing * keep checkout while running with osc * fix local checkout when running in osc * force remove of files while 'make clean' * fix: also exclude directories when called .git * fix problems with generatechanges when ~/.obs/tar_scm exists * initial appimage support * Provide version rewrite using a regex pattern and replacement. * new parameter --match-tag to filter tags * keep .gitlab/.github directories - Update to version 0.7.0.1491998613.3890456: * refactor of detect_changes into classes * url as attribute of TarSCM.scm * run_cmd and safe_run moved into class helpers * combine os.path.join statement * refactoring fetch_upstream to be part of TarSCM.scm * new classes for archives * common method 'get_current_commit' to get rid of exception for git * refactored detect_changes to get rid of changesgenerate exception * get_repocachedir -> TarSCM.scm * Add description to the README.md file - split services into own rpms - Update to version 0.7.0.1490358243.8de854e: * keep .gitlab/.github directories - Update to version 0.7.0.1490263157.682db30: * Provide version rewrite using a regex pattern and replacement. * initial appimage support * make pep8 happy again * test cases for version rewrite * new parameter --match-tag to filter tags - Replayce python-yaml Requires/Buildrequires with python-PyYAML, which is actually its correct name. - Update to version 0.7.0.1484082405.7671be8: * fix problems with generatechanges when ~/.obs/tar_scm exists - Update to version 0.7.0.1481203567.804351a: * fix: also exclude directories when called .git - Update to version 0.7.0.1480953937.a4b8b09: * fix local checkout when running in osc * force remove of files while 'make clean' - Update to version 0.7.0.1480000004.4027270: * fixed pip8 problems * keep checkout while running with osc - Update to version 0.7.0.1478249268.e162c66: * prevent key errors when $HOME is not set - Update to version 0.7.0.1477858520.51a62fb: * added locking for cachedir in jailed mode * removed setup_tracking_branches and '--dissociate' * inital version of TarSCM classes * scm_object generation moved to singletask * FETCH_UPSTREAM_COMMANDS into classes * moved update_cache_* to classes * moved detect_version into classes and refactored calls of get_timestamp_* * moved get_timestamp functions into scm classes * git_ref_exists -> TarSCM.git._ref_exists * fetch_upstream_git_submodules -> fetch_submodules to get rid of exceptions for git * just moved some functions for better overview * refactor of detect_changes into classes * url as attribute of TarSCM.scm * run_cmd and safe_run moved into class helpers * combine os.path.join statement * refactoring fetch_upstream to be part of TarSCM.scm * new classes for archives * common method 'get_current_commit' to get rid of execption for git * refactored detect_changes to get rid of changesgenerate exception * get_repocachedir -> TarSCM.scm * revision, repodir and repocachedir as attribute for TarSCM.<scm> * new class TarSCM.cli to make testing easier * testing script name more reliable * fixed arguments for singletask in case of snapcraft * refactored snapcraft code + first tests for snapcraft * added testcase for snapcraft finalize * split classes into serveral files * more testing for TarSCM.tasks * clone_dir/repodir/arch_dir(tar_dir) now attributes of scm objects * test case for save_run * major refactor of git cache handling * consolidation of archive.obscpio and archive.tar parameters * next test cases * sytnax fix for "tar" service * fixed tests for tar * unset CACHEDIRECTORY env variable in unit tests * update atime/mtime of repocachedir if already exists - Update to version 0.7.0.1474270818.3e05f80: * - Update to version 0.7.0.1477567374.d44d677: * use '--dissociate' for git if package-meta is set * added locking for cachedir in jailed mode * removed setup_tracking_branches and '--dissociate' * inital version of TarSCM classes * scm_object generation moved to singletask * FETCH_UPSTREAM_COMMANDS into classes * moved update_cache_* to classes * moved detect_version into classes and refactored calls of get_timestamp_* * moved get_timestamp functions into scm classes * git_ref_exists -> TarSCM.git._ref_exists * fetch_upstream_git_submodules -> fetch_submodules to get rid of exceptions for git * just moved some functions for better overview * refactor of detect_changes into classes * url as attribute of TarSCM.scm * run_cmd and safe_run moved into class helpers * combine os.path.join statement * refactoring fetch_upstream to be part of TarSCM.scm * new classes for archives * common method 'get_current_commit' to get rid of execption for git * refactored detect_changes to get rid of changesgenerate exception * get_repocachedir -> TarSCM.scm * revision, repodir and repocachedir as attribute for TarSCM.<scm> * new class TarSCM.cli to make testing easier * testing script name more reliable * fixed arguments for singletask in case of snapcraft * refactored snapcraft code + first tests for snapcraft * added testcase for snapcraft finalize * split classes into serveral files * more testing for TarSCM.tasks * clone_dir/repodir/arch_dir(tar_dir) now attributes of scm objects * test case for save_run * major refactor of git cache handling * consolidation of archive.obscpio and archive.tar parameters * next test cases * sytnax fix for "tar" service - Update to version 0.7.0.1476904507.e88eed1: * fixed arguments for singletask in case of snapcraft * refactored snapcraft code + first tests for snapcraft * added testcase for snapcraft finalize * split classes into serveral files * more testing for TarSCM.tasks * clone_dir/repodir/arch_dir(tar_dir) now attributes of scm objects * test case for save_run * major refactor of git cache handling * consolidation of archive.obscpio and archive.tar parameters * next test cases - Update to version 0.6.1.1473925745.c5264bb: * jailed mode for docker integration * added setup of remote branches in jailed mode * new handling for remote/local branches when caching * fix permission problem of .changes files when running jailed in docker * fix problem with outdated git refs in cache - Update to version 0.6.1.1472657181.ff9a5ca: * make yaml dependency optional for travis * Add an option 'master' to submodules to fetch the latest mater branch. * tar_scm.py: Always use an absolute path for the 'output' directory * do not set files back to 1970... * transfer mtime via obsinfo * create needed sub directories for cache handling * prefer local cache directory * - weak dependency to mercurial for debian * add python-dateutil require for debian * testing on debian is broken atm - Update to version 0.6.1.1472656157.58c52d8: * make yaml dependency optional for travis * Add an option 'master' to submodules to fetch the latest mater branch. * tar_scm.py: Always use an absolute path for the 'output' directory * do not set files back to 1970... * transfer mtime via obsinfo * create needed sub directories for cache handling * prefer local cache directory * - weak dependency to mercurial for debian * add python-dateutil require for debian * testing on debian is broken atm - Update to version 0.6.1.1472655284.4930b81: * add python-dateutil require for debian * testing on debian is broken atm - fix debian builds - Update to version 0.6.1.1472636708.355b59a: * fix some more merge regressions * pep8 fixes/workarounds * make yaml dependency optional for travis * Add an option 'master' to submodules to fetch the latest mater branch. * tar_scm.py: Always use an absolute path for the 'output' directory * do not set files back to 1970... * transfer mtime via obsinfo * create needed sub directories for cache handling * prefer local cache directory * - weak dependency to mercurial for debian - Update to version 0.6.1.1471594222.d257927: * prefer local cache directory * jailed mode for docker integration * added setup of remote branches in jailed mode * new handling for remote/local branches when caching - cache handling will be refactored to have only one implementation in future. - fix mtime handling - Update to version 0.6.0.1469628830.67456b7: * pep8 fixes/workarounds * make yaml dependency optional for travis * Add an option 'master' to submodules to fetch the latest mater branch. * do not set files back to 1970... * transfer mtime via obsinfo * create needed sub directories for cache handling - update to official version 0.6.0 (latest package became official) - Update to version 0.6.0.1467889501.49c9462: + very first obs_scm implementation + allow extracting of (spec) files + allow to include local changes when using "obs_scm" service via local osc commands. + make obsinfo parameter for tar service optional + support filtering on creation of cpio archives + - add debian provides + - make cleaning message a debug message + report error when specified revision got not found + add snapcraft.yaml support + merge upstream + minor cleanup + fix typo, wrong file name of new snapcraft.yaml + fix some more merge regressions + pep8 fixes/workarounds + make yaml dependency optional for travis - added snapcraft support via own service - Update to version 0.6.0~pre.1467126663.ec976d1: * Allow to manually specify a base for @TAG_OFFSET@ * - make cleaning message a debug message * Honour "subdir" param for changesgenerate * report error when specified revision got not found * Extend fixture to create commits with a specific timestamp * Use commit timestamp as mtime for files and directories in tarball * Workaround bug in Mercurial localdate filter * fix breakage from conflict of #63 and #85 * Provide test for git tag fetching * Add ability to generate changes file when using svn * add snapcraft.yaml support - Update to version 0.6.0~pre.1461678268.e8b5d73: * fix TESTING.md link in CONTRIBUTING.md * Use correct level 2 bullet point (*) * very first obs_scm implementation * allow extracting of (spec) files * allow to include local changes when using "obs_scm" service via local osc commands. * make obsinfo parameter for tar service optional * support filtering on creation of cpio archives * - add debian provides - add debian provides - fix dependency on SLE 11 to python-argparse - Correctly reference patch in previous entry - Update to version 0.6.0~pre.1460377105.35a4ea4: * support filtering on creation of cpio archives - Update to version 0.6.0~pre.1460098798.dda5411: + make obsinfo parameter for tar service optional - Update to version 0.6.0.1460017418.4e4b2d6: + Correct error message about lack of git tags + GNUmakefile: Use default python in $PATH unless it is a python 3. + fix TESTING.md link in CONTRIBUTING.md + Use correct level 2 bullet point (*) + very first obs_scm implementation + allow extracting of (spec) files + allow to include local changes when using "obs_scm" service via local osc commands. - building this pre-version currently from private branch as discussed with Adam - only require git-core to not pull in git-web and gitk - Fix build on Ubuntu by disabling mercurial tests * 0001-Debianization-disable-running-mercurial-tests.patch - Update to version 0.5.3.1434983686.0b4ce51: + Add missing extension parameter to service file + Fix build on Debian 7.0/8.0 - Update to version 0.5.3.1433158390.b0e72e1: + use the same Python interpreter for testing tar_scm + Split up the steps of git cloning and submodule initialization + fix Makefile test runner for Debian - Update to version 0.5.2.1432717816.cff60cf: + be explicit about python2, python may be python3 + Fix newline at the end of @PARENT_TAG@ + Fix Mercurial version format strings in unittest + Refactoring of package metadata regex matching + Refactor resetting of uid/gid so that it is reusable + Fix handling of --include option + Fix handling of --exclude option + Refactor subdir handling of tarchecker's to prevent code duplication + ignore PEP8's E731 check for lambdas + PEP8 E402 fix: set PYTHONPATH outside code + add @TAG_OFFSET@ support in versionformat for git + fix inconsistencies in tar_scm.service + - fix .service file syntax (OBS 2.6.1 is checking now) + mention need to set PYTHONPATH when running tests + keep STDERR separate + don't allow --subdir to wander outside repo (boo#927120, #71) - Update to version 0.5.1.1426664483.de67b88: + be explicit about python2, python may be python3 + Fix newline at the end of @PARENT_TAG@ + Fix Mercurial version format strings in unittest + Refactoring of package metadata regex matching + Refactor resetting of uid/gid so that it is reusable + Fix handling of --include option + Fix handling of --exclude option + Refactor subdir handling of tarchecker's to prevent code duplication + ignore PEP8's E731 check for lambdas + PEP8 E402 fix: set PYTHONPATH outside code + add @TAG_OFFSET@ support in versionformat for git + fix inconsistencies in tar_scm.service + - fix .service file syntax (OBS 2.6.1 is checking now) - Update to version 0.5.0.1412769870.6cda976: + change default git versionformat to %ct.%h + fix changes generation when version is blank + lots of refactoring + add info and caveats about data persisting between tests + gittests: give default author test a unique name - Update to version 0.4.2.1412467141.df3329e. Many changes, including: + Retrieve tags for a cached git repo + Add PEP8 checking everywhere + Significantly improved tests + Fixed checkout of a hg url that ends with a trailing slash + Fix Debian build dependencies for python + Change Debian package format to 3.0 (native) + Install into /usr on Debian + Honor submodules=disable as before (fixes #38) + Fix directory name of repository clone + Fix handling of symbolic links + Fix crash when changesrevision <param> is missing + Improved usage text + Store git and hg hashes in full + Fix crash during copy of _servicedata + Fix format of new changes to match old shell tar_scm + Fix bug when temp file is on a different filesystem + Fix change generation bug introduced by Python rewrite + Fix retrieval of email address from ~/.oscrc + Refactor changesgenerate code - Update to version 0.4.0.1410288598.7f38281: + Python rewrite of tar_scm + Make pep8 happy (except for regex in tar_scm:299) + Address some feedback from pylint + make Python version PEP8-compliant + Let Travis execute pep8 + Strip newline ('\n') characters from safe_run output in detect_version() + Make potentially long-running tasks print output in real-time + Improve efficiency of stdout handling in safe_run() + Release obs-service-tar_scm 0.4.0 - Update to version 0.3.2.1404723797.745a470: + Initial debianization + switch git submodule versions correctly + add some basic documentation to the tests + split off info into TESTING.md + add CONTRIBUTING.md + improve formatting + whitelist accepted chars in arguments. + Correct/update install information + Reverse changes lines again with tac - Update to version 0.3.2.1386694317.b85b342: + Fix adding to already existing _servicedata case + Don't reverse changes lines with 'tac' + Fix Python FutureWarning about comparison with None + Improve description of the versionformat parameter. - Enable changes generation - Bump version to 0.3.2 * changes file generation support written by Sascha - Bump version to 0.3.1 * do not execute tar base file name - Bump version to 0.3.0 and include git timestamp / SHA1 in version. - Update to latest git (9de0986): + add git submodule update test + extract submodule_path() method + allow git commands to run from cwd + rename opts to args + annotate cwd + ensure all scm invocations succeed when expected + record revisions per repository path + allow creation of git submodules + Fixtures.create_commits(): add repository path parameter + GitFixtures.create_repo(): add repository path parameter + fix hg tests when run in timezone east of UTC + add hint about running tests quicker + don't hardcode revision in helper method + quoting tweak + make test output more consistent + get line spacing right + Travis: also test with Python 2.6 + tweak debugging for mv invocations + a bit more info on the test suite + leave temporary files behind on failure, for debugging + add some docstrings to a few of the more complex tests + make switching to a given git revision more robust + try to make test output a little easier to understand + improve README.md + switch README to markdown and add Travis build status icon + replace XML entities with dollar-curlies + Properly encode XML reserved entities (&,<,>) + add better revision description/documentation for git + We are still not allowed to have dashes inside version. Fix for mercurial. + allow-different-naming-schemes-for-resulting-tar-files + Fix breakage when LANG is not English (issue #8) + Make test.py executable + README: add information about the test suite + Don't rely on git error codes for "git describe", catch all + Better error handling for @PARENT_TAG@ expansion + the correct tag is 'param', 'parameter' won't work + Tell Travis where to find the tests + Cleanup testing tmp_dir afterwards + Add description for @PARENT_TAG@ + Ignore .coverage + Move tests into sub-directory + Last change for some bonus points + Naa, typo + Update package database before installing dependencies + Add initial Travis-CI configuration + Add .gitignore file + Add test for @PARENT_TAG@ - Pass --tags to "git describe" for @PARENT_TAG@ - Disable testsuite on SLE_11_SP2 to fix build - Use upstream github repository and download via _service file - Add custom git versionformat extensions: + @PARENT_TAG@: Replaced by first tag that is reachable from the current commit (see 'git describe') Future custom additions could follow the @NAME@ scheme - Fix usage text for submodules option - change default versionformat from author date (%at) to commiter date (%ct) for git, to fix issues with cherry-picked commits resulting in decreased version - add --date=short to get_vesion of git and remove '-' chars by sed. This allows us to use %ad as versionformat and have something like "20120916" as version instead of terrible Unix timestamps. - Prevent local users from appearing as user/group owner in generated tar files (thanks bmwiedemann for this) - fix option for submodule update - Fixed error with cache - Added an option to disable git submodules - Replaced --exclude=.$MYSCM with --exclude-vcs tar option - Added support for git submodules - Re-iterating the last change once again, 'git rev-parse --verify $REV' will return false even if $REV is a normal branch upon first clone of the repo. Thus 'git fetch $URL +$REV:$REV" is run initially. However, the 'git checkout $REV' then fails because it's missing tracking information. Therefore, try a normal checkout first and fetch the specific $REV only when that fails (due to reasons described below). - Allow git revision to refer to revisions not available from a default clone/fetch (i.e. refs other than refs/heads/* or refs/tags/*) - Check that git pull succeeds - Remove accidental reference to keep-source parameter which was never pushed upstream (obsoleted by new cache). - When the cache is used, output location of repo in the cache - add new 'versionformat' option to determine how version is extracted via git show --pretty=... - support caching of cloned repositories to speed up fetch from upstream Mon Feb 13 15:52:19 GMT 2012 - aspiers@suse.com - Add test suite - Fix --subdir with --scm svn - Fix --scm bzr - patch license to follow spdx.org standard - add new option to specify a subset of files/subdirectories to pack in the tar ball - Checking out a specific revision cannot work when only the latest version is cloned. - make svn checkout --trust-server-cert option conditional, since this option is not supported by versions prior to subversion 1.6. - Trim user prefix from tarball filename. This enables tar_scm service to be used with git and ssh transport (in conjuction with a passphrase less ssh-pubkey). Example Git URL: git@gitrepo.tld:foobar.git - git 1.6.x and very likely other version only support "show --pretty=format:%at" as parameter with "format:" prefix. git show --pretty=%at is also support by recent git versions. - make it possible to create tar balls without version tag (#714542) - support old tar bar lookup also for OBS 2.3 bs_service using .old/ directory - drop broken code for same-commit-detection as suggested by Markus - history-depth parameter: use hackish depth=999999999 if "full" is given so that a shallow clone will be fully deepened if the _service file is changed. Also, fix git clone cmd line (remove a pair of quotes that cause problems). - add support for (git) checkout depth, original patch by Markus Lehtonen <markus.lehtonen@linux.intel.com> - make packaging of meta data optional to reduce tar ball size - fix exclude expansion - add support for bzr - Fix: recompressed tars were never reused - cleanup mercurial commands - always trust svn server certificate. We don't have a secure handling for it anyway. Trust needs to established via extra service. - fix subdir usage for git - add option exclude files/directories when creating the tar ball - git clone runs now with --depth 1 option - support mercurial repositories - Fix --filename parameter use - initial version to checkout/update svn or git repos and create a tar Changes in obs-service-recompress: - zstd is now available on SLE 15 SP0 Adding dependency there as well to fix boo#1216361 - update to version 0.5.2: * zstd compression with rsyncable and higher compression - disable zstd on RHEL, the package is not available on OBS - use filebased requires on gzip so that zstd can supplement it as well - Fixed checking for zstd support on different distributions - Update to version 0.5.1: * Use at least 2 threads for xz compression - Update to version 0.5.0: * do not follow symlinks (issue 9) * add license file * compression using # of core threads for zstd and xz * Add support for keeping of original file * use --threads=0 - Update to version 0.4.0+git20200123.696d003: * run test suite during build - Update to version 0.4.0+git20200123.946b23f: * add zstd compression support - Update to version 0.3.1+git20170704.59bf231: * Add README.md file * [dist] added spec file to git - Update to version 0.3.1+git20160217.7897d3f: + security fixes (boo#967265) - Fix build for Debian 8.0 - Use install target from Makefile - Include git revision in version number - Update to version 0.3.1+git20150622.d908b54: + Tell rm not to prompt + Change debian source format to 'native' + Add Makefile with install target - Update to version 0.3.1: + debian: use install-file to simplify rules-file + Initial debianization + - avoid problematic quoting + Fix typo - Update to version 0.3.1: + Fix diffing uncompressed files - Update to version 0.3: + Don't overwrite identical files - Move service to github.com/openSUSE/obs-service-recompress - Add _service file to update package from there - Drop local sources and use tarball from source services - Display message on successful (re)compression. - always remove uncompressed files - fix rpmlint warnings obs-service-recompress-0.5.2-bp157.2.1.noarch.rpm obs-service-recompress-0.5.2-bp157.2.1.src.rpm obs-service-appimage-0.11.0-bp157.2.1.noarch.rpm obs-service-obs_scm-0.11.0-bp157.2.1.noarch.rpm obs-service-obs_scm-common-0.11.0-bp157.2.1.noarch.rpm obs-service-snapcraft-0.11.0-bp157.2.1.noarch.rpm obs-service-tar-0.11.0-bp157.2.1.noarch.rpm obs-service-tar_scm-0.11.0-bp157.2.1.noarch.rpm obs-service-tar_scm-0.11.0-bp157.2.1.src.rpm openSUSE-2026-114 Recommended update for putty moderate openSUSE Backports SLE-15-SP7 Update This update for putty fixes the following issues: - Update to release 0.83 * Support for ML-KEM, a NIST-standardised post-quantum key exchange mechanism. * Bug fix: psftp -b works again. * Fixed bug which crashed Pageant if an SSH connection is abandoned while waiting for a deferred decryption passphrase. * Fix a tight loop bug occurring if PuTTY tried to send an empty answerback string. * Fixed a bug where some configuration edit boxes' contents were accidentally truncated to 127 characters. * Bug fix: the small keypad keys did not reliably work in the terminal on Unix. - Update to release 0.82 * Major refactoring of Unicode handling to allow the use of 'foreign' Unicode characters outside the system's configured default character set. * Bracketed paste mode can now be turned off in the Terminal > Features panel. * The "border width" configuration option is now honoured even when the window is maximised. putty-0.83-bp157.2.3.1.src.rpm putty-0.83-bp157.2.3.1.x86_64.rpm putty-0.83-bp157.2.3.1.i586.rpm putty-0.83-bp157.2.3.1.aarch64.rpm putty-0.83-bp157.2.3.1.ppc64le.rpm putty-0.83-bp157.2.3.1.s390x.rpm openSUSE-2026-110 Security update for perl-Crypt-URandom important openSUSE Backports SLE-15-SP7 Update This update for perl-Crypt-URandom fixes the following issues: - updated to 0.550.0 (0.55) see /usr/share/doc/packages/perl-Crypt-URandom/Changes 0.55 Tue Feb 17 07:01:43 2026 - Fix for sysread/read failures. Thanks to Miha Purg for GH#20 - Fix for test suite failures on STDOUT encoding. Thanks to Lukas Mai for GH#19 - CVE-2026-2474: Fix for heap buffer overflow in the XS function crypt_urandom_getrandom() (boo#1258266) - updated to 0.540.0 (0.54) see /usr/share/doc/packages/perl-Crypt-URandom/Changes 0.54 Sat Mar 15 20:37:13 2025 - Reverse solaris changes and remove errstr checks. Thanks to eserte for GH#18 perl-Crypt-URandom-0.550.0-bp157.2.3.1.src.rpm perl-Crypt-URandom-0.550.0-bp157.2.3.1.x86_64.rpm perl-Crypt-URandom-0.550.0-bp157.2.3.1.i586.rpm perl-Crypt-URandom-0.550.0-bp157.2.3.1.aarch64.rpm perl-Crypt-URandom-0.550.0-bp157.2.3.1.ppc64le.rpm perl-Crypt-URandom-0.550.0-bp157.2.3.1.s390x.rpm openSUSE-2026-111 Security update for tinyproxy important openSUSE Backports SLE-15-SP7 Update This update for tinyproxy fixes the following issues: - CVE-2026-3945: Fixed denial of service by unauthenticated remote attacker (boo#1261024) - Update to release 1.11.3 * conf: add BasicAuthRealm feature * basic auth: fix error status 401 vs 407 * tinyproxy.conf.5: explain what a site_spec looks like * tinyproxy.conf.5: add an IPv6 example to allow/deny section * reqs: fix integer overflow in port number processing tinyproxy-1.11.3-bp157.2.6.1.src.rpm tinyproxy-1.11.3-bp157.2.6.1.x86_64.rpm tinyproxy-1.11.3-bp157.2.6.1.i586.rpm tinyproxy-1.11.3-bp157.2.6.1.aarch64.rpm tinyproxy-1.11.3-bp157.2.6.1.ppc64le.rpm tinyproxy-1.11.3-bp157.2.6.1.s390x.rpm openSUSE-2026-113 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 146.0.7680.177 (boo#1261249) * CVE-2026-5273: Use after free in CSS * CVE-2026-5272: Heap buffer overflow in GPU * CVE-2026-5274: Integer overflow in Codecs * CVE-2026-5275: Heap buffer overflow in ANGLE * CVE-2026-5276: Insufficient policy enforcement in WebUSB * CVE-2026-5277: Integer overflow in ANGLE * CVE-2026-5278: Use after free in Web MIDI * CVE-2026-5279: Object corruption in V8 * CVE-2026-5280: Use after free in WebCodecs * CVE-2026-5281: Use after free in Dawn * CVE-2026-5282: Out of bounds read in WebCodecs * CVE-2026-5283: Inappropriate implementation in ANGLE * CVE-2026-5284: Use after free in Dawn * CVE-2026-5285: Use after free in WebGL * CVE-2026-5286: Use after free in Dawn * CVE-2026-5287: Use after free in PDF * CVE-2026-5288: Use after free in WebView * CVE-2026-5289: Use after free in Navigation * CVE-2026-5290: Use after free in Compositing * CVE-2026-5291: Inappropriate implementation in WebGL * CVE-2026-5292: Out of bounds read in WebCodecs chromedriver-146.0.7680.177-bp157.2.142.1.x86_64.rpm chromium-146.0.7680.177-bp157.2.142.1.nosrc.rpm chromium-146.0.7680.177-bp157.2.142.1.x86_64.rpm chromedriver-146.0.7680.177-bp157.2.142.1.aarch64.rpm chromium-146.0.7680.177-bp157.2.142.1.aarch64.rpm chromedriver-146.0.7680.177-bp157.2.142.1.ppc64le.rpm chromium-146.0.7680.177-bp157.2.142.1.ppc64le.rpm openSUSE-2026-116 Security update for osslsigncode critical openSUSE Backports SLE-15-SP7 Update This update for osslsigncode fixes the following issues: - Update to 2.13 (boo#1260680, CVE-2025-70888): * fixed integer overflows when processing APPX compressed data streams * fixed double-free vulnerabilities in APPX file processing * fixed multiple memory corruption issues in PE page hash computation - Changes from 2.12: * fixed a buffer overflow while extracting message digests - Changes from 2.11: * added keyUsage validation for signer certificate * added printing CRL details during signature verification * implemented a workaround for CRL servers returning the HTTP Content-Type header other than application/pkix-crl * fixed HTTP keep-alive handling * fixed macOS compiler and linker flags * fixed undefined BIO_get_fp() behavior with BIO_FLAGS_UPLINK_INTERNAL - update to 2.10: * added JavaScript signing * added PKCS#11 provider support (requires OpenSSL 3.0+) * added support for providers without specifying "-pkcs11module" option * (OpenSSL 3.0+, e.g., for the upcoming CNG provider) * added compatibility with the CNG engine version 1.1 or later * added the "-engineCtrl" option to control hardware and CNG engines * added the '-blobFile' option to specify a file containing the blob content * improved unauthenticated blob support (thanks to Asger Hautop Drewsen) * improved UTF-8 handling for certificate subjects and issuers * fixed support for multiple signerInfo contentType OIDs (CTL and Authenticode) * fixed tests for python-cryptography >= 43.0.0 - update to version 2.9: * added a 64 bit long pseudo-random NONCE in the TSA request * missing NID_pkcs9_signingTime is no longer an error * added support for PEM-encoded CRLs * fixed the APPX central directory sorting order * added a special "-" file name to read the passphrase from stdin * used native HTTP client with OpenSSL 3.x, removing libcurl dependency * added '-login' option to force a login to PKCS11 engines * added the "-ignore-crl" option to disable fetching and verifying CRL Distribution Points * changed error output to stderr instead of stdout * various testing framework improvements * various memory corruption fixes - update to version 2.8: * Microsoft PowerShell signing sponsored by Cisco Systems, Inc. * fixed setting unauthenticated attributes (Countersignature, Unauthenticated * Data Blob) in a nested signature * added the "-index" option to verify a specific signature or modify its unauthenticated attributes * added CAT file verification * added listing the contents of a CAT file with the "-verbose" option * added the new "extract-data" command to extract a PKCS#7 data content to be signed with "sign" and attached with "attach-signature" * added PKCS9_SEQUENCE_NUMBER authenticated attribute support * added the "-ignore-cdp" option to disable CRL Distribution Points (CDP) online verification * unsuccessful CRL retrieval and verification changed into a critical error the "-p" option modified to also use to configured proxy to connect CRL Distribution Points * added implicit allowlisting of the Microsoft Root Authority serial number 00C1008B3C3C8811D13EF663ECDF40 * added listing of certificate chain retrieved from the signature in case of verification failure - update to 2.7.0 * fixed signing CAB files (by Michael Brown) * fixed handling of unsupported commands (by Maxim Bagryantsev) * fixed writing DIFAT sectors * added APPX support (by Maciej Panek and Małgorzata Olszówka) * added a built-in TSA response generation (-TSA-certs, -TSA-key and -TSA-time options) * added verification of CRLs specified in the signing certificate * added MSI DIFAT sectors support (by Max Bagryantsev) * added the "-h" option to set the cryptographic hash function for the "attach -signature" and "add" commands * set the default hash function to "sha256" * added the "attach-signature" option to compute and compare the leaf certificate hash for the "add" command * renamed the "-st" option "-time" * updated the "-time" option to also set explicit verification time * added the "-ignore-timestamp" option * removed the "-timestamp-expiration" option * numerous bugfixes * documentation updates osslsigncode-2.13-bp157.2.3.1.src.rpm osslsigncode-2.13-bp157.2.3.1.x86_64.rpm osslsigncode-2.13-bp157.2.3.1.i586.rpm osslsigncode-2.13-bp157.2.3.1.aarch64.rpm osslsigncode-2.13-bp157.2.3.1.ppc64le.rpm osslsigncode-2.13-bp157.2.3.1.s390x.rpm openSUSE-2026-118 Recommended update for etcd moderate openSUSE Backports SLE-15-SP7 Update This update for etcd fixes the following issues: - Update to version 3.6.10: * etcdserver: allow non-admin to fetch member list and alarms * Bump golang.org/x/image to v0.38.0 to resolve GO-2026-4815 * Fix etcdctl endpoint command with option --cluster when auth is enabled - Update to version 3.6.9: * dependency: Bump google.golang.org/grpc from v1.75.0 to 1.79.3 * server/etcdserver: guard unauthenticated endpoints with auth checks * server/etcdserver: enforce auth checks for nested txn ops * build(deps): bump distroless/static-debian12 from `3f2b64e` to `20bc6c0` * Revert "Reuse events between sync loops" * Bump golang.org/x/net@ v0.51.0 fixes GO-2026-4559 * Don't reuse same ReadIndex * etcdctl: add license header * etcdctl: add unit test for Argify * etcdctl: fix slice bounds trimming single-quoted args * Add defer-recover block to prevent panic when cc is nil * Print the endpoint the grpc client connected to in unary interceptor * Fix race berween read index and leader change causing a stale read * server/etcdmain: fix deadlock issue for grpcproxy * dependency: bump go.opentelemetry.io/otel/sdk from v1.34.0 to v1.40.0 * server/etcdserver/api/v3rpc: run metrics interceptors before handlers - Update to version 3.6.8: * version: bump up to 3.6.8 * [release-3.6] Bump go version to 1.24.13 * Remove the use of grpc-go's Metadata field * Bump go version to 1.24.11 * Keep the --snapshot-count flag * Remove flag --max-snapshots in 3.8 rather than 3.7 * tools: explicitly require golang.org/x/tools/cmd/goimports * dependency: Bump golang.org/x/crypto from 0.42.0 to 0.45.0 - Update to version 3.6.7: * dependency: Bump golang.org/x/net from 0.38.0 to 0.45.0 * Bump go to 1.24.11 * Print token fingerprint instead of the original tokens in log messages - Update to version 3.6.6: * v3rpc: add and use getServerMetrics() with global metricsServerCached * Fix the '--force-new-cluster' can't clean up learners issue * etcdserver: follow convention to extract auth token in cluster_util.go * etcdserver: fix cannot promote with auth from follower * Fix endpoint status not retuning the correct storage quota * server/embed: Log EOF on DEBUG in TLS handshake * Reject watch request with -1 revision and make rangeEvents safe against negative revision etcd-3.6.10-bp157.2.12.1.src.rpm etcd-3.6.10-bp157.2.12.1.x86_64.rpm etcdctl-3.6.10-bp157.2.12.1.x86_64.rpm etcdutl-3.6.10-bp157.2.12.1.x86_64.rpm etcd-3.6.10-bp157.2.12.1.aarch64.rpm etcdctl-3.6.10-bp157.2.12.1.aarch64.rpm etcdutl-3.6.10-bp157.2.12.1.aarch64.rpm etcd-3.6.10-bp157.2.12.1.ppc64le.rpm etcdctl-3.6.10-bp157.2.12.1.ppc64le.rpm etcdutl-3.6.10-bp157.2.12.1.ppc64le.rpm etcd-3.6.10-bp157.2.12.1.s390x.rpm etcdctl-3.6.10-bp157.2.12.1.s390x.rpm etcdutl-3.6.10-bp157.2.12.1.s390x.rpm openSUSE-2026-119 Recommended update for virtme moderate openSUSE Backports SLE-15-SP7 Update This update for virtme fixes the following issues: - Update to 1.41: * Improve the consistency and reliability of the guest init process (virtme-ng-init / virtme-init). * Broader support across different distributions and architectures, including better compatibility with minimal rootfs environments. * Debugging capabilities have been enhanced with support for customizing the GDB port for each guest session. * Networking has been refined as well, with improved SSH handling and new options for PCI device passthrough via --vfio-pci. * Integration with AI agents has also been enhanced. In particular, vng can now be used more effectively in non-interactive sessions, allowing AI agents to automate fairly advanced workflows for kernel testing and patch validation. virtme-1.41-bp157.2.18.1.noarch.rpm virtme-1.41-bp157.2.18.1.src.rpm openSUSE-2026-123 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: Chromium 147.0.7727.55 (boo#1261758): * CVE-2026-5858: Heap buffer overflow in WebML * CVE-2026-5859: Integer overflow in WebML * CVE-2026-5860: Use after free in WebRTC * CVE-2026-5861: Use after free in V8 * CVE-2026-5862: Inappropriate implementation in V8 * CVE-2026-5863: Inappropriate implementation in V8 * CVE-2026-5864: Heap buffer overflow in WebAudio * CVE-2026-5865: Type Confusion in V8 * CVE-2026-5866: Use after free in Media * CVE-2026-5867: Heap buffer overflow in WebML * CVE-2026-5868: Heap buffer overflow in ANGLE * CVE-2026-5869: Heap buffer overflow in WebML * CVE-2026-5870: Integer overflow in Skia * CVE-2026-5871: Type Confusion in V8 * CVE-2026-5872: Use after free in Blink * CVE-2026-5873: Out of bounds read and write in V8 * CVE-2026-5874: Use after free in PrivateAI * CVE-2026-5875: Policy bypass in Blink * CVE-2026-5876: Side-channel information leakage in Navigation * CVE-2026-5877: Use after free in Navigation * CVE-2026-5878: Incorrect security UI in Blink * CVE-2026-5879: Insufficient validation of untrusted input in ANGLE * CVE-2026-5880: Incorrect security UI in browser UI * CVE-2026-5881: Policy bypass in LocalNetworkAccess * CVE-2026-5882: Incorrect security UI in Fullscreen * CVE-2026-5883: Use after free in Media * CVE-2026-5884: Insufficient validation of untrusted input in Media * CVE-2026-5885: Insufficient validation of untrusted input in WebML * CVE-2026-5886: Out of bounds read in WebAudio * CVE-2026-5887: Insufficient validation of untrusted input in Downloads * CVE-2026-5888: Uninitialized Use in WebCodecs * CVE-2026-5889: Cryptographic Flaw in PDFium * CVE-2026-5890: Race in WebCodecs * CVE-2026-5891: Insufficient policy enforcement in browser UI * CVE-2026-5892: Insufficient policy enforcement in PWAs * CVE-2026-5893: Race in V8 * CVE-2026-5894: Inappropriate implementation in PDF * CVE-2026-5895: Incorrect security UI in Omnibox * CVE-2026-5896: Policy bypass in Audio * CVE-2026-5897: Incorrect security UI in Downloads * CVE-2026-5898: Incorrect security UI in Omnibox * CVE-2026-5899: Incorrect security UI in History Navigation * CVE-2026-5900: Policy bypass in Downloads * CVE-2026-5901: Policy bypass in DevTools * CVE-2026-5902: Race in Media * CVE-2026-5903: Policy bypass in IFrameSandbox * CVE-2026-5904: Use after free in V8 * CVE-2026-5905: Incorrect security UI in Permissions * CVE-2026-5906: Incorrect security UI in Omnibox * CVE-2026-5907: Insufficient data validation in Media * CVE-2026-5908: Integer overflow in Media * CVE-2026-5909: Integer overflow in Media * CVE-2026-5910: Integer overflow in Media * CVE-2026-5911: Policy bypass in ServiceWorkers * CVE-2026-5912: Integer overflow in WebRTC * CVE-2026-5913: Out of bounds read in Blink * CVE-2026-5914: Type Confusion in CSS * CVE-2026-5915: Insufficient validation of untrusted input in WebML * CVE-2026-5918: Inappropriate implementation in Navigation * CVE-2026-5919: Insufficient validation of untrusted input in WebSockets * enforce a num,ber of new Local Area Network (LAN) restrictions * New Web Printing API * vertical tabs support (trial) - new in 147 (for developers): * Element-scoped view transitions exposes startViewTransition on arbitrary HTML elements. * CSS contrast-color() helps meet accessibility requirements * The CSS border-shape property lets you create non-rectangular borders * CVE-2025-4096: Heap buffer overflow in HTML * CVE-2025-4050: Out of bounds memory access in DevTools * CVE-2025-4051: Insufficient data validation in DevTools * CVE-2025-4052: Inappropriate implementation in DevTools * CVE-2024-7000: Use after free in CSS * CVE-2024-3834: Use after free in Downloads * CVE-2020-6465: Use after free in reader mode * CVE-2020-6466: Use after free in media * CVE-2020-6467: Use after free in WebRTC * CVE-2020-6468: Type Confusion in V8 * CVE-2020-6469: Insufficient policy enforcement in developer tools * CVE-2020-6470: Insufficient validation of untrusted input in clipboard * CVE-2020-6471: Insufficient policy enforcement in developer tools * CVE-2020-6472: Insufficient policy enforcement in developer tools * CVE-2020-6473: Insufficient policy enforcement in Blink * CVE-2020-6474: Use after free in Blink * CVE-2020-6475: Incorrect security UI in full screen * CVE-2020-6476: Insufficient policy enforcement in tab strip * CVE-2020-6477: Inappropriate implementation in installer * CVE-2020-6478: Inappropriate implementation in full screen * CVE-2020-6479: Inappropriate implementation in sharing * CVE-2020-6480: Insufficient policy enforcement in enterprise * CVE-2020-6481: Insufficient policy enforcement in URL formatting * CVE-2020-6482: Insufficient policy enforcement in developer tools * CVE-2020-6483: Insufficient policy enforcement in payments * CVE-2020-6484: Insufficient data validation in ChromeDriver * CVE-2020-6485: Insufficient data validation in media router * CVE-2020-6486: Insufficient policy enforcement in navigations * CVE-2020-6487: Insufficient policy enforcement in downloads * CVE-2020-6488: Insufficient policy enforcement in downloads * CVE-2020-6489: Inappropriate implementation in developer tools * CVE-2020-6490: Insufficient data validation in loader * CVE-2020-6491: Incorrect security UI in site information * CVE-2019-5754: Inappropriate implementation in QUIC Networking * CVE-2019-5782: Inappropriate implementation in V8 * CVE-2019-5755: Inappropriate implementation in V8 * CVE-2019-5756: Use after free in PDFium * CVE-2019-5757: Type Confusion in SVG * CVE-2019-5758: Use after free in Blink * CVE-2019-5759: Use after free in HTML select elements * CVE-2019-5760: Use after free in WebRTC * CVE-2019-5761: Use after free in SwiftShader * CVE-2019-5762: Use after free in PDFium * CVE-2019-5763: Insufficient validation of untrusted input in V8 * CVE-2019-5764: Use after free in WebRTC * CVE-2019-5765: Insufficient policy enforcement in the browser * CVE-2019-5766: Insufficient policy enforcement in Canvas * CVE-2019-5767: Incorrect security UI in WebAPKs * CVE-2019-5768: Insufficient policy enforcement in DevTools * CVE-2019-5769: Insufficient validation of untrusted input in Blink * CVE-2019-5770: Heap buffer overflow in WebGL * CVE-2019-5771: Heap buffer overflow in SwiftShader * CVE-2019-5772: Use after free in PDFium * CVE-2019-5773: Insufficient data validation in IndexedDB * CVE-2019-5774: Insufficient validation of untrusted input in SafeBrowsing * CVE-2019-5775: Insufficient policy enforcement in Omnibox * CVE-2019-5776: Insufficient policy enforcement in Omnibox * CVE-2019-5777: Insufficient policy enforcement in Omnibox * CVE-2019-5778: Insufficient policy enforcement in Extensions * CVE-2019-5779: Insufficient policy enforcement in ServiceWorker * CVE-2019-5780: Insufficient policy enforcement * CVE-2019-5781: Insufficient policy enforcement in Omnibox * High CVE-2018-6031: Use after free in PDFium * High CVE-2018-6032: Same origin bypass in Shared Worker * High CVE-2018-6033: Race when opening downloaded files * Medium CVE-2018-6034: Integer overflow in Blink * Medium CVE-2018-6035: Insufficient isolation of devtools from extensions * Medium CVE-2018-6036: Integer underflow in WebAssembly * Medium CVE-2018-6037: Insufficient user gesture requirements in autofill * Medium CVE-2018-6038: Heap buffer overflow in WebGL * Medium CVE-2018-6039: XSS in DevTools * Medium CVE-2018-6040: Content security policy bypass * Medium CVE-2018-6041: URL spoof in Navigation * Medium CVE-2018-6042: URL spoof in OmniBox * Medium CVE-2018-6043: Insufficient escaping with external URL handlers * Medium CVE-2018-6045: Insufficient isolation of devtools from extensions * Medium CVE-2018-6046: Insufficient isolation of devtools from extensions * Medium CVE-2018-6047: Cross origin URL leak in WebGL * Low CVE-2018-6048: Referrer policy bypass in Blink * Low CVE-2017-15420: URL spoofing in Omnibox * Low CVE-2018-6049: UI spoof in Permissions * Low CVE-2018-6050: URL spoof in OmniBox * Low CVE-2018-6051: Referrer leak in XSS Auditor * Low CVE-2018-6052: Incomplete no-referrer policy implementation * Low CVE-2018-6053: Leak of page thumbnails in New Tab Page * Low CVE-2018-6054: Use after free in WebUI * CVE-2017-5070: Type confusion in V8 * CVE-2017-5071: Out of bounds read in V8 * CVE-2017-5072: Address spoofing in Omnibox * CVE-2017-5073: Use after free in print preview * CVE-2017-5074: Use after free in Apps Bluetooth * CVE-2017-5075: Information leak in CSP reporting * CVE-2017-5086: Address spoofing in Omnibox * CVE-2017-5076: Address spoofing in Omnibox * CVE-2017-5077: Heap buffer overflow in Skia * CVE-2017-5078: Possible command injection in mailto handling * CVE-2017-5079: UI spoofing in Blink * CVE-2017-5080: Use after free in credit card autofill * CVE-2017-5081: Extension verification bypass * CVE-2017-5082: Insufficient hardening in credit card editor * CVE-2017-5083: UI spoofing in Blink * CVE-2017-5085: Inappropriate javascript execution on WebUI pages - CVE-2016-1663: Use-after-free in Blink's V8 bindings * CVE-2013-6643: Unprompted sync with an attacker's * Use Google's online spellchecker to identify misspelled words chromedriver-147.0.7727.55-bp157.2.145.1.x86_64.rpm chromium-147.0.7727.55-bp157.2.145.1.nosrc.rpm chromium-147.0.7727.55-bp157.2.145.1.x86_64.rpm chromedriver-147.0.7727.55-bp157.2.145.1.aarch64.rpm chromium-147.0.7727.55-bp157.2.145.1.aarch64.rpm chromedriver-147.0.7727.55-bp157.2.145.1.ppc64le.rpm chromium-147.0.7727.55-bp157.2.145.1.ppc64le.rpm openSUSE-2026-122 Security update for python-Flask-HTTPAuth moderate openSUSE Backports SLE-15-SP7 Update This update for python-Flask-HTTPAuth fixes the following issues: - CVE-2026-34531: Do not accept empty tokens (boo#1261355) python-Flask-HTTPAuth-4.8.0-bp157.2.3.1.src.rpm python311-Flask-HTTPAuth-4.8.0-bp157.2.3.1.noarch.rpm openSUSE-2026-127 Recommended update for certbot-systemd-timer moderate openSUSE Backports SLE-15-SP7 Update This update for certbot-systemd-timer fixes the following issues: - Require just 'certbot' to work with any python flavour - Fix build with RPM 4.20: referencing ../ in %doc/%license is not guaranteed. certbot-systemd-timer-0.0-bp157.2.3.1.noarch.rpm certbot-systemd-timer-0.0-bp157.2.3.1.src.rpm openSUSE-2026-143 Security update for coturn moderate openSUSE Backports SLE-15-SP7 Update This update for coturn fixes the following issues: - Update to version 4.9.0 * Multiple security fixes. * Fix to Web Admin password check. * Cleanup of deprecated openssl APIs. * CVE-2026-27624: bypass localhost and IP range block using IPv4-mapped IPv6. (boo#1258847) - Update to version 4.8.0 * Faster packet validation on listener threads to improve handling of DDoS attacks. * Make socket buffer size configurable with sock-buf-size. * Address memory leaks and potential crashes. * CVE-2025-69217: Improve random number usage to address (boo#1255744) - Update to version 4.7.0 * Breaking changes in order to get to sane defaults for improved security by default + Support for openssl 1.1.1 and 3.x only. + Cleanup deprecated options - if your scripts have them turnserver will fail to start. + Reverse SOFTWARE_ATTRIBUTE_OPT to avoid inverse logic - now need to explicitly enable it. + Deprecate response-origin-only-with-rfc5780. + Invert no-stun-backward-compatibility to be default on. * TLSv1 and TLSv1_1 are now optional (no need to turn them off). * Minor bug fixes and regressions. * Improved support for modern version of prometheus. - Upgrade to coturn 4.6.3 * Release highlights: - Multiple memory fixes - New drain feature - Better support for new versions of Redis - Add support for raw public keys * Complete change list - Add clang-tidy, include-what-you-use, and msvc-analyzer github actions - Add CodeQL workflow - added missing function prototype of turn_random_number() - Added sessionID to some log lines - added support for amazon linux and renamed tests.yml - added warnings for prometheus apt unavailability - Add github action that runs tests with compiler sanitizers - Additional refactoring of ns_turn_allocation.* to address security scanner concerns - Add MariaDB support to README.md - Add new Drain feature - Add prometheus setting suggestions on turn.conf in example folder - Address clang-tidy warnings in db files - Address some build issues introduced by api changes - Add support for raw public keys - Add the InsertBraces command for clang-format to ensure that all conditionals always have braces - Add warning and disable web admin if no-tls option used - Adjust wording in cmake message when prometheous cannot be found. - Allow authenticating with a username to redis - Always run lint, regardless of branch - Avoid nullptr dereference of server variable in various functions - avoid potential nullptr derefernence in udp_create_server_socket - Avoid read-past-end of string in get_bold_admin_title - Avoid writing potentially uninitialized data to aes_128 key file - changed variables in stunclient.c to bool - Change minimal required cmake version to 3.16 - Change printf() to TURN_LOG_FUNC() for --no-stdout-log - Change the various map functions to return bool instead of inconsistantly return 0, 1, or -1 - Check allocation results in add_static_user_account - Check the result of calloc in handle_logon_request - Check the result of malloc in del_alt_server - Check the result of malloc in mongo_set_realm_option_one - Check the result of malloc in send_message_to_redis - Check the result of malloc in string_list_add - Check the result of realloc and calloc in ch_map_get - CMake: Declare the variable nearby - configure: data files shouldn't be executable - defined a magic number for stun fingerprinting - Delete dead code - Delete unused variable - Doc: add flowchart - Easy installation of coturn on AWS - Fix buffer overflow in generate_enc_password with increase rsalt by 2 - Fix build with libressl 3.6+ - Fix clang-format lint warnings - Fix cli auth - Fix Cmake find issue in libevent - Fix cmake find prometheus(fix #1304) - Fix compiler warnings from continuous integration - Fix const during free warning in rfc5769check app - Fix error of make command in Cygwin environment - Fix formatting to fix lint error - Fix lint complaint about comment - Fix lint errors - Fix linting error in mainrelay.c - Fix make lint - Fix memcpy len checks stun_is_challenge_response_str - Fix memleak in pgsql_reread_realms - Fix memory leak in netengine.c - Fix memory leak in rfc5769check.c - Fix memory leak on http_server.c - Fix mingw build - Fix missing strncpy in fix_stun_check_message_integrity_str - Fix msvc analyzer error on goto label on rfc5769check - Fix nodejs/glibc problem with old container images. - Fix no-tls warning typo - Fix potential null passed to function expecting nonnull - Fix recursive call in delete alternate server - Fix return correct error code for `create_relay_connection` in case of `RESERVATION-TOKEN` failure - Fix rpm version scripts - Fix run cmake.yml in any github action - Fix typos - Fix ubuntu 16 build with GH action checkout version to v3 - Implement custom prometheus http handler - Include what you use - Install openssl-1.1.1 on amazonlinux:2 instead of openssl-1.0.1 - malloc now allocates space for string terminator - Memset user_db before reading conf file, not after - Missing session ID in coturn logs for denied IP - 1330 - Move the hiredis_libevent2 code from common to relay - Only set MHD_USE_DUAL_STACK if IPv6 is available - Print version only, no extra lines - Reduce ifdefs in code: TURN_NO_PROMETHEUS - Refactor: peer_input_handle - Reformat code - Remove unimplemented test folder reference from CMakeLists.txt - Replace HeapAlloc with malloc - Replace srand/rand with srandom/random - Return a 400 response to HTTP requests - Run all of the CI except for Docker builds on any change - Simplify macOS detection macros - Simplify workflow for codeql - strncpy doesn't return size_t - ubuntu build dependencies extracted to composite actions - Update FlowChart - Update libtelnet - Update lukka/run - Update SQLite.md - Update turnserver.conf Example about listening-ip - Update turnserver.spec - Update version in vcpkg.json - Use active CPU number instead of total number - Use bool, instead of int, for the functions in ns_turn_msg.c - Use bool over int for the turnutils_uclient program - Use calloc where appropriate, avoid memset when normal buffer initialization works - Windows: Only attempt to bind when the network interface is up - workflow tidying - Don't hard require systemd -- not needed in containers - enable 'verbose' log to see listening IPs and more, not just server start/stop - have a meaningful turnserver.conf.default - create a ready-to-run turnserver.conf - fix logrotate script - Update README.SUSE for Let's Encrypt Certificates - move certs to /etc/coturn/tls - Update apparmor profile - rework sysusers.d config file coturn-4.9.0-bp157.2.3.1.src.rpm coturn-4.9.0-bp157.2.3.1.x86_64.rpm coturn-debuginfo-4.9.0-bp157.2.3.1.x86_64.rpm coturn-debugsource-4.9.0-bp157.2.3.1.x86_64.rpm coturn-devel-4.9.0-bp157.2.3.1.x86_64.rpm coturn-utils-4.9.0-bp157.2.3.1.x86_64.rpm coturn-utils-debuginfo-4.9.0-bp157.2.3.1.x86_64.rpm coturn-4.9.0-bp157.2.3.1.aarch64.rpm coturn-debuginfo-4.9.0-bp157.2.3.1.aarch64.rpm coturn-debugsource-4.9.0-bp157.2.3.1.aarch64.rpm coturn-devel-4.9.0-bp157.2.3.1.aarch64.rpm coturn-utils-4.9.0-bp157.2.3.1.aarch64.rpm coturn-utils-debuginfo-4.9.0-bp157.2.3.1.aarch64.rpm coturn-4.9.0-bp157.2.3.1.ppc64le.rpm coturn-debuginfo-4.9.0-bp157.2.3.1.ppc64le.rpm coturn-debugsource-4.9.0-bp157.2.3.1.ppc64le.rpm coturn-devel-4.9.0-bp157.2.3.1.ppc64le.rpm coturn-utils-4.9.0-bp157.2.3.1.ppc64le.rpm coturn-utils-debuginfo-4.9.0-bp157.2.3.1.ppc64le.rpm coturn-4.9.0-bp157.2.3.1.s390x.rpm coturn-debuginfo-4.9.0-bp157.2.3.1.s390x.rpm coturn-debugsource-4.9.0-bp157.2.3.1.s390x.rpm coturn-devel-4.9.0-bp157.2.3.1.s390x.rpm coturn-utils-4.9.0-bp157.2.3.1.s390x.rpm coturn-utils-debuginfo-4.9.0-bp157.2.3.1.s390x.rpm openSUSE-2026-133 Recommended update for gitea-tea moderate openSUSE Backports SLE-15-SP7 Update This update for gitea-tea fixes the following issues: - update to 0.13.0: * docs: add v0.13.0 release notes to CHANGELOG (#945) * feat(pulls): add edit subcommand for pull requests (#944) * fix(deps): update module github.com/go-git/go-git/v5 to v5.17.2 (#943) * fix(deps): update module github.com/go-git/go-git/v5 to v5.17.1 (#942) * fix(deps): update module code.gitea.io/sdk/gitea to v0.24.1 (#936) * fix(deps): update module github.com/go-authgate/sdk-go to v0.6.1 (#935) * fix(deps): update module github.com/urfave/cli/v3 to v3.8.0 (#937) * replace log.Fatal/os.Exit with error returns (#941) * chore(deps): update docker.gitea.com/gitea docker tag to v1.25.5 (#934) * fix(deps): update module github.com/olekukonko/tablewriter to v1.1.4 (#933) * chore(deps): update mcr.microsoft.com/devcontainers/go docker tag to v2.1 (#930) * chore(deps): update Go dependencies and CI workflow action versions (#932) * feat(repos): support owner-based repository listing with robust lookup (#931) * feat(repos): add repo edit subcommand (#928) * feat: store OAuth tokens in OS keyring via credstore (#926) * add function comment * make vet&fmt pass * Update to charm libraries v2 (#923) * fix(deps): update module golang.org/x/oauth2 to v0.36.0 (#919) * go 1.26 * fix(deps): update module github.com/go-git/go-git/v5 to v5.17.0 (#910) * Parse multiple values in api subcommand (#911) gitea-tea-0.13.0-bp157.2.18.1.src.rpm gitea-tea-0.13.0-bp157.2.18.1.x86_64.rpm gitea-tea-bash-completion-0.13.0-bp157.2.18.1.noarch.rpm gitea-tea-zsh-completion-0.13.0-bp157.2.18.1.noarch.rpm gitea-tea-0.13.0-bp157.2.18.1.i586.rpm gitea-tea-0.13.0-bp157.2.18.1.aarch64.rpm gitea-tea-0.13.0-bp157.2.18.1.ppc64le.rpm gitea-tea-0.13.0-bp157.2.18.1.s390x.rpm openSUSE-2026-135 Security update for kubo moderate openSUSE Backports SLE-15-SP7 Update This update for kubo fixes the following issues: - Update to 0.40.1 * IPIP-499: UnixFS CID Profiles * Automatic cleanup of interrupted imports * Light clients can now use your node for delegated routing * See total size when pinning * IPIP-523: ?format= takes precedence over Accept header * IPIP-524: Gateway codec conversion disabled by default * More reliable IPNS over PubSub * New ipfs diag datastore commands * New ipfs swarm addrs autonat command * Improved ipfs p2p tunnels with foreground mode * Friendlier ipfs dag stat output * ipfs key improvements * More reliable content providing after startup * No unnecessary DNS lookups for AutoTLS addresses * Configurable gateway request duration limit * Recovery from corrupted MFS root * RPC Content-Type headers for binary responses * New ipfs name get|put commands * Long listing format for ipfs ls * WebUI Improvements * Fixed Prometheus metrics bloat on popular subdomain gateways * libp2p announces all interface addresses * Badger v1 datastore slated for removal this year * Go 1.26 * Dependency updates - github.com/ipld/go-ipld-prime v0.22.0 (boo#1261818, CVE-2026-35480) - Update to 0.39.0 * Made DHT Sweep provider the default * Fast root CID providing for immediate content discovery * Persist provider state across restarts * Detailed statistics with ipfs provide stat * Add warnings about slow reprovide * Rename: provider_provides_total * Automatic UPnP recovery after router restarts * No longer publish deprecated go-ipfs name * Limit for gateway range request for CDN compatibility - golang.org/x/net v0.47.0 (boo#1251613, CVE-2025-58190, boo#1251419, CVE-2025-47911) - golang.org/x/crypto v0.45.0 (boo#1253857, CVE-2025-58181) - 0.38.0 * Repository migration: simplified provide configuration * Add Experimental Sweeping DHT Provider * Expose DHT metrics * Improve gateway error pages with diagnostic tools * Update WebUI * Pin name improvements * Enforce identity CID size and ipfs files write fixes * Provide Filestore and Urlstore blocks on write * Limit MFS operation for --flush=false - Bump golang build requirement to 1.25 - Update to 0.37.0: * Anonymous telemetry for better feature prioritization * Repository migration from v16 to v17 with embedded tooling * Gateway concurrent request limits and retrieval timeouts * AutoConf: Complete control over network defaults * Clear provide queue when reprovide strategy changes * Revamped ipfs log level command * Named pins in ipfs add command * New IPNS publishing options * Custom sequence numbers in ipfs name publish * Reprovider.Strategy is now consistently respected * Reprovider.Strategy=all: improved memory efficiency * Removed unnecessary dependencies * Improved ipfs cid * Deprecated ipfs stats reprovide * AutoRelay now uses all connected peers for relay discovery * Full changelog at https://github.com/ipfs/kubo/releases/tag/v0.37.0 - Update to 0.36.0: * Full changelog at https://github.com/ipfs/kubo/releases/tag/v0.36.0 * HTTP Retrieval Client Now Enabled by Default * Bitswap Broadcast Reduction * Update go-log to v2 * Kubo now uses AutoNATv2 as a client * Overwrite option for files cp command * Gateway now supports negative HTTP Range requests * Option for filestore command to remove bad blocks * ConnMgr.SilencePeriod configuration setting exposed * Fix handling of EDITOR env var * Dependency updates kubo-0.40.1-bp157.2.9.1.src.rpm kubo-0.40.1-bp157.2.9.1.x86_64.rpm kubo-0.40.1-bp157.2.9.1.i586.rpm kubo-0.40.1-bp157.2.9.1.aarch64.rpm kubo-0.40.1-bp157.2.9.1.ppc64le.rpm kubo-0.40.1-bp157.2.9.1.s390x.rpm openSUSE-2026-129 Security update for python-jwcrypto important openSUSE Backports SLE-15-SP7 Update This update for python-jwcrypto fixes the following issues: - CVE-2022-3102: jwcrypto token substitution can lead to authentication bypass (boo#1209496) - CVE-2023-6681: denial of service Via specifically crafted JWE (boo#1219837) - CVE-2024-28102: malicious JWE token can cause denial of service (boo#1221230) - CVE-2026-39373: Memory exhaustion via crafted compressed JWE tokens (boo#1261802) python-jwcrypto-0.7-bp157.2.3.1.src.rpm python3-jwcrypto-0.7-bp157.2.3.1.noarch.rpm openSUSE-2026-136 Recommended update for mkdud moderate openSUSE Backports SLE-15-SP7 Update This update for mkdud fixes the following issues: version 2.6: - merge gh#openSUSE/mkdud#49 - fix "How to apply" report - minor spec file adjustments version 2.5: - merge gh#openSUSE/mkdud#48 - align with latest Agama adjustment and support Slowroll (boo#1261030) - adapt to also work with xorriso (boo#1260860) - simplify spec file - update documentation version 2.4: - merge gh#openSUSE/mkdud#47 - de-duplicate files to reduce size (boo#1258149) - update dist handling to match our official product naming more closely - update supported architecture list version 2.3: - merge gh#openSUSE/mkdud#46 - make dependence on osc package optional (boo#1254110) mkdud-2.6-bp157.2.9.1.noarch.rpm mkdud-2.6-bp157.2.9.1.src.rpm openSUSE-2026-140 security update to Chromium 147.0.7727.101 (boo#1262174) low openSUSE Backports SLE-15-SP7 Update security update to Chromium 147.0.7727.101 (boo#1262174) chromedriver-147.0.7727.101-bp157.2.148.1.x86_64.rpm chromium-147.0.7727.101-bp157.2.148.1.nosrc.rpm chromium-147.0.7727.101-bp157.2.148.1.x86_64.rpm chromedriver-147.0.7727.101-bp157.2.148.1.aarch64.rpm chromium-147.0.7727.101-bp157.2.148.1.aarch64.rpm chromedriver-147.0.7727.101-bp157.2.148.1.ppc64le.rpm chromium-147.0.7727.101-bp157.2.148.1.ppc64le.rpm openSUSE-2026-145 Security update for ocaml-patch, opam moderate openSUSE Backports SLE-15-SP7 Update This update for ocaml-patch, opam fixes the following issues: Changes in opam: - Update to version 2.5.1 (CVE-2026-41082 boo#1262281) see included CHANGES file for details - Update to version 2.5.0 see included CHANGES file for details - Update to version 2.4.1 see included CHANGES file for details - Update to version 2.4.0 see included CHANGES file for details Changes in ocaml-patch: - Relax requirement for ocaml-rpm-macros, remove ExclusiveArch - Update to version 3.1.0 see included CHANGES.md file for details - Initial version 3.0.0 ocaml-patch-3.1.0-bp157.2.1.src.rpm ocaml-patch-3.1.0-bp157.2.1.x86_64.rpm ocaml-patch-debuginfo-3.1.0-bp157.2.1.x86_64.rpm ocaml-patch-devel-3.1.0-bp157.2.1.x86_64.rpm opam-2.5.1-bp157.2.3.1.src.rpm opam-2.5.1-bp157.2.3.1.x86_64.rpm opam-devel-2.5.1-bp157.2.3.1.x86_64.rpm opam-installer-2.5.1-bp157.2.3.1.x86_64.rpm ocaml-patch-3.1.0-bp157.2.1.i586.rpm ocaml-patch-debuginfo-3.1.0-bp157.2.1.i586.rpm ocaml-patch-devel-3.1.0-bp157.2.1.i586.rpm ocaml-patch-3.1.0-bp157.2.1.aarch64.rpm ocaml-patch-debuginfo-3.1.0-bp157.2.1.aarch64.rpm ocaml-patch-devel-3.1.0-bp157.2.1.aarch64.rpm opam-2.5.1-bp157.2.3.1.aarch64.rpm opam-devel-2.5.1-bp157.2.3.1.aarch64.rpm opam-installer-2.5.1-bp157.2.3.1.aarch64.rpm ocaml-patch-3.1.0-bp157.2.1.ppc64le.rpm ocaml-patch-debuginfo-3.1.0-bp157.2.1.ppc64le.rpm ocaml-patch-devel-3.1.0-bp157.2.1.ppc64le.rpm opam-2.5.1-bp157.2.3.1.ppc64le.rpm opam-devel-2.5.1-bp157.2.3.1.ppc64le.rpm opam-installer-2.5.1-bp157.2.3.1.ppc64le.rpm ocaml-patch-3.1.0-bp157.2.1.s390x.rpm ocaml-patch-debuginfo-3.1.0-bp157.2.1.s390x.rpm ocaml-patch-devel-3.1.0-bp157.2.1.s390x.rpm opam-2.5.1-bp157.2.3.1.s390x.rpm opam-devel-2.5.1-bp157.2.3.1.s390x.rpm opam-installer-2.5.1-bp157.2.3.1.s390x.rpm openSUSE-2026-147 Security update for tor moderate openSUSE Backports SLE-15-SP7 Update This update for tor fixes the following issues: - update to 0.4.8.23: * Fix a memory compare using the wrong length. This could lead to a remote crash when using the conflux subsystem (TROVE-2026-004, boo#1262302) * Fix a series of defense in depth security issues found across the codebase * Regenerate fallback directories generated on March 25, 2026. * Update the geoip files to match the IPFire Location Database, as retrieved on 2026/03/25. - includes changes from 0.4.8.22: * Avoid an out-of-bounds read error that could occur with V1-formatted EXTEND cells (TROVE-2025-016, boo#1262301) * Allow old clients to fetch the consensus even if they use version 0 of the SENDME protocol * Do not check for compression bombs for buffers smaller than 5MB (increased from 64 KB) * Improvements to directory server statistics - update to 0.4.8.21: * This release is a continuation of the previous one and addresses additional Conflux-related issues identified through further testing and feedback from relay operators. We strongly recommend upgrading as soon as possible. * Major bugfixes (conflux, exit): - When dequeuing out-of-order conflux cells, the circuit could be close in between two dequeue which could lead to a mishandling of a NULL pointer. Fixes bug 41162; * Add -mbranch-protection=standard for arm64. * Regenerate fallback directories generated on November * Update the geoip files to match the IPFire Location Database, as retrieved on 2025/11/17. * Fix a bug causing the initial tor process to hang intead of exiting with RunAsDaemon, when pluggable transports are used. - 0.4.8.20 * Add a new hardening compiler flag -fcf-protection=full * Fix the root cause of some conflux fragile asserts * Fix a series of conflux edge cases - 0.4.8.19 * Fix some clients not being able to connect to LibreSSL relays * Improve stream flow control performance tor-0.4.8.23-bp157.2.6.1.src.rpm tor-0.4.8.23-bp157.2.6.1.x86_64.rpm tor-debuginfo-0.4.8.23-bp157.2.6.1.x86_64.rpm tor-debugsource-0.4.8.23-bp157.2.6.1.x86_64.rpm tor-0.4.8.23-bp157.2.6.1.aarch64.rpm tor-debuginfo-0.4.8.23-bp157.2.6.1.aarch64.rpm tor-debugsource-0.4.8.23-bp157.2.6.1.aarch64.rpm tor-0.4.8.23-bp157.2.6.1.ppc64le.rpm tor-debuginfo-0.4.8.23-bp157.2.6.1.ppc64le.rpm tor-debugsource-0.4.8.23-bp157.2.6.1.ppc64le.rpm tor-0.4.8.23-bp157.2.6.1.s390x.rpm tor-debuginfo-0.4.8.23-bp157.2.6.1.s390x.rpm tor-debugsource-0.4.8.23-bp157.2.6.1.s390x.rpm openSUSE-2026-141 Security update for roundcubemail important openSUSE Backports SLE-15-SP7 Update This update for roundcubemail fixes the following issues: - update to 1.6.15 This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to some regressions introduced in the previous release as well a recently reported security vulnerability: SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm. This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating! + Fix regression where mail search would fail on non-ascii search criteria (#10121) + Fix regression where some data url images could get ignored/lost (#10128) + Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke (boo#1261157) - update to 1.6.14 This is a security update to the stable version 1.6 of Roundcube Webmail. + Fix Postgres connection using IPv6 address (#10104) + Security: Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler (boo#1261488, CVE-2026-35537) + Security: Fix bug where a password could get changed without providing the old password + Security: Fix IMAP Injection + CSRF bypass in mail search + Security: Fix remote image blocking bypass via various SVG animate attributes + Security: Fix remote image blocking bypass via a crafted body background attribute + Security: Fix fixed position mitigation bypass via use of !important + Security: Fix XSS issue in a HTML attachment preview + Security: Fix SSRF + Information Disclosure via stylesheet links to a local network hosts roundcubemail-1.6.15-bp157.2.9.1.noarch.rpm roundcubemail-1.6.15-bp157.2.9.1.src.rpm openSUSE-2026-142 Security update for Botan important openSUSE Backports SLE-15-SP7 Update This update for Botan fixes the following issues: - CVE-2026-34582: client authentication bypass in TLS 1.3 implementation (boo#1261880) Botan-3.5.0-bp157.2.3.1.src.rpm Botan-3.5.0-bp157.2.3.1.x86_64.rpm Botan-doc-3.5.0-bp157.2.3.1.noarch.rpm libbotan-3-5-3.5.0-bp157.2.3.1.x86_64.rpm libbotan-devel-3.5.0-bp157.2.3.1.x86_64.rpm python3-botan-3.5.0-bp157.2.3.1.x86_64.rpm Botan-3.5.0-bp157.2.3.1.i586.rpm libbotan-3-5-3.5.0-bp157.2.3.1.i586.rpm libbotan-3-5-32bit-3.5.0-bp157.2.3.1.x86_64.rpm libbotan-devel-3.5.0-bp157.2.3.1.i586.rpm libbotan-devel-32bit-3.5.0-bp157.2.3.1.x86_64.rpm python3-botan-3.5.0-bp157.2.3.1.i586.rpm Botan-3.5.0-bp157.2.3.1.aarch64.rpm libbotan-3-5-3.5.0-bp157.2.3.1.aarch64.rpm libbotan-3-5-64bit-3.5.0-bp157.2.3.1.aarch64_ilp32.rpm libbotan-devel-3.5.0-bp157.2.3.1.aarch64.rpm libbotan-devel-64bit-3.5.0-bp157.2.3.1.aarch64_ilp32.rpm python3-botan-3.5.0-bp157.2.3.1.aarch64.rpm Botan-3.5.0-bp157.2.3.1.ppc64le.rpm libbotan-3-5-3.5.0-bp157.2.3.1.ppc64le.rpm libbotan-devel-3.5.0-bp157.2.3.1.ppc64le.rpm python3-botan-3.5.0-bp157.2.3.1.ppc64le.rpm Botan-3.5.0-bp157.2.3.1.s390x.rpm libbotan-3-5-3.5.0-bp157.2.3.1.s390x.rpm libbotan-devel-3.5.0-bp157.2.3.1.s390x.rpm python3-botan-3.5.0-bp157.2.3.1.s390x.rpm openSUSE-2026-151 Security update for rclone critical openSUSE Backports SLE-15-SP7 Update This update for rclone fixes the following issues: - Update to version 1.73.5: (boo#1262439 boo#1262438) * operations: add AuthRequired to operations/fsinfo to prevent backend creation CVE-2026-41179 * rc: snapshot NoAuth at startup to prevent runtime auth bypass CVE-2026-41176 * rc: add AuthRequired to options/set to prevent auth bypass CVE-2026-41176 * s3: fix empty delimiter parameter rejected by Archiware P5 server * azureblob/auth: add Microsoft Partner Network User-Agent prefix * drime: fix User.EntryPermissions JSON unmarshalling * filter: fix debug logs that fire before logger is configured - fixes #9291 * s3: fix TencentCOS CDN endpoint failing on bucket check * iclouddrive: fix 'directory not found' error when the directory contains accent marks * Start v1.73.5-DEV development - Update to version 1.73.4: * Version v1.73.4 * Update to go 1.25.9 to fix multiple CVEs * build: fix Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder * docs: fix markdown issues in mount docs * docs: fix header level for metadata option * fix(docs): Fix link to not be language specific * filen: update SDK version * build(deps): bump golang.org/x/image from 0.36.0 to 0.38.0 * docs: note macOS 10.15 (Catalina) support with version v1.70.3 * Start v1.73.4-DEV development - Update to version 1.73.3: (CVE-2026-33186 GHSA-6g7g-w4f8-9c9x) * Version v1.73.3 * build(deps): bump github.com/buger/jsonparser from 1.1.1 to 1.1.2 * docs/jottacloud: fix broken link * docs: clarify Filen password change requires updating both password and API key in rclone config * docs: note that Filen API key changes on password change * build(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.3 * s3: add multi tenant support for Cubbit * lib/rest: fix URLPathEscapeAll breaking WebDAV servers (eg nzbdav) with strict path matching * list: fix nil pointer panic in Sorter when temp file creation fails * docs: update RELEASE procedure to avoid mistakes * docs: added text to the label showing version-introduced info * Start v1.73.3-DEV development * docs: update sponsors - Update to version 1.73.2: * Version v1.73.2 * Update to go 1.25.8 to fix multiple CVEs * build: update to golang.org/x/net v0.51.0 to fix CVE-2026-27141 #9220 * docs: fix new drive flag typo in changelog * webdav: add missing headers for CORS * docs: Document unsupported S3 object keys with double slashes * docs: note that --use-server-modtime only works on some backends * internxt: fix Entry doesn't belong in directory errors on windows * drime: fix chunk-uploaded files ignoring workspace ID * docs: Fix headers hierarchy for mount.md * webdav: escape reserved characters in URL path segments * bisync: add group Sync to the bisync command * archive: extract: strip "./" prefix from tar entry paths * docs: add instructions on how to update Go version * buid: update github.com/cloudflare/circl to v1.6.3 to fix CVE-2026-1229 * Start v1.73.2-DEV development - Update to version 1.73.1: * Version v1.73.1 * build: fix build using go 1.26.0 instead of go 1.25.7 * fs/march: fix runtime: program exceeds 10000-thread limit * accounting: fix missing server side stats from core/stats rc * pacer: re-read the sleep time as it may be stale * pacer: fix deadlock between pacer token and --max-connections * build: fix CVE-2025-68121 by updating go to 1.25.7 or later - fixes #9167 * drime: fix files and directories being created in the default workspace * docs: update sponsors * copyurl: Extend copyurl docs with an example of CSV FILENAMEs starting with a path. * internxt: implement re-login under refresh logic, improve retry logic - fixes #9174 * docs: add ExchangeRate-API as a sponsor * build: bump github.com/go-chi/chi/v5 from 5.2.3 to 5.2.5 to fix GO-2026-4316 * Set list_version to 2 for FileLu S3 configuration * filelu: add multipart upload support with configurable cutoff * filelu: add multipart init response type * filelu: add comment for response body wrapping * filelu: avoid buffering entire file in memory * docs: update sponsor logos * filen: fix potential panic in case of error during upload * filen: fix 32 bit targets not being able to list directories Fixes #9142 * Start v1.73.1-DEV development - Update to version 1.73.0: * Version v1.73.0 * drive: fix crash when trying to creating shortcut to a Google doc * azureblob,azurefiles: factor the common auth into a library * test: allow backends to return fs.ErrorCantListRoot to skip Root tests * build: add privatebeta Makefile target * docs: add Internxt as a sponsor * internxt: remove use of CVE laden github.com/disintegration/imaging * docs: fix Internxt docs after merge * docs: update making a new backend docs * docs: build overview page from the backend data * docs: add tiering to the documentation - fixes #8873 * docs: add data about each backend in YAML format * docs: add bin/manage_backends.py for managing the backend data files * internxt: use rclone's http.Client to enable more features * internxt: fix lint problems * Add StarHack to contributors * Add lullius to contributors * Add jzunigax2 to contributors * internxt: add Internxt backend - fixes #7610 * drive: add --drive-metadata-force-expansive-access flag - Fixes #8980 * test_all: allow drime more time to complete * onedrive: fix permissions on onedrive Personal * onedrive: fix require sign in for Onedrive Personal * onedrive: Onedrive Personal no longer supports description * onedrive: fix setting modification time on directories for onedrive Personal * onedrive: fix cancelling multipart upload * docs: fix WinFsp link in mount documentation * cmount: make work under OpenBSD - fixes #1727 * vfs: make mount tests run on OpenBSD * docs: improve alignment of icons * protondrive: update to use forks of upstream modules * Add hyusap to contributors * Add Nick Owens to contributors * Add Mikel Olasagasti Uranga to contributors * docs: fix googlephotos custom client_id instructions * cmount: fix OpenBSD mount support. * fs: fix bwlimit: correctly report minutes * fs: fix bwlimit: use %d instead of %q for ints * mega: reverts TLS workaround * docs: fix formatting * docs: add faq entry about re-enabling old TLS ciphers * Add Marc-Philip to contributors * Add yy to contributors * filen: swap to blake3 hashes * docs: fix echo command syntax for password input * docs: fix typos in comments and messages * docs: fix use of removed rem macro * uptobox: remove backend as service is no longer available * rc: add operations/hashsumfile to sum a single file only * docs: update sponsor link * filen: add Filen backend - Fixes #6728 * sftp: fix proxy initialisation * fstest: skip Copy mutation test with --sftp-copy-is-hardlink * fstest: Make Copy mutation test work properly * Add Qingwei Li to contributors * Add Nicolas Dessart to contributors * log: fix systemd adding extra newline - fixes #9086 * oracleobjectstorage, sftp: eliminate unnecessary heap allocation * sftp,ftp: add http proxy authentication support * Add Drime backend * lib/rest: add opts.MultipartContentType to explicitly set Content-Type of attachements * dircache: allow empty string as root parent id * docs: update sponsors * s3: add provider Bizfly Cloud Simple Storage * docs: update sponsor logos * Add sys6101 to contributors * Add darkdragon-001 to contributors * Add vupn0712 to contributors * docs: add cloudinary to readme * docs: fix headers hierarchy in mount docs * s3: fix Copy ignoring storage class * serve s3: make errors in --s3-auth-key fatal - fixes #9044 * Add masrlinu to contributors * pcloud: add support for real-time updates in mount * memory: add --memory-discard flag for speed testing - fixes #9037 * Add vyv03354 to contributors * shade: Fix VFS test issues * docs: mention use of ListR feature in ls docs * build: bump actions/download-artifact from 6 to 7 * build: bump actions/upload-artifact from 5 to 6 * build: bump actions/cache from 4 to 5 * docs: reflects the fact that pCloud supports ListR * S3: Linode: updated endpoints to use ISO 3166-1 alpha-2 standard * sync: fix error propagation in tests (#9025) * Changelog updates from Version v1.72.1 * s3: add more regions for Selectel * Add jhasse-shade to contributors * Add Shade backend * log: fix backtrace not going to the --log-file #9014 * build: fix lint warning after linter upgrade * Add Jonas Tingeborn to contributors * Add Tingsong Xu to contributors * configfile: add piped config support - fixes #9012 * fs/log: fix PID not included in JSON log output * build: adjust lint rules to exclude new errors from linter update * proxy: fix error handling in tests spotted by the linter * Add Johannes Rothe to contributors * Add Leo to contributors * Add Vladislav Tropnikov to contributors * Add Cliff Frey to contributors * Add vicerace to contributors * b2: Fix listing root buckets with unrestricted API key * googlecloudstorage: improve endpoint parameter docs * serve webdav: implement download-directory-as-zip * s3: The ability to specify an IAM role for cross-account interaction * azureblob: add metadata and tags support across upload and copy paths * refactor: use strings.Cut to simplify code * docs: note where a provider has an S3 compatible alternative * Add Shade as sponsor * Add Duncan Smart to contributors * Add Diana to contributors * docs: Clarify OAuth scopes for readonly Google Drive access * b2: support authentication with new bucket restricted application keys * docs: update sponsor logos * docs: fix lint error in changelog * Start v1.73.0-DEV development - Update to version 1.72.1: * Version v1.72.1 * s3: add more regions for Selectel * log: fix backtrace not going to the --log-file #9014 * build: fix lint warning after linter upgrade * configfile: add piped config support - fixes #9012 * fs/log: fix PID not included in JSON log output * build: adjust lint rules to exclude new errors from linter update * proxy: fix error handling in tests spotted by the linter * googlecloudstorage: improve endpoint parameter docs * docs: note where a provider has an S3 compatible alternative * Add Shade as sponsor * docs: Clarify OAuth scopes for readonly Google Drive access * docs: update sponsor logos * docs: fix lint error in changelog * Start v1.72.1-DEV development - Update to version 1.72.0: * Version v1.72.0 * rc: fix formatting in job/batch * test speed: fix formatting of help * docs: update sponsor logos * build: bump actions/checkout from 5 to 6 * s3: add multi-part-upload support for If-Match and If-None-Match * rc: config/unlock: rename parameter to `configPassword` accept old as well * rc: correct names of parameters in job/list output * Add Nikolay Kiryanov to contributors * rc: add `executeId` to job statuses - fixes #8972 * build: bump golang.org/x/crypto from 0.43.0 to 0.45.0 to fix CVE-2025-58181 * s3: fix single file copying behavior with low permission - Fixes #8975 * docs: onedrive: note how to backup up any user's data * Add Dominik Sander to contributors * Add jijamik to contributors * box: allow to configure with config file contents * http: add basic metadata and provide it via serve * ftp: fix transfers from servers that return 250 ok messages * b2: allow individual old versions to be deleted with --b2-versions - fixes #1626 * build: fix tls: failed to verify certificate: x509: negative serial number * Add Sean Turner to contributors * s3: add support for --upload-header If-Match and If-None-Match * fix: comment typos * dropbox: fix error moving just created objects - fixes #8881 * s3: add --s3-use-data-integrity-protections to fix BadDigest error in Alibaba, Tencent * rc: make sure fatal errors don't crash rclone - fixes #8955 * pacer: factor call stack searching into its own package * rc: add osVersion, osKernel and osArch to core/version * build: update all dependencies * build(deps): bump golangci/golangci-lint-action from 8 to 9 * webdav: fix out of memory with sharepoint-ntlm when uploading large file * testserver: fix owncloud test server startup * Add aliaj1 to contributors * ulozto: Fix downloads returning HTML error page * docs: adjust spectra logic example endpoint name * docs: update version introduced to v1.70 in doi docs * testserver: fix HDFS server after run.bash adjustments * testserver: remind developers about allocating a port * testserver: make run.bash variables less likely to collide with scripts * testserver: fix seafile servers messing up _connect string * testserver: make sure TestWebdavInfiniteScale uses an assigned port * testserver: make sure we don't overwrite the NAME variable set * Add n4n5 to contributors * Add Alex to contributors * Add Copilot to contributors * docs: update contributing docs regarding backend documentation * rc: add jobs stats * docs: fix alignment of some of the icons in the storage system dropdown * docs: run markdownlint on _index.md * docs: fix markdownlint issues and other styling improvements in backend command docs * docs: fix markdownlint issue md046/code-block-style in backend command docs * docs: fix missing punctuation in backend commands short description * docs: fix markdownlint issues in backend command generated output * build: improve backend docs autogenerated marker line * backend/compress: add zstd compression * sftp: fix zombie SSH processes with --sftp-ssh - Fixes #8929 * testserver: fix tests failing due to stopped servers * docs: add new integration tester site link * docs: update the method for running integration tests * bisync: fix failing tests * Add SublimePeace to contributors * b2: fix "expected a FileSseMode but found: ''" * docs: s3: clarify multipart uploads memory usage * test_all: fix detection of running servers * accounting: add AccountReadN for use in cluster * fs: add NonDefaultRC for discovering options in use * fs: move tests into correct files * rc: add NewJobFromBytes for reading jobs from non HTTP transactions * rc: add job/batch for sending batches of rc commands to run concurrently * Add Ted Robertson to contributors * Add Joseph Brownlee to contributors * Add fries1234 to contributors * Add Fawzib Rojas to contributors * Add Riaz Arbi to contributors * Add Lukas Krejci to contributors * Add Adam Dinwoodie to contributors * Add dulanting to contributors * docs: add AppArmor restrictions to rclone mount * check: improved reporting of differences in sizes and contents * mega: implement 2FA login * docs: change to light code block style to better match overall theme * docs: fix various markdownlint issues * build: restrict the markdown languages to use for code blocks * docs: fix various markdownlint issues * docs: fix markdownlint issue md013/line-length * docs: change syntax hightlighting for command examples from sh to console * docs: Clarify remote naming convention * b2: Add Server-Side encryption support * Added rclone archive command to create and read archive files * accounting: add io.Seeker/io.ReaderAt support to accounting.Account * operations: add ReadAt method to ReOpen * fstest: add ResetRun to allow the remote to be reset in tests * gcs: fix --gcs-storage-class to work with server side copy for objects * ulozto: implement the about functionality * local: add --skip-specials to ignore special files * swift: Report disk usage in segment containers * refactor: use strings.Builder to improve performance * Archive backend to read archives on cloud storage. * vfs: remove unecessary import in tests to fix import cycles * Add Lakshmi-Surekha to contributors * Add Andrew Gunnerson to contributors * Add divinity76 to contributors * build: enable support for aix/ppc64 * rc: fix name of "queue" JSON key in docs for vfs/cache * cmount: windows: improve error message on missing winfsp * docs: add the Provider to the options examples in the backend docs * Add Aneesh Agrawal to contributors * Add viocha to contributors * Add reddaisyy to contributors * fs: remove unnecessary Seek call on log file * s3: make it easier to add new S3 providers * build(deps): bump actions/upload-artifact from 4 to 5 * build(deps): bump actions/download-artifact from 5 to 6 * ftp: fix SOCK proxy support - fixes #8892 (#8918) * webdav: Add Access-Control-Max-Age header for CORS preflight caching - fixes #5078 * webdav: use SpaceSepList to parse bearer token command * refactor: use strings.Builder to improve performance * docs: re-arrange sponsors page * docs: add Spectra Logic as a sponsor * Add Oleksandr Redko to contributors * build: enable all govet checks (except fieldalignment and shadow) and fix issues. * march: fix --no-traverse being very slow - fixes #8860 * Add vastonus to contributors * s3: add new FileLu S5 endpoints * build: remove obsolete build tag * azurefiles: add ListP interface - #4788 * dropbox: add ListP interface - #4788 * webdav: add ListP interface - #4788 * pcloud: add ListP interface - #4788 * box: add ListP interface - #4788 * onedrive: add ListP interface - #4788 * drive: add ListP interface - #4788 * Add hunshcn to contributors * webdav: optimize bearer token fetching with singleflight * Changelog updates from Version v1.71.2 * lib/http: cleanup indentation and other whitespace in http serve template * docs: improve formatting of http serve template parameters * build: stop markdown linter leaving behind docker containers * Add Marco Ferretti to contributors * s3: add cubbit as provider * s3: add servercore as a provider * docs: update sponsors * docs: update sponsor images * docs: update privacy policy with a section on user data * Add Dulani Woods to contributors * Add spiffytech to contributors * gcs: add region us-east5 - fixes #8863 * jottacloud: refactor service list from map to slice to get predefined order * jottacloud: added support for traditional oauth authentication also for the main service * oauthutil: improved debug logs from token refresh * backend: add S3 provider for Hetzner object storage #8183 * jottacloud: improved token refresh handling * s3: provider reordering * index: add missing providers * docs: add missing ` * s3: add rabata as a provider * mega: fix 402 payment required errors - fixes #8758 * Add Andrew Ruthven to contributors * Add Microscotch to contributors * Add iTrooz to contributors * build: Bump SwiftAIO container to a newer one * build: Retry stopping the test server * build: Increase attempts to connect to test server * swift: If storage_policy isn't set, use the root containers policy * proton: automated 2FA login with OTP secret key * serve s3: fix log output to remove the EXTRA messages * docs/jottacloud: update description of invalid_grant error according to changes * jottacloud: add support for MediaMarkt Cloud as a whitelabel service * s3: add FileLu S5 provider * docs: fix variants of --user-from-header * vfs: fix chunker integration test * test_all: give TestZoho: extra time as it has been timing out * test_all: give TestCompressDrive: extra time as it has been timing out * rclone config string: reduce quoting with Human rendering for strings #8859 * Add juejinyuxitu to contributors * docs/jottacloud: update documentation with new whitelabel services and changed configuration flow * jottacloud: abort attempts to run unsupported rclone authorize command * jottacloud: minor adjustment of texts in config ui * jottacloud: add support for Let's Go Cloud (from MediaMarkt) as a whitelabel service * jottacloud: fix authentication for whitelabel services from Elkjøp subsidiaries * jottacloud: refactor config handling of whitelabel services to use openid provider configuration * jottacloud: remove nil error object from error message * jottacloud: fix legacy authentication * docs: add remote setup page to main docs dropdown * docs: update remote setup page * docs: add link from authorize command docs to remote setup docs * docs: lowercase internet and web browser instead of Internet browser * docs: use the term backend name instead of fs name for authorize command * add `rclone config string` for making connection strings #8859 * config: add more human readable configmap.Simple output * serve http: download folders as zip * s3: reorder providers to be in alphabetical order * refactor: use strings.FieldsFuncSeq to reduce memory allocations * accounting: add SetMaxCompletedTransfers method to fix bisync race #8815 * accounting: add RemoveDoneTransfers method to fix bisync race #8815 * bisync: fix race when CaptureOutput is used concurrently #8815 * build: update all dependencies * Makefile: remove deprecated go mod usage * azurefiles: Fix server side copy not waiting for completion - fixes #8848 * Changelog updates from Version v1.71.1 * test_all: fix branch name in test report * pacer: fix deadlock with --max-connections * Revert "azureblob: fix deadlock with --max-connections with InvalidBlockOrBlob errors" * Add Youfu Zhang to contributors * Add Matt LaPaglia to contributors * smb: optimize smb mount performance by avoiding stat checks during initialization * pikpak: fix unnecessary retries by using URL expire parameter - fixes #8601 * serve http: fix: logging url on start * docs: fix typo * b2: fix 1TB+ uploads * march: fix deadlock when using --fast-list on syncs - fixes #8811 * build: slices.Contains, added in go1.21 * build: use strings.CutPrefix introduced in go1.20 * build: use sequence Split introduced in go1.24 * build: use "for i := range n", added in go1.22 * build: modernize benchmark usage * build: in tests use t.Context, added in go1.24 * build: replace interface{} by the 'any' type added in go1.18 * build: use the built-in min or max functions added in go1.21 * Add russcoss to contributors * build: remove x := x made unnecessary by the new semantics of loops in go1.22 * lib/pool: fix unreliable TestPoolMaxBufferMemory test * Update S-Pegg1 email * Add Jean-Christophe Cura to contributors * pool: fix flaky unreliability test * copyurl: reworked code, added concurrency and tests * copyurl: Added --url to read urls from csv file - #8127 * docs: HDFS: erasure coding limitation #8808 * fstest: fix slice bounds out of range error when using -remotes local * local: fix time zones on tests * s3: added SpectraLogic as a provider * local: fix rmdir "Access is denied" on windows - fixes #8363 * bisync: fix error handling for renamed conflicts * docs: pcloud: update root_folder_id instructions * operations: fix partial name collisions for non --inplace copies * drive: docs: update making your own client ID instructions * swift: add ListP interface - #4788 * memory: add ListP interface - #4788 * oraceobjectstorage: add ListP interface - #4788 * B2: add ListP interface - #4788 * azureblob: add ListP interface - #4788 * googlecloudstorage: add ListP interface - Fixes #8763 * build: bump actions/github-script from 7 to 8 * build: bump actions/setup-go from 5 to 6 * bisync: fix chunker integration tests * bisync: fix koofr integration tests * internetarchive: fix server side copy files with spaces * lib/rest: add URLPathEscapeAll to URL escape as many chars as possible * Add alternate email for dougal to contributors * test speed: add command to test a specified remotes speed * docs: add link to MEGA S4 from MEGA page * Add Robin Rolf to contributors * Add anon-pradip to contributors * s3: Add Intercolo provider * gendocs: refactor and add logging of skipped command docs * gendocs: ignore missing rclone_mount.md, rclone_nfsmount.md, rclone_serve_nfs.md on windows * bin: add bisync.md generator * fstest: refactor to decouple package from implementation * gendocs: ignore missing rclone_mount.md on macOS * bisync: ignore expected "nothing to transfer" differences on tests * bisync: fix TestBisyncConcurrent ignoring -case * bisync: make number of parallel tests configurable * docs: clarify subcommand description in rclone usage * docs: fix description of regex syntax of name transform * docs: add some more details about supported regex syntax * makefile: fix lib/transform docs not getting updated * lib/pool: fix flaky test which was causing timeouts * Add dougal to contributors * vfs: fix SIGHUP killing serve instead of flushing directory caches * bisync: use unique stats groups on tests * fstest: stop errors in test cleanup changing the global stats * Add Motte to contributors * Add Claudius Ellsel to contributors * build: add local markdown linting to make check * lsf: add support for unix and unixnano time formats * docs: remove broken links from rc to commands * hashsum: changed output format when listing algorithms * docs: add example of how to add date as suffix * box: fix about after change in API return - fixes #8776 * Add skbeh to contributors * Add Tilman Vogel to contributors * docs: fix incorrectly escaped windows path separators * build: restore error handling in gendocs * combine: propagate SlowHash feature * docs/oracleobjectstorage: add introduction before external links and remove broken link * docs: fix markdown lint issues in backend docs * docs: fix markdown lint issues in command docs * docs: update markdown code block json indent size 2 * mount: do not log successful unmount as an error - fixes #8766 * Start v1.72.0-DEV development - Update to version 1.71.2: * Version v1.71.2 * docs: update sponsors * docs: update sponsor images * docs: update privacy policy with a section on user data * gcs: add region us-east5 - fixes #8863 * index: add missing providers * docs: add missing ` * mega: fix 402 payment required errors - fixes #8758 * docs: fix variants of --user-from-header * docs: add remote setup page to main docs dropdown * docs: update remote setup page * docs: add link from authorize command docs to remote setup docs * docs: lowercase internet and web browser instead of Internet browser * docs: use the term backend name instead of fs name for authorize command * bisync: fix race when CaptureOutput is used concurrently #8815 * azurefiles: Fix server side copy not waiting for completion - fixes #8848 * pikpak: fix unnecessary retries by using URL expire parameter - fixes #8601 * serve http: fix: logging url on start * docs: fix typo * b2: fix 1TB+ uploads * Start v1.71.2-DEV development - Update to version 1.71.1: * Version v1.71.1 * pacer: fix deadlock with --max-connections * Revert "azureblob: fix deadlock with --max-connections with InvalidBlockOrBlob errors" * march: fix deadlock when using --fast-list on syncs - fixes #8811 * docs: HDFS: erasure coding limitation #8808 * local: fix rmdir "Access is denied" on windows - fixes #8363 * bisync: fix error handling for renamed conflicts * docs: pcloud: update root_folder_id instructions * operations: fix partial name collisions for non --inplace copies * drive: docs: update making your own client ID instructions * internetarchive: fix server side copy files with spaces * lib/rest: add URLPathEscapeAll to URL escape as many chars as possible * docs: add link to MEGA S4 from MEGA page * docs: clarify subcommand description in rclone usage * docs: fix description of regex syntax of name transform * docs: add some more details about supported regex syntax * makefile: fix lib/transform docs not getting updated * vfs: fix SIGHUP killing serve instead of flushing directory caches * docs: remove broken links from rc to commands * docs: add example of how to add date as suffix * box: fix about after change in API return - fixes #8776 * docs: fix incorrectly escaped windows path separators * build: restore error handling in gendocs * combine: propagate SlowHash feature * docs/oracleobjectstorage: add introduction before external links and remove broken link * docs: fix markdown lint issues in backend docs * docs: fix markdown lint issues in command docs * docs: update markdown code block json indent size 2 * mount: do not log successful unmount as an error - fixes #8766 * Start v1.71.1-DEV development - Update to version 1.71.0: * Version v1.71.0 * fs: tls: add --client-pass support for encrypted --client-key files * ftp: make TLS config default to global TLS config - Fixes #6671 * fshttp: return *Transport rather than http.RoundTripper from NewTransport * bisync: release from beta * bisync: fix markdown formatting issues flagged by linter in docs * bisync: fix --no-slow-hash settings on path2 * Add cui to contributors * docs: add code of conduct * lib/mmap: convert to using unsafe.Slice to avoid deprecated reflect.SliceHeader * build: bump golangci/golangci-lint-action from 6 to 8 * build: update golangci-lint configuration * build: ignore revive lint issue var-naming: avoid meaningless package names * build: fix lint issue: should omit type error from declaration * Revert "build: downgrade linter to use go1.24 until it is fixed for go1.25" * build: migrate golangci-lint configuration to v2 format * s3: add --s3-use-arn-region flag - fixes #8686 * Add Binbin Qian to contributors * Add Lucas Bremgartner to contributors * docs: add tips about outdated certificates * FAQ: specify the availability of SSL_CERT_* env vars * pikpak: add file name integrity check during upload * bisync: skip TestBisyncConcurrent on non-local * internetarchive: fix server side copy files with & * Revert "s3: set useAlreadyExists to false for Alibaba OSS" * Add huangnauh to contributors * smb: improve multithreaded upload performance using multiple connections * bisync: fix data races on tests * bisync: remove unused parameters * bisync: deglobalize to fix concurrent runs via rc - fixes #8675 * mount: fix identification of symlinks in directory listings * s3: fix Content-Type: aws-chunked causing upload errors with --metadata * config: fix problem reading pasted tokens over 4095 bytes * config: fix test failure on local machine with a config file * log: add log rotation to --log-file - fixes #2259 * accounting: Fix stats (speed=0 and eta=nil) when starting jobs via rc * docs: update overview table for oracle object storage * Add praveen-solanki-oracle to contributors * oracleobjectstorage: add read only metadata support - Fixes #8705 * doc: sync doesn't symlinks in dest without --link - Fixes #8749 * s3: sort providers in docs * s3: add docs for Exaba Object Storage * azureblob: fix double accounting for multipart uploads - fixes #8718 * pool: fix deadlock with --max-buffer-memory * azureblob: fix deadlock with --max-connections with InvalidBlockOrBlob errors * build: downgrade linter to use go1.24 until it is fixed for go1.25 * build: update all dependencies * build: update to go1.25 and make go1.24 the minimum required version * Add Timothy Jacobs to contributors * bisync: fix time.Local data race on tests - fixes #8272 * googlecloudstorage: fix rateLimitExceeded error on bisync tests * accounting: populate transfer snapshot with "what" value * build(deps): bump actions/checkout from 4 to 5 * build(deps): bump actions/download-artifact from 4 to 5 * googlecloudstorage: enable bisync integration tests * fstest: fix parsing of commas in -remotes * azurefiles: fix hash getting erased when modtime is set * bisync: disable --sftp-copy-is-hardlink on sftp tests * local: fix --copy-links on Windows when listing Junction points * operations: fix too many connections open when using --max-memory * pool: fix deadlock with --max-memory and multipart transfers * pool: unify memory between multipart and asyncreader to use one pool * docs: update links to rcloneui * docs: add MEGA S4 as a gold sponsor * about: fix potential overflow of about in various backends * box: fix about: cannot unmarshal number 1.0e+18 into Go struct field * oauthutil: fix nil pointer crash when started with expired token * rc: listremotes should send an empty array instead of nil * config: add error if RCLONE_CONFIG_PASS was supplied but didn't decrypt config * rc: add config/unlock to unlock the config file * ftp: allow insecure TLS ciphers - fixes #8701 * s3: set useAlreadyExists to false for Alibaba OSS * docs: update sponsors page * fs: allow global variables to be overriden or set on backend creation * fs: allow setting of --http_proxy from command line * tests: cloudinary: remove test ignore after merging fix from #8707 * Add Antonin Goude to contributors * Add Yu Xin to contributors * Add houance to contributors * Add Florent Vennetier to contributors * Add n4n5 to contributors * Add Albin Parou to contributors * Add liubingrun to contributors * sync: fix testLoggerVsLsf when backend only reads modtime * sync: fix testLoggerVsLsf checking wrong fs * docs: fix make opengraph tags absolute as not all sites understand relative * docs: update contributing guide regarding markdown documentation * build: add markdown linting to workflow * build: add markdownlint configuration * docs: minor format cleanup install.md * docs: fix markdownlint issue md049/emphasis-style * docs: fix markdownlint issue md036/no-emphasis-as-heading * docs: fix markdownlint issue md033/no-inline-html * docs: fix markdownlint issue md025/single-title * docs: fix markdownlint issue md041/first-line-heading * docs: fix markdownlint issue md001/heading-increment * docs: fix markdownlint issue md003/heading-style * docs: fix markdownlint issue md034/no-bare-urls * docs: fix markdownlint issue md010/no-hard-tabs * docs: fix markdownlint issue md013/line-length * docs: fix markdownlint issue md038/no-space-in-code * docs: fix markdownlint issue md040/fenced-code-language * docs: fix markdownlint issue md046/code-block-style * docs: fix markdownlint issue md037/no-space-in-emphasis * docs: fix markdownlint issue md059/descriptive-link-text * docs: fix markdownlint issues md007/ul-indent md004/ul-style * docs: fix markdownlint issue md012/no-multiple-blanks * docs: fix markdownlint issue md058/blanks-around-tables * docs: fix markdownlint issue md022/blanks-around-headings * docs: fix markdownlint issue md031/blanks-around-fences * docs: fix markdownlint issue md032/blanks-around-lists * docs: fix markdownlint issue md009/no-trailing-spaces * docs: fix markdownlint issue md014/commands-show-output * docs: fix markdownlint issues md007/ul-indent md004/ul-style (bin/update-authors.py) * docs: fix markdownlint issues md007/ul-indent md004/ul-style (authors.md) * docs: add opengraph tags for website social media previews * mount: note that bucket based remotes can use directory markers * pikpak: add docs for methods to clarify name collision handling and restrictions * pikpak: enhance Copy method to handle name collisions and improve error management * pikpak: enhance Move for better handling of error and name collision * accounting: fix incorrect stats with --transfers=1 - fixes #8670 * rc: fix `operations/check` ignoring `oneWay` parameter * s3: add OVHcloud Object Storage provider * docs: rc: fix description of how to read local config * build: limit check for edits of autogenerated files to only commits in a pull request * build: extend check for edits of autogenerated files to all commits in a pull request * smb: refresh Kerberos credentials when ccache file changes * s3: fix multipart upload and server side copy when using bucket policy SSE-C * backend/s3: Fix memory leak by cloning strings #8683 * purge: exit with a fatal error if filters are set on `rclone purge` * docs: Add Backblaze as a Platinum sponsor * Add Sam Pegg to contributors * googlephotos: added warning for Google Photos compatability-fixes #8672 * test: remove flakey TestChunkerChunk50bYandex: test * docs: Consolidate entries for Josh Soref in contributors * docs: remove dead link to example of writing a plugin * filescom: document that hashes need to be enabled - fixes #8674 * Add Sudipto Baral to contributors * docs: fix incorrect json syntax in sample output * docs: ignore author email piyushgarg80 * docs: fix header level for --dump option section * docs: use stringArray as parameter type * docs: use consistent markdown heading syntax * imagekit: remove server side Copy method as it was downloading and uploading * imagekit: don't low level retry uploads * imagekit: return correct error when attempting to upload zero length files * smb: add --smb-kerberos-ccache option to set kerberos ccache per smb backend * test: fix smb kerberos integration tests * Changelog updates from Version v1.70.3 * config: make parsing of duration options consistent * docs: cleanup usage * docs: break long lines * docs: add option value type to header where missing * docs: mention that identifiers in option values are case insensitive * docs: rewrite dump option examples * docs: use markdown inline code format for dump option headers that are real examples * docs: change spelling from server side to server-side * docs: cleanup header casing * docs: rename OSX to macOS * docs: fix list and code block issue * docs: consistent markdown list format * docs: split section with general description of options with that documenting actual main options * docs: improve description of option types * docs: use space instead of equal sign to separate option and value in headers * docs: use comma to separate short and long option format in headers * docs: remove use of uncommon parameter types * docs: remove use of parameter type FILE * docs: remove use of parameter type DIR * docs: remove use of parameter type CONFIG_FILE * docs: change use of parameter type N and NUMBER to int consistent with flags and cli help * docs: change use of parameter type TIME to Duration consistent with flags and cli help * docs: change use of parameter type BANDWIDTH_SPEC to BwTimetable consistent with flags and cli help * docs: change use of parameter type SIZE to SizeSuffix consistent with flags and cli help * docs: cleanup markdown header format * docs: explain separated list parameters * azureblob: fix server side copy error "requires exactly one scope" * test: remove and ignore failing integration tests * docs: explain the json log format in more detail * check: fix difference report (was reporting error counts) * serve sftp: add support for more hashes (crc32, sha256, blake3, xxh3, xxh128) * serve sftp: extract function refactoring for handling hashsum commands * sftp: add support for more hashes (crc32, sha256, blake3, xxh3, xxh128) * local: configurable supported hashes * hash: add support for BLAKE3, XXH3, XXH128 * vfs: make integration TestDirEntryModTimeInvalidation test more reliable * smb: skip non integration tests when doing integration tests * seafile: fix integration test errors by adding dot to encoding * linkbox: fix upload error "user upload file not exist" * build: remove integration tests which are too slow * march: fix deadlock when using --no-traverse - fixes #8656 * pikpak: improve error handling for missing links and unrecoverable 500s * pikpak: rewrite upload to bypass AWS S3 manager - fixes #8629 * test: fix TestSMBKerberos password expiring errors * Add Vikas Bhansali to contributors * Add Ross Smith II to contributors * azureblob,azurefiles: add support for client assertion based authentication * webdav: fix setting modtime to that of local object instead of remote * build: set default shell to bash in build.yml * docs: fix filescom/filelu link mixup * Add Davide Bizzarri to contributors * fix: b2 versionAt read metadata * test: make TestWebdavInfiniteScale startup more reliable * test_all: add _connect_delay for slow starting servers * docs: update link for filescom * test_all: make TestWebdav InfiniteScale integration tests run * test_all: make SMB with Kerberos integration tests run properly * test_all: allow an env parameter to set environment variables * Changelog updates from Version v1.70.2 * Add Ali Zein Yousuf to contributors * Add $@M@RTH_ to contributors * docs: update client ID instructions to current Azure AD portal - fixes #8027 * s3: add Zata provider * pacer: fix nil pointer deref in RetryError - fixes #8077 * docs: Remove Warp as a sponsor * docs: add files.com as a Gold sponsor * docs: add links to SecureBuild docker image * Add curlwget to contributors * convmv: fix moving to unicode-equivalent name - fixes #8634 * transform: add truncate_keep_extension and truncate_bytes * convmv: make --dry-run logs less noisy * sync: avoid copying dir metadata to itself * docs: fix some function names in comments * combine: fix directory not found errors with ListP interface - Fixes #8627 * local: fix --skip-links on Windows when skipping Junction points * Add Marvin Rösch to contributors * build: bump github.com/go-chi/chi/v5 from 5.2.1 to 5.2.2 to fix GHSA-vrw8-fxc6-2r93 * copy,copyto,move,moveto: implement logger flags to store result of sync * log: fix deadlock when using systemd logging - fixes #8621 * docs: googlephotos: detail how to make your own client_id - fixes #8622 * Add necaran to contributors * mega: fix tls handshake failure - fixes #8565 * Changelog updates from Version v1.70.1 * Add jinjingroad to contributors * docs: DOI grammar error * docs: lib/transform: cleanup formatting * lib/transform: avoid empty charmap entry * chore: fix function name * convmv: fix spurious "error running command echo" on Windows * docs: client-credentials is not support by all backends * Start v1.71.0-DEV development - Update to version 1.70.3: * Version v1.70.3 * azureblob: fix server side copy error "requires exactly one scope" * docs: explain the json log format in more detail * check: fix difference report (was reporting error counts) * linkbox: fix upload error "user upload file not exist" * march: fix deadlock when using --no-traverse - fixes #8656 * pikpak: improve error handling for missing links and unrecoverable 500s * webdav: fix setting modtime to that of local object instead of remote * fix: b2 versionAt read metadata * Start v1.70.3-DEV development * docs: fix filescom/filelu link mixup * docs: update link for filescom - Update to version 1.70.2: * Version v1.70.2 * docs: update client ID instructions to current Azure AD portal - fixes #8027 * mega: fix tls handshake failure - fixes #8565 * pacer: fix nil pointer deref in RetryError - fixes #8077 * convmv: fix moving to unicode-equivalent name - fixes #8634 * convmv: make --dry-run logs less noisy * sync: avoid copying dir metadata to itself * combine: fix directory not found errors with ListP interface - Fixes #8627 * local: fix --skip-links on Windows when skipping Junction points * build: bump github.com/go-chi/chi/v5 from 5.2.1 to 5.2.2 to fix GHSA-vrw8-fxc6-2r93 * log: fix deadlock when using systemd logging - fixes #8621 * docs: googlephotos: detail how to make your own client_id - fixes #8622 * pikpak: fix uploads fail with "aws-chunked encoding is not supported" error * Start v1.70.2-DEV development * docs: Remove Warp as a sponsor * docs: add files.com as a Gold sponsor * docs: add links to SecureBuild docker image - Update to version 1.70.1: * Version v1.70.1 * docs: DOI grammar error * docs: lib/transform: cleanup formatting * lib/transform: avoid empty charmap entry * chore: fix function name * convmv: fix spurious "error running command echo" on Windows * docs: client-credentials is not support by all backends * Start v1.70.1-DEV development - Update to version 1.70.0: * Version v1.70.0 * ftp: add --ftp-http-proxy to connect via HTTP CONNECT proxy * pcloud: fix "Access denied. You do not have permissions to perform this operation" on large uploads * operations: fix TransformFile when can't server-side copy/move * fstest: fix -verbose flag after logging revamp * googlecloudstorage: fix directory marker after // changes in #5858 * s3: fix directory marker after // changes in #5858 * azureblob: fix directory marker after // changes in #5858 * tests: ignore some more habitually failing tests * googlephotos: fix typo in error message - Fixes #8600 * s3: MEGA S4 support * Add Ser-Bul to contributors * chunker: fix double-transform * docs: mailru: added note about permissions level choice for the apps password * tests: ignore habitually failing tests and backends * docs: link to asciinema rather than including the js * docs: target="_blank" must have rel="noopener" * sync: fix testLoggerVsLsf when dst is local * docs: fix FileLu docs * build: update all dependencies * onedrive: fix crash if no metadata was updated * Add kingston125 to contributors * Add Flora Thiebaut to contributors * Add FileLu cloud storage backend * doi: add new doi backend * build: fix check_autogenerated_edits.py flagging up files that didn't exist * docs: rc: add more info on how to discover _config and _filter parameters #8584 * s3: add Exaba provider * convmv: add convmv command * lib/transform: add transform library and --name-transform flag * march: split src and dst * Add ahxxm to contributors * Add Nathanael Demacon to contributors * b2: use file id from listing when not presented in headers - fixes #8113 * fs: fix goroutine leak and improve stats accounting process * march: fix syncing with a duplicate file and directory * Add PrathameshLakawade to contributors * Add Oleksiy Stashok to contributors * docs: fix page_facing_up typo next to Lyve Cloud in README.md * backend/s3: require custom endpoint for Lyve Cloud v2 support * backend: skip hash calculation when the hashType is None - fixes #8518 * azureblob: fix multipart server side copies of 0 sized files * Add Jeremy Daer to contributors * Add wbulot to contributors * s3: add Pure Storage FlashBlade provider support (#8575) * backend/gofile: update to use new direct upload endpoint * log: add --windows-event-log-level to support Windows Event Log * fs: Remove github.com/sirupsen/logrus and replace with log/slog * Add fhuber to contributors * cmd serve s3: fix ListObjectsV2 response * Changelog updates from Version v1.69.3 * onedrive: re-add --onedrive-upload-cutoff flag * onedrive: fix "The upload session was not found" errors * Add Germán Casares to contributors * Add Jeff Geerling to contributors * googlephotos: update read only and read write scopes to meet Google's requirements. * build: update github.com/ebitengine/purego to v0.8.3 to fix mac_amd64 build * docs: add hint about config touch and config file not found * docs: add FAQ for dismissing 'rclone.conf not found' * docs: document how to keep an out of tree backend * Add Clément Wehrung to contributors * iclouddrive: fix panic and files potentially downloaded twice * docs: move --max-connections documentation to the correct place * Add Ben Boeckel to contributors * Add Tho Neyugn to contributors * docs: fix typo in s3/storj docs * serve s3: remove redundant handler initialization * Changelog updates from Version 1.69.2 * sftp: add --sftp-http-proxy to connect via HTTP CONNECT proxy * Add Jugal Kishore to contributors * docs: correct SSL docs anchor link from #ssl-tls to #tls-ssl * drive: metadata: fix error when setting copy-requires-writer-permission on a folder * docs: Update contributors * build: bump golang.org/x/net from 0.36.0 to 0.38.0 * Update README.md * docs: fix typos via codespell * webdav: add an ownCloud Infinite Scale vendor that enables tus chunked upload support * onedrive: fix metadata ordering in permissions * Add Ben Alex to contributors * Add simwai to contributors * iclouddrive: fix so created files are writable * cmd/authorize: show required arguments in help text * cloudinary: var naming convention - #8416 * cloudinary: automatically add/remove known media files extensions #8416 * Add Markus Gerstel to contributors * Add Enduriel to contributors * Add huanghaojun to contributors * Add simonmcnair to contributors * Add Samantha Bowen to contributors * s3: documentation regression - fixes #8438 * hash: add SHA512 support for file hashes * vfs: fix inefficient directory caching when directory reads are slow * docs: update fuse version in docker docs * fs/config: Read configuration passwords from stdin even when terminated with EOF - fixes #8480 * cmd/gitannex: Reject unknown layout modes in INITREMOTE * cmd/gitannex: Add configparse.go and refactor * cmd/gitannex: Permit remotes with options * serve ftp: add serve rc interface * serve sftp: add serve rc interface * serve restic: add serve rc interface * serve s3: add serve rc interface * serve dlna: add serve rc interface * serve webdav: add serve rc interface - fixes #4505 * serve http: add serve rc interface * serve nfs: add serve rc interface * serve: Add rc control for serve commands #4505 * configstruct: add SetAny to parse config from the rc * rc: In options/info make FieldName contain a "." if it should be nested * serve restic: convert options to new style * serve s3: convert options to new style * serve http: convert options to new style * serve webdav: convert options to new style * auth proxy: convert options to new style * auth proxy: add VFS options parameter for use for default VFS * serve: make the servers self registering * lib/http: fix race between Serve() and Shutdown() * lib/http: add Addr() method to return the first configured server address * Add Danny Garside to contributors * docs: fix minor typo in box docs * sync: implement --list-cutoff to allow on disk sorting for reduced memory use * march: Implement callback based syncing * list: add ListDirSortedFn for callback oriented directory listing * list: Implement Sorter to sort directory entries * cache: mark ListP as not supported yet * hasher: implement ListP interface * compress: implement ListP interface * chunker: mark ListP as not supported yet * union: mark ListP as not supported yet * crypt: implement ListP interface * combine: implement ListP interface * s3: Implement paged listing interface ListP * list: add WithListP helper to implement List for ListP backends * walk: move NewListRHelper into list.Helper to avoid circular dependency * fs: define ListP interface for paged listing #4788 * accounting: Add listed stat for number of directory entries listed * walk: factor Listing helpers into their own file and add tests * serve nfs: make metadata files have special file handles * serve nfs: change the format of --nfs-cache-type symlink file handles * vfs: add --vfs-metadata-extension to expose metadata sidecar files * docs: Add rcloneui.com as Silver Sponsor * Add Klaas Freitag to contributors * Add eccoisle to contributors * Add Fernando Fernández to contributors * Add alingse to contributors * Add Jörn Friedrich Dreyer to contributors * docs: replace option --auto-filename-header with --header-filename * build: update github.com/golang-jwt/jwt/v5 from 5.2.1 to 5.2.2 to fix CVE-2025-30204 * docs/googlephotos: fix typos * build: bump github.com/golang-jwt/jwt/v4 from 4.5.1 to 4.5.2 * operations: fix call fmt.Errorf with wrong err * webdav: retry propfind on 425 status * Add --max-connections to control maximum backend concurrency * rc: fix debug/* commands not being available over unix sockets * cmd/gitannex: Prevent tests from hanging when assertion fails * cmd/gitannex: Add explicit timeout for mock stdout reads in tests * http: correct root if definitely pointing to a file - fixes #8428 * pool: add --max-buffer-memory to limit total buffer memory usage * filter: Add `--hash-filter` to deterministically select a subset of files * build: update golang.org/x/net to 0.36.0. to fix CVE-2025-22869 * rc: add add short parameter to core/stats to not return transferring and checking * fs: fix corruption of SizeSuffix with "B" suffix in config (eg --min-size) * filters: show --min-size and --max-size in --dump filters * build: check docs for edits of autogenerated sections * Add jack to contributors * docs: fix incorrect mentions of vfs-cache-min-free-size * fs/object: fix memory object out of bounds Seek * serve nfs: fix unlikely crash * docs: update minimum OS requirements for go1.24 * cmd/gitannex: Tweak parsing of "rcloneremotename" config * cmd/gitannex: Drop var rebindings now that we have go1.23 * docs: add note for using rclone cat for slicing out a byte range from a file * rcserver: improve content-type check * build: modernize Go usage * build: update all dependencies and fix deprecations * build: update golang.org/x/crypto to v0.35.0 to fix CVE-2025-22869 * build: make go1.23 the minimum go version * cmd/gitannex: Add to integration tests * cmd/gitannex: Simplify verbose failures in tests * cmd/gitannex: Port unit tests to fstest * vfs: fix integration test failures * azureblob: fix errors not being retried when doing single part copy * azureblob: handle retry error codes more carefully * touch: make touch obey --transfers * Add luzpaz to contributors * Add Dave Vasilevsky to contributors * docs: fix various typos * dropbox: Retry link without expiry * Dropbox: Support Dropbox Paper * chore: update contributor email * docs: correct stable release workflow * Add Lorenz Brun to contributors * Add Michael Kebe to contributors * vfs: fix directory cache serving stale data * build: fix docker plugin build - fixes #8394 * docs: improved sftp limitations * Changelog updates from Version v1.69.1 * docs: add FileLu as sponsors and tidy sponsor logos * accounting: fix percentDiff calculation -- fixes #8345 * vfs: fix the cache failing to upload symlinks when --links was specified * Add jbagwell-akamai to contributors * Add ll3006 to contributors * doc: add note on concurrency of rclone purge * s3: add latest Linode Object Storage endpoints * cmd: fix crash if rclone is invoked without any arguments - Fixes #8378 * build: disable docker builds on PRs & add missing dockerfile changes * sync: copy dir modtimes even when copyEmptySrcDirs is false - fixes #8317 * sync: add tests to check dir modtimes are kept when syncing * fix golangci-lint errors * bisync: fix false positive on integration tests * s3: split the GCS quirks into -s3-use-x-id and -s3-sign-accept-encoding #8373 * Add Joel K Biju to contributors * stats: fix the speed not getting updated after a pause in the processing * opendrive: added --opendrive-access flag to handle permissions * bisync: fix listings missing concurrent modifications - fixes #8359 * Added parallel docker builds and caching for go build in the container * smb: improve connection pooling efficiency * lib/oauthutil: fix redirect URL mismatch errors - fixes #8351 * b2: fix "fatal error: concurrent map writes" - fixes #8355 * Add Alexander Minbaev to contributors * Add Zachary Vorhies to contributors * Add Jess to contributors * s3: add IBM IAM signer - fixes #7617 * serve nfs: update docs to note Windows is not supported - fixes #8352 * cmd/config(update remote): introduce --no-output option * s3: add DigitalOcean regions SFO2, LON1, TOR1, BLR1 * sync: fix cpu spinning when empty directory finding with leading slashes * s3: fix handling of objects with // in #5858 * azureblob: fix handling of objects with // in #5858 * fstest: add integration tests objects with // on bucket based backends #5858 * fs/list: tweak directory listing assertions after allowing // names * lib/bucket: fix tidying of // in object keys #5858 * lib/bucket: add IsAllSlashes function * azureblob: remove uncommitted blocks on InvalidBlobOrBlock error * azureblob: implement multipart server side copy * azureblob: speed up server side copies for small files #8249 * azureblob: cleanup uncommitted blocks on upload errors * azureblob: factor readMetaData into readMetaDataAlways returning blob properties * Add b-wimmer to contributors * azurefiles: add --azurefiles-use-az and --azurefiles-disable-instance-discovery * onedrive: mark German (de) region as deprecated * Add Trevor Starick to contributors * Add hiddenmarten to contributors * Add Corentin Barreau to contributors * Add Bruno Fernandes to contributors * Add Moises Lima to contributors * Add izouxv to contributors * Add Robin Schneider to contributors * Add Tim White to contributors * Add Christoph Berger to contributors * azureblob: add support for `x-ms-tags` header * rc: disable the metrics server when running `rclone rc` * internetarchive: add --internetarchive-metadata="key=value" for setting item metadata * lib/batcher: Deprecate unused option: batch_commit_timeout * s3: Added new storage class to magalu provider * http servers: add --user-from-header to use for authentication * b2: add SkipDestructive handling to backend commands - fixes #8194 * vfs: close the change notify channel on Shutdown * Docker image: Add label org.opencontainers.image.source for release notes in Renovate dependency updates * docs: add OneDrive Impersonate instructions - fixes #5610 * docs: explain the stringArray flag parameter descriptor * iclouddrive: add notes on ADP and Missing PCS cookies - fixes #8310 * docs: fix typos found by codespell in docs and code comments * fs: fix confusing "didn't find section in config file" error * vfs: fix race detected by race detector * Add Jonathan Giannuzzi to contributors * Add Spencer McCullough to contributors * Add Matt Ickstadt to contributors * smb: add support for kerberos authentication * drive: added `backend moveid` command * docs: fix reference to serves3 setting disable_multipart_uploads which was renamed * docs: fix link to Rclone Serve S3 * serve s3: fix list objects encoding-type * build: update gopkg.in/yaml.v2 to v3 * build: update all dependencies * bisync: fix go vet problems with go1.24 * build: update to go1.24rc1 and make go1.22 the minimum required version * version: add --deps flag to show dependencies and other build info * doc: make man page well formed for whatis - fixes #7430 * Start v1.70.0-DEV development rclone-1.73.5-bp157.2.3.1.src.rpm rclone-1.73.5-bp157.2.3.1.x86_64.rpm rclone-bash-completion-1.73.5-bp157.2.3.1.noarch.rpm rclone-debuginfo-1.73.5-bp157.2.3.1.x86_64.rpm rclone-zsh-completion-1.73.5-bp157.2.3.1.noarch.rpm rclone-1.73.5-bp157.2.3.1.i586.rpm rclone-debuginfo-1.73.5-bp157.2.3.1.i586.rpm rclone-1.73.5-bp157.2.3.1.aarch64.rpm rclone-debuginfo-1.73.5-bp157.2.3.1.aarch64.rpm rclone-1.73.5-bp157.2.3.1.ppc64le.rpm rclone-debuginfo-1.73.5-bp157.2.3.1.ppc64le.rpm rclone-1.73.5-bp157.2.3.1.s390x.rpm rclone-debuginfo-1.73.5-bp157.2.3.1.s390x.rpm openSUSE-2026-155 Security update for freeciv moderate openSUSE Backports SLE-15-SP7 Update This update for freeciv fixes the following issues: - CVE-2026-33250: Fix a vulnerability allowing remote crashing of the server (boo#1260036). - update to version 3.0.10: * Generic bugfix release* Generic bugfix release * Fixed nation color selection assert failures when moving from pre-game to turn 1 * Fixed a crash when city removal left a unit stranded * Fixed growing of the internal string handling buffer, fixing, e.g., issues with very long lines in the savegame * Fixed fc_vsnprintf() return value on Windows, fixing, e.g., issues on loading the tutorial scenario * Various internal changes which should only affect developers * Fixed bad memory access while loading freeciv-2.6 format ruleset * Miscellaneous improvements to in-game text and user documentation * Miscellaneous changes to developer/install/ruleset docs * Updated translations * see https://freeciv.fandom.com/wiki/NEWS-3.0.10 - update to version 3.0.9: * Generic bugfix release * Set diplomatic relations state correctly between team members osdn#48295 * Fixed assert failures when city grows to freeciv's internal max city size (255) * Sammarinese city name Borgo Maggiore corrected osdn#48316 * Cargo gets bounced when transport is lost due to terrain change * Fixed crash with recursive autoattacks in case of occupychance setting being > 0 * Fixed memory corruption when transport is not bounced, but cargo is * Corrected amount treasury gets increased by a city in some situations * Cities stop working tiles turned unworkable at turn change * Fixed clearing city border claims when player gets removed from the game osdn#48837 * see https://freeciv.fandom.com/wiki/NEWS-3.0.9 freeciv-3.1.6-bp157.2.3.1.src.rpm freeciv-3.1.6-bp157.2.3.1.x86_64.rpm freeciv-debuginfo-3.1.6-bp157.2.3.1.x86_64.rpm freeciv-debugsource-3.1.6-bp157.2.3.1.x86_64.rpm freeciv-gtk3-3.1.6-bp157.2.3.1.x86_64.rpm freeciv-gtk3-debuginfo-3.1.6-bp157.2.3.1.x86_64.rpm freeciv-gtk4-3.1.6-bp157.2.3.1.x86_64.rpm freeciv-gtk4-debuginfo-3.1.6-bp157.2.3.1.x86_64.rpm freeciv-lang-3.1.6-bp157.2.3.1.noarch.rpm freeciv-qt-3.1.6-bp157.2.3.1.x86_64.rpm freeciv-qt-debuginfo-3.1.6-bp157.2.3.1.x86_64.rpm freeciv-3.1.6-bp157.2.3.1.aarch64.rpm freeciv-debuginfo-3.1.6-bp157.2.3.1.aarch64.rpm freeciv-debugsource-3.1.6-bp157.2.3.1.aarch64.rpm freeciv-gtk3-3.1.6-bp157.2.3.1.aarch64.rpm freeciv-gtk3-debuginfo-3.1.6-bp157.2.3.1.aarch64.rpm freeciv-gtk4-3.1.6-bp157.2.3.1.aarch64.rpm freeciv-gtk4-debuginfo-3.1.6-bp157.2.3.1.aarch64.rpm freeciv-qt-3.1.6-bp157.2.3.1.aarch64.rpm freeciv-qt-debuginfo-3.1.6-bp157.2.3.1.aarch64.rpm freeciv-3.1.6-bp157.2.3.1.ppc64le.rpm freeciv-debuginfo-3.1.6-bp157.2.3.1.ppc64le.rpm freeciv-debugsource-3.1.6-bp157.2.3.1.ppc64le.rpm freeciv-gtk3-3.1.6-bp157.2.3.1.ppc64le.rpm freeciv-gtk3-debuginfo-3.1.6-bp157.2.3.1.ppc64le.rpm freeciv-gtk4-3.1.6-bp157.2.3.1.ppc64le.rpm freeciv-gtk4-debuginfo-3.1.6-bp157.2.3.1.ppc64le.rpm freeciv-qt-3.1.6-bp157.2.3.1.ppc64le.rpm freeciv-qt-debuginfo-3.1.6-bp157.2.3.1.ppc64le.rpm freeciv-3.1.6-bp157.2.3.1.s390x.rpm freeciv-debuginfo-3.1.6-bp157.2.3.1.s390x.rpm freeciv-debugsource-3.1.6-bp157.2.3.1.s390x.rpm freeciv-gtk3-3.1.6-bp157.2.3.1.s390x.rpm freeciv-gtk3-debuginfo-3.1.6-bp157.2.3.1.s390x.rpm freeciv-gtk4-3.1.6-bp157.2.3.1.s390x.rpm freeciv-gtk4-debuginfo-3.1.6-bp157.2.3.1.s390x.rpm freeciv-qt-3.1.6-bp157.2.3.1.s390x.rpm freeciv-qt-debuginfo-3.1.6-bp157.2.3.1.s390x.rpm openSUSE-2026-152 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 147.0.7727.116 (boo#1262586) chromedriver-147.0.7727.116-bp157.2.151.1.x86_64.rpm chromium-147.0.7727.116-bp157.2.151.1.nosrc.rpm chromium-147.0.7727.116-bp157.2.151.1.x86_64.rpm chromedriver-147.0.7727.116-bp157.2.151.1.aarch64.rpm chromium-147.0.7727.116-bp157.2.151.1.aarch64.rpm chromedriver-147.0.7727.116-bp157.2.151.1.ppc64le.rpm chromium-147.0.7727.116-bp157.2.151.1.ppc64le.rpm openSUSE-2026-149 Security update for flannel important openSUSE Backports SLE-15-SP7 Update This update for flannel fixes the following issues: - Update to version 0.28.4: * fix go version (don't set patch version) (#2428) * Bump flannel-cni-plugin to v1.9.1-flannel1 (#2427) * Bump the other-go-modules group across 1 directory with 3 updates (#2425) * Bump the tencent group with 2 updates (#2417) * Bump the etcd group with 4 updates (#2398), includes fix for CVE-2026-33413 (boo#1260853) and CVE-2026-33343 (boo#1260847) * Bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0 (#2420) * Bump go to 1.25 (#2424) * Bump actions/upload-pages-artifact from 4.0.0 to 5.0.0 * Bump docker/build-push-action from 7.0.0 to 7.1.0 * Bump docker/login-action from 4.0.0 to 4.1.0 * Verify the kubectl sha256sum * Secure makefile (#2414) * Improve the security of Dockerfile * Bump github/codeql-action from 4.34.1 to 4.35.1 (#2409) * Bump actions/deploy-pages from 4.0.5 to 5.0.0 * lease: only print BackendData when json.Marshal succeeds * vxlan: delete v6 direct route with correct Route struct * fix: honor --stderrthreshold flag when --logtostderr is enabled * Bump actions/configure-pages from 5.0.0 to 6.0.0 * Bump actions/setup-go from 6.3.0 to 6.4.0 * don't use unquoted shell vars in extensions backend example * Don't use shell invocations in extensions backend. * Bump google.golang.org/grpc from 1.71.1 to 1.79.3 * Bump ossf/scorecard-action from 2.4.1 to 2.4.3 * Bump actions/upload-artifact from 4.6.1 to 7.0.0 * Bump docker/metadata-action from 5.10.0 to 6.0.0 * Bump actions/checkout from 4.2.2 to 6.0.2 * Bump docker/setup-buildx-action from 3.12.0 to 4.0.0 * Bump aquasecurity/trivy-action from 0.33.1 to 0.35.0 * Bump docker/setup-qemu-action from 3.7.0 to 4.0.0 * [StepSecurity] Apply security best practices * Bump actions/attest-build-provenance from 3.2.0 to 4.1.0 * Fix logic in AddBlackholeV4Route and AddBlackholeV6Route to correctly check for existing routes * Added check for nftables before checking br_netfilter module * Bump golang.org/x/crypto from 0.36.0 to 0.45.0 * Bump k8s deps to v0.32.10 * Bump golang-ci-lint to v2.7.2 * Bump golangci/golangci-lint-action from 6.1.1 to 9.2.0 * Additional check on podCIDR * ip: improve primary address selection to account for address flags * Added TAG to fix bin version flannel-0.28.4-bp157.2.6.1.src.rpm flannel-0.28.4-bp157.2.6.1.x86_64.rpm flannel-k8s-yaml-0.28.4-bp157.2.6.1.noarch.rpm flannel-0.28.4-bp157.2.6.1.i586.rpm flannel-0.28.4-bp157.2.6.1.aarch64.rpm flannel-0.28.4-bp157.2.6.1.ppc64le.rpm flannel-0.28.4-bp157.2.6.1.s390x.rpm openSUSE-2026-156 Security update for cacti moderate openSUSE Backports SLE-15-SP7 Update This update for cacti fixes the following issues: - Update to version 1.2.30+git306.82d5aef5: * add a collapse icon (#7047) * security: consolidated defense-in-depth hardening (1.2.x) (#7039) * fix(security): harden boost cache, deserialization, GET_LOCK, and process management (#7021) * CVE-2026-0540 - Update DOMPurify to 3.3.3. phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack (#7022) * fix(security): harden exec_background, log path redirection, and CLI argument handling (#7016) * fix: IPv6 support hardening for SNMP sessions, ping validation, and binary transport (#7014) * fix(security): enforce strict metric serialization at RRDtool IPC boundary (#7012) * fix(security): harden rrd.php, database.php, and html_utility.php (1.2.x) (#7002) * fix(security): harden auth lockout, CSPRNG fallback, error escaping, and redirect (1.2.x) (#7000) * fix(security): harden core execution boundaries and XML processing (#7010) * fix(security): harden utility.php PHP binary validation, SQL injection, PRNG, and XSS (#7006) * fix(security): escape html_filter form attributes and JS context (1.2.x) (#6995) * fix: prevent empty CDEF RPN expressions in aggregate graphs (1.2.x) (#6985) * fix: aggregate 95th percentile uses SUM instead of MAX for SIMILAR (1.2.x) (#6984) * fix: CF fallback selection overwritten by cf_reference (1.2.x) (#6982) * fix: remove unconditional overwrite of coerced multi-DS values (1.2.x) (#6981) * fix: cacti_snmp_validate_oid accepts non-numeric OIDs (1.2.x) (#6980) * fix(scripts): return 'U' on error in ss_webseer, ss_gexport, query_host_cpu (1.2.x) (#6983) * fix: Fixing additional review issues (#6979) * fix: Fixing issues with dns call (#6977) * fix: Fixing wrong variable use (#6976) * fix(security): cast effective_user to int and validate OID format in remote_agent (1.2.x) (#6969) * fix(security): escape rrdtool tune arguments to prevent command injection (#6967) * fix(security): forward-verify PTR result in remote_client_authorized() (#6968) * fix(security): validate graph_theme with basename() to prevent LFI (#6966) * fix(security): escape error message output in auth_login.php (#6958) * fix: Simplify redirect handling in Cacti and Fix Multi-Sort (#6955) * fix(security): use strict comparisons in auth and restrict unserialize (#6960) * fix: correct spikekill user/default inversion and add RRD file check (1.2.x) (#6962) * fix(security): parameterize SQL, add column allow-list, and type-safe counter math (#6961) * fix(hardening): replace raw $_REQUEST with input wrapper functions (#6959) * fix graph debug (#6956) * fix: return text error in graph debug mode when RRD file missing (1.2.x) (#6924) * security: fix XSS in JavaScript contexts across UI pages (1.2.x) (#6929) * fix: correct colourBrightness calculation for negative and integer percentages (1.2.x) (#6928) * Fix: Removing backtick operator from code (#6922) * fix: remove noisy RRD file-not-found log message (#6918) * security: remaining hardening backports to 1.2.x (#6917) * Fix: Issuesing changing poller and audit plugin (#6915) * Fix: Add missing functiosn rrdtool_file_exists (#6914) * security: harden shell command execution against injection (1.2.x backport) (#6902) * security: fix SSRF and SSL verification in help.php (1.2.x backport) (#6906) * fix: backport spikekill and realtime graph fixes to 1.2.x (#6909) * security: fix XSS and open redirect in auth and UI pages (1.2.x backport) (#6910) * security: parameterize SQL in sequence functions and data_queries.php (1.2.x backport) (#6911) * security: fix SSRF, command injection, and XSS in core functions (1.2.x) (#6913) * security: support array arguments in exec_background and __rrd_execute (1.2.x backport) (#6912) * Fixing managers actions not taking action (#6901) * security: harden SQL query construction against injection (1.2.x backport) (#6897) * security: fix XSS, path traversal, open redirect, and IDOR (1.2.x backport) (#6899) * security: fix unsafe deserialization in managers.php (1.2.x backport) (#6898) * Update translation files * Translated using Weblate (Swedish) * Update translation files * Translated using Weblate (Swedish) * Update translation files * Translated using Weblate (Swedish) * fix(1.2.x): correct codespell-detected spelling errors in PHP source files (#6808) * qa: Removing php7.4 and php8.0 from our validation matrix due recent plugin changes (#6817) * Update translation files * Translated using Weblate (Swedish) * [1.2.x] fix: exec_with_timeout operator precedence, child kill, and stderr handling (#6732) * fix(auth): add column-name whitelist to is_view_allowed() (#6708) * fix: parameterize SQL in cli/add_device.php (#6710) * fix: remove PHP_EOL from force_https redirect header (#6711) * fix: three one-line typos in spikekill subsystem (#6712) * fix: add output_format to ifName and ifDescr in interface.xml (#6713) * fix: strict comparison in replicate_table_to_poller column exclusion (#6714) * fix: escape values in array_to_sql_or() to prevent SQL injection (#6709) * fix: correct JOIN condition in is_view_allowed() group membership query (#6734) * fix false down status in gui (#6706) * add dell idrac template (#6681) * Backport check_all_pages.sh to 1.2.x (#6678) - Update to version 1.2.30+git233.9b67d5e98: * remove wrong styles (#6654) * Fix paper-plane theme (#6640) - Update to latest release/1.2.30+git231.bca15e70c: - Updates since 1.2.30: * security#GHSA-6RVG-2VM8-5WRF: CVE-2026-22802 Authentication Bypass leads to information disclosure * security: CVE-2026-1513 billboard.js before 3.18.0 Improper Input Sanitization Allows Remote JavaScript Execution * issue#6168: When purging RRD files, paths are not correctly handled * issue#6202: When using automation, devices may not be added as expected * issue#6204: Attempting to match a field in automation may cause unexpected errors * issue#6210: Ensure column names are escaped to prevent reserved word issues * issue#6240: Improve sort order for incorrect RRA's * issue#6249: Unable to send Email to users without a domain name * issue#6251: When viewing a graph, do not produce unnecessary errors if graph has been removed * issue#6253: When i18n formatting numbers, assume null means 0 by xmacan * issue#6257: When data sources are removed, ensure only RRD files are removed by xmacan * issue#6262: When the database connection drops during query, retry to ensure success * issue#6270: Incorrect escaping may prevent drop downs working as intended * issue#6271: When validation errors occur, provide more information to help diagnosis * issue#6283: When calculating total pages, ensure math errors do not occur * issue#6292: When validating null request variables, fatal errors may occur * issue#6294: Automation may produce unexpected warnings when detecting the OS * issue#6296: Process timeouts may not end processes as expected * issue#6297: Improve support for Secure SMTP * issue#6299: Improve email address handling to support UTF8 * issue#6313: When editing multiple devices, unexpected errors may be recorded * issue#6314: When editing an Aggregation Graph, total count may not reflect number of items correctly * issue#6315: When duplicating a Data Input Method, unexpected errors may occur * issue#6326: Improve SNMP v3 support for Cisco devices * issue#6327: Implement Autocomplete standards for Login and Change Password * issue#6329: When using LDAP, checking a user's groups may cause unexpected errors * issue#6331: When upgrading from pre-1.0.5, unexpected errors may occur by YATV * issue#6334: When creating Aggregate graphs, unable to hide HRULE and COMMENT based items * issue#6335: Email addresses with leading or trailing spaces can cause issues * issue#6441: Spikekill uses the wrong option for retention periods by 3432 * issue#6444: When a Data Input's Title is applied, unexpected errors and values may be seen * issue#6490: When using Clear All on Selective Debug, first item is reselected * issue#6507: Importing packages may not work as expected by xmacan * issue#6508: When exporting graphs, data issues may lead to unexpected errors by xmacan * issue#6516: When modifying Graph Automation Rules, unexpected errors may be logged * issue#6518: Improve security of CSRF Secret by SMark-Black * issue#6519: When using Real Time graphing, unexpected errors may appear if graph is removed * issue#6546: Restore some missing SNMP Script Server configurations * issue#6551: Improve support for FreeBSD when Auditing Databases by xmacan * issue#6573: Create new device_change_javascript hook for THOLD plugin by xmacan * issue#6598: Improve PHP 8 support by TheWitness * issue#6600: When replicating plugins, unexpected errors may appear due to missing tables * issue#6605: Prevent Row Data Loss When Rebuilding RRD Files * issue#6606: When using SpikeKill, actions would not always lead to expected results * feature#6523: When disabling users, ensure that their authentication cookies and sessions cleared * feature#6524: When changing your password, log off from all sessions * feature#6534: Improve Cacti Session ID security * feature#6607: Implement session security on Password change * feature: Update DOMPurify to 3.3.0 * feature: Update PHPMailer to 6.10 to support SMTPUTF8 * feature: Update phpseclib for the Service Check plugi - Update requires/recommends for better fresh install experience - Requires: php-intl - Recommends: php-gettext php-pcntl mysql-tools cacti-1.2.30+git306.82d5aef5-bp157.2.6.1.noarch.rpm cacti-1.2.30+git306.82d5aef5-bp157.2.6.1.src.rpm openSUSE-2026-159 Recommended update for gn moderate openSUSE Backports SLE-15-SP7 Update This update for gn fixes the following issues: - Update to version 0.20260331: * Add modulemap generation to GN. * Support building gn without a .git directory. * Limit the maximum number of GN worker threads to 32. * Remove premature target writing before validation during `gn gen`. * Only run target checks in background threads during resolution. * Add additional files to gitignore * Add `inputs` parameter to `tool`. * Unit test foo* not just *foo patterns * Unit test edge cases around consecutive \b in patterns * Reject newlines in string config values (defines, cflags, etc.) * Set clang-format to use C++20 * Run formatter * Bump min mac version flag. * Add --error-limit flag to control error output count * [gn] Fix Value::operator== for empty lists * [gn] Optimize Value::LIST with Copy-On-Write using nullptr * Capture C++ modules compilation commands in compile_commands.json * Output -fmodule-map-file as well as -fmodule-file for module dependencies. * Optimize HeaderChecker by parallelizing ReachabilityCache pre-calculation and removing lock contention. * Optimize HeaderChecker file I/O by parsing files only once * Optimize reachability cache to drastically reduce BFS executions * Remove unused targets_count_ in HeaderChecker * Apply clang-format * Use high-performance cores on Apple Silicon for worker pool * Optimize HeaderChecker::IsDependencyOf using HashTableBase * [perf] Optimize HeaderChecker BFS using reserve() * [perf] Share ResolvedTargetData across worker threads * [perf] Cache dependency checks in HeaderChecker * [test] Fix SetupTest.AbsolutePythonPathInsideRootDir on macOS * [mac] Update minimum macOS version to 10.12 * Include validations when collecting metadata * Fix target being written twice under certain circumstances * Add validation support to gn analyze/desc/path/refs * Fix race condition when using validations * Add pcm files to the deps of phony target * Add `validations` dependency type to targets * Fix result of Scheduler::Run() with empty work queue * Add conductor setup files * Improve writing runtime deps * Unit test label user visible name * Improve error message for rebase_path builtin * Minor table-driven test refactor * win: Use relative path for python in ninja files if possible gn-0.20260331-bp157.2.12.1.src.rpm gn-0.20260331-bp157.2.12.1.x86_64.rpm gn-0.20260331-bp157.2.12.1.i586.rpm gn-0.20260331-bp157.2.12.1.aarch64.rpm gn-0.20260331-bp157.2.12.1.ppc64le.rpm gn-0.20260331-bp157.2.12.1.s390x.rpm openSUSE-2026-166 Recommended update for python-podman moderate openSUSE Backports SLE-15-SP7 Update This update for python-podman fixes the following issues: - update to 5.8.0: * Fix PodManager.prepare_model set manager by @inknos in #619 * Implement Quadlet, QuadletManager and GET calls by @inknos in #622 * Enable renovate-bot for pre-commit by @inknos in #626 * Add healthcheck to create and run by @inknos in #617 * Fix pytest flag for rootful test by @inknos in #623 * Implemente delete calls for quadlets by @inknos in #629 * Adding timeout parameter to container.wait() and fixing interval type by @mutax in #632 * add network_dns_servers as supported parameter to network.create by @mutax in #630 * tests/integration: Skip test on non-x86_64 arches by @ricardobranco777 in #637 * Implement client.quadlets.install by @inknos in #633 * Add release PR workflow by @inknos in #627 * Bump release to 5.8.0 by @inknos in #639 - update to 5.7.0: * Fix attr getters in Network Resource by @nlacasse in #576 * Include test files in the source distribution by @mgorny in #586 * Inknos update publish to pypy steps by @inknos in #590 * Update testing section by @inknos in #591 * Add support for export and import commands by @Riushda in #593 * fix: use active service connection when no explicit connection specified by @Honny1 in #597 * Add direct support to --manifest when building container images. by @MisterOwlPT in #596 * fix: typing in podman.domain.containers_run by @dklimpel in #599 * misc: improve type checking by @dklimpel in #601 * bump tmt pre-commit hook to 1.62.1 by @Honny1 in #606 * Enable tests downstream via packit/tmt by @inknos in #588 * Add support to --secrets when building container images by @gsilva00 in #603 * fix image build not using cache by @fulminemizzega in #559 * Delete custom cached_property in favor of functools.cached_property by @yangdanny97 in #607 * Fixed filtering for networks by @sekyHC in #616 * networks_manager: fix dns_enabled parameter description by @sekyHC in #615 * Bump release to 5.7.0 by @inknos in #620 - update to 5.6.0: * [skip-ci] Update sigstore/gh-action-sigstore-python action to v3.0.1 by @renovate[bot] in #561 * Fix/#489 by @Mr-Sunglasses in #513 * fix: broken configuration for readthedocs by @dklimpel in #562 * remove cirrus files by @Luap99 in #563 * Implement policy option for image.pull by @inknos in #565 * Run tests conditionally based on os_release by @inknos in #567 * Skip tests conditionally based on version by @inknos in #578 * [skip-ci] Update actions/checkout action to v5 by @renovate[bot] in #568 * [skip-ci] Update actions/download-artifact action to v5 by @renovate[bot] in #566 * tests: Fix deprecation warning for utcfromtimestamp() by @ricardobranco777 in #575 * Implement sparse keyword for containers.list() by @inknos in #540 * [skip-ci] Update actions/setup-python action to v6 by @renovate[bot] in #579 * Update Ruff to 0.12.8 by @inknos in #569 * Add Honn1 to OWNERS by @inknos in #580 * Bump release to 5.6.0 by @inknos in #581 - update to 5.5.0: * fix(doc): correction of the example for the registry at the login by @dklimpel in #518 * fix: set return type for ImagesManager.load() to Image by @dklimpel in #519 * Enable tmt downstream by @inknos in #522 * Implement container.update() by @inknos in #521 * skip tests when the test image is not available (e.g. 32-bit) by @eighthave in #524 * chore(deps): update dependency containers/automation_images to v20250324 by @renovate in #529 * feat: expose *ns keys to consumers by @josegomezr in #525 * Fix: fix timeout type as int by @inknos in #537 * Enable Unit test coverage upstream by @inknos in #531 * Add inspect volume by @rkozlo in #535 * fix: push image does not stream by @dklimpel in #538 * misc: add mypy for type checking by @dklimpel in #541 * chore(deps): update dependency containers/automation_images to v20250422 by @renovate in #543 * Set X-Registry-Auth header on manifest push and bump to new API by @dklimpel in #536 * Set verbose: true to debug twine uploads to PypI by @inknos in #520 * Improve testing against distro and podman-next by @inknos in #548 * Add support for custom contexts by @aseering in #552 * fix: move digest label to the repository instead of tag by @Alex-Izquierdo in #555 * Bump release to 5.5.0 and enable updates-testing repos on Fedora by @inknos in #549 python-podman-5.8.0-bp157.2.4.1.src.rpm python311-podman-5.8.0-bp157.2.4.1.noarch.rpm openSUSE-2026-161 Security update for chromium critical openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 147.0.7727.137 (boo#1263158) * CVE-2026-7363: Use after free in Canvas * CVE-2026-7361: Use after free in iOS * CVE-2026-7344: Use after free in Accessibility * CVE-2026-7343: Use after free in Views * CVE-2026-7333: Use after free in GPU * CVE-2026-7360: Insufficient validation of untrusted input in Compositing * CVE-2026-7359: Use after free in ANGLE * CVE-2026-7358: Use after free in Animation * CVE-2026-7334: Use after free in Views * CVE-2026-7357: Use after free in GPU * CVE-2026-7356: Use after free in Navigation * CVE-2026-7354: Out of bounds read and write in Angle * CVE-2026-7353: Heap buffer overflow in Skia * CVE-2026-7352: Use after free in Media * CVE-2026-7351: Race in MHTML * CVE-2026-7350: Use after free in WebMIDI * CVE-2026-7349: Use after free in Cast * CVE-2026-7348: Use after free in Codecs * CVE-2026-7335: Use after free in media * CVE-2026-7336: Use after free in WebRTC * CVE-2026-7337: Type Confusion in V8 * CVE-2026-7347: Use after free in Chromoting * CVE-2026-7346: Inappropriate implementation in Tint * CVE-2026-7345: Insufficient validation of untrusted input in Feedback * CVE-2026-7338: Use after free in Cast * CVE-2026-7342: Use after free in WebView * CVE-2026-7341: Use after free in WebRTC * CVE-2026-7339: Heap buffer overflow in WebRTC * CVE-2026-7340: Integer overflow in ANGLE * CVE-2026-7355: Use after free in Media chromedriver-147.0.7727.137-bp157.2.154.1.x86_64.rpm chromium-147.0.7727.137-bp157.2.154.1.nosrc.rpm chromium-147.0.7727.137-bp157.2.154.1.x86_64.rpm chromedriver-147.0.7727.137-bp157.2.154.1.aarch64.rpm chromium-147.0.7727.137-bp157.2.154.1.aarch64.rpm chromedriver-147.0.7727.137-bp157.2.154.1.ppc64le.rpm chromium-147.0.7727.137-bp157.2.154.1.ppc64le.rpm openSUSE-2026-163 Security update for trivy important openSUSE Backports SLE-15-SP7 Update This update for trivy fixes the following issues: Update to version 0.70.0 ( boo#1260193, CVE-2026-33186, boo#1260971, CVE-2026-33747, boo#1261052, CVE-2026-33748, boo#1262389, CVE-2026-39984, boo#1262893, CVE-2026-34986): * release: v0.70.0 [main] (#10105) * chore(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 (#10496) * chore(deps): bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 (#10526) * chore(deps): bump the common group across 1 directory with 8 updates (#10540) * chore(deps): bump the docker group across 1 directory with 2 updates (#10538) * fix: use Development category for GoReleaser discussions (#10530) * chore(deps): bump testcontainers-go to v0.42.0 (#10531) * chore: update CODEOWNERS (#10529) * chore(deps): bump helm.sh/helm/v3 from 3.20.1 to 3.20.2 (#10511) * chore(deps): bump github.com/hashicorp/go-getter from 1.8.5 to 1.8.6 (#10510) * chore(deps): bump github.com/moby/buildkit from 0.27.1 to 0.28.1 (#10449) * ci: migrate from mkdocs-material-insiders to mkdocs-material (#10509) * chore: remove aquasecurity/homebrew-trivy tap from GoReleaser (#10508) * ci: update runners for workflows that interact with GitHub API (#10502) * ci: rename tokens and update runners (#10500) * ci: trigger helm chart publishing via helm-charts workflow (#10474) * ci: remove ruleset update step from release-please workflow (#10499) * ci: use large runner and replace ORG_REPO_TOKEN in release-please workflow (#10498) * ci: trigger rpm/deb deployment via trivy-repo workflow (#10476) * fix: remove os.Stdout from wazero module config (#10403) * chore(deps): bump the common group across 1 directory with 22 updates (#10408) * chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#10407) * fix(flag): validate template file extension (#10296) * fix(sbom): preserve Red Hat BuildInfo when scanning SBOMs without layer info (#10378) * fix: handle Go 1.26 GOEXPERIMENT version format change (#10351) * fix(python): handle multiple version specifiers in requirements.txt (#10361) * ci: run Trivy version bump in trivy-action (#10272) * fix(python): nil pointer dereference with optional poetry groups without dependencies (#10359) * ci: replace personal email with github-actions[bot] in workflows (#10369) * chore: replace smithy epoch parsing with stdlib time.Unix (#10286) * test: update golden files for purl changes (#10372) * ci: add zizmor to scan GitHub Actions workflows (#10322) * refactor: log statuses as strings (#10285) * ci: add build provenance attestations for release artifacts (#10316) * fix(sbom): add NOASSERTION for licenseDeclared/licenseConcluded in SPDX non-library packages (#10368) * fix(report): set correct sarif ROOTPATH uri when scanning a git repository (#10366) * perf(plugin): optimize directory traversal by replacing filepath.Walk with filepath.WalkDir (#10325) * docs: correct typos in CHANGELOG and diagram (#10320) * chore: delete roadmap wf (#10295) * ci(helm): bump Trivy version to 0.69.3 for Trivy Helm Chart 0.21.3 (#10310) * fix(cyclonedx): include CVSS v4 vulnerability ratings (#10313) * fix: detected vulnerability fields in azure and mariner detector (#10275) * ci: add persist-credentials: false to checkout steps (#10306) * ci(helm): bump Trivy version to 0.69.2 for Trivy Helm Chart 0.21.2 (#10270) * chore(deps): bump the common group across 1 directory with 8 updates (#10248) * chore(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 (#10257) * chore(deps): bump the aws group across 1 directory with 6 updates (#10249) * chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 (#10241) * ci: remove apidiff workflow (#10259) * chore(deps): bump github.com/docker/cli from 29.1.4+incompatible to 29.2.1+incompatible in the docker group across 1 directory (#10221) * ci: bump golangci-lint to v2.10 in cache-test-assets (#10243) * feat(java): add support for proxy configuration from Maven settings.xml (#10187) * chore(deps): bump the github-actions group across 3 directories with 11 updates (#10242) * feat(python): add pylock.toml support (#10137) * chore: bump SPDX license IDs and exceptions to `v3.28.0` (#10233) * docs: fix typos and upgrade insecure HTTP links to HTTPS (#10219) * chore: bump golangci-lint to v2.10.0 (#10223) * feat(misconf): support for azurerm_network_interface_security_group_association (#10215) * ci: pin Docker Engine to v29 for integration tests (#10232) * feat(go): detect version from ELF symbol table for binaries built with -trimpath (#10197) * docs: migrate private registry documentation from GCR to GAR (#10208) * chore(deps): bump the common group across 1 directory with 24 updates (#10206) * chore(deps): update Docker client SDK to v29 (#10202) * test: update Docker Engine integration tests for Docker API v0.29.0+ compatibility (#10199) * fix(misconf): initialize custom annotation field if empty (#10123) * feat(ubuntu): add eol data for 25.10 (#10181) * docs: fix incorrect count of Python package managers (#10175) * chore(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 (#10179) * feat(misconf): resolve Azure resources via resource_id (#10173) * ci(helm): bump Trivy version to 0.69.1 for Trivy Helm Chart 0.21.1 (#10155) * refactor: remove unused Insecure field from ServiceOption (#10113) * refactor: reduce complexity of init in detect.go (#10163) * feat(misconf): adapt ARM k8s clusters (#9696) (#10125) * docs: update version endpoint example in client/server documentation (#10151) * feat(vuln): skip third-party packages in common Detect function (#10129) * ci: add composite action for Go setup (#10146) * fix(misconf): apply check aliases when filtering results via .trivyignore (#10112) * docs(terraform): add limitation for data sources and computed resource attributes (#10128) * fix: update PhotonOS feed URL (#10122) * feat(server): include server version info in JSON output for client/server mode (#10075) * chore(deps): bump to alpine:3.23.3 and go-1.25.6 to fix CVEs (#10107) * refactor: unify scanner error limit and compiler limit (#10106) * ci(helm): bump Trivy version to 0.69.0 for Trivy Helm Chart 0.21.0 (#10103) * fix(java): Disable overwriting exclusions (#10088) * refactor(rust): use txtar format for cargo analyzer test data (#10104) * feat(python): add pylock.toml (PEP 751) parser (#9632) * chore(deps): bump the aws group across 1 directory with 6 updates (#10068) * fix(server): exclude JavaDB and CheckBundle from /version endpoint (#10100) - Update to version 0.69.3 (CVE-2026-25934, boo#1258094): * release: v0.69.3 [release/v0.69] (#10293) * fix(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 [backport: release/v0.69] (#10291) * release: v0.69.2 [release/v0.69] (#10266) * fix(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 [backport: release/v0.69] (#10267) * fix(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 [backport: release/v0.69] (#10264) * ci: remove apidiff workflow * release: v0.69.1 [release/v0.69] (#10145) * ci: add composite action for Go setup [backport: release/v0.69] (#10150) * fix(misconf): apply check aliases when filtering results via .trivyignore [backport: release/v0.69] (#10143) * chore(deps): bump to alpine:3.23.3 and go-1.25.6 to fix CVEs [backport: release/v0.69] (#10135) - Update to version 0.69.0 (boo#1255366, CVE-2025-64702, boo#1258513, CVE-2025-69725): * release: v0.69.0 [main] (#9886) * chore: bump trivy-checks to v2 (#9875) * chore(deps): bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 (#10091) * fix(repo): return a nil interface for gitAuth if missing (#10097) * fix(java): correctly inherit properties from parent fields for pom.xml files (#9111) * fix(rust): implement version inheritance for Cargo mono repos (#10011) * feat(activestate): add support ActiveState images (#10081) * feat(vex): support per-repo tls configuration (#10030) * refactor: allow per-request transport options override (#10083) * chore(deps): bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 (#10084) * chore(deps): bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 (#10085) * fix(java): correctly propagate repositories from upper POMs to dependencies (#10077) * feat(rocky): enable modular package vulnerability detection (#10069) * chore(deps): bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.3.1 (#10079) * docs: fix mistake in config file example for skip-dirs/skip-files flag (#10070) * feat(report): add Trivy version to JSON output (#10065) * fix(rust): add cargo workspace members glob support (#10032) * feat: add AnalyzedBy field to track which analyzer detected packages (#10059) * fix: use canonical SPDX license IDs from embeded licenses.json (#10053) * docs: fix link to Docker Image Specification (#10057) * feat(secret): add detection for Symfony default secret key (#9892) * refactor(misconf): move common logic to base value and simplify typed values (#9986) * fix(java): add hash of GAV+root pom file path for pkgID for packages from pom.xml files (#9880) * feat(misconf): use Terraform plan configuration to partially restore schema (#9623) * feat(misconf): add action block to Terraform schema (#10035) * fix(misconf): correct typos in block and attribute names (#9993) * test(misconf): simplify test values using *Test helpers (#9985) * fix(misconf): safely parse rotation_period in google_kms_crypto_key (#9980) * feat(misconf): support for ARM resources defined as an object (#9959) * feat(misconf): support for azurerm_*_web_app (#9944) * test: migrate private test helpers to `export_test.go` convention (#10043) * chore(deps): bump github.com/sigstore/cosign/v2 from 2.2.4 to 2.6.2 (#10048) * fix(secret): improve word boundary detection for Hugging Face tokens (#10046) * fix(go): use ldflags version for all pseudo-versions (#10037) * chore: switch to ID from AVDID in internal and user-facing fields (#9655) * refactor(misconf)!: use ID instead of AVDID for providers mapping (#9752) * fix: move enum into items for array-type fields in JSON Schema (#10039) * docs: fix incorrect documentation URLs (#10038) * feat(sbom): exclude PEP 770 SBOMs in .dist-info/sboms/ (#10033) * fix(docker): fix non-det scan results for images with embedded SBOM (#9866) * chore(deps): bump the github-actions group with 11 updates (#10001) * test: fix assertion after 2026 roll over (#10002) * fix(vuln): skip vulns detection for CentOS Stream family without scan failure (#9964) * fix(license): normalize licenses for PostAnalyzers (#9941) * feat(nodejs): parse licenses from `package-lock.json` file (#9983) * chore: update reference links to Go Wiki (#9987) * refactor: add xslices.Map and replace lo.Map usages (#9984) * fix(image): race condition in image artifact inspection (#9966) * feat(flag): add JSON Schema for trivy.yaml configuration file (#9971) * refactor(debian): use txtar format for test data (#9957) * chore(deps): bump `golang.org/x/tools` to `v0.40.0` + `gopls` to `v0.21.0` (#9973) * feat(rootio): Update trivy db to support usage of Severity from root.io feed (#9930) * feat(vuln): skip vulnerability scanning for third-party packages in Debian/Ubuntu (#9932) * docs: add info that `--file-pattern` flag doesn't disable default behaviuor (#9961) * perf(misconf): optimize string concatenation in azure scanner (#9969) * chore: add client option to install script (#9962) * ci(helm): bump Trivy version to 0.68.2 for Trivy Helm Chart 0.20.1 (#9956) * chore(deps): bump github.com/quic-go/quic-go from 0.54.1 to 0.57.0 (#9952) * docs: update binary signature verification for sigstore bundles (#9929) * chore(deps): bump alpine from `3.22.1` to `3.23.0` (#9935) * chore(alpine): add EOL date for alpine 3.23 (#9934) * feat(cloudformation): add support for Fn::ForEach (#9508) * ci: enable `check-latest` for `setup-go` (#9931) * feat(debian): detect third-party packages using maintainer list (#9917) * fix(vex): add CVE-2025-66564 as not_affected into Trivy VEX file (#9924) * feat(helm): add sslCertDir parameter (#9697) * fix(misconf): respect .yml files when Helm charts are detected (#9912) * feat(php): add support for dev dependencies in Composer (#9910) * chore(deps): bump the common group across 1 directory with 9 updates (#9903) * chore(deps): bump github.com/docker/cli from 29.0.3+incompatible to 29.1.1+incompatible in the docker group (#9859) * fix: remove trailing tab in statefulset template (#9889) * feat(julia): enable vulnerability scanning for the Julia language ecosystem (#9800) * feat(misconf): initial ansible scanning support (#9332) * feat(misconf): Update Azure Database schema (#9811) * ci(helm): bump Trivy version to 0.68.1 for Trivy Helm Chart 0.20.0 (#9869) * chore: update the install script (#9874) trivy-0.70.0-bp157.2.9.1.src.rpm trivy-0.70.0-bp157.2.9.1.x86_64.rpm trivy-0.70.0-bp157.2.9.1.i586.rpm trivy-0.70.0-bp157.2.9.1.aarch64.rpm trivy-0.70.0-bp157.2.9.1.ppc64le.rpm trivy-0.70.0-bp157.2.9.1.s390x.rpm openSUSE-2026-164 Security update for tor critical openSUSE Backports SLE-15-SP7 Update This update for tor fixes the following issues: - Update to 0.4.9.8 * Fix out-of-bounds read (boo#1264341, CVE-2026-44597, TROVE-2026-011) * Do not attempt or accept BEGIN_DIR via conflux legs (boo#1264342, CVE-2026-44599,TROVE-2026-008) * Adjust conflux out-of-order queue accounting when clearing a queue (boo#1264343, CVE-2026-44600, TROVE-2026-010) * Fix a client-side crash caused by double-close of a circuit while under circuit queue memory pressure (boo#1264344, CVE-2026-44601, TROVE-2026-009) * Fix null pointer dereference when receiving a CERT cell out of order (boo#1264345, CVE-2026-44602, TROVE-2026-006) * Fix off-by-one out-of-bounds read if a malformed BEGIN cell is received (boo#1264346, CVE-2026-44603, TROVE-2026-007) - upate to 0.4.9.5: * first stable release in the 0.4.9 series * introduces a new circuit-level encryption design for better client security * introduce a more scalable way for large relay operators to annotate which relays they run so clients can avoid using too many of them in a single circuit tor-0.4.9.8-bp157.2.9.1.src.rpm tor-0.4.9.8-bp157.2.9.1.x86_64.rpm tor-0.4.9.8-bp157.2.9.1.aarch64.rpm tor-0.4.9.8-bp157.2.9.1.ppc64le.rpm tor-0.4.9.8-bp157.2.9.1.s390x.rpm openSUSE-2026-174 Security update for cpp-httplib important openSUSE Backports SLE-15-SP7 Update This update for cpp-httplib fixes the following issues: - CVE-2026-21428: Fixed a server-side request forgery via header injection (boo#1255835) - CVE-2026-22776: Fixed unsafe handling of compressed HTTP request that could cause a denial of service (boo#1256518) - CVE-2026-28434: Fixed that the default exception handler could leak e.what() to clients via EXCEPTION_WHAT response header (boo#1259221) - CVE-2026-28435: Fixed a payload size limit bypass via gzip decompression in ContentReader (streaming) that could lead to denial of service (boo#1259220) - CVE-2026-29076: Fixed denial of service via crafted HTTP POST request (boo#1259373) cpp-httplib-0.20.1-bp157.2.6.1.src.rpm cpp-httplib-devel-0.20.1-bp157.2.6.1.x86_64.rpm libcpp-httplib0_20-0.20.1-bp157.2.6.1.x86_64.rpm cpp-httplib-devel-0.20.1-bp157.2.6.1.i586.rpm libcpp-httplib0_20-0.20.1-bp157.2.6.1.i586.rpm cpp-httplib-devel-0.20.1-bp157.2.6.1.aarch64.rpm libcpp-httplib0_20-0.20.1-bp157.2.6.1.aarch64.rpm cpp-httplib-devel-0.20.1-bp157.2.6.1.ppc64le.rpm libcpp-httplib0_20-0.20.1-bp157.2.6.1.ppc64le.rpm cpp-httplib-devel-0.20.1-bp157.2.6.1.s390x.rpm libcpp-httplib0_20-0.20.1-bp157.2.6.1.s390x.rpm openSUSE-2026-165 Security update for python-jupyterlab important openSUSE Backports SLE-15-SP7 Update This update for python-jupyterlab fixes the following issues: - CVE-2026-40171: Fixed a one-click authentication token theft via command linker attributes chained with help command (boo#1264348) jupyter-jupyterlab-2.2.10-bp157.3.3.1.noarch.rpm python-jupyterlab-2.2.10-bp157.3.3.1.src.rpm python3-jupyterlab-2.2.10-bp157.3.3.1.noarch.rpm openSUSE-2026-167 Security update for gosec moderate openSUSE Backports SLE-15-SP7 Update This update for gosec fixes the following issues: - Update to version 2.26.1: * Update cosign to v3.0.6 (#1659) * Sync taint rule docs and add missing CWE mappings for G113/G307 (#1658) * Update all dependencies (#1657) * Add G710 rule for open redirect via taint analysis (#1654) * Fix formatting * Update the default models use by autofix and phase out the older models * Format and clean-up the README * Add HTTP file-serving function to the skins of pathtraversal analyzer (#1647) * Skip flaging the TLS min version for go 1.18+ (#1646) * chore(deps): bump go.opentelemetry.io/otel from 1.39.0 to 1.41.0 (#1645) * Added filepath.Abs as a sanitizer (#1643) * Allow rune to byte conversion (#1642) * Allow platform specific conversions (#1641) * chore(deps): update all dependencies (#1639) * chore(deps): update all dependencies (#1634) * chore(go): update supported Go versions to 1.25.9 and 1.26.2 (#1633) * Fix: Bump go-version: 1.25.8 to 1.25.9 in ci (#1632) * fix(taint): gate *http.Request auto-taint on entry-point detection (#1630) * chore(deps): update all dependencies (#1631) * Added a visited cycle-detection guard in the *ssa.Phi case (#1626) * chore(deps): update all dependencies (#1625) * fix(G706): scope slog sinks to msg arg only to prevent false positives on structured attributes (#1623) * Gate the AI security review by the security-review environment (#1621) * Fix anthropic autofix after dependencies update (#1620) * chore(deps): update all dependencies (#1619) * chore(action): bump gosec to 2.25.0 (#1618) - Update to version 2.25.0: * chore(deps): bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#1617) * fix: allow barry action to access secrets on fork PRs (#1616) * fix: reduce G117 false positives for custom marshalers and transformed values (#1614) (#1615) * Add barry security scanner as a step in the CI (#1612) * chore(deps): update all dependencies (#1611) * fix: prevent taint analysis hang on packages with many CHA call graph edges (#1608) (#1610) * Add some skills for claude code to automate some tasks (#1609) * Add G701-G706 rule-to-CWE mappings and CWE-117, CWE-918 entries (#1606) * fix: skip SSA analysis on ill-typed packages to prevent panic (#1607) * Port G120 from SSA-based to taint analysis (fixes #1600, #1603) (#1605) * fix(G118): eliminate false positive for package-level cancel variables (#1602) * feat: add G124 rule for insecure HTTP cookie configuration (#1599) * feat: add G709 rule for unsafe deserialization of untrusted data (#1598) * feat: add G708 rule for server-side template injection via text/template (#1597) * fix(G118): eliminate false positive when cancel is called via struct field in a closure (#1596) * Fix infinite recursion in interprocedural taint analysis (#1594) * Fix G118 false positive when cancel is stored in returned struct field (#1593) * Fix G118 false positive on cancel called inside goroutine closure (#1592) * fix(analyzer): per-package rule instantiation eliminates concurrent map crash (#1589) * chore(deps): update all dependencies (#1588) * fix(G118): treat returned cancel func as called (fixes #1584) (#1585) * chore(go): update supported Go versions to 1.25.8 and 1.26.1 (#1583) * Update the README with the correct version of the Github action for gosec (#1582) * chore(deps): update all dependencies (#1579) * Fix G115 false positives for guarded int64-to-byte conversions (#1578) * Update the container image migration notice (#1576) * chore(action): bump gosec to 2.24.7 (#1575) - Update to version 2.24.7: * Ignore nosec comments in action integration workflow to generate some warnings (#1573) * Add a workflow for action integration test (#1571) * fix(sarif): avoid invalid null relationships in SARIF output (#1569) * chore: migrate gosec container image references to GHCR (#1567) * Update gorelease to use the latest cosign bundle argument (#1565) * Migrate goreleaser to use the proper cosign arguments (#1564) * Update the cosing to version v3.0.5 (#1563) * fix(release): use existing cosign-installer action version (#1562) * chore(prompts): add skill and prompt to update supported Go versions (#1561) * chore(prompts): add action version update skill and prompt (#1560) * fix(analyzers): avoid SSA dependency cycle blowups in issue #1555 paths (#1559) * Add a SKILL and PROMPT for fixing a GitHub issue (#1558) * Add a SKILL and PROMPT for generating rules with AI (#1557) * fix(G120): prevent hang-like analysis blowup in wrapper protection checks (#1556) * fix(G705): eliminate false positive when guard type cannot be resolved (#1554) * Remove gcmurphy from funding list * Extend the release workflow to push the container images also to GHCR * Update to gosec to v2.24.0 in the action and fix the docker image signing (#1552) - Update to version 2.24.0: * fix: G704 false positive on const URL (#1551) * fix(G705): eliminate false positive for non-HTTP io.Writer (#1550) * G120: avoid false positive when MaxBytesReader is applied in middleware (#1547) * Fix G602 regression coverage for issue #1545 and stabilize G117 TOML test dependency (#1546) * taint: skip `context.Context` arguments during taint propagation to fix false positives (#1543) * test: add missing rules to formatter report tests (#1540) * chore(deps): update all dependencies (#1541) * Regenrate the TLS config rule (#1539) * Improve documentation (#1538) * Expand analyzer-core test coverage for orchestration, go/analysis adapter logic, and taint integration (#1537) * Add unit tests for CLI orchestration, TLS config generation, and SSA cache behavior (#1536) * Add G707 taint analyzer for SMTP command/header injection (#1535) * Add G123 analyzer for tls.VerifyPeerCertificate resumption bypass risk (#1534) * Add G122 SSA analyzer for filepath.Walk/WalkDir symlink TOCTOU race risks (#1532) * fix(G602): avoid false positives for range-over-array indexing (#1531) * Improve taint analyzer performance with shared SSA cache, parallel analyzer execution, and CI regression guard (#1530) * fix: taint analysis false positives with G703,G705 (#1522) * Extend the G117 rule to cover other types of serialization such as yaml/xml/toml (#1529) * Fix the G117 rule to take the JSON serialization into account (#1528) * (docs) fix justification format (#1524) * Add G121 analyzer for unsafe CORS bypass patterns in CrossOriginProtection (#1521) * Add G120 SSA analyzer for unbounded form parsing in HTTP handlers (#1520) * Add G119 analyzer for unsafe redirect header propagation in CheckRedirect callbacks (#1519) * Fix G115 false positives and negatives (Issue #1501) (#1518) * chore(deps): update all dependencies (#1517) * Add G118 SSA analyzer for context propagation failures that can cause goroutine/resource leaks (#1516) * Add G113: Detect HTTP Request Smuggling via conflicting headers (CVE-2025-22891, CWE-444) (#1515) * Add G408: SSH PublicKeyCallback Authentication Bypass Analyzer (#1513) * Add more unit tests to improve coverage (#1512) * Improve test coverage in various areas (#1511) * Imprve the test coverage (#1510) * Fix incorrect detection of fixed iv in G407 (#1509) * Add support for go 1.26.x and removed support for go 1.24.x (#1508) * Fix the sonar report to follow the latest schema (#1507) * fix: broken taint analysis causing false positives (#1506) * fix: panic on float constants in overflow analyzer (#1505) * fix: panic when scanning multi-module repos from root (#1504) * fix: G602 false positive for array element access (#1499) * Update gosec to version v2.23.0 in the Github action (#1496) - Update to version 2.23.0: * feat: Support for adding taint analysis engine (#1486) * chore(deps): update all dependencies (#1494) * chore(deps): update all dependencies (#1494) * chore(deps): update all dependencies (#1488) * Fix G602 analyzer panic that kills gosec process (#1491) * update go version to 1.25.7 (#1492) * Fix URL regexp and remove redundant Google regex patterns (#1485) * feat: implement global cache usage in rules (#1480) * chore(deps): update module google.golang.org/genai to v1.43.0 (#1484) * refactor: optimize nosec parsing and reduce allocations (#1478) * Fix SARIF artifactChanges null validation error (#1483) * feat: optimize GetCallInfo with per-package sync.Pool caching (#1481) * feat: implement entropy pre-filtering to optimize secret detection (#1479) * feat: ensure GoVersion is cached using sync.Once (#1477) * Fix #1240: nosec comments now work with trailing open brackets (#1475) * Debug Build Profiling Support: Code improvement suggestions for PR#1471 (#1476) * Update the go version to 1.25.6 and 1.24.12 (#1474) * G115: Enhance RangeAnalyzer with constant propagation and chained arithmetic support (#1470) * chore(deps): update all dependencies (#1473) * feat: support path-based rule exclusions via exclude-rules (#1465) * Optimize analyzer with parallel package processing (#1466) * feat: add goanalysis package for nogo (#1449) * Refactor Analyzers: Unify Range Logic & Optimize Allocations (#1464) * Optimize G115, G602, G407 analyzers to reduce allocations and memory (#1463) * refactor(g115): improve coverage (#1462) * Refine G407 to improve detection and coverage of hardcoded nonces (#1460) * chore(deps): update all dependencies (#1461) * Refactor rules to use callListRule base structure (#1458) * feat(slice): enhance slice bounds analysis with dynamic bounds handling (#1457) * remove deprecated ast.Object (#1455) * feat(sql): enhance SQL injection detection with improved string concatenation checks (#1454) * feat(rules): enhance subprocess variable checks (#1453) * feat(resolve): enhance TryResolve to handle KeyValueExpr, IndexExpr, and SliceExpr (#1452) * feat: add secrets serialization G117 (#1451) * feat(rules): add support for detecting high entropy strings in composite literals (#1447) * whitelist crypto/rand Read from error checks (#1446) * chore(deps): update all dependencies (#1443) * Improve slice bound check (#1442) * docs: add documentation for using gosec with private modules (#1441) * chore(deps): update all dependencies (#1440) * docs: add G116 rule description to README (#1439) * Update GitHub action to gosec 2.22.11 (#1438) - Update to version 2.22.11: * feature: add rule for trojan source (#1431) * feat(ai): add OpenAI and custom API provider support (#1424) * chore: Migrate from gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 (#1437) * chore(deps): update module google.golang.org/genai to v1.37.0 (#1435) * refactor: simplify report functions in main.go (#1434) * Update go to 1.25.5 and 1.24.11 in CI (#1433) * chore(deps): update all dependencies (#1425) * feat(ai): add support for latest Claude models and update provider flags (#1423) * Bump golang.org/x/crypto from 0.43.0 to 0.45.0 (#1427) * chore(deps): update module golang.org/x/crypto to v0.45.0 [security] (#1428) * fix: correct schema with temporary placeholder (#1418) * perf: skip SSA analysis if no analyzers are loaded (#1419) * test: add sarif validation (#1417) * chore(deps): update all dependencies (#1421) * Update go to version 1.25.4 and 1.24.10 in CI (#1415) * fix: build tag parsing. (#1413) * chore(deps): update all dependencies (#1411) * chore(deps): update all dependencies (#1409) * chore(deps): update all dependencies (#1408) * Update gosec to version v2.22.10 in the github action (#1405) - Update to version 2.22.10: * Update go to version 1.25.3 and 1.24.9 in CI (#1404) * chore(deps): update all dependencies (#1402) * Update go to version 1.25.2 and 2.24.8 in CI (#1401) * chore(deps): update all dependencies (#1399) * check nil slices, partially check bounds (#1396) * Remove unused target from the makefile * Use the ginkgo command install by the dependencies * Keep the go module at 1.24 version for compatibility reasons * Remove manual test deps * fix: text must be supplied when markdown is used * fix: improve error message of CheckAnalyzers * fix: log panic on SSA * chore(deps): update all dependencies * Update gosec to version v.22.9 in the github action - Update to version 2.22.9: * Update cosign to v2.6.0 and go in the CI to latest version * fix(autofix): unnecessary conversion * feat(autofix): update gemini sdk and add anthropic claude * feat(G304): add os.Root remediation hint (Autofix) when Go >= 1.24 * chore(deps): update all dependencies * refactor(G304): remove unused trackJoin helper; no functional change * style: gofmt rules/readfile.go * test(g304): add samples for var perm and var flag with cleaned path\n\n- Ensure G304 does not fire when only non-path args (flag/perm) are variables\n- Both samples use filepath.Clean on the path arg\n- Rules suite remains green (42 passed) * rules(G304): analyze only path arg; ignore flag/perm vars; track Clean and safe Join; fix nil-context panic\n\n- Limit G304 checks to first arg (path) for os.Open/OpenFile/ReadFile, avoiding false positives when flag/perm are variables\n- Track filepath.Clean so cleaned identifiers are treated as safe\n- Consider safe joins: filepath.Join(const|resolvedBase, Clean(var)|cleanedIdent)\n- Record Join(...) assigned to identifiers and allow if later cleaned\n- Fix panic by passing non-nil context in trackJoinAssignStmt\n- All rules tests: 42 passed * rules(G202): detect SQL concat in ValueSpec declarations; add test sample\n\n- Handle var query string = 'SELECT ...' + user style declarations\n- Reuse existing binary expr detection on ValueSpec.Values\n- Add postgres sample mirroring issue #1309 report\n- Rules tests: 42 passed * chore(deps): update all dependencies * chore(deps): update all dependencies * chore(deps): update all dependencies * Update gosec version to v2.22.8 in the Github action - Update to version 2.22.8: * Add support for go version 1.25.0 * Update go version in CI to 1.24.6 and 1.23.12 * chore(deps): update all dependencies * chore(deps): update all dependencies * Update github action to release v2.22.7 - Update to version 2.22.7: * Fix crash in hardcoded_nonce analyzer * Update go action to use release v2.22.6 * Update go version to 1.24.5 and 1.23.11 in the CI * chore(deps): update module google.golang.org/api to v0.242.0 * chore(deps): update all dependencies * chore(deps): update all dependencies * chore(deps): update all dependencies * chore(deps): update all dependencies * Do not allow dashes in file names * Update gosec to version 2.22.5 in Github action - Update to version 2.22.5: * Switch back go.mod to minimum 1.23.0 * Update dependencies * Update go version 1.24.4 and 1.23.10 in CI * chore(deps): update all dependencies * G201/G202: add checks for injection into sql.Conn methods * chore(deps): update module google.golang.org/api to v0.235.0 * chore(deps): update module google.golang.org/api to v0.234.0 * chore(deps): update module google.golang.org/api to v0.233.0 * chore(deps): update module google.golang.org/api to v0.232.0 - Switch vendor from gz to xz for consistency - Switch from version to revision in _service gosec-2.26.1-bp157.2.6.1.src.rpm gosec-2.26.1-bp157.2.6.1.x86_64.rpm gosec-2.26.1-bp157.2.6.1.i586.rpm gosec-2.26.1-bp157.2.6.1.aarch64.rpm gosec-2.26.1-bp157.2.6.1.ppc64le.rpm gosec-2.26.1-bp157.2.6.1.s390x.rpm openSUSE-2026-168 Recommended update for gn moderate openSUSE Backports SLE-15-SP7 Update This update for gn fixes the following issues: - Update to version 0.20260429: * Run update reference in CI * Add `gn suggest` subcommand. * Update documentation * [apple] Optimise enumeration of additional files for Xcode project * [gn] Split SOURCE_SET phony targets to exclude additional outputs from linking * Run formatter in CI * Rework update_reference.sh to run correctly in CI. * IWYU: gn/target.h * Revert "Run formatter and update reference in CI" * Revert "Fix: Ensure only actual object files are included in link inputs" * Run formatter and update reference in CI * Add --diff to run_formatter and update_reference * Fix: Ensure only actual object files are included in link inputs * Run `infra/recipes.py test train`. * Improve EXPECT_EQ diff printing * Simplify success expectations in GN. * Add support for c_additional_outputs in config * Add diffs to EXPECT_EQ. * Advertise QtCreator v20+ built-in GN support * Rename impl:$MODULE to $MODULE_Private. * Only output -fmodule-map-file for the root generated modulemap. * Add function `expand_directory` to gn. * Refactor ModuleType from an enum to a bitset. * Generate two modulemaps per target. * Put dependencies in modulemaps * Run formatter * Include your own modulemap files in module_deps_no_self. * Change default module name in GN to be the full label. gn-0.20260429-bp157.2.15.1.src.rpm gn-0.20260429-bp157.2.15.1.x86_64.rpm gn-0.20260429-bp157.2.15.1.i586.rpm gn-0.20260429-bp157.2.15.1.aarch64.rpm gn-0.20260429-bp157.2.15.1.ppc64le.rpm gn-0.20260429-bp157.2.15.1.s390x.rpm openSUSE-2026-169 Security update for cacti important openSUSE Backports SLE-15-SP7 Update This update for cacti fixes the following issues: - Update to version 1.2.30+git422.049d9187: * fix(cli): repair dead PHP-binary dash-prefix guard in push_out_hosts.php (#7148) * security: require POST for data_input.php?action=whitelist_update (#7149) * fix(database): guard db_fetch_cell_return against missing column name (#7150) * fix(poller-cache): reset loop-scoped $oid and $script_path between iterations (#7136) * security(1.2.x): cacti_validate_sort_column allowlist and related sink hardening (#7072) * fix: Minor wording missed in last pull (#7144) * Data input push issues (#7143) * fix: cacti_input_string_is_safe rejected quoted and digit-suffixed placeholders (#7130) * fix(poller-cache): four integrity bugs in lib/utility.php (#7134) * Checkbox defaults and unsafe metachars (#7141) * fix(test-infra): point Playwright harness plugin defaults at develop, not develop-1.2.x (#7140) * Translated using Weblate (Latvian) * fix: Worflow issues with push_out_hosts.php (#7120) * fix(ci): proc_close exit code on PHP 8.0-8.2; add_device path (#7118) * revert debug change (#7119) * fix: dqselect change handler passes full prefix to dqUpdateDeps (#7117) * security: fix cacti_input_string_is_safe() bypass and add cacti_exec() (GHSA-c4qp-j9r9-fq24) (#7112) * revert: Restore rrdtool hack to compensate for missing CFs in RRDfiles (#7116) * fix: Updating harnesses (#7115) * fix: Restore functions removed in #7098 (#7114) * fix(mailer): prevent null from_name reaching PHPMailer preg_replace() (#7113) * security: harden CSP compliance changes and fix potential XSS in data attributes (#7100) * security: audit and implement SafeSort helpers across missing endpoints (#7098) * fix: Some more CSP Level 3 warnings (#7110) * security: fix sort_column SQL injection in reports list (GHSA-72vr-jr4v-55vf) (#7111) * security: fix stored XSS in CDEF/VDEF/GPRINT preset names (GHSA-v2mq-mxpw-55pf) (#7109) * fix: Stop CSP Level 3 issues on forms (#7107) * fix: One last round of CSP Level 3 fixes (#7106) * feature: Update jstree to 3.3.17 for CSP Level 3 compliance (#7105) * fix: Improve the performance around the internal plugin (#7104) * Dispense with open redirects in link.php to remove any CWE exploit paths (#7103) * fix: Minor Issues Identified by Copilot in Reports Pull Request (#7102) * fix: Remove most of inline reports in Cacti (#7096) * fix(auth): use cacti_cookie_session_set in cacti_auth_transition (#7093) * test(csp): plugin e2e harness covers thold + monitor (#7081) * fix: Auth issues with cookies (#7094) * fix: Harness tests (#7092) * fix: Reduce navigation nonces (#7087) * security: CVE In tree rules interface (#7086) * fix: Add nonces to script tags (#7085) * fix: Adjust placement and wording, update cacti.pot (#7079) * security(csp): nonce mode behind config flag + 3-page pilot + tests (1.2.x) (#7071) * Update translation files * feat(security): architectural security helpers — eliminate vulnerability classes at root (#7054) * docs(changelog): add 12 CVE-2026 security entries resolved in 1.2.31 (#7059) cacti-1.2.30+git422.049d9187-bp157.2.9.1.noarch.rpm cacti-1.2.30+git422.049d9187-bp157.2.9.1.src.rpm openSUSE-2026-170 Security update for perl-CryptX important openSUSE Backports SLE-15-SP7 Update This update for perl-CryptX fixes the following issues: - updated to 0.89.0 (0.089) 0.089 2026-05-10 - new: Crypt::ASN1 - new: Crypt::AuthEnc::SIV - new: Crypt::AuthEnc::XChaCha20Poly1305 - new: Crypt::Cipher::SM4 - new: Crypt::Digest::TurboSHAKE - new: Crypt::Digest::KangarooTwelve - new: Crypt::PK::Ed448 - new: Crypt::PK::X448 - new: Crypt::Stream::XChaCha - new: Crypt::Stream::XSalsa20 - Crypt::PK::Ed25519 - new functions: sign_message_ctx, verify_message_ctx, sign_message_ph, verify_message_ph - Crypt::Digest: object digest accessors now finalize the object; use reset() before reuse - Crypt::Mac + Crypt::AuthEnc: finalized-object lifecycle is now enforced consistently - security/hardening fixes across Digest/Mac/AuthEnc/Mode/Stream/PK/PRNG - fixes related to wycheproof test suite - documentation cleanup & improvements - support for RFC 8702 RSA-PSS-SHAKE128/256 and ECDSA-SHAKE128/256 - support for FRP256v1 elliptic-curve - bundled libtomcrypt update branch:develop (commit: 8b5af49b 2026-05-06) 0.088 2026-04-23 - Crypt::KeyDerivation - new functions: pbkdf1_openssl, bcrypt_pbkdf, scrypt_pbkdf, argon2_pbkdf - Crypt::Misc - new functions: random_v7uuid, is_uuid - bundled libtomcrypt update branch:develop (commit: 2e441a17 2026-04-15) - bundled libtommath update branch:develop (commit: ae40a87 2026-04-20) - security fix CVE-2026-41564 https://github.com/DCIT/perl-CryptX/security/advisories/GHSA-24c2-gp6c-24c6 (boo#1262697) - updated to 0.87.0 (0.087) 0.087 2025-06-11 - bundled libtomcrypt update branch:develop (commit: d448df1 2025-05-06) - bundled libtommath update branch:develop (commit: 839ae9e 2025-06-11) - fix #120 Create SECURITY.md - fix #121 Failures on ARM after upgrading libtommath - security fix CVE-2025-40914 https://github.com/DCIT/perl-CryptX/security/advisories/GHSA-6fh3-7qjq-8v22 (boo#1244472) - updated to 0.86.0 (0.086) 0.086 2025-05-02 - fixe #118 Syncing with recent Math-BigInt - bundled libtomcrypt update branch:develop (commit:3905c289 2025-04-23) - updated to 0.85.0 (0.085) 0.085 2025-02-08 - fix #114 #113 #112 (improved detection of Apple+x86_64 / AESNI) - fix #115 Crypt::PRNG - fix typo and specify ChaCha20 is the default - updated to 0.84.0 (0.084) 0.084 2024-10-16 - libtommath: fix cpantesters crash on freebsd/i386 - updated ppport.h 0.083 2024-10-15 - fix #110 regression: 0.081 fails to parse PEMs that 0.080 parsed fine - bundled libtomcrypt update branch:develop (commit:cbb01b37 2024-10-14) 0.082 2024-10-07 - fix #111 libcryptx-perl: t/sshkey.t fails on some architectures - CHANGE: Crypt::Cipher::Blowfish max key size increased to 72 bytes - bundled libtomcrypt update branch:develop (commit:29af8922 2024-10-07) 0.081 2024-09-08 - fix #107 Drop -msse4.1 -maes for libtomcrypt - fix #105 Several functions in CryptX::AuthEnc deal weirdly with non-simple-string plaintext - fix #104 Add ethereum format signature - fix #103 Use standard __asm__ blocks instead of asm - fix #99 ltc: fix aesni flag handling - fix #87 Add possibility to use different hash algorithms in RSAES-OAEP - BIG CHANGE switch to PEM/SSH key loading via libtomcrypt - bundled libtomcrypt update branch:develop (commit:ce904c86 2024-09-02) perl-CryptX-0.89.0-bp157.2.3.1.src.rpm perl-CryptX-0.89.0-bp157.2.3.1.x86_64.rpm perl-CryptX-0.89.0-bp157.2.3.1.i586.rpm perl-CryptX-0.89.0-bp157.2.3.1.aarch64.rpm perl-CryptX-0.89.0-bp157.2.3.1.ppc64le.rpm perl-CryptX-0.89.0-bp157.2.3.1.s390x.rpm openSUSE-2026-173 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 148.0.7778.167 (boo#1265159) * CVE-2026-8509: Heap buffer overflow in WebML * CVE-2026-8510: Integer overflow in Skia * CVE-2026-8511: Use after free in UI * CVE-2026-8512: Use after free in FileSystem * CVE-2026-8513: Use after free in Input * CVE-2026-8514: Use after free in Aura * CVE-2026-8515: Use after free in HID * CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer * CVE-2026-8517: Object lifecycle issue in WebShare * CVE-2026-8518: Use after free in Blink * CVE-2026-8519: Integer overflow in ANGLE * CVE-2026-8520: Race in Payments * CVE-2026-8521: Use after free in Tab Groups * CVE-2026-8522: Use after free in Downloads * CVE-2026-8523: Use after free in Mojo * CVE-2026-8558: Out of bounds write in Fonts * CVE-2026-8524: Out of bounds write in WebAudio * CVE-2026-8525: Heap buffer overflow in ANGLE * CVE-2026-8526: Out of bounds write in WebRTC * CVE-2026-8527: Insufficient validation of untrusted input in Downloads * CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8529: Heap buffer overflow in Codecs * CVE-2026-8530: Use after free in Network * CVE-2026-8531: Heap buffer overflow in WebML * CVE-2026-8532: Integer overflow in XML * CVE-2026-8533: Use after free in Accessibility * CVE-2026-8534: Integer overflow in GPU * CVE-2026-8535: Out of bounds read in Media * CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode * CVE-2026-8537: Insufficient policy enforcement in ViewTransitions * CVE-2026-8538: Insufficient validation of untrusted input in GPU * CVE-2026-8539: Script injection in SanitizerAPI * CVE-2026-8540: Type Confusion in V8 * CVE-2026-8541: Out of bounds read in UI * CVE-2026-8542: Use after free in Core * CVE-2026-8543: Out of bounds read in FileSystem * CVE-2026-8544: Use after free in Media * CVE-2026-8545: Object corruption in Compositing * CVE-2026-8546: Out of bounds read in GPU * CVE-2026-8547: Insufficient policy enforcement in Passwords * CVE-2026-8548: Out of bounds write in Media * CVE-2026-8549: Use after free in Media * CVE-2026-8550: Use after free in Google Lens * CVE-2026-8551: Use after free in Downloads * CVE-2026-8552: Heap buffer overflow in GPU * CVE-2026-8553: Use after free in GPU * CVE-2026-8554: Type Confusion in ANGLE * CVE-2026-8555: Use after free in GTK * CVE-2026-8556: Inappropriate implementation in ANGLE * CVE-2026-8557: Use after free in Accessibility * CVE-2026-8559: Integer overflow in Internationalization * CVE-2026-8560: Heap buffer overflow in SwiftShader * CVE-2026-8561: Incorrect security UI in Fullscreen * CVE-2026-8562: Side-channel information leakage in Navigation * CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox * CVE-2026-8564: Incorrect security UI in Downloads * CVE-2026-8565: Inappropriate implementation in Downloads * CVE-2026-8566: Insufficient policy enforcement in Payments * CVE-2026-8567: Integer overflow in ANGLE * CVE-2026-8568: Insufficient policy enforcement in AI * CVE-2026-8569: Out of bounds write in Codecs * CVE-2026-8570: Type Confusion in V8 * CVE-2026-8571: Insufficient policy enforcement in GPU * CVE-2026-8572: Insufficient policy enforcement in Network * CVE-2026-8573: Integer overflow in Codecs * CVE-2026-8574: Use after free in Core * CVE-2026-8575: Use after free in UI * CVE-2026-8576: Inappropriate implementation in CORS * CVE-2026-8577: Integer overflow in Fonts * CVE-2026-8578: Out of bounds read in GPU * CVE-2026-8579: Insufficient validation of untrusted input in Skia * CVE-2026-8580: Use after free in Mojo * CVE-2026-8581: Use after free in GPU * CVE-2026-8582: Object lifecycle issue in Dawn * CVE-2026-8583: Insufficient policy enforcement in WebXR * CVE-2026-8584: Inappropriate implementation in Views * CVE-2026-8585: Inappropriate implementation in Media * CVE-2026-8586: Inappropriate implementation in Chromoting * CVE-2026-8587: Use after free in Extensions - Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175) * CVE-2026-7896: Integer overflow in Blink * CVE-2026-7897: Use after free in Mobile * CVE-2026-7898: Use after free in Chromoting * CVE-2026-7899: Out of bounds read and write in V8 * CVE-2026-7900: Heap buffer overflow in ANGLE * CVE-2026-7901: Use after free in ANGLE * CVE-2026-7902: Out of bounds memory access in V8 * CVE-2026-7903: Integer overflow in ANGLE * CVE-2026-7904: Out of bounds read in Fonts * CVE-2026-7905: Insufficient validation of untrusted input in Media * CVE-2026-7906: Use after free in SVG * CVE-2026-7907: Use after free in DOM * CVE-2026-7908: Use after free in Fullscreen * CVE-2026-7909: Inappropriate implementation in ServiceWorker * CVE-2026-7910: Use after free in Views * CVE-2026-7911: Use after free in Aura * CVE-2026-7912: Integer overflow in GPU * CVE-2026-7913: Insufficient policy enforcement in DevTools * CVE-2026-7914: Type Confusion in Accessibility * CVE-2026-7915: Insufficient data validation in DevTools * CVE-2026-7916: Insufficient data validation in InterestGroups * CVE-2026-7917: Use after free in Fullscreen * CVE-2026-7918: Use after free in GPU * CVE-2026-7919: Use after free in Aura * CVE-2026-7920: Use after free in Skia * CVE-2026-7921: Use after free in Passwords * CVE-2026-7922: Use after free in ServiceWorker * CVE-2026-7923: Out of bounds write in Skia * CVE-2026-7924: Uninitialized Use in Dawn * CVE-2026-7925: Use after free in Chromoting * CVE-2026-7926: Use after free in PresentationAPI * CVE-2026-7927: Type Confusion in Runtime * CVE-2026-7928: Use after free in WebRTC * CVE-2026-7929: Use after free in MediaRecording * CVE-2026-7930: Insufficient validation of untrusted input in Cookies * CVE-2026-7931: Insufficient validation of untrusted input in iOS * CVE-2026-7932: Insufficient policy enforcement in Downloads * CVE-2026-7933: Out of bounds read in WebCodecs * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker * CVE-2026-7935: Inappropriate implementation in Speech * CVE-2026-7936: Object lifecycle issue in V8 * CVE-2026-7937: Insufficient policy enforcement in DevTools * CVE-2026-7938: Use after free in CSS * CVE-2026-7939: Inappropriate implementation in SanitizerAPI * CVE-2026-7940: Use after free in V8 * CVE-2026-7941: Insufficient validation of untrusted input in Mobile * CVE-2026-7942: Integer overflow in ANGLE * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache * CVE-2026-7945: Insufficient validation of untrusted input in COOP * CVE-2026-7946: Insufficient policy enforcement in WebUI * CVE-2026-7947: Insufficient validation of untrusted input in Network * CVE-2026-7948: Race in Chromoting * CVE-2026-7949: Out of bounds read in Skia * CVE-2026-7950: Out of bounds read and write in GFX * CVE-2026-7951: Out of bounds write in WebRTC * CVE-2026-7952: Insufficient policy enforcement in Extensions * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox * CVE-2026-7954: Race in Shared Storage * CVE-2026-7955: Uninitialized Use in GPU * CVE-2026-7956: Use after free in Navigation * CVE-2026-7957: Out of bounds write in Media * CVE-2026-7958: Inappropriate implementation in ServiceWorker * CVE-2026-7959: Inappropriate implementation in Navigation * CVE-2026-7960: Race in Speech * CVE-2026-7961: Insufficient validation of untrusted input in Permissions * CVE-2026-7962: Insufficient policy enforcement in DirectSockets * CVE-2026-7963: Inappropriate implementation in ServiceWorker * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem * CVE-2026-7965: Insufficient validation of untrusted input in DevTools * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-7967: Insufficient validation of untrusted input in Navigation * CVE-2026-7968: Insufficient validation of untrusted input in CORS * CVE-2026-7969: Integer overflow in Network * CVE-2026-7970: Use after free in TopChrome * CVE-2026-7971: Inappropriate implementation in ORB * CVE-2026-7972: Uninitialized Use in GPU * CVE-2026-7973: Integer overflow in Dawn * CVE-2026-7974: Use after free in Blink * CVE-2026-7975: Use after free in DevTools * CVE-2026-7976: Use after free in Views * CVE-2026-7977: Inappropriate implementation in Canvas * CVE-2026-7978: Inappropriate implementation in Companion * CVE-2026-7979: Inappropriate implementation in Media * CVE-2026-7980: Use after free in WebAudio * CVE-2026-7981: Out of bounds read in Codecs * CVE-2026-7982: Uninitialized Use in WebCodecs * CVE-2026-7983: Out of bounds read in Dawn * CVE-2026-7984: Use after free in ReadingMode * CVE-2026-7985: Use after free in GPU * CVE-2026-7986: Insufficient policy enforcement in Autofill * CVE-2026-7987: Use after free in WebRTC * CVE-2026-7988: Type Confusion in WebRTC * CVE-2026-7989: Insufficient data validation in DataTransfer * CVE-2026-7990: Insufficient validation of untrusted input in Updater * CVE-2026-7991: Use after free in UI * CVE-2026-7992: Insufficient validation of untrusted input in UI * CVE-2026-7993: Insufficient validation of untrusted input in Payments * CVE-2026-7994: Inappropriate implementation in Chromoting * CVE-2026-7995: Out of bounds read in AdFilter * CVE-2026-7996: Insufficient validation of untrusted input in SSL * CVE-2026-7997: Insufficient validation of untrusted input in Updater * CVE-2026-7998: Insufficient validation of untrusted input in Dialog * CVE-2026-7999: Inappropriate implementation in V8 * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver * CVE-2026-8001: Use after free in Printing * CVE-2026-8002: Use after free in Audio * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups * CVE-2026-8004: Insufficient policy enforcement in DevTools * CVE-2026-8005: Insufficient validation of untrusted input in Cast * CVE-2026-8006: Insufficient policy enforcement in DevTools * CVE-2026-8007: Insufficient validation of untrusted input in Cast * CVE-2026-8008: Inappropriate implementation in DevTools * CVE-2026-8009: Inappropriate implementation in Cast * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8011: Insufficient policy enforcement in Search * CVE-2026-8012: Inappropriate implementation in MHTML * CVE-2026-8013: Insufficient validation of untrusted input in FedCM * CVE-2026-8014: Inappropriate implementation in Preload * CVE-2026-8015: Inappropriate implementation in Media * CVE-2026-8016: Use after free in WebRTC * CVE-2026-8017: Side-channel information leakage in Media * CVE-2026-8018: Insufficient policy enforcement in DevTools * CVE-2026-8019: Insufficient policy enforcement in WebApp * CVE-2026-8020: Uninitialized Use in GPU * CVE-2026-8021: Script injection in UI * CVE-2026-8022: Inappropriate implementation in MHTML chromedriver-148.0.7778.167-bp157.2.157.1.x86_64.rpm chromium-148.0.7778.167-bp157.2.157.1.nosrc.rpm chromium-148.0.7778.167-bp157.2.157.1.x86_64.rpm chromedriver-148.0.7778.167-bp157.2.157.1.aarch64.rpm chromium-148.0.7778.167-bp157.2.157.1.aarch64.rpm chromedriver-148.0.7778.167-bp157.2.157.1.ppc64le.rpm chromium-148.0.7778.167-bp157.2.157.1.ppc64le.rpm openSUSE-2026-176 Security update for cockpit important openSUSE Backports SLE-15-SP7 Update This update for cockpit fixes the following issues: - CVE-2026-4802: Fixed a remote command execution via unsanitized user-controlled parameters within crafted links in system logs UI (boo#1265040). cockpit-321-bp157.2.3.2.src.rpm cockpit-321-bp157.2.3.2.x86_64.rpm cockpit-bridge-321-bp157.2.3.2.x86_64.rpm cockpit-devel-321-bp157.2.3.2.x86_64.rpm cockpit-doc-321-bp157.2.3.2.noarch.rpm cockpit-kdump-321-bp157.2.3.2.noarch.rpm cockpit-networkmanager-321-bp157.2.3.2.noarch.rpm cockpit-packagekit-321-bp157.2.3.2.noarch.rpm cockpit-pcp-321-bp157.2.3.2.x86_64.rpm cockpit-selinux-321-bp157.2.3.2.noarch.rpm cockpit-storaged-321-bp157.2.3.2.noarch.rpm cockpit-system-321-bp157.2.3.2.noarch.rpm cockpit-ws-321-bp157.2.3.2.x86_64.rpm cockpit-321-bp157.2.3.2.aarch64.rpm cockpit-bridge-321-bp157.2.3.2.aarch64.rpm cockpit-devel-321-bp157.2.3.2.aarch64.rpm cockpit-pcp-321-bp157.2.3.2.aarch64.rpm cockpit-ws-321-bp157.2.3.2.aarch64.rpm cockpit-321-bp157.2.3.2.ppc64le.rpm cockpit-bridge-321-bp157.2.3.2.ppc64le.rpm cockpit-devel-321-bp157.2.3.2.ppc64le.rpm cockpit-pcp-321-bp157.2.3.2.ppc64le.rpm cockpit-ws-321-bp157.2.3.2.ppc64le.rpm cockpit-321-bp157.2.3.2.s390x.rpm cockpit-bridge-321-bp157.2.3.2.s390x.rpm cockpit-devel-321-bp157.2.3.2.s390x.rpm cockpit-pcp-321-bp157.2.3.2.s390x.rpm cockpit-ws-321-bp157.2.3.2.s390x.rpm openSUSE-2026-171 Security update for git-bug important openSUSE Backports SLE-15-SP7 Update This update for git-bug fixes the following issues: - Fix CVE-2026-1229 and CVE-2026-41506 - CVE-2026-1229: CIRCL has an incorrect calculation in secp384r1 CombinedMult (boo#1265416, GO-2026-4550) update github.com/cloudflare/circl to v1.6.3 - CVE-2026-41506: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (boo#1264955, GO-2026-4910), update github.com/go-git/go-git/v5 to v5.17.1 - Revendor to include fixed version of depending libraries: - GO-2025-4116 (CVE-2025-47913, boo#1253506) upgrade golang.org/x/crypto to v0.43.0 - GO-2025-3900 (GHSA-2464-8j7c-4cjm) upgrade github.com/go-viper/mapstructure/v2 to v2.4.0 - GO-2025-3787 (GHSA-fv92-fjc5-jj9h) included in the previous - GO-2025-3754 (GHSA-2x5j-vhc8-9cwm) upgrade github.com/cloudflare/circl to v1.6.1 - GO-2025-4134 (CVE-2025-58181, boo#1253930) upgrade golang.org/x/crypto/ssh to v0.45.0 - GO-2025-4135 (CVE-2025-47914, boo#1254084) upgrade golang.org/x/crypto/ssh/agent to v0.45.0 git-bug-0.10.1-bp157.2.6.1.src.rpm git-bug-0.10.1-bp157.2.6.1.x86_64.rpm git-bug-bash-completion-0.10.1-bp157.2.6.1.noarch.rpm git-bug-fish-completion-0.10.1-bp157.2.6.1.noarch.rpm git-bug-zsh-completion-0.10.1-bp157.2.6.1.noarch.rpm git-bug-0.10.1-bp157.2.6.1.i586.rpm git-bug-0.10.1-bp157.2.6.1.aarch64.rpm git-bug-0.10.1-bp157.2.6.1.ppc64le.rpm git-bug-0.10.1-bp157.2.6.1.s390x.rpm openSUSE-2026-172 Security update for perl-Net-CIDR important openSUSE Backports SLE-15-SP7 Update This update for perl-Net-CIDR fixes the following issues: - updated to 0.270.0 (0.27) 0.27 Sam Varshavchik cidrvalidate() bug fix. - updated to 0.260.0 (0.26) 0.26 Sam Varshavchik cidrvalidate() should accept IPv6 addresses with one uncompressed 0. - updated to 0.250.0 (0.25) 0.25 Sam Varshavchik Fix warning with Perl 5.40 0.24.1 No changes, re-pushed due to a release problem. 0.24 2025-03-09 brian d foy * Strip leading zeros from octets from addr2cidr boo#1259024 CVE-2021-4456 - updated to 0.230.0 (0.23) 0.23 2025-03-09 brian d foy * Allow unabbreviated IPv6 addresses. 0.22 2025-03-09 Sam Varshavchik * Improve several error messages. 2025-03-09 brian d foy * Allow unabbreviated IPv6 addresses. perl-Net-CIDR-0.270.0-bp157.2.3.1.noarch.rpm perl-Net-CIDR-0.270.0-bp157.2.3.1.src.rpm openSUSE-2026-175 Security update for chromium critical openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 148.0.7778.178 (boo#1265848) * CVE-2026-9111: Use after free in WebRTC * CVE-2026-9110: Inappropriate implementation in UI * CVE-2026-9112: Use after free in GPU * CVE-2026-9113: Out of bounds read in GPU * CVE-2026-9114: Use after free in QUIC * CVE-2026-9115: Insufficient policy enforcement in Service Worker * CVE-2026-9116: Insufficient policy enforcement in ServiceWorker * CVE-2026-9117: Type Confusion in GFX * CVE-2026-9118: Use after free in XR * CVE-2026-9119: Heap buffer overflow in WebRTC * CVE-2026-9120: Use after free in WebRTC * CVE-2026-9126: Use after free in DOM * CVE-2026-9121: Out of bounds read in GPU * CVE-2026-9122: Out of bounds read in GPU * CVE-2026-9123: Heap buffer overflow in Chromecast * CVE-2026-9124: Insufficient validation of untrusted input in Input - add system-wide chromium.conf as in fedora package enable several features by default and disable ai features allow to override via setting CHROMIUM_USER_FLAGS chromedriver-148.0.7778.178-bp157.2.160.1.x86_64.rpm chromium-148.0.7778.178-bp157.2.160.1.nosrc.rpm chromium-148.0.7778.178-bp157.2.160.1.x86_64.rpm chromedriver-148.0.7778.178-bp157.2.160.1.aarch64.rpm chromium-148.0.7778.178-bp157.2.160.1.aarch64.rpm chromedriver-148.0.7778.178-bp157.2.160.1.ppc64le.rpm chromium-148.0.7778.178-bp157.2.160.1.ppc64le.rpm openSUSE-2026-178 Recommended update for perl-JSON-Validator, perl-MCP, perl-Mojolicious moderate openSUSE Backports SLE-15-SP7 Update This update for perl-JSON-Validator, perl-MCP, perl-Mojolicious fixes the following issues: - updated to 0.100.0 (0.10) 0.10 2026-05-06 - Added opt-in server-to-client streaming and session termination to the HTTP transport. Not compatible with pre-forking web servers. - Added support for list_changed notifications. - Added support for progress notifications. - Added MCP::Primitive class. - Added MCP::Server::Context class. - Added MCP::Server::Session class. - Added heartbeat, session_timeout, sessions, and streaming attributes, and a notify method, to MCP::Server::Transport::HTTP. - Added notify method to MCP::Server::Transport::Stdio. - Added notifications method to MCP::Server::Transport. - Added notify_all method to MCP::Server::Transport::HTTP and MCP::Server::Transport::Stdio. - Added notify_list_changed method to MCP::Server. - Added delete_session method to MCP::Client. - updated to 0.80.0 (0.08) 0.08 2026-02-17 - Added support for tool annotations. (d3flex) - updated to 0.70.0 (0.07) 0.07 2026-01-16 - Fixed bug in MCP::Prompt where text prompts had the wrong format. - updated to 0.60.0 (0.06) 0.06 2025-12-05 - Protocol version is now 2025-11-25. - Added support for resources. - Added support for audio and resource results. - Added support for sessions specific prompt, resource, and tool lists. - Added MCP::Resource class. - Added read_resource and list_resources methods to MCP::Client. - Added resource method to MCP::Server. - Added audio_result and resource_link_result methods to MCP::Tool. - Added prompts, resources, and tools events to MCP::Server. - updated to 0.50.0 (0.05) 0.05 2025-08-28 - Added supprot for prompts. - Added MCP::Prompt class. - Added get_prompt and list_pronmpts methods to MCP::Client. - Added prompt method to MCP::Server. - initial package 0.40.0 (0.04) * created by cpanspec 1.84.01 Perl-JSON-Validator was updated: 5.15 2025-03-16T18:47:47 - Make JSON::Validator::Util::is_bool return true when passed perl v5.36+ builtin booleans #275 - Fix wrong resolving of responses component using $ref #277 - Fix array coercion for array parameters with a $ref schema #274 perl-Mojolicious is added as new dependency. perl-JSON-Validator-5.150.0-bp157.2.3.1.noarch.rpm perl-JSON-Validator-5.150.0-bp157.2.3.1.src.rpm perl-MCP-0.100.0-bp157.2.1.noarch.rpm perl-MCP-0.100.0-bp157.2.1.src.rpm perl-Mojolicious-9.450.0-bp157.2.1.noarch.rpm perl-Mojolicious-9.450.0-bp157.2.1.src.rpm openSUSE-2026-177 Recommended update for fwts moderate openSUSE Backports SLE-15-SP7 Update This update for fwts fixes the following issues: - Update to version 26.03.00: * klog.json: Remove duplicate 'too many record IDs' pattern * klog.json: Remove duplicate 'Failed to remap late EFI memory map' pattern * klog.json: Remove duplicate 'SRAT: Failed to mark hotplug range' pattern * klog.json: Remove duplicate 'SRAT: Failed to add memblk to node' pattern * klog.json: Remove duplicate 'SRAT: Too many proximity domains' pattern * klog.json: Remove duplicate 'amba_device_alloc() failed' pattern * klog.json: Remove duplicate 'amba_device_add() failed' pattern * klog.json: Remove duplicate 'Failed to create AML debugger thread' pattern * klog.json: Remove duplicate 'ID map has NULL parent reference' pattern * klog.json: Remove duplicate 'requested ITS ID index' pattern * klog.json: Remove duplicate 'could not register gsi hwirq' pattern * klog.json: Remove duplicate 'iort node pointer overflows, bad table' pattern * klog.json: Remove duplicate 'Limiting number of LPI states to max' pattern * klog.json: Remove duplicate 'SRAT: Unexpected header length' pattern * klog.json: Remove duplicate 'Invalid _FIF element' pattern * klog.json: Remove duplicate 'Could not allocate size' pattern * klog.json: Remove duplicate 'Invalid _TSS data' patterns * klog.json: Remove duplicate 'Invalid _TSD data' pattern * klog.json: Remove duplicate '_OSC request failed' pattern * klog.json: Remove duplicate 'PM: Some devices failed to power down' patterns * klog.json: Add AMD IOMMU command line validation error messages to klog database * klog.json: Add ACPI Embedded Controller ECDT firmware bug error messages to klog database * klog.json: Add ACPI bus kobject registration error messages to klog database * klog.json: Add ACPI SRAT CFMWS BIOS alignment violation error messages to klog database * klog.json: Add ACPI GTDT platform timer firmware bug error messages to klog database * klog.json: Add ACPI IORT firmware bug workaround error messages to klog database * klog.json: Add ACPI processor performance frequency constraint error messages to klog database * kernelscan: Add macro expansion for known kernel logging prefixes * fwts_modprobe: Remove unused sys_finit_module() and sys_delete_module() * build: allow disabling -Werror * acpi: crsdump: Fix printing of IRQ numbers * configure: Allow compilation without libbsd if strlcpy() is available in libc * Make inclusion of <bsd/string.h> optional * acpi: hest: Remove unused variable to avoid compiler warning * lib: framework: Remove unused variable to avoid compiler warning * fwts_args: Silence compiler warning about unused "master_option_index" * lib: fwts_version.h - update to V26.03.00 * debian: update changelog * github: replace softprops/action-gh-release with gh release create * klog.json: remove Interpreter disabled ACPI pattern * acpi: asf: fix wrong format specifiers for id and iana_id fields * acpi: mchi: fix PRIx8 format specifier for uint32_t GSI field * lib: fwts_acpi_tables: fix signed format specifier for subtable type * hotkey: fix const-correctness in hotkey_find_keymap * acpi: wmi: fix const-correctness in wmi_acpi_get_parent_name * lib: fwts_devicetree: fix build error for const-correctness * github: add fwts release workflow * autopackager: mkpackage.sh: remove plucky * klog.json: Add AMD IOMMU driver error messages to klog database * klog.json: Add WMI core driver error messages to klog database * klog.json: Add IdeaPad laptop input and backlight error messages to klog database * klog.json: Add HP WMI platform profile and hwmon error messages to klog database * klog.json: Add Dell WMI base event enable failure message to klog database * klog.json: Add Dell WMI AIO input and notify handler error messages to klog database * klog.json: Add Dell laptop keyboard state error message to klog database * klog.json: Add x86 SMP boot APIC and CPU bringup error messages to klog database * klog.json: Add x86 CPU common error messages to klog database * klog.json: Add x86 MTRR allocation failure message to klog database * klog.json: Add EFI 32-bit ioremap failure to klog database * klog.json: Add EFI 64-bit kernel mapping errors to klog database * klog.json: Add EFI 32/64-bit mismatch error to klog database * klog.json: Add ACPI boot LAPIC/MADT parse errors to klog database * klog.json: Add ACPI MADT wakeup CPU handover error to klog database * klog.json: Add ACPI processor PDC memory allocation error to klog database * klog.json: Add ACPI battery hook errors to klog database * klog.json: Add ACPI ARM64 FFH invalid SMCCC conduit error to klog database * klog.json: Add ACPI DPTF power unsupported event error to klog database * klog.json: Add ACPI watchdog device creation error to klog database * klog.json: Add ACPI PMIC XPower I2C address error to klog database * fwts-test: sync up with s0idle warning change * fwts-test: Update ASPT to include types 3 and 4 * acpi: aspt: Add support for ASPT revision 2 types 3 and 4 * fwts-test: sync up with srat fix memory affinity flags validation * acpi: srat: Fix Memory Affinity Structure flags validation * bios: s0idle: do not treat unsupported S0idle as an error * New tests for Arm PSCI functions * lib: fwts_version.h - update to V26.01.00 * debian: update changelog * debian/tests: only run smccc dkms test when dkms module is run * efi_runtime: remove efi_runtime dkms * fwts-test: sync up for aest update to 2.0 * acpi: aest: update the aest tests for the specification 2.0 * bios: smm: skip lock checks if IGD is not present * doc: update contributors, date and spelling mistake to the manual * acpi: method: fix the LPI packages check and some typos * acpi: rhct: fix typo in error message * Update copyright year to 2026 * ACPICA: Update to version 20251212 * autobrightness: Drop test2 that checks actual_brightness * acpi: apmt: fix typo in APMTNodeTypeUnknown * libfwtsacpica: guard AcpiOsDeleteSemaphore against stale handles * Apicedge tests fail on systems with large number of CPUs * lib: fwts_version.h - update to V25.11.00 * debian: update changelog * auto-packager: mkpackage.sh: add resolute * fwts-test: sync up adding nhlt test * acpi: nhlt: add ACPI 6.6 NHLT table test (mantis 2430) * acpi: nhltdump: sync with ACPI 6.6 NHLT spec * acpi: remove standalone s3pt test * fwts-test: sync up with fpdt records adding * acpi: fpdt: update the FPDT records for ACPI 6.6 (mantis 2416) * fwts-test: sync with the method _VDM was added * acpi: madt: align MP wakeup struct with ACPI 6.6 (mantis 2404) * acpi: method: add _VDM voltage domain test (mantis 2374) * acpi: method: extend _CPC test for ACPI 6.6 (mantis 2353) * acpi: madt: handle GICR and ITS flags for ACPI 6.6 (mantis 2422) * acpi: madt: enforce PSCI when parking protocol deprecated (mantis 2425) * fwts-test: srat: add regression test for the RINTC affinity data * acpi: srat: add RINTC affinity validation (mantis 2433) * fwts-test: sync with the methods _PCS and _PST were added * acpi: method: add tests for _PCS and _PST power source methods (mantis 2478) * acpi: ras2: fix the wrong feature type check * fwts: skip the wake alarm suite if the feature is not implemented * lib: fwts_version.h - update to V25.09.00 * debian: update changelog * auto-packer: mkpackage.sh: use the github tag source directly * wakealarm: skip the reset check when RTC time earlier than current system time * smccc_test: remove deprecated no_llseek to fix the compilation error * fwts-test: add regression tests for MSCT * acpi: msct: fix incorrect length check on max proximity domains * smccc: move the smccc folder out of pci * smccc: minor code style clean-ups, no functional changes * dmicheck: minor code style clean-ups, no functional changes * ACPICA: Update to version 20250807 * lib: fwts_version.h - update to V25.07.00 * debian: update changelog * acpi: madt: fix the wrong length of the multiprocessor wakeup structure * fwts-test: add regression tests for RHCT * acpi: rhct: refine test result layout and format specifiers * auto-packager: mkpackage.sh: remove oracular * acpi: aspt: fix the lable of statement build error * lib: Enable checks and compilation on LoongArch * lib: fwts_klog: return list null when klog read returns zero length * dmicheck: Validation in AARCH64 for Processor ID field in SMBIOS type04 * smccc: Test for implementation of ARM_SMCCC functions * lib: Update current version to ACPI 6.6 * acpi: acpitables: Update acpitables test for ACPI 6.6 * acpi: rhct: Add tests for ACPI RHCT table * acpi: madt: Add AIA and PLIC sub-tables test for RISC-V * acpi: madt: update madt revisions to ACPI 6.6 and add RISC-V * acpi: rsdp: Add xsdt_address check for RISC-V * lib: Add fwts_architecture macro for RISC-V - Update to version 25.05.00: * fwts: slit: sync up with the slit remove equality checking * acpi: slit: remove the checking of the bi-directional equality * fwts-test: add regression tests for ASPT v2 * acpi: aspt: support for the aspt revision 2 * fwts-test: sync up the aspt revision 1 update * acpi: aspt: update ASPT tests for official revision 1 specification * lib: fwts_version.h - update to V25.05.00 * debian: update changelog * fwts.h: fix typo verision * acpi: madt: fix false FAIL on missing GICC UID for disabled CPUs * dmicheck: add total size read checking below maximum allowed * auto-packager: mkpackage.sh: add questing * autobrightness: fix calloc argument order for GCC 15 compatibility * lib: fwts_memorymap: fix failure to retrieve BIOS memory map from dmesg e820 * lib: fwts_memorymap: fix the unchecked end address for strtoull * lib: fwts_log: fix the potential overflow for dumping all log fields * kernelscan: fix structurally unreachable code * opal: fix the unexpected line format * aspm: fix dereference pointer rp_cap before null check * lib/fwts_cpu: correct determination of SEV enablement * acpi: method: Fix _DDC test arguments * cpu/msr: Drop `VM_HSAVE_PA` from consistency checks * ACPICA: Update to version 20250404 * efi_runtime: Fix missing pending status update in getwakeuptime - Update to version 25.03.00: * lib: fwts_version.h - update to V25.03.00 * debian: update changelog * efi_runtime: remove no_llseek which have been removed on kernel 6.12 * klog.json: Add more parse mode setting messages to klog database * klog.json: Add the object type for evaluation messages to klog database * klog.json: Add more ownerid allocate and release messages to klog database * klog.json: Add package init messages to klog database * klog.json: Add child missing data message to klog database * klog.json: Add null object pushing message to klog database * klog.json: Add EC timeout messages to klog database * klog.json: Add ACPI fpdt messages to klog database * klog.json: Add nfit intel messages to klog database * klog.json: Add more intel pmic messages to klog database * klog.json: Add more cppc checking and sending messages to klog database * klog.json: Add more spcr access width messages to klog database * klog.json: Add the thread create failed message to klog database * fwts-test: add regression tests for APMT * acpi: apmt: add tests for acpi APMT table * fwts-test: cedt: sync up tests with CEDT version update * acpi: cedt: update the cedt tests for CXL spec rev3.2 - Update to version 25.01.00: * lib: fwts_version.h - update to V25.01.00 * debian: update changelog * dmicheck: check the config files exist for CONFIG_STRICT_DEVMEM setting * acpi: s3: reading residencyslp_s0_residency_usec for intel platforms * Update copyright year to 2025 * ACPICA: Update to version 20241212 * acpi/s3 : fix stack smashing crash for s3 test * acpitables: update ACPI table revsion test to ACPI 6.5 * acpi: uniqueid: fix the uniqueid test for the CID with package * acpi: acpitables: Correct PCCT revision for ACPI 6.2 * dmicheck: fix the wrong size check for type 4 * acpi/wmi: Stop directing users to outdated LWN article fwts-26.03.00-bp157.2.3.1.src.rpm fwts-26.03.00-bp157.2.3.1.x86_64.rpm fwts-26.03.00-bp157.2.3.1.i586.rpm fwts-26.03.00-bp157.2.3.1.aarch64.rpm openSUSE-2026-180 Security update for perl-YAML-Syck moderate openSUSE Backports SLE-15-SP7 Update This update for perl-YAML-Syck fixes the following issues: updated to 1.450.0 (1.45) see /usr/share/doc/packages/perl-YAML-Syck/Changes * 1.45 Apr 23 2026 [Bug Fixes] - Fix: use syck_base64_free() to fix Windows "Free to wrong pool" crash in base64 encode/decode buffers; also plugs a memory leak (PR #189) - Fix: clear type tag on blessed scalar alias early-return so the stale tag no longer leaks onto the next emitted item (GH #193, PR #194) - Fix: negative float#base60 values produce wrong results; strip sign before accumulating and avoid negative zero for portable stringification (PR #191) - Fix: prevent memory leaks when Load/LoadJSON croak on parse errors (PR #192) [Maintenance] - Test: add coverage for SortKeys and JSON MaxDepth (PR #188) - Test: add error handling coverage for LoadFile/DumpFile (PR #190) - Update README updated to 1.440.0 (1.44) see /usr/share/doc/packages/perl-YAML-Syck/Changes * 1.44 Apr 02 2026 [Bug Fixes] - Fix: positive hex and octal values parsed as 0 with ImplicitTyping (PR #187) - Fix: resolve uintptr_t redefinition error on Win64 MinGW (PR #186) * 1.43 Apr 01 2026 [Bug Fixes] - Fix: prevent resource leaks on croak/early-return paths in Dump (PR #161) - Fix: prevent output SV leaks on croak in Dump/DumpFile callers (PR #163) - Fix: Load() in list context returns empty list for empty/undef input; also applies to LoadBytes and LoadUTF8 (GH #164, PR #165) - Fix: DumpCode serializes prototype string instead of code body (PR #168) - Fix: memory leak in !perl/scalar Load newRV_inc should be newRV_noinc (PR #170) - Fix: add pTHX_ to SAVEDESTRUCTOR_X callback for threaded Perl (GH #175, PR #176) - Fix: add TODO guard for eval_pv leak on Perl < 5.14 (GH #179, PR #180) - Fix: negative hex and octal values parsed as 0 with ImplicitTyping (PR #183) - Fix: negative int#base60 values produce unsigned wraparound (PR #185) [Improvements] - Modernize META_MERGE for CPANTS compliance (PR #162) - Fix hash table size handling and remove compile warnings in syck_st (PR #174) [Maintenance] - Restore TODO guard for Dump code leak test on Perl < 5.26 (PR #167) - Resolve 2010 TODO in perl_json_postprocess with test coverage (PR #166) - CI: upgrade actions to resolve Node.js 20 deprecation warnings (PR #177) * 1.42 Mar 27 2026 [Bug Fixes] - Fix: replace strtok() with strpbrk() and fix sign-compare warnings in perl_syck.h (PR #145) - Fix: terminate plain scalars at document boundaries --- and ... (PR #150) - Fix: skip %TAG and %YAML directives in document header (PR #151) - Fix: plug SV leak when eval_pv croaks on bad perl/code blocks (PR #153) - Fix: allow non-specific tag '!' before block scalars (GH #27, PR #102) - Fix: remove spurious %type <nodeId> for indent_open in gram.y (GH #157, PR #158) - Fix: use modern bison %define api.prefix directive (GH #159, PR #160) [Improvements] - Implement YAML merge key (<<) support (PR #149) [Maintenance] - Remove dead Perl 5.6/5.8 version guards from test files (PR #146) - Add YAML 1.0 spec compliance audit and coverage tests (PR #148) - Add comprehensive round-trip tests for YAML 1.0 spec features (PR #152) - Remove unneeded TODO in t/json-basic.t (PR #154) - Add regex Dump/Load/round-trip tests to perl tag scheme (PR #155) - Do not require a .y file to build YAML::Syck; add brew support for bison - Don't ship docs/ directory in tarball * 1.41 Mar 22 2026 [Bug Fixes] - Fix float parsing on -Dusequadmath perls: use Perl's Atof() instead of strtod() so that floats like -3.14 are not corrupted by double-precision rounding artifacts (GH #140, PR #141) * 1.39 Mar 21 2026 [Bug Fixes] - Fix t/yaml-implicit-typing.t failure with -Duselongdouble perls (GH #138, PR #139) * 1.38 Mar 20 2026 [Bug Fixes] - Fix: escape solidus (/) as \/ in JSON::Syck::Dump for XSS safety (GH #125, PR #130) - Fix: anchor tracking for blessed scalar refs in Dump (GH #126, PR #131) - Fix: prevent buffer underflow in base60 (sexagesimal) parsing (PR #133) - Fix: guard against NULL type from strtok in tag parsing (PR #135) - Fix: correct copy-paste bug in syck_seq_assign() ASSERT macros (PR #137) [Improvements] - Resolve TODO tests for empty/invalid YAML to match actual behavior (GH #127, PR #129) [Maintenance] - Remove dead Perl 5.6 TODOs and convert 5.8 TODO to SKIP (PR #129) - Add comprehensive implicit type resolution test suite (PR #137) - Update MANIFEST to include all unit tests - Clean up test names to remove unnecessary numbering * 1.37 Mar 18 2026 [Features] - Add LoadBytes, LoadUTF8, DumpBytes, DumpUTF8 functions (GH #51) [Fixes] - Fix heap buffer overflow in the YAML emitter - CVE-2026-4177 (GH #67) boo#1259757 - Fix DumpFile with tied filehandles (IO::String, IO::Scalar) (GH #22) - Fix _is_glob to recognize IO::Handle subclasses (GH #23) - Fix memory leak when dumping filehandles (GH #42) - Fix dumping of tied hashes (GH #31) - Fix dumping strings starting with '...' as unquoted plain scalars (GH #34) - Fix dumping strings with tabs and carriage returns as plain scalars (GH #59) - Fix double-dash YAML parsing (GH #35) - Fix extra newline after empty arrays/hashes in YAML output (GH #36) - Remove trailing whitespace from YAML output lines (GH #37, #38, #39) - Fix quoting of \r and \t in YAML output instead of emitting raw bytes (GH #40) - Fix growing !!perl/regexp objects in roundtrips (GH #43) - Fix quoted '=' being transformed into 'str' (GH #45) - Fix backslash-space escape in double-quoted YAML strings (GH #61) - Fix flow sequence comma separator not recognized without trailing space (GH #60) - Fix wide character warning in DumpFile (GH #28) - Fix inline arrays without space after comma (GH #25) - Fix: quote strings matching YAML implicit types to prevent roundtrip failures (GH #26) - Fix JSON::Syck::Dump to use JSON-valid \uXXXX escapes in output (GH #21) - Fix JSON::Syck::Load decoding of \/ and \uXXXX escape sequences (GH #30) - Fix: apply JSON postprocessing to JSON::Syck::DumpFile output (GH #104) - Fix: add tied-filehandle fallback to JSON::Syck::DumpFile (GH #98) - Fix: handle JSON escape sequences in SingleQuote mode Load (GH #99) - Fix: restore Perl 5.8 compatibility in test suite (GH #121) - Fix: correct copy-paste error in Makefile.PL clean target (GH #101) - Fix: correct $SortKeys POD default from false to true (GH #100) - Fix: correct POD documentation errors (GH #103) [Maintenance] - Add C23-compatible function prototypes for GCC 15 compatibility (GH #112) - Silence macOS compiler warnings (GH #92) - Guard stdint.h include for portability (HP-UX 11.11) (GH #33) - Guard stdint.h include in syck_st.h for portability (GH #24) - Update ppport.h to 3.68 - Add regression tests for magical variable dumping (GH #32) - CI: modernize GitHub Actions workflow (GH #123, #124) - CI: add disttest job to validate MANIFEST completeness updated to 1.360.0 (1.36) see /usr/share/doc/packages/perl-YAML-Syck/Changes * 1.36 Oct 10 2025 - Address memory corruption leading to 'str' value being set on empty keys Thanks @timlegge CVE-2025-11683 boo#1252111 * 1.35 Oct 9 2025 - Address parsing error related to string detection on read for empty strings. perl-YAML-Syck-1.450.0-bp157.2.3.1.src.rpm perl-YAML-Syck-1.450.0-bp157.2.3.1.x86_64.rpm perl-YAML-Syck-1.450.0-bp157.2.3.1.i586.rpm perl-YAML-Syck-1.450.0-bp157.2.3.1.aarch64.rpm perl-YAML-Syck-1.450.0-bp157.2.3.1.ppc64le.rpm perl-YAML-Syck-1.450.0-bp157.2.3.1.s390x.rpm openSUSE-2026-179 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 148.0.7778.215 (boo#1266471) chromedriver-148.0.7778.215-bp157.2.163.1.x86_64.rpm chromium-148.0.7778.215-bp157.2.163.1.nosrc.rpm chromium-148.0.7778.215-bp157.2.163.1.x86_64.rpm chromedriver-148.0.7778.215-bp157.2.163.1.aarch64.rpm chromium-148.0.7778.215-bp157.2.163.1.aarch64.rpm chromedriver-148.0.7778.215-bp157.2.163.1.ppc64le.rpm chromium-148.0.7778.215-bp157.2.163.1.ppc64le.rpm openSUSE-2026-181 Security update for re critical openSUSE Backports SLE-15-SP7 Update This update for re fixes the following issues: * Fixed integer overflow in websock_decode() masked frame length check leads to heap buffer overflow. * Fix DTLS single_conn mode lacks peer address validation, allowing connection hijacking and DoS #3705. libre16-3.4.0-bp157.2.3.1.x86_64.rpm re-3.4.0-bp157.2.3.1.src.rpm re-devel-3.4.0-bp157.2.3.1.x86_64.rpm libre16-3.4.0-bp157.2.3.1.i586.rpm re-devel-3.4.0-bp157.2.3.1.i586.rpm libre16-3.4.0-bp157.2.3.1.aarch64.rpm re-devel-3.4.0-bp157.2.3.1.aarch64.rpm libre16-3.4.0-bp157.2.3.1.ppc64le.rpm re-devel-3.4.0-bp157.2.3.1.ppc64le.rpm libre16-3.4.0-bp157.2.3.1.s390x.rpm re-devel-3.4.0-bp157.2.3.1.s390x.rpm openSUSE-2026-187 Recommended update for gitea-tea moderate openSUSE Backports SLE-15-SP7 Update This update for gitea-tea fixes the following issues: - Fix access to sha256 repositories - update to 0.14.1: * fix(deps): update module github.com/go-authgate/sdk-go to v0.11.0 in #988 * fix(deps): update module golang.org/x/term to v0.43.0 in #989 * fix(deps): update module code.gitea.io/sdk/gitea to v0.25.1 in #991 * fix(deps): update module github.com/urfave/cli/v3 to v3.9.0 in #992 * fix(deps): update github.com/urfave/cli to v3.9.0 in #993 * Fix login edit to check config existence in #987 * fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 in #984 * fix: pass the name flag value as the organization FullName in #832 * Fix login edit to open one editor only in #977 * fix(deps): update module github.com/go-authgate/sdk-go to v0.10.0 in #976 * feat: add additional admin users subcommands in #842 * feat(ssh-keys): add ssh-keys command to manage SSH public keys in #940 * Multiple PRs in #848 * Move integration tests to tests/ directory in #973 * fix(deps): update module github.com/go-authgate/sdk-go to v0.9.0 in #974 * fix(deps): update module github.com/go-authgate/sdk-go to v0.8.0 in #972 * fix(webhook): Fix when creating webhook, branch filter and auth header cannot be added in #964 * fix: read --assignee flag value instead of nonexistent --assigned-to in #971 * Fix man page section in #969 * fix(deps): update module github.com/go-authgate/sdk-go to v0.7.0 in #970 * chore(deps): update docker.gitea.com/gitea docker tag to v1.26.1 in #968 * fix(pagination): replace Page:-1 with explicit pagination loops in #967 * fix(cmd): Update CmdRepos description and usage in repos.go in #946 * fix(context): skip local repo detection for repo slugs in #960 * fix(deps): update module charm.land/lipgloss/v2 to v2.0.3 in #959 * fix(deps): update module github.com/go-git/go-git/v5 to v5.18.0 in #961 * chore(deps): update docker.gitea.com/gitea docker tag to v1.26.0 in #962 - update to 0.14.0: * 63bc90e feat(branches): add rename subcommand (#939) * 9e0a620 feat(pulls): add ci status field to pull request list (#956) * 84ecd16 fix(deps): update Go dependencies to latest versions (#955) * 53e53e1 feat(workflows): add dispatch, view, enable and disable subcommands (#952) * 0489d8c fix(deps): update module golang.org/x/sys to v0.43.0 (#951) * f538c05 refactor: code cleanup across codebase (#947) * 662e339 feat(pulls): add resolve, unresolve and review-comments subcommands (#948) gitea-tea-0.14.1-bp157.2.21.1.src.rpm gitea-tea-0.14.1-bp157.2.21.1.x86_64.rpm gitea-tea-bash-completion-0.14.1-bp157.2.21.1.noarch.rpm gitea-tea-zsh-completion-0.14.1-bp157.2.21.1.noarch.rpm gitea-tea-0.14.1-bp157.2.21.1.i586.rpm gitea-tea-0.14.1-bp157.2.21.1.aarch64.rpm gitea-tea-0.14.1-bp157.2.21.1.ppc64le.rpm gitea-tea-0.14.1-bp157.2.21.1.s390x.rpm openSUSE-2026-188 Security update for tor moderate openSUSE Backports SLE-15-SP7 Update This update for tor fixes the following issues: - Update to 0.4.9.9 * Major bugfixes (compression, security): - Fix a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. TROVE-2026-022. Fixes bug 41275; bugfix on 0.3.1.1-alpha. - Fix an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. TROVE-2026-021. Fixes bug 41274; bugfix on 0.2.6.1-alpha. * Major bugfixes (conflux, security): - Fix a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller to write to the now-freed current leg and resulting in a crash. TROVE-2026-017. Fixes bug 41263; bugfix on 0.4.8.1-alpha. * Major bugfixes (security, TROVE-2026-019): - Avoid out-of-bounds read/write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. Fixes bug 41267; bugfix on 0.2.8.2-alpha. * Major bugfixes (client stability, TROVE-2026-013, TROVE-2026-015): - Protect against a client-side assert that can happen if a malicious onion service gets the client to load its carefully crafted onion descriptor. Fixes bugs 41259 and 41261; bugfix on 0.3.1.1-alpha. * Major bugfixes (code safety): - Avoid a dangerous situation in router_find_exact_exit_enclave() where we could have reached an assert if bridges or relays claim an IP address of 0.0.0.0. Fixes bug 41276; bugfix on 0.4.5.1-alpha. * Major bugfixes (conflux, shutdown): - Fix a use-after-free in the shutdown path when freeing conflux circuits. cfx_add_leg() shares stream list pointers across legs without NULLing the old leg, so circuit_free_all() would free the lists via one leg and then access freed memory via another. TROVE- 2026-016. Fixes bug 41262; bugfix on 0.4.8.1-alpha. * Major bugfixes (DNSPort, TROVE-2026-018): - Fix a client-side crash that would happen if we decide to stop reading on a RESOLVE request that came from the DNSPort or controller. This crash could happen naturally under heavy load and with poor luck, but since 0.4.7.2-alpha it could be induced by the exit relay via a flow control request. Fixes bug 41265; bugfix on 0.2.0.1-alpha. * Major bugfixes (memory safety, TROVE-2026-014): - Avoid a heap-use-after-free mistake that can happen in the conflux subsystem, and which can be induced at either the client or the exit relay. Fixes bug 41260; bugfix on 0.4.8.1-alpha. * Major bugfixes (onion services, TROVE-2026-020): - Avoid a possible divide by zero crash on onion services that have the proof-of-work (PoW) defense enabled. This bug could be hit by extreme bad luck or maybe by the help of an attacker crafting just the right circumstances. Fixes bug 41270; bugfix on 0.4.8.1-alpha. tor-0.4.9.9-bp157.2.12.1.src.rpm tor-0.4.9.9-bp157.2.12.1.x86_64.rpm tor-0.4.9.9-bp157.2.12.1.aarch64.rpm tor-0.4.9.9-bp157.2.12.1.ppc64le.rpm tor-0.4.9.9-bp157.2.12.1.s390x.rpm openSUSE-2026-189 Security update for cacti moderate openSUSE Backports SLE-15-SP7 Update This update for cacti fixes the following issues: - Update to version 1.2.30+git457.e55c2aea: * docs(changelog): add security fix refs for 1.2.31 (#7170) * fix: Upgrade DOMPurify again for additional hardening (#7168) * security: Ensure that reports does not work as guest (#7167) * Update translation files * security: GHSA-m7v2-f3xw-3qh7 - User Enumeration via Error Messages (#7166) * chore: Move around developers, rest in peace my friend (#7165) * Import undefined variable (#7164) * fix: guard api_plugin_moveup/movedown against NULL prior/next id (1.2.x backport) (#7158) * fix(correctness): loop-state leaks, chunk-aware poller CRC, header-suppression and tree false-guards (1.2.x) (#7151) * fix: Remove composer.lock (#7156) * test: source-pattern coverage backfill for PR 7148, 7149, 7150 (#7153) * fix: CVE-2024-27355 in phpseclib (#7155) * chore: Update ChangeLogs (#7152) cacti-1.2.30+git457.e55c2aea-bp157.2.12.1.noarch.rpm cacti-1.2.30+git457.e55c2aea-bp157.2.12.1.src.rpm openSUSE-2026-182 Security update for libjxl important openSUSE Backports SLE-15-SP7 Update This update for libjxl fixes the following issues: - CVE-2025-70103: take EC into account when checking required PNM input length (boo#1266460). libjxl-0.8.5-bp157.2.6.1.src.rpm libjxl-devel-0.8.5-bp157.2.6.1.x86_64.rpm libjxl-tools-0.8.5-bp157.2.6.1.x86_64.rpm libjxl0_8-0.8.5-bp157.2.6.1.x86_64.rpm gdk-pixbuf-loader-jxl-0.8.5-bp157.2.6.1.x86_64.rpm gimp-plugin-jxl-0.8.5-bp157.2.6.1.x86_64.rpm jxl-thumbnailer-0.8.5-bp157.2.6.1.noarch.rpm libjxl-gtk-0.8.5-bp157.2.6.1.src.rpm libjxl-devel-0.8.5-bp157.2.6.1.i586.rpm libjxl-tools-0.8.5-bp157.2.6.1.i586.rpm libjxl0_8-0.8.5-bp157.2.6.1.i586.rpm libjxl0_8-32bit-0.8.5-bp157.2.6.1.x86_64.rpm gdk-pixbuf-loader-jxl-0.8.5-bp157.2.6.1.i586.rpm gimp-plugin-jxl-0.8.5-bp157.2.6.1.i586.rpm libjxl-devel-0.8.5-bp157.2.6.1.aarch64.rpm libjxl-tools-0.8.5-bp157.2.6.1.aarch64.rpm libjxl0_8-0.8.5-bp157.2.6.1.aarch64.rpm libjxl0_8-64bit-0.8.5-bp157.2.6.1.aarch64_ilp32.rpm gdk-pixbuf-loader-jxl-0.8.5-bp157.2.6.1.aarch64.rpm gimp-plugin-jxl-0.8.5-bp157.2.6.1.aarch64.rpm libjxl-devel-0.8.5-bp157.2.6.1.ppc64le.rpm libjxl-tools-0.8.5-bp157.2.6.1.ppc64le.rpm libjxl0_8-0.8.5-bp157.2.6.1.ppc64le.rpm gdk-pixbuf-loader-jxl-0.8.5-bp157.2.6.1.ppc64le.rpm gimp-plugin-jxl-0.8.5-bp157.2.6.1.ppc64le.rpm libjxl-devel-0.8.5-bp157.2.6.1.s390x.rpm libjxl-tools-0.8.5-bp157.2.6.1.s390x.rpm libjxl0_8-0.8.5-bp157.2.6.1.s390x.rpm gdk-pixbuf-loader-jxl-0.8.5-bp157.2.6.1.s390x.rpm gimp-plugin-jxl-0.8.5-bp157.2.6.1.s390x.rpm openSUSE-2026-190 Recommended update for fwts moderate openSUSE Backports SLE-15-SP7 Update This update for fwts fixes the following issues: - Update to version 26.05.00: * lib: fwts_version.h - update to V26.05.00 * debian: update changelog * github: add stonking to github actions * fwts-test: update disassemble-0001 reference files for ACPICA 20260408 * auto-packager: mkpackage.sh: add stonking * ACPICA: Update to version 20260408 fwts-26.05.00-bp157.2.6.1.src.rpm fwts-26.05.00-bp157.2.6.1.x86_64.rpm fwts-26.05.00-bp157.2.6.1.i586.rpm fwts-26.05.00-bp157.2.6.1.aarch64.rpm openSUSE-2026-191 Security update for perl-HTTP-Tiny moderate openSUSE Backports SLE-15-SP7 Update This update for perl-HTTP-Tiny fixes the following issues: - updated to 0.094 0.094 2026-05-17 10:31:00+02:00 Europe/Brussels - No changes from 0.093-TRIAL 0.093 2026-05-11 17:18:12+02:00 Europe/Brussels (TRIAL RELEASE) - fix to prevent invalid characters in all headers, and prevent header smuggling (CVE-2026-7010) boo#1264992 - updated to 0.092 0.092 2025-12-27 20:49:41+01:00 Europe/Berlin - No changes from 0.091-TRIAL 0.091 2025-12-13 06:26:51+01:00 Europe/Brussels (TRIAL RELEASE) [ADDED] - Added keep_alive_timeout to force keepalive connections to be closed based on a timeout. [CHANGED] - Optional tests are always required when releasing. - Always use TCP_NODELAY option. [FIXED] - Fixed test incorrectly testing cookie jar interactions multiple times. - Fixed perl version comparisons to work when not starting with 5. - Fixed link to LIMITATIONS in documentation. - updated to 0.090 0.090 2024-11-12 11:51:32+01:00 Europe/Brussels - No changes from 0.089-TRIAL 0.089 2024-10-21 09:35:48+02:00 Europe/Brussels (TRIAL RELEASE) [CHANGED] - Find the certificate bundle via IO::Socket::SSL rather than implementing it in HTTP::Tiny. - When encoding form data, given a hashref with an arrayref value, preserve the order of the values in the arrayref rather than sorting. [DOCS] - Fixed internal link to "TLS/SSL SUPPORT" section - Fix disabling of __perllib_provides - updated to 0.088 0.088 2023-07-11 08:52:54-04:00 America/New_York [DOCS] - Update metadata to point to new Perl-Toolchain-Gang repository. perl-HTTP-Tiny-0.094-bp157.2.3.1.noarch.rpm perl-HTTP-Tiny-0.094-bp157.2.3.1.src.rpm openSUSE-2026-183 Security update for roundcubemail important openSUSE Backports SLE-15-SP7 Update This update for roundcubemail fixes the following issues: Update to 1.6.16 - Fix potential too long value in IMAP ID command (#10136) - CVE-2026-48849: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [boo#1266337] - CVE-2026-48848: Fix CSS injection bypass in HTML sanitizer via SVG <animate attributeName="style"> [boo#1266336] - CVE-2026-48842: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [boo#1266329] - CVE-2026-48843: Fix SSRF bypass via specific local address URLs [boo#1266331] - CVE-2026-48846: Fix bypass of remote image blocking via CSS var() [boo#1266334] - CVE-2026-48845: Fix local/private URL fetch bypass when remote resources were not allowed [boo#1266333] - CVE-2026-48847: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [boo#1266335] - CVE-2026-48844: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [boo#1266332] roundcubemail-1.6.16-bp157.2.12.1.noarch.rpm roundcubemail-1.6.16-bp157.2.12.1.src.rpm openSUSE-2026-184 Security update for rclone important openSUSE Backports SLE-15-SP7 Update This update for rclone fixes the following issues: - Update to version 1.74.1: * Version v1.74.1 * build: update golang.org/x/net to v0.53.0 to fix CVE-2026-33814 * build: fix multiple CVEs by upgrading to go1.26.3 * drime: fix uploads of 100..200M files * drime: fix large file uploads landing in drive root instead of configured folder * docs: sponsor updates * s3: add new Fastly Object Storage regions * cloudinary: fix retrying every error and fix pacer sleep units * s3: fix STS call per request by caching AssumeRole credentials * protondrive: fix segfault when copying files missing revision metadata * protondrive: route library logging through rclone's logger * protondrive: route HTTP through rclone's transport * bisync: fix retryable without --resync error message when --resync has a critical failure * cmd/serve/s3: return object listings in key order * Start v1.74.1-DEV development - Update to version 1.74.0: * Version v1.74.0 * docs: add missing Huawei Drive docs * Add Huawei Drive support * s3: add Impossible Cloud as a new S3 provider * build: add `make fetch-gui-and-commit` to fetch and commit the embedded GUI * gui: embed compressed dist.zip in the binary for smaller, reproducible builds * docs: update the GUI docs to reflect the new `rclone gui` * Add John Volk to contributors * drime: fix listings of large directories * docs: fix iCloud docs after website update (missed in the merge) * protondrive: fix server-side moveto and DirMove against current API * build: Update all packages with pseudo versions which aren't v0.0.0 * Add Chris Coughlan to contributors * Add Yakov Till to contributors * iclouddrive: add read only iCloud Photos support and SRP authentication * mountlib: rc: fix mounts created with mountPoint "*" overwriting each other * vfs/vfscache/downloaders: kick waiters periodically, not just once * rc: add user directories to core/disks and filter mounts better * docs: notes on how to update pseudo versions * Add dlaumen to contributors * Add Luke Cyca to contributors * Add mathieulongtin to contributors * protondrive: update to latest go-proton-api to use new host * docs: amend Google Drive client_id instructions to include running web-based auth flow * azureblob,azurefile: fix documentation about federated identity * internxt: implement multi-part uploads * serve dlna: remove file extensions from titles to prevent Samsung TV duplication * serve dlna: fix XML quote escaping for Samsung TV compatibility * serve dlna: handle empty ObjectID from Samsung TVs * serve dlna: add Samsung-specific XML namespace * serve dlna: fix invalid dc:date for containers * serve dlna: fix container childCount to reflect actual contents * serve dlna: fix SOAP response argument ordering for Samsung TV compatibility * Add Anton Bordwine to contributors * listremotes: add --exact flag for filtering - fixes #9076 * build: bump github.com/Azure/go-ntlmssp to 0.1.1 to fix CVE-2026-32952 * azurefiles: fix missing x-ms-file-request-intent header with OAuth - fixes #9367 * Add tdawe to contributors * Add Jan Heylen to contributors * protondrive: align backend with newer Proton SDK stack * s3: fix bucket creation failing on Ceph/radosgw * rc: add core/disks to enumerate attached disks * build: update golang.org/x/image/webp to v0.39.0 to fix CVE-2026-33813 * Add SyoBoN to contributors * docs: fix typo * docs: fix code comment regarding cmount tag * s3: add HCP provider and list_versions_oldest_first quirk * mega: fix crash when logging in with previous auth keys fails * pcloud: fix recursive listing from the root - fixes #9315 * rc: flip auth default so all endpoints require auth unless opted out * Changelog updates from Version v1.73.5 * operations: add AuthRequired to operations/fsinfo to prevent backend creation CVE-2026-41179 * rc: snapshot NoAuth at startup to prevent runtime auth bypass CVE-2026-41176 * rc: add AuthRequired to options/set to prevent auth bypass CVE-2026-41176 * accounting: fix rcat/copyurl for files.com * bisync: fix integration tests after sftp log changes * build: bump actions/github-script from 8 to 9 * fstest/test_all: stop test servers on signal, panic, or exit * fstest/testserver: add CleanupAll for end-of-run server sweep * fstest/testserver: add force-stop and reconcile stale refcounts * fshttp: add --dump curl for dumping HTTP requests as curl commands * s3: fix empty delimiter parameter rejected by Archiware P5 server * serve nfs: fix EOF flag in READ response not being set when read reaches end of file * webdav: optimize performance by using Depth=0 for metadata requests * bisync: fix flaky TestBisyncConcurrent by increasing random name entropy * azureblob: add --azureblob-decompress flag to download gzip-encoded files * docs: serve backend metadata as JSON on the website * azureblob/auth: add Microsoft Partner Network User-Agent prefix * vfs: add context parameter to New() for config propagation * vfs: replace context.TODO/Background with stored VFS context * build: fix `make fetch-gui` in CI workflow - it was in the wrong place * gui: join Wait goroutines on shutdown * gui: remove flag.Lookup test guard around browser open * gui: drop freePort helper, use libhttp port binding for the RC server * gui: allow serving from a local zip file or an unpacked directory * gui: don't run fetch-gui on make * build: fix GitHub API rate limit errors when fetching GUI dist in CI * drime: fix User.EntryPermissions JSON unmarshalling * filen: make multi-threaded upload chunks individually retryable * chore: add Enduriel as filen backend maintainer * filter: fix debug logs that fire before logger is configured - fixes #9291 * Add Mozi to contributors * Add Brais Couce to contributors * gui: new command to launch the https://github.com/rclone/rclone-web/ GUI * s3: fix TencentCOS CDN endpoint failing on bucket check * s3: fix --s3-versions flag ignored by cleanup-hidden when GetBucketVersioning fails * iclouddrive: fix 'directory not found' error when the directory contains accent marks * downloaders: fix flaky TestDownloaders/EnsureDownloader test * sftp: warn the user if no host key validation is configured * Add TheBabu to contributors * lib/http: Add HTTP/2 cleartext support in server configuration * build: add explicit permissions to GitHub Actions workflows * vfscache: fix grace timer reusing stale fd after _checkObject removes cache file * webdav: Add a section on symlink/junction points in the help * Changelog updates from Version v1.73.4 * build: update all dependencies * docs: fix XSS vulnerability in dropdown mobile header * build: fix Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder * linkbox: fix downloading files by using web API - fixes #8665 * vfs: fix tests after --vfs-handle-caching * Add Suyun to contributors * build: fix loong64 and s390x build * jottacloud: add encoding of percent character to default backend encoding * docs: fix markdown issues in mount docs * docs: fix header level for metadata option * vfs: fix slow nfs serve by adding --vfs-handle-caching * Add Xiangzhe to contributors * Add Mike GIllan to contributors * fix(docs): Fix link to not be language specific * iclouddrive: lowercase Apple ID for SRP authentication * iclouddrive: use dynamic origin for SRP auth headers * iclouddrive: replace plaintext signin with SRP authentication * docs: modernize rclone.org site design * Add Andriy Senyshyn to contributors * Add Claude Opus 4.6 to contributors * Add jinyu.han to contributors * Add jinkeyuu to contributors * Add lif to contributors * Add BizaNator to contributors * Add Patrick Farrell to contributors * Add Jason to contributors * Add ZRHan to contributors * Add Andrew Furman to contributors * Add Andriy Senyshyn to contributors * Add Bhagyashreek8 to contributors * s3: add UCloud Object Storage provider (#9230) * bisync: fix handling of unreadable lockfiles - fixes #9290 * librclone/ctest: add Windows support and fix memory management * s3: fix regression where PutObject fails with non-seekable readers * filen: update SDK version * build(deps): bump golang.org/x/image from 0.36.0 to 0.38.0 * docs: note macOS 10.15 (Catalina) support with version v1.70.3 * Add OVHcloud storage classes * local: remove fadvise calls that cause spinlock contention * Changelog updates from Version v1.73.3 * build(deps): bump github.com/buger/jsonparser from 1.1.1 to 1.1.2 * docs/jottacloud: fix broken link * docs: clarify Filen password change requires updating both password and API key in rclone config * docs: note that Filen API key changes on password change * build(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.3 * webdav: request only required properties in listAll to improve performance * s3: fix Content-MD5 for Object Lock uploads and add GCS quirk * s3: add multi tenant support for Cubbit * lib/rest: fix URLPathEscapeAll breaking WebDAV servers (eg nzbdav) with strict path matching * copyurl: fix ignored --upload-headers and --download-headers * s3: IBM COS: provide ibm_iam_endpoint as a configurable param for IBM IAM-based auth * list: fix nil pointer panic in Sorter when temp file creation fails * docs: update RELEASE procedure to avoid mistakes * Add Billy Hughes to contributors * accounting: Add deletedDirs stat to core/stats help output * docs: added text to the label showing version-introduced info * Changelog updates from Version v1.73.2 * fs/log: fix data race on OutputHandler.format field * build(deps): bump docker/build-push-action from 6 to 7 * build(deps): bump docker/setup-buildx-action from 3 to 4 * build(deps): bump docker/metadata-action from 5 to 6 * build(deps): bump docker/setup-qemu-action from 3 to 4 * build(deps): bump docker/login-action from 3 to 4 * bisync: update changelog * bisync: auto-generate rc help docs * bisync: add more structured info to rc output * bisync: add missing rc params - fixes #7799 * operations: multithread copy: grab memory before making go routines * b2: add server side copy real time accounting * s3: add server side copy real time accounting * azureblob: add server side copy real time accounting * operations: add method to real time account server side copy * Add Duncan F to contributors * azureblob: add --azureblob-copy-total-concurrency to limit total multipart copy concurrency * Add razorloves to contributors * docs: fix new drive flag typo in changelog * build: update to golang.org/x/net v0.51.0 to fix CVE-2026-27141 #9220 * Add Bjoern Franke to contributors * Add Brian Bockelman to contributors * Add Romāns Potašovs to contributors * Add Adam Kasztenny to contributors * Add hxnd to contributors * Add Bjoern Franke to contributors * Add FTCHD to contributors * build(deps): bump actions/upload-artifact from 6 to 7 * build(deps): bump actions/download-artifact from 7 to 8 * serve http: add gzip compression * webdav: permit redirects on PROPFIND for metadata * webdav: add missing headers for CORS * docs: Document unsupported S3 object keys with double slashes * touch: add metadata when using `--metadata-set` * s3: ionos: updated regions & endpoints * s3: scaleway: ONEZONE_IA is available in all zones, GLACIER only in FR-PAR * drive: add integration test for handling folder names with single quotes * http: dark mode for browser * docs: note that --use-server-modtime only works on some backends * Add a1pcm to contributors * Add Leon Brocard to contributors * Add Dark Dragon to contributors * internxt: fix Entry doesn't belong in directory errors on windows * drime: fix chunk-uploaded files ignoring workspace ID * s3: add new Fastly Object Storage regions * docs: Fix headers hierarchy for mount.md * serve http: add fallback embedded favicon * graphics: optimise images losslessly with ImageOptim * docs: update sponsors * Add Jan-Philipp Reßler to contributors * Add Chris to contributors * Add Shlomi Avihou to contributors * Add Jan-Philipp Reßler to contributors * Add Varun Chawla to contributors * Add Prakhar Chhalotre to contributors * s3: add Object Lock support * webdav: escape reserved characters in URL path segments * s3: add Zadara Object Storage provider * bisync: add group Sync to the bisync command * archive: extract: strip "./" prefix from tar entry paths * accounting: update String method output format for clarity in transfer rate representation - fixes #9129 * docs: add instructions on how to update Go version * build: modernize Go code with go fix for go1.25 * build: update all dependencies * lib/rest: remove go1.24 workaround now go1.25 is the minimum * build: update to go1.26 and make go1.25 the minimum required version * Add Jack Kelly to contributors * Changelog updates from Version v1.73.1 * build: fix build using go 1.26.0 instead of go 1.25.7 * fs/march: fix runtime: program exceeds 10000-thread limit * accounting: fix missing server side stats from core/stats rc * pacer: re-read the sleep time as it may be stale * pacer: fix deadlock between pacer token and --max-connections * test_all: increase retries for Internxt eventual consistency * build: fix CVE-2025-68121 by updating go to 1.25.7 or later - fixes #9167 * drime: fix files and directories being created in the default workspace * docs: update sponsors * Add kingston125 to contributors * copyurl: Extend copyurl docs with an example of CSV FILENAMEs starting with a path. * filelu: migrate API calls to lib/rest * internxt: implement re-login under refresh logic, improve retry logic - fixes #9174 * docs: add ExchangeRate-API as a sponsor * Add Cohinem to contributors * Add Leon Brocard to contributors * s3: remove StackPath Object Storage provider * drime: implement About * build: bump github.com/go-chi/chi/v5 from 5.2.3 to 5.2.5 to fix GO-2026-4316 * Set list_version to 2 for FileLu S3 configuration * filelu: add multipart upload support with configurable cutoff * filelu: add multipart init response type * filelu: add comment for response body wrapping * filelu: avoid buffering entire file in memory * docs: update sponsor logos * s3: add Fastly Object Storage provider * filen: fix potential panic in case of error during upload * filen: fix 32 bit targets not being able to list directories Fixes #9142 * pikpak: support custom filenames for addurl backend command - fixes #9111 * Start v1.74.0-DEV development rclone-1.74.1-bp157.2.6.1.src.rpm rclone-1.74.1-bp157.2.6.1.x86_64.rpm rclone-bash-completion-1.74.1-bp157.2.6.1.noarch.rpm rclone-debuginfo-1.74.1-bp157.2.6.1.x86_64.rpm rclone-zsh-completion-1.74.1-bp157.2.6.1.noarch.rpm rclone-1.74.1-bp157.2.6.1.i586.rpm rclone-debuginfo-1.74.1-bp157.2.6.1.i586.rpm rclone-1.74.1-bp157.2.6.1.aarch64.rpm rclone-debuginfo-1.74.1-bp157.2.6.1.aarch64.rpm rclone-1.74.1-bp157.2.6.1.ppc64le.rpm rclone-debuginfo-1.74.1-bp157.2.6.1.ppc64le.rpm rclone-1.74.1-bp157.2.6.1.s390x.rpm rclone-debuginfo-1.74.1-bp157.2.6.1.s390x.rpm openSUSE-2026-185 Security update for sshfs critical openSUSE Backports SLE-15-SP7 Update This update for sshfs fixes the following issues: - Update to 3.7.6: - Added new maintainer: abhinavagarwal07 Abhinav Agarwal - CVE-2026-47187: Fixed critical vulnerability - Symlink Escape: Rogue SFTP Server to Local File Read/Write), credit to abhinavagarwal07 (boo#1267017) - New -o contain_symlinks and -o no_contain_symlinks to control symlink containment behavior - CVE-2026-48711: Fixed high severity vulnerability - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), credit to abhinavagarwal07 (boo#1267016) - Fixed null-deref warning in tokenize_on_space, promote strict-warnings to required - Added a number of tests in CI, including rename, chmod, fsync, statvfs values, error paths, option coverage - Fixed malformed SFTP reply handling - Update to 3.7.5: * Implement connect to vsock * use latest major version for actions/checkout * Fix memleak in cache after readlink * Fill stat info when returning cached data for readdir * ipv6 support for directport connection - reverts to original fork - Don't globstar files in shared directory _bindir. - build the man page sshfs-3.7.6-bp157.2.3.1.src.rpm sshfs-3.7.6-bp157.2.3.1.x86_64.rpm sshfs-3.7.6-bp157.2.3.1.i586.rpm sshfs-3.7.6-bp157.2.3.1.aarch64.rpm sshfs-3.7.6-bp157.2.3.1.ppc64le.rpm sshfs-3.7.6-bp157.2.3.1.s390x.rpm openSUSE-2026-186 Security update for perl-Sereal-Decoder important openSUSE Backports SLE-15-SP7 Update This update for perl-Sereal-Decoder fixes the following issues: - CVE-2026-8796: Fixed heap out-of-bounds read via crafted input (boo#1267015) perl-Sereal-Decoder-5.004-bp157.2.3.1.src.rpm perl-Sereal-Decoder-5.004-bp157.2.3.1.x86_64.rpm perl-Sereal-Decoder-5.004-bp157.2.3.1.i586.rpm perl-Sereal-Decoder-5.004-bp157.2.3.1.aarch64.rpm perl-Sereal-Decoder-5.004-bp157.2.3.1.ppc64le.rpm perl-Sereal-Decoder-5.004-bp157.2.3.1.s390x.rpm openSUSE-2026-192 Security update for kanidm critical openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: - Update to version 1.10.2~git0.f3dc9ef1f: * Release 1.10.2 * Security - CRITICAL - authenticated user privilege escalation * Refactor modification access paths to remove duplication * Revert ClientID header (#4334) * Disable prompt=login (#4340) * Add missing `/sbin/kanidm-mail-sender` (#4323) * Remove debug symbols in release builds. (#4319) - Update to version 1.10.1~git0.d02660a98: * Release 1.10.1 * Fix copy in TOTP removal prompt and align TOTP case (#4314) * Resolve base64 encoding of webauthn fields (#4312) - Update to version 1.10.0-pre~git1.32e2f8ec6: * Release 1.10.0 * Release 1.10.0-pre * Release notes (#4304) * Update ldap3/webauthn-rs (#4302) * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Add notes on server migration (#4301) * 20260517 sparkle (#4280) * Bump mozilla-actions/sccache-action in the all group (#4298) * Bump the all group with 6 updates (#4299) * Bump the all group across 1 directory with 3 updates (#4283) * 20260331 send account recovery emails (#4259) * Update oauth2 well known urls (#4296) * Clippy for Rust 1.95 (#4291) * Invert incorrect thread count logic (#4294) * Allow modification of OAuth2 Refresh Expiry (#4276) * 20260327 Introspection token auth metadata (#4230) * fix: add missing kanidm-mail-sender binary (#4279) * Correctly handle deleted accounts during page visits (#4275) * don't fail auth when passed ui_locales (#4288) * Bump actions/upload-pages-artifact from 4 to 5 in the all group (#4284) * Fix link formatting in oauth2.rs documentation (#4278) * Feat: Add OIDC Prompt Support (#4224) * Handle multivalue URLs in SCIM (#4271) * Correctly encode ssh tag values (#4272) * Bump the all group with 2 updates (#4263) * Bump the all group in /rlm_python with 4 updates (#4262) * Bump the all group with 8 updates (#4264) * Update deployment.md with configuration notes (#4258) * Add .well-known/passkey-endpoints (#4255) * show repl cert metadata and also handle socket timeouts (#4252) * Update docs regarding replication cert lifetime (#4251) * Log cleanup (#4248) * adding timeouts and tests and port docs for mail_sender (#4246) * Bump the all group with 5 updates (#4247) * add dependency data to released containers (#4239) * Fix to end code block and render remaining md correctly (#4241) * Update readme.md for replication (#4236) * Added note on primary email address and email aliases (#4237) * Bump the all group with 6 updates (#4235) * Bump the all group with 2 updates (#4234) * Bump the uv group across 1 directory with 2 updates (#4231) * cli: allow clearing person's legalname attribute (#4228) * Add shell diagnostics (#4220) * OpenSSL shall be vanquished (#4219) * Bump the all group across 1 directory with 16 updates (#4225) * Bump rustls-webpki from 0.103.9 to 0.103.10 (#4223) * Bump flatted (#4222) * Tabular data is tabular (#4221) * Example sshd-config fragment, deployment de-activated on Debian (#4214) * Update RELEASE_NOTES.md (#4215) * fix(debian): Use correct bin path for kanidmd reload (#4212) * Allow urlencoded client_id in basic auth (#4141) * add nsswitch config check to unixd (#4210) * 20260311 zxcvbn check (#4206) * Enhance Traefik documentation (#4194) * Re-add incorrectly removed utopia feature flag (#4207) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Added PasswordChangedTime attribute and database field (#3999) * Defer on some routes (#4202) * Remove thread local storage (#4204) * Improve FreeBSD building, fully drop ring as a dependency. * 20260218 credential reset emails (authenticated only) (#4151) * android support for cli (#4197) * Bump the all group with 4 updates (#4198) * Bump the all group with 7 updates (#4199) * feat: bind mount home strategy (#3997) * Bump the all group with 2 updates (#4183) * Bump the all group with 8 updates (#4184) * Bump minimatch (#4180) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Don't revert admin changes in some groups during migrcation (#4176) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) * 20260220 prevent migration accidents (#4156) * Bump the all group across 1 directory with 20 updates (#4163) * Move the grafana group creation step (#4160) * Alert on unsaved changes (#4155) * pykanidm v1.3.0 - major rewrite to use openapi-generated codebase based on 1.9.0 spec (#4149) * Warn about systemd-userdb (#4147) * Dont require basic auth on token introspection (#4142) * Dont be as upset when migration dir doesnt exist (#4146) * Add AGENTS.md instructions (#4148) * Feature OIDC updated at (#4007) * pykanidm: clarify token use with service accounts (#4043) * Fixed small typo in how_does_oauth2_work.md (#4138) * Bye bye lazy static (#4134) * Allow LDAP CA verification to be disabled in sync (#4133) * Add oauth2 example, fix inter-migration reference handling (#4136) * Add missing future migration in domain check (#4132) * Corrected recycle_bin.md typo (#4135) * 20260211 dev version (#4131) - Update to version 1.9.3~git0.7d4108698: * Release 1.9.3 * Security - High: SCIM Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user * Security - Moderate: PNG Image validation did not correctly handle short images allowing a panic to occur in a worker thread. This may lead to system instability over time * Security - Low: HTML injection via user DisplayName in Passkey enrolment dialogs. This allows an admin to execute JS in the context of a users browser. Since the admin already can reset the users credentials, the impact of this is minimal. * Security - Low: non-constant time comparison of OAuth2 client secret may allow a remote attacker to remotely recovery the bytes of the secret. Due to the length of the secret (48 chars) this is infeasible practically. * Security - Low: incorrect handling of origin validation in Webauthn-RS allowed a malicious domain to collide with a valid one (badexample.com would match with example.com). This is mitigated by browsers detecting the forgery and preventing the authentication from proceeding. * Security - High: LDAP Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user. * Update two vulnerable dependencies * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Remove thread local storage (#4204) - Update to version 1.9.2~git6.896acba35: * Release 1.9.3 * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Update two vulnerable dependencies - Update to version 1.9.2~git0.6a2bb66bd: * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Remove thread local storage (#4204) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) kanidm-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.src.rpm kanidm-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.x86_64.rpm kanidm-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.x86_64.rpm kanidm-docs-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.x86_64.rpm kanidm-server-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.x86_64.rpm kanidm-unixd-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.x86_64.rpm kanidm-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.aarch64.rpm kanidm-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.aarch64.rpm kanidm-docs-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.aarch64.rpm kanidm-server-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.aarch64.rpm kanidm-unixd-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1.aarch64.rpm openSUSE-2026-194 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 149 (149.0.7827.53) stable (boo#1267706): * CVE-2026-10881: Out of bounds read and write in ANGLE * CVE-2026-10882: Use after free in Network * CVE-2026-10883: Out of bounds write in ANGLE * CVE-2026-10884: Use after free in Chromecast * CVE-2026-10885: Use after free in Chrome for iOS * CVE-2026-10886: Use after free in FileSystem * CVE-2026-10887: Use after free in Chromoting * CVE-2026-10888: Use after free in Cast Streaming * CVE-2026-10889: Out of bounds read in ANGLE * CVE-2026-10890: Use after free in Cast * CVE-2026-10891: Use after free in GFX * CVE-2026-10892: Out of bounds write in GPU * CVE-2026-10893: Use after free in Chromoting * CVE-2026-10894: Use after free in Printing * CVE-2026-10895: Use after free in Ozone * CVE-2026-10896: Use after free in Chrome for iOS * CVE-2026-10897: Out of bounds write in GPU * CVE-2026-10898: Stack buffer overflow in GPU * CVE-2026-10899: Use after free in Ozone * CVE-2026-10900: Use after free in Passwords * CVE-2026-10901: Use after free in Passwords * CVE-2026-10902: Use after free in Ozone * CVE-2026-10903: Use after free in WebRTC * CVE-2026-10904: Inappropriate implementation in V8 * CVE-2026-10905: Use after free in Network * CVE-2026-10906: Use after free in WebAuthentication * CVE-2026-10907: Out of bounds write in ANGLE * CVE-2026-10908: Use after free in FullScreen * CVE-2026-10909: Use after free in Dawn * CVE-2026-10910: Type Confusion in V8 * CVE-2026-10911: Insufficient validation of untrusted input in Media * CVE-2026-10912: Insufficient validation of untrusted input in Extensions * CVE-2026-10913: Use after free in ANGLE * CVE-2026-10914: Use after free in ANGLE * CVE-2026-10915: Use after free in Core * CVE-2026-10916: Insufficient validation of untrusted input in DevTools * CVE-2026-10917: Insufficient validation of untrusted input in Media * CVE-2026-10918: Use after free in Viz * CVE-2026-10919: Use after free in ANGLE * CVE-2026-10920: Insufficient validation of untrusted input in WebShare * CVE-2026-10921: Integer overflow in Dawn * CVE-2026-10922: Insufficient validation of untrusted input in DevTools * CVE-2026-10923: Use after free in WebAppInstalls * CVE-2026-10924: Integer overflow in Chromecast * CVE-2026-10925: Out of bounds write in Skia * CVE-2026-10926: Use after free in Cast * CVE-2026-10927: Out of bounds read in Dawn * CVE-2026-10928: Script injection in Headless * CVE-2026-10929: Heap buffer overflow in ANGLE * CVE-2026-10930: Out of bounds read in ANGLE * CVE-2026-10931: Use after free in FileSystem * CVE-2026-10932: Use after free in UI * CVE-2026-10933: Use after free in Audio * CVE-2026-10934: Use after free in Autofill * CVE-2026-10935: Inappropriate implementation in V8 * CVE-2026-10936: Type Confusion in V8 * CVE-2026-10937: Inappropriate implementation in Passwords * CVE-2026-10938: Insufficient validation of untrusted input in Input * CVE-2026-10939: Use after free in WebRTC * CVE-2026-10940: Race in Codecs * CVE-2026-10941: Out of bounds memory access in Skia * CVE-2026-10942: Insufficient validation of untrusted input in UI * CVE-2026-10943: Use after free in WebRTC * CVE-2026-10944: Insufficient policy enforcement in Autofill * CVE-2026-10945: Use after free in PDF * CVE-2026-10946: Heap buffer overflow in Media * CVE-2026-10947: Use after free in WebRTC * CVE-2026-10948: Use after free in WebRTC * CVE-2026-10949: Heap buffer overflow in Video * CVE-2026-10950: Insufficient policy enforcement in Autofill * CVE-2026-10951: Use after free in Autofill * CVE-2026-10952: Use after free in Chrome for iOS * CVE-2026-10953: Use after free in Core * CVE-2026-10954: Use after free in Actor * CVE-2026-10955: Type Confusion in ANGLE * CVE-2026-10956: Use after free in MimeHandlerView * CVE-2026-10957: Use after free in Glic * CVE-2026-10958: Use after free in Chrome for iOS * CVE-2026-10959: Use after free in Input * CVE-2026-10960: Uninitialized Use in Codecs * CVE-2026-10961: Use after free in Chrome for iOS * CVE-2026-10962: Type Confusion in Media * CVE-2026-10963: Integer overflow in V8 * CVE-2026-10964: Integer overflow in V8 * CVE-2026-10965: Integer overflow in DevTools * CVE-2026-10966: Insufficient validation of untrusted input in Codecs * CVE-2026-10967: Use after free in SurfaceCapture * CVE-2026-10968: Insufficient validation of untrusted input in Dawn * CVE-2026-10969: Insufficient validation of untrusted input in Extensions * CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups * CVE-2026-10971: Insufficient validation of untrusted input in Printing * CVE-2026-10972: Use after free in Ozone * CVE-2026-10973: Uninitialized Use in Dawn * CVE-2026-10974: Insufficient validation of untrusted input in ANGLE * CVE-2026-10975: Use after free in WebRTC * CVE-2026-10976: Uninitialized Use in Dawn * CVE-2026-10977: Uninitialized Use in Skia * CVE-2026-10978: Use after free in Chromoting * CVE-2026-10979: Out of bounds read in ANGLE * CVE-2026-10980: Insufficient validation of untrusted input in DevTools * CVE-2026-10981: Insufficient validation of untrusted input in Codecs * CVE-2026-10982: Use after free in WebXR * CVE-2026-10983: Insufficient validation of untrusted input in Dawn * CVE-2026-10984: Inappropriate implementation in Accessibility * CVE-2026-10985: Out of bounds read in Skia * CVE-2026-10986: Integer overflow in Media * CVE-2026-10987: Integer overflow in V8 * CVE-2026-10988: Use after free in Views * CVE-2026-10989: Inappropriate implementation in V8 * CVE-2026-10990: Use after free in Glic * CVE-2026-10991: Use after free in V8 * CVE-2026-10992: Insufficient data validation in Animation * CVE-2026-10993: Heap buffer overflow in Skia * CVE-2026-10994: Uninitialized Use in ANGLE * CVE-2026-10995: Heap buffer overflow in TabStrip * CVE-2026-10996: Inappropriate implementation in Workers * CVE-2026-10997: Insufficient policy enforcement in Extensions * CVE-2026-10998: Out of bounds read in Media * CVE-2026-10999: Out of bounds memory access in ANGLE * CVE-2026-11000: Use after free in Fonts * CVE-2026-11001: Incorrect security UI in Payments * CVE-2026-11002: Use after free in Autofill * CVE-2026-11003: Use after free in WebRTC * CVE-2026-11004: Out of bounds read in ANGLE * CVE-2026-11005: Out of bounds read in ANGLE * CVE-2026-11006: Out of bounds read in Dawn * CVE-2026-11007: Insufficient validation of untrusted input in WebView * CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11009: Use after free in USB * CVE-2026-11010: Use after free in WebShare * CVE-2026-11011: Insufficient policy enforcement in Password Manager * CVE-2026-11012: Use after free in Serial * CVE-2026-11013: Insufficient validation of untrusted input in Network * CVE-2026-11014: Insufficient policy enforcement in Extensions * CVE-2026-11015: Out of bounds read in WebGPU * CVE-2026-11016: Insufficient validation of untrusted input in Network * CVE-2026-11017: Inappropriate implementation in Link Preview * CVE-2026-11018: Insufficient policy enforcement in Actor * CVE-2026-11019: Inappropriate implementation in Payments * CVE-2026-11020: Inappropriate implementation in Extensions * CVE-2026-11021: Insufficient validation of untrusted input in GPU * CVE-2026-11022: Insufficient validation of untrusted input in DevTools * CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11024: Stack buffer overflow in Skia * CVE-2026-11025: Insufficient policy enforcement in Navigation * CVE-2026-11026: Insufficient policy enforcement in Extensions * CVE-2026-11027: Insufficient validation of untrusted input in Glic * CVE-2026-11028: Use after free in Media * CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop * CVE-2026-11030: Use after free in Network * CVE-2026-11031: Insufficient validation of untrusted input in Password Manager * CVE-2026-11032: Insufficient data validation in Password Manager * CVE-2026-11033: Uninitialized Use in WebML * CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync * CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs * CVE-2026-11036: Inappropriate implementation in DOM * CVE-2026-11037: Out of bounds write in Codecs * CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity * CVE-2026-11039: Uninitialized Use in Skia * CVE-2026-11040: Use after free in ANGLE * CVE-2026-11041: Insufficient validation of untrusted input in Media * CVE-2026-11042: Use after free in Views * CVE-2026-11043: Out of bounds write in ANGLE * CVE-2026-11044: Integer overflow in ANGLE * CVE-2026-11045: Insufficient validation of untrusted input in GPU * CVE-2026-11046: Insufficient validation of untrusted input in Media * CVE-2026-11047: Insufficient validation of untrusted input in Base * CVE-2026-11048: Inappropriate implementation in Extensions * CVE-2026-11049: Use after free in Password Manager * CVE-2026-11050: Use after free in V8 * CVE-2026-11051: Out of bounds read in ANGLE * CVE-2026-11052: Type Confusion in GPU * CVE-2026-11053: VULNERABILITY in WebRTC * CVE-2026-11054: Use after free in WebRTC * CVE-2026-11055: Use after free in ANGLE * CVE-2026-11056: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-11057: Uninitialized Use in Skia * CVE-2026-11058: Integer overflow in CredentialProvider * CVE-2026-11059: Use after free in Blink * CVE-2026-11060: Use after free in Media * CVE-2026-11061: Out of bounds read in ANGLE * CVE-2026-11062: Insufficient policy enforcement in Extensions * CVE-2026-11063: Insufficient validation of untrusted input in WebNN * CVE-2026-11064: Uninitialized Use in GPU * CVE-2026-11065: Use after free in ANGLE * CVE-2026-11066: Insufficient validation of untrusted input in ANGLE * CVE-2026-11067: Uninitialized Use in Dawn * CVE-2026-11068: Use after free in WebSockets * CVE-2026-11069: Insufficient validation of untrusted input in Cast * CVE-2026-11070: Insufficient validation of untrusted input in Chromoting * CVE-2026-11071: Use after free in Base * CVE-2026-11072: Use after free in WebView * CVE-2026-11073: Use after free in WebGL * CVE-2026-11074: Use after free in WebRTC * CVE-2026-11075: Out of bounds read in V8 * CVE-2026-11076: Type Confusion in CSS * CVE-2026-11077: Out of bounds read in Dawn * CVE-2026-11078: Insufficient validation of untrusted input in FileSystem * CVE-2026-11079: Insufficient validation of untrusted input in Codecs * CVE-2026-11080: Use after free in WebView * CVE-2026-11081: Policy bypass in Canvas * CVE-2026-11082: Use after free in GPU * CVE-2026-11083: Inappropriate implementation in Password Manager * CVE-2026-11084: Inappropriate implementation in Password Manager * CVE-2026-11085: Integer overflow in GPU * CVE-2026-11086: Insufficient validation of untrusted input in Dawn * CVE-2026-11087: Uninitialized Use in ANGLE * CVE-2026-11088: Integer overflow in ANGLE * CVE-2026-11089: Uninitialized Use in Media * CVE-2026-11090: Uninitialized Use in ANGLE * CVE-2026-11091: Inappropriate implementation in Dawn * CVE-2026-11092: Insufficient policy enforcement in DevTools * CVE-2026-11093: Insufficient validation of untrusted input in Printing * CVE-2026-11094: Use after free in Codecs * CVE-2026-11095: Insufficient validation of untrusted input in Codecs * CVE-2026-11096: Out of bounds read in WebRTC * CVE-2026-11097: Inappropriate implementation in WebView * CVE-2026-11098: Insufficient validation of untrusted input in GPU * CVE-2026-11099: Vulnerability in Skia * CVE-2026-11100: Use after free in File Input * CVE-2026-11101: Uninitialized Use in Dawn * CVE-2026-11102: Inappropriate implementation in Isolated Web Apps * CVE-2026-11103: Inappropriate implementation in Installer * CVE-2026-11104: Uninitialized Use in ANGLE * CVE-2026-11105: Insufficient validation of untrusted input in WebUI * CVE-2026-11106: Inappropriate implementation in Media * CVE-2026-11107: Inappropriate implementation in Downloads * CVE-2026-11108: Inappropriate implementation in NFC * CVE-2026-11109: Uninitialized Use in ANGLE * CVE-2026-11110: Uninitialized Use in ANGLE * CVE-2026-11111: Out of bounds read in ANGLE * CVE-2026-11112: Insufficient validation of untrusted input in Chromoting * CVE-2026-11113: Insufficient validation of untrusted input in ANGLE * CVE-2026-11114: Use after free in Device Trust * CVE-2026-11115: Use after free in Updater * CVE-2026-11116: Use after free in Chromoting * CVE-2026-11117: Use after free in Views * CVE-2026-11118: Use after free in WebRTC * CVE-2026-11119: Insufficient validation of untrusted input in GPU * CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting * CVE-2026-11121: Insufficient validation of untrusted input in Skia * CVE-2026-11122: Inappropriate implementation in Keyboard * CVE-2026-11123: Uninitialized Use in ANGLE * CVE-2026-11124: Heap buffer overflow in Skia * CVE-2026-11125: Use after free in Compositing * CVE-2026-11126: Insufficient validation of untrusted input in DevTools * CVE-2026-11127: Inappropriate implementation in WebAPKs * CVE-2026-11128: Insufficient validation of untrusted input in Web Share * CVE-2026-11129: Inappropriate implementation in Extensions * CVE-2026-11130: Use after free in Media * CVE-2026-11131: Use after free in Autofill * CVE-2026-11132: Policy bypass in Paint * CVE-2026-11133: Insufficient policy enforcement in Paint * CVE-2026-11134: Insufficient data validation in Media * CVE-2026-11135: Insufficient policy enforcement in Autofill * CVE-2026-11136: Use after free in Canvas * CVE-2026-11137: Uninitialized Use in ANGLE * CVE-2026-11138: Uninitialized Use in ANGLE * CVE-2026-11139: Policy bypass in Paint * CVE-2026-11140: Insufficient validation of untrusted input in Chromecast * CVE-2026-11141: Uninitialized Use in Audio * CVE-2026-11142: Policy bypass in Paint * CVE-2026-11143: Heap buffer overflow in Extensions * CVE-2026-11144: Use after free in Media * CVE-2026-11145: Race in Geolocation * CVE-2026-11146: Insufficient validation of untrusted input in Chromoting * CVE-2026-11147: Use after free in WebML * CVE-2026-11148: Inappropriate implementation in Payments * CVE-2026-11149: Insufficient validation of untrusted input in Extensions * CVE-2026-11150: Inappropriate implementation in XML * CVE-2026-11151: Insufficient validation of untrusted input in Password Manager * CVE-2026-11152: Object lifecycle issue in Dawn * CVE-2026-11153: Side-channel information leakage in Forms * CVE-2026-11154: Use after free in Dawn * CVE-2026-11155: Insufficient policy enforcement in CSS * CVE-2026-11156: Inappropriate implementation in CSS * CVE-2026-11157: Script injection in Accessibility * CVE-2026-11158: Insufficient validation of untrusted input in Downloads * CVE-2026-11159: Uninitialized Use in Skia * CVE-2026-11160: Out of bounds read in Input * CVE-2026-11161: Insufficient data validation in DataTransfer * CVE-2026-11162: Insufficient policy enforcement in CSS * CVE-2026-11163: Use after free in Messages * CVE-2026-11164: Use after free in Blink * CVE-2026-11165: Use after free in WebMIDI * CVE-2026-11166: Inappropriate implementation in SVG * CVE-2026-11167: Inappropriate implementation in WebView * CVE-2026-11168: Insufficient policy enforcement in Extensions * CVE-2026-11169: Inappropriate implementation in XML * CVE-2026-11170: Inappropriate implementation in Chromoting * CVE-2026-11171: Integer overflow in Blink * CVE-2026-11172: Incorrect security UI in Contact Picker * CVE-2026-11173: Out of bounds write in V8 * CVE-2026-11174: Insufficient policy enforcement in Site Isolation * CVE-2026-11175: Incorrect security UI in Messages * CVE-2026-11176: Inappropriate implementation in Media * CVE-2026-11177: Use after free in Omnibox * CVE-2026-11178: Policy bypass in WebView * CVE-2026-11179: Inappropriate implementation in ORB * CVE-2026-11180: Policy bypass in SVG * CVE-2026-11181: Inappropriate implementation in Media Session * CVE-2026-11182: Inappropriate implementation in SVG * CVE-2026-11183: Out of bounds read in GWP-ASan * CVE-2026-11184: Insufficient policy enforcement in Actor * CVE-2026-11185: Use after free in V8 * CVE-2026-11186: Inappropriate implementation in CSS * CVE-2026-11187: Insufficient policy enforcement in Glic * CVE-2026-11188: Use after free in USB * CVE-2026-11189: Insufficient validation of untrusted input in DevTools * CVE-2026-11190: Insufficient policy enforcement in Extensions * CVE-2026-11191: Out of bounds memory access in ANGLE * CVE-2026-11192: Insufficient validation of untrusted input in Password Manager * CVE-2026-11193: Insufficient policy enforcement in Password Manager * CVE-2026-11194: Inappropriate implementation in Network * CVE-2026-11195: Inappropriate implementation in MHTML * CVE-2026-11196: Type Confusion in XML * CVE-2026-11197: Insufficient policy enforcement in Workers * CVE-2026-11198: Insufficient validation of untrusted input in Codecs * CVE-2026-11199: Insufficient validation of untrusted input in WebRTC * CVE-2026-11200: Inappropriate implementation in WebRTC * CVE-2026-11201: Use after free in ServiceWorker * CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11203: Policy bypass in GPU * CVE-2026-11204: Inappropriate implementation in Signin * CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11206: Policy bypass in ServiceWorker * CVE-2026-11207: Insufficient validation of untrusted input in Autofill * CVE-2026-11208: Use after free in Codecs * CVE-2026-11209: Insufficient policy enforcement in Passwords * CVE-2026-11210: Insufficient policy enforcement in Safe Browsing * CVE-2026-11211: Integer overflow in V8 * CVE-2026-11212: Insufficient policy enforcement in DevTools * CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode * CVE-2026-11214: Inappropriate implementation in Chrome for iOS * CVE-2026-11215: Inappropriate implementation in Cronet * CVE-2026-11216: Incorrect security UI in File Input * CVE-2026-11217: Insufficient policy enforcement in Fenced Frames * CVE-2026-11218: Inappropriate implementation in PlatformIntegration * CVE-2026-11219: Insufficient data validation in Navigation * CVE-2026-11220: Insufficient validation of untrusted input in Navigation * CVE-2026-11221: Insufficient validation of untrusted input in PointerLock * CVE-2026-11222: Incorrect security UI in Tab Strip * CVE-2026-11223: Insufficient validation of untrusted input in Network * CVE-2026-11224: Use after free in Chromoting * CVE-2026-11225: Incorrect security UI in WebUI * CVE-2026-11226: Insufficient policy enforcement in PreviewTab * CVE-2026-11227: Incorrect security UI in Tab Hover Cards * CVE-2026-11228: Incorrect security UI in File Input * CVE-2026-11229: Insufficient policy enforcement in Enterprise * CVE-2026-11230: Use after free in Extensions * CVE-2026-11231: Inappropriate implementation in Safe Browsing * CVE-2026-11232: Inappropriate implementation in TabGroups * CVE-2026-11233: Insufficient validation of untrusted input in FoldableAPIs * CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs * CVE-2026-11235: Insufficient validation of untrusted input in Compositing * CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth * CVE-2026-11237: Insufficient validation of untrusted input in Media * CVE-2026-11238: Inappropriate implementation in DevTools * CVE-2026-11239: Insufficient validation of untrusted input in Extensions * CVE-2026-11240: Insufficient validation of untrusted input in Loader * CVE-2026-11241: Insufficient validation of untrusted input in Cast * CVE-2026-11242: Insufficient validation of untrusted input in Plugins * CVE-2026-11243: Incorrect security UI in Downloads * CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication * CVE-2026-11245: Inappropriate implementation in Payments * CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB * CVE-2026-11247: Insufficient policy enforcement in CustomTabs * CVE-2026-11248: Policy bypass in Google Lens * CVE-2026-11249: Use after free in Network * CVE-2026-11250: Inappropriate implementation in DevTools * CVE-2026-11251: Insufficient validation of untrusted input in Password Manager * CVE-2026-11252: Policy bypass in Content Settings * CVE-2026-11253: Race in Permissions * CVE-2026-11254: Inappropriate implementation in Permissions * CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API * CVE-2026-11256: Out of bounds read in GPU * CVE-2026-11257: Inappropriate implementation in Browser * CVE-2026-11258: Inappropriate implementation in File System Access * CVE-2026-11259: Insufficient validation of untrusted input in Cast * CVE-2026-11260: Policy bypass in Permissions * CVE-2026-11261: Insufficient validation of untrusted input in PDF * CVE-2026-11262: Use after free in TabStrip * CVE-2026-11263: Insufficient policy enforcement in WebAuthentication * CVE-2026-11264: Policy bypass in Content Security Policy * CVE-2026-11265: Insufficient data validation in Autofill * CVE-2026-11266: Policy bypass in SafeBrowsing * CVE-2026-11267: Insufficient policy enforcement in Extensions * CVE-2026-11268: Uninitialized Use in ANGLE * CVE-2026-11269: Inappropriate implementation in Extensions * CVE-2026-11270: Inappropriate implementation in UI * CVE-2026-11271: Incorrect security UI in Passwords * CVE-2026-11272: Insufficient validation of untrusted input in Reading List * CVE-2026-11273: Insufficient validation of untrusted input in Omnibox * CVE-2026-11274: Inappropriate implementation in DOM Distiller * CVE-2026-11275: Insufficient policy enforcement in Page Info * CVE-2026-11276: Inappropriate implementation in Cast * CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11278: Inappropriate implementation in CustomTabs * CVE-2026-11279: Out of bounds read in DevTools * CVE-2026-11280: Insufficient validation of untrusted input in Signin * CVE-2026-11281: Integer overflow in Chromoting * CVE-2026-11282: Policy bypass in Sandbox * CVE-2026-11283: Policy bypass in Shortcuts * CVE-2026-11284: Side-channel information leakage in PerformanceAPIs * CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11286: Insufficient validation of untrusted input in Wallet * CVE-2026-11287: Insufficient validation of untrusted input in Navigation * CVE-2026-11288: Policy bypass in CSS * CVE-2026-11289: Side-channel information leakage in Paint * CVE-2026-11290: Integer overflow in WebView * CVE-2026-11291: Policy bypass in Android Autofill * CVE-2026-11292: Policy bypass in Blink * CVE-2026-11293: Use after free in Input * CVE-2026-11294: Inappropriate implementation in Passwords * CVE-2026-11295: Inappropriate implementation in WebView * CVE-2026-11296: Inappropriate implementation in ImageCapture * CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode * CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11299: Out of bounds read in Fonts * CVE-2026-11300: Inappropriate implementation in Permissions * CVE-2026-11301: Out of bounds read in LiveCaption * CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11303: Use after free in PDFium * CVE-2026-11304: Use after free in PDFium * CVE-2026-11305: Use after free in PDFium * CVE-2026-11306: Use after free in PDFium * CVE-2026-11307: Use after free in PDFium * CVE-2026-11308: Inappropriate implementation in Extensions * CVE-2026-11309: Insufficient policy enforcement in History chromedriver-149.0.7827.53-bp157.2.166.1.x86_64.rpm chromium-149.0.7827.53-bp157.2.166.1.nosrc.rpm chromium-149.0.7827.53-bp157.2.166.1.x86_64.rpm chromedriver-149.0.7827.53-bp157.2.166.1.aarch64.rpm chromium-149.0.7827.53-bp157.2.166.1.aarch64.rpm chromedriver-149.0.7827.53-bp157.2.166.1.ppc64le.rpm chromium-149.0.7827.53-bp157.2.166.1.ppc64le.rpm openSUSE-2026-193 Security update for epiphany important openSUSE Backports SLE-15-SP7 Update This update for epiphany fixes the following issues: - Update to version 42.5 (boo#1208472): + Hide bookmark star in application mode. + Fix type error when displaying about:overview empty state. + Fix thumbnails when loading about:overview from session state. + Fix double free when file monitor for user JavaScript fails. + Don't autofill passwords in sandboxed contexts (CVE-2023-26081) + Updated translations. epiphany-42.5-bp157.2.3.1.src.rpm epiphany-42.5-bp157.2.3.1.x86_64.rpm epiphany-branding-upstream-42.5-bp157.2.3.1.noarch.rpm epiphany-lang-42.5-bp157.2.3.1.noarch.rpm gnome-shell-search-provider-epiphany-42.5-bp157.2.3.1.x86_64.rpm epiphany-42.5-bp157.2.3.1.i586.rpm gnome-shell-search-provider-epiphany-42.5-bp157.2.3.1.i586.rpm epiphany-42.5-bp157.2.3.1.aarch64.rpm gnome-shell-search-provider-epiphany-42.5-bp157.2.3.1.aarch64.rpm epiphany-42.5-bp157.2.3.1.ppc64le.rpm gnome-shell-search-provider-epiphany-42.5-bp157.2.3.1.ppc64le.rpm epiphany-42.5-bp157.2.3.1.s390x.rpm gnome-shell-search-provider-epiphany-42.5-bp157.2.3.1.s390x.rpm openSUSE-2026-196 Recommended update for ansible-sap-launchpad moderate openSUSE Backports SLE-15-SP7 Update This update for ansible-sap-launchpad fixes the following issues: - 1.3.2 - Bugfixes: - all - Replace inject vars with ansible_facts for 2.20 ansible-sap-launchpad-1.3.2-bp157.2.9.1.noarch.rpm ansible-sap-launchpad-1.3.2-bp157.2.9.1.src.rpm openSUSE-2026-195 Security update for keybase-client important openSUSE Backports SLE-15-SP7 Update This update for keybase-client fixes the following issues: - Fixed multiple security issues in golang.org/x/crypto/ssh (boo#1266158). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (boo#1266596). - Update to version 6.6.2 * Improve git default branch handling - Switch to go1.25 as required by update go image library. - Update to version 6.6.0 * Various bug fixes and performance improvements - Update to version 6.5.1 * Fix team deletion not working * Chat attachments improvements * Miscellaneous bugfixes - Switch source download service from deprecated disabledrun to manualrun. - Update to version 6.3.1 * Archive your chats/files/repos for easy backups. * Wrap text in spoiler to hide spoilers. - Update the used Go version to 1.21 which is the first version to support the slices modules which is now used by Keybase. kbfs-6.6.2-bp157.2.6.1.x86_64.rpm kbfs-git-6.6.2-bp157.2.6.1.x86_64.rpm kbfs-tool-6.6.2-bp157.2.6.1.x86_64.rpm keybase-client-6.6.2-bp157.2.6.1.src.rpm keybase-client-6.6.2-bp157.2.6.1.x86_64.rpm kbfs-6.6.2-bp157.2.6.1.i586.rpm kbfs-git-6.6.2-bp157.2.6.1.i586.rpm kbfs-tool-6.6.2-bp157.2.6.1.i586.rpm keybase-client-6.6.2-bp157.2.6.1.i586.rpm kbfs-6.6.2-bp157.2.6.1.aarch64.rpm kbfs-git-6.6.2-bp157.2.6.1.aarch64.rpm kbfs-tool-6.6.2-bp157.2.6.1.aarch64.rpm keybase-client-6.6.2-bp157.2.6.1.aarch64.rpm kbfs-6.6.2-bp157.2.6.1.ppc64le.rpm kbfs-git-6.6.2-bp157.2.6.1.ppc64le.rpm kbfs-tool-6.6.2-bp157.2.6.1.ppc64le.rpm keybase-client-6.6.2-bp157.2.6.1.ppc64le.rpm kbfs-6.6.2-bp157.2.6.1.s390x.rpm kbfs-git-6.6.2-bp157.2.6.1.s390x.rpm kbfs-tool-6.6.2-bp157.2.6.1.s390x.rpm keybase-client-6.6.2-bp157.2.6.1.s390x.rpm openSUSE-2026-201 security update to Chromium 149.0.7827.102 (boo#1267911) low openSUSE Backports SLE-15-SP7 Update security update to Chromium 149.0.7827.102 (boo#1267911) chromedriver-149.0.7827.102-bp157.2.169.1.x86_64.rpm chromium-149.0.7827.102-bp157.2.169.1.nosrc.rpm chromium-149.0.7827.102-bp157.2.169.1.x86_64.rpm chromedriver-149.0.7827.102-bp157.2.169.1.aarch64.rpm chromium-149.0.7827.102-bp157.2.169.1.aarch64.rpm chromedriver-149.0.7827.102-bp157.2.169.1.ppc64le.rpm chromium-149.0.7827.102-bp157.2.169.1.ppc64le.rpm openSUSE-2026-199 Security update for rclone critical openSUSE Backports SLE-15-SP7 Update This update for rclone fixes the following issues: - Update to version 1.74.3: (boo#1267869) - Bug Fixes - rc - Fix unauthenticated command execution via --rc-serve inline remotes CVE-2026-49980 (Nick Craig-Wood) - Stop global.* connection string options changing config CVE-2026-49980 (Nick Craig-Wood) - build: Fix multiple CVEs by upgrading to go1.26.4 (Nick Craig-Wood) - CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader - CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping - CVE-2026-27145: crypto/x509: split candidate hostname only once - log: Fix wrong source file:line in JSON logs from release builds (Nick Craig-Wood) - mount2: Fix empty directory listings on re-read (Janne Beate Bakeng) - serve s3: Fix multipart ListParts pagination returning wrong part numbers (Nick Craig-Wood) - serve sftp - Fix file corruption when a client resumes an upload (Nick Craig-Wood) - Fix truncate request being silently ignored (Nick Craig-Wood) - Local - Fix getXattr returning empty map instead of nil (Leon Brocard) - Drime - Fix server-side copy and move failing with Cloudflare 520 error (Nick Craig-Wood) - Fix files being uploaded to the wrong directory (Nick Craig-Wood) - Remove duplicate upload_cutoff config option (Nick Craig-Wood) - Fix directory rename leaving the renamed folder empty in VFS (Nick Craig-Wood) - Drive - Fix server-side move failing on shared drives with duplicate dirs (Nick Craig-Wood) - Iclouddrive - Fix ADP/PCS cookie acquisition for iCloud Drive (Yakov Till) - Fix "Index has invalid data" error listing iCloud Photos (Nick Craig-Wood) - Update to version 1.74.2: (boo#1266210) - Bug Fixes - build - Update golang.org/x/net to v0.55.0 to address: - CVE-2026-42506: html: incorrect handling of namespaced elements in foreign content - CVE-2026-39821: idna: failure to reject ASCII-only Punycode-encoded labels - CVE-2026-42502: html: incorrect handling of HTML elements in foreign content - CVE-2026-25680: html: denial of service when parsing arbitrary HTML - CVE-2026-25681: html: incorrect handling of character references in DOCTYPE nodes - CVE-2026-27136: html: duplicate attributes can cause XSS - Update golang.org/x/crypto to v0.52.0 to address: - CVE-2026-46598: ssh/agent: pathological inputs can lead to client panic - CVE-2026-46597: ssh: byte arithmetic causes underflow and panic - CVE-2026-39828: ssh: bypass of certificate restrictions - CVE-2026-39835: ssh: server panic during CheckHostKey/Authenticate - CVE-2026-39833: ssh/agent: key constraints not enforced - CVE-2026-39832: ssh/agent: agent constraints dropped when forwarding keys - CVE-2026-39827: ssh: memory leak when rejecting channels can lead to DoS - CVE-2026-39830: ssh: client can cause server deadlock on unexpected responses - CVE-2026-39829: ssh: pathological RSA/DSA parameters may cause DoS - CVE-2026-39831: ssh: bypass of FIDO/U2F security keys physical interaction - CVE-2026-39834: ssh: infinite loop on large channel writes - CVE-2026-42508: ssh/knownhosts: auth bypass via unenforced @revoked status - CVE-2026-46595: ssh: VerifiedPublicKeyCallback permissions skip enforcement - update golang.org/x/image to v0.41.0 to address: - CVE-2026-42500: bmp: panic when reading out of bound palette index - CVE-2026-33809: tiff: excessive resource consumption in PackBits decompression - Update golang.org/x/sys to version v0.45.0 to address: - CVE-2026-39824: windows: integer overflow in NewNTUnicodeString - Update github.com/go-git/go-billy/v5 to 5.9.0 to fix CVE-2026-44740 - bisync: Fix --conflict-loser pathname with --conflict-resolve newer (nielash) - gui: Update embedded release to 1.1.8 (Nick Craig-Wood) - lib/http: Replace deprecated h2c.NewHandler with http.Server.Protocols (Nick Craig-Wood) - rc: Remove duplicate metrics_addr option registration (Nick Craig-Wood) - vfs/vfscache: Fix silent write failure when mounting with remote:. (Lucky945H) - doc fixes (FTCHD, Iizuki, Leon Brocard, Nick Craig-Wood) - Drime - Fix file doesn't exists error when trying to delete (John Volk) - Fix 500 errors when listing shared folders (Alvinwylim) - Jottacloud - Support whitelabel service Phonero Sky (Tore Anderson) - Protondrive - Fix corrupted on transfer: sha1 hashes differ (William Tange) - S3 - Add new MEGA S4 endpoints on megas4.com including Asia-Pacific region (Nick Craig-Wood) - WebDAV - Honour auth_redirect on listAll PROPFIND (Sai Asish Y) rclone-1.74.3-bp157.2.9.1.src.rpm rclone-1.74.3-bp157.2.9.1.x86_64.rpm rclone-bash-completion-1.74.3-bp157.2.9.1.noarch.rpm rclone-zsh-completion-1.74.3-bp157.2.9.1.noarch.rpm rclone-1.74.3-bp157.2.9.1.i586.rpm rclone-1.74.3-bp157.2.9.1.aarch64.rpm rclone-1.74.3-bp157.2.9.1.ppc64le.rpm rclone-1.74.3-bp157.2.9.1.s390x.rpm openSUSE-2026-200 Security update for NetworkManager-libreswan important openSUSE Backports SLE-15-SP7 Update This update for NetworkManager-libreswan fixes the following issues: - Update to version 1.2.24 (boo#1232040): + Fixed formatting of ipsec.conf snippet. This is a security issue with severity of "Important." (CVE-2024-9050). + Added support for "require-id-on-certificate" setting. + Updated translations. - Changes from version 1.2.22: + Add IPv6 support. - Changes from version 1.2.20: + Support setting "leftmodecfgclient" to "no" + Support for the "type", "hostaddrfamily" and "clientaddrfamily", "leftsubnet" and "rightcert" parameters. - Changes from version 1.2.18: + Drop libnm-glib compatibility (NetworkManager < 1.0). + Add support for the "authby", "dpdaction", "dpddelay", "dpdtimeout", "ipsec-interface" parameters. NetworkManager-libreswan-1.2.24-bp157.3.3.1.src.rpm NetworkManager-libreswan-1.2.24-bp157.3.3.1.x86_64.rpm NetworkManager-libreswan-gnome-1.2.24-bp157.3.3.1.x86_64.rpm NetworkManager-libreswan-lang-1.2.24-bp157.3.3.1.noarch.rpm NetworkManager-libreswan-1.2.24-bp157.3.3.1.i586.rpm NetworkManager-libreswan-gnome-1.2.24-bp157.3.3.1.i586.rpm NetworkManager-libreswan-1.2.24-bp157.3.3.1.aarch64.rpm NetworkManager-libreswan-gnome-1.2.24-bp157.3.3.1.aarch64.rpm NetworkManager-libreswan-1.2.24-bp157.3.3.1.ppc64le.rpm NetworkManager-libreswan-gnome-1.2.24-bp157.3.3.1.ppc64le.rpm NetworkManager-libreswan-1.2.24-bp157.3.3.1.s390x.rpm NetworkManager-libreswan-gnome-1.2.24-bp157.3.3.1.s390x.rpm openSUSE-2026-203 Security update for flannel moderate openSUSE Backports SLE-15-SP7 Update This update for flannel fixes the following issues: - Update to version 0.28.5: * Bump docker/login-action from 4.1.0 to 4.2.0 * Bump docker/setup-qemu-action from 4.0.0 to 4.1.0 * Bump docker/metadata-action from 6.0.0 to 6.1.0 * Bump github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common (#2456) * Bump the etcd group with 4 updates (#2455), includes fix for CVE-2026-44283 (boo#1265337) * Bump github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common (#2448) * Bump golang.org/x/sys in the other-go-modules group (#2449) * Bump docker/build-push-action from 7.1.0 to 7.2.0 (#2451) * Bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 (#2453) * Bump github/codeql-action from 4.35.3 to 4.36.0 (#2450) * Update iptables-wrapper to v3 to fix zombie child process * Bump docker/setup-buildx-action from 4.0.0 to 4.1.0 * Bump github/codeql-action from 4.35.2 to 4.35.3 (#2441) * Bump aquasecurity/trivy-action from 0.35.0 to 0.36.0 (#2436) * fix(vxlan): drop slices, use scalar IPs for v4/v6 (review feedback) * fix(vxlan): guard ifaceAddrsV6[0] on IPv4-only setups * Bump the tencent group with 2 updates (#2430) * BUmp k8s deps to v0.33.11 (#2432) * Bump github/codeql-action from 4.35.1 to 4.35.2 (#2431) * Fail early in e2e tests and remove unnecessary step (#2429) * Bump actions/upload-artifact from 7.0.0 to 7.0.1 (#2421) flannel-0.28.5-bp157.2.9.1.src.rpm flannel-0.28.5-bp157.2.9.1.x86_64.rpm flannel-k8s-yaml-0.28.5-bp157.2.9.1.noarch.rpm flannel-0.28.5-bp157.2.9.1.i586.rpm flannel-0.28.5-bp157.2.9.1.aarch64.rpm flannel-0.28.5-bp157.2.9.1.ppc64le.rpm flannel-0.28.5-bp157.2.9.1.s390x.rpm openSUSE-2026-202 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 149.0.7827.114 (boo#1268158): * CVE-2026-12007: Use after free Core * CVE-2026-12008: Use after free DigitalCredentials * CVE-2026-12009: Insufficient validation of untrusted input Accessibility * CVE-2026-12010: Heap buffer overflow GPU * CVE-2026-12011: Use after free WebMIDI * CVE-2026-12012: Use after free Network * CVE-2026-12013: Use after free Media * CVE-2026-12014: Use after free Cast * CVE-2026-12015: Use after free Autofill * CVE-2026-12016: Insufficient validation of untrusted input DevTools * CVE-2026-12017: Insufficient validation of untrusted input Extensions * CVE-2026-12018: Inappropriate implementation Mojo * CVE-2026-12019: Out of bounds write Codecs * CVE-2026-12020: Use after free Autofill * CVE-2026-12022: Race Safe Browsing * CVE-2026-12023: Use after free GPU * CVE-2026-12024: Insufficient policy enforcement DevTools * CVE-2026-12025: Insufficient validation of untrusted input Network * CVE-2026-12026: Out of bounds read Video * CVE-2026-12027: Insufficient policy enforcement Headless * CVE-2026-12028: Use after free GPU * CVE-2026-12029: Use after free Video * CVE-2026-12030: Heap buffer overflow GPU * CVE-2026-12031: Inappropriate implementation Views * CVE-2026-12032: Inappropriate implementation Passwords * CVE-2026-12033: Out of bounds read VideoCapture * CVE-2026-12034: Insufficient validation of untrusted input Linux Toolkit Theming * CVE-2026-12035: Use after free Views chromedriver-149.0.7827.114-bp157.2.172.1.x86_64.rpm chromium-149.0.7827.114-bp157.2.172.1.nosrc.rpm chromium-149.0.7827.114-bp157.2.172.1.x86_64.rpm chromedriver-149.0.7827.114-bp157.2.172.1.aarch64.rpm chromium-149.0.7827.114-bp157.2.172.1.aarch64.rpm chromedriver-149.0.7827.114-bp157.2.172.1.ppc64le.rpm chromium-149.0.7827.114-bp157.2.172.1.ppc64le.rpm openSUSE-2026-206 Security update for restic important openSUSE Backports SLE-15-SP7 Update This update for restic fixes the following issues: Update to 0.19.0 (boo#1266795 boo#1266211): For all the details see: https://github.com/restic/restic/releases/tag/v0.19.0 - Fix #2034: Support serving a restic mount of a Windows system via Samba - Fix #4447: Use mode 0700 for repository directories created over SFTP - Fix #4467: Exit with code 3 when some backup source paths do not exist - Fix #4759: Error out when environment variables hold invalid values - Fix #5233: Return exit code 3 when failing to remove snapshots - Fix #5258: Exit with code 130 on SIGINT - Fix #5280: Reject impossible find time bounds immediately - Fix #5280: Make find --pack list blobs for tree packs - Fix #5354: Allow rclone and sftp backends when running in background - Fix #5427: Correctly restore ACL inheritance state on Windows - Fix #5477: Password prompt was sometimes not shown for backup -v - Fix #5487: Mark repository files read-only when using the SFTP backend - Fix #5586: Correctly handle snapshots --group-by with --latest - Fix #5595: Avoid spurious chmod errors on certain file backends - Fix #5683: Prevent backup --stdin-from-command from hanging - Fix #5757: Respect --user and --host in key passwd - Fix #21820: Correct handling of duplicate index entries - Fix #21820: Correctly handle pack files missing from the index - Chg #5293: Prune small packfiles more aggressively - Chg #5767: Prevent excluding paths explicitly passed to backup - Chg #21791: Update dependencies and require Go 1.25 or newer - Enh #3326: Limit check to snapshots selected by filters - Enh #3572: Support restoring ownership by name on UNIX systems - Enh #3738: Optional GitHub token for self-update API requests - Enh #4278: Support include filters in the rewrite command - Enh #4728: Support zstd compression levels fastest and better - Enh #4868: Include repository ID in the filesystem name used by mount - Enh #5175: Add status counters to copy in verbose text output - Enh #5352: Support excluding cloud-backed files on macOS - Enh #5383: Reduce progress bar refresh rates to decrease energy usage - Enh #5424: Enable Windows filesystem privileges before file access - Enh #5440: Make --host override environment variable RESTIC_HOST - Enh #5448: Support configuring nice and ionice in the Docker image - Enh #5453: Copy multiple snapshots in batches - Enh #5523: Add Open Container Initiative labels to release Docker image - Enh #5531: Reduce Azure storage costs by optimizing uploads - Enh #5562: Rewrite only changed status lines each frame - Enh #5588: Show timezone context in snapshots output - Enh #5610: Reduce check, copy, diff and stats memory usage - Enh #5689: Show more detailed progress for stats - Enh #5713: Significantly speed up index loading - Enh #5718: Stricter and earlier validation of the mount point - refresh disable-selfupdate.patch - Update golang.org/x/net to 0.53.0 (boo#1265915 CVE-2026-33814) - Add fuse recommends as it's needed for mounting restic snapshots and should as such be part of the package. update to 0.18.1: - Fix #5324: Correctly handle backup --stdin-filename with directory paths - Fix #5325: Accept RESTIC_HOST environment variable in forget command - Fix #5342: Ignore "chmod not supported" errors when writing files - Fix #5344: Ignore EOPNOTSUPP errors for extended attributes - Fix #5421: Fix rare crash if directory is removed during backup - Fix #5429: Stop retrying uploads when rest-server runs out of space - Fix #5467: Improve handling of download retries in check command all details at https://github.com/restic/restic/releases/tag/v0.18.1 restic-0.19.0-bp157.2.3.1.src.rpm restic-0.19.0-bp157.2.3.1.x86_64.rpm restic-bash-completion-0.19.0-bp157.2.3.1.noarch.rpm restic-zsh-completion-0.19.0-bp157.2.3.1.noarch.rpm restic-0.19.0-bp157.2.3.1.i586.rpm restic-0.19.0-bp157.2.3.1.aarch64.rpm restic-0.19.0-bp157.2.3.1.ppc64le.rpm openSUSE-2026-204 Security update for cyrus-imapd important openSUSE Backports SLE-15-SP7 Update This update for cyrus-imapd fixes the following issues: - Adapt license - cyrus-imapd don't start because of missing "Requires=var-run.mount" from systemd (boo#1251788) Remove var-run.mount from Requires and After - update to version 3.8.6 (bugfix release) VUL-0: CVE-2025-49812: cyrus-imapd: Opossum Attack Application Layer Desynchronization using Opportunistic TLS (boo#1246165) The industry is deprecating STARTTLS (aka opportunistic TLS) in favor of implicit TLS over a dedicated port. STARTTLS is now disabled by default. * Fixed issue #5477: master: tighten up pidfile/etc handling (boo#1241543) VUL-0: cyrus-imapd: privilege drop happens too late, opening attack vectors from cyrus to root * Fixed issue #5450: fix zoneinfo_db code for GCC 15 (thanks Yadd) * Fixed issue #5309: deadlock on shutdown (thanks Mark Cammidge) * Fixed issue #5424: recognise service-specific SASL options in ``cyr_info conf-lint`` * Fixed issue #5420: fix double-free in http_admin (thanks Wolfgang Breyha) * Fixed issue #5460: pop3d: add basic prometheus support (thanks Wolfgang Breyha) * Fixed issue #5454: httpd fails to parse OpenSSL version for status string - update to version 3.8.5 (bugfix release) * Fixed Issue #5029: check for unexpected extra tiny-tests directories * Fixed Issue #5148: added --enable-release-checks configure option for use when building releases * Fixed Issue #4489: calendar-color "changes" namespace * Fixed Issue #5009: various portability warnings and nits * Fixed Issue #5050: iTIP line endings * Fixed Issue #5052: iMIP line endings * Fixed Issue #5072: http_cgi use after free * Fixed Issue #5094: httpd crash when PROPFIND url is /dav/calendars * Fixed Issue #5118: broken language checks for "zr-hant" and "sr-me" * Fixed Issue #5047: proxying UID SEARCH - rebased patches: - CVE-2025-23394: cyrus-imapd: daily-backup.sh allows escalation from cyrus to root (boo#1241536) Adapt backup-cyrus.service to run as user cyrus:mail cyradm-3.8.6-bp157.2.3.1.x86_64.rpm cyrus-imapd-3.8.6-bp157.2.3.1.src.rpm cyrus-imapd-3.8.6-bp157.2.3.1.x86_64.rpm cyrus-imapd-devel-3.8.6-bp157.2.3.1.x86_64.rpm cyrus-imapd-snmp-3.8.6-bp157.2.3.1.x86_64.rpm cyrus-imapd-snmp-mibs-3.8.6-bp157.2.3.1.x86_64.rpm cyrus-imapd-utils-3.8.6-bp157.2.3.1.x86_64.rpm libcyrus0-3.8.6-bp157.2.3.1.x86_64.rpm perl-Cyrus-Annotator-3.8.6-bp157.2.3.1.x86_64.rpm perl-Cyrus-IMAP-3.8.6-bp157.2.3.1.x86_64.rpm perl-Cyrus-SIEVE-managesieve-3.8.6-bp157.2.3.1.x86_64.rpm cyradm-3.8.6-bp157.2.3.1.i586.rpm cyrus-imapd-3.8.6-bp157.2.3.1.i586.rpm cyrus-imapd-devel-3.8.6-bp157.2.3.1.i586.rpm cyrus-imapd-snmp-3.8.6-bp157.2.3.1.i586.rpm cyrus-imapd-snmp-mibs-3.8.6-bp157.2.3.1.i586.rpm cyrus-imapd-utils-3.8.6-bp157.2.3.1.i586.rpm libcyrus0-3.8.6-bp157.2.3.1.i586.rpm perl-Cyrus-Annotator-3.8.6-bp157.2.3.1.i586.rpm perl-Cyrus-IMAP-3.8.6-bp157.2.3.1.i586.rpm perl-Cyrus-SIEVE-managesieve-3.8.6-bp157.2.3.1.i586.rpm cyradm-3.8.6-bp157.2.3.1.aarch64.rpm cyrus-imapd-3.8.6-bp157.2.3.1.aarch64.rpm cyrus-imapd-devel-3.8.6-bp157.2.3.1.aarch64.rpm cyrus-imapd-snmp-3.8.6-bp157.2.3.1.aarch64.rpm cyrus-imapd-snmp-mibs-3.8.6-bp157.2.3.1.aarch64.rpm cyrus-imapd-utils-3.8.6-bp157.2.3.1.aarch64.rpm libcyrus0-3.8.6-bp157.2.3.1.aarch64.rpm perl-Cyrus-Annotator-3.8.6-bp157.2.3.1.aarch64.rpm perl-Cyrus-IMAP-3.8.6-bp157.2.3.1.aarch64.rpm perl-Cyrus-SIEVE-managesieve-3.8.6-bp157.2.3.1.aarch64.rpm cyradm-3.8.6-bp157.2.3.1.ppc64le.rpm cyrus-imapd-3.8.6-bp157.2.3.1.ppc64le.rpm cyrus-imapd-devel-3.8.6-bp157.2.3.1.ppc64le.rpm cyrus-imapd-snmp-3.8.6-bp157.2.3.1.ppc64le.rpm cyrus-imapd-snmp-mibs-3.8.6-bp157.2.3.1.ppc64le.rpm cyrus-imapd-utils-3.8.6-bp157.2.3.1.ppc64le.rpm libcyrus0-3.8.6-bp157.2.3.1.ppc64le.rpm perl-Cyrus-Annotator-3.8.6-bp157.2.3.1.ppc64le.rpm perl-Cyrus-IMAP-3.8.6-bp157.2.3.1.ppc64le.rpm perl-Cyrus-SIEVE-managesieve-3.8.6-bp157.2.3.1.ppc64le.rpm cyradm-3.8.6-bp157.2.3.1.s390x.rpm cyrus-imapd-3.8.6-bp157.2.3.1.s390x.rpm cyrus-imapd-devel-3.8.6-bp157.2.3.1.s390x.rpm cyrus-imapd-snmp-3.8.6-bp157.2.3.1.s390x.rpm cyrus-imapd-snmp-mibs-3.8.6-bp157.2.3.1.s390x.rpm cyrus-imapd-utils-3.8.6-bp157.2.3.1.s390x.rpm libcyrus0-3.8.6-bp157.2.3.1.s390x.rpm perl-Cyrus-Annotator-3.8.6-bp157.2.3.1.s390x.rpm perl-Cyrus-IMAP-3.8.6-bp157.2.3.1.s390x.rpm perl-Cyrus-SIEVE-managesieve-3.8.6-bp157.2.3.1.s390x.rpm openSUSE-2026-207 Security update for java-11-openj9 important openSUSE Backports SLE-15-SP7 Update This update for java-11-openj9 fixes the following issues: - Make post scripts less noisy (boo#1267355) - Use libalternatives instead of update-alternatives for distributions where libalternatives is available - Update to OpenJDK 11.0.31 with OpenJ9 0.59.0 virtual machine - Include Oracle April 2026 CPU changes * CVE-2026-22007 (boo#1262490), CVE-2026-22013 (boo#1262494), CVE-2026-22016 (boo#1262495), CVE-2026-22018 (boo#1262496), CVE-2026-22021 (boo#1262497), CVE-2026-23865 (boo#1259118), CVE-2026-34268 (boo#1262500), CVE-2026-34282 (boo#1262501) - OpenJ9 specific security fix * CVE-2026-1188 (boo#1265261) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.59/ - Update to OpenJDK 11.0.30 with OpenJ9 0.57.0 virtual machine - Including Oracle January 2026 CPU changes * CVE-2026-21925 (boo#1257034), CVE-2026-21932 (boo#1257036), CVE-2026-21933 (boo#1257037), CVE-2026-21945 (boo#1257038) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.57/ - Do not depend on update-desktop-files (jsc#PED-14507) - Update to OpenJDK 11.0.29 with OpenJ9 0.56.0 virtual machine - Including Oracle October 2025 CPU changes * CVE-2025-53057 (boo#1252414), CVE-2025-53066 (boo#1252417) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.56/ - Remove pack200 and unpack200 from alternatives java-11-openj9-11.0.31.0-bp157.2.6.1.src.rpm java-11-openj9-11.0.31.0-bp157.2.6.1.x86_64.rpm java-11-openj9-demo-11.0.31.0-bp157.2.6.1.x86_64.rpm java-11-openj9-devel-11.0.31.0-bp157.2.6.1.x86_64.rpm java-11-openj9-headless-11.0.31.0-bp157.2.6.1.x86_64.rpm java-11-openj9-javadoc-11.0.31.0-bp157.2.6.1.noarch.rpm java-11-openj9-jmods-11.0.31.0-bp157.2.6.1.x86_64.rpm java-11-openj9-src-11.0.31.0-bp157.2.6.1.x86_64.rpm java-11-openj9-11.0.31.0-bp157.2.6.1.aarch64.rpm java-11-openj9-demo-11.0.31.0-bp157.2.6.1.aarch64.rpm java-11-openj9-devel-11.0.31.0-bp157.2.6.1.aarch64.rpm java-11-openj9-headless-11.0.31.0-bp157.2.6.1.aarch64.rpm java-11-openj9-jmods-11.0.31.0-bp157.2.6.1.aarch64.rpm java-11-openj9-src-11.0.31.0-bp157.2.6.1.aarch64.rpm java-11-openj9-11.0.31.0-bp157.2.6.1.ppc64le.rpm java-11-openj9-demo-11.0.31.0-bp157.2.6.1.ppc64le.rpm java-11-openj9-devel-11.0.31.0-bp157.2.6.1.ppc64le.rpm java-11-openj9-headless-11.0.31.0-bp157.2.6.1.ppc64le.rpm java-11-openj9-jmods-11.0.31.0-bp157.2.6.1.ppc64le.rpm java-11-openj9-src-11.0.31.0-bp157.2.6.1.ppc64le.rpm java-11-openj9-11.0.31.0-bp157.2.6.1.s390x.rpm java-11-openj9-demo-11.0.31.0-bp157.2.6.1.s390x.rpm java-11-openj9-devel-11.0.31.0-bp157.2.6.1.s390x.rpm java-11-openj9-headless-11.0.31.0-bp157.2.6.1.s390x.rpm java-11-openj9-jmods-11.0.31.0-bp157.2.6.1.s390x.rpm java-11-openj9-src-11.0.31.0-bp157.2.6.1.s390x.rpm openSUSE-2026-208 Security update for java-17-openj9 important openSUSE Backports SLE-15-SP7 Update This update for java-17-openj9 fixes the following issues: - Make post scripts less noisy (boo#1267355) - Use libalternatives instead of update-alternatives for distributions where libalternatives is available - Update to OpenJDK 17.0.19 with OpenJ9 0.59.0 virtual machine - Including Oracle April 2026 CPU changes * CVE-2026-22007 (boo#1262490), CVE-2026-22013 (boo#1262494), CVE-2026-22016 (boo#1262495), CVE-2026-22018 (boo#1262496), CVE-2026-22021 (boo#1262497), CVE-2026-23865 (boo#1259118), CVE-2026-34268 (boo#1262500), CVE-2026-34282 (boo#1262501) - OpenJ9 specific security fix * CVE-2026-1188 (boo#1265261) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.59/ - Update to OpenJDK 17.0.18 with OpenJ9 0.57.0 virtual machine - Including Oracle January 2026 CPU changes * CVE-2026-21925 (boo#1257034), CVE-2026-21932 (boo#1257036), CVE-2026-21933 (boo#1257037), CVE-2026-21945 (boo#1257038) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.57/ - Do not depend on update-desktop-files (jsc#PED-14507) - Update to OpenJDK 17.0.17 with OpenJ9 0.56.0 virtual machine - Including Oracle October 2025 CPU changes * CVE-2025-53057 (boo#1252414), CVE-2025-53066 (boo#1252417) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.56/ java-17-openj9-17.0.19.0-bp157.2.6.1.src.rpm java-17-openj9-17.0.19.0-bp157.2.6.1.x86_64.rpm java-17-openj9-demo-17.0.19.0-bp157.2.6.1.x86_64.rpm java-17-openj9-devel-17.0.19.0-bp157.2.6.1.x86_64.rpm java-17-openj9-headless-17.0.19.0-bp157.2.6.1.x86_64.rpm java-17-openj9-javadoc-17.0.19.0-bp157.2.6.1.noarch.rpm java-17-openj9-jmods-17.0.19.0-bp157.2.6.1.x86_64.rpm java-17-openj9-src-17.0.19.0-bp157.2.6.1.x86_64.rpm java-17-openj9-17.0.19.0-bp157.2.6.1.aarch64.rpm java-17-openj9-demo-17.0.19.0-bp157.2.6.1.aarch64.rpm java-17-openj9-devel-17.0.19.0-bp157.2.6.1.aarch64.rpm java-17-openj9-headless-17.0.19.0-bp157.2.6.1.aarch64.rpm java-17-openj9-jmods-17.0.19.0-bp157.2.6.1.aarch64.rpm java-17-openj9-src-17.0.19.0-bp157.2.6.1.aarch64.rpm java-17-openj9-17.0.19.0-bp157.2.6.1.ppc64le.rpm java-17-openj9-demo-17.0.19.0-bp157.2.6.1.ppc64le.rpm java-17-openj9-devel-17.0.19.0-bp157.2.6.1.ppc64le.rpm java-17-openj9-headless-17.0.19.0-bp157.2.6.1.ppc64le.rpm java-17-openj9-jmods-17.0.19.0-bp157.2.6.1.ppc64le.rpm java-17-openj9-src-17.0.19.0-bp157.2.6.1.ppc64le.rpm java-17-openj9-17.0.19.0-bp157.2.6.1.s390x.rpm java-17-openj9-demo-17.0.19.0-bp157.2.6.1.s390x.rpm java-17-openj9-devel-17.0.19.0-bp157.2.6.1.s390x.rpm java-17-openj9-headless-17.0.19.0-bp157.2.6.1.s390x.rpm java-17-openj9-jmods-17.0.19.0-bp157.2.6.1.s390x.rpm java-17-openj9-src-17.0.19.0-bp157.2.6.1.s390x.rpm openSUSE-2026-205 Security update for cheat important openSUSE Backports SLE-15-SP7 Update This update for cheat fixes the following issues: - CVE-2026-41506: HTTP authentication credential leak (boo#1264943) Bump go-git to 5.18.0 - CVE-2026-1229: Fix incorrect value (boo#1265539) Bump circl to 1.6.3 - CVE-2026-39827,CVE-2026-39834,CVE-2026-39828,CVE-2026-39829,CVE-2026-39831, CVE-2026-42508,CVE-2026-39833,CVE-2026-39830,CVE-2026-39832,CVE-2026-46597, CVE-2026-46598,CVE-2026-46595,CVE-2026-39835: Fix multiple issues (boo#1266184) Bump crypto to 0.52.0 - CVE-2026-44740: Improper input handling (boo#1267330) Bump go-billy to 5.9.0 - Update to 5.1.0: * --update / -u flag: Pull the latest changes for all git-backed cheatpaths from the CLI. Reports per-path status (ok, skipped, error). Works with --path filtering to update specific cheatpaths. Supports SSH remotes via key file discovery and SSH agent. (#552) Documentation: * Fixed config filename references in man page (conf.yaml → conf.yml) * Added missing /etc/cheat/conf.yml config search path to man page * Fixed stale code references in CLAUDE.md, HACKING.md, and ADRs * Updated Go version requirement in INSTALLING.md - Update to 5.0.0: * Migrated from docopt to cobra (#768, #705, #632, #476) * Dynamic shell completions Breaking changes: * The static completion scripts under scripts/ have been removed. Users must regenerate completions using cheat --completion <shell>. * The CHEAT_USE_FZF environment variable is no longer supported. Bug fixes: * Fixed _init_completion: command not found error (#768) * Fixed autocompletion not working (#705) * Fixed zsh autocompletion not resolving cheatsheet names (#632) - Update to 4.7.1: * Internal cleanup and project restructuring. No user-facing behavior changes - Update to 4.7.0: * Brief list output (-b/--brief) - Update to 4.6.0: New Features: * Recursive .cheat directory discovery: cheat now walks up the directory tree to find .cheat directories, mirroring how git discovers .git directories. Place a .cheat directory at your project root and it will be available from any subdirectory. (#602) Documentation: * ADR-004: documents the design decisions for recursive .cheat discovery * Updated README and package docs to describe the new behaviour - Update to 4.5.2: Bug Fixes: * Static binaries: Build with CGO_ENABLED=0 to produce fully static binaries (#744) * Editor env vars: Respect $VISUAL and $EDITOR environment variables at runtime (#589) * .git in path: Fix cheatsheets being silently skipped when the cheatpath contains a directory ending in .git (#711) Other Changes: * Remove dead Homebrew formula bump workflow * Move ADRs from doc/adr/ to adr/ for discoverability - Update to 4.5.1: * Fix first-run experience (#721, #730, #771): Declining community cheatsheets during initial setup no longer causes errors on subsequent runs. config.New() now skips missing cheatpaths with a warning instead of a fatal error. * Fix --init output (#773): cheat --init now comments out the community cheatpath by default and includes clone instructions, so the output works as a config file without modification. * Fix stdin buffering in installer prompts: The installer's interactive prompts now read stdin without buffering, allowing cheat to be scripted (e.g., printf "y\nn\n" | cheat). * Fix frontmatter parsing on Windows: Line ending detection in cheatsheet frontmatter now inspects file content instead of checking runtime.GOOS, fixing parsing failures when files have Unix line endings on Windows. * CI modernized: Go 1.26, GitHub Actions v4/v5, Windows added to test matrix * Dependencies updated (addresses dependabot CVEs in golang.org/x/crypto, golang.org/x/net) * End-to-end integration tests added for first-run experience * Dockerfile updated to Go 1.26 - Update to 4.5.0: Bug Fixes: * Fix inverted pager detection logic (returned error string instead of path) * Fix repo.Clone ignoring destination directory parameter * Fix sheet loading using append on pre-sized slices, causing nil entries * Clean up partial files on copy failure * Trim whitespace from editor config during loading Security: * Add path traversal protection for cheatsheet names Performance: * Move regex compilation outside search loop * Replace O(n²) string concatenation with strings.Join in search Build & Testing: * Remove go:generate; embed config and usage as string literals * Parallelize release builds * Add fuzz testing infrastructure * Improve test coverage from 38.9% to 50.2% Documentation: * Fix inaccurate code examples in HACKING.md * Add missing --conf and --all options to man page * Add ADRs for path traversal, env parsing, and search parallelization * Update CONTRIBUTING.md to reflect project policy cheat-5.1.0-bp157.2.6.1.src.rpm cheat-5.1.0-bp157.2.6.1.x86_64.rpm cheat-5.1.0-bp157.2.6.1.i586.rpm cheat-5.1.0-bp157.2.6.1.aarch64.rpm cheat-5.1.0-bp157.2.6.1.ppc64le.rpm cheat-5.1.0-bp157.2.6.1.s390x.rpm openSUSE-2026-209 Security update for perl-GD important openSUSE Backports SLE-15-SP7 Update This update for perl-GD fixes the following issues: - CVE-2026-11526: Fixed a command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle (boo#1268240) perl-GD-2.76-bp157.2.3.1.src.rpm perl-GD-2.76-bp157.2.3.1.x86_64.rpm perl-GD-2.76-bp157.2.3.1.aarch64.rpm perl-GD-2.76-bp157.2.3.1.ppc64le.rpm perl-GD-2.76-bp157.2.3.1.s390x.rpm openSUSE-2026-210 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 149.0.7827.155 (boo#1268373): * CVE-2026-12437: Use after free in WebShare * CVE-2026-12438: Inappropriate implementation in WebView * CVE-2026-12439: Use after free in Digital Credentials * CVE-2026-12440: Use after free in DigitalCredentials * CVE-2026-12441: Use after free in File Input * CVE-2026-12442: Use after free in Passwords * CVE-2026-12443: Use after free in Web Authentication * CVE-2026-12444: Out of bounds read in Chromoting * CVE-2026-12445: Use after free in Extensions * CVE-2026-12446: Insufficient data validation in Passwords * CVE-2026-12447: Heap buffer overflow in WebRTC * CVE-2026-12448: Inappropriate implementation in WebView * CVE-2026-12449: Use after free in Chromoting * CVE-2026-12450: Inappropriate implementation in Media * CVE-2026-12451: Use after free in DigitalCredentials * CVE-2026-12452: Use after free in Downloads * CVE-2026-12453: Insufficient validation of untrusted input in Input * CVE-2026-12454: Race in Safe Browsing * CVE-2026-12455: Use after free in Tab Strip * CVE-2026-12456: Insufficient validation of untrusted input in Extensions * CVE-2026-12457: Insufficient data validation in Extensions * CVE-2026-12458: Incorrect security UI in Passwords * CVE-2026-12459: Inappropriate implementation in Serial * CVE-2026-12460: Insufficient policy enforcement in File System Access * CVE-2026-12461: Out of bounds read in WebRTC * CVE-2026-12462: Use after free in Media * CVE-2026-12463: Inappropriate implementation in Views * CVE-2026-12464: Use after free in Browser * CVE-2026-12465: Insufficient validation of untrusted input in Metrics * CVE-2026-12466: Heap buffer overflow in WebRTC * CVE-2026-12467: Use after free in Extensions * CVE-2026-12468: Inappropriate implementation in Updater * CVE-2026-12469: Uninitialized Use in GPU chromedriver-149.0.7827.155-bp157.2.175.1.x86_64.rpm chromium-149.0.7827.155-bp157.2.175.1.nosrc.rpm chromium-149.0.7827.155-bp157.2.175.1.x86_64.rpm chromedriver-149.0.7827.155-bp157.2.175.1.aarch64.rpm chromium-149.0.7827.155-bp157.2.175.1.aarch64.rpm chromedriver-149.0.7827.155-bp157.2.175.1.ppc64le.rpm chromium-149.0.7827.155-bp157.2.175.1.ppc64le.rpm openSUSE-2026-230 Security update for perl-Crypt-SaltedHash critical openSUSE Backports SLE-15-SP7 Update This update for perl-Crypt-SaltedHash fixes the following issues: - updated to 0.120.0 (0.12) see /usr/share/doc/packages/perl-Crypt-SaltedHash/Changes 0.12 2026-05-23 07:29:34+01:00 Europe/London - Add reference to Crypt::Passphrase::SaltedHash - Removed DOS line-endings - updated to 0.110.0 (0.11) 0.11 2026-05-20 14:05:07+01:00 Europe/London - Fixed metadata - Moved author tests into xt 0.10 2026-05-19 - Maintenance taken over by Robert Rothenberg <perl@rhizomnic.com> - Updated the Git Repository - Updated copyright year - Minimum Perl version is v5.6.0 - Added missing prerequisites, fixes RT#116392 - Security: Use system randomness source to generate the salt CVE-2026-47372 boo#1265927 - Security: Use constant-time comparison of hashes CVE-2026-47373 boo#1265912 - Deprecated module - Updated README perl-Crypt-SaltedHash-0.120.0-bp157.2.3.1.noarch.rpm perl-Crypt-SaltedHash-0.120.0-bp157.2.3.1.src.rpm openSUSE-2026-231 Security update for radare2 important openSUSE Backports SLE-15-SP7 Update This update for radare2 fixes the following issues: - switch to python311 for sle15 build - CVE-2026-8695: Fix use-after-free in gdbr_threads_list() (boo#1265403) - Update to version 6.1.4 (boo#1262142, CVE-2026-40499): * Analysis: improve autoname scoring, jmptbl detection, and performance * Add callargs modifier, rnum expressions, and typed function context * Refactor autoname into plugin; extend RAnalPlugin hooks * Fix leaks, overflows, and command injection in analysis scripts * Improve string detection, wide strings, and switch/case analysis * Arch: fix v850/nds32 ESIL, optimize to O(1), improve pseudo support * Cache capstone options and improve multi-arch disassembly * ASM: add camel syntax support, unify via RArch API * Bin: major parser fixes (ELF, Mach-O, PE, DEX, PDB, WAD, XCOFF) * Fix leaks, OOB reads/writes, overflows, and improve bounds checks * Improve Swift demangling, ARM hints, relocations, and imports * Add nds32 reloc support and optimize kernelcache parsing * Build: install to lib64, fix illumos and packaging issues * CI: add GitHub Actions and FilC builds * Console: fix multiple overflows, OOB issues, and improve performance * Core: API renames, plugin load order, sandbox/config fixes * Crash: extensive fixes (UAF, OOB, overflows, injections, fuzz bugs) * Harden ELF, PDB, kernelcache, regex, disassemblers, and webserver * Debug: improve ptrace, winkd support, breakpoints, checkpoints * Disasm: cache flag lookups for performance * FS/IO: fix leaks, bounds, sparse IO, and device handling * HTTP/socket: webserver fixes and SSL fallback handling * Print/projects: improve formatting, endian handling, project metadata * Pseudo: add while/switch support and cleaner control flow * Search/shell: improve commands, parsing, and usability * Security: fix widespread command injection and sandbox escapes * Tests/tools: improve r2r, CLI tools, fuzzing, and plugin support * Types/util: parsing improvements, JSON/base64 updates, optimizations * Visual: fix UAF/leaks, improve panels and UX * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.1.4 - Update to version 6.1.2: * Analysis: preserve timeouts, improve bb/jmptbl validation and limits * Optimize string detection and hot-path functions * Add APIs for function signatures, vars limits, and instruction hints * Fix overlapped functions, invalid code checks, and large bb handling * API: remove deprecated librmagic/filetype APIs and name filter * Arch: fix Thumb/endianness issues, add Python pseudo plugin * ASM: unify settings via RArch, fix directives, add bf pseudo plugin * Bin: improve ELF/Mach-O stripped detection and parsing safety * Harden Mach-O bounds, optimize kernelcache and XNU parsing * Fix many leaks (DEX, demangler, parsers) and infinite loops * Improve DWARF handling and symbol/type extraction * Build: improve meson, toolchains, and add ISO/docker support * Console: preserve timeout, fix themes and UTF-8 handling * Core: fix config bugs, improve startup and addressing support * Crash: fix UAF, OOB, race conditions, regex bugs, and overflows * Add safety checks across dotnet, Mach-O, DWARF, and webserver * Debug/ESIL: safer execution and divide-by-zero handling * FS/IO: fix HFS+, dyldcache speedups, safer zip handling * Graph: add bb size limit option * Print: merge commands, improve UTF-8 and formatting * Projects/tools: new configs, plugin support, CLI improvements * Search: faster analysis search and block buffering * Shell: improve grep/macros and file operations * Types: lazy-load, cache, and improve parsing (varargs, structs) * Tests: expand fuzzing and test suites * General cleanup, performance tuning, and safety improvements * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.1.4 - Update to version 6.1.0: * Reimplement RBufRef using RRef; fix RLibDelHandler API * Remove stale JAY code; improve analysis performance and CI speed * Optimize type propagation, jump tables, and plugin integration * Fix infinite loops, antidisasm tricks, and function autonaming * Add new analysis options and trace import plugin (DRCOV) * Improve RCore seek operations and naming APIs * API: add RNum.getErr, enforce safe alloc macros, new helpers * Arch: update ARC disasm, refactor sessions, remove unsafe string ops * ASM: improve x86 validation, add CIL and ARC pseudo plugins * Bin: major fixes for PE, ELF, Java, MDMP, LE, DEX; reduce memory use * Add/import DWARF types, improve relocations and symbol handling * Extensive memory leak fixes and parser hardening across formats * Improve string handling, caching, and zero-copy optimizations * Build: improve meson, remove zip deps, add 3rd-party plugin support * Console: fix UTF-8 graphs and color propagation * Core: improve plugin handling and background task stability * Crash: fix multiple UAF, OOB, overflows, and injection issues * Sanitize inputs (function names, demangler, callconv) * Debug: add source breakpoints, ARM64/XNU support, FPU regs * Disasm: improve string handling, comments, and color logic * ESIL: extend x86 FPU emulation * FS/IO: fixes and plugin reorganizations * HTTP: fix sandbox webserver issues * Hash/tools: minor fixes and output improvements * General cleanup, safety checks, and performance optimizations * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.1.0 - Update to version 6.0.8: * Migrate r_vector to RVec across core components * Refactor and optimize type propagation (now plugin-based) * Remove redundant anal.a2f and related duplication * Improve caching, memoization, and performance in analysis * Fix file corruption, null asserts, and command issues * Enhance x86 (AT&T syntax, enter instruction) and z80 support * Add initial .NET (CIL) disasm/asm support * Improve Java, ELF, Mach-O, APK, and PDB handling * Fix demangling, symbols, and relocation issues * Resolve multiple memory leaks and parser bugs * Fix UAF, OOB, overflows, and command injection vulnerabilities * Improve GDB debugging and breakpoint handling * Enhance disassembly visuals and color options * Update ESIL operators and behavior * Add support for APFS, GPT, BSD, APM partitions * Improve IO handling and add new plugins * Optimize performance (strbuf, memory usage) * Improve console UI, themes, and terminal handling * Refine SDK builds and CI pipelines * Improve CLI tools (rabin2, rasm2, rafs2) * Add JSON support and better help/version info * Expand type parsing (typedef, enum, union) * Improve socket/HTTP handling and downloads * Add and refine tests and reporting * General cleanup, safety checks, and code modernization * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.0.8 - Expand %{bindir}/* - Rename sdb.1 man page to r2sdb.1 to avoid conflict with snobol4 - Fix patch pkgconfig.patch to be -p1-able - Update to version 6.0.7: * shell: Fix parsing r2 -H$(VARNAME) without a space - Update to version 6.0.6: * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.0.6 - Update to version 6.0.4: * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.0.4 - Update to version 6.0.2: * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.0.2 - Add missing sub directories for r_util.h and r_muta.h otherwise it might fails in calling r2pm -ci <plugin> - Correct library package nameing scheme to make it build also on x86_64 on 15.6 and 15.7 - Update to version 6.0.0: * ABI changes: ~ RCorePlugins now have a session ~ Finish the RKons refactoring, all r_cons calls take instance instead of global ~ Rename RCrypto to RMuta ~ Use RCons instance from RLine ~ Rename RIOPlugin.widget to RIOPlugin.data ~ Refactor the RRegAlias api ~ Camelcase all the RCoreBind methods * Breaking API changes: ~ Boolify r_cons_rgb_parse ~ Add RLogLevel.fromString() and use it from -e log.level=? ~ Deprecate r_bin_addr2line ~ Rename RBinDbgItem into RBinAddrline ~ RNumCalc is now known as RNumMath ~ Move RFlagItem.alias into the Meta ~ Rename core->offset into core->addr (asm.offset and more!) ~ Rename RFlagItem.offset -> addr * API changes: ~ Boolify r_cons_rgb_parse ~ Add RLogLevel.fromString() and use it from -e log.level=? ~ Deprecate r_bin_addr2line ~ Rename RBinDbgItem into RBinAddrline ~ RNumCalc is now known as RNumMath ~ Move RFlagItem.alias into the Meta ~ Rename core->offset into core->addr (asm.offset and more!) ~ Rename RFlagItem.offset -> addr ~ Deprecate RLang.list() ~ Unified function to jsonify the plugin meta + more fields ~ Redesign the REvent API * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.0.0 libsdb2_4_2-6.1.4-bp157.5.3.5.x86_64.rpm radare2-6.1.4-bp157.5.3.5.src.rpm radare2-6.1.4-bp157.5.3.5.x86_64.rpm radare2-devel-6.1.4-bp157.5.3.5.x86_64.rpm radare2-zsh-completion-6.1.4-bp157.5.3.5.noarch.rpm libsdb2_4_2-6.1.4-bp157.5.3.5.aarch64.rpm radare2-6.1.4-bp157.5.3.5.aarch64.rpm radare2-devel-6.1.4-bp157.5.3.5.aarch64.rpm libsdb2_4_2-6.1.4-bp157.5.3.5.ppc64le.rpm radare2-6.1.4-bp157.5.3.5.ppc64le.rpm radare2-devel-6.1.4-bp157.5.3.5.ppc64le.rpm libsdb2_4_2-6.1.4-bp157.5.3.5.s390x.rpm radare2-6.1.4-bp157.5.3.5.s390x.rpm radare2-devel-6.1.4-bp157.5.3.5.s390x.rpm openSUSE-2026-217 Security update for perl-Net-Dropbox-API moderate openSUSE Backports SLE-15-SP7 Update This update for perl-Net-Dropbox-API fixes the following issues: - Improve entropy for secure tokens CVE-2024-58036 boo#1240884 Add cpanspec.yml file used by cpanspec for autogenerating the spec. - Normalize CPAN version See https://github.com/openSUSE/cpanspec/issues/47 for details perl-Net-Dropbox-API-1.900.0-bp157.2.3.1.noarch.rpm perl-Net-Dropbox-API-1.900.0-bp157.2.3.1.src.rpm openSUSE-2026-215 Security update for python-biopython moderate openSUSE Backports SLE-15-SP7 Update This update for python-biopython fixes the following issues: - CVE-2025-68463: Fixed a information disclosure caused by a XXE vulnerability (boo#1255465). python-biopython-1.75-bp157.2.3.1.src.rpm python3-biopython-1.75-bp157.2.3.1.x86_64.rpm python3-biopython-1.75-bp157.2.3.1.i586.rpm python3-biopython-1.75-bp157.2.3.1.aarch64.rpm python3-biopython-1.75-bp157.2.3.1.ppc64le.rpm python3-biopython-1.75-bp157.2.3.1.s390x.rpm openSUSE-2026-211 Security update for python-nltk important openSUSE Backports SLE-15-SP7 Update This update for python-nltk fixes the following issues: - CVE-2026-54293: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read (boo#1268526) python-nltk-3.7-bp157.3.12.1.src.rpm python3-nltk-3.7-bp157.3.12.1.noarch.rpm openSUSE-2026-218 Security update for python-zeroconf moderate openSUSE Backports SLE-15-SP7 Update This update for python-zeroconf fixes the following issues: - CVE-2026-47183: zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion (boo#1268342) - CVE-2026-47184: zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood (boo#1268343) - CVE-2026-48487: python-zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet (boo#1268235) python-zeroconf-0.25.1-bp157.2.3.1.src.rpm python3-zeroconf-0.25.1-bp157.2.3.1.noarch.rpm openSUSE-2026-212 Security update for hamlib important openSUSE Backports SLE-15-SP7 Update This update for hamlib fixes the following issues: - Update to 4.7.2: * Fix IC-7600/IC-7610 clock commands * Icom: Add CWR to modes eligible for DSP filtering * Kenwood: New model Hamgeek uSGX * Various fixes for Skywatcher, DX-SR8, FT-710, FTX-1, IC-705, X6100 * rigctld: Fix send_raw stack out-of-bounds write and uninitialized memory CVE-2026-54634 (boo#1268628) * rigctld: Fix stack/heap overflow primitive in read_string_generic + auth bypass in rigctld + weak password handling (boo#1268629) - Update to 4.7.1: * Various compiler and portability fixes * Fix rig port timeout * Fix various FTX-1 meter, level and CTCSS table * Add power off capability to Flrig backend * Add SWR to supported 'get levels' for K3/K4 * Add get_split_vfo to TS-850 backend * New simplecat backend * Fix and generalize clock handling for Icom radios * Fix Yaesu attenuator levels and LVL_KEYSPD reinitialization * Add new rig model Harris PRC-138 * Various FT-710 fixes, eespecially handling SH format and RX bandwidth * Ensure FT-710 simulator rejects RF command * Fix low power calculation for K3/K3S * Fix FTX-1 SH bandwidth command in set/get_mode - Update to 4.7.0: * Revamp Kenwood voice memory handler - Fixes TS-890S & TS-990S * libusb is now detected using the pkg-config facility. * Functions rig_get_conf, rot_get_conf, amp_get_conf deprecated use *_get_conf2() instead * rig_set_trn and rig_get_trn deprecated. * Many fixes for SWIG binding generation and improved Python support and testing * Fix AGC for IC-R75, fix AGC for all Icom rigs * New Drake R8 backend * New AF6SA WRC rotator backend * New Yaesu FTX-1 model support (alpha) * Update QRPLabs QMX backend for max serial rate of 230400 bps * Updates to Icom IC-F8101 * New rig model Icom ID-52A/W Plus * Fix memory leaks in rigctld and rigctltcp * Fix Skywatcher backend for firmware that doesn't echo commands * Additional Yaesu FTX-1 capabilities * Add extended commands for the IC-7300MK2-- * Revert updating FLRig model name * Add manual pages for rigctltcp, rigtestlibusb, rigtestmcast, and rigtestmcastrx * Pause building rigfreqwalk as the code does not align with the required commandline parameters * Developer visible changes, code moves and refactoring - Update to 4.6.5: * Update Kenwood CW buffer max message size, fix one byte buffer overrun * Fix segmentation Faults - Update to 4.6.4: * Fix handling of unprintable characters affecting radios such as the TM-D710/TM-V71 * Fix memory leak in rigctld * Fix powerstat check for Icom R75 which rejects the command * Restore TS-590S/SG RIG_LEVEL_RFPOWER_METER * Fix rotctl \dump_caps output * Add CW sending capability to Flex SmartSDR * Handle spaces correctly for Fles SmartSDR - Update to 4.6.3: * JRC: Remove RIG_FUNC_FAGC from 535D as erroneous * Add RIG_FUNC_NB2 functionality to both 535D and 545 * * Restore IC-7300 spectrum data callback - regression in 4.6 * Add locking to rig_[gs]et_level() - fixes sending CW from tlf * Fix attempt to use memory returned by setlocale() after being freed * Language bindings configuration and build fixes * Various build system and compilation fixes * IC-705 filter selection bandwidth for FM and WFM * IC-705 COMP, VD, and ID meter calibration values * Fix ACLog thousands separator * Documentation updates, typo fixes, man page fixes * Drop redundant token lookups and make local functions static * Fix rigctl showing hamlib_verson when connecting to rigctld * Add rig CODAN 2110 - Update to 4.6.2: * Add missing levels for IC746/PRO RIG_LEVEL_RFPOWER_METER, RIG_LEVEL_RFPOWER_METER_WATTS,RIG_LEVEL_SWR,RIG_LEVEL_ALC * Fix IC905 for gpredict * Fix potential segfault on QMX * Fix pmr171 - update to 4.6.1: * Fix C++ builds failing on rig_list_foreach function * Fix IC9100 rigctld startup to end up on VFOA * Fix grig build by removing sys/socket.h -- apparently not needed * Add new QMX entry to fix incompability with QDX * Fix IC746/PROT to not use data byte * FLRig to add DATA-U DATA-L modes * Fix TS570 RIG_LEVEL_STRENGTH with cal table * Remove get_powerstat from IC785X -- not supported * Fix SDRConsole by removing lots of things it does not have - Update to version 4.6 (2024-12-24) * send_raw can now take hex digits as colon-separated -- e.g. send _raw icom xfe:xfe:x94:xe0:03:xfd * Add IC7760 * IC7300 Mode filter can now be set by # (i.e. 1,2,3) * Fixed AF6SA WRC rotor controller * Added Rhode&Schwarz XK852 * Added Xiegu X6200 * Added Commradio CTX-10 * Added Guoehe PMR-171 * Added csntechnoligies.net S.A.T Satellite rotor control * Added PSTRotator control * Added Flex SmartSDR slices A-H * Added Motorola Micom M2/M3 * Added SDR Radio SDRConsole -- TS-2000 is now hardware flow control so need separate entry * Added --set-conf=filter_usb, filter_usbd, and filter_cw to allow Icom rigs set mode to set filter number too * Added macros for applications to obtain pointers to Hamlib structures(issues #1445, #1420, #487). Internal conversion is still a WIP, but use of these macros will make the final cutover transparent to applications. * Added Guohe Q900 entry * Unify behavior of all rigctl split commands * Make the set_split_* commands modify the state of the specified split VFO -- the current or targeted VFO do not have any effect * Make the set_split_* commands enable split automatically if not enabled * Make the get_split_* commands return frequency of 0 Hz, mode NONE and filter of 0 Hz if split is not enabled * Allow all split commands to avoid VFO swapping if supported by the rig model * Improve Icom backend to set/get frequency, mode and filter without VFO swapping if supported by the rig model * Improve Yaesu newcat backend split handling * Expose "Targetable features" (RIG_TARGETABLE_*) in dump_caps output to allow clients to determine which commands can be executed without VFO swapping * Added RIG_FUNC_SYNC for FTDX101D/MP * Added Barrett 4100 * Added DL2MAN (tr)uSDX -- needs refinement * Added Thetis entry -- derived from FlexRadio/Apache PowerSDR * Added VOICE/CW memory capability to many rigs -- thanks to David Balharrie M0DGB/G8FKH * Add -# --skip_init option to rigctl to skip rig initialization -- useful for executing commands quickly * rig_caps is no longer constant -- this may break some 3rd party relying on the "const" declaration. * IC7610 now has IPP, DPP, and TX_INHIBIT functions set/get * Hamlib now starts a multicast server that sends out rig information. Does not receive commands yet. See README.multicast * rigctld has new -b/bind-all option to try all interfaces -- restores original behavior. This was done to fix duplicate rigctld instances on Windows * Yaesu rigs can now use send_morse to send keyer message 1-5 or a CW message up to 50 chars (which will use memory 1) * rig set level METER can now take SWR,COMP,ALC,IC/ID,DB,PO, VDD,TEMP arguments to set which meter to display * reg get level displays meter number=name now * Added parm BANDSELECT for Yaesu rigs 'p BANDSELECT' returns current band of VFOA 'P BANDSELECT BAND160M' example selects the 160M band 'P BANDSELECT ?' shows bands available for the rig * Added rig_cm108_get/set_bit to API and get/set_gpio to rigctl(d) for GPIO1,2,3,4 access on CM108 * Added BG2FX FX4/C/CR/L * Fixed IC7610 to use new 0x25 0x26 command added in latest firmware * Fix W command in rigctld to work properly -- can take terminating char or # of bytes to expect * Add rig_set_debug_filename so Python can redirect debug stream * Fix Yaesu LBL_NR to use proper values * Add IC-905 * Add Anytone D578UVIII -- should work on any D558 model and perhaps others too * Add saebrtrack rotor https://sites.google.com/site/marklhammond/saebrtrack * Add offset_vfoa and offset_vfob applying to rig_set_freq * Fix K4 to put it in K40 mode when requesting ID * Fixes for M2 Rotors * Add rigctlsync utility to synchronize frequency from a rig to SDR# (or others) * Add SDR# rig for use with SDR#'s gpredict plugin -- can only get/set freq * Add Apex Shared Loop rotator -- unidirectional only so far * Add client_version to rigctld so client can report it's version for future use/compatibility/alternatives * Add --set-conf=tuner_control_pathname=hamlib_tuner_control (default). If file exists then it will be called with 0/1 (Off/On) argument with 'U TUNER 0' or 'U TUNER 1". Default path is for current directory * Add MDS 4710/9710 rigs * Add FLIR PTU-D48, E46, D100, D300 rotors * Fix FTDX3000 rig split * Fix rigctld/rigctltcp information * Fix FT817 get/set_vfo hamlib-4.7.2-bp157.2.3.1.src.rpm hamlib-4.7.2-bp157.2.3.1.x86_64.rpm hamlib-devel-4.7.2-bp157.2.3.1.x86_64.rpm libhamlib++4-4.7.2-bp157.2.3.1.x86_64.rpm libhamlib4-4.7.2-bp157.2.3.1.x86_64.rpm lua-Hamliblua-4.7.2-bp157.2.3.1.x86_64.rpm perl-Hamlib-4.7.2-bp157.2.3.1.x86_64.rpm python3-Hamlib-4.7.2-bp157.2.3.1.x86_64.rpm tcl-Hamlib-4.7.2-bp157.2.3.1.x86_64.rpm hamlib-4.7.2-bp157.2.3.1.i586.rpm hamlib-devel-4.7.2-bp157.2.3.1.i586.rpm libhamlib++4-4.7.2-bp157.2.3.1.i586.rpm libhamlib4-4.7.2-bp157.2.3.1.i586.rpm lua-Hamliblua-4.7.2-bp157.2.3.1.i586.rpm perl-Hamlib-4.7.2-bp157.2.3.1.i586.rpm python3-Hamlib-4.7.2-bp157.2.3.1.i586.rpm tcl-Hamlib-4.7.2-bp157.2.3.1.i586.rpm hamlib-4.7.2-bp157.2.3.1.aarch64.rpm hamlib-devel-4.7.2-bp157.2.3.1.aarch64.rpm libhamlib++4-4.7.2-bp157.2.3.1.aarch64.rpm libhamlib4-4.7.2-bp157.2.3.1.aarch64.rpm lua-Hamliblua-4.7.2-bp157.2.3.1.aarch64.rpm perl-Hamlib-4.7.2-bp157.2.3.1.aarch64.rpm python3-Hamlib-4.7.2-bp157.2.3.1.aarch64.rpm tcl-Hamlib-4.7.2-bp157.2.3.1.aarch64.rpm hamlib-4.7.2-bp157.2.3.1.ppc64le.rpm hamlib-devel-4.7.2-bp157.2.3.1.ppc64le.rpm libhamlib++4-4.7.2-bp157.2.3.1.ppc64le.rpm libhamlib4-4.7.2-bp157.2.3.1.ppc64le.rpm lua-Hamliblua-4.7.2-bp157.2.3.1.ppc64le.rpm perl-Hamlib-4.7.2-bp157.2.3.1.ppc64le.rpm python3-Hamlib-4.7.2-bp157.2.3.1.ppc64le.rpm tcl-Hamlib-4.7.2-bp157.2.3.1.ppc64le.rpm hamlib-4.7.2-bp157.2.3.1.s390x.rpm hamlib-devel-4.7.2-bp157.2.3.1.s390x.rpm libhamlib++4-4.7.2-bp157.2.3.1.s390x.rpm libhamlib4-4.7.2-bp157.2.3.1.s390x.rpm lua-Hamliblua-4.7.2-bp157.2.3.1.s390x.rpm perl-Hamlib-4.7.2-bp157.2.3.1.s390x.rpm python3-Hamlib-4.7.2-bp157.2.3.1.s390x.rpm tcl-Hamlib-4.7.2-bp157.2.3.1.s390x.rpm openSUSE-2026-213 Security update for mbedtls-2 important openSUSE Backports SLE-15-SP7 Update This update for mbedtls-2 fixes the following issues: - Update to version 2.28.10 (2.28 LTS line), fixing: * CVE-2025-27809: the TLS client accepted certificates valid for arbitrary hostnames unless the application called mbedtls_ssl_set_hostname() (boo#1240051) * CVE-2025-27810: use of uninitialized stack memory when composing the TLS Finished message could lead to an authentication bypass such as a replay (boo#1240052) - Sync packaging with Factory: enable MBEDTLS_SSL_DTLS_SRTP and MBEDTLS_SSL_PROTO_DTLS and ship the everest headers and pkg-config files in the -devel subpackage libmbedcrypto7-2.28.10-bp157.2.3.1.x86_64.rpm libmbedtls14-2.28.10-bp157.2.3.1.x86_64.rpm libmbedx509-1-2.28.10-bp157.2.3.1.x86_64.rpm mbedtls-2-2.28.10-bp157.2.3.1.src.rpm mbedtls-2-devel-2.28.10-bp157.2.3.1.x86_64.rpm libmbedcrypto7-2.28.10-bp157.2.3.1.i586.rpm libmbedcrypto7-32bit-2.28.10-bp157.2.3.1.x86_64.rpm libmbedtls14-2.28.10-bp157.2.3.1.i586.rpm libmbedtls14-32bit-2.28.10-bp157.2.3.1.x86_64.rpm libmbedx509-1-2.28.10-bp157.2.3.1.i586.rpm libmbedx509-1-32bit-2.28.10-bp157.2.3.1.x86_64.rpm mbedtls-2-devel-2.28.10-bp157.2.3.1.i586.rpm libmbedcrypto7-2.28.10-bp157.2.3.1.aarch64.rpm libmbedcrypto7-64bit-2.28.10-bp157.2.3.1.aarch64_ilp32.rpm libmbedtls14-2.28.10-bp157.2.3.1.aarch64.rpm libmbedtls14-64bit-2.28.10-bp157.2.3.1.aarch64_ilp32.rpm libmbedx509-1-2.28.10-bp157.2.3.1.aarch64.rpm libmbedx509-1-64bit-2.28.10-bp157.2.3.1.aarch64_ilp32.rpm mbedtls-2-devel-2.28.10-bp157.2.3.1.aarch64.rpm libmbedcrypto7-2.28.10-bp157.2.3.1.ppc64le.rpm libmbedtls14-2.28.10-bp157.2.3.1.ppc64le.rpm libmbedx509-1-2.28.10-bp157.2.3.1.ppc64le.rpm mbedtls-2-devel-2.28.10-bp157.2.3.1.ppc64le.rpm libmbedcrypto7-2.28.10-bp157.2.3.1.s390x.rpm libmbedtls14-2.28.10-bp157.2.3.1.s390x.rpm libmbedx509-1-2.28.10-bp157.2.3.1.s390x.rpm mbedtls-2-devel-2.28.10-bp157.2.3.1.s390x.rpm openSUSE-2026-214 Security update for mbedtls important openSUSE Backports SLE-15-SP7 Update This update for mbedtls fixes the following issues: - Update to the 3.6 LTS line (3.6.6) to fix several security issues; this bumps the SONAMEs (libmbedtls20 -> libmbedtls21, libmbedcrypto15 -> libmbedcrypto16, libmbedx509-6 -> libmbedx509-7): * CVE-2025-49600: possible LMS signature forgery due to unchecked return values in mbedtls_lms_verify (boo#1245808) * CVE-2025-49601: out-of-bounds read in mbedtls_lms_import_public_key on truncated input (boo#1245809) * CVE-2025-52496: race condition in AESNI detection allowing AES key extraction or GCM forgery (boo#1245810) * CVE-2025-52497: one-byte heap buffer underflow in PEM parsing (boo#1245811) * CVE-2025-59438: observable timing discrepancy (padding oracle) in CBC-PKCS7 (boo#1252454) * CVE-2026-34874: NULL pointer dereference in X.509 distinguished-name parsing (boo#1261527) - Ship the pkg-config files in the -devel subpackage libeverest-3.6.6-bp157.2.3.1.x86_64.rpm libmbedcrypto16-3.6.6-bp157.2.3.1.x86_64.rpm libmbedtls21-3.6.6-bp157.2.3.1.x86_64.rpm libmbedx509-7-3.6.6-bp157.2.3.1.x86_64.rpm libp256m-3.6.6-bp157.2.3.1.x86_64.rpm mbedtls-3.6.6-bp157.2.3.1.src.rpm mbedtls-devel-3.6.6-bp157.2.3.1.x86_64.rpm libeverest-3.6.6-bp157.2.3.1.i586.rpm libeverest-32bit-3.6.6-bp157.2.3.1.x86_64.rpm libmbedcrypto16-3.6.6-bp157.2.3.1.i586.rpm libmbedcrypto16-32bit-3.6.6-bp157.2.3.1.x86_64.rpm libmbedtls21-3.6.6-bp157.2.3.1.i586.rpm libmbedtls21-32bit-3.6.6-bp157.2.3.1.x86_64.rpm libmbedx509-7-3.6.6-bp157.2.3.1.i586.rpm libmbedx509-7-32bit-3.6.6-bp157.2.3.1.x86_64.rpm libp256m-3.6.6-bp157.2.3.1.i586.rpm libp256m-32bit-3.6.6-bp157.2.3.1.x86_64.rpm mbedtls-devel-3.6.6-bp157.2.3.1.i586.rpm libeverest-3.6.6-bp157.2.3.1.aarch64.rpm libeverest-64bit-3.6.6-bp157.2.3.1.aarch64_ilp32.rpm libmbedcrypto16-3.6.6-bp157.2.3.1.aarch64.rpm libmbedcrypto16-64bit-3.6.6-bp157.2.3.1.aarch64_ilp32.rpm libmbedtls21-3.6.6-bp157.2.3.1.aarch64.rpm libmbedtls21-64bit-3.6.6-bp157.2.3.1.aarch64_ilp32.rpm libmbedx509-7-3.6.6-bp157.2.3.1.aarch64.rpm libmbedx509-7-64bit-3.6.6-bp157.2.3.1.aarch64_ilp32.rpm libp256m-3.6.6-bp157.2.3.1.aarch64.rpm libp256m-64bit-3.6.6-bp157.2.3.1.aarch64_ilp32.rpm mbedtls-devel-3.6.6-bp157.2.3.1.aarch64.rpm libeverest-3.6.6-bp157.2.3.1.ppc64le.rpm libmbedcrypto16-3.6.6-bp157.2.3.1.ppc64le.rpm libmbedtls21-3.6.6-bp157.2.3.1.ppc64le.rpm libmbedx509-7-3.6.6-bp157.2.3.1.ppc64le.rpm libp256m-3.6.6-bp157.2.3.1.ppc64le.rpm mbedtls-devel-3.6.6-bp157.2.3.1.ppc64le.rpm libeverest-3.6.6-bp157.2.3.1.s390x.rpm libmbedcrypto16-3.6.6-bp157.2.3.1.s390x.rpm libmbedtls21-3.6.6-bp157.2.3.1.s390x.rpm libmbedx509-7-3.6.6-bp157.2.3.1.s390x.rpm libp256m-3.6.6-bp157.2.3.1.s390x.rpm mbedtls-devel-3.6.6-bp157.2.3.1.s390x.rpm openSUSE-2026-220 Security update for openbabel moderate openSUSE Backports SLE-15-SP7 Update This update for openbabel fixes the following issues: - CVE-2026-2704: bounds-check the transform3d DescribeAsString() matrix scan to fix an out-of-bounds read on crafted CIF input (boo#1258501) libinchi0-2.4.1-bp157.2.3.1.x86_64.rpm libopenbabel5-2.4.1-bp157.2.3.1.x86_64.rpm openbabel-2.4.1-bp157.2.3.1.src.rpm openbabel-2.4.1-bp157.2.3.1.x86_64.rpm openbabel-devel-2.4.1-bp157.2.3.1.x86_64.rpm python3-openbabel-2.4.1-bp157.2.3.1.x86_64.rpm libinchi0-2.4.1-bp157.2.3.1.i586.rpm libinchi0-32bit-2.4.1-bp157.2.3.1.x86_64.rpm libopenbabel5-2.4.1-bp157.2.3.1.i586.rpm libopenbabel5-32bit-2.4.1-bp157.2.3.1.x86_64.rpm openbabel-2.4.1-bp157.2.3.1.i586.rpm openbabel-devel-2.4.1-bp157.2.3.1.i586.rpm python3-openbabel-2.4.1-bp157.2.3.1.i586.rpm libinchi0-2.4.1-bp157.2.3.1.aarch64.rpm libinchi0-64bit-2.4.1-bp157.2.3.1.aarch64_ilp32.rpm libopenbabel5-2.4.1-bp157.2.3.1.aarch64.rpm libopenbabel5-64bit-2.4.1-bp157.2.3.1.aarch64_ilp32.rpm openbabel-2.4.1-bp157.2.3.1.aarch64.rpm openbabel-devel-2.4.1-bp157.2.3.1.aarch64.rpm python3-openbabel-2.4.1-bp157.2.3.1.aarch64.rpm libinchi0-2.4.1-bp157.2.3.1.ppc64le.rpm libopenbabel5-2.4.1-bp157.2.3.1.ppc64le.rpm openbabel-2.4.1-bp157.2.3.1.ppc64le.rpm openbabel-devel-2.4.1-bp157.2.3.1.ppc64le.rpm python3-openbabel-2.4.1-bp157.2.3.1.ppc64le.rpm libinchi0-2.4.1-bp157.2.3.1.s390x.rpm libopenbabel5-2.4.1-bp157.2.3.1.s390x.rpm openbabel-2.4.1-bp157.2.3.1.s390x.rpm openbabel-devel-2.4.1-bp157.2.3.1.s390x.rpm python3-openbabel-2.4.1-bp157.2.3.1.s390x.rpm openSUSE-2026-216 Security update for ofono important openSUSE Backports SLE-15-SP7 Update This update for ofono fixes the following issues: - CVE-2024-7537: out-of-bounds read when processing SMS message lists (boo#1228903). - CVE-2024-7538: stack-based buffer overflow when parsing AT command responses (boo#1228904). - CVE-2024-7539: stack-based buffer overflow when parsing AT+CUSD responses (boo#1228905). - CVE-2024-7540: information disclosure when parsing AT+CMGL responses (boo#1228906). - CVE-2024-7541: information disclosure when parsing AT+CMT responses (boo#1228907). - CVE-2024-7542: information disclosure when parsing AT+CMGR responses (boo#1228908). - CVE-2024-7544: heap-based buffer overflow when parsing STK command PDUs (boo#1228913). - CVE-2024-7546: heap-based buffer overflow when parsing STK command PDUs (boo#1228916). - CVE-2024-7547: stack-based buffer overflow when parsing SMS PDUs (boo#1228917). ofono-2.19-bp157.2.3.1.src.rpm ofono-2.19-bp157.2.3.1.x86_64.rpm ofono-devel-2.19-bp157.2.3.1.x86_64.rpm ofono-tests-2.19-bp157.2.3.1.x86_64.rpm ofono-2.19-bp157.2.3.1.i586.rpm ofono-devel-2.19-bp157.2.3.1.i586.rpm ofono-tests-2.19-bp157.2.3.1.i586.rpm ofono-2.19-bp157.2.3.1.aarch64.rpm ofono-devel-2.19-bp157.2.3.1.aarch64.rpm ofono-tests-2.19-bp157.2.3.1.aarch64.rpm ofono-2.19-bp157.2.3.1.ppc64le.rpm ofono-devel-2.19-bp157.2.3.1.ppc64le.rpm ofono-tests-2.19-bp157.2.3.1.ppc64le.rpm ofono-2.19-bp157.2.3.1.s390x.rpm ofono-devel-2.19-bp157.2.3.1.s390x.rpm ofono-tests-2.19-bp157.2.3.1.s390x.rpm openSUSE-2026-219 Security update for trivy important openSUSE Backports SLE-15-SP7 Update This update for trivy fixes the following issues: - CVE-2026-50195: containerd: fails to validate the image references specified within a checkpoint image's configuration (boo#1268399). - CVE-2026-53488: containerd: CRI plugin propagates labels from an image config to a container without validation (boo#1268400). - CVE-2026-53492: containerd: improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration (boo#1268403). - CVE-2026-53489: containerd: CRI plugin restores container.log from a checkpoint image without validating a symlinked path (boo#1268404). - CVE-2026-47262: trivy: github.com/containerd/containerd/v2/pkg/oci: Denial of Service (DoS) condition via a maliciously crafted image (boo#1268440). - CVE-2026-44740: trivy: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (boo#1267268). - CVE-2026-46680: trivy: github.com/containerd/containerd/v2/pkg/oci: containerd user ID handling bypass allows runAsNonRoot evasion (boo#1268356). - CVE-2026-39821: trivy: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (boo#1266495). - CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: trivy: golang.org/x/net/html: multiple issues when parsing HTML files (boo#1267047). - CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833, CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598, CVE-2026-46595, CVE-2026-39835: trivy: golang.org/x/crypto/ssh: multiple issues (boo#1266075). - CVE-2026-41506: trivy: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (boo#1264873). - CVE-2026-33814: trivy: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (boo#1265648). trivy-0.71.2-bp157.2.12.1.src.rpm trivy-0.71.2-bp157.2.12.1.x86_64.rpm trivy-0.71.2-bp157.2.12.1.i586.rpm trivy-0.71.2-bp157.2.12.1.aarch64.rpm trivy-0.71.2-bp157.2.12.1.ppc64le.rpm trivy-0.71.2-bp157.2.12.1.s390x.rpm openSUSE-2026-223 Security update for assimp important openSUSE Backports SLE-15-SP7 Update This update for assimp fixes the following issues: - CVE-2026-10232: heap use-after-free in aiNode::~aiNode due to invalid node tree when processing malformed ASE files (boo#1267037) assimp-5.3.1-bp157.5.3.1.src.rpm assimp-devel-5.3.1-bp157.5.3.1.x86_64.rpm libassimp5-5.3.1-bp157.5.3.1.x86_64.rpm assimp-devel-5.3.1-bp157.5.3.1.aarch64.rpm libassimp5-5.3.1-bp157.5.3.1.aarch64.rpm assimp-devel-5.3.1-bp157.5.3.1.ppc64le.rpm libassimp5-5.3.1-bp157.5.3.1.ppc64le.rpm assimp-devel-5.3.1-bp157.5.3.1.s390x.rpm libassimp5-5.3.1-bp157.5.3.1.s390x.rpm openSUSE-2026-221 Security update for xtrabackup moderate openSUSE Backports SLE-15-SP7 Update This update for xtrabackup fixes the following issues: - CVE-2025-5918: embedded libarchive: Reading past EOF may be triggered for piped file streams (boo#1244285) xtrabackup-2.4.26-bp157.2.6.1.src.rpm xtrabackup-2.4.26-bp157.2.6.1.x86_64.rpm xtrabackup-test-2.4.26-bp157.2.6.1.x86_64.rpm xtrabackup-2.4.26-bp157.2.6.1.i586.rpm xtrabackup-test-2.4.26-bp157.2.6.1.i586.rpm xtrabackup-2.4.26-bp157.2.6.1.aarch64.rpm xtrabackup-test-2.4.26-bp157.2.6.1.aarch64.rpm xtrabackup-2.4.26-bp157.2.6.1.ppc64le.rpm xtrabackup-test-2.4.26-bp157.2.6.1.ppc64le.rpm xtrabackup-2.4.26-bp157.2.6.1.s390x.rpm xtrabackup-test-2.4.26-bp157.2.6.1.s390x.rpm openSUSE-2026-222 - Chromium 149.0.7827.200 (boo#129061): low openSUSE Backports SLE-15-SP7 Update - Chromium 149.0.7827.200 (boo#129061): * CVE-2026-13281: Integer overflow in Mojo * CVE-2026-13282: Use after free in Payments * CVE-2026-13283: Use after free in AdFilter chromedriver-149.0.7827.200-bp157.2.178.1.x86_64.rpm chromium-149.0.7827.200-bp157.2.178.1.nosrc.rpm chromium-149.0.7827.200-bp157.2.178.1.x86_64.rpm chromedriver-149.0.7827.200-bp157.2.178.1.aarch64.rpm chromium-149.0.7827.200-bp157.2.178.1.aarch64.rpm chromedriver-149.0.7827.200-bp157.2.178.1.ppc64le.rpm chromium-149.0.7827.200-bp157.2.178.1.ppc64le.rpm openSUSE-2026-234 Recommended update for kanidm moderate openSUSE Backports SLE-15-SP7 Update This update for kanidm fixes the following issues: - Update to version 1.10.4~git0.97b1edbc4: * Release 1.10.4 * Clippy * Update ldap3_lber to 0.8.0 * Avoid LSE instructions in arm64 Linux builds (#4372) * Release 1.10.3 * Resolve incorrect login in commited flag * Prevent migration double-deletes kanidm-1.10.4~git0.97b1edbc4-bp157.2.35.1.src.rpm kanidm-1.10.4~git0.97b1edbc4-bp157.2.35.1.x86_64.rpm kanidm-clients-1.10.4~git0.97b1edbc4-bp157.2.35.1.x86_64.rpm kanidm-docs-1.10.4~git0.97b1edbc4-bp157.2.35.1.x86_64.rpm kanidm-server-1.10.4~git0.97b1edbc4-bp157.2.35.1.x86_64.rpm kanidm-unixd-clients-1.10.4~git0.97b1edbc4-bp157.2.35.1.x86_64.rpm kanidm-1.10.4~git0.97b1edbc4-bp157.2.35.1.aarch64.rpm kanidm-clients-1.10.4~git0.97b1edbc4-bp157.2.35.1.aarch64.rpm kanidm-docs-1.10.4~git0.97b1edbc4-bp157.2.35.1.aarch64.rpm kanidm-server-1.10.4~git0.97b1edbc4-bp157.2.35.1.aarch64.rpm kanidm-unixd-clients-1.10.4~git0.97b1edbc4-bp157.2.35.1.aarch64.rpm openSUSE-2026-227 Recommended update for python-jupyterlab moderate openSUSE Backports SLE-15-SP7 Update This update for python-jupyterlab fixes the following issues: - GHSA-vmhf-c436-hxj4: stored XSS in extension manager through package metadata unsanitized URI protocol (boo#1269072) jupyter-jupyterlab-2.2.10-bp157.3.6.1.noarch.rpm python-jupyterlab-2.2.10-bp157.3.6.1.src.rpm python3-jupyterlab-2.2.10-bp157.3.6.1.noarch.rpm openSUSE-2026-228 Security update for nilfs-utils moderate openSUSE Backports SLE-15-SP7 Update This update for nilfs-utils fixes the following issues: - CVE-2026-55392: Fixed undefined behavior in nilfs_sb_is_valid() (bsc#1268553) libnilfs0-2.2.9-bp157.2.3.1.x86_64.rpm libnilfscleaner0-2.2.9-bp157.2.3.1.x86_64.rpm libnilfsgc0-2.2.9-bp157.2.3.1.x86_64.rpm nilfs-utils-2.2.9-bp157.2.3.1.src.rpm nilfs-utils-2.2.9-bp157.2.3.1.x86_64.rpm nilfs-utils-devel-2.2.9-bp157.2.3.1.x86_64.rpm libnilfs0-2.2.9-bp157.2.3.1.i586.rpm libnilfscleaner0-2.2.9-bp157.2.3.1.i586.rpm libnilfsgc0-2.2.9-bp157.2.3.1.i586.rpm nilfs-utils-2.2.9-bp157.2.3.1.i586.rpm nilfs-utils-devel-2.2.9-bp157.2.3.1.i586.rpm libnilfs0-2.2.9-bp157.2.3.1.aarch64.rpm libnilfscleaner0-2.2.9-bp157.2.3.1.aarch64.rpm libnilfsgc0-2.2.9-bp157.2.3.1.aarch64.rpm nilfs-utils-2.2.9-bp157.2.3.1.aarch64.rpm nilfs-utils-devel-2.2.9-bp157.2.3.1.aarch64.rpm libnilfs0-2.2.9-bp157.2.3.1.ppc64le.rpm libnilfscleaner0-2.2.9-bp157.2.3.1.ppc64le.rpm libnilfsgc0-2.2.9-bp157.2.3.1.ppc64le.rpm nilfs-utils-2.2.9-bp157.2.3.1.ppc64le.rpm nilfs-utils-devel-2.2.9-bp157.2.3.1.ppc64le.rpm libnilfs0-2.2.9-bp157.2.3.1.s390x.rpm libnilfscleaner0-2.2.9-bp157.2.3.1.s390x.rpm libnilfsgc0-2.2.9-bp157.2.3.1.s390x.rpm nilfs-utils-2.2.9-bp157.2.3.1.s390x.rpm nilfs-utils-devel-2.2.9-bp157.2.3.1.s390x.rpm openSUSE-2026-235 Security update for openQA, os-autoinst moderate openSUSE Backports SLE-15-SP7 Update This update for openQA, os-autoinst fixes the following issues: Changes in openQA: - Update to version 5.1782486535.1bf71ec4: * fix(details view): Align video link the same as the bugref actions * fix: Correct call to console.error - Update to version 5.1782295118.57cb8aa0: * chore(deps): Dependency cron 2026-06-24 * feat: Don't rewrite history for test result tabs * chore(deps): Dependency cron 2026-06-23 - Update to version 5.1782133597.39cd80e0: * refactor: Calculate module category headings in frontend * chore(deps): Dependency cron 2026-06-20 * test: Make parallel execution of the fullstack test more reliable * ci: disable Mergify interactive queue controls in PR comments * feat(worker): enable direct execution with podman * fix(worker): add --init and --rm flags for containerized engine * feat(worker): support containerized os-autoinst worker engine * test: refactor archive download tests for maintainability * feat: implement category-specific ZIP downloads for jobs * chore(deps): Dependency cron 2026-06-19 - Update to version 5.1781832185.5ddf5343: * fix: fix user namespace mapping errors in podman * chore(mergify): Update the number of required checks * fix: use webui cache for download all archives * chore(deps): Dependency cron 2026-06-18 * refactor: Extract changing prio and computing sign * fix: Fix typos in `t/api/04-jobs.t` and `t/config.t` * feat: Throttle jobs not using Git-URL as `CASEDIR` * ci: Change repo paths for SLE-15-SP7 in consistency with os-autoinst * fix: Avoid unresolvable openQA-devel-test package for SLE-SP7 * feat: improve detection of unexpanded variables in clone-job * feat: support expanding variables in openqa-clone-job - Update to version 5.1781712973.4c20e5c1: * test: make search API tests robust * fix: resolve openqa-llm-server crash on startup * chore(deps): Dependency cron 2026-06-17 * feat: Improve job archive generation efficiency and UI * feat: Efficiently serve job archives via web server redirect * feat: Add 'Download All' ZIP archive button to job downloads page - Update to version 5.1781621316.6d025b35: * refactor: set clean monikers for Mojo services * feat: use encrypted session cookies * chore(deps): Dependency cron 2026-06-13 * docs: Mention how to enable UEFI and recently added variables * docs: fix broken badge syntax in README.md * feat(apparmor): add current worker profile as generated by aa-logprof * feat(apparmor): add current worker requirements in /proc and /sys * chore(deps): Dependency cron 2026-06-12 * git subrepo pull (merge) external/os-autoinst-common * docs: Fix wrapping in "Job Priority Throttling" section * fix(apparmor): Allow worker profile to use virt-fw-vars * fix(livelog): Prevent timeouts due to nginx buffering * fix: avoid initial delay when replying from livestream * chore(deps): Dependency cron 2026-06-10 * chore(deps): Dependency cron 2026-06-09 * test: Skip earlier in tests_dependencies.t * fix: Use reload-or-restart for openQA auto restart worker slots * fix: Update codecov orb to latest version 6.0.0 fixing PGP error * chore(deps): Dependency cron 2026-06-06 * fix: Support invent.kde.org and 'work_items' in bug URL handling * ci(mergify): prevent annoying conflict messages * docs: Rewrite medium version globbing in more user-facing style * docs: Mention globbing in "Spawning multiple jobs …" and "Medium types" * feat(scheduling): Allow globbing in version specifications * fix: Set correct settings for scheduling example test * refactor: Fix comment regarding `test_preset` INI section - Update to version 5.1780561853.63760953: * fix(rpm): eliminate systemd on-disk warnings during worker upgrade * chore(deps): Dependency cron 2026-06-04 * ci: Run OBS scm checks only for master branch * fix(systemd): activate inactive workers and reload active ones safely * chore(deps): Dependency cron 2026-06-03 * test(full-stack): remove redundant ISO size check to be flexible - Update to version 5.1780410522.ad58d974: * feat(tests): enable parallel-safe fullstack and developer mode tests * fix: ignore transient 'database is locked' errors in cache service * git subrepo pull (merge) --force external/os-autoinst-common * Revert "fix: avoid permission denied on cgroup creation for v2" * feat: add run-test-env target to start all local services * fix: add functional API keys for local test environment * fix: use absolute paths for local test environment * feat: Improve CLI retry error feedback with detailed messages * fix: avoid permission denied on cgroup creation for v2 * ci: Auto-import keys to avoid interactive prompt for devel_openQA * docs: require atomic commits in agent guidelines * fix: include file paths in worker logging errors * chore(AGENTS.md): add rules for ensuring valid commits * fix: only report job limit in UI when globally reached * docs: Clarify wording in "Spawning multiple jobs …" * docs: Fix wrapping in "Medium Types" section * docs: Fix wrapping and use of blank lines in "Spawning multiple jobs …" - Update to version 5.1780322162.c1836389: * refactor: Use more readable regex in `process-docs` * refactor: Turn `process-docs` into proper style-checked Perl script * feat: Add Makefile target to tidy Shell code * docs: Fix links in documentation generated via `generate-docs` * fix(openqa-clone-job): Allow empty API key/secret for auth.method=None * fix(spec): Supplement bash-completion subpackage against bash-completion * docs: Fix broken list under "Further systemd …" and wrap consistently * docs: Fix example config for `git_auto_commit` * docs: Wrap lines consistently under "Terms and variables …" * docs: Fix wrapping in "Triggering tests …" section and below * docs: Remove Git conflict markers that were missed by b51c609679 * feat: watch worker auto-restart systemd drop-ins for reloads - Update to version 5.1779808735.8c9bd805: * docs: Fix link to "Conducting tests" section * refactor: Use Feature::Compat::Try consistently * ci: Build packages for SLE 15 SP7 instead of SP6 which reached EOL * ci: Remove package builds for Leap 15.6 as it reached EOL * fix: make TESTS selection work again (regression from cd76f31f3) * feat: add Nginx proxy template for local LLM load balancing * feat: add openQA-llm-server sub-package for local LLM support * feat(pyproject): Streamline summary with spec file * fix: Fix wording in summary of rpm package * feat: Apply formatting of Python code also to documentation snippets * feat: Change `openqa-label-all` to satisfy ruff checks * test: Add target to run format Python code * test: Add targets to run static Python checks * feat: Add `pyproject.toml` as in other repositories * feat(needle-editor): Validate that there is at least one match area * docs: Reference "Asset handling" section directly * fix: Fix some wrong uses of "check out" * docs: Fix broken references in further places * docs: Fix wrapping in section about importing production data * docs: Fix broken references in several documentation files * test(isos post): Assert behavior when specifying parameters twice * refactor(isos post): Use `$validation` consistently * fix(spec): add RPM Group tag to all subpackages * style: Include core perlcritic rules as well * fix: resolve 'Too many open files' by clearing AssetPack FD cache * fix: work around DBD::Pg bug regarding INSERT ON CONFLICT row count * refactor: Remove superfluous Test::MockModule instance * refactor: Use a hash instead of string eval * refactor: Use Syntax::Keyword::Try instead of eval * style: Enforce perlcritic policies regarding eval * fix: allow worker to start without API keys * refactor: Split scheduler tests to avoid failing complexity check * feat: Distinguish parallel jobs in info when cluster cannot be assigned * fix: Reword misleading message about "incomplete parallel cluster" * fix(docs): remove zero-length draw.io marker file * fix(branding): add placeholder content to empty sponsorbox template * test: fix "Too many open files" in t/api/03-auth.t * fix: fix security vulnerability in Auth::check and minor typo * test: fix hmac_sha1_sum calculation in auth tests * docs: fix typo in Auth controller * refactor: use DEFAULT_ADMIN constant for admin username * feat: switch bootstrap to 'None' authentication provider * fix(packaging): avoid repeating package name in Summary * fix(packaging): replace obsolete packageand() with boolean Supplements * fix(build): install openqa-cli.yaml without executable bit * style: Enforce perlcritic policy Community::EmptyReturn * ci: Remove `perl-TAP-Harness-JUnit` from devel container again * ci: Use distinct container introduced by f33029623 * chore: Use `https://download.opensuse.org` consistently * feat(worker): Pass reason to web UI when skipping job due to self-check * feat(worker): Prevent skipping directly chained jobs due to self-checks * fix(build): add executable bit to dbicdh migration scripts * refactor: Remove @EXPORT and add %EXPORT_TAGS * refactor: Move @EXPORT to @EXPORT_OK * refactor: Remove unused var @EXPORT * style: Add no critic * style: Enforce perlcritic policy ProhibitAutomaticExportation * refactor: Remove non-existing functions from export list * feat: Require Perl::Critic >= 1.156.0 * style: Enforce perlcritic policy Subroutines::ProhibitManyArgs * feat: support configurable secrets hiding in UI and API * chore(deps): Dependency cron 2026-05-16 * chore(deps): Dependency cron 2026-05-15 * chore(deps): Dependency cron 2026-05-14 * refactor(create_admin): switch to Getopt::Long::Descriptive * style: Enforce perlcritic policy BuiltinFunctions::ProhibitUniversalIsa * test: Prevent unhandled output after b278ab6dfd3 * style: Enforce perlcritic policy regarding open() * ci: Add distinct container image for CI * style: Enforce perlcritic policy Subroutines::ProhibitReturnSort * style: Enforce perlcritic policy ProhibitReadlineInForLoop * style: Enforce perlcritic policy Community::POSIXImports * style: Enforce perlcritic policy ClassHierarchies::ProhibitOneArgBless * chore(deps): Dependency cron 2026-05-13 * fix: parse URL-derived settings for cloned jobs * style: Enforce perlcritic policy TestingAndDebugging::ProhibitNoWarnings * ci(dependabot): apply deps update cooldown to prevent PR fatigue * refactor: Improve global variables in SeleniumTest * style: Enforce perlcritic policy Variables::ProhibitPackageVars * style: Enforce perlcritic policy Community::ConditionalImplicitReturn * test: Add `python3-ruff` for static checks of Python scripts * style: Enforce perlcritic policy CodeLayout::ProhibitHardTabs * test(worker-engine): Cover all lines of `set_engine_exec` * chore(ci): Avoid running into authenticity error * chore(ci): Allow running caching jobs in parallel * chore(ci): Log installed rpm packages after removing explicit tracking * chore(ci): Simplify CI runtime using devel container image * chore(Makefile): Avoid depending on the `which` utility * fix(apparmor): allow /usr/bin/getopt needed for os-autoinst-scripts * style: Enforce perlcritic policy ProhibitConditionalUseStatements * style: Enforce perlcritic policy Subroutines::ProhibitExcessComplexity * style: enforce perlcritic policy ProhibitCascadingIfElse * perf(cleanup): replace N+1 per-group queries with single batch query * style: Enforce perlcritic ProhibitQuotesAsQuotelikeOperatorDelimiters * style: Enforce perlcritic policy RequirePackageMatchesPodName * style: Enforce perlcritic policy BuiltinFunctions::ProhibitUselessTopic * feat(api): filter job statistics by group globs * test: stabilize test_containers_compose * test: use IfNotPresent pull policy for postgres init container * fix(tools): handle pandoc TeX math misinterpretation in API docs * fix(docs): link to the correct cleanup section * style: Enforce perlcritic policy Miscellanea::ProhibitUselessNoCritic * style: Rewrite some for loops in foreach style * style: Enforce erlcritic policy Modules::ProhibitExcessMainComplexity * feat(cli): generate shell completions from openqa-cli.yaml * fix(test overview): Bring query for "Aborted" in-line with accounting * chore(deps): Dependency cron 2026-05-11 * ci: fix "conflicts with file" problems * fix: update fast-uri to address security vulnerabilities (boo#1264376) * docs: Fix wrapping in users guide after Markdown conversion * feat: add scheduling skip reasons to the webUI - Update to version 5.1778257070.d9915684: * docs: show document levels in generated TOC * feat(search): Add link to job in job modules search * feat(test overview): Make "Job result/state" in filter form clickable * test(test overview): Test filtering for "None" * fix(test overview): Bring query for "None" in-line with accounting * feat(test overview): Improve accounting for certain states * feat(test overview): Add distinct counter/button for canceled jobs - Update to version 5.1778239460.4b750ff3: * feat(search): Add job id to search results response - Update to version 5.1778134320.e889287c: * test: simplify postgres healthcheck in docker-compose * fix: correctly handle MOJO_CLIENT_DEBUG in Helm chart * test: add yamale and yamllint to test_helm_chart dependencies * test: fail early in test_helm_chart if dependencies are missing * test: use isolated environment for helm chart tests * test: serialize helm chart test execution * refactor: Remove superfluous line in script usage * style: Enforce perlcritic policy Subroutines::RequireArgUnpacking * fix: ktap: ignore selftest status comments * fix(apparmor): allow write to /dev/tty necessary for Leap 16 * chore(spec): Exclude devel sub package from builds for Leap < 16 * ci: Ensure all required dependencies are part of the devel container * fix(apparmor): allow further paths for 16.x - Update to version 5.1777995277.b985bea2: * style: Enforce perlcritic policy Variables::ProtectPrivateVars * fix(docs): Fix links to documentation after converting to Markdown * docs: fix broken references to former .asciidoc files * docs: Fix wrapping list of directories after Markdown migration * docs: Improve documentation of `git_auto_clone` feature * docs: Make remark about worker cache service clearer using a comma * docs: Fix casing of Git in the section about setting up Git support * feat: Include log in IPA results * feat: enhance dynamic job limit with fast ramp-up - Update to version 5.1777888278.38a3a85c: * style: Enforce perlcritic policy ProhibitUselessTopic * style: Enforce perlcritic policy BuiltinFunctions::RequireBlockGrep - Update to version 5.1777617029.fd9e1e69: * style: Enforce perlcritic policy ProhibitSingleCharAlternation * fix(apparmor): Add jsonnet to worker profile * style: Enforce perlcritic policy CodeLayout::ProhibitQuotedWordLists * style: Enforce perlcritic policy RequireNumberSeparators * build(deps-dev): bump eslint from 10.1.0 to 10.2.1 * style: Enforce perlcritic policy Variables::ProhibitUnusedVariables * feat: Ensure temporary directory exists when caching assets * fix(docs): fix mobile view rendering by ensuring CSS override * chore(lint): extend stylelint to cover documentation CSS * refactor: break down create_from_settings into smaller functions * feat: automatically add configurable worker classes to jobs - Update to version 5.1777474261.55e5cd5e: * build(deps): bump postcss from 8.5.8 to 8.5.12 * fix(apparmor): adjust the /usr/bin/ssh child profile for 16.x * fix: Fix rendering bugrefs as links in lists and other structures * feat: use full job group name for priority check by default * chore(AGENTS.md): refine coverage requirements * fix(apparmor): allow worker to execute "df" * feat: Restore styling and TOC for API documentation * feat: add "badge" option to openqa-clone-job for markdown output * fix(AMQP): Avoid keeping unused AMQP connections around * test: Use more compact syntax in AMQP tests * test: Use signatures in AMQP tests * fix(apparmor): allow access to all Python 3 versions * style: Add tools/ to perlcritic check * fix(Plugin::IssueReporter): prevent erroneous "mailto" links * perf: tweak jobs evaluated on job groups based on recent improvement * fix: try to resolve package conflicts with zypper * docs: Keep filenames in links for GitHub but strip them in build * docs: fix typo in WritingTests * fix: dynamically check pandoc support in generate-documentation * fix: dynamically check pandoc support in generate-docs * fix: add python3-weasyprint for build-docs * feat(ui): Simplify warning about full storage * feat(scheduler): Consider all relevant paths in storage space check * docs: Polish rendering and fix conversion artifacts * style: Enforce perlcritic policy RequireQuotedHeredocTerminator * refactor: Reduce complexity in openqa-load-templates * style: Enable strictures before first line of code * style: Add script/ to perlcritic check * docs: Mimic Asciidoctor style with custom CSS and Pandoc template * docs: Fix broken anchors and rendering issues in generate-documentation * docs: Post-conversion cleanup of artifacts and broken links * docs: Switch PDF engine to weasyprint in generate-documentation * docs: Improve glossary highlighting and remove redundant divs * style: Remove trailing whitespace from Markdown files * docs: Enable section numbering and clean up index.md * feat: Convert documentation from AsciiDoc to Markdown * git subrepo pull (merge) --force external/os-autoinst-common * fix(t/33-developer_mode): make needle renaming robust * fix(t/33-developer_mode): bypass storage space check * build(deps-dev): bump prettier from 3.8.1 to 3.8.3 * build(deps): bump delaunator from 5.0.1 to 5.1.0 * fix(apparmor): adapt snd2png path to os-autoinst#2881 * feat: Throttle consistently failing test scenarios * test: fix sporadic failure in scheduling-and-worker-scalability * perf: optimize compute_build_results with DB-level aggregation * feat: disable dashboard inclusion checkbox if ignored by config * fix: remove redundant title attribute in group property editor * refactor: Avoid duplicate access like `$details->{$nickname_field}` * feat: Make all assignments configurable on login via OAuth2 configurable * feat: Make assignment of fullname on login via OAuth2 configurable * fix: Improve auth logic to support API fallback and fix CSRF handling - Update to version 5.1776705613.1c2c8716: * ci: ensure full statement coverage - Update to version 5.1776681647.73d96c66: * feat(Git): Use nickname as a fallback for fullname * perf: Select only needed columns in _previous_scenario_jobs * perf(IssueReporter): Cache regression_links * feat: ignore "Investigations" job group on dashboard by default * fix: prevent "Not enough storage" with consistent setting * refactor: Improve code for `None` auth method * refactor: Avoid duplicating code for OAuth2 and OpenID auth * test: Improve OAuth2 tests * docs: Explain the design of the OAuth2 plugin * feat: Return to previous page after login via OAuth2 * fix: ensure priority increases for job groups with NULL description * feat(Makefile): add convenience targets for all services * feat: Handle deleted/altered system user more gracefully * fix(worker): handle missing D-Bus socket gracefully * test: Consider everything we track coverage of as covered * test: Cover YAML validation script * feat(cli): support lower-case test argument passing * feat(mcp): promote endpoint from /experimental/mcp to /mcp - Update to version 5.1776202410.3448a30a: * feat(worker): Resolve share directory correctly for relative basedir * fix: SQL ON CONFLICT constraints for Assets registration * feat: allow ignoring job groups on dashboard evaluation - Update to version 5.1776103434.91af0a8b: * feat: expand parallel test execution in t/testrules.yml * feat: set no expiration for "None" auth API keys * fix: Avoid gap between caret and preview container * refactor(upload): Move chunk size constant to constants module * refactor(upload): Define chunk size only once * test: Check for unhandled output by default * git subrepo pull (merge) external/os-autoinst-common * perf(upload): Speed up asset uploads * feat: enable videos for all jobs again * ci: remove redundant perl-critic GHA covered by circleCI * ci: separate compile tests into independent job * test: Move author tests to xt/ and separate compile checks * fix: use Test::Warnings in 02-perlcritic * chore(deps): Remove obsolete Freenode::StrictWarnings policy * chore(ci): bump checkout v4->v6 * feat: implement "None" authentication provider * feat: Prevent job assignments when running out of space by default * fix(results_min_free_storage_space_percentage): Allow disabling with `0` * fix(results_min_free_storage_space_percentage): Add to `Setup.pm` * feat: make compute_build_results faster by passing the query for jobs * feat: optimize comment_data_for_jobs when passed a result set - Update to version 5.1775828534.8622a781: * refactor: Rename `results_storage_above_threshold` * feat: Log a meaningful error message if `check_df` fails * feat: Add separate setting for scheduler storage space check * fix: address further XSS in admin_needle.js response loop * fix: address XSS vulnerability in admin_needle.js handleSingleError * fix: address further XSS vulnerabilities in admintable.js catch blocks * fix: address XSS vulnerability in admintable.js catch block * fix: address XSS vulnerability in ws_console.js sendAndLogCommand * fix: address XSS vulnerability in ws_console.js logLine * build(deps): bump lodash from 4.17.23 to 4.18.1 * fix: Calculate upload speed correctly by including milliseconds * docs: Clarify description of `force_result_regex` * test: Cover remaining lines of `upgradedb` * test: Fix missing assignment in upgradedb test * refactor: Avoid duplicating user handling in database scripts * fix: Apply force result label correctly if `force_result_regex` is empty * test: Verify applying force_result label from carried over comments * fix: Reference schema files from the installed package for helm lint * feat: limit job results on group overview and dashboard * build(deps-dev): bump eslint-plugin-prettier from 5.5.4 to 5.5.5 - Update to version 5.1775643384.e9cf2643: * fix: Move Workers constants to Constants.pm * refactor: Remove $VERSION variables from modules * fix(apparmor): let ipmitool read enterprise-numbers * fix(apparmor): add rules for xterm-console * fix(apparmor): allow to start icewm * fix(apparmor): remove unnecessary rules from x3270 profile * test: Cover initdb * fix(apparmor): allow x3270 to write trace files * fix: Let worker init fail for missing working dir * ci(mergify): prevent any unused merge queue checks * test(43-scheduling-and-worker-scalability): automate job count scenarios * feat: Show possible candidates for working directory in error message * test: Cover `t/44-scripts-create_admin.t` * test: refactor dynamic limit tests to use table-driven approach * fix(create_admin): Fix order of arguments in help text * refactor(js): fix lint errors in needlediff.js * fix(js): disable no-unassigned-vars in ESLint config * build(deps-dev): upgrade ESLint to 10.1.0 and add missing peer deps * build(deps-dev): bump eslint from 9.39.2 to 10.0.0 * fix(deps): bump brace-expansion from 5.0.3 to 5.0.4 * fix: avoid redundant commas in job group summary list * fix: avoid redundant commas in job group summary list * feat: show priority calculation tooltip on job details page * feat: allow custom badge labels via query parameter * feat: refine priority adjustment messages for clarity * feat: visualize priority calculation in web UI * feat: increase priority based on job group properties * build(deps-dev): bump prettier from 3.6.2 to 3.8.1 * build(deps): bump anser from 2.3.2 to 2.3.5 * chore(profiles): allow web UI to read loadavg * feat: Reduce level of "Failed … command" log message further * test(clone-job): Improve checks of transaction handling * fix(clone-job): Prevent duplicate jobs after d813ac3655 * fix(clone-job): Restore compatibility with older curl versions * test: Debug `t/ui/27-plugin_obs_rsync_status_details.t` * fix: cancel job icon invisible in tests list * feat(ui): indicate number of previous job restarts in all lists * refactor(t): use proper subtests and test labels in 10-tests_overview * feat: Limit list of job groups in summary header box * feat: Filter job groups in tests overview by availability of results * chore(deps): Dependency cron 2026-03-31 * refactor(assets): remove deprecated KeyEvent usage * docs: relocate scheduler and worker load documentation * feat: dynamically adjust global job limit based on system load * chore(deps): bump picomatch from 2.3.1 to 2.3.2 * build(deps-dev): bump flatted from 3.4.1 to 3.4.2 - Update to version 5.1774895777.6c2911d1: * feat: Customizable time_limit_days * fix: arrow navigation not working in Chrome-based browsers * style: Remove various magic numbers * fix: ensure cache sync creates parent directory * feat: Improve log message when sending command to ws server fails * refactor: Use `any` instead of `grep` in worker schema * refactor: Avoid repeated access to `$args{command}` in worker schema * fix(clone-job): Restore authorized asset downloads after 06bc5193d25b * fix: restore broken label and flag icons in comments * feat: support parallel Perl tests with PROVE_JOBS in Makefile * fix(ui): Prevent build tag labels from rendering in all caps * feat: replace Test::Strict with Test::Compile in compilation check - Update to version 5.1774854217.24dbd811: * style: Fix TestingAndDebugging::RequireUseStrict violations * style: Fix TestingAndDebugging::ProhibitNoStrict violations * style: Fix BuiltinFunctions::RequireBlockMap violations * style: Use only positive conditions for unless * style: Fix OpenQA::RedundantStrictWarning violations * style: Fix BuiltinFunctions::ProhibitStringySplit violations * style: Fix ProhibitInterpolationOfLiterals violations * style: Fix CodeLayout::ProhibitParensWithBuiltins violations * style: Run perlcritic also for t/ * chore(deps): Dependency cron 2026-03-28 * feat: complete shim-less migration to Font Awesome 6 * chore: Add dependency for extending `t/11-commands.t` * chore: Reduce permissions of workflows * feat: support "always_run" test flag in web UI and API * feat(Makefile): enable heavy and fullstack tests by default locally * feat: Retry API calls in `clone-job` like already `openqa-cli` does * feat: migrate to timeago.js for proper jquery4 compatibility * feat(clone-job): Retry asset downloads on transient errors * feat(scheduler): provide visual indication of limited disk space * feat(scheduler): provide visual indication of limited disk space * feat(scheduler): prevent openQA depleting storage with new openQA jobs * refactor(tests): consolidate page loads in 01-list.t * feat: replace deprecated fork-awesome with Font Awesome 6 Free * fix(influxdb): prevent empty tags populated to telegraf * feat(MCP): Add MCP tool annotations - Update to version 5.1774510397.efec10a7: * Revert "refactor: Replace jQuery-dependent timeago with vanilla timeago.js" * docs(userguide): fix position of job_templates unique id * docs(amqp): cover usage examples of amqp and slack integration * feat: Allow resuming asset downloads with `openqa-clone-job` * feat: migrate to timeago.js for proper jquery4 compatibility * style: Exclude external/ directory from 01-style.t checks * style: Fix various perlcritic violations in script/ * git subrepo pull (merge) external/os-autoinst-common - Update to version 5.1774384552.1377209d: * test: Add Test::Perl::Critic * test: Consider everything under `lib/openQA/` covered * refactor: Avoid duplicate code for making test suite name unique * test: Consider everything under `lib/OpenQA/Scheduler/` covered * test: Cover handling missing response from ws server when assigning jobs * test: Cover assigning multiple jobs to worker * refactor: Extract functions to assign jobs in scheduler code * refactor: Remove probably useless error handling in scheduler code * test: Cover all cases of sorting criteria in scheduler * test: Consider everything under `lib/OpenQA/Resource/` covered * test: Cover remaining uncovered lines in `OpenQA::Resource::Locks` * refactor: Simplify `unlock` function to be in-line with `lock` * test: Cover restarting jobs with no job IDs specified * style: Use ProhibitNegativeExpressionsInUnlessAndUntilConditions * chore(deps): Dependency cron 2026-03-24 * chore: migrate remaining ESLint settings from legacy to flat config * style: migrate all JavaScript consistently from var to let/const * chore(ci): bump javascript check to node 22 - Update to version 5.1774278862.ea002efa: * refactor: slightly simplify BuildResults * chore(AGENTS.md): add customized file * refactor: deduplicate configuration defaults and verify openqa.ini * fix(ci): fix referencing commit-message-checker * style: Add Test::Perl::Critic dependency * docs: document "always_run" test flag * feat(Makefile): add help text for missing targets * fix: prevent intermittent failure in t/ui/13-admin.t * fix: remove fixed container sizing in needlediff view - Update to version 5.1774104919.9788babf: * feat: add pre-commit hooks with gitlint * ci: replace GHA commit-message-checker with os-autoinst-common one * refactor: replace .gitlint with identical os-autoinst-common one * git subrepo pull (merge) external/os-autoinst-common * fix: needlediff view alignment (regression from dc1a3709e) * fix: robust group property validation and reliable UI tests * test: Consider the `CacheService` directory fully covered * test: Mark whole function `_kill_db_accessing_processes` as uncoverable * test: Track coverage of InfluxDB route of cache service * refactor: Remove CORE:: prefix from function calls * fix: avoid duplicating users on provider mismatch * refactor(Utils): remove unnecessary CORE:: prefix again * fix: use proper Mojo::Base attribute for developer_session_running * refactor: convert all remaining lib/ modules to signatures * fix: use Scalar::Util::set_prototype for compatibility with Perl 5.26.1 * refactor(LiveHandler): convert remaining modules to signatures * refactor(Scheduler): convert remaining modules to signatures * refactor(Schema): convert remaining modules to signatures * refactor(Shared): convert remaining modules to signatures * refactor(Task): convert remaining modules to signatures * refactor(WebAPI): convert remaining modules to signatures * refactor(WebSockets): convert remaining modules to signatures * refactor(Worker): convert remaining modules to signatures * refactor(Parser): convert remaining modules to signatures * refactor(CacheService): convert remaining modules to signatures * refactor(t::lib::OpenQA): convert remaining modules to signatures * refactor: Simplify `_handle_command_resume_test_execution` * chore(t::OpenQA::Test::Utils): remove obsolete "_get_worker" mock * fix: Add missing Mojo::File import in Parser::Format::Base * refactor: remove unused function OpenQA::Parser::Result::write_json * feat(tests): reduce wait_for_ajax default timeout from 5min to 30s * Revert "feat: modernize test result styling with data attributes" * refactor: Use File::stat to avoid magic numbers * refactor: Use Time::Seconds to avoid magic numbers * chore: adapt openQA for jQuery 4.0.0 * feat: improve local gitlint by picking the most recent base branch * ci: ensure local gitlint checks all commits in the branch * ci(check-helm-chart): try harder to download from registry.opensuse.org * fix: resolve instability in cache-service rsync test * feat: use localhost instead of manual IP addresses in startup message * feat: modernize test result styling with data attributes * fix(audit): show all audit events in the web UI * docs: Add missing line break to fix Deletion section * build: integrate stylelint for automated CSS/SCSS styling * feat: Allow reproducing test with pinned test code via clone-job * feat(webui): make rendering batch size configurable * fix: resolve sporadic failure in UI test tabs loading * fix(investigation): select casedir/needledir correctly when no symlink - Update to version 5.1773427330.0b172206: * fix: Display GitHub bugrefs correctly when used within a label * refactor: Improve style in `t/39-scheduled_products-table.t` * feat: improve responsiveness of tabs in job details view * ci(helm): override pullPolicy when install helm via ct * test: Consider everything under `lib/OpenQA/Schema` covered * test: Cover generating Gravatar URLs * test: Cover handling failed job cancellation when scheduling iso * feat: add zypper clean command in base container * test: Cover computing Git log diff * test: Cover adding logs to result file list * refactor: Simplify and slightly improve `create_asset` * refactor: Simplify error handling in function for appending job logs * test: Cover setting and deleting job properties * test: Cover error handling when duplicating jobs * test: Mark error handling in `_hashref` as uncoverable * test: Cover remaining lines of `JobModules.pm` * refactor: Remove unused function `locked_by_jobs` * test: Cover removing test suite defaults * test: Cover rendering description of parent job group * test: Consider everything under `lib/OpenQA/Script/` covered * test: Cover `openqa_baseurl` used by clone script * test: Cover handling unexpected return code in clone script - Update to version 5.1773333964.ffc5eff5: * test: Fix unstable test for stacking of parallel tests on overview page - Update to version 5.1773291834.69acf4b4: * chore(deps): Dependency cron 2026-03-12 * style: Use HTTP::Status status code constants * Revert "feat: optimize size of devel:openQA:ci/base container" * feat: adapt to os-autoinst switching to markdown - Update to version 5.1773151075.654d76ed: * refactor: Write `renderComments()` in a more compact way * fix: Restore spacing between bug and other icons after 9346b7165 * ci(helm): replace internal retry with okurz/retry/ * refactor: Use signature in callback to clarify input parameters * style: Add three perlcritic rules * style: Make .perlcriticrc a real file instead of a symlink * chore(deps): Adjust bot commit message to conventional commits * test: Add test for rendering `label:linked` with bug reference * feat: Improve handling non-bugref URLs in `mark_job_linked` after 7f6790 * test: Verify that only one label is added via `mark_job_linked` * feat: Render labels with bug references as clickable links * refactor: Improve coding style in `renderComments()` * feat: Use bugref within label when creating 'Job mentioned in …' comment * docs: document the priority throttling for scheduled jobs * Dependency cron 2026-03-09 * feat: Streamline "relates to default checkout" condition * feat: Enable `git_auto_update` if `CASEDIR` and `NEEDLES_DIR` are set * feat: Support `CASEDIR` lookup introduced in ef229dc also in Git tasks * fix: Handle error when determining Git server host correctly * feat: add privacy policy - Update to version 5.1773068319.a9347c1b: * docs: Link to latest passed job to ensure the download tab exists * feat: allow filtering by job result and state in /tests/latest * style: Always pass a regex match to split * style: Use map only in block form * style: Use grep only in block form * style(gitlint): allow unwrappable longer URLs in git commit message body * feat: unify priority management of max_job_time and throttling * ci(helm): pull container images in advance * ci(helm): make sure that install-chart runs after lint-chart * feat: optimize size of devel:openQA:ci/base container * feat: allow users to delete/anonymize their own account - Update to version 5.1772722702.3877b2ca: * style: Use builtin functions without parentheses consistently * build: update minimatch to fix ReDoS vulnerabilities - Update to version 5.1772705410.5c7fe0aa: * style(t): fix formatting of long line in t/37-limit_assets.t * test(Makefile): treat t/01-style consistently with tidy+compile tests * ci: cover sporadic download errors with retries * feat: support show_build=1 for overview badges - Update to version 5.1772550094.48b5cce5: * refactor: Improve code for testing OpenID auth * test: Consider everything under `lib/OpenQA/WebAPI/` covered * test: Cover all code for OpenID auth * test: Cover retrying of OBS rsync tasks * fix: Return correctly when OBS dirty status cannot be determined * refactor: Remove unused local variable in OBS rsync code * test: Cover parameter validation warnings code for API descriptions * fix(config): Drop max_conns to allow proper queueing * refactor: Improve code in `renderTestLists()` * feat: Pass all parameters when making AJAX requests on "All tests" page * feat: Allow use of `job_setting` parameter also on "All tests" page * refactor: Simplify code for passing query parameters on "All tests" * fix(dependencies): add missing "make" to devel sub-package * test: remove stabilized tests from tools/unstable_tests.txt * test(lib): remove unused "disconnect" function * test(lib): mark uncovered line - Update to version 5.1772475695.6c6c7eda: * build(Makefile): add make target help text * fix(npm): bump to non-vulerable versions (boo#1259005, boo#1258632) - Update to version 5.1772460208.7a4e1e06: * docs: Document array-like job settings and `job_setting` parameter * test: Ensure test of filter params of jobs API fails if code breaks * feat: Support searching by job settings in API to list jobs * refactor: Improve `cancel_by_settings` * fix: Allow filtering by more than one job setting in various routes * test: Improve checks in `t/api/02-iso.t` * feat: Allow searching by job settings via overview routes * style: use consistent q{} syntax for SQL strings in Cache Model * refactor: streamline IPC::Run usage and signal handling * test: remove t/25-cache-service.t from unstable_tests.txt * test: improve robustness of t/25-cache-service.t * test: refactor InfluxDB subtest to reduce duplication * test: improve infrastructure for t/25-cache-service.t * fix: improve database robustness in Cache model * fix: log rsync stderr in CacheService::Task::Sync * test: support OPENQA_TEST_WAIT_INTERVAL in wait_for * fix(cache): capture stderr and handle exit status robustly in Sync task * test: make SIGCHLD handler selective in OpenQA::Test::Utils * docs: document aggregate result badges for overview queries - Update to version 5.1772092969.74a39650: * test: Consider all of `lib/OpenQA/Task/` covered * test: Cover handling developer session when saving needles * test: Cover further error cases when saving needles * fix: Fix error handling when saving needle JSON * test: Workaround limitation of coverage tracking * feat: Improve needle JSON validation * test: Cover all cases of needle JSON validation * fix: Avoid Perl warning when validating needle JSON * refactor: Simplify code in `_delete_needles` * test: Cover handling error when asset directory is not writable * test: Cover skipping screenshot cleanup if still enqueued * feat(openqa-upstreams.inc): set `max_conns` to max connection handled * refactor: optimize and harden aggregate overview badges implementation * refactor: improve aggregate overview badges implementation * test: consolidate SVG badge unit tests * feat: implement test result badges for aggregate overview queries - Update to version 5.1772031289.93bc2a13: * docs(image): describe the TW image with openQA available in o3 * fix(t/03-auth): avoid 'Too many open files' with mocks * fix: avoid constant redefinition warnings in ScheduledProducts * feat: add aggregate favicons for test overview * build: improve cleanup of generated favicon assets * feat: add Makefile targets to run services with temporary test database * ci(helm): increase timeout on ct install * feat: add gitlint for conventional commit checks - Update to version 5.1771942065.808b073f: * test(t/44-scripts): extend to cover Python scripts * test(t/44-scripts): implement individual timeouts * fix(script): add early argument validation where missing * test: harmonize Test::More call format using '+' prefix * Dependency cron 2026-02-24 * test: refine style check and fix ambiguous test calls * Replace Ingress with Kubernetes Gateway API for external access * refactor: ensure consistent test call parentheses format * chore: add dependency for python3-gitlint commit checks * tweak: Improve logging of Git output * tweak: Avoid warnings about invalid revision ranges * tweak: Use normal warning log messages when encountering Git problems * fix: Avoid Perl warnings if URL passed to `git_commit_url` is invalid * docs: Add section about security * Fix tools/test_helm_chart after Helm chart reorganization * Update Helm chart documentation * Move worker subchart under openqa/ and fix connectivity * Add single openqa parent chart with ingress and nginx * Remove old helm chart structure - Update to version 5.1771846996.b67911c1: * fix: update ajv to fix moderate severity ReDoS vulnerability * fix: update minimatch override to fix high severity ReDoS vulnerability * openqa-load-templates: Slightly simplify - Update to version 5.1771626210.b82f14f2: * refactor(test/overview): use signatures and clean up code * refactor(test/overview): reduce duplication - Update to version 5.1771589939.8f8502b4: * feat: Improve default `PRODUCTDIR` after ef229dc2 * refactor(ui): simplify removal of empty query parameters (after rebase) * test(45-make-update-deps): allow bypassing dependency update check * fix(test): improve UI test robustness by using state-based waiting * test: Improve workaround for candidates menu not opening sometimes * docs: Mention use of relative paths in `CASEDIR` to avoid symlinking * fix: Fix wrong uses of "checkout" that should be "check out" * feat: support filtering by meta-results+states in /tests/overview * Revert "feat: Add symlink for aeon in openqa-bootstrap script" * fix(43-scheduling-and-worker-scalability): prevent sporadic issues * refactor: use join for properties in determine_free_workers * fix: do not cache websocket_api_version if not set - Update to version 5.1771473096.98530511: * feat(ui): remove empty query parameters from /tests/overview URL * fix(mcp): set navbar check expression to read-only * feat: support inverted result filters in /tests/overview * feat: Allow specifying `CASEDIR` to avoid symlinking * fix(test): Enable helm install-chart test again * git subrepo pull (merge) --force external/os-autoinst-common * feat: Make allowed hosts for SCENARIO_DEFINITIONS_YAML_FILE configurable * test: Consider everything under `lib/OpenQA/Shared/` covered * fix: Provide specific error message if job was removed `enqueue_…_track` * refactor: Remove useless error message in `enqueue_and_keep_track` * test: Cover case of successful executing in `enqueue_and_keep_track` * refactor: Simplify error handling of `enqueue_and_keep_track` * test: Cover error handling of `enqueue_and_keep_track` * test: Consider shared session controller fully covered * refactor: Avoid duplications in sessions controller * refactor: Use signatures in session controller code * test: Cover error handling in case of a bad CRSF token * test: Cover test route for session * fix(worker): reject jobs explicitly when worker is stopping * feat: Remove workaround for codecov and gpg * feat: Switch to Leap 16 in Helm charts * feat: Switch to Leap 16.0 in openqa_data container * feat: Replace all Leap 15.6 with 16.0 in docs and scripts * test: Cover showing special image when backend has terminated * fix: Use new apachectl command * Update openQA containers to Leap 16.0 * test: Extend tests for controller handling live view * refactor: Move throttling into its own function * feat(throttling): throttle jobs resources based on parameters size * refactor: Avoid repeated use of `$t->app->minion` in gru tasks tests * feat: Allow archiving jobs with infinite important storage durations * feat: Flag jobs without results as archived for consistency * feat: Remove one corner case preventing jobs from being archived - Update to version 5.1770718745.ce2072d3: * feat(ui): use clickable test overview summary counts for quick filtering * build(Makefile): fix uninterruptable tests * docs: Mention caveats of `…_cleanup_max_free_percentage` setting * test(25-cache-service): fix race conditions * test(ui/21-admin-needles): properly wait for modal dialog and deletion * test(ui/13-admin): properly wait for API key deletion * test(40-openqa-clone-job): properly isolate from system config * test(15-asset): bump timeout to current runtime * chore: fix CVE-2026-25547 (boo#1257852) by overriding minimatch * build(deps-dev): bump @eslint from 9.36.0 to 9.38.0 * fix(eslint): correct style to be eslint-9.38 compliant * build(deps-dev): bump @eslint-community/regexpp from 4.12.1 to 4.12.2 * build(deps-dev): bump @eslint/config-array from 0.21.0 to 0.21.1 * build(deps-dev): bump @eslint/object-schema from 2.1.6 to 2.1.7 * refactor: Improve variable names in function to determine expired jobs * test: Improve name of subtest for archiving * test: Verify that archiving works regardless of logs/results present * Dependency cron 2026-02-06 * Bump js-yaml from 4.1.0 to 4.1.1 * build(deps): bump ace-builds from 1.43.3 to 1.43.4 - Update to version 5.1770308102.12dfd0e4: * fix: Configure sudoers correctly in Leap 16 * Also use devel:openQA/16.0 in dependency bot workflow * Remove dependencies not available in 16 * Remove all explicit versions from ci-packages.txt * Explicitly use new cache key for fullstack_cache * Use devel:openQA 16.0 repositories * fix: Create user directory without sudo * refactor(ui): use native DOM APIs for bulk action logic * Update devel:openQA:ci/base container to Leap 16 * test: Consider all controller code covered * refactor: Remove unused "group connect" endpoints * test: Cover `openqa_jobs_by_worker` field of InfluxDB endpoint * test: Cover all cases of search of audit log table * refactor: Simplify function to render audit log index page * test: Add test for `eventid` parameter of audit log page * test: Cover remaining lines of `Asset.pm` * Mark some one line catch statements uncoverable * Move t/07-api_jobtokens.t to t/api/ * refactor: Avoid mapping of actions in df-based cleanup * refactor: Use loop to invoke `_delete_jobs` repeatedly * refactor: Simplify code for df-based cleanup further * refactor: Extract repeated lookup and loop into separate function * Dependency cron 2026-02-03 * feat(ui): add bulk action checkboxes to test overview filters * feat(openqa-clone-custom-git-refspec): add "BADGE" mode * fix(openqa-clone-custom-git-refspec): fix "MARKDOWN" mode * feat(UI): add delete button for job groups and parent groups * refactor(javascripts): harden by using const in admin_groups.js * feat(api): prevent deletion of non-empty parent job groups * docs: Fix typo in MCP documentation * docs: Improve note about enabling modern Perl features * test: Remove unused parameters in `OpenQA::Test::Case::login` * navbar: add new item in menu to link MCP documentation * Refactor t/lib/OpenQA/Test/Case.pm with signatures * test: Consider all API controller code covered * test: Cover remaining error cases of worker API * fix: Improve error handling when updating records in admin tables * test: Ensure consistent coverage of job cancellation function * Prepare documentation generation for Leap 16.0 * test: Cover remaining lines of `Search.pm` * test: Cover remaining lines of `Locks.pm` * refactor: Simplify `JobTemplate::destroy` * refactor: Remove unused code from `JobTemplate.pm` * git subrepo pull (merge) external/os-autoinst-common - Update to version 5.1769644379.ef069e9d: * style: Add quotes in openqa-bootstrap * feat: default API key expiration to 1 year, aligning with UI * feat: wrap array in an object in api_key API responses * feat: add API endpoint for deleting API keys * feat: add API endpoint for listing API keys * feat: add API endpoint for creating API keys * fix(openqa-bootstrap): prevent shellcheck warning SC2086 * Add dependency on 'file' * refactor: Write code in `JobGroup.pm` in a more compact way * test: Consider `Job.pm` fully covered * test: Add tests for error handling of artefact upload * refactor: Format artefact upload test in a more compact way * test: Add tests for using assigned worker on job status updates * test: Add tests for re-scheduling invalid scheduled product * test: Add tests for querying non-existent scheduled product * refactor: Use more compact coding style in `show_scheduled_product` * refactor: Improve `Mm.pm` * test: Improve tests of multi-machine API * Remove unused module Config::Tiny from dependencies * Handle links on test_log on missing git repo extension * test: Consider `Test.pm` fully covered * test: Extend tests for showing dependency graph * fix: Merge parallel clusters correctly for displaying dependency tree - Update to version 5.1769550212.662a4f95: * refactor(investigation): Use TEST_GIT_URL and NEEDLES_GIT_URL * refactor(investigation): Rename gitrepodir function * Restart: handle subclassed AMQP plugin * Revert "Update CircleCI image to Leap 16.0" * fix: Fix invalid HTML in test creation form * feat: Make test creation discoverable to all users * refactor: Simplify/extend flash message templates * feat: Avoid confusing/wrong "Administrator level required" error * Update CircleCI image to Leap 16.0 * feat: Support `async=1` flag via `openqa-cli schedule --monitor` * fix: Avoid serializing `null` click point after e19aee4 and da7cce6b * test: Fix failing style checks due to test file with invalid YAML * test: Cover redirection to Git platform via CASEDIR and TEST_GIT_HASH * fix: Fix error handling when redirecting to Git platform * test: Distinguish different cases for showing settings files * test: Cover case of invalid scenario definitions when creating test * test: Consider `Step.pm` fully covered * test: Cover case of showing unsupported results * fix: Improve condition for checking valid step result * test: Cover case of showing candidate needle with no tags * refactor: Simplify `calc_matches` * refactor: Write uncoverable error handler in one line * refactor: Simplify `_new_screenshot` * refactor: Rewrite code for screenshot name in a more compact way * test: Cover options to take images/areas from existing needles * Use body parameters in POST request * feat: Add symlink for aeon in openqa-bootstrap script * chore(deps): bump lodash from 4.17.21 to 4.17.23 * test: Add test for displaying audio results * test: Cover remaining lines of `File.pm` * feat: Improve log message about invalid config in df-based cleanup * feat: Add dry run to df-based cleanup of job results * Fix grammatic mistakes on the snapshots documentation * Describe how snapshots work internally * doc: Improve wording in documentation about space-aware cleanup * doc: Clarify settings for space-aware cleanup * doc: Use "file system" consistently in comments in config files * doc: Wrap comments in `openqa.ini` at 80 characters * doc: Use "file system" consistently in users documentation * doc: Mention also `…_cleanup_max_free_percentage` * doc: Move documentation about space-aware cleanup into its own section * doc: Use "filesystem" instead of "partition" in config comments * fix: Account deletion of screenshots of archived jobs correctly * doc: Mention variables for df-based job result cleanup * feat: Consider archive as well in df-based cleanup of job results - Update to version 5.1769068942.639067ee: * Dependency cron 2026-01-22 * feat: Show limits on "Next & Previous" tab within table - Update to version 5.1768996386.e3f58202: * fix: Avoid Perl warning if product spec contains undef values * GenericBug: Add [QE] to the subject * doc: Mention version lookup of mediums and special value `*` * doc: Wrap section about medium types consistently at 80 characters * doc: Remove surplus white-space * chore: Improve indentation/wrapping of comment * feat: Improve error message when product contains no templates * tests: Improve/add tests for "no products found" case * KernelBug: Extend the kernel bug template * feat: Improve error message when falling back to version `*` - Update to version 5.1768856318.847e4fc7: * fix(systemd): prevent openqa-gru starting while mounts are unavailable * fix(systemd): try restarts on failure to be more resilient * feat: Show when "Next & Previous" jobs are limited * refactor: Format SQL code for "Next & Previous" jobs more nicely * refactor: Simplify determining latest job in "Next & Previous" list - Update to version 5.1768564451.45d5d5b2: * OpenSuseIssueReporter: Avoid multiple push calls * unit_tests: Add unit tests for OpenSuseBugzillaUtils * unit_tests: Adapt the UI tests to the new kernel bug button * plugins: Introduce OpenSuseIssueReporter for external issue reporting - Update to version 5.1768402729.462b3957: * feat: optionally configure fake auth key+secret+expiration - Update to version 5.1768323619.9a70ab91: * refactor: Extend tests of df-based cleanup * fix: Avoid wrong deletion of archived jobs in df-based cleanup * refactor: Move logic for validating percentage into helper * refactor: Clarify wording in comment regarding job cleanup * Use template literals in certain JavaScript code * Retry delete_needles job on server restart * Add test for _delete_needles * feat(OpenQA::Git): Cleanup git dir in commit() on shutdown * feat: Improve rendering results on the scheduled product page - Update to version 5.1768209690.f34c2973: * feat(scheduled-products): Allow adding note to result data * docs: Use node_modules target * docs: Mention minimum PostgreSQL version * ci: Update PostgreSQL in CI/packaging to at least 14 * Revert "Add MCP tool annotations for Claude connector compliance" - Update to version 5.1767868268.dacbd3f7: * Add MCP tool annotations for Claude connector compliance - Update to version 5.1767864265.63cd20df: * Skip caching for KERNEL and INITRD variables - Update to version 5.1766150951.2799046e: * Coverage of openQA: add folder Client/ in codecov.yaml * Improve openQA coverage of _download_handler in Archive.pm - Update to version 5.1766053374.57cdeee3: * fix(docs): Fix indentation in job template examples * feat(Needle::Save): Adapt to new error handling * feat(OpenQA::Git): Make error handling more flexible with exceptions - Update to version 5.1765887110.8fc02990: * Avoid partial deletion of a screenshot if Minion job is aborted * Add `SignalBlocker` to delay signal handling during critical sections - Update to version 5.1765805960.2112d43d: * fix(codecov): Fix wrong casing for 'fully_covered' entries - Update to version 5.1765535865.b566a24c: * fix(codecov): Be strict about coverage thresholds * Show jobs that have been cloned when `t` parameter is used on overview - Update to version 5.1765469360.5c0525b5: * worker: Add coverage for OVS DBus checks * Fix overview when filtering by test and module result at the same time * Return signal as part of run_cmd result * Add scanner for untracked screenshots * KTAP: Properly hide details of a skipped subtest * docs: Restory logic of the sentence about NFT vs firewalld * docs: Clarify DHCP/RA availability on MM networks * feat: Allow to configure key+secret with env variables - Update to version 5.1765286149.3debb8ea: * KTAP: Don't increment parsed_lines_count in "SKIP" lines * KTAP: Define unparsed_lines and parsed_lines_count - Update to version 5.1765217707.d6e697fd: * Test commenting on overview page together with TODO filter * Fix job IDs that are considered for mass-commenting on overview page - Update to version 5.1765009312.be30f6e0: * README: Remove left-over empty badge reference - Update to version 5.1764349525.ffb59486: * Also use TIMEOUT_SCALE for priority malus calculation * docs: Fix wrapping and typo * Document multi machine ovs flow setup and IPv6 usage * Avoid computing time constraint for scheduled product cleanup in Perl * rpm: Move `…-enqueue-needle-ref-cleanup` to other `…-enqueue-…` scripts * Add task to limit scheduled products similar to audit events * Extract generic parts from audit event cleanup task into generic task * parser: ktap: Show full output by default if no line was parsed * Ignore npm scripts also via `.npmrc` to make bare npm calls more secure * Avoid repeating `MAIN_SETTINGS` in various places * Fix possibly excessive memory use when computer test result overview * Fix typo in `_prepare_complex_query_search_args` * Fix indentation in `overview.html.ep` * Prevent logging AMQP credentials in debug output * Make restart_openqa_job emit proper event payload * Enable gru tasks to emit AMQP messages * Remove explicit loading AMQP plugin in Gru plugin * Emit restart events when job restarted automatically * Add debug message about priority malus * Fix ordering of job groups after 2ad929ceca43d - Update to version 5.1763743683.1da97aa2: * Optimize Job Group dropdown database query * Split dependency handling out of create_from_settings * Give jobs with high MAX_JOB_TIME a priority malus * Make the number of builds per group on the front page configurable * docs: Feature auto-generated deepwiki less prominently * apparmor: Additional perms for tests in osado to run - Update to version 5.1763153079.b36ac754: * Skip a build if there are no jobs * Remove unused variable - Update to version 5.1762879267.52145e9a: * Avoid installing unwanted package versions * Fix check in git_clone for dirty git dir * Prevent `t/24-worker-webui-connection.t` from running into timeout * Be explicit about certain aspects of archiving in the documentation * Fix sporadic failures in `t/ui/10-tests_overview.t` * Adapt os-autoinst-scripts reference after rename * Properly conclude scheduling if there are no jobs - Update to version 5.1762193001.2f6e71ca: * Potentially improve stability of `t/ui/16-tests_job_next_previous.t` * Avoid failing check in `t/16-utils-runcmd.t` * README: Add deepwiki badge * Dependency cron 2025-10-27 * Retry image optimizations - Update to version 5.1761296552.ae7c17aa: * Add tests for file_security_policy * Pass parameter $is_userfile to log_url * Remove redirect and serve files as attachments if necessary * Serve files uploaded by tests via asset domain * Use direct link to subdomain for the test assets * Revert "Don't redirect to asset domain via /needles/ID/(image|json) route" * Revert "Don't redirect screenshots, thumbs and needles to files_domain" - Update to version 5.1761228068.a3a7f84d: * Dependency cron 2025-10-23 - Update to version 5.1761037330.ad78558e: * Avoid needless check for number of clones * Avoid creation of `git_clone` tasks for jobs with empty `DISTRI` - Update to version 5.1760515610.a802d1dd: * Lower the prio of archiving jobs to avoid piling up finalize jobs * Add signatures in Schema::Result::ApiKeys - Update to version 5.1760245411.e3aeaaec: * Dependency cron 2025-10-12 - Update to version 5.1760108577.fd2f2a48: * Log unavailability due to high load only as warning * Filter job stats of scheduled products also by arch and build * Document how to disable image optimizations * Make image optimization errors stop the job producing an incomplete job * Improve wording in description about job stats API * Run `optipng` for real and handle errors if it fails - Update to version 5.1759912962.689b31ed: * Avoid failing `obs_rsync_run` jobs when restarting `openqa-gru.service` - Update to version 5.1759834744.06a7028a: * parser: ktap: Return earlier if subtest result is SKIP * parser: ktap: Fallback to subtest index if name is not available - Update to version 5.1759440640.bb989cab: * Don't redirect to asset domain via /needles/ID/(image|json) route - Update to version 5.1759402042.49e912c3: * Introduce array job settings * Retry `obs_rsync_update_*` tasks if Gru service terminates - Update to version 5.1759329378.3b8e8685: * Reduce the number of required checks for Mergify again * Ensure a failing cache service is seen as such by the worker/scheduler - Update to version 5.1759248257.70b23b32: * Increase number of successful checks in Mergify config again * Disable Helm Chart CI checks temporarily * Consider all jobs for cleanup, not just jobs that were executed * Verify job deletion when dependent job present - Update to version 5.1759149505.49c40b0b: * Use always the latest PostgreSQL image in Compose and documentation * Update the PostgreSQL version in the contributing documentation * Update PostgreSQL data path in Docker Compose file after updating to v18 * Specify PostgreSQL version in Docker Compose configuration explicitly * mergify: Allow more time for dependabot update reaction * Remove version property from docker-compose * README: Fix openQA badge after switch to UEFI * build(deps-dev): bump eslint from 9.35.0 to 9.36.0 - Update to version 5.1758910696.7549bb98: * Replace argument assignment with signatures on ObsRsync/Task * Enable automatic dependabot updates again after improvements * docs: Add instructions for a continuous dashboard setup * Replace argument assignment with signatures Folders package * Fully cover WebAPI::Plugin::ObsRsync::Controller::Folders * script: Also use OPENQA_WEBUI_MODE for related services - Update to version 5.1758814503.03d923a4: * Use Mojo::File in Worker for is_qemu_running * Use Mojo::File in Worker for meminfo * Document archiving of important jobs - Update to version 5.1758729450.b88c0b40: * Reject jobs if worker is broken when receiving a new job - Update to version 5.1758711845.e5c02221: * script: Allow to configure openQA mode * t: run at least once Memorylimit register with max_rss_limit > 0 * Replace argument assignation with signatures on MemoryLimit - Update to version 5.1758632540.ed64f555: * Check for consistent zypper setting for auto/continuous-update * Ignore scripts when installing NPM packages in RPM builds * Avoid installing NPM dev deps unnecessarily in RPM builds * Avoid installing NPM dev deps unnecessarily in `Makefile` - Update to version 5.1758551670.e3aa50f9: * Don't redirect screenshots, thumbs and needles to files_domain * Cleanup .gitignore files * Update Dockerfile to setup proxy via script/configure-web-proxy * Redirect test assets to file_domain if configured * Make sure assets are generated before listing them - Update to version 5.1758307053.75367131: * docs: Fix shell syntax in development setup * Replace argument assignment with signatures on ObsRsync - Update to version 5.1758276230.9cef0ea3: * Treat SVG files as attachment for security reasons * Fix LegacyKeyValueFormat on openqa_data/Dockerfile - Update to version 5.1758194931.aa2c9a8b: * bootstrap-container: Workaround SELinux issue by split of zypper calls * Prevent abort while doing database interaction in Delete needles - Update to version 5.1758036156.d3e99d09: * Temporarily require manual review of Dependabot PRs * Prevent warning from `DBIx::Class::Storage::TxnScopeGuard` * Avoid sporadic test failures in `t/ui/15-comments.t` * Worker: Detect IPMI config and shutdown SUT when unused - Update to version 5.1757954579.4d0727fe: * Use of finish method in place of close_connection * Clean up streamtext signature from unused params * Fix invocation of `validateJobGroupForm()` when expanding group editor * Improve showing advanced fields in case there are warnings * Avoid race condition when creating job asset * Ensure the `created_by` flag of job assets is set during registration * Add unit test for 486c6e05ca * build(deps-dev): bump debug from 4.4.1 to 4.4.3 * Update automatically updated group properties in UI * Automatically increase important durations to match regular durations - Update to version 5.1757798615.f8615cd6: * t: Fix comparison by interpolating variable - Update to version 5.1757696527.61d51d58: * Avoid partitioning in raid0 device * Avoid "Server returned …" error if there is an actual error message * Highlight invalid/problematic group config fields in UI when applying * Improve validation of cleanup configuration * AMQP: include list of failed modules in job.done messages - Update to version 5.1757597587.61c22a78: * Add usage examples of netrc to the access tokens - Update to version 5.1757512851.666d7dc7: * build(deps): bump datatables.net-bs5 from 2.3.3 to 2.3.4 * Fix regression handling retention of important jobs * Use newly introduced `_all_parents` function in `_sort_dep` as well * Include parallel children when scheduling with `_INCLUDE_CHILDREN=1` * build(deps-dev): bump eslint from 9.34.0 to 9.35.0 * Fix typos in PosgreSQL related documentation * Use autoyast ERB helper to detect disk dynamically * Use find_or_create when registering assets * Stop logging confusing exception when GruTask is gone * parser: ktap: Don't add skipped subtests to output * t: Use proper test description strings in 03-auth.t * t: Condense variable assignment with ok-check - Update to version 5.1757135418.ec726f9c: * Dependency cron 2025-09-06 - Update to version 5.1757084700.fad3731d: * Ensure no untracked files in unit test run part 2 * Dependency cron 2025-09-05 * Add MCP support as an optional feature * Allow specifying a full domain via `file_security_policy` * Allow using a different subdomain via `file_security_policy` * t: Ensure no leftover files in git directory * ci: Ensure clean git status with Test::CheckGitStatus - Update to version 5.1757005118.aac56dbc: * CI: Fix SLE_15_SP6_Backports repo lookup order * Add perl(MCP) dependency in preparation for AI support * build(deps-dev): bump @humanfs/node from 0.16.6 to 0.16.7 * Revert "MCP: Add MCP support as an optional feature" * Fix typo on Contributing documentation * Add MCP support as an optional feature * Reword `can't write` to `Cannot write` as suggested by review comment * Ensure destination dir for asset downloads exists when cloning jobs * build(deps): bump ace-builds from 1.43.2 to 1.43.3 - Update to version 5.1756962167.74f0204f: * Dependency cron 2025-09-04 - Update to version 5.1756905114.bb4fa746: * Fix syntax error in nginx config * Mark unconfigured api route log as uncoverable statement * Increase test coverage for lib/OpenQA/WebAPI/Description.pm * parser: ktap: Don't write diagnostic data into $subtest_name * Extend tests for configuring subdomain to serve files * Avoid job terminated unexpectedly with signal handler in delete needles * Allow configuring subdomain for serving logs/assets more securely * Do not invoke Mojo::IOLoop->remove twice * Add support for Bearer token authentication * Worker::Engines::isotovideo: Simplify using more Mojo::File * Worker::Engines::isotovideo: Remove obsolete comment - Update to version 5.1756479924.9488e2cc: * docs: Fix typo in path to script folder - Update to version 5.1756374919.f1ac1b58: * build(deps): bump bootstrap from 5.3.7 to 5.3.8 * build(deps-dev): bump eslint from 9.33.0 to 9.34.0 * parser: ktap: Sanitize spaces from group name * Cleanup unused parameter in streamtext * build(deps): bump datatables.net-bs5 from 2.3.2 to 2.3.3 * Document semantics of low limits for important data * Log disconnection of the livehandler due to file changes * Disallow browsing HTML assets/results/logs by default * Extend coverage on streamtext function of Running.pm * Fix Too few arguments for subroutine error on close_connection * Handle 'expand_placeholders' return value consistently - Update to version 5.1755616303.131c0f0a: * Add space in concatenation of args and string for the fall back note - Update to version 5.1755609067.e3c951fe: * Stash gru_dependencies to avoid helper usage in view * Move infopanel gru task link creation to the controller * Create test for GRU task in test details * Link minion job from openQA job with waiting task - Update to version 5.1755504216.b51ff4b1: * Use signatures in worker reactor error handler * Use signatures in worker job code and related mocking - Update to version 5.1755366162.ba8741a1: * Use backticks in docs for querying job settings - Update to version 5.1755247660.ecd6aa3e: * Fix return code of worker in error case * Prevent worker from getting stuck on fatal error during upload * Describe job_settings/jobs in UsersGuide * Describe job_settings/jobs in UsersGuide * Add perlpod for job_settings/jobs * Fix generation of PDF documentation * Remove outdated comment in worker error handling * tests: Extend ktap parser tests to cover TODO directive * parser: ktap: Polish the ktap parser * parser: ktap: Add handling of the TODO directive * parser: ktap: Refactor to use internal state - Update to version 5.1755087548.49d62b92: * Add instructions for running a openQA/tools dev environment - Update to version 5.1754970590.1f9110da: * build(deps-dev): bump eslint from 9.32.0 to 9.33.0 - Update to version 5.1754903895.e603536f: * build(deps-dev): bump @eslint/plugin-kit from 0.3.4 to 0.3.5 * build(deps-dev): bump @eslint/core from 0.15.1 to 0.15.2 * build(deps-dev): bump @eslint/config-helpers from 0.3.0 to 0.3.1 - Update to version 5.1754716201.09d147dc: * Dependency cron 2025-08-09 - Update to version 5.1754665747.0074044f: * Revert "Rewrote client script from perl to bash to fix heavy tests" * Revert "Remove test related to deprecated client script" - Update to version 5.1754567283.cc45a4c0: * Rewrote client script from perl to bash to fix heavy tests * Remove script declaration on profiles * build(deps-dev): bump eslint-plugin-prettier from 5.5.3 to 5.5.4 * Remove test related to deprecated client script * Obsolete script/client after 4 year deprecation period - Update to version 5.1754477962.22b1fea4: * Extend docs on lua test modules - Update to version 5.1754383059.0426baa1: * Dependency cron 2025-08-05 * Fix LegacyKeyValueFormat in Dockerfiles - Update to version 5.1754297241.bf37533a: * Stop flagging obs_rsync errors as failures * Mention use of CRITICAL_LOAD_AVG_THRESHOLD - Update to version 5.1753967288.48036af4: * Double default storage duration for jobs in database - Update to version 5.1753868091.5fba34bf: * docs: Remove deprecated references to openqa-client * Fix weird validation errors of date time on API keys page * build(deps-dev): bump eslint from 9.31.0 to 9.32.0 * Simplify `_set_default_storage_durations` * Rename template for "Show advanced cleanup …" button * Use loop to setup validation of cleanup properties * Validate cleanup fields for important jobs as well * Ensure advanced cleanup settings are shown if error relates to them * Improve showing error in group property editor * Fix id/label/default in group property editor after recent changes * Move link to documentation next to "Show advanced …" button * Improve help popover for retention durations * Collapse settings for keeping jobs in database longer by default * Reorder group property editor so important fields come first * Move lengthy description of cleanup settings to the users guide * Update and improve documentation about cleanup * Explain what "important" means in help popover of group properties * Ensure default config of limits/durations make sense * Make use of configured job storage duration when limiting jobs * Extend UI for configuring job storage duration * Extend job group API for configuring job storage duration * Add settings for configuring job storage duration * Add database columns for configuring job storage duration * Show note about sorting on group overview pages * Improve documentation section about Python API * Mention Lua based tests in documentation - Update to version 5.1753703782.e7ffc367: * docs: Clarify that openQA is not only Perl * Use and recommend --ignore-scripts with npm install - Update to version 5.1753506485.d911de9f: * Dependency cron 2025-07-26 * Require openssh-clients for git clone with ssh * Allow empty values in openqa-cli parameters - Update to version 5.1753359903.308980e8: * Retrieve oldest/newest build results job in the loop - Update to version 5.1753279335.b2b4eddc: * Clarify role of set_var in variable precedence * Use signatures in code for handling special group columns * Sort keys in test of job group API * Avoid duplicated code in job group API code * Dependency cron 2025-07-23 * build(deps-dev): bump @eslint/plugin-kit from 0.3.3 to 0.3.4 * Allow querying the state of scheduled products by distri/version/flavor * unit_tests: Add unit tests for KTAP parser * parser: Add KTAP parser for handling kernel selftests * Deduplicate openqa-cli options and help - Update to version 5.1753110584.5810ee79: * build(deps-dev): bump eslint-plugin-prettier from 5.5.1 to 5.5.3 * build(deps-dev): bump synckit from 0.11.8 to 0.11.11 * build(deps-dev): bump @pkgr/core from 0.2.7 to 0.2.9 * build(deps-dev): bump eslint-config-prettier from 10.1.5 to 10.1.8 * Replace bareword filehandles with lexical filehandles * Add spaces around signatures * Do not quote hash keys unless necessary * Use single quotes where no interpolation is happening * Fix PostgreSQL startup failure in non-systemd environments * Support short test urls in openqa-clone-custom-git-refspec * Escape comments in regexes - Update to version 5.1753006709.37380d09: * tidy: Enforce blank lines before subs - Update to version 5.1752690982.12f3e8e6: * Add link to Helm in README - Update to version 5.1752668195.a61b311b: * Make hint about cloning example repo more prominent * build(deps): bump ace-builds from 1.43.1 to 1.43.2 - Update to version 5.1752509403.fe96ee50: * build(deps-dev): bump eslint from 9.30.1 to 9.31.0 - Update to version 5.1752296678.00670b57: * Dependency cron 2025-07-12 - Update to version 5.1752221648.28a02145: * Fix build overview timestamps - Update to version 5.1752164310.2f1c94d6: * openQA-bootstrap: Replace hardcoded openqa directory path with variable * Avoid trying to insert job modules without all required fields * Removed unused and erroneous function `update_backend` * Validate fields of update status before using them * Schema::Result::Jobs: Catch undefined parent jobs * Skip upload of test modules and extra tests with no name * worker: disconnect dbus from NameOwnerChanged signal (POO #183833) * Fix race cond when date ref job got deleted while serving build list * Prevent error when workers config not found, throw warning instead - Update to version 5.1751964812.235a2034: * Revert "Update CircleCI image to Leap 16.0" * Update CircleCI image to Leap 16.0 - Update to version 5.1751898525.cfb73284: * Avoid `Transaction already destroyed` being logged as error * Get BUILD time from oldest job if not sorting by newest job per build * Implement build version sorting by oldest job in build * Add frontend config option to sort by oldest job per build in jobgroup * Allow schemeless ip address as job url * Refactor and add tests for openqa-clone-job * Convert build version sorting type from bool to int - Update to version 5.1751834777.ce019b36: * dist: Simplify dependency for /etc/os-release (boo#1244139) - Update to version 5.1751707651.71eebf76: * dbicdh: Cleanup pre-2020 files * Avoid showing AJAX error on index page when user is navigating elsewhere * Dependency cron 2025-07-03 * Avoid showing confusing data in the needles table - Update to version 5.1751472215.9a30d4e5: * Discard needles under symlinked locations from needles table * build(deps): bump ace-builds from 1.43.0 to 1.43.1 * build(deps-dev): bump eslint from 9.30.0 to 9.30.1 * Fix pagination in server-side tables * openqa-bootstrap: Prevent error about unknown hosts (boo#1245378) * Bump eslint from 9.29.0 to 9.30.0 * Avoid creating stale needle entries in needle editor when symlinks used - Update to version 5.1751367844.1d8f9140: * create_admin: improve search for admin users * create_admin: fix for POO #179359 changes * openqa-bootstrap: Allow curl to follow redirects (boo#1245379) * Fix debugging SQL queries via `OPENQA_SQL_DEBUG` * Apply dependency changes after adding python3-argparse-manpage * Use argparse-manpage to create openqa-label-all.1 * Bump prettier from 3.6.0 to 3.6.2 * configure-web-proxy: deal with debian-style sites-available * apparmor: +/usr/bin/env * apparmor: additional worker perms * apparmor: allow access to Arm UEFI (AAVMF) files * apparmor: enable use of git-lfs for worker * Bump @eslint/plugin-kit from 0.3.2 to 0.3.3 * Add --odn option to specify openqa.debian.net * Command.pm: add missing quotes to o3 & osd options * configure-web-proxy: Use variables for /etc paths - Update to version 5.1751274619.acdc8609: * Apply dependency changes after adding python3-argparse-manpage * Use argparse-manpage to create openqa-label-all.1 * Makefile: generate manpages * Add manpage (as POD) to openqa-validate-yaml * Bump prettier from 3.6.0 to 3.6.2 * configure-web-proxy: deal with debian-style sites-available * Add Documentation to some systemd units * Add --odn option to specify openqa.debian.net * Command.pm: add missing quotes to o3 & osd options * configure-web-proxy: Use variables for /etc paths - Update to version 5.1751037189.b3da736b: * Bump prettier from 3.6.0 to 3.6.2 * configure-web-proxy: deal with debian-style sites-available * apparmor: +/usr/bin/env * apparmor: additional worker perms * apparmor: allow access to Arm UEFI (AAVMF) files * Bump @eslint/plugin-kit from 0.3.2 to 0.3.3 * Add --odn option to specify openqa.debian.net * Command.pm: add missing quotes to o3 & osd options * configure-web-proxy: Use variables for /etc paths - Update to version 5.1750754160.1caccdc7: * Bump prettier from 3.5.3 to 3.6.0 * Bump ace-builds from 1.42.0 to 1.43.0 * Log less verbose error message for missing files * Allow dots in test names * Refactor existing Helm Charts and README - Update to version 5.1750408965.72531a72: * Extend single-instance container documentation * Bump bootstrap from 5.3.6 to 5.3.7 * apparmor: Allow read access to device-tree files - Update to version 5.1750237596.0e254038: * Bump eslint-plugin-prettier from 5.4.1 to 5.5.0 * Avoid adding non-fatal API errors as incomplete reason in general * Avoid misleading errors about the websocket connection - Update to version 5.1750081859.24dae152: * Bump eslint from 9.28.0 to 9.29.0 * Document where docs/images/openqa-in-5-minutes.webm comes from * Fix string definition to be more consistent - initial package Changes in os-autoinst: - Update to version 5.1782809557.0ae98f8: * docs: document testing custom os-autoinst forks within openQA * feat: Also output module information for wait_serial result steps * feat: Add module name and step number to autoinst-log * feat: Log the CASEDIR git url/hash for easy frontend access * fix: exclude virt-firmware on older Leap ppc64 * fix: stop deepening when repo is no longer shallow - Update to version 5.1782140090.fe34efb: * fix: exclude virt-firmware on older Leap ppc64 * style: enforce signatures in anonymous subroutines * fix: stop deepening when repo is no longer shallow * ci: disable Mergify interactive queue controls in PR comments * style(perlcritic): Add Modules::ProhibitConditionalUseStatements * refactor: improve t/01-test_needle.t structure and style - Update to version 5.1781797043.0fb1077: * test: assert Level 3 pretty serial markers * fix: fallback pretty marker console to 'sut' * test: fix color test resilience to NO_COLOR * fix: stop QMP wait hangs on early QEMU exits * fix: stop autodie unlink crashes in qemu backend * fix: cleanly recreate virtio console pipe if already exists * fix: suppress spurious virtio console unlink warnings * test: reliably assert pipe size adjustments - Update to version 5.1781702821.22ced0d: * ci: Avoid unresolvable os-autoinst-openvswitch-test package for SLE-SP7 * fix: Avoid unresolvable os-autoinst-devel-test package for SLE-SP7 * feat: expose detect_serial_marker_capability as public * chore(mergify): adjust expectations to current OBS checks * style(perlcritic): Add BuiltinFunctions::RequireBlockGrep - Update to version 5.1781620242.0160257: * fix: Fix comment about OVMF firmware locations * fix(test): fix Test::More precedence in autotest * git subrepo pull (merge) --force external/os-autoinst-common * feat: Avoid silent fallback to MS certs with `UEFI_PFLASH_CERTS` * fix: Fix enrolling cert in UEFI firmware vars for SecureBoot - Update to version 5.1780506677.7bacdcd: * test: enable pretty serial markers in full-stack test * test: replace Core 7.2 ISO with bash-remastered version * test: add script to remaster Core ISO with bash * feat!: fail by default if always_rollback is not supported * fix: Clean up the last VM disks to avoid disk image creation failure * fix: script_run - type command and marker together on serial console * fix: fail explicitly on test module basename collisions - Update to version 5.1780410333.aed07e0: * fix(test): use linuxboot_dma.bin in 18-backend-qemu.t * feat: consolidate tidy targets into CMake * fix: fail explicitly on test module basename collisions * feat(mouse_drag): use the clickpoints * test: allow to configure full-stack test output directory * test: allow shortening long typing in full-stack tests - Update to version 5.1780332012.6ee8da2: * chore(AGENTS.md): phrase tidying as mandatory * feat(mouse_drag): use the clickpoints * test: allow to configure full-stack test output directory * test: allow shortening long typing in full-stack tests * chore: video_stream: accept ustreamer version 8 - Update to version 5.1779973703.70686ac: * ci: Use CI container in fullstack test as well * feat: Log details about relevant port if cmd srv cannot be started * refactor: Move function to get port details to OS utils * refactor: Use Feature::Compat::Try consistently * perf: use sourcing for efficient pretty serial marker activation * fix: Fix condition for devel/deps packages * feat: use efficient OA_NO_MARKER skip flag for pretty serial markers * refactor: use __oa_prompt shell function for pretty serial markers * feat: warn on manual serial terminal redirection in script_run - Update to version 5.1779461317.d4fb5bd: * refactor: Use Feature::Compat::Try consistently * perf: use sourcing for efficient pretty serial marker activation * fix: Fix condition for devel/deps packages * fix: Fix condition for Lua support * ci: Build packages for SLE 15 SP7 instead of SP6 which reached EOL * ci: Remove package builds for Leap 15.6 as it reached EOL * feat: use efficient OA_NO_MARKER skip flag for pretty serial markers - Update to version 5.1778246511.7a6bac3: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * style: unify copyright headers by dropping years - Update to version 5.1778097909.35320dd: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * style: unify copyright headers by dropping years - Update to version 5.1778069368.c751b82: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * fix: re-install serial marker hook after console reset - Update to version 5.1777891128.f572829: * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * fix: re-install serial marker hook after console reset * fix: support pretty_serial_markers in script_output regex * fix(test): handle D-Bus AccessDenied in Open vSwitch test - Update to version 5.1777537682.913fce0: * fix: re-install serial marker hook after console reset * fix: support pretty_serial_markers in script_output regex * feat: disable storage check in CI environments * fix(test): handle D-Bus AccessDenied in Open vSwitch test * fix: Avoid restarting openvswitch/NM after OVS bridge setup * refactor: import IO::Socket::UNIX explicitly wherever is used - Update to version 5.1776943886.0619ca6: * feat: add absolute storage threshold to prevent over-conservative aborts * style: Enforce ProhibitNegativeExpressionsInUnlessAndUntilConditions * style: Enforce perlcritic policy BuiltinFunctions::ProhibitStringySplit * style: Enforce perlcritic policy BuiltinFunctions::RequireBlockMap * git subrepo pull (merge) --force external/os-autoinst-common * chore(mergify): Update required number of successful checks - Update to version 5.1776765124.5d91657: * feat: fail explicitly if always_rollback is not supported * feat: add unique hash to pretty serial markers * feat: include executed command in step details and serial markers * docs: explain assert_screen semantics with multiple tags * feat(debugviewer): Move to /usr/lib * feat(snd2png): Move to /usr/lib * feat: Prefer modules in CASEDIR/lib over test module paths - Update to version 5.1776179508.bd2644d: * feat: abort test with incomplete if requested HDD size > threshold * chore: Remove obsolete HashKeyQuotes module * chore(deps): Remove obsolete Freenode::StrictWarnings policy * fix(manpages): Fix the output of pod2man * chore(ci): bump checkout v4->v6 - Update to version 5.1776074266.6a6c5ee: * fix(manpages): Fix the output of pod2man * fix(t/08-autotest.t): Fix FTBFS for reproducible builds * chore(ci): bump checkout v4->v6 * fix: prevent deprecation warning about "spurt" * style(llm): use indented heredocs for better readability * refactor: consolidate logic in _detect_serial_marker_capability * style: use non-capturing group for BASH version detection * fix(distribution): make PRETTY_SERIAL_MARKER reboot-safe * refactor: early returns in _detect_serial_marker_capability - Update to version 5.1775932217.bd11042: * fix: prevent deprecation warning about "spurt" * feat(edid): Add virtio-vga-gl support * style(llm): use indented heredocs for better readability * refactor: consolidate logic in _detect_serial_marker_capability * style: use non-capturing group for BASH version detection * fix(distribution): make PRETTY_SERIAL_MARKER reboot-safe - Update to version 5.1775744546.1ee50c6: * style(llm): use indented heredocs for better readability * refactor: consolidate logic in _detect_serial_marker_capability * style: use non-capturing group for BASH version detection * fix(distribution): make PRETTY_SERIAL_MARKER reboot-safe * refactor: early returns in _detect_serial_marker_capability * fix(consoles): support newer x3270 versions * refactor: unconditionally import LLM analysis to fix coverage * feat(llm): integrate LLM analysis into isotovideo * feat(llm): add core LLM failure analysis module and tests - Update to version 5.1775569433.3681116: * fix(consoles): support newer x3270 versions * refactor: unconditionally import LLM analysis to fix coverage * feat(llm): integrate LLM analysis into isotovideo * feat(llm): add core LLM failure analysis module and tests * fix(t/34-git): make test resilient to default branch name changes * chore(AGENTS.md): extend with better proactive style following - Update to version 5.1774620706.b22e21b: * feat: Add option to add signatures * style: Add tool to add Mojo::Base include automatically * test: Add CoverageWorkaround.pm * test: Use Syntax::Keyword::Try::Deparse to avoid warnings * chore: Reduce permissions of remaining workflow * test: skip t/ files in Test::Compile syntax check * refactor: Deduplicate svirt tests in t/22-svirt.t - Update to version 5.1774551362.dd2a78c: * feat(svirt): add "stop_vm" in consoles::sshVirtsh * feat: correct isotovideo handle_shutdown log calls * refactor(consoles/sshVirtsh): properly concatenate remote_vmm * feat(svirt): retry disk create also in case of copy-img * chore: Reduce permissions of workflows * feat(VNC): Add AltGr key - Update to version 5.1774435114.41aff24: * style: Remove superfluous use of strict * git subrepo pull (merge) --force external/os-autoinst-common * Revert "style: Remove local Perl::Critic::Policy::HashKeyQuotes" * style: Remove local Perl::Critic::Policy::HashKeyQuotes * style: Add xt/02-perlcritic.t * style: Fix Community::WhileDiamondDefaultAssignment * style: Fix various no strict / no critic violations * style: Fix OpenQA::HashKeyQuotes * style: Fix OpenQA::SpaceAfterSubroutineName * style: Fix ProhibitConditionalDeclarations * style: Disable OpenQA::RedundantStrictWarning temporarily - Update to version 5.1774283485.5af53fe: * Revert "style: Remove local Perl::Critic::Policy::HashKeyQuotes" * style: Remove local Perl::Critic::Policy::HashKeyQuotes * style: Add xt/02-perlcritic.t * style: Fix Community::WhileDiamondDefaultAssignment * fix(ci): correct import of commit-message-checker * style: Fix various no strict / no critic violations * style: Fix OpenQA::HashKeyQuotes - Update to version 5.1774101470.e82b4cb: * feat: implement 'always_run' test flag * refactor: use gitlint from os-autoinst-common * git subrepo pull (merge) --force external/os-autoinst-common * feat(snd2png): restore erroneously deleted test * style: fix copyright in crop.py * chore: remove unused pyproject line * chore(deps): Add PPI to development dependencies * chore(snd2png): update test.png.md5.original based on current snd2png * test(full-stack): optimize execution time by reducing timeouts * feat(vnc): make connection retry sleep configurable * feat: add configurable secret key hiding support - Update to version 5.1773429030.ba0de6e: * fix: Correct number of internal test_count * chore(AGENTS.md): add customized file * chore(deps): add perl-Test-Perl-Critic dependency for parallel execution * fix: Remove logger message from else condition * style: Use single quotes for strings without interpolation * docs: convert doc/backend_vars.asciidoc to Markdown * docs: convert README.asciidoc to Markdown * docs: convert doc/memorydumps.asciidoc to Markdown * feat: add gitlint pre-commit setup - Update to version 5.1773327169.ae7c574: * chore(AGENTS.md): add customized file * chore(deps): add perl-Test-Perl-Critic dependency for parallel execution * chore(deps): Update perltidy * fix: Remove logger message from else condition * docs: convert doc/backend_vars.asciidoc to Markdown * docs: convert README.asciidoc to Markdown * docs: convert doc/memorydumps.asciidoc to Markdown * feat: add gitlint pre-commit setup - Update to version 5.1773245056.43fc8f0: * chore(deps): Update perltidy * fix: Remove logger message from else condition * style: Use single quotes for strings without interpolation * fix: restore author tests in CI and optimize git message check * docs: convert doc/backend_vars.asciidoc to Markdown - Update to version 5.1773054031.9ab699d: * chore(deps): Update perltidy * fix: Remove logger message from else condition * style: Use single quotes for strings without interpolation * fix: restore author tests in CI and optimize git message check * refactor: move scheduling rules out of basetest::is_applicable - Update to version 5.1772729929.93a4b15: * feat: normalize gre tunnel script for NetworkManager and wicked * refactor: use more Mojo::File operations in commands.pm * refactor: use more Mojo::File operations in bmwqemu.pm * refactor: use more Mojo::File operations in t/ * refactor: move scheduling rules out of basetest::is_applicable * feat: add EXIT_AFTER_MODULE to stop after a specified module - Update to version 5.1772663930.9a9bd7d: * feat: add EXIT_AFTER_MODULE to stop after a specified module * fix: Update gre_tunnel_preup script to support NetworkManager * feat: Handle timeout when typing command in `background_script_run` * feat: Allow opting-out of check when typing command in `script_run` * feat: Handle timeout when typing command in `script_run` * test: implement conventional commits check with gitlint - Update to version 5.1772097392.f4e2912: * fix: Update gre_tunnel_preup script to support NetworkManager * build(Makefile): add top-level help target * test: implement conventional commits check with gitlint * fix: Fix wrong uses of "checkout" that should be "check out" * git subrepo pull (merge) --force external/os-autoinst-common - Update to version 5.1771958644.63a1790: * build(Makefile): add top-level help target * test: implement conventional commits check with gitlint * fix: Fix wrong uses of "checkout" that should be "check out" * git subrepo pull (merge) --force external/os-autoinst-common * style: Fix crop.py style issues * parse_extra_log: Allow passing additional args to upload_logs - Update to version 5.1771858186.01b8328: * test: implement conventional commits check with gitlint * fix: Fix wrong uses of "checkout" that should be "check out" * git subrepo pull (merge) --force external/os-autoinst-common * style: Fix crop.py style issues * workaround: Remove "get_mempolicy" warning from qemu-img output - Update to version 5.1771520411.2601197: * fix: Fix wrong uses of "checkout" that should be "check out" * git subrepo pull (merge) --force external/os-autoinst-common * style: Fix crop.py style issues * workaround: Remove "get_mempolicy" warning from qemu-img output * parse_extra_log: Allow passing additional args to upload_logs - Update to version 5.1771353921.c8005c9: * git subrepo pull (merge) --force external/os-autoinst-common * style: Fix crop.py style issues * workaround: Remove "get_mempolicy" warning from qemu-img output * parse_extra_log: Allow passing additional args to upload_logs * refactor: Distinguish tests by the script path in `loadtest` * refactor: Simplify approach for avoiding redefine warnings - Update to version 5.1770715824.6a80a85: * style: Fix crop.py style issues * workaround: Remove "get_mempolicy" warning from qemu-img output * parse_extra_log: Allow passing additional args to upload_logs * refactor: Distinguish tests by the script path in `loadtest` * refactor: Simplify approach for avoiding redefine warnings * test: Allow running tests with `Test::Warnings<0.033` * test: Format test of `loadtestdir` in a more compact way - Update to version 5.1770127521.c249fe9: * refactor: Distinguish tests by the script path in `loadtest` * refactor: Simplify approach for avoiding redefine warnings * test: Allow running tests with `Test::Warnings<0.033` * test: Format test of `loadtestdir` in a more compact way * test: Use `ENABLE_MODERN_PERL_FEATURES=1` in test suite * feat: Allow enabling strict/warnings/signatures globally * fix: Improve wrong comment about enablement of modern Perl features - Update to version 5.1769602729.9728790: * fix: Improve wrong comment about enablement of modern Perl features * Replace remaining functions with subroutine signatures in 18-qemu.t * Fix snapshot overlay mechanism to avoid duplication * fix(dist): provide proper copyright headers in all spec-files * fix(dist): try to fix os-autoinst-obs-auto-submit reverting content * Remove deprecated BIOS and UEFI_PFLASH variables - Update to version 5.1769153586.72cabd0: * Replace remaining functions with subroutine signatures in 18-qemu.t * Fix snapshot overlay mechanism to avoid duplication * fix(dist): provide proper copyright headers in all spec-files * fix(dist): try to fix os-autoinst-obs-auto-submit reverting content * fix(dist): exclude unstable t/28-signalblocker.t in OBS checks * Add documentation of APPEND variable * Add undocumented KERNEL/INITRD to the supported variables * os-autoinst-generate-needle-preview: Embed PNG - Update to version 5.1768577300.b85e486: * fix(dist): provide proper copyright headers in all spec-files * fix(dist): try to fix os-autoinst-obs-auto-submit reverting content * fix(dist): exclude unstable t/28-signalblocker.t in OBS checks * Remove deprecated BIOS and UEFI_PFLASH variables * Add documentation of APPEND variable * os-autoinst-generate-needle-preview: Embed PNG - Update to version 5.1767893100.fd5003c: * Add documentation of APPEND variable * Add undocumented KERNEL/INITRD to the supported variables * os-autoinst-generate-needle-preview: Embed PNG * Tweak curl call not to hang * Fix opencv dependency due to upstream changes - Update to version 5.1767623406.688dd0e: * os-autoinst-generate-needle-preview: Embed PNG * Tweak curl call not to hang * Fix opencv dependency due to upstream changes * Restore package builds on older openSUSE versions * Remove `ShellCheck` from devel dependencies on s390x - Update to version 5.1766037062.44c7d2a: * Tweak curl call not to hang * Fix opencv dependency due to upstream changes * Restore package builds on older openSUSE versions * Remove `ShellCheck` from devel dependencies on s390x * Remove obsolete 'bin/' folder - Update to version 5.1765976654.0026f92: * Fix opencv dependency due to upstream changes * Restore package builds on older openSUSE versions * Remove `ShellCheck` from devel dependencies on s390x * Remove obsolete 'bin/' folder * Improve documentation strings for get/check_var - Update to version 5.1765808557.b89e9b4: * Restore package builds on older openSUSE versions * Remove `ShellCheck` from devel dependencies on s390x * Remove obsolete 'bin/' folder * Simplify the code to increment the counter * audio: Allow for multiple audio recordings per test - Update to version 5.1765804109.1e7c99a: * Remove `ShellCheck` from devel dependencies on s390x * Remove obsolete 'bin/' folder * Simplify the code to increment the counter * audio: Allow for multiple audio recordings per test * Improve documentation strings for get/check_var - Update to version 5.1765533145.a82864c: * Remove obsolete 'bin/' folder * Simplify the code to increment the counter * audio: Allow for multiple audio recordings per test * Improve documentation strings for get/check_var * Add port forwarding example for NICTYPE_USER_OPTIONS - Update to version 5.1765450253.f16e6ac: * Simplify the code to increment the counter * audio: Allow for multiple audio recordings per test * Improve documentation strings for get/check_var * Add port forwarding example for NICTYPE_USER_OPTIONS * Fix regression from abcaa66b by disabling virtio-keyboard by default * distribution: Add "disable_key_repeat" * Use 'virtio-keyboard' by default to allow fixing key repetition errors - Update to version 5.1765311639.7e3a762: * Simplify the code to increment the counter * audio: Allow for multiple audio recordings per test * Add port forwarding example for NICTYPE_USER_OPTIONS * Fix regression from abcaa66b by disabling virtio-keyboard by default * Add IPv6 support for multi machine tests - Update to version 5.1764330105.c5cfd48: * Add port forwarding example for NICTYPE_USER_OPTIONS * Fix regression from abcaa66b by disabling virtio-keyboard by default * Add IPv6 support for multi machine tests * distribution: Add "disable_key_repeat" * Use 'virtio-keyboard' by default to allow fixing key repetition errors - Update to version 5.1763561851.03e049d: * Avoid `Can't exec "ffmpeg"` if ffmpeg isn't present * Fix syntax errors in nft due to multiple interfaces in $ethernet * README: Feature auto-generated deepwiki less prominently * Install NetworkManager-ovs in os-autoinst-setup-multi-machine * Add disconnect_usb (qemu only, for now) - Update to version 5.1763048144.30f43a0: * Configure ftables in os-autoinst-setup-multi-machine * Makefile: Fix reruns on incomplete build dir generations * Propagate C++ exceptions to Perl in image write function * Add support NICPCIADDR variable to QEMU backend * Remove test which causes unhandled output * Improve includes in tinycv library * Handle OpenCV exceptions when writing an image * Avoid ignoring errors silently when writing images * Avoid saving test results referring to non-existent screenshots - Update to version 5.1762250353.5150272: * Makefile: Fix reruns on incomplete build dir generations * Propagate C++ exceptions to Perl in image write function * Add support NICPCIADDR variable to QEMU backend * Remove test which causes unhandled output * Allow array keys like `ISSUES[]` as introduced in openQA commit a53b19b * Improve includes in tinycv library - Update to version 5.1761723693.2b88807: * Propagate C++ exceptions to Perl in image write function * Add support NICPCIADDR variable to QEMU backend * Remove test which causes unhandled output * Allow array keys like `ISSUES[]` as introduced in openQA commit a53b19b * Improve includes in tinycv library * Handle OpenCV exceptions when writing an image * Avoid ignoring errors silently when writing images - Update to version 5.1761036042.c43e4ab: * Update perltidy * Allow redirects in needle NeedleDownloader * Don't overwrite firewall xml * Add UEFI support for ipxe kernel boot * os-autoinst-setup-multi-machine: Simplify determine_ethernet_interface - Update to version 5.1759328765.e7438f7: * Allow redirects in needle NeedleDownloader * Don't overwrite firewall xml * Add UEFI support for ipxe kernel boot * t: Use consistent Mojo::File in 08-autotest as well * os-autoinst-setup-multi-machine: Simplify determine_ethernet_interface - Update to version 5.1759134946.e08d7c7: * Add UEFI support for ipxe kernel boot * t: Use consistent Mojo::File in 08-autotest as well * os-autoinst-setup-multi-machine: Simplify determine_ethernet_interface * os-autoinst-setup-multi-machine: Only call zypper when necessary * os-autoinst-setup-multi-machine: Improve network interface check - Update to version 5.1758621990.22a2baa: * t: Use consistent Mojo::File in 08-autotest as well * os-autoinst-setup-multi-machine: Simplify determine_ethernet_interface * os-autoinst-setup-multi-machine: Only call zypper when necessary * os-autoinst-setup-multi-machine: Improve network interface check * Document max_interval (and quiet) in (assert_)script_run * testapi: allow passing max_interval through (assert_)script_run - Update to version 5.1758611445.fc0a714: * os-autoinst-setup-multi-machine: Only call zypper when necessary * os-autoinst-setup-multi-machine: Improve network interface check * Document max_interval (and quiet) in (assert_)script_run * testapi: allow passing max_interval through (assert_)script_run * t/consoles-s3270.t: fix with IPC::Run 20250809.0 - Update to version 5.1758276418.9dda31e: * Document max_interval (and quiet) in (assert_)script_run * testapi: allow passing max_interval through (assert_)script_run * t/consoles-s3270.t: fix with IPC::Run 20250809.0 * backend: Simplify json_fails collection with map * backend: Simplify check_socket with early-return * backend: Simplify do_capture by moving loop one level up - Update to version 5.1758095301.2731a7d: * testapi: allow passing max_interval through (assert_)script_run * t/consoles-s3270.t: fix with IPC::Run 20250809.0 * backend: Simplify json_fails collection with map * backend: Simplify check_socket with early-return * backend: Simplify do_capture by moving loop one level up * backend: Extract method for do_capture loop body * backend: Use more member variables in baseclass - Update to version 5.1757691610.477636b: * backend: Simplify json_fails collection with map * backend: Simplify check_socket with early-return * backend: Simplify do_capture by moving loop one level up * backend: Extract method for do_capture loop body * backend: Use more member variables in baseclass * backend: Extract function 'find_needles_with_tags' in baseclass * backend: Add missing text in svirt::die * t: Fix typos in 29-backend-svirt test strings - Update to version 5.1757357708.90c68ad: * backend: Add missing text in svirt::die * t: Fix typos in 29-backend-svirt test strings * Update perltidy * Add ping dependency to allow runtime IPv6 detection on workers * baseclass: Fix missing error details on failed SSH connection attempts * backend::svirt: Extract methods for serial_console command * backend::svirt: Extract method for serial_grab command * backend::svirt: Combine and simplify save_snapshot commands * backend::svirt: Extract method 'vmname' * backend::svirt: Extract methods for is_shutdown cmd * backend::svirt: Extract specific stop_vm methods - Update to version 5.1757071172.ffc94dc: * Add ping dependency to allow runtime IPv6 detection on workers * baseclass: Fix missing error details on failed SSH connection attempts * baseclass: Extend error details on failed ssh attempts * consoles: Improve error reporting on unavailable VNC * backend::svirt: Extract methods for serial_console command * backend::svirt: Extract method for serial_grab command * backend::svirt: Combine and simplify save_snapshot commands - Update to version 5.1756894972.736fbfd: * baseclass: Fix missing error details on failed SSH connection attempts * baseclass: Extend error details on failed ssh attempts * consoles: Improve error reporting on unavailable VNC * backend::svirt: Extract methods for serial_console command * backend::svirt: Extract method for serial_grab command * backend::svirt: Combine and simplify save_snapshot commands * backend::svirt: Extract method 'vmname' * backend::svirt: Extract methods for is_shutdown cmd - Update to version 5.1756120159.1bc0abb: * Fix signature of test module * VMWare: Use grep -F to handle fixed-strings in variables * VMWare: Use POSIX shell on ESXi host that uses Busybox * Add wrappers for testapi variables * backend: Turn off direct-io for multi-fd migration - Update to version 5.1755088400.98b9a6c: * VMWare: Use grep -F to handle fixed-strings in variables * VMWare: Use POSIX shell on ESXi host that uses Busybox * Add wrappers for testapi variables * backend: Turn off direct-io for multi-fd migration * backend: Use tpm-tis-device for TPM as default - Update to version 5.1754924817.84ae0ae: * VMWare: Use grep -F to handle fixed-strings in variables * VMWare: Use POSIX shell on ESXi host that uses Busybox * Add wrappers for testapi variables * backend: Use tpm-tis-device for TPM as default * Require openssh-clients for git clone with ssh * t: use mock not redefine for lua_set * t: make autotest tests pass if lua and/or python are missing - Update to version 5.1754492266.4c80bae: * Add wrappers for testapi variables * backend: Use tpm-tis-device for TPM as default * Require openssh-clients for git clone with ssh * Avoid running `$basetest->parse_serial_output_qemu` without checks * t: use mock not redefine for lua_set * setup-multi-machine: extend network service detection - Update to version 5.1753993900.1487e47: * backend: Use tpm-tis-device for TPM as default * Require openssh-clients for git clone with ssh * Avoid running `$basetest->parse_serial_output_qemu` without checks * t: use mock not redefine for lua_set * t: make autotest tests pass if lua and/or python are missing - Update to version 5.1753467593.10e57cf: * Require openssh-clients for git clone with ssh * Avoid running `$basetest->parse_serial_output_qemu` without checks * t: use mock not redefine for lua_set * t: make autotest tests pass if lua and/or python are missing * setup-multi-machine: extend network service detection * Autodetect default ethernet dev/br in os-autoinst-setup-multi-machine * Fix category generation for paths to lua test modules - Update to version 5.1752671185.6fc0c66: * Avoid running `$basetest->parse_serial_output_qemu` without checks * t: use mock not redefine for lua_set * t: make autotest tests pass if lua and/or python are missing * setup-multi-machine: extend network service detection * CI: Enable Leap 16.0 OBS build checks - Update to version 5.1752576096.2a4e8ff: * Avoid running `$basetest->parse_serial_output_qemu` without checks * setup-multi-machine: extend network service detection * CI: Enable Leap 16.0 OBS build checks * Autodetect default ethernet dev/br in os-autoinst-setup-multi-machine * Fix category generation for paths to lua test modules - Update to version 5.1752222511.9791c75: * setup-multi-machine: extend network service detection * CI: Enable Leap 16.0 OBS build checks * Autodetect default ethernet dev/br in os-autoinst-setup-multi-machine * Fix category generation for paths to lua test modules * Update Perl::Tidy to 20250616.0.0 - Update to version 5.1751897761.d55ec72: * CI: Enable Leap 16.0 OBS build checks * Autodetect default ethernet dev/br in os-autoinst-setup-multi-machine * Fix category generation for paths to lua test modules * Update Perl::Tidy to 20250616.0.0 * Workaround coverage issue * Rename `$mock_main` to `$mock_ovs` in OVS unit test * Extend logging in OVS service to debug its occasional unresponsiveness - Update to version 5.1751470028.ff900af: * Autodetect default ethernet dev/br in os-autoinst-setup-multi-machine * Fix category generation for paths to lua test modules * Update Perl::Tidy to 20250616.0.0 * generalhw: fix is_shutdown signature * Workaround coverage issue - Update to version 5.1751292366.cb60853: * Fix category generation for paths to lua test modules * Update Perl::Tidy to 20250616.0.0 * generalhw: fix is_shutdown signature * Workaround coverage issue * Rename `$mock_main` to `$mock_ovs` in OVS unit test * Extend logging in OVS service to debug its occasional unresponsiveness - Update to version 5.1750841733.3fc0bf7: * Update Perl::Tidy to 20250616.0.0 * generalhw: fix is_shutdown signature * Workaround coverage issue * Rename `$mock_main` to `$mock_ovs` in OVS unit test * Extend logging in OVS service to debug its occasional unresponsiveness * VMWare-related code made compatible with non-GNU ps - Update to version 5.1750149141.e9a7b3a: * generalhw: fix is_shutdown signature * Workaround coverage issue * Rename `$mock_main` to `$mock_ovs` in OVS unit test * Extend logging in OVS service to debug its occasional unresponsiveness * Support Wait() timeout message from newer versions of x3270 * VMWare-related code made compatible with non-GNU ps - Update to version 5.1750077297.e0e64ba: * generalhw: fix is_shutdown signature * Support Wait() timeout message from newer versions of x3270 * VMWare-related code made compatible with non-GNU ps * Fix error from stricter Git permission checks when checking repo URL * VMware new routine provide_image_vmware_in_ds * ci: Remove workaround for Devel::Cover * Require Inline::Lua * Add support for lua test modules * Use CPAN module Test::CheckGitStatus * Apply macro to support upcoming opensuse/sle 16 build * Add dependency perl-Test-CheckGitStatus - Update to version 5.1749816802.bfdf10e: * Support Wait() timeout message from newer versions of x3270 * VMWare-related code made compatible with non-GNU ps * Fix error from stricter Git permission checks when checking repo URL * generalhw: implement is_shutdown * doc: Fix casing in GENERAL_HW_* descriptions - Update to version 5.1749203452.c6860a3: * generalhw: implement is_shutdown * doc: Fix casing in GENERAL_HW_* descriptions * VMware new routine provide_image_vmware_in_ds * ci: Remove workaround for Devel::Cover * Use CPAN module Test::CheckGitStatus * Apply macro to support upcoming opensuse/sle 16 build * Add dependency perl-Test-CheckGitStatus * t: Catch output in 23-baseclass.t * ci: Ensure 100% coverage without threshold * Fix coverage for package statements * Create link to the common prove_wrapper * Sync os-autoinst-common with the subrepo external/os-autoinst-common * Handle unhandled output from qemu and openvswitch tests * Mitigate perl version mismatch on test case * Try to increase pipe size for external video encoder * Avoid warning about uninitialized value * video_stream: add RGB<->BGR swapping support * t: fix frame format used in video_stream * video_stream: use ustreamer --persistent * tinycv: scale starting search position if size is different * Avoid sporadic test failures of fullstack test * Wrap prove to prevent unhandled output - Update to version 5.1748859519.44e4a9e: * ci: Remove workaround for Devel::Cover * Require Inline::Lua * Add support for lua test modules * Use CPAN module Test::CheckGitStatus * Apply macro to support upcoming opensuse/sle 16 build - Update to version 5.1747913329.a855b3a: * t: Catch output in 23-baseclass.t * ci: Ensure 100% coverage without threshold * Fix coverage for package statements * Create link to the common prove_wrapper * Sync os-autoinst-common with the subrepo external/os-autoinst-common * Try to increase pipe size for external video encoder * Avoid warning about uninitialized value * video_stream: add RGB<->BGR swapping support * t: fix frame format used in video_stream * video_stream: use ustreamer --persistent * tinycv: scale starting search position if size is different * Avoid sporadic test failures of fullstack test openQA-5.1782486535.1bf71ec4-bp157.2.9.1.src.rpm openQA-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-auto-update-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-bootstrap-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-client-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-client-bash-completion-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-client-zsh-completion-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-common-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-continuous-update-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-doc-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-llm-server-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-local-db-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-mcp-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-munin-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-python-scripts-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-single-instance-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-single-instance-nginx-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-worker-5.1782486535.1bf71ec4-bp157.2.9.1.x86_64.rpm openQA-client-test-5.1782486535.1bf71ec4-bp157.2.9.1.src.rpm openQA-test-5.1782486535.1bf71ec4-bp157.2.9.2.src.rpm openQA-worker-test-5.1782486535.1bf71ec4-bp157.2.9.2.src.rpm os-autoinst-5.1782809557.0ae98f8-bp157.2.3.1.src.rpm os-autoinst-5.1782809557.0ae98f8-bp157.2.3.1.x86_64.rpm os-autoinst-debuginfo-5.1782809557.0ae98f8-bp157.2.3.1.x86_64.rpm os-autoinst-debugsource-5.1782809557.0ae98f8-bp157.2.3.1.x86_64.rpm os-autoinst-openvswitch-5.1782809557.0ae98f8-bp157.2.3.1.x86_64.rpm os-autoinst-qemu-kvm-5.1782809557.0ae98f8-bp157.2.3.1.x86_64.rpm os-autoinst-qemu-x86-5.1782809557.0ae98f8-bp157.2.3.1.x86_64.rpm os-autoinst-swtpm-5.1782809557.0ae98f8-bp157.2.3.1.x86_64.rpm os-autoinst-openvswitch-test-5.1782809557.0ae98f8-bp157.2.3.1.src.rpm os-autoinst-test-5.1782809557.0ae98f8-bp157.2.3.1.src.rpm openQA-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-auto-update-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-bootstrap-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-client-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-client-bash-completion-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-client-zsh-completion-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-common-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-continuous-update-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-doc-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-llm-server-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-local-db-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-mcp-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-munin-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-python-scripts-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-single-instance-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-single-instance-nginx-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm openQA-worker-5.1782486535.1bf71ec4-bp157.2.9.1.aarch64.rpm os-autoinst-5.1782809557.0ae98f8-bp157.2.3.1.aarch64.rpm os-autoinst-debuginfo-5.1782809557.0ae98f8-bp157.2.3.1.aarch64.rpm os-autoinst-debugsource-5.1782809557.0ae98f8-bp157.2.3.1.aarch64.rpm os-autoinst-openvswitch-5.1782809557.0ae98f8-bp157.2.3.1.aarch64.rpm os-autoinst-swtpm-5.1782809557.0ae98f8-bp157.2.3.1.aarch64.rpm openQA-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-auto-update-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-bootstrap-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-client-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-client-bash-completion-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-client-zsh-completion-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-common-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-continuous-update-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-doc-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-llm-server-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-local-db-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-mcp-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-munin-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-python-scripts-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-single-instance-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-single-instance-nginx-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm openQA-worker-5.1782486535.1bf71ec4-bp157.2.9.1.ppc64le.rpm os-autoinst-5.1782809557.0ae98f8-bp157.2.3.1.ppc64le.rpm os-autoinst-debuginfo-5.1782809557.0ae98f8-bp157.2.3.1.ppc64le.rpm os-autoinst-debugsource-5.1782809557.0ae98f8-bp157.2.3.1.ppc64le.rpm os-autoinst-openvswitch-5.1782809557.0ae98f8-bp157.2.3.1.ppc64le.rpm os-autoinst-swtpm-5.1782809557.0ae98f8-bp157.2.3.1.ppc64le.rpm openQA-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-auto-update-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-bootstrap-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-client-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-client-bash-completion-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-client-zsh-completion-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-common-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-continuous-update-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-doc-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-llm-server-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-local-db-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-mcp-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-munin-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-python-scripts-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-single-instance-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-single-instance-nginx-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm openQA-worker-5.1782486535.1bf71ec4-bp157.2.9.1.s390x.rpm os-autoinst-5.1782809557.0ae98f8-bp157.2.3.1.s390x.rpm os-autoinst-debuginfo-5.1782809557.0ae98f8-bp157.2.3.1.s390x.rpm os-autoinst-debugsource-5.1782809557.0ae98f8-bp157.2.3.1.s390x.rpm os-autoinst-openvswitch-5.1782809557.0ae98f8-bp157.2.3.1.s390x.rpm os-autoinst-swtpm-5.1782809557.0ae98f8-bp157.2.3.1.s390x.rpm openSUSE-2026-224 Security update for cadvisor important openSUSE Backports SLE-15-SP7 Update This update for cadvisor fixes the following issues: - CVE-2026-39821: Update golang.org/x/net/idna reference (boo#1266645). - CVE-2026-33186: Update google.golang.org/grpc reference (boo#1260305). - CVE-2024-45310: Update github.com/opencontainers/runc/libcontainer/utils reference (boo#1257429). - CVE-2026-10722: Update github.com/cilium/ebpf reference (boo#1267788). cadvisor-0.60.3-bp157.2.3.1.src.rpm cadvisor-0.60.3-bp157.2.3.1.x86_64.rpm cadvisor-0.60.3-bp157.2.3.1.i586.rpm cadvisor-0.60.3-bp157.2.3.1.aarch64.rpm cadvisor-0.60.3-bp157.2.3.1.ppc64le.rpm cadvisor-0.60.3-bp157.2.3.1.s390x.rpm openSUSE-2026-226 Feature update for docker-compose moderate openSUSE Backports SLE-15-SP7 Update This update for docker-compose fixes the following issues: - Update to version 5.2.0: This version introduces a new reconciliation algorithm between the observed state and the expected state. If you experience any issues with a Compose workload that was previously working, please open an issue. * Improvements - Reconciliation plan by @ndeloof & @glours in #13830 - Add rawsetenv message type for provider plugins by @rajyan in #13742 * Fixes - Fix(build): skip remote URL contexts from bake fs.read allowlist by @ndeloof in #13816 - Skip validation when extracting config variables by @scarab-systems in #13831 - Fix(progress): probe stderr (not stdout) for TTY auto-detection by @glours in #13837 - Fix(publish): honor env_file required: false for missing files by @Ijtihed in #13848 * Internal - Docs: compose logs: add links for since/until flag descriptions by @thaJeztah in #13806 - Ci: add Dependabot cooldown (20260603-170456) by @securityeng-bot[bot] in #13820 - Docs(CLAUDE.md): note that commits must be signed off (DCO) by @ndeloof in #13817 - Refactor: replace Split in loops with more efficient SplitSeq and replace HasPrefix+TrimPrefix with CutPrefix by @caltechustc in #13810 - Chore: fix some comments to improve readability by @solunolab in #13823 - GHA: update docs-upstream to pin workflows by sha by @thaJeztah in #13834 - Docs: compose logs: add more links for flag descriptions by @thaJeztah in #13833 - Fix/progress tty line overflow 13595 by @glours in #13840 - Fix(publish): bypass Docker Desktop proxy for loopback registries by @ptrdom in #13825 - Watch: do not rebuild depends_on services on file change by @ndeloof in #13856 - pkg/e2e: fix malformed JWT in fixtures by @thaJeztah in #13857 - pkg/e2e: drop unused run param from getEnv by @glours in #13867 - Docs: ps --format json outputs JSON Lines, not a JSON array by @glours in #13868 * Dependencies - Build(deps): bump github.com/docker/cli from 29.5.1+incompatible to 29.5.2+incompatible by @dependabot[bot] in #13802 - Update to go 1.26.4 by @thaJeztah in #13828 - Chore(deps): github.com/containerd/typeurl/v2 v2.3.0 by @thaJeztah in #13829 - Build(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 by @dependabot[bot] in #13838 - Chore(deps): github.com/docker/cli v29.5.3, github.com/docker/buildx v0.34.1, buildkit v0.30.0 by @thaJeztah in #13841 - Build(deps): bump golang.org/x/sys from 0.45.0 to 0.46.0 by @dependabot[bot] in #13832 - Chore(deps): golang.org/x/crypto v0.53.0 by @thaJeztah in #13844 - Build(deps): bump github.com/containerd/containerd/v2 from 2.2.3 to 2.2.4 in the go_modules group across 1 directory by @dependabot[bot] in #13804 - Chore(deps): bump github.com/containerd/containerd/v2 to v2.2.5 by @thaJeztah in #13855 - Chore(deps): bump github.com/golang-jwt/jwt/v5 to v5.3.1 by @thaJeztah in #13847 - Chore(deps): github.com/docker/cli v29.6.0, github.com/docker/buildx v0.35.0, buildkit v0.31.0 by @thaJeztah in #13842 - Bump compose-go to version v2.12.1 by @glours in #13865 docker-compose-5.2.0-bp157.2.3.1.src.rpm docker-compose-5.2.0-bp157.2.3.1.x86_64.rpm docker-compose-5.2.0-bp157.2.3.1.i586.rpm docker-compose-5.2.0-bp157.2.3.1.aarch64.rpm docker-compose-5.2.0-bp157.2.3.1.ppc64le.rpm docker-compose-5.2.0-bp157.2.3.1.s390x.rpm openSUSE-2026-225 Security update for keybase-client important openSUSE Backports SLE-15-SP7 Update This update for keybase-client fixes the following issues: - CVE-2026-46604: TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset (boo#1269600) kbfs-6.6.3-bp157.2.9.1.x86_64.rpm kbfs-git-6.6.3-bp157.2.9.1.x86_64.rpm kbfs-tool-6.6.3-bp157.2.9.1.x86_64.rpm keybase-client-6.6.3-bp157.2.9.1.src.rpm keybase-client-6.6.3-bp157.2.9.1.x86_64.rpm kbfs-6.6.3-bp157.2.9.1.i586.rpm kbfs-git-6.6.3-bp157.2.9.1.i586.rpm kbfs-tool-6.6.3-bp157.2.9.1.i586.rpm keybase-client-6.6.3-bp157.2.9.1.i586.rpm kbfs-6.6.3-bp157.2.9.1.aarch64.rpm kbfs-git-6.6.3-bp157.2.9.1.aarch64.rpm kbfs-tool-6.6.3-bp157.2.9.1.aarch64.rpm keybase-client-6.6.3-bp157.2.9.1.aarch64.rpm kbfs-6.6.3-bp157.2.9.1.ppc64le.rpm kbfs-git-6.6.3-bp157.2.9.1.ppc64le.rpm kbfs-tool-6.6.3-bp157.2.9.1.ppc64le.rpm keybase-client-6.6.3-bp157.2.9.1.ppc64le.rpm kbfs-6.6.3-bp157.2.9.1.s390x.rpm kbfs-git-6.6.3-bp157.2.9.1.s390x.rpm kbfs-tool-6.6.3-bp157.2.9.1.s390x.rpm keybase-client-6.6.3-bp157.2.9.1.s390x.rpm openSUSE-2026-240 Security update for perl-CGI-Session moderate openSUSE Backports SLE-15-SP7 Update This update for perl-CGI-Session fixes the following issues: - updated to 4.490.0 (4.49) see /usr/share/doc/packages/perl-CGI-Session/Changelog.ini * SECURITY: Strengthen cryptographic randomness of MD5 driver, CVE-2026-56016 (boo#1269983) - Normalize CPAN version See https://github.com/openSUSE/cpanspec/issues/47 for details perl-CGI-Session-4.490.0-bp157.2.3.1.noarch.rpm perl-CGI-Session-4.490.0-bp157.2.3.1.src.rpm openSUSE-2026-229 Recommended update for perl-Crypt-SysRandom moderate openSUSE Backports SLE-15-SP7 Update This update for perl-Crypt-SysRandom fixes the following issues: Introduce perl-Crypt-SysRandom. perl-Crypt-SysRandom-0.7.0-bp157.2.1.noarch.rpm perl-Crypt-SysRandom-0.7.0-bp157.2.1.src.rpm openSUSE-2026-236 Recommended update for hugo moderate openSUSE Backports SLE-15-SP7 Update This update for hugo fixes the following issues: - Update to version 0.163.1 (boo#1269014, boo#1269015): * releaser: Bump versions for release of 0.163.1 * build(deps): bump golang.org/x/image from 0.41.0 to 0.42.0 * Fix multi --renderSegments merge behavior * security: Normalize integer IPv4 host encodings in http.urls check * Drop symlinks in os.ReadDir, os.ReadFile, os.Stat and os.FileExists * Update CI workflow to exclude macOS * commands: Fix convert command * releaser: Prepare repository for 0.164.0-DEV * releaser: Bump versions for release of 0.163.0 * pagesfromdata: Use relative path for content adapter template metrics * ci: Re-add macos-latest to the test matrix * build(deps): bump github.com/bits-and-blooms/bitset * build(deps): bump github.com/tetratelabs/wazero * all: Run go fix ./... * images: Deprecate Imaging.Compression and move it down to webp and avif configs * Only support the latest Go version * resources/jsconfig: Remove deprecated baseUrl setting * build(deps): bump github.com/rogpeppe/go-internal from 1.14.1 to 1.15.0 * page: Add IsBranch and deprecate IsNode * images: Force cache invalidation for AVIF target * images: Add a per-format AVIF hint setting * build(deps): bump github.com/getkin/kin-openapi from 0.138.0 to 0.139.0 * images: Make AVIF chroma subsampling content-aware via the hint * Cap AVIF lossy quality at 99 * config: Deprecate the glogal imaging quality setting * images: Make 60 the default quality for AVIF * livereload: Disconnect from websocket server on pageswap * tpl/tplimpl/embedded: Prevent leading newline in sitemap template * images: Recover from memory alloc errors in WASM image processors * images: Add quality setting per image format * all: Adjust tests for deprecated link and image render hook settings * misc: Remove duplicate words in comments * Add some PNG to AVIF golden test cases * releaser: Prepare repository for 0.163.0-DEV * releaser: Bump versions for release of 0.162.1 * modules/npm: Fix false stale warning after npm pack * tpl/tplimpl: Fix X shortcode test * tpl: Skip broken x shortcode test * Revert "tpl/collections: Make dict return nil when no values are provided" * tpl/time: Fix locale-specific month abbreviations * releaser: Bump versions for release of 0.162.0 * Disallow HTML content by default * Add image processing support for AVIF * config: Preserve intentionally empty maps * hugolib: Fix Page.GitInfo for modules with go.mod in a repo subdirectory * hugolib: Merge existing hugo_stats.json when renderSegments is set * all: Replace RWMutex struct caches with ConcurrentMap * tpl/tplimpl: Consolidate and improve embedded template integration tests * parser: Drop empty sub maps from hugo config output * markup/highlight: Allow overriding type and code via options * Fix typo in CONTRIBUTING.md * Remove note on refactoring contributions * Update AI assistance disclosure requirements * build(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 * build(deps): bump golang.org/x/image from 0.40.0 to 0.41.0 * hugolib: Use AllTranslated in IsTranslated * tpl: Simplify sitemap template * tpl: Use AllTranslations in sitemap template * tpl/collections: Make dict return nil when no values are provided * Sync Go template package to 1.26.3 * Squashed 'docs/' changes from 0755fb534d..1f8ddb8a52 * resources: Fix the :counter placeholder * Upgrade to Go 1.26.3 * ci: Check embedded template formatting with gotmplfmt * tpl: Run gotmplfmt -w . * build(deps): bump github.com/getkin/kin-openapi from 0.137.0 to 0.138.0 * build(deps): bump github.com/JohannesKaufmann/html-to-markdown/v2 * markup/goldmark/codeblocks: Always split Chroma options into .Options * docs: Update docs.yaml * hugolib: Allow empty params front matter * commands: Fix import from Jekyll * common/hmaps: Merge slice-valued module config into site config * build(deps): bump golang.org/x/image from 0.39.0 to 0.40.0 * tpl: Use GetMatch for both local and global image resources * Revert "markup/tableofcontents: Skip empty TOC levels" * build(deps): bump golang.org/x/tools from 0.44.0 to 0.45.0 * tpl/templates: Reject Defer inside partialCached * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 * common/hexec: Make NODE_PATH a fallback for ESM bare imports * build(deps): bump github.com/pelletier/go-toml/v2 from 2.3.0 to 2.3.1 * config: Allow repeating the root key in /config files * Revise test naming guidelines in AGENTS.md * Update AGENTS.md * js: Return error for missing batch imports * resources/images: Keep smart crop target size * testing: Use synctest where relevant * Fix prevention of direct symlink reads in resources.Get * security: Validate redirects against security.http.urls * markup/tableofcontents: Skip empty TOC levels * Fall back to hugo.buildDate in hugo.BuildDate() in non-vcs builds * agents: Add a note to Ai security researchers * deps: Upgrade to Chroma v2.24.1 * commands: Fix github-dark chromastyles * css: Make css.Build's file-loader URLs absolute to web context root * hugolib: Don't warn about lang/kind/path coming from cascade.params * markup/goldmark: Unwrap inner HTML for plain code blocks * tpl/tplimpl: Extend page image lookup to include global resources * security: Allow hostnames starting with digits in default http.urls * commands: Improve description of command flags * releaser: Prepare repository for 0.162.0-DEV - update to 0.161.1: * resources: Honor Retry-After header in resources.GetRemote retries c4eba928 @bep #14828 * warpc: Move to parson.c in https://github.com/kgabis/parson 8b40a96b @bep #14823 * config/security: Add AllowChildProcess to security.node.permissions d65af84d @bep #14824 * config/security: Restrict default http.urls "@" deny to userinfo 454450a6 @bep #14825 - update to 0.161.0: * This release contains two security hardening fixes: * We now run the Node tools PostCSS, Babel and TailwindCSS, by default, with the `--permission` flag with the permissions defined in security.node.permissions. This means that you need Node >= 22 installed and that `css.TailwindCSS` now requires that the Tailwind CSS CLI must be installed as a Node.js package. The standalone executable is no longer supported * We have made the defaults in security.http.urls more restrictive. - update to 0.160.1: * Fix panic when passthrough elements are used in headings 8b00030b @bep #14677 * Fix panic on edit of legacy mapped template names that's also a valid path in the new setup c4855167 @bep #14740 * Fix RenderShortcodes leaking context markers when indented 161d0d47 @bep #12457 * Strip nested page context markers from standalone RenderShortcodes 45e45966 @bep #14732 * Rename deprecated cascade._target to cascade.target in tests 58927aa1 @bep * Fix auto-creation of root sections in multilingual sites ce009e3a @bep #14681 * readme: Fix links 07558724 @chicks-net - Update to version 0.161.1: * releaser: Bump versions for release of 0.161.1 * resources: Honor Retry-After header in resources.GetRemote retries * warpc: Move to parson.c in https://github.com/kgabis/parson * config/security: Add AllowChildProcess to security.node.permissions * config/security: Restrict default http.urls "@" deny to userinfo * releaser: Prepare repository for 0.162.0-DEV * releaser: Bump versions for release of 0.161.0 * build(deps): bump github.com/getkin/kin-openapi from 0.135.0 to 0.137.0 * build(deps): bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22 * build(deps): bump github.com/tdewolff/minify/v2 from 2.24.12 to 2.24.13 * css: Support nested hugo:vars/<name> imports * github: Update GitHub actions versions * hugolib: Do not render aliases if the page is not rendered * langs/i18n: Improve default content language fallback * Replace deprecated .Site.Sites/.Page.Sites with hugo.Sites intests * helpers: Remove unused code * common/constants: Remove unused consts * common/paths: Remove unused code * langs/i18n: Fix translation lookup when using language variants * tests: Update Ruby setup action to v1.305.0 * build(deps): bump github.com/magefile/mage from 1.17.1 to 1.17.2 * deps: Upgrade github.com/bep/imagemeta v0.17.1 => v0.17.2 * langs: Use Language.Locale as primary localization key * config/security: Add "! " negation to Whitelist, harden default http.urls * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront (#14789) * build(deps): bump github.com/mattn/go-isatty from 0.0.20 to 0.0.21 (#14788) * build(deps): bump github.com/bep/mclib (#14787) * Harden Node tool execution with --permission flag * tpl/collections: Honor the Eqer interface in where comparisons * build(deps): bump google.golang.org/api from 0.267.0 to 0.276.0 * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.41.5 to 1.41.6 * modules: Ignore non-require blocks in go.mod rewrite * Replace the concurrent map with an identical upstream version * build(deps): bump github.com/getkin/kin-openapi from 0.134.0 to 0.135.0 (#14781) * build(deps): bump github.com/bep/goportabletext from 0.1.0 to 0.2.0 (#14779) * build(deps): bump golang.org/x/image from 0.38.0 to 0.39.0 (#14780) * deps: Upgrade github.com/bep/imagemeta v0.17.0 => v0.17.1 (#14775) * Add slice-based permalinks config with PageMatcher target * commands: Add missing import * Revert "common/hugo: Deprecate extended and extended_withdeploy editions" * Adjust the SECURITY.md slightly * create: Fix non-deterministic conflict detection in hugo new content * build(deps): bump golang.org/x/tools from 0.43.0 to 0.44.0 * resources/page: Add passing test for Issue #14325 * agents: Add a note about having the issue ID in test names * commands: Fix environment isolation for configuration settings * build(deps): bump github.com/evanw/esbuild from 0.27.4 to 0.28.0 * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.41.1 to 1.41.5 * build(deps): bump github.com/pelletier/go-toml/v2 from 2.2.4 to 2.3.0 * build(deps): bump github.com/tdewolff/minify/v2 from 2.24.11 to 2.24.12 * Fix filename dimension identifiers (_role_X_, _version_X_) to replace mount config * Add a more flexible filename identifier scheme that also allows setting roles and versions (#14754) * Fix it so we never auto-fallback to page resources in other roles/versions * common/hugo: Deprecate extended and extended_withdeploy editions * parser/pageparser: Add a parser fuzz test * releaser: Bump versions for release of 0.160.1 * Fix panic when passthrough elements are used in headings * Fix panic on edit of legacy mapped template names that's also a valid path in the new setup * Fix RenderShortcodes leaking context markers when indented * Strip nested page context markers from standalone RenderShortcodes * Rename deprecated cascade._target to cascade.target in tests * Fix auto-creation of root sections in multilingual sites * readme: Fix links * releaser: Prepare repository for 0.161.0-DEV - Update to version 0.160.0: * releaser: Bump versions for release of 0.160.0 * build(deps): bump github.com/magefile/mage from 1.16.1 to 1.17.1 * Fix some recently introduced Position issues * markup/goldmark: Fix double-escaping of ampersands in link URLs * all: Replace NewIntegrationTestBuilder with Test/TestE/TestRunning * tpl: Fix stray quotes from partial decorator in script context * readme: Revise edition descriptions and installation instructions * build(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 * tpl/css: Support @import "hugo:vars" for CSS custom properties in css.Build * Improve and extend .Position handling in Goldmark render hooks * build(deps): bump golang.org/x/image from 0.37.0 to 0.38.0 * markup/goldmark: Clean up test * releaser: Prepare repository for 0.160.0-DEV - Update to version 0.159.2: * releaser: Bump versions for release of 0.159.2 * Fix potential content XSS by escaping dangerous URLs in links and images * releaser: Add standard withdeploy release assets * resources/page: Fix shared reader in Source.ValueAsOpenReadSeekCloser * testing: Simplify line ending handling in tests * readme: Update Go version to 1.25.0 * releaser: Prepare repository for 0.160.0-DEV - Update to version 0.159.1: * releaser: Bump versions for release of 0.159.1 * minifiers: Keep x-bind and blank namespace in SVG minification * Adjust depreceated syntax in tests * releaser: Prepare repository for 0.160.0-DEV - Update to version 0.159.0: * releaser: Bump versions for release of 0.159.0 * docs: Update docs.yaml * Squashed 'docs/' changes from 80dd7b067..0755fb534 * commands: Update docs linke to Node.js docs * create: Return error instead of panic when page not found * commands: Preserve non-content files in convert output * npm: Use workspaces to simplify `hugo mod npm pack` * build(deps): bump github.com/olekukonko/tablewriter from 1.1.3 to 1.1.4 (#14641) * commands: Close cpu profile file when StartCPUProfile fails * Replace deprecated site.Data with hugo.Data in tests * Replace deprecated excludeFiles and includeFiles with files in tests * build(deps): bump github.com/yuin/goldmark from 1.7.16 to 1.7.17 * build(deps): bump github.com/magefile/mage from 1.15.0 to 1.16.1 * build(deps): bump golang.org/x/image from 0.36.0 to 0.37.0 * build(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 * tpl/tplimpl: Fix Vimeo shortcode test * Remove the AI Watchdog workflow for now * Remove 'bep' from PR user logins skip list * tpl/tplimpl: Comment out the Vimeo simple shortcode tests * Replace deprecated :filename with :contentbasename in the permalinks test * releaser: Prepare repository for 0.159.0-DEV - Update to version 0.158.0: * releaser: Bump versions for release of 0.158.0 * deps: Upgrade github.com/evanw/esbuild v0.27.3 => v0.27.4 * build(deps): bump github.com/getkin/kin-openapi from 0.133.0 to 0.134.0 * build(deps): bump golang.org/x/tools from 0.42.0 to 0.43.0 * resources: Re-publish on transformation cache hit * create/skeletons: Use css.Build in theme skeleton * tpl/css: Add a test case for rebuilds on CSS options changes * hugolib: Allow regular pages to cascade to self * build(deps): bump gocloud.dev from 0.44.0 to 0.45.0 * build(deps): bump golang.org/x/sync from 0.19.0 to 0.20.0 * tpl/css: Allow the user to override single loader entries * tpl/css: Fix external source maps * tpl/css: Make default loader resolution for CSS @import and url() always behave the same * hugolib: Fix server no watch * internal/js: Add default mainFields for CSS builds * Add css.Build * Upgrade to to Go 1.26.1 (#14597) (note) * resources: Fix context canceled on GetRemote with per-request timeout * resources: Use full path for Exif etc. decoding error/warning messages * Move to new locales library and upgrade CLDR from v36.1 to v48.1 * tpl/tplimpl: Prefer early suffixes when media type matches * tpl/strings: Add strings.ReplacePairs function * all: Run go fix ./... * internal/warpc: Fix SIGSEGV in Close() when dispatcher fails to start * github: Remove pull_request_template.md * testing: Make commands tests pass in Go 1.26.1 * refactor: Deprecate language configuration and template methods * Replace Exif with Meta in tests * build(deps): bump golang.org/x/net from 0.50.0 to 0.51.0 (#14569) * build(deps): bump github.com/tdewolff/minify/v2 from 2.24.9 to 2.24.10 (#14585) * build(deps): bump github.com/bep/imagemeta from 0.15.0 to 0.17.0 (#14584) * Fix index out of range panic in fileEventsContentPaths * resources: Improve getImageOps error message * resources/images: Add IsImageResourceWithMeta etc. tests for bmp and gif * releaser: Prepare repository for 0.158.0-DEV - Packaging improvements: * Update to BuildRequires: golang(API) >= 1.25 matching go.mod - Update to version 0.157.0: * releaser: Bump versions for release of 0.157.0 * Fix menu pageRef resolution in multidimensional setups * Handle GitInfo for modules where Origin is not set when running go list * commands: Update link to highlighting style examples * docs: Regen and fix the imaging docshelper output * Squashed 'docs/' changes from 42914c50e..80dd7b067 * Add AVIF, HEIF and HEIC partial support (only metadata for now) * resources/images: Adjust WebP processing defaults * Add Page.GitInfo support for content from Git modules * Add per-request timeout option to `resources.GetRemote` * Update AI Watchdog action version in workflow * build(deps): bump github.com/tdewolff/minify/v2 from 2.24.8 to 2.24.9 * build(deps): bump github.com/bep/imagemeta from 0.14.0 to 0.15.0 * config: Skip taxonomy entries with empty keys or values * Add guideline for brevity in code and comments * modules: Include JSON error info from go mod download in error messages * hugolib: Fix automatic section pages not replaced by sites.complements * releaser: Prepare repository for 0.157.0-DEV - Update to version 0.156.0: * releaser: Bump versions for release of 0.156.0 * hugolib: Move site.Data to hugo.Data, deprecate Site.AllPages/BuildDrafts/Languages * build(deps): bump google.golang.org/api from 0.255.0 to 0.267.0 * hugolib: Add Page.Sites to Site.Sites deprecation notice * hugolib: Simplify sites collection * hugolib: Adjust hugo.Sites.Default * Move common/hugo/HugoInfo to resources/page * commands: Fix --panicOnWarning flag having no effect with module version warnings * hugolib: Add hugo.Sites and .Site.IsDefault(), modify .Site.Sites * build(deps): bump github.com/bep/textandbinarywriter * paths: Fix handling of _ as a path name * output: Remove unused method * build(deps): bump github.com/bep/simplecobra from 0.6.1 to 0.7.0 * build(deps): bump github.com/bep/tmc from 0.5.1 to 0.6.0 * snap: Stop building for ppc64el and s390x * docs: Fix lineNos default value in docs.yaml * hugolib: Fix term title when taxonomy name contains spaces * Update AI assistance guidelines in CONTRIBUTING.md * tpl/collections: Speed up where and sort performance * tpl/internal: Replace deprecated parser.ParseDir and doc.New * docs: Regenerate docs.yaml * Squashed 'docs/' changes from 1ad3c75ad..42914c50e * commands: Skip chmod for files without owner-write permission * build(deps): bump github.com/gohugoio/hugo-goldmark-extensions/extras * build(deps): bump github.com/gohugoio/hugo-goldmark-extensions/passthrough * tpl/collections: Add some more benchmarks for where and sort * all: Change site to project where appropriate * docker: Add full tar and openssh-client to support GitHub Actions * markup/highlight: Allow lineNos to be true, false, "inline", or "table" * Remove items deprecated <= v0.136.0 (note) * Upgrade to Go 1.26 * tpl: Move from md5 to xxhash for some in memory keys * build(deps): bump golang.org/x/tools from 0.41.0 to 0.42.0 * build(deps): bump github.com/bep/helpers from 0.6.0 to 0.7.0 * resources/page: Deprecate cascade._target in favor of cascade.target * tpl/tplimpl: Throw error when calling gist shortcode * tpl/tplimpl: Throw error when calling twitter/twitter_simple shortcodes * testscripts/commands: Update 'future' date to far future * Reapply "release: Support alpha, beta, and RC releases" * build(deps): bump golang.org/x/image from 0.35.0 to 0.36.0 * releaser: Prepare repository for 0.156.0-DEV - Update to version 0.155.3: * releaser: Bump versions for release of 0.155.3 * hugolib: Don't render default site redirect for non-primary isHTML output formats * server: Fix stuck server global error logging * build(deps): bump github.com/evanw/esbuild from 0.27.2 to 0.27.3 * server: Fix panic when the server browser error handler tried to use a config in a state of flux * releaser: Prepare repository for 0.156.0-DEV - Update to version 0.155.2: * releaser: Bump versions for release of 0.155.2 * resources/image: Add some image decode/encode debug logging * Fix template change detection for multi-version sites * releaser: Prepare repository for 0.156.0-DEV - Update to version 0.155.1: * releaser: Bump versions for release of 0.155.1 * Fix image DecodeConfig regression of WebP images from file cache * Remove go vet from check.sh * Add ./check.sh script * Update AGENTS.md with debug printing note * resources/images: Fix WebP useSharpYuv being ignored * tpl/tplimpl: Remove failing Twitter tests * releaser: Prepare repository for 0.156.0-DEV - Update to version 0.155.0: * releaser: Bump versions for release of 0.155.0 * Revert "release: Support alpha, beta, and RC releases" * Fix data race when clearing cache in cachebusters * resources/images: Fix comment for Quality field in ImageConfig * Fix panic reported in discourse * Remove disableDate and disableLatLong from MetaConfig * internal/warpc: Make webp C defaults match the Go defaults * testscripts: Move server tests to own folder * testing: Skip some slow tests when not running in CI * misc: Update image processing description in README.md * docs: Update docs.yaml * magefile: Skip commands test when running mage check locally * Fix recently introduced partial rendering bug * Remove -p 2 parallelism limit for local test runs * build(deps): bump golang.org/x/tools from 0.40.0 to 0.41.0 * build(deps): bump github.com/olekukonko/tablewriter from 1.1.2 to 1.1.3 * build(deps): bump github.com/alecthomas/chroma/v2 from 2.23.0 to 2.23.1 * Make docs helper maxAge JSON output user friendly * Add AGENTS.md and CLAUDE.md * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * build(deps): bump golang.org/x/image from 0.34.0 to 0.35.0 * build(deps): bump golang.org/x/mod from 0.31.0 to 0.32.0 * tpl: Fix partial decorator panic when partial returns falsy * Add == and != operators to range predicates * resources: Fix race condition in test helper * Add modulequeries file cache for module version queries * Allow v1,v2 etc. style version names while still supporting full semver in queries * Make Page.Aliases more useful in multidimensional setups (note) * Fix cascade draft panic * Add range matchers for site matrix vector store filtering * Misc webp performance work * hugolib: Fix multilingual alias generation * Fix file mount specifity issue within the same module * deps: Upgrade github.com/gohugoio/gift v0.1.0 => v0.2.0 * Move from github.com/disintegration/gift to github.com/gohugoio/gift * build(deps): bump github.com/alecthomas/chroma/v2 from 2.22.0 to 2.23.0 * warpc: Fix typed nil return in Start * resources/images: Stabilize order of valid sources in error message * hugolib: Fix relative alias generation * Add XMP and IPTC image metadata support * output: Add TestCanonical integration test * Rename common/maps to common/hmaps (#14384) * build(deps): bump golang.org/x/net from 0.48.0 to 0.49.0 * build(deps): bump github.com/bep/lazycache from 0.8.0 to 0.8.1 * deps: Upgrade github.com/alecthomas/chroma v2.21.1 => v2.22.0 * Decode webp.ImageConfig natively * releaser: Prepare repository for 0.155.0-DEV - Update to version 0.154.5: * releaser: Bump versions for release of 0.154.5 * Fix some default site redirect woes * hugolib: Fix newly created shortcodes not found during server rebuild * tpl/tplimpl: Remove trailing slash from void elements * releaser: Prepare repository for 0.155.0-DEV - Update to version 0.154.4: * releaser: Bump versions for release of 0.154.4 * build(deps): bump github.com/goccy/go-yaml from 1.19.1 to 1.19.2 * tpl: Fix language resolution for markdown shortcodes * For multiple dimensions setups, fix alias handling and multihost publish path * releaser: Prepare repository for 0.155.0-DEV - Update to version 0.154.3: * releaser: Bump versions for release of 0.154.3 * build(deps): bump github.com/yuin/goldmark from 1.7.13 to 1.7.16 * releaser: Prepare repository for 0.155.0-DEV - Update to version 0.154.2: * releaser: Bump versions for release of 0.154.2 * Fix alpha/fuzzy border issue with new webp decoder for images with with transparent background * snap: Limit build platforms to amd64, arm64, ppc64el, and s390x * snap: Update to core 24 * releaser: Prepare repository for 0.155.0-DEV - Update to version 0.154.1: * releaser: Bump versions for release of 0.154.1 * Add WASM licensing information to README * Fix partial decorator detection in partial with blocks with outer range break or continue * releaser: Prepare repository for 0.155.0-DEV - Update to version 0.154.0: * releaser: Bump versions for release of 0.154.0 * tpl/collections: Fix apply to work with built-in funcs like len * Remove Linode sponsor from README * helpers: Limit verbose watch output for better readability * tpl/reflect: Make the IsImageResource implementation less technical * internal/warpc: Increase WebP memory limit to 384 MiB * build(deps): bump github.com/tetratelabs/wazero from 1.10.1 to 1.11.0 * Revert "resources/page: Fix slugorcontentbasename for section pages" * Update tpl/reflect/reflect.go * Add reflect.Is{Page,Site,Resource,ImageResource} * Allow partials to work as decorators * releaser: Prepare repository for 0.154.0-DEV - Update to version 0.153.5: * releaser: Bump versions for release of 0.153.5 * images: Add compression option to image config and clean up some of the options handling * config: Fix cascade per language in hugo.toml regression * images: Fix WebP quality and hint parameters being ignored * releaser: Prepare repository for 0.154.0-DEV - Update to version 0.153.4: * releaser: Bump versions for release of 0.153.4 * Set cascade target to the content matrix if not set in the cascade itself * releaser: Prepare repository for 0.154.0-DEV - Update to version 0.153.3: * releaser: Bump versions for release of 0.153.3 * build(deps): bump github.com/bep/imagemeta from 0.12.0 to 0.12.1 * Fix error with _content.gotmpl file with index.md siblings * releaser: Prepare repository for 0.154.0-DEV - Update to version 0.153.2: * releaser: Bump versions for release of 0.153.2 * Fix "image: unknown format" error * modules: Remove extended edition check * misc: Update edition comparison and guidance in README.md * releaser: Prepare repository for 0.154.0-DEV - Update to version 0.153.1: * releaser: Bump versions for release of 0.153.1 * Handle PNG named *.webp * Revert deprecation logging for contentDir per language * images: Add some more PNG tests * Fix panic when 404 is backed by a content file * internal/warpc: Increase WebP memory limit to 256 MiB * releaser: Prepare repository for 0.154.0-DEV - Update to version 0.153.0: * releaser: Bump versions for release of 0.153.0 * hugoreleaser: Updage macospkgremote to increase notarization timeout * Squashed 'docs/' changes from 71f739460..1ad3c75ad * resources/images: Don't trust the file extension when decoding JPEG and PNG images * Add full filename to image processing error messages if possible * tailwindcss: Add referece to skipInlineImportsNotFound when import not found in assets * build(deps): bump github.com/goccy/go-yaml from 1.19.0 to 1.19.1 * build(deps): bump github.com/alecthomas/chroma/v2 from 2.21.0 to 2.21.1 * Improve error messages for template failures * Improve error handling/messages in Hugo Pipes * Fix some outdated front matter * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * deps: Upgrade github.com/alecthomas/chroma/v2 v2.20.0 => v2.21.0 * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.40.1 to 1.41.0 * build(deps): bump github.com/evanw/esbuild from 0.27.1 to 0.27.2 * images: Add a webp test with bg color * tpl/css: Deprecate libsass in favor of dartsass (note) * Encode and Decode using the libwebp library via WASM with animation support * config/allconfig: Correct error message * tpl: Add missing functions to init files * github: Add some known humans to the AI whitelist * build(deps): bump golang.org/x/image from 0.33.0 to 0.34.0 * build(deps): bump golang.org/x/tools from 0.39.0 to 0.40.0 * build(deps): bump github.com/tdewolff/minify/v2 from 2.24.7 to 2.24.8 * build(deps): bump gocloud.dev from 0.43.0 to 0.44.0 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * build(deps): bump github.com/evanw/esbuild from 0.27.0 to 0.27.1 * Fix server rebuilds on editing content with Chinese terms * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.40.0 to 1.40.1 * build(deps): bump github.com/spf13/cobra from 1.9.1 to 1.10.2 * release: Skip pushing stable and docs update for pre-releases * release: Support alpha, beta, and RC releases * snap: Address snapcraft deprecations * build(deps): bump github.com/goccy/go-yaml from 1.18.0 to 1.19.0 * build(deps): bump github.com/olekukonko/tablewriter from 1.1.1 to 1.1.2 * build(deps): bump github.com/JohannesKaufmann/html-to-markdown/v2 * langs/i18n: Prefer languageCode when picking translation file * Add entitlements for WebAssembly for macOS Tahoe * testscripts: Move layouts file to new structure * resources: Skip integration test if Dart Sass is not installed * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * testing: Replace legacy config.toml with hugo.toml in most tests * testing: Port integration tests to new templates structure * github: Correct dependabot => dependabot[bot] * config/privacy: Change GoogleAnalytics.RespectDoNotTrack default to true * Add signed and notarized MacOS pkg builds * Upgrade to Go 1.25.4 * tpl/urls: Add PathEscape and PathUnescape functions * Fix slow server startup of very big content trees * Speedup and simplify page assembly for deeper content trees * markup/asciidocext: Improve Asciidoctor integration * gemini: Remove styleguide.md (for now) * github: Reenable Gemini, but no auto code review * github: Partition tests by their root * github: Make the clean commands work * github: Also test the root package (left out in previous commit) * github: More disk space saving optimizations * github: Add PR Template * Adjust benchmark * tpl/openapi: Add support for OpenAPI external file references * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * build(deps): bump golang.org/x/image from 0.32.0 to 0.33.0 * build(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0 * github: Skip dependabot for AI Watchdog workflow * build(deps): bump github.com/tdewolff/minify/v2 from 2.24.5 to 2.24.7 * github: Remove the 386 test step in GitHub test workflow * github: Remove test binaries after CI test runs * github: Fix "no space left on device" issue in CI * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * build(deps): bump golang.org/x/tools from 0.38.0 to 0.39.0 * build(deps): bump github.com/tetratelabs/wazero from 1.10.0 to 1.10.1 * github: Adjust watchdog run logic (now with correct spelling) * github: Adjust watchdog run logic (again) * github: Adjust watchdog run logic * github: Only run AI Watchdog when the PR is ready for review * build(deps): bump github.com/bits-and-blooms/bitset * build(deps): bump github.com/olekukonko/tablewriter from 1.1.0 to 1.1.1 * build(deps): bump golang.org/x/text from 0.30.0 to 0.31.0 * build(deps): bump github.com/evanw/esbuild from 0.25.12 to 0.27.0 * Update aiwatchdog.yml * Update aiwatchdog.yml * Update aiwatchdog.yml * github: Add label to AI suspects and do not fail when confident * github: Adjust AI Watchdog workflow to make it run PRs from forks * github: Adjust workflow permissions * performance: Misc allocation improvements * hugolib/doctree: Simplify lock setup in SimpleThreadSafeTree to reduce read allocation * github: Add ai-watchdog workflow and update other workflows' versions * build(deps): bump google.golang.org/api from 0.251.0 to 0.255.0 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * build(deps): bump github.com/tetratelabs/wazero from 1.9.0 to 1.10.0 * tpl/collections: Improve collections.D * Optimize memory allocations for sites matrix vector stores * gemini: Disable auto PR codereviews for now * docs: Fix link to CGO wiki page * github: Update asciidoctor-diagrams extension and add GoAT * Fix grammatical error in styleguide.md * Update styleguide.md * Add gemini setup files * static: Preserve .gitignore and .gitattributes in --cleanDestinationDir * hugolib: Fix recently introduced data race * hugolib: Improve performance of content trees with many sections * markup/asciidocext: Support boolean document attributes * github: Allow AsciiDoc content in tests to render Ditaa diagrams * Add a site assembly benchmark test for a deeper site structure with more sections and pages * sitesmatrix: Clary default dimension values * Run go mod tidy to clean up go.mod and go.sum * docshelper: Fix some YAML serialization issues with sites matrix configuration * resources/page: Fix slugorcontentbasename for section pages * build(deps): bump github.com/evanw/esbuild from 0.25.11 to 0.25.12 * testing: Rewrite all the old style integration tests to txtar style tests * commands: newDocsHelper encode integers as ints in generated YAML * config: Add struct tags to deprecated and unused fields * hugolib: Delete some old integration tests * testing: Revise usage of b.N and b.Loop() in benchmarks * all: Fix some benchmarks broken by modernize * all: Run modernize -fix ./... * Add roles and versions as new dimensions (in addition to language) * Update CONTRIBUTING.md * github: Allow AsciiDoc content in tests to render diagrams * hreflect: Cache reflect method lookups used in collections.Where and others * all: Simplify the reflect usage * releaser: Prepare repository for 0.153.0-DEV - Update to version 0.152.2: * releaser: Bump versions for release of 0.152.2 * deps: Update github.com/tdewolff/minify v2.24.4 => v2.24.5 * hugofs: Make node_modules a "special case" mount * github: Fix typo in stale PR message * releaser: Prepare repository for 0.153.0-DEV - Update to version 0.152.1: * releaser: Bump versions for release of 0.152.1 * Expand the numeric conversions to template funcs/methods * Fix where with uint64 * Fix it so YAML integer types can be used where Go int types are expected * tpl/compare: Fix compare/sort of uint64s * Fix "assignment to entry in nil map" on empty YAML config files * releaser: Prepare repository for 0.153.0-DEV - Update to version 0.152.0: * releaser: Bump versions for release of 0.152.0 * config: Clone language map entries before modifying them * Skip flaky test for now * Misc YAML adjustments * hugofs: Make sure that non-project module mounts are local paths * langs/i18n: Improve reserved key error message * deps: Upgrade github.com/gohugoio/go-i18n/v2 * langs: Add test case using a "reserved" i18n code * Replace to gopkg.in/yaml with github.com/goccy/go-yaml (note) * build(deps): bump github.com/tdewolff/minify/v2 from 2.24.3 to 2.24.4 * releaser: Prepare repository for 0.152.0-DEV - Update to version 0.151.2: * releaser: Bump versions for release of 0.151.2 * parser/pageparser: Add a testcase for nested shortcodes of the same name * parser/pageparser: Fix shortcode nesting regression * testscripts: Add and improve commands tests for static mounts * releaser: Prepare repository for 0.152.0-DEV - Update to version 0.151.1: * releaser: Bump versions for release of 0.151.1 * Upgrade Go to 1.25.3 * tpl: Fix strings/truncate CJK handling * build(deps): bump github.com/gohugoio/hashstructure from 0.5.0 to 0.6.0 * build(deps): bump golang.org/x/image from 0.30.0 to 0.32.0 * build(deps): bump github.com/evanw/esbuild from 0.25.10 to 0.25.11 * build(deps): bump golang.org/x/tools from 0.37.0 to 0.38.0 * build(deps): bump golang.org/x/mod from 0.28.0 to 0.29.0 * create/skeletons: Wrap section and home lists with section tags * markup/goldmark: Align blockquote default output with Goldmark * parser/pageparser: Store shortcode names as unique.Handle[string] to save memory allocations * parser/pagerparser: Fix closing shortcode error handling when repeated * testscripts: Make test assertion less specific * releaser: Prepare repository for 0.152.0-DEV - Update to version 0.151.0: * releaser: Bump versions for release of 0.151.0 * Adjust the terminal progress reporter a little * transform/livereloadinject: Skip livereload.js injection if no tags found (note) * build(deps): bump google.golang.org/api from 0.248.0 to 0.251.0 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * Add transform.HTMLToMarkdown * Report OSC 9;4 progress when building * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.38.1 to 1.39.2 * build(deps): bump golang.org/x/tools from 0.36.0 to 0.37.0 * build(deps): bump github.com/spf13/afero from 1.14.0 to 1.15.0 * build(deps): bump github.com/tdewolff/minify/v2 from 2.24.2 to 2.24.3 * Fix file caching for 404 responses in resources.GetRemote * build(deps): bump github.com/evanw/esbuild from 0.25.9 to 0.25.10 * tpl: Workaround s390x precision of Atan and Tan * cache/httpcache: Add respectCacheControlNoStoreInResponse and respectCacheControlNoStoreInRequest options * common/hreflect: Speed up IsTrutfulValue * build(deps): bump golang.org/x/text from 0.28.0 to 0.29.0 * build(deps): bump github.com/olekukonko/tablewriter from 1.0.9 to 1.1.0 * build(deps): bump github.com/spf13/cast from 1.9.2 to 1.10.0 * markup/goldmark: Enhance footnote extension with backlinkHTML option * markup/goldmark: Enhance footnote extension with auto-prefixing option * releaser: Prepare repository for 0.151.0-DEV - Update to version 0.150.1: * releaser: Bump versions for release of 0.150.1 * hugolib: Change duplicate content path warning to an info log * hugolib: Restore integration test * commands: Map --minify CLI flag to the correct configuration key * snap: Add desktop plug * test(deps): Update setup-ruby action to v1.257.0 * releaser: Prepare repository for 0.151.0-DEV - Update to version 0.150.0: * releaser: Bump versions for release of 0.150.0 * build(deps): bump golang.org/x/mod from 0.27.0 to 0.28.0 * modules: Add support for direct version module imports in hugo.toml * resources/page: Fix truncated summary logic * config/security: Add PROGRAMDATA to the osenv allowlist * releaser: Prepare repository for 0.150.0-DEV - Update to version 0.149.1: * releaser: Bump versions for release of 0.149.1 * Remove noindex meta tag from alias.html * Fix nilpointer on ToC heading * tpl/collections: Require collections.D args to be ints * Upgrade to Go 1.25.1 * Fix config env handling for some slice options * minifiers: Update deprecation handling * Update README.md * releaser: Prepare repository for 0.150.0-DEV - Update to version 0.149.0: * releaser: Bump versions for release of 0.149.0 * tpl/collections: Add an integration test for collections.D * misc: Update Go version to 1.24.0 in README * create: Fix new content command with future dates * build(deps): bump github.com/getkin/kin-openapi from 0.132.0 to 0.133.0 * tpl/collections: Add collections.D using Vitter's Method D for sequential random sampling * build(deps): bump google.golang.org/api from 0.247.0 to 0.248.0 * build(deps): bump github.com/evanw/esbuild from 0.25.6 to 0.25.9 * build(deps): bump gocloud.dev from 0.40.0 to 0.43.0 * commands: Deprecate --omitEmpty on chromastyles command * commands: Add --omitClassComments to the chromastyles command * deps: Upgrade github.com/alecthomas/chroma/v2 v2.19.0 => v2.20.0 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * build(deps): bump github.com/tdewolff/minify/v2 from 2.23.11 to 2.24.0 * all: Use slices.Equal * Squashed 'docs/' changes from 60dd993a6..71f739460 * resources/page: Add :sectionslug and :sectionslugs permalink tokens * Upgrade to Go 1.25 * common/hcontext: Replace with external package * Fix server rebuild when adding a new leaf bundle with resources in one go * resources/page: Use reflect.TypeFor * build(deps): bump github.com/tdewolff/minify/v2 from 2.23.8 to 2.23.11 * Remove test with deprecated path usage * build(deps): bump github.com/olekukonko/tablewriter from 1.0.8 to 1.0.9 * Update README.md * Fix rebuild when deleting a content adapter file * build(deps): bump google.golang.org/api from 0.237.0 to 0.247.0 * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.36.4 to 1.38.0 * build(deps): bump golang.org/x/tools from 0.35.0 to 0.36.0 * build(deps): bump github.com/bep/simplecobra from 0.6.0 to 0.6.1 * tpl/strings: Remove unnecessary error check * markup/goldmark: Apply Hugo Goldmark Extras when rendering TOC * build(deps): bump golang.org/x/mod from 0.25.0 to 0.27.0 * build(deps): bump github.com/yuin/goldmark from 1.7.12 to 1.7.13 * markup/goldmark: Sanitize TOC heading titles * build(deps): bump golang.org/x/image from 0.28.0 to 0.30.0 * deps: Upgrade github.com/niklasfasching/go-org v1.8.0 => v1.9.1 * Add a key to the partialCached deadlock prevention * transform: Add support for "format" option in transform.Unmarshal * Skip flakey test on CI * releaser: Prepare repository for 0.149.0-DEV - Update to version 0.148.2: * releaser: Bump versions for release of 0.148.2 * tpl: Add test for recent template selection regression * Revert "hugolib: Honor implicit "page" type during template selection" * Fix regression with hyphenated codeblock templates, e.g. render-codeblock-go-html-template.html * commands: Avoid full browser refresh on simple CSS changes * releaser: Prepare repository for 0.149.0-DEV - Update to version 0.148.1: * releaser: Bump versions for release of 0.148.1 * Fix assignment to entry in nil map * deps: Downgrade github.com/niklasfasching/go-org v1.9.0 => v1.8.0 * releaser: Prepare repository for 0.149.0-DEV - Update to version 0.148.0: * releaser: Bump versions for release of 0.148.0 * Add Ancestors (plural) method to GitInfo, rename Ancestor field to Parent * build(deps): bump github.com/evanw/esbuild from 0.25.5 to 0.25.6 * Allow creating home pages from content adapters * build(deps): bump github.com/olekukonko/tablewriter from 1.0.7 to 1.0.8 * Remove the internal GitInfo type and make Page.GitInf() return a pointer * source: Expose Ancestor in GitInfo * Squashed 'docs/' changes from b654fcba0..60dd993a6 * config: Increase test coverage * build(deps): bump github.com/niklasfasching/go-org from 1.8.0 to 1.9.0 * build(deps): bump github.com/alecthomas/chroma/v2 from 2.18.0 to 2.19.0 * markup/goldmark: Change link and image render hook enablement to enums * Fix some uglyURLs issues for home, section and taxonomy kind (note) * Fix branch paths when OutputFormat.Path is configured (note) * resources/page: Allow full datetime prefix in filenames * build(deps): bump golang.org/x/tools from 0.32.0 to 0.34.0 * hugolib: Honor implicit "page" type during template selection * deploy: walkLocal worker pool for performance * releaser: Prepare repository for 0.148.0-DEV - Update to version 0.147.9: * releaser: Bump versions for release of 0.147.9 * Remove WARN with false negatives * resources/page: Make sure a map is always initialized * tpl/tplimpl: Copy embedded HTML table render hook to each output format * tpl/tplimpl: Change resources.GetRemote errors to suppressible warnings * build(deps): bump google.golang.org/api from 0.221.0 to 0.237.0 * hugolib: Remove test for deprecated future * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.36.1 to 1.36.4 * build(deps): bump golang.org/x/image from 0.27.0 to 0.28.0 * deps: Upgrade github.com/spf13/cast v1.8.0 => v1.9.2 * common/terminal: Enable color output on windows * releaser: Prepare repository for 0.148.0-DEV - Update to version 0.147.8: * releaser: Bump versions for release of 0.147.8 * hugolib: Emit ignorable warning when home page is a leaf bundle * dockerfile: Update Alpine * dockerfile: Update Go version * build(deps): bump github.com/evanw/esbuild from 0.25.3 to 0.25.5 * build(deps): bump github.com/niklasfasching/go-org from 1.7.0 to 1.8.0 * build(deps): bump golang.org/x/net from 0.39.0 to 0.40.0 * build(deps): bump github.com/yuin/goldmark from 1.7.11 to 1.7.12 * build(deps): bump github.com/tdewolff/minify/v2 from 2.23.5 to 2.23.8 * all: Replace _build with build in tests * releaser: Prepare repository for 0.148.0-DEV - Update to version 0.147.7: * releaser: Bump versions for release of 0.147.7 * Fix language handling in shortcode templates * Handle KaTeX warnings (#13760) * build(deps): bump golang.org/x/image from 0.26.0 to 0.27.0 * build(deps): bump golang.org/x/text from 0.24.0 to 0.25.0 * build(deps): bump github.com/spf13/cast from 1.7.1 to 1.8.0 * build(deps): bump github.com/alecthomas/chroma/v2 from 2.17.2 to 2.18.0 * resources/page: Respect disablePathToLower for permalink tokens * common/collections: Increase test coverage * parser/pageparser: Add coverage for all IsX methods of Item * resources: Remove unused interface * Make sure that unreferenced but changed bundle resources gets republished * deps: Upgrade github.com/olekukonko/tablewriter v0.0.5 => v1.0.7 * releaser: Prepare repository for 0.148.0-DEV - Update to version 0.147.6: * releaser: Bump versions for release of 0.147.6 * Improve warning message on superfluous prefix when using function 'partials.Include' * Fix recent regression with cascading of params to content adapters * Fix it so e.g. de in layouts/_shortcodes/de.html is not interpreted as a language code * commands: Make sure the browser gets refreshed on changes when --disableFastRender is set * tpl/transform: Expose the KaTeX strict option * releaser: Prepare repository for 0.148.0-DEV - Update to version 0.147.5: * releaser: Bump versions for release of 0.147.5 * Fix live reload when editing inline partials * build(deps): bump github.com/tdewolff/minify/v2 from 2.20.37 to 2.23.5 * releaser: Prepare repository for 0.148.0-DEV - Update to version 0.147.4: * releaser: Bump versions for release of 0.147.4 * Fix it so css.TailwindCSS inlineImports options isn't always enabled * tpl: Add a test case * tpl: Narrow down the usage of plain text shortcodes when rendering HTML * tpl: Fix theme overrides when theme has old layout setup (e.g. _default) * releaser: Prepare repository for 0.148.0-DEV - Update to version 0.147.3: * releaser: Bump versions for release of 0.147.3 * tpl/tplimpl: Change calls to simple versions of embedded shortcodes * Update README.md * config: Fix env override of slices * Fix/implement cascade for content adapters * commands: Fix description of new theme commands * tpl/tplimpl: Fix vimeo shortcode test to accommodate API changes * tpl/math: Add MaxInt64 function * releaser: Prepare repository for 0.148.0-DEV - Update to version 0.147.2: * releaser: Bump versions for release of 0.147.2 * Fix handling of "outputs" from content adapter pages * tpl: Fix case issue in templates.Exists * config: Add some more merge tests * releaser: Prepare repository for 0.148.0-DEV - Update to version 0.147.1: * releaser: Bump versions for release of 0.147.1 * build(deps): bump github.com/alecthomas/chroma/v2 from 2.17.0 to 2.17.2 * build(deps): bump github.com/getkin/kin-openapi from 0.131.0 to 0.132.0 * tpl: Add some more test cases * build(deps): bump github.com/yuin/goldmark from 1.7.10 to 1.7.11 * tpl: Fix overlapping layout sections * Fix it so the owning taxonomy gets rerendered in server when new tags are added * commands/server: Display correct multihost language in console * hugolib: Use new build key in content placeholder * releaser: Prepare repository for 0.148.0-DEV - Update to version 0.147.0: * releaser: Bump versions for release of 0.147.0 * tpl: Fix it so we always prefer internal codeblock rendering over render-codeblock-foo.html and similar * tpl/tplimpl: Fix allowFullScreen option in Vimeo and YouTube shortcodes * create/skeletons: Adjust template names in theme skeleton * tpl: Remove some unreached code branches * images: Add some test cases for aligny on images.Text * images: Add option for vertical alignment to images.Text * config: Fix _merge issue when key doesn't exist on the left side * Squashed 'docs/' changes from dc7a9ae12..b654fcba0 * all: Fix typos * build(deps): bump github.com/evanw/esbuild from 0.25.2 to 0.25.3 * build(deps): bump github.com/alecthomas/chroma/v2 from 2.16.0 to 2.17.0 * releaser: Prepare repository for 0.147.0-DEV - Update to version 0.146.7: * releaser: Bump versions for release of 0.146.7 * Revert the breaking change from 0.146.0 with dots in content filenames * tpl: Fix indeterminate template lookup with templates with and without lang * parser/metadecoders: Add CSV targetType (map or slice) option to transform.Unmarshal * build(deps): bump github.com/yuin/goldmark-emoji from 1.0.5 to 1.0.6 * build(deps): bump github.com/bep/imagemeta from 0.11.0 to 0.12.0 * tpl/collections: Fix where ... not in with empty slice * tpl: Fix layout fall back logic when layout is set in front matter but not found * tpl: Detect and fail on infinite template recursion * build(deps): bump github.com/yuin/goldmark from 1.7.9 to 1.7.10 * releaser: Prepare repository for 0.147.0-DEV - Update to version 0.146.6: * releaser: Bump versions for release of 0.146.6 * tpl: Fix when layout specified in front matter and no match is found * Update watchtestscripts.sh * releaser: Prepare repository for 0.147.0-DEV - Update to version 0.146.5: * releaser: Bump versions for release of 0.146.5 * build(deps): bump github.com/yuin/goldmark from 1.7.8 to 1.7.9 * tpl: Fix language handling in partials * releaser: Prepare repository for 0.147.0-DEV - Update to version 0.146.4: * releaser: Bump versions for release of 0.146.4 * tpl: Fix issue with partials without suffix * tpl: Avoid panic on nonsensical return construct * tpl: Fix the case for a shortcode in a nested folder only * tpl: Add proper file context to template parse errors * tpl: Make {{ template "partials/foo.html" . }} work in older setups * releaser: Prepare repository for 0.147.0-DEV - Update to version 0.146.3: * releaser: Bump versions for release of 0.146.3 * tpl: Make any layout set in front matter higher priority * tpl: Fix it so embedded render-codeblock-goat is used even if custom render-codeblock exists * releaser: Prepare repository for 0.147.0-DEV - Update to version 0.146.2: * releaser: Bump versions for release of 0.146.2 * tpl: Fix codeblock hook resolve issue * tpl: Fix legacy section mappings * tpl: Resolve layouts/all.html for all html output formats * tpl: Fix some baseof lookup issues * releaser: Prepare repository for 0.147.0-DEV - Update to version 0.146.1: * releaser: Bump versions for release of 0.146.1 * tpl: Skip dot and temp files inside /layouts * releaser: Prepare repository for 0.147.0-DEV - Packaging improvements: * Update to BuildRequires: golang(API) >= 1.24 matching go.mod - Update to version 0.146.0: * releaser: Bump versions for release of 0.146.0 * tpl: Warn and skip non-hook templates inside /layouts/_markup * Squashed 'docs/' changes from d1a251933..dc7a9ae12 * tpl: Add a partial lookup cache * build(deps): bump github.com/fsnotify/fsnotify from 1.8.0 to 1.9.0 * build(deps): bump golang.org/x/tools from 0.31.0 to 0.32.0 * build(deps): bump github.com/evanw/esbuild from 0.25.1 to 0.25.2 * tpl: Add templates.Current * build(deps): bump golang.org/x/image from 0.25.0 to 0.26.0 * build(deps): bump github.com/pelletier/go-toml/v2 from 2.2.3 to 2.2.4 * build(deps): bump github.com/alecthomas/chroma/v2 from 2.15.0 to 2.16.0 * commands/new: Improve theme creation * build(deps): bump golang.org/x/net from 0.37.0 to 0.39.0 * build(deps): bump github.com/bep/imagemeta from 0.10.0 to 0.11.0 * deps: Upgrade github.com/gohugoio/hugo-goldmark-extensions/passthrough v0.3.0 => v0.3.1 * tpl/tplimpl: Update embedded pagination template * Reimplement and simplify Hugo's template system * config: Use the non-global logger for deprecations when possible * tpl/time: Add time.In function * resources: Add option to silence dependency deprecation warnings * tpl/tplimpl: Fix full screen option in vimeo and youtube shortcodes * common/hreflect: Replace the map/RWMutex method cache with sync.Map * build(deps): bump golang.org/x/tools from 0.30.0 to 0.31.0 * build(deps): bump github.com/getkin/kin-openapi from 0.129.0 to 0.131.0 * build(deps): bump github.com/spf13/afero from 1.11.0 to 1.14.0 * build(deps): bump github.com/bep/imagemeta from 0.9.0 to 0.10.0 * build(deps): bump github.com/golang-jwt/jwt/v5 from 5.2.1 to 5.2.2 * build(deps): bump github.com/evanw/esbuild from 0.24.2 to 0.25.1 * build(deps): bump github.com/bep/godartsass/v2 from 2.4.0 to 2.4.1 * build(deps): bump golang.org/x/net from 0.35.0 to 0.37.0 * common/hexec: Remove github.com/cli/safeexec * parser/metadecoder: Improve errors for non-map XML root values * identity: Use clear to clear the finder seen map * build(deps): bump github.com/bep/godartsass/v2 from 2.3.2 to 2.4.0 * commands/gen: Set url in command pages to /docs/reference/commands/ * cache: Apply httpcache defaults for polling config * build(deps): bump golang.org/x/image from 0.24.0 to 0.25.0 * deps: Upgrade golang.org/x/mod v0.23.0 => v0.24.0 * build(deps): bump github.com/bep/overlayfs from 0.9.2 to 0.10.0 * build(deps): bump github.com/bep/lazycache from 0.7.0 to 0.8.0 * tpl/tplimpl: Add loading attribute to Vimeo shortcode * build(deps): bump github.com/bep/imagemeta from 0.8.4 to 0.9.0 * build(deps): bump github.com/bep/simplecobra from 0.5.0 to 0.6.0 * commands: Add --omitEmpty flag to gen chromastyles * tpl: Add trailing newline to robots.txt template * commands: Skip flaky test on Windows * resources/image: Mark loong64 as FMA-using architecture * releaser: Prepare repository for 0.146.0-DEV - Update to version 0.145.0: * releaser: Bump versions for release of 0.145.0 * github: Build docker image with both extended and withdeploy tags * all: Typo fixes * deps: Upgrade github.com/rogpeppe/go-internal v1.13.1 => v1.14.1 * Use the page path and not the backing filename as the last resort in the default sort * all: Run modernize -fix ./... * build(deps): bump github.com/yuin/goldmark-emoji from 1.0.4 to 1.0.5 * tpl: HTTPS the instagram Shortcode JS * build(deps): bump github.com/google/go-cmp from 0.6.0 to 0.7.0 * build(deps): bump github.com/tetratelabs/wazero from 1.8.2 to 1.9.0 * Add transform.PortableText * readme: Fix relative links in Editions section * Fix some related content issues with content adapters * Fix potential nilpointer in httpcache config * hugolib: Deprecate _build front matter key in favor of build * snap: Update Node.js to 22.x - Update to version 0.144.2: * releaser: Bump versions for release of 0.144.2 * Fix --printPathWarnings when site calls templates.Defer * releaser: Prepare repository for 0.145.0-DEV - Update to version 0.144.1: * releaser: Bump versions for release of 0.144.1 * markup/goldmark: Fix panic on empty Markdown header * releaser: Prepare repository for 0.145.0-DEV - Update to version 0.144.0: * releaser: Bump versions for release of 0.144.0 * markup/goldmark: Fix panic on stray attribute nodes * Fix Position for passthrough hooks * Fix auto generated header ids so they don't contain e.g. hyperlink destinations (note) * build(deps): bump github.com/spf13/cobra from 1.8.1 to 1.9.1 * build(deps): bump github.com/sanity-io/litter from 1.5.7 to 1.5.8 * config/allconfig: Deprecate :filename and :slugorfilename tokens * resources/page: Revise the new contentbasename permalinks tokens * resources/page: Add :contentbasename and :contentbasenameorslug permalink tokens * Add autoID for definition terms * build(deps): bump github.com/sanity-io/litter from 1.5.5 to 1.5.7 * build(deps): bump github.com/gohugoio/hugo-goldmark-extensions/extras * config: Fix server.redirects.fromRe being ignored unless server.redirects.from is also set * internal/warpc: Enable KaTeX mhchem extension * Update README.md * build(deps): bump golang.org/x/tools from 0.29.0 to 0.30.0 * modules: Add GOAUTH to module config * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * build(deps): bump google.golang.org/api from 0.206.0 to 0.221.0 * Support menus as maps in content adapters * js/esbuild: Add drop option * Squashed 'docs/' changes from 73a01565c..d1a251933 * build(deps): bump github.com/bep/imagemeta from 0.8.3 to 0.8.4 * config: Remove unused code * commands: Use punctuation consistently in short description * Upgrade to Go 1.24 * Deprecate kind, lang, and path from front matter * commands: Move the CHMOD event filter up * build(deps): bump golang.org/x/image from 0.22.0 to 0.24.0 * build(deps): bump golang.org/x/mod from 0.22.0 to 0.23.0 * build(deps): bump github.com/gohugoio/hashstructure from 0.3.0 to 0.5.0 * build(deps): bump github.com/bep/simplecobra from 0.4.0 to 0.5.0 * parser: Handle org-mode filetags as slice * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.32.4 to 1.36.1 * build(deps): bump github.com/getkin/kin-openapi from 0.123.0 to 0.129.0 * build(deps): bump github.com/spf13/pflag from 1.0.5 to 1.0.6 * Add ContentTypes to config * all: Remove deprecated build tags * helpers: Add Chroma styles to docs.yaml * commands: Validate style argument passed to gen chromastyles * Update CONTRIBUTING.md * Move "print unused templates" after renderDeferred * Add some more server options/improvements * Fix shortcode name in error message on self-closing shortcodes with no .Inner * releaser: Prepare repository for 0.144.0-DEV - Update to version 0.143.1: * releaser: Bump versions for release of 0.143.1 * Fix RSS with baseURL with sub dir when render hooks is enabled * mage: Simplify magefile * common/hugo: Adjust deprecation timing and message * Re-introduce the LRU-evicted identities in change set calculation * releaser: Prepare repository for 0.144.0-DEV - Update to version 0.143.0: * releaser: Bump versions for release of 0.143.0 * Fix some server/watch rebuild issues * Don't re-render aliases on server rebuilds * tpl/tplimpl: Remove leading whitespaces produced by Youtube shortcode * Fix "concurrent map iteration and map write" in pages from data * resources: Remove debug statement * Fix TailwindCSS related server rebuild issue * markup/goldmark: Trim space from blockquote render hook text * Fix some server rebuild issues for non-HTML custom output formats * parser/pageparser: Don't allow parameters after closing tag in shortcodes * Fix cascade with overlapping sections * tpl/tplimpl: Improve shortcode test coverage * tpl/tplimpl: Deprecate gist shortcode * resources: Remove conditional used for debugging * resources: Add responseHeaders option to resources.GetRemote * tpl/tplimpl: Skip TestTemplateFuncsExamples on s390x * Squashed 'docs/' changes from 4429eeeea..73a01565c * Make cascade front matter order deterministic * tpl/tplimpl: Deprecate comment shortcode * markup/goldmark: Fix typo in func comment * releaser: Prepare repository for 0.143.0-DEV - Update to version 0.142.0: * releaser: Bump versions for release of 0.142.0 * Fix render hook's PlainText with typographer extension enabled * Improve assert * Improve assertions * Also handle inline HTML comments * Do not warn on potentially unsafe HTML comments when unsafe=false * Fix build with Go 1.24 * tpl/tplimpl: Fix context in shortcode error messages * resources: Fix 2 image file cache key issues * tpl: Add loading attribute to qr shortcode * releaser: Prepare repository for 0.142.0-DEV - Update to version 0.141.0: * releaser: Bump versions for release of 0.141.0 * tpl/tplimpl: Simplify some test assertions * common/paths: Fix docstring * Squashed 'docs/' changes from f0f4bcb24..4429eeeea * docs: Regen CLI docs * tpl/tplimpl: Deprecate twitter shortcode in favor of x shortcode * commands: Fix spelling in comment * commands: Set up the glboal logger early * commands: Add --printZero to the config command * For render hooks, only fallback to HTML (or the defaultOutputFormat) template * tpl/collections: Use MapRange/SetIterKey/SetIterValue for Where, Sort and Merge * deps: Upgrade github.com/gohugoio/hashstructure from 0.1.0 to 0.3.0 * tpl/collections: Add BenchmarkWhereMap * tpl/collections: Add BenchmarkSortMap * tpl/collections: Add Merge benchmark * resources/images: Refactor golden image tests to locate them closer to the implementation * resources/images: Add some mask tests * resources/images: Add images.Mask * tpl/tplimpl: Use plain text for image render hook alt attribute * Adjust error handling in ToMath vs try (note) * resources/images: Add some golden tests for images.QR * Fix branch resource overlapping bundle path * templates: Fix handling of multiple defers in the same template * tpl/images: Change signature of images.QR to images.QR TEXT OPTIONS * resources/images: Add some golden tests for images.Text * images.Text: Add "alignx" option for horizontal alignment * images: Rework the golden tests * Fix NPX issue with TailwindCSS v4 * build(deps): bump golang.org/x/tools from 0.28.0 to 0.29.0 * build(deps): bump golang.org/x/net from 0.33.0 to 0.34.0 * snap: Always package latest stable version of Go * docs: Regen CLI docs * Squashed 'docs/' changes from 8390a4a3a..f0f4bcb24 * create: Respect --noBuildLock in hugo new * build(deps): bump github.com/evanw/esbuild from 0.24.0 to 0.24.2 * tpl/images: Format the QR hashes as hex * build(deps): bump github.com/alecthomas/chroma/v2 from 2.14.0 to 2.15.0 * resources: Replace error handling in GetRemote with try (note) * tpl/images: Add images.QR function * Add try * resources: Add FromOpts for more effective resource creation * Fix server refresh on 404 template changes * markup/highlight: Remove noHl option * releaser: Prepare repository for 0.141.0-DEV - Update to version 0.140.2: * releaser: Bump versions for release of 0.140.2 * Print cli usage of `hugo gen chromastyles` alongside css * build(deps): bump golang.org/x/net from 0.32.0 to 0.33.0 * config/allconfig: Fix slice of language configs * config/allconfig: Throw error when output format is not defined * Fix same resource file published more than once * markup/highlight: Add wrapperClass option * Update README.md * releaser: Prepare repository for 0.141.0-DEV - Update to version 0.140.1: * releaser: Bump versions for release of 0.140.1 * Update gocloud and docs for S3-Compatible Endpoints * js/esbuild: Don't try to resolve packages in /assets marked as external * Fix union, complement, symdiff, and intersect for transient resources * release: Add withdeploy deb extended archives * common/loggers: Write PrintTimerIfDelayed output to stdErr * build(deps): bump github.com/spf13/cast from 1.7.0 to 1.7.1 * hugolib: Fix fallbacks for menu entry Name and Title * releaser: Prepare repository for 0.141.0-DEV - Update to version 0.140.0: * releaser: Bump versions for release of 0.140.0 * js/esbuild: Add missing es2024 target * Fix panic on server rebuilds when using both base templates and template.Defer * js: Fix js.Batch for multihost setups * parser/pageparser: Fix Org Mode summary delimiter assignment * Fix a rebuild on resource rename case * js/esbuild: Add runners after scripts * js/esbuild: Batch: Avoid nil Instances slice * tpl/tplimpl: Fix title attribute in details shortcode * tpl/tplimpl: Update youtube shortcode * tpl/tplimpl: Update details shortcode * tpl/collections: Allow querify to accept a map argument * js/esbuild: Build groups in order of their ID * tpl/tplimpl: Add details shortcode * Write all logging (INFO, WARN, ERROR) to stderr * js/esbuild: Add platform option * Add config option disableDefaultLanguageRedirect * Add js.Batch * build(deps): bump golang.org/x/crypto from 0.30.0 to 0.31.0 * Upgrade to Go 1.23.4 * build(deps): bump golang.org/x/tools from 0.27.0 to 0.28.0 * Remove some old and unused shell scripts * build(deps): bump github.com/hairyhenderson/go-codeowners * Squashed 'docs/' changes from 227aab619..8390a4a3a * Fix Sass imports on the form index.{scss,sass} * build(deps): bump golang.org/x/net from 0.31.0 to 0.32.0 * markup/goldmark: Fix blockquote render hook text parsing * releaser: Bump versions for release of 0.139.4 - Update to version 0.139.5: * releaser: Bump versions for release of 0.139.5 - Update to version 0.139.4: * releaser: Bump versions for release of 0.139.4 * tpl/tplimpl: Escape Markdown attributes in render hooks and shortcodes * deps: Upgrade github.com/bep/godartsass/v2 v2.3.1 => v2.3.2 * common/maps: Simplify TestScratchSetInMap/DeleteInMap * markup/tableofcontents: Cast Fragments.ToHTML args to int * releaser: Prepare repository for 0.140.0-DEV - Update to version 0.139.3: * releaser: Bump versions for release of 0.139.3 * Fix server edits of resources included in shortcode/hooks * Fix some typos * build(deps): bump github.com/bep/godartsass/v2 from 2.3.0 to 2.3.1 * build(deps): bump github.com/tetratelabs/wazero from 1.8.1 to 1.8.2 * commands: Fix flaw in the livereload logic * releaser: Prepare repository for 0.140.0-DEV - Update to version 0.139.2: * releaser: Bump versions for release of 0.139.2 * modules: Skip empty lines in modules.txt * releaser: Prepare repository for 0.140.0-DEV - Update to version 0.139.1: * releaser: Bump versions for release of 0.139.1 * Revert "build(deps): bump github.com/tdewolff/minify/v2 from 2.20.37 to 2.21.1" * minifiers: Add failing test for upstream bug * dartsass: Fix nilpointer on Close when Dart Sass isn't installed * common: Fix some GoDoc typos * readme: Update dependency list * releaser: Prepare repository for 0.140.0-DEV - Update to version 0.139.0: * releaser: Bump versions for release of 0.139.0 * dartsass: Fix error message * Make sure term is always set * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * dartsass: Add silenceDeprecations option * dartsass: Remove support for v1 of the protocol/binary (note) * build(deps): bump google.golang.org/api from 0.191.0 to 0.206.0 * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.30.3 to 1.32.4 * build(deps): bump github.com/fsnotify/fsnotify from 1.7.0 to 1.8.0 * Squashed 'docs/' changes from 159c843fd..227aab619 * deps: Upgrade github.com/bep/imagemeta v0.8.1 => v0.8.3 * docs: Regen CLI docs * Remove deprecations <= v0.122.0 (note) * release: Add missing withdeploy archive for arm64 Linux * Fix extra newline/paragraphs issue with .RenderShortcodes * build(deps): bump golang.org/x/tools from 0.26.0 to 0.27.0 * build(deps): bump github.com/tdewolff/minify/v2 from 2.20.37 to 2.21.1 * build(deps): bump github.com/fatih/color from 1.17.0 to 1.18.0 * build(deps): bump golang.org/x/image from 0.21.0 to 0.22.0 * Run go mod tidy * docs: Regenerate CLI docs * commands: Add -O flag to server to open browser * Preserve input type. * deps: Upgrade github.com/yuin/goldmark v1.7.4 => v1.7.8 * server: Strip ANSI escape codes from browser error log * build(deps): bump golang.org/x/sync from 0.8.0 to 0.9.0 * build(deps): bump github.com/hairyhenderson/go-codeowners * parser/metadecoders: Add benchmark * Add site.Store and hugo.Store and Shortcode.Store * Squashed 'docs/' changes from ccb1b97cb..159c843fd * markup/goldmark: Fix typo in error message * markup/goldmark: Improve the raw HTML omitted warning * releaser: Prepare repository for 0.139.0-DEV - Update to version 0.138.0: * releaser: Bump versions for release of 0.138.0 * Fix concurrent map read and map write in short page lookups * Alias Page.Scratch to Page.Store (note) * releaser: Prepare repository for 0.138.0-DEV - Update to version 0.137.1: * releaser: Bump versions for release of 0.137.1 * common/hugo: Add withdeploy to the version string printed in hugo version * markup: Goldmark log "Raw HTML omitted" warning also for inline HTML * build: Add missing withdeploy archive for Windows * commands: Print the "deploy not available" error message even if flags provided * tpl/tplimpl: Create an embedded comment shortcode * releaser: Prepare repository for 0.138.0-DEV - Update to version 0.137.0: * releaser: Bump versions for release of 0.137.0 * Do not watch directories with no mounted files in it * markup/goldmark: Only log Raw HTML omitted WARN on block entering * markup/goldmark: Add warning (using Warnidf) on Goldmark <!-- raw HTML omitted --> * Fix stale pages on rebuilds in GetPage with short refs * Fix some RenderShortcodes error cases * Update README.md * resources: Address Dart Sass deprecation of global built-in functions * github: Adjust test workflow to install Dart Sass v1.80.3 * deps: Upgrade github.com/bep/godartsass/v2 v2.1.0 => v2.2.0 * Update README.md * Build without the deploy feature by default * deps: Upgrade github.com/bep/lazycache v0.6.0 => v0.7.0 * dynacache: Fix potential deadlocks on panics in GetOrCreate * releaser: Prepare repository for 0.137.0-DEV - Update to version 0.136.5: * releaser: Bump versions for release of 0.136.5 * hugolib/commands: Fix stuck server error issues - Update to version 0.136.4: * releaser: Bump versions for release of 0.136.4 * tpl/transform: Revert unmarshal whitespace removal * releaser: Prepare repository for 0.137.0-DEV - Update to version 0.136.3: * releaser: Bump versions for release of 0.136.3 * docker: Fix permission issues in Dockerfile * Make sure that HugoSites is always closed when done * tpl/strings: Add TrimSpace function * common/herrors: Fix the deferred error message cleaner regexp * tpl/transform: Don't fail on "no data to transform" * releaser: Prepare repository for 0.137.0-DEV - Update to version 0.136.2: * releaser: Bump versions for release of 0.136.2 * docker: Fix Dart Sass ARM64 arch mismatch, /cache permissions * releaser: Prepare repository for 0.137.0-DEV - Update to version 0.136.1: * releaser: Bump versions for release of 0.136.1 * Never sanitize when url set in front matter * Remove erroneously permalink validation * create/skeletons: Add delimiters to archetype front matter * releaser: Prepare repository for 0.137.0-DEV - Update to version 0.136.0: * releaser: Bump versions for release of 0.136.0 * circleci: Use default docker image * docs: Regen CLI docs * resources/page: Adjust the permalinks colon implementation a little * resources/page: Allow colons in permalinks to be escaped * commands: Use consistent style when describing subcommands * build(deps): bump github.com/tetratelabs/wazero from 1.8.0 to 1.8.1 * build(deps): bump golang.org/x/image from 0.20.0 to 0.21.0 * build(deps): bump github.com/yuin/goldmark-emoji from 1.0.3 to 1.0.4 * config: Imrove uglyurls section test * config: Fix uglyurls map parse * create/skeletons: Honor --format flag when creating default archetype * hugolib: Make .Site.Author deprecation warning clearer * Upgrade to latest Go version + Some Docker image improvements (note) * ci: Build multi-platform image with cross-compilation * tpl/tplimpl: Trim descriptions rather than just chomp * build(deps): bump golang.org/x/tools from 0.23.0 to 0.26.0 * build(deps): bump github.com/rogpeppe/go-internal from 1.12.0 to 1.13.1 * build(deps): bump github.com/evanw/esbuild from 0.23.1 to 0.24.0 * build(deps): bump github.com/hairyhenderson/go-codeowners * tailwind: Pin Tailwind 4 test to alpha 26 or later * resources/page: Treat null dates as zero dates * resources/page: Improve front matter date validation * commands: Add "hugo build" as an alias for "hugo" * markup/goldmark: Change default cell alignment in table render hook * tests: Address deprecation warnings and errors * releaser: Prepare repository for 0.136.0-DEV - Update to version 0.135.0: * releaser: Bump versions for release of 0.135.0 * build(deps): bump golang.org/x/mod from 0.19.0 to 0.21.0 * build(deps): bump github.com/bep/helpers from 0.4.0 to 0.5.0 * build(deps): bump golang.org/x/net from 0.28.0 to 0.29.0 * resources/page: Validate predefined front matter dates * build(deps): bump golang.org/x/image from 0.19.0 to 0.20.0 * github: Trigger image workflow on release.published * tailwind: Pin Tailwind 4 test to alpha 24 * tpl/compare: Use any data type for compare.Conditional condition * deps: Upgrade github.com/gobuffalo/flect v1.0.2 => v1.0.3 * releaser: Prepare repository for 0.135.0-DEV - Update to version 0.134.3: * releaser: Bump versions for release of 0.134.3 * tpl: Remove RSS deprecation site.Author check * modules: Improve console output on hugo mod init * commands: Ignore "module does not exist" errors in hugo mod init * Add exclusion for helix .bck files * hugolib: Move hugolib/site_new.go into hugolib/site.go * libsass: Resolve directory paths to directory index files * dartsass: Resolve directory paths to directory index files * internal/warpc: Improve the JS plugin API * releaser: Prepare repository for 0.135.0-DEV - Update to version 0.134.2: * releaser: Bump versions for release of 0.134.2 * Don't count HTML markup in auto summaries * releaser: Prepare repository for 0.135.0-DEV - Update to version 0.134.1: * releaser: Bump versions for release of 0.134.1 * Fix stray end p tag in Obsidian callout titles * Make ContentWithoutSummary return Content when summary is fetched from front matter * Squashed 'docs/' changes from a49697e53..ccb1b97cb * releaser: Prepare repository for 0.135.0-DEV - Update to version 0.134.0: * releaser: Bump versions for release of 0.134.0 * Update Dockerfile * markup/goldmark/blockquotes: Improve some tests * Add support for Obsidian type blockquote alerts * Squashed 'docs/' changes from fcc3ed651..a49697e53 * Rename hstring.RenderedHTML => hstring.HTML * github: Try to fix "no space left on device" on MacOS * Make all renderhook Text methods return template.HTML * Add Markdown render hooks for tables * create/skeletons: Clean up lang attribute in base template * Fix deprecation warning for resources.ToCSS * tpl/resources: Improve resources.Concat error message * tpl: Trim whitespace from google_analytics.html * Add Page.Contents with scope support * deps: Upgrade github.com/bep/golibsass v1.1.1 => v1.2.0 * build(deps): bump github.com/evanw/esbuild from 0.23.0 to 0.23.1 * build(deps): bump github.com/pelletier/go-toml/v2 from 2.2.2 to 2.2.3 * output: Fix docshelper template lookup order for AMP pages * hugolib: Add a test for overriding _internal templates * releaser: Prepare repository for 0.134.0-DEV - Update to version 0.133.1: * releaser: Bump versions for release of 0.133.1 * Revert "Adjust Circleci workflow to make the Docker images build" * Adjust Circleci workflow to make the Docker images build * Fix missing method NameNormalized panic * deps: Upgraded github.com/bep/imagemeta v0.8.0 => v0.8.1 * config: Fix pagination deprecation messages * Revert "releaser: Rework the run conditions" * Revert "circleci: Upgrade to version 2.1 of the schema" * circleci: Upgrade to version 2.1 of the schema * releaser: Rework the run conditions * Revert "releaser: Rework the run conditions" * releaser: Rework the run conditions * releaser: Prepare repository for 0.134.0-DEV - Update to version 0.133.0: * releaser: Bump versions for release of 0.133.0 * Add config options page.nextPrevSortOrder/nextPrevInSectionSortOrder * build(deps): bump gocloud.dev from 0.38.0 to 0.39.0 * deps: Upgrade github.com/tetratelabs/wazero v1.7.4-0.20240805170331-2b12e189eeec => v1.8.0 * Upgrade to Go 1.23 * releaser: Prepare repository for 0.133.0-DEV - Packaging improvements (TODO: do not forward to Factory until): * Remove bundled .wasm compiled units and compile from JS source: - ./internal/warpc/wasm - ./internal/warpc/wasm/greet.wasm - ./internal/warpc/wasm/quickjs.wasm - ./internal/warpc/wasm/renderkatex.wasm - Update to version 0.132.2: * releaser: Bump versions for release of 0.132.2 * markup/goldmark/blockquotes: Fix handling of lower/mixed case GitHub alerts * tpl/transform: Don't run ToMath tests in parallel * resources: Add URI GetRemote error * loggers: Omit map nil check * github: Add workflow_dispatch to the Docker workflow * github: Simplify Docker workflow / only trigger on new tags * github: Simplify Docker workflow * releaser: Prepare repository for 0.133.0-DEV - Update to version 0.132.1: * releaser: Bump versions for release of 0.132.1 * github: Adjust image workflow * Fix nilpointer regression with empty blockquotes * releaser: Prepare repository for 0.133.0-DEV - Update to version 0.132.0: * releaser: Bump versions for release of 0.132.0 * internal/warpc: Add license headers * Improve Katex error handling and fix handling of large expressions * Add katex option ThrowOnError * Add some more KaTeX options * tpl/transform: Make Plainify and ToMath return template.HTML * deps: Upgrade github.com/bep/imagemeta v0.7.6 => v0.8.0 * Fix compare of uints and ints in eq, gt etc. * docs: Regen docshelper * Add build time math rendering * github: Turn off the image workflow for pull request * github: Update image actions versions and some adjustments * github: Build and publish Docker image on release * Squashed 'docs/' changes from 9b06f951e..fcc3ed651 * github: Update GitHub actions versions * markup: Add blockquote render hooks * markup/goldmark/codeblocks: Simplify codeblcok hook code * Add render hooks for inline and block passthrough snippets * build(deps): bump golang.org/x/net from 0.27.0 to 0.28.0 * build(deps): bump golang.org/x/image from 0.18.0 to 0.19.0 * tpl/cast: Improve float * Skip TestEchoParam * build(deps): bump github.com/bep/imagemeta from 0.7.5 to 0.7.6 (#12720) * Fix deprecation errors * releaser: Prepare repository for 0.132.0-DEV - Update to version 0.131.0: * releaser: Bump versions for release of 0.131.0 * Fix images.AutoOrient regression * revamp pagegroup tests with quicktest * allow nested params when using Pages.GroupByParam and Pages.GroupByParamDate * build(deps): bump github.com/bep/godartsass/v2 from 2.0.0 to 2.1.0 * build(deps): bump google.golang.org/api from 0.152.0 to 0.189.0 * build(deps): bump github.com/spf13/cobra from 1.8.0 to 1.8.1 * build(deps): bump gocloud.dev from 0.36.0 to 0.38.0 * build(deps): bump github.com/gorilla/websocket from 1.5.1 to 1.5.3 * build(deps): bump github.com/kyokomi/emoji/v2 from 2.2.12 to 2.2.13 * deps: Upgrade github.com/hairyhenderson/go-codeowners v0.4.0 => v0.5.0 * build(deps): bump github.com/fatih/color from 1.16.0 to 1.17.0 * build(deps): bump github.com/evanw/esbuild from 0.21.4 to 0.23.0 * build(deps): bump github.com/tdewolff/minify/v2 from 2.20.36 to 2.20.37 * Revert "deps: Set toolchain go1.21.0 in go.mod" * Run go mod tidy * resources/page: Expand parmalinks tokens in `url` * Bump to go 1.21 in go.mod * tpl: Sync Go template packages with the Go 1.22.5 source * Upgrade to Go 1.22.5 * deps: Set toolchain go1.21.0 in go.mod * deps: Upgrade golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d => v0.23.0 * Shorten processed image filenames * Consolidate all hashing to the common/hashing package * Replace the MD5 hashing of images with xxHash * resources: Add BenchmarkHashImage * deps: Replace github.com/mitchellh/hashstructure/v2 with github.com/gohugoio/hashstructure * identity: Use xxHash in hashstructure (note) * identity: Upgrade to github.com/mitchellh/hashstructure/v2 v2.0.2 * identity: Add BenchmarkHashString * deps: Upgrade github.com/bep/imagemeta v0.7.4 => v0.7.5 * deps: Upgrade github.com/aws/aws-sdk-go-v2 v1.26.1 => v1.30.3 * deps: Upgrade to github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.7.0 * releaser: Prepare repository for 0.131.0-DEV - Packaging improvements: * Update to BuildRequires: golang(API) >= 1.21 matching go.mod - Update to version 0.130.0: * releaser: Bump versions for release of 0.130.0 * math: Add trigonometric functions and some angle helper functions * deps: Upgrade github.com/bep/imagemeta v0.7.3 => v0.7.4 * deps: Upgrade github.com/bep/imagemeta v0.7.1 => v0.7.3 * readme: Pull the star history down a little * deps: Upgraded github.com/bep/imagemeta v0.7.0 => v0.7.1 * Switch EXIF library * readme: Add Star History * releaser: Prepare repository for 0.130.0-DEV - Update to version 0.129.0: * tpl: Use xxHash instead of MD5 to hash the deferred templates * Throw error if resources.PostProcess is used in a deferred template * deps: Upgrade github.com/bep/gitmap v1.4.0 => v1.6.0 (note) * deps: Go mod tidy * deps: Upgraded github.com/tdewolff/minify/v2 v2.20.20 => v2.20.36 * deps: Upgrade to golang.org/x/image v0.18.0 * commands: Fix --navigateToChanged server behavior when editing headless content * commands: Simplify the browser live reload logic * Use xxHash for the change detector * source: Expose GitInfo Body * commands: Fix hugo mod get -u ./... * Add hash.XxHash - Update to version 0.128.2: * Fix site.GetPage, never do short lookups for paths with leadig slash - Update to version 0.128.1: * create/skeletons: Fix languageCode region subtag * Fix it so publishDate rolls up to section, taxonomy, or term pages * Update README.md - Update to version 0.128.0: * deps: Upgrade github.com/yuin/goldmark v1.7.2 => v1.7.4 * Add css.TailwindCSS * Clean up the css related template funcs package structure * Delete unused release hook script * modules: Remove newly introduced "mount source" does not exist warning * deps: Upgrade github.com/yuin/goldmark-emoji v1.0.2 => v1.0.3 * tpl/debug: Fix reset of debug timers when running the server * Implement defer * Fix Erroridf/Warnidf mixed case issue * Update README.md * common/hexec: Fall back to the binary in PATH if npx fails * deploy: Add stripIndexHtml target option * Speed up GetTerms * markup/goldmark: Add the Hugo Goldmark Extras "delete" extension * Fix live reload when both CSS and HTML changes * resources: Update Dart Sass error message * config: Fix typo * resources/page: Deprecate PageSize in favor of PagerSize * Rename DefaultPageSize => PagerSize * deps: Upgrade github.com/alecthomas/chroma v2.13.0 => v2.14.0 * resources/page: Let GroupByParam return nil instead of error * Add option to not generate aliases for first page of pagination pages * js: Support more recent targets with js.Build / esbuild * deps: Upgrade github.com/evanw/esbuild v0.20.2 => v0.21.4 - Update to version 0.127.0: * Misc remote HTTP/content adapter enhancements * resources: Fix spelling * deps: Upgrade github.com/gohugoio/httpcache v0.6.0 => v0.7.0 * Add a HTTP cache for remote resources. - Update to version 0.126.3: * content adapter: Fix site.GetPage using the base part of the path * resources/page: Deprecate .Sites.First in favor of .Sites.Default * metrics: Increase maximum length of cumulative duration to 15 * content adapter: Handle <!--more--> separator in content.value - Update to version 0.126.2: * content adapter: Fix server crash on partial edit * Delete .github/workflows/test-dart-sass-v1.yml * commands: Add shorthand flags -M (--renderToMemory) and -N (--navigateToChanged) * content adapter: Add support for menus in AddPage * content adapter: Fix issue with content starting out with a shortcode * hugolib: Allow override of sitemap file name * commands: Improve list command * config: Remove extraneous BuildConfig setting * tpl/tplimpl: Resolve render hook destinations with leading ./ * Also warn about duplicate content paths with --printPathWarnings - Update to version 0.126.1: * Fix mixed case Page params handling in content adapters * Fix paths with dots issue with content adapters - Update to version 0.126.0: * tpl/tplimpl: Plainify title and description in twitter_cards.html * tpl/tplimpl: Plainify title and description in schema.html * resources/images: Handle NaN EXIF latitude and longitude * Create pages from _content.gotmpl * create/skeletons: Remove superfluous language code fallback * tpl/tplimpl: Improve locale value in opengraph.html * build(deps): bump golang.org/x/net from 0.24.0 to 0.25.0 * build(deps): bump golang.org/x/image from 0.15.0 to 0.16.0 * livereload: Improve the livereload script build and update to v4.0.2 * tpl/tplimpl: Retain query string and fragment in render-image.html * markup/goldmark: Support extras extension - Update to version 0.125.7: * deps: Downgrade github.com/getkin/kin-openapi v0.124.0 => v0.123.0 * readme: Update Sponsors - Update to version 0.125.6: * Fix one more resource change eviction logic issue * Make the cache eviction logic for stale entities more robust * build(deps): bump github.com/pelletier/go-toml/v2 from 2.2.1 to 2.2.2 * Run mage generate * resources/page: Pull internal Page methods into its own interface - Update to version 0.125.5: * Fix rebuilds on cascade deletes/renames * commands: Print "Webserver is ..." right before "Total ..." * Make sure replaced pages gets marked as stale - Update to version 0.125.4: * commands: Clarify that create or install a theme are two options * config: Setups with only one active language can never be multihost * Fix rebuilds when running hugo -w * build(deps): bump github.com/tdewolff/minify/v2 from 2.20.19 to 2.20.20 * tpl/tplimpl: Fix double-escaping in opengraph template * Use Apache License without modification - Update to version 0.125.3: Refs boo#1223309 * markup/goldmark: Fix data race in the hugocontext wrapper * Delete .hugo_build.lock * tpl: Escape .Title in built-in image and link render hooks * tpl/tplimpl: Improve embedded templates * SECURITY.md: Update link to security model * modules: Fix potential infinite loop in module collection - Update to version 0.125.2: * Only add root sections to the section pages menu * Fix partial rebuilds for SCSS fetched with GetMatch and similar Fixes #12395 * commands: Add gen chromastyles --lineNumbersTableStyle flag * resources/images: Fix TestColorLuminance on s390x * commands: Provide examples for chromastyles flags - Update to version 0.125.1: * tpl: Use erroridf for remote YouTube errors * build: Fix `GLIBC_2.29' not found issue - Update to version 0.125.0: * docs: Regen docshelper * Fix server rebuilds when adding a content file on Linux * build(deps): bump github.com/pelletier/go-toml/v2 from 2.2.0 to 2.2.1 * Add Luminance to Color * hugolib: Add an asciidoc rebuild test case * Pass .RenderShortcodes' Page to render hooks as .PageInner * build(deps): bump google.golang.org/protobuf from 1.31.0 to 1.33.0 * helpers: Fix TrimShortHTML when used with AsciiDoc content * github: Add a "free space" step on Ubuntu * helpers: Add BenchmarkTrimShortHTML * github: Update actions * github: Format GitHub actions files * hugolib: Display server address after each rebuild * resources/page: Add taxonomies Page method * commands: Adjust completions * completion: Improve existing argument completions, add many more * Upgrade to Go 1.22.2 * build(deps): bump golang.org/x/tools from 0.19.0 to 0.20.0 * github: Fix CI build * all: Fix duplicate words in comments * build(deps): bump golang.org/x/net from 0.23.0 to 0.24.0 * build(deps): bump github.com/getkin/kin-openapi from 0.123.0 to 0.124.0 * all: Typo fixes * babel: Run go fmt * babel: Close file before removing * bump golang.org/x/mod from 0.16.0 to 0.17.0 * hugolib: Fix regression for blank summaries * Fix sectionPagesMenu for pages in root level * resources/page: Escape hash sign in permalinks * build(deps): bump github.com/pelletier/go-toml/v2 from 2.1.1 to 2.2.0 * build(deps): bump github.com/yuin/goldmark from 1.7.0 to 1.7.1 * tpl/strings: Improve type checking * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront * build(deps): bump golang.org/x/net from 0.22.0 to 0.23.0 * tpl/tplimpl: Improve youtube shortcode * errors: Return error from cast.ToStringE() consistently * tpl/tplimpl: Improve embedded opengraph template * tpl/strings: Create strings.Diff template function * Fix resource bundling for overlapping page.md vs page.txt * tpl/tplimpl: Optionally exclude content from sitemap * tpl/tplimpl: Remove trailing slash from void elements * tpl/tplimpl: Update RSS template * tpl/tplimpl: Update schema template * resources: Use different cache key when copying resources * Fix panic with debug.Dump with Page when running the server * tpl/tplimpl: Update Google Analytics template and config * hugolib: Conditionally suppress .Site.Author deprecation notice * resources/page: Fix GoDoc comment * markup/asciidocext: Add Level to Heading struct - Packaging improvements: * Add basic %check to execute binary --help - added zsh completion package - added %check section in spec file following rpmlint warning - Update to version 0.124.1: * Fix potential deadlock in Translations * Fix rebuild when changing mixed case named templates * testing: Set usesFMA as true for riscv64 too * Fix regression for outputs defined in front matter for term pages - Update to version 0.124.0: * Add segments config + --renderSegments flag * Fix .Parent when there are overlapping regular pages inbetween * hugolib: Remove Site.HomeAbsURL * deps: Upgrade github.com/gohugoio/hugo-goldmark-extensions/passthrough v0.1.0 => v0.2.0 * hugolib: Fix sitemap index with monolingual site * hugolib: Deprecate site methods Author, Authors, and Social * all: Typo fixes * Fix translationKey handling for term pages * Fix intersect and similar for term entry page collections * Upgrade to Go 1.22.1 * build(deps): bump github.com/evanw/esbuild from 0.20.1 to 0.20.2 * Fix server rebuilds when adding sub sections especially on Windows * tpl/tplimpl: Remove deprecated method from sitemapindex.xml * build(deps): bump golang.org/x/tools from 0.18.0 to 0.19.0 * build(deps): bump github.com/tdewolff/minify/v2 from 2.20.17 to 2.20.19 * deps: Upgrade github.com/alecthomas/chroma/v2 to v2.13.0 * tpl/tplimpl: Modify figure shortcode to look for page resource * Fix panic when changing archetype files when servere is running * build(deps): bump golang.org/x/mod from 0.15.0 to 0.16.0 * Fix front matter date location when value gets inherited from other dates * Fix Name for nested resourced fetched in resources.ByName and similar * common/hugo: Rename IsMultiHost and IsMultiLingual * hugolib: Deprecate .Site.MultiLingual in favor of hugo.IsMultiLingual * snap: Transition to from core20 to core22 - Update to version 0.123.8: * markup/goldmark: TOC: render strikethrough, emojis * Add hugo.IsMultiHost * docs: Fix hyphens and grammar in synopsis of command 'hugo server' * resources/images: Retain newlines with text overlays * Don't auto-create empty sections for nested taxonomies * Fix resource name in resources.ByType * Fix global resource isn't published when using an uncommon code construct * Fix section page resource not published if resource filename partially matches content file name * Fix taxonomy kind template lookup issue * tpl/tplimpl: Honor markdown attributes in embedded image render hook - Update to version 0.123.7: * hugofs: Fix vertical mount merge issue * Fix and add integration test for the Bootstrap SCSS module for both Dart Sass and Libsass * Fix resources.GetMatch, resources.Match, and resources.ByType to they don't normalize permalinks * Make sure that sitemaps gets generated even if there is a content bundle with the same path * resources/page: Make Taxonomy.Get and Taxonomy.Count case-insensitive - Update to version 0.123.6: * Fix panic when cascading headless from site config to section that does not have an _index.md file * Fix assets vs data issue * Fix draft for non-default content when content in default language does not exist - Update to version 0.123.5: * Fix .Page.Pages with similary named sections * Fix single mount rename panic * Fix multihost processed image not copied to non-default content languages * build(deps): bump github.com/bep/overlayfs from 0.9.1 to 0.9.2 - Update to version 0.123.4: * Fix cascade-pattern-with-extension for cascade in site config * build(deps): bump github.com/spf13/fsync from 0.10.0 to 0.10.1 * Fix term template lookup when its backed by a content file * resource: Revert the normalization of Resource.Name * Fix panic for disableKinds page for content resources * tocss: Fix the import resolving from absolute to relative assets paths * Maek Resoyrce.Key as (mostly) internal * config/allconfig: Fix typo - Update to version 0.123.3: * cache/dynacache: Reset ticker in case one cache eviction takes some time * Revert "cache/dynacache: Prevent multiple concurrent resizes" * cache/dynacache: Prevent multiple concurrent resizes * Speed up GetPage * hugolib: Fix a .Page.GetPage from bundle case * resources: Skip the image golden tests when running locally * js: Support JSX and JSXImportSourceOptions * hugolib: Add capitalizeListTitles config option - Update to version 0.123.2: * Fix it so not all bundled resources are removed when one translation is drafted * commands/mod: Ignore invalid module path * Fix regression on handling of overlapping file mounts * Sitemap should not use list.xml * Fix rebuild when adding a bundle with space in name * Fix relative import issue in libsass/dart sass * Fix relref regression with trailing slash - Update to version 0.123.1: * tpl/tplimpl: Resolve fragments in link render hook * Fix rebuilding of pages without default content language * Fix dart sass import regression * Fall back to original name in Resources.GetMatch/Match * Fix robots.txt using the built-in template regression - Update to version 0.123.0: * build(deps): bump github.com/tdewolff/minify/v2 from 2.20.16 to 2.20.17 * build(deps): bump github.com/evanw/esbuild from 0.20.0 to 0.20.1 * Handle rebuilds when resources passed to transform.Unmarshal etc. changes * Fix handling of build options for term pages * Fix sample logic when adding content files in server * build(deps): bump golang.org/x/tools from 0.17.0 to 0.18.0 * Fix handling of draft term pages * releaser: Fix archive homepage and description * commands: Fix --clock with the list command * Don't use the same value in .Data.Term.Title as in .Title * Fix server panic on i18n file change * build(deps): bump golang.org/x/net from 0.20.0 to 0.21.0 * Fix rebuild regression on non-default content language edits * Let standard library handle charset parameter to MIME types * Fix i18n rebuild regression * Fix rebuild with resources.Concat * Add images.Dither filter * markup/goldmark: Update TOC test * Fix taxonomy term with backing file regression * markup/goldmark: Improve TOC tests * Move the duplicate page/resource filter * Make HTML behave exactly like other content formats (note) * docs: Regen CLI docs * docs: Regenerate docshelper * build(deps): bump golang.org/x/mod from 0.14.0 to 0.15.0 * Upgrade to Go 1.22 * Avoid impporting deploy from config when nodeploy tag is set * Fix rebuild of changed bundled content files * Fix site.Taxonomies for taxonomies with space in name * commands: Remove unused memstats flag * source: Remove unused Filesystem struct * Filter dot files etc. in i18n * commands: Revert the recent changes that allowed profiling on server rebuilds * commands: Make the server flag --renderToDisk into --renderToMemory (note) * build(deps): bump github.com/yuin/goldmark from 1.6.0 to 1.7.0 * Handle resource changes when the resources is already evicted from cache * all: Rename Unmormalized => Unnormalized * hugolib: Formally deprecate .Page.NextPage .Page.PrevPage * hugio: Rename strigReadSeeker => stringReadSeeker * resources/page: Formally deprecate .Site.LastChange * Preserve file/dir name case when loading data * Detect now invalid path patterns in cascade * Handle build vs _build in front matter * resources: Optimize reading resource Content when it's already a string * Misc resource fixes/improvements * tpl/tplimpl: Update embedded instagram, twitter, and vimeo shortcodes * Add some more context to error * build(deps): bump github.com/getkin/kin-openapi from 0.122.0 to 0.123.0 * build(deps): bump github.com/tdewolff/minify/v2 from 2.20.13 to 2.20.16 * Improve nilpointer error message * Fix disabled languages regression * tpl/data: Fix GetCSV deprecation message * hugolib: Adjust a test case * hugolib: Revert deprecation of .Page.Lang * all: Deprecate .Page.Lang and .Page.File.Lang * Fix failing test on Windows * config/security: Add SYSTEMDRIVE to OsEnv allowlist * hugolib: Add some more details to the "paginator not supported" error * Run go mod tidy * build(deps): bump github.com/evanw/esbuild from 0.19.12 to 0.20.0 * deploy: Fix CloudFront invalidation with AWS SDK2 * deps: Update gocloud.dev/aws * Upgrade to deploy to use AWS SDK V2 * Improve error message when attempting to paginate from a single page template * build(deps): bump github.com/aws/aws-sdk-go from 1.48.6 to 1.50.7 * build(deps): bump golang.org/x/image from 0.14.0 to 0.15.0 * Fix build error * docs: Make null booleans falsy in the docs helper * Filter out duplicate content resource files * docs: Regen docs helper * output: Prevent setting Name directly in new output formats * Create default link and image render hooks * Fix recent regression .Resources.Get for resources with spaces in filename * Emit a warning that can be turned off when overwriting built-in .Params values * Add warnidf template function * Add path, kind and lang to content front matter * hugofs/glob: Fix dropped test error * all: Run gofumpt -l -w . * testing: Simplify some integration tests * Add the [params] concept to front matter * tpl/data: Deprecate data.GetJSON and data.GetCSV * modules: Print required Hugo version for incompatible modules * hugolib: Remove unused test image * navigation: Improve menu cache * testing: Rename integration_test.go to PACKAGE_integration_test.go * Port some integration tests to new test setup * all: Rework page store, add a dynacache, improve partial rebuilds, and some general spring cleaning hugo-0.163.1-bp157.2.3.1.src.rpm hugo-0.163.1-bp157.2.3.1.x86_64.rpm hugo-bash-completion-0.163.1-bp157.2.3.1.noarch.rpm hugo-zsh-completion-0.163.1-bp157.2.3.1.noarch.rpm hugo-0.163.1-bp157.2.3.1.i586.rpm hugo-0.163.1-bp157.2.3.1.aarch64.rpm hugo-0.163.1-bp157.2.3.1.ppc64le.rpm hugo-0.163.1-bp157.2.3.1.s390x.rpm openSUSE-2026-237 Security update for transmission moderate openSUSE Backports SLE-15-SP7 Update This update for transmission fixes the following issues: - CVE-2026-38978: add clickjack safeguards when serving http responses (boo#1267404). - Update to 4.0.6: + Improved parsing HTTP tracker announce response. (#6223) + Fixed 4.0.0 bug that caused some user scripts to have an invalid TR_TORRENT_TRACKERS environment variable. (#6434) + Fixed 4.0.0 bug where alt-speed-enabled had no effect in settings.json. (#6483) + Fixed 4.0.0 bug where the GTK client's "Use authentication" option was not saved between's sessions. (#6514) + Fixed 4.0.0 bug where the filename for single-file torrents aren't sanitized. (#6846) + Fixed 4.0.0 bug where piece size description text and slider state in torrent creation dialog are not always up-to-date. + Fixed build when compiling with GTKMM 4. (#6393) + Added the launchable desktop-id to metainfo files. (#6779) + Fixed build when compiling on BSD. (#6812) + Fixed a 4.0.0 bug where the infinite ratio symbol was displayed incorrectly in the WebUI. (#6491, #6500) + Fixed layout issue in speed display. (#6570) + General UI improvement related to filterbar and fixes download/upload speed info wrap. (#6761) + Fixed a couple of logging issues. (#6463) system-user-transmission-4.0.6-bp157.2.3.1.noarch.rpm transmission-4.0.6-bp157.2.3.1.src.rpm transmission-4.0.6-bp157.2.3.1.x86_64.rpm transmission-common-4.0.6-bp157.2.3.1.noarch.rpm transmission-daemon-4.0.6-bp157.2.3.1.x86_64.rpm transmission-gtk-4.0.6-bp157.2.3.1.x86_64.rpm transmission-gtk-lang-4.0.6-bp157.2.3.1.noarch.rpm transmission-qt-4.0.6-bp157.2.3.1.x86_64.rpm transmission-qt-lang-4.0.6-bp157.2.3.1.noarch.rpm transmission-4.0.6-bp157.2.3.1.aarch64.rpm transmission-daemon-4.0.6-bp157.2.3.1.aarch64.rpm transmission-gtk-4.0.6-bp157.2.3.1.aarch64.rpm transmission-qt-4.0.6-bp157.2.3.1.aarch64.rpm transmission-4.0.6-bp157.2.3.1.ppc64le.rpm transmission-daemon-4.0.6-bp157.2.3.1.ppc64le.rpm transmission-gtk-4.0.6-bp157.2.3.1.ppc64le.rpm transmission-qt-4.0.6-bp157.2.3.1.ppc64le.rpm transmission-4.0.6-bp157.2.3.1.s390x.rpm transmission-daemon-4.0.6-bp157.2.3.1.s390x.rpm transmission-gtk-4.0.6-bp157.2.3.1.s390x.rpm transmission-qt-4.0.6-bp157.2.3.1.s390x.rpm openSUSE-2026-233 Security update for chromium critical openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - promote Chromium 150 (150.0.7871.46) to stable (boo#1270051) * CVE-2026-13774: Use after free in Extensions * CVE-2026-13775: Use after free in GPU * CVE-2026-14398: Use after free in ANGLE * CVE-2026-13776: Type Confusion in Dawn * CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb * CVE-2026-13778: Use after free in WebUSB * CVE-2026-13779: Use after free in Chromoting * CVE-2026-13780: Insufficient validation of untrusted input in ANGLE * CVE-2026-13781: Insufficient validation of untrusted input in Skia * CVE-2026-14417: Use after free in Dawn * CVE-2026-13782: Use after free in Browser * CVE-2026-13783: Use after free in Views * CVE-2026-13784: Use after free in Views * CVE-2026-14419: Use after free in Skia * CVE-2026-13785: Use after free in Bluetooth * CVE-2026-14420: Out of bounds read and write in Dawn * CVE-2026-13786: Use after free in Ozone * CVE-2026-14427: Heap buffer overflow in Skia * CVE-2026-13787: Use after free in Chromoting * CVE-2026-13788: Use after free in Fullscreen * CVE-2026-14382: Insufficient validation of untrusted input in ANGLE * CVE-2026-13790: Side-channel information leakage in Scroll * CVE-2026-14385: Heap buffer overflow in ANGLE * CVE-2026-13791: Insufficient validation of untrusted input in Downloads * CVE-2026-13792: Use after free in Touchbar * CVE-2026-13793: Insufficient policy enforcement in SVG * CVE-2026-14392: Out of bounds write in Tint * CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-14422: Out of bounds read and write in Tint * CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS * CVE-2026-14426: Use after free in V8 * CVE-2026-13796: Integer overflow in Chromecast * CVE-2026-13797: Insufficient validation of untrusted input in Chromecast * CVE-2026-14386: Out of bounds read in ANGLE * CVE-2026-13798: Heap buffer overflow in Chromecast * CVE-2026-13799: Use after free in QUIC * CVE-2026-13800: Inappropriate implementation in Updater * CVE-2026-13801: Integer overflow in Chromecast * CVE-2026-13802: Use after free in Views * CVE-2026-13803: Type Confusion in Chrome Tabs * CVE-2026-13804: Use after free in Chromecast * CVE-2026-13805: Use after free in GFX * CVE-2026-14390: Use after free in ANGLE * CVE-2026-13806: Insufficient validation of untrusted input in Accessibility * CVE-2026-13807: Use after free in Import * CVE-2026-13808: Insufficient data validation in Chrome for iOS * CVE-2026-13809: Side-channel information leakage in Safe Browsing * CVE-2026-13810: Inappropriate implementation in Input * CVE-2026-13811: Use after free in IME * CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13814: Use after free in Views * CVE-2026-13815: Use after free in Blink * CVE-2026-13816: Insufficient validation of untrusted input in File Input * CVE-2026-14396: Out of bounds read in ANGLE * CVE-2026-13817: Insufficient validation of untrusted input in Glic * CVE-2026-13818: Inappropriate implementation in Passwords * CVE-2026-13819: Out of bounds read in ANGLE * CVE-2026-13820: Out of bounds read in Skia * CVE-2026-14400: Out of bounds write in ANGLE * CVE-2026-14401: Insufficient validation of untrusted input in ANGLE * CVE-2026-14402: Uninitialized Use in ANGLE * CVE-2026-13821: Use after free in Canvas * CVE-2026-13822: Inappropriate implementation in Extensions * CVE-2026-13823: Use after free in Glic * CVE-2026-13824: Insufficient validation of untrusted input in Extensions * CVE-2026-13825: Uninitialized Use in Dawn * CVE-2026-13826: Inappropriate implementation in Autofill * CVE-2026-13827: Use after free in Updater * CVE-2026-13828: Inappropriate implementation in Enterprise * CVE-2026-13829: Insufficient validation of untrusted input in Settings * CVE-2026-13830: Use after free in Chromoting * CVE-2026-13831: Use after free in GPU * CVE-2026-13832: Use after free in Headless * CVE-2026-14411: Insufficient validation of untrusted input in ANGLE * CVE-2026-13833: Uninitialized Use in ANGLE * CVE-2026-14412: Insufficient validation of untrusted input in ANGLE * CVE-2026-14413: Uninitialized Use in ANGLE * CVE-2026-13834: Insufficient validation of untrusted input in ANGLE * CVE-2026-13835: Inappropriate implementation in XML * CVE-2026-13836: Inappropriate implementation in CSS * CVE-2026-13837: Inappropriate implementation in CSS * CVE-2026-13838: Inappropriate implementation in CSS * CVE-2026-13839: Inappropriate implementation in CSS * CVE-2026-13840: Insufficient policy enforcement in Canvas * CVE-2026-13841: Integer overflow in Skia * CVE-2026-13842: Incorrect security UI in Chrome for iOS * CVE-2026-14418: Uninitialized Use in ANGLE * CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13844: Use after free in Updater * CVE-2026-13845: Use after free in DOM * CVE-2026-13846: Use after free in USB * CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13848: Use after free in Forms * CVE-2026-13849: Insufficient validation of untrusted input in Chromoting * CVE-2026-14423: Type Confusion in Tint * CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-14424: Use after free in Dawn * CVE-2026-14425: Use after free in ANGLE * CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-14428: Insufficient validation of untrusted input in Dawn * CVE-2026-14429: Insufficient validation of untrusted input in Skia * CVE-2026-14430: Integer overflow in V8 * CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-13853: Use after free in Journeys * CVE-2026-13854: Use after free in Ozone * CVE-2026-14431: Type Confusion in V8 * CVE-2026-13855: Use after free in Ozone * CVE-2026-13856: Insufficient validation of untrusted input in Speech * CVE-2026-13857: Inappropriate implementation in Geometry * CVE-2026-13858: Out of bounds read in FFmpeg * CVE-2026-13859: Inappropriate implementation in ANGLE * CVE-2026-14391: Integer overflow in ANGLE * CVE-2026-13860: Incorrect security UI in Autofill * CVE-2026-14408: Uninitialized Use in Dawn * CVE-2026-14381: Incorrect security UI in WebAppInstalls * CVE-2026-14383: Inappropriate implementation in V8 * CVE-2026-13861: Use after free in Core * CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) * CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs * CVE-2026-13864: Insufficient policy enforcement in WebHID * CVE-2026-13865: Insufficient validation of untrusted input in Enterprise * CVE-2026-13866: Insufficient validation of untrusted input in Input * CVE-2026-13867: Inappropriate implementation in Geolocation * CVE-2026-13868: Inappropriate implementation in Network * CVE-2026-14384: Out of bounds read in ANGLE * CVE-2026-13869: Use after free in Device * CVE-2026-13870: Use after free in WebView * CVE-2026-13871: Insufficient data validation in GuestView * CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-13873: Out of bounds memory access in Layout * CVE-2026-13874: Inappropriate implementation in DataTransfer * CVE-2026-13875: Insufficient validation of untrusted input in GPU * CVE-2026-13876: Inappropriate implementation in Network * CVE-2026-13877: Insufficient validation of untrusted input in ANGLE * CVE-2026-13878: Use after free in Bluetooth * CVE-2026-13879: Use after free in Bluetooth * CVE-2026-13880: Use after free in USB * CVE-2026-13881: Insufficient data validation in WebAppInstalls * CVE-2026-13882: Inappropriate implementation in USB * CVE-2026-13883: Type Confusion in ANGLE * CVE-2026-13884: Heap buffer overflow in Chromecast * CVE-2026-14387: Integer overflow in Skia * CVE-2026-13885: Use after free in Skia * CVE-2026-13886: Policy bypass in Isolated Web Apps * CVE-2026-14388: Out of bounds read in ANGLE * CVE-2026-14389: Integer overflow in Skia * CVE-2026-13887: Insufficient policy enforcement in NFC * CVE-2026-13888: Use after free in Extensions * CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication * CVE-2026-13890: Out of bounds read in Chromecast * CVE-2026-13891: Insufficient validation of untrusted input in Extensions * CVE-2026-13892: Inappropriate implementation in Chrome for iOS * CVE-2026-13893: Insufficient validation of untrusted input in WebUI * CVE-2026-13894: Insufficient policy enforcement in Network * CVE-2026-13895: Inappropriate implementation in Autofill * CVE-2026-13896: Insufficient policy enforcement in Glic * CVE-2026-13897: Insufficient policy enforcement in Chromecast * CVE-2026-13898: Use after free in Cast Receiver * CVE-2026-13899: Use after free in HTML * CVE-2026-13900: Insufficient validation of untrusted input in Chromecast * CVE-2026-13901: Insufficient validation of untrusted input in Serial * CVE-2026-13902: Inappropriate implementation in Chrome for iOS * CVE-2026-13903: Insufficient policy enforcement in Bluetooth * CVE-2026-13904: Incorrect security UI in Safe Browsing * CVE-2026-13905: Incorrect security UI in Chrome for iOS * CVE-2026-13906: Out of bounds read in Codecs * CVE-2026-13907: Inappropriate implementation in iOSWeb * CVE-2026-13908: Insufficient validation of untrusted input in Omnibox * CVE-2026-13909: Insufficient policy enforcement in DevTools * CVE-2026-13910: Insufficient policy enforcement in WebXR * CVE-2026-13911: Insufficient data validation in Spellcheck * CVE-2026-13912: Incorrect security UI in Safe Browsing * CVE-2026-13913: Insufficient policy enforcement in Autofill * CVE-2026-13914: Inappropriate implementation in Passwords * CVE-2026-13915: Use after free in Chrome for iOS * CVE-2026-13916: Inappropriate implementation in Chrome for iOS * CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13918: Use after free in Chrome for iOS * CVE-2026-13919: Insufficient data validation in Extensions * CVE-2026-14393: Use after free in V8 * CVE-2026-13920: Insufficient validation of untrusted input in Media * CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials * CVE-2026-13922: Side-channel information leakage in Paint * CVE-2026-13923: Uninitialized Use in GPU * CVE-2026-14397: Out of bounds write in ANGLE * CVE-2026-13924: Insufficient validation of untrusted input in WebView * CVE-2026-13925: Inappropriate implementation in Downloads * CVE-2026-13926: Insufficient validation of untrusted input in Network * CVE-2026-13927: Insufficient validation of untrusted input in UI * CVE-2026-13928: Insufficient validation of untrusted input in Enterprise * CVE-2026-13929: Insufficient validation of untrusted input in DevTools * CVE-2026-13930: Insufficient policy enforcement in Actor * CVE-2026-13931: Inappropriate implementation in Media * CVE-2026-13932: Inappropriate implementation in Sharing * CVE-2026-13933: Insufficient policy enforcement in Passwords * CVE-2026-13934: Insufficient validation of untrusted input in Dawn * CVE-2026-14399: Uninitialized Use in Dawn * CVE-2026-13935: Side-channel information leakage in ComputePressure * CVE-2026-13936: Inappropriate implementation in Passwords * CVE-2026-13937: Insufficient policy enforcement in Passwords * CVE-2026-13938: Integer overflow in Fonts * CVE-2026-13939: Insufficient validation of untrusted input in WebShare * CVE-2026-13940: Uninitialized Use in Cast * CVE-2026-13941: Inappropriate implementation in SiteSettings * CVE-2026-13942: Insufficient validation of untrusted input in Video Capture * CVE-2026-13943: Uninitialized Use in CSS * CVE-2026-13944: Inappropriate implementation in DataTransfer * CVE-2026-13945: Insufficient policy enforcement in Extensions * CVE-2026-13946: Inappropriate implementation in ScriptInjections * CVE-2026-13947: Uninitialized Use in XR * CVE-2026-13948: Insufficient policy enforcement in Extensions * CVE-2026-13949: Insufficient policy enforcement in Payments * CVE-2026-14404: Inappropriate implementation in PDFium * CVE-2026-13950: Uninitialized Use in GPU * CVE-2026-13951: Policy bypass in USB * CVE-2026-13952: Inappropriate implementation in PerformanceAPIs * CVE-2026-14406: Out of bounds read in V8 * CVE-2026-13953: Inappropriate implementation in SplitView * CVE-2026-13954: Insufficient policy enforcement in XML * CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs * CVE-2026-13956: Incorrect security UI in PageInfo * CVE-2026-13957: Incorrect security UI in Extensions * CVE-2026-13958: Uninitialized Use in Codecs * CVE-2026-14407: Inappropriate implementation in V8 * CVE-2026-13959: Insufficient validation of untrusted input in Blink * CVE-2026-13960: Inappropriate implementation in Passwords * CVE-2026-13961: Insufficient validation of untrusted input in DevTools * CVE-2026-13962: Insufficient data validation in PDF * CVE-2026-13963: Inappropriate implementation in DevTools * CVE-2026-13964: Insufficient policy enforcement in WebView * CVE-2026-13965: Use after free in Oilpan * CVE-2026-13966: Inappropriate implementation in History * CVE-2026-13967: Type Confusion in V8 * CVE-2026-13968: Insufficient validation of untrusted input in DevTools * CVE-2026-13969: Uninitialized Use in UI * CVE-2026-13970: Uninitialized Use in Media * CVE-2026-13971: Uninitialized Use in Skia * CVE-2026-13972: Inappropriate implementation in Paint * CVE-2026-13973: Inappropriate implementation in UI * CVE-2026-13974: Integer overflow in Safe Browsing * CVE-2026-13975: Out of bounds read in ANGLE * CVE-2026-13976: Heap buffer overflow in Storage * CVE-2026-13977: Inappropriate implementation in HTMLParser * CVE-2026-13978: Insufficient policy enforcement in PageInfo * CVE-2026-14414: Insufficient validation of untrusted input in Skia * CVE-2026-13979: Inappropriate implementation in Paint * CVE-2026-13980: Incorrect security UI in Chrome for iOS * CVE-2026-13981: Inappropriate implementation in Chrome for iOS * CVE-2026-13982: Incorrect security UI in Passwords * CVE-2026-13983: Incorrect security UI in Chrome for iOS * CVE-2026-13984: Incorrect security UI in TabStrip * CVE-2026-13985: Inappropriate implementation in MediaCapture * CVE-2026-13986: Inappropriate implementation in Media UI * CVE-2026-13987: Incorrect security UI in Mobile * CVE-2026-13988: Inappropriate implementation in Paint * CVE-2026-13989: Insufficient policy enforcement in PageInfo * CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer * CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13992: Inappropriate implementation in UI * CVE-2026-13993: Incorrect security UI in WebAppInstalls * CVE-2026-13994: Inappropriate implementation in Credential Management * CVE-2026-13995: Insufficient validation of untrusted input in Autofill * CVE-2026-13996: Incorrect security UI in Permissions * CVE-2026-13997: Incorrect security UI in Extensions * CVE-2026-13998: Incorrect security UI in File Input * CVE-2026-13999: Inappropriate implementation in Extensions * CVE-2026-14000: Inappropriate implementation in XML * CVE-2026-14001: Inappropriate implementation in Network * CVE-2026-14002: Inappropriate implementation in Geolocation * CVE-2026-14003: Insufficient policy enforcement in Extensions * CVE-2026-14004: Inappropriate implementation in CSS * CVE-2026-14005: Use after free in Omnibox * CVE-2026-14006: Use after free in Navigation * CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy * CVE-2026-14008: Uninitialized Use in WebXR * CVE-2026-14009: Insufficient data validation in Passwords * CVE-2026-14010: Uninitialized Use in Codecs * CVE-2026-14011: Out of bounds read in SurfaceCapture * CVE-2026-14421: Uninitialized Use in Dawn * CVE-2026-14012: Side-channel information leakage in CSS * CVE-2026-14013: Inappropriate implementation in SVG * CVE-2026-14014: Inappropriate implementation in Paint * CVE-2026-14015: Inappropriate implementation in WebRTC * CVE-2026-14016: Insufficient policy enforcement in SVG * CVE-2026-14017: Inappropriate implementation in Navigation * CVE-2026-14018: Use after free in Updater * CVE-2026-14019: Inappropriate implementation in Passwords * CVE-2026-14020: Insufficient validation of untrusted input in WebXR * CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI * CVE-2026-14022: Insufficient validation of untrusted input in Network * CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI * CVE-2026-14024: Use after free in Ozone * CVE-2026-14432: Use after free in V8 * CVE-2026-14025: Use after free in Views * CVE-2026-14026: Incorrect security UI in SplitView * CVE-2026-14027: Use after free in SignIn * CVE-2026-14028: Incorrect security UI in Chrome for iOS * CVE-2026-14030: Incorrect security UI in SplitView * CVE-2026-14031: Incorrect security UI in File Input * CVE-2026-14032: Use after free in Bluetooth * CVE-2026-14033: Insufficient policy enforcement in Media * CVE-2026-14034: Inappropriate implementation in WebXR * CVE-2026-14035: Insufficient policy enforcement in Bluetooth * CVE-2026-14036: Insufficient policy enforcement in Bluetooth * CVE-2026-14037: Insufficient policy enforcement in GPU * CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page * CVE-2026-14039: Insufficient policy enforcement in GetUserMedia * CVE-2026-14040: Use after free in BrowserTag * CVE-2026-14041: Insufficient policy enforcement in Serial * CVE-2026-14042: Inappropriate implementation in Isolated Web Apps * CVE-2026-14043: Use after free in GetUserMedia * CVE-2026-14044: Use after free in ANGLE * CVE-2026-14045: Insufficient validation of untrusted input in Network * CVE-2026-14046: Inappropriate implementation in CustomTabs * CVE-2026-14047: Insufficient policy enforcement in Extensions * CVE-2026-14048: Use after free in Chromecast * CVE-2026-14049: Inappropriate implementation in GPU * CVE-2026-14050: Insufficient policy enforcement in Passwords * CVE-2026-14051: Uninitialized Use in GamepadAPI * CVE-2026-14052: Insufficient policy enforcement in FileSystem * CVE-2026-14053: Insufficient policy enforcement in Extensions * CVE-2026-14054: Insufficient policy enforcement in Network * CVE-2026-14055: Insufficient validation of untrusted input in Device Trust * CVE-2026-14056: Insufficient validation of untrusted input in Media * CVE-2026-14057: Insufficient policy enforcement in FedCM * CVE-2026-14058: Policy bypass in Parser * CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets * CVE-2026-14060: Insufficient validation of untrusted input in Chromoting * CVE-2026-14061: Inappropriate implementation in Dawn * CVE-2026-14062: Inappropriate implementation in Views * CVE-2026-14063: Out of bounds memory access in Chromecast * CVE-2026-14064: Use after free in PageInfo * CVE-2026-14065: Insufficient validation of untrusted input in PageInfo * CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-14067: Use after free in Chrome for iOS * CVE-2026-14068: Inappropriate implementation in Omnibox * CVE-2026-14069: Integer overflow in WebNN * CVE-2026-14070: Uninitialized Use in WebNN * CVE-2026-14071: Side-channel information leakage in WebAudio * CVE-2026-14072: Incorrect security UI in SplitView * CVE-2026-14073: Insufficient policy enforcement in WebXR * CVE-2026-14394: Use after free in V8 * CVE-2026-14395: Out of bounds write in V8 * CVE-2026-14074: Side-channel information leakage in WebAuthentication * CVE-2026-14075: Policy bypass in Chrome for iOS * CVE-2026-14076: Policy bypass in Network * CVE-2026-14077: Incorrect security UI in Select * CVE-2026-14078: Policy bypass in WebRTC * CVE-2026-14079: Policy bypass in Network * CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher * CVE-2026-14081: Insufficient policy enforcement in DevTools * CVE-2026-14082: Race in Storage * CVE-2026-14083: Insufficient validation of untrusted input in HTML * CVE-2026-14084: Insufficient validation of untrusted input in Chromoting * CVE-2026-14085: Side-channel information leakage in CSS * CVE-2026-14086: Insufficient policy enforcement in HID * CVE-2026-14087: Insufficient validation of untrusted input in WebNN * CVE-2026-14088: Uninitialized Use in Canvas * CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker * CVE-2026-14090: Out of bounds read in CameraCapture * CVE-2026-14091: Use after free in DevTools * CVE-2026-14092: Insufficient policy enforcement in Privacy * CVE-2026-14093: Use after free in Cast * CVE-2026-14094: Use after free in Installer * CVE-2026-14095: Insufficient validation of untrusted input in Browser * CVE-2026-14403: Use after free in V8 * CVE-2026-14096: Object lifecycle issue in Input * CVE-2026-14097: Inappropriate implementation in WebAppInstalls * CVE-2026-14098: Inappropriate implementation in CSS * CVE-2026-14405: Uninitialized Use in V8 * CVE-2026-14099: Use after free in Chrome for iOS * CVE-2026-14100: Insufficient data validation in NetworkCache * CVE-2026-14101: Insufficient policy enforcement in Sandbox * CVE-2026-14102: Use after free in Passwords * CVE-2026-14103: Use after free in SSL * CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-14105: Insufficient policy enforcement in Speech * CVE-2026-14106: Insufficient validation of untrusted input in Text * CVE-2026-14107: Use after free in Scheduling * CVE-2026-14108: Use after free in PDFium * CVE-2026-14109: Insufficient policy enforcement in Mojo * CVE-2026-14110: Inappropriate implementation in DarkMode * CVE-2026-14111: Use after free in WebProtect * CVE-2026-14112: Inappropriate implementation in Enterprise * CVE-2026-14113: Use after free in Updater * CVE-2026-14114: Inappropriate implementation in WebAppInstalls * CVE-2026-14115: Insufficient validation of untrusted input in Cast * CVE-2026-14116: Insufficient validation of untrusted input in DevTools * CVE-2026-14117: Insufficient validation of untrusted input in DevTools * CVE-2026-14118: Insufficient data validation in DevTools * CVE-2026-14119: Type Confusion in Bluetooth * CVE-2026-14120: Inappropriate implementation in DevTools * CVE-2026-14121: Use after free in Chromoting * CVE-2026-14409: Inappropriate implementation in V8 * CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-14410: Inappropriate implementation in Skia * CVE-2026-14123: Incorrect security UI in Chrome for iOS * CVE-2026-14124: Inappropriate implementation in CredentialProvider * CVE-2026-14125: Uninitialized Use in ANGLE * CVE-2026-14126: Incorrect security UI in UI * CVE-2026-14127: Inappropriate implementation in Printing * CVE-2026-14128: Insufficient data validation in Chrome for iOS * CVE-2026-14129: Incorrect security UI in PreviewTab * CVE-2026-14130: Incorrect security UI in Omnibox * CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-14132: Inappropriate implementation in WebXR * CVE-2026-14133: Race in History Embeddings * CVE-2026-14134: Inappropriate implementation in Autofill * CVE-2026-14135: Insufficient validation of untrusted input in Network * CVE-2026-14136: Incorrect security UI in Chrome for iOS * CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-14138: Inappropriate implementation in WebAppInstalls * CVE-2026-14139: Inappropriate implementation in TabStrip * CVE-2026-14140: Insufficient validation of untrusted input in Input * CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture * CVE-2026-14142: Inappropriate implementation in Extensions * CVE-2026-14143: Incorrect security UI in Passwords * CVE-2026-14144: Incorrect security UI in Views * CVE-2026-14145: Inappropriate implementation in CSS * CVE-2026-14146: Inappropriate implementation in CSS * CVE-2026-14147: Inappropriate implementation in CSS * CVE-2026-14415: Inappropriate implementation in V8 * CVE-2026-14148: Type Confusion in CSS * CVE-2026-14149: Use after free in Audio * CVE-2026-14416: Out of bounds read in Dawn * CVE-2026-14150: Insufficient validation of untrusted input in Speech * CVE-2026-14151: Inappropriate implementation in AI * CVE-2026-14152: Out of bounds write in ANGLE * CVE-2026-14153: Inappropriate implementation in Glic * CVE-2026-14154: Inappropriate implementation in DevTools * CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI * CVE-2026-14156: Policy bypass in StorageAccessAPI chromedriver-150.0.7871.46-bp157.2.181.1.x86_64.rpm chromium-150.0.7871.46-bp157.2.181.1.nosrc.rpm chromium-150.0.7871.46-bp157.2.181.1.x86_64.rpm chromedriver-150.0.7871.46-bp157.2.181.1.aarch64.rpm chromium-150.0.7871.46-bp157.2.181.1.aarch64.rpm chromedriver-150.0.7871.46-bp157.2.181.1.ppc64le.rpm chromium-150.0.7871.46-bp157.2.181.1.ppc64le.rpm openSUSE-2026-232 Security update for go-sendxmpp important openSUSE Backports SLE-15-SP7 Update This update for go-sendxmpp fixes the following issues: Update to 0.16.0: - CVE-2026-1229: circl: The CombinedMult function produces an incorrect value (boo#1265538). - CVE-2026-39821: net: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (boo#1266617). go-sendxmpp-0.16.0-bp157.2.9.1.src.rpm go-sendxmpp-0.16.0-bp157.2.9.1.x86_64.rpm go-sendxmpp-0.16.0-bp157.2.9.1.i586.rpm go-sendxmpp-0.16.0-bp157.2.9.1.aarch64.rpm go-sendxmpp-0.16.0-bp157.2.9.1.ppc64le.rpm go-sendxmpp-0.16.0-bp157.2.9.1.s390x.rpm openSUSE-2026-241 Security update for python-social-auth-app-django moderate openSUSE Backports SLE-15-SP7 Update This update for python-social-auth-app-django fixes the following issues: - CVE-2025-61783: unsafe account association could lead to account compromise (boo#1251851). python-social-auth-app-django-5.4.0-bp157.2.3.1.src.rpm python311-social-auth-app-django-5.4.0-bp157.2.3.1.noarch.rpm openSUSE-2026-238 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 150.0.7871.114 (boo#1271093): * CVE-2026-15112: Use after free in Ozone * CVE-2026-15129: Use after free in Views * CVE-2026-15132: Uninitialized Use in V8 * CVE-2026-15133: Use after free in InterestGroups * CVE-2026-15108: Integer overflow in Extensions API * CVE-2026-15109: Uninitialized Use in ANGLE * CVE-2026-15110: Use after free in Extensions * CVE-2026-15111: Use after free in Views * CVE-2026-15113: Use after free in Autofill * CVE-2026-15114: Out of bounds read and write in Codecs * CVE-2026-15115: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-15116: Use after free in Actor * CVE-2026-15117: Use after free in Payments * CVE-2026-15118: Use after free in Input * CVE-2026-15119: Inappropriate implementation in GetUserMedia * CVE-2026-15120: Use after free in Core * CVE-2026-15121: Use after free in WebRTC * CVE-2026-15122: Insufficient validation of untrusted input in Codecs * CVE-2026-15123: Insufficient data validation in DOM * CVE-2026-15124: Insufficient policy enforcement in Passwords * CVE-2026-15125: Inappropriate implementation in Forms * CVE-2026-15126: Use after free in Forms * CVE-2026-15127: Inappropriate implementation in WebGL * CVE-2026-15128: Inappropriate implementation in Forms * CVE-2026-15130: Insufficient policy enforcement in Navigation * CVE-2026-15107: Use after free in IndexedDB * CVE-2026-15131: Insufficient data validation in Navigation - Chromium 150.0.7871.100: * stability improvements, no further information available chromedriver-150.0.7871.114-bp157.2.184.1.x86_64.rpm chromium-150.0.7871.114-bp157.2.184.1.nosrc.rpm chromium-150.0.7871.114-bp157.2.184.1.x86_64.rpm chromedriver-150.0.7871.114-bp157.2.184.1.aarch64.rpm chromium-150.0.7871.114-bp157.2.184.1.aarch64.rpm chromedriver-150.0.7871.114-bp157.2.184.1.ppc64le.rpm chromium-150.0.7871.114-bp157.2.184.1.ppc64le.rpm openSUSE-2026-246 Recommended update for openQA, os-autoinst moderate openSUSE Backports SLE-15-SP7 Update This update for openQA, os-autoinst fixes the following issues: Changes in openQA: - Update to version 5.1782822561.fa3defef: * docs: Add paragraph describing suse_notify AMQP service * feat: Link to autoinst-log from details view - Update to version 5.1782729563.8f5a14b2: * chore(deps): bump js-yaml from 4.1.1 to 4.3.0 * test: bail out when worker fails to become active * refactor(test): use shared wait_for in wait_for_worker * test: fix flaky race in t/05-scheduler-full.t Changes in os-autoinst: - Update to version 5.1782828634.82ceeb1: * docs: document testing custom os-autoinst forks within openQA * fix: mmapi test failures and infinite loop hangs * feat: Also output module information for wait_serial result steps * feat: Add module name and step number to autoinst-log * feat: Log the CASEDIR git url/hash for easy frontend access * fix: exclude virt-firmware on older Leap ppc64 openQA-5.1782822561.fa3defef-bp157.2.12.1.src.rpm openQA-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-auto-update-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-bootstrap-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-client-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-client-bash-completion-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-client-zsh-completion-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-common-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-continuous-update-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-doc-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-llm-server-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-local-db-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-mcp-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-munin-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-python-scripts-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-single-instance-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-single-instance-nginx-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-worker-5.1782822561.fa3defef-bp157.2.12.1.x86_64.rpm openQA-client-test-5.1782822561.fa3defef-bp157.2.12.2.src.rpm openQA-test-5.1782822561.fa3defef-bp157.2.12.2.src.rpm openQA-worker-test-5.1782822561.fa3defef-bp157.2.12.3.src.rpm os-autoinst-5.1782828634.82ceeb1-bp157.2.6.1.src.rpm os-autoinst-5.1782828634.82ceeb1-bp157.2.6.1.x86_64.rpm os-autoinst-debuginfo-5.1782828634.82ceeb1-bp157.2.6.1.x86_64.rpm os-autoinst-debugsource-5.1782828634.82ceeb1-bp157.2.6.1.x86_64.rpm os-autoinst-openvswitch-5.1782828634.82ceeb1-bp157.2.6.1.x86_64.rpm os-autoinst-qemu-kvm-5.1782828634.82ceeb1-bp157.2.6.1.x86_64.rpm os-autoinst-qemu-x86-5.1782828634.82ceeb1-bp157.2.6.1.x86_64.rpm os-autoinst-swtpm-5.1782828634.82ceeb1-bp157.2.6.1.x86_64.rpm os-autoinst-openvswitch-test-5.1782828634.82ceeb1-bp157.2.6.1.src.rpm os-autoinst-test-5.1782828634.82ceeb1-bp157.2.6.3.src.rpm openQA-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-auto-update-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-bootstrap-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-client-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-client-bash-completion-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-client-zsh-completion-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-common-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-continuous-update-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-doc-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-llm-server-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-local-db-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-mcp-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-munin-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-python-scripts-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-single-instance-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-single-instance-nginx-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm openQA-worker-5.1782822561.fa3defef-bp157.2.12.1.aarch64.rpm os-autoinst-5.1782828634.82ceeb1-bp157.2.6.1.aarch64.rpm os-autoinst-debuginfo-5.1782828634.82ceeb1-bp157.2.6.1.aarch64.rpm os-autoinst-debugsource-5.1782828634.82ceeb1-bp157.2.6.1.aarch64.rpm os-autoinst-openvswitch-5.1782828634.82ceeb1-bp157.2.6.1.aarch64.rpm os-autoinst-swtpm-5.1782828634.82ceeb1-bp157.2.6.1.aarch64.rpm openQA-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-auto-update-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-bootstrap-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-client-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-client-bash-completion-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-client-zsh-completion-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-common-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-continuous-update-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-doc-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-llm-server-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-local-db-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-mcp-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-munin-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-python-scripts-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-single-instance-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-single-instance-nginx-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm openQA-worker-5.1782822561.fa3defef-bp157.2.12.1.ppc64le.rpm os-autoinst-5.1782828634.82ceeb1-bp157.2.6.1.ppc64le.rpm os-autoinst-debuginfo-5.1782828634.82ceeb1-bp157.2.6.1.ppc64le.rpm os-autoinst-debugsource-5.1782828634.82ceeb1-bp157.2.6.1.ppc64le.rpm os-autoinst-openvswitch-5.1782828634.82ceeb1-bp157.2.6.1.ppc64le.rpm os-autoinst-swtpm-5.1782828634.82ceeb1-bp157.2.6.1.ppc64le.rpm openQA-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-auto-update-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-bootstrap-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-client-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-client-bash-completion-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-client-zsh-completion-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-common-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-continuous-update-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-doc-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-llm-server-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-local-db-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-mcp-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-munin-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-python-scripts-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-single-instance-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-single-instance-nginx-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm openQA-worker-5.1782822561.fa3defef-bp157.2.12.1.s390x.rpm os-autoinst-5.1782828634.82ceeb1-bp157.2.6.1.s390x.rpm os-autoinst-debuginfo-5.1782828634.82ceeb1-bp157.2.6.1.s390x.rpm os-autoinst-debugsource-5.1782828634.82ceeb1-bp157.2.6.1.s390x.rpm os-autoinst-openvswitch-5.1782828634.82ceeb1-bp157.2.6.1.s390x.rpm os-autoinst-swtpm-5.1782828634.82ceeb1-bp157.2.6.1.s390x.rpm openSUSE-2026-239 Security update for flannel important openSUSE Backports SLE-15-SP7 Update This update for flannel fixes the following issues: - Update to version 0.28.7: * prepare for release v0.28.7 (#2485) * fix: use install-conf in chart (#2484) * fix: use semver tag type in Docker meta to support release events (#2483) * build(deps): bump github/codeql-action/upload-sarif (#2480) * build(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 (#2473), fix for CVE-2026-33814 (boo#1265780) and CVE-2026-39821 (boo#1266620) * build(deps): bump docker/build-push-action from 7.2.0 to 7.3.0 (#2479) * build(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 (#2478) * build(deps): bump docker/metadata-action from 6.1.0 to 6.2.0 (#2476) * build(deps): bump the tencent group with 2 updates (#2475) * build(deps): bump the etcd group with 4 updates (#2474) * fix: skip invalid CIDRs in subnet file readers (#2454) * subnet/etcd: recover subnet watch from compaction (#2471) * Bump the tencent group across 1 directory with 2 updates (#2461) * Bump actions/attest-build-provenance from 4.1.0 to 4.1.1 (#2467) * Bump actions/setup-go from 6.4.0 to 6.5.0 (#2468) * feat: new install_conf cmd to install flannel's config file (#2466) * Bump the other-go-modules group with 2 updates (#2464) * Bump actions/checkout from 6.0.2 to 7.0.0 (#2465) * Bump github/codeql-action from 4.36.0 to 4.36.2 (#2463) flannel-0.28.7-bp157.2.12.1.src.rpm flannel-0.28.7-bp157.2.12.1.x86_64.rpm flannel-k8s-yaml-0.28.7-bp157.2.12.1.noarch.rpm flannel-0.28.7-bp157.2.12.1.i586.rpm flannel-0.28.7-bp157.2.12.1.aarch64.rpm flannel-0.28.7-bp157.2.12.1.ppc64le.rpm flannel-0.28.7-bp157.2.12.1.s390x.rpm openSUSE-2026-242 Security update for gh critical openSUSE Backports SLE-15-SP7 Update This update for gh fixes the following issues: - Update to version 2.96.0: * Critical security fix: patched vulnerability in gh codespace jupyter that could allow command execution when connecting to malicious Codespaces * Merge commit from fork * Fix concurrent map writes in codespace port forwarding (#13313) * docs: fix broken install command and link/grammar errors (#13690) * Clarify `--clone` boolean flag behaviour in `gh repo fork` help (#13786) * docs: fix duplicated word in primer README (#13677) * fix(skills): honor --dir without agent prompt (#13766) * Support antigravity-cli and antigravity2.0 in gh skill (#13784) * chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 * docs(search): reword raw qualifier examples * chore(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 * docs(search): simplify raw qualifier examples * docs(search): add examples for multiple qualifiers * chore(deps): bump actions/attest from 4.1.0 to 4.1.1 * chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0 * fix(cmdutil): honor DisableAuthCheck under repo-override parents * feat(release): allow download without authentication * fix(release): don't let a failed draft lookup mask a found release * Fix flaky TestHuhPrompterMultiSelectWithSearchPersistence on slow architectures (#13675) * Detect additional third-party coding agents (#13722) * Add security disclosure guidance to AGENTS.md (#13720) * chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 * chore(deps): bump github.com/microsoft/dev-tunnels from 0.1.19 to 0.1.27 * ci: pin GitHub Actions to commit SHAs * chore(deps): bump github.com/google/go-containerregistry * Use int64 for GitHub database IDs (#13403) * docs: fix broken anchor link in release-process-deep-dive (#13688) * Cover all printSummary branches in a table test * fix(skills): install universal agent to ~/.agents/skills * fix: show checks summary when all checks were cancelled - The following bugs are no longer present in this release (may have been fixed in previous releases): boo#1234566, boo#1235345, boo#1237669, boo#1239496, boo#1241837, boo#1243930, boo#1251464, boo#1251666, boo#1253929, boo#1258617, boo#1260271, boo#1262339, boo#1262943, boo#1265405, boo#1265777, boo#1266173, boo#1266618, boo#1266975, boo#1267158, boo#1269427 - Update to version 2.95.0: * feat(skills): list available skills when install runs non-interactively (#13548) * fix(skills): stage updates in a temp dir and swap in-place (#13449) * feat: add `repo read-file` and `repo read-dir` (#13580) * Bump Go in devcontainer * Make filtering by bot authors more discoverable (#13642) * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 * chore(deps): bump charm.land/lipgloss/v2 from 2.0.3 to 2.0.4 * chore(deps): bump github.com/sigstore/sigstore-go from 1.1.4 to 1.2.1 * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 * test(skill): fix test case name * test(skill): merge isolated test into table * Potential fix for pull request finding * docs(discussion): polish help docs * chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2 * fix test * support custom CLAUDE_CONFIG_DIR in install - Update to version 2.94.0: * Add gh discussion and Issues 2.0 reference to the `gh` skill, plus a README note (#13631) * fix(discussion comment): fix bug in requiring body/body-file in add/edit mode * chore(discussion/client): rename client files * test(acceptance): fix discussion comment acceptance tests * fix(discussion/shared): error on out-of-range discussion number in URL * fix(discussion view): print only requested items in non-tty output * docs(discussion list): clarify answered examples refer to Q&A discussions * fix(discussion view): show comments and replies in chronological order * refactor(discussion list): simplify no-results message and use success icon helper * fix(discussion view): use color scheme method for success icon * fix(discussion view): error when --comments is used with a comment argument * test(acceptance): use positional comment argument in discussion view test * refactor(discussion/client): take host instead of repo in GetComment * refactor(discussion view): replace --replies flag with positional comment argument * chore: fix formatting * test(acceptance): cover discussion comment URLs in comment and view tests * feat(discussion): support comment URLs in --replies and comment command * test(discussion comment): add non-tty delete flag validation test case * test(acceptance): add discussion comment acceptance test * refactor(acceptance): use discussion comment command instead of raw API calls * feat(discussion): add discussion comment command * feat(discussion/client): add comment manipulation methods * chore: apply formatting * chore(discussion): remove unused HttpClient field from create and edit * fix(discussion): remove redundant error wrapping on ListCategories * test(discussion list): rename TestNewCmdList2 to TestNewCmdList * Add terminal-mockup canvas extension for marketing screenshots (#13612) * fix(discussion): add missing repo flag override * test(discussion list): consolidate tests into table-driven format * docs(acceptance): add new jq2env and jq-assert functions * test(discussion): add acceptance tests for discussion commands * fix(discussion list): print "answered" instead of checkmark in non-tty mode * refactor(discussion/client): precheck discussions enabled via getRepositoryMeta * refactor(discussion): add Cursor field and ExportData to DiscussionListResult * feat(extension): alias `uninstall` to `remove` * chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 * chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 * chore(deps): bump charm.land/bubbletea/v2 from 2.0.6 to 2.0.7 * docs(discussion view): improve long help text for clarity * fix(discussion): handle partial failure on create/update label mutations * Clean up deferred issue update helper (#13584) * Auto-install official extension stubs in CI (#13581) * chore(discussion/client): fix formatting * docs(discussion/client): add godoc to exported consts * refactor(discussion list): make pager call/error consistent with view command * refactor(discussion): extract command-level consts for enums * fix(discussion): various polish and small fixes * Merge pull request #13057 from cli/kw/issues-2.0 * Bump Go to 1.26.4 * chore(deps): bump github.com/mattn/go-colorable from 0.1.14 to 0.1.15 * address review comments * feat(discussion edit): add discussion edit command * feat(discussion create): add discussion create command * feat(discussion view): add discussion view command * feat(discussion list): add discussion list command * feat(discussion/shared): add shared utilities for discussion commands * feat(discussion/client): add discussion client package * Use github-copilot agent ID in skill list tests and help text * Rename hosts field and helpers to agentHosts in skill list * Stat SKILL.md before reading in skill list * Sanitize terminal control characters in skill list output * chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 * chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.9 to 2.13.10 * address copilot comments, clarify text * address copilot comments * handle skills in skills/ folder when running list command, by marking them as published * address bagtoad's feedback * add --all flag to install all skills in a repo * fix warning message to make it clear * skip prompting for skills without metadata when running gh skill update --all * add logic to preview too * fix discovery support in nested dirs * fix test * fix tests * fix linting * add skill list command - Update to version 2.93.0: * test(attestation): align integration tests with new external HTTP client * fix: use separate http client for non-github hosts * docs: note immutable releases starting v2.93.0 * bump golang.org/x/net * Link to Accessibility category for community discussions instead of ACR (#13481) * Allow agents as application for secrets (#13421) * SHA pin first-party GitHub Actions * chore(deps): bump github/codeql-action from 4 to 4.35.5 * Add 3 day dependabot cooldown period * chore(deps): bump github.com/google/go-containerregistry * Run govulncheck daily instead of weekly * Merge pull request #13486 from cli/tommy/update-x-crypto * Potential fix for pull request finding * Potential fix for pull request finding * Stop bumping homebrew on release * chore(deps): bump goreleaser/goreleaser-action from 7.2.1 to 7.2.2 (#13461) * Remove discussion workflow * Remove dependency on persistent token * Remove third-party license debris * chore(deps): bump github.com/theupdateframework/go-tuf/v2 * docs: drop --repo gh-cli from dnf install lines * Assert digest prefix in release verify no-attestation tests * chore(deps): bump google.golang.org/grpc from 1.81.0 to 1.81.1 * Derive digest algorithm from ref length in release verify commands * docs: fix duplicated "of" in release-process-deep-dive * chore(deps): bump golang.org/x/crypto from 0.50.0 to 0.51.0 * Simplify bump-go.sh toolchain logic * Remove unnecessary null checks in jq output handling * Rewrite script to use go mod edit instead of grep/sed * Address code review comments * Improve version comparison to handle both X.Y.0 and X.Y.Z formats * Update bump-go.sh to handle missing toolchain directive * Initial plan * Update CODEOWNERS for skills directory ownership * chore(deps): bump golang.org/x/text from 0.36.0 to 0.37.0 * chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.81.0 * chore(deps): bump golang.org/x/term from 0.42.0 to 0.43.0 * fix(copilot): update test assertion to match updated error message * fix(copilot): provide full path to copilot binary on exec error * fix(copilot): hint to run copilot directly when exec fails * fix(telemetry): use CREATE_NO_WINDOW to prevent tzutil console flash on Windows * Fix triage-pull-requests skipping PRs that open as draft * chore(deps): bump golang.org/x/sys from 0.43.0 to 0.44.0 * Bump Go toolchain to 1.26.3 * Fix skills acceptance tests * Add explicit build tags to platform-specific echo test files * Address review feedback on echo mode polling * Poll TTY echo mode instead of sleeping in password tests * Record accessibility state in telemetry * Bump copilot telemetry sampling to 100% * chore(deps): bump github.com/klauspost/compress from 1.18.5 to 1.18.6 * Remove numberFieldOnly API shortcut * Grammar fixes * Switch from actions/attest-build-provenance to actions/attest * Enable extended PR screening for external PRs * Fix flaky Password test by increasing echo mode setup timeout * Add missing //go:build integration tag to verify_integration_test.go * chore(deps): bump goreleaser/goreleaser-action from 7.0.0 to 7.2.1 * Apply patch from code review feedback. * Print `gh auth refresh` for 401 returns * Update installation commands for GitHub CLI - Update to version 2.92.0: * Bump Go to 1.26.2 * chore(deps): bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22 * Update command.go * Add "Resource not accessible" to ProjectsV2IgnorableError * chore: fix zsh completion on debian * install_linux: correct typo in Homebrew copy * chore(deps): bump charm.land/bubbletea/v2 from 2.0.2 to 2.0.6 * chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.8 to 2.13.9 * Update acceptance/testdata/workflow/run-view-log-escape-sequences.txtar * Fix log terminal injection * fix(skills): include --allow-hidden-dirs in preview hint from install * Install skills flat by Name, not namespaced InstallName * feat(skills): add --allow-hidden-dirs flag to preview command * feat(skills): support GHEC with data residency hosts * Fix SetSampleRate not updating sample_rate dimension * fix: yaml.github-actions.security.run-shell-injection.run-shell-injection security vulnerability * Enable telemetry without env var * test(telemetry): assert ANSI escape chars for color codes * fix(telemetry): lower bias in sample bucket calc * feat(skills): detect re-published skills and offer upstream install * Log when there is no telemetry * Add telemetry command * Record official extension telemetry * fix(skills): prioritize DisplayName/Name over InstallName match * fix(skills): match skills by install name in preview command * use the right json field names for skills * fix totalCount guidance * docs(skills): note --template collisions and single-string search * backtick skill filename * docs(skills): drop hand-copied naming rules from gh-skill * use hyphen instead * docs(skills): add gh and gh-skill agent skills * feat(skills): support nested skills/ directories in discovery * fix(skills): make --fix and --dry-run mutually exclusive, suppress publish prompt * fix(skills): use canonical 'gh skill' not 'gh skills' alias * fix(skills): stop publish --fix from publishing * Include CI context in telemetry * refactor: decouple hidden-dir filtering from discovery layer * Add support for installation in multiple agent hosts in `gh skills install` (#13209) * Add skills specific telemetry * chore(deps): bump github.com/google/go-containerregistry * Do not send telemetry for aliases * Apply review feedback * Disable telemetry for GHES * remove misleading text * Add sampled command telemetry * Update publish_test.go * refactor: replace real git with run.CommandStubber in publish tests * fix: apply review feedback nil HttpClient, local dedup type * Remove dispatch after install, install only * Rename official extension files and types to stubs * Replace em-dashes with regular dashes * Address PR review feedback * Add no em dash rule to AGENTS.md * Suggest and install official extensions via stub commands * Add @cli/code-reviewers to all CODEOWNERS rules * Add cli/skill-reviewers as CODEOWNERS for skills packages * style: fix gofmt alignment in publish tests * fix: update acceptance test to match current error message * fix: address post-merge review feedback for skills commands * refactor: remove redundant nil-client fallback in skills publish (#13168) * feat(skills): auto-push unpushed commits before publish * refactor: use shared discovery logic in publish command * fix(skill publish): remove misleading `validate` alias * docs(skill): improve help docs * fix skills names in examples * Disable auth check for `gh extension install` * Suggest and install official extensions for unknown commands * Update acceptance/testdata/skills/skills-search-noresults.txtar * URL-encode parentPath in skills discovery API call * Disable auth check for local-only skill flags * fix: address review feedback on namespace changes * chore: remove unused newTestGitClient function * fix: preserve namespace in skills search deduplication * fix: use target directory remotes in skills publish * fix: enforce size cap on first preview file, surface corrupted skills, fail on path traversal * fix: align relevanceScore comments with implementation and fix typo * chore(deps): bump charm.land/lipgloss/v2 from 2.0.2 to 2.0.3 * chore(deps): bump github.com/mattn/go-isatty from 0.0.20 to 0.0.21 * address review comments * clean up interface and fix a few bugs * cleanup frontmatter fields * add .agents/skills as default installation path for hosts that support it: cursor, codex, gemini CLI, github copilot, antigravity. * show loading spinner during installation, even for multi-file skills * use markdown renderer in preview when previewing multi-file skills * Expand test coverage and fix invariants/bugs * add core logic and improve test coverage * improve test coverage/cleanup * register initial skills commands * add skills command scaffold * docs: fix SHA512 checksum for GPG key * chore(deps): bump github.com/hashicorp/go-version from 1.8.0 to 1.9.0 * chore(deps): bump google.golang.org/grpc from 1.79.3 to 1.80.0 * chore(deps): bump github.com/sigstore/timestamp-authority/v2 * docs: add sha/md5 checksums of keyring files * chore(deps): bump github.com/google/go-containerregistry * chore(deps): bump github.com/sigstore/protobuf-specs from 0.5.0 to 0.5.1 * chore: delete experimental script/debian-devel * chore(deps): bump charm.land/bubbles/v2 from 2.0.0 to 2.1.0 * Document dependency CVE policy in SECURITY.md * docs: add manual PGP key verification commands * chore: re-add toolchain to go1.26.2 * docs: polish wording around PGP keys * docs: include PGP key fingerprints * Fix infinite loop in 'gh release list --limit 0' * chore(deps): bump github.com/in-toto/attestation from 1.1.2 to 1.2.0 * chore(deps): bump github.com/klauspost/compress from 1.18.4 to 1.18.5 * test(internal/authflow): assert user-agent header is not modified/added * replace github.com/golang/snappy with klauspost/compress/snappy * docs: require tests and linter pass before committing * fix(auth): preserve User-Agent in authflow getViewer * fix(api): propagate InvokingAgent in gh api HTTP client * chore(deps): bump github.com/yuin/goldmark from 1.7.16 to 1.8.2 * chore(deps): bump advanced-security/filter-sarif from 1.0.1 to 1.1 - Update to version 2.89.0: * Ensure huh prompter cleans up * fix(huh prompter): remove unused fields and imports * go mod tidy * feat(huh prompter): clear search input after submitting query * refactor(huh prompter): custom Field for MultiSelectWithSearch * feat(huh prompter): add placeholder to search input * fix(huh prompter): use synchronized accessors to eliminate data race * fix(accessible prompter): update test expectations for huh v2 * refactor(huh prompter): pipe-based test harness with full coverage * test(huh prompter): add table-driven tests for all prompt types * Upgrade to huh/v2 and fix selection persistence in MultiSelectWithSearch * Fix gofmt alignment for prompter-enabled fields in IOStreams * Use LayoutStack for huhPrompter MultiSelectWithSearch * Add experimental huh-only prompter gated by GH_EXPERIMENTAL_PROMPTER * Add nameWithOwner to necessary tests * fix(pr view): fetch nameWithOwner in headRepository GraphQL query * test(acceptance): remove run-download-traversal test * fix(acceptance): set git identity in testscript sandbox * internal/codespaces/portforwarder: define err in go func instead of use err defined in outer scope * chore(deps): bump github.com/zalando/go-keyring from 0.2.6 to 0.2.8 * Update docs/triage.md * Update docs/triage.md * Align triage.md with unified triage process * Fix typo: remove extra space in README.md link * fix(survey): use useReviewerSearch consistently in prompt path * fix(pr create): wire up @copilot assignee replacement and [bot] suffix * refactor(survey): simplify ApiActorsSupported in RepoMetadataInput * docs(featuredetection): document GHES removal criteria for ApiActorsSupported * refactor(featuredetection): rename ActorIsAssignable to ApiActorsSupported * refactor(pr shared): consolidate ActorAssignees and ActorReviewers into ApiActorsSupported * refactor(pr shared): extract SpecialAssigneeReplacer for @me and Copilot expansion * chore(deps): bump github.com/google/go-containerregistry * Record agentic invocations in User-Agent header * Address review: table tests, godocs, code style * Add AGENTS.md optimized for AI agent token efficiency * docs: simplify flag text * docs(pr edit): improve command examples with grouped sections * docs: clarify that --add-reviewer can re-request reviews * feat(pr create, issue create): search-based assignee selection in MetadataSurvey * review: address code review feedback * refactor(issue edit): wire up search-based assignee selection * refactor(pr edit): remove actor accumulation hack from assignee search * refactor(pr edit, issue edit): use login-based assignee mutation for flag flows * fix(pr create): use login-based assignee mutation on github.com * chore(deps): bump microsoft/setup-msbuild from 2.0.0 to 3.0.0 * chore(deps): bump mislav/bump-homebrew-formula-action from 3.6 to 4.1 * Remove auto-labels from issue templates * fix(agent-task): resolve Copilot API URL dynamically (#12956) * chore(deps): bump google.golang.org/grpc from 1.79.2 to 1.79.3 * chore(deps): bump azure/login from 2.3.0 to 3.0.0 * fix: improve docs around IssueRepoInfo * test(issue transfer): update stub for IssueRepositoryInfo query * fix(issue transfer): use IssueRepoInfo to fetch minimal fields for issues * test(issue create): update stubs for IssueRepositoryInfo query * fix(issue create): use IssueRepoInfo to avoid requiring Contents:Read permission * test(api): add tests for GitHubRepo and IssueRepoInfo * refactor(api): add IssueRepoInfo for minimal issue repo queries - Update to version 2.88.1: * Revert "fix: clarify scope error while creating issues for projects" * Revert "refactor: deduplicate scope error handling between api/client.go and project queries" * Switch deployment signing to OIDC authentication gh-2.96.0-bp157.2.21.1.src.rpm gh-2.96.0-bp157.2.21.1.x86_64.rpm gh-bash-completion-2.96.0-bp157.2.21.1.noarch.rpm gh-fish-completion-2.96.0-bp157.2.21.1.noarch.rpm gh-zsh-completion-2.96.0-bp157.2.21.1.noarch.rpm gh-2.96.0-bp157.2.21.1.i586.rpm gh-2.96.0-bp157.2.21.1.aarch64.rpm gh-2.96.0-bp157.2.21.1.ppc64le.rpm gh-2.96.0-bp157.2.21.1.s390x.rpm openSUSE-2026-249 Recommended update for dropwatch moderate openSUSE Backports SLE-15-SP7 Update This update for dropwatch fixes the following issues: - version update to 1.5.5 * Added abilty to build and run in a docker container * kas is the default symbol lookup method now * Fix building without libtool installed * Misc fixes for kas lookup logic dropwatch-1.5.5-bp157.2.3.1.src.rpm dropwatch-1.5.5-bp157.2.3.1.x86_64.rpm dropwatch-1.5.5-bp157.2.3.1.i586.rpm dropwatch-1.5.5-bp157.2.3.1.aarch64.rpm dropwatch-1.5.5-bp157.2.3.1.ppc64le.rpm dropwatch-1.5.5-bp157.2.3.1.s390x.rpm openSUSE-2026-243 Security update for afterburn important openSUSE Backports SLE-15-SP7 Update This update for afterburn fixes the following issues: - Update to version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 not vulnerable but patches CVE-2026-45784 AKA boo#1270949 https://github.com/coreos/afterburn/pull/1277 - Update to version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 fixes CVE-2026-42327 AKA boo#1270483 , CVE-2026-44662 AKA boo#1270886 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 fixes GHSA-82j2-j2ch-gfr8 , GHSA-965h-392x-2mh5 , GHSA-xgp8-3hg3-c2mh * build(deps): bump openssl from 0.10.73 to 0.10.78 fixes CVE-2026-41898 AKA boo#1270817 , CVE-2026-41681 AKA boo#1270787 , CVE-2026-41676 AKA boo#1270175 , CVE-2026-41678 AKA boo#1270651 , CVE-2026-41677 AKA boo#1270555 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 not vulnerable but patches RUSTSEC-2026-0097 AKA GHSA-cq8v-f236-94qc * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 fixes GHSA-pwjx-qhcg-rvj4 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates * build(deps): bump bytes from 1.10.1 to 1.11.1 fixes CVE-2026-25541 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 - Update to version 5.10.0: * cargo: Afterburn release 5.10.0 * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates * Sync repo templates afterburn-5.10.0.git73.b97f772-bp157.2.9.1.src.rpm afterburn-5.10.0.git73.b97f772-bp157.2.9.1.x86_64.rpm afterburn-dracut-5.10.0.git73.b97f772-bp157.2.9.1.noarch.rpm afterburn-5.10.0.git73.b97f772-bp157.2.9.1.i586.rpm afterburn-5.10.0.git73.b97f772-bp157.2.9.1.aarch64.rpm afterburn-5.10.0.git73.b97f772-bp157.2.9.1.ppc64le.rpm afterburn-5.10.0.git73.b97f772-bp157.2.9.1.s390x.rpm openSUSE-2026-244 Security update for gosec important openSUSE Backports SLE-15-SP7 Update This update for gosec fixes the following issues: - Fixing multiple vulnerabilities in the following embedded dependencies: golang.org/x/crypto/ssh (bsc#1266209), golang.org/x/net/html (bsc#1267195), golang.org/x/net/idna (bsc#1266793), golang.org/x/net/http2 (bsc#1265919). - Update to version 2.27.1: * Downgrade google lib to avoid min Go version bump (#1687) * Downgrade the jsonschema dep to v0.13.0 due to incompatibility with anthropick-sdk-go (#1686) * Update all dependencies (#1685) * Downgrade the github.com/invopop/jsonschema v0.13.0 to solve incopatibility with anthropic-sdk (#1683) * Update all dependencies (#1682) * Update vulnerabilities alerts for indirect dependencies * Pin dependencies (#1681) * Skip pining for my repos * Update renovate configuration * Fix typo * Update branch config in renovate config * Migrate config renovate.json (#1678) * Update renovate to refresh the branch creation * Update the renovate branch prefix * Update renovate config to pin the actions dependencies by digests (#1676) * Migrate the html remport to react v19. (#1675) * Manually update version to fix renovate (#1674) * feat: integrate Atlas Cloud provider (#1672) * Refactor error position parsing to support path with colon. (#1673) * Add two options to require rule ID and justificaiton for inline annotations (#1671) * Fix false positive in G118 when cancel is stored in a slice/map (#1670) * chore(go): update supported Go versions to 1.25.10 and 1.26.3 (#1669) * Harden the github workflows and action (#1665) * Fix justification delimiter in annotation format doc (#1661) * Update all dependencies (#1664) * Update action to use gosec version v2.26.1 (#1660) gosec-2.27.1-bp157.2.9.1.src.rpm gosec-2.27.1-bp157.2.9.1.x86_64.rpm gosec-2.27.1-bp157.2.9.1.i586.rpm gosec-2.27.1-bp157.2.9.1.aarch64.rpm gosec-2.27.1-bp157.2.9.1.ppc64le.rpm gosec-2.27.1-bp157.2.9.1.s390x.rpm openSUSE-2026-245 Security update for enc important openSUSE Backports SLE-15-SP7 Update This update for enc fixes the following issues: - CVE-2026-1229: Fix incorrect value produced by CombinedMult() in ecc/p384 (boo#1265533) Bump circl to 1.6.3 - Update to 1.1.5: * Update dependencies #10 - Update to 1.1.4: * Update all dependencies #9 - Update to 1.1.3: * Fix typo in README #7 * Update all dependencies #8 enc-1.1.5-bp157.2.3.1.src.rpm enc-1.1.5-bp157.2.3.1.x86_64.rpm enc-1.1.5-bp157.2.3.1.i586.rpm enc-1.1.5-bp157.2.3.1.aarch64.rpm enc-1.1.5-bp157.2.3.1.ppc64le.rpm enc-1.1.5-bp157.2.3.1.s390x.rpm openSUSE-2026-247 Security update for openQA, os-autoinst important openSUSE Backports SLE-15-SP7 Update This update for openQA, os-autoinst fixes the following issues: Changes in openQA: - Update to version 5.1783672871.e689eb3c: * chore(deps): Dependency cron 2026-07-10 * fix(test): resolve List::Util::any coverage bug * refactor(test): use List::Util::any in full-stack * feat(scheduler): Clarify job missing class reason * feat(scheduler): distinguish busy vs offline workers * fix(test): wait for processes in full-stack teardown * docs(agents): document make check-line-coverage in AGENTS.md * feat(build): add check-line-coverage target * chore(deps): Dependency cron 2026-07-09 * ci: Add cli tool to report uncovered lines * feat: allow UEFI_PFLASH_CODE as asset * refactor: Remove duplicate 'use' statement * fix(client): Encode text_data as UTF-8 in archive command * fix: Handle source Urls ending with .git - Update to version 5.1783486111.5733fbdf: * fix(source links): Category and module can contain an underscore * fixup! feat: Log early aborts during disk space cleanup * feat: Log early aborts during disk space cleanup * feat: Abort results cleanup early to prevent load surges * refactor: Make `t/05-scheduler-full.t` easier to understand * refactor: Improve marking workers as dead in `t/05-scheduler-full.t` * refactor: Use signatures in `t/05-scheduler-full.t` * test: Remove simulation of "heavy load" from `t/05-scheduler-full.t` * chore(deps): Dependency cron 2026-07-07 * fix(packaging): remove duplicate openqa spec dir * fix(packaging): create podman cache dir via RPM * fix(worker): ensure podman cache directory exists * fix: XUnit: render skipped testcases as missing instead of ok * test: Stabilize `t/ui/26-jobs_restart.t` * chore(deps): bump the all-actions group across 1 directory with 5 updates * ci: Reduce memory usage of `t/05-scheduler.t` * feat: Turn code locations in autoinst-log into links - Update to version 5.1783327469.933c54e2: * fix(obs_rsync): use scope guards to avoid stalls * chore(deps): Dependency cron 2026-07-04 * feat: Retry git_clone minion job with exponential backoff * feat: request unredacted settings in openqa-clone-job and warn * feat: allow authenticated operators to fetch unredacted job settings - Update to version 5.1783076943.6691832d: * test: Stabilize `t/05-scheduler-full.t` - Clarify resolution of three CVEs * The following CVEs have been fixed (see previous changelog entries that mentioned only the according Bugzilla tickets): - boo#1259005 - CVE-2026-27904 - boo#1264376 - CVE-2026-6321 - boo#1258632 - CVE-2026-26996 - Update to version 5.1782995932.ffeb09be: * feat: throw 404 for nonexistent groups in overview * feat: Avoid logwarn notifications for non-critical auth error * chore(deps): Dependency cron 2026-07-02 * git subrepo pull (merge) external/os-autoinst-common * fix: Check also hidden files in checklist plugin * test: Enable faster re-connects in full scheduler test consistently * test: Avoid silent daemons in verbose mode * test: Allow running `t/43-…-scalability.t` in parallel * test: Allow running `t/05-scheduler-full.t` in parallel * test: Avoid race condition when generating ports in `25-cache.t` * test: Avoid wasting seconds in `40-script_load_dump_templates.t` * refactor: Remove disabled code in `openqa-load-templates` * test: Avoid race condition when generating ports in many tests * chore(deps): Dependency cron 2026-07-01 * fix(ci): format inline comments in workflows to pass yamllint * test: Avoid running into "Address already in use" in fullstack test * feat(ci): pin GitHub Actions by commit hash Changes in os-autoinst: - Update to version 5.1783672666.346fbe5: * fix(consoles): strip video parameters from shm sink name * feat(consoles): add mediadev/mediaentity parameters for ustreamer * refactor(consoles): use Mojo::URL for GENERAL_HW_VIDEO_STREAM_URL * feat(consoles): add ustreamer version 10 frame format * feat: Log module step in case of failed needle match * feat: allow UEFI_PFLASH_CODE as asset - Update to version 5.1783514748.b19cdea: * feat: allow UEFI_PFLASH_CODE as asset * test: clean up t/29-backend-driver.t * test: fix race condition in t/29-backend-driver.t * fix(t/34-git): prevent t/34-git.t from leaking t/vars.json * test: fix flaky timeout in t/18-qemu-options.t - Update to version 5.1783329367.214f5bc: * test: fix flaky timeout in t/18-qemu-options.t * feat: optimize and shorten pretty serial hook * test: Disable unstable `t/28-signalblocker.t` on ppc64le OBS builds * fix: Check also hidden files in checklist plugin * test: assert pipe size adjustment dynamically * test: assert terminal session boundary safety * refactor: support pretty markers in script_sudo and become_root * test: simplify Level 3 pretty marker detection - Update to version 5.1782917048.dcc97e9: * fix: Check also hidden files in checklist plugin * feat(ci): disable Mergify interactive queue controls in PR comments * fix(ci): format inline comments in workflows to pass yamllint * feat(ci): pin GitHub Actions by commit hash * test: assert pipe size adjustment dynamically * test: assert terminal session boundary safety * refactor: support pretty markers in script_sudo and become_root * fix: mmapi test failures and infinite loop hangs * test: simplify Level 3 pretty marker detection * fix: exclude virt-firmware on all older Leap archs openQA-5.1783672871.e689eb3c-bp157.2.15.1.src.rpm openQA-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-auto-update-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-bootstrap-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-client-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-client-bash-completion-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-client-zsh-completion-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-common-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-continuous-update-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-doc-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-llm-server-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-local-db-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-mcp-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-munin-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-python-scripts-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-single-instance-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-single-instance-nginx-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-worker-5.1783672871.e689eb3c-bp157.2.15.1.x86_64.rpm openQA-client-test-5.1783672871.e689eb3c-bp157.2.15.1.src.rpm openQA-test-5.1783672871.e689eb3c-bp157.2.15.1.src.rpm openQA-worker-test-5.1783672871.e689eb3c-bp157.2.15.1.src.rpm os-autoinst-5.1783672666.346fbe5-bp157.2.9.1.src.rpm os-autoinst-5.1783672666.346fbe5-bp157.2.9.1.x86_64.rpm os-autoinst-debuginfo-5.1783672666.346fbe5-bp157.2.9.1.x86_64.rpm os-autoinst-debugsource-5.1783672666.346fbe5-bp157.2.9.1.x86_64.rpm os-autoinst-openvswitch-5.1783672666.346fbe5-bp157.2.9.1.x86_64.rpm os-autoinst-qemu-kvm-5.1783672666.346fbe5-bp157.2.9.1.x86_64.rpm os-autoinst-qemu-x86-5.1783672666.346fbe5-bp157.2.9.1.x86_64.rpm os-autoinst-swtpm-5.1783672666.346fbe5-bp157.2.9.1.x86_64.rpm os-autoinst-openvswitch-test-5.1783672666.346fbe5-bp157.2.9.1.src.rpm os-autoinst-test-5.1783672666.346fbe5-bp157.2.9.1.src.rpm openQA-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-auto-update-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-bootstrap-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-client-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-client-bash-completion-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-client-zsh-completion-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-common-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-continuous-update-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-doc-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-llm-server-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-local-db-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-mcp-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-munin-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-python-scripts-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-single-instance-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-single-instance-nginx-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm openQA-worker-5.1783672871.e689eb3c-bp157.2.15.1.aarch64.rpm os-autoinst-5.1783672666.346fbe5-bp157.2.9.1.aarch64.rpm os-autoinst-debuginfo-5.1783672666.346fbe5-bp157.2.9.1.aarch64.rpm os-autoinst-debugsource-5.1783672666.346fbe5-bp157.2.9.1.aarch64.rpm os-autoinst-openvswitch-5.1783672666.346fbe5-bp157.2.9.1.aarch64.rpm os-autoinst-swtpm-5.1783672666.346fbe5-bp157.2.9.1.aarch64.rpm openQA-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-auto-update-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-bootstrap-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-client-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-client-bash-completion-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-client-zsh-completion-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-common-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-continuous-update-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-doc-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-llm-server-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-local-db-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-mcp-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-munin-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-python-scripts-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-single-instance-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-single-instance-nginx-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm openQA-worker-5.1783672871.e689eb3c-bp157.2.15.1.ppc64le.rpm os-autoinst-5.1783672666.346fbe5-bp157.2.9.1.ppc64le.rpm os-autoinst-debuginfo-5.1783672666.346fbe5-bp157.2.9.1.ppc64le.rpm os-autoinst-debugsource-5.1783672666.346fbe5-bp157.2.9.1.ppc64le.rpm os-autoinst-openvswitch-5.1783672666.346fbe5-bp157.2.9.1.ppc64le.rpm os-autoinst-swtpm-5.1783672666.346fbe5-bp157.2.9.1.ppc64le.rpm openQA-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-auto-update-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-bootstrap-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-client-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-client-bash-completion-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-client-zsh-completion-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-common-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-continuous-update-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-doc-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-llm-server-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-local-db-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-mcp-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-munin-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-python-scripts-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-single-instance-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-single-instance-nginx-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm openQA-worker-5.1783672871.e689eb3c-bp157.2.15.1.s390x.rpm os-autoinst-5.1783672666.346fbe5-bp157.2.9.1.s390x.rpm os-autoinst-debuginfo-5.1783672666.346fbe5-bp157.2.9.1.s390x.rpm os-autoinst-debugsource-5.1783672666.346fbe5-bp157.2.9.1.s390x.rpm os-autoinst-openvswitch-5.1783672666.346fbe5-bp157.2.9.1.s390x.rpm os-autoinst-swtpm-5.1783672666.346fbe5-bp157.2.9.1.s390x.rpm openSUSE-2026-248 Security update for chromium critical openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 150.0.7871.124 (boo#1271415): * CVE-2026-15764: Use after free in Ozone * CVE-2026-15765: Use after free in Ozone * CVE-2026-15766: Uninitialized Use in Skia * CVE-2026-15767: Heap buffer overflow in libyuv * CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas * CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming * CVE-2026-15770: Uninitialized Use in V8 * CVE-2026-15771: Insufficient validation of untrusted input in Media * CVE-2026-15772: Use after free in GPU * CVE-2026-15773: Use after free in Core * CVE-2026-15774: Use after free in Skia * CVE-2026-15775: Insufficient policy enforcement in V8 * CVE-2026-15776: Type Confusion in V8 * CVE-2026-15777: Use after free in UI * CVE-2026-15778: Insufficient validation of untrusted input in Navigation chromedriver-150.0.7871.124-bp157.2.187.1.x86_64.rpm chromium-150.0.7871.124-bp157.2.187.1.nosrc.rpm chromium-150.0.7871.124-bp157.2.187.1.x86_64.rpm chromedriver-150.0.7871.124-bp157.2.187.1.aarch64.rpm chromium-150.0.7871.124-bp157.2.187.1.aarch64.rpm chromedriver-150.0.7871.124-bp157.2.187.1.ppc64le.rpm chromium-150.0.7871.124-bp157.2.187.1.ppc64le.rpm openSUSE-2026-251 Security update for python-weasyprint moderate openSUSE Backports SLE-15-SP7 Update This update for python-weasyprint fixes the following issues: - CVE-2026-49452: CSS Injection via Presentational Hints (boo#1270401) python-weasyprint-60.2-bp157.2.6.1.src.rpm python311-weasyprint-60.2-bp157.2.6.1.noarch.rpm openSUSE-2026-253 Recommended update for easy-rsa moderate openSUSE Backports SLE-15-SP7 Update This update for easy-rsa fixes the following issues: - Update to 3.2.6: - CI: Enable shell switch errexit in #1417 - V325 326 minor touches in #1421 - Inline sub ca v1 in #1423 - X509-Type ca: Enable 'basicConstraints = critical' for CA/subCA certificates in #1428 - Import tls key v1 in #1429 - import_tls_key(): Use set_no_clobber() to preserve existing key file in #1430 - Changes from 3.2.5: - Replace local / global openssl-easyrsa.cnf in #1394 - init-pki: Introduce configurable cryptography in #1397 - Drop x509 type kdc built-in in #1399 - Always generate an openssl-easyrsa.cnf or x509-types tmp-file in #1401 - Libressl use $EASYRSA_FORCE_SAFE_SSL in #1402 - Update EasyRSA-Advanced.md in #1403 - source_vars(): Add grep regex for assign by equal = in #1405 - export_pkcs(), PKCS12 inline: Respect $EASYRSA_NO_INLINE in #1407 - Introduce peer-fingerprint inline lists in #1410 - help: Add '-b' alias for --batch and correct default 'vars' file in #1411 - New function ssl_cert_sig_digest(); Extract certificae digest name in #1414 - Upgrading OpenSSL for Windows to 3.6.0 in #1416 - Changes from 3.2.4: - export-p12: Move inline file to 'inline/private' folder in #1356 - Restructure help in #1363 - New global option: --no-lockfile = env-var: $EASYRSA_NO_LOCKFILE in #1364 - Restructure verify_working_env() in #1367 - Improve verbose in #1368 - Windows easyrsa-shell-init.sh: Replace 'read -p' in #1371 - mutual_exclusions(): Include basic checks for --startdate/--enddate in #1372 - easyrsa-shell-init.sh: Allow Easy-RSA to use '\User$HOME' directory in #1374 - Remove 'easyrsa_mkdir()', use only 'mkdir' in #1376 - revoke: Archive request and private key files and expand help in #1378 - set_no_clobber(): Add simple error detection in #1379 - random: Use verify_working_env() to configure EASYRSA_OPENSSL in #1381 - self_sign(): Force use of Easy-RSA X509-type file 'selfsign' in #1383 - Changes from 3.2.3: - Update OpenSSL to v3.5.0 - renew: Print 'unique_subject = no' to index.txt.attr in #1293 - check_serial_unique(): Check for duplicate Subject error in #1294 - Correctly define options names - Remove wild-card pattern in #1297 - Remove all references to file:easyrsa-tools.lib in #1298 - Reinstate old function as 'db_date_to_iso_8601()' [Renamed] in #1303 - expire_status_v2(): Refactor 'if' statement to capture error correctly in #1304 - source_vars() improvements in #1300 - add_critical_attrib(): Do not add 'critical' if 'critical' exists in #1308 - inline_file(): Include DH file or placeholder, for RSA Servers in #1310 - Fix shellcheck warnings in #1311 - Introduce command line options --umask|--no-umask, to set 'umask' in #1312 - Introduce "robust" lock-file mechanism in #1313 - New function set_no_clobber() in #1314 - Easyrsa mktemp v2 in #1315 - add_critical_attrib_v2(): Move file access to function in #1316 - Command 'write': Remove options 'overwrite' and 'filename' in #1318 - Introduce option --text: Create CSR files with human readable text in #1319 - will_cert_be_valid(): Remove SSL option -noout in #1321 - easyrsa_mktemp(): Remove secondary atomic operation in #1322 - easyrsa_mkdir(): Separate Windows from *nix in #1324 - Update Copyright 2025 in #1327 - inine_file(): Correct logic and add 'dh none' for DH params file in #1330 - show-expire: Move setting $pre_expire_window_s to status() in #1332 - Always export EASYRSA_SSL_CONF, when assigned (code standard) in #1334 - Unit-test: Drop old *nix test in #1335 - add_critical_attrib(): export temp-file name as input file in #1333 - Inline improvements in #1337 - Unit-test: Minimize Windows test in #1339 - PKI lock-file: Move possible creation to sub-function request_lock_file() in #1340 - forbid_selfsign(): Compare cert serial to signing cert serial in #1342 - inline_file(): Use ssl_cert_serial() in #1343 - Inline self sign improvements in #1345 - peer-fingerprint mode: Make CA mode mutually exclusive to PFP mode in #1347 - Remove init pki soft in #1351 easy-rsa-3.2.6-bp157.2.3.1.noarch.rpm easy-rsa-3.2.6-bp157.2.3.1.src.rpm openSUSE-2026-250 Security update for opam important openSUSE Backports SLE-15-SP7 Update This update for opam fixes the following issues: Update to version 2.5.2: - CVE-2026-57825: Fixed a bug that allowed a package to install files anywhere on the system using a symlink to an external directory without warning the user and asking for their permission. opam-2.5.2-bp157.2.6.1.src.rpm opam-2.5.2-bp157.2.6.1.x86_64.rpm opam-devel-2.5.2-bp157.2.6.1.x86_64.rpm opam-installer-2.5.2-bp157.2.6.1.x86_64.rpm opam-2.5.2-bp157.2.6.1.aarch64.rpm opam-devel-2.5.2-bp157.2.6.1.aarch64.rpm opam-installer-2.5.2-bp157.2.6.1.aarch64.rpm opam-2.5.2-bp157.2.6.1.ppc64le.rpm opam-devel-2.5.2-bp157.2.6.1.ppc64le.rpm opam-installer-2.5.2-bp157.2.6.1.ppc64le.rpm opam-2.5.2-bp157.2.6.1.s390x.rpm opam-devel-2.5.2-bp157.2.6.1.s390x.rpm opam-installer-2.5.2-bp157.2.6.1.s390x.rpm openSUSE-2026-252 Security update for python-django-haystack important openSUSE Backports SLE-15-SP7 Update This update for python-django-haystack fixes the following issues: - Remote Code Execution via `eval()` in Elasticsearch Result Deserialization (boo#1271593) python-django-haystack-3.2.1-bp157.2.3.1.src.rpm python311-django-haystack-3.2.1-bp157.2.3.1.noarch.rpm openSUSE-2026-254 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 150.0.7871.128 (boo#1271656): * CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura chromedriver-150.0.7871.128-bp157.2.190.1.x86_64.rpm chromium-150.0.7871.128-bp157.2.190.1.nosrc.rpm chromium-150.0.7871.128-bp157.2.190.1.x86_64.rpm chromedriver-150.0.7871.128-bp157.2.190.1.aarch64.rpm chromium-150.0.7871.128-bp157.2.190.1.aarch64.rpm chromedriver-150.0.7871.128-bp157.2.190.1.ppc64le.rpm chromium-150.0.7871.128-bp157.2.190.1.ppc64le.rpm openSUSE-2026-258 Recommended update for openQA moderate openSUSE Backports SLE-15-SP7 Update This update for openQA fixes the following issues: - Update to version 5.1784178984.04ce3617: * chore(deps): Dependency cron 2026-07-16 * feat(job-restart): Allow restarting parent job skipping OK children * test: Fix check `Consistent Test::More call` to exclude comments * feat(overview-page): Reload automatically after adding comments * test: Unify raw port socket reuse across create_* helpers * test: reuse reserved socket in create_webapi * feat(overview-page): Allow restarting jobs with advanced options * feat(overview-page): Improve displaying number of restarts * fix(overview-page): Remove surplus spaces after buttons * chore(deps): Dependency cron 2026-07-14 * chore: Update `Perl::Tidy` to 20260705 * feat: Change worker job lock limit to be in line with config example * docs: Remove example from `LOCK_NAME` worker setting * fix(mergify): prevent endless dependabot PR recreation loops * feat: optionally fail ISO API if no jobs created * test(worker): Cover rejecting job when acquiring job lock failed * refactor: Rename `OpenQA::CacheService::DB` * feat(worker): Re-evaluate unavailability due to job lock quickly * feat(worker): Allow configuring lock to throttle job execution * feat(worker): Add local locking on worker-instance scope * refactor: Move database setup of cache service to separate module openQA-5.1784178984.04ce3617-bp157.2.18.1.src.rpm openQA-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-auto-update-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-bootstrap-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-client-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-client-bash-completion-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-client-zsh-completion-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-common-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-continuous-update-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-doc-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-llm-server-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-local-db-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-mcp-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-munin-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-python-scripts-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-single-instance-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-single-instance-nginx-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-worker-5.1784178984.04ce3617-bp157.2.18.1.x86_64.rpm openQA-client-test-5.1784178984.04ce3617-bp157.2.18.1.src.rpm openQA-test-5.1784178984.04ce3617-bp157.2.18.1.src.rpm openQA-worker-test-5.1784178984.04ce3617-bp157.2.18.1.src.rpm openQA-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-auto-update-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-bootstrap-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-client-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-client-bash-completion-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-client-zsh-completion-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-common-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-continuous-update-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-doc-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-llm-server-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-local-db-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-mcp-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-munin-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-python-scripts-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-single-instance-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-single-instance-nginx-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-worker-5.1784178984.04ce3617-bp157.2.18.1.aarch64.rpm openQA-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-auto-update-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-bootstrap-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-client-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-client-bash-completion-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-client-zsh-completion-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-common-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-continuous-update-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-doc-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-llm-server-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-local-db-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-mcp-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-munin-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-python-scripts-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-single-instance-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-single-instance-nginx-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-worker-5.1784178984.04ce3617-bp157.2.18.1.ppc64le.rpm openQA-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-auto-update-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-bootstrap-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-client-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-client-bash-completion-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-client-zsh-completion-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-common-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-continuous-update-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-doc-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-llm-server-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-local-db-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-mcp-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-munin-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-python-scripts-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-single-instance-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-single-instance-nginx-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openQA-worker-5.1784178984.04ce3617-bp157.2.18.1.s390x.rpm openSUSE-2026-261 Recommended update for os-autoinst moderate openSUSE Backports SLE-15-SP7 Update This update for os-autoinst fixes the following issues: - Update to version 5.1784551853.234e380: * ci: Add tool to check line coverage * git subrepo pull (merge) external/os-autoinst-common * style(testapi): apply Modules::ProhibitAutomaticExportation on testapi * style(testapi.pm): apply Subroutines::RequireArgUnpacking on testapi.pm * style(perlcritic): RegularExpressions::ProhibitSingleCharAlternation * build(deps): bump actions/checkout (#3018) * fix(backend): bring back support for legacy BIOS os-autoinst-5.1784551853.234e380-bp157.2.12.1.src.rpm os-autoinst-5.1784551853.234e380-bp157.2.12.1.x86_64.rpm os-autoinst-openvswitch-5.1784551853.234e380-bp157.2.12.1.x86_64.rpm os-autoinst-qemu-kvm-5.1784551853.234e380-bp157.2.12.1.x86_64.rpm os-autoinst-qemu-x86-5.1784551853.234e380-bp157.2.12.1.x86_64.rpm os-autoinst-swtpm-5.1784551853.234e380-bp157.2.12.1.x86_64.rpm os-autoinst-openvswitch-test-5.1784551853.234e380-bp157.2.12.2.src.rpm os-autoinst-test-5.1784551853.234e380-bp157.2.12.2.src.rpm os-autoinst-5.1784551853.234e380-bp157.2.12.1.aarch64.rpm os-autoinst-openvswitch-5.1784551853.234e380-bp157.2.12.1.aarch64.rpm os-autoinst-swtpm-5.1784551853.234e380-bp157.2.12.1.aarch64.rpm os-autoinst-5.1784551853.234e380-bp157.2.12.1.ppc64le.rpm os-autoinst-openvswitch-5.1784551853.234e380-bp157.2.12.1.ppc64le.rpm os-autoinst-swtpm-5.1784551853.234e380-bp157.2.12.1.ppc64le.rpm os-autoinst-5.1784551853.234e380-bp157.2.12.1.s390x.rpm os-autoinst-openvswitch-5.1784551853.234e380-bp157.2.12.1.s390x.rpm os-autoinst-swtpm-5.1784551853.234e380-bp157.2.12.1.s390x.rpm openSUSE-2026-260 Recommended update for glab moderate openSUSE Backports SLE-15-SP7 Update This update for glab fixes the following issues: - Update to version 1.108.0: * Features - ff181daa: feat(mr): show absolute time alongside relative in note output (Tomas Vik tvik@gitlab.com) - 2b6946d7: feat(mr): show note and discussion IDs in mr note list (Tomas Vik tvik@gitlab.com) - b3fafd19: feat(securefile): remove by name (Jack 30406998-jack1902@users.noreply.gitlab.com) - 53756300: feat: Add Wait Flag for CI Status Subcommand (Jonathan Bowe jonathan@bowedev.com) * Bug Fixes - 33acf839: fix(auth): preserve saved values on re-authentication (Kai Armstrong karmstrong@gitlab.com) - 76c823ef: fix(changelog): strip newline from git describe output (Kai Armstrong karmstrong@gitlab.com) - 3860206d: fix(issue): avoid panic when viewing a closed issue with no closer (Kai Armstrong karmstrong@gitlab.com) - 24f5e59c: fix(mr): fall back to raw body when markdown rendering fails (Tomas Vik tvik@gitlab.com) * Documentation - f30aa8d1: docs(config): list missing user-settable global keys in help (Kai Armstrong karmstrong@gitlab.com) - 215c18e8: docs(security): mark experimental subcommands and clarify synopsis (Brendan Lynch blynch@gitlab.com) - 2cabe0db: docs: updates for GitLab Duo CLI GA (Uma Chandran uchandran@gitlab.com) * Dependencies - 1f440305: chore(deps): update dependency @commitlint/cli to ^21.2.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 9d222d04: chore(deps): update module charm.land/bubbletea/v2 to v2.0.8 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 1dcfc3c9: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.47.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 9ba9110d: chore(git): remove duplicate mockgen directive for GitRunner (Tomas Vik tvik@gitlab.com) - a9044ba3: refactor: enforce IOStreams output helpers over direct fmt.Fprint calls (Oscar Tovar otovar@gitlab.com) * Others - 152be15c: test(mrutils): parallelize noteTimeAgo test (Tomas Vik tvik@gitlab.com) - Update to version 1.107.0: * Features - ad8642d8: feat(duo): support Duo CLI v9 auto-updates (Tomas Vik tvik@gitlab.com) - b8ba875f: feat(security config): add commands to manage security configuration profiles (Oscar Tovar otovar@gitlab.com) * Documentation - 76d0ac66: docs: add new CLAUDE.md file and reference AGENTS.md (Brendan Lynch blynch@gitlab.com) - 4a143d44: docs: clarify glab token rotate command info (Brendan Lynch blynch@gitlab.com) - 96ab83c0: docs: update stage from Create to AI Coding (Uma Chandran uchandran@gitlab.com) * Dependencies - 3329b298: chore(deps): update dependency @commitlint/format to ^21.1.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - d176bd65: chore(deps): update module charm.land/lipgloss/v2 to v2.0.5 (GitLab Renovate Bot gitlab-bot@gitlab.com) - b9c46379: chore(deps): update module github.com/docker/cli to v29.6.1+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - f6fefa6d: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.45.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 7fd07149: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.46.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 0e195d0d: chore: update documentation MR template (Brendan Lynch blynch@gitlab.com) - Update to version 1.106.0: * Features - ca99cc32: feat(packages): add delete command (Oscar Tovar otovar@gitlab.com) - 2ffa2f05: feat(packages): add download command (Oscar Tovar otovar@gitlab.com) - b323eaca: feat(stack): add --reword flag to fix commits without staging files (Gary Holtz is no longer with GitLab gary@holtz.tech) * Documentation - d0f83885: docs(whatsnew): document show_whats_new config and env var (Kai Armstrong karmstrong@gitlab.com) - 15b64e4e: docs: refine packages and container-registry command help text (Brendan Lynch blynch@gitlab.com) * Dependencies - 45b73a0f: chore(deps): update module github.com/docker/cli to v29.6.0+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - 28d5db5c: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.42.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - b14d7c7c: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.43.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 0987f270: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.44.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 2661db6c: chore: explain that token env will work in snap (Tomas Vik tvik@gitlab.com) - Update to version 1.105.0: * Features - c8fed254: feat(orbit): rename --format flag to --response-format (Dmitry Gruzd dgruzd@gitlab.com) * Bug Fixes - e9a1266d: fix(orbit): handle new nested status response shape (Dmitry Gruzd dgruzd@gitlab.com) - 122f46f4: fix: route deprecation warnings to stderr (Kai Armstrong karmstrong@gitlab.com) * Dependencies - ba0f56a8: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.40.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - Update to version 1.104.0: * Features - 5380ef66: feat(duo): warn when running duo cli under snap confinement (Kai Armstrong karmstrong@gitlab.com) - 4ee1edf5: feat(packages): add upload command (Oscar Tovar otovar@gitlab.com) - 383d5994: feat: generate GitLab Docs navigation block for glab (Brendan Lynch blynch@gitlab.com) * Documentation - 6440f987: docs(skills): improve glab threaded-reply guidance (Thomas Schmidt tschmidt@gitlab.com) * Dependencies - 2ba749a0: chore(deps): update module charm.land/glamour/v2 to v2.0.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 5f958dff: chore(deps): update module charm.land/lipgloss/v2 to v2.0.4 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 4e20a953: chore(deps): update module github.com/coder/websocket to v1.8.15 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 2f358bfa: chore(deps): update module golang.org/x/crypto to v0.53.0 (Jay McCure jmccure@gitlab.com) - d9be4c7a: chore(deps): update module k8s.io/client-go to v0.36.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - dd6eb3c8: chore: update labels in templates (Kai Armstrong karmstrong@gitlab.com) - 41afe2f6: refactor: uppercase initialisms in test key generators (Jay McCure jmccure@gitlab.com) - Update to version 1.103.0: * Features - b39a801c: feat(container-registry): add container registry repository and tag commands (Jeroen Monteban jeroen.monteban@mgb.ch) - ea9fd25a: feat(packages): add packages command group with list (Oscar Tovar otovar@gitlab.com) - 1dd20b11: feat(stack): make switch interactive (Ahmed Abdelbaset a7med3bdulbaset@gmail.com) - 7b9703ab: feat(stacked-diffs): add --no-verify to 'stack amend' command (Kev Kloss kkloss@gitlab.com) - 6e4e3284: feat(stacked-diffs): add --no-verify to 'stack save' command (Kev Kloss kkloss@gitlab.com) - 481f63fb: feat: Handle glab mr checkout failure when there are non fast-forwarding conflicts (Gabriel Mazzetto gabriel@gitlab.com) - 84fd9f33: feat: compile arm64 windows bianry (Andrei Zubov azubov@gitlab.com) * Bug Fixes - 91eb7aad: fix(ci): set release token inline so project GITLAB_TOKEN can't shadow it (Jay McCure jmccure@gitlab.com) - 10561d78: fix(mcp): add content to structuredContent (Florian Imdahl git@ffflorian.de) - bcf700bd: fix(orbit): install dependency-free Linux build to fix glibc version errors (Dmitry Gruzd dgruzd@gitlab.com) - 0a119c02: fix(stacks): share stacks across worktrees (Ahmed Abdelbaset a7med3bdulbaset@gmail.com) - e3236d94: fix(update): give post-upgrade and skill nudges breathing room (Kai Armstrong karmstrong@gitlab.com) * Documentation - 913e5d9d: docs(api): add GLAB_DEBUG_HTTP example for debugging requests (Kai Armstrong karmstrong@gitlab.com) - 3a983d41: docs(variable): add synopsis and examples to variable commands (Brendan Lynch blynch@gitlab.com) - 98e70a25: docs: Remove manual (default false) flag annotations (Brendan Lynch blynch@gitlab.com) - 6c71e24c: docs: add troubleshooting guide for invalid_client OAuth error (Stan Hu stanhu@gmail.com) - e73a8cde: docs: move troubleshooting guide to the generated CLI docs page (Brendan Lynch blynch@gitlab.com) * Dependencies - 7779ffec: chore(deps): bump go to v1.26.4 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 39cda83f: chore(deps): update dependency @commitlint/cli to ^21.0.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - f434057f: chore(deps): update dependency @commitlint/lint to ^21.0.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - c583440d: chore(deps): update module charm.land/bubbletea/v2 to v2.0.7 (GitLab Renovate Bot gitlab-bot@gitlab.com) - a1898d01: chore(deps): update module github.com/docker/cli to v29.5.1+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - f1b74aae: chore(deps): update module github.com/docker/cli to v29.5.2+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6131acf7: chore(deps): update module github.com/docker/cli to v29.5.3+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - 9b83a7ff: chore(deps): update module github.com/docker/docker-credential-helpers to v0.9.8 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 0767cd08: chore(deps): update module github.com/mattn/go-colorable to v0.1.15 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 765b526d: chore(deps): update module github.com/mattn/go-runewidth to v0.0.24 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 756377a6: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.36.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 55a4f6b3: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.36.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 34a8e5b0: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.36.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) - e500b3f4: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.39.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - bda16f22: chore(deps): update module golang.org/x/sync to v0.21.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - a27fa5a4: chore(deps): update module golang.org/x/term to v0.44.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 79575672: chore(deps): update module golang.org/x/text to v0.38.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 4c0cc23d: chore(ci): automate weekly release via pipeline schedule (Jay McCure jmccure@gitlab.com) - d0d9bc3e: chore: Refactor mr_checkout removing global var and moving dependencies to struct (Gabriel Mazzetto gabriel@gitlab.com) - 47eeadad: chore: Update MR review instructions YAML (Brendan Lynch blynch@gitlab.com) - b5ac12f9: chore: add support for modern linux-x64 duo cli binary (Andrei Zubov azubov@gitlab.com) - 7d26ca46: ci: update code-intelligence job to fix job failures (Oscar Tovar otovar@gitlab.com) - 45b9fcc3: ci: wire ci/cd inputs to release variables (Oscar Tovar otovar@gitlab.com) * Others - 080c4e2c: test: add archived field to label list JSON expectation (Tomas Vik tvik@gitlab.com) - Update to version 1.102.0: * Features - 044e5b03: feat(api): forward DUO_WORKFLOW_WORKFLOW_ID as X-Gitlab-Duo-Workflow-Id header (Eduardo Bonet ebonet@gitlab.com) - 12cfcf44: feat(api): forward GITLAB_DUO_SESSION_ID as X-Gitlab-Duo-Session-Id header (Eduardo Bonet ebonet@gitlab.com) - d64700ce: feat(repo): add prune command to delete merged local branches (Kai Armstrong karmstrong@gitlab.com) - e1cd4cf0: feat(skills): notify when installed skills have updates (Kai Armstrong karmstrong@gitlab.com) - fadd3939: feat(whatsnew): add command and post-upgrade banner (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - d914d050: fix(api): URL-encode magic placeholder substitutions (Kai Armstrong karmstrong@gitlab.com) - 98a00775: fix(binarymgr): sort packages by semver client-side (Kai Armstrong karmstrong@gitlab.com) * Documentation - 65169664: docs(duo): expand MR review instructions from 3 to 17 blocks (Kai Armstrong karmstrong@gitlab.com) - 38602dd2: docs(iteration): add synopsis and examples to iteration commands (Brendan Lynch blynch@gitlab.com) - 2f6cb6d5: docs(mr): add synopsis and examples to mr commands (Brendan Lynch blynch@gitlab.com) - 40d9474f: docs(opentofu): add synopsis and examples to opentofu commands (Brendan Lynch blynch@gitlab.com) - a9fe77fd: docs(release): add synopsis and examples to release commands (Brendan Lynch blynch@gitlab.com) - ecd623cb: docs(repo): add synopsis and fix usage notation in repo commands (Brendan Lynch blynch@gitlab.com) - d788de5e: docs(snippet): add synopsis and examples to snippet commands (Brendan Lynch blynch@gitlab.com) - 49f80867: docs(todo): add synopsis and examples to todo commands (Brendan Lynch blynch@gitlab.com) - 42fb614b: docs: Format quoted command references as code in env vars table (Ben Bodenmiller bbodenmiller@gmail.com) - c9507bbf: docs: add synopsis and examples to issue and incident commands (Brendan Lynch blynch@gitlab.com) - eb4fec3f: docs: add synopsis and examples to misc standalone commands (Brendan Lynch blynch@gitlab.com) - 5f87ec4c: docs: document GLAB_NO_PROMPT and mark NO_PROMPT deprecated (Ben Bodenmiller bbodenmiller@gmail.com) - f4b2593b: docs: fix flag punctuation and example formatting (quick wins) (Brendan Lynch blynch@gitlab.com) - d9a6681e: docs: update AGENTS.md with comprehensive agent instructions (Brendan Lynch blynch@gitlab.com) - 2e64fa29: docs: update README environment variables (Brendan Lynch blynch@gitlab.com) - 6734e7ab: docs: update env vars table to use GLAB_ prefixed names (Kate Grechishkina khrechyshkina@gitlab.com) * Dependencies - d8ca77c7: chore(deps): update dependency @commitlint/config-conventional to ^21.0.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 21f186ce: chore(deps): update dependency @commitlint/read to ^21.0.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - d4a4afeb: chore(lint): enable 19 new linters and address violations (Kai Armstrong karmstrong@gitlab.com) - 19c91cc9: refactor(config): canonical schema with config set validation (Kai Armstrong karmstrong@gitlab.com) - 98cbeebf: refactor(config): do not use StubConfig in tests (Timo Furrer tfurrer@gitlab.com) - 1e5735ef: refactor(config): follow ups (Timo Furrer tfurrer@gitlab.com) - bced871c: refactor(config): give each Config its own persistence directory (Timo Furrer tfurrer@gitlab.com) - a95fae2a: refactor(config): remove global config stubbers (Timo Furrer tfurrer@gitlab.com) - 769e47ec: refactor(glrepo): inject config instead of reaching for the global (Timo Furrer tfurrer@gitlab.com) - Update to version 1.101.0: * Features - 98e075fb: feat(ci): add --force flag to glab ci cancel job (Filip Aleksic faleksic@gitlab.com) - 56083b99: feat(mr note create): add --resolvable flag (Silviu Marchis silviu.marchis@sygnum.com) - 3a8da34f: feat(orbit): add Windows support for orbit local (Bohdan Parkhomchuk bparkhomchuk@gitlab.com) - 1b8ac8a6: feat(orbit): add glab orbit setup guided onboarding command (Kai Armstrong karmstrong@gitlab.com) - 7c5c41f3: feat(stack): add --skip-mr-creation flag to stack sync command (Gary Holtz gholtz@gitlab.com) - 8a9f818d: feat: Display progress during glab mr checkout (Gabriel Mazzetto gabriel@gitlab.com) * Bug Fixes - 1db48d89: fix(ci): align ci delete and ci list default pagination (Kai Armstrong karmstrong@gitlab.com) * Documentation - 04deff1d: docs(config): add synopsis and improve examples for config commands (Brendan Lynch blynch@gitlab.com) - a4b6dc76: docs(deploy-key): add synopsis and examples to deploy-key commands (Brendan Lynch blynch@gitlab.com) - 700695f5: docs(gpg-key): add synopsis and examples to gpg-key commands (Brendan Lynch blynch@gitlab.com) - 684df227: docs(label): add synopsis and examples to label commands (Brendan Lynch blynch@gitlab.com) - c1a8d0e7: docs(milestone): add synopsis and examples to milestone commands (Brendan Lynch blynch@gitlab.com) - b1bff4ba: docs(schedule): add synopsis and examples to schedule commands (Brendan Lynch blynch@gitlab.com) - 9e7f7b38: docs(securefile): add synopsis and examples to securefile commands (Brendan Lynch blynch@gitlab.com) - 44ca2124: docs(ssh-key): add synopsis and examples to ssh-key commands (Brendan Lynch blynch@gitlab.com) - ac004c5d: docs: clarify --all and --per-page pagination behavior (Brendan Lynch blynch@gitlab.com) * Dependencies - dce8a8d0: chore(deps): update module github.com/modelcontextprotocol/go-sdk to v1.6.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - baf77b6b: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.34.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8cd1295e: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.36.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 349287c5: chore(deps): update module golang.org/x/crypto to v0.52.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 58f32068: chore: Ensure git exit error codes are wrapped as Error (Gabriel Mazzetto gabriel@gitlab.com) - 220d0473: chore: Extract GitRunner into internal/git/git_runner (Gabriel Mazzetto gabriel@gitlab.com) * Others - 12b11497: test(iostreams): isolate NO_COLOR in detectIsColorEnabled default case (Filip Aleksic faleksic@gitlab.com) - Update to version 1.100.0: * Features - 02f8ae0a: feat(api): expand Coding-Agent detection list (Sam Wiskow swiskow@gitlab.com) - 1f462ed8: feat(ci status): keep --live polling through transient pipeline states (Kai Armstrong karmstrong@gitlab.com) - ae28d6dd: feat(issue): allow work_items URLs (Jay McCure jmccure@gitlab.com) - 35926816: feat(stack): add Body() method to StackRef and fix subject/body parsing in MR creation (Gary Holtz gholtz@gitlab.com) - 4f5f192a: feat(stack): add glab stack infer command to create stack layers from a commit range (Gary Holtz gholtz@gitlab.com) - ddf45787: feat(update): nudge is install-aware and agent-aware (Sam Wiskow swiskow@gitlab.com) - 0db2448f: feat: Introduce repo remote add <namespace/project> command (Gabriel Mazzetto gabriel@gitlab.com) - e6a25a75: feat: add detection for Gemini CLI (Isaac Dawson idawson@gitlab.com) - 1f49782a: feat: add global --jq flag for filtering JSON output (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - b98561dc: fix(ci view): harden bridge/child-pipeline navigation against crashes (Kai Armstrong karmstrong@gitlab.com) - 979568c6: fix(cmd): remove workaround (Filip Aleksic faleksic@gitlab.com) - 1aa323e5: fix(infer): build branch chain via cherry-pick with conflict rollback (Gary Holtz gholtz@gitlab.com) - 6fa36242: fix(pager): set LESS=FRX unless hyperlinks are forced (Kai Armstrong karmstrong@gitlab.com) - df2a507f: fix(test): align TestAcceptableZipFile path check with friendlyPath output (Filip Aleksic faleksic@gitlab.com) - 2deffd68: fix: update link for creating new legacy personal access token (Evan Read eread@gitlab.com) * Documentation - 6270cd3d: docs: improve glab ci command docs 2 (Brendan Lynch blynch@gitlab.com) - 75ac9bce: docs: improve help text for glab cluster commands (Brendan Lynch blynch@gitlab.com) - 30fa9fd8: docs: update glab SKILL.md with comments section and API content-type guidance (Thomas Schmidt tschmidt@gitlab.com) * Dependencies - 6642b29e: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.31.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 08c5f240: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.32.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 9879b156: chore(deps): update versions (Filip Aleksic faleksic@gitlab.com) * Maintenance - 38f97c78: chore(ci): improve check docs job (Filip Aleksic faleksic@gitlab.com) - 6c452a46: chore(code): remove dead code (Filip Aleksic faleksic@gitlab.com) - 4e80e10c: refactor: route command JSON output through PrintJSON helper (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.99.0: * Features - 45b1a43c: feat(orbit): add glab orbit remote dsl subcommand (Michael Angelo Rivera arivera@gitlab.com) - Update to version 1.98.1 (1.98.0 was not released): * Features - 4508ae6b: feat(api): detect coding agents in User-Agent header (Jean-Gabriel Doyon jgdoyon@gitlab.com) - 32489b18: feat: add glab work-items update (Carlos Corona ccorona@gitlab.com) - 646d89b3: feat(auth): add OAuth 2.0 device authorization flow for glab auth login (Kai Armstrong karmstrong@gitlab.com) - c52b7b2c: feat(skills): add skills list and bundle glab-stack skill (Kai Armstrong karmstrong@gitlab.com) - 5777fca9: feat: add glab mr note update and glab mr note delete commands (Tomas Vik tvik@gitlab.com) - 85e204a3: feat(ci): add --mr and --failed-jobs-only flags to glab ci get (Eduardo Bonet ebonet@gitlab.com) - 8073187d: feat(skills): add curated remote skill source backed by gitlab.com (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - 1a815c81: fix(orbit): preserve @ in JSON string literals for orbit remote query (Dmitry Gruzd dgruzd@gitlab.com) - ac76df59: fix(orbit): stream raw response body in 'remote query' (Dmitry Gruzd dgruzd@gitlab.com) - 95ee612f: fix(orbit): address review nits from !3269 (merged) (Dmitry Gruzd dgruzd@gitlab.com) - 1f0076d7: fix: enable OSC 8 hyperlinks by default in TTY terminals (Brendan Lynch blynch@gitlab.com) - 283611d8: fix(orbit): adopt client-go QueryRaw for streaming response body (Dmitry Gruzd dgruzd@gitlab.com) * Documentation - 0d634e3e: docs: replace getting-started.gif with VHS-driven recording (Kai Armstrong karmstrong@gitlab.com) - ac1a7e68: docs: improve glab api command docs (Brendan Lynch blynch@gitlab.com) - 7e95900f: docs: improve glab attestation commands docs (Brendan Lynch blynch@gitlab.com) - 21f6647b: docs: improve glab auth commands docs (Brendan Lynch blynch@gitlab.com) - d9df010f: docs: improve glab alias command docs (Brendan Lynch blynch@gitlab.com) - 41aa1096: docs: improve glab changelog and glab check-update command docs (Brendan Lynch blynch@gitlab.com) - 234c3ed1: docs: improve glab cli command docs 1 (Brendan Lynch blynch@gitlab.com) - 5a787012: docs: maintenance task - update redirected links (Uma Chandran uchandran@gitlab.com) * Dependencies - fb32af9d: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.25.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - de67aa8b: chore(deps): update dependency @commitlint/config-conventional to ^20.5.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 91d80b0c: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 120abea0: chore(deps): update module github.com/docker/docker-credential-helpers to v0.9.7 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8a22a890: chore(deps): update dependency @commitlint/cli to v21 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 0bf3140e: chore(deps): update dependency @commitlint/config-conventional to v21 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 4386cdd7: chore(deps): update dependency @commitlint/lint to v21 (GitLab Renovate Bot gitlab-bot@gitlab.com) - dca41751: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 2a28d5bd: chore(deps): update dependency @commitlint/read to v21 (GitLab Renovate Bot gitlab-bot@gitlab.com) - bc0f789a: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.27.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 818a3a88: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.28.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - b7452760: chore(deps): update dependency @commitlint/config-conventional to ^21.0.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 24e1895e: chore(deps): update dependency @commitlint/lint to ^21.0.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 1b913446: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.29.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - d1346954: chore(deps): update module k8s.io/client-go to v0.36.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6f6a1830: chore(deps): update dependency @commitlint/read to ^21.0.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 02372655: chore(deps): update dependency @commitlint/cli to ^21.0.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6f92316b: chore(deps): update dependency @commitlint/format to v21 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - bfc43900: refactor(skills): support multi-file skills and fail-fast on bad bundles (Kai Armstrong karmstrong@gitlab.com) - 93a9e5b2: ci: set MTU on docker:dind for release jobs (Stan Hu stanhu@gmail.com) * Others - b402a62f: test(binarymgr): isolate runner_test config writes from the user's config (Jay McCure jmccure@gitlab.com) - Update to version 1.97.0: * Features - 2b685d63: feat(orbit): add 'glab orbit local' command + extract binarymgr package (Kai Armstrong karmstrong@gitlab.com) * Others - ee2757f9: test(ask): skip flaky TestAskCmd ahead of removal (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.96.0: * Features - 43f15255: feat: add duo cli support for arm64 windows (Andrei Zubov azubov@gitlab.com) * Bug Fixes - d14064ca: fix(cmdutils): Avoid race on global viper state in GroupOverride (Caleb Madara calebmadara58@gmail.com) * Dependencies - ce62ac33: chore(deps): bump go to v1.26.3 (Kai Armstrong karmstrong@gitlab.com) - cd438239: chore(deps): update dependency @commitlint/cli to ^20.5.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 5a11bf9b: chore(dep): update x/net (Filip Aleksic faleksic@gitlab.com) - 31255b35: refactor(git): decouple StandardGitCommand from run.PrepareCmd (Gary Holtz gholtz@gitlab.com) - Update to version 1.95.0: * Features - e5b53d65: feat(duo): add --install and --yes flags to duo cli command (Kai Armstrong karmstrong@gitlab.com) - 76d00d65: feat(skills): add glab skills install to install bundled agent skill (experimental) (Thomas Schmidt tschmidt@gitlab.com) * Documentation - d173eac2: docs(issuable): add synopsis to close, note, reopen, subscribe, and unsubscribe (Brendan Lynch blynch@gitlab.com) - de019774: docs(mr): add synopsis to approve, approvers, diff, close, delete, for,... (Brendan Lynch blynch@gitlab.com) - 4fbb1820: docs(mr): add synopsis to list, view, create, checkout, merge, and update (Brendan Lynch blynch@gitlab.com) - 86d43fd9: docs: Add synopsis to CI/CD pipeline and job commands (Brendan Lynch blynch@gitlab.com) - 655b6ca3: docs: add info on deprecation messages (Brendan Lynch blynch@gitlab.com) - 634601b0: docs: add synopsis to experimental subcommands (Brendan Lynch blynch@gitlab.com) - 49d4b88e: docs: add synopsis to fork, opentofu, and auth docker commands (Brendan Lynch blynch@gitlab.com) - a84c20e7: docs: add synopsis to list and view commands (Brendan blynch@gitlab.com) - d225cb5d: docs: add synopsis to set, update, list, and export (Brendan blynch@gitlab.com) - ea774f21: docs: add synopsis to trace, lint, and config compile (Brendan Lynch blynch@gitlab.com) * Dependencies - 6e175217: chore(deps): update module github.com/modelcontextprotocol/go-sdk to v1.6.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - Update to version 1.94.0: * Features - f620f7a2: feat(mr note create): add --reply flag and refactor to options struct (Tomas Vik tvik@gitlab.com) - bed805c0: feat(mr): create diff comments (Tomas Vik (OOO back on 2026-05-11) tvik@gitlab.com) - 56718ff9: feat(orbit): add glab orbit subcommands (experimental) (Dmitry Gruzd dgruzd@gitlab.com) - 56b22863: feat(workitems): add glab work-items create (Carlos Corona ccorona@gitlab.com) - 5b4bc4a6: feat: add --reviewer flag to glab stack sync (Gary Holtz gholtz@gitlab.com) - fa792f3c: feat: add glab work-items delete (Carlos Corona ccorona@gitlab.com) - 5d59e0be: feat: render Markdown links as OSC 8 hyperlinks in help text (Brendan Lynch blynch@gitlab.com) * Bug Fixes - 9a6f9de4: fix(repo create): clone instead of git init when --readme is used (Kai Armstrong karmstrong@gitlab.com) - 339ff8cc: fix(snapcraft): /etc/gitconfig permissions (Filip Aleksic faleksic@gitlab.com) - 7f22b23c: fix: correct inverted condition for GITLAB_RELEASE_ASSETS_USE_PACKAGE_REGISTRY env var (Kai Armstrong karmstrong@gitlab.com) - 3394d202: fix: eliminate data race in ci and job tests by avoiding global os.Stdout/os.Stderr mutation (Timo Furrer tfurrer@gitlab.com) - a07c2c1c: fix: update flag description and remove backticks (Brendan blynch@gitlab.com) * Documentation - 774ea4f2: docs: add carapace completions note (Jonathan Bowe jonathan@bowedev.com) - 53918c5a: docs: document both head and merge ref formats for MR pipelines (Kai Armstrong karmstrong@gitlab.com) - da6f7b2f: docs: ensure glab check-update is accurately described (Brendan blynch@gitlab.com) * Dependencies - a0e977eb: chore(deps): update dependency @commitlint/cli to ^20.5.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - d7008ef5: chore(deps): update module charm.land/bubbletea/v2 to v2.0.6 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 5453a863: chore(deps): update module github.com/docker/cli to v29.4.1+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - ea1e87bd: chore(deps): update module github.com/docker/cli to v29.4.2+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - ea24f0a9: chore(deps): update module github.com/docker/docker-credential-helpers to v0.9.6 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8bb00fb6: chore(deps): update module github.com/gdamore/tcell/v2 to v2.13.9 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 5762ad2e: chore(deps): update module github.com/mattn/go-isatty to v0.0.21 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 41d476fc: chore(deps): update module github.com/mattn/go-isatty to v0.0.22 (GitLab Renovate Bot gitlab-bot@gitlab.com) - f1c53172: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.21.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 58ca66f7: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.22.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6f317c36: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.24.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 230c924a: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.24.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - bd77d705: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.24.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - ada4904f: chore: sync commit-lint script from gitlab-lsp (Kai Armstrong karmstrong@gitlab.com) - f60689c7: chore: update docs linting tools and docs linting container image (Evan Read eread@gitlab.com) - 9e274d09: ci: add Duo agent environment configuration (Thomas Schmidt tschmidt@gitlab.com) - 76ba508c: refactor(checkout): inject GitRunner dependency for testability (Gary Holtz gholtz@gitlab.com) - fe74aaf3: refactor(duo): improve Duo CLI update notification message (Arthur Foltz afoltz@gitlab.com) - Update to version 1.93.0: * Features - 90960872: feat(ci-list): display running pipelines in blue, use light/dark 24-bit colors when able (Emil Chludziński tanstaafl@tlen.pl) - f8f25b15: feat(mr note): add 'create' subcommand with discussion-based notes (Tomas Vik tvik@gitlab.com) - 95a61c83: feat: add --assignee flag to glab stack sync (Gary Holtz gholtz@gitlab.com) - f73a54fe: feat: add --label flag to glab stack sync (Gary Holtz gholtz@gitlab.com) - 35df967c: feat: add --template flag to issue and mr create commands (Kai Armstrong karmstrong@gitlab.com) - e59047ed: feat: add glab search semantic command (Tian Gao tgao@gitlab.com) * Bug Fixes - d3454a07: fix(api): avoid panic on invalid absolute endpoint URL (Mikel mikel@olasagasti.info) - b98d93a6: fix(ci view): Setup default theme (Philipp Hahn pmhahn@pmhahn.de) - f07689ce: fix(duo): honor custom Duo CLI path on unsupported CPU architectures (Mikel mikel@olasagasti.info) - 033e8039: fix: Always Use Long Git Status (Jonathan Bowe jonathan@bowedev.com) - 3e5c995d: fix: add HTTP timeout and propagate context in auth commands (Kai Armstrong karmstrong@gitlab.com) - ee920b4d: fix: respect repository target branch rules in mr create (Kai Armstrong karmstrong@gitlab.com) - 5593a1e8: fix: support git worktrees in stack operations (Daniel Bankmann 11852855-dba223@users.noreply.gitlab.com) - 34af5c48: fix: use local viper instance in GroupOverride to prevent data race (Jay McCure jmccure@gitlab.com) * Documentation - 4edb2bdd: docs: Clarify time format for glab token rotate (Brendan Lynch blynch@gitlab.com) - 40099e89: docs: add CLI docs style guide references and contributor guidance (Brendan Lynch blynch@gitlab.com) - fe2ed6fc: docs: fix punctuation in Short and flag descriptions (Brendan Lynch blynch@gitlab.com) - ee555c88: docs: improve auth login CI/CD documentation and --api-host flag (Kai Armstrong karmstrong@gitlab.com) - 784d046e: docs: standardize positional arg notation in mr commands (Brendan blynch@gitlab.com) * Dependencies - bb755050: chore(deps): Switch to a maintained YAML library (Mikel mikel@olasagasti.info) - 377c4198: chore(deps): drop github.com/pkg/errors in favor of stdlib errors (Mikel mikel@olasagasti.info) - 0a9d6bc7: chore(deps): drop mitchellh/go-homedir for stdlib home dir (Mikel mikel@olasagasti.info) - 7821c8d9: chore(deps): update module charm.land/bubbletea/v2 to v2.0.5 (GitLab Renovate Bot gitlab-bot@gitlab.com) - f4807f6c: chore(deps): update module charm.land/lipgloss/v2 to v2.0.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 0e3c1048: chore(deps): update module github.com/docker/cli to v29.4.0+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6ca80615: chore(deps): update module github.com/mattn/go-runewidth to v0.0.22 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8c3b14f9: chore(deps): update module github.com/mattn/go-runewidth to v0.0.23 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 5cca166a: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.17.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 1cca432d: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.19.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 59cdf34d: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.20.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - aa8b94d1: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.20.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - ef351c1e: chore(deps): update module golang.org/x/crypto to v0.50.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8c009a20: chore(deps): update module k8s.io/client-go to v0.35.4 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 4e8a8817: chore(duo): hide and deprecate 'glab duo ask' command (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.92.1: * Bug Fixes - a91ac2ae: fix(auth): clear stale credentials before OAuth flow, not after (Kai Armstrong karmstrong@gitlab.com) * Maintenance - b830236f: ci: fix release notes bot token override and remove redundant jq install (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.92.0: * Features - a5848540: feat: add duo-cli path override (Andrei Zubov azubov@gitlab.com) - 388a0f44: feat: add glab todo list and done commands (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - 8acb8487: fix(auth): clear stale credentials on re-login to fix OAuth-to-token switch (Kai Armstrong karmstrong@gitlab.com) - 6f30fd44: fix(clone): "glab repo clone" with custom directory (Martin Schurz 2090677-schurzi@users.noreply.gitlab.com) - 3dffae69: fix(token): fix rotate command failing to match tokens by numeric ID (Kai Armstrong karmstrong@gitlab.com) - b5624786: fix: add enum constraints and positional arg hints to MCP tool schemas (Kai Armstrong karmstrong@gitlab.com) - 8b01065a: fix: avoid GET /projects/:id in changelog generate to support CI job tokens (Kai Armstrong karmstrong@gitlab.com) - 5a83a038: fix: handle numeric timezone offsets in oauth2_expiry_date parsing (Kai Armstrong karmstrong@gitlab.com) - d0fa983b: fix: map 'user' config key to GLAB_USER to prevent $USER shadowing (Kai Armstrong karmstrong@gitlab.com) - 0d7a0be7: fix: use GitLab API for default branch instead of git remote show (Kai Armstrong karmstrong@gitlab.com) * Documentation - 5b34c099: docs: Add link to changelogs info (Brendan blynch@gitlab.com) - 5cd14e11: docs: update mr note examples to use resolve/reopen subcommands (Kai Armstrong karmstrong@gitlab.com) * Dependencies - 29e4990c: chore(deps): update module github.com/hashicorp/go-version to v1.9.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 4571890b: chore(deps): update module github.com/modelcontextprotocol/go-sdk to v1.5.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 3284fe2a: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.13.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 08deb1d3: chore: add Claude Code project settings and gitignore local overrides (Kai Armstrong karmstrong@gitlab.com) - 412f53ec: ci: add expire_in to sign_windows job artifacts (Kai Armstrong karmstrong@gitlab.com) - 40d9efbd: ci: use dedicated GITLAB_TOKEN_RELEASE_NOTES variable for notify-issues job (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.91.0: * Features - 7347ec5d: feat(duo): lock Duo CLI auto-updates to compatible major version (Kai Armstrong karmstrong@gitlab.com) - e60b4a84: feat: add multipart/form-data support to glab api via --form flag (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - 2ce57436: fix: URL-encode filename in release asset DirectAssetPath (Kai Armstrong karmstrong@gitlab.com) - bdda0f84: fix: improve diagnostics when env-based token fails auth (Kai Armstrong karmstrong@gitlab.com) - 6d4c9d43: fix: improve duo cli confirm prompt UX (Kai Armstrong karmstrong@gitlab.com) - 44d7c10f: fix: nil pointer dereference in DisplayIssueList and DisplayIssue when CreatedAt is null (Kai Armstrong karmstrong@gitlab.com) - dc75f9f3: fix: use /bin/sh shebang in notify-issues-on-release script (Kai Armstrong karmstrong@gitlab.com) * Documentation - 1892d844: docs: make Markdown for 'glab runner' command adhere to standards (Evan Read eread@gitlab.com) - 3f03c08c: docs: update command docs for Duo CLI beta release (Uma Chandran uchandran@gitlab.com) * Dependencies - 71b960c7: chore(deps): bump golangci-lint to v2.11.4 (GitLab Renovate Bot gitlab-bot@gitlab.com) - d8ee4806: chore(deps): update module github.com/zalando/go-keyring to v0.2.8 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 874b483b: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.11.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - a6031009: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.7.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8bd1ac64: chore(deps): update ruby docker tag to v3.4 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 879dce24: chore: Apply 1 suggestion(s) to 1 file(s) (Evan Read eread@gitlab.com) - ba5fb25b: chore: add documentation review apps to project (Evan Read eread@gitlab.com) - b0df7324: chore: add jq to Docker image (Kai Armstrong karmstrong@gitlab.com) - 8401888f: chore: adds beta string and applies it to duo cli (Uma Chandran uchandran@gitlab.com) * Others - 0e917e36: test: reduce unit test runtime by fixing slow polling and real HTTP calls (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.90.0: * Features - c33f8508: feat(auth): add --web, --container-registry-domains, --ssh-hostname flags to login (Ashutosh Kumar Singh ashutoshkumarsingh0x@gmail.com) - ceb51ebd: feat(ci auto login): move from experimental to GA (Timo Furrer tfurrer@gitlab.com) - 4f7b1815: feat(mr): add note list subcommand (Tomas Vik tvik@gitlab.com) - e3ff3569: feat(mr): add note resolve and reopen subcommands (Tomas Vik tvik@gitlab.com) - 9c6e4129: feat(runner-controller): implement new get command (Timo Furrer tfurrer@gitlab.com) - d1ad6fd2: feat(stack): model save and amend add file behavior after git commit (Casey Morris casey@philo.com) - a535468c: feat(stacked-diffs): add warning when saving from non-last stack entry (Gary Holtz gholtz@gitlab.com) - e2dfc31c: feat: add --auto-merge flag to mr create command (Kai Armstrong karmstrong@gitlab.com) - d54279e5: feat: add new command for checking job status by runner (kumaraayush9810 kumaraayush9810@gmail.com) - 59808c96: feat: add new command for listing the manager of runner (kumaraayush9810 kumaraayush9810@gmail.com) - b9f1c8cc: feat: automatically notify issues when released (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - 8e876852: fix(auth): rewrite remote repo host when SSH hostname maps to config host (Carsten Hoffmann morl99@web.de) - 31fa0af6: fix(mr): show all proposed changes in update preview (Kai Armstrong karmstrong@gitlab.com) - 4280006b: fix(style): ensure config value is used (Filip Aleksic faleksic@gitlab.com) - 735e6f1b: fix: add Ctrl+C signal handling to exit glab ci status --live (Kai Armstrong karmstrong@gitlab.com) - d14dd1dc: fix: bump CI Go version to 1.25.8 for glamour v2 compatibility (Tomas Vik tvik@gitlab.com) - d1e1217e: fix: remove redundant SCP parsing and add smart Git protocol defaults (Kai Armstrong karmstrong@gitlab.com) - 5d0ba457: fix: resolve linting issues introduced by Go 1.26 version bump (Jay McCure jmccure@gitlab.com) - 30b1d0f1: fix: restore glamour v1 auto-detection for TTY/noTTY style selection (Tomas Vik tvik@gitlab.com) - 799a8298: fix: return error when release notes file exists but is unreadable (Ashutosh Kumar Singh ashutoshkumarsingh0x@gmail.com) - fa616eff: fix: sanitize git hook env vars in test helpers for worktree isolation (Tomas Vik tvik@gitlab.com) - 144e41c0: fix: skip TestDetectPlatform on unsupported architectures (Ashutosh Kumar Singh ashutoshkumarsingh0x@gmail.com) - 8d9197d9: fix: update Remote.Repo hostname for SSH remotes in split-host setups (Kai Armstrong karmstrong@gitlab.com) - 8d404c09: fix: update glamour v2 import path and API changes (Tomas Vik tvik@gitlab.com) * Documentation - abd3ff94: docs: Remove EOL spaces in doc files - 2026-03-06 (Brendan Lynch blynch@gitlab.com) - 10548a1c: docs: Review and update glab note list subcommand page (Brendan Lynch blynch@gitlab.com) - 6b47f909: docs: renames classic chat to non-agentic chat (Uma Chandran uchandran@gitlab.com) - 515ab7f1: docs: wrap glab CLI commands in backticks (Evan Read eread@gitlab.com) * Dependencies - a0241495: chore(deps): bump go version updates to v1.26.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 67acc347: chore(deps): bump golangci-lint to v2.11.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 736b087b: chore(deps): bump golangci-lint to v2.11.1 (Ahmed Hemdan ahemdan@gitlab.com) - 83758be2: chore(deps): bump golangci-lint to v2.11.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - a6f2afa7: chore(deps): bump golangci-lint to v2.11.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 0e7a03e7: chore(deps): migrate fang to charm.land/fang/v2 (Tomas Vik tvik@gitlab.com) - 47e7f706: chore(deps): replace huhtest with ugh to support huh v2 (Timo Furrer tfurrer@gitlab.com) - c483714b: chore(deps): update dependency @commitlint/cli to ^20.4.4 (GitLab Renovate Bot gitlab-bot@gitlab.com) - e2168b07: chore(deps): update dependency @commitlint/cli to ^20.5.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 9e0d8a41: chore(deps): update dependency @commitlint/format to ^20.4.4 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 28d6a89f: chore(deps): update dependency @commitlint/format to ^20.5.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - c167e385: chore(deps): update dependency @commitlint/lint to ^20.5.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 0dc4ec68: chore(deps): update dependency @commitlint/read to ^20.5.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - a0f4e7c3: chore(deps): update dependency markdownlint-cli2 to v0.22.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 9a364b95: chore(deps): update module charm.land/lipgloss/v2 to v2.0.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - a8ceb927: chore(deps): update module github.com/charmbracelet/glamour to v2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - dc8eff1f: chore(deps): update module github.com/docker/cli to v29.3.0+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - a27c93b8: chore(deps): update module github.com/mattn/go-runewidth to v0.0.21 (GitLab Renovate Bot gitlab-bot@gitlab.com) - c2a9f2cb: chore(deps): update module github.com/modelcontextprotocol/go-sdk to v1.4.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 192012ae: chore(deps): update module github.com/zalando/go-keyring to v0.2.7 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 93a3e065: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.4.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 245f98e4: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.5.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 1b384b6a: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.6.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 5b744812: chore(deps): update module golang.org/x/crypto to v0.49.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - cf354fb0: chore(deps): update module golang.org/x/oauth2 to v0.36.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - bc5dcc57: chore(deps): update module golang.org/x/text to v0.35.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - d35095ba: chore(deps): update module k8s.io/client-go to v0.35.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 4275d2b0: chore(deps): upgrade to huh v2 (Timo Furrer tfurrer@gitlab.com) * Maintenance - 5f37677f: chore(ai): add AGENTS.md and pre-push verification (Tomas Vik tvik@gitlab.com) - 699b5d18: chore(ci): ci maintenance (Filip Aleksic faleksic@gitlab.com) - e21faffe: chore(gen-docs): dont create empty dirs (Filip Aleksic faleksic@gitlab.com) - 76292112: chore(mod): regroup go.mod (Timo Furrer tfurrer@gitlab.com) - f7308511: chore(tests): ensure keyring test uses tmp env (Filip Aleksic faleksic@gitlab.com) - 009cd795: chore: final tidy up of Markdown in project (Evan Read eread@gitlab.com) - cfcc00f1: chore: make 'repo' and other Markdown files adhere to linting standards (Evan Read eread@gitlab.com) - 00a7aaf2: chore: make Markdown files for subcommands adhere to linting standards (Evan Read eread@gitlab.com) - d0899a30: chore: make Markdown files in 'mr' directory adhere to linting standards (Evan Read eread@gitlab.com) - e26db556: chore: make additional Markdown files adhere to linting standards (Evan Read eread@gitlab.com) - ebdf5693: chore: make even more Markdown files adhere to linting standards (Evan Read eread@gitlab.com) - 65a0481a: chore: make more Markdown files adhere to linting standards (Evan Read eread@gitlab.com) - 6620df6b: chore: make remaining 'ci' Markdown files adhere to linting standards (Evan Read eread@gitlab.com) - 7464b954: chore: make remaining Markdown files for subcommands adhere to standards (Evan Read eread@gitlab.com) - 49703916: chore: make runner-related Markdown files adhere to linting standards (Evan Read eread@gitlab.com) - 6dc90c5a: chore: make some Markdown files adhere to linting standards (Evan Read eread@gitlab.com) - c8856222: chore: use alternative method for wrapping bare URLs in Markdown (Evan Read eread@gitlab.com) - c761ae27: ci: add Go version consistency check (Tomas Vik tvik@gitlab.com) - 64c52d3c: refactor(mr): extract discussion helpers and rendering to mrutils (Tomas Vik tvik@gitlab.com) - f5e9828c: refactor: remove redundant signal handling in ci status command (Kai Armstrong karmstrong@gitlab.com) - dd04eb2f: refactor: rename glamourStyle to getGlamourStyle for clarity (Tomas Vik tvik@gitlab.com) - e29240c2: refactor: use EnableJSONOutput helper for 14 additional commands (Kai Armstrong karmstrong@gitlab.com) * Others - ec7b3600: build: update Go version in .tool-versions to match go.mod (Tomas Vik tvik@gitlab.com) - Update to version 1.89.0: * Features - 039a3495: feat(auth): add SSH hostname prompting for self-hosted instances (Kai Armstrong karmstrong@gitlab.com) - 05fe9806: feat(stack): Add update-base flag to sync command to rebase onto updated base branch (Casey Morris casey@philo.com) - 1c42d1e8: feat: add JSON output support to 18 commands for agent automation (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - 5650beec: fix(release): make notes optional for create/update operations (Kai Armstrong karmstrong@gitlab.com) - ad5731ae: fix(runner): remove redundant EnableRepoOverride from parent runner command (Ashutosh Kumar Singh ashutoshkumarsingh0x@gmail.com) * Documentation - 9b5c3efc: docs: Review and update glab runner docs (Brendan Lynch blynch@gitlab.com) - f3de08bb: docs: Review and update new glab duo cli docs (Brendan Lynch blynch@gitlab.com) * Dependencies - 14c4a74b: chore(deps): adjust to client-go v2 breaking changes (Timo Furrer tfurrer@gitlab.com) - 65c93b4e: chore(deps): change client-go import paths to v2 (Timo Furrer tfurrer@gitlab.com) - 72007fcc: chore(deps): update dependency @commitlint/cli to ^20.4.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 0deaee8b: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - Update to version 1.88.0: * Features - 6fcf0f0f: feat(duo cli): add support for help command (Kai Armstrong karmstrong@gitlab.com) - 608d331a: feat(mr note): add --resolve and --unresolve flags (Kai Armstrong karmstrong@gitlab.com) - 8409c32c: feat(mr view): add --resolved and --unresolved filtering flags (Kai Armstrong karmstrong@gitlab.com) - f1b8d6be: feat: add a new command for the unassigning the runner from the project (Aayush kumaraayush9810@gmail.com) - 184e47a5: feat: add new command for assigning the project to a runner (Aayush kumaraayush9810@gmail.com) * Bug Fixes - 7347ebe2: fix(create): show template selection before editor for -d- flag (Kai Armstrong karmstrong@gitlab.com) - 87064fda: fix(duo): force update check when --update flag is used (Kai Armstrong karmstrong@gitlab.com) - e333c538: fix: parse editor command arguments for huh external editor (Kai Armstrong karmstrong@gitlab.com) * Documentation - 7537c2f7: docs: Update and clarify glab auth login command (Brendan Lynch blynch@gitlab.com) * Dependencies - 7cf3cd3d: chore(deps): update dependency @commitlint/format to ^20.4.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) - Update to version 1.87.0: * Features - c56196f1: feat(duo): add cli command with binary download management (Kai Armstrong karmstrong@gitlab.com) - e3ba483a: feat(mr-list): add more flags (Filip Aleksic faleksic@gitlab.com) - 29e4b5a3: feat(runner-controller): add runner controller runner scope create support (Timo Furrer tfurrer@gitlab.com) - c15d2a2f: feat(runner-controller): add runner controller runner scope delete support (Timo Furrer tfurrer@gitlab.com) - cb1b9639: feat(runner-controller): add runner controller runner scope list support (Timo Furrer tfurrer@gitlab.com) - 02052a33: feat(workitems): add list command (Carlos Corona ccorona@gitlab.com) - dcec8338: feat: add subfolder and ssh_host support for GitLab instances (Kai Armstrong karmstrong@gitlab.com) - 8db560e5: feat: create a new command for getting list of runners info (Aayush kumaraayush9810@gmail.com) - 7f6bcddf: feat: new command for the pausing the runner (Aayush kumaraayush9810@gmail.com) - fcd88b76: feat: new delete command for the runner (kumaraayush9810 kumaraayush9810@gmail.com) * Bug Fixes - 0c9c0326: fix(ci view): prevent crash when viewing unrun downstream pipeline triggers (Kai Armstrong karmstrong@gitlab.com) - 6f89aa11: fix(ci): trigger/retry when branch is not specified and not on default branch (Jay McCure jmccure@gitlab.com) - 317d1453: fix(mr-view): usernames have at prefix (Filip Aleksic faleksic@gitlab.com) - 608c001a: fix: URL encode state name in OpenTofu URLs (Timo Furrer tfurrer@gitlab.com) - 1fb2815a: fix: detect piped stdin properly in snippet create (Kai Armstrong karmstrong@gitlab.com) - 9a51b51b: fix: enable filtering and fetch all members in user selection prompts (Kai Armstrong karmstrong@gitlab.com) - a3934515: fix: use separate config keys for base and head repository resolutions (Kai Armstrong karmstrong@gitlab.com) * Documentation - 4816190b: docs: Update glab job artifact docs (Brendan blynch@gitlab.com) - c5f2fe5f: docs: fix instance of double space in docs (Evan Read eread@gitlab.com) - a724a137: docs: improve error message and examples for --variables-from flag (Kai Armstrong karmstrong@gitlab.com) - 1dbaffe1: docs: remove now unused image from project (Evan Read eread@gitlab.com) * Dependencies - f8fdd33b: chore(deps): update dependency @commitlint/cli to ^20.4.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - ffaaedff: chore(deps): update dependency @commitlint/config-conventional to ^20.4.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8a2125e2: chore(deps): update module github.com/mattn/go-runewidth to v0.0.20 (GitLab Renovate Bot gitlab-bot@gitlab.com) - b7606ac0: chore(deps): update module github.com/modelcontextprotocol/go-sdk to v1.4.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 5d897b63: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1.44.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 91ab5aa6: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1.46.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - cb75cad0: chore(deps): update module k8s.io/client-go to v0.35.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - e3d3de69: chore(ci): golangci-lint update, dont print empty tests (Filip Aleksic faleksic@gitlab.com) - d92a64f9: refactor(cmdutils): improve bool flag pair type (Timo Furrer tfurrer@gitlab.com) - 24800c62: refactor(mr view): switch from Notes API to Discussions API (Kai Armstrong karmstrong@gitlab.com) - 189ed700: refactor: improve TTY checks for non-interactive environments (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.86.0: * Features - adfbc234: feat(config): support per-host https proxy config (Filipe Pina french-ember-gap@duck.com) - 5df7c2b5: feat(mcp): auto-enable JSON output for better LLM parsing (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - 5f8bc6cc: fix(ci): resolve SIGTTOU hang in ci view for snap installations (Kai Armstrong karmstrong@gitlab.com) - 8602557a: fix(mcp): return only content field in tool responses (Kai Armstrong karmstrong@gitlab.com) - 4fdb0082: fix(release-download): checkbox should be green (Filip Aleksic faleksic@gitlab.com) * Dependencies - 38f8bc43: chore(deps): bump golangci-lint to v2.10.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 0c39bcc6: chore(deps): update module github.com/modelcontextprotocol/go-sdk to v1.3.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - b32b2865: refactor(config): split config command into subcommand packages (Kai Armstrong karmstrong@gitlab.com) - d2241b81: refactor(mcp): add MCP annotations to commands that were missing it (Timo Furrer tfurrer@gitlab.com) - d40ec1eb: refactor(mcp): do not register unannotated commands as MCP tools (Timo Furrer tfurrer@gitlab.com) - Update to version 1.85.3: * Bug Fixes - 0a42506b: fix(auth): prevent legacy keyring ambiguity causing 401 errors (Kai Armstrong karmstrong@gitlab.com) - fe12c08d: fix(token): preserve JSON field names in list output (Kai Armstrong karmstrong@gitlab.com) * Documentation - f14c3fd0: docs: Minor changes to runner controller scopes docs (Brendan Lynch blynch@gitlab.com) - 9724cb17: docs: avoid bare URLs in YAML frontmatter in documentation (Evan Read eread@gitlab.com) * Dependencies - d5dc84ba: chore(deps): update dependency @commitlint/cli to ^20.4.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - bd2b3bcf: chore(deps): update dependency markdownlint-cli2 to v0.21.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - Update to version 1.85.2: * Features - feat(cred-helper): fallback to default configured host in non-git folders - Update to version 1.85.1: * Maintenance - ccff6d6b: chore(mcp): add exclude annotation commands when running mcp (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.85.0: * Features - b9acbf32: feat(runner-controller): add runner controller scope create command (Timo Furrer tfurrer@gitlab.com) - 440e067e: feat(runner-controller): add runner controller scope delete command (Timo Furrer tfurrer@gitlab.com) - 17584dfd: feat(runner-controller): add runner controller scope list command (Timo Furrer tfurrer@gitlab.com) - a60d14e8: feat: allow to skip commands for MCP (Timo Furrer tfurrer@gitlab.com) - 1426c9ff: feat: support generic credential helper (Timo Furrer tfurrer@gitlab.com) * Bug Fixes - fb5725e5: fix(download): propagate context for same‑host asset download (David Grieser gitlab@david-grieser.de) * Dependencies - 89ad9a1d: chore(deps): bump GitLab client-go (Timo Furrer tfurrer@gitlab.com) - 699e23b9: chore(deps): update module github.com/modelcontextprotocol/go-sdk to v1.3.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 056a9c97: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1.32.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - f5d08210: chore(deps): update module golang.org/x/crypto to v0.48.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - fb83e882: chore(deps): update module k8s.io/client-go to v0.35.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - b1de8584: refactor(test): support api client with auth source (Timo Furrer tfurrer@gitlab.com) - 61e07344: refactor: use unauthenticated auth source from GitLab client-go (Timo Furrer tfurrer@gitlab.com) - Update to version 1.84.0: * Bug Fixes - 032e82b0: fix(auth): store tokens in keyring when --use-keyring is specified (Kai Armstrong karmstrong@gitlab.com) - c6b792d5: fix(token): respect --active flag in JSON output (Kai Armstrong karmstrong@gitlab.com) * Documentation - aa792b84: docs: Update the text for experiment string (Brendan Lynch blynch@gitlab.com) - Update to version 1.83.0: * Features - 402b39f8: feat(runner-controller): add runner controller create command (Timo Furrer tfurrer@gitlab.com) - 1ee82efe: feat(runner-controller): add runner controller delete command (Timo Furrer tfurrer@gitlab.com) - 265eef13: feat(runner-controller): add runner controller list command (Timo Furrer tfurrer@gitlab.com) - 13c7a4f7: feat(runner-controller): add runner controller token create command (Timo Furrer tfurrer@gitlab.com) - b0ce395b: feat(runner-controller): add runner controller token list command (Timo Furrer tfurrer@gitlab.com) - f561b857: feat(runner-controller): add runner controller token revoke command (Timo Furrer tfurrer@gitlab.com) - e57ddb48: feat(runner-controller): add runner controller token rotate command (Timo Furrer tfurrer@gitlab.com) - 890f1cd2: feat(runner-controller): add runner controller update command (Timo Furrer tfurrer@gitlab.com) - fed9d351: feat(stack): add git push options support to stack sync command (Swapnaneel Patra swapnaneel06@gmail.com) * Bug Fixes - cfc236d9: fix(ci): add merge result pipeline support to glab ci status trace and glab ci trace <job_name> (Tomas Vik tvik@gitlab.com) - a146646e: fix(ci): prevent crash when ci view used in non-interactive environments (Kai Armstrong karmstrong@gitlab.com) - 43bc0a2a: fix(config): detect symlinked config paths as same file (Miroslav Vadkerti mvadkert@redhat.com) - 238aced4: fix(mr): allow boolean flags to explicitly override project defaults (Kai Armstrong karmstrong@gitlab.com) - 4cb5c2c2: fix: Download gotestsum with correct arch (Patrick Bajao ebajao@gitlab.com) - 23759fcc: fix: correct MCP server flag schema (Caio Ramos caioramos97@gmail.com) - 9f4a05d9: fix: properly set gitlab base URL in tests (Timo Furrer tfurrer@gitlab.com) * Documentation - e7b5bb2b: docs(repo): improve clone command documentation and examples (Kai Armstrong karmstrong@gitlab.com) - b44a4394: docs: Fix issue related to capitalization error (Brendan blynch@gitlab.com) - c97e0d17: docs: avoid using redirecting GitLab Handbook links (Evan Read eread@gitlab.com) - f509cae1: docs: clarifies that duo ask uses classic, add link to duo cli (Uma Chandran uchandran@gitlab.com) - 0ffa4ec3: docs: fix link to DPoP information (Evan Read eread@gitlab.com) - abedc299: docs: updates the issue link for consolidating the CLI tools (Uma Chandran uchandran@gitlab.com) * Dependencies - cfc51ba1: chore(deps): update dependency @commitlint/config-conventional to ^20.4.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 326ae073: chore(deps): update dependency @commitlint/config-conventional to ^20.4.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - cc091c98: chore(deps): update dependency @commitlint/config-conventional to ^20.4.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 13fad6f6: chore(deps): update dependency @commitlint/format to ^20.4.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 97c32d06: chore(deps): update dependency @commitlint/read to ^20.4.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - c8ed4b79: chore(deps): update module github.com/avast/retry-go/v4 to v5 (GitLab Dependency Bot tfurrer+gitlab-renovate-bot@gitlab.com) - 8d780b56: chore(deps): update module github.com/charmbracelet/fang to v0.4.4 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 07d97c27: chore(deps): update module github.com/docker/cli to v29.2.1+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - 2b5931dc: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1.29.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 19b9ebdc: chore: Update linting configuration from GitLab project (Evan Read eread@gitlab.com) - 7f4416e4: chore: update appsec handle in vulnerability issue template (Félix Veillette-Potvin fveillette@gitlab.com) - 0739d003: refactor(mcp): migrate to official MCP SDK (Kai Armstrong karmstrong@gitlab.com) - f16c985a: refactor: support ~string types enum flag values (Timo Furrer tfurrer@gitlab.com) - Update to version 1.82.0: * Features - 5ff014e1: feat(installer): Add dark mode support in setup_windows.iss (RC Chuah 4343069-rc-chuah@users.noreply.gitlab.com) - 1304c75f: feat(installer): improve PATH management with programmatic control (Oldřich Jedlička oldium.pro@gmail.com) - e170e21f: feat: add -d- flag support to create commands (Kai Armstrong karmstrong@gitlab.com) - e53cde38: feat: support OAuth2 Access Token only authentication (Timo Furrer tfurrer@gitlab.com) * Bug Fixes - 7883dc24: fix(glrepo): use Host instead of Hostname in FromURL function (Swapnaneel Patra swapnaneel06@gmail.com) - 3aca775d: fix(stack): reorder spinner is displayed over terminal-based editor (Sandro Sauer sauersandro149@gmail.com) - ba8e90ef: fix: normalize nil slices to empty arrays in JSON output (Kai Armstrong karmstrong@gitlab.com) - 9cc43eee: fix: suppress informational messages in JSON output mode (Kai Armstrong karmstrong@gitlab.com) * Documentation - e501773c: docs: Remove EOL spaces in doc files - 2026-01-28 (Marcel Amirault mamirault@gitlab.com) - e6e2eb2d: docs: Remove trailing dot from auth login URL tip (Benedikt Reinartz benedikt.reinartz@statkraft.com) - 56e9970b: docs: Update SHA description for glab mr merge (Brendan Lynch blynch@gitlab.com) - 4c4e16ea: docs: Update install from source instructions (Tom Elliff-O'Shea telliffoshea@rigetti.com) * Dependencies - 52d33754: chore(deps): update dependency golangci-lint to v2.8.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 2d5732d4: chore(deps): update golangci-lint version in CI (Ahmed Hemdan ahemdan@gitlab.com) - b3f9cc6c: chore(deps): update module github.com/docker/cli to v29.2.0+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - 807598a6: chore(deps): update module github.com/gdamore/tcell/v2 to v2.13.8 (GitLab Renovate Bot gitlab-bot@gitlab.com) - b5de98e9: chore(deps): update module github.com/golang-jwt/jwt/v5 to v5.3.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 614c42a5: chore(ci): remove unnecessary pre-build step from prepare_go_cache (Kai Armstrong karmstrong@gitlab.com) - dcba5bc1: chore(docs): gen-docs for mr list (Filip Aleksic faleksic@gitlab.com) - ab44a3bf: chore: Add fdignore to gitignore file (Gary Holtz gholtz@gitlab.com) - 2406d1c7: chore: Adding fdignore to prevent markdown edits (Gary Holtz gholtz@gitlab.com) - 7c5b1dfa: chore: clarify sort/order flags and add consistency improvements (Kai Armstrong karmstrong@gitlab.com) - 4f107308: chore: enable a few linters (Oleksandr Redko oleksandr.red+gitlab@gmail.com) - 428e1d2b: ci(deps): remove GOLANGCI_LINT_VERSION from CI configuration (Ahmed Hemdan ahemdan@gitlab.com) * Others - a8c7c1b6: Revert "Merge branch 'gmh-add-fdignore' into 'main'" (Gary Holtz gholtz@gitlab.com) - 21d1ef08: test: fix expires value in TestClear_WithRevoke_ActiveToken (Oleksandr Redko oleksandr.red+gitlab@gmail.com) - Update to version 1.81.0: * Features - 508116ae: feat(attestation): implement attestation verification in glab (Sam Roque-Worcel sroque-worcel@gitlab.com) - f1dc549a: feat(ci-autologin): exclusively use predefined vars when enabled (Timo Furrer tfurrer@gitlab.com) - 476c3902: feat(stacked-diffs): allow multiline stack ref descriptions (Kev Kloss kkloss@gitlab.com) - 84176fbc: feat: add --active flag to repo clone command for group filtering (Kai Armstrong karmstrong@gitlab.com) - 48970633: feat: implement Executor factory function (Timo Furrer tfurrer@gitlab.com) * Bug Fixes - b514a082: fix(auth login): Fix missing-client_id message (FeRD (Frank Dana) ferdnyc@gmail.com) - 971f673c: fix: allow approving and revoking approvals on draft merge requests (Kai Armstrong karmstrong@gitlab.com) - d156ceb9: fix: ci lint --dry-run fails with 'Reference not found' when --ref is not specified (Kai Armstrong karmstrong@gitlab.com) - 2eb49b9b: fix: directly open external editor when using -d- flag (Kai Armstrong karmstrong@gitlab.com) - 66ff43ee: fix: prevent panic when baseRepoFactory is not initialized in project mirror (Kai Armstrong karmstrong@gitlab.com) - 09779a25: fix: properly propagate errors in mr create when outside git repo (Kai Armstrong karmstrong@gitlab.com) - 5887ad30: fix: properly setup SIGTERM and SIGINT signal handling (Timo Furrer tfurrer@gitlab.com) * Documentation - 754cadaf: docs: improve project mirror command documentation and error messages (Kai Armstrong karmstrong@gitlab.com) * Dependencies - 21f0a360: chore(deps): update dependency @commitlint/cli to ^20.3.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 01a7223c: chore(deps): update dependency @commitlint/cli to ^20.3.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - eb4f9e30: chore(deps): update dependency @commitlint/config-conventional to ^20.3.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 478b5921: chore(deps): update dependency @commitlint/format to ^20.3.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 4ad653dc: chore(deps): update dependency @commitlint/read to ^20.3.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 2f85f2c8: chore(deps): update module github.com/docker/cli to v29.1.5+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8e9988f4: chore(deps): update module github.com/docker/docker-credential-helpers to v0.9.5 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 47d3b309: chore(deps): update module github.com/gdamore/tcell/v2 to v2.13.7 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 04c8e4e2: chore(deps): update module github.com/google/renameio/v2 to v2.0.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6e727e16: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1.10.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 810aadad: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1.11.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - a2e643ac: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1.12.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - f0f30513: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1.13.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 2790055a: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1.14.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 5495005e: chore(deps): update module golang.org/x/crypto to v0.47.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 91c50a8f: chore(deps): update module golang.org/x/term to v0.39.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - a5f6780c: chore(ci): improve caching with separate cache keys per job type (Kai Armstrong karmstrong@gitlab.com) - bfff40a4: chore(makedeb removal): removing unmaintained software documentation (Filip Aleksic faleksic@gitlab.com) - f1d59ace: chore: fix dupword lint issues (Oleksandr Redko oleksandr.red+gitlab@gmail.com) - 72a7a06d: chore: fix typos in comments and variable names across multiple files (Oleksandr Redko oleksandr.red+gitlab@gmail.com) - f5f3d18c: ci: allow failure in snap release job (Timo Furrer tfurrer@gitlab.com) - f3db768a: refactor(alias): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - 1c988f4d: refactor(attestation): use new command executor interface (Timo Furrer tfurrer@gitlab.com) - f88498a8: refactor(auth): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - ea264208: refactor(ci): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - d6f8fdfc: refactor(ci): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - 33006b32: refactor(ci): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - ce81090c: refactor(commands): use context from cobra cmd instead of Background (Timo Furrer tfurrer@gitlab.com) - f1028d1b: refactor(deploy key): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - f99ed615: refactor(duo): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - b8936f99: refactor(gpg-key): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - 6b5e8803: refactor(httpmock): remove unused httpmock package (Timo Furrer tfurrer@gitlab.com) - 4da67d62: refactor(issuable): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - ff522b28: refactor(issuable): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - 228ff301: refactor(issue): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - d4f360c6: refactor(iteration): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - 76448cd6: refactor(label): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - 080c872d: refactor(mr): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - 21c3f34f: refactor(mr): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - aa479583: refactor(opentofu): use new factory executor for tf subprocesses (Timo Furrer tfurrer@gitlab.com) - 94a13bb1: refactor(project): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - c1d841ed: refactor(project): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - 889b6a0a: refactor(release): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - 5944cd40: refactor(schedule): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - 89df3156: refactor(securefile): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - 299328d3: refactor(securefile): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - 0a19d0ab: refactor(snippet): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - 89dae8c8: refactor(stack): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - 7f83526b: refactor(stacks): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - af34285b: refactor(testing): allow to override test IOStreams (Timo Furrer tfurrer@gitlab.com) - 543cc13e: refactor(testing): isolate integration test-only helpers (Timo Furrer tfurrer@gitlab.com) - f0b6a94c: refactor(testing): move api test helper to dedicated file (Timo Furrer tfurrer@gitlab.com) - a09aa417: refactor(testing): move factory test helper to dedicated file (Timo Furrer tfurrer@gitlab.com) - 48dba104: refactor(testing): move generic test tools to dedicated file (Timo Furrer tfurrer@gitlab.com) - 9368f8b5: refactor(testing): move iostreams test helper to dedicated file (Timo Furrer tfurrer@gitlab.com) - 8fbfe78b: refactor(testing): remove tests without value (Timo Furrer tfurrer@gitlab.com) - aae3766a: refactor(token): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - 9705ecae: refactor(update): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - c9eba1ae: refactor(update): use cmdtest.SetupCmdForTest instead of custom cmd setup (Timo Furrer tfurrer@gitlab.com) - 396ed205: refactor(variable): use GitLab client-go mocking instead of HTTP mocks (Timo Furrer tfurrer@gitlab.com) - f468a8ad: refactor: allow attestation verify cmd tests to run in parallel (Timo Furrer tfurrer@gitlab.com) - ce31da55: refactor: remove execext package (Timo Furrer tfurrer@gitlab.com) - fafb990e: refactor: remove unused global variable (Timo Furrer tfurrer@gitlab.com) - 4ccb6536: refactor: rename attestation verify command ctor (Timo Furrer tfurrer@gitlab.com) - 37dd5d47: refactor: rename attestation verify command files (Timo Furrer tfurrer@gitlab.com) * Others - 87acb329: test: adjust whitespace in issuable list test (Jay McCure jmccure@gitlab.com) - 751e6793: test: update ci get test expectations for api client v1.14.0 (Tomas Vik tvik@gitlab.com) - Update to version 1.80.4 (.3 was not released): * Bug Fixes - e8b10d9d: fix(goreleaser): replace unsupported negative lookahead with group reordering (Kai Armstrong karmstrong@gitlab.com) * Dependencies - chore(deps): update module k8s.io/client-go to v0.35.0 - Update to version 1.80.2: * Maintenance - 4bc7ac00: chore(goreleaser): use .ReleaseNotes template variable in Slack announcement (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.80.1: * Bug Fixes - f32543b1: fix: correct syntax for slack announcement (Kai Armstrong karmstrong@gitlab.com) * Maintenance - 6c638a17: refactor(ci): improve Go module caching strategy (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.80.0: * Features - 91cf0912: feat(api): add ndjson output option (Kai Armstrong karmstrong@gitlab.com) - 77b4c815: feat(release): fallback to predefined CI/CD variable for default branch (Timo Furrer tfurrer@gitlab.com) - a9f37d71: feat: migrate prompts from survey to huh (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - 29753e92: fix(installer): support non-admin Windows installation mode (Oldřich Jedlička oldium.pro@gmail.com) - a8ed68af: fix(mr): enable label priority ordering for project and group MRs (Itzamna itzamna@mayaprotocol.com) * Maintenance - dcbcc550: chore(deps): update dependency @commitlint/config-conventional to ^20.2.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8048060f: chore(deps): update dependency @commitlint/format to ^20.2.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - bcfa59c6: chore(deps): update dependency @commitlint/lint to ^20.2.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6e8dabdd: chore(deps): update dependency @commitlint/read to ^20.2.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - c75b1ba7: chore(deps): update dependency golangci-lint to v2.7.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 506962fc: chore(deps): update dependency markdownlint-cli2 to v0.20.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 5b07844b: chore(deps): update module github.com/docker/cli to v29.1.3+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - 043f3533: chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1.8.2 (GitLab Dependency Bot tfurrer+gitlab-renovate-bot@gitlab.com) - 4c4b0a44: chore(deps): update module golang.org/x/crypto to v0.46.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 38011a0a: chore(deps): update module golang.org/x/sync to v0.19.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 15d13baf: chore(deps): update module golang.org/x/term to v0.38.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6edf0caa: chore(deps): update module k8s.io/apimachinery to v0.34.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6ca9b74b: chore(deps): update module k8s.io/client-go to v0.34.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) - f2cd4488: chore(tooling): update golangci lint version (Filip Aleksic faleksic@gitlab.com) - 9d1268e6: chore: improve changelog and add slack announce (Kai Armstrong karmstrong@gitlab.com) - 399fe403: chore: migrate note commands from utils.Editor() to IOStreams.Editor() (Kai Armstrong karmstrong@gitlab.com) - 62a747d1: chore: remove explicit Go version requirements in docs and direct to SSOT (Kai Armstrong karmstrong@gitlab.com) - e1955f0a: chore: remove legacy prompt package and complete huh migration (Kai Armstrong karmstrong@gitlab.com) - 5319171e: chore: remove survey/v2 dependency and complete huh migration (Kai Armstrong karmstrong@gitlab.com) - 4ca48d95: refactor: fix modernize lint issues (Oleksandr Redko oleksandr.red+gitlab@gmail.com) - 2727d78f: refactor: use directional channel parameters (Oleksandr Redko oleksandr.red+gitlab@gmail.com) * Others - 91cc1a93: fix(repo create): handle git operation failures and fix NO_PROMPT behavior (Kai Armstrong karmstrong@gitlab.com) - 71060345: fix(repo list): --group with --include-subgroups does not work with --all (Eric de Ruiter eric@famderuiter.net) - ef41e568: fix(variable export): provide clean JSON output on stdout (Daniel Sonck daniel@sonck.nl) - Update to version 1.79.0: * chore(deps): update dependency @commitlint/cli to ^20.2.0 * fix: make token cache tests compatible with macOS * feat: add --output flag and deprecate --format for variable export * fix: ensure Git output is in English for stack sync * chore(deps): update dependency golangci-lint to v2.7.1 * chore(deps): update module github.com/mark3labs/mcp-go to v0.43.2 * chore(deps): update module github.com/spf13/cobra to v1.10.2 * chore(deps): update dependency golangci-lint to v2.7.0 * feat: support GITLAB_HOST in auth status * chore: wrap bare urls in markdown syntax for doc generation * feat: CI auto-login * chore(deps): update module github.com/docker/cli to v29.1.2+incompatible * refactor(ci): remove factory dependency and handle empty pipelines * fix(ci): correct branch filtering in ci view command * docs: add example for glab mr note command * feat: add securefile download via name * chore: migrate multi-option select prompts to huh * chore: migrate login prompts to huh * docs: update glab repo delete description * docs: update StringSliceVar flags that support repetition * chore(deps): update module github.com/docker/cli to v29.1.1+incompatible * chore(deps): update module github.com/hashicorp/go-version to v1.8.0 * chore(deps): update module github.com/docker/cli to v29.1.0+incompatible * docs: update description for variable strings option * docs(config set): fixing glab config set helper messages * refactor: move away from deprecated tcell code in v2.12.0 * refactor: adapt to breaking changes of client-go v1 * chore(deps): update module github.com/gdamore/tcell/v2 to v2.12.0 * chore(deps): update module github.com/docker/cli to v29.0.4+incompatible * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v1 - Update to version 1.78.3: * chore(deps): update module github.com/docker/cli to v29.0.3+incompatible * chore(deps): update module github.com/mark3labs/mcp-go to v0.43.1 * chore: sort imports with gci formatter * chore(deps): update module github.com/gdamore/tcell/v2 to v2.11.0 * chore(deps): update dependency markdownlint-cli2 to v0.19.1 * chore: allow homebrew to update again for release * chore(deps): update module golang.org/x/crypto to v0.45.0 - Update to version 1.78.2: * chore: prevent homebrew update for publishing - Update to version 1.78.1: * chore: remove edge publish on tag and pin brew version - Update to version 1.78.0: * fix: improve token duration flag clarity and consistency * chore: remove legacy install instruction for script * fix(check-update): avoid using self-hosted credentials for gitlab.com * ci(docs): update Hugo test build * chore(dependencies): roll documentation linting tool versions forward * fix: move token cache info and delete file * chore: refactor make bootstrap to separate script * fix: create config directory earlier in init * feat(token-cache): add token-cache commands for GitLab Agent tokens * chore(deps): update module github.com/gdamore/tcell/v2 to v2.10.0 * chore: update docs for mcp configuration * fix: resource leaks in file handles and HTTP response bodies * chore: fix typos in tests * chore(deps): update module github.com/docker/cli to v29.0.2+incompatible * chore(deps): update module github.com/google/renameio/v2 to v2.0.1 * chore(deps): update module github.com/docker/cli to v29 * chore(deps): update dependency golangci-lint to v2.6.2 * chore(deps): update dependency markdownlint-cli2 to v0.19.0 * chore(deps): update dependency @commitlint/cli to ^20.1.0 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.160.0 * chore(deps): update module k8s.io/client-go to v0.34.2 * chore: add lefthook configuration and bootstrap tools command * chore(deps): update module k8s.io/apimachinery to v0.34.2 * chore: publish to snapcraft edge on tag release * feat: migrate survey prompts to huh (phase 2) * chore(deps): bump all Go versions to 1.25.4 * chore(deps): update module github.com/mark3labs/mcp-go to v0.43.0 * chore(deps): bump go to v1.25.4 - Update to version 1.77.0: * docs(duo): improve documentation for duo and duo ask commands * chore(deps): update module golang.org/x/crypto to v0.44.0 * chore: pin dind version for API mismatch * chore(deps): update module golang.org/x/sync to v0.18.0 * chore(deps): update module golang.org/x/oauth2 to v0.33.0 * feat(milestone): edit and delete * ci(tests): speed up tests execution by using cache * fix: Revert "feat(milestone): edit and delete milestone" * feat(milestone): edit and delete milestone * fix(docs): update the documentation * feat(milestone): added create, list and get commands * refactor(tests): separate unit from integration tests via build tags * chore(deps): update dependency go to v1.25.4 * chore(contributing): fix the vscode debug command * chore(ci): start tests immediately * chore(ci): automate snapcraft build and publishing * feat(label): edit labels * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.159.0 - Update to version 1.76.2: * fix(config): deduplicate paths in config file detection * chore(deps): update dependency golangci-lint to v2.6.1 - Update to version 1.76.1: * fix(ci): snapcraft remove proxy - Update to version 1.76.0: * chore(ci): snapcraft and build stage * fix(config): maintain backward compatibility with legacy config path * fix(logger): clarify log target * chore(tests): create tests for all ssh-key commands * chore(docs): updates name on docs index page * chore(docs): Move images to source directory * chore(docs): prep for Hugo site * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.158.0 * docs(release-process): remove outdated info * feat: migrate Confirm prompts from survey to huh * fix: sign macOS binaries * chore(deps): update dependency golangci-lint to v2.6.0 - Update to version 1.75.0: * chore(snapcraft): add more information on how the package is built * chore(ci): update image versions * chore: use a post-build hook to sign binaries * feat: create shared GitLab theme for Charm libraries * chore(release-docs): update the release docs * feat(auth login): auto-detect GitLab URLs from git remotes * fix(docs): remove index with no underscore * feat(ci-view): view any pipeline via id * docs(repo-list): clarify available options * feat(gpg-key): add gpg-key management commands * chore(deps): update module github.com/docker/cli to v28.5.1+incompatible * fix(config): implement XDG Base Directory Spec compliance * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.157.1 * feat(members): add commands to manage project members * build: adding s390x linux build * chore(deps): bump go to v1.25.3 * fix(ci view): display masked variables in job logs * fix(auth git-credentials): refresh oauth2 access token when expired * chore(deps): update module github.com/mark3labs/mcp-go to v0.42.0 * fix(auth git-credentials): ignore unsupported operations * feat(git-credential): properly support all token types in git-credential plugin * chore(deps): update module github.com/avast/retry-go/v4 to v4.7.0 * chore(deps): update module github.com/charmbracelet/huh to v0.8.0 * chore: Update Vale rules from GitLab project * chore(deps): update dependency golang to v1.25.3 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.157.0 * test(job artifact): simplify zip tests * chore(deps): update module golang.org/x/oauth2 to v0.32.0 * chore(deps): update dependency @commitlint/lint to v20 - Update to version 1.74.0: * caac5301: fix: do not result in bool parse error for empty config (Timo Furrer tfurrer@gitlab.com) - Update to version 1.73.1: * 4ae0efc4: docs: update CLI docs format to work with Hugo (Pearl Latteier platteier@gitlab.com) * 159d7ab4: fix(events): print the title when listing user events (Oleksandr Redko oleksandr.red+gitlab@gmail.com) * 97fcfa9f: fix(tables): add table names to output data (Filip Aleksic faleksic@gitlab.com) * 45524b28: fix: prevent cmdutils.SilentError from printing in error handler (Daniel Lecklider lecklider.6@gmail.com) * 3612240c: fix: return proper not found error for empty hosts in config file (Timo Furrer tfurrer@gitlab.com) * 6e9ce18e: fix: stop generating documentation for deprecated commands (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.73.0: * b47057c7: feat(api): Add support for custom HTTP headers via config (which can point to environment variables) (Henri Cook 2467396-henricook@users.noreply.gitlab.com) * ac56c58a: feat(auth logout): logout from job token and OAuth2 auth (Timo Furrer tfurrer@gitlab.com) * ba8946a7: feat(config): setting empty config value removes its node from config (Timo Furrer tfurrer@gitlab.com) * 0555045f: feat(duo / codex): Added Codex support to Duo (Shekhar Patnaik spatnaik@gitlab.com) * 2839a829: feat(duo claude): add option to configure GitLab MCP for claude code (Timo Furrer tfurrer@gitlab.com) * 85b5a8bf: feat(env): deprecate glab variables without GLAB_ prefix (Filip Aleksic faleksic@gitlab.com) * 5e6c63aa: feat(securefile): Add --all flag to download all secure files (Fred Reinink freinink@gitlab.com) * 5b79e347: feat(securefile): Verify checksum when downloading secure files (Fred Reinink freinink@gitlab.com) * d176a870: feat: add support for CI/CD pipeline inputs in ci run and ci run-trig commands (Florian Forster fforster@gitlab.com) * b427ce28: fix(ci status): properly exit status (Kai Armstrong karmstrong@gitlab.com) * b0013035: fix(mr view): runtime error: invalid memory address or nil pointer dereference (Kai Armstrong karmstrong@gitlab.com) * e068b8d5: fix(repo list): fix project group filtering reliability (Eric de Ruiter eric@thisisdevelopment.nl) * 493e48ca: fix(tests): avoid duplicate test case names (Timo Furrer tfurrer@gitlab.com) * 0d3765e6: fix(tests): properly use t.Parallel() where it's currently used (Timo Furrer tfurrer@gitlab.com) * 6c9f1f1c: fix: cli display parity chars (Jose Gabriel Companioni Benitez 53531665+elC0mpa@users.noreply.github.com) * 8e59a412: fix: prevents claude tests from writing settings.json (Kai Armstrong karmstrong@gitlab.com) * db9d5296: refactor(cmdtest): mark test helper as such (Timo Furrer tfurrer@gitlab.com) * 7c1c95e5: refactor(confirm): use new IOStreams Confirm (Timo Furrer tfurrer@gitlab.com) * 7947cff0: refactor(dependency): remove dependency to securejoin by using os.Root (Timo Furrer tfurrer@gitlab.com) * 973c3f17: refactor(duo ask): use cmdtest.SetupCmdForTest directly (Timo Furrer tfurrer@gitlab.com) * 58e6abec: refactor(select): use select prompt from huh (Timo Furrer tfurrer@gitlab.com) * 668c79b9: refactor(testing): setup test factory for huh (Timo Furrer tfurrer@gitlab.com) * chore(deps): adjust test for client-go bump * chore(deps): update dependency @commitlint/config-conventional to v20 * chore(deps): update dependency @commitlint/format to v20 * chore(deps): update dependency @commitlint/read to v20 * chore(deps): update dependency golangci-lint to v2.5.0 * chore(deps): update module github.com/charmbracelet/fang to v0.4.3 * chore(deps): update module github.com/docker/docker-credential-helpers to v0.9.4 * chore(deps): update module github.com/mark3labs/mcp-go to v0.40.0 * chore(deps): update module github.com/mark3labs/mcp-go to v0.40.0 * chore(deps): update module github.com/mark3labs/mcp-go to v0.41.0 * chore(deps): update module github.com/mark3labs/mcp-go to v0.41.1 * chore(deps): update module github.com/mattn/go-runewidth to v0.0.17 * chore(deps): update module github.com/mattn/go-runewidth to v0.0.19 * chore(deps): update module github.com/mattn/go-runewidth to v0.0.19 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.146.0 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.147.0 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.147.1 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.148.0 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.148.1 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.149.0 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.150.0 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.151.0 - Update to version 1.72.0: * chore: flag claude and mcp features as experimental * feat(cluster agent): introduce revoke command * fix: normalized all commands chars * refactor(login): use url.Parse instead of regex to validate hostname - Update to version 1.71.2: * feat(duo claude): improve error message when duo claude token retrieval is forbidden * chore: optimize MCP tool descriptions and reduce token usage * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.145.0 - Update to version 1.71.1: * Revert "chore: enable signing for all (test)" * chore: enable signing for all (test) * fix: tweak signature name to avoid bin/ - Update to version 1.71.0: * a61ec841: fix: add checksums to signing (Stan Hu) - Update to version 1.70.0 (1.69.0 does not exist): * fix(release): ignore .gitlab-secrets * feat: sign all macOS and Windows binaries in goreleaser * feat(duo claude): add MCP server integration for enhanced Claude Code functionality * fix: glab ci status fails for an MR branch, when Merged Results Pipelines are enabled * docs: Fix malformed link in CONTRIBUTING * feat: sign Windows installer * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.144.1 * feat: sign Windows glab.exe * chore: Use go 1.25.1 * chore: Better explain hosts + Self-Managed for 'repo create' * chore(deps): update module k8s.io/client-go to v0.34.1 * fix(auth): allow dash in hostname URI * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.143.3 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.143.2 * chore: Remove period from "EXPERIMENTAL" string * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.143.1 * docs: Revise docs for 'release create' command * chore(deps): update module golang.org/x/oauth2 to v0.31.0 * chore(deps): update module github.com/spf13/viper to v1.21.0 * feat(opentofu init): support OAuth2 token auth * chore(deps): update module golang.org/x/crypto to v0.42.0 * fix(debug http): deep-copy body for request dump * chore(deps): update module oss.terrastruct.com/d2 to v0.7.1 * chore(deps): update module golang.org/x/sync to v0.17.0 * chore(deps): update module github.com/coder/websocket to v1.8.14 * fix: Subsequent job traces fail to load after the first call to RunTraceSha() * feat: add automatic documentation generation for root command * chore(cluster/graph): add HelmRelease metadata - Update to version 1.68.0: * Changelog - 78c7dc2f: feat(agent bootstrap): support configuring commit author (Timo Furrer tfurrer@gitlab.com) - ab9c7f09: feat(agent): implement token list command (Timo Furrer tfurrer@gitlab.com) - 3a4d34d5: feat(duo/claude): Added support for Claude Code (Shekhar Patnaik spatnaik@gitlab.com) - a1809f2b: feat(issue-list): sort and order functionality (Filip Aleksic faleksic@gitlab.com) - 240f6800: feat(mr): add URL parsing support for mr (Munish munishkumar631@gmail.com) - 76692fd8: feat(release): remove experimental status from --use-package-registry flag (Timo Furrer tfurrer@gitlab.com) - 5101d572: feat(schedule-id): print schedule id on creation (Filip Aleksic faleksic@gitlab.com) - 6e81bd0d: fix(cluster/agent/get_token): clean up lock on OS signal (Mikhail Mazurskiy mmazurskiy@gitlab.com) - 376f3ffa: fix(commands): fixes to commands and env vars (Filip Aleksic faleksic@gitlab.com) - 713ea1b7: fix(env-var): respect GITLAB_HOST environment variable in all commands (Timo Furrer tfurrer@gitlab.com) - 8a6f45d7: fix(help): preserve newlines in glamour output (Jay McCure jmccure@gitlab.com) - d2c2e9da: fix(mr ci): use gitlab api to fetch default branch with fallback to main when... (Munish munishkumar631@gmail.com) - 6adb5415: fix: resolve host mismatch bug in repository resolution (Alex Romanov alex@romanov.ws) - 2fc5d0c6: refactor(cluster/agent/get_token): ensure the right error is returned (Mikhail Mazurskiy mmazurskiy@gitlab.com) * Dependencies - chore(deps): update module github.com/docker/cli to v28.4.0+incompatible - chore(deps): update module github.com/spf13/pflag to v1.0.10 - chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.142.6 - chore(deps): update module github.com/spf13/cobra to v1.10.1 - chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.142.4 - chore(deps): update module k8s.io/client-go to v0.34.0 - chore(deps): update module github.com/stretchr/testify to v1.11.1 - chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.142.2 - chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.142.1 - chore(deps): update module github.com/stretchr/testify to v1.11.0 - chore(deps): update module github.com/gdamore/tcell/v2 to v2.9.0 - chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.142.0 - chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.141.2 - chore(deps): update mock/mockgen to v0.6.0 - chore(deps): update golangci-lint to v2.4.0 - chore(deps): bump go to v1.25.0 in .tool-versions and .gitlab-ci.yml - chore(deps): bump go to v1.25.0 - chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.141.1 - chore(deps): bump effectively used mockgen version - chore(deps): update module go.uber.org/mock to v0.6.0 - chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.139.2 - chore(deps): update dependency golangci-lint to v2.4.0 - Update to version 1.67.0: * refactor(release download): cleanup request creation * fix(release download): use unauthenticated client for non-GitLab asset links * feat(opentofu): add `terraform` and `tf` as aliases for the `opentofu` * feat(debug): support `GLAB_DEBUG_HTTP` env variable to log HTTP traffic * chore(deps): update module k8s.io/client-go to v0.33.4 - Update to version 1.66.0: * feat(agent token): generate new token if cached token has been revoked * feat(agent token): lock token creation for concurrent plugin calls * feat(agent token): force keyring mode by default * feat(opentofu): add delete command * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.139.0 * chore(opentofu): fix command docs * fix(tests): Add missing can_create_organization to mock * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.138.0 * feat(state list): add OpenTofu state download command * feat(state list): add OpenTofu state unlock command * feat(state list): add OpenTofu state lock command * feat(state list): add OpenTofu state list command * refactor(release): avoid repeating calls to cmd.Flags() * feat(release): support configuring name of release asset package * fix(git): fix git test * chore: Apply 3 suggestion(s) to 3 file(s) * feat(cluster/graph): support ignoring arc direction when filtering by roots * feat(opentofu): implement new `opentofu init` command * feat(project): enhance fork handling for existing repos * chore: add .vscode/launch.json for debugging configuration * fix(mr checkout): respect git_protocol configuration instead of hardcoding SSH * fix(warnings): fix misc warnings across the code base * chore(deps): update module golang.org/x/crypto to v0.41.0 * refactor(factory): rename GitLab client variables * refactor(factory): rename misleading HttpClient func to GitLabClient * refactor: simplify tests with t.TempDir and t.Chdir * chore(deps): bump go to v1.24.6 * chore(deps): update dependency golang to v1.24.6 * feat(cluster/graph): support filtering by roots * feat: add autofill flags to mr update command * docs: Add a troubleshooting subheading to the README * feat(help): document -h short option * chore: Add additional mocks to git package * chore: don't run tests for doc changes only * chore(deps): remove duplicate golangci-lint entry from tools-versions * chore(deps): update dependency golangci-lint to v2.3.1 * docs: testing against staging * chore(hostname): remove h flag for hostname * chore(gen-docs): run gen docs without cmdtest package dependency * fix(api): respect --hostname argument * chore(deps): update module github.com/golang-jwt/jwt/v5 to v5.3.0 * feat(mr-list): support "Any" user * chore: simplified token validation * feat(duo ask): self-hosted instance url check - Update to version 1.65.0: * fix(get-token): gracefully handle concurrent token cache writes * feat(issue-update): add due-date functionality * chore(deps): update module github.com/docker/cli to v28.3.3+incompatible * feat(issue): Remove --label and --not-label mutual exclusivity * feat(mr): display file and line context for code comments * feat(job artifact): Add --list-paths to print paths - Update to version 1.64.0: * fix(ci run): honor passing `--variables` * docs: Add bare explanation of mTLS config * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.137.0 * chore(deps): update dependency golangci-lint to v2.3.0 * refactor: use AutoMerge * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.135.0 * refactor: factory ApiClient method does not ned to rely on config * refactor(config): remove unused UnsetHost method from Config * fix(docker-credential-helper): default config stub fixes * fix(api): use correct API path for GraphQL requests * refactor(get-token): us os.UserCacheDir instead of own version * feat: show all configured hosts in interactive login prompt * refactor(agent get-token): support cache mode * chore(enum flag): implement enum flag helper * refactor(agent get-token): use keyring and fallback to fs for token cache * feat(release): support uploading release assets to generic package registry * chore(deps): update module k8s.io/client-go to v0.33.3 * chore(deps): update module k8s.io/client-go to v0.33.3 * chore(deps): update module github.com/golang-jwt/jwt/v5 to v5.2.3 * feat(agent): support configurable token expiration duration * refactor(agent update-kubeconfig): remove unnecessary use of persistent flags * feat(agent get-token): cache token in local file * refactor(agent get-token): move pat creation into separate function - Update to version 1.63.0: * fix(docker-credential-helper): init cred helpers if empty * feat(hidden-variables): List and set hidden variables * refactor: do not use SSH URL translator for non-SSH URLs * refactor: remove unused url translator function * chore(deps): bump go to v1.24.5 * chore(deps): update dependency golangci-lint to v2.2.2 * chore(deps): update module golang.org/x/crypto to v0.40.0 * chore(deps): update module github.com/docker/cli to v28.3.2+incompatible - Update to version 1.62.0: * feat: allow (un)archiving repo with `repo update --archive` * chore(deps): update module golang.org/x/text to v0.27.0 * chore(deps): update module golang.org/x/sync to v0.16.0 * refactor: use oauth2 package from GitLab client-go * refactor: use context in OAuth2 authorization flow * refactor: use x/oauth2 instead of custom OAuth2 types * refactor: rename oAuthClientID to oauthClientID * refactor: use x/oauth2 for authorization flow * refactor: use x/oauth2 for refreshing token * chore(deps): update module github.com/docker/cli to v28.3.1+incompatible * feat: add docker-credential-helper * chore: Backport change to backend file * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.134.0 * chore: Revise UI and docs strings * fix: glab auth login to work with mTLS by using api.NewClientWithCfg instead of native HTTPClient * feat(var): add option to list instance vars * refactor: do not write test key files if they already exist * chore(pipeline): add job to verify generated code * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.133.0 * fix: reflection panic when using survey with release create * refactor: improve structure of API client constructor * refactor: make api client auth source available for OAuth2 refresh workflow * refactor: use context for client HTTPRequest functions * refactor: make api client initialization more flexible and more maintainable * refactor: remove condition httpclient nil check in api client * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.132.0 * refactor: remove globals in variable create command * refactor: remove globals in create issue board command * refactor: remove globals in ci run command * refactor: remove globals in ci lint command * refactor: remove globals in issue board view command * refactor: move global API functions that are overridden in tests to a local scope * refactor: use GitLab client-go directly in some commands * refactor: use GitLab client-go directly in some ci commands * refactor: use GitLab client-go mocks instead of HTTP mocks in changelog commands * refactor: use GitLab client-go mocks instead of HTTP mocks in auth commands * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.131.0 * refactor: speed up dpop generate test by pre-generating test data * refactor: remove unused BaseURL method in API client * refactor: remove unnecessary lazy initalization of GitLab Client in API client * refactor: rename api.NewClientWithCfg to api.NewClientFromConfig * refactor: remove unused protocol parameter for api.NewClientWithCfg * refactor: remove unnecessary if err check when creating new client * refactor: move commands/flag into cmdutils * chore(pipeline): use 2x large runners for release test * refactor: use NewTestFactory instead of manually constructing test factory * refactor: use NewTestFactory with NewTestApiClient to remove TestClient * refactor: rename MustTestClient to NewTestApiClient * refactor: remove unused cmdtest.InitFactory * refactor: use NewTestFactory instead of InitFactory in command tests * feat(cluster/graph): use struct for arc attributes * refactor: use NewTestFactory in SetupCmdTest * refactor: move hooks package into telemetry files in main pkg * fix: prevent crash when it is not possible to get client for telemtry * refactor: do not used named returns unless it makes sense * refactor: remove unused parameters * refactor: remove unneccessary type conversions * refactor: remove deadcode * refactor: move httpmock to testing/ and introduce testing/gitmock * refactor: remove unused git_mock package * refactor: move api package into internal/ * refactor: add depguard rule that no testing package is used in non-testing code * refactor: only depend on cmdutils from commands * refactor: move cmdutils package from commands/ to internal/ directly * refactor: move cmdtest package into internal/testing * refactor: move packages from pkg/ under internal/ * refactor: move commands/ under internal/ * refactor: cache base repo * chore(deps): update dependency golangci-lint to v2.2.1 * chore(deps): update dependency golangci-lint to v2.2.0 * feat(cluster/graph): better error reporting * refactor: remove integration test that doesn't make sense * refactor: remove manual RepoOverride from integration tests * refactor: remove manual RepoOverride from commands * chore(deps): update dependency golangci-lint to v1.64.8 * ci: upgrade golangci-lint to v2 * chore(ci): enable race detector in tests * refactor: update check from main function * refactor: rename telemtry hook setup function * refactor: concentrate debug mode setup in one place * refactor: move survey core setup out of main function * refactor: introduce build info to factory and use consistently in commands * refactor: remove global debug variable * refactor: remove global default hostname and protocol variables * refactor: remove global build info and introduce user agent to factories * refactor: use ExecuteCommand in favor of RunCommnad * refactor: remove exotic FirstLine test helper function * refactor: remove custom Eq test helper * refactor: use prod factory directly in integration tests * refactor: directly create factory with test config instead of stubbing * refactor: do not stub factory when no required * refactor: initialize config exactly once * refactor: reduce down to single factory creation function * refactor: configure iostreams from config in factory func * refactor: create config before factory to improve factory immutability * refactor: exclusively use `cmdtest.TestIOStreams` factory func in tests * refactor: unexport internal 256 color support check function * refactor: use tagged switch instead of if to set iostreams prompt * refactor: introduce proper factory for iostreams * refactor: remove global terminal-related variables * refactor: remove IOStreams globals * refactor: remove global apiClient instance * refactor: always use factory to create client from commands * refactor: introduce ApiClient factory function * refactor: remove unneccessary use of global apiClient * refactor: remove obsolete client refresh functionality * refactor: remove introduce HTTP client override functionality * refactor: introduce http client client option funcs * refactor: unexport internal gitlab client * refactor: unexport client protocol * refactor: introduce client option funcs to replace various client factory functions * refactor: unexport private client factory functions * refactor: move API test client to cmdtest package * refactor: add allowInsecure flag to tlsConfig func - remove ldflags '-s -w' from build command - fix missing git commit in 'glab version' output - Update to version 1.61.0: * refactor: remove unused option struct fields * refactor: align more commands with common structure * refactor: remove unnecessary copying of test var * refactor: remove unused runE / runF cmd args * feat(cluster/graph): extra docs on CEL * feat(cluster/graph): support logging watch request * feat(cluster/graph): support selecting namespaces * feat: add 'repo update' command * feat: command for ci run mr * refactor: first pass of aligning command structure * chore(deps): update module k8s.io/client-go to v0.33.2 * feat(cluster/graph): enhance docs * feat(cluster/graph): allow selecting resources by name * feat(cluster/graph): allow selecting common resources in common groups * refactor(cluster/graph): rework default query construction * fix(cluster/graph): remove print * chore(deps): update module k8s.io/apimachinery to v0.33.2 * chore(deps): update module github.com/hashicorp/go-retryablehttp to v0.7.8 - Update to version 1.60.2: * chore: Make telemetry warning debug level * refactor: custom factory for docs generation * refactor: use the test factory * refactor: use stubs in the test factory * refactor: mutate io before passing * refactor: rework test factory * refactor: use IO function * refactor: pass IO streams to factory constructor * refactor: remove error handling from RepoOverride() calls * refactor: use the interface * refactor: new factory interface - Update to version 1.60.1: * fix: fix regression from 6fbcfab310b545cdd1cd4ca20918b5862be34255 * chore(deps): bump go to v1.24.4 - Update to version 1.60.0: * fix: correctly use t.Setenv() in tests * refactor: remove unused fucntions * refactor: do not use global OverrideAPIProtocol, set it on local client * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.130.1 * refactor(agent bootstrap): use options struct * refactor(cluster agent): mock GitLab API in get token cmd tests * refactor(cluster agent): use options struct * fix(agent): use UTC when calculating token expiration * chore: Readding telemetry, fixing segfault * refactor(cluster graph): unexport run method * refactor: Add thread safety for factory * chore(deps): update module github.com/coder/websocket to v1.8.13 * feat: cluster graph command * feat: :wrench: Add helm-repository-address to cluster agent bootstrap command * fix(cluster/agent): propagate repo host and name * refactor: cleanup cluster agent update-kubeconfig * fix: Improving user feedback when no jobs exist in a pipeline * fix: log errors to StdErr * fix(deps): drop direct golang.org/x/exp dependency * fix: add missing newline * docs(workspace): update doc for using workspace with cli project * chore(docs): update example to $># format * refactor: remove globals from tests * chore(deps): update module golang.org/x/crypto to v0.39.0 * chore(deps): update module golang.org/x/text to v0.26.0 * refactor: remove some of the global state, part 2 - Update to version 1.59.2: * Revert "fix(telemetry): remove data race in telemetry hook" - Update to version 1.59.1: * fix(telemetry): remove data race in telemetry hook - Update to version 1.59.0: * refactor: do not use the global client * refactor: do not use api.GetClient() in commands/api * fix: make HttpClient always safe to use * chore(usage-ping): Add telemetry data for commands/projects/namespaces * feat(config): added GitDir to get proper location to put local configs * chore: Update command examples following new style guide * feat: add pagination to ci trigger command * docs(api): add simple GraphQL oneliner - Update to version 1.58.0: * feat(deploy-key): Deploy key functionality * fix(auth): fix CI JOB TOKEN with custom CA file * chore: Adding initial git function mocks * chore(usage-ping): Add configuration option to opt out of usage data * feat(securefile): add project secure file get support * chore: Update command examples following new style guide, fixes #7833 * chore: Make scopes of non-admin PATs clearer * chore(docs): update example to $># format * chore(deps): update module k8s.io/client-go to v0.33.1 * chore(deps): update module k8s.io/apimachinery to v0.33.1 * chore(deps): update dependency markdownlint-cli2 to v0.18.1 * docs: Add mise as an install method * chore: Update go to 1.24.3 * chore(deps): update dependency markdownlint-cli2 to v0.18.0 * chore(deps): update dependency @commitlint/read to ^19.8.1 * chore(deps): update dependency @commitlint/format to ^19.8.1 * chore(deps): update dependency @commitlint/lint to ^19.8.1 * feat(cluster): add FluxCD environment creation during agent bootstrap * chore(deps): update dependency golang to v1.24.3 * refactor(auth): Move auth helper to its own location * chore(deps): update module golang.org/x/oauth2 to v0.30.0 * chore(docs): update example tro $># format * fix: try to update ref head only if remote has diverged * chore(deps): update module golang.org/x/crypto to v0.38.0 * docs: improve help text for `ci run` `--variables-from` * feat: Add iteration command * chore: Update links to docs.gitlab.com * chore(docs): update example to $># format * test(stacked-diffs): adding missing test for stack save * refactor(cmdutils): remove used once function - Update to version 1.57.0: * test: Use GITLAB_TOKEN_TEST instead of GITLAB_TOKEN * chore: update to gomock 0.5.2 * chore(deps): update module go.uber.org/mock to v0.5.2 * test: Add UT for StackRootDir * chore: apply gopls modernize * chore(deps): update module k8s.io/client-go to v0.33.0 * chore(deps): add node * chore: account for breaking changes in client-go 0.128.0 * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.128.0 * chore: format release commands * chore: format schedule commands * chore(deps): update module k8s.io/apimachinery to v0.32.4 * refactor: mrutils.getMRForBranch & mrutils.mrOptions * chore(deps): update module github.com/charmbracelet/glamour to v0.10.0 - Update to version 1.56.0: * feat(securefile): add project secure file create support * chore: Update command examples following new style guide * fix(release): allow use of commit log for release notes * fix: readibility & consistency of persing pipeline variable error * refactor: Explicit nil return for error in successful snippet creation * chore: apply new style guide for MR command examples * fix: Initialize factory HTTP client with error handling to support stub behavior * chore: apply new style guide for misc ci command help texts * chore: apply new style guide for more cli ci command help texts * chore: Change plaintext syntax to 'console' for examples * chore: apply new style guide for cli ci command help texts * chore(docs): update examples to $># format * chore(docs): update example to $># format * chore: apply new style guide for more cli help texts * docs: Add docs change to clear a couple of Vale warnings * chore: Update Vale rules for project * chore: apply new style guide for cli help texts * chore(docs): update example to $># format * chore(docs): update example to $># format * chore(docs): update example to `$>#` format * chore(docs): update example to $># format * chore(docs): update example to $># format * chore: disable markdownlint rule MD014 * fix: change the example cli help example section * feat: ouput option json for project search * chore: Update linting tools in project * feat(issue): Implement the `--epic` option for `issue list` * docs: Fix last markdownlint errors, restore linting * feat(securefile): add project secure file remove support * chore: restrict access to test job artifacts * fix(project): remove extra --tag option from "publish catalog" command * feat(securefile): add project secure file download support * chore(deps): update module golang.org/x/oauth2 to v0.29.0 * chore(deps): update module go.uber.org/mock to v0.5.1 * chore(deps): update module golang.org/x/crypto to v0.37.0 * feat(securefile): add project secure file list support * chore(deps): update module gitlab.com/gitlab-org/api/client-go to v0.127.0 * fix(update-check): environment variable has higher priority * chore: Update glamour version * ci: update commit lint to the latest version * feat(logout): support token removal * fix(ci list): correct timezone format * chore(deps): update dependency @commitlint/config-conventional ^19.8.0 * chore(deps): update dependency @commitlint/read to ^19.8.0 * chore(deps): bump golang to v1.24.2 * chore(ci): enable dependency proxy * chore(deps): update module github.com/gdamore/tcell/v2 to v2.8.1 * chore(deps): update dependency @commitlint/format to ^19.8.0 * chore(deps): update dependency danger-review to v2.1.0 * refactor: set HTTPClient without factory * chore: Fixing homebrew pull request version bump * chore(deps): update module github.com/spf13/viper to v1.20.1 * docs(examples): update all examples * chore(deps): update module k8s.io/client-go to v0.32.3 - Update to version 1.55.0: * chore(deps): update module github.com/golang-jwt/jwt/v5 to v5.2.2 * refactor(cluster agent): use new client-go testing pkg * refactor(tokens): Add description and refactor token creation * feat(config-edit): add config edit command * build(windows-builds): include installer sha in checksum file * feat: add command for publishing to CI catalog * refactor: move CI/CD catalog publishing to project command - Update to version 1.54.0: * chore(deps): update dependency axios to ^1.8.4 * build(version): standardize versions accross builds * feat: create project command can skip creating git repository * chore: Updating client-go * feat: Create stack from created branch * chore(deps): update golang to v1.24.1 * test: Start using mocks for git tests * feat(ssh-key): add usage-type when creating ssh key * chore(deps): update module github.com/spf13/viper to v1.20.0 * chore(deps): adjust for breaking changes in client-go * chore(deps): update module client-go to v0.125.0 * fix(issue/mr create): add ability to assign group milestones * feat: Render markdown help text in glamour * chore(deps): update module k8s.io/apimachinery to v0.32.3 * chore(deps): update dependency axios to ^1.8.3 * chore: update gitlab.com/gitlab-org/api/client-go v0.124.0 * feat(dpop): add option to generate DPoP JWTs * chore(deps): update dependency @commitlint/lint to ^19.8.0 * fix: goreleaser archives.format is deprecated * chore(deps): update dependency axios to ^1.8.2 * chore(deps): update module golang.org/x/oauth2 to v0.28.0 * chore(deps): update module golang.org/x/crypto to v0.36.0 * chore(deps): update module golang.org/x/text to v0.23.0 * chore(docs): use consistent language in flags * chore: Add USERNAME to environment variables cleared for test * fix(formatting): fixed output formatting for commands * chore: Update source of documentation linting image * chore: Update Vale rules from 'gitlab' project * chore(deps): update golang to v1.24.0 * chore(deps): update dependency axios to ^1.8.1 * feat: give credits in changelog * chore(deps): update module golang.org/x/oauth2 to v0.27.0 * chore(deps): update module golang.org/x/crypto to v0.35.0 * chore(deps): update module github.com/avast/retry-go/v4 to v4.6.1 * feat(var): make count of listed vars configurable * fix(token-list): expiration time can be null * docs(help): document all environment variables * chore: Improve re-auth and self-managed strings * fix(ci status): allow live to loop with NO_PROMPT * chore(snap): update base and fix version * feat(ssh-key): add usage type to output * feat: show help hint on error instead of full usage * docs: improve ci job variable docs * fix(token-list): token list works outside a repository * fix: replace `GetLastPipeline` calls with `GetLatestPipeline` * chore(deps): update module github.com/spf13/cobra to v1.9.1 * feat(ci status): return error when pipeline failed * fix(ci status): use GetLatestPipeline API for branches * chore(deps): update gitlab.com/gitlab-org/api/client-go to v0.123.0 * feat(ci-run-web): add --web flag to ci run * chore(deps): update module k8s.io/apimachinery to v0.32.2 * chore(ca-certificates): include ca-certificates in docker * fix(ci get): do not require branch if pipelineID is given * fix(mr update): multiple draft prefixes * chore(onboarding): update urls * chore(deps): update module golang.org/x/crypto to v0.33.0 * test: create with multiple files * fix(table-headers): add table headers to output * fix(parsing): recover from unparsable structs * chore(deps): update module golang.org/x/term to v0.29.0 * fix: accept input from stdin when stdin is TTY * fix: print to `Opts.IO` because it can be processed * docs: document multiple files feature * feat(snippets): support uploading multiple files * refactor(snippets): use newer files API * feat(snippets): support multiple files * refactor: remove unnecessary `opts.Lab` - Update to version 1.53.0: * feat(release): add experimental notes text-or-file parameter * feat(diffs): Add --raw option to mr diffs * fix: fix incorrect API host being shown in status * fix(docs): document GLAB_CHECK_UPDATE environment variable * chore(tests): added ssh-key list tests * refactor(pagination): add parameters on struct creation * feat(repo): list user projects * fix(pkg/tableprinter): handle nil pointer cell values * test(archive): fix flaky archive test * chore(deps): update module golang.org/x/text to v0.22.0 * refactor(main): move SilentError check out of printError * chore: Fixing a test that keeps failing * fix(issueable list): remove support multiple not- filter flags * chore(uploads): ignore deprecated UploadFile function * refactor(issues): rename ListIssues to ListProjectIssues * chore(client-go): account for breaking changes * chore(deps): update module client-go to v0.122.0 * fix: make SilentError exit with code 1 as documented * feat(update): check for updates periodically * chore(deps): update module golang.org/x/oauth2 to v0.26.0 * fix(snippet): show friendly error for project snippet without repo * feat(variables): add option to list/update/set description of vars * chore(deps): update dep @commitlint/config-conventional to ^19.7.1 * chore(deps): update dependency @commitlint/lint to ^19.7.1 * refactor(git): remove excessive argument processing for RunClone * docs(project-search): Fixed project search example usage * chore(deps): update dependency @commitlint/lint to ^19.7.1 * feat(label): add command to delete labels * test(label): add missing tests to label-creation * docs: Shift environment variables from unordered list to table * fix(snippet create): complete usage info * chore: Tidy up docs for 'schedule update' * feat(update_check): Rename variable to GLAB_CHECK_UPDATE * build(flags): strip symbols from binary * refactor(var): rename functions to match what they do * fix(artifact): create subdirs instead of failing * fix(mr merge): friendly error when merges require CI to pass * refactor(perms): cleanup Windows permissions FIXME * fix(ci status): detect branch repo from remote * feat(schedule): Add option to edit an existing scheduled pipeline * chore: show colored diff when docs update is needed * fix: listing of group variables without git repository * feat(update check): Add env variable to skip update check * fix(repo clone): correctly separate gitflags arguments * feat(mr list): Add sorting functionality for MRs * feat(cancel): implement glab ci cancel command * docs(repo): explain archive-flag better * feat(repo clone): document group syntax in usage * feat: add debug output for tracing `glab ci status` * chore(deps): update module k8s.io/client-go to v0.32.1 * chore(deps): update module k8s.io/client-go to v0.32.1 - Update to version 1.52.0: * feat(release): add --no-close-milestone flag for release creation * chore(deps): update module github.com/briandowns/spinner to v1.23.2 * chore: roll docs linting tooling forward * feat(release): Add --no-update to release create * chore(deps): update module k8s.io/apimachinery to v0.32.1 * chore(deps): update module github.com/mattn/go-colorable to v0.1.14 * fix: update path where config.yml is displayed * feat: Add reordering of stacks * fix(docs): change toc to show actual contents * chore: Post-merge review of UI strings * docs: Fix missing period in display * chore(deps): update golang to v1.23.4 * docs: add command for previewing release commits * chore(deps): update module golang.org/x/crypto to v0.32.0 * chore(deps): update module golang.org/x/term to v0.28.0 * chore(deps): update module github.com/otiai10/copy to v1.14.1 * chore(deps): update module golang.org/x/oauth2 to v0.25.0 * feat: add support for setting issue weight in glab issue update * chore(dep): update x/net * chore(deps): update golang to v1.23.3 - Update to version 1.51.0: * feat(ci): add more flags to filter ci list output * refactor: Moving and adding some test helpers for `stack reorder` * feat(list): add project list filter for all non-archived projects * chore(deps): update module k8s.io/client-go to v0.32.0 * chore(deps): migrate go-gitlab to gitlab.com/gitlab-org/api/client-go * chore(deps): update module k8s.io/apimachinery to v0.32.0 * chore(deps): update module golang.org/x/crypto to v0.31.0 * fix(variable): add quotes to export-commands * refactor: Refactor some functions and add some stack helpers * feat: add --active flag to glab token list * fix(agent bootstrap): panic when cfg exists but no user access defined * chore(deps): update module golang.org/x/term to v0.27.0 * chore(deps): update module golang.org/x/text to v0.21.0 * chore(deps): update dependency danger-review to v2 * chore(deps): update dependency axios to ^1.7.9 * feat: added mr list filtering flag --not-draft - Update to version 1.50.0: * feat(release): "release create --publish-to-catalog" flag * feat: add environment scope for export * chore(deps): update dependency axios to ^1.7.8 * feat(label list): flag to list group labels * chore(deps): update module github.com/stretchr/testify to v1.10.0 * feat(auth): support CI JOB TOKEN * refactor: Fix some package names * chore(deps): update module k8s.io/client-go to v0.31.3 * fix(cluster agent): constructing KAS Kubernetes API Proxy URL * chore(dep): update cross-spawn * test: Add basic stack sync testing * chore(deps): update dependency @commitlint/config-conventional ^19.6.0 * chore(deps): update dependency @commitlint/lint to ^19.6.0 * fix: adjust test data for new go-gitlab release * chore(deps): update module github.com/xanzy/go-gitlab to v0.114.0 * docs(debug): add information about debugging glab * feat(test): Integration test for create mr with recover option - Update to version 1.49.0: * chore: Restore markdownlint testing, disable rule MD029 for ol-prefix * fix(stacked-diffs): remove merged or closed MRs in sync * feat(test): Integration test for create issue with recover option * docs: Spacing, capitalization, and punctuation * fix(commands/cluster/agent/get_token): agentID is always 64 bit * feat(release): "release create --tag-message" flag * refactor: Remove package-level vars * fix(diff): return most recent diff version only * chore(deps): update module golang.org/x/oauth2 to v0.24.0 * chore(deps): update module golang.org/x/crypto to v0.29.0 * feat: list personal, project or group access tokens * chore(deps): update module github.com/xanzy/go-gitlab to v0.113.0 * test: Adding checking of post body to http mocks * chore(license): Update LICENSE * docs: add flux bootstrap path note to agent bootstrap cmd * docs: ignore generated documentation when running markdownlint-cli2 * fix: add more info to gitlab agent reconcile error * chore(deps): update module github.com/zalando/go-keyring to v0.2.6 * chore(deps): update module k8s.io/client-go to v0.31.2 * chore(deps): update module k8s.io/apimachinery to v0.31.2 * feat: add environment format for variable export * feat(auth login): allow more non-interactive login options * feat(issues): add filter by iteration option to issue list * feat: rotate personal, project or group access tokens * fix: utilize api_host in config to avoid git subdomain issues * chore(deps): update module go.uber.org/mock to v0.5.0 * feat(agent bootstrap): support specifying Agent Helm Chart values - Update to version 1.48.0: * docs: Explain set-upstream for stacks in forks * chore(release): release for freebsd and ppc64le * feat: configure KAS address explicitly in agent bootstrapping * feat: add token id reference to agent secret * feat: implement environment and dashboard support * chore(deps): update module github.com/xanzy/go-gitlab to v0.112.0 * refactor(pkg/utils): Add require.Equals in pkg/utils_test.go * chore: use goreleaser nightly * chore(deps): update golang to v1.23.2 * fix(staging): consider foo.gitlab.com self managed * chore(deps): update module github.com/xanzy/go-gitlab to v0.111.0 * chore(go-gitlab): bump to 0.110.0 * chore: make goreleaser use the go version in GitLab CI * docs: Add notes on discussing large contributions * chore(deps): update module golang.org/x/crypto to v0.28.0 * chore(deps): update module golang.org/x/text to v0.19.0 * feat: revoke personal, project and group access tokens * docs: make documentation conform to linting rules * chore: update linting tools and configuration * feat: add `stack switch` command * chore: don't run 'release-test' for actual releases - Update to version 1.47.0: * feat(stacked-diffs): Add origin fetch so sync will fully pull+push * docs: revise token-create page lightly * feat(stack): introduce stack list command * fix: use conventional linux package and archive file names * chore(ci): run build_windows asap * fix(stacked-diffs): fix MR creation for forks * feat: cluster agent bootstrap command * fix: glab mr view prompt disabled if NO_PROMPT is set with multiple mr * chore: insert commit subject + body to MR template descriptions * chore: increase size of CI runners * chore: optimize pipeline runtime * feat: create personal, project or group tokens * chore(deps): update @commitlint/config-conventional to ^19.5.0 * fix(repo clone): fix --with-shared behaviour * chore: bump code intel component to v0.0.3 * chore(deps): update module k8s.io/client-go to v0.31.1 * chore(deps): update dependency @commitlint/lint to ^19.5.0 * fix: revise docker image dependencies * chore(deps): update dependency @commitlint/format to ^19.5.0 * chore(deps): update golang to v1.23.1 * chore(deps): update module golang.org/x/oauth2 to v0.23.0 - Update to version 1.46.1: * fix(login): use verifier to create oauth challenge * docs: fix violation of updated linting rules * chore(deps): use latest docs Docker image and linting configuration * chore(deps): update module golang.org/x/crypto to v0.27.0 * chore(deps): update module golang.org/x/text to v0.18.0 * fix(typo): update token generation URL * chore(deps): update module golang.org/x/term to v0.24.0 - Update to version 1.46.0: * fix: fix example command for stack sync * refactor: Add a more secure way to generate a random string * chore(deps): update dependency axios to ^1.7.7 * fix(api): ensure stable sorting of MRs by descending CreatedAt * feat(variable get): allow scope for group vars * chore(deps): update dependency @commitlint/lint to ^19.4.1 * chore: add GitLab Advanced SAST to CI/CD config * style: Removing `exportloopref` since we're using go 1.22 * fix(api): enable group MR listing with reviewer and assignee filters * chore(deps): update dependency axios to ^1.7.5 * chore: remove space before colons * chore: update code intelligence component to v0.0.2 * feat(stack): stack save/amend use $EDITOR * chore(deps): upgrade to go 1.23 * feat: repo list include/exclude subgroups and archived support * fix(snippet create): allow for stdin * chore: switch to code intel CI/CD Component * chore(deps): update module golang.org/x/text to v0.17.0 * chore(deps): update module golang.org/x/crypto to v0.26.0 * chore(deps): update dependency axios to ^1.7.4 * fix: restrict zip decompression * chore(deps): update module k8s.io/client-go to v0.31.0 * chore: update axios for commit lint * chore(deps): update module golang.org/x/sync to v0.8.0 * chore(deps): update module github.com/spf13/cast to v1.7.0 * Gitignore gitlab reports * chore(deps): update module golang.org/x/term to v0.23.0 * chore(deps): update module github.com/charmbracelet/glamour to v0.8.0 * docs(installation): Add ASDF section in the installation_options TOC * fix(release upload): fix asset URL format for uploads in GitLab 17.2 * chore(deps): update dependency axios to ^1.7.3 * chore(deps): update module github.com/xanzy/go-gitlab to v0.107.0 * chore: Merge security fixes * docs: Adding snapcraft info * chore: Downcase 'personal access token' (CLI) * chore: catch up security fork * chore: merge security branch * test(duo ask): integration test for duo ask - Update to version 1.45.0: * Go mod tidy * fix: validate state parameter passed in OAuth2 login * Address linter findings for stack save * Add current timestamp to hashed data in stack save * Rework stack save to make hashes without exec * Fix command injection stack save, remove newline from hash gen - Update to version 1.44.1 (1.44.0 was not released): * chore: CI/CD changes to fix release bug * chore(deps): update module github.com/mattn/go-runewidth to v0.0.16 * fix(ci view): pipeline creator is shown incorrectly * chore(deps): update module k8s.io/client-go to v0.30.3 * chore(deps): update module k8s.io/apimachinery to v0.30.3 * fix(config): negate `HasSecurePerms` and fix workaround on windows * chore(deps): update golang to v1.22.5 * chore: use latest-available Markdown linting Docker image * chore: manually update Vale and markdownlint rules from GitLab project * chore: Second (final) pass through docs / UI strings * fix(view/list release): use url returned from API as link * chore(deps): update module golang.org/x/crypto to v0.25.0 * fix(snippet create): use filename when path missing * feat(snippets): allow creation of personal snippets * chore: Updating goreleaser config to v2 * fix(issuable note): respect editor from config * chore: finish the UI string pass * chore: String fixes for project-related strings * chore: fix strings related to merge requests * fix: allow listening hostname to be provided * feat: remove experimental wording for duo * chore: Yet more string cleanup * fix(config): ignore windows config file permission checks * chore: ensure user's settings don't impact tests * chore: Fix capitalization and punctuation in commands * chore: Fix punctuation and phrasing in messages * chore(deps): update dependency danger-review to v1.4.1 * chore: add goleak testing for goroutine leaks * fix: always stop spinner to avoid to mess up the terminal * chore(deps): update module github.com/zalando/go-keyring to v0.2.5 - Update to version 1.43.0: * chore: Merge security fork * chore(deps): update dependency danger-review to v1.4.0 * docs: add details to stack command * chore: remove alias for `ask` and `git` as part of `duo` * chore: switch to heredoc v2 * perf: always skip check-update after completion command * fix: Require CLI configuration file to have 0600 permissions * fix(auth status): move warning to end of auth status * chore(deps): update module github.com/spf13/cobra to v1.8.1 - Update to version 1.42.0: * feat(stacked-diffs): add stacked diffs feature * Revert "Merge branch..." * ci: use the danger-review component * fix: require user configuration files to only have 600 permissions * chore(deps): update module github.com/briandowns/spinner to v1.23.1 * feat(mr create): Add --signoff option * feat(user): Add json format option to events * chore(deps): update module k8s.io/client-go to v0.30.2 * chore(deps): update golang to v1.22.4 * fix: Mention all available token environment variables in warning * chore: remove multi-version Go testing from CI * chore(deps): update github.com/hashicorp/go-retryablehttp to v0.7.7 * chore(ci): fail on linting issues * chore(deps): update module github.com/gdamore/tcell/v2 to v2.7.4 * chore(deps): update module golang.org/x/text to v0.16.0 * chore(deps): update module github.com/otiai10/copy to v1.14.0 * chore(deps): update module github.com/charmbracelet/glamour to v0.7.0 * chore(deps): update module golang.org/x/term to v0.21.0 * chore(deps): update dependency golang to v1.22.3 * chore: update docs linting image and check Markdown links in pipelines * chore(deps): update module github.com/spf13/viper to v1.19.0 * fix(cluster agent): fix joining KAS proxy subpaths * chore: fix code_navigation job for latest GO_VERSION * docs: minor update to GitLab Duo title * chore(deps): update module github.com/makenowjust/heredoc to v2 * chore(deps): update module github.com/muesli/termenv to v0.15.2 * chore(deps): update module github.com/mattn/go-isatty to v0.0.20 - Update to version 1.41.0: * feat(issue): add epic and due-date to issue create * chore(deps): update dependency go to v1.22.3 * chore(deps): update module github.com/xanzy/go-gitlab to v0.105.0 * chore(deps): update module github.com/spf13/viper to v1.18.2 * fix(cluster-agent): construct kubeconfig authinfo name with agent id * feat: rename `ask git` to `duo ask` * chore(deps): update module github.com/hashicorp/go-version to v1.7.0 * docs: improve integration test docs * docs: clarify that fill option automatically pushes * chore(deps): update dependency axios to ^1.7.2 * chore(deps): update dependency @commitlint/format to ^19.3.0 * fix(auth status): better output for auth status * chore(deps): update module golang.org/x/term to v0.20.0 * chore(deps): update module github.com/mattn/go-runewidth to v0.0.15 * chore(deps): update module k8s.io/client-go to v0.30.1 * chore(deps): update module golang.org/x/text to v0.15.0 * docs: Fix broken or redirecting links * chore(deps): update module gopkg.in/yaml.v2 to v3 * chore(deps): update module github.com/spf13/cobra to v1.8.0 * chore: update code nagivation to use scip * chore(deps): update module github.com/spf13/cast to v1.6.0 * chore(deps): update module github.com/zalando/go-keyring to v0.2.4 * chore(deps): update module github.com/alecaivazis/survey/v2 to v2.3.7 * chore: upgrade to Go 1.22 * feat(cluster): Add check manifest usage command * build: Updating golanglint recommendation * fix(glab repo fork): clone if --clone flag set * test: fixing error running integration test locally * fix(project): don't request statistics * fix(auth status): exit with code 1 when auth fails * chore: fix typo in Dangerfile * refactor: Moving test helper functions to their own file for reuse * chore: Add a Maintainer Onboarding issue template * test: have git tests actually use git instead of stubs - Update to version 1.40.0: * feat: allow to provide custom client-id * chore(deps): Update retry-go dependency * feat(release): support `direct_asset_path` and alias `filepath` * chore(ci): remove deprecated Jobs/License-Scanning.latest.gitlab-ci.yml * fix(docs): w/o issue-no, the example will fail * chore(docs): update dependencies for commit-lint script * chore: run tests with Go 1.22 * feat: Create a job artifact command * test: fix issue with environment variables being set * chore(deps): update github.com/xanzy/go-gitlab to v0.103.0 * docs(config): update editor and browser config docs - Update to version 1.39.0: * feat: Add new command to run Pipeline Triggers * fix(deps): update github.com/xanzy/go-gitlab to v0.101.0 * fix(issue list): change output flag back to output-format * fix(test): update test data for updated github.com/xanzy/go-gitlab * fix: Getting the last pipeline is broken with merged results * fix: update "glab ci run-trig" to use new go-gitlab functions * refactor: Moving sanitize function to utilities - Update to version 1.38.0: * fix: updating golang version * feat(checkout): Fixing bug with private forks * refactor: Refactor code that returns buffer contents in tests * chore: fix typo in trigger command docs * chore: fix typo support -> supported glab-1.108.0-bp157.2.3.1.src.rpm glab-1.108.0-bp157.2.3.1.x86_64.rpm glab-bash-completion-1.108.0-bp157.2.3.1.noarch.rpm glab-doc-1.108.0-bp157.2.3.1.noarch.rpm glab-fish-completion-1.108.0-bp157.2.3.1.noarch.rpm glab-zsh-completion-1.108.0-bp157.2.3.1.noarch.rpm glab-1.108.0-bp157.2.3.1.i586.rpm glab-1.108.0-bp157.2.3.1.aarch64.rpm glab-1.108.0-bp157.2.3.1.ppc64le.rpm glab-1.108.0-bp157.2.3.1.s390x.rpm openSUSE-2026-255 Security update for libkrun important openSUSE Backports SLE-15-SP7 Update This update for libkrun fixes the following issues: Update vendored openssl crate to version 0.10.81 to deal with: CVE-2026-41676 (boo#1270198), CVE-2025-24898 (boo#1270429), CVE-2026-41677 (boo#1270582), CVE-2026-42327 (boo#1270470), CVE-2026-41678 (boo#1270683), CVE-2026-41898 (boo#1270831), CVE-2026-41681 (boo#1270721), CVE-2026-44662 (boo#1270877). libkrun-1.4.10-bp157.2.3.1.src.rpm libkrun-devel-1.4.10-bp157.2.3.1.x86_64.rpm libkrun-sev-devel-1.4.10-bp157.2.3.1.x86_64.rpm libkrun-sev1-1.4.10-bp157.2.3.1.x86_64.rpm libkrun1-1.4.10-bp157.2.3.1.x86_64.rpm libkrun-devel-1.4.10-bp157.2.3.1.aarch64.rpm libkrun1-1.4.10-bp157.2.3.1.aarch64.rpm openSUSE-2026-257 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 150.0.7871.181 (boo#1272156): * CVE-2026-16420: Type Confusion in WebAudio * CVE-2026-16421: Inappropriate implementation in WebAudio * CVE-2026-16413: Out of bounds write in ANGLE * CVE-2026-16414: Insufficient validation of untrusted input in Chromecast * CVE-2026-16415: Insufficient validation of untrusted input in Extensions * CVE-2026-16416: Integer overflow in Chromecast * CVE-2026-16417: Uninitialized Use in Skia * CVE-2026-16418: Stack buffer overflow in V8 * CVE-2026-16419: Out of bounds read and write in ANGLE * CVE-2026-16422: Insufficient validation of untrusted input in Certificate * CVE-2026-16423: Use after free in UI * CVE-2026-16424: Use after free in GPU chromedriver-150.0.7871.181-bp157.2.193.1.x86_64.rpm chromium-150.0.7871.181-bp157.2.193.1.nosrc.rpm chromium-150.0.7871.181-bp157.2.193.1.x86_64.rpm chromedriver-150.0.7871.181-bp157.2.193.1.aarch64.rpm chromium-150.0.7871.181-bp157.2.193.1.aarch64.rpm chromedriver-150.0.7871.181-bp157.2.193.1.ppc64le.rpm chromium-150.0.7871.181-bp157.2.193.1.ppc64le.rpm openSUSE-2026-256 Security update for rclone important openSUSE Backports SLE-15-SP7 Update This update for rclone fixes the following issues: - Update to version 1.74.4 (boo#1267192): * Version v1.74.4 * gui: update embedded release to 1.1.10 * local: stop --links symlinks escaping the destination directory CVE-2026-54572 * local: don't restore setuid/setgid/sticky bits from metadata by default GHSA-945v-v9p3-v5xw * s3: strip STS security token on same-host HTTPS->HTTP redirect GHSA-cf44-9pgv-m4xc * serve restic: fix --private-repos isolation bypass CVE-2026-59733 * archive extract: fix path traversal letting archives escape the destination CVE-2026-59732 * serve s3: fix path traversal letting clients see files in the root GHSA-8v25-v8p6-qf7v * build: fix multiple CVEs by upgrading to go1.26.5 * s3: fix mounting a prefix failing with 403 when HEAD is not permitted * drive, googlephotos: warn when using rclone's shared client_id #9580 * drive: fix stray %!(EXTRA) in unexportable google document log message * serve/http: fix --disable-zip so it works over rc * serve webdav: fix MOVE overwrite failing without Overwrite header * fs: fix negative offset when a suffix Range request exceeds object size * accounting: fix goroutine leak in NewStatsGroup for zero-transfer rc jobs * cmd/mount2: fix NFS directory listings by supporting non-zero Seekdir offsets * cmd/mount2: fix ESTALE over NFS by reporting stable inode numbers * cmd/mount2: fix NFS file creation by implementing Mknod * smb: fix for IBM iSeries and signature verification * mega: fix hard deleted files reappearing in listings - fixes #9554 * mega: wait for server events after upload, delete and move * vfs: fix hang reopening a file during the handle-caching grace period * s3: correct documented copy_cutoff minimum to 1 byte - Fixes #7391 * fs: fix command line flag being ignored when set to its default value * docs: fix copy to clipboard functionality for code blocks * fs/operations: correct DeleteFile --backup-dir documentation * build: update golang.org/x/image to v0.43.0 to fix image decoding vulnerabilities * docs: clarify copyto command description - Fixes #9527 * docs: fix typo in remote setup docs * serve s3: fix spurious 404 on HEAD/GET during VFS writeback - fixes #8188 * * s3: fix error mapping in GetObject to match HeadObject * filter: fix --files-from copy stopping at the first unreadable file * docs: Fix RELEASE.md * ncdu: fix duplicated keystrokes on Windows by pinning tcell to v2.9.0 * completion: fix powershell completion corrupting non-ASCII names - fixes #9412 * docs/crypt: fix encrypted size example - Fixes #9202 * docs: drive: note Google verification exemption for personal use apps * rc: document that rc API access is equivalent to shell access * docs: drive: update documentation about "Computers" folder * accounting: fix goroutine leak in ResetCounters * docs: fix --windows-event-log-level help * backend/filelu: fix recursive listing path handling and file filtering * docs: bisync - clarify flag interaction and minor changes * docs: Update RELEASE.md to use cherry-pick -x * webdav: fix mixed property statuses in multi-status responses * s3: remove session token on cross-host redirects * drive: warn when non-exportable Google documents are skipped - #9475 * Start v1.74.4-DEV development - update x/image to 0.43 (boo#1271056) rclone-1.74.4-bp157.2.12.1.src.rpm rclone-1.74.4-bp157.2.12.1.x86_64.rpm rclone-bash-completion-1.74.4-bp157.2.12.1.noarch.rpm rclone-zsh-completion-1.74.4-bp157.2.12.1.noarch.rpm rclone-1.74.4-bp157.2.12.1.i586.rpm rclone-1.74.4-bp157.2.12.1.aarch64.rpm rclone-1.74.4-bp157.2.12.1.ppc64le.rpm rclone-1.74.4-bp157.2.12.1.s390x.rpm openSUSE-2026-259 Security update for gh important openSUSE Backports SLE-15-SP7 Update This update for gh fixes the following issues: - CVE-2026-39821: reject all-ASCII xn-- Punycode labels in the vendored golang.org/x/net/idna package regardless of Go's unicode.Version (boo#1266618). gh-2.96.0-bp157.2.24.1.src.rpm gh-2.96.0-bp157.2.24.1.x86_64.rpm gh-bash-completion-2.96.0-bp157.2.24.1.noarch.rpm gh-fish-completion-2.96.0-bp157.2.24.1.noarch.rpm gh-zsh-completion-2.96.0-bp157.2.24.1.noarch.rpm gh-2.96.0-bp157.2.24.1.i586.rpm gh-2.96.0-bp157.2.24.1.aarch64.rpm gh-2.96.0-bp157.2.24.1.ppc64le.rpm gh-2.96.0-bp157.2.24.1.s390x.rpm openSUSE-2026-262 Recommended update for distribution-gpg-keys important openSUSE Backports SLE-15-SP7 Update This update for distribution-gpg-keys fixes the following issues: - Update to version 1.120: * Update RPM-GPG-KEY-openSUSE-2022 boo#1272293 * add Teams for Linux repository key * add Oracle Linux 10 key * Add NetBSD security officer key * update copr keys * Add EndeavourOS, Tuxedo OS, and Linux Mint keys - Update to version 1.119: * update copr keys * add: ultramarine repository keys * add: terra repository keys * update Google key block - Update to version 1.118: * update copr keys * Add symlinks to rpmfusion 44, 45 and 46 * Add Fedora 46 key * Add Remi's key for 2026 (Fedora 44 and 45) * Add CentOS PQC signing keys * Add RHEL PQC signing keys * suse: Update RPM-GPG-KEY-SuSE-SLE-12 * Refresh CentOS SIG Extras key * Update CentOS SIG keys downlod script * Add missing CentOS SIG keys * Add new Slack key used by versions 4.47 and above * Add openSUSE Leap SLE imports * Add Slack key - Update to version 1.115: * Update for openSUSE 16 keys * Microsoft: add 2025 & open tech keys * alpine-linux: Add loongarch64 key * fedora: Update rawhide symlink - update to 1.114: + Add Fedora 45 key - update to 1.113: + Add Rocky Linux 10 keys + Add FreeBSD keys + Fix AlmaLinux name and alphabetical ordering of distros + Add AlmaLinux EPEL AltArch Key - update to 1.111 + add link for remi/EL-10 key + update copr keys + Update Mageia gpg key + Add Fedora 44 key + add Remi 2025 key + alma: Add AlmaLinux 10 key + Update keys for Azure Linux and Kylin + fedora: Update rawhide symlink + Navy Linux GPG key Update + Add symlinks to rpmfusion 42 and 43 + Add keys for el-10 rpmfusion-free and nonfree + Add RHEL 10 keys + Add OpenWrt keys - Update to 1.105 + Add fedora 43 keys and change rawhide symlink + Refresh GPG keys for Dell + Add RPM-GPG-KEY-CentOS-Official-SHA256 + Add FFmpeg, LibreWolf, Monero, VideoLAN, and yt-dlp keys + Add CentOS 10 and EPEL 10 GPG keys + add Alpine Linux and postmarketOS keys - update to 1.102: * update copr keys * Create cathugger.asc * Create zzz.key.asc * Create idk.key.asc * Create hulahoop.asc * Create adrelanos.asc * Create makemkv_pub.txt * add F42 key and move rawhide link * update copr keys * update postgresql keys * Add Qubes OS 4.2 release key * Split AlmaLinux OS 8 GPG public keys to fix microdnf * Update AlmaLinux OS 8 public key * Add openSUSE Backports 2023 key * Update Amazon Linux 2023 public key * add script to check all keys * remove expired jenkins key * update expired intel security key * update expired navy linux key * update expired bluejeans key * add script to check expiration * Add the key for pkgs.k8s.io (Kubernetes) * Restructure openSUSE GPG keys * Add SUSE ALP signing keys * Add SLE 2023 signing keys * add symlinkg to rpmfusion 40 and 41 * update copr keys * add remi fedora 39 link to 2023 key * update Google key * add Fedora 41 key * Add source URL for AL2023 * update copr keys * Update expired RPM-GPG-KEY-Mageia key * Add keys for Azure Linux distribution-gpg-keys-1.120-bp157.2.3.1.noarch.rpm distribution-gpg-keys-1.120-bp157.2.3.1.src.rpm openSUSE-2026-263 Security update for trivy important openSUSE Backports SLE-15-SP7 Update This update for trivy fixes the following issues: - Update embedded dependencies: * update x/net to 0.57.0 (boo#1266495, CVE-2026-39821) * update x/text to 0.40.0 (boo#1271670, CVE-2026-56852) * update oras-go to 2.6.1 (boo#1271658, CVE-2026-50151) - Update trivy to version 0.72.0: * release: v0.72.0 [main] (#10782) * test: close plugin manager in tests cleanup (#10904) * Merge commit from fork * feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893) * fix(misconf): support github_repository_vulnerability_alerts resource (#10680) * feat(java): detect JAR licenses from packaged LICENSE files (#10856) * fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#10861) * fix(server): propagate package repository class in client/server mode (#10874) * chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#10888) * fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795) * feat(java): detect JAR licenses from the embedded pom.xml (#10851) * chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863) * ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2 (#10873) * chore(deps): bump alpine to 3.24.1 (#10868) * docs: fix article typo in plugin developer guide (#10860) * feat(misconf): Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848) * docs: fix typos (#10857) * fix(terraform): avoid data race on global getter.Getters in remote module resolver (#10843) * feat(secret): support new stateless format for GitHub App installation tokens (#10826) * fix: correct format verbs in diagnostic messages (#10805) * ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1 (#10845) * refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist (#10830) * docs: fix repository scan heading typo (#10828) * Merge commit from fork * fix: forward ospkg detector options through ospkg.NewScanner (#10811) * chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801) * fix(vex): load VEX documents from within the repository directory (#10820) * ci!: migrate docker config to dockers_v2 (#10783) * feat(dotnet): detect bundled runtime in self-contained deployments (#10786) * feat(secret): add OpenAI secret detection rules (#10798) * ci: expect GitHub App bot as backport PR author (#10813) * fix: surface the original analysis error instead of context cancellation (#10793) * chore(deps): bump the github-actions group across 1 directory with 11 updates (#10803) * chore(deps): bump the common group with 4 updates (#10797) * chore(deps): bump the aws group with 4 updates (#10796) * fix: use random suffix for process temp directory instead of PID (#10431) * docs: update signature verification for deb and rpm packages (#10784) * fix(image): lookup origin layer for custom resources in merged layers (#10788) * test: fix flaky containerd integration test (#10760) * ci: bump GoReleaser to v2.16.0 (#10774) * docs: fix broken nixpkgs reference link in installation guide (#10776) * test(java): force offline-scan for client/server integration tests (#10721) * fix(image): deterministic OS package deduplication for images with embedded SBOMs (#10777) * fix(spdx): guard against nil root component in SPDX marshaler (#10771) * ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0 (#10768) trivy-0.72.0-bp157.2.15.1.src.rpm trivy-0.72.0-bp157.2.15.1.x86_64.rpm trivy-0.72.0-bp157.2.15.1.i586.rpm trivy-0.72.0-bp157.2.15.1.aarch64.rpm trivy-0.72.0-bp157.2.15.1.ppc64le.rpm trivy-0.72.0-bp157.2.15.1.s390x.rpm openSUSE-2026-264 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 150.0.7871.186 (boo#1272460): * CVE-2026-16807: Out of bounds write in Codecs * CVE-2026-16806: Use after free in WebMCP * CVE-2026-16805: Use after free in Blink * CVE-2026-16804: Use after free in Input chromedriver-150.0.7871.186-bp157.2.196.1.x86_64.rpm chromium-150.0.7871.186-bp157.2.196.1.nosrc.rpm chromium-150.0.7871.186-bp157.2.196.1.x86_64.rpm chromedriver-150.0.7871.186-bp157.2.196.1.aarch64.rpm chromium-150.0.7871.186-bp157.2.196.1.aarch64.rpm chromedriver-150.0.7871.186-bp157.2.196.1.ppc64le.rpm chromium-150.0.7871.186-bp157.2.196.1.ppc64le.rpm openSUSE-2026-266 Recommended update for openQA, os-autoinst moderate openSUSE Backports SLE-15-SP7 Update This update for openQA, os-autoinst fixes the following issues: Changes in openQA: - Update to version 5.1784641659.4dee7d1f: * fix: Escape `@` sign in strings and regexes * chore(deps): Dependency cron 2026-07-21 * chore(deps-dev): bump brace-expansion from 5.0.5 to 5.0.7 (#7647) * feat(admin): show exact timestamp on hover in product log * feat(admin): query parameter search in product log * feat(admin): search in settings in product log * chore(deps): bump actions/setup-node in the all-actions group (#7645) * fix: filter out md files when collecting python files * feat(BCI): dedicated report template for BCI * chore(deps): Dependency cron 2026-07-19 * docs: remove blank lines from variable precedence list * feat: support global instance-wide test settings - Update to version 5.1784324412.123ebeb6: * fix: avoid foreign key error in screenshot_links * fix(test): Drop test for token equality * fix: Call open_sqlite_database with correct arguments * chore(deps): Dependency cron 2026-07-17 * feat: Improve scalability of dependency tree computation Changes in os-autoinst: - Update to version 5.1784715353.1b58686: * test(t/34-git): prevent parallel fetch failures by disabling git auto-gc * ci: Add tool to check line coverage * git subrepo pull (merge) external/os-autoinst-common * style(testapi): apply Modules::ProhibitAutomaticExportation on testapi * style(testapi.pm): apply Subroutines::RequireArgUnpacking on testapi.pm * style(perlcritic): RegularExpressions::ProhibitSingleCharAlternation * fix(backend): bring back support for legacy BIOS openQA-5.1784641659.4dee7d1f-bp157.2.21.1.src.rpm openQA-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-auto-update-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-bootstrap-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-client-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-client-bash-completion-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-client-zsh-completion-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-common-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-continuous-update-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-doc-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-llm-server-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-local-db-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-mcp-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-munin-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-python-scripts-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-single-instance-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-single-instance-nginx-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-worker-5.1784641659.4dee7d1f-bp157.2.21.1.x86_64.rpm openQA-client-test-5.1784641659.4dee7d1f-bp157.2.21.1.src.rpm openQA-test-5.1784641659.4dee7d1f-bp157.2.21.1.src.rpm openQA-worker-test-5.1784641659.4dee7d1f-bp157.2.21.2.src.rpm os-autoinst-5.1784715353.1b58686-bp157.2.15.1.src.rpm os-autoinst-5.1784715353.1b58686-bp157.2.15.1.x86_64.rpm os-autoinst-debuginfo-5.1784715353.1b58686-bp157.2.15.1.x86_64.rpm os-autoinst-debugsource-5.1784715353.1b58686-bp157.2.15.1.x86_64.rpm os-autoinst-openvswitch-5.1784715353.1b58686-bp157.2.15.1.x86_64.rpm os-autoinst-qemu-kvm-5.1784715353.1b58686-bp157.2.15.1.x86_64.rpm os-autoinst-qemu-x86-5.1784715353.1b58686-bp157.2.15.1.x86_64.rpm os-autoinst-swtpm-5.1784715353.1b58686-bp157.2.15.1.x86_64.rpm os-autoinst-openvswitch-test-5.1784715353.1b58686-bp157.2.15.1.src.rpm os-autoinst-test-5.1784715353.1b58686-bp157.2.15.1.src.rpm openQA-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-auto-update-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-bootstrap-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-client-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-client-bash-completion-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-client-zsh-completion-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-common-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-continuous-update-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-doc-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-llm-server-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-local-db-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-mcp-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-munin-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-python-scripts-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-single-instance-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-single-instance-nginx-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm openQA-worker-5.1784641659.4dee7d1f-bp157.2.21.1.aarch64.rpm os-autoinst-5.1784715353.1b58686-bp157.2.15.1.aarch64.rpm os-autoinst-debuginfo-5.1784715353.1b58686-bp157.2.15.1.aarch64.rpm os-autoinst-debugsource-5.1784715353.1b58686-bp157.2.15.1.aarch64.rpm os-autoinst-openvswitch-5.1784715353.1b58686-bp157.2.15.1.aarch64.rpm os-autoinst-swtpm-5.1784715353.1b58686-bp157.2.15.1.aarch64.rpm openQA-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-auto-update-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-bootstrap-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-client-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-client-bash-completion-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-client-zsh-completion-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-common-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-continuous-update-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-doc-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-llm-server-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-local-db-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-mcp-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-munin-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-python-scripts-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-single-instance-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-single-instance-nginx-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm openQA-worker-5.1784641659.4dee7d1f-bp157.2.21.1.ppc64le.rpm os-autoinst-5.1784715353.1b58686-bp157.2.15.1.ppc64le.rpm os-autoinst-debuginfo-5.1784715353.1b58686-bp157.2.15.1.ppc64le.rpm os-autoinst-debugsource-5.1784715353.1b58686-bp157.2.15.1.ppc64le.rpm os-autoinst-openvswitch-5.1784715353.1b58686-bp157.2.15.1.ppc64le.rpm os-autoinst-swtpm-5.1784715353.1b58686-bp157.2.15.1.ppc64le.rpm openQA-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-auto-update-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-bootstrap-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-client-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-client-bash-completion-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-client-zsh-completion-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-common-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-continuous-update-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-doc-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-llm-server-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-local-db-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-mcp-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-munin-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-python-scripts-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-single-instance-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-single-instance-nginx-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm openQA-worker-5.1784641659.4dee7d1f-bp157.2.21.1.s390x.rpm os-autoinst-5.1784715353.1b58686-bp157.2.15.1.s390x.rpm os-autoinst-debuginfo-5.1784715353.1b58686-bp157.2.15.1.s390x.rpm os-autoinst-debugsource-5.1784715353.1b58686-bp157.2.15.1.s390x.rpm os-autoinst-openvswitch-5.1784715353.1b58686-bp157.2.15.1.s390x.rpm os-autoinst-swtpm-5.1784715353.1b58686-bp157.2.15.1.s390x.rpm openSUSE-2026-267 Security update for nano moderate openSUSE Backports SLE-15-SP7 Update This update for nano fixes the following issues: - CVE-2026-6390: prevent interpretation of printf format specifiers in a filename when redisplaying a stored multibuffer startup error message, which could leak stack contents, crash, or allow arbitrary memory writes (boo#1272394) nano-7.2-bp157.3.3.1.src.rpm nano-7.2-bp157.3.3.1.x86_64.rpm nano-lang-7.2-bp157.3.3.1.noarch.rpm nano-7.2-bp157.3.3.1.i586.rpm nano-7.2-bp157.3.3.1.aarch64.rpm nano-7.2-bp157.3.3.1.ppc64le.rpm nano-7.2-bp157.3.3.1.s390x.rpm openSUSE-2026-268 Security update for kronosnet moderate openSUSE Backports SLE-15-SP7 Update This update for kronosnet fixes the following issues: - CVE-2026-15811: encryption key exposure in memory after cryptographic configuration changes (bsc#1271923) - CVE-2026-15812: access control list bypass via link ID spoofing on unencrypted dynamic links (bsc#1271924) - CVE-2026-15813: memory corruption and out-of-bounds access via malformed network packet defragmentation (bsc#1271925) - kronosnet-1.33 * Build fixes for gcc-15 (boo#1257258) * Build fixes for rust coreutils * Coverity tests cleanup * Release: ship all files for completeness - kronosnet-1.32 * IMPORTANT: sctp support is now officially deprecated. It is disabled by default and it will be removed in knet 2.x. * Fix potential thread race condition in libnozzle close. * Fix wrong pointer in libknet RX thread, only triggered by old gcc (< 11). * Libnozzle: different fixes for BSD to deal with new tap driver changes and don´t leak interfaces. * New API call in libknet to allow configuring a dscp value for KNET_LINK_FLAG_TRAFFICHIPRIO. * Bump soname to reflect new API call. * Improve OpenSSL error handling. * Add support for OpenIndiana. * Documentation updates. * Fix several tests to better deal with execution timing. * Handle some new coverity errors. * Create and refine STYLE_GUIDE.md for project contributions. - kronosnet-1.31 * Fixed incorrect lzo1x_decompress call to use the safe version * Udp: lower log levels for messages triggered by every single packets to trace level. - kronosnet-1.30 * Convert time_t to unsigned long long before formatting * Add warning when packets are being received from the wrong interface - kronosnet-1.29 * Fix FORTIFY source detection * libknet/tests: fix potential overflow with sprintf * [man] update to latest doxyxml from libqb kronosnet-1.33-bp157.2.3.1.src.rpm libknet-devel-1.33-bp157.2.3.1.x86_64.rpm libknet1-1.33-bp157.2.3.1.x86_64.rpm libknet1-compress-bzip2-plugin-1.33-bp157.2.3.1.x86_64.rpm libknet1-compress-lz4-plugin-1.33-bp157.2.3.1.x86_64.rpm libknet1-compress-lzma-plugin-1.33-bp157.2.3.1.x86_64.rpm libknet1-compress-lzo2-plugin-1.33-bp157.2.3.1.x86_64.rpm libknet1-compress-plugins-all-1.33-bp157.2.3.1.x86_64.rpm libknet1-compress-zlib-plugin-1.33-bp157.2.3.1.x86_64.rpm libknet1-compress-zstd-plugin-1.33-bp157.2.3.1.x86_64.rpm libknet1-crypto-nss-plugin-1.33-bp157.2.3.1.x86_64.rpm libknet1-crypto-openssl-plugin-1.33-bp157.2.3.1.x86_64.rpm libknet1-crypto-plugins-all-1.33-bp157.2.3.1.x86_64.rpm libknet1-plugins-all-1.33-bp157.2.3.1.x86_64.rpm libnozzle-devel-1.33-bp157.2.3.1.x86_64.rpm libnozzle1-1.33-bp157.2.3.1.x86_64.rpm libknet-devel-1.33-bp157.2.3.1.i586.rpm libknet1-1.33-bp157.2.3.1.i586.rpm libknet1-compress-bzip2-plugin-1.33-bp157.2.3.1.i586.rpm libknet1-compress-lz4-plugin-1.33-bp157.2.3.1.i586.rpm libknet1-compress-lzma-plugin-1.33-bp157.2.3.1.i586.rpm libknet1-compress-lzo2-plugin-1.33-bp157.2.3.1.i586.rpm libknet1-compress-plugins-all-1.33-bp157.2.3.1.i586.rpm libknet1-compress-zlib-plugin-1.33-bp157.2.3.1.i586.rpm libknet1-compress-zstd-plugin-1.33-bp157.2.3.1.i586.rpm libknet1-crypto-nss-plugin-1.33-bp157.2.3.1.i586.rpm libknet1-crypto-openssl-plugin-1.33-bp157.2.3.1.i586.rpm libknet1-crypto-plugins-all-1.33-bp157.2.3.1.i586.rpm libknet1-plugins-all-1.33-bp157.2.3.1.i586.rpm libnozzle-devel-1.33-bp157.2.3.1.i586.rpm libnozzle1-1.33-bp157.2.3.1.i586.rpm libknet-devel-1.33-bp157.2.3.1.aarch64.rpm libknet1-1.33-bp157.2.3.1.aarch64.rpm libknet1-compress-bzip2-plugin-1.33-bp157.2.3.1.aarch64.rpm libknet1-compress-lz4-plugin-1.33-bp157.2.3.1.aarch64.rpm libknet1-compress-lzma-plugin-1.33-bp157.2.3.1.aarch64.rpm libknet1-compress-lzo2-plugin-1.33-bp157.2.3.1.aarch64.rpm libknet1-compress-plugins-all-1.33-bp157.2.3.1.aarch64.rpm libknet1-compress-zlib-plugin-1.33-bp157.2.3.1.aarch64.rpm libknet1-compress-zstd-plugin-1.33-bp157.2.3.1.aarch64.rpm libknet1-crypto-nss-plugin-1.33-bp157.2.3.1.aarch64.rpm libknet1-crypto-openssl-plugin-1.33-bp157.2.3.1.aarch64.rpm libknet1-crypto-plugins-all-1.33-bp157.2.3.1.aarch64.rpm libknet1-plugins-all-1.33-bp157.2.3.1.aarch64.rpm libnozzle-devel-1.33-bp157.2.3.1.aarch64.rpm libnozzle1-1.33-bp157.2.3.1.aarch64.rpm libknet-devel-1.33-bp157.2.3.1.ppc64le.rpm libknet1-1.33-bp157.2.3.1.ppc64le.rpm libknet1-compress-bzip2-plugin-1.33-bp157.2.3.1.ppc64le.rpm libknet1-compress-lz4-plugin-1.33-bp157.2.3.1.ppc64le.rpm libknet1-compress-lzma-plugin-1.33-bp157.2.3.1.ppc64le.rpm libknet1-compress-lzo2-plugin-1.33-bp157.2.3.1.ppc64le.rpm libknet1-compress-plugins-all-1.33-bp157.2.3.1.ppc64le.rpm libknet1-compress-zlib-plugin-1.33-bp157.2.3.1.ppc64le.rpm libknet1-compress-zstd-plugin-1.33-bp157.2.3.1.ppc64le.rpm libknet1-crypto-nss-plugin-1.33-bp157.2.3.1.ppc64le.rpm libknet1-crypto-openssl-plugin-1.33-bp157.2.3.1.ppc64le.rpm libknet1-crypto-plugins-all-1.33-bp157.2.3.1.ppc64le.rpm libknet1-plugins-all-1.33-bp157.2.3.1.ppc64le.rpm libnozzle-devel-1.33-bp157.2.3.1.ppc64le.rpm libnozzle1-1.33-bp157.2.3.1.ppc64le.rpm libknet-devel-1.33-bp157.2.3.1.s390x.rpm libknet1-1.33-bp157.2.3.1.s390x.rpm libknet1-compress-bzip2-plugin-1.33-bp157.2.3.1.s390x.rpm libknet1-compress-lz4-plugin-1.33-bp157.2.3.1.s390x.rpm libknet1-compress-lzma-plugin-1.33-bp157.2.3.1.s390x.rpm libknet1-compress-lzo2-plugin-1.33-bp157.2.3.1.s390x.rpm libknet1-compress-plugins-all-1.33-bp157.2.3.1.s390x.rpm libknet1-compress-zlib-plugin-1.33-bp157.2.3.1.s390x.rpm libknet1-compress-zstd-plugin-1.33-bp157.2.3.1.s390x.rpm libknet1-crypto-nss-plugin-1.33-bp157.2.3.1.s390x.rpm libknet1-crypto-openssl-plugin-1.33-bp157.2.3.1.s390x.rpm libknet1-crypto-plugins-all-1.33-bp157.2.3.1.s390x.rpm libknet1-plugins-all-1.33-bp157.2.3.1.s390x.rpm libnozzle-devel-1.33-bp157.2.3.1.s390x.rpm libnozzle1-1.33-bp157.2.3.1.s390x.rpm openSUSE-2026-270 Security update for python-magic-wormhole low openSUSE Backports SLE-15-SP7 Update This update for python-magic-wormhole fixes the following issues: - CVE-2026-42448: wormhole receive, with --output pointing at an existing directory can be path-traversed (boo#1272449) python-magic-wormhole-0.10.5-bp157.2.3.1.src.rpm python3-magic-wormhole-0.10.5-bp157.2.3.1.noarch.rpm openSUSE-2026-265 Security update for nsd important openSUSE Backports SLE-15-SP7 Update This update for nsd fixes the following issues: - Update nsd.keyring - update to 4.14.3: https://github.com/NLnetLabs/nsd/blob/NSD_4_14_3_REL/doc/ChangeLog * CVE-2026-12490: Bypass of client certificate verification with transfer over TLS (boo#1269563) * CVE-2026-12246: Out of bounds stack write with crafted APL RR (boo#1269564) * CVE-2026-12245: Denial of DNS over TLS service by any DoT client (boo#1269565) * CVE-2026-12244: Heap overflow and crash with crafted SVCB RR (boo#1269566) - update to 4.14.2: https://github.com/NLnetLabs/nsd/blob/NSD_4_14_2_REL/doc/ChangeLog - update to 4.14.1: https://github.com/NLnetLabs/nsd/blob/NSD_4_14_1_REL/doc/ChangeLog - update to 4.14.0: https://github.com/NLnetLabs/nsd/blob/NSD_4_14_0_REL/doc/ChangeLog - update to 4.13.0: https://github.com/NLnetLabs/nsd/blob/NSD_4_13_0_REL/doc/ChangeLog https://github.com/NLnetLabs/nsd/blob/NSD_4_12_1_REL/doc/ChangeLog https://github.com/NLnetLabs/nsd/blob/NSD_4_12_0_REL/doc/ChangeLog https://github.com/NLnetLabs/nsd/blob/NSD_4_11_1_REL/doc/ChangeLog https://github.com/NLnetLabs/nsd/blob/NSD_4_11_0_REL/doc/ChangeLog https://github.com/NLnetLabs/nsd/blob/NSD_4_10_1_REL/doc/ChangeLog https://github.com/NLnetLabs/nsd/blob/NSD_4_10_0_REL/doc/ChangeLog https://github.com/NLnetLabs/nsd/blob/NSD_4_9_1_REL/doc/ChangeLog https://github.com/NLnetLabs/nsd/blob/NSD_4_9_0_REL/doc/ChangeLog - enable systemd notify support. - enable dnstap support. - enable tcp fast open support - enable support for >= 2038 - As far as it is known the kernel has a working recvmmsg pass --enable-recvmmsg to configure. - Don't --enable-mmap. Replacing malloc may sound attractive but all safety checks to prevent corruption included in libc are lost. - Provide user/group symbol for user created during pre. - update to 4.8.0: * Fix unit test kill_from_pidfile function for nonexistent files because the argument is evaluated before the test expression. * Fix rr-test to also convert the contents of the just written output file. * Fix test set to remove -f nsd.db and rm nsd.db commands. * Fix test set to remove difffile option. * Fix #14: Set timeout to 3s when servicing remaining TCP connections. * Fix: Always instate write handler after reading queries from TCP. * Answer first query on connections accepted just before reload. * Merge #305: faster stats. Statistics can be gathered while a reload is in progress. * Remove on-disk database. * Fix processing of consolidated IXFRs. * Fix for interprocess communication to set quit sync command from main process explicitly. * Merge #281: Proxy protocol. An implementation of PROXYv2 for NSD. * It can be configured with proxy-protocol-port: portnum with the port number of the interface on which proxy traffic is handled. * The interface can support proxy traffic for UDP, TCP and TLS. * Fix autoconf 2.69 warnings in configure. * Merge #287: Update nsd.conf.5.in. * Fix unused variable warning in unit test of udb. * Fix #284: dnstap_collector.c: SOCK_NONBLOCK is not available on Mac/Darwin. * Fix unused but set variable warning. bind8-stats and --without-ssl are specified. * Add missing items to doc/RELNOTES. nsd-4.14.3-bp157.2.3.1.src.rpm nsd-4.14.3-bp157.2.3.1.x86_64.rpm nsd-4.14.3-bp157.2.3.1.i586.rpm nsd-4.14.3-bp157.2.3.1.aarch64.rpm nsd-4.14.3-bp157.2.3.1.ppc64le.rpm nsd-4.14.3-bp157.2.3.1.s390x.rpm openSUSE-2026-272 Security update for keybase-client low openSUSE Backports SLE-15-SP7 Update This update for keybase-client fixes the following issues: - CVE-2026-39824: failure to reject ASCII-only Punycode-encoded labels kbfs-6.6.3-bp157.2.12.1.x86_64.rpm kbfs-git-6.6.3-bp157.2.12.1.x86_64.rpm kbfs-tool-6.6.3-bp157.2.12.1.x86_64.rpm keybase-client-6.6.3-bp157.2.12.1.src.rpm keybase-client-6.6.3-bp157.2.12.1.x86_64.rpm kbfs-6.6.3-bp157.2.12.1.i586.rpm kbfs-git-6.6.3-bp157.2.12.1.i586.rpm kbfs-tool-6.6.3-bp157.2.12.1.i586.rpm keybase-client-6.6.3-bp157.2.12.1.i586.rpm kbfs-6.6.3-bp157.2.12.1.aarch64.rpm kbfs-git-6.6.3-bp157.2.12.1.aarch64.rpm kbfs-tool-6.6.3-bp157.2.12.1.aarch64.rpm keybase-client-6.6.3-bp157.2.12.1.aarch64.rpm kbfs-6.6.3-bp157.2.12.1.ppc64le.rpm kbfs-git-6.6.3-bp157.2.12.1.ppc64le.rpm kbfs-tool-6.6.3-bp157.2.12.1.ppc64le.rpm keybase-client-6.6.3-bp157.2.12.1.ppc64le.rpm kbfs-6.6.3-bp157.2.12.1.s390x.rpm kbfs-git-6.6.3-bp157.2.12.1.s390x.rpm kbfs-tool-6.6.3-bp157.2.12.1.s390x.rpm keybase-client-6.6.3-bp157.2.12.1.s390x.rpm openSUSE-2026-269 Security update for python-nltk important openSUSE Backports SLE-15-SP7 Update This update for python-nltk fixes the following issues: - CVE-2025-71408: replace eval() with getattr() in collocations CLI (boo#1272667) python-nltk-3.7-bp157.3.15.1.src.rpm python3-nltk-3.7-bp157.3.15.1.noarch.rpm openSUSE-2026-271 Security update for chromium important openSUSE Backports SLE-15-SP7 Update This update for chromium fixes the following issues: - Chromium 151.0.7922.71 (boo#1272936): * CVE-2026-17650: Use after free in Compositing * CVE-2026-17651: Insufficient validation of untrusted input in Dawn * CVE-2026-17652: Use after free in Views * CVE-2026-17653: Use after free in Skia * CVE-2026-17654: Race in Updater * CVE-2026-17655: Insufficient validation of untrusted input in ANGLE * CVE-2026-17656: Use after free in Ozone * CVE-2026-17657: Use after free in Navigation * CVE-2026-17658: Use after free in V8 * CVE-2026-17659: Inappropriate implementation in SiteIsolation * CVE-2026-17660: Insufficient validation of untrusted input in Network * CVE-2026-17661: Use after free in Loader * CVE-2026-17662: Insufficient policy enforcement in Prefetch * CVE-2026-17663: Insufficient validation of untrusted input in GPU * CVE-2026-17664: Insufficient validation of untrusted input in Loader * CVE-2026-17665: Use after free in V8 * CVE-2026-17666: Cryptographic Flaw in Enterprise * CVE-2026-17667: Uninitialized Use in ANGLE * CVE-2026-17668: Uninitialized Use in ANGLE * CVE-2026-17669: Inappropriate implementation in Chrome for iOS * CVE-2026-17670: Use after free in Views * CVE-2026-17671: Insufficient validation of untrusted input in ANGLE * CVE-2026-17672: Insufficient validation of untrusted input in Chromecast * CVE-2026-17673: Integer overflow in QUIC * CVE-2026-17674: Inappropriate implementation in HTML * CVE-2026-17675: Out of bounds write in ANGLE * CVE-2026-17676: Inappropriate implementation in ANGLE * CVE-2026-17677: Inappropriate implementation in ANGLE * CVE-2026-17678: Out of bounds read in ANGLE * CVE-2026-17679: Insufficient validation of untrusted input in Print Preview * CVE-2026-17680: Heap buffer overflow in Color * CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication * CVE-2026-17682: Integer overflow in ANGLE * CVE-2026-17683: Inappropriate implementation in ANGLE * CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-17685: Use after free in Autofill * CVE-2026-17686: Insufficient validation of untrusted input in Passwords * CVE-2026-17687: Type Confusion in ANGLE * CVE-2026-17688: Use after free in Input * CVE-2026-17689: Uninitialized Use in ANGLE * CVE-2026-17690: Insufficient validation of untrusted input in PDF * CVE-2026-17691: Out of bounds write in ANGLE * CVE-2026-17692: Use after free in DataTransfer * CVE-2026-17693: Inappropriate implementation in FileSystem * CVE-2026-17694: Use after free in DOM * CVE-2026-17695: Inappropriate implementation in ANGLE * CVE-2026-17696: Side-channel information leakage in Media * CVE-2026-17697: Type Confusion in ANGLE * CVE-2026-17698: Insufficient validation of untrusted input in UI * CVE-2026-17699: Use after free in Views * CVE-2026-17700: Insufficient validation of untrusted input in Actor * CVE-2026-17701: Out of bounds read in ANGLE * CVE-2026-17702: Inappropriate implementation in Skia * CVE-2026-17703: Policy bypass in Chrome for iOS * CVE-2026-17704: Use after free in ANGLE * CVE-2026-17705: Integer overflow in libxml * CVE-2026-17706: Insufficient validation of untrusted input in Media * CVE-2026-17707: Uninitialized Use in Media * CVE-2026-17708: Use after free in Audio * CVE-2026-17709: Race in Downloads * CVE-2026-17710: Inappropriate implementation in MHTML * CVE-2026-17711: Race in Downloads * CVE-2026-17712: Race in Skia * CVE-2026-17713: Insufficient validation of untrusted input in Accessibility * CVE-2026-17714: Uninitialized Use in ANGLE * CVE-2026-17715: Inappropriate implementation in Passwords * CVE-2026-17716: Use after free in Updater * CVE-2026-17717: Integer overflow in ANGLE * CVE-2026-17718: Use after free in ANGLE * CVE-2026-17719: Use after free in Input * CVE-2026-17720: Insufficient policy enforcement in Passwords * CVE-2026-17721: Out of bounds write in ANGLE * CVE-2026-17722: Object lifecycle issue in WebView * CVE-2026-17723: Use after free in Media * CVE-2026-17724: Race in Chrome for iOS * CVE-2026-17725: Type Confusion in V8 * CVE-2026-17726: Integer overflow in WebGL * CVE-2026-17727: Out of bounds write in WebGL * CVE-2026-17728: Inappropriate implementation in Extensions * CVE-2026-17758: Heap buffer overflow in Dawn * CVE-2026-17732: Inappropriate implementation in SVG * CVE-2026-17729: Use after free in V8 * CVE-2026-17730: Side-channel information leakage in Autofill * CVE-2026-17731: Inappropriate implementation in Autofill * CVE-2026-17733: Inappropriate implementation in QUIC * CVE-2026-17734: Inappropriate implementation in Autofill * CVE-2026-17735: Insufficient validation of untrusted input in BFCache * CVE-2026-17736: Insufficient validation of untrusted input in WebView * CVE-2026-17737: Use after free in Bluetooth * CVE-2026-17738: Insufficient validation of untrusted input in Payments * CVE-2026-17739: Insufficient policy enforcement in Extensions * CVE-2026-17740: Uninitialized Use in ANGLE * CVE-2026-17741: Insufficient validation of untrusted input in WebView * CVE-2026-17742: Insufficient policy enforcement in Payments * CVE-2026-17743: Insufficient policy enforcement in ControlledFrame * CVE-2026-17744: Inappropriate implementation in File Input * CVE-2026-17745: Out of bounds read in Skia * CVE-2026-17746: Use after free in GPU * CVE-2026-17747: Insufficient validation of untrusted input in Payments * CVE-2026-17748: Inappropriate implementation in Extensions * CVE-2026-17749: Insufficient validation of untrusted input in Extensions * CVE-2026-17750: Use after free in ANGLE * CVE-2026-17751: Inappropriate implementation in AdFilter * CVE-2026-17752: Use after free in Views * CVE-2026-17753: Inappropriate implementation in Autofill * CVE-2026-17754: Inappropriate implementation in Blink * CVE-2026-17755: Incorrect security UI in Extensions * CVE-2026-17756: Insufficient policy enforcement in Presentation * CVE-2026-17757: Uninitialized Use in Skia * CVE-2026-17759: Uninitialized Use in Codecs * CVE-2026-17760: Side-channel information leakage in NoStatePrefetch * CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-17762: Inappropriate implementation in Chrome for iOS * CVE-2026-17763: Inappropriate implementation in GPU * CVE-2026-17764: Inappropriate implementation in FedCM * CVE-2026-17765: Inappropriate implementation in WebProtect * CVE-2026-17766: Insufficient validation of untrusted input in Clipboard * CVE-2026-17767: Insufficient validation of untrusted input in WebView * CVE-2026-17768: Insufficient validation of untrusted input in WebSockets * CVE-2026-17769: Insufficient validation of untrusted input in Cast * CVE-2026-17770: Out of bounds read in Media * CVE-2026-17771: Uninitialized Use in Skia * CVE-2026-17772: Out of bounds read in WebGL * CVE-2026-17773: Insufficient validation of untrusted input in Cast * CVE-2026-17774: Insufficient validation of untrusted input in Variations * CVE-2026-17775: Inappropriate implementation in PresentationAPI * CVE-2026-17776: Policy bypass in Receiver * CVE-2026-17777: Inappropriate implementation in Autofill * CVE-2026-17778: Use after free in Extensions * CVE-2026-17779: Inappropriate implementation in Site Isolation * CVE-2026-17780: Inappropriate implementation in Isolated Web Apps * CVE-2026-17781: Inappropriate implementation in Extensions * CVE-2026-17782: Incorrect security UI in Chrome for iOS * CVE-2026-17783: Inappropriate implementation in Loader * CVE-2026-17784: Use after free in Audio * CVE-2026-17785: Uninitialized Use in ANGLE * CVE-2026-17786: Insufficient validation of untrusted input in DevTools * CVE-2026-17787: Inappropriate implementation in DevTools * CVE-2026-17788: Inappropriate implementation in Blink * CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-17790: Uninitialized Use in ANGLE * CVE-2026-17791: Insufficient validation of untrusted input in Payments * CVE-2026-17792: Inappropriate implementation in Credential Management * CVE-2026-17793: Inappropriate implementation in Messages * CVE-2026-17794: Insufficient validation of untrusted input in Mobile * CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia * CVE-2026-17796: Side-channel information leakage in WebXR * CVE-2026-17797: Inappropriate implementation in CSS * CVE-2026-17798: Inappropriate implementation in Cast * CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing * CVE-2026-17800: Side-channel information leakage in MediaRecording * CVE-2026-17801: Out of bounds memory access in ANGLE * CVE-2026-17802: Side-channel information leakage in GPU * CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive * CVE-2026-17804: Use after free in Media * CVE-2026-17805: Insufficient policy enforcement in Glic * CVE-2026-17806: Insufficient validation of untrusted input in Extensions * CVE-2026-17807: Use after free in V8 * CVE-2026-17808: Uninitialized Use in WebGL * CVE-2026-17809: Insufficient validation of untrusted input in Extensions * CVE-2026-17810: Uninitialized Use in Dawn * CVE-2026-17811: Use after free in ANGLE * CVE-2026-17812: Inappropriate implementation in DigitalCredentials * CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS * CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-17815: Insufficient policy enforcement in GuestView * CVE-2026-17816: Inappropriate implementation in Speech * CVE-2026-17817: Inappropriate implementation in ReportingAndNEL * CVE-2026-17818: Inappropriate implementation in Network * CVE-2026-17819: Inappropriate implementation in WebAppInstalls * CVE-2026-17820: Insufficient policy enforcement in Autofill * CVE-2026-17821: Insufficient policy enforcement in Extensions * CVE-2026-17822: Inappropriate implementation in Chrome for iOS * CVE-2026-17823: Insufficient policy enforcement in WebXR * CVE-2026-17824: Insufficient policy enforcement in ServiceWorker * CVE-2026-17825: Insufficient policy enforcement in Passwords * CVE-2026-17826: Inappropriate implementation in Chrome for iOS * CVE-2026-17827: Inappropriate implementation in CSS * CVE-2026-17828: Inappropriate implementation in Chrome for iOS * CVE-2026-17829: Insufficient policy enforcement in Passwords * CVE-2026-17830: Inappropriate implementation in Chrome for iOS * CVE-2026-17831: Insufficient validation of untrusted input in Passwords * CVE-2026-17832: Use after free in ANGLE * CVE-2026-17833: Inappropriate implementation in Passwords * CVE-2026-17834: Inappropriate implementation in Passwords * CVE-2026-17835: Inappropriate implementation in Chrome for iOS * CVE-2026-17836: Use after free in V8 * CVE-2026-17837: Insufficient validation of untrusted input in DevTools * CVE-2026-17838: Incorrect security UI in Chrome for iOS * CVE-2026-17839: Inappropriate implementation in Chrome for iOS * CVE-2026-17840: Incorrect security UI in Passwords * CVE-2026-17841: Race in Chrome for iOS * CVE-2026-17842: Inappropriate implementation in Chrome for iOS * CVE-2026-17843: Inappropriate implementation in CSS * CVE-2026-17844: Insufficient validation of untrusted input in Cast * CVE-2026-17845: Inappropriate implementation in CSS * CVE-2026-17846: Inappropriate implementation in Media * CVE-2026-17847: Insufficient validation of untrusted input in ANGLE * CVE-2026-17848: Insufficient validation of untrusted input in Codecs * CVE-2026-17849: Inappropriate implementation in Chrome for iOS * CVE-2026-17850: Inappropriate implementation in Permissions * CVE-2026-17851: Side-channel information leakage in Autofill * CVE-2026-17852: Inappropriate implementation in Media Router * CVE-2026-17853: Inappropriate implementation in DevTools * CVE-2026-17854: Insufficient policy enforcement in WebMCP * CVE-2026-17855: Race in DevTools * CVE-2026-17856: Inappropriate implementation in Network * CVE-2026-17857: Inappropriate implementation in Network * CVE-2026-17858: Uninitialized Use in WebNN * CVE-2026-17859: Side-channel information leakage in Favicons * CVE-2026-17860: Insufficient validation of untrusted input in Mobile * CVE-2026-17861: Insufficient validation of untrusted input in Updater * CVE-2026-17862: Use after free in Tracing * CVE-2026-17863: Inappropriate implementation in Browser * CVE-2026-17864: Inappropriate implementation in Updater * CVE-2026-17865: Inappropriate implementation in Crypto * CVE-2026-17866: Type Confusion in Tab * CVE-2026-17867: Insufficient validation of untrusted input in Dawn * CVE-2026-17868: Insufficient policy enforcement in USB * CVE-2026-17869: Out of bounds read in WebXR * CVE-2026-17870: Insufficient validation of untrusted input in Cast * CVE-2026-17871: Inappropriate implementation in Passwords * CVE-2026-17872: Cryptographic Flaw in WebAppInstalls * CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS * CVE-2026-17874: Inappropriate implementation in Chrome for iOS * CVE-2026-17875: Use after free in PDFium * CVE-2026-17876: Inappropriate implementation in Payments * CVE-2026-17877: Inappropriate implementation in Chromoting * CVE-2026-17878: Inappropriate implementation in CSS * CVE-2026-17879: Inappropriate implementation in Autofill * CVE-2026-17880: Inappropriate implementation in Autofill * CVE-2026-17881: Use after free in WebXR * CVE-2026-17882: Policy bypass in Extensions * CVE-2026-17883: Inappropriate implementation in Headless * CVE-2026-17884: Object lifecycle issue in WebRTC * CVE-2026-17885: Inappropriate implementation in Paint * CVE-2026-17886: Use after free in Enterprise * CVE-2026-17887: Use after free in TabStrip * CVE-2026-17888: Insufficient validation of untrusted input in WebUI * CVE-2026-17889: Uninitialized Use in WebXR * CVE-2026-17890: Insufficient validation of untrusted input in DevTools * CVE-2026-17891: Use after free in ANGLE * CVE-2026-17892: Inappropriate implementation in WebXR * CVE-2026-17893: Insufficient validation of untrusted input in Updater * CVE-2026-17894: Use after free in Views * CVE-2026-17895: Inappropriate implementation in DataTransfer * CVE-2026-17896: Use after free in DevTools * CVE-2026-17897: Inappropriate implementation in ORB * CVE-2026-17898: Use after free in DevTools * CVE-2026-17899: Insufficient policy enforcement in DevTools * CVE-2026-17900: Inappropriate implementation in Enterprise * CVE-2026-17901: Inappropriate implementation in Sharing * CVE-2026-17902: Inappropriate implementation in Editing * CVE-2026-17903: Insufficient policy enforcement in Chromecast * CVE-2026-17904: Insufficient policy enforcement in NFC * CVE-2026-17905: Inappropriate implementation in SurfaceCapture * CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth * CVE-2026-17907: Side-channel information leakage in Network * CVE-2026-17908: Insufficient validation of untrusted input in Printing * CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps * CVE-2026-17910: Insufficient policy enforcement in NFC * CVE-2026-17911: Insufficient policy enforcement in SVG * CVE-2026-17912: Inappropriate implementation in Chrome for iOS * CVE-2026-17913: Inappropriate implementation in Chrome for iOS * CVE-2026-17914: Side-channel information leakage in Skia * CVE-2026-17915: Inappropriate implementation in WebView * CVE-2026-17916: Insufficient policy enforcement in Settings * CVE-2026-17917: Policy bypass in Chrome for iOS * CVE-2026-17918: Use after free in Sync * CVE-2026-17919: Insufficient policy enforcement in Enterprise * CVE-2026-17920: Use after free in V8 * CVE-2026-17921: Insufficient validation of untrusted input in Navigation * CVE-2026-17922: Inappropriate implementation in Enterprise * CVE-2026-17923: Policy bypass in Enterprise * CVE-2026-17924: Use after free in DNS * CVE-2026-17925: Inappropriate implementation in Cast * CVE-2026-17926: Insufficient validation of untrusted input in DevTools * CVE-2026-17927: Insufficient policy enforcement in DevTools * CVE-2026-17928: Inappropriate implementation in DataTransfer * CVE-2026-17929: Insufficient validation of untrusted input in DevTools * CVE-2026-17930: Insufficient validation of untrusted input in Extensions * CVE-2026-17931: Inappropriate implementation in DevTools * CVE-2026-17932: Use after free in DataTransfer * CVE-2026-17933: Inappropriate implementation in DOMStorage * CVE-2026-17934: Insufficient validation of untrusted input in DevTools * CVE-2026-17935: Heap buffer overflow in Codecs * CVE-2026-17936: Inappropriate implementation in DevTools * CVE-2026-17937: Inappropriate implementation in DevTools * CVE-2026-17938: Inappropriate implementation in FullScreen * CVE-2026-17939: Inappropriate implementation in Passwords * CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture * CVE-2026-17941: Inappropriate implementation in Chrome for iOS * CVE-2026-17942: Side-channel information leakage in SVG * CVE-2026-17943: Inappropriate implementation in Parser * CVE-2026-17944: Inappropriate implementation in Chrome for iOS * CVE-2026-17945: Inappropriate implementation in Navigation * CVE-2026-17946: Uninitialized Use in Dawn * CVE-2026-17947: Use after free in WebSockets * CVE-2026-17948: Type Confusion in V8 * CVE-2026-17949: Uninitialized Use in GPU * CVE-2026-17950: Policy bypass in Safebrowsing * CVE-2026-17951: Heap buffer overflow in WebRTC * CVE-2026-17952: Inappropriate implementation in V8 * CVE-2026-17953: Insufficient policy enforcement in WebView * CVE-2026-17954: Policy bypass in MHTML * CVE-2026-17955: Insufficient validation of untrusted input in Payments * CVE-2026-17956: Inappropriate implementation in Scheduling * CVE-2026-17957: Inappropriate implementation in CORS * CVE-2026-17958: Inappropriate implementation in Views * CVE-2026-17959: Inappropriate implementation in Network * CVE-2026-17960: Inappropriate implementation in Chrome for iOS * CVE-2026-17961: Inappropriate implementation in Session * CVE-2026-17962: Inappropriate implementation in Blink * CVE-2026-17963: Inappropriate implementation in SVG * CVE-2026-17964: Incorrect security UI in UI * CVE-2026-17965: Incorrect security UI in Chrome for iOS * CVE-2026-17966: Inappropriate implementation in Views * CVE-2026-17967: Use after free in Chrome for iOS * CVE-2026-17968: Uninitialized Use in WebXR * CVE-2026-17969: Inappropriate implementation in Passwords * CVE-2026-17970: Insufficient validation of untrusted input in Passwords * CVE-2026-17971: Inappropriate implementation in Frame * CVE-2026-17972: Inappropriate implementation in Chrome for iOS * CVE-2026-17973: Inappropriate implementation in Views * CVE-2026-17974: Insufficient policy enforcement in DevTools * CVE-2026-17975: Inappropriate implementation in IME * CVE-2026-17976: Policy bypass in Extensions * CVE-2026-17977: Policy bypass in CSS * CVE-2026-17978: Side-channel information leakage in WebCodecs * CVE-2026-17979: Race in V8 * CVE-2026-17980: Inappropriate implementation in UI * CVE-2026-17981: Inappropriate implementation in Blink * CVE-2026-17982: Insufficient validation of untrusted input in Cast * CVE-2026-17983: Incorrect security UI in Global Media Controls * CVE-2026-17984: Inappropriate implementation in Browser * CVE-2026-17985: Insufficient policy enforcement in Speech * CVE-2026-17986: Insufficient policy enforcement in Bluetooth * CVE-2026-17987: Insufficient validation of untrusted input in Notifications * CVE-2026-17988: Insufficient validation of untrusted input in Navigation * CVE-2026-17989: Type Confusion in V8 * CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn * CVE-2026-17991: Insufficient validation of untrusted input in AI * CVE-2026-17992: Uninitialized Use in Skia * CVE-2026-17993: Race in Updater * CVE-2026-17994: Inappropriate implementation in Media * CVE-2026-17995: Out of bounds read in Dawn * CVE-2026-17996: Inappropriate implementation in Browser * CVE-2026-17997: Inappropriate implementation in Passwords * CVE-2026-17998: Incorrect security UI in Extensions * CVE-2026-17999: Incorrect security UI in PictureInPicture * CVE-2026-18000: Insufficient policy enforcement in USB * CVE-2026-18001: Inappropriate implementation in WebGL * CVE-2026-18002: Insufficient validation of untrusted input in Google Lens * CVE-2026-18003: Inappropriate implementation in Chrome for iOS * CVE-2026-18004: Insufficient policy enforcement in Speech * CVE-2026-18005: Inappropriate implementation in WebXR * CVE-2026-18006: Inappropriate implementation in Google Lens * CVE-2026-18007: Inappropriate implementation in Input * CVE-2026-18008: Inappropriate implementation in Settings * CVE-2026-18009: Insufficient validation of untrusted input in Passwords * CVE-2026-18010: Inappropriate implementation in Passwords * CVE-2026-18011: Inappropriate implementation in Chrome for iOS * CVE-2026-18012: Use after free in PDFium * CVE-2026-18013: Inappropriate implementation in Chrome for iOS * CVE-2026-18014: Insufficient validation of untrusted input in DevTools * CVE-2026-18015: Inappropriate implementation in Tint * CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS * CVE-2026-18017: Use after free in Dawn * CVE-2026-18018: Inappropriate implementation in Updater * CVE-2026-18019: Side-channel information leakage in Media chromedriver-151.0.7922.71-bp157.2.199.1.x86_64.rpm chromium-151.0.7922.71-bp157.2.199.1.nosrc.rpm chromium-151.0.7922.71-bp157.2.199.1.x86_64.rpm chromedriver-151.0.7922.71-bp157.2.199.1.aarch64.rpm chromium-151.0.7922.71-bp157.2.199.1.aarch64.rpm chromedriver-151.0.7922.71-bp157.2.199.1.ppc64le.rpm chromium-151.0.7922.71-bp157.2.199.1.ppc64le.rpm openSUSE-2026-278 Security update for perl-Mojolicious moderate openSUSE Backports SLE-15-SP7 Update This update for perl-Mojolicious fixes the following issues: - updated to 9.480.0 (9.48) see /usr/share/doc/packages/perl-Mojolicious/Changes 9.48 2026-07-14 - Fixed a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session. CVE-2026-15747 boo#1271431 - updated to 9.470.0 (9.47) see /usr/share/doc/packages/perl-Mojolicious/Changes 9.47 2026-07-05 - Added support for the QUERY HTTP request method from RFC 10008. - Added query and query_p methods to Mojo::UserAgent. - Added query method to Mojolicious::Routes::Route. - Added query method to Mojolicious::Lite. - Added query_ok method to Test::Mojo. - Fixed a security issue where the pure-Perl implementation of Mojo::JSON could exhaust all available memory when decoding deeply nested data. Decoding is now limited to 512 levels of nesting, to match the default of Cpanel::JSON::XS. - Fixed a memory leak in Morbo. (heikojansen) - Fixed Mojo::File::list_tree to no longer follow symbolic links to directories. - updated to 9.460.0 (9.46) see /usr/share/doc/packages/perl-Mojolicious/Changes 9.46 2026-06-04 - Added random_bytes function to Mojo::Util. (leont) - Improved randomness for CSRF token generation. (leont) - Fixed tls_options handling in Mojo::IOLoop::TLS. (krauro) - Fixed spec compliance issue with attribute selectors in Mojo::DOM::CSS. perl-Mojolicious-9.480.0-bp157.5.1.noarch.rpm perl-Mojolicious-9.480.0-bp157.5.1.src.rpm openSUSE-2026-273 Security update for perl-YAML-Syck important openSUSE Backports SLE-15-SP7 Update This update for perl-YAML-Syck fixes the following issues: - updated to 1.470.0 (1.47) see /usr/share/doc/packages/perl-YAML-Syck/Changes 1.47 Jul 13 2026 [Security] - Fix four libsyck memory-safety CVEs reachable from the default YAML::Syck::Load() path on untrusted input with no special flags (reported by Paul Johnson via CPANSec, PR #213): - CVE-2026-57075 (CWE-125): out-of-bounds read in the base64 decoder caused by signed-char indexing of the decode table on !!binary input boo#1271632 - CVE-2026-57076 (CWE-416): use-after-free of an anchor key string shared between the node and the anchors table boo#1271633 - CVE-2026-57077 (CWE-125): one-byte out-of-bounds read in the lexer newline scan during block-scalar parsing (incomplete-fix follow-on to CVE-2025-11683) boo#1271634 - CVE-2026-13713 (CWE-416/CWE-415): use-after-free / double-free of an anchor node on anchor redefinition, a remote-crash DoS from a 7-byte input boo#1271631 - Harden syck_base64dec() to bounds-check each read so it cannot run past a non-NUL-terminated input buffer (defense-in-depth for callers passing raw buffers; PR #213) [Bug Fixes] - Fix: enforce $MaxDepth on Load to prevent C-stack exhaustion from deeply nested YAML/JSON input; YAML::Syck and JSON::Syck Load now default to 512, matching Dump (PR #204) - Fix: emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf values in Dump so they roundtrip with ImplicitTyping instead of reloading as plain strings (PR #201) [Maintenance] - CI: add an AddressSanitizer job that builds the XS with -fsanitize=address and runs the suite plus the CVE trigger inputs to catch libsyck memory-safety defects; de-pin the libasan version so it tracks the runner's GCC (PR #213) - updated to 1.460.0 (1.46) see /usr/share/doc/packages/perl-YAML-Syck/Changes 1.46 May 24 2026 [Bug Fixes] - Fix: preserve string nature of numeric-looking values in Dump; pure strings (POK only, no IOK/NOK) are now quoted to maintain roundtrip fidelity (GH #199, PR #200) - Fix: accept trailing commas in flow sequences and mappings ([a, b,] and {a: 1,}), valid per YAML 1.0/1.1/1.2 spec (GH #195, PR #196) [Maintenance] - CI: upgrade install-with-cpm to v2 for compatibility with Perl versions prior to 5.24 in perldocker containers (GH #197, PR #198) - Clean up MANIFEST.SKIP: add #!include_default, remove redundant entries, exclude .claude/ from distribution perl-YAML-Syck-1.470.0-bp157.2.6.1.src.rpm perl-YAML-Syck-1.470.0-bp157.2.6.1.x86_64.rpm perl-YAML-Syck-1.470.0-bp157.2.6.1.i586.rpm perl-YAML-Syck-1.470.0-bp157.2.6.1.aarch64.rpm perl-YAML-Syck-1.470.0-bp157.2.6.1.ppc64le.rpm perl-YAML-Syck-1.470.0-bp157.2.6.1.s390x.rpm openSUSE-2026-274 Security update for perl-HTTP-Tiny important openSUSE Backports SLE-15-SP7 Update This update for perl-HTTP-Tiny fixes the following issues: - updated to 0.096 see /usr/share/doc/packages/perl-HTTP-Tiny/Changes 0.096 2026-06-08 11:21:49+02:00 Europe/Brussels - No changes from 0.095-TRIAL 0.095 2026-06-03 13:10:05+02:00 Europe/Brussels (TRIAL RELEASE) [!!! SECURITY !!!] - CVE-2026-7017 boo#1271020 - Caller-supplied Authorization, Cookie, and Proxy-Authorization headers are now stripped on cross-origin redirects by default. Use allow_credentialed_redirects to opt out. - Redirects are no longer automatically followed when going from https to http. Use allow_downgrade to revert to the original behaviour. perl-HTTP-Tiny-0.096-bp157.2.6.1.noarch.rpm perl-HTTP-Tiny-0.096-bp157.2.6.1.src.rpm openSUSE-2026-279 Security update for perl-Mojo-JWT moderate openSUSE Backports SLE-15-SP7 Update This update for perl-Mojo-JWT fixes the following issues: - CVE-2026-9537: verification of HMAC signatures with a non-constant-time string comparison (boo#1271935) perl-Mojo-JWT-0.09-bp157.2.3.1.noarch.rpm perl-Mojo-JWT-0.09-bp157.2.3.1.src.rpm openSUSE-2026-275 Security update for thrift important openSUSE Backports SLE-15-SP7 Update This update for thrift fixes the following issues: - update to 0.24.0 ( boo#1272609, CVE-2026-41608, boo#1272654, CVE-2026-58023, boo#1272655, CVE-2026-55970, boo#1272656, CVE-2026-49158, boo#1272657, CVE-2026-48586, boo#1272658, CVE-2026-48145, boo#1272652, CVE-2026-58389, boo#1272653, CVE-2026-55971, boo#1272645, CVE-2026-48144, boo#1272647, CVE-2026-45112, boo#1272648, CVE-2026-43871, boo#1272649, CVE-2026-55969, boo#1272650, CVE-2026-55968, boo#1272651, CVE-2026-58662, boo#1272609, CVE-2026-41608): * THRIFT-5930 - thrift_server_socket() copies Unix socket paths into sockaddr_un.sun_path without bounds checking * #3585 - limit recursion depth in c_glib thrift_protocol_skip * #3507 - Add peer hostname validation to c_glib TLS client * #3393 - Fix parent class resolution in c_glib generated dispatch_call * THRIFT-3165 - Disable unsafe TLSv1.0 and TLSv1.1 by default * THRIFT-6021 - When C++ client with HTTP transport calls a oneway RPC method, it must not expect a response * THRIFT-6060 - C++ THttpClient does not reopen socket after server sends Connection: close * THRIFT-6073 - Allow injecting external SSL_CTX into C++ SSLContext * #3597 - link UnitTests against libthriftz to resolve THeaderTransport vtable * #3597 - fix off-by-ten header bounds check in readHeaderFormat * #3569 - Add the cpp.ref (&) annotation to the recursive exception in Recursive.thrift * #3519 - Preserve private_optional field order * #3498 - change sprintf to snprintf to eliminate security warnings on OSX * #3506 - Enforce RFC 6125 wildcard placement in TSSLSocket hostname matching * #3508 - Replace memory-safety asserts with unconditional throws in TBufferTransports * #3431 - Remove another boost header from the public API * #3529 - nodejs+compiler: Add opt-in BigInt support for int64 via js:bigint flag * #3461 - Migration *.sln to *.slnx (except c++ libs) * #2957 - Fix PHP cross-test server IPv4 binding * #3372 - Fix JavaScript exception construction implementation (ES6) * #3520 - added thrift-threat-model.md, SECURITY.md and security section to AGENTS.md * THRIFT-6030 - Harden Erlang protocol negative sizes * #3410 - Add byte-count limit to TCompactProtocol varint reader * THRIFT-5214 - go: Implement connection check in TSocket * THRIFT-5969 - Introduce gofmt for Go library * THRIFT-5996 - go: connection check should work for TLS sockets * THRIFT-6011 - Make compiled Go code formatting compatible with gofmt * THRIFT-6012 - Fix inverted regexp.MatchString arguments and precompile patterns in Go validator * THRIFT-6044 - Limit struct read/write recursion depth in Go library * THRIFT-6071 - Validate container size fits int32 range before narrowing conversion in TSimpleJSONProtocol * #3604 - Bound the container element count before the 64-bit size precheck in the Go JSON protocol * #3604 - widen container size precheck to 64-bit in go protocols * #3599 - check wire-supplied size in simple json ReadMapBegin * #3497 - Bump golang.org/x/sys to 0.0.0-20220412211240-33da011f77ad * #3458 - Prevent concurrent calls to socketConn.Close() in Go * #3428 - Fix range check on 32-bit architectures * #3379 - Replace addr with factory in TServerSocket * #3410 - Add byte-count limit to TCompactProtocol varint reader * #3381 - added int range checks * #3618 - Bump jvm from 2.3.21 to 2.4.0 in /lib/kotlin * #3619 - Bump com.diffplug.spotless from 8.5.1 to 8.7.0 in /lib/kotlin * #3605 - enforce stringLengthLimit in TCompactProtocol.readBinary * #3574 - Bump com.diffplug.spotless from 8.4.0 to 8.5.1 in /lib/kotlin * #3572 - Bump org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in /lib/kotlin * #3452 - Add message byte tracking to consumeBuffer() in Java transports * #3434 - Bump jvm from 2.3.20 to 2.3.21 in /lib/kotlin * #3420 - Fix Java Spotless formatting * #3415 - Connect skip() to TConfiguration recursion limit * #3412 - Use bounded default for maxSkipDepth in TProtocolUtil * #3410 - Add byte-count limit to TCompactProtocol varint reader * #3396 - Enable TLS hostname verification in TNonblockingSSLSocket * #3390 - Enable TLS hostname verification in TSSLTransportFactory * THRIFT-5915 - Python 3.12+ is not supported due to distutils * THRIFT-5923 - UUID support for Python * THRIFT-6024 - Python THeaderTransport and TZlibTransport default max frame/decompressed size should be DEFAULT_MAX_FRAME_SIZE (16384000), not HARD_MAX_FRAME_SIZE (0x3FFFFFFF) * THRIFT-6043 - Harden Python binary protocol negative sizes * THRIFT-6067 - Python: pip install fails on setuptools < 69 due to sys.exit() in setup.py (PEP 517 build backend) * THRIFT-6069 - suggestion for a few python perf improvements * THRIFT-6070 - Publish Python wheel distributions to PyPI * #3410 - Add byte-count limit to TCompactProtocol varint reader * #3413 - Use sslcompat hostname matcher in TSSLSocket * #3411 - Add default recursion depth limit to TProtocol.skip() * #3408 - Add decompressed payload size limit to Python THeaderTransport * #3377 - Optimize Python C extension readStruct for nested structs * #2957 - Fix PHP cross-test server IPv4 binding - update to 0.23.0 (boo#1263557, CVE-2026-41602, boo#1263492, CVE-2026-41604, boo#1263438, CVE-2026-41605, boo#1263365, CVE-2026-41606, boo#1263321, CVE-2026-41607, boo#1263322, CVE-2026-41636): * THRIFT-5877 - Add cpp cross tests * THRIFT-5866 - Dockerfile to support Ubuntu 24.04 LTS (Noble Numbat) * THRIFT-5909 - add Ruby in GitHub workflow * THRIFT-5649 - add go in GitHub workflow / action * THRIFT-5871 - Improve MAX_MESSAGE_SIZE check and friends * THRIFT-5911 - Inconsistent UUID compilation for aliased types * THRIFT-5912 - Assertion failed: `delta > 0`, file ThreadManagerTests.h, line 162 * THRIFT-5880 - C++ TSocket on an IPv6-only system fails if you use a hostname of 127.0.0.1 * THRIFT-3268 - warning: token pasting of ',' and `__VA_ARGS__` is a GNU extension * THRIFT-5887 - build/cmake/ should be prepended (not appended) to CMAKE_MODULE_PATH * THRIFT-5878 - Add UUID support for THeaderProtocol and TProtocolTap * THRIFT-5898 - Unable to build Thrift as a shared library on Windows * THRIFT-5939 - Replace GUID generation with stable UUID algorithm * THRIFT-5876 - Add Delphi WinHTTP client TLS1.3 support * THRIFT-5896 - Race condition in TServerSocket.Addr() method * THRIFT-5925 - UUID implementation in JAVA is not according to the Thrift Specification * THRIFT-5869 - Close the transport after TServerEventHandler deleteContext * THRIFT-5863 - Make TServerTransport able to customize the max message size * THRIFT-5774 - Add remote client's IP address to ServerContext in TServerEventHandler * THRIFT-4280 - Add async nonblocking ssl support in java client * THRIFT-5879 - java and kotlin cross tests fail in the GitHub action * THRIFT-5902 - Add net10 support * THRIFT-5874 - Introduce new type `MESSAGE_SIZE_LIMIT` in TTransportException * THRIFT-5937 - nodejs episodic generation does not handle extending services * THRIFT-5924 - UUID support for nodejs and nodets * THRIFT-4987 - TProtocolException: Bad version in readMessageBegin when using XHR client with C++ server * THRIFT-5924 - UUID support for nodejs and nodets * THRIFT-5935 - Fix deprecated non-canonical casts for PHP 8.5 compatibility * THRIFT-5921 - Ubuntu focal fail to run composer install * THRIFT-5929 - Fix build failure on PHP 8.5 due to removed zend_exception_get_default * THRIFT-5927 - Cannot use reserved language keyword "None" with target language Python * THRIFT-5885 - TBinaryProtocolAccelerated incorrectly deserializes IntEnum to None * THRIFT-5923 - UUID support for Python * THRIFT-5926 - TSaslClientTransport.open() crashes with DIGEST-MD5 due to None initial response * THRIFT-5915 - Python 3.12+ is not supported due to distutils * THRIFT-5892 - PY_SSIZE_T_CLEAN error in some environments * THRIFT-5873 - mTLS broken with python THttpClient * THRIFT-792 - TSocket hides underlying exceptions when open() fails * THRIFT-5888 - declare support for free-threaded CPython in extension modules * THRIFT-5900 - Thrift Cross Test broken in Github (Python 3.14) * THRIFT-5308 - implement ruby seq reply * THRIFT-5910 - Add UUID support in Ruby * THRIFT-5906 - Remove Fixnum references to support modern Ruby versions * THRIFT-5905 - Add base64 and logger as explicit dependencies * THRIFT-5903 - Fixnum is no longer supported since Ruby 3.2 * THRIFT-5687 - Ruby gems deprecation warning: Gem::Specification#has_rdoc= is deprecated with no replacement * THRIFT-4035 - Thrift ruby runtime does not send unique sequence IDs in requests according to the unit tests * THRIFT-1911 - IOError not being caught in socket.rb * THRIFT-4526 - Implement rubocop for ruby in the sca build, once clean into every make * THRIFT-5273 - warning in ruby version >= 2.4 * THRIFT-5918 - Implement header protocol support for Ruby * THRIFT-5559 - Processor can be implemented on handler trait itself * THRIFT-5928 - skip() call on unknown binary field fails deserialization instead of graceful skipping over field * THRIFT-5739 - set_nodelay should be enabled for TTcpChannel - Update to 0.22.0: * ### Build Process - THRIFT-5836 - 0.21.0 fails to build from sources at Arch Linux: No rule to make target 'Thrift5272.thrift', needed by 'gen-cpp/Thrift5272_types.h' - THRIFT-5860 - cmake 3.5 as a minimum version does not work with cmake 4.0.0 * ### C glib - THRIFT-5817 - [C++] Avoid copy of TUuid * ### C++ - THRIFT-5637 - Thrift compiler should be able to output c++ Aggregate types - THRIFT-5667 - Make ThriftConfig.cmake relocatable - THRIFT-5817 - [C++] Avoid copy of TUuid - THRIFT-5821 - Cannot compile against aws-lc libcrypto (openssl replacement from AWS) - THRIFT-5841 - possible init/deinit conflict with manual initialization flag - THRIFT-5853 - Remove oldstyle casts from TBufferTransports and TCompactProtocol - THRIFT-5854 - TCompactProtocol readString checks maxMessageSize at wrong position and off by one - THRIFT-5868 - UUID Support for TCompactProtocol - THRIFT-5865 - Fix TBinayProtocol with list<UUID> * ### Compiler (General) - THRIFT-5823 - Fix illegal uses of exceptions as normal struct type - THRIFT-5835 - Allow exceptions to be used as regular struct datatype * # Delphi - THRIFT-5822 - Remove deprecated AnsiString functions from the library - THRIFT-5824 - Migrate, refactor and improve Delphi code generation test script - THRIFT-5825 - UUID constants lead to uncompileable Delphi code - THRIFT-5826 - binary constants create uncompilable Delphi code - THRIFT-5827 - enums in typedefs are not resolved in all cases - THRIFT-5837 - Delphi implementation for THRIFT-5835 - THRIFT-5839 - incorrect cast under Win64 - THRIFT-5850 - Switch IThriftConfiguration interface from Cardinal to Integer - THRIFT-5851 - Promote known total stream sizes for seekable stream transports properly - THRIFT-5856 - Client should validate HTTP status * ### Go - THRIFT-5833 - go: Combine I/O and original error in compiler generated Process functions - THRIFT-5845 - The write error for union fields should be TException - THRIFT-5859 - go: Generate a map for know values of an enum type * ### Java - THRIFT-5858 - Introduce new type MESSAGE_SIZE_LIMIT in TTransportException * ### netstd - THRIFT-5832 - Drop net6 support and add net9 instead - THRIFT-5838 - THttpTransport.FlushAsync does not include original exception - THRIFT-5852 - Promote known total stream sizes for seekable stream transports * ### Node.js - THRIFT-5811 - Add ES module support to JS codegen - THRIFT-5848 - Expose InputBufferUnderrunError in nodejs client - THRIFT-5849 - Expose createClient in browser version of nodejs package * ### PHP - THRIFT-1482 - Unix domain socket support under PHP - THRIFT-5829 - PHP lib Use of "static" in callables is deprecated notice * ### Python - THRIFT-5024 - tutorial\py.tornado\PythonServer.py failed under Tornado6 - THRIFT-5847 - Python3.12 deprecation in THttpClient - THRIFT-5857 - Remove deprecated Tornado io_loop usage - THRIFT-5861 - Add isOpen method to TTornadoStreamTransport * ### Swift - THRIFT-4838 - add unix domain socket support to Swift TSocketTransport implementation libthrift-0_24_0-0.24.0-bp157.2.3.1.x86_64.rpm libthrift-devel-0.24.0-bp157.2.3.1.x86_64.rpm libthrift_c_glib0-0.24.0-bp157.2.3.1.x86_64.rpm libthriftnb-0_24_0-0.24.0-bp157.2.3.1.x86_64.rpm libthriftz-0_24_0-0.24.0-bp157.2.3.1.x86_64.rpm perl-thrift-0.24.0-bp157.2.3.1.x86_64.rpm python3-thrift-0.24.0-bp157.2.3.1.x86_64.rpm thrift-0.24.0-bp157.2.3.1.src.rpm thrift-0.24.0-bp157.2.3.1.x86_64.rpm libthrift-0_24_0-0.24.0-bp157.2.3.1.i586.rpm libthrift-devel-0.24.0-bp157.2.3.1.i586.rpm libthrift_c_glib0-0.24.0-bp157.2.3.1.i586.rpm libthriftnb-0_24_0-0.24.0-bp157.2.3.1.i586.rpm libthriftz-0_24_0-0.24.0-bp157.2.3.1.i586.rpm perl-thrift-0.24.0-bp157.2.3.1.i586.rpm python3-thrift-0.24.0-bp157.2.3.1.i586.rpm thrift-0.24.0-bp157.2.3.1.i586.rpm libthrift-0_24_0-0.24.0-bp157.2.3.1.aarch64.rpm libthrift-devel-0.24.0-bp157.2.3.1.aarch64.rpm libthrift_c_glib0-0.24.0-bp157.2.3.1.aarch64.rpm libthriftnb-0_24_0-0.24.0-bp157.2.3.1.aarch64.rpm libthriftz-0_24_0-0.24.0-bp157.2.3.1.aarch64.rpm perl-thrift-0.24.0-bp157.2.3.1.aarch64.rpm python3-thrift-0.24.0-bp157.2.3.1.aarch64.rpm thrift-0.24.0-bp157.2.3.1.aarch64.rpm libthrift-0_24_0-0.24.0-bp157.2.3.1.ppc64le.rpm libthrift-devel-0.24.0-bp157.2.3.1.ppc64le.rpm libthrift_c_glib0-0.24.0-bp157.2.3.1.ppc64le.rpm libthriftnb-0_24_0-0.24.0-bp157.2.3.1.ppc64le.rpm libthriftz-0_24_0-0.24.0-bp157.2.3.1.ppc64le.rpm perl-thrift-0.24.0-bp157.2.3.1.ppc64le.rpm python3-thrift-0.24.0-bp157.2.3.1.ppc64le.rpm thrift-0.24.0-bp157.2.3.1.ppc64le.rpm libthrift-0_24_0-0.24.0-bp157.2.3.1.s390x.rpm libthrift-devel-0.24.0-bp157.2.3.1.s390x.rpm libthrift_c_glib0-0.24.0-bp157.2.3.1.s390x.rpm libthriftnb-0_24_0-0.24.0-bp157.2.3.1.s390x.rpm libthriftz-0_24_0-0.24.0-bp157.2.3.1.s390x.rpm perl-thrift-0.24.0-bp157.2.3.1.s390x.rpm python3-thrift-0.24.0-bp157.2.3.1.s390x.rpm thrift-0.24.0-bp157.2.3.1.s390x.rpm openSUSE-2026-276 Security update for vifm important openSUSE Backports SLE-15-SP7 Update This update for vifm fixes the following issues: - Update to 0.14.4: Invocation: * Reworked --help output to be more compact and readable. Documentation: * Added menu index to the documentation. Patch by CaptainFantastic. * Improved description of the local filter in the documentation. * Documented quoting and escaping on command-line. Patch by Kirill Rekhov. * Documented name conflict resolution dialog. Patch by Kirill Rekhov. * Rewrote documentation about command-line ranges to make it complete and more readable. * Improved wording in documentation describing general behaviour of visual mode. Menus and dialogs: * Improved potentially confusing wording in the dialog confirming exit while background jobs are running. * Don't offer "append the tail" conflict resolution option for al and rl operations because it's inappropriate for creation of symbolic links. File preview: * Display an error on trying to switch from external preview to raw mode. Integration: * Fall back to using standard::fast-content-type from GLib if standard::content-type is missing. Patch by Jan Palus (a.k.a. jpalus). Other changes: * Added example of handling .deb-files to sample vifmrc. Patch by Kirill Rekhov. * Updated sample vifmrc files to use vi as a last resort if it exists. * Updated list of categories in .desktop-file. Patch by Jared Cervantes (a.k.a. Jaredy899). Fixes: * Fixed :normal not being able to run commands which end with whitespace. * Fixed printing newline on cancelling choosing a directory via --choose-dir option. * Fixed escaping characters with codes greater than 127 producing garbage. * Fixed vifm-media-osx script for modern versions of OS X. * Fixed weird delays in FUSE when running an AppImage caused by a trailing colon in $LD_LIBRARY_PATH. * Fixed a small memory leak on trying to display a map menu which doesn't show up because it would be empty. * Fixed vifm-pause and other helpers not being available from within AppImage. * Fixed vifm.vim not cleaning up buffers properly when used as a netrw replacement. * Fixed a crash if GLib didn't return a file type. Patch by Jan Palus (a.k.a. jpalus). * Fixed undoing of chmod operation not restoring owner's read permission. * Fixed incorrect progress indicator for dp and do keys in compare view. * Fixed UID/GID occasionally not being formatted as requested (numeric vs. symbolic form) in the UI. * Fixed rl normal mode key sometimes not moving cursor to the newly inserted link and simultaneously logging partial name in the undo history message, which is merely informative. * Fixed :open not entering symbolic links to directories if there is no vifm executable in $PATH. * Fixed :yank and :delete not handling optional count parameter correctly (a regression since v0.11-beta). * Fixed completion of :highlight truncating long custom column names. * Fixed a Lua column disabling search highlighting for all columns to its right. * Fixed a buffer overflow in trie implementation (CVE-2026-8997) (boo#1273413) * Fixed Lua modules written in C not being loaded on Unix-like systems. - Update to 0.14.3: Documentation: * Improved documentation on the use of registers. Menus and dialogs: * Say primary instead of default in the title of :colorscheme menu. Other changes: * Provided more details on file handlers and viewers in sample vifmrc files. Fixes: * Fixed picking trash directory when rooted trash is included in 'trashdir' and root is writable. Regression in v0.14.2 (unfortunately, testing this automatically is problematic). * Fixed unlimited growth of directory histories when 'history' is set to its default value or not set at all in vifmrc. * Fixed abort due to assertion on displaying a statusbar message with a newline when 'shortmess' includes T. - Update to 0.14.2: * Fix an issue with %r in 'trashdir' when root file-system is read-only (like on macOS) and also broke build with musl libc. * Trash directories specified via an absolute path and containing %u weren't created with 700 permissions. * Don't use strverscmp() of musl if it doesn't sort things correctly (A must be greater than 0). This avoids numerical sorting results looking different with musl. - Update to 0.14.1: * Fixed a preview-related crash on Windows easily reproducible using binary files. * Fixed a tree-related crash when using {fileext} or {ext} columns. * Fixed 'trashdir' with %r not working on BSD-like systems. * Fixed vifm path/to/file incorrectly running file handling in current working directory. * Restored terminal access for commands that use %i macro (so :!echo ... %i can affect the terminal as before v0.12.1). Use %i & for ignoring output while denying terminal accesses. * Fixed occasional incorrect truncation of wide characters on drawing columns broken while introducing column-specific highlighting in v0.14-beta. * Clarified information on comments after :commands. Provided some information on copy-on-write file copying. Improved documentation on leaving compare and custom views. - Update to 0.14: * Somewhat incompatible changes This release contains a number of changes which are technically non-backwards compatible. However, all of them should have very little negative impact (i.e., hard to notice the change without reading the changelog). At the same time, a bug, fixing which is likely to have an impact on user configuration, has been identified but not yet fixed to give a chance to update all affected vifmrc files. If a bug is likely to be relied on by the configuration, a dialog with the explanation and instructions will appear. * Sorting and non-Latin characters Until this release Vifm has always used byte sorting (effectively, sorting of UTF-8 byte sequences). From now on a form of Unicode normalization is applied to strings when sorting views and completion results. The change can be expanded to other cases in future releases. The measured performance impact is negligible (several percent). Practically, this means that characters like a and ä are now grouped together regardless of the way in which diacritic is being encoded. Some characters can still appear in weird non-alphabetic positions because full Unicode normalization results in losing case sensitivity and is therefore not applied. * Addressing some longtime woes For one reason or another some inconvenient peculiarities have accumulated over the years. Time has come to replace workarounds with something better: + global variables (g:var) replace the use of environmental variables for internal purposes, thus avoiding polluting environment of child processes + use of :let to invoke a builtin function discarding its result is superseded by a proper :call command + use of execute 'normal! gl' to run selection now has :open command as a better alternative + size of selection can now be queried via selected() (previous releases required expand('%c') == expand('%f') or an equivalent trick) + %{expression} macro in 'statusline' can now have } embedded as \} (\\ still means two slashes) + dialogs now recognize Enter and Escape keys as "yes" and "no" replies * More useful menus :copen recalled last navigation menu for years, but that's not always enough. Now up to 25 such menus are stored after their use and can be navigated to via :chistory/:colder/:cnewer. In addition, :grep or :find can be rerun on the same set of commands right from the menu which previously required leaving the menu just to get back to it. History of command-line in menus is now also managed and stored, making staying in menu mode for longer a more pleasant experience. * UI improvements Navigation between views/tabs via new :wingo command with optional incremental completion thanks to new 'wildinc' option (applicable to any other command or all of them at once). Ability to highlight a view column (:highlight column:size ...), specify how highlighting applies ('hloptions'), set a separator between miller columns in set fillchars+=millersep:'|', shorten columns in the middle (^ in 'viewcolumn'). Also, displaying of CJK characters on Windows should have much fewer issues now. * Lua API Slowly adding new functionality. This batch comes with things like primitive file operations, ability to create custom views or menus and handling ranges of :commands. * Other Search matches can be traversed via Tab and Shift-Tab while in the prompt (applies to navigation mode as well). An invalid expression in :if or :elseif no longer just skips that command, now all commands up to and including matching :endif are skipped to avoid executing half-random sequences of commands due to a mistake, which also results in better error messages. Previously, :elseif was also evaluating its expression even some earlier branch was already taken. :rename now asks whether file move is intended instead of assuming a user mistake and refusing to proceed. Support MTP devices by bundled vifm-media script if simple-mtpfs is installed. Also improve what devices are offered for mounting (e.g., don't offer a whole drive if it contains partitions). v:version to branch depending on release. * Fixes Get preview graphics out of the way in more cases (like when opening menus). Terminals with more than 32768 color pairs should not cause visual defects or crashes anymore. Merging of directories was either not asking for confirmation or aborting after skipping a file. Paths with some unreadable characters were not processed due to a regression. Directories weren't counted in estimates of file operations. && operator was always evaluating both branches instead of properly short-circuiting. %a macro of 'statusline' was displaying wrong values on non-Linux Unix-like systems. :compare falsely claimed that files of identical size and with common prefix are identical. vifm-0.14.4-bp157.2.3.1.src.rpm vifm-0.14.4-bp157.2.3.1.x86_64.rpm vifm-0.14.4-bp157.2.3.1.i586.rpm vifm-0.14.4-bp157.2.3.1.aarch64.rpm vifm-0.14.4-bp157.2.3.1.ppc64le.rpm vifm-0.14.4-bp157.2.3.1.s390x.rpm openSUSE-2026-277 Security update for python-nltk important openSUSE Backports SLE-15-SP7 Update This update for python-nltk fixes the following issues: - CVE-2026-12061: ReDoS in NLTK ReviewsCorpusReader FEATURES regex (boo#1273252) - CVE-2026-12072: Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True) (boo#1273254) - CVE-2026-12074: python-nltk: path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True) (boo#1273255) python-nltk-3.7-bp157.3.18.1.src.rpm python3-nltk-3.7-bp157.3.18.1.noarch.rpm openSUSE-2026-280 Security update for go-sendxmpp important openSUSE Backports SLE-15-SP7 Update This update for go-sendxmpp fixes the following issues: - Update to 0.17.0: * Add --ox-transfer-private-key to transfer the encrypted private key to PEP to transfer it to other devices (requires go-xmpp >= v0.3.7). * Add --ox-receive-private-key to receive the encrypted private key from PEP. * Add config option no_root_warning. * Add config option no_legacy_pgp_warning. * Also disable legacy PGP when running as root (Ox was already disabled). * Disable pinning for not using PLAIN when running as root. * Add config option ox_trust_mode with settings blind and tofu. * Due to new tofu trust mode for Ox, only one public key per contact is accepted for easier ID handling. * Ox: Check that fingerprint of received key equals the advertised one. * CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (boo#1266617): Bump net to 0.57.0 go-sendxmpp-0.17.0-bp157.2.12.1.src.rpm go-sendxmpp-0.17.0-bp157.2.12.1.x86_64.rpm go-sendxmpp-0.17.0-bp157.2.12.1.i586.rpm go-sendxmpp-0.17.0-bp157.2.12.1.aarch64.rpm go-sendxmpp-0.17.0-bp157.2.12.1.ppc64le.rpm go-sendxmpp-0.17.0-bp157.2.12.1.s390x.rpm