Packages changed: 389-ds (3.1.4+e2562f589 -> 3.2.2+4b41542b2) Imath (3.2.2 -> 3.2.3) LibVNCServer Mesa (26.1.6 -> 26.2.1) Mesa-drivers (26.1.6 -> 26.2.1) MozillaFirefox (153.0.3 -> 154.0) MozillaFirefox-branding-openSUSE PackageKit adwaita-fonts (50.0 -> 51.0) akonadi (26.04.3 -> 26.08.0) akonadi-calendar (26.04.3 -> 26.08.0) akonadi-calendar-tools (26.04.3 -> 26.08.0) akonadi-contacts (26.04.3 -> 26.08.0) akonadi-import-wizard (26.04.3 -> 26.08.0) akonadi-mime (26.04.3 -> 26.08.0) akonadi-search (26.04.3 -> 26.08.0) akregator (26.04.3 -> 26.08.0) analitza (26.04.3 -> 26.08.0) apparmor apr-util (1.6.3 -> 1.6.5) ark (26.04.3 -> 26.08.0) at-spi2-core (2.60.5 -> 2.60.6) aurorae6 (6.7.3 -> 6.7.4) aws-lc (5.4.0 -> 5.5.0) babl (0.1.126 -> 0.1.128) baloo-widgets (26.04.3 -> 26.08.0) blinken (26.04.3 -> 26.08.0) bluedevil6 (6.7.3 -> 6.7.4) bolt breeze6 (6.7.3 -> 6.7.4) breeze6-gtk (6.7.3 -> 6.7.4) busybox bzip2 c-ares (1.34.6 -> 1.34.8) cairomm1_0 (1.14.5 -> 1.14.6) calendarsupport (26.04.3 -> 26.08.0) ceph cfitsio (4.6.4 -> 4.7.0) chrony (4.8 -> 4.9) cifs-utils clamav (1.5.3 -> 1.5.4) colord cpio dLeyna (0.8.3 -> 0.8.4) ddcutil (2.2.5 -> 2.2.7) discover6 (6.7.3 -> 6.7.4) dolphin (26.04.3 -> 26.08.0) dos2unix (7.5.6 -> 7.5.7) dracut (110+suse.45.geaec47e4 -> 112+suse.34.g35e16b7) dracut-pcr-signature (0.7+0 -> 0.8+0) drkonqi6 (6.7.3 -> 6.7.4) ed (1.22.5 -> 1.22.6) emacs (30.2 -> 31.1) emacs-compat (31.0.0.1 -> 31.0.0.2) emacs-jinx (2.8 -> 2.10) enchant (2.8.15 -> 2.8.19) erofs-utils (1.9.2 -> 1.9.3) eventviews (26.04.3 -> 26.08.0) evolution-data-server expat (2.8.1 -> 2.8.2) faad2 (2.11.2.git18 -> 2.11.3) ffmpegthumbs (26.04.3 -> 26.08.0) flatpak (1.18.0 -> 1.18.2) flatpak-kcm6 (6.7.3 -> 6.7.4) freerdp (3.30.0 -> 3.31.0) fwupd gcab gcc16 (16.1.1+git9481 -> 16.2.0+git9497) gdm (50.1 -> 50.2) geocode-glib gexiv2 (0.16.1 -> 0.16.2) gimp gjs glib-networking glibmm2_4 (2.66.9 -> 2.66.10) glslang (16.4.0 -> 16.5.0) gnome-characters gnome-control-center (50.3 -> 50.4) gnome-maps (50.2 -> 50.4) gnome-shell (50.3 -> 50.4) gnome-user-docs (50.2 -> 50.4) gnutls grantleetheme (26.04.3 -> 26.08.0) graphene gspell gtksourceview4 gtksourceview5 gvfs (1.60.1 -> 1.60.2) gwenview (26.04.3 -> 26.08.0) gzip harfbuzz (14.2.1 -> 14.3.1) icewm (3.9.0 -> 4.1.0) incidenceeditor (26.04.3 -> 26.08.0) java-25-openjdk (25.0.4.0 -> 25.0.4.1) json-glib kaccounts-integration (26.04.3 -> 26.08.0) kaccounts-providers (26.04.3 -> 26.08.0) kactivitymanagerd6 (6.7.3 -> 6.7.4) kaddressbook (26.04.3 -> 26.08.0) kalgebra (26.04.3 -> 26.08.0) kamera (26.04.3 -> 26.08.0) kanagram (26.04.3 -> 26.08.0) kapptemplate (26.04.3 -> 26.08.0) kate (26.04.3 -> 26.08.0) kbruch (26.04.3 -> 26.08.0) kcachegrind (26.04.3 -> 26.08.0) kcalc (26.04.3 -> 26.08.0) kcalutils (26.04.3 -> 26.08.0) kcharselect (26.04.3 -> 26.08.0) kcolorchooser (26.04.3 -> 26.08.0) kde-cli-tools6 (6.7.3 -> 6.7.4) kde-dev-utils (26.04.3 -> 26.08.0) kde-gtk-config6 (6.7.3 -> 6.7.4) kdecoration6 (6.7.3 -> 6.7.4) kdeedu-data (26.04.3 -> 26.08.0) kdegraphics-mobipocket (26.04.3 -> 26.08.0) kdegraphics-thumbnailers (26.04.3 -> 26.08.0) kdenetwork-filesharing (26.04.3 -> 26.08.0) kdepim-addons (26.04.3 -> 26.08.0) kdepim-runtime (26.04.3 -> 26.08.0) kdeplasma6-addons (6.7.3 -> 6.7.4) kdialog (26.04.3 -> 26.08.0) kernel-source (7.1.6 -> 7.2.2) kf6-attica (6.28.0 -> 6.29.0) kf6-baloo (6.28.0 -> 6.29.0) kf6-bluez-qt (6.28.0 -> 6.29.0) kf6-breeze-icons (6.28.0 -> 6.29.0) kf6-frameworkintegration (6.28.0 -> 6.29.0) kf6-karchive (6.28.0 -> 6.29.0) kf6-kauth (6.28.0 -> 6.29.0) kf6-kbookmarks (6.28.0 -> 6.29.0) kf6-kcalendarcore (6.28.0 -> 6.29.0) kf6-kcmutils (6.28.0 -> 6.29.0) kf6-kcodecs (6.28.0 -> 6.29.0) kf6-kcolorscheme (6.28.0 -> 6.29.0) kf6-kcompletion (6.28.0 -> 6.29.0) kf6-kconfig (6.28.0 -> 6.29.0) kf6-kconfigwidgets (6.28.0 -> 6.29.0) kf6-kcontacts (6.28.0 -> 6.29.0) kf6-kcoreaddons (6.28.0 -> 6.29.0) kf6-kcrash (6.28.0 -> 6.29.0) kf6-kdav (6.28.0 -> 6.29.0) kf6-kdbusaddons (6.28.0 -> 6.29.0) kf6-kdeclarative (6.28.0 -> 6.29.0) kf6-kded (6.28.0 -> 6.29.0) kf6-kdesu (6.28.0 -> 6.29.0) kf6-kdnssd (6.28.0 -> 6.29.0) kf6-kdoctools (6.28.0 -> 6.29.0) kf6-kfilemetadata (6.28.0 -> 6.29.0) kf6-kglobalaccel (6.28.0 -> 6.29.0) kf6-kguiaddons (6.28.0 -> 6.29.0) kf6-kholidays (6.28.0 -> 6.29.0) kf6-ki18n (6.28.0 -> 6.29.0) kf6-kiconthemes (6.28.0 -> 6.29.0) kf6-kidletime (6.28.0 -> 6.29.0) kf6-kimageformats (6.28.0 -> 6.29.0) kf6-kio (6.28.0 -> 6.29.0) kf6-kirigami (6.28.0 -> 6.29.0) kf6-kitemmodels (6.28.0 -> 6.29.0) kf6-kitemviews (6.28.0 -> 6.29.0) kf6-kjobwidgets (6.28.0 -> 6.29.0) kf6-knewstuff (6.28.0 -> 6.29.0) kf6-knotifications (6.28.0 -> 6.29.0) kf6-knotifyconfig (6.28.0 -> 6.29.0) kf6-kpackage (6.28.0 -> 6.29.0) kf6-kparts (6.28.0 -> 6.29.0) kf6-kplotting (6.28.0 -> 6.29.0) kf6-kpty (6.28.0 -> 6.29.0) kf6-kquickcharts (6.28.0 -> 6.29.0) kf6-krunner (6.28.0 -> 6.29.0) kf6-kservice (6.28.0 -> 6.29.0) kf6-kstatusnotifieritem (6.28.0 -> 6.29.0) kf6-ksvg (6.28.0 -> 6.29.0) kf6-ktexteditor (6.28.0 -> 6.29.0) kf6-ktexttemplate (6.28.0 -> 6.29.0) kf6-ktextwidgets (6.28.0 -> 6.29.0) kf6-kunitconversion (6.28.0 -> 6.29.0) kf6-kuserfeedback (6.28.0 -> 6.29.0) kf6-kwallet (6.28.0 -> 6.29.0) kf6-kwidgetsaddons (6.28.0 -> 6.29.0) kf6-kwindowsystem (6.28.0 -> 6.29.0) kf6-kxmlgui (6.28.0 -> 6.29.0) kf6-modemmanager-qt (6.28.0 -> 6.29.0) kf6-networkmanager-qt (6.28.0 -> 6.29.0) kf6-prison (6.28.0 -> 6.29.0) kf6-purpose (6.28.0 -> 6.29.0) kf6-qqc2-desktop-style (6.28.0 -> 6.29.0) kf6-solid (6.28.0 -> 6.29.0) kf6-sonnet (6.28.0 -> 6.29.0) kf6-syndication (6.28.0 -> 6.29.0) kf6-syntax-highlighting (6.28.0 -> 6.29.0) kf6-threadweaver (6.28.0 -> 6.29.0) kgamma6 (6.7.3 -> 6.7.4) kgeography (26.04.3 -> 26.08.0) kglobalacceld6 (6.7.3 -> 6.7.4) khangman (26.04.3 -> 26.08.0) khelpcenter (26.04.3 -> 26.08.0) kidentitymanagement (26.04.3 -> 26.08.0) kig (26.04.3 -> 26.08.0) kimap (26.04.3 -> 26.08.0) kinfocenter6 (6.7.3 -> 6.7.4) kio-extras (26.04.3 -> 26.08.0) kio_audiocd (26.04.3 -> 26.08.0) kiten (26.04.3 -> 26.08.0) kitinerary (26.04.3 -> 26.08.0) kldap (26.04.3 -> 26.08.0) kleopatra (26.04.3 -> 26.08.0) kmag (26.04.3 -> 26.08.0) kmahjongg (26.04.3 -> 26.08.0) kmail (26.04.3 -> 26.08.0) kmail-account-wizard (26.04.3 -> 26.08.0) kmailtransport (26.04.3 -> 26.08.0) kmbox (26.04.3 -> 26.08.0) kmenuedit6 (6.7.3 -> 6.7.4) kmines (26.04.3 -> 26.08.0) kmousetool (26.04.3 -> 26.08.0) kmplot (26.04.3 -> 26.08.0) knighttime6 (6.7.3 -> 6.7.4) kompare (26.04.3 -> 26.08.0) konsole (26.04.3 -> 26.08.0) kontact (26.04.3 -> 26.08.0) kontactinterface (26.04.3 -> 26.08.0) konversation (26.04.3 -> 26.08.0) korganizer (26.04.3 -> 26.08.0) kpat (26.04.3 -> 26.08.0) kpimtextedit (26.04.3 -> 26.08.0) kpipewire6 (6.7.3 -> 6.7.4) kpkpass (26.04.3 -> 26.08.0) kqtquickcharts (26.04.3 -> 26.08.0) kreversi (26.04.3 -> 26.08.0) ksanecore (26.04.3 -> 26.08.0) kscreen6 (6.7.3 -> 6.7.4) kscreenlocker6 (6.7.3 -> 6.7.4) ksmtp (26.04.3 -> 26.08.0) ksshaskpass6 (6.7.3 -> 6.7.4) ksudoku (26.04.3 -> 26.08.0) ksystemstats6 (6.7.3 -> 6.7.4) ktextaddons (2.0.1 -> 2.1.2) ktnef (26.04.3 -> 26.08.0) ktouch (26.04.3 -> 26.08.0) kwalletmanager (26.04.3 -> 26.08.0) kwayland-integration6 (6.7.3 -> 6.7.4) kwayland6 (6.7.3 -> 6.7.4) kwin6 (6.7.3 -> 6.7.4) kwordquiz (26.04.3 -> 26.08.0) lapack layer-shell-qt6 (6.7.3 -> 6.7.4) leancrypto libadwaita (1.9.2 -> 1.9.3) libalternatives (1.2+31.da24cd4 -> 2.0+0.4f22c01) libapparmor libdvdread (7.0.1 -> 7.1.1) libebml (1.4.5 -> 1.4.7) libevdev (1.13.6 -> 1.13.7) libfprint libgedit-gfls (0.4.1 -> 0.4.2) libgedit-gtksourceview (299.7.0 -> 299.7.1) libgit2 (1.9.6 -> 1.9.7) libgravatar (26.04.3 -> 26.08.0) libjpeg-turbo (3.1.4.1 -> 3.2.0) libkcddb-qt6 (26.04.3 -> 26.08.0) libkdcraw (26.04.3 -> 26.08.0) libkdegames (26.04.3 -> 26.08.0) libkdepim (26.04.3 -> 26.08.0) libkeduvocdocument (26.04.3 -> 26.08.0) libkexiv2-qt6 (26.04.3 -> 26.08.0) libkgapi6 (26.04.3 -> 26.08.0) libkleo (26.04.3 -> 26.08.0) libkmahjongg (26.04.3 -> 26.08.0) libkomparediff2 (26.04.3 -> 26.08.0) libksane (26.04.3 -> 26.08.0) libkscreen6 (6.7.3 -> 6.7.4) libksieve (26.04.3 -> 26.08.0) libksysguard6 (6.7.3 -> 6.7.4) liblqr (0.4.2 -> 0.4.3) libmatroska (1.7.1 -> 1.7.2) libopenmpt (0.8.7 -> 0.8.9) libostree (2026.2 -> 2026.4) libplasma6 (6.7.3 -> 6.7.4) libpsl (0.23.1 -> 0.23.3) libreoffice (26.2.5.1 -> 26.2.5.2) librest librist librsvg libseccomp libselinux libselinux-bindings libshumate (1.6.2 -> 1.6.3) libsoup libsoup2 libssh libstorage-ng (4.5.341 -> 4.5.342) libupnp (22.0.4 -> 22.0.6) liburing (2.14 -> 2.15) libva (2.24.0 -> 2.24.1) libva-gl (2.24.0 -> 2.24.1) libvirt libwacom (2.19.0 -> 2.19.1) libxfce4windowing (4.20.6 -> 4.20.7) libxmlb linux-glibc-devel (7.1 -> 7.2) live555 (2026.06.01 -> 2026.08.14) llvm22 localsearch lokalize (26.04.3 -> 26.08.0) mailcommon (26.04.3 -> 26.08.0) mailimporter (26.04.3 -> 26.08.0) markdownpart (26.04.3 -> 26.08.0) mbox-importer (26.04.3 -> 26.08.0) messagelib (26.04.3 -> 26.08.0) microos-tools (4.0+git28 -> 4.0+git29) milou6 (6.7.3 -> 6.7.4) mimetreeparser (26.04.3 -> 26.08.0) mozilla-nss (3.125 -> 3.126.1) mozjs140 (140.13.0 -> 140.14.0) msgraph (0.3.4 -> 0.3.5) multipath-tools (0.15~1+230+suse.d36a6a70 -> 0.15.1+227+suse.6644513) mutter (50.3 -> 50.4) ncurses (6.6.20260613 -> 6.6.20260815) nghttp3 ngtcp2 numlockx nvidia-open-driver-G06-signed (580.159.03_k7.1.6_1 -> 580.178.04_k7.2.0_1) nvidia-open-driver-G07-signed (595.84_k7.1.6_1 -> 595.99.02_k7.2.0_1) nvidia-open-driver-G07-signed-cuda (610.43.02_k7.1.6_1 -> 610.57.04_k7.2.0_1) ocean-sound-theme6 (6.7.3 -> 6.7.4) okular (26.04.3 -> 26.08.0) openSUSE-release (20260806 -> 20260830) openexr (3.4.13 -> 3.4.14) openssh (10.4p1 -> 10.5p1) openvpn (2.6.14 -> 2.7.5) orc (0.4.42 -> 0.4.43) pam_kwallet6 (6.7.3 -> 6.7.4) pango (1.58.0 -> 1.58.2) parley (26.04.3 -> 26.08.0) patterns-base patterns-kde patterns-media perl-CryptX (0.89.0 -> 0.91.0) perl-HTTP-Cookies (6.110.0 -> 6.120.0) perl-HTTP-Message (7.20.0 -> 7.40.0) perl-LWP-Protocol-https (6.150.0 -> 6.170.0) permissions (1699_20260728 -> 1699_20260806) pim-data-exporter (26.04.3 -> 26.08.0) pim-sieve-editor (26.04.3 -> 26.08.0) pimcommon (26.04.3 -> 26.08.0) pipewire plasma5support6 (6.7.3 -> 6.7.4) plasma6-activities (6.7.3 -> 6.7.4) plasma6-activities-stats (6.7.3 -> 6.7.4) plasma6-browser-integration (6.7.3 -> 6.7.4) plasma6-desktop (6.7.3 -> 6.7.4) plasma6-disks (6.7.3 -> 6.7.4) plasma6-integration (6.7.3 -> 6.7.4) plasma6-nm (6.7.3 -> 6.7.4) plasma6-openSUSE plasma6-pa (6.7.3 -> 6.7.4) plasma6-print-manager (6.7.3 -> 6.7.4) plasma6-systemmonitor (6.7.3 -> 6.7.4) plasma6-thunderbolt (6.7.3 -> 6.7.4) plasma6-workspace (6.7.3 -> 6.7.4) polkit-default-privs (1550+20260803.90784eb -> 1550+20260825.76d85e6) polkit-kde-agent-6 (6.7.3 -> 6.7.4) postfix (3.11.5 -> 3.11.6) postgresql18 (18.4 -> 18.6) powerdevil6 (6.7.3 -> 6.7.4) procps (4.0.6 -> 4.0.7) publicsuffix (20260708 -> 20260819) python-M2Crypto (0.48.0 -> 0.49.0) python-Pygments (2.20.0 -> 2.21.0) python-cssselect (1.4.0 -> 1.5.0) python-gevent (26.5.0 -> 26.8.0) python-greenlet (3.5.3 -> 3.5.5) python-h2 (4.3.0 -> 4.4.1) python-hpack (4.1.0 -> 4.2.0) python-msgpack (1.1.2 -> 1.2.1) python-numpy (2.4.6 -> 2.5.2) python-ptyprocess python-pycairo (1.29.0 -> 1.29.1) python-pyzmq (27.1.0 -> 27.2.0) python-rich python-rpm python-six python-socksio python-tornado6 (6.5.7 -> 6.5.8) python-typing_extensions (4.15.0 -> 4.16.0) python-zope.interface (8.5 -> 8.6) python313 python313-core qalculate (5.11.0 -> 5.12.0) qpdf (12.3.2 -> 12.4.1) qqc2-breeze-style6 (6.7.3 -> 6.7.4) qrca (26.04.3 -> 26.08.0) qt6-base (6.11.1 -> 6.11.2) qt6-declarative (6.11.1 -> 6.11.2) qt6-imageformats (6.11.1 -> 6.11.2) qt6-location (6.11.1 -> 6.11.2) qt6-multimedia (6.11.1 -> 6.11.2) qt6-networkauth (6.11.1 -> 6.11.2) qt6-positioning (6.11.1 -> 6.11.2) qt6-qt5compat (6.11.1 -> 6.11.2) qt6-quick3d (6.11.1 -> 6.11.2) qt6-quicktimeline (6.11.1 -> 6.11.2) qt6-shadertools (6.11.1 -> 6.11.2) qt6-speech (6.11.1 -> 6.11.2) qt6-svg (6.11.1 -> 6.11.2) qt6-tools (6.11.1 -> 6.11.2) qt6-translations (6.11.1 -> 6.11.2) qt6-virtualkeyboard (6.11.1 -> 6.11.2) qt6-wayland (6.11.1 -> 6.11.2) qt6-webchannel (6.11.1 -> 6.11.2) qt6-webengine (6.11.1 -> 6.11.2) qt6-webview (6.11.1 -> 6.11.2) rsyslog salt sdbootutil (1+git20260714.d9bb736 -> 1+git20260825.c7a5a97) sddm (0.21.0 -> 0.21.0+git57) sddm-kcm6 (6.7.3 -> 6.7.4) sddm-qt6 (0.21.0 -> 0.21.0+git57) selinux-policy (20260804 -> 20260826) serd (0.32.8 -> 0.32.10) setools (4.7.0 -> 4.7.1) shadow (4.20.0 -> 4.20.2) signon-kwallet-extension (26.04.3 -> 26.08.0) skanlite (26.04.3 -> 26.08.0) spectacle (6.7.3 -> 6.7.4) spice-gtk (0.42 -> 0.43) srt (1.5.6 -> 1.5.7) step (26.04.3 -> 26.08.0) strace (7.1 -> 7.2) suitesparse (7.12.2 -> 7.13.0) svgpart (26.04.3 -> 26.08.0) swtpm (0.10.1 -> 0.10.2) systemsettings6 (6.7.3 -> 6.7.4) thai-fonts (0.7.3 -> 0.7.4) thin-provisioning-tools timezone tree-sitter u-boot-rpiarm64 udisks2 (2.11.1 -> 2.11.2) umbrello (26.04.3 -> 26.08.0) unbound util-linux util-linux-systemd vim (9.2.0780 -> 9.2.0901) vte (0.84.0 -> 0.84.1) wacomtablet-kcm6 (6.7.3 -> 6.7.4) webkitgtk3 (2.52.5 -> 2.52.6) webkitgtk4 (2.52.5 -> 2.52.6) wget wicked wpa_supplicant (2.11 -> 2.12) xdg-dbus-proxy (0.1.7 -> 0.1.8) xdg-desktop-portal-kde6 (6.7.3 -> 6.7.4) xfce4-dict (0.8.9 -> 0.8.10) yast2-ntp-client (5.0.1 -> 5.0.2) yast2-storage-ng (5.0.49 -> 5.0.50) yelp (49.1+3 -> 49.2) zstd === Details === ==== 389-ds ==== Version update (3.1.4+e2562f589 -> 3.2.2+4b41542b2) Subpackages: lib389 libsvrcore0 - Due to an administration error some patches were missed in the previous update. - bsc#1268047 - CVE-2026-11791 - schema reload triggered during concurrent LDAP query traffic can lead to a use-after-free - bsc#1268064 - CVE-2026-11786 - lack of length check can cause an out-of-bound read - bsc#1268065 - CVE-2026-11785 - type confusion in the SSO token handler can cause partial stack address information disclosure - bsc#1268298 - CVE-2026-11774 - integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow - Update to version 3.2.2+4b41542b2: * Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY operations (#7706) * Issue 7698 - Fix silent entry loss in LMDB bulk import waiter handling (#7699) * Issue 7711 - Fix typo in accountpolicy --login-history-size help text (#7713) * Issue 6419 - Error: name 'cockpit_present' is not defined (#7719) * Issue 7666 - Replication performance degradation during total init on high-latency storage (#7667) * Issue 7645 - Add runtime LeakSanitizer leak check (#7646) * Issue 7709 - Add EPEL 10 target to Packit COPR builds * Issue 7714 - UI - sass import rules are deprecated * Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND * Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop * Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM Reload * Issue 7578 - schema - attribute refcount is not maintained properly * Issue 7468 - RFE - HIBP password breach validation (#7492) * Issue 7605 - Harden CI test ports against ephemeral allocation (#7692) * Issue 7528 - Retry the CI image pull instead of failing the job (#7691) * Backport Issue 7519 — ignore obsolete entrydn when entryrdn is in use (#7657) * Issue 7466 - UI - Refactor all TextInput number types to NumberInput * Issue 7505 - RFE - CLI - add feature to determine which password policy applies to a user * Issue 7670 - BDB range searches intermittently fail with err=1 under write load (#7671) * Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7662) * Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value (#7608) * Issue 7200 - repl-agmt create doesn't set some parameters (#7663) * Issue 7573 - Post-import cache autotuning does not recompute entry cache size (#7574) * Issue 7611 - Preserve legacy PBKDF2 hash compatibility (#7649) * Issue 7547 - Heap buffer overflow in ldap_utf8prev() * Issue 7611 - PBKDF2 password verification should reject invalid iteration count (#7613) * Issue 7535 - Fix race in test_schema_update_policy_reject * Issue 7558 - Total init sends the suffix entry twice (#7640) * Issue 7635 - Integer Underflow in {SMD5} Password Comparison (#7636) - bsc#1269120 - [QE] Exception in dsctl - bsc#1267975 - CVE-2026-11611 - content synchronization persistent search plugin can allow unbounded memory growth - bsc#1268041 - CVE-2026-11793 - crafted nsDS5ReplicaCredentials can lead to a stack buffer overflow - bsc#1268046 - CVE-2026-11792 - password value shorter than 23 characters can cause a heap buffer overflow - bsc#1268047 - CVE-2026-11791 - schema reload triggered during concurrent LDAP query traffic can lead to a use-after-free - bsc#1268057 - CVE-2026-11788 - lack of allocation failure check can lead to null pointer dereference - bsc#1268058 - CVE-2026-11789 - crafted SMD5 hash can lead to an integer underflow - bsc#1268060 - CVE-2026-11790 - crafted password hash can cause excessive CPU consumption - bsc#1268062 - CVE-2026-11787 - lack of bounds check can lead to a heap buffer over-read - bsc#1268064 - CVE-2026-11786 - lack of length check can cause an out-of-bound read - bsc#1268065 - CVE-2026-11785 - type confusion in the SSO token handler can cause partial stack address information disclosure - bsc#1268115 - CVE-2026-11884 - Remote Code Execution and Denial of Service via heap buffer overflow - bsc#1268298 - CVE-2026-11774 - integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow - bsc#1268491 - CVE-2026-12528 - heap-buffer-overflows in __aclp__normalize_acltxt() - bsc#1270695 - CVE-2026-11610 - Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND - Update to version 3.2.2+e58d96e17: * Issue 7406 - Fix ldap-agent SNMP stats file loading (#7630) * Issue 7621 - Stack Buffer Overflow in Password checkPrefix * Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking * Issue 7602 - CI - lib389 user compare fails due to parentid mismatch (#7603) * Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, babel/core (#7599) * Issue 7263 - UI - Use cockpit.file API for temporary file writes (#7590) * Issue 7541 - Add invalid ACL text header regression test (#7591) * Issue 7554 - UI - Revise local password policy layout * Issue 7521 - UI - make changes for cockpit API updates * Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542) * Issue 7490 - Enable USDT probes by default in RPM (#7491) * Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload * Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values (#7550) * Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540) * Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559) * Issue 7500 - Prevent unsigned integer underflow during stalled import * Issue 7562 - Error: NssSsl.add_cert() got an unexpected keyword argument 'input_file' (#7563) * Issue 7560 - lib389 - Add helper function for checking ASAN files * Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7556) * Issue 7554 - deref plugin null pointer dereference if ber_init fails * Bump version to 3.2.2 * Issue 6753 - Port ticket 49658 test * Issue 6753 - Removing ticket48252_test and porting to DSLdapObject (#7520) * Issue 6753 - Port ticket 48354 test * Issue 6753 - Port ticket 48745 and 48746 tests (#7513) * Issue 7493 - RFE - Add ShadowAccount fixup task * Issue 7507 - UI - cleanup style and alignments * Issue 7514 - Crash when doing moddn on very large subtree * Issue 7516 - dblayer_bulk_nextdata should not return an error when maxrecords is hit * Issue 7475 - Fix CI test failures in test_fd_limits (#7488) * Issue 7496 - Fix latest GCC compiler warnings * Issue 7503 - CVE-2026-9064 - Add a limit to the number controls per operation * Issue 7468 - RFE - Add HIBP HTTP client (#7469) * Issue 7402 - remove debug print state * address Simon's comments * Minor fixes * fix CI tests * Add disk space checking functionality for offline server * Issue 7402 - CLI - allow healthcheck to work when server is stopped * Issue 6753 - Removing ticket49412_test and porting to DSLdapObject (#7428) * Issue 6753 - Removing ticket49303_test and porting to DSLdapObject (#7429) * Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets (#7461) * Issue 6753 - Removing ticket49287 test and porting to DSLdapObject (#7480) * Issue 7464 - CLI - allow dsidm to work with other user types * Issue 7435 - Add AGENTS.md to support AI coding assistants * Issue 6753 - Port ticket 48266 test * Bump fast-uri from 3.1.0 to 3.1.2 in /src/cockpit/389-console (#7487) * Issue 6753 - Port ticket 48383 test (#7486) ... changelog too long, skipping 242 lines ... * Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7285) ==== Imath ==== Version update (3.2.2 -> 3.2.3) - version update to 3.2.3 * Vec integer method resolution improved — Replaced  =delete with SFINAE ("Substitution Failure Is Not An Error"), via a new `is_float_like` trait, for `length()`, `normalize()`, `normalizedExc()`, etc on integer-typed Vec2/3/4. This gives clearer compiler diagnostics and allows custom numeric types (with an `is_float_like` specialization) to opt into these methods. `half` is explicitly supported. (#[575](https://github.com/AcademySoftwareFoundation/Imath/pull/575)) * Fixed duplicate installation of `ImathConfig.h` (#[591](https://github.com/AcademySoftwareFoundation/Imath/pull/591)) * Fixed shared library installation path (#[556](https://github.com/AcademySoftwareFoundation/Imath/pull/556)) * Fixed Python module install directory, now derived correctly from `Python3_SITEARCH` instead of a hardcoded/absolute path (#[528](https://github.com/AcademySoftwareFoundation/Imath/pull/528)) * Suppressed a C++23 deprecation warning for `std::float_denorm_style/denorm_present` usage in `numeric_limits` (#[546](https://github.com/AcademySoftwareFoundation/Imath/pull/546)) only) * Simplified CMake minimum-version policy handling by removing explicit CMP0074/CMP0077 settings now implied by the 3.14 minimum (#[526](https://github.com/AcademySoftwareFoundation/Imath/pull/526)) * Documentation fixes: corrected install instructions in README.md, fixed broken links, minor spelling corrections ==== LibVNCServer ==== - added patches CVE-2026-50538: a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker-controlled data past the end of its framebuffer [bsc#1276218] * LibVNCServer-CVE-2026-50538.patch ==== Mesa ==== Version update (26.1.6 -> 26.2.1) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.2.1 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.1 - Enable virtio vulkan driver - Apparently %patch -P 18 -p1 is ignored when the patch does not exist on TW. But seems to fail on older distributions. Remove the line for the dropped patch. - Update to 26.2.0 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.0 - drop patches u_PR-40161.patch - refresh patches n_drirc-disable-rgb10-for-chromium-on-amd.patch ==== Mesa-drivers ==== Version update (26.1.6 -> 26.2.1) Subpackages: Mesa-dri Mesa-libva Mesa-vulkan-device-select libvulkan_lvp - Update to 26.2.1 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.1 - Enable virtio vulkan driver - Apparently %patch -P 18 -p1 is ignored when the patch does not exist on TW. But seems to fail on older distributions. Remove the line for the dropped patch. - Update to 26.2.0 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.0 - drop patches u_PR-40161.patch - refresh patches n_drirc-disable-rgb10-for-chromium-on-amd.patch ==== MozillaFirefox ==== Version update (153.0.3 -> 154.0) Subpackages: MozillaFirefox-branding-upstream - Mozilla Firefox 154.0 * https://www.firefox.com/en-US/firefox/154.0/releasenotes MFSA 2026-74 (bsc#1274867) * CVE-2026-75874 (bmo#2039972) Sandbox escape in the Remote Settings Client component * CVE-2026-74934 (bmo#2050584) Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 (bmo#2051013) Privilege escalation in the DOM: Networking component * CVE-2026-74936 (bmo#2052688) Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 (bmo#2053337) Use-after-free in the JavaScript: GC component * CVE-2026-74938 (bmo#2053688) Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 (bmo#2054416) Privilege escalation in the DOM: Navigation component * CVE-2026-74940 (bmo#2054842) Use-after-free in the Graphics: Text component * CVE-2026-74941 (bmo#2055056) Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 (bmo#2056571) Privilege escalation in the Remote Settings Client component * CVE-2026-74943 (bmo#2057308) Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 (bmo#2057778) Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 (bmo#2057808) Information disclosure in the Graphics: Text component * CVE-2026-74946 (bmo#2059997) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 (bmo#2060010) Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 (bmo#2060106) Information disclosure in the Graphics component * CVE-2026-74949 (bmo#2060245) Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 (bmo#1880253) Privilege escalation in the Downloads API component * CVE-2026-74951 (bmo#1978587) Clickjacking issue in Firefox for Android * CVE-2026-74952 (bmo#2021757) Privilege escalation in the Application Update component * CVE-2026-74953 (bmo#2022382) Privilege escalation in the Networking: Cookies component * CVE-2026-74954 (bmo#2025732) Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 (bmo#2029265) Privilege escalation in the Request Handling component * CVE-2026-74956 (bmo#2032406) Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 (bmo#2041906) Mitigation bypass in the Safe Browsing component * CVE-2026-74958 (bmo#2045368) Information disclosure in the WebRTC component * CVE-2026-74959 (bmo#2047853) Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 (bmo#2049148) Site isolation issue in the WebExtensions component * CVE-2026-74961 (bmo#2050380) Side-channel in the Web Audio component * CVE-2026-74962 (bmo#2050425) Site isolation issue in the Networking: Cookies component * CVE-2026-74963 (bmo#2050482) Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 (bmo#2053327) Integer overflow in the Graphics component * CVE-2026-74965 (bmo#2053455) Privilege escalation in the Shell Integration component * CVE-2026-74966 (bmo#2054776) Information disclosure in the Form Autofill component * CVE-2026-74967 (bmo#2055697) Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 (bmo#2055738) Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 (bmo#2056065) Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 (bmo#2056558) Site isolation issue in the Graphics component * CVE-2026-74971 (bmo#2057204) Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 (bmo#2059053) Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 (bmo#2060357) Race condition, use-after-free in the Graphics component * CVE-2026-74974 (bmo#2061794) Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74975 (bmo#1842361) Spoofing issue in the Downloads component in Firefox for Android * CVE-2026-74976 (bmo#1952164) JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 (bmo#2028440) Integer overflow in the Graphics component * CVE-2026-74978 (bmo#2036097) Clickjacking issue in the Widget component ... changelog too long, skipping 53 lines ... - refresh mozilla.keyring ==== MozillaFirefox-branding-openSUSE ==== - recognize Leap 15.6, 16.0 and 16.1 ==== PackageKit ==== Subpackages: PackageKit-backend-zypp PackageKit-gstreamer-plugin PackageKit-gtk3-module libpackagekit-glib2-18 typelib-1_0-PackageKitGlib-1_0 - Only make DNF backend available in openSUSE Leap 16+. Add 0%{?is_opensuse} check to make sure it's only available in Leap. ==== adwaita-fonts ==== Version update (50.0 -> 51.0) - Update to version 51.0: + mono: Update ==== akonadi ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6AkonadiAgentBase6 libKPim6AkonadiAgentWidgetBase6 libKPim6AkonadiCore6 libKPim6AkonadiPrivate6 libKPim6AkonadiWidgets6 libKPim6AkonadiXml6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Port away from deprecated Q_FLAGS * Fix i18n (missing arg) * ETMViewStateSaver: add stable remote-path key format - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Clarify ambiguous trash collection message * agentinstancewidget - use a smaller icon size for agents - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * Fixes for Akonadi killing MariaDB too quickly * FormCollectionComboBox: Drop unused collection property (kde#518048) ==== akonadi-calendar ==== Version update (26.04.3 -> 26.08.0) Subpackages: akonadi-plugin-calendar kalendarac libKPim6AkonadiCalendar6 libKPim6AkonadiCalendarCore6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes to list here. - Update build requirements ==== akonadi-calendar-tools ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * konsolekalendar.cpp - fix viewing a date range (kde#520686) * konsolekalendar/main.cpp - fix the --create command line parsing (kde#450299) ==== akonadi-contacts ==== Version update (26.04.3 -> 26.08.0) Subpackages: akonadi-plugin-contacts libKPim6AkonadiContactCore6 libKPim6AkonadiContactWidgets6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix Bug 522343: Countries are not listed in alphabetical order (kde#522343) * Fix Bug 522344: Cannot remove custom fields for contacts (kde#522344) * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Port away from deprecated setContextText API taking QStrings * Reflect the move of KMime to Frameworks in the dependency data * Remove unused includes * Add forward compatibility with KMime from KDE Frameworks * Make sure that list is not empty * Allow to use prek - Update build requirements ==== akonadi-import-wizard ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6ImportWizard6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add missing find_package(KF6I18n) * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Fix autogenerate clang format * BUILD_QCH is not useful * Remove unused variable * CMakeLists.txt - remove uninitialized variables * Add prek support - Drop patch: * 0001-Add-missing-find_package-KF6I18n.patch ==== akonadi-mime ==== Version update (26.04.3 -> 26.08.0) Subpackages: akonadi-plugin-mime libKPim6AkonadiMime6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Add KF6Mime dependency * coding style * Minor optimization * Assign correct job when we delete it * When we click selection; MarkMailAsUnread must be disable too * Add missing return. Otherwise it can emit (ok) * Port away from deprecated setContextText API taking QStrings * Reflect the move of KMime to Frameworks in the dependency data * Remove unused #include already includes by #include * Add forward compatibility with KMime from KDE Frameworks * Add missing include * Fix logic * Fix potential crash - Update build requirements ==== akonadi-search ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6AkonadiSearch6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * BUG: 522332 - Repair "contains" search on mail addresses (kde#522332) * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Reflect the move of KMime to Frameworks in the dependency data * Port to the named-argument variant of the Akonadi CMake test macro * Fix includes * Add forward compatibility with KMime from KDE Frameworks * CMake fixes for uninitialized variables * Allow to use prek support - Update build requirements ==== akregator ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * Fix scroll to top when click on a linking (kde#424633) ==== analitza ==== Version update (26.04.3 -> 26.08.0) Subpackages: libAnalitza9 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * operations.h: include all own headers relatively * find_package(Qt6): fix variable used for min version * configure_package_config_file: drop unused PATH_VARS arg ==== apparmor ==== Subpackages: apparmor-abstractions apparmor-docs apparmor-parser apparmor-profiles apparmor-utils python3-apparmor - add changes-since-5.0.2.diff - several profile updates - fix compability with Swig 4.5 (boo#1275508) - drop upstreamed nslookup.diff - refresh kerberosclient-usrmerge.diff - add dovecot.diff with several dovecot profile updates (boo#1265453) ==== apr-util ==== Version update (1.6.3 -> 1.6.5) - Update to 1.6.5. - Changes for APR 1.6.5: * Fix Win32 build breakage in apr_os_exp_time_put() in 1.6.4. - Changes for APR 1.6.4: * configure: Fix detection of on OpenBSD. * Fix apr_parse_addr_port() regression in scope_id parsing introduced. * Fix Win32 file buffer locking behavior for single threaded file streams. * Numerous corrections to APR poll behavior. ==== ark ==== Version update (26.04.3 -> 26.08.0) Subpackages: libkerfuffle26 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Clang-format: Use version 18 which is the lowest available on SUSE - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Move extraction DirHistory from config to state config * compressfileitemaction: fix parenting of actions and subjobs * file exists dialog: apply auto skip/overwrite choices in batch (kde#260312) * Rename member variables m_pluginManger to m_pluginManager * arkpart: Build into proper qt plugin directory * compressfileitemaction: user the compressMenu as parent for its actions ==== at-spi2-core ==== Version update (2.60.5 -> 2.60.6) Subpackages: libatk-1_0-0 libatk-bridge-2_0-0 libatspi0 typelib-1_0-Atk-1_0 typelib-1_0-Atspi-2_0 - Update to version 2.60.6: + atk-bridge: Attempt to fix a crash in get_registered_event_listeners + AtspiDevice: Avoid assigning 0 as a grab id + Remove G_GNUC_CONST from *_get_type_declarations ==== aurorae6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * v2: Visualize checked state * Update version for new release 6.7.4 ==== aws-lc ==== Version update (5.4.0 -> 5.5.0) Subpackages: libcrypto-awslc1 libssl-awslc1 - Update to version 5.5.0: + Restore ADX/AVX2 code paths under OPENSSL_SMALL via new MY_ASSEMBLER_IS_TOO_OLD_FOR_ADX_AVX2 flag + Include from for OpenSSL compat + Fix flaky s_client cipher tests by using better ciphers + Add tests for RSASSA-PSS with SHA-3 digest and MGF1 + Link header documentation from README + Rename autofix reasoning role to AwsLcGitHubActionsBedrockRole + delocate: Drop redundant -dI flag + Add Neoverse-V3 (Graviton5) detection and dispatch + Update FIPS.md + Update concurrency in security-review + Enable linker garbage collection for non-FIPS static builds ==== babl ==== Version update (0.1.126 -> 0.1.128) Subpackages: libbabl-0_1-0 typelib-1_0-Babl-0_1 - Update to version 0.1.128: + avx512 support is now more extensively checked at runtime + exported symbols and library version, initial WASM support. ==== baloo-widgets ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Revert "filemetadatawidget: remove TextInteractionFlag" * tagsfileitemaction: fix crash on empty selection (kde#521325) * Remove FileMetaDataConfigWidget, deprecated since 23.08 * Use default DEFAULT_SEVERITY for logging * Remove pointless path check for indexed files * autotests: Fix leak of test widget * filemetadatawidget: remove TextInteractionFlag (kde#515867) ==== blinken ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Use an actual SPDX ID and not a custom one - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== bluedevil6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== bolt ==== - Add bolt-tests subpackage with installed tests for gnome-desktop-testing-runner ==== breeze6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: breeze6-cursors breeze6-decoration breeze6-style breeze6-style-qt5 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== breeze6-gtk ==== Version update (6.7.3 -> 6.7.4) Subpackages: gtk2-metatheme-breeze6 gtk3-metatheme-breeze6 gtk4-metatheme-breeze6 metatheme-breeze6-common - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== busybox ==== Subpackages: busybox-static - Fix stack exhaustion in the ash applet caused by unbounded shell function recursion (CVE-2026-38755, bsc#1271548) * ash-fix-evalfun.patch - Fix out-of-bounds read in ifsbreakup() (CVE-2026-38754, bsc#1271547) * 0001-ash-fix-out-of-bounds-read-in-ifsbreakup.patch - Fix use-after-free in the awk applet regexp processing code when text replacement operations are used (CVE-2026-38753, bsc#1271545) * awk-fix-use-after-free-sub.patch - Fix stack exhaustion in the awk applet caused by unbounded function call recursion (CVE-2026-38752, bsc#1271544) * awk-fix-recursion.patch - Fix heap buffer overflow in the awk applet when a regexp ends with a backslash (CVE-2023-42366, bsc#1217586) * 0001-awk.c-fix-CVE-2023-42366-bug-15874.patch ==== bzip2 ==== Subpackages: libbz2-1 - Fix CVE-2026-42250, off‑by‑one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786) * CVE-2026-42250.patch ==== c-ares ==== Version update (1.34.6 -> 1.34.8) - c-ares 1.36.8: * CVE-2026-33630: Fixes use-after-free/double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP (bsc#1270416) * CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290) * CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291) - README.md: Add readme with build status For details, see https://c-ares.org/changelog.html ==== cairomm1_0 ==== Version update (1.14.5 -> 1.14.6) - Update to version 1.14.6: + Fix memory leak in Context::pop_group() + Documentation: - Fix outdated FSF mailing address in COPYING - Change license info. Lesser GPL 2.1 instead of Library GPL 2 - Meson: Use SPDX expression for license - MSVC-Builds.md: Mention Visual Studio 2026 - MSVC-Builds.md: Update build documentation for NMake - cairomm.h: Add the Basic Usage section + Build system (meson) fixes. ==== calendarsupport ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6CalendarSupport6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes to list here. - Update build requirements ==== ceph ==== Subpackages: librados2 librbd1 - Achieve reproducible builds (boo#1274069) * Simplify cephadm-reproducible.patch * Add cephadm-source-date-epoch.patch ==== cfitsio ==== Version update (4.6.4 -> 4.7.0) - Update to version 4.7.0: * This release includes patches to security vulnerabilities. * New test framework added, containing a collection of unit tests. * Bug fix for parsing octal integer constants in expressions. * Enhanced output from uncompress2mem_from_mem function. * Appended 'fits_' prefix to stream driver function names to reduce chances of potential symbol name conflicts with outside libraries. - Bump min version of cmake in BuildRequires to 3.15 to keep up with upstream. - Add pregenerated documentation as Sources. ==== chrony ==== Version update (4.8 -> 4.9) Subpackages: chrony-pool-openSUSE - Add chrony-test-tolerance.patch: relax the clock-accuracy bounds of the offline holdover phase in the 129-reload simulation test. Its jitter is generated by clknetsim via glibc log(), which is not correctly-rounded and differs in the last ULP between architectures (armv7l and ppc64le vs x86_64 and aarch64). Without a server to correct it, that tiny difference grows past the default limit, making the test fail there although chronyd behaves correctly. - Update to 4.9: * New minstratum and maxstratum directives to bound which source strata are acceptable * New maxntsretry option on server/pool to cap the NTS-KE retry interval * New maxtxbuffers directive enabling hardware and kernel TX timestamps on non-Ethernet devices and tunnels * NTP-over-PTP updated to the final specification (RFC 10030) * seccomp filter updated -- we build with --enable-scfilter, so this is on the default path * Better local clock precision measurement, and client logging no longer costs server performance * Fixed ratelimit directives rejecting burst values over 32 * Fixed handling of hardware RX timestamps with a zero interface index * Further refclock, chronyc and OpenBSD changes: see upstream's NEWS for the full list - Drop chrony-libnettle4.patch: merged upstream, 4.9 carries the same NETTLE_VERSION_MAJOR guards verbatim - Bump the bundled clknetsim simulator 6ee99f50 -> 56b60ef2, now taken from the chrony project's own GitLab as 4.9's test/simulation/README directs. 4.9's simulation tests need clknetsim's new raw-socket support; against the old pin all 69 of them fail. ==== cifs-utils ==== Subpackages: wb-cifs-idmap-plugin - Correctly fix shebangs in Python scripts (bsc#1270134). ==== clamav ==== Version update (1.5.3 -> 1.5.4) Subpackages: libclamav12 libclammspack0 libfreshclam4 - update to 1.5.4 ClamAV 1.5.4 is a patch release with the following fixes: * CVE-2026-20337, bsc#1274597: Fixed ZIP catalogue capacity tracking that could write beyond a heap allocation while indexing local file headers. * CVE-2026-20345, bsc#1274600: Fixed an indexing error while converting GPT partition names that could read or write beyond a stack-allocated partition entry. * CVE-2026-20339, bsc#1274599: Fixed an integer overflow in the PESpin unpacker that could allocate an undersized buffer and then write beyond it while rebuilding a PE file. * CVE-2026-20338, bsc#1274598: Fixed ownership handling while merging ZIP catalogue records that could cause an invalid free while scanning a malformed archive. * CVE-2026-20346, bsc#1274601: Fixed an integer underflow in the PDF parser that could cause a crash while reading a malformed hex string. * CVE-2026-20347, bsc#1274602: Fixed undefined behavior and integer overflow in the Mach-O parser that could cause a crash while scanning a malformed Mach-O file. * CVE-2026-20348, bsc#1274603: Fixed XAR parser size handling that could request an excessive allocation or exceed scan limits while decompressing a malformed table of contents. * CVE-2025-8088: Adopted the upstream UnRAR project fix in ClamAV's bundled UnRAR library. The fix rejects path separators in NTFS alternate data stream names to prevent extraction outside ClamAV's temporary scan directory on Windows. * Fixed thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon while scans and STATS requests run concurrently. Also fixed partial socket-write handling used for large STATS responses. * FreeBSD: Restored support for safe quarantine move and remove actions while preserving protection against source-path replacement races. * Fixed an OpenSSL library-context leak in legacy hashing helpers when a requested message digest cannot be fetched, such as when the default provider is unavailable in a FIPS-enabled environment. * Upgraded the Rust crossbeam-epoch dependency to resolve the RUSTSEC-2026-0204 advisory. - CVE-2026-46671, bsc#1271922: Add clamav-CVE-2026-46671.patch to fix path traversal vulnerability in OneNote parser. - Add clamav-vendor-cve-2026-46671.tar.gz to provide the sanitise-file-name Rust crate required by the security fix. ==== colord ==== Subpackages: colord-color-profiles libcolord2 libcolorhug2 - Build the ICC print profiles with GLIBC_TUNABLES=glibc.cpu.hwcaps=-FMA,-FMA4 so that they no longer depend on the build host CPU (boo#1217747) ==== cpio ==== Subpackages: cpio-mt - Fix CVE-2026-66484: path traversal allows creating hard links outside intended directory via malicious tar archives (bsc#1274856) * CVE-2026-66484.patch - Fix CVE-2026-66485: denial of service via uncontrolled memory allocation from crafted archives (bsc#1274857) * CVE-2026-66485.patch - Fix CVE-2026-66486: terminal control sequence injection via crafted archive member names (bsc#1274858) * CVE-2026-66486.patch - Refresh patches to apply with -p1: * cpio-close_files_after_copy.patch * cpio-default_tape_dev.patch * cpio-dev_number.patch * cpio-eof_tape_handling.patch * cpio-open_nonblock.patch * cpio-use_new_ascii_format.patch * cpio-use_sbin_rmt.patch - Reorder patches, apply with %autosetup -p1 - Add makeinfo build requirement ==== dLeyna ==== Version update (0.8.3 -> 0.8.4) - Update to version 0.8.4: + Core: Fix compatibility with musl + Renderer: Potentially fix crash if renderer device disappears ==== ddcutil ==== Version update (2.2.5 -> 2.2.7) Subpackages: ddcutil-i2c-udev-rules libddcutil5 - Update to 2.2.7: * New: - Extensive diagnostics are written to the system log if opening a /dev/i2c device fails with errno EACCES. - Implemented a basic segfault handler. - Option max-eacces-retry-ms. (See above.) * Changes: - Re-enable reporting of laptop display connection/disconnection. Do not check DDC operation for the laptop /dev/i2c bus or for any bus unresponsive on slave address x37. - When watching for display connection/disconnection using watch-mode UDEV: * watch for UDEV notifications for subsystem i2c-dev as well as drm. * write udev event detail to the system log - dw_hotplug_change_handler(): write additonal messages to the system log when a /dev/i2c device unexpectedly no longer exists - Option --skip-ddc-checks: valid only for command line ddcutil, not shared library libddcutil. If specified in config file ddcutilrc, it must now be in the [ddcutil] section, not the [global] section. - The installed udev rules file, 60-ddcutil-i2c.rules now sets group i2c and mode 0660 as well as using token uaccess to assign /dev/i2c permissions. Users encountering the transient EACCES errors may need to use the old group permissions method. * Fixes: - ddca_redetect_displays(): Recover from an unexpected system state that previously triggered assert() failures. (gh#rockowitz/ddcutil#595), (kde#517571) - dw_create_display_status_event(), test for event type DDCA_EVENT_DDC_DISABLED incorrectly used flag DDCA_DISPLAY_EVENT_DDC_WORKING. - man page ddcutil: Replace "getvcp supported" by "getvcp all". Group "supported" was replaced long ago by "all". (gh#rockowitz/ddcutil#579). - segfault in diagnose_open_failure_to_syslog(). (gh#rockowitz/ddcutil#596) - Error parsing option --maxtries. - run command line programs lsof, getfacl caused a segfault when those programs are not found on the user's system. (gh#rockowitz/ddcutil#590) - In syslog, reported thread id might be the process id. - Change the sample rules file 60-ddcutil-i2c.rules, to conform to /usr/lib/udev/rules.d/60-ddcutil-i2c.rules. Loosens the display adapter test (gh#rockowitz/ddcutil#597) - Fix ioctl call in hiddev_get_report(), for monitors using USB rather that I2C - reading the EDID bytewise use get_edid_bytes_directly_using_fileio(), only every other byte was saved. - Incorrect call to i2c-dev set address ioctl. - General source cleanup using Claude Code - Update Doxygen documentaion. - Consistenly make #include "config.h" the first include. - Consistenly set AM_CFLAGS = $(AM_CLAGS_STD) in the Makefile.am - Avoid a possible buffer overflow when printing an EDID field such as serial number that contains invalid ASCII characters - Write error message during getvcp --brief* to stderr, not stdout. (gh#rockowitz/ddcutil#598) - More consistent formatting of syslog output. - Use atomic variables to fix time of use to time of check (TOCTOU) race conditions identified by Claude Code. * Drop 0001-fix-freezes-on-laptops.patch ==== discover6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: discover6-backend-flatpak discover6-backend-fwupd discover6-backend-packagekit discover6-notifier - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 * Submit usefulness for the right review regardless of how the list is sorted * ui: Only keep a state saver around when we are visible * UpdateModel: Do not pass a lambda to a unique connect * UpdatesModel: Remove destroyed resources (kde#522255) * ApplicationDelegate: relocate "non-default backend" badge with size * ApplicationDelegate: align icons when delegate is showing size * Update version for new release 6.7.4 ==== dolphin ==== Version update (26.04.3 -> 26.08.0) Subpackages: dolphin-part libdolphinvcs6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * selectionmode: Show Delete action in trash (kde#523348) * dolphinview,dolphinviewactionhandler: split create folder into two actions * dolphinmainwindow: use base url fallback on slotSelectionChanged * tests: build dolphinquerytest only when HAVE_BALOO - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Make inline-rename re-triggering robust and add a regression test (kde#514401) - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * kitemviews: Draw icon overlays at a fixed size instead of baking them into the thumbnail (kde#498211) * Allow grouping by a separate criterion (kde#416134) * DolphinNavigatorsWidgetAction: Let non-Breeze QStyles style the non-toolbar navbar how they want (kde#518285) * KItemListWidget: Add pressedChanged (kde#508329) * viewproperties: respect saved properties for special folders with global view props enabled (kde#520089) * kfileitemmodelrolesupdater: fix directory item count for large folders (kde#509150) * dolphintabpage: drop swapActiveView in RightView close path (kde#520002) * userfeedback: prevent dangling pointer access in SettingsDataSource (kde#519876) * Restore session if this is the first instance (kde#464693) * Fix occasional UAF crashes in KConfig::sync() during exit * terminalpanel: allow refreshing the terminal location (kde#510557) * dolphincontextmenu: move "Empty Trash" to where you expect destructive actions to be (kde#518713) * dolphinmainwindow: use directly ShowMenubar action to change menuBar visibility (kde#492298) * kfileitemmodel: sort dotted numeric names naturally (kde#411707) * Refresh shortcut: Ignore repeat events (kde#514209) * KItemListWidget: Use primitives instead of custom painting (kde#508294) * kitemviews: Preserve inline rename when item scrolls out of view (kde#506884) * DolphinTabPage: Prevent re-entrant signal activation for slotViewActivated (kde#508554, kde#512011, kde#508405, kde#511076, kde#503576) * dolphinviewcontainer: Avoid adding an extra history entry when leaving search results (kde#515236) * animatedheightwidget: prevent viewport scrolling (kde#510469) * informationpanel: ignore gestures on media slider (kde#431307) * Fix incorrect app id for Kfind (kde#510370) * information/pixmapviewer: handle hdipi for animated images (kde#510829) * kitemviews: add "Folder Name" column to details view (kde#433937) * kitemlistview: when editing file name set anchored selection (kde#453262) ==== dos2unix ==== Version update (7.5.6 -> 7.5.7) - update to 7.5.7: * Detect a missing UTF-16 low surrogate at the end of a file. * Fixed the processing of files containing only half a BOM. * unix2dos: Fixed conversion of a DOS line break immediately after a Mac line break. * mac2unix/unix2mac: Fixed counting line breaks in verbose mode of files with mixed line break types. * Code cleanup. ==== dracut ==== Version update (110+suse.45.geaec47e4 -> 112+suse.34.g35e16b7) - Update to version 112+suse.34.g35e16b7: * fix(devicetree-firmware): include Qualcomm X2 laptop model specific firmwares * fix(devicetree-firmware): include soc specific firmwares in install_generic() (bsc#1267865) * refactor(devicetree-firmware): make looping over fw_dir top-level loop * fix(resume): handle noresume kernel command line option (bsc#1274588) * fix(resume): actually get value from resume= kernel command line option - Update to version 112+suse.29.gc0c5e1d * fix(base): sanitize message written by die() to the emergency hook - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency hook script in die() (bsc#1274432) - Update to version 112+suse.28.g84b3ea7: Full list of changes: * https://github.com/dracut-ng/dracut-ng/releases/tag/112 * https://github.com/dracut-ng/dracut-ng/releases/tag/111 Additional openSUSE-specific changes and post-release fixes: * fix(net-lib): validate iSCSI port parameters * refactor(net-lib): use strip_non_digits() to validate iSCSI LUN parameters * fix(net-lib): source dracut-lib.sh in net-lib.sh * fix(hwdb): always install this module, except in strict hostonly mode * fix(dracut): --remove allows to remove files from the host filesystem * fix(dracut): --remove globbing does not work * fix(shell-completion): add missing --remove option * style(dracut): correct indentation in help text * fix(dracut-functions): typo in log function * fix(iscsi): normalize the target name in the generated netroot= * fix(iscsi): do not source the boot-time net-lib.sh into module-setup.sh * fix(net-lib): normalize iSCSI target names on the iqn./eui./naa. path * fix(systemd-sysusers): do not run systemd-sysusers as part of the build process * feat(systemd-coredump): save coredumps to journal * fix(dracut): remove wrong auto-detection logic for output file * feat(dracut-install): do not return non-zero if a dependency cannot be resolved * feat(dracut-systemd): add back and fix printing fs help in the emergency shell * feat(resume): add openSUSE-specific sanity check * fix(rngd): revert changes that removed the custom systemd service * fix(systemd-pcrextend): revert changes related to inclusion and dependencies * fix(lsinitrd, dracut-initramfs-restore): detect initrd for BLS Type #1 entries * fix(dracut.sh): improve detection of installed kernel versions * feat: add openSUSE-specific code related to networking * feat(convertfs): add openSUSE-specific code * fix(fips): handle zipl * feat(fips): add openSUSE-specific code * chore(suse): add openSUSE-specific modules * ci: change openSUSE code owners ==== dracut-pcr-signature ==== Version update (0.7+0 -> 0.8+0) - Update to version 0.8+0: * Install the module iff systemd-boot or grub2-bls * Make sure that our sysefi.mount takes precedence * Do not copy old tpm2-pcr-signature files ==== drkonqi6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== ed ==== Version update (1.22.5 -> 1.22.6) - GNU ed 1.22.6: * Add gcc's static analyzer issues * documentation updates ==== emacs ==== Version update (30.2 -> 31.1) Subpackages: emacs-el emacs-eln emacs-info emacs-nox etags - Use lexical-binding for lisp file - Update to GNU Emacs version 31.1 + This update fix bsc#1275941, bsc#1275927 (CVE-2026-79992), and bsc#1276264 * Using the mouse to control Emacs in a terminal enabled by default * New user-lisp/ subdirectory of your Emacs configuration directory * Child frames supported on text frames * Various improvements to the *Completions* buffer * Commands to split windows make better choices about the split direction * The *grep* and *xref* buffers now support editable modes * New feature to review changes to packages before installing or upgrading them * New theme designed to make Emacs more approachable for new users * No ctags support in etags anymore - Remove obsolete patches now upstream solved * 0009-pdumper-set-DUMP_RELOC_ALIGNMENT_BITS-1-for-m68k.patch * 03_all_ruby-flymake.patch * 04_all_shorthands.patch * emacs-30.1-seccomp.patch * emacs-30.2-boo1262611.patch * emacs-30.2-bsc1275927.patch * emacs-30.2-tree-sitter-0.26.8.patch - Port patch emacs-29.1.dif and renamed it to emacs-31.1.dif - Port patches * 0012-Add-inhibit-native-compilation.patch * 0013-Rename-to-inhibit-automatic-native-compilation.patch * 0016-Change-native-comp-async-report-warnings-errors-to-s.patch * emacs-24.1-ps-mule.patch * emacs-24.3-iconic.patch * emacs-24.4-glibc.patch * emacs-24.4-nonvoid.patch * emacs-24.4-ps-bdf.patch * emacs-27.1-pdftex.patch * emacs-30.1-pdumper.patch * emacs-30.1-silent.patch * pdump.patch - Add upstream patch * 0001-speedbar-mode-must-be-enabled-in-the-speedbar-window.patch - Add patch 04_all_shorthands.patch and 03_all_ruby-flymake.patch * First patch fixes bsc#1275941 with VUL-0: emacs: code execution upon opening arbitrary file * Second patch makes ruby support work with ruby 3.4.5 - Add patch emacs-30.2-bsc1275927.patch to Fix bug 1275927: VUL-0: emacs: zero-click local command execution via TRAMP - Add patch emacs-30.2-pgtk-visual-bell-boo1271643.patch from upstream mailing list to fix memory leak in wayland port (boo#1271643) ==== emacs-compat ==== Version update (31.0.0.1 -> 31.0.0.2) - Update to version 31.0.0.2: * compat-31: Fix extended function seconds-to-string. ==== emacs-jinx ==== Version update (2.8 -> 2.10) - Update to version 2.10: * Let-bind parse-sexp-lookup-properties to nil during Jinx tokenization. This avoids interference with the syntax-table property attached by some major modes like haskell-mode. * Rename CHANGELOG.org to NEWS.org - Changes from version 2.9: * New command jinx-remove-word to remove words from personal dictionary, file local variable, and so on. * New customizable variable jinx-save-prop-line. ==== enchant ==== Version update (2.8.15 -> 2.8.19) Subpackages: enchant-2-backend-hunspell enchant-data libenchant-2-2 - Update to version 2.8.19: + This release adds a provider for WinSpell. + The change in the previous release to update the tests and require the use of C++20 have been reverted. - Changes from version 2.8.18: + This release fixes compatibility with the latest Vala compiler, version 0.56.19. + enchant(1) now assumes UTF-8 input and produces only UTF-8 output. + The macOS spelling checker used to have a hard-wired list of languages it supported. Drop this, and support all languages supported by the system. + Some code clean-up has been done, removing some unused code, and making somr minor improvements to the build system. + The tests have been updated to drop the use of the deprecated codecvt APIs, and instead use u8 string literals. As a result, Enchant’s build system now requires C++20. - Changes from version 2.8.17: + Make enchant silently ignore -C flag, for better Emacs compatibility. - Changes from version 2.8.16: + Fix a bug introduced in 2.8.14: after rejecting a word for not containing at least one letter, enchant(1) would skip the rest of the line. ==== erofs-utils ==== Version update (1.9.2 -> 1.9.3) - Update to release 1.9.3 * mkfs: Sort inline xattrs for reproducible builds * mkfs: Fix rebuild mode handling for opaque directories * mkfs: Fix `--incremental=data` functionality * mkfs: Fix raw inline handling with `-Eztailpacking` * mkfs: Harden tar index parsing against invalid sizes * mkfs: Fix memory leaks for small fragments ==== eventviews ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6EventViews6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * agendaview - updateView() - always update the day labels (kde#498687) * monthview.cpp - in updateView also make sure to update the scene (kde#519909) * agendaview.cpp - underline today's date in the day header (kde#207967) * monthview.cpp - always show holidays, even if they land on a weekend. (kde#451862) - Update build requirements ==== evolution-data-server ==== Subpackages: libcamel-1_2-67 libebackend-1_2-11 libebook-1_2-21 libebook-contacts-1_2-5 libecal-2_0-3 libedata-book-1_2-27 libedata-cal-2_0-2 libedataserver-1_2-27 libedataserverui-1_2-4 - Add evolution-data-server-tests subpackage with installed tests for gnome-desktop-testing-runner ==== expat ==== Version update (2.8.1 -> 2.8.2) Subpackages: libexpat1 - update to 2.8.2 ( bsc#1267631, CVE-2026-50219, bsc#1268572, CVE-2026-56131, bsc#1268573, CVE-2026-56132, bsc#1275096, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407, CVE-2026-56408, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, CVE-2026-56412): * #1246 CVE-2026-50219 -- Disallow calls to functions * `XML_GetBuffer`, `XML_Parse`, `XML_ParseBuffer`, * `XML_ParserFree`, `XML_ParserReset` to guard e.g. * Expat bindings from memory corruption; * #1267 CVE-2026-56131 -- Protect XML_ResumeParser from being called from a handler, plugging a hole in the fix to CVE-2026-50219 * #1272 CVE-2026-56132 -- Fix out-of-bound scaffolding index store in `doProlog` * #1229 #1232 CVE-2026-56403 -- Integer overflow in `storeAtts` * #1249 CVE-2026-56404 -- Integer overflow in `addBinding` * #1251 CVE-2026-56405 -- Integer overflow in `getAttributeId` * #1255 CVE-2026-56406 -- Integer overflow in `XML_ParseBuffer` * #1262 CVE-2026-56407 -- Integer overflow in `textLen` handling * #565 CVE-2026-56408 -- Integer overflow in `copyString` * #1259 CVE-2026-56409 -- xmlwf: Integer overflow in output path join * #1252 CVE-2026-56410 -- xmlwf: Integer overflow in `resolveSystemId` * #1263 CVE-2026-56411 -- xmlwf: Integer overflow in notation list allocation * #1278 CVE-2026-56412 -- Guard XML_TOK_DATA_CHARS handler calls in `doCdataSection`, plugging a hole in the fix to CVE-2026-50219 ==== faad2 ==== Version update (2.11.2.git18 -> 2.11.3) - Update to version 2.11.3: * Fix ISO C warning in libfaad/fixed.h * Check for mp4config.frame.nsclices == 0 in frontend/mp4read.c to fix Heap Buffer Overflow * SBR: prevent heap overflow in channel-pair reconstruction * Fix off-by-one frame index check in mp4read_seek * Fix integer overflow in stszin/stscin allocation size checks * Bound sscanf field width in option parsing * Fix out-of-bounds iq_table read in iquant for -32768 * Prevent length_of_rvlc_sf underflow in rvlc_scale_factor_data * Fix out-of-bounds Xsbr write in hf_assembly sinusoid addition * Fix out-of-bounds X underflow in SBR low-power QMF assembly * Fix ssr_gc_function signature mismatch in ssr_gain_control * Fix signed overflow in estimate_current_envelope energy sum * Cap escape length in huffman_spectral_data_2 * Prevent num_bits_left underflow in ps_data extension parsing * Fix signed overflow in fixed-point sample rounding before saturation * Add sanity checks on the width in libfaad/specrec.c * Check the last swb_offset value is valid in libfaad/specrec.c * Return early from NeAACDecInit when the object type can't be supported * Fix null pointer dereferences in intra channel and long term prediction * Increase the ASC buffer from 10 to 64 bytes in frontend/mp4read.h ==== ffmpegthumbs ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix OSS-Fuzz build ==== flatpak ==== Version update (1.18.0 -> 1.18.2) Subpackages: flatpak-remote-flathub flatpak-selinux libflatpak0 system-user-flatpak - Update to version 1.18.2: + Bug fixes: - Validate GVariant structure of summaries before using generated variant readers - Fix crash in system helper when iterating cache directories - Avoid corrupted output from non-UTF-8 characters in error messages - Fix portal passing wrong file descriptor when sandbox-expose-fd-ro triggers fd remapping collision - Fix system helper tracking wrong D-Bus sender for pulls - Fix extensions not being populated in the sandbox due to unhandled EAGAIN from openat2 - Fix build failure with GLib versions older than 2.72 - Test infrastructure improvements - Update to version 1.18.1: + Security fixes: - Fix sandbox escape with full host filesystem read/write access via symlink attack on app data directories (GHSA-8688-9x26-hhxj) - Fix local root privilege escalation via revokefs symlink path traversal and commit tampering (GHSA-qrwq-7qwx-q9rp) - Fix arbitrary root write via symlink and path traversal in extra-data extraction (GHSA-fqx6-vh4p-42cg) - Fix arbitrary root write via path traversal in `flatpak build-init` (GHSA-8qxj-x646-phcm) - Fix arbitrary host file read via hardlink path traversal in OCI archive extraction (GHSA-9rww-v4mm-x4jg) - Fix path traversal via unvalidated architecture parameter in DeployAppstream (GHSA-v2gw-v9h5-9q4x) - Fix buffer overflow in OCI delta stream path names on 32-bit systems (GHSA-jr92-2v97-wgvc) - Fix fixed-filename writes to arbitrary locations via symlink attack on .ld.so (GHSA-99wv-m8rp-g58x) - Fix extension metadata path traversal allowing host filesystem probing and unintended mount locations (GHSA-w69g-9x8j-7p8f) - Fix anti-downgrade bypass allowing unprivileged users to downgrade system apps (GHSA-q4gr-vc25-57m5) + Bug fixes: - Fix portal flatpak-spawn environment handling regression - Fix negated permission strings for allow and share run options - Fix build failure when exporting metainfo releases.xml files - Fix crashes in the portal update monitor and OCI JSON handling - Error out if file forwarding of empty paths is attempted - Check OCI signatures from the mirrored repo in the system helper instead of fetching from the lookaside server - Apply TLS certs to OCI registry requests and propagate stream write failures to curl - Fix GI annotation for flatpak_instance_get_all - Cleanup of Bash completion - Numerous internal fixes for crashes, error handling, and hardening ==== flatpak-kcm6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - No code changes since 6.7.3 ==== freerdp ==== Version update (3.30.0 -> 3.31.0) Subpackages: libfreerdp3-3 librdtk0-0 libwinpr3-3 - Update to version 3.31.0: + Huge bugfix and security release. We've received quite a number of smaller and bigger bugfixes and security reports that have been addressed with this release. Most important user facing change is a optimization of the YUV decoder which will result in faster client graphics for AVC/H264 sessions + CVE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c5gr-hmqp-pwj4 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h5w2-q35j-443h https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m85m-3qxv-63h5 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r9pv-ffph-6gg6 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-ffjr-p229-hpch https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4464-r7qj-pgrx https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2vf2-grvj-6g8x https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hg4r-vv53-vwf8 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-57h7-vw2f-2f9x https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v649-94v2-p72q https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-j5mq-3349-gwmm https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-23pf-q83q-x45r https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pj8w-fh79-f438 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vccg-35r5-8jrf https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-w9qg-g24r-77f6 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f5p6-88mh-59vg https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r7jx-j9h7-j4xj https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v6-xfx3-52j6 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jcm-x588-gh26 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q65v-4w7q-hx3r + Lots of other changes, please see upstream changelog: https://github.com/FreeRDP/FreeRDP/releases/tag/3.31.0 - Add pkgconfig(aom), pkgconfig(dav1d) and pkgconfig(libyuv) BuildRequires: and pass WITH_AOM=ON, WITH_DAV1D=ON and WITH_YUV=ON to cmake, enable optional encoders/decoders. ==== fwupd ==== Subpackages: fwupd-bash-completion libfwupd3 typelib-1_0-Fwupd-2_0 - Add Requires: gnome-desktop-testing to fwupd-tests subpackage - Add fwupd-tests subpackage with installed tests for gnome-desktop-testing-runner. ==== gcab ==== Subpackages: libgcab-1_0-0 - Enable meson installed tests (-D tests=true) and add %check section ==== gcc16 ==== Version update (16.1.1+git9481 -> 16.2.0+git9497) Subpackages: cpp16 libasan8 libatomic1 libgcc_s1 libgccjit0 libgfortran5 libgomp1 libhwasan0 libitm1 liblsan0 libobjc4 libstdc++6 libstdc++6-pp libtsan2 libubsan1 - Disable cross-x86_64-gcc build for SLFO - Update to GCC 16.2 release (gcc-16.2.0+git9497) * accumulated bugfixes from the gcc-16 release branch - Disable multilibs for cross-x86_64-gcc ==== gdm ==== Version update (50.1 -> 50.2) Subpackages: gdm-schema gdm-systemd gdm-xdm-integration libgdm1 typelib-1_0-Gdm-1_0 - Add gdm-fix-tty1-mode.patch: During system startup, tty1 is left in an invalid state, preventing it from being switched away from (bsc#1250688, bsc#1272490, bsc#1252888) - Drop gdm-initial-vt-tty1.patch: Fixed by gdm-fix-tty1-mode.patch - Update solution for switching to tty1 on gdm service stop + Drop gdm-switch-to-tty1.patch + Add /usr/lib/systemd/system/gdm.service.d/10-switch-to-vt1-on-stop.conf - Update to version 50.2: + Fixed path traversal vulnerability where a compromised greeter could load arbitrary .desktop files via SelectSession, potentially executing attacker-controlled commands as the authenticated user + Fixed autologin bypass where a compromised greeter could request autologin for any local account by sending arbitrary usernames via BeginAutoLogin + Fixed denial of service where an invalid session name from the greeter would cause the entire daemon to exit, terminating all active sessions + Fixed passphrase handling in pam_gdm to wipe cached plaintext passwords before freeing and to bound the keyring buffer walk preventing out-of-bounds reads + Fixed crashes, memory leaks and wrong hash key type in reauthentication channel handler, session worker and dynamic user store + Updated translations. ==== geocode-glib ==== Subpackages: libgeocode-glib-2-0 typelib-1_0-GeocodeGlib-2_0 - Add geocode-glib-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gexiv2 ==== Version update (0.16.1 -> 0.16.2) - Update to version 0.16.2: + Fix crash when opening files without preview images ==== gimp ==== Subpackages: gimp-plugin-aa gimp-plugin-python3 libgimp-3_0-0 libgimpui-3_0-0 - Add CVE fixes: + gimp-CVE-2026-59087.patch (bsc#1274809, glgo#GNOME/gimp#16491) + gimp-CVE-2026-59088.patch (bsc#1274837, glgo#GNOME/gimp#16492) + gimp-CVE-2026-59090.patch (bsc#1274840, glgo#GNOME/gimp#16509) + gimp-CVE-2026-59091.patch (bsc#1274851, glgo#GNOME/gimp#16510) ==== gjs ==== Subpackages: libgjs0 typelib-1_0-GjsPrivate-1_0 - Provide GjsPrivate-by-GNOME by typelib-1_0-GjsPrivate-1 and require this symbol by libgjs0: ensure libgjs0 gets the own typelib installed, without risking the variant from cjs to be considered (could not happen so far as cjf marked a conflict with gjs, but that seems not actually to be true). ==== glib-networking ==== - Add glib-networking-tests subpackage with installed tests for gnome-desktop-testing-runner ==== glibmm2_4 ==== Version update (2.66.9 -> 2.66.10) Subpackages: libgiomm-2_4-1 libglibmm-2_4-1 - Update to version 2.66.10: + Drop G_GNUC_CONST as in GLib. + Gio: Emblem and DBus::ActionGroup: Don't derive gtkmm__Gxxx types. The underlying C classes are final types since GLib 2.89.2. + Meson build: Use Meson's pkgconfig module instead of using the * .pc.in templates. - Update to version 2.66.9+3: + Gio::DBus::ActionGroup: Improve the test whether GDBusActionGroup is final + Drop G_GNUC_CONST as in glib + Gio: Emblem and DBus::ActionGroup: Don't derive gtkmm__Gxxx types - Use source service to generate tarball. - Add mm-common and perl-XML-Parser BuildRequries: Needed now that we are using a git checkout. - Pass maintainer-mode=true to meson setup, needed since we are using a git checkout. ==== glslang ==== Version update (16.4.0 -> 16.5.0) - Update to release 16.5.0 * Implement `GLSL_EXT_split_barrier`/`SPV_EXT_split_barrier`, `GLSL_QCOM_multiple_wait_queues`, `GLSL_QCOM_image_processing3`, `GL_EXT_function_control_attributes`. ==== gnome-characters ==== Subpackages: gnome-shell-search-provider-gnome-characters - Replace appstream-glib with AppStream BuildRequires: Align with what meson really checks for (appstreamcli). ==== gnome-control-center ==== Version update (50.3 -> 50.4) Subpackages: gnome-control-center-color gnome-control-center-goa gnome-control-center-user-faces gnome-control-center-users - Update to version 50.4: + Updated translations. ==== gnome-maps ==== Version update (50.2 -> 50.4) - Update to version 50.4: + Only show furigana (hiragana phonetic) names for places when the user has the language set to Japanese. + Fix showing points for via locations for route searching. + Updated translations. - Update to version 50.3: + Allow public transit routing to places further from a routable walking path (increased distance from 25 to 250 meters, to match behavior in MOTIS web app) + Updated translations. ==== gnome-shell ==== Version update (50.3 -> 50.4) Subpackages: gnome-extensions gnome-shell-calendar - Update to version 50.4: + Fix some menu animations + Fix glitch when switching to minimized window on another workspace + Fix miscaled magnified cursor on HiDPI + Fix sound glitch when pushing redundant volume changes + Fix removing arbitrary provider when removing unregistered search provider + Misc. bug fixes and cleanups + Updated translations. ==== gnome-user-docs ==== Version update (50.2 -> 50.4) - Update to version 50.4: + Updates to GNOME Help + Updated translations. ==== gnutls ==== Subpackages: libgnutls-dane0 libgnutls30 - FIPS: Deprecate ECDSA siggen with less than 128-bit (bsc#1265613) * NIST SP 800-131Arev3 marked ECDSA siggen < 128-bit of security strength as deprecated after the deadline of 31 dic 2030. * Add gnutls-FIPS-Deprecate-ECDSA-with-less-that-128-bit.patch - FIPS: Mark SHA-224 and SHA3-224 as legacy (bsc#1265609, bsc#1265611) * NIST SP 800-131Arev3 has marked SHA-224 and SHA3-224 as legacy after the deadline of 31 dic 2030. * Add gnutls-FIPS-SHA224-SHA3224-Legacy-Status.patch - FIPS: Deprecate HMAC with keys less than 128-bit (bsc#1265610) * NIST SP 800-131Arev3 marked HMAC with keys less than 128-bits as disallowed after the deadline of 31 dic 2030. * Add gnutls-FIPS-Deprecate-HMAC-with-less-that-128-bit-keys.patch - FIPS: Deprecate RSA Signatures with less than 128-bit (bsc#1265612) * NIST SP 800-131Arev3 has marked RSA Signatures with less than 128-bit as deprecated after the deadline of 31 dic 2030. * Add gnutls-FIPS-Deprecate-RSAsig-with-less-that-128-bit.patch ==== grantleetheme ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6GrantleeTheme6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * grantleetheme.cpp - explicit reset on application quit * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * USe QT_ENABLE_STRICT_MODE_UP_TO * Remove unused #include already includes by #include * Don't leak template engine * GRANTLEETHEME_LIB_VERSION is not used * KPIMGrantleeMacros.cmake - fix uninitialized variable warnings ==== graphene ==== Subpackages: libgraphene-1_0-0 typelib-1_0-Graphene-1_0 - Add graphene-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gspell ==== - Add gspell-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gtksourceview4 ==== Subpackages: libgtksourceview-4-0 typelib-1_0-GtkSource-4 - Add gtksourceview4-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gtksourceview5 ==== - Add gtksourceview5-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gvfs ==== Version update (1.60.1 -> 1.60.2) Subpackages: gvfs-backend-afc gvfs-backend-goa gvfs-backend-gphoto gvfs-backend-samba gvfs-backends gvfs-fuse - Update to version 1.60.2: + build: Drop G_GNUC_PURE from *_get_type() functions + afp/dav/ftp/mtp/sftp: Harden input validation + common: Clear password strings from memory before freeing + mtp/onedrive/smb: Fix crashes in onedrive, mtp, and smb backends + Some other fixes + Updated translations. ==== gwenview ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - Changes since 26.07.80: * On switch to browser mode: keep scheme for non-local URLs in window title - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add option to sort by type (kde#478316) * Port to new KActionCategory API * Use default DEFAULT_SEVERITY for logging * Fix cmake warnings * Open Image dialog: Restrict to open Existing single File ==== gzip ==== - Fix CVE-2026-41992, global buffer overflow in the LZH decompression logic (CVE-2026-41992, bsc#1269623, bsc#1272554) * CVE-2026-41992.patch - Refresh patches to apply with -p1: * non-exec-stack.diff * zdiff.diff * zgrep.diff - Use %autosetup to apply patches ==== harfbuzz ==== Version update (14.2.1 -> 14.3.1) Subpackages: libharfbuzz-gobject0 libharfbuzz-icu0 libharfbuzz-subset0 libharfbuzz0 typelib-1_0-HarfBuzz-0_0 - Update to version 14.3.1: + Various fuzzing and build fixes. + Various subsetting fixes. + Fix AAT insertion at the end of the text. + Fix various rendering bugs in the experimental GPU library. + WASM shaper code can now read the user features. - Update to version 14.3.0: + Changes affecting shaping output: - Lookup order is now respected for mark positioning in the cross-direction (y in horizontal text, x in vertical text): marks no longer follow a cross-direction shift that a later lookup applies to the base. This improves compatibility with DirectWrite and Core Text. - Fix mark attachment to ligatures formed from decomposed glyphs. - The `calt` feature in Hangul text is now disabled only for the Jamos, not the whole buffer. + Support for partially instancing version of `avar` table, as well as `CFF2` table. + New fill-glyph paint operation and APIs for the common case of filling a glyph with a solid color. + New API to fetch assorted raw values from the `OS/2`, `head`, and `post` tables. + New experimental API to extract a font’s glyph dependency graph, that applications can use to compute glyph closures themselves without running the subsetter. + New subset flag to convert the charset of a subsetted CID-keyed `CFF` fonts into identity charset, and a matching `hb-subset` option. Useful for embedding fonts in PDF. + Command-line utilities now handle non-ASCII arguments correctly on Windows. + Various instancing and subsetting fixes. + Various fixes to the experimental `harfbuzz-vector`, `harfbuzz-raster` and `harfbuzz-gpu` libraries. + Various improvements to the HarfRust integration shaper. + Various build, CI, portability, and fuzzing fixes. + Various new APIs. ==== icewm ==== Version update (3.9.0 -> 4.1.0) Subpackages: icewm-config-upstream icewm-default icewm-lite - Update to version 4.1.0: + Fixes: - Default Alpha to false to avoid rare video performance problems.. - Properly handle unterminated strings in configuration files.. - Properly handle a string parsing error for _NET_STARTUP_ID.. - Free the picture before its pixmap to prevent an error message. + Changes: - Add a new winoption ignoreUserTime. - Add a "mousemove" command to icesh. + Updated translations. - update to 4.0.0: * Features: - Add QuickSwitchPreview for application previews during Alt+Tab switching. - Support for high-resolution icons (up to 256x256) in previews and taskbar. - Add getWorkspaceName and getWorkspaceNames commands to icesh. - Select applications by the first letter of their class name in Alt+Tab. - Improved system tray icon handling for mixed bit depths - Improved clock LED rendering and fallback to fonts if pixmaps are missing. - Recognition of UTF-8 combining marks in window titles. - Enhanced QuickSwitch with workspace separators and keypad support. - Server-side caching of icon pictures to improve drawing performance. * Fixes: - Prevent crash when a dock layer window exits. - Fix keyboard layout switching on OpenBSD. - Fix bug where tasks pane could overlap workspaces pane. - Fix sorting of FDO menu entries with non-English characters. - Improve workspace name updates on the taskbar when changed externally. - Diagnostic messages for loadicon and saveicon in icesh. * Changes: - Increase maximum icon size to 256 for LargeIconSize and HugeIconSize. - Set the default value for Alpha blending to 1 and drop DoubleBuffer preference. - Update issue tracker and repository URLs to the ice-wm organization. - Improved autogen.sh with better versioning and error handling. - Updated translations for many languages including Indonesian, Russian, Dutch, and Japanese. ==== incidenceeditor ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6IncidenceEditor6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * Don't LLCONFLICT when moving an incidence to a new collection. (kde#522164) * templatemanagementdialog.cpp - disable OK button until new or remove (kde#228683) * Prompt for overwriting changed values with a template (kde#228675) * guard against crash from empty organiser email (kde#495848) - Update build requirements ==== java-25-openjdk ==== Version update (25.0.4.0 -> 25.0.4.1) Subpackages: java-25-openjdk-headless - Update to upstream tag jdk-25.0.4.1+1 (August 2026 CSPU) * Changes + JDK-8382471, bsc#1275777, CVE-2026-60589: Improve Resource Resolving + JDK-8384708, bsc#1275778, CVE-2026-61308: Enhance HTTP Connections + JDK-8386205, bsc#1275764, CVE-2026-70907: Enhance TLS server + JDK-8386298, bsc#1275763, CVE-2026-70906: Improve font loading + JDK-8388788: Bump update version for OpenJDK: jdk-25.0.4.1 + JDK-8389945: [25u] Remove designator DEFAULT_PROMOTED_VERSION_PRE=ea for release 25.0.4.1 - Added patch: * tzdata-2026c.patch + backport upcoming upgrade of timezone data (bsc#1275035) ==== json-glib ==== Subpackages: libjson-glib-1_0-0 typelib-1_0-Json-1_0 - Add json-glib-tests subpackage with installed tests for gnome-desktop-testing-runner ==== kaccounts-integration ==== Version update (26.04.3 -> 26.08.0) Subpackages: libkaccounts6-2 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kaccounts-providers ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kactivitymanagerd6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kaddressbook ==== Version update (26.04.3 -> 26.08.0) Subpackages: kaddressbook-doc libKPim6AddressbookImportExport6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Explicitely check KF6I18n dependency ourselves, using it directly * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * increase version * Add save() * coding style * Add application name * Use WHATSNEWSNG * Prepare to use WhatsNewNgDialog * Fix whatsnewtranslations * Remove duplicate includes * Increase PlasmaActivities version * install kcfg file * BUILD_QCH is not useful * Increase ktextaddons dep * CMakeLists.txt - set missing QT_REQUIRED_VERSION to "6.9.0" * Add prek support - Drop patch: * 0001-Explicitely-check-KF6I18n-dependency-ourselves-using.patch ==== kalgebra ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kamera ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kanagram ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Remove not initialized variable ==== kapptemplate ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kate ==== Version update (26.04.3 -> 26.08.0) Subpackages: kate-plugins - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * only add processId if we are not sandboxed (kde#522883) * use Utils::absoluteUrl to have same normalization as via the KateDocManager (kde#519737) * improve handling of view change with search bars & Co. (kde#488164) * ensure we work on a local copy of the session config (kde#520168) * Add missing include (kde#520771) * ensure we hide the buttons in the view space if no tabs & nav bar there (alternative implementation) (kde#515133) * Use proper working directory when invoking git (kde#519685) * Fix middle click on tab doesn't work when close button disabled (kde#519325) * add filename to location copy (kde#519077) * try to add suffix that matches the document mime-type (kde#518537) * Fix possible out of bound read (kde#515975) * Check for index validity (kde#513191) * Fix possible out of bound read (kde#518496) * Remove custom prettier formatter (kde#517926) * add hint that missing char means ignore for spell checking (kde#517428) ==== kbruch ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kcachegrind ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Remove left-over KF version include * Add bounds check ==== kcalc ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - Changes since 26.07.80: * fixed infinity loop when degree token is found in calculation (kde#515379) - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add option to force scientific notation (kde#142729) * README.md proofreading * tests: Force locale so tests pass on locales with , as decimal separator * kcalc binaries are shipped as GPL-2.0-or-later. Only CMakePresets.json is BSD-3-Clause ==== kcalutils ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6CalendarUtils6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes to list here. ==== kcharselect ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Support copying selected text from detail panel (kde#400257) ==== kcolorchooser ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kde-cli-tools6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kde-dev-utils ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kde-gtk-config6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: kde-gtk-config6-gtk3 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kdecoration6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libkdecorations3-6 libkdecorations3private2 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kdeedu-data ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kdegraphics-mobipocket ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * DocumentPrivate::init: return early if dec is not valid * Protect against malformed header size - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Don't check for size of parseEXTH twice * Harden bounds validation in DocumentPrivate::parseEXTH * Prevent integer underflow in DocumentPrivate::parseEXTH * ecm_generate_export_header: fix spurious } to USE_VERSION_HEADER arg ==== kdegraphics-thumbnailers ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix invalid memory access * Fix off by one access * Fix memory leak ==== kdenetwork-filesharing ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * filepropertiesplugin: fix build without systemd * Handle service being an alias ==== kdepim-addons ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Fix compilation of markdown plugin - Update to 26.07.80 * New feature release - Too many changes to list here. - Update build requirements ==== kdepim-runtime ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Add icon - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Add google icons - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * dav: add CreateDavCollectionJob upon collectionAdded (kde#439502) - Update build requirements ==== kdeplasma6-addons ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * applets/diskquota: Properly set ItemDelegate content (kde#523618) * [Vietnamese Lunar Calendar] Fix month offset after leap month * applets/kickerdash: add BugReportUrl * applets/colorpicker: correct bug report URL (kde#522459) * applets/mediaframe: Fix media not updating when watched file changes on disk (kde#521538) * Update version for new release 6.7.4 ==== kdialog ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kernel-source ==== Version update (7.1.6 -> 7.2.2) Subpackages: kernel-64kb kernel-default - Linux 7.2.2 (bsc#1012628). - inet: frags: strip GSO state from fragments before reassembly (bsc#1012628 CVE-2026-80590). - commit 820247d - Linux 7.2.1 (bsc#1012628). - ptp: vmclock: prevent read-only mappings from becoming writable (bsc#1012628). - futex: Fix might_sleep() warning in futex_pivot_pending() (bsc#1012628). - Bluetooth: hci_aml: validate firmware segment lengths (bsc#1012628). - Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 (bsc#1012628). - Bluetooth: ISO: zero the sockaddr before returning it in getname (bsc#1012628). - Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync (bsc#1012628). - Bluetooth: hci_sync: Fix accept list UAF during suspend (bsc#1012628). - Bluetooth: hci_event: validate LE Set CIG Parameters response (bsc#1012628). - Bluetooth: hci_event: fix LE list UAF on reset (bsc#1012628). - HID: input: read battery capacity from its actual report offset (bsc#1012628). - HID: hyperv: validate initial device info bounds (bsc#1012628). - HID: uclogic: fix use-after-free of inrange_timer on remove (bsc#1012628). - HID: sensor: custom: Fix use-after-free in enable_sensor (bsc#1012628). - HID: ft260: fix stack-use-after-return write in I2C read race (bsc#1012628). - HID: core: fix number/pointer type confusion on long items (bsc#1012628). - HID: rapoo: fix missing hid_is_usb() check (bsc#1012628). - HID: nintendo: stop device IO before hid_hw_stop on probe failure (bsc#1012628). - HID: nintendo: register input device after capabilities are set (bsc#1012628). - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (bsc#1012628). - HID: huawei: fix missing hid_is_usb() check (bsc#1012628). - HID: asus: fix missing hid_is_usb() check (bsc#1012628). - net/ionic: avoid OOB TX partner lookup for hwstamp RXQ (bsc#1012628). - HID: pidff: fix OOB write when hid->inputs is empty (bsc#1012628). - HID: core: fix OOB read of field->usage in hid_set_field() (bsc#1012628). - HID: magicmouse: do not keep a stale msc->input if no input is claimed (bsc#1012628). - HID: magicmouse: re-enable multitouch after reset-resume (bsc#1012628). - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (bsc#1012628). - HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C (bsc#1012628). - nvmet: pci-epf: put CQ ref on create_cq mapping failure (bsc#1012628). - nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() (bsc#1012628). - nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations (bsc#1012628). - nvmet-tcp: bound SGL data length before allocating command buffers (bsc#1012628). - nvmet-fc: fix invalid free in LS IOD error path (bsc#1012628). - nvmet-auth: zero the AUTH_RECEIVE response buffer (bsc#1012628). - dmaengine: fsl-edma: Add error handling for devm_kasprintf (bsc#1012628). - mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() (bsc#1012628). - ipv6: fix use-after-free in ip6_finish_output2() (bsc#1012628). - ipv4: reject undersized MTUs in ip_do_fragment() (bsc#1012628). - nfc: nci: free destination parameters when closing a connection (bsc#1012628). - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (bsc#1012628). - nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (bsc#1012628). - nfc: nci: add data_len bound checks to activation parameter extractors (bsc#1012628). - nfc: st21nfca: validate ATR_REQ length against the received frame (bsc#1012628). - nfc: pn533: purge fragmented skbs during cleanup (bsc#1012628). - nfc: llcp: reject PDUs shorter than the LLCP header (bsc#1012628). - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (bsc#1012628). - nfc: llcp: bound the connect_sn TLV walk to the skb (bsc#1012628). - nfc: microread: validate target discovery payload lengths (bsc#1012628). - nfc: fdp: bound the device-reported read length and fix an skb leak (bsc#1012628). - nfc: digital: clamp SENSF_RES length to the destination buffer (bsc#1012628). - xfs: restore nofs context unconditionally in xfs_trans_roll (bsc#1012628). - xfs: validate attr entry pointer before field access (bsc#1012628). ... changelog too long, skipping 2398 lines ... - commit 585bfaf ==== kf6-attica ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Attica6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-baloo ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-baloo-file kf6-baloo-imports kf6-baloo-kioslaves kf6-baloo-tools libKF6Baloo6 libKF6Baloo6-lang libKF6BalooEngine6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Install kcfg file * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-bluez-qt ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-bluez-qt-imports libKF6BluezQt6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove obsolete doxygen file * mediatypes.h services.h types.h: provide version macros to consumers * fix: resolve race condition in Bluetooth object manager initialization. * Update version to 6.29.0 ==== kf6-breeze-icons ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6BreezeIcons6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Add im-matrix icon * Rename icons for typst mimetype * Add tab icons for KWin Options KCM * add Android App Bundle icons * remove inkscape cruft from Android Package Archive icons * Update version to 6.29.0 ==== kf6-frameworkintegration ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-frameworkintegration-plugin libKF6Style6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-karchive ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Archive6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * kzip: write data in chunks * Documentation fixes * kzip: zip64 write support (kde#514117) * kzip: use qToLittleEndian * kzip: change some ints to qint64 to allow writing zip64 archives * kzip: fix opening zip64 archives * Update version to 6.29.0 ==== kf6-kauth ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kauth-lang libKF6AuthCore6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kbookmarks ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Bookmarks6 libKF6BookmarksWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kcalendarcore ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * autotests/data/xCalendar-libicalV4 - update reference data for libicalv4 * Add methods for encoding/decoding iCal objects in QMimeData * Make ScheduleMessage a Q_GADGET * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kcmutils ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kcmutils-imports libKF6KCMUtils6 libKF6KCMUtilsCore6 libKF6KCMUtilsQuick6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * kpluginmodel: Only write enabled state when not default * Run clang-format * kcmshell: React to KCModule::representsDefaultsChanged * Update version to 6.29.0 ==== kf6-kcodecs ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Codecs6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * [KEncodingProber] Improve const-correctness * [KEncodingProber] Explicitly initialize some structs * [KEncodingProber] Replace pointer to SMModel with reference * [KEncodingProber] Fix broken UTF16 filtering for MBCS * [KEncodingProber] Fix GB18030 false positive * [KEncodingProber] Extend unit tests, notably for japanese text * [KEncodingProber] Shortcut no longer active group probers * [KEncodingProber] Refactor UnicodeGroupProber * [KEncodingProber] Refactor Unicode/UTF prober * [KEncodingProber] Clean up comments and naming for MB mapping * [KEncodingProber] Make one virtual base method pure virtual * [KEncodingProber] Remove obsolete padding in state tables * [KEncodingProber] Replace debug printf with categorized logging output * [KEncodingProber] Add dedicated logging category * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kcolorscheme ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6ColorScheme6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kcompletion ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Completion6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * KCompletionBase/KCompletionMatches: move Q_DECLARE_PRIVATE to PRIVATE * KCompletionBox::eventFilter: minimize code executed when filter not hit * Update version to 6.29.0 ==== kf6-kconfig ==== Version update (6.28.0 -> 6.29.0) Subpackages: kconf_update6 kf6-kconfig-imports libKF6ConfigCore6 libKF6ConfigGui6 libKF6ConfigQml6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove unused variables in KConfig implementation * Revert "kwindowstatesaverquick: Do not force-show windows" (kde#522205) * Add test for KConfigLoader ctor that takes KConfigGroup * Use Qt for ASCII && alphanumeric detection * Read config files in system locations before user-writable config files * Add tests to document status quo * kreadconfig: Add option to dump default values * kreadconfig: Dump entries sorted by group name/entry key * Don't change immutable non-default entry when setting default entry * Add failing tests demonstrating wrong behavior * Add helper to set/override an environment variable for a test * Remove obsolete doxygen file * Always insert deleted key into internal map (kde#519481) * Ensure that deleted default entries are deleted * Fix generated setters for enum options with UseEnumTypes * Export StandardAction as Q_ENUM_NS * Update version to 6.29.0 ==== kf6-kconfigwidgets ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6ConfigWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * kviewstatemaintainer.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-kcontacts ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Contacts6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove dependency on KCoreAddons * addresseelist.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-kcoreaddons ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kcoreaddons-imports libKF6CoreAddons6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * kdirwatch: use certified KDE if style with {} * KDirWatch: fix/tweak determination of default * KDirWatch: expose additional verbosity as envvar * Don't let fromAppStreamFile() modify the application data * aboutData: Add support for AppStream URLs * Documentation fixes * aboutData: Improve fromAppStreamForApplication() usability * Update version to 6.29.0 ==== kf6-kcrash ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Crash6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * delete the char ptrs properly as arrays * load platform details ahead of time (kde#518503) * Update version to 6.29.0 ==== kf6-kdav ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6DAV6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Use CardDAV allprop in multiget address-data * Make sure network replies are parented to the corresponding job * Add some debug to DavPrincipalSearchJob * Add a DavSslUiProxy to allow plugging user interaction for SSL errors * network: Setup more strict network policy * davitemmodifyjob: Fix redirection * davmanager: Add missing doctype to sent XML * Adapt tests * Port network management from KIO to QNAM * Add fetching DavPush data in DavCollectionsFetchJob * enums.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-kdbusaddons ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kdbusaddons-tools libKF6DBusAddons6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kdeclarative ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kdeclarative-imports libKF6CalendarEvents6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * graphicaleffects: Avoid complicated matrix multiply * graphicaleffects: Make shader uniform "buf" identical * graphicaleffects: Use "coord" input on lanczos.frag shader * graphicaleffects: Fix Lanczos shader path * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kded ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Use correct type for desktop file * Update version to 6.29.0 ==== kf6-kdesu ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Su6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kdnssd ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kdoctools ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6DocTools6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update Turkish entities * Update version to 6.29.0 ==== kf6-kfilemetadata ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6FileMetaData3 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * autotests/ossfuzz: clone libpng from github to fix unreliable sourceforge downloads * Fix overflow in extractAudioProperties * taglib: Protect against UnknownFrame * types.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-kglobalaccel ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6GlobalAccel6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kguiaddons ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kguiaddons-imports libKF6GuiAddons6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Add missing since information * Add KSystemClipboard::ownsClipboard * waylandclipboard: Properly clean up device and manager * kiconutils: Fix overlay emblem size and placement on non-square icons * Update version to 6.29.0 ==== kf6-kholidays ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kholidays-imports libKF6Holidays6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * lunarphase.cpp - use the system timezone rather than utc * Support Hebrew Calendar holidays (kde#383896) * .clang-tidy - update * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-ki18n ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-ki18n-imports libKF6I18n6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kiconthemes ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kiconthemes-imports libKF6IconThemes6 libKF6IconWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Add notes to drop dependency on KWidgetsAddons for KF7 * Update version to 6.29.0 ==== kf6-kidletime ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kidletime-plugins libKF6IdleTime6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kimageformats ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * autotests: add AVIF and JXL with animation * KRA/ORA: merged in a single plugin and added metadata support * Readme: update supported formats * Test Readme: added JPG support * avif: enable decoding of files with invalid EXIF metadata * autotests: allow JPG as test source * QOI: check format only in lowercase * ossfuzz: optimize build, collect all HEIF subformats * fix HEIC writetest * ossfuzz: enable uncompressed codec in libheif * heif: declare read support for HIF * EXIF: add support for Windows Explorer tags * heif: increase Maximum number of child boxes limit * HEIF: keep reader callback table alive (kde#523105) * More HEIF-related tests. * heif: AVCI saving, JPEG in HEIF read support * IFF: support for ZIP compressed RGFX * Update version to 6.29.0 - Drop patch: * 0001-HEIF-keep-reader-callback-table-alive.patch ==== kf6-kio ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6KIO6 - Add upstream fix (kde#524239, boo#1275906) * 0001-kfileitemactions-fix-submenu-lifetime-using-main-men.patch - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Too many changes since 6.28.0, only listing bugfixes: * WidgetsAskUserActionHandler: show the SSL error dialog on the GUI thread (kde#519614) * file: strip local host from file:// URLs before accessing the path (kde#483297) ==== kf6-kirigami ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kirigami-imports libKirigamiPlatform6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Clickable link OverlaySheet QML type (kde#522348) * FormEntry/FormAction (cards): fix items alignments * FormGroup/flat: Consider also invisible items for implicitWidth * Fix tst_menudialog not actually doing anything * Make the GlobalDrawer correctly size to its contents again * Sensible height for license sheet * FormEntry: don't show invalid leading ind trailing icons * FormEntry: fix the subtitle when the contentITem doesn't have an indicator * Default to small size in FormAction * Same default width that kirigami-addons form has * Port AboutItem to the new form layout * FormEntry: items don't fill the width by default * ScrollablePage: Fix enter animation running when changing focus (kde#515811) * Work around missing support for QKeyShortcut in shortcut * Icon: use QUrl::toLocalFile() for file: URL sources * Icon: keep the aspect ratio of portrait images with roundToIconSize * PlatformTheme: Only emit color changes if color actually changes * Icon: snap the aspect-preserving painted size to device pixels * autotests: fix flaky keyboard list navigation test * autotests: fix flaky test_defaultFocusInScrollablePage * NavigationTabBar: add scrolling/shortcuts for tab switching * ToolBarPageHeader: Rephrase page.actions check to make more sense * Make qml generation deterministic by adding explicit dependencies * Port application template away from deprecated ki18n API * controls: Guard against re-setting the global header with the same URL in Page * Update version to 6.29.0 ==== kf6-kitemmodels ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kitemmodels-imports libKF6ItemModels6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kitemviews ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6ItemViews6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kjobwidgets ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6JobWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-knewstuff ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-knewstuff-imports libKF6NewStuffCore6 libKF6NewStuffWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-knotifications ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-knotifications-imports libKF6Notifications6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Fix since version in documentation * Ensure we have notifyrc file for platform notification configuration * Add API for showing the platform's notification configuration * Remove message extraction in KNotifications * Update version to 6.29.0 ==== kf6-knotifyconfig ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6NotifyConfig6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kpackage ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Package6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kparts ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Parts6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kplotting ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kpty ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Pty6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kquickcharts ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-krunner ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Runner6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kservice ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Service6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Deprecate KSycoca::setupTestMenu * Fix static build by exporting resource targets * Remove LegacyDir from fallback applications.menu * Add fallback applications.menu file * ksycocatype.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-kstatusnotifieritem ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6StatusNotifierItem6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-ksvg ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-ksvg-imports libKF6Svg6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-ktexteditor ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6TextEditor6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * vi-mode: Avoid redundant BLOCK in the status bar * vi-mode: Fix synchronization of the view block selection * vi-mode: Fix block insert with tabs (kde#488801) * Drag pixmap: use devicePixelRatio of highest screen device pixel ratio * Drag pixmap: adapt hotspot to pixmap scaling * vi-mode: Add Ctrl-A command to insert mode * vi-mode: Implement column cursor swap for v-block mode * vi-mode: Update view selection when switching modes * vi-mode: Fix switching to vblock mode from another visual mode * vi-mode: Simplify switching to visual modes * vi-mode: Add the Date command * vi-mode: Fix cursor position after paste in insert mode * vi-mode: Fix cursor position after pasting block * vi-mode: Fix AltGr detection on Windows * renderer: Small refactoring of paintCaret method * renderer: Fix drawing of all the cursor styles * Change icon for search plugin display options * fix animation artifact during animation run * avoid initial draw * cleanup more painting * cleanup render hint setting * ensure we abort completion on config changes (kde#521492) * vi-mode: Fix count-paste of a block * Update version to 6.29.0 ==== kf6-ktexttemplate ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6TextTemplate6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Consider non-empty generic containers "true" as well * Turn scriptable tag support in a plugin, as originally intended * Use QLocale for currency value formatting * Don't hardcode ISO date/time format * token.h: provide version macros to consumers * Out-of-line the ScriptableTagLibrary destructor * Update version to 6.29.0 ==== kf6-ktextwidgets ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kunitconversion ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6UnitConversion6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kuserfeedback ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kuserfeedback-imports kf6-kuserfeedback-lang libKF6UserFeedbackCore6 libKF6UserFeedbackWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * CI - Flatpak - Update Runtime to 6.11 * Update version to 6.29.0 ==== kf6-kwallet ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kwallet-tools kwalletd6 libKF6Wallet6 libKF6WalletBackend6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Drop kwalletmanager launching from kwalletd * Move org.freedesktop.secrets group to KConfigXT * ksecretd: Drop unused functions * ksecretd: Drop registering KWallet interface * Use correct internal function to query local wallet * Port to KConfigXT * Drop code for writing default wallet in kwalletd * Query NetworkWallet and LocalWallet from backend * Fix localWallet with external backend * kwalletd: Remove config fallback for networkWallet() * Actually set ok to true when defaultCollection succeeds * Drop unused internal pamOpen from kwalletd * Drop dead screensaver integration * kwalletd: fix use-after-move in retrieveCollection() returning null on first lookup (kde#522847) * kwallet-query: persist writes to new entries (kde#491898) * Update version to 6.29.0 ==== kf6-kwidgetsaddons ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6WidgetsAddons6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * KColorCombo: support d'n'dropping colors to set the color * KColorButton, KColorCombo: add contextmenu for Copy & Paste of color * KColorCombo: fix missing render update on changing color from code * Split off KColorMimeData copy into separate file, for shared internal usage * KColorButton: mark drag properly as copy-only * KUrlLabel: fix default value of useCursor flag to match docs & used corsor * KAssistantDialog: Merge "next" and "finish" buttons * Allow to test if on last visibile page * KColorButton: use chained constructor calls over duplicating logic * Update version to 6.29.0 ==== kf6-kwindowsystem ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kwindowsystem-imports libKF6WindowSystem6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kxmlgui ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6XmlGui6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Avoid duplicate aboutToShow connections on the Settings menu * KEditToolBar: show no-drop cursor with "Available" list for own items * Update version to 6.29.0 ==== kf6-modemmanager-qt ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6ModemManagerQt6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-networkmanager-qt ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-networkmanager-qt-imports libKF6NetworkManagerQt6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-prison ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-prison-imports libKF6Prison6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Include only needed headers instead of QtConcurrent module header * Update version to 6.29.0 ==== kf6-purpose ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-purpose-services libKF6Purpose6 libKF6PurposeWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * AlternativesView: Added a disabledPlugins property * Update version to 6.29.0 ==== kf6-qqc2-desktop-style ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * TextArea: Use Wrap instead of WordWrap * Use StyleItem for item view background painting * Allow QPA Platform Themes to avoid KIconEngine * Prevent TextField height changes when switching echo modes * Update version to 6.29.0 ==== kf6-solid ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-solid-tools libKF6Solid6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * udisks2: StorageAccess: if '/' is a mountpoint, return that as filePath() * solidnamespace.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-sonnet ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-sonnet-imports libKF6SonnetCore6 libKF6SonnetUi6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-syndication ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Syndication6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-syntax-highlighting ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-syntax-highlighting-imports libKF6SyntaxHighlighting6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * don't do a reload on language change (kde#523233) * Slint: Include upstream changes * RTF: Fix unbounded context stack growth * cmake.xml: update syntax for CMake 4.4 * Fix listening for language changes, just react on the app instance event * Update MIME types for shell scripts * Meson: add meson.options to recognized extensions * m3u: add m3u8 as one possible extension * cpp: Add qmqlintegration macros from Qt 6.5 * Update version to 6.29.0 - Drop patch: * 0001-Fix-listening-for-language-changes-just-react-on-the.patch ==== kf6-threadweaver ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kgamma6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kgeography ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix Novaya Zemlya oblast (kde#522802) ==== kglobalacceld6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libKGlobalAccelD6-0 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== khangman ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix some cmake warnings ==== khelpcenter ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Apply content color scheme based on current theme ==== kidentitymanagement ==== Version update (26.04.3 -> 26.08.0) Subpackages: kidentitymanagement-lang libKPim6IdentityManagementCore6 libKPim6IdentityManagementWidgets6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * Fix coding style * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Add missing dep * identitytreedelegate.cpp - fix compile warning * Emit dataChanged after that we assign/save settings * Don't store qlineedit * Add check about value * Make sure that pointer is not null * USe QT_ENABLE_STRICT_MODE_UP_TO * Remove unused #include already includes by #include * KIDENTITYMANAGEMENT_LIB_VERSION is not used ==== kig ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kimap ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6IMAP6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes to list here. - Update build requirements ==== kinfocenter6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kio-extras ==== Version update (26.04.3 -> 26.08.0) Subpackages: libkioarchive6-6 trash_kcm - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * kcmtrash.cpp: fix trash settings not detecting multiple mounts (kde#469598) - Update to 26.07.90 * New feature release - Changes since 26.07.80: * workers: fill UDSEntry one value type at a time * smb: fix DFS namespace authentication (kde#510902) - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix incorrect display aspect ratio on SVG thumbnails with height > width * kio_thumbnail: poll wasKilled() in the directory thumbnail loops * Poll wasKilled() in worker transfer and listing loops * kio_filenamesearch: Skip content searches in /dev, /proc and /sys * Restore original "None" string in accordance with review comments * Update help tooltip in accordance with review comments * Web Search Keywords: Update tool tips and reduce duplication * Web Search Keywords: Show provider domain as tool tip for name column * Web Search Keywords: Allow the "Preferred" column to be sorted * Web Search Keywords: Add icons to action buttons * man: Accept a case insensitive or fuzzy match for the page name * sftp: avoid copying captured variables to pass to qScopeGuard * sftp: added an autotest suite using a paramiko-based sftp server * sftp: fixes for mime type detection and resuming files * proxykcm: fix auto configuration help button spacing * Use default DEFAULT_SEVERITY for logging * mtp: only handle portable media players that explicitly support MTP * D-Bus spec doesn't allow hyphens in object paths, exchanged for underscores, which are allowed (kde#516856) * Drop MinimumKeepSize from KCM * Drop MinimumKeepSize config from workers * filenamesearch: Treat any url with non empty path as invalid ==== kio_audiocd ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Install encoder plugins into subdirectory * Use default DEFAULT_SEVERITY for logging ==== kiten ==== Version update (26.04.3 -> 26.08.0) Subpackages: fonts-KanjiStrokeOrders - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kitinerary ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6Itinerary6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Add extractor script for Lufthansa PDF itineraries * Add autotests for new Lufthansa event format * Add train support to Lufthansa event extractor * Fix Lufthansa event extractor * Support seat ranges in DB PDF tickets * Support new Westbahn PDF ticket layout * Update SBB booking confirmation email filter pattern - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * Fix extracting return descriptions in FCB NRT tickets (kde#520826) - Update build requirements ==== kldap ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6LdapCore6 libKPim6LdapWidgets6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Fix includes * Move lib as public * Add missing QT version * Use QT_ENABLE_STRICT_MODE_UP_TO * ldapoperation: fix forwarding of client controls * Fix memory leak in Ber assignment operator * Add nullptr after assigned value * It can be nullptr => add Q_ASSERT * Remove dead code * Fix mem lead. strdup but never free it * Fix emit signal after adding it * Update coding style * We don't use it * Not used * Allow to use prek ==== kleopatra ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Clear lists of added keys and groups after removing their widgets * Avoid crash when modifying iterated list * Don't leak export jobs when dragging & dropping keys * Fix check of protocol of detached signature * Avoid multiple connections for each unknown recipient * Avoid crash while updating widgets for unknown recipients * Fix use-after-free on repeated decryption in the notepad (kde#523471) - Update to 26.07.80 * New feature release - Too many changes to list here. - Update build requirements ==== kmag ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Drop Qt5-code for linking QAccessibilityClient ==== kmahjongg ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kmail ==== Version update (26.04.3 -> 26.08.0) Subpackages: kmail-application-icons ktnef - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Fix bug 523845: KMail Segmentation fault (kde#523845) - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes to list here. - Update build requirements ==== kmail-account-wizard ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Reflect the move of KMime to Frameworks in the dependency data * Use QT_ENABLE_STRICT_MODE_UP_TO=0x060B00 * BUILD_QCH is not useful * Add forward compatibility with KMime from KDE Frameworks * Increase ktextaddons dep * Move license to REUSE.toml * Use prek support - Update build requirements ==== kmailtransport ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6MailTransport6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * transportmodel: Add roleNames for QtQuick * Add missing dependencies * Add missing public lib * Remove duplicate include(KDEGitCommitHooks) * Fix includes * Outlook SMTP: force XOAUTH token refresh when server returns authentication error (kde#500123) * Use prek + move license info in REUSE.toml ==== kmbox ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6Mbox6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * Fix first mbox entry being considered invalid * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Reflect the move of KMime to Frameworks in the dependency data * Add forward compatibility with KMime from KDE Frameworks * KMBOX_LIB_VERSION is unused * Add prek support - Update build requirements ==== kmenuedit6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kmines ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kmousetool ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kmplot ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== knighttime6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libKNightTime0 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kompare ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== konsole ==== Version update (26.04.3 -> 26.08.0) Subpackages: konsole-part konsole-part-lang - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Drop bogus ZLIB dependency * ViewManager: Add container loading back to createSession * EscapeSequenceUrlHotSpot: add Copy & Open actions (kde#520743) * Fix kitty graphics byteCount overflow - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Revert "Fix warnings from PreviewJob" - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * ViewSplitter: make sure restoreAll and hideRecurse set container visibility (kde#520395) * Implement Kitty keyboard protocol (kde#519627) * EditProfileMousePage: reword the open links setting (kde#481115) * Add automatic profile switching based on system theme (kde#449235) * Prevent QTabBar from closing tabs on middle mouse clicks * we could arrive here with already destructed currentTerminalDisplay() (kde#519274) * Fix duplicated Copy entry in Configure Keyboard Shortcuts dialog (kde#513011) ==== kontact ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Define stable version * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * BUILD_QCH is not useful * Use QT_ENABLE_STRICT_MODE_UP_TO * Increase ktextaddons dep * Add prek support ==== kontactinterface ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6KontactInterface6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * pimuniqueapplication.cpp - prevent crash in exportWindow() with Wayland * Add a signal for minuteChanged() * .kde-ci.yml - require merge requests do not introduce cppcheck issues * Use reinterpret_cast to convert from integral to pointer type * cppcheck-suppressions.xml - add cppcheck suppressions * cppcheck ignoredReturnValue fixes * cppcheck cstyleCast fixes * cppcheck uninitMemberVar fix * clang-tidy readability-const-return-type suppress * clang-tidy readability-inconsistent-declaration-parameter-name fixes * clang-tidy bugprone-integer-division suppression * clang-tidy misc-const-correctness fixes * clang-tidy misc-use-internal-linkage fix * clang-tidy strict-iterators fix * .clang-tidy - add the pim clang-tidy configuration * Add ECMInstalledLibraryCheck support * Fix compile on freebsd * Port to new api * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Remove unused variable * Move license info in REUSE.toml * Allow to use prek ==== konversation ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix build without QCA * Remove left-over KF version includes * Disconnect only the necessary signal * Wayland: position topic history context menu correctly * Simplify topic height measurement in channel dialog (kde#521536) * Prevent Sonnet-related crash * Remove duplicate headers in cpp files * Move to C++20 and clear up some warnings ==== korganizer ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Persist checked calendars by stable remote path * Better icons again that look good in dark-mode * lunarphases plugin - improve icons and complete the set of lunar phases - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * apptsummarywidget.cpp, summaryeventinfo.cpp - event in-progress or ended (kde#125162) * todosummarywidget.cpp, sdsummarywidget.cpp - use today and urgent colors (kde#107783) * Month view: add an option to display the event start and end times (kde#104732) * Add default access classification setting when creating new incidences (kde#474036, kde#55539) * Agenda View: allow showing incidence description in the agenda items (kde#364968) * calendarview.cpp - use the "from scratch" newTodo if summary is empty (kde#472725) * kitemiconcheckcombo.cpp - enable all icons in monthview too (kde#161652) * Implement holiday category selection and filtering. (kde#336147) * Implement holiday category selection and filtering. (kde#336147) * Agenda view: bold hour marker every two hours (kde#212164) - Update build requirements ==== kpat ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix Freecell docs about sequences (kde#519409) ==== kpimtextedit ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6TextEdit6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Add missing dependancy * precommit uses reuse now * Fix potential mem leak * compare with command line * Add parent * Move in same check * Fix includes * KPIMTEXTEDIT_LIB_VERSION is not used * src/CMakeLists.txt - remove unused KPimTextEdit_grantlee_HEADERS * Move license to REUSE * Allow to use prek support ==== kpipewire6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: kpipewire6-imports libKPipeWire6 libKPipeWireDmaBuf6 libKPipeWireRecord6 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kpkpass ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6PkPass6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add additional API for semantic tag seat information * Add basic support for semantic tag seat information * Also print ZIP decoding error when we fail to open a pkpass * Expose semantic tag API to QML as well * Expose translation catalog lookup in public API * Add method for checking whether a field value contains rich text markup * Support date-only/time-only field formats * Fix organization and description fields not being translated * Install Qt metatypes file * Support multi-row auxiliary fields * Add properties for checking whether a specific color is set * Support rgba() color values * Find image assets only existing in a higher pixel ratio variant as well * Add support for semantic tags and new pass styles * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Move CMakePresets.json.license to REUSE.toml * Use prek support ==== kqtquickcharts ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kreversi ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== ksanecore ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Inline now one-value-only CMake variable * Fix crash on skanlite startup (kde#517465) * Added internalValue(AsString) for PageSizeOption * Prevent translated values to appear in Interface::getOptionsMap() ==== kscreen6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * osd: trigger Configure button on Enter, too (kde#515214) * Update version for new release 6.7.4 ==== kscreenlocker6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libKScreenLocker6 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== ksmtp ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6SMTP6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Prepare to support cmake preset support * Add ecm_installed_library_check_version_preprocessor_macros/ecm_installed_library_check_preprocessor_macro * Add ECMInstalledLibraryCheck support * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * USe QT_ENABLE_STRICT_MODE_UP_TO * Add support for RFC 6532. * KSMTP_LIB_VERSION is not used * src/CMakeLists.txt - fix an uninitialized variable * Move license to REUSE.toml * Add prek support - Update build requirements ==== ksshaskpass6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Handle when unknown host prompt has no period after the finger print * Support unknown RSA when it has a colon (kde#444862) * Don't offer to remember password without identifier * prompt: Fix password change prompts * Update version for new release 6.7.4 ==== ksudoku ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * main: set surface format to support legacy OpenGL (kde#521401) ==== ksystemstats6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== ktextaddons ==== Version update (2.0.1 -> 2.1.2) Subpackages: libKF6TextAddons1 - Update to 2.1.2 * When we define default dialog size, it didn't work when screen scale size was different to 100% * In textaddons autogenerate lib, don't allow to collapse with double click in textautogeneratehistorylistview * Reduce duplicate FlowLayout class * Fix attachment widget layout (Use QToolButton). This class is used in kaichat. * Fix initialise variable in plugincommonmodelinstalledinfosdelegate * Reduce duplicate code in plugin textaddons autogenerate - Update to 2.1.1. No changelog. ==== ktnef ==== Version update (26.04.3 -> 26.08.0) Subpackages: ktnef-debug-categories libKPim6Tnef6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Use QT_ENABLE_STRICT_MODE_UP_TO=0x060B00 * KTNEF_LIB_VERSION is not used * Add prek support ==== ktouch ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kwalletmanager ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Disable UI for access control when unavailable - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * kwalletconfig.json: fix BugReportUrl * Bump KF_MIN_VERSION to 6.13 * Set a sensible default window size on first launch ==== kwayland-integration6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kwayland6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libKWaylandClient6 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Add support for wl_fixes.ack_global_remove * Update version for new release 6.7.4 ==== kwin6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libkwin6 - Add patch to improve issues after unplugging outputs: * 0001-wayland-Increase-global-removal-timer-timeout-to-1-d.patch - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * kcms/xwayland: Add missing default indicator * effects/windowview: fix current desktop class border activation * debugconsole: show executable for unknown sources * backends/drm: don't remove GPUs without outputs (kde#519461) * effect/quickeffect: fix QuickSceneEffect module reload condition * scene/windowitem: also set suspended state for dpms off * x11window: also take screen locking and dpms into account for visibility * opengl/egldisplay: work around libepoxy failing when GPU resets happen (kde#500114,kde#519263) * backends/drm: release the scanout buffer of virtual layers in beginFrame (kde#523353) * plugins/eis: Set zones mapping_ids * autotests: check the right virtual tablet before removing it * core/gpumanager: add KWIN_RENDER_NODES environment variable * kcms/effects: Take into account system-wide defaults * Update version for new release 6.7.4 ==== kwordquiz ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Remove not initialized variable ==== lapack ==== Subpackages: libblas3 libcblas3 liblapack3 - Switch Conflicts with openblas alterative providers from libopenblas_{openmp,pthreads,serial}0 to compatlibopenblas_{openmp,pthreads,serial}0 when not built with alternatives enabled. - Fix aarch64 build on 15.x by properly forcing macro expansion and dropping redundant %{_lto_cflags} ==== layer-shell-qt6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libLayerShellQtInterface6 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== leancrypto ==== - Add to the devel subpackage leancrypto-devel also a requires on libleancrypto-fips. (bsc#1273211) - Workaround for armv6 build (leancrypto assumes 32-bit is armv7) ==== libadwaita ==== Version update (1.9.2 -> 1.9.3) Subpackages: libadwaita-1-0 typelib-1_0-Adw-1 - Update to version 1.9.3: + AdwAboutDialog: Fix a bug with deselecting text in the legal section + AdwSidebar: Fix item suffixes ending up after the arrow in page mode + AdwTabOverview: Make sure we don't round corners in adaptive preview + AdwWindow/AdwApplicationWindow: Fix false minimum size warnings in adaptive preview + Updated translations. ==== libalternatives ==== Version update (1.2+31.da24cd4 -> 2.0+0.4f22c01) Subpackages: alts libalternatives1 - Update to version v2.0+0.4f22c01: * add missing test * Capture saved_errno correctly * Check for null pointer * reset argv0 to original if execve() fails * Clarify value of argv0 * Return errno from failed exec() * Use basename for argv[0] resolution * Update unit test * Document behaviour changes - KeepArgv0 is default * Correct pointer in corner case * Add UpdateArgv0 option * Clarify priority as increasing with integer size - Functionality change: KeepArgv0 is default option unless another is specified. Functionality should now be same as with symlinks (bsc#1262785) ==== libapparmor ==== - add changes-since-5.0.2.diff - several profile updates - fix compability with Swig 4.5 (boo#1275508) - drop upstreamed nslookup.diff - refresh kerberosclient-usrmerge.diff - add dovecot.diff with several dovecot profile updates (boo#1265453) ==== libdvdread ==== Version update (7.0.1 -> 7.1.1) - update to 7.1.1: * reduce the number of symbols exported to avoid conflicts when linking * DVD-Audio support: * Allow CPRM and CSS decryption support to be available simultaneously * Add Audio Still Video Set (ASVS) IFO structures and readers * Add ASVS and SAMG support to public IFO open APIs * Expose ASVS IFO, backup and menu VOB files * Improve AOB/VOB stream type handling * Misc fixes on structures documentation * DVD-VR support: * Add DVD-VR IFO parsing (PGIT, PG_GI, PS_GI) * Add DVDOpenVideoRecording functions * Add ifoOpenVideoRecording support * Add CPRM decryption support * Add DVDProbeType auto-detection for DVD-Video, DVD-Audio and DVD-VR * Add support for user-defined cells and time maps * Harden parsing of missing or malformed DVD-VR metadata * Add DVDOpenFiles for caller-provided virtual filesystem implementations * Split the internal filesystem implementation into platform- specific helpers * Improve file and directory handling on Windows, macOS and iOS * Improve logger fallback behavior when no controlling terminal is available * Add audio and subpicture code extension enums * Fixes and hardening: * Hardened IFO parsing for oversized still video groups * Fix DVD-Audio ASVS/SAMG fallback handling * Fix DVD-VR cell entry point byte swapping * Fix DVDFileSeek validation for non-sector-aligned files * Fix partial-block size accounting * Fix resource leaks, null pointer checks and error paths ==== libebml ==== Version update (1.4.5 -> 1.4.7) - Update to version 1.4.7 * Fixed cmake rules for building with utf8cpp 4.x version 1.4.6: * Set EbmlHead as not allowed to be infinite (as per RFC 8794) * Fix leak on upper element found inside the last element * EbmlString::ReadFully: use automatic memory management/fewer allocations * EbmlUnicodeString: use std::string when reading instead of manual memory management * IOCallback: avoid reading more than 2^32 at once * Fix some includes that are not implicit in modern compilers * Download utfcpp automatically * Show a summary of build configuration when configuring CMake * Add a DEV_MODE CMake option to check more compiler errors (default off) ==== libevdev ==== Version update (1.13.6 -> 1.13.7) - update to 1.13.7: * Refuse devices with more than 256 slots * Fix off-by-one in slot_value() bounds check * include: sync with kernel 7.0 ==== libfprint ==== Subpackages: libfprint-2-2 libfprint-2-tod1 - Add libfprint-tests subpackage with installed tests for gnome-desktop-testing-runner ==== libgedit-gfls ==== Version update (0.4.1 -> 0.4.2) - Update to version 0.4.2: + Updated translations. ==== libgedit-gtksourceview ==== Version update (299.7.0 -> 299.7.1) Subpackages: libgedit-gtksourceview-300-5 typelib-1_0-GtkSource-300 - Update to version 299.7.1: + Updated translations. ==== libgit2 ==== Version update (1.9.6 -> 1.9.7) - update to 1.9.7: * CVE-2026-5917: Escape remote repository paths in libssh2 (boo#1274971) ==== libgravatar ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6Gravatar6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Add public lib (need by public headers) * USe QT_ENABLE_STRICT_MODE_UP_TO * Use forward declaration * LIBGRAVATAR_LIB_VERSION not used * Move .license in REUSE file * Add prek support ==== libjpeg-turbo ==== Version update (3.1.4.1 -> 3.2.0) Subpackages: libjpeg8 libturbojpeg0 - update to 3.2.0: * Fixed a regression introduced by 3.2 beta1[9] that broke Arm64EC Windows builds. * Hardened the PNG writer (which is used by djpeg and tj3SaveImage*()) against applications that may erroneously attempt to write sample values that are out of range for the specified output data precision. * Hardened the libjpeg API against hypothetical applications that may erroneously call jpeg_crop_scanline() with buffered-image mode and raw data output enabled. * Fixed a buffer overrun and subsequent segfault in jpegtran that occurred when attempting to use the -crop and -trim options to expand the width of an image narrower than one iMCU, discard partial iMCUs, and fill each block in the expanded region with the DC coefficient of the nearest block in the input image ("flatten.") - deleted sources * libjpeg-turbo-3.1.4.1.tar.gz.sig (not needed) - added sources * libjpeg-turbo-3.2.0.tar.gz.sig ==== libkcddb-qt6 ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKCddb5 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * CMake config file: fix required version variable for KF6Config * Inline now one-value-only CMake variables * libkcddb: reset deprecation values (no deprecations yet in Qt6 variant) * Remove no longer used compatheader.h.in ==== libkdcraw ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKDcrawQt6-5 libkdcraw-qt6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Use KDE_INSTALL_TARGETS_DEFAULT_ARGS, KF_ one reserved for KF * Inline now one-value-only CMake variables * Remove no longer needed passing of namespace to KDcrawTargets export ==== libkdegames ==== Version update (26.04.3 -> 26.08.0) Subpackages: kdegames-carddecks-default libKDEGames6 libkdegames-imports - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * fix misspelled spdx id - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== libkdepim ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6Libkdepim6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Add missing dependency + move lib as public * Make sure that line is correctly removed * We don't use ++ value => simplify code * Make sure that item is not null * Fix QAssert logic * Make sure that it doesn't crash when list is empty * Coding style * kcheckcombobox.cpp - fix the lineeditor text display (kde#518240) * LIBKDEPIM_LIB_VERSION is not used * src/CMakeLists.txt - clean unused variables * Use prek + move license info in REUSE.toml ==== libkeduvocdocument ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== libkexiv2-qt6 ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKExiv2Qt6-0 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Use KDE_INSTALL_TARGETS_DEFAULT_ARGS, KF_ one reserved for KF * Remove duplicated and unused OUTPUT_NAME arg for KExiv2 properties * Inline now one-value-only CMake variables * Remove no longer needed passing of namespace to KExiv2Targets export * Remove no longer used deprecation version ==== libkgapi6 ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6GAPICalendar6 libKPim6GAPICore6 libKPim6GAPIPeople6 libKPim6GAPITasks6 libkgapi6-lang libkgapi6-sasl2-kdexoauth2 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Add method to set person from kcontacts addressee * Improve addressee edit details handling * Fix conversions for addresses * Add conversion test * Fix qstring comparisons * Fix wrong data insert that breaks recurrent event exceptions * Don't leak auth jobs * Delete network replies * Delete jobs created by unit tests * src/core/CMakeLists.txt - remove unused/uninitialized variables ==== libkleo ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6libkleo6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Drop 0001-Revert-Explicitly-use-Boost-s-cmake-config-file.patch, no longer needed - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Don't leak jobs in formattingtest * Use simple linear search to find given key filter - Update to 26.07.80 * New feature release - Too many changes to list here. ==== libkmahjongg ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKMahjongg6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== libkomparediff2 ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== libksane ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKSaneWidgets6 libksane-icons libksane-lang - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Adapt name of CMake config file template to new library name * CMake config file: fix required version variable for Qt6Widgets * Inline now one-value-only CMake variables * Remove no longer needed passing of namespace to KSaneWidgetsTargets export ==== libkscreen6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libKF6Screen8 libKF6ScreenDpms8 libkscreen6-plugin - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Remove unused maxPriority variable in adjustPriorities() * fix: emit edrPolicyChanged() instead of getter in setEdrPolicy() * Update version for new release 6.7.4 ==== libksieve ==== Version update (26.04.3 -> 26.08.0) Subpackages: libksieve6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes to list here. - Update build requirements ==== libksysguard6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: ksysguardsystemstats6-data libKSysGuardSystemStats2 libksysguard6-imports libksysguard6-plugins - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * systemstats: don't keep dangling SensorObject pointers in SensorContainer (kde#523562) * Update version for new release 6.7.4 ==== liblqr ==== Version update (0.4.2 -> 0.4.3) - update to 0.4.3: * Fix autogen.sh/configure.ac ==== libmatroska ==== Version update (1.7.1 -> 1.7.2) - update to 1.7.2: * Do not allow infinite sizes on all Master elements except Segment+Cluster * Only allow `KaxSeekId` of 4 bytes length (as per RFC 9559). * KaxBlock: release read buffers on `EndOfStream` error. * Catch some allocation failures internally. * Deprecate `KaxTrackMinCache`/`KaxTrackMaxCache` elements (as per RFC 9559). * Deprecate `KaxTrackOverlay` element (as per RFC 9559). * Fix `MATROSKA_VIDEO_FIELDORDER_TOPFIELDSWAPPED`/ * `MATROSKA_VIDEO_FIELDORDER_BOTTOMFIELDSWAPPED` values. * Add missing `MatroskaChapProcessCodecID` enum. * [API break] remove `MatroskaChapterTranslateCodec`/`MatroskaT rackTranslateCodec`. * KaxSemantic: update enum comments to match RFC 9559. * Add `MATROSKA_CHAPTERSKIPTYPE_INTERMISSION` to `MatroskaChapterSkipType`. * Fix some includes that are not implicit in modern compilers. * Show a summary of build configuration when configuring CMake. * Add a DEV_MODE CMake option to check more compiler errors (default off). * Add a BUILD_EXAMPLES CMake option (default off). ==== libopenmpt ==== Version update (0.8.7 -> 0.8.9) - Update to version 0.8.9: * [Sec] Possible heap out-of-bounds write when loading SymMOD files containing WAV IMA ADPCM samples. See also https://github.com/OpenMPT/openmpt/security/advisories/GHSA-fxf7-wc37-p2cx * [Sec] Possible heap out-of-bounds read when loading custom tunings from MPTM files. - Charges in version 0.8.8: * IT: Due to an Impulse Tracker bug in Compatible Gxx mode, Envelope Carry may not resume the envelope from the correct position when there is both an instrument number and tone portamento next to a note. * XM: NitroTracker ignores instrument numbers where there is no note next to them, so they are no longer imported. Fixes various NitroTracker-made XMs such as notominous-a19.xm. * STK: Loosen heuristics a bit to allow STK.CRB-GreatMuzaxs6 to load. * GT2: Loading file versions 6 and later was broken since libopenmpt 0.8.0. ==== libostree ==== Version update (2026.2 -> 2026.4) Subpackages: libostree-1-1 - Update to 2026.4: * Revert the static delta decompression-size safety margin introduced in 2026.3, which turned out to reject legitimate large deltas at apply time -- most visibly, Flathub Firefox updates were failing with Decompressed delta part exceeds configured limit. Both the margin heuristic and the flat 512MiB per-part decompression cap it fed into have been dropped for now. This deliberately reopens a DoS (unbounded decompression of a given delta part) until a precise, per-part exact-size- based replacement lands in a future release. The LZMA decoder memory limit (100 MiB) from that same advisory's fix is unaffected and remains in place (boo#1273918) * core: fixed a bug that caused every other xattr entry to be skipped during validation, letting a crafted xattr array hide unsorted or duplicate entries in odd-indexed slots - Update to 2026.3: * Unbounded LZMA decompression in static delta processing allows denial of service via decompression (boo#1273918) * Heap buffer overflow via integer truncation in static delta bspatch on 32-bit systems (boo#1273917) ==== libplasma6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libPlasma7 libplasma6-components libplasma6-desktoptheme - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Use Wrap instead of WordWrap everywhere (kde#523614) * ExpandableListItem: resize properly when number of enabled contextual actions changes (kde#506295) * Update version for new release 6.7.4 ==== libpsl ==== Version update (0.23.1 -> 0.23.3) - Update to version 0.23.3: * meson: compile and run the copyright-year helper program with the native (build machine) compiler, so that cross builds no longer abort at configure time * No change to the library code itself - this package is built with the autotools build system, which is unaffected - Update to version 0.23.2: * Fix a configure.ac typo (LC_ALL=Cdate) that made COPYRIGHT_YEAR ignore SOURCE_DATE_EPOCH and fall back to the current build date, so the copyright year embedded in the installed libpsl.h and in the psl.1 manual page is reproducible again * meson: derive the copyright date with portable C code instead of invoking the external date command * Drop the empty README file in favour of README.md ==== libreoffice ==== Version update (26.2.5.1 -> 26.2.5.2) Subpackages: libreoffice-base libreoffice-calc libreoffice-draw libreoffice-filters-optional libreoffice-gnome libreoffice-gtk3 libreoffice-icon-themes libreoffice-impress libreoffice-l10n-en libreoffice-mailmerge libreoffice-math libreoffice-pyuno libreoffice-qt5 libreoffice-qt6 libreoffice-writer libreofficekit - Update to 26.2.5.2: * Release notes: https://wiki.documentfoundation.org/Releases/26.2.5/RC2 ==== librest ==== Subpackages: librest-1_0-0 typelib-1_0-Rest-1_0 - Add librest-CVE-2026-16615.patch: Fix weak random number generation (bsc#1272399, glgo#GNOME/librest!44). ==== librist ==== - Switch from mbedtls to gnutls ==== librsvg ==== Subpackages: librsvg-2-2 typelib-1_0-Rsvg-2_0 - Disable librsvg --test reference, failing with new pango 1.58.2 ==== libseccomp ==== - `python` build should not install non-Python files. - replace deprecated 'setup.py install' with PEP 517 wheel install ==== libselinux ==== Subpackages: libselinux1 selinux-tools - fix swig 4.5.0 compatibility (bsc#1275512). adding libselinux-Replace-PyString_FromString-with-PyUnicod.patch - Drop man_selinux_disabled_mismatch_kernel_config.patch, current libselinux doesn't behave like this anymore ==== libselinux-bindings ==== - fix swig 4.5.0 compatibility (bsc#1275512). adding libselinux-Replace-PyString_FromString-with-PyUnicod.patch ==== libshumate ==== Version update (1.6.2 -> 1.6.3) Subpackages: libshumate-1_0-1 typelib-1_0-Shumate-1_0 - Update to version 1.6.3: + Deselect markers before removing from layer ==== libsoup ==== Subpackages: libsoup-3_0-0 typelib-1_0-Soup-3_0 - Fix runtime dependency of libsoup-tests, correctly requiring libsoup-3_0-0 - Add libsoup-CVE-2026-12548.patch: Fix heap out-of-bounds read flaw when parsing multipart HTTP messages. (bsc#1272196, glgo#GNOME/libsoup!524) - Add libsoup-tests subpackage with installed tests for gnome-desktop-testing-runner ==== libsoup2 ==== - Add libsoup2-CVE-2026-12548.patch: Fix heap out-of-bounds read flaw when parsing multipart HTTP messages. (bsc#1272196, glgo#GNOME/libsoup!524) - Add libsoup2-tests subpackage with installed tests for gnome-desktop-testing-runner ==== libssh ==== Subpackages: libssh-config libssh4 - Fix libssh ignores system wide crypto policies (bsc#1272547) * Add patch: libssh-cmake-Add-option-WITH_HERMETIC_USR.patch ==== libstorage-ng ==== Version update (4.5.341 -> 4.5.342) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - Translated using Weblate (Lao) (bsc#1149754) - 4.5.342 ==== libupnp ==== Version update (22.0.4 -> 22.0.6) Subpackages: libixml22 libupnp22 - Update to release 22.0.6 * Build fixes for OmniOS ==== liburing ==== Version update (2.14 -> 2.15) - exclude more tests: they fail on 7.2 so far - update to 2.15 * Classic BPF (cBPF) filter support. * New register helpers: io_uring_register_query() and io_uring_register_zcrx_ctrl() * Out-of-source build support. * Many other improvements, see: https://github.com/axboe/liburing/releases/tag/liburing-2.15 - disable some new tests for SLE 15 and 16 - keyring updated ==== libva ==== Version update (2.24.0 -> 2.24.1) Subpackages: libva-drm2 libva-wayland2 libva-x11-2 libva2 - update to 2.24.1: * va: include for getuid/getgid in secure_getenv fallback ==== libva-gl ==== Version update (2.24.0 -> 2.24.1) - update to 2.24.1: * va: include for getuid/getgid in secure_getenv fallback ==== libvirt ==== Subpackages: libvirt-client libvirt-daemon-common libvirt-daemon-config-network libvirt-daemon-driver-network libvirt-daemon-driver-nodedev libvirt-daemon-driver-qemu libvirt-daemon-driver-secret libvirt-daemon-driver-storage libvirt-daemon-driver-storage-core libvirt-daemon-driver-storage-disk libvirt-daemon-driver-storage-iscsi libvirt-daemon-driver-storage-iscsi-direct libvirt-daemon-driver-storage-logical libvirt-daemon-driver-storage-mpath libvirt-daemon-driver-storage-rbd libvirt-daemon-driver-storage-scsi libvirt-daemon-lock libvirt-daemon-log libvirt-daemon-plugin-lockd libvirt-daemon-qemu libvirt-libs - CVE-2026-77159: qemu: tpm: Avoid following symlinks when chown'ing log file bsc#1274946 - CVE-2026-18917: remote: Fix integer overflow in RPC handler for virNodeGetFreePages bsc#1275863 ==== libwacom ==== Version update (2.19.0 -> 2.19.1) Subpackages: libwacom-data libwacom9 - update to 2.19.1: * Build fixes for older systems and other arches ==== libxfce4windowing ==== Version update (4.20.6 -> 4.20.7) Subpackages: libxfce4windowing-0-0 libxfce4windowing-lang libxfce4windowingui-0-0 - Update to version 4.20.7 * Add xfw_monitor_get_edid() * Support the xfce-output-private-v1 protocol * build: Add missing check for bind_textdomain_codeset * Implement xfce-foreign-toplevel-management-private-v1 * Remove G_GNUC_CONST * gobject-linter: Fix property_enum_coverage * gobject-linter: Fix missing_implementation * gobject-linter: Fix use_g_steal_pointer * gobject-linter: Fix g_param_spec_static_strings * gobject-linter: Fix use_clear_functions * gobject-linter: Fix matching_declare_define * gobject-linter: Fix property_switch_exhaustiveness * cppcheck: Fix invalidPrintfArgType_sint warning in test code * Fix includes that should use double quotes * cppcheck: Fix knownConditionTrueFalse * cppcheck: Fix unreadVariable * cppcheck: Fix invalidPrintfArgType_sint * scan-build: Update false positive file after clang version bump * Fix fallback icons for pixmaps path * Translation Updates ==== libxmlb ==== - Add libxmlb-tests subpackage with installed tests for gnome-desktop-testing-runner ==== linux-glibc-devel ==== Version update (7.1 -> 7.2) - Update to kernel headers 7.2 ==== live555 ==== Version update (2026.06.01 -> 2026.08.14) Subpackages: libBasicUsageEnvironment2 libUsageEnvironment3 libgroupsock33 - update to 2026.08.14: * Fixed a bug that could cause a problem with subclassed variants of H.264 or H.265 RTP sinks. * Fixed old code in "GroupsockHelper.cpp" that was using hardcoded numeric error numbers * Fixed a memory leak that could occur when parsing a SDP description that contains two or more * When adding protection against the use of 'stolen' RTSP session ids we forgot to do so for every "SETUP" command. This release fixes that. * Fixed a typo in "RTSPCommon.cpp": "smtpe" -> "smpte". * Updated the RTSP server implementation to return a "Unsupported Transport" error if a "SETUP" request does not include a "Transport:" header. * Added "-std=c++20" to the "CPLUSPLUS_FLAGS" line in each "config.*" file, so that "std::atomic_flag::test" will compile with compilers that support * Made the parsing of MP3 audio files more robust to protect against malformed MP3 data. * Minor change to "testProgs/testRTSPClient.cpp" to make compiling on Mac OS X happier. ==== llvm22 ==== - Add llvm-deterministic-loopunroll.patch for reproducible builds. - Remove soft limit on open files. Depending on the number of jobs, linking can sometimes open more than 1024 files (boo#1261761). ==== localsearch ==== - Replace pkgconfig(gexiv2) with pkgconfig(gexiv2-0.16) BuildRequires: Use the new stable branch of gexiv. ==== lokalize ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Revert "Add KDDockWidgets as new dependency" - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * Fix Tab button for keyboard navigation (kde#519058) * feature: expand project list directories to show untranslated files (kde#517866) * Sort terms in Glossary View (kde#442704) * Remove unnecessary menu action, disable project tab Edit menu (kde#517633) * Fix KXMLGUI menu deletion (kde#517631) * fix: stop constant "load project?" dialogues when closing tabs / project (kde#516944) * fix: editor tab labels display file name and dir rather than complete file path (kde#516928) * fix: enabling movement of previous/next bookmark in filtered view (kde#517200) ==== mailcommon ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6MailCommon6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Add noexcept here * Add missing dependancies * Add KPim6::MessageViewer in public (need by some headers) * Add missing QMetaType for Q_DECLARE_METATYPE * Use index not current index * Fix EntityCollectionOrderProxyModel::lessThan with isUnifiedMailboxesAgent * Fix check * Fix check index * Fix invalid index * Assign directly not using temporary element * Don't duplicate item * coding style * Increase PlasmaActivities version * Reflect the move of KMime to Frameworks in the dependency data * Port to the named-argument variant of the Akonadi CMake test macro * Remove unused include * Add forward compatibility with KMime from KDE Frameworks * Use if(..) as in release mode it can crash * MAILCOMMON_LIB_VERSION unused * Use PIM_VERSION * Use prek + move license info in REUSE.toml - Update build requirements ==== mailimporter ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6MailImporter6 libKPim6MailImporterAkonadi6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Move lib as public when necessary for headers * Add prek support * Reflect the move of KMime to Frameworks in the dependency data * Add forward compatibility with KMime from KDE Frameworks * MAILIMPORTER_LIB is not used - Update build requirements ==== markdownpart ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== mbox-importer ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add find_package(KF6I18n...) * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * USe QT_ENABLE_STRICT_MODE_UP_TO * BUILD_QCH is not useful * Remove unused variables * Add prek support ==== messagelib ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Save DKIM authentication servers immediately * HasInvitation must be unique - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Fix the "Open Attachment" dialogue appearing after an attachment drag (kde#506314) - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * contactdisplaymessagememento.cpp - Fix crash in slotSearchJobFinished() (kde#521291) * Do not convert \n into
(kde#368394) - Update build requirements ==== microos-tools ==== Version update (4.0+git28 -> 4.0+git29) - Update to version 4.0+git29: * Move man-online to an own sub-package ==== milou6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== mimetreeparser ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6MimeTreeParserCore6 libKPim6MimeTreeParserWidgets6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes to list here. - Update build requirements ==== mozilla-nss ==== Version update (3.125 -> 3.126.1) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs mozilla-nss-tools - update to NSS 3.126.1 * bmo#2054719 - fix content type tag for CMS AuthEnvelopedData plaintext - update to NSS 3.126 * no public releasenotes - Move the test suite into a separate multibuild flavour: * the test suite is 1465s of a 1586s build, of which only 83s is compiling nss itself, and 1278 packages build depend on nss, so a large part of the distribution waits on it * the default flavour now builds and packages only, the new test flavour runs the same suite completely unchanged * the test flavour ships no packages, so a red run blocks no rebuild * the sqlite3 command line tool is only used by the test suite and is now required by that flavour alone - No shipped file changes: the FIPS integrity checksums are produced by shlibsign in build and again in the install post step, both of which run before check, so the test suite only ever consumed them ==== mozjs140 ==== Version update (140.13.0 -> 140.14.0) - Update mozjs140-rust1.98.patch: Base the patch on upstream commited solution from commit 1ecaa12: andle the *-oe-linux-* rust targets added in rustc 1.98 in rust target detection. - Add mozjs140-rust1.98.patch: Fix detection of rust target when building against Rust 1.98 (build system gets confused by the new target x86_64-oe-linux-gnu). - Update to version 140.14.0: + Various security fixes + See https://www.firefox.com/en-US/firefox/140.14.0/releasenotes/ ==== msgraph ==== Version update (0.3.4 -> 0.3.5) - Update to version 0.3.5: + drive: fall back to /me/drive when /me/drives is denied + doc: update URLs ==== multipath-tools ==== Version update (0.15~1+230+suse.d36a6a70 -> 0.15.1+227+suse.6644513) Subpackages: kpartx libmpath0 - Update to version 0.15.1+227+suse.6644513 (see NEWS.md for details) * The `preferredip=`parameter for the `iet` prioritizer has been generalized. See multipath.conf(5) for details. - Upstream fixes for vulnerabilities: * DoS on mulipathd socket by blocking IPC send operations (GHSA-hmcm-9cq4-r2xm bsc#1277199) * DoS on multipathd socket by exhausting connections (GHSA-pvp6-c9p3-25fp bsc#1277203) * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (GHSA-g5mh-253r-jjw5 bsc#1277205) * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (GHSA-pxwh-g75c-95pc 1277208) * kpartx: Heap Out-of-Bounds Read in GPT Header Validation (GHSA-p6rh-9x9j-3hvx, bsc#1277209) * Path traversal in device-mapper-multipath failed_wwids management (GHSA-gr7q-prfc-q636 bsc#1277210) * libmpathpersist PRIN READ FULL STATUS parser — unbounded descriptor rewrite causes root heap overflow (GHSA-hj7j-qr9h-5fv6 bsc#1277212) - Bug fixes: * Fix use-after free error during shutdown (gh#opensvc/multipath-tools#152) * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155) ==== mutter ==== Version update (50.3 -> 50.4) - Update to version 50.4: + Fix blurred rendering with non-pixel-aligned monitors + Do not add unsupported fallback monitor modes + Fill in mastering display metadata for HDR output + Fix invalid redraw clips on rotated monitors + Fixed crashes + Misc. bug fixes and cleanups + Updated translations. ==== ncurses ==== Version update (6.6.20260613 -> 6.6.20260815) Subpackages: libncurses6 ncurses-utils terminfo terminfo-base terminfo-iterm terminfo-screen - Add ncurses patch 20260815 + improve tic warnings for paired capabilities, including ich/ich1. + use xterm+tmux2 in xterm+nofkeys to match xterm patch #407 -TD + use ST in xterm+osc104 -TD + use ansi+sc -TD + modify test/dup_field.c to also demonstrate link_field(). + work around use of ^D for exiting test/ncurses except in the form test which uses ^D for movement (patch by Branden Robinson). + improve appearance of test/dup_field and test/move_field, adding a help-hint (patches by Branden Robinson). + improve formatting/style of manpages (patches by Branden Robinson). + add limit-checks in lib_screen.c and lib_ins_wch.c in case a 2-cell character is added at the right-margin (report by Miroslav Lichvar). + improve limit-check for extended names in _nc_read_termtype (report/patch by Yeo Jooho). + improve description of init_extended_color in man page (patch by Andrew Burgess). + modify test/Makefile.in to fix "make check" when ncurses is built in a non-source tree (report by Bruno Haible). - Add ncurses patch 20260808 + various improvements/fixes to test/dup_field.c + correct a check for FORM* in test/tracemunch + correct an ifdef in delscreen when using --enable-reentrant (report by Vassili Courzakis). + modify dup_field to allocate buffers needed for wide-character configuration of dup_field (report by Serhiy Storchaka). + correct masking of wide characters into chtype in winch (report by Serhiy Storchaka). - Add ncurses patch 20260801 + use ansi+csr in aaa+dec -TD + use ansi+idc in hurd, tw100, vt420 -TD + use ansi+erase in tw100 -TD + add vt100+tabs -TD + fix unbounded recursion in winsch if given a parameter which is not a valid character in the current encoding (report/analysis by Serhiy Storchaka). - Add ncurses patch 20260725 + use ansi+cpr in beterm -TD + use ansi+csr in aixterm, att6386, hirez100, iris-ansi -TD + use ansi+idc in vt220-base -TD + add ansi+sc -TD + fixes for compiler warnings/cppcheck. + amend 20260307 change to read_entry.c, to allow reading terminfo compiled in ncurses 6.1 and earlier (reports by Todd Richmond, Sven Joachim, cf: 20180331). - Add ncurses patch 20260718 + drop kbs from vt100+arrows and vt100+apparrows to increase usage -TD + add xterm+24fkeys -TD + fixes to escape comma and backslash consistently with infocmp for - g/-G options. - Add ncurses patch 20260711 + add otty -TD + add vt100+arrows, vt100+apparrows -TD - Add ncurses patch 20260704 + add zutty -TD + modify winch() and winsch() to use wcstombs() to convert 8-bit codes to Unicode when ncurses is configured to support Unicode but is not using UTF-8 encoding (report/analysis by Serhiy Storchaka). + fixes for compiler warnings/cppcheck. + fixes for scan-build, valgrind build/testing. + fix a memory leak in _nc_resolve_uses2 (report/testcase by Yufeng Wu, Zhijie Zhang, Qizhen Xu) + add a check for escaped nul in fmt_complex (report/testcase by Yufeng Wu, Zhijie Zhang, Qizhen Xu). + add a limit-check in _nc_tgetent (report by Utku Yildirim). + add a buffer-limit check in tgetstr. - Port ncurses-6.6.dif, ncurses-5.9-ibm327x.dif, and ncurses-6.5-ghostty.dif - Add ncurses patch 20260627 + add a makefile symbol for the names of the installed libraries to simplify parallel build of more than one configuration (patch by Luca Fancellu). + change misc/Makefile to eliminate "pc-files" stamp target (report by Luca Fancellu). + change internal type for file-descriptor to int, eliminate cast (report by Antonio Nino Diaz). + add xon to several entries, based on manuals and product descriptions -TD + revise adm36, based on manual -TD + add u6, u7, kdch1 to vp3a+ based on manual -TD + add u6, u7, home, cbt to adm20 based on manual -TD - Add ncurses patch 20260620 + add il1 to ibcs2 -TD + add ich1 to several entries, providing for support of non-curses applications via termcap only -TD + add ich/ich1 to teraterm2.3 based on ttsrcp23.zip source-code -TD + add ich/ich1 to x10term based on X.V10R4/xterm source-code -TD + add ich/ich1 to xterm-r6 based on source-code -TD + add ich/ich1 to mterm-ansi and decansi based on source-code -TD + add ich/ich1 to tek4025a, tek4105a, tek4106brl from manual -TD + modify infocmp, tic, and tgetent to omit ich1 (termcap "ic") while providing termcap data when smir/rmir (termcap "im/ei") are given. + reduce warning in tic regarding termcap applications which do not work with smir/rmir combined with ich1. ==== nghttp3 ==== - Add curl-impersonate.patch backporting backward compatible changes used by curl-impersonate project ==== ngtcp2 ==== Subpackages: libngtcp2-16 libngtcp2_crypto_gnutls8 libngtcp2_crypto_ossl0 - Require boringssl-devel >= 0.20260813 at build time: the previous 0.20210430 snapshot lacks SSL_set_quic_early_data_context, so configure rejected it with a misleading "boringssl was requested but not found" failure instead of an unresolvable dependency - Add ngtcp2-boringssl-shared.patch bulding the boringssl bridge as shared library - Enable building the boringssl bridge in Factory - Add curl-impersonate.patch backporting backward compatible changes used by curl-impersonate project ==== numlockx ==== - Implement default NumLock state, uses KBD_NUMLOCK variable in /etc/sysconfig/keyboard using /run/numlock-on set by kbdsettings.service from kbd package (numlockx-sysconfig-default.patch). ==== nvidia-open-driver-G06-signed ==== Version update (580.159.03_k7.1.6_1 -> 580.178.04_k7.2.0_1) - update CUDA variant to 580.178.04 - supersedes kernel-5.14.patch, linux-7.1.patch - update non-CUDA variant to version 580.178.04 (boo#1271603) ==== nvidia-open-driver-G07-signed ==== Version update (595.84_k7.1.6_1 -> 595.99.02_k7.2.0_1) Subpackages: nvidia-open-driver-G07-signed-kmp-64kb nvidia-open-driver-G07-signed-kmp-default - update non-CUDA variant to 595.99.02 (boo#1277068) - enable -rt kernel flavor for SLE >= 16.1 - update non-CUDA variant to 595.91.07 (boo#1271601) - update CUDA variant to 610.57.04 - update CUDA variant to 610.57.02 - supersedes linux-7.0.patch - update non-CUDA variant to 595.91.05 (boo#1271601) ==== nvidia-open-driver-G07-signed-cuda ==== Version update (610.43.02_k7.1.6_1 -> 610.57.04_k7.2.0_1) Subpackages: nvidia-open-driver-G07-signed-cuda-kmp-64kb nvidia-open-driver-G07-signed-cuda-kmp-default - update non-CUDA variant to 595.99.02 (boo#1277068) - enable -rt kernel flavor for SLE >= 16.1 - update non-CUDA variant to 595.91.07 (boo#1271601) - update CUDA variant to 610.57.04 - update CUDA variant to 610.57.02 - supersedes linux-7.0.patch - update non-CUDA variant to 595.91.05 (boo#1271601) ==== ocean-sound-theme6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== okular ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Accept invalid data in DOM (restore pre-qt6.12 default) * Notify the user about possible changes at printing * Don't execute load-scripts on signed documents * Block some actions for signature fields - Update to 26.07.90 * New feature release - Changes since 26.07.80: * fix(core): use atomic for FontExtractionThread::mGoOn to prevent data race * fix(script): remove double-free in JSApp::alert() * fix: resolve ScriptAction memory leak in openDocument - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * Revert "Improve annotation window sizing and positioning" (kde#518663) * Dont autorepeat color invert shortcuts (kde#519246) * Add ability to copy and paste annotations (kde#427629) * Add column-number to emacsclient command in editor-settings (kde#518741) ==== openSUSE-release ==== Version update (20260806 -> 20260830) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openexr ==== Version update (3.4.13 -> 3.4.14) Subpackages: libIex-3_4-33 libIlmThread-3_4-33 libOpenEXR-3_4-33 libOpenEXRCore-3_4-33 - version update to 3.4.14 * [CVE-2026-68514](https://www.cve.org/CVERecord?id=CVE-2026-68514) PyOpenEXR deep prefixed literal RGB key collision heap buffer overflow * [CVE-2026-68513](https://www.cve.org/CVERecord?id=CVE-2026-68513) PyOpenEXR prefixed literal RGB key collision heap buffer overflow * [CVE-2026-62986](https://www.cve.org/CVERecord?id=CVE-2026-62986) PyOpenEXR deep prefixed RGB stale lane disclosure * [CVE-2026-61703](https://www.cve.org/CVERecord?id=CVE-2026-61703) PyOpenEXR deep mixed RGB heap buffer overflow * [CVE-2026-61555](https://www.cve.org/CVERecord?id=CVE-2026-61555) empty multiView viewFromChannelName file crash * [CVE-2026-59985](https://www.cve.org/CVERecord?id=CVE-2026-59985) ILP32 OpenEXRCore RLE decode heap OOB read DoS * [CVE-2026-59984](https://www.cve.org/CVERecord?id=CVE-2026-59984) ILP32 B44 InputFile decode scratch buffer overflow * [CVE-2026-59983](https://www.cve.org/CVERecord?id=CVE-2026-59983) ILP32 DeepTiledInputFile sample count table decode OOB read * [CVE-2026-59982](https://www.cve.org/CVERecord?id=CVE-2026-59982) ILP32 DWAA InputFile packed AC buffer overflow * [CVE-2026-59981](https://www.cve.org/CVERecord?id=CVE-2026-59981) OpenEXRUtil SampleCountChannel row nonzero dataWindow heap OOB read * [CVE-2026-59189](https://www.cve.org/CVERecord?id=CVE-2026-59189) OpenEXRUtil DeepImageChannel row nonzero dataWindow heap OOB read * [CVE-2026-59187](https://www.cve.org/CVERecord?id=CVE-2026-59187) OpenEXR exrmetrics deep pixelmode heap buffer overflow * [CVE-2026-59186](https://www.cve.org/CVERecord?id=CVE-2026-59186) OpenEXR ILP32 TiledRgbaInputFile large tile Array2D heap OOB write * [CVE-2026-59184](https://www.cve.org/CVERecord?id=CVE-2026-59184) OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write * [CVE-2026-59183](https://www.cve.org/CVERecord?id=CVE-2026-59183) Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile Decoding - for other changes see CHANGES.md - fixes CVE-2026-59183 [bsc#1276428] CVE-2026-65979 [bsc#1276843] CVE-2026-68513 [bsc#1276845] CVE-2026-68514 [bsc#1276846] CVE-2026-68515 [bsc#1276848] CVE-2026-59184 [bsc#1276849] CVE-2026-59186 [bsc#1276850] CVE-2026-59187 [bsc#1276851] CVE-2026-59982 [bsc#1276853] CVE-2026-59189 [bsc#1276855] CVE-2026-59983 [bsc#1276856] CVE-2026-59984 [bsc#1276857] CVE-2026-59985 [bsc#1276858] CVE-2026-61555 [bsc#1276859] CVE-2026-62986 [bsc#1276861] CVE-2026-59981 [bsc#1276862] ==== openssh ==== Version update (10.4p1 -> 10.5p1) Subpackages: openssh-clients openssh-common openssh-server - Update to openssh 10.5p1: = Potentially-incompatible changes * Portable OpenSSH now requires ECC (Elliptic Curve Cryptography) support in libcrypto, including support for the NISTP521 curve. ECC is included in the default build configurations of all versions of all libcrypto implementations currently supported by OpenSSH, including LibreSSL, OpenSSL, BoringSSL and AWS LC. The --without-openssl build configuration is not affected. = Security * ssh-agent(1): fix an interaction between agent locking and the session-bind@openssh.com extension that is used to identify forwarded agents. These binding requests were refused when the agent was locked, with the result that operations that were intended to be limited to local use only could be performed remotely, including the ability to add PKCS#11 tokens and make use of keys that had destination restrictions applied. Reported by sn0x-sharma * ssh(1): avoid potential realloc use-after-free in the client if a remote forwarding is added via the local session multiplexing socket while a remote forwarding open request is pending with the server. Report and fix from Brian Mingus of Cognatory * sshd(8): make the authorized_keys "restrict" keyword apply correctly to tunnel forwarding too (which is administratively disabled by default). Reported by Erichen, Institute of Computing Technology, Chinese Academy of Sciences = New features * ssh-keygen(1): add ability to set or clear the touch-required and verify-required flags on FIDO private keys when resetting a private key's passphrase. * ssh(1): tweak ordering of certificates tried during pubkey authentication to prefer FIDO keys that do not require user presence (touch) first, and FIDO keys that require user verification via PIN or biometrics last. This effectively tries low-friction authenticators before higher friction ones. * ssh(1): add a "ssh -Z user@host" mode that prints the keys that will be tried for public key authentication in the order that they will be used. * sshd(8) use setproctitle(3) to identify sshd-session when its acting as a post-authentication monitor. = Bugfixes * ssh-keyscan(1): make reading the server banner a non-blocking operation to prevent a stuck server from blocking a many-host keyscan from proceeding. * sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the packet code as this provides context of the failing peer (address, port, user, etc). * sshd(8): when signing hostkey proofs for a client UpdateHostKeys request, allow each hostkey to perform at most one signature operation. * sshd(8) fix GSSAPI option names, that were broken during a servconf.c refactoring in openssh-10.4; bz3974. * ssh-keygen(1): pass back errors from ed25519 key generation, which theoretically can fail. GHPR702. * sshd(8): move check of public key type against allowed algorithms to before parsing of the key sent by the peer. This removes at least some key parsing and verification paths from the pre-auth attack surface. Suggested by Christopher Paul Rohlf of Anthropic. * ssh-keygen(1): fix double frees (impossible to reach outside of a test harness), and also use freezero where possible. From Christopher Paul Rohlf at Anthropic. * sshd(8): fix ChannelTimeout and RekeyLimit not being applied in sshd_config Match blocks. * sshd(8): in sshd config dump mode, write all directives in mixed case for consistency = Portability * sshd(8): re-allow PAMServiceName inside a Match block, which was incorrectly disabled during a refactoring in openssh-10.4. bz3987 - Drop patch which is already included upstream: * 0001-Fix-GSSAPI-server-option-names.diff - Rebase patches: * openssh-7.7p1-fips.patch * openssh-7.7p1-pam_check_locks.patch * openssh-8.0p1-gssapi-keyex.patch * openssh-8.1p1-audit.patch * openssh-9.6p1-crypto-policies-man.patch ==== openvpn ==== Version update (2.6.14 -> 2.7.5) - Update to version 2.7.5 * Multiple security fixes (CVE-2026-13379, CVE-2026-12996, CVE-2026-13117, CVE-2026-13122, CVE-2026-12932, CVE-2026-11771, CVE-2026-13698) * Improved DCO (Data Channel Offload) support built-in * Better multi-socket event handling * Enhanced DNS configuration handling * Windows openvpnserv improvements and fixes - Add debian packaging files (debian.control, debian.rules, debian.tar.xz, *.dsc) as Source entries - Remove all DCO patches (integrated or superseded in 2.7.5): * 0001-dco-better-naming-for-function-parameters.patch * 0001-dco_linux-extend-netlink-error-cb-with-extra-info.patch * 0001-Handle-missing-DCO-peer-by-restarting-the-session.patch * 0001-dco_linux-Introduce-new-uAPIs.patch * 0001-Implement-ovpn-version-detection.patch * 0001-dco_linux-fix-peer-stats-parsing-with-new-ovpn-kerne.patch * 0001-dco_linux-avoid-bogus-text-when-netlink-message-is-n.patch * 0001-dco-linux-avoid-redefining-ovpn-enums.patch - Change Recommends to ovpn-kmp (simplified) ==== orc ==== Version update (0.4.42 -> 0.4.43) - Update to version 0.4.43: + Add AVX512 support + neon: - add divluw rule (used in GStreamer's compositor, videomixer, gaudieffects and alpha-blending code paths) - add mulslq, mululq rules, shlq, shrsq, shruq (used in GStreamer's audio processing element) + orccodemem: Invalidate code chunks when recycling for QEMU + orcprogram-c: Allow negative constants + arm, neon: Split ARM and NEON logic into 32-bit and 64-bit + RISC-V: many fixes and enhancements, including some new rules + LoongArch: various fixes and enhancements + OpenBSD/FreeBSD improvements + Miscellaneous fixes ==== pam_kwallet6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: pam_kwallet6-common - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== pango ==== Version update (1.58.0 -> 1.58.2) Subpackages: libpango-1_0-0 typelib-1_0-Pango-1_0 - Update to version 1.58.2: + Require harfbuzz 11 + Require glib 2.88 + CoreText: - Support variations - Support font features from descriptions + Renderer: Keep over/under/through lines in sync + Fixes for undefined behavior ==== parley ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== patterns-base ==== Subpackages: patterns-base-apparmor patterns-base-base patterns-base-basesystem patterns-base-basic_desktop patterns-base-console patterns-base-enhanced_base patterns-base-minimal_base patterns-base-selinux patterns-base-sw_management patterns-base-x11 patterns-base-x11_enhanced - immutable_base: install transactional-wrapper by default on SLE (jsc#PED-15607) ==== patterns-kde ==== Subpackages: patterns-kde-kde patterns-kde-kde_edutainment patterns-kde-kde_games patterns-kde-kde_ide patterns-kde-kde_imaging patterns-kde-kde_internet patterns-kde-kde_multimedia patterns-kde-kde_office patterns-kde-kde_pim patterns-kde-kde_plasma patterns-kde-kde_utilities patterns-kde-kde_utilities_opt patterns-kde-kde_yast - Remove plasma6-session-x11 from the plasma 6 pattern (boo#1274552) ==== patterns-media ==== Subpackages: patterns-media-rest_cd_core patterns-media-rest_dvd - Media rest_dvd: recommend sudo-policy-wheel-auth-self and openSUSE-repos-Tumbleweed, as they are referenced by the Agama installer. ==== perl-CryptX ==== Version update (0.89.0 -> 0.91.0) - updated to 0.91.0 (0.091) see /usr/share/doc/packages/perl-CryptX/Changes 0.091 2026-08-10 - fix #125 (non-NUL-terminated PVs) - new: Crypt::Mode::XTS - new: Crypt::Digest::BLAKE3 - re-enable SHA1/SHA224/SHA256 hash state cloning - bundled libtomcrypt update branch:develop (commit: a10cad62 2026-08-07) - updated to 0.90.0 (0.090) see /usr/share/doc/packages/perl-CryptX/Changes 0.090 2026-06-17 - new: Crypt::AuthEnc::GCMSIV - new: Crypt::Cipher::ARIA - new: Crypt::Digest::SM3 - new: Crypt::Mac::KMAC - bundled libtomcrypt update branch:develop (commit: a68fa19b 2026-05-19) ==== perl-HTTP-Cookies ==== Version update (6.110.0 -> 6.120.0) - updated to 6.120.0 (6.12) see /usr/share/doc/packages/perl-HTTP-Cookies/Changes 6.12 2026-07-26 02:34:52Z - Honour Max-Age when extracting cookies; it had been silently ignored since 6.10, so Max-Age=0 no longer deleted a cookie and a Max-Age lifetime was never applied (GH#69) (reported by Robert Mueller) - When both Max-Age and Expires are present, let Max-Age take precedence regardless of order, and let a repeated attribute's last value win, per RFC 6265 5.3 (GH#69) ==== perl-HTTP-Message ==== Version update (7.20.0 -> 7.40.0) - updated to 7.40.0 (7.04) see /usr/share/doc/packages/perl-HTTP-Message/Changes 7.04 2026-07-24 00:01:56Z - add RFC 10008 HTTP QUERY method (GH#225) (Daniel Böhmer), see https://datatracker.ietf.org/doc/rfc10008/ 7.03 2026-07-21 20:45:16Z - Fix max_body_size for Content-Encoding: br, which made every brotli response fail to decode whenever a limit was set (GH#229) ==== perl-LWP-Protocol-https ==== Version update (6.150.0 -> 6.170.0) - updated to 6.170.0 (6.17) see /usr/share/doc/packages/perl-LWP-Protocol-https/Changes 6.17 2026-07-23 14:32:07Z - Move the live httpbin.org test from t/example.t to xt/author/example.t so that a transient outage of the external service (e.g. a 503) can no longer fail an end-user install. The test still runs in CI, and now skips (rather than fails) when httpbin.org itself is unhealthy, e.g. returns a 5xx. (GH#100) (Claude Opus 4.8) 6.16 2026-07-23 03:48:07Z - Remove undeclared Try::Tiny dependency from t/diag.t, which could cause the test suite to fail to install on minimal perls (GH#96) (Olaf Alders) ==== permissions ==== Version update (1699_20260728 -> 1699_20260806) Subpackages: permctl permissions-config - Update to version 1699_20260806: * profiles: add spine cap_net_raw (bsc#1273300) - Update to version 1699_20260805: * profiles: Make uucp work even with latest chkstat (bsc#1273735) ==== pim-data-exporter ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * precommit uses reuse * Reflect the move of KMime to Frameworks in the dependency data * BUILD_QCH is not useful * Remove unused #include already includes by #include * Add forward compatibility with KMime from KDE Frameworks * Increase ktextaddons dep * gui/CMakeLists.txt - remove unused/uninitialized variable * Use prek support - Update build requirements ==== pim-sieve-editor ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes to list here. ==== pimcommon ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6PimCommon6 libKPim6PimCommonAkonadi6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add ECMInstalledLibraryCheck support * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Add find_dependency(KF6Completion...) * We have KLineEdit in header => add KF6::Completion in public * Don't use static for this list * Use value(...) directly * When we found email break directly => optimization * Fix logic error * Fix include * Fix includes * Remove unused #include already includes by #include * Add if pointer is not null * fix comment * Use QStringLiteralView * CMake clean out unused/uninitialized variables * Drop unused kitemviews dependency * Remove it * Use prek + move license info in REUSE.toml ==== pipewire ==== Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-jack pipewire-libjack-0_3 pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Add pipewire-tests subpackage with installed tests for gnome-desktop-testing-runner ==== plasma5support6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libPlasma5Support6 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Fix screen power management inhibition never being re-acquirable (kde#523605) * Update version for new release 6.7.4 ==== plasma6-activities ==== Version update (6.7.3 -> 6.7.4) Subpackages: libPlasmaActivities7 plasma6-activities-imports - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-activities-stats ==== Version update (6.7.3 -> 6.7.4) Subpackages: libPlasmaActivitiesStats1 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-browser-integration ==== Version update (6.7.3 -> 6.7.4) - Place native-messaging-hosts files in /usr/lib in addition to /usr/lib64 (boo#1275979) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-desktop ==== Version update (6.7.3 -> 6.7.4) Subpackages: plasma6-desktop-emojier plasma6-kimpanel-ibus - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 * Fix dragging onto grouped tasks when floating applets are enabled (kde#510643) * applets/kimpanel: Avoid unrefing a null engine descriptor * applets/{folder,showdesktop,minimizeall,kickoff,showActivityManager}: fix BugReportUrl * emojier: Focus emojiView on downPressed when using search (kde#523254) * kcms/gamecontroller: Fix std::out_of_range exception (kde#522886) * Update version for new release 6.7.4 ==== plasma6-disks ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-integration ==== Version update (6.7.3 -> 6.7.4) Subpackages: plasma6-integration-plugin plasma6-integration-plugin-qt5 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-nm ==== Version update (6.7.3 -> 6.7.4) Subpackages: plasma6-nm-openconnect plasma6-nm-openvpn plasma6-nm-pptp plasma6-nm-vpnc - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-openSUSE ==== Subpackages: plasma6-branding-openSUSE plasma6-sddm-theme-openSUSE plasma6-theme-openSUSE - Update to 6.7.4 ==== plasma6-pa ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-print-manager ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 * libkcups/plasmoid: Add a timer to reload the job queue when not empty (kde#512442) * Update version for new release 6.7.4 ==== plasma6-systemmonitor ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-thunderbolt ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - No code changes since 6.7.3 ==== plasma6-workspace ==== Version update (6.7.3 -> 6.7.4) Subpackages: plasma6-session plasma6-workspace-libs sddm-qt6-branding-openSUSE - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * libnotificationmanager: Return empty icon name in jobs model (kde#522846) * Move plasmaLocked property from KLookAndFeelManager to KCM * libklookandfeel: Drop Latte Dock integration * containmentlayoutmanager: guard against non-finite item geometry (kde#522039) * applets/digital-clock: apply font family to time zone label, too (kde#523164) * applets/digital-clock: Fix label not adjusting in size when showSeconds is changed (kde#523010) * startkde: Update LookAndFeelPackage in kdeglobals * CursorTheme/main.qml: Ensure the cursor icons and text fit combobox popup (kde#521187) * startkde: Drop plasma-svgelements purging code * kcms/color: Update ColorSchemeHash (kde#511740) * Update version for new release 6.7.4 ==== polkit-default-privs ==== Version update (1550+20260803.90784eb -> 1550+20260825.76d85e6) - Update to version 1550+20260825.76d85e6: * profiles: add lact profile-hook action (bsc#1274863) ==== polkit-kde-agent-6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== postfix ==== Version update (3.11.5 -> 3.11.6) - update to 3.11.6 This release addresses medium-impact problems that need to be fixed as some enable remote DOS or policy bypass. * Bug (introduced: Postfix 2.2, date: 20041102): missing SMTP server resets of MAIL FROM and RCPT TO command state after smtpd_end_of_data_restrictions rejected a message. This resulted in SMTP protocol state desynchronization between the remote SMTP client and the Postfix SMTP server. A crafted remote SMTP client could then send RCPT TO and DATA without MAIL FROM, and deliver a second message. Then, smtpd_end_of_data_restrictions skipped check_recipient_access constraints, because a recipient counter was > 1. * Bug (defect introduced: Postfix 3.4, date: 20180805): SMTP server command history memory exhaustion with a large number of very small BDAT requests. * Bug (defect introduced: Postfix 1.1, date: 20021116): address verification cache poisoning. A local user could use the postdrop command to submit an address verification probe with envelope or message content that Postfix rejected later, resulting in a negative address verification cache entry for that address. On systems that enable address verification, the negative address verification cache entry would force the Postfix SMTP server to reject a message that it should accept (denial of service). * Bug (defect introduced: Postfix 3.4, date: 20180805): missing SMTP server reset of RCPT TO state, after a BDAT command error. A crafted remote SMTP client could then send a DATA command without MAIL FROM or RCPT TO, and crash a Postfix SMTP daemon process with a null pointer read error. * Bug (defect introduced: Postfix 2.4, date: 20051222): null pointer read crash while parsing a malformed Dovecot AUTH server response. * Bug (defect introduced: Postfix 2.8, date: 20100914): read-after-free in the PSC_CALL_BACK_NOTIFY() macro. This had no effect on program execution, because myfree() wiped memory, and that memory was not yet reused. * Read after free (no privilege escalation) in debug logging (defect introduced: Postfix 2.2, date: 20050117). * Bug (defect introduced: Postfix 2.10, date: 20120617): uninitialized memory read in postscreen HaProxy client after remote I/O exception, causing garbage to be logged. * Latent bug (defect introduced: Postfix 2.7, date: 20090618): uninitialized memory read after dnsblog(8) returns a string that is not an IPv4 address. * Bug (defect introduced: before Postfix alpha, date 19970424): the DNS client could read up to two bytes past the end of an MX record, before discovering that the record was too short. This behavior was later copied with SRV records, potentially over-reading up to six bytes. * Bug (defect introduced: Postfix 1,1, date: 20010524): the postsuper command under-read or over-read a very short queue filename. No crash, information leak, or privilege escalation. * Bug (defect introduced: before Postfix alpha, date: 19971106): 'int' over-shift, in the queue file record-length parser. Postfix programs do not generate such records, but an attacker could cause postdrop to reject input or panic(). * Bug (defect introduced: Postfix 2.2, date: 20050117): non-transitive comparison of IPv4 addresses. * Bug (defect introduced: Postfix 1.0, date: 20000928): the fast flush server, used by the SMTP command "ETRN", and by the commands "postqueue -s site" and "postqueue -i queue_id" (and their sendmail(1) equivalents), used the wrong duplicate suppression API, resulting in unnecessary queue scans by the queue manager. * Queue hygiene: the postdrop command accepted the null record type which the rest of Postfix ignores. - Add %bcond_with config * brings back sysconfig.postfix and config.postfix * add postfix-config.tar.gz * add postfix-main.cf.patch * add postfix-master.cf.patch - rebase patches * avoid-inherited-file-descriptor.patch * fix-postfix-script.patch * ipv6_disabled.patch * postfix-linux45.patch * postfix-no-md5.patch * postfix-ssl-release-buffers.patch * postfix-vda-v14-3.0.3.patch * set-default-db-type.patch ==== postgresql18 ==== Version update (18.4 -> 18.6) Subpackages: libpq5 postgresql18-contrib postgresql18-llvmjit postgresql18-server - Let llvmjit-devel require the llc and clang binaries to fix build of extensions on SLE-16.1 and newer. - Update to version 18.6: https://www.postgresql.org/docs/18/release-18-6.html https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ Security Fixes: - bsc#1275046, CVE-2026-6464: psql COPY FROM STDIN early failure processes data lines as psql commands (CVSS v3.1: 8.1) - bsc#1275044, CVE-2026-6469: ALTER TABLE ALTER TYPE resets extended statistics ownership (CVSS v3.1: 3.8) - bsc#1275043, CVE-2026-6470: Fails to check type USAGE privilege (CVSS v3.1: 4.3) - bsc#1275042, CVE-2026-6471: Logical decoding can dlopen arbitrary file (CVSS v3.1: 7.2) - bsc#1275001, CVE-2026-14662: tsvector and tsquery undersize allocations, via integer wraparound (CVSS v3.1: 8.8) - bsc#1275002, CVE-2026-14663: pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (CVSS v3.1: 6.5) - bsc#1275068, CVE-2026-14664: Regexp heap buffer overflow executes arbitrary code (CVSS v3.1: 8.8) - bsc#1275067, CVE-2026-14666: Row security caching disregards role modifications (CVSS v3.1: 4.2) - bsc#1275066, CVE-2026-14668: ctid type confusion in selectivity estimator discloses derivative of arbitrary read (CVSS v3.1: 8.1) - bsc#1275065, CVE-2026-14669: to_char heap buffer overflow executes arbitrary code (CVSS v3.1: 8.8) - bsc#1275064, CVE-2026-14670: plperl tied object heap buffer overflow executes arbitrary code (CVSS v3.1: 8.8) - bsc#1275063, CVE-2026-14671: refint plan cache type confusion executes arbitrary code (CVSS v3.1: 8.8) - bsc#1275062, CVE-2026-14672: Observable response discrepancy with non-default scram_iterations provides user existence oracle (CVSS v3.1: 5.3) - bsc#1275061, CVE-2026-14673: amcheck does not clear untrusted search path (CVSS v3.1: 3.8) - bsc#1275060, CVE-2026-14676: pg_stat_statements heap buffer overflow executes arbitrary code (CVSS v3.1: 8.8) - bsc#1275059, CVE-2026-14677: 32-bit pltcl and plperl undersize allocations, via integer wraparound (CVSS v3.1: 8.8) - bsc#1275058, CVE-2026-14678: pg_trgm picksplit reads past end of buffer (CVSS v3.1: 4.3) - bsc#1275057, CVE-2026-14679: Stack buffer overflow in argument match writes 0x0 and 0x1 to server memory (CVSS v3.1: 8.2) - bsc#1275056, CVE-2026-14680: Type confusion via "internal" arguments (CVSS v3.1: 8.8) - bsc#1275055, CVE-2026-14681: Improper enforcement of GSSAPI encryption when coupled with SSL (CVSS v3.1: 4.2) - bsc#1275054, CVE-2026-15741: Expression deparse allows SQL injection via EXTRACT argument (CVSS v3.1: 8.8) - bsc#1275053, CVE-2026-15742: fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound (CVSS v3.1: 8.8) - bsc#1275052, CVE-2026-16238: Type confusion in pg_restore_attribute_stats() executes arbitrary code (CVSS v3.1: 8.8) - bsc#1275051, CVE-2026-16239: Type confusion in cursor CLOSE + DECLARE executes arbitrary code (CVSS v3.1: 8.8) - bsc#1275050, CVE-2026-16241: ECPG integer underflow can crash the client (CVSS v3.1: 3.8) - bsc#1275049, CVE-2026-18024: ascii() function reads past end of buffer (CVSS v3.1: 4.3) - bsc#1275048, CVE-2026-18408: psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client (CVSS v3.1: 8.8) - bsc#1275047, CVE-2026-19385: pg_dump heap buffer overflow executes arbitrary code (CVSS v3.1: 8.8) ==== powerdevil6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Demote kameleon supported/enabled messages to debugs * Update version for new release 6.7.4 ==== procps ==== Version update (4.0.6 -> 4.0.7) Subpackages: libproc2-1 - Add patch procps-ng-4.0.7-sysctl_ipv6.patch (boo#1276206) * Really ignore stable_secret below /proc/sys/net/ipv6/conf - Extend the corrected patch procps-ng-3.3.8-readeof.patch to do open with O_NOATIME only for root - Update to procps-ng-4.0.7 * library version: inc revision to 2 now 1:2:0 internal: procps_pids_length off by one issue #412 external: fix slabinfo header extern 'C' declaration issue #415 internal: fix file descriptor leaks in api issue #421 internal: strv items are now escaped in api issue #429 internal: fix output if on seconds edge values merge !246 RHEL-60825 * pidof: Add -d aliased option issue #418 * pgrep: Don't treat empty list as 0 issue #427 * pmap: Fix testsuite for Alpha Debian #1141465 * ps: correct 'environ' output when file unavailable * ps: minimize potential EACCES with 'environ' files issue #431 * top: avoid batch mode segfault with maximum width issue #422 * w: Correctly check for end of tty using utmp issue #430 * watch: Dont remove 2 lines when using -t option issue #413 * watch: Handle resizing better issue #417 * watch: Restore LINES and COLUMNS env variables issue #432 - Port patches * procps-ng-3.3.11-pmap4suse.patch * procps-ng-3.3.8-petabytes.patch * procps-ng-3.3.8-readeof.patch * procps-ng-3.3.8-tinfo.dif * procps-ng-3.3.9-w-notruncate.diff * procps-ng-4.0.4-ignore-sysctl_conf.patch * procps-v3.3.3-read-sysctls-also-from-boot-sysctl.conf-kernelversion.diff - Remove patches now obsolete * procps-ng-4.0.4-pmapX-not-twice-anymore.patch * procps-v3.3.3-ia64.diff * glibc-2.43.patch * d9c96ec0.patch - Add patch procps-4.0.7-pmap-test.patch Simply add the leading zeros of an address for test_shm ==== publicsuffix ==== Version update (20260708 -> 20260819) - Update to version 20260819 (public_suffix_list.dat snapshot taken from upstream commit of 2026-08-19): * Add claudeusercontent.com to PSL (Anthropic) (#3087) * Add *.cursorusercontent.com (#3092) * Add *.aivencloud.com subdomain and remove the non-wildcard aivencloud.com (#3019, #3169) * Add CodePen domains (#3143) * Add online-server.cloud to PSL (#3138) * Add scw.site, ams.scw.site, waw.scw.site (#3110) * Add here.now (#3096) * Remove adaptable entries (#3144) - Update to version 20260814: * migrate `vps.hrsn.au` to `vps.hrsn.net` (#3121) - Update to version 20260725: * Remove Acorn Labs on-acorn.io entries from public_suffix_list.dat (#3093) * util: gTLD data autopull updates for 2026-07-24T16:40:16 UTC (#3090) * Add playcode.site to PRIVATE section (#3072) * Remove deta.dev, deta.app entries from public_suffix_list.dat (#3066) * Add a workflow that checks the PR template is filled out (#3077) * Remove onfabrica.com Fabrica Technologies entry (#3065) * Remove Bytemark Hosting entries: uk0.bigv.io dh.bytemark.co.uk vm.bytemark.co.uk (#3053) * Update `.it` (#3049) * Remove cryptonomic.net Cryptonomic entries from public_suffix_list.dat (#3050) * Remove api.stdlib.com from public suffix list (#3051) * Remove hzc.io RethinkDB entries from public_suffix_list.dat (#3052) * AI Agent notice about not modifying the repo PR template (#3043) * Delete protonet.io and Protonet GmbH entry (#3048) * Remove Storj Labs entries from public_suffix_list.dat (#3063) * util: gTLD data autopull updates for 2026-07-15T16:20:56 UTC (#3042) * remove ac.tj from public_suffix_list.dat (#3001) * Adding aero.in, alumni.in, school.in and ub.in (#2988) * Update `.no` (#3029) * Add cyb.ge, llc.ge, online.ge and tnx.ge (#2963) * Add mygov.scot (#2900) * Add IPv64.net dynamic DNS domains (#3009) ==== python-M2Crypto ==== Version update (0.48.0 -> 0.49.0) - Update to 0.49.0: - defer unavailable ENGINE constant lookup - fixes problematic behaviour of pkcs11-provider - support TLS 1.0 contexts with modern OpenSSL - use Python 3 C APIs in handwritten SWIG code (bsc#1275165) - feat: Add AES-GCM (AEAD) support to M2Crypto - remove Black configuration from setup.cfg - release X509V3 config with its context - keep IOBuffer chains alive until destruction - test: free low-level OpenSSL objects in leak tests - avoid leaking X509V3 extension config - free RSA exponent on modulus conversion failure - free replaced EVP digest contexts - wrap created X509 name entries with ownership - own ASN1 values created from Python data - own PKCS7 certificate stack copies - release BIOs on explicit close - Add AuthorityKeyIdentifier extension support ==== python-Pygments ==== Version update (2.20.0 -> 2.21.0) - update to 2.21.0: * New lexers: + BitBake (#3103) + Caddyfile (#3225) + CEL (#3048) + PureScript (#1077, #3054) * Updated lexers: + Bash: Fix coloured keyword at the beginning of a name (#2926) + Boogie: Add missing Boogie and Civl Verifier keywords (#3156) + C#: - Recognize interpolated verbatim strings with either ``$@`` or ``@$`` prefixes (#2685) - Support dollar-prefixed and multi-quote raw strings (#3129, #2897) - Recognize ``union`` (#3182) + C/C++: - Add C23/C++26 attributes (#3084) - Add more C2Y keywords (#3092) - Highlight a function following a namespace body (#2928) - Fix C/C++ lexer support for multiline pre-processor comments (#3051) - Add ``.ipp`` as a file extension (#3141, #1008) + Clojure: Recognize named, octal and unicode character literals such as ``\space`` and ``\o377`` as a single token (#979) + Csound: Add missing opcode parameter type letter (#3161) + CUDA: Derive from the C++ lexer instead of C to highlight C++ constructs such as ``template``, ``class`` and ``namespace`` (#3127) + D: Allow non-ASCII (Unicode) identifiers (#1088) + Fish: Fix single quote backslash escape (#3138, #2821) + Go: Various lexer improvements (#3199) + GoogleSQL: Require a word break after ``SET`` (#3167) + Hexdump: Only match valid digits (#3200, #2847) + JavaScript: Highlight the ``arguments`` object (#3146) + Jsonnet: Recognize colons in array slice expressions (#2828) + JSX: Allow apostrophes in element text (#2816) + Julia: Fix rstrings backslash (#3140, #2537) + Kotlin: Support companion objects without an explicit name (#2525) + Kotlin: Don't let a nullable type marker (``?``) consume the following character, so ``Foo?,`` and ``a?:b`` tokenize correctly (#2964) + Kusto: Recognize member-access dots in dynamic objects (#2779) + Lua: Various improvements (#3143) + Macaulay2: Update symbols to 1.26.05 (#3120) + Markdown: - Highlight bold-italics (``***...***`` and ``___...___``) (#3067) - Fix mention regex to support hyphens in usernames (#3139, #3135) + Markdown, reStructuredText, TiddlyWiki5: Fix wrong token offsets for embedded code blocks (#3133) + Mathematica: Recognize ``\[Name]`` named-character escapes such as ``\[Nu]`` instead of emitting an ``Error`` token (#3097) + MATLAB, Octave, Scilab: Allow ``...`` line continuations in function definition signatures (#659) + MySQL: Require a word break after ``SET`` (#3110) + PostgreSQL: Add more keywords (#3066) + Python: - Recognize ``sentinel`` (#3114) - Recognize ``frozendict`` (#3119) - Recognize lazy imports (#3115) + reStructuredText: Allow ``.`` and ``+`` in directive/role names (#3085) + Ruby: Don't duplicate the body of an unterminated heredoc (#2998) + Ruby: Treat ``<<`` after ``)``, ``]`` or ``}`` as the shift operator rather than the start of a heredoc (#760) + SCSS: Recognize variable references in property values (#2818) + Shell: Recognize chevron prompts (#3096) + Smithy: Fix text blocks and add missing syntax (#3168) + Swift: Keep ``func`` a keyword in ``class func`` type methods (#1125) + Tcl: Stop ``$name`` variable references at a dash (#1720) + TeX: Recognize LaTeX math environments as math (#3034) + Twig: Allow uppercase letters at the start of identifiers (#3159, #2965) + TypeScript: Only treat ``module`` as a keyword when followed by whitespace, so identifiers like ``modules`` and ``module.exports`` are highlighted correctly (#2823) + Vala: Recognize verbatim strings before ordinary quoted strings (#2861) + Vala: Recognize conditional compilation directives (#2858) + Vim: - Bump the syntax file to vim 9.2 (#3183, #3174) - Small improvements to the VimScript lexer (#3173) + YAML: Add ``yml`` alias (#3169), recognize non-breaking spaces as valid scalar content (#2827) + WebAssembly: Recognize sign-extension operators (#2991, #3160) + XML: Mark SVG files as XML (#3093) * New styles: Night Owl (#3132) * Fix catastrophic backtracking in ``looks_like_xml`` (#2931, #3112) * Improve monokai theme colors (#3100) ... changelog too long, skipping 13 lines ... * HtmlFormatter: ``"`` and ``'`` now render literally (#3185) ==== python-cssselect ==== Version update (1.4.0 -> 1.5.0) - update to 1.5.0: * **Backward-incompatible change**: removed the no longer used ``closing_combiner`` and ``has_inner_condition`` arguments of ``XPathExpr.join()``. They were added for ``:has()`` support which no longer needs them. * Fixed and improved support for the following selector features: * Fixed some issues with the ``Selector.canonical()`` method. * Improved the ``Element.__repr__()`` and ``Relation.__repr__()`` methods. * Fixed ``Selector.specificity()`` calculation for the ``:is()``, ``:where()`` and ``:matches()`` pseudo-classes. * Improved the docs about the ``:has()``, ``:is()`` and ``:where()`` pseudo-classes and the `!=`` attribute operator. ==== python-gevent ==== Version update (26.5.0 -> 26.8.0) - update to 26.8.0: * Binary wheels for 3.15 are now built with 3.15rc1. This should be a stable ABI. * Replace concurrent.futures.thread._global_shutdown_lock when patching threads, importing that module if needed. Executor.submit holds it across Thread.start(), so a worker greenlet that forks runs the :func:`os.register_at_fork` handlers it is registered with while another greenlet holds it: a native lock deadlocked, a cooperative one parked the greenlet inside os.fork() (which filelock 3.30 rejects). Like the rest of patch_thread(existing_locks=True), this needs the process to be single threaded when patching. See :issue:`1865`. * Fixed a semaphore acquired and released by a hubless native thread failing to wake greenlets waiting on the semaphore's owning hub. See :issue:`2013`. * Stop the greenlets that communicate() spawned before gevent.subprocess.Popen.__exit__ closes the child's pipes. Leaving the with block while one of them was still parked in a pipe, because an exception was propagating or because the greenlet running the block was killed, raised RuntimeError: reentrant call out of __exit__. That replaced the exception that was really unwinding, and skipped the wait() that reaps the child. A pipe some other greenlet is reading is now left alone rather than raising, which is what communicate() already did. See :issue:`2194`. * Fix repr() of a destroyed hub raising :exc:`AttributeError`. Hub.destroy() deleted the _resolver and _threadpool attributes that Hub.__repr__ reads; it now sets them to None. This also fixes gevent.util.format_run_info(), which renders any destroyed hub that is still reachable. See :issue:`2185`. * Fix a hang at interpreter exit, on Python 3.13 and above, when a non-daemon thread is waiting on a threading._register_atexit hook. The patched threading._shutdown joined those threads before running the hooks, the reverse of the native order. This hung any program holding a live :class:`concurrent.futures.ThreadPoolExecutor`, whose non- daemon workers stop only when its _python_exit hook runs. See :issue:`2188`. * Make gevent.os.close not initialize a hub if one wasn't already present. In that case, it can just directly close the file descriptor. * In a future version (early 2027), gevent.monkey.patch_all will ONLY accept keyword arguments. Currently, you could be calling it with positional arguments, although that has never been the intent or documented way to call it. * Binary wheels for Python 3.15 are now built with 3.15b4. They may not be compatible with older or newer versions of Python. Likewise, binary wheels built by previous gevent releases may not be compatible with 3.15b4 or newer. ==== python-greenlet ==== Version update (3.5.3 -> 3.5.5) - Update to 3.5.5 * Link the C++ runtime statically into the Windows wheels again, as the Appveyor builds did through 3.3.0. Since 3.3.1 ``_greenlet.pyd`` imported ``MSVCP140.dll``, which no Windows CPython distribution ships, so importing greenlet failed on machines without the Visual C++ redistributable. See issue 525. Issue and pull request by Daniel Sticker. - from version 3.5.4 * Fix a crash (segfault) on free-threaded builds of Python 3.14 and later when the garbage collector runs while a greenlet that was started from a non-empty C-stack-reference state is active. See issue 515. Thanks to ddorian and Kumar Aditya. * Fix a potential use-after-free on free-threaded builds of Python 3.14 and later when the garbage collector runs while a greenlet is suspended holding a ``_PyCStackRef`` (for example, mid attribute resolution). See issue 515. Thanks to ddorian and Kumar Aditya. - Fix a deadlock on free-threaded builds when a greenlet switch happened while a ``PyCriticalSection`` was held -- for example inside asyncio's ``Task.__step``, which holds one on the running task for the duration of the step. See PR 519. Thanks to ddorian and Kumar Aditya. ==== python-h2 ==== Version update (4.3.0 -> 4.4.1) - Update to 4.4.1 (fixes CVE-2026-71554, bsc#1274386) * Performance improvement: remove consumed frames in-place from data buffer. * Reject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report. - Update to 4.4.0 * Support for Python 3.9 has been removed. * Support for PyPy 3.9 has been removed. * Stream.end_stream() now raises NoSuchStreamError or StreamClosedError exceptions, instead of a generic KeyError. * Duplicate content-length headers with different values now raise ProtocolError. Previously, the first content-length header was accepted and later conflicting values were ignored. Thanks to Harshal Parekh for the report. * Parse content-length headers according to RFC9110 grammar for numbers (1*DIGIT). Thanks to Arkadiusz Marta for the report. * backfill from v4.3.0 Convert emitted events into Python dataclass, which introduces new constructors with required arguments. Instantiating these events without arguments, as previously commonly used API pattern, will no longer work. * Support for Python 3.14 has been added. * H2Connection.receive_data now accepts any byte-like object that implements the buffer protocol, such as bytes, bytearray, and memoryview. Existing bytes callers are unaffected. * Align CONNECT pseudo-header validation with RFC 9113 s8.3 and RFC 8441 s4. Ordinary CONNECT now requires :method=CONNECT and :authority, and forbids :scheme/:path. Extended CONNECT (e.g., WebSocket) requires :scheme, :path, :authority plus :protocol. * Fix incorrect substring matching of secure header in cookie and :method. * Fix to allow sending 0 bytes on a stream even if the flow control window is negative. * Reject non-zero SETTINGS_ENABLE_PUSH values received from servers. ==== python-hpack ==== Version update (4.1.0 -> 4.2.0) - Update to 4.2.0 (fixes boo#1275232 and CVE-2026-59980) * Support for Python 3.9 has been removed. * Support for PyPy 3.9 has been removed. * Support for Python 3.14 has been added. * Headers marked as sensitive will no longer log their value at DEBUG level. Instead a placeholder value of SENSITIVE_REDACTED is logged. * Fixed perfect match missed for headers with empty values. * Restricted variable integer decoding to uint32 to prevent run-away computation. With thanks to Hiroki Nishino. ==== python-msgpack ==== Version update (1.1.2 -> 1.2.1) - update to 1.2.1 (bsc#1269947, CVE-2026-57585) * Fix a segfault when calling Unpacker.unpack() or Unpacker.skip() after an unpacking failure. - update to 1.2.0: * relax setuptools version * update setuptools requirements to >=78.1.1 * cython: freethreading_compatible * drop Python 3.9 * update cython and cibuildwheel * ci: add riscv64 manylinux/musllinux wheels * fix: check `unpack_callback_uint32` result * fix: re-raise existing exception when available * fix: check return code in `unpack_callback_int64` * Fixed README example * Bump the all-dependencies group with 6 updates * ci: use ubuntu-slim for lint * fix: enforce `strict_map_key` with `object_pairs_hook` * Raise DEFAULT_RECURSE_LIMIT from 511 to 1024 * fix: properly handle return codes in `pack_timestamp` * fix: avoid memory leak when decoding invalid nested arrays * Add missing autoreset in Packer.pack_ext_type * Add no-GIL interpreter support * skip recursion limit test on free-threaded CPython builds * Fix Timestamp.from_datetime returning wrong value for pre- epoch datetimes * Add 3.15 to CI * fix: use-after-free in `get_data_from_buffer` * change changelog format to markdown * Bump the all-dependencies group with 2 updates * Bump sys.setrecursionlimit within test_nest_limit_1024 * Guard `Packer` buffer protocol hooks with Cython critical sections * Harden `Unpacker.__init__` re-entry cleanup to prevent buffer/context leaks * release v1.2.0rc1 * Wheels CI hangs for MacOS Intel * Bump pypa/cibuildwheel from 3.4.1 to 4.0.0 in the all- dependencies group * release v1.2.0 ==== python-numpy ==== Version update (2.4.6 -> 2.5.2) - Update to 2.5.2 * drop support for Python 3.11 * distutils has been removed * many expired deprecations, see below * many new deprecations, see upstream changes * static typing improvements * improved support for free threading * support for descending sorts Expired deprecations: * passing None as dtype to np.finfo will now raise a TypeError * numpy.cross no longer supports 2-dimensional vectors * numpy._core.numerictypes.maximum_sctype has been removed * numpy.row_stack has been removed in favor of numpy.vstack * get_array_wrap has been removed * recfromtxt and recfromcsv have been removed from numpy.lib._npyio in favor of numpy.genfromtxt * numpy.chararray (re-export of numpy.char.chararray) has been removed * bincount now raises a TypeError for non-integer inputs * numpy.lib.math (alias for the standard library math module) has been removed * data type alias 'a' was removed in favor of 'S' * _add_newdoc_ufunc(ufunc, newdoc) has been removed in favor of ufunc.__doc__ = newdoc - Drop numpy-buildfix.patch as distutils was dropped ==== python-ptyprocess ==== - Add patch support-flit-core-4.patch: * Use PEP 621 metadata to support flit-core >= 4. ==== python-pycairo ==== Version update (1.29.0 -> 1.29.1) - Update to 1.29.1: * Update dependencies (libpng, zlib) for the Windows wheels * Fix documentation build with Python 3.15 * Build wheels for Python 3.15 (except for 32bit Windows) * Fix a memory leak in ScaledFont.text_to_glyphs() * Fix some minor reference leaks ==== python-pyzmq ==== Version update (27.1.0 -> 27.2.0) - update to 27.2.0: * Lots of new type coverage. * Add `python3 -m zmq.curve_keygen` entrypoint for creating curve key pairs * Require Python 3.9 (drops Python 3.8) * Stop building wheels for free-threaded CPython 3.13 (cp313t) * Add wheels for free-threaded CPython 3.15 (cp315t) * Fix builds on Windows with Visual Studio 2026 * Fix builds with upcoming Cython release * Add more type coverage, fix some typing, typing compatibility with mypy 2.1 ==== python-rich ==== - Skip tests broken by Pygments 2.21.0 for now - Add patch support-python-315.patch: * Support signature changes for Python 3.15. ==== python-rpm ==== - drop unneeded ima-evm-utils-devel BuildRequires ==== python-six ==== - Do not install the py module to run the testsuite. ==== python-socksio ==== - Add patch support-flit-core-4.patch: * Suppport changes required by flit-core 4. ==== python-tornado6 ==== Version update (6.5.7 -> 6.5.8) - update to 6.5.8 (bsc#1276210, bsc#1276211): * Form-encoded POST bodies are now subject to a limit of 1000 arguments by default. This prevents a CPU and memory denial of service attack. This limit can be overridden via the set_parse_body_config function. Thanks to Arpit Jain for reporting this issue. * Multipart parsing now rejects requests with an excessive number of parts earlier in the parsing process, limiting memory consumption. Thanks to afldl for reporting this issue. * The deprecated mixed-case arguments to RequestHandler.set_cookie now enforce the same restrictions on invalid characters that were introduced in Tornado 6.5.5 for the standard lowercase arguments. Thanks to sec-reex and Arpit Jain for reporting this issue. - drop python-tornado6-Fix-test_strip_headers_on_redirects.patch (upstream) ==== python-typing_extensions ==== Version update (4.15.0 -> 4.16.0) - permit flit-core 4 - Drop not needed patch py314-fix-tests.patch - Add upstream patch remove-obsolete-literal-deduplication-assertion.patch (gh#python/typing_extensions#785, bsc#1274786) - Update to 4.16.0: * Avoid a DeprecationWarning when deprecated is applied to a coroutine function on Python 3.14.0. * Make `typing_extensions.TypeAliasType`'s `__module__` attribute writable. Backport of CPython PR [#149172](https://github.com/python/cpython/pull/149172). * Fix setting of `__required_keys__` and `__optional_keys__` when inheriting keys with the same name. * Add support for `AsyncIterator`, `io.Reader`, `io.Writer` and `os.PathLike` protocols as bases for other protocols. * Fix incorrect behaviour on Python 3.9 and Python 3.10 that meant that calling `isinstance` with `typing_extensions.Concatenate[...]` or `typing_extensions.Unpack[...]` as the first argument could have a different result in some situations depending on whether or not a profiling function had been set using `sys.setprofile`. This affected both CPython and PyPy implementations. Patch by Brian Schubert. * Fix `__init_subclass__()` behavior in the presence of multiple inheritance involving an `@deprecated`*decorated base class. Backport of CPython PR [#138210](https://github.com/python/cpython/pull/138210) by Brian Schubert. * Raise `TypeError` when attempting to subclass `typing_extensions.ParamSpec` on Python 3.9. The `typing` implementation has always raised an error, and the `typing_extensions` implementation has raised an error on Python 3.10+ since `typing_extensions` v4.6.0. Patch by Brian Schubert. * Add the `bound`, `covariant`, `contravariant`, and `infer_variance` parameters to `TypeVarTuple`. * Officially support the `bound`, `covariant`, `contravariant` and `infer_variance` parameters to `ParamSpec`. Improve the validation of these parameters at runtime. * Rename `typing_extensions.Sentinel` to `typing_extensions.sentinel`, following the name that has been adopted for `builtins.sentinel` on Python 3.15. `typing_extensions.Sentinel` is retained as a soft*deprecated alias for backwards compatibility. * Add support for pickling sentinels. * Sentinels now preserve their identity when copied or deep*copied. * Deprecate passing `name` as a keyword argument or `repr` as a positional argument to the `sentinel` constructor. * The default repr of a sentinel `X = sentinel("X")` is now `X` rather than ``. * Deprecate arbitrary attribute assignments to sentinels. * Deprecate subclassing sentinels. * Add support for Python 3.15. ==== python-zope.interface ==== Version update (8.5 -> 8.6) - update to 8.6: * Add support for Python 3.15. ==== python313 ==== Subpackages: python313-curses python313-dbm python313-tk - Add reproducible_stencils.patch from gh#python/cpython!154988 - CVE-2026-0864: Normalize all line endings (CR, CRLF, and LF) in configparser (bsc#1269066, gh#python/cpython#143927) CVE-2026-0864-normalize-LFTAB-configparser.patch - CVE-2026-11972: Make tarfile._Stream.seek break at EOF (bsc#1269788, gh-151981) CVE-2026-11972-tarfile-Stream-seek-EOF.patch - CVE-2026-4360: Pass filter_function to TarFile._extract_one() during .extract() (bsc#1269959, gh#python/cpython#151987) CVE-2026-4360-filter_function-TarFile-extractone.patch - CVE-2026-15308: Fix quadratic complexity in incremental parsing in HTMLParser (bsc#1271192, gh#python/cpython#153030) CVE-2026-15308-HTMLParser-CPU-exhaust.patch ==== python313-core ==== Subpackages: libpython3_13-1_0 python313-base python313-devel - Add reproducible_stencils.patch from gh#python/cpython!154988 - CVE-2026-0864: Normalize all line endings (CR, CRLF, and LF) in configparser (bsc#1269066, gh#python/cpython#143927) CVE-2026-0864-normalize-LFTAB-configparser.patch - CVE-2026-11972: Make tarfile._Stream.seek break at EOF (bsc#1269788, gh-151981) CVE-2026-11972-tarfile-Stream-seek-EOF.patch - CVE-2026-4360: Pass filter_function to TarFile._extract_one() during .extract() (bsc#1269959, gh#python/cpython#151987) CVE-2026-4360-filter_function-TarFile-extractone.patch - CVE-2026-15308: Fix quadratic complexity in incremental parsing in HTMLParser (bsc#1271192, gh#python/cpython#153030) CVE-2026-15308-HTMLParser-CPU-exhaust.patch ==== qalculate ==== Version update (5.11.0 -> 5.12.0) Subpackages: libqalculate23 qalculate-data - Update to version 5.12 * LaTeX input and output (using latex() function, "$...$" syntax, and "to latex" or "-latex" in qalc) * Solve ax^b+cd^x=0 for real x * Solve equations with absolute value and complex x (xabs(x)=a, x^2abs(x)=a, and af(x)+babs(x)=c) * Improve simplification of a^(c/d)/b^(c/d) in exact mode (e.g. cbrt(12)/cbrt(4)=cbrt(3)) * Apply logical and bitwise operation entrywise to vectors and matrices * Allow symbols with suffix when input using backslash (e.g. \x_n = "x_n", with n shown as subscript in output) * Add argument for reverse conversion to roman(), bijective() and bcd() functions * Add tsp and tbsp abbreviations, change cup to exactly 240 mL (U.S. legal), and add U.S. customary cup, tablespoon, and teaspoon * Mixed units conversion improvements/fixes * Fix conversion of feet and inches when using ' and " (e.g. 5'2" to cm) * Fix ax+bln(x)=c where sgn(a)!=sgn(b) (only one solution were found) * Fix segfault when calculating limit for expression with sinh or cosh (also affects integrals with infinite lower or upper limit) * Fix RPN syntax for expressions with multiple functions * Add max history option to configure maximum number of expressions saved in history * Minor bug fixes and feature enhancements ==== qpdf ==== Version update (12.3.2 -> 12.4.1) - Update to version 12.4.1: - Update to 12.4.1: * Avoid generating JSON with leading zeroes when converting real numbers. * Detect and warn in check linearization when the cross-reference (xref) stream reports that the object containing a compressed object is itself a compressed object. * Improve uniformity and accuracy of progress reporting when writing linearized files and files with a large number of object streams. 10 - Update to 12.4.0: * Fix error message when --check encounters a PDF file with no pages. * Remove non-array/empty /Annots entries and non-dictionary annotations from copied pages in QPDFAcroFormDocumentHelper::fixCopiedAnnotations. * Fix failure in QPDFWriter when trailer /ID entries are invalid. * Limit the effect of QPDF::setMaxWarnings to the initial loading of the PDF file to prevent treating subsequent exceptions as recoverable. * Correctly handle page rotation values outside [0, 360] range in QPDFPageObjectHelper::getMatrixForTransformations. * Enforce conservative limits on the depth of direct objects created via QPDFObjectHandle::makeDirect to reduce stack overflow risk. * Enforce conservative limits on pages tree depth to prevent stack overflows. * Detect duplicate entries in the AcroForm field hierarchy earlier. * Rewrite zsh and bash shell completion functions to autogenerate from argument parsing metadata (job.yml) instead of invoking the executable. * Show linearization data even if linearization checks throw an exception. * Add REQUIRE_SHELLS CMake option to fail completion tests if new bash/zsh are missing (enabled by default in maintainer mode). * Deprecate external-libs on Windows in favor of vcpkg. ==== qqc2-breeze-style6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== qrca ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Tidy Readme and update copyright year * Use Kirigami Addons from the Flatpak runtime * Use KDE_INSTALL_TARGETS_DEFAULT_ARGS, KF_ one reserved for KF * Fix Android build with Qt 6.11 ==== qt6-base ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Concurrent6 libQt6Core6 libQt6DBus6 libQt6Gui6 libQt6Network6 libQt6OpenGL6 libQt6OpenGLWidgets6 libQt6PrintSupport6 libQt6Sql6 libQt6Test6 libQt6WaylandClient6 libQt6Widgets6 libQt6WlShellIntegration6 libQt6Xml6 qt6-network-tls qt6-networkinformation-connman qt6-networkinformation-glib qt6-networkinformation-nm qt6-platformtheme-gtk3 qt6-printsupport-cups qt6-sql-mysql qt6-sql-sqlite qt6-wayland - Add patch to fix a regression in icon loading (kde#=524657, QTBUG-149431): * 0001-QIconLoader-Don-t-consider-fallbackThemeName-in-them.patch - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released - Add patch to fix incomplete docs (QTBUG-149045): * 0001-CMake-Handle-generated-headers-in-syncqt-scan-all-mo.patch ==== qt6-declarative ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6LabsAnimation6 libQt6LabsFolderListModel6 libQt6LabsPlatform6 libQt6LabsQmlModels6 libQt6LabsSettings6 libQt6LabsSharedImage6 libQt6LabsStyleKit6 libQt6LabsSynchronizer6 libQt6LabsWavefrontMesh6 libQt6Qml6 libQt6QmlCore6 libQt6QmlLocalStorage6 libQt6QmlMeta6 libQt6QmlModels6 libQt6QmlNetwork6 libQt6QmlWorkerScript6 libQt6QmlXmlListModel6 libQt6Quick6 libQt6QuickControls2-6 libQt6QuickControls2Impl6 libQt6QuickDialogs2-6 libQt6QuickDialogs2QuickImpl6 libQt6QuickDialogs2Utils6 libQt6QuickEffects6 libQt6QuickLayouts6 libQt6QuickParticles6 libQt6QuickShapes6 libQt6QuickTemplates2-6 libQt6QuickTest6 libQt6QuickVectorImage6 libQt6QuickWidgets6 qt6-declarative-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released - Drop patch, merged upstream: * 0001-QQmlTableInstanceModel-refactor-QModelIndex-calculat.patch ==== qt6-imageformats ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-location ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Location6 - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-multimedia ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Multimedia6 libQt6MultimediaQuick6 libQt6MultimediaWidgets6 libQt6Quick3DSpatialAudio6 libQt6SpatialAudio6 qt6-multimedia-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-networkauth ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-positioning ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Positioning6 libQt6PositioningQuick6 qt6-positioning-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-qt5compat ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Core5Compat6 qt6-qt5compat-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-quick3d ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Quick3D6 libQt6Quick3DAssetImport6 libQt6Quick3DAssetUtils6 libQt6Quick3DEffects6 libQt6Quick3DHelpers6 libQt6Quick3DHelpersImpl6 libQt6Quick3DParticleEffects6 libQt6Quick3DParticles6 libQt6Quick3DRuntimeRender6 libQt6Quick3DUtils6 libQt6Quick3DXr6 qt6-quick3d-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-quicktimeline ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-shadertools ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-speech ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6TextToSpeech6 qt6-texttospeech - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-svg ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Svg6 libQt6SvgWidgets6 - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-tools ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Designer6 libQt6UiTools6 qt6-tools-qdbus - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released - Add patch to make documentation more reproducible (QTBUG-145807): * 0001-QDoc-Use-deterministic-tiebreaker-for-shared-notifie.patch ==== qt6-translations ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-virtualkeyboard ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6HunspellInputMethod6 libQt6VirtualKeyboard6 libQt6VirtualKeyboardQml6 qt6-virtualkeyboard-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-wayland ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-webchannel ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6WebChannel6 libQt6WebChannelQuick6 qt6-webchannel-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-webengine ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6WebEngineCore6 libQt6WebEngineQuick6 libQt6WebEngineWidgets6 qt6-webengine-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released - Drop patch, merged upstream: * 0001-Fix-AMD-VA-API-flickering-on-Wayland-by-allowing-mul.patch ==== qt6-webview ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== rsyslog ==== - fix RainerScript replace() heap buffer overflow (bsc#1275926) * add 0001-fix-RainerScript-replace-heap-buffer-overflow.patch ==== salt ==== Subpackages: python313-salt salt-master salt-minion - Honor proxy settings in gitfs, git_pillar and winrepo (bsc#1261147) - Added: * honor-proxy-settings-in-gitfs-git_pillar-and-winrepo.patch - Fix test failures with pytest>=8 - Added: * migrate-rest_tornado-saltnado-tests-to-pytest-774.patch ==== sdbootutil ==== Version update (1+git20260714.d9bb736 -> 1+git20260825.c7a5a97) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper - Update to version 1+git20260825.c7a5a97: * Refactor free space calculation * Do not use /proc/cmdline in half configured systems * Warning when the recovery PIN is not validated * Show default and booted snapshots with marks * Improve detection of snapshot systems * Fix when searching for a boot entry * Fix boot order and boot order entry * Create the entries directory in the ESP * Fix get_final_pcr parser * Keep btrfs error and show it when fails * Fix set -e early exit instances * Fix measure-pcr-validator when there is no terminal * Don't include measure-pcr-validator in initrd if TPM2 is not used * Update predictions even if crypttab did not change * Improve PCR 15 signing * Detect NAME=VALUE passed as parameters and complain * When asking a password, require a terminal * Filter some warnings from pcrlock * Detect directories that are not part of the snapshot * Write bash completion errors to /dev/null * Detect when t-u apply is done and avoid data corruption * Detect pcr-oracle leftovers * Show in title that it's the initial version for transactional systems * Manually generate PCR7 measurements * Regenerate pcrlock.json when it is missing - Update to version 1+git20260813.357956d: * Do not update the predictions without a TPM2 enrollment (bsc#1273384) - Update to version 1+git20260812.305d9f2: * Do not supplement if GRUB2-EFI is installed (bsc#1272525) ==== sddm ==== Version update (0.21.0 -> 0.21.0+git57) - Build from develop branch - Update to version 0.21.0+git57: * Fix error checking in XcbKeyboardBackend::initLayouts() * fix(greeter): show dark fallback background when image fails to load * Update Romanian translation * Update Kazakh translation * CI: Install the right package for "dnf builddep" command * sddm.service: conflicts with kmsconvt@ttyX * Display: also reuse session created by sddm-autologin * fixed wrong string literal assignment * Update Arabic Translation (#2067) * Do not manage setCursor with startProcess as latter adds X-specific logic * Delete QProcess objects only after waiting for process termination * xorg-user: Allow overriding -verbose Xorg option * Bump minimal timeout for waitForFinished() to 5 seconds * Remove use of qAsConst which is deprecated * Fix index check for UserModel * Update Traditional Chinese translation * CMake: Raise required version to 3.5 * Redesign login shell use in session scripts * Simplify Seat::displayStopped * Less strict [Section Header] parsing for session .desktop files * CI: Replace ubuntu 23.04 with 24.04 * Apply suggestions from review * Apply suggestions from code review * Update Japanese translation * Hebrew translation update * Update he.ts * Update es.ts * Updated spanish translation * If autologin is used, avoid starting a display server for the greeter * Reset daemonApp->first in the Display constructor * Load autologin configuration in Display::Display * Set Display::m_started early * Remove unused Display::m_relogin variable * xcb: use xcb_connection_has_error to check for failue * Fix for issue Suspicious code in PamHandle::end #1990 * CI: Drop building with clang on CentOS Stream9 * CI: Fix order of arguments for dnf * Update Czech translations * Add translation for Persian * Use xrdb to set Xcursor.theme and Xcursor.size * Introduce utmps support (#1962) * Switch back to greeter when logind emits SecureAttentionKey * Prevent the greeter display server from hanging if SwitchToGreeter() is sent to a seat when the greeter is already active * cmake: remove the final (Arch) PAM modules * cmake: drop Debian specific PAM modules * cmake: drop FreeBSD specific PAM modules * Docs: add QtVersion information to THEMING * Themes: set QtVersion=@QT_MAJOR_VERSION@ * Themes: fix deprecated signal handler declarations * Components: use Transitions instead of Behaviors * Themes: explicitly resolve image URLs * Themes: hide LayoutBox when keyboard model is empty or disabled * Mark keyboard backend as disabled on Wayland * UserSession: Only act on the VT when XDG_VTNR is set * Conditionalize more VT related calls * Allow non-root greeters and sessions to start on kernels without VTs * VirtualTerminal: Export defaultVtPath - Drop patches, now upstream: * 0001-CMake-Raise-required-version-to-3.5.patch * 0001-Redesign-login-shell-use-in-session-scripts.patch * 0001-Use-xrdb-to-set-Xcursor.theme.patch * 0001-Remove-unused-Display-m_relogin-variable.patch * 0002-Set-Display-m_started-early.patch * 0003-Load-autologin-configuration-in-Display-Display.patch * 0004-Reset-daemonApp-first-in-the-Display-constructor.patch * 0005-If-autologin-is-used-avoid-starting-a-display-server.patch - Refresh 0003-Leave-duplicate-symlinks-out-of-the-SessionModel.patch - Drop sddm-service-handle-plymouth.patch, plymouth-quit.service is wanted by multi-user.target already - Bundled themes use Qt 6 now, soften sddm-greeter-qt5 requirement to a suggests ==== sddm-kcm6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== sddm-qt6 ==== Version update (0.21.0 -> 0.21.0+git57) Subpackages: sddm-greeter-qt6 - Build from develop branch - Update to version 0.21.0+git57: * Fix error checking in XcbKeyboardBackend::initLayouts() * fix(greeter): show dark fallback background when image fails to load * Update Romanian translation * Update Kazakh translation * CI: Install the right package for "dnf builddep" command * sddm.service: conflicts with kmsconvt@ttyX * Display: also reuse session created by sddm-autologin * fixed wrong string literal assignment * Update Arabic Translation (#2067) * Do not manage setCursor with startProcess as latter adds X-specific logic * Delete QProcess objects only after waiting for process termination * xorg-user: Allow overriding -verbose Xorg option * Bump minimal timeout for waitForFinished() to 5 seconds * Remove use of qAsConst which is deprecated * Fix index check for UserModel * Update Traditional Chinese translation * CMake: Raise required version to 3.5 * Redesign login shell use in session scripts * Simplify Seat::displayStopped * Less strict [Section Header] parsing for session .desktop files * CI: Replace ubuntu 23.04 with 24.04 * Apply suggestions from review * Apply suggestions from code review * Update Japanese translation * Hebrew translation update * Update he.ts * Update es.ts * Updated spanish translation * If autologin is used, avoid starting a display server for the greeter * Reset daemonApp->first in the Display constructor * Load autologin configuration in Display::Display * Set Display::m_started early * Remove unused Display::m_relogin variable * xcb: use xcb_connection_has_error to check for failue * Fix for issue Suspicious code in PamHandle::end #1990 * CI: Drop building with clang on CentOS Stream9 * CI: Fix order of arguments for dnf * Update Czech translations * Add translation for Persian * Use xrdb to set Xcursor.theme and Xcursor.size * Introduce utmps support (#1962) * Switch back to greeter when logind emits SecureAttentionKey * Prevent the greeter display server from hanging if SwitchToGreeter() is sent to a seat when the greeter is already active * cmake: remove the final (Arch) PAM modules * cmake: drop Debian specific PAM modules * cmake: drop FreeBSD specific PAM modules * Docs: add QtVersion information to THEMING * Themes: set QtVersion=@QT_MAJOR_VERSION@ * Themes: fix deprecated signal handler declarations * Components: use Transitions instead of Behaviors * Themes: explicitly resolve image URLs * Themes: hide LayoutBox when keyboard model is empty or disabled * Mark keyboard backend as disabled on Wayland * UserSession: Only act on the VT when XDG_VTNR is set * Conditionalize more VT related calls * Allow non-root greeters and sessions to start on kernels without VTs * VirtualTerminal: Export defaultVtPath - Drop patches, now upstream: * 0001-CMake-Raise-required-version-to-3.5.patch * 0001-Redesign-login-shell-use-in-session-scripts.patch * 0001-Use-xrdb-to-set-Xcursor.theme.patch * 0001-Remove-unused-Display-m_relogin-variable.patch * 0002-Set-Display-m_started-early.patch * 0003-Load-autologin-configuration-in-Display-Display.patch * 0004-Reset-daemonApp-first-in-the-Display-constructor.patch * 0005-If-autologin-is-used-avoid-starting-a-display-server.patch - Refresh 0003-Leave-duplicate-symlinks-out-of-the-SessionModel.patch - Drop sddm-service-handle-plymouth.patch, plymouth-quit.service is wanted by multi-user.target already - Bundled themes use Qt 6 now, soften sddm-greeter-qt5 requirement to a suggests ==== selinux-policy ==== Version update (20260804 -> 20260826) Subpackages: selinux-policy-targeted - Update to version 20260826: * Fix NFS mount with xprtsec=tls / xprtsec=mtls (bsc#1275783) * named filetrans for netconfig (bsc#1275219) * Revert "Apply fix_unconfined.patch" (bsc#1275219) * sshd_session_t needs to access kanidm sshkeys (bsc#1275492) * Fix broken kanidm_sshkeys_t security context (bsc#1275492) * Initial policy for xrdp (bsc#1262291) - Update to version 20260820: * Label the postgresql executables correctly (bsc#1274861) - Update to version 20260810: * (open)SUSE only sendmail fixes (bsc#1273901) ==== serd ==== Version update (0.32.8 -> 0.32.10) - update to 0.32.10 * Address new warnings in clang-tidy 22 * Fix writing quotes at the end of long literals ==== setools ==== Version update (4.7.0 -> 4.7.1) Subpackages: python313-setools setools-console - Fixup mcp flavor: make Name: explicitly unique per flavor. Change 'mcp' flavor to mcp-multibuild to cheat with the name for the subpackage (otherwise we get setools-mcp as source name, which requires us to conidionalize summary/description in the preamble) - Move sedta and seinfoflow to setools-console-analyses and exlude its build for SLE16 as python-networkx won't be available there (bsc#1273200). - Add mcp flavor to allow it to be excluded from ring0 - Update to version 4.7.1: * Add initial prompts to MCP server * Add file_contexts querying class * Change MCP server to use standalone FastMCP package - Make tests run only on x86_64 because of missing dependencies on other archs ==== shadow ==== Version update (4.20.0 -> 4.20.2) Subpackages: libsubid6 login_defs shadow-pw-mgmt - Update to 4.20.2: * lib/: Add missing include. * Remove unused build flag - Drop upstreamed shadow-4.20-stdint.patch ==== signon-kwallet-extension ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== skanlite ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Be a tiny bit more lenient with KSaneWidgets versions - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Remove left-over KF version include ==== spectacle ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 * Scan for QR code when editing existing image (kde#521097) * Fix QTimer construction in annotation sync * Update version for new release 6.7.4 ==== spice-gtk ==== Version update (0.42 -> 0.43) Subpackages: libspice-client-glib-2_0-8 libspice-client-glib-helper libspice-client-gtk-3_0-5 - Update to version 0.43: + Add multi-plane scanout support (SpiceGlScanout2), deprecate spice_display_channel_get_gl_scanout(). + Add EGL direct scanout support on X11 + Add Windows certificate store support for TLS + Add partial chain verification for TLS certificates GStreamer: prefer playbin3, use h/w decoders with Intel GPUs, fallback to s/w decoder if h/w fails + spice-widget: use nearest scaling for integral scaling factors + spicy: add command line option to hide menu bar + Migrate documentation from gtk-doc to gi-docgen + wayland: fix mouse ungrab in server mode + wayland: use separate event queue thread for widgets + gstaudio: fix race replacing existing channels on connect + spice-channel: read all available data from OpenSSL buffer + usb-backend: fix missing refcount increase when allocating device from fd + usb-backend: fix compiling with i686 clang in mingw + channel-display: fix wrong macro expansion + gstreamer: fix leak using GstBus watch + Fix symbol visibility and export handling - Convert package to source service, reference https://gitlab.freedesktop.org/spice/spice-gtk, where there is a 0.43 tag. No tarballs have been published. - Follow upstreams port to gi-docgen: + Drop pkgconfig(gtk-doc) BuildRequires + Add gi-docgen BuildRequires. - Drop spice-gtk-no-six.patch: fixed upstream. - Enable test suite in %check section. - Drop spice-gtk.keyring and signature file: as we clone a git tree now using _service, there is no gpg signature. ==== srt ==== Version update (1.5.6 -> 1.5.7) - Update to version 1.5.7: + Security Notice: - This release includes important security hardening and multiple vulnerability fixes identified during extensive security audits of the SRT codebase. Several issues could allow memory corruption, protocol state manipulation, resource exhaustion, or misuse of auxiliary tools and CI infrastructure. - Users are strongly encouraged to upgrade to this version to benefit from these security improvements and protocol hardening measures. + Security Improvements: - Handshake and Encryption Security: . Fully remediated the KMREQ processing vulnerability by validating all incoming KM message lengths before they reach internal conversion and copy routines, protecting both HSv4 and HSv5 negotiation paths. . Completed the remediation of the encryption downgrade vulnerability by preventing post-establishment KMRSP messages from modifying the security state of already secured sessions. Additional protections were added for both HSv4 and HSv5 negotiation paths. . Added minimum MSS enforcement during connection negotiation to prevent undersized payload buffers that could otherwise lead to heap corruption and information disclosure during handshake generation. . Hardened handshake state processing to correctly derive connection state from the live connection status and prevent unintended state rollback caused by late or malformed handshake exchanges. - Data Plane Protection: . Fixed validation of ACK control messages to prevent send-buffer corruption caused by forged or malformed acknowledgements. Additional bounds checking now ensures that sequence number ranges remain valid before buffer state updates occur. . Added protection against invalid DROPREQ ranges. Reversed ranges and invalid sequence number distances are now rejected before modifying receiver buffer state. . Corrected receive-path connection status handling to prevent non-addressed packets from affecting unrelated connection attempts. - FEC Robustness: . Added payload-size validation in FEC clipping operations to prevent out-of-bounds writes when processing oversized payloads. . Introduced minimum-size validation for FEC control packets, eliminating integer-underflow conditions that could occur when processing malformed packets. . Added upper bounds for peer-supplied FEC configuration values and improved error handling to prevent excessive memory allocation during connection establishment. - Bonding Reliability: . Fixed a use-after-free condition in the bonding BACKUP send path. Internal member context tracking now safely handles members removed while locks are temporarily released, preventing dangling references during failover processing. - Application Hardening: . Added validation of remotely supplied filenames in the srt-file-transmit utility. Path separators, parent directory references, and platform-specific path manipulation patterns are now rejected before files are created. + Build and CI Security Enhancements: - Replaced the dynamic Codecov script download mechanism with a pinned and integrity-verified version. - Pinned ABI compatibility checker dependencies to specific versions and removed reliance on mutable default branches. - Improved GitHub workflow supply-chain protection by pinning third-party actions, container images, and external dependencies to known revisions. + Stability Improvements: - Fixed local connection teardown handling following rejected late handshakes, ensuring the local endpoint correctly terminates invalid connection states. - Improved error handling for FEC initialization failures and memory allocation exceptions, providing graceful connection rejection instead of abrupt failures. + Test Coverage: - Additional negative and security-focused test coverage has been added for: . Malformed KMRSP messages. . Encryption downgrade scenarios. . ACK validation. . DROPREQ malformed and reversed ranges. . FEC oversized payloads and invalid configurations. . Connection cleanup and shutdown paths. ==== step ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== strace ==== Version update (7.1 -> 7.2) - Update to strace 7.2 * Implemented decoding of OPENAT2_REGULAR openat2 flag. * Implemented decoding of IFLA_BRPORT_NEIGH_FORWARD_GRAT attribute. * Implemented decoding of BPF_TRACE_FENTRY_MULTI, BPF_TRACE_FEXIT_MULTI, and BPF_TRACE_FSESSION_MULTI bpf attach types. * Updated decoding of BPF_LINK_CREATE uprobe_multi attribute. * Updated decoding of struct landlock_ruleset_attr. * Updated decoding of landlock_add_rule syscall flags. * Implemented decoding of ZCRX_CTRL_ARM_NOTIFICATION io_uring zcrx ctrl operation. * Implemented decoding of IO_URING_QUERY_ZCRX_EVENT io_uring query operation. * Updated lists of BPF_*, ETH_P_*, FS_*, FUTEX_*, IFLA_*, IO_URING_*, KVM_*, LANDLOCK_*, NL80211_*, O_*, RTEXT_*, V4L2_*, and XFRM_MSG_* constants. * Updated lists of ioctl commands from Linux 7.2. ==== suitesparse ==== Version update (7.12.2 -> 7.13.0) Subpackages: libamd3 libcamd3 libccolamd3 libcholmod5 libcolamd3 libsuitesparseconfig7 libumfpack6 - Update to 7.13.0 * GraphBLAS 10.4.1: memory arenas, faster GhB MATLAB/Octave interface * ParU 1.1.2: backport to gcc 7.5.0 - Update to 7.12.3 * ParU 1.1.1: MATLAB mexFunction does not #include mkl.h on Intel systems * GraphBLAS 10.3.2: minor update for recent clang compilers * SuiteSparse_config 7.12.3: version update to match SuiteSparse. Require cmake 3.23 for CUDA -arch="all" parameter to nvcc. * CSparse 4.4.2: minor fix to build system; sync version with CXSparse * UMFPACK 6.3.8: sync definition and declaration of umf_row_search. ==== svgpart ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Port to KStandardActions * Fix cmake warnings ==== swtpm ==== Version update (0.10.1 -> 0.10.2) Subpackages: swtpm-selinux - update to 0.10.2: * CVE-2026-75900: swtpm: Fix length check in SWTPM_NVRAM_CheckHeader() (boo#1275653) * Properly check for truncation following snprintf call - drop patches included upstream: * 1271417-drop-tunable-requires.patch * 1027.patch * 1132.patch - add upstream signing key and validate source signature ==== systemsettings6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== thai-fonts ==== Version update (0.7.3 -> 0.7.4) - Update to version 0.7.4. * Build system: - Fix make rules to prevent parallel build failure, following the fix for fonts-arundina in Debian #1105308. - Fix reproducibility issues in Type1 fonts (with different approach from the fix of the same problem in fonts-arundina). - Fix reproducibility issue caused by collation in TeX font map generation. * LaTeX: - Update example LaTeX documents for ucs 2.3+. - Sync dummy AFM with ENC files for more correct Latin part in TFM generation. - Make top-level directory of the generated CTAN tarball unversioned. * Fonts: - Kinnari, Norasi: Balance cubic splines for optimal quadratic splines. - Add Stylistic Set 1 (ss01) lookup to all fonts for descenderless YO YING and THO THAN. - modified patches * build.patch (refreshed) ==== thin-provisioning-tools ==== - Refresh the vendored Rust crates: 62 changed version, two added (jiff-core, palette_math), three dropped (fast-srgb8 and the proc-macro-error2 pair); upstream sources are unchanged. - Re-derive License from the crates actually linked into the shipped binary: Apache-2.0 AND GPL-3.0-only AND MIT AND MPL-2.0 AND Unicode-3.0, and install each linked crate's licence text next to COPYING. - Move %check into a separate "test" multibuild flavour, so a test failure no longer blocks the binaries that the 88 dependent packages build against. - Add thin-provisioning-tools-tests-clap-single-alias.patch: the refreshed clap renders "alias" instead of "aliases" for a single alias, which broke two hardcoded thin_delta help assertions (gh#jthornber/thin-provisioning-tools#328). ==== timezone ==== Subpackages: tzselect - Install "right" files in SLES/Leap 16.x (bsc#1273508) ==== tree-sitter ==== - Do not emit treesitter_grammar_src() rpm symbols for relative require() paths (., .., ./, ../). Local relative requires are still followed to find nested external grammar deps. Fixes installcheck on grammars that share a sibling common/ directory (nothing provides treesitter_grammar_src(../common) for tree-sitter-php-devel). - Add an opt-in Python binding macro to the grammar framework. Review follow-up: generate a Python loader instead of compiling the upstream C binding, so the parser is not built a second time: * %treesitter_python_install installs upstream's pure-Python bindings/python package files as-is and replaces the compiled _binding extension with a generated _binding.py that loads the grammar library from %{_libdir}/tree-sitter via ctypes and hands its TSLanguage pointer to python-tree-sitter as the "tree_sitter.Language" PyCapsule the Language() constructor expects - no duplicate parser, no compiler, no wheel * New source tree-sitter-python-shim.py.in: the template the generated _binding.py comes from, shipped in %{_rpmconfigdir} so it is versioned and testable instead of inlined in a macro * %treesitter_python_build is a deprecated no-op; consumers no longer need the python devel/pip/wheel/setuptools/installer BuildRequires * The python subpackage pins the grammar package exactly (Requires: %{name} = %{version}-%{release}); library and binding come from the same source package and move in lockstep * %treesitter_python_install also takes an explicit multi-language form, MODNAME GRAMMAR..., for upstream modules that expose several grammars from one python package: each grammar yields a language_() function loading its own library, matching the upstream binding of tree-sitter-typescript (language_typescript and language_tsx, no plain language) * Consuming specs still carry the (now much smaller) singlespec template literally: the python-rpm-macros generator re-reads the raw spec text for the %package template, so an %include fragment cannot provide it (the BuildRequires alone could move to a fragment - the OBS scheduler does resolve %include - but splitting one small block across two files is not worth it) * Documented python subpackage dep is Suggests: python-tree-sitter >= 0.22, not Requires -- python-tree-sitter is not in Rings:1-MinimalX, so a hard Requires fails Staging installcheck for ring1 grammars (matching tree-sitter-bash) * No change for grammar packages that do not opt in ==== u-boot-rpiarm64 ==== Subpackages: u-boot-rpiarm64-doc - Add beaglevfire flavor ==== udisks2 ==== Version update (2.11.1 -> 2.11.2) Subpackages: libudisks2-0 libudisks2-0_btrfs udisks2-bash-completion - Update to 2.11.2 (CVE-2026-7867): * This is a bugfix release with a security fix, several crash and memory leak fixes, and mount options update. * Security fix: - CVE-2026-7867: An unprivileged D-Bus caller could use the 'as-user' Filesystem.Mount() option combined with fstab entries containing 'user' or 'users' mount options to mount on behalf of another user without polkit authorization. * Changes from 2.11.1: - udiskslinuxnvmenamespace: Report cancellation as error in format job - udiskslinuxprovider: Fix memory leak on spurious uevents - udiskslinuxprovider: Initialize GError pointer in sleep signal handler - udisksdaemonutil: Fix missing NULL terminator in resolve_links() - udiskslinuxdriveata: Add missing D-Bus method completion for SecurityEraseUnit - udiskslinuxfilesystem: Fix missing goto after mount state check in handle_resize - udiskslinuxfilesystem: Fix missing goto after mount state check in handle_repair - udiskslinuxfilesystem: Fix missing goto after mount state check in handle_check - udiskslinuxfilesystem: Fix mounted check in filesystem update - udiskslinuxmountoptions: Fix integer overflow in UID/GID option parsing - udiskslinuxmountoptions: Fix static buffer and hardcoded limit in is_uid_in_gid - doap: Update storaged.org https link - udisksmodulemanager: Fix broken module error check - lvm2: Fix NULL dereference in VG create uevent trigger loop - mount options: Sync exfat allowed options with the latest kernel - udiskslinuxfilesystem: Separate real caller identity from as-user target - udiskslinuxfilesystem: Rework fstab mount authorization for as-user - udiskslinuxfilesystem: Log real caller uid for as-user mounts - udisksdaemonutil: Pass as-user target to polkit details - tests: Add security tests for as-user mount authorization - tests: Trigger controller rescan after namespace re-attach in test_ns_detach - tests: Temporarily skip NTFS3 configurable mount options test ==== umbrello ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Added option to make KDocTools optional (similar to the other components). * Use QGuiApplication in svg2png * svn2png: documentation on cursor configuration added * cmake: remove references to redundant variables in endif() * svn2png: Fix bug not checking the correct svg renderer instance * Fix clip4 paste of sequence messages across instances (kde#418395) * Fix bug not initializing the scene background color (kde#519794) * Qt6: Fix not finding configuration files for layout generator (kde#519790) * Fixup for last commit * Refine association duplicate check to full edge identity * Fix duplicate named association widgets during diagram load (kde#519215) ==== unbound ==== Subpackages: libunbound8 unbound-anchor - Add patch to fix build issue with swig 4.5 [unbound-swig-4.5-compat.patch] ==== util-linux ==== Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 - Fix post installation message conditions (bsc#1268886#c17). ==== util-linux-systemd ==== Subpackages: lastlog2 liblastlog2-2 - Fix post installation message conditions (bsc#1268886#c17). ==== vim ==== Version update (9.2.0780 -> 9.2.0901) Subpackages: vim-data vim-data-common xxd - gvim.desktop: Remove deprecated values - Update to 9.2.0901: 9.2.0781: tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir 9.2.0782: tests: missing cleanup in test_mksession.vim 9.2.0783: tests: personal spell files leak into later tests 9.2.0784: crash when borrowing statusline highlight in silent Ex mode 9.2.0785: WinResized not triggered when the whole Vim is resized 9.2.0786: filetype: Containerfile is not recognized 9.2.0787: regexp: code 0x1ecb duplicated for equivalence class 9.2.0788: filetype: hip files are not recognized 9.2.0789: 'statuslineopt' status line too high after a window is minimized 9.2.0790: 'completeslash' breaks :find completion with 'findfunc' 9.2.0791: wincol() counts from right side for 'rightleft' 9.2.0792: runtime(netrw): Explore without optional dir broken 9.2.0793: If session restored a tiny window, restore fails 9.2.0794: extend() and extendnew() don't handle NULL expr2 properly 9.2.0795: popup menu shadow is not cleared when the menu shrinks 9.2.0796: Visual block reselection wrong with 'virtualedit' 9.2.0797: Memory leak in get_qfline_items() on alloc failure 9.2.0798: Memory leak in compile_expr6() on alloc failure 9.2.0799: Memory leak in compile_def_function_body() on alloc failure 9.2.0800: Memory leak in call_func() on alloc failure 9.2.0801: Memory leak in f_getreginfo() on alloc failure 9.2.0802: Memory leak with list_append_dict/dict_add_list on alloc failure 9.2.0803: Memory leak on alloc failure with taglist/gettagstack() 9.2.0804: wincol() is wrong for a double-wide character with 'rightleft' 9.2.0805: screenpos() "curscol" is wrong with 'rightleft' 9.2.0806: 'showcmd' may show internal command keys 9.2.0807: MS-Windows: ellipsis character is garbled 9.2.0808: getregionpos: double-free on alloc failure 9.2.0809: getframelayout() uses wrong function to free lists 9.2.0810: add_llist_tags() uses wrong function to free dict 9.2.0811: mksession writes terminal command unquoted 9.2.0812: :argdelete with pattern leads to wrong argidx() 9.2.0813: dict_add_func() may corrupt funcref count on failure 9.2.0814: Vim9: E1041 when reloading an autoload script with exported variables 9.2.0815: deeply nested regexp patterns may cause stack overflow 9.2.0816: GTK4: Memory leak in gui_gtk_set_dnd_targets() 9.2.0817: crash when building a stacktrace during an autocommand 9.2.0818: tests: client-server test fails without X11 server 9.2.0819: MS-Windows: sixel image shown as raw text in the console 9.2.0820: GUI: hidden popup image is displayed and not erased 9.2.0821: filetype: msmtp system-wide rc file not detected 9.2.0822: GTK4: crash menu id is null in gui_mch_destroy_menu() 9.2.0823: tests: Test_clientserver_servlist_list may fail 9.2.0824: Makefile: Make tags depends on configure 9.2.0825: regexp: submatch in a look-behind is empty with the NFA engine 9.2.0826: highlighting for broken terminals can be improved 9.2.0827: :startinsert enters Insert mode in a non-modifiable buffer 9.2.0828: GTK4: hardware rendering can be improved 9.2.0829: Sessions do not preserve script version for expression options 9.2.0830: the completion menu is not used on terminals without colors 9.2.0831: diff highlighting hard to read with syntax enabled 9.2.0832: socketserver: remote commands can be processed in reverse order 9.2.0833: GTK4: menu mnemonics do not work properly 9.2.0834: cleared last search pattern is restored from viminfo 9.2.0835: features in version.c are not sorted 9.2.0836: filetype: .git-blame-ignore-revs file is not recognized 9.2.0837: Using wrong colors in hl_blend_attr() 9.2.0838: searchcount() returns wrong cached maxcount 9.2.0839: [security]: arbitrary code execution via keyword lookup 9.2.0840: [security]: code injection in netrw via bookmarks 9.2.0841: [security]: heap overflow when adding > 65535 text properties 9.2.0842: [security]: stack buffer overflow in socket server 9.2.0843: [security]: popup: opacity mask indexed out of bounds 9.2.0844: [security]: use-after-free on json decode error 9.2.0845: [security]: arbitrary Ex command execution during C omni-completion 9.2.0846: [security]: heap buffer overflow in set_sofo() 9.2.0847: [security]: vimball: code execution via .VimballRecord file 9.2.0848: tagfunc "cmd" with a generic Ex command corrupts the tag entry 9.2.0849: filetype: osquery config files are not recognized 9.2.0850: MS-Windows: commands from a client can be lost 9.2.0851: Focus autocommands triggered inconsistently 9.2.0852: GTK: ligatures not correctly displayed 9.2.0853: popup: popup images do not support scaling 9.2.0854: memory leak when reading a spell file with SN_SAL and SN_SOFO 9.2.0855: 'showcmd' not redrawn with empty mapping triggered on timeout 9.2.0856: GTK4: undercurl rendering is inefficient 9.2.0857: popup: opacity popup over a terminal is not cleared when closed 9.2.0858: MS-Windows GUI: white flash when VimEnter is slow 9.2.0859: GTK2: Link error 9.2.0860: filetype: xilinx design constraint files are not recognized 9.2.0861: GTK4: bleed region updates in jumps 9.2.0862: Missing test change from v9.2.0857 9.2.0863: MS-Windows GUI: window contents can be missing when VimEnter is slow 9.2.0864: Using some dead code in Wayland feature 9.2.0865: GTK4: non-hardware accelerated UI is too slow 9.2.0866: MS-Windows: ":language messages" only works once 9.2.0867: MS-Windows: messages are not in the display language 9.2.0868: GTK: Window Manager hint prevents giving focus to dialog 9.2.0869: buf_copy_options() can lose the P_INSECURE flag 9.2.0870: filetype: marko files are not recognized 9.2.0871: screen line is lost when splitting a 'winfixheight' window 9.2.0872: popup with opacity does not use the font of the highlight group 9.2.0873: :redrawstatus does not update the ruler of the last window 9.2.0874: fold size is compared against 'foldminlines' of the wrong window 9.2.0875: GTK4: GUI does not support command-line arguments 9.2.0876: GTK4: compile error with disabled netbeans feat 9.2.0877: Vim9: crash when a closure assigns to a variable declared in a loop ... changelog too long, skipping 24 lines ... 9.2.0901: textprop: wrong cursor line with truncated virtual text ==== vte ==== Version update (0.84.0 -> 0.84.1) - Update to version 0.84.1: * vte.sh: Unify the escape character's notation * vte.sh: Preserve the previous value of PS0 * vte.sh: Fix improper escaping in PS0 * lib: Unify erase/backspace binding handling * lib: Fix typo in comment * app: Try a XTERM_RQTCAP query when --no-pty * build: simdutf: Update to 8.2.0 * app: Add preset option ==== wacomtablet-kcm6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== webkitgtk3 ==== Version update (2.52.5 -> 2.52.6) Subpackages: libjavascriptcoregtk-4_1-0 libwebkit2gtk-4_1-0 typelib-1_0-JavaScriptCore-4_1 typelib-1_0-WebKit2-4_1 webkit2gtk-4_1-injected-bundles - Update to version 2.52.6 (bsc#1275791): + Improve memory usage in pages that use font variations. + The webkit://gpu page now respects the dark theme user preference. + Fix cross compilation due to failure to pick the correct gio-unix-2.0 headers in certain configurations. + Fix calculating data sizes of reported through WebKitWebsiteData. + Fix the build with CMake 4.4 or newer. + Fix several crashes and rendering issues. + Security fixes: CVE-2026-43804, CVE-2026-64713, CVE-2026-64719, CVE-2026-64728, CVE-2026-64730, CVE-2026-64757, CVE-2026-64783. ==== webkitgtk4 ==== Version update (2.52.5 -> 2.52.6) Subpackages: libjavascriptcoregtk-6_0-1 libwebkitgtk-6_0-4 typelib-1_0-JavaScriptCore-6_0 typelib-1_0-WebKit-6_0 webkitgtk-6_0-injected-bundles - Update to version 2.52.6 (bsc#1275791): + Improve memory usage in pages that use font variations. + The webkit://gpu page now respects the dark theme user preference. + Fix cross compilation due to failure to pick the correct gio-unix-2.0 headers in certain configurations. + Fix calculating data sizes of reported through WebKitWebsiteData. + Fix the build with CMake 4.4 or newer. + Fix several crashes and rendering issues. + Security fixes: CVE-2026-43804, CVE-2026-64713, CVE-2026-64719, CVE-2026-64728, CVE-2026-64730, CVE-2026-64757, CVE-2026-64783. ==== wget ==== - Fix server-controlled unbounded MD5 loop in FTP OPIE [bsc#1276962; CVE-2026-16599] * CVE-2026-16599.patch - Fix segmentation fault in metalink4, bsc#1273449 * Fix-segfault-in-retrieve_from_metalink-when-a-metalink.patch ==== wicked ==== Subpackages: wicked-service - Fix two OOB reads in ni_capture_inspect_udp_header and improve: [+ 0001-capture-fix-two-OOB-reads-in-ni_capture_inspect_udp.patch] - Reject packets with ip_len < ihl to avoid a size_t underflow of the UDP length, which the checksum truncates to uint16_t (bsc#1274627, CVE-2026-71401). - Set payload_len to the remaining payload, not ip_len, which over-read the DHCP option walker by ihl + 8 bytes past the buffer (bsc#1274627, CVE-2026-71402). - Avoid checksumming packets that fail the length/protocol checks and tidy up the debug messages (bsc#1274627). - Fix underflow check in ni_dhcp4_option_next to handle option code and length separately as the END and PAD options don't have length (bsc#1274627). Thanks to Daniel Birtwhistle for discovering and reporting the issues. ==== wpa_supplicant ==== Version update (2.11 -> 2.12) - Update to v2.12: * support RSN overriding (e.g., WPA3-Personal Compatibility Mode) * EHT/IEEE 802.11be/Wi-Fi 7 - more complete support - fix message validation issues that could enable DoS attacks - fix group key rekeying * enable SAE group 20 by default if SAE-EXT-KEY is enabled * reject unexpected SAE password identifier to avoid DoS attack against a specific STA * mandate use of SAE H2E when using password identifiers * assign VLAN when using SAE with PMKSA caching * support SPP A-MSDU negotiation * support IEEE 802.11bi functionality - changing SAE password identifiers - EPPKE - IEEE 802.1X/EAP in Authentication frames - Association frame encryption - PMKID privacy * remove the driver interface for now obsolete Host AP driver * remove the driver interface for now obsolete Atheros WEXT interface * move supported, basic, and Beacon TX rate configuration to be at BSS level instead of per-radio for all BSSs * fix various issues in Multiple-BSSID functionality * support OpenSSL 3.0 API changes * EAP-TEAP: protocol changes based on RFC 9930; this is not compatible with previous versions * support Automated Frequency Coordination (AFC) on the 6 GHz band * improve GAS/ANQP processing to support larger ANQP responses * a large number of other fixes, cleanup, and extensions * Remove included patches: - 0001-wpa_gui-Port-to-Qt6.patch - CVE-2025-24912.patch - CVE-2026-58374.patch - Require-network_ctx-and-AKMP-match-for-accepting-PMK.patch - SAE-Fix-crash-due-to-NULL-pointer-dereference-in-H2E.patch - mesh-Reject-AMPE-MIC-element-with-length-AES_BLOCK_S.patch - wpa_supplicant_support_pem_encoded_chain.patch * Refresh patches: - Revert-Mark-authorization-completed-on-driver-indica.patch - wpa_supplicant-alloc_size.patch - wpa_supplicant-flush-debug-output.patch - wpa_supplicant-sigusr1-changes-debuglevel.patch - Update build config * CONFIG_HE_OVERRIDES=y (Support HE overrides) * CONFIG_IPV6=y * CONFIG_SAE_PK=y (SAE Public Key, WPA3-Personal) * CONFIG_IEEE80211BE=y (enable native support for Wi-Fi 7) * CONFIG_PMKSA_PRIVACY=y (PMKSA caching privacy support) * CONFIG_IEEE8021X_AUTH=y (IEEE P802.11bi/D4.0, 12.16.5 ) * CONFIG_TLS_ENGINE_TRUSTED_PATH=y - Add RADIUS-Fix-Message-Authenticator-attribute-validatio.patch https://w1.fi/security/2026-5 ==== xdg-dbus-proxy ==== Version update (0.1.7 -> 0.1.8) - Update to version 0.1.8: + Fix broadcast messages bypassing path/interface/member checks + Improvements to the existing testing infrastructure + Add tests for owning names, issuing method calls, receiving messages - Add xdg-dbus-proxy-tests subpackage with installed tests for gnome-desktop-testing-runner ==== xdg-desktop-portal-kde6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * screencast: Implement v5; provide mapping_id for eis users * globalshortcuts: Do not register shortcuts on session creation (kde#523063) * Update version for new release 6.7.4 ==== xfce4-dict ==== Version update (0.8.9 -> 0.8.10) Subpackages: xfce4-dict-lang - Update to version 0.8.10 * Fix more leaks * Avoid dereference of NULL * Fix heap-buffer-overflow * I18n: Update po/LINGUAS list * build: Fix typo in optimization level * README.md: Add uninstall info * Stop using xfce_panel_plugin_(block|unblock)_menu * Remove also #include * build: Fix deprecated feature warning * Update README * Drop autotools support * Add LLM support * Translation Updates ==== yast2-ntp-client ==== Version update (5.0.1 -> 5.0.2) - bsc#1274746 - fix loading 'server' entries when there is only one of them - fixed removing of ntp source - 5.0.2 ==== yast2-storage-ng ==== Version update (5.0.49 -> 5.0.50) - Fix automatic generation of crypt names (bsc#1247173). - 5.0.50 ==== yelp ==== Version update (49.1+3 -> 49.2) Subpackages: libyelp-1-0 - Update to version 49.2: + Fixed build issue caused by direct inclusion of a GDK header + Fixed typo in the metainfo data + Fixed compiler warning caused by unused return value + Removed a duplicate key in the Flatpak manifest + Updated translations. ==== zstd ==== Subpackages: libzstd1 - Move the tests into a multibuild flavor: * speed up build from 1092s to 167s - important for bootstrap * only apply the constraint to tests for faster scheduling