Packages changed: MicroOS-release (20240425 -> 20240426) docker (25.0.3_ce -> 26.1.0_ce) dracut (059+suse.563.g4900899a -> 059+suse.581.g19b7c06c) ffmpeg-4 ffmpeg-6 google-noto-coloremoji-fonts (20230315 -> 20240424) libupnp (1.14.18 -> 1.14.19) pcsc-lite (2.0.3 -> 2.1.0) podman sqlite3 (3.45.2 -> 3.45.3) systemd-presets-branding-Aeon thin-provisioning-tools tracker (3.7.1 -> 3.7.2) tracker-miners (3.7.1 -> 3.7.2) === Details === ==== MicroOS-release ==== Version update (20240425 -> 20240426) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== docker ==== Version update (25.0.3_ce -> 26.1.0_ce) Subpackages: docker-rootless-extras - Update to Docker 26.1.0-ce. See upstream changelog online at - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch * cli-0001-docs-include-required-tools-in-source-tree.patch - Update to Docker 26.0.1-ce. See upstream changelog online at - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch * cli-0001-docs-include-required-tools-in-source-tree.patch - Update --add-runtime to point to correct binary path. [NOTE: This update was only ever released in SLES and Leap.] - Update to Docker 25.0.5-ce. See upstream changelog online at bsc#1223409 - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch * cli-0001-docs-include-required-tools-in-source-tree.patch - Remove upstreamed patches: - 0007-daemon-overlay2-remove-world-writable-permission-fro.patch - Update --add-runtime to point to correct binary path. [NOTE: This update was only ever released in SLES and Leap.] - Add patch to fix bsc#1220339 * 0007-daemon-overlay2-remove-world-writable-permission-fro.patch - rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch * 0006-Vendor-in-latest-buildkit-v0.11-branch-including-CVE.patch ==== dracut ==== Version update (059+suse.563.g4900899a -> 059+suse.581.g19b7c06c) Subpackages: dracut-ima - Update to version 059+suse.581.g19b7c06c: * fix(dracut): move hooks directory from /usr/lib to /var/lib (bsc#1218068) * feat(tpm2-tss): add tpm2.target and systemd-tpm2-generator * fix(systemd): explicitly install some libs that will not be statically included * fix(dracut-lib): only remove initqueue/finished scripts, not the hook dir * fix(dracut-util): avoid memory leak * fix(dracut-install): memory leak in two `hashmap_put` calls if key exists * fix(dracut-install): release memory allocated for regular expressions * fix(dracut-install): memory leak in `--modalias` option * refactor(dracut-install): strerror(errno) -> %m * perf(dracut-install): don't strdup() environment block * perf(dracut-install): don't reallocate {src,dst}path in hmac_install() * perf(dracut-install): don't strdup() excessively for dracut_install() * perf(dracut-install): stat() w/unused buf -> access(F_OK) in dracut-install * perf(dracut-install): multiple single-character strstr()s -> strpbrk() ==== ffmpeg-4 ==== Subpackages: libavcodec58_134 libavformat58_76 libavutil56_70 libpostproc55_9 libswresample3_9 libswscale5_9 - Add ffmpeg-CVE-2023-51793.patch: Backporting 0ecc1f0e from upstream, Fix odd height handling. (CVE-2023-51793 bsc#1223272) - Add ffmpeg-CVE-2023-49502.patch: Backporting 737ede40 from upstream, account for chroma sub-sampling in min size calculation. (CVE-2023-49502 bsc#1223235) - Address boo#1223304/CVE-2023-51798: add patch 0001-avfilter-vf_minterpolate-Check-pts-before-division.patch ==== ffmpeg-6 ==== Subpackages: libavcodec60 libavfilter9 libavformat60 libavutil58 libpostproc57 libswresample4 libswscale7 - Add ffmpeg-CVE-2023-50008.patch: Backporting 5f87a68c from upstream, Fix memory leaks. (CVE-2023-50008 bsc#1223254) - Add ffmpeg-CVE-2023-50007.patch: Backporting b1942734 from upstream, Fix crash with EOF handling. (CVE-2023-50007 bsc#1223253) ==== google-noto-coloremoji-fonts ==== Version update (20230315 -> 20240424) - Update to v2.042 * Unicode 15.1 update ==== libupnp ==== Version update (1.14.18 -> 1.14.19) Subpackages: libixml11 libupnp17 - Update to release 1.14.19 * Fix some memory allocations in the "TvDevice" example ==== pcsc-lite ==== Version update (2.0.3 -> 2.1.0) - Update the spec for building with version 2.1.0 - version 2.1.0 * LIBPCSCLITE_DELEGATE is used to redirect to another libpcsclite library * setup_spy.sh displays the LIBPCSCLITE_DELEGATE value to use for spying * provides libfake.c as a sample source code * Some other minor improvements- ==== podman ==== - convert to using obs_scm ==== sqlite3 ==== Version update (3.45.2 -> 3.45.3) - Update to release 3.45.3: * Fix a long-standing bug (going back to version 3.24.0) that might (rarely) cause the "old.*" values of an UPDATE trigger to be incorrect if that trigger fires in response to an UPSERT. * Reduce the scope of the NOT NULL strength reduction optimization that was added as item 8e in version 3.35.0. The optimization was being attempted in some contexts where it did not work, resulting in incorrect query results. - Add SQLITE_STRICT_SUBTYPE=1 as recommended by upstream. ==== systemd-presets-branding-Aeon ==== - Remove redundant services formerly from MicroOS - Remove sshd from presets (we're a desktop OS) ==== thin-provisioning-tools ==== - Update vendored dependencies ==== tracker ==== Version update (3.7.1 -> 3.7.2) Subpackages: libtracker-sparql-3_0-0 tracker-data-files - Update to version 3.7.2: + Fix runtime issue introduced by SQLite 3.45.3. + Fix possible inconsistency in the handling of DELETE WHERE queries. + Updated translations. ==== tracker-miners ==== Version update (3.7.1 -> 3.7.2) Subpackages: tracker-miner-files - Update to version 3.7.2: + Fixes to data deletion after removing an indexed folder from configuration. + Fixed glib/inotify based monitors to not follow symlinks in some circumstances. + Added a build-time option for fanotify. + Fix build with musl libc. + Updated translations.