3.11 openjpeg
- community/clsync: add init script
- community/php7: security upgrade to 7.3.13
- community/kea: take over maintainership
- main/pcre2: fix bug causing rspamd segfault
- community/alpine-make-vm-image: upgrade to 0.6.0
- main/rsyslog: enable Input Module Docker
- community/mongo-c-driver: remove obsolete comment and re-enable on all arches
- community/gedit-plugins: add missing dep on libpeas-python3
- community/shadow: add pam file for newusers
- main/glib: upgrade to 2.62.4
- main/clamav: add secinfo
- main/linux-lts: upgrade to 5.4.6
- community/jool-modules-lts: rebuild against kernel 5.4.6-r0
- community/virtualbox-guest-modules-lts: rebuild against kernel 5.4.6-r0
- community/wireguard-lts: rebuild against kernel 5.4.6-r0
- main/drbd-lts: rebuild against kernel 5.4.6-r0
- main/xtables-addons-lts: rebuild against kernel 5.4.6-r0
- community/cacti: add secfixes comment
- main/zfs-lts: rebuild against kernel 5.4.6-r0
- main/monit: fix invalid use of vfork
- main/linux-rpi: fix dtbs location
- main/linux-rpi: upgrade to 5.4.6
- community/jool-modules-rpi: rebuild against kernel 5.4.6-r0
- community/wireguard-rpi: rebuild against kernel 5.4.6-r0
- community/hexchat: upgrade to 2.14.3
- community/hexchat: modernize
- community/hexchat: build with python3-embed
- main/cyrus-sasl: fix CVE-2019-19906
- main/zstd: fix bus error on armhf
- community/go: depen on binuutils-gold on arm*/aarch64
- main/expat: re-enable static library
- scripts/mkimg.netboot.sh: make initramfs readable
- ==== release 3.11.1 ====
- ==== release 3.11.2 ====
- main/awall: upgrade to 1.6.13
- community/kdeconnect: add missing runtime dep sshfs
- community/chromium: upgrade to 79.0.3945.88
- main/etckeeper: upgrade to 1.18.13
- community/drupal7: security upgrade to 7.69
- community/chromium: fix build on armv7
- community/kea: upgrade to 1.7.3
- community/jetty-runner: upgrade to 9.4.15.20190215
- main/haproxy: upgrade to 2.0.12
- main/py3-django: security upgrade to 1.11.27 (CVE-2019-19844)
- main/openssl: fix CVE-2019-1551
- community/repmgr: upgrade to 5.0.0
- community/lua-busted: upgrade to 2.0.0
- community/dia: fix CVE-2019-19451.patch
- main/python3: upgrade to 3.8.1
- testing/fontforge: rebuild against python3.8
- main/xen: add secinfo
- community/py3-keepass: use Cryptodome instead of Crypto
- community/gnome-passwordsafe: use Cryptodome instead of Crypto
- community/opensc: security upgrade to 0.20.0
- community/kea: fix capabilities
- community/kea-hook-runscript: rebuild against kea 1.7.3
- community/kea-hook-runscript: take over maintainership
- community/salt: fix python3.8 incompattibilities
- main/samba: backport fix for python 3.8
- community/ruby-rspec-support: upgrade to 3.9.2
- community/ruby-rspec-mocks: upgrade to 3.9.1
- community/ruby-rspec-core: upgrade to 3.9.1
- main/openvpn: upgrade to 2.4.8
- main/ctags: enable tests on s390x again
- main/hunspell: fix CVE-2019-16707
- community/lua-turbo: add missing ca-certificates
- main/linux-lts: upgrade to 5.4.7
- main/linux-lts: set UEVENT_HELPER_PATH for armv7
- main/linux-lts: upgrade to 5.4.8
- community/jool-modules-lts: rebuild against kernel 5.4.8-r0
- community/virtualbox-guest-modules-lts: rebuild against kernel 5.4.8-r0
- community/wireguard-lts: rebuild against kernel 5.4.8-r0
- main/drbd-lts: rebuild against kernel 5.4.8-r0
- main/xtables-addons-lts: rebuild against kernel 5.4.8-r0
- main/zfs-lts: rebuild against kernel 5.4.8-r0
- main/linux-rpi: upgrade to 5.4.7
- main/linux-rpi: upgrade to 5.4.8
- community/wireguard: update to 20191226
- community/wireguard-rpi: enable for rpi4
- community/jool-modules-rpi: rebuild against kernel 5.4.8-r0
- community/wireguard-rpi: rebuild against kernel 5.4.8-r0
- main/libjpeg-turbo: security upgrade to 2.0.4 (CVE-2019-2201)
- community/muacme: fix depends on cmd:openssl
- main/msmtp: fix init script
- main/kamailio: increase timout for stopping service
- community/phpmyadmin: upgrade to 4.9.4
- community/firefox-esr: security upgrade to 68.4.1
- main/ulogd: fix logrotate pattern
- community/accerciser: upgrade to 3.34.3
- community/mutter: upgrade to 3.34.3
- community/gnome-shell: upgrade to 3.34.3
- community/dconf-editor: upgrade to 3.34.3
- community/eog: upgrade to 3.34.2
- community/epiphany: upgrade to 3.34.3.1
- community/gnome-boxes: upgrade to 3.34.3
- community/seahorse: upgrade to 3.34.1
- community/gnome-contacts: upgrade to 3.34.1
- community/rhythmbox: upgrade to 3.4.4
- community/gnome-music: upgrade to 3.34.3
- community/gnome-initial-setup: upgrade to 3.34.3
- community/gnome-maps: upgrade to 3.34.3
- community/evolution-data-server: upgrade to 3.34.3
- community/evolution: upgrade to 3.34.3
- community/evolution-ews: upgrade to 3.34.3
- community/lxcfs: let lxc use lxcfs if installed
- community/pflogsumm: remove sysklogd dependency
- community/ldap-passwd-webui: fix depends on py-waitress
- main/grub: fix booting Xen under EFI
- community/py3-waitress: fix broken upgrade from older versions
- main/xen: add secinfo
- main/busybox: enable FEATURE_NSLOOKUP_BIG
- main/libvirt: qemu: Fix migration without parameters
- main/e2fsprogs: security upgrade to 1.45.5
- community/wireguard-(lts|rpi): upgrade to 0.0.20200105
- main/linux-rpi: upgrade to 5.4.12
- community/wireguard-rpi: rebuild against kernel 5.4.12-r0
- community/jool-modules-rpi: rebuild against kernel 5.4.12-r0
- main/linux-lts: enable cannonlake pinctrl for x86_64
- main/linux-lts: enable rtw88 driver for x86/x86_64
- main/linux-lts: upgrade to 5.4.11
- main/linux-lts: upgrade to 5.4.12
- main/linux-lts: enable serial_ir module
- community/jool-modules-lts: rebuild against kernel 5.4.12-r1
- community/virtualbox-guest-modules-lts: rebuild against kernel 5.4.12-r1
- community/wireguard-lts: rebuild against kernel 5.4.12-r1
- main/drbd-lts: rebuild against kernel 5.4.12-r1
- main/xtables-addons-lts: rebuild against kernel 5.4.12-r1
- main/zfs-lts: rebuild against kernel 5.4.12-r1
- main/openrc: allow to change interfaces config location
- main/nginx: fix CVE-2019-20372
- main/mkinitfs: upgrade to 3.4.5
- ==== release 3.11.3 ====
- main/openrc: fix do_unmount function
- community/php7-pecl-xdebug: upgrade to 2.9.1
- community/phpmyadmin: add secfixes
- main/ansible: security upgrade to 2.9.3 CVE-2019-14904 CVE-2019-14905
- community/cesnet-tcs-cli: upgrade to 0.3.0
- main/awall: upgrade to 1.7.0
- main/iproute2: fix LIBDIR for tc plugins
- community/gdal: upgrade to 3.0.3
- community/firefox-esr: upgrade to 68.4.2
- main/luajit: add support for s390x
- community/chromium: change maintainer
- community/chromium: upgrade to 79.0.3945.130
- main/alpine-conf: backport lbu fix for listing ciphers
- main/alpine-conf: unbreak lbu
- community/google-authenticator: upgrade to 1.08
- community/kea: fix depends_dev
- community/kea: move binary kea-lfc to kea-common, remove subpkg kea-utils
- main/freeradius: fix segfault in process request_running()
- main/samba: security upgrade to 4.11.5
- community/wireshark: security upgrade to 3.0.8 (CVE-2020-7045)
- community/php7: security upgrade to 7.3.14 (CVE-2020-7059 CVE-2020-7060)
- community/webkit2gtk: upgrade to 2.26.3
- main/opensmtpd: security upgrade to 6.6.2p1
- community/orca: upgrade to 3.34.2
- community/openjdk8: security upgrade to 8.242.08
- main/opensmtpd: add secfixes
- main/mariadb: upgrade to 10.4.11
- main/mariadb: upgrade to 10.4.12 and fix deps
- community/kea: fix problem with kea service doesn't want to stop
- community/gcc6: fix wrong code when returning padded struct
- main/sudo: don't warn about missing /etc/environment with no PAM
- community/bcc: add static subpackage
- community/libbpf: upgrade to 0.0.6
- main/open-iscsi: fix path of commands on initd, add -dev and -libs subpkg
- main/py3-django: security upgrade to 1.11.28
- main/libebml: fix secfixes comment
- main/lz4: fix secfixes comment
- main/e2fsprogs: fix secfixes comment
- main/faac: fix secfixes comment
- community/sox: fix secfixes comment
- main/zzliplib: fix secfixes comment
- community/containerd: fix whitespace damage in comment
- main/uwsgi: mitigate backward compat. breakage in -python3 and -gevent3
- main/uwsgi: actually add post-upgrade script
- main/postfix: upgrade to 3.4.9
- main/sudo: fix CVE-2019-18634
- main/sudo: upgrade to 1.8.31
- community/webkit2gtk: update secfixes comment
- main/openjpeg: secfixes (CVE-2020-6851,CVE-2020-8112)
- main/ca-certificates: fix bundle with certs without newline
- main/doas: fix simple typo in description
- main/doas: upgrade to 6.6.1
- main/nodejs: upgrade to 12.15.0
- main/nodejs: fix man pages to have npm- prefix
- main/openvpn: allow to pass additional arguments for openvpn
- main/awall: upgrade to 1.7.1
- community/uacme: upgrade to 1.0.22
- community/uacme: create acme-challenge dir
- main/libxml2: fix CVE-2020-7595
- community/firefox-esr: upgrade to 68.5.0
- main/vala: upgrade to 0.46.6
- main/haproxy: upgrade to 2.0.13
- main/freeradius: remove sites-available/*.orig
- main/freeradius: fix perms in certs directory
- main/postgresql: security upgrade to 12.2
- main/dmvpn: fix race condition
- main/dovecot: security upgrade to 2.3.9.3
- ci: silence fetching from upstream
- ci: enable shallow cloning/fetching
- ci: use clone instead of fetch
- main/dmvpn: various fixes
- community/webkit2gtk: upgrade to 2.26.4
- main/protobuf: fix ruby gem - missing symbol __va_copy
- community/py3-prettytable: fix permissions
- main/ppp: security fix
- community/weechat: security upgrade to 2.7.1 (CVE-2020-8955)
- community/lua-mmdb: new aport (needed for knot-resolver)
- community/knot-resolver: add missing dependencies
- community/knot-resolver: add init script for kres-cache-gc
- main/opensmtpd: security upgrade to 6.6.4p1
- main/glib: add missing CVE info
- main/glib: upgrade to 2.62.5
- main/ncurses: fix automatic dependency due to symlinks
- main/ncurses: upgrade to 6.1_p20200118
- main/zfs: upgrade to 0.8.3
- main/zfs-lts: use zfs 0.8.3
- community/xterm: depend on ncurses-terminfo
- community/alacritty: depend on ncurses-terminfo
- community/gnome-terminal: depend on ncurses-terminfo
- testing/kitty: depend on ncurses-terminfo
- community/konsole: depend on ncurses-terminfo
- main/putty: depend on ncurses-terminfo
- main/cvs: security upgrade to 1.12.12
- main/ncurses: re-arrange terminfo contents
- {main,community,testing}: make terminals depend on ncurses-terminfo-base
- main/zfs: fix paths in /etc/zfs/zfs{,-functions}
- main/ncurses: move screen-256color to ncurses-terminfo-base
- community/librsvg: add missing secinfo for CVE-2019-20446
- community/php7: security upgrade to 7.3.15
- community/tvheadend: change pkggroup to video
- main/python3: upgrade to 3.8.2
- community/cesnet-tcs-cli: upgrade to 0.3.1
- community/acme.sh: upgrade to 2.8.5
- community/cesnet-tcs-cli: upgrade to 0.3.2
- main/musl: update URL and sources
- main/musl: thumb2 support for arm memcpy
- main/acf-core: upgrade to 0.22.0
- main/acf-alpine-baselayout: upgrade to 0.13.3
- main/acf-lib: upgrade to 0.11.0
- community/live-media: fixed symbol-not-found issue
- community/vlc: bump pkgrel due to upgrade of live-media
- community/mplayer: bump pkgrel due to upgrade of live-media
- main/nsd: enable ratelimit configure option
- main/mercurial: upgrade to 5.3.1
- main/libwebsockets: upgrade to 3.2.2
- community/wireshark: security upgrade to 3.0.9
- main/py3-django: upgrade to 1.11.29
- main/ppp: secfix for radius and EAP
- main/squid: upgrade to 4.10
- main/libarchive: upgrade to 3.4.2
- community/py3-waitress: upgrade to 1.4.1
- community/firefox-esr: security upgrade to 68.6.0
- community/py3-bleach: upgrade to 3.1.1
- community/sleuthkit: fix CVE-2020-10232 and CVE-2020-10233
- community/cacti: upgrade to 1.2.10
- main/iptables: restore lost init.d script for ebtables
- community/okular: security upgrade to 19.08.3-r1
- main/exiv2: fix CVE-2019-20421
- main/virglrenderer: security upgrade to 0.8.1
- main/gst-plugins-base: add secfixes
- community/py3-bleach: security upgrade to 3.1.2
- main/ansible: security upgrade to 2.9.6
- main/glib: upgrade to 2.62.6
- community/tor: security upgrade to 0.4.1.9
- community/ipmitool: fix CVE-2020-5208
- main/clamav: add missing secfixes info
- main/py3-yaml: security upgrade to 5.3.1
- community/php7: security upgrade to 7.3.16
- main/linux-lts: upgrade to 5.4.26
- community/jool-modules-lts: rebuild against kernel 5.4.26-r0
- community/virtualbox-guest-modules-lts: rebuild against kernel 5.4.26-r0
- community/wireguard-lts: rebuild against kernel 5.4.26-r0
- main/drbd-lts: rebuild against kernel 5.4.26-r0
- main/xtables-addons-lts: rebuild against kernel 5.4.26-r0
- main/zfs-lts: rebuild against kernel 5.4.26-r0
- main/linux-rpi: add check to verify kernel version
- main/linux-rpi: upgrade to 5.4.26
- community/jool-modules-rpi: rebuild against kernel 5.4.26-r0
- community/wireguard-rpi: rebuild against kernel 5.4.26-r0
- main/raspberrypi-bootloader: upgrade to 1.20200212
- main/gcc: fix wrong code when returning padded struct
- main/musl: backport fixes from 1.2.0
- community/phpmyadmin: security upgrade to 4.9.5
- main/linux-lts: upgrade to 5.4.27
- community/jool-modules-lts: rebuild against kernel 5.4.27-r0
- community/virtualbox-guest-modules-lts: rebuild against kernel 5.4.27-r0
- community/wireguard-lts: rebuild against kernel 5.4.27-r0
- main/drbd-lts: rebuild against kernel 5.4.27-r0
- main/xtables-addons-lts: rebuild against kernel 5.4.27-r0
- main/zfs-lts: rebuild against kernel 5.4.27-r0
- main/linux-rpi: upgrade to 5.4.27
- community/jool-modules-rpi: rebuild against kernel 5.4.27-r0
- community/wireguard-rpi: rebuild against kernel 5.4.27-r0
- ===== release 3.11.5 =====
- community/py3-twisted: security upgrade to 20.3.0
- main/bluez: fix CVE-2020-0556
- main/apk-tools: upgrade to 2.10.5
- main/icu: fix CVE-2020-10531
- main/vala: upgrade to 0.46.7
- community/py3-bleach: security upgrade to 3.1.4
- main/libmspack: security upgrade to 0.10.1_alpha
- main/libvpx: add missing secfixes info
- community/nethack: upgrade to 3.6.6
- main/unzip: fix CVE-2019-13232
- community/jenkins: security upgrade to 2.228
- community/nextcloud: upgrade to 17.0.5
- community/libwpe: new aport
- community/libwpebackend-fdo: new aport
- community/webkit2gtk: security upgrade to 2.28.0
- main/unzip: actually fix CVE-2019-13232
- community/gjs: upgrade to 1.58.6
- main/py-dbus: fix packaging
- main/screen: fix CVE-2020-9366
- main/screen: fix patch for CVE-2020-9366
- community/mutter: upgrade to 3.34.5
- community/gnome-shell: upgrade to 3.34.5
- community/dia: fix secfixes comment
- main/gnutls: fix GNUTLS-SA-2020-03-31
- community/gnome-control-center: upgrade to 3.34.5
- main/uwsgi: use libucontext for ugreen plugin
- main/ruby: security upgrade to 2.6.6
- main/apache2: security upgrade to 2.4.43
- main/apache2: modernize
- community/graphicsmagick: security upgrade to 1.3.35 (CVE-2020-10938)
- main/libgit2: upgrade to 0.28.5
- main/haproxy: security upgrade to 2.0.14
- community/gnome-desktop: upgrade to 3.34.5
- main/gnutls: add CVE secfixes info
- main/mbedtls: security upgrade to 2.16.5
- main/bubblewrap: security upgrade to 0.4.1
- main/xen: add missing CVE info
- community/firefox-esr: upgrade to 68.6.1
- community/gnome-weather: upgrade to 3.34.1
- main/mercurial: upgrade to 5.3.2
- main/gd: patch CVE-2018-14553 and CVE-2019-11038
- community/firefox-esr: upgrade to 68.7.0
- main/libssh: security upgrade to 0.9.4
- community/freerdp: security upgrade to 2.0.0
- community/gnome-weather: upgrade to 3.34.2
- main/strongswan: subpackage for logfile config
- main/in-sync: backport from edge
- main/dmvpn: file list for in-sync
- main/ncurses: fix missing vtXXX terminfo in ncurses-terminfo-base
- main/st: set depends on ncurses-terminfo-base
- testing/st-xrdb: set depends on ncurses-terminfo-base
- community/wireshark: security upgrade to 3.0.10
- main/git: security upgrade to 2.24.2
- community/php7: security upgrade to 7.3.17 CVE-2020-7067
- main/mcpp: fix CVE-2019-14274
- [3.11] main/ansible: security upgrade to 2.9.7
- community/tor: disable package pending security review
- community/tor: re-enable and rebuild to avoid bogus IDS warning
- main/xen: fix various security issues
- main/git: fix and enable tests
- community/cacti: upgrade to 1.2.11
- community/racktables: needs mbstring PHP module
- main/freeradius: fix going though post-proxy on dead home server
- community/webkit2gtk: security upgrade to 2.28.1
- community/openblas: revert LAPACK changes
- main/vala: upgrade to 0.46.8
- main/openssl: security upgrade to 1.1.1g (CVE-2020-1967)
- main/git: security upgrade to 2.24.3 (CVE-2020-11008)
- community/runc: security upgrade to 1.0.0_rc10
- main/py3-crypto: fix operator
- main/linux-lts: upgrade to 5.4.34 and misc config fixes
- community/jool-modules-lts: rebuild against kernel 5.4.34-r0
- community/virtualbox-guest-modules-lts: rebuild against kernel 5.4.34-r0
- community/wireguard-lts: update to 1.0.20200401 / 5.4.34-r0
- main/drbd-lts: rebuild against kernel 5.4.34-r0
- main/xtables-addons-lts: rebuild against kernel 5.4.34-r0
- main/zfs-lts: rebuild against kernel 5.4.34-r0
- main/linux-rpi: upgrade to 5.4.34
- community/jool-modules-rpi: rebuild against kernel 5.4.34-r0
- community/wireguard-rpi: upgrade to 1.0.20200401 / 5.4.34-r0
- ===== release 3.11.6 =====
- main/vala: upgrade to 0.46.9
- community/chromium: security upgrade to 80.0.3987.149
- community/chromium: explicitly call python2 instead of python
- community/chromium: install swiftshader
- community/chromium: upgrade to 81.0.4044.113
- main/ntfs-3g: patch CVE-2019-9755
- main/tzdata: upgrade to 2020a
- Revert "main/ncurses: fix missing vtXXX terminfo in ncurses-terminfo-base"
- community/go: security upgrade to 1.13.10 (CVE-2020-7919)
- main/re2c: fix CVE-2020-11958
- community/mutter: upgrade to 3.34.6
- community/gnome-desktop: upgrade to 3.34.6
- community/nextcloud: upgrade to 17.0.6
- community/gnome-control-center: upgrade to 3.34.6
- community/webkit2gtk: upgrade to 2.28.2
- main/python2: security upgrade to 2.7.18
- community/salt: upgrade to 2019.2.4
- community/python2-tkinter: security upgrade to 2.7.17
- community/python2-tkinter: security upgrade to 2.7.18
- main/libxml2: modernize
- main/libxml2: store patch in aports tree
- main/libxml2: fix CVE-2019-20388
- community/ceph: security upgrade to 14.2.7
- community/ceph: remove stale boost-1.70 patch
- community/ceph: upgrade to 14.2.8
- community/ceph: security upgrade to 14.2.9
- community/rpm: build without broken plugin support
- community/firefox-esr: security upgrade to 68.8.0
- main/ldb: upgrade to 2.0.10
- main/samba: security upgrade to 4.11.8
- main/sqlite: security fix (CVE-2020-11655)
- main/openldap: fix CVE-2020-12243
- community/various: rebuild go packages for CVE-2020-7919
- community/umoci: add chmod-clean option
- main/libvirt: security fix for CVE-2020-12430
- main/sprunge: use https when possible
- main/mariadb: security upgrade to 10.4.13
- community/cheese: add missing dep on gsettings-desktop-schemas
- [3.11] main/libmaxminddb: fix database retrieval Backport of !7853 (closed) - Allow MaxMind license key input required for downloads - Update db retrieval (new endpoint with license key and new compressed file structure)
- community/php7: security upgrade to 7.3.18 CVE-2019-11048
- main/postfix: upgrade to 3.4.12
- main/xen: Remove dependency on syslinux
- main/libexif: security upgrade to 0.6.22
- main/vala: upgrade to 0.46.10
- main/unbound: fix CVE-2020-12662 and CVE-2020-12663
- main/bind: security upgrade to 9.14.12
- community/drupal7: security upgrade to 7.70
- community/gnome-photos: upgrade to 3.34.1
- community/knot-resolver: fix CVE-2020-12667
- community/wireshark: security upgrade to 3.0.11
- community/pdns-recursor: security upgrade to 4.2.2
- main/iproute2: add missing secfixes info
- community/apache-ant: security upgrade to 1.10.8
- main/clamav: security upgrade to 0.102.3
- main/dovecot: security upgrade to 2.3.10.1
- community/exim: security fix (CVE-2020-12783)
- main/jbig2dec: security fix (CVE-2020-12268)
- main/jbig2dec: update checksums
- main/perl-mozilla-ca: upgrade to 20200520
- community/vlc: security upgrade to 3.0.9.2
- main/py3-httplib2: fix CWE-93
- community/prometheus: correct init.d variables
- main/mbedtls: security upgrade to 2.16.6
- main/python3: add missing secfixes info
- main/json-c: fix CVE-2020-12762
- community/rtorrent: rebuild
- [3.11] main/xen: backport upgrade to 4.13.1
- community/zabbix: upgrade to zabbix 4.4.9
- main/dbus: fix CVE-2020-12049
- main/abuild: backport fixes for crosscompile
- main/ca-certificates: remove expired certificate
- main/ca-certificates: use source package from gitlab
- main/nghttp2: fix CVE-2020-11080
- main/gnutls: security upgrade to 3.6.14 (CVE-2020-13777)
- main/gnutls: add corresponding GNUTLS-SA to CVE-2020-13777
- community/intel-ucode: upgrade to 20200609
- main/axel: fix CVE-2020-13614
- main/hostapd: fix CVE-2020-12695
- community/nextcloud: upgrade to 17.0.7
- main/samba: upgrade to 4.11.9
- main/xen: fix XSA-320
- community/mumble: security upgrade to 1.3.1
- community/intel-ucode: upgrade to 20200616
- community/drupal7: security upgrade to 7.72 CVE-2020-13663
- main/perl: fix typo in include for BZIP2
- main/perl: security upgrade to 5.30.3 (CVE-2020-10543,CVE-2020-10878,CVE-2020-12723)
- main/dropbear: backport security fixes
- main/libjpeg-turbo: fix CVE-2020-13790
- main/ngircd: fix CVE-2020-14148
- community/gitea: upgrade to v1.10.6
- main/vala: upgrade to 0.46.11
- main/ruby: Correct wrong CVE number in secfixes for version 2.6.6-r0
- main/xen: security fixes for XSA-317, XSA-319, XSA-321, XSA-327 and XSA-328
- community/opam: upgrade to 2.0.7
- community/ffmpeg: security upgrade to 4.2.4
- community/go: upgrade to 1.13.13
- main/python3: fix CVE-2020-14422
- main/smokeping: needs ttf-dejavu
- [3.11] main/alpine-conf: avoid unwanted syslinux for setup-disk on mounted root
- main/hylafaxplus: fix CVE-2020-15396 and CVE-2020-15397
- community/firefox-esr: upgrade to 68.9.0
- community/firefox-esr: security upgrade to 68.10.0
- community/firefox-esr: security upgrade to 68.11.0
- main/libx11: security upgrade to 1.6.10
- main/vala: upgrade to 0.46.12
- main/xorg-server: fix CVE-2020-14347
- main/patch: add missing CVE to secfixes
- main/fail2ban: fix logging after rotate
- main/spamassassin: security upgrade to 3.4.4
- main/knock: upgrade to 0.8.1
- community/java-gcj-compat: update gccpkgrel to match gcc6-java
- community/openjdk7: security upgrade to 7.231.2.6.19
- community/openjdk7: security upgrade to 7.241.2.6.20
- community/openjdk7: security upgrade to 7.251.2.6.21
- community/openjdk7: security upgrade to 7.261.2.6.22
- community/openjdk8: security upgrade to 8.252.09
- community/firefox-esr: disable, fails to build
- main/apache2: security upgrade to 2.4.46
- main/vala: upgrade to 0.46.13
- main/rsyslog: drop boot.log
- main/rsyslog: rsyslog logrotate should not touch messages
- main/gcc: security upgrade to 9.3.0 (CVE-2019-15847)
- main/busybox: add secfixes comment for CVE-2018-1000500
- main/libvirt: security fix for CVE-2019-20485
- main/chrony: security upgrade to 3.5.1
- main/libx11: security upgrade to 1.6.12
- community/nextcloud: upgrade to 17.0.9
- main/ansible: remove duplicate in secfixes comment
- community/exim: remove dup CVE-2018-6789 in secfixes comment
- main/gnutls: security upgrade to 3.6.15
- main/postgresql: security upgrade to 12.4
- community/php7: upgrade to 7.3.22
- main/zeromq: security upgrade to 4.3.3
- main/xen: security fix for CVE-2020-14364/XSA-335
- main/libssh: fix CVE-2020-16135
- main/curl: fix CVE-2020-8169 and CVE-2020-8177
- main/libxml2: fix CVE-2020-24977
- community/drupal7: security upgrade to 7.73 CVE-2020-13666
- main/openjpeg: fix CVE-2019-12973 and CVE-2020-15389
- main/perl-dbi: security upgrade to 1.643
- main/cryptsetup: fix CVE-2020-14382
- community/pdns: upgrade to 4.2.2
- community/pdns: security upgrade to 4.2.3
- main/xen: security fixes for XSA-333, XSA-334, XSA-336, XSA-337, XSA-338, XSA-339, XSA-340, XSA-342, XSA-343 and XSA-344
- community/wireshark: security upgrade to 3.0.14
- main/ansible: upgrade to 2.9.9
- main/ansible: upgrade to 2.9.11
- main/ansible: security update to 2.9.13
- main/mbedtls: security upgrade to 2.16.8
- community/apache-ant: security upgrade to 1.10.9
- community/apache-ant: fix checksum
- main/mariadb: security upgrade to 10.4.15
- community/zabbix: upgrade to 4.4.10
- community/nextcloud: upgrade to 17.0.10
- main/oniguruma: fix CVE-2020-26159
- main/ansible: upgrade to 2.9.14
- main/putty: upgrade to 0.74 (CVE-2020-14002)
- main/tzdata: upgrade to 2020b
- main/tzdata: upgrade to 2020c
- main/freetype: fix CVE-2020-15999
- main/ghostscript: clean up duplicate secfixes comment
- community/firefox: remove duplicate CVE in secfixes comment
- main/lame: remove duplicates in secfixes comment
- main/sdl: remove duplicate CVE in secfixes comment
- community/wireshark: fix secfixes comment
- main/samba: remove duplicate CVE in secfixes comment
- main/sqlite: fix secfixes comment
- main/hostapd: remove duplicate CVE in secfixes comment
- main/libsndfile: remove dulicate CVE secfixes comment
- main/libvorbis: remove duplicate CVE in secfixes comment
- main/wpa_supplicant: remove CVE dupes in secfixes comment
- main/busybox: fix duplicate CVE in secfixes comment
- main/rdesktop: fix duplicate CVEs in secfixes comment
- community/tor: fix duplicate CVE in secfixes comment
- main/linux-lts: upgrade to 5.4.72
- community/jool-modules-lts: rebuild against kernel 5.4.72-r0
- community/virtualbox-guest-modules-lts: rebuild against kernel 5.4.72-r0
- community/wireguard-lts: rebuild against kernel 5.4.72-r0
- main/drbd-lts: rebuild against kernel 5.4.72-r0
- main/xtables-addons-lts: rebuild against kernel 5.4.72-r0
- main/zfs-lts: rebuild against kernel 5.4.72-r0
- main/xorg-server: fix various CVEs
- main/perl-datetime-timezone: upgrade to 2.39
- main/perl-datetime-timezone: upgrade to 2.41
- main/perl-datetime-timezone: upgrade to 2.42
- main/perl-datetime-timezone: upgrade to 2.43
- community/php7-pecl-timezonedb: upgrade to 2020.1
- community/php7-pecl-timezonedb: fix license and improve
- community/php7-pecl-timezonedb: upgrade to 2020.2
- community/php7-pecl-timezonedb: upgrade to 2020.3
- community/php7-pecl-timezonedb: upgrade to 2020.4
- main/linux-rpi: upgrade to 5.4.72
- community/jool-modules-rpi: rebuild against kernel 5.4.72-r0
- community/wireguard-rpi: rebuild against kernel 5.4.72-r0
- main/squid: security upgrade to 4.13
- main/open-iscsi: upgrade to 2.1.2
- community/zabbix: rundir is needed for control socket
- main/xen: security upgrade to 4.13.2
- main/tmux: fix CVE-2020-27347
- community/intel-ucode: security upgrade to 20201110
- community/intel-ucode: security upgrade to 20201112
- community/drupal7: security upgrade to 7.74 - CVE-2020-13671
- main/musl: security fix for CVE-2020-28928
- main/xen: security fix for XSA-351
- main/tzdata: switch to fat format
- main/krb5: security upgrade to 1.17.2
- main/tcpdump: fix CVE-2020-8037
- main/postgresql: security upgrade to 12.5
- main/xen: security fix for XSA-355
- community/drupal7: security upgrade to 7.75
- main/xen: CVE-2020-28368 assigned to XSA-351
- [3.11] community/containerd: update to 1.3.9
- main/ldb: upgrade to 2.0.12
- main/samba: security upgrade to 4.11.14
- main/samba: security upgrade to 4.11.16
- main/curl: fix CVE-2020-8231
- main/clamav: security upgrade to 0.102.4
- main/redis: fix CVE-2015-8080
- main/bluez: fix CVE-2020-27153
- main/bluez: fix CVE-2020-27153
- main/openldap: fix a few CVEs
- main/openldap: use local patch for CVE-2020-12243
- main/pcre: fix CVE-2020-14155
- main/cups: fix CVE-2019-8842 and CVE-2020-3898
- main/dovecot: fix CVE-2020-12673 and CVE-2020-12674
- main/mariadb-connector-c: fix CVE-2020-13249
- main/squid: add missing secfixes info
- main/squid: fix typo in CVE identifier
- main/nrpe: fix CVE-2020-6581 and CVE-2020-6582
- main/py3-django: fix CVE-2020-24583 and CVE-2020-24584
- main/curl: fix CVE-2020-8285 and CVE-2020-8286
- main/p11-kit: fix CVE-2020-29361 CVE-2020-29362 CVE-2020-29363
- main/mbedtls: upgrade to 2.16.9
- main/nrpe: revert fixes for CVE-2020-6581 and CVE-2020-6582
- main/nrpe: rebuild after revert
- main/openssl: security upgrade to 1.1.1i
- main/linux-lts: upgrade to 5.4.83
- community/jool-modules-lts: rebuild against kernel 5.4.83-r0
- community/virtualbox-guest-modules-lts: rebuild against kernel 5.4.83-r0
- community/wireguard-lts: upgrade to 1.0.20201112 / 5.4.83-r0
- main/drbd-lts: rebuild against kernel 5.4.83-r0
- main/xtables-adons-lts: rebuild against kernel 5.4.83-r0
- main/zfs-lts: rebuild against kernel 5.4.83-r0
- main/linux-rpi: upgrade to 5.4.83
- community/jool-modules-rpi: rebuild against kernel 5.4.83-r0
- community/wireguard-rpi: upgrade to 1.0.20201112 / 5.4.83-r0
- main/linux-rpi: upgrade to 5.4.84
- community/jool-modules-rpi: rebuild against kernel 5.4.84-r0
- community/wireguard-rpi: rebuild against kernel 5.4.84-r0
- main/linux-lts: upgrade to 5.4.84
- community/jool-modules-lts: rebuild against kernel 5.4.84-r0
- community/virtualbox-guest-modules-lts: rebuild against kernel 5.4.84-r0
- community/wireguard-lts: rebuild against kernel 5.4.84-r0
- main/drbd-lts: rebuild against kernel 5.4.84-r0
- main/xtables-addons-lts: rebuild against kernel 5.4.84-r0
- main/zfs-lts: rebuild against kernel 5.4.84-r0
- ===== release 3.11.7 =====
- main/knot: upgrade to 2.9.8
- community/autossh: fix source URL
- main/openjpeg: fix CVE-2020-27814, CVE-2020-27823 and CVE-2020-27824
- main/libmaxminddb: fix CVE-2020-28241
- main/xen: fix XSA-115
- main/xen: fix XSA-322
- main/xen: fix XSA-323
- main/xen: fix XSA-324
- main/xen: fix XSA-325
- main/xen: fix XSA-330
- main/xen: fix XSA-348
- main/xen: fix XSA-352
- main/xen: fix XSA-353
- main/xen: fix XSA-358
- main/xen: fix XSA-359
- community/gtk+3.0: remove demo files from main package
- main/tzdata: upgrade to 2020d
- main/tzdata: switch to fat format
- main/tzdata: upgrade to 2020f
- main/bind: add security patches
- main/nodejs: build with bundled libuv
- main/nodejs: security upgrade to 12.20.1
- main/ruby: patch CVE-2020-25613
- main/py3-yaml: fix CVE-2020-14343
- main/xen: add missing CVE info
- main/razor: fix license, manpage installation
- main/dnsmasq: security upgrade to 2.83
- main/xen: fix XSA-360
- main/esh: upgrade to 0.3.1
- main/dovecot: security upgrade to 2.3.13
- main/perl-datetime-timezone: upgrade to 2.47
- testing/libspatialite: fix source=
- main/doas: patch out PATH reset vulnerability
- main/doas: include secfixes for CVE-2019-25016
- main/sudo: patch CVE-2021-3156
- main/mariadb: security upgrade to 10.4.17
- main/tzdata: upgrade to 2021a
- main/mariadb: fix syntax error due to missing quote
- main/quagga: cherry pick ipsec SA counter overflow fix
- main/mariadb: fix stacktrace-t
- community/openjdk7: security upgrade to 2.6.24 (7u281)
- main/wpa_supplicant: fix CVE-2021-0326
- main/subversion: fix CVE-2020-17525
- [various]: fix secfixes comments
- main/screen: fix CVE-2021-26937
- main/screen: use better patch for CVE-2021-26937
- community/openjdk8: security upgrade to 3.17.1 (8.275.01)
- main/openssl: upgrade to 1.1.1j
- main/linux-lts: upgrade to 5.4.99
- community/jool-modules-lts: rebuild against kernel 5.4.99-r0
- community/virtualbox-guest-modules-lts: rebuild against kernel 5.4.99-r0
- community/wireguard-lts: rebuild against kernel 5.4.99-r0
- main/drbd-lts: upgrade to 9.0.27 / kernel 5.4.99-r0
- main/xtables-addons-lts: rebuild against kernel 5.4.99-r0
- main/zfs-lts: rebuild against kernel 5.4.99-r0
- main/python3: fix CVE-2021-3177
- main/python3: add reliability fix for test_nntplib
- main/drbd-lts: fix build on 32 bit architectures
- main/libbsd: add missing secfixes info
- main/redis: security upgrade to 5.0.11
- main/python3: disable test_threading on aarch64
- ===== release 3.11.8 =====
- main/postgresql: security upgrade to 12.6
- main/nodejs: security upgrade to 12.21.0
- community/firefox-esr: fix rust triplet detection
- main/gdk-pixbuf: add patch for CVE-2021-20240
- main/xen: fix XSA-364/CVE-2021-26933
- main/xen: CVE-2021-3308 assigned to XSA-360
- main/wpa_supplicant: patch CVE-2021-27803
- main/openjpeg: fix CVE-2020-27844