3.10 openjpeg
- main/samba: security upgrade to 4.10.5
- community/intel-ucode: upgrade to 20190618
- community/mutt: upgrade to 1.12.1
- main/bind: security upgrade to 9.14.3 (CVE-2019-6471)
- community/pdns: security upgrade to 4.1.10
- main/py-django: security upgrade to 1.11.21 (CVE-2019-12308)
- main/haproxy: upgrade to 2.0.1
- community/firefox-esr: security upgrade to 60.7.2 (CVE-2019-11708)
- main/postgresql: security upgrade to 11.4
- main/expat: security upgrade to 2.2.7 (CVE-2018-20843)
- community/docker: update to 18.09.7
- main/libvirt: security upgrade to 5.5.0
- community/patchwork: security fix for CVE-2019-13122
- main/irssi: security upgrade to 1.2.1 (CVE-2019-13045)
- main/bzip2: add patch for CVE-2019-12900
- main/apk-tools: cherry-pick fix for #10648
- main/linux-vanilla: upgrade to 4.19.57
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.57-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.57-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.57-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.57-r0
- main/drbd-vanilla: rebuild against kernel 4.19.57-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.57-r0
- main/zfs-vanilla: rebuild against kernel 4.19.57-r0
- testing/ipt-netflow-vanilla: rebuild against kernel 4.19.57-r0
- main/linux-rpi: upgrade to 4.19.57
- community/wireguard-rpi: rebuild against kernel 4.19.57-r0
- main/imagemagick: Fix install location for PerlMagick modules
- community/php7: add argon2 support
- community/php7: upgrade to 7.3.7
- community/evince: fix CVE-2019-11459
- main/tcpflow: backport fix for CVE-2018-18409
- main/tcpflow: fix secfixes comment
- main/linux-vanilla: upgrade to 4.19.58
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.58-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.58-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.58-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.58-r0
- main/drbd-vanilla: rebuild against kernel 4.19.58-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.58-r0
- main/zfs-vanilla: rebuild against kernel 4.19.58-r0
- main/linux-rpi: upgrade to 4.19.58
- community/wireguard-rpi: rebuild against kernel 4.19.58-r0
- main/heimdal: security fix for CVE-2019-12098
- main/heimdal: add missing patch
- main/squid: upgrade to 4.8 (CVE-2019-13345)
- main/raspberrypi-bootloader: upgrade to 1.20190620
- ==== relase 3.10.1 ====
- community/nextcloud: upgrade to 16.0.3
- main/irqbalance: fix missing socket dir
- community/zabbix: upgrade to 4.2.4
- main/avahi: fix CVE-2017-6519 and CVE-2018-1000845
- main/libxkbcommon: provide static library
- community/webkit2gtk: upgrade to 2.24.2
- main/keyutils: link libkeyutils.so to ../../lib/libkeyutils.so.1
- community/webkit2gtk: upgrade to 2.24.3 and enable on arm
- community/webkit2gtk: enable on x86
- main/mozjs60: security upgrade to 60.7.2
- main/alpine-git-mirror-syncd: security upgrade to 0.3.1
- community/docker: upgrade to 18.09.8
- community/libraw: add missing CVEs to secfixes comment
- community/openexr: fix CVE-2018-18444
- community/gvfs: security upgrade to 1.40.2
- main/py-django: security upgrade to 1.11.22 (CVE-2019-12781)
- main/freeswitch: upgrade to 1.8.7
- main/libcroco: fix a few CVEs
- main/mozjs60: upgrade to 60.8.0
- main/dmvpn: upgrade to 1.1.0
- community/libosinfo: fix CVE-2019-13313
- testing/docker-compose: add shell completion subpackages
- testing/docker-compose: upgrade to 1.24.1
- testing/docker-compose: move to community
- community/docker-compose: update checksums
- testing/py3-cached-property: move to community
- testing/py3-dockerpty: move to community
- testing/py3-pysocks: move to community
- testing/py3-texttable: move to community
- main/patch: fix CVE-2019-13636
- main/zeromq: security upgrade to 4.3.2
- main/zeromq: delete the -static subpackage
- community/sox: backport a few CVEs
- main/libtasn1: security upgrade to 4.14
- community/firefox-esr: security upgrade to 60.8.0
- community/imagemagick6: security upgrade to 6.9.10-53
- community/imagemagick6: security upgrade to 6.9.10.55
- main/haproxy: upgrade to 2.0.3
- main/sdl2: security upgrade to 2.0.10
- main/libgcrypt: fix CVE-2019-12904
- community/exim: security upgrade to 4.92.1
- community/vlc: fix CVE-2019-13602
- main/libebml: add secfixes comment for CVE-2019-13615
- main/redis: add secfixes comment
- main/kamailio: fix memleak in mohqueue module
- community/wireshark: security upgrade to 3.0.3
- community/zabbix: upgrade to 4.2.5
- community/esh: upgrade to 0.3.0
- community/pdns: security upgrade to 4.1.11
- community/pdns: add missing schema file
- community/php7: security upgrade 7.3.8 - CVE-2019-11041 - CVE-2019-11041
- main/ansible: security upgrade to 2.8.3 (CVE-2019-10156)
- community/vault: security upgrade to 1.1.1
- main/subversion: security upgrade to 1.12.2
- main/py-django: security upgrade to 1.11.23
- main/mariadb: security upgrade to 10.3.17
- main/musl: security fix in i386 math asm (CVE-2019-14697)
- community/sox: fix secfixes comment
- main/patch: security fixes
- community/libreoffice: security upgrade to 6.2.5.2
- main/haproxy: upgrade to 2.0.4
- main/postgresql: security upgrade to 11.5
- community/exempi: security upgrade to 2.5.1
- community/openjdk8: add missing nss dependency to -jre-base
- main/pango: security fix (CVE-2019-1010238)
- main/ghostscript: fix CVE-2019-10216
- main/imagemagick: security upgrade to 7.0.8-53
- main/imagemagick: security upgrade to 7.0.8-56
- main/imagemagick: security upgrade to 7.0.8-58
- main/xen: security upgrade to 4.12.1
- main/nginx: security upgrade to 1.16.1
- main/linux-rpi: upgrade to 4.19.59
- community/wireguard-rpi: rebuild against kernel 4.19.66-r0
- main/linux-vanilla: upgrade to 4.19.60
- main/linux-vanilla: add usb module for sun4i boards fixes #10677 (closed)
- main/linux-vanilla: upgrade to 4.19.62
- main/linux-vanilla: Enable CONFIG_SND_HDA_RECONFIG
- main/linux-vanilla: upgrade to 4.19.66
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.66-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.66-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.66-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.66-r0
- main/drbd-vanilla: rebuild against kernel 4.19.66-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.66-r0
- main/zfs-vanilla: rebuild against kernel 4.19.66-r0
- testing/ipt-netflow-vanilla: rebuild against kernel 4.19.66-r0
- main/libmad: fix CVE-2017-8372, CVE-2017-8373, CVE-2017-8374
- main/sdl: fix multiple vulnerabilities
- community/ruby-nokogiri: security upgrade to 1.10.4
- community/imagemagick6: upgrade to 6.9.10.60
- community/go: security upgrade to 1.12.8
- community/ruby-nokogiri: rebuild against libxml 2.9.9
- main/wpa_supplicant: security fix (CVE-2019-13377)
- community/znc: security upgrade to 1.7.4
- community/elogind: depend on shadow
- main/hostapd: security fixes (CVE-2019-13377)
- community/alpine-make-rootfs: upgrade to 0.3.1
- community/nextcloud: upgrade to 16.0.4
- community/ffmpeg: security upgrade to 4.1.4
- community/ffmpeg: remove duplicate secfixes
- main/linux-vanilla: upgrade to 4.19.67
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.67-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.67-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.67-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.67-r0
- main/drbd-vanilla: rebuild against kernel 4.19.67-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.67-r0
- main/zfs-vanilla: rebuild against kernel 4.19.67-r0
- testing/ipt-netflow-vanilla: rebuild against kernel 4.19.67-r0
- main/cups: security upgrade to 2.2.12
- main/linux-rpi: upgrade to 4.19.67
- community/wireguard-rpi: rebuild against kernel 4.19.67-r0
- main/raspberrypi-bootloader: upgrade to 1.20190718
- main/apache2: upgrade to 2.4.41
- ==== release 3.10.2 ====
- community/libreoffice: security upgrade to 6.2.6.2
- main/freeradius: security fix (CVE-2019-10143)
- community/miniupnpd: rebuild against iptables 1.8
- main/collectd: rebuild against iptables 1.8
- main/kamailio: upgrade to 5.2.4
- main/libx11: provide static libraries in libx11-static
- community/vlc: security upgrade to 3.0.8
- main/flite: fix underlinking
- main/tzdata: upgrade to 2019b
- main/nghttp2: upgrade to 1.39.1
- main/nghttp2: security upgrade to 1.39.2
- main/haproxy: upgrade to 2.0.5
- main/ansible: security upgrade to 2.8.4
- main/wavpack: fix a few CVEs
- main/awall: upgrade to 1.6.11
- main/lua-bit32: fix upgrade from lua-bitlib
- main/openldap: security upgrade to 2.4.48
- main/nodejs: security upgrade to 10.16.3
- main/tiff: security fix (CVE-2019-14973)
- community/tvheadend: upgrade to 4.2.8
- main/dovecot: upgrade to 2.3.7.1
- main/dovecot: security upgrade to 2.3.7.2
- community/zabbix: upgrade to 4.2.6
- community/php7: security upgrade to 7.3.9 (CVE-2019-13224)
- community/webkit2gtk: add secfixes
- community/cesnet-tcs-cli: upgrade to 0.1.2
- main/irssi: security upgrade to 1.2.2
- main/postgresql: fix psql segmentation fault
- community/cesnet-tcs-cli: upgrade to 0.1.3
- main/clamav: upgrade to 0.101.4
- main/asterisk: rebuild against pjproject 2.8
- community/firefox-esr: security update to 60.9.0
- main/lmdb: upgrade to 0.9.24
- main/ldb: upgrade to 1.5.5
- main/samba: upgrade to 4.10.8
- main/varnish: security upgrade to 6.2.1
- [3.10] community/containerd: upgrade to 1.2.9
- community/exim: security upgrade to 4.92.2
- main/awall: upgrade to 1.6.12
- main/ulogd: include logrotate config
- main/dmvpn: upgrade to 1.2.0
- community/libreoffice: security upgrade to 6.2.7.1
- main/acf-core: upgrade to 0.21.2
- main/imap: SNI patch required for TLS 1.3
- main/openssl: security upgrade to 1.1.1d
- main/expat: fix CVE-2019-15903
- community/firefox-esr: update secinfo
- main/sdl2_image: upgrade to 2.0.5
- main/sdl2_image: security upgrade to 2.0.5
- main/ghostscript: add security patches
- main/ghostscript: security fix (CVE-2019-14817)
- main/asterisk: security fixes
- main/curl: security upgrade to 7.66.0
- main/hostapd: security fix (CVE-2019-16275)
- main/wpa_supplicant: security fix (CVE-2019-16275)
- Revert "community/firefox-esr: update secinfo"
- main/acf-jquery: upgrade to 0.4.3
- main/acf-core: upgrade to 0.21.3
- main/expat: security upgrade to 2.2.8
- main/haproxy: upgrade to 2.0.6
- community/milter-greylist: start daemon after network
- main/poppler: security fix (CVE-2019-9959)
- main/poppler: add secinfo
- main/nfdump: security upgrade to 1.6.18
- community/phpmyadmin: security upgrade to 4.9.1 - CVE-2019-12922
- community/nextcloud: upgrade to 16.0.5
- main/lxc: add init.lxc.static
- main/linux-vanilla: increase number of CPUs
- linux-vanilla: enable xfrm-interface for x86 and x86_64 linux-virt
- main/linux-vanilla: enable dm-writecache
- main/linux-vanilla: upgrade to 4.19.75
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.75-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.75-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.75-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.75-r0
- main/drbd-vanilla: rebuild against kernel 4.19.75-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.75-r0
- main/zfs-vanilla: rebuild against kernel 4.19.75-r0
- testing/ipt-netflow-vanilla: rebuild against kernel 4.19.75-r0
- main/mosquitto: fix CVE-2019-11779
- main/linux-rpi: upgrade to 4.19.75
- community/wireguard-rpi: rebuild against kernel 4.19.75-r0
- community/milter-greylist: typo in init script
- gitlab-ci: enable for 3.10-stable
- main/linux-rpi: upgrade to 4.19.76
- community/wireguard-rpi: rebuild against kernel 4.19.76-r0
- main/python3: upgrade to 3.7.4 and enable optimizations
- main/haproxy: upgrade to 2.0.7
- community/openjdk8: security upgrade to 8.222.10
- main/postfix: upgrade to 3.4.7
- community/intel-ucode: upgrade to 20190918
- community/php7: upgrade to 7.3.10
- main/linux-vanilla: upgrade to 4.19.76
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.76-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.76-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.76-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.76-r0
- main/drbd-vanilla: rebuild against kernel 4.19.76-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.76-r0
- main/zfs-vanilla: rebuild against kernel 4.19.76-r0
- main/libpcap: upgrade to 1.9.1
- main/tcpdump: upgrade to 4.9.3
- community/zoneminder: add missing symlink and deps
- main/openssl: Fix openssl secfix version number
- communuty/jenkins: security upgrade to 2.199
- main/multipath-tools: fix udev location
- main/multipath-tools: update checksums
- main/dmvpn: upgrade to 1.2.1
- main/linux-vanilla: enable CONFIG_BLK_DEV_THROTTLING
- main/linux-vanilla: upgrade to 4.19.78
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.78-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.78-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.78-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.78-r0
- main/drbd-vanilla: rebuild against kernel 4.19.78-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.78-r0
- main/zfs-vanilla: rebuild against kernel 4.19.78-r0
- testing/ipt-netflow-vanilla: rebuild against kernel 4.19.78-r0
- community/ceph: security upgrade to 14.2.3
- community/httpie: security upgrade to 1.0.3
- community/exim: patch CVE-2019-16928
- community/wireshark: security upgrade to 3.0.4
- community/wireshark: fix source=
- main/sqlite: fix CVE-2019-16168
- main/ruby: security upgrade to 2.5.7
- main/libgcrypt: security upgrade to 1.8.5
- main/libgcrypt: fix typo in -static description
- gitlab-ci: add build job for aarch64
- gitlab-ci: temporarily disable s390x
- main/faad2: security upgrade to 2.9.0
- scripts/bootstrap.sh: fix openssh bootstrap
- main/openssh: fix segfault with VerifyHostKeyDNS=yes
- main/openssh: security upgrade to 8.1p1
- main/openssh: fix build
- community/uacme: upgrade to 1.0.20
- community/mumble: upgrade to stable 1.3.0 release
- community/uacme: backport patch fixing uacme.sh
- main/bacula: upgrade to 9.4.4
- main/bacula: create bacula user for client package
- main/python3: security upgrade to 3.7.5 (CVE-2019-16056)
- main/bacula: use root as rundir owner for bacula-client
- main/libssh2: security upgrade to 1.9.0 (CVE-2019-13115)
- community/go: upgrade to 1.12.10
- main/libssh2: fix for CVE-2019-17498
- main/python3: reduce number of unit tests for PGO
- main/python3: add CVE-2019-16935 to secfixes comment
- community/imagemagick6: upgrade to 6.9.10.62
- community/imagemagick6: security upgrade to 6.9.10.68
- main/tzdata: upgrade to 2019c
- main/mariadb: upgrade to 10.3.18
- main/mariadb: fix build by enable pam
- main/linux-rpi: upgrade to 4.19.79
- main/zfs: upgrade to 0.8.2
- main/zfs-vanilla: rebuild against ZFS 0.8.2
- main/linux-vanilla: upgrade to 4.19.79
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.79-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.79-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.79-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.79-r0
- main/drbd-vanilla: rebuild against kernel 4.19.79-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.79-r0
- main/zfs-vanilla: rebuild against kernel 4.19.79-r0
- testing/ipt-netflow-vanilla: rebuild against kernel 4.19.79-r0
- main/e2fsprogs: fix CVE-2019-5094
- main/openresolv: upgrade to 3.9.2
- main/openresolv: add compat symlinks
- main/sshguard: fix handling of shutdown signal
- scripts/genrootfs.sh: fix permissions of / in minirootfs
- community/chromium: upgrade to 76
- community/chromium: upgrade to 76.0.3809.132
- community/chromium: upgrade to 77.0.3865.75
- community/chromium: fix build on armv7
- community/chromium: upgrade to 77.0.3865.90
- community/chromium: upgrade to 77.0.3865.120
- main/python3: disable test threading on arm*
- community/go: upgrade to 1.12.11
- community/go: update secfixes comments
- main/linux-vanilla: upgrade to 4.19.80
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.80-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.80-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.80-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.80-r0
- main/drbd-vanilla: rebuild against kernel 4.19.80-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.80-r0
- main/zfs-vanilla: rebuild against kernel 4.19.80-r0
- testing/ipt-netflow-vanilla: rebuild against kernel 4.19.80-r0
- community/go: upgrade to 1.12.12
- main/linux-rpi: upgrade to 4.19.80
- community/wireguard-rpi: rebuild against kernel 4.19.80-r0
- gitlab-ci: revert temporarily disable s390x
- gitlab-ci: update to latest changes
- main/raspberrypi-bootloader: upgrade to 1.20190925
- ==== release 3.10.3 ====
- main/sdl2_image: security fix for CVE-2019-13616.
- main/qemu: upgrade to 4.0.1
- main/rsyslog: fix CVE-2019-17041 and CVE-2019-17042
- main/bind security upgrade to 9.14.7 (CVE-2019-6475, CVE-2019-6476)
- main/libssh2: Update release version for CVE patch
- community/php7: security upgrade to 7.3.11 - CVE-2019-11043
- main/busybox: fix behavior of ln -T
- main/nginx: fix broken subpkg -mod-http-geoip2
- main/nginx: fix support for more so libs per module
- main/nmap: fix CVE-2018-15173 and CVE-2017-18594
- main/file: fix CVE-2019-18218
- community/imagemagick6: upgrade to 6.9.10.69
- community/zziplib: fix CVE-2018-16548 and CVE-2018-17828
- main/unbound: fix CVE-2019-16866
- main/aspell: fix CVE-2019-17544
- main/libxslt: fix CVE-2019-18197
- main/libarchive: fix CVE-2019-18408
- main/tiff: fix CVE-2019-17546
- main/libvncserver: fix CVE-2019-15681
- community/nextcloud: upgrade to 16.0.6
- main/fribidi: fix CVE-2019-18397
- main/squid: security fix (CVE-2019-18679)
- main/linux-firmware: upgrade to 20191022
- community/intel-ucode: upgrade to 20191112
- main/oniguruma: security upgrade to 6.9.3
- main/ldb: upgrade to 1.5.6
- main/samba: security upgrade to 4.10.10
- main/xen: fix secfixes info typo
- main/unbound: fix secfixes comment
- community/zziplib: fix secfixes comment
- community/containerd: fix whitespace damage in secfixes comment
- main/freetds: security fix (CVE-2019-13508)
- main/libjpeg-turbo: security upgrade to 2.0.3
- main/uwsgi: set --wait for start-stop-daemon to 200 by default
- main/uwsgi: allow to override retry from confd file
- main/mqtt-exec: let libmosquitto generate client id
- community/intel-ucode: upgrade to 20191113
- main/kamailio: upgrade to 5.2.5
- main/postgresql: upgrade to 11.6
- community/intel-ucode: upgrade to 20191115
- main/file: fix CVE-id
- community/postgresql-bdr-extension0.9: downgrade to 0.9.0 to maintain compatibility with earlier Alpine versions
- community/cesnet-tcs-cli: upgrade to 0.2.0
- main/freeradius: upgrade to 3.0.20
- main/freeradius: fix permissions of certs
- main/ghostscript: patch CVE-2019-1486
- main/unbound: fix CVE-2019-18934
- main/sdl_image: fix CVE-2019-13616
- main/sdl: fix CVE-2019-13616
- community/libcaca: fix a few CVEs
- community/libcaca: fix build
- main/haproxy: upgrade to 2.0.9
- main/ansible: security upgrade to 2.8.6
- main/bind: upgrade to 9.14.8
- main/faac: upgrade to 1.30
- main/alpine-conf: fix lbu exit codes on error
- community/knot: upgrade to 2.8.4
- community/knot: take maintainership
- main/nss: security upgrade to 3.44.3
- community/phpmyadmin: security upgrade to 4.9.2
- main/vala: upgrade to 0.44.11
- community/libsoup: fix CVE-2019-17266
- community/nq: backport from edge for infra
- community/py-psutil: fix CVE-2019-18874
- main/haproxy: upgrade to 2.0.10
- main/tiff: fix CVE-2019-6128
- github: add pull request template
- community/knot-resolver: fix segfault in stats module
- main/unbound: auto-create directory for control-interface
- main/asterisk: security fixes
- main/mariadb: security upgrade to 10.3.20
- main/unbound: fix init script to not potentially modify wrong directory
- main/unbound: remove problematic logic for creating dir for control-interface
- main/oniguruma: security upgrade to 6.9.4
- main/ulogd: fix path in logrotate script
- main/git: security upgrade to 2.22.2
- main/samba: security upgrade to 4.10.11
- main/haproxy: upgrade to 2.0.11
- community/stunnel: upgrade to 5.56
- main/sqlite: security fixes (CVE-2019-19242, CVE-2019-19244)
- main/gnupg: security upgrade to 2.2.19 (CVE-2019-14855)
- main/imagemagick: security upgrade to 7.0.8.68
- main/dnsmasq: fix CVE-2019-14834
- main/dnsmasq: bump pkgrel
- community/wireshark: security upgrade to 3.0.7 (CVE-2019-19553)
- community/nextcloud: upgrade to 16.0.7
- main/net-snmp: broken ErrorMsg at ucd-snmp
- community/clsync: upgrade to 0.4.3
- community/clsync: add init script
- community/php7: security upgrade to 7.3.13
- community/cacti: security upgrade to 1.2.8 (CVE-2019-17358)
- community/xdg-dbus-proxy: new aport, required for webkit2gtk
- community/webkit2gtk: security upgrade to 2.26.2
- main/cyrus-sasl: fix CVE-2019-19906
- main/libxslt: fix CVE-2019-13117, CVE-2019-13118
- main/clamav: upgrade to 0.101.5
- community/webkit2gtk: disable on s390x, GCC 8.x crashes with ICE on s390x
- community/atril: disable on s390x due to webkit2gtk
- community/eog: disable on s390x due to webkit2gtk
- community/glade: remove support for webkit2gtk on s390x
- community/gnome-online-accounts: disable on s390x due to webkit2gtk
- community/gvfs: disable on s390x due to webkit2gtk
- community/libgdata: disable on s390x due to webkit2gtk
- community/midori: disable on s390x due to webkit2gtk
- community/shotwell: disable on s390x due to webkit2gtk
- main/mkinitfs: backport rpirtc support
- community/drupal7: security upgrade to 7.69
- main/haproxy: upgrade to 2.0.12
- main/libssh: security upgrade to 0.8.8 (CVE-2019-14889)
- community/remmina: rebuild against libssh-0.8.8
- main/exiv2: backport fix for CVE-2019-17402
- main/py-django: security upgrade to 1.11.27 (CVE-2019-19844)
- main/openssl: install man pages in different section
- main/openssl: fix CVE-2019-1551
- main/spamassassin: security upgrade to 3.4.3 (CVE-2018-11805, CVE-2019-12420)
- main/putty: security upgrade to 0.73
- main/xen: security fixes
- main/libxml2: security fix for CVE-2019-19956. Fixes #11098 (closed)
- main/squid: add secinfo
- main/squid: add secinfo
- community/knot: upgrade to 2.8.5
- community/py3-distro: new aport
- community/salt: fix python3.8 incompattibilities
- main/hunspell: fix CVE-2019-16707
- main/libjpeg-turbo: security upgrade to 2.0.4 (CVE-2019-2201)
- main/ulogd: fix logrotate pattern
- community/terraform: upgrade to 0.12.6
- main/python2: security fix (CVE-2019-16935)
- main/xen: security upgrade to 4.12.2
- main/nginx: security fix (CVE-2019-20372)
- main/ansible: security upgrade to 2.8.8 CVE-2019-14864 CVE-2019-14904 CVE-2019-14905
- main/e2fsprogs: security upgrade to 1.45.5 (CVE-2019-5188)
- main/linux-vanilla: upgrade to 4.19.97
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.97-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.97-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.97-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.97-r0
- main/drbd-vanilla: rebuild against kernel 4.19.97-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.97-r0
- main/zfs-vanilla: rebuild against kernel 4.19.97-r0
- main/linux-rpi: upgrade to 4.19.97
- community/wireguard-rpi: rebuild against kernel 4.19.97-r0
- main/linux-rpi: upgrade to 4.19.98
- community/wireguard-rpi: rebuild against kernel 4.19.98-r0
- main/linux-vanilla: upgrade to 4.19.98
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.98-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.98-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.98-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.98-r0
- main/drbd-vanilla: rebuild against kernel 4.19.98-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.98-r0
- main/zfs-vanilla: rebuild against kernel 4.19.98-r0
- ===== release 3.10.4 =====
- main/alpine-conf: unbreak lbu
- main/freeradius: fix segfault in process request_running()
- main/samba: security upgrade to 4.10.12
- community/wireshark: security upgrade to 3.0.8 (CVE-2020-7045)
- community/php7: security upgrade to 7.3.14 (CVE-2020-7059 CVE-2020-7060)
- community/openjdk8: update to IcedTea 3.14.0 / OpenJDK 8u232
- community/openjdk8: security upgrade to 8.242.08
- main/py-django: security upgrade to 1.11.28
- main/sudo: fix CVE-2019-14287
- main/sudo: fix CVE-2019-18634
- main/openjpeg: fix path for cmake
- main/openjpeg: cleanup patches and update url
- main/openjpeg: secfixes (CVE-2020-6851,CVE-2020-8112)
- main/nodejs: security upgrade to 10.19.0
- main/postgresql: security upgrade to 11.7
- main/dmvpn: various fixes
- main/faac: fix secfixes
- main/ncurses: fix automatic dependency due to symlinks
- main/putty: depend on ncurses-terminfo
- community/xterm: depend on ncurses-terminfo
- main/cvs: security upgrade to 1.12.12
- main/ncurses: re-arrange terminfo contents
- {main,community,testing}: make terminals depend on ncurses-terminfo-base
- main/ncurses: move screen-256color to ncurses-terminfo-base
- main/librsvg: security upgrade to 2.40.21
- community/cesnet-tcs-cli: fix openssl command for generating EC key
- community/cesnet-tcs-cli: fix openssl command for generating EC key (again)
- community/live-media: fixed symbol-not-found issue
- community/vlc: bump pkgrel due to live-media upgrade
- community/mpv: bump pkgrel due to live-media upgrade
- main/py-django: security upgrade to 1.11.29
- main/ppp: secfix for radius and EAP
- main/libarchive: fix CVE-2020-19221 and CVE-2020-9308
- main/iptables: restore lost init.d script for ebtables
- main/gst-plugins-base: add secfixes
- main/lz4: fix CVE-2019-17543
- main/ansible: security upgrade to 2.8.9
- community/tor: security upgrade to 0.3.5.10
- main/bluez: fix CVE-2020-0556
- main/icu: fix CVE-2020-10531
- main/libmspack: fix CVE-2019-1010305
- main/unzip: fix CVE-2019-13232
- community/nextcloud: upgrade to 16.0.9
- main/unzip: actually fix CVE-2019-13232
- main/screen: fix CVE-2020-9366
- main/screen: fix patch for CVE-2020-9366
- main/gnutls: fix GNUTLS-SA-2020-03-31
- main/ruby: upgrade to 2.5.8
- main/apache2: security upgrade to 2.4.43
- main/squid: security upgrade to 4.10
- main/haproxy: upgrade to 2.0.13
- main/haproxy: security upgrade to 2.0.14
- main/gnutls: add CVE secfixes info
- main/mbedtls: security upgrade to 2.16.5
- main/xen: add missing secfixes info
- community/ffmpeg: security upgrade to 4.1.5
- main/mariadb: security upgrade to 10.3.22
- main/mariadb: disable on armhf and armv7
- main/gd: patch CVE-2018-14553 and CVE-2019-11038
- main/libssh: security upgrade to 0.8.9
- main/ca-certificates: upgrade to 20191127
- main/git: security upgrade to 2.22.3
- Revert "main/mariadb: disable on armhf and armv7"
- main/mcpp: fix CVE-2019-14274
- main/ansible: security upgrade to 2.8.11
- community/tor: disable package pending security review
- community/tor: re-enable and rebuild to avoid bogus IDS warning
- main/xen: fix various security issues
- main/openssl: security upgrade to 1.1.1g (CVE-2020-1967)
- main/git: security upgrade to 2.22.4
- main/linux-vanilla: upgrade to 4.19.117
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.117-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.117-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.117-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.117-r0
- main/drbd-vanilla: rebuild against kernel 4.19.117-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.117-r0
- main/zfs-vanilla: rebuild against kernel 4.19.117-r0
- testing/ipt-netflow-vanilla: rebuild against kernel 4.19.117-r0
- main/linux-vanilla: upgrade to 4.19.118
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.118-r0
- community/wireguard-vanilla: rebuild against kernel 4.19.118-r0
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.118-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.118-r0
- main/drbd-vanilla: rebuild against kernel 4.19.118-r0
- main/xtables-addons-vanilla: rebuild against kernel 4.19.118-r0
- main/zfs-vanilla: rebuild against kernel 4.19.118-r0
- testing/ipt-netflow-vanilla: rebuild against kernel 4.19.118-r0
- ===== release 3.10.5 =====
- community/networkmanager: upgrade to 1.18.6
- main/ntfs-3g: patch CVE-2019-9755
- community/graphicsmagick: upgrade to 1.3.33
- main/tzdata: upgrade to 2020a
- main/python2: security upgrade to 2.7.18
- community/python2-tkinter: security upgrade to 2.7.17
- community/python2-tkinter: security upgrade to 2.7.18
- community/ceph: upgrade to 14.2.3, assume maintainership
- community/ceph: security upgrade to 14.2.7
- community/ceph: upgrade to 14.2.8
- community/ceph: security upgrade to 14.2.9
- community/salt: upgrade to 2019.2.1
- community/salt: upgrade to 2019.2.2
- community/salt: reabse patches
- community/salt: upgrade to 2019.2.4
- main/openldap: fix CVE-2020-12243
- main/sqlite: security fix (CVE-2020-11655)
- main/libvirt: security fix for CVE-2020-12430
- main/mariadb: security upgrade to 10.3.23
- main/libexif: security upgrade to 0.6.22
- main/unbound: fix CVE-2020-12662 and CVE-2020-12663
- main/bind: security upgrade to 9.14.12
- main/iproute2: fix CVE-2019-20795
- community/pdns-recursor: security upgrade to 4.1.16
- main/dovecot: security upgrade to 2.3.10.1
- main/perl-mozilla-ca: upgrade to 20200520
- main/fail2ban: fix permissions on .egg-info
- main/fail2ban: fix tests
- main/mbedtls: security upgrade to 2.16.6
- main/json-c: fix CVE-2020-12762
- main/busybox: fix ip -oneline link
- main/python3: security upgrade to 3.7.7
- main/ca-certificates: fix bundle with certs without newline
- main/ca-certificates: remove expired certificate
- main/dbus: fix CVE-2020-12049
- main/ca-certificates: use source package from gitlab
- main/nghttp2: fix CVE-2020-11080
- main/gnutls: security upgrade to 3.6.14 (CVE-2020-13777)
- main/gnutls: add corresponding GNUTLS-SA to CVE-2020-13777
- community/intel-ucode: upgrade to 20200609
- main/axel: fix CVE-2020-13614
- main/hostapd: fix CVE-2020-12695
- community/nextcloud: upgrade to 16.0.10
- main/ldb: upgrade to 1.5.7
- main/samba: security upgrade to 4.10.15
- main/xen: security upgrade to 4.12.3
- main/xen: fix XSA-320
- community/intel-ucode: upgrade to 20200616
- main/sprunge: use https when possible
- main/perl: security upgrade to 5.28.3 (CVE-2020-10543,CVE-2020-10878,CVE-2020-12723)
- main/dropbear: backport security fixes
- main/libjpeg-turbo: fix CVE-2020-13790
- main/ngircd: fix CVE-2020-14148
- main/ruby: correct wrong CVE number in secfixes
- main/xen: remove outdated patch files
- main/xen: security fixes for XSA-317, XSA-319, XSA-321, XSA-327 and XSA-328
- community/opam: upgrade to 2.0.7
- community/ffmpeg: security upgrade to 4.1.6
- main/python3: fix CVE-2020-14422
- main/smokeping: needs ttf-dejavu
- main/hylafaxplus: fix CVE-2020-15396 and CVE-2020-15397
- main/libx11: security upgrade to 1.6.10
- main/xorgproto: adapt to libx11 >= 1.6.9
- main/xorg-server: fix CVE-2020-14347
- main/patch: add missing CVE to secfixes
- main/spamassassin: update secfixes and url
- main/spamassassin: security upgrade to 3.4.4
- main/knock: upgrade to 0.8.1
- community/openjdk7: security upgrade to 7.231.2.6.19
- community/openjdk7: security upgrade to 7.241.2.6.20
- community/openjdk7: security upgrade to 7.251.2.6.21
- community/openjdk7: security upgrade to 7.261.2.6.22
- community/openjdk8: security upgrade to 8.252.09
- main/apache2: security upgrade to 2.4.46
- main/busybox: add secfixes comment for CVE-2018-1000500
- main/libvirt: security fix for CVE-2019-20485
- main/chrony: security upgrade to 3.5.1
- main/libx11: security upgrade to 1.6.12
- main/ldb: upgrade to 1.5.8
- main/samba: security upgrade to 4.10.17
- community/exim: remove dup CVE-2018-6789 in secfixes comment
- main/gnutls: security upgrade to 3.6.15
- main/postgresql: security upgrade to 11.9
- main/zeromq: security upgrade to 4.3.3
- main/xen: security fix for CVE-2020-14364/XSA-335
- main/libssh: fix CVE-2020-16135
- main/curl: fix CVE-2020-8169 and CVE-2020-8177
- main/libxml2: fix CVE-2020-24977
- main/openjpeg: fix CVE-2019-12973 and CVE-2020-15389
- main/perl-dbi: security upgrade to 1.643
- main/xen: security fixes for XSA-333, XSA-334, XSA-336, XSA-337, XSA-338, XSA-339, XSA-340, XSA-342, XSA-343 and XSA-344
- community/wireshark: security upgrade to 3.0.14
- main/ansible: security upgrade to 2.8.15
- main/mbedtls: security upgrade to 2.16.8
- main/samba: security upgrade to 4.10.18
- main/mariadb: security upgrade to 10.3.25
- community/pdns: security upgrade to 4.1.14
- community/nextcloud: upgrade to 16.0.11
- main/oniguruma: fix CVE-2020-26159
- main/ansible: upgrade to 2.8.16
- main/putty: upgrade to 0.74 (CVE-2020-14002)
- main/tzdata: upgrade to 2020b
- main/tzdata: upgrade to 2020c
- main/freetype: fix CVE-2020-15999
- main/ghostscript: clean up duplicate secfixes comment
- community/firefox: remove duplicate CVE in secfixes comment
- main/lame: remove duplicates in secfixes comment
- main/sdl: remove duplicate CVE in secfixes comment
- community/wireshark: fix secfixes comment
- main/samba: remove duplicate CVE in secfixes comment
- main/sqlite: fix secfixes comment
- main/hostapd: remove duplicate CVE in secfixes comment
- main/libsndfile: remove dulicate CVE secfixes comment
- main/libvorbis: remove duplicate CVE in secfixes comment
- main/wpa_supplicant: remove CVE dupes in secfixes comment
- Revert "main/wpa_supplicant: add secinfo"
- main/busybox: fix duplicate CVE in secfixes comment
- main/rdesktop: fix duplicate CVEs in secfixes comment
- main/unbound: fix duplicate CVEs in secfixes comment
- main/xorg-server: fix various CVEs
- main/perl-datetime-timezone: upgrade to 2.36
- main/perl-datetime-timezone: upgrade to 2.37
- main/perl-datetime-timezone: upgrade to 2.38
- main/perl-datetime-timezone: upgrade to 2.39
- main/perl-datetime-timezone: upgrade to 2.41
- main/perl-datetime-timezone: upgrade to 2.42
- main/perl-datetime-timezone: upgrade to 2.43
- community/php7-pecl-timezonedb: add check()
- community/php7-pecl-timezonedb: format check()
- community/php7-pecl-timezonedb:upgrade to 2019.2
- community/php7-pecl-timezonedb: upgrade to 2019.3
- community/php7-pecl-timezonedb: upgrade to 2020.1
- community/php7-pecl-timezonedb: fix license and improve
- community/php7-pecl-timezonedb: upgrade to 2020.2
- community/php7-pecl-timezonedb: upgrade to 2020.3
- community/php7-pecl-timezonedb: upgrade to 2020.4
- main/squid: security upgrade to 4.13
- main/tmux: fix CVE-2020-27347
- community/intel-ucode: security upgrade to 20201110
- community/intel-ucode: security upgrade to 20201112
- community/tor: security upgrade to 0.3.5.12
- main/musl: security fix for CVE-2020-28928
- main/tzdata: switch to fat format
- main/krb5: security upgrade to 1.17.2
- main/tcpdump: fix CVE-2020-8037
- main/postgresql: security upgrade to 11.10
- main/xen: security upgrade to 4.12.4
- main/xen: security fix for XSA-351
- main/xen: security fix for XSA-355
- main/curl: fix CVE-2020-8231
- main/bluez: fix CVE-2020-27153
- main/redis: fix CVE-2015-8080
- main/openldap: fix a few CVEs
- main/openldap: use local patch for CVE-2020-12243
- main/pcre: fix CVE-2020-14155
- main/cups: fix CVE-2019-8842 and CVE-2020-3898
- main/dovecot: fix CVE-2020-12673 and CVE-2020-12674
- main/mariadb-connector-c: fix CVE-2020-13249
- main/squid: add missing secfixes info
- main/squid: fix wrong CVE identifier
- main/nrpe: fix CVE-2020-6581 and CVE-2020-6582
- main/jbig2dec: fix CVE-2020-12268
- main/py-django: fix CVE-2020-24583 and CVE-2020-24584
- main/curl: fix CVE-2020-8285 and CVE-2020-8286
- main/p11-kit: fix CVE-2020-29361 CVE-2020-29362 CVE-2020-29363
- main/mbedtls: upgrade to 2.16.9
- main/nrpe: revert fixes for CVE-2020-6581 and CVE-2020-6582
- main/nrpe: rebuild after revert
- main/openssl: security upgrade to 1.1.1i
- community/autossh: fix source URL
- main/openjpeg: fix CVE-2020-27814, CVE-2020-27823 and CVE-2020-27824
- main/libmaxminddb: fix CVE-2020-28241
- main/tzdata: upgrade to 2020d
- main/tzdata: switch to fat format
- main/tzdata: upgrade to 2020f
- main/bind: add security patches
- main/ruby: patch CVE-2020-25613
- main/xen: add missing CVE info
- main/razor: fix license, manpage installation
- main/dnsmasq: security upgrade to 2.83
- main/dovecot: security upgrade to 2.3.13
- main/doas: security upgrade to 6.6.1
- community/doas: include security fixes for CVE-2019-25016
- main/redis: security upgrade to 5.0.10
- main/mariadb: security upgrade to 10.3.27
- community/openjdk7: security upgrade to 2.6.24 (7u281)
- main/wpa_supplicant: fix CVE-2021-0326
- main/subversion: fix CVE-2020-17525
- main/screen: fix CVE-2021-26937
- community/graphicsmagick,zabbix: updated security fixes description to secfixes
- main/collectd,libssh2: updated security fixes description to secfixes
- main/screen: use better patch for CVE-2021-26937
- community/openjdk8: security upgrade to 3.17.1 (8.275.01)
- main/openssl: upgrade to 1.1.1j
- community/tor: upgrade to 0.3.5.13
- main/tzdata: upgrade to 2021a
- main/python3: fix CVE-2021-3177
- main/python3: add reliability fix for test_nntplib
- main/linux-vanilla: upgrade to 4.19.176
- community/virtualbox-guest-modules-vanilla: rebuild against kernel 4.19.176-r0
- community/wireguard-vanilla: upgrade to 1.0.20210124 / 4.19.176
- main/dahdi-linux-vanilla: rebuild against kernel 4.19.176-r0
- main/devicemaster-linux-vanilla: rebuild against kernel 4.19.176-r0
- main/drbd-vanilla: upgrade to 9.0.27 / kernel 4.19.176
- main/xtables-addons-vanilla: upgrade to 3.6 / 4.19.176
- main/zfs-vanilla: rebuild against kernel 4.19.176-r0
- testing/ipt-netflow-vanilla: rebuild against kernel 4.19.176-r0
- main/libbsd: fix CVE-2019-20367
- main/redis: security upgrade to 5.0.11
- main/linux-vanilla: build fix for aarch64
- ===== release 3.10.6 =====
- main/postgresql: security upgrade to 11.11
- main/nodejs: build with bundled libuv
- main/nodejs: upgrade to 10.24.0
- main/python3: security upgrade to 3.7.10
- main/wpa_supplicant: patch CVE-2021-27803
- main/openjpeg: fix CVE-2020-27844