Packages changed: Imath (3.2.2 -> 3.2.3) Mesa (26.1.6 -> 26.2.1) Mesa-drivers (26.1.6 -> 26.2.1) MicroOS-release (20260806 -> 20260830) PackageKit adwaita-fonts (50.0 -> 51.0) apparmor at-spi2-core (2.60.5 -> 2.60.6) aurorae6 (6.7.3 -> 6.7.4) baloo-widgets (26.04.3 -> 26.08.0) bluedevil6 (6.7.3 -> 6.7.4) bolt breeze6 (6.7.3 -> 6.7.4) breeze6-gtk (6.7.3 -> 6.7.4) busybox bzip2 c-ares (1.34.6 -> 1.34.8) chrony (4.8 -> 4.9) cloud-init cockpit (364 -> 365) cockpit-podman (128 -> 129) colord cpio ddcutil (2.2.5 -> 2.2.7) discover6 (6.7.3 -> 6.7.4) dolphin (26.04.3 -> 26.08.0) dracut (110+suse.45.geaec47e4 -> 112+suse.34.g35e16b7) dracut-pcr-signature (0.7+0 -> 0.8+0) exfatprogs (1.4.2 -> 1.4.3) expat (2.8.1 -> 2.8.2) faad2 (2.11.2.git18 -> 2.11.3) falkon (26.04.3 -> 26.08.0) ffmpegthumbs (26.04.3 -> 26.08.0) flatpak (1.18.0 -> 1.18.2) flatpak-kcm6 (6.7.3 -> 6.7.4) fwupd gcab gcc16 (16.1.1+git9481 -> 16.2.0+git9497) glib-networking glibmm2_4 (2.66.9 -> 2.66.10) glslang (16.4.0 -> 16.5.0) gnutls graphene gvfs (1.60.1 -> 1.60.2) gzip harfbuzz (14.2.1 -> 14.3.1) json-glib kaccounts-integration (26.04.3 -> 26.08.0) kaccounts-providers (26.04.3 -> 26.08.0) kactivitymanagerd6 (6.7.3 -> 6.7.4) kate (26.04.3 -> 26.08.0) kde-cli-tools6 (6.7.3 -> 6.7.4) kde-gtk-config6 (6.7.3 -> 6.7.4) kdecoration6 (6.7.3 -> 6.7.4) kdegraphics-mobipocket (26.04.3 -> 26.08.0) kdegraphics-thumbnailers (26.04.3 -> 26.08.0) kdenetwork-filesharing (26.04.3 -> 26.08.0) kdeplasma6-addons (6.7.3 -> 6.7.4) kdialog (26.04.3 -> 26.08.0) kernel-default-base (7.1.6 -> 7.2.2) kernel-source (7.1.6 -> 7.2.2) kf6-attica (6.28.0 -> 6.29.0) kf6-baloo (6.28.0 -> 6.29.0) kf6-bluez-qt (6.28.0 -> 6.29.0) kf6-breeze-icons (6.28.0 -> 6.29.0) kf6-frameworkintegration (6.28.0 -> 6.29.0) kf6-karchive (6.28.0 -> 6.29.0) kf6-kauth (6.28.0 -> 6.29.0) kf6-kbookmarks (6.28.0 -> 6.29.0) kf6-kcmutils (6.28.0 -> 6.29.0) kf6-kcodecs (6.28.0 -> 6.29.0) kf6-kcolorscheme (6.28.0 -> 6.29.0) kf6-kcompletion (6.28.0 -> 6.29.0) kf6-kconfig (6.28.0 -> 6.29.0) kf6-kconfigwidgets (6.28.0 -> 6.29.0) kf6-kcontacts (6.28.0 -> 6.29.0) kf6-kcoreaddons (6.28.0 -> 6.29.0) kf6-kcrash (6.28.0 -> 6.29.0) kf6-kdbusaddons (6.28.0 -> 6.29.0) kf6-kdeclarative (6.28.0 -> 6.29.0) kf6-kded (6.28.0 -> 6.29.0) kf6-kdesu (6.28.0 -> 6.29.0) kf6-kdnssd (6.28.0 -> 6.29.0) kf6-kdoctools (6.28.0 -> 6.29.0) kf6-kfilemetadata (6.28.0 -> 6.29.0) kf6-kglobalaccel (6.28.0 -> 6.29.0) kf6-kguiaddons (6.28.0 -> 6.29.0) kf6-kholidays (6.28.0 -> 6.29.0) kf6-ki18n (6.28.0 -> 6.29.0) kf6-kiconthemes (6.28.0 -> 6.29.0) kf6-kidletime (6.28.0 -> 6.29.0) kf6-kimageformats (6.28.0 -> 6.29.0) kf6-kio (6.28.0 -> 6.29.0) kf6-kirigami (6.28.0 -> 6.29.0) kf6-kitemmodels (6.28.0 -> 6.29.0) kf6-kitemviews (6.28.0 -> 6.29.0) kf6-kjobwidgets (6.28.0 -> 6.29.0) kf6-knewstuff (6.28.0 -> 6.29.0) kf6-knotifications (6.28.0 -> 6.29.0) kf6-knotifyconfig (6.28.0 -> 6.29.0) kf6-kpackage (6.28.0 -> 6.29.0) kf6-kparts (6.28.0 -> 6.29.0) kf6-kpty (6.28.0 -> 6.29.0) kf6-kquickcharts (6.28.0 -> 6.29.0) kf6-krunner (6.28.0 -> 6.29.0) kf6-kservice (6.28.0 -> 6.29.0) kf6-kstatusnotifieritem (6.28.0 -> 6.29.0) kf6-ksvg (6.28.0 -> 6.29.0) kf6-ktexteditor (6.28.0 -> 6.29.0) kf6-ktextwidgets (6.28.0 -> 6.29.0) kf6-kunitconversion (6.28.0 -> 6.29.0) kf6-kuserfeedback (6.28.0 -> 6.29.0) kf6-kwallet (6.28.0 -> 6.29.0) kf6-kwidgetsaddons (6.28.0 -> 6.29.0) kf6-kwindowsystem (6.28.0 -> 6.29.0) kf6-kxmlgui (6.28.0 -> 6.29.0) kf6-modemmanager-qt (6.28.0 -> 6.29.0) kf6-networkmanager-qt (6.28.0 -> 6.29.0) kf6-prison (6.28.0 -> 6.29.0) kf6-purpose (6.28.0 -> 6.29.0) kf6-qqc2-desktop-style (6.28.0 -> 6.29.0) kf6-solid (6.28.0 -> 6.29.0) kf6-sonnet (6.28.0 -> 6.29.0) kf6-syndication (6.28.0 -> 6.29.0) kf6-syntax-highlighting (6.28.0 -> 6.29.0) kgamma6 (6.7.3 -> 6.7.4) kglobalacceld6 (6.7.3 -> 6.7.4) kinfocenter6 (6.7.3 -> 6.7.4) kio-extras (26.04.3 -> 26.08.0) kio-gdrive (26.04.3 -> 26.08.0) kmenuedit6 (6.7.3 -> 6.7.4) knighttime6 (6.7.3 -> 6.7.4) konsole (26.04.3 -> 26.08.0) kpipewire6 (6.7.3 -> 6.7.4) kpmcore (26.04.3 -> 26.08.0) kscreen6 (6.7.3 -> 6.7.4) kscreenlocker6 (6.7.3 -> 6.7.4) ksshaskpass6 (6.7.3 -> 6.7.4) ksystemstats6 (6.7.3 -> 6.7.4) kwalletmanager (26.04.3 -> 26.08.0) kwayland-integration6 (6.7.3 -> 6.7.4) kwayland6 (6.7.3 -> 6.7.4) kwin6 (6.7.3 -> 6.7.4) layer-shell-qt6 (6.7.3 -> 6.7.4) leancrypto libalternatives (1.2+31.da24cd4 -> 2.0+0.4f22c01) libapparmor libdvdread (7.0.1 -> 7.1.1) libebml (1.4.5 -> 1.4.7) libevdev (1.13.6 -> 1.13.7) libjpeg-turbo libkdcraw (26.04.3 -> 26.08.0) libkexiv2-qt6 (26.04.3 -> 26.08.0) libkgapi6 (26.04.3 -> 26.08.0) libkscreen6 (6.7.3 -> 6.7.4) libksysguard6 (6.7.3 -> 6.7.4) libmatroska (1.7.1 -> 1.7.2) libopenmpt (0.8.7 -> 0.8.9) libostree (2026.2 -> 2026.4) libplasma6 (6.7.3 -> 6.7.4) libpsl (0.23.1 -> 0.23.3) librist librsvg libseccomp libselinux libselinux-bindings libsoup libssh libupnp (22.0.4 -> 22.0.6) liburing (2.14 -> 2.15) libva (2.24.0 -> 2.24.1) libwacom (2.19.0 -> 2.19.1) libxmlb live555 (2026.06.01 -> 2026.08.14) llvm22 microos-tools (4.0+git28 -> 4.0+git29) milou6 (6.7.3 -> 6.7.4) mozilla-nss (3.125 -> 3.126.1) multipath-tools (0.15~1+230+suse.d36a6a70 -> 0.15.1+227+suse.6644513) ncurses (6.6.20260613 -> 6.6.20260815) nghttp3 ngtcp2 openexr (3.4.13 -> 3.4.14) openssh (10.4p1 -> 10.5p1) openvpn (2.6.14 -> 2.7.5) orc (0.4.42 -> 0.4.43) pango (1.58.0 -> 1.58.2) partitionmanager (26.04.3 -> 26.08.0) patterns-base patterns-kde patterns-microos permissions (1699_20260728 -> 1699_20260806) pipewire plasma-branding-Kalpa (20260612 -> 20260819) plasma5support6 (6.7.3 -> 6.7.4) plasma6-activities (6.7.3 -> 6.7.4) plasma6-activities-stats (6.7.3 -> 6.7.4) plasma6-browser-integration (6.7.3 -> 6.7.4) plasma6-desktop (6.7.3 -> 6.7.4) plasma6-integration (6.7.3 -> 6.7.4) plasma6-nm (6.7.3 -> 6.7.4) plasma6-openSUSE plasma6-pa (6.7.3 -> 6.7.4) plasma6-print-manager (6.7.3 -> 6.7.4) plasma6-systemmonitor (6.7.3 -> 6.7.4) plasma6-workspace (6.7.3 -> 6.7.4) polkit-default-privs (1550+20260803.90784eb -> 1550+20260825.76d85e6) polkit-kde-agent-6 (6.7.3 -> 6.7.4) powerdevil6 (6.7.3 -> 6.7.4) procps (4.0.6 -> 4.0.7) python-Mako (1.3.12 -> 1.4.1) python-gpg python-greenlet (3.5.3 -> 3.5.5) python-pycairo (1.29.0 -> 1.29.1) python-pyzmq (27.1.0 -> 27.2.0) python-tornado6 (6.5.7 -> 6.5.8) python-typing_extensions (4.15.0 -> 4.16.0) python313 python313-core qalculate (5.11.0 -> 5.12.0) qpdf (12.3.2 -> 12.4.1) qqc2-breeze-style6 (6.7.3 -> 6.7.4) qrca (26.04.3 -> 26.08.0) qt6-base (6.11.1 -> 6.11.2) qt6-declarative (6.11.1 -> 6.11.2) qt6-imageformats (6.11.1 -> 6.11.2) qt6-location (6.11.1 -> 6.11.2) qt6-multimedia (6.11.1 -> 6.11.2) qt6-positioning (6.11.1 -> 6.11.2) qt6-qt5compat (6.11.1 -> 6.11.2) qt6-quick3d (6.11.1 -> 6.11.2) qt6-quicktimeline (6.11.1 -> 6.11.2) qt6-shadertools (6.11.1 -> 6.11.2) qt6-speech (6.11.1 -> 6.11.2) qt6-svg (6.11.1 -> 6.11.2) qt6-tools (6.11.1 -> 6.11.2) qt6-virtualkeyboard (6.11.1 -> 6.11.2) qt6-webchannel (6.11.1 -> 6.11.2) qt6-webengine (6.11.1 -> 6.11.2) qt6-webview (6.11.1 -> 6.11.2) rootlesskit (3.0.2 -> 3.1.0) run0-wrappers (0.5.0+git20260717.efd7268 -> 0.5.0+git20260822.4d653d8) sdbootutil (1+git20260714.d9bb736 -> 1+git20260825.c7a5a97) sddm-kcm6 (6.7.3 -> 6.7.4) sddm-qt6 (0.21.0 -> 0.21.0+git57) selinux-policy (20260804 -> 20260826) serd (0.32.8 -> 0.32.10) setools (4.7.0 -> 4.7.1) shadow (4.20.0 -> 4.20.2) signon-kwallet-extension (26.04.3 -> 26.08.0) skopeo (1.23.0 -> 1.24.0) sndiff (0.2.2~2 -> v0.3~0) spectacle (6.7.3 -> 6.7.4) srt (1.5.6 -> 1.5.7) sysextmgr (1.0.0+git20260429.bf44eec -> 1.3.0+git20260820.0628c3a) systemsettings6 (6.7.3 -> 6.7.4) thin-provisioning-tools timezone u-boot-rpiarm64 udisks2 (2.11.1 -> 2.11.2) util-linux util-linux-systemd vim (9.2.0780 -> 9.2.0901) wget wpa_supplicant (2.11 -> 2.12) xdg-dbus-proxy (0.1.7 -> 0.1.8) xdg-desktop-portal-kde6 (6.7.3 -> 6.7.4) zstd === Details === ==== Imath ==== Version update (3.2.2 -> 3.2.3) - version update to 3.2.3 * Vec integer method resolution improved — Replaced  =delete with SFINAE ("Substitution Failure Is Not An Error"), via a new `is_float_like` trait, for `length()`, `normalize()`, `normalizedExc()`, etc on integer-typed Vec2/3/4. This gives clearer compiler diagnostics and allows custom numeric types (with an `is_float_like` specialization) to opt into these methods. `half` is explicitly supported. (#[575](https://github.com/AcademySoftwareFoundation/Imath/pull/575)) * Fixed duplicate installation of `ImathConfig.h` (#[591](https://github.com/AcademySoftwareFoundation/Imath/pull/591)) * Fixed shared library installation path (#[556](https://github.com/AcademySoftwareFoundation/Imath/pull/556)) * Fixed Python module install directory, now derived correctly from `Python3_SITEARCH` instead of a hardcoded/absolute path (#[528](https://github.com/AcademySoftwareFoundation/Imath/pull/528)) * Suppressed a C++23 deprecation warning for `std::float_denorm_style/denorm_present` usage in `numeric_limits` (#[546](https://github.com/AcademySoftwareFoundation/Imath/pull/546)) only) * Simplified CMake minimum-version policy handling by removing explicit CMP0074/CMP0077 settings now implied by the 3.14 minimum (#[526](https://github.com/AcademySoftwareFoundation/Imath/pull/526)) * Documentation fixes: corrected install instructions in README.md, fixed broken links, minor spelling corrections ==== Mesa ==== Version update (26.1.6 -> 26.2.1) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.2.1 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.1 - Enable virtio vulkan driver - Apparently %patch -P 18 -p1 is ignored when the patch does not exist on TW. But seems to fail on older distributions. Remove the line for the dropped patch. - Update to 26.2.0 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.0 - drop patches u_PR-40161.patch - refresh patches n_drirc-disable-rgb10-for-chromium-on-amd.patch ==== Mesa-drivers ==== Version update (26.1.6 -> 26.2.1) Subpackages: Mesa-dri Mesa-vulkan-device-select libvulkan_lvp - Update to 26.2.1 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.1 - Enable virtio vulkan driver - Apparently %patch -P 18 -p1 is ignored when the patch does not exist on TW. But seems to fail on older distributions. Remove the line for the dropped patch. - Update to 26.2.0 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.0 - drop patches u_PR-40161.patch - refresh patches n_drirc-disable-rgb10-for-chromium-on-amd.patch ==== MicroOS-release ==== Version update (20260806 -> 20260830) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== PackageKit ==== Subpackages: PackageKit-backend-dnf5 libpackagekit-glib2-18 typelib-1_0-PackageKitGlib-1_0 - Only make DNF backend available in openSUSE Leap 16+. Add 0%{?is_opensuse} check to make sure it's only available in Leap. ==== adwaita-fonts ==== Version update (50.0 -> 51.0) - Update to version 51.0: + mono: Update ==== apparmor ==== - add changes-since-5.0.2.diff - several profile updates - fix compability with Swig 4.5 (boo#1275508) - drop upstreamed nslookup.diff - refresh kerberosclient-usrmerge.diff - add dovecot.diff with several dovecot profile updates (boo#1265453) ==== at-spi2-core ==== Version update (2.60.5 -> 2.60.6) Subpackages: libatk-1_0-0 libatk-bridge-2_0-0 libatspi0 typelib-1_0-Atk-1_0 typelib-1_0-Atspi-2_0 - Update to version 2.60.6: + atk-bridge: Attempt to fix a crash in get_registered_event_listeners + AtspiDevice: Avoid assigning 0 as a grab id + Remove G_GNUC_CONST from *_get_type_declarations ==== aurorae6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * v2: Visualize checked state * Update version for new release 6.7.4 ==== baloo-widgets ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Revert "filemetadatawidget: remove TextInteractionFlag" * tagsfileitemaction: fix crash on empty selection (kde#521325) * Remove FileMetaDataConfigWidget, deprecated since 23.08 * Use default DEFAULT_SEVERITY for logging * Remove pointless path check for indexed files * autotests: Fix leak of test widget * filemetadatawidget: remove TextInteractionFlag (kde#515867) ==== bluedevil6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== bolt ==== - Add bolt-tests subpackage with installed tests for gnome-desktop-testing-runner ==== breeze6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: breeze6-cursors breeze6-decoration breeze6-style breeze6-style-qt5 breeze6-wallpapers - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== breeze6-gtk ==== Version update (6.7.3 -> 6.7.4) Subpackages: gtk3-metatheme-breeze6 metatheme-breeze6-common - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== busybox ==== - Fix stack exhaustion in the ash applet caused by unbounded shell function recursion (CVE-2026-38755, bsc#1271548) * ash-fix-evalfun.patch - Fix out-of-bounds read in ifsbreakup() (CVE-2026-38754, bsc#1271547) * 0001-ash-fix-out-of-bounds-read-in-ifsbreakup.patch - Fix use-after-free in the awk applet regexp processing code when text replacement operations are used (CVE-2026-38753, bsc#1271545) * awk-fix-use-after-free-sub.patch - Fix stack exhaustion in the awk applet caused by unbounded function call recursion (CVE-2026-38752, bsc#1271544) * awk-fix-recursion.patch - Fix heap buffer overflow in the awk applet when a regexp ends with a backslash (CVE-2023-42366, bsc#1217586) * 0001-awk.c-fix-CVE-2023-42366-bug-15874.patch ==== bzip2 ==== - Fix CVE-2026-42250, off‑by‑one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786) * CVE-2026-42250.patch ==== c-ares ==== Version update (1.34.6 -> 1.34.8) - c-ares 1.36.8: * CVE-2026-33630: Fixes use-after-free/double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP (bsc#1270416) * CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290) * CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291) - README.md: Add readme with build status For details, see https://c-ares.org/changelog.html ==== chrony ==== Version update (4.8 -> 4.9) Subpackages: chrony-pool-openSUSE - Add chrony-test-tolerance.patch: relax the clock-accuracy bounds of the offline holdover phase in the 129-reload simulation test. Its jitter is generated by clknetsim via glibc log(), which is not correctly-rounded and differs in the last ULP between architectures (armv7l and ppc64le vs x86_64 and aarch64). Without a server to correct it, that tiny difference grows past the default limit, making the test fail there although chronyd behaves correctly. - Update to 4.9: * New minstratum and maxstratum directives to bound which source strata are acceptable * New maxntsretry option on server/pool to cap the NTS-KE retry interval * New maxtxbuffers directive enabling hardware and kernel TX timestamps on non-Ethernet devices and tunnels * NTP-over-PTP updated to the final specification (RFC 10030) * seccomp filter updated -- we build with --enable-scfilter, so this is on the default path * Better local clock precision measurement, and client logging no longer costs server performance * Fixed ratelimit directives rejecting burst values over 32 * Fixed handling of hardware RX timestamps with a zero interface index * Further refclock, chronyc and OpenBSD changes: see upstream's NEWS for the full list - Drop chrony-libnettle4.patch: merged upstream, 4.9 carries the same NETTLE_VERSION_MAJOR guards verbatim - Bump the bundled clknetsim simulator 6ee99f50 -> 56b60ef2, now taken from the chrony project's own GitLab as 4.9's test/simulation/README directs. 4.9's simulation tests need clknetsim's new raw-socket support; against the old pin all 69 of them fail. ==== cloud-init ==== - Add cloud-init-tsync.patch (bsc#1274554) ==== cockpit ==== Version update (364 -> 365) Subpackages: cockpit-bridge cockpit-networkmanager cockpit-packagekit cockpit-system cockpit-ws cockpit-ws-selinux - Update to 365 * Translations and dependency updates * Fix btrfs subvolume mount option parsing (rhbz#2483145) ==== cockpit-podman ==== Version update (128 -> 129) - Update to 129 * Bugfixes * Translations and dependency updates ==== colord ==== - Build the ICC print profiles with GLIBC_TUNABLES=glibc.cpu.hwcaps=-FMA,-FMA4 so that they no longer depend on the build host CPU (boo#1217747) ==== cpio ==== - Fix CVE-2026-66484: path traversal allows creating hard links outside intended directory via malicious tar archives (bsc#1274856) * CVE-2026-66484.patch - Fix CVE-2026-66485: denial of service via uncontrolled memory allocation from crafted archives (bsc#1274857) * CVE-2026-66485.patch - Fix CVE-2026-66486: terminal control sequence injection via crafted archive member names (bsc#1274858) * CVE-2026-66486.patch - Refresh patches to apply with -p1: * cpio-close_files_after_copy.patch * cpio-default_tape_dev.patch * cpio-dev_number.patch * cpio-eof_tape_handling.patch * cpio-open_nonblock.patch * cpio-use_new_ascii_format.patch * cpio-use_sbin_rmt.patch - Reorder patches, apply with %autosetup -p1 - Add makeinfo build requirement ==== ddcutil ==== Version update (2.2.5 -> 2.2.7) - Update to 2.2.7: * New: - Extensive diagnostics are written to the system log if opening a /dev/i2c device fails with errno EACCES. - Implemented a basic segfault handler. - Option max-eacces-retry-ms. (See above.) * Changes: - Re-enable reporting of laptop display connection/disconnection. Do not check DDC operation for the laptop /dev/i2c bus or for any bus unresponsive on slave address x37. - When watching for display connection/disconnection using watch-mode UDEV: * watch for UDEV notifications for subsystem i2c-dev as well as drm. * write udev event detail to the system log - dw_hotplug_change_handler(): write additonal messages to the system log when a /dev/i2c device unexpectedly no longer exists - Option --skip-ddc-checks: valid only for command line ddcutil, not shared library libddcutil. If specified in config file ddcutilrc, it must now be in the [ddcutil] section, not the [global] section. - The installed udev rules file, 60-ddcutil-i2c.rules now sets group i2c and mode 0660 as well as using token uaccess to assign /dev/i2c permissions. Users encountering the transient EACCES errors may need to use the old group permissions method. * Fixes: - ddca_redetect_displays(): Recover from an unexpected system state that previously triggered assert() failures. (gh#rockowitz/ddcutil#595), (kde#517571) - dw_create_display_status_event(), test for event type DDCA_EVENT_DDC_DISABLED incorrectly used flag DDCA_DISPLAY_EVENT_DDC_WORKING. - man page ddcutil: Replace "getvcp supported" by "getvcp all". Group "supported" was replaced long ago by "all". (gh#rockowitz/ddcutil#579). - segfault in diagnose_open_failure_to_syslog(). (gh#rockowitz/ddcutil#596) - Error parsing option --maxtries. - run command line programs lsof, getfacl caused a segfault when those programs are not found on the user's system. (gh#rockowitz/ddcutil#590) - In syslog, reported thread id might be the process id. - Change the sample rules file 60-ddcutil-i2c.rules, to conform to /usr/lib/udev/rules.d/60-ddcutil-i2c.rules. Loosens the display adapter test (gh#rockowitz/ddcutil#597) - Fix ioctl call in hiddev_get_report(), for monitors using USB rather that I2C - reading the EDID bytewise use get_edid_bytes_directly_using_fileio(), only every other byte was saved. - Incorrect call to i2c-dev set address ioctl. - General source cleanup using Claude Code - Update Doxygen documentaion. - Consistenly make #include "config.h" the first include. - Consistenly set AM_CFLAGS = $(AM_CLAGS_STD) in the Makefile.am - Avoid a possible buffer overflow when printing an EDID field such as serial number that contains invalid ASCII characters - Write error message during getvcp --brief* to stderr, not stdout. (gh#rockowitz/ddcutil#598) - More consistent formatting of syslog output. - Use atomic variables to fix time of use to time of check (TOCTOU) race conditions identified by Claude Code. * Drop 0001-fix-freezes-on-laptops.patch ==== discover6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: discover6-backend-flatpak discover6-backend-fwupd discover6-notifier - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 * Submit usefulness for the right review regardless of how the list is sorted * ui: Only keep a state saver around when we are visible * UpdateModel: Do not pass a lambda to a unique connect * UpdatesModel: Remove destroyed resources (kde#522255) * ApplicationDelegate: relocate "non-default backend" badge with size * ApplicationDelegate: align icons when delegate is showing size * Update version for new release 6.7.4 ==== dolphin ==== Version update (26.04.3 -> 26.08.0) Subpackages: dolphin-part libdolphinvcs6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * selectionmode: Show Delete action in trash (kde#523348) * dolphinview,dolphinviewactionhandler: split create folder into two actions * dolphinmainwindow: use base url fallback on slotSelectionChanged * tests: build dolphinquerytest only when HAVE_BALOO - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Make inline-rename re-triggering robust and add a regression test (kde#514401) - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * kitemviews: Draw icon overlays at a fixed size instead of baking them into the thumbnail (kde#498211) * Allow grouping by a separate criterion (kde#416134) * DolphinNavigatorsWidgetAction: Let non-Breeze QStyles style the non-toolbar navbar how they want (kde#518285) * KItemListWidget: Add pressedChanged (kde#508329) * viewproperties: respect saved properties for special folders with global view props enabled (kde#520089) * kfileitemmodelrolesupdater: fix directory item count for large folders (kde#509150) * dolphintabpage: drop swapActiveView in RightView close path (kde#520002) * userfeedback: prevent dangling pointer access in SettingsDataSource (kde#519876) * Restore session if this is the first instance (kde#464693) * Fix occasional UAF crashes in KConfig::sync() during exit * terminalpanel: allow refreshing the terminal location (kde#510557) * dolphincontextmenu: move "Empty Trash" to where you expect destructive actions to be (kde#518713) * dolphinmainwindow: use directly ShowMenubar action to change menuBar visibility (kde#492298) * kfileitemmodel: sort dotted numeric names naturally (kde#411707) * Refresh shortcut: Ignore repeat events (kde#514209) * KItemListWidget: Use primitives instead of custom painting (kde#508294) * kitemviews: Preserve inline rename when item scrolls out of view (kde#506884) * DolphinTabPage: Prevent re-entrant signal activation for slotViewActivated (kde#508554, kde#512011, kde#508405, kde#511076, kde#503576) * dolphinviewcontainer: Avoid adding an extra history entry when leaving search results (kde#515236) * animatedheightwidget: prevent viewport scrolling (kde#510469) * informationpanel: ignore gestures on media slider (kde#431307) * Fix incorrect app id for Kfind (kde#510370) * information/pixmapviewer: handle hdipi for animated images (kde#510829) * kitemviews: add "Folder Name" column to details view (kde#433937) * kitemlistview: when editing file name set anchored selection (kde#453262) ==== dracut ==== Version update (110+suse.45.geaec47e4 -> 112+suse.34.g35e16b7) Subpackages: dracut-ima - Update to version 112+suse.34.g35e16b7: * fix(devicetree-firmware): include Qualcomm X2 laptop model specific firmwares * fix(devicetree-firmware): include soc specific firmwares in install_generic() (bsc#1267865) * refactor(devicetree-firmware): make looping over fw_dir top-level loop * fix(resume): handle noresume kernel command line option (bsc#1274588) * fix(resume): actually get value from resume= kernel command line option - Update to version 112+suse.29.gc0c5e1d * fix(base): sanitize message written by die() to the emergency hook - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency hook script in die() (bsc#1274432) - Update to version 112+suse.28.g84b3ea7: Full list of changes: * https://github.com/dracut-ng/dracut-ng/releases/tag/112 * https://github.com/dracut-ng/dracut-ng/releases/tag/111 Additional openSUSE-specific changes and post-release fixes: * fix(net-lib): validate iSCSI port parameters * refactor(net-lib): use strip_non_digits() to validate iSCSI LUN parameters * fix(net-lib): source dracut-lib.sh in net-lib.sh * fix(hwdb): always install this module, except in strict hostonly mode * fix(dracut): --remove allows to remove files from the host filesystem * fix(dracut): --remove globbing does not work * fix(shell-completion): add missing --remove option * style(dracut): correct indentation in help text * fix(dracut-functions): typo in log function * fix(iscsi): normalize the target name in the generated netroot= * fix(iscsi): do not source the boot-time net-lib.sh into module-setup.sh * fix(net-lib): normalize iSCSI target names on the iqn./eui./naa. path * fix(systemd-sysusers): do not run systemd-sysusers as part of the build process * feat(systemd-coredump): save coredumps to journal * fix(dracut): remove wrong auto-detection logic for output file * feat(dracut-install): do not return non-zero if a dependency cannot be resolved * feat(dracut-systemd): add back and fix printing fs help in the emergency shell * feat(resume): add openSUSE-specific sanity check * fix(rngd): revert changes that removed the custom systemd service * fix(systemd-pcrextend): revert changes related to inclusion and dependencies * fix(lsinitrd, dracut-initramfs-restore): detect initrd for BLS Type #1 entries * fix(dracut.sh): improve detection of installed kernel versions * feat: add openSUSE-specific code related to networking * feat(convertfs): add openSUSE-specific code * fix(fips): handle zipl * feat(fips): add openSUSE-specific code * chore(suse): add openSUSE-specific modules * ci: change openSUSE code owners ==== dracut-pcr-signature ==== Version update (0.7+0 -> 0.8+0) - Update to version 0.8+0: * Install the module iff systemd-boot or grub2-bls * Make sure that our sysefi.mount takes precedence * Do not copy old tpm2-pcr-signature files ==== exfatprogs ==== Version update (1.4.2 -> 1.4.3) - Update to 1.4.3: Changes: * exfatprogs: honor the user's full locale for diagnostic messages and date formatting. * mkfs.exfat: report final fsync errors and suppress completion messages with "-q". * fsck.exfat: increase scan speed when scanning large unused directory tails. Bug fixes: * exfatprogs: fix building DOS attribute utilities with non-Bash shells. * dump.exfat and fsck.exfat: ignore reserved allocation-bitmap bits when counting clusters. * fsck.exfat: reject invalid sector sizes without crashing. * mkfs.exfat: notify the kernel after creating partition tables. * mkfs.exfat: generate GUIDs with correct version and variant fields. * mkfs.exfat and tune.exfat: use standard GUID byte order for GUID input and output. * libexfat: fix directory iterator alignment for large offsets. * exfatprogs: prevent allocation bitmap size overflow near the maximum cluster count. ==== expat ==== Version update (2.8.1 -> 2.8.2) - update to 2.8.2 ( bsc#1267631, CVE-2026-50219, bsc#1268572, CVE-2026-56131, bsc#1268573, CVE-2026-56132, bsc#1275096, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407, CVE-2026-56408, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, CVE-2026-56412): * #1246 CVE-2026-50219 -- Disallow calls to functions * `XML_GetBuffer`, `XML_Parse`, `XML_ParseBuffer`, * `XML_ParserFree`, `XML_ParserReset` to guard e.g. * Expat bindings from memory corruption; * #1267 CVE-2026-56131 -- Protect XML_ResumeParser from being called from a handler, plugging a hole in the fix to CVE-2026-50219 * #1272 CVE-2026-56132 -- Fix out-of-bound scaffolding index store in `doProlog` * #1229 #1232 CVE-2026-56403 -- Integer overflow in `storeAtts` * #1249 CVE-2026-56404 -- Integer overflow in `addBinding` * #1251 CVE-2026-56405 -- Integer overflow in `getAttributeId` * #1255 CVE-2026-56406 -- Integer overflow in `XML_ParseBuffer` * #1262 CVE-2026-56407 -- Integer overflow in `textLen` handling * #565 CVE-2026-56408 -- Integer overflow in `copyString` * #1259 CVE-2026-56409 -- xmlwf: Integer overflow in output path join * #1252 CVE-2026-56410 -- xmlwf: Integer overflow in `resolveSystemId` * #1263 CVE-2026-56411 -- xmlwf: Integer overflow in notation list allocation * #1278 CVE-2026-56412 -- Guard XML_TOK_DATA_CHARS handler calls in `doCdataSection`, plugging a hole in the fix to CVE-2026-50219 ==== faad2 ==== Version update (2.11.2.git18 -> 2.11.3) - Update to version 2.11.3: * Fix ISO C warning in libfaad/fixed.h * Check for mp4config.frame.nsclices == 0 in frontend/mp4read.c to fix Heap Buffer Overflow * SBR: prevent heap overflow in channel-pair reconstruction * Fix off-by-one frame index check in mp4read_seek * Fix integer overflow in stszin/stscin allocation size checks * Bound sscanf field width in option parsing * Fix out-of-bounds iq_table read in iquant for -32768 * Prevent length_of_rvlc_sf underflow in rvlc_scale_factor_data * Fix out-of-bounds Xsbr write in hf_assembly sinusoid addition * Fix out-of-bounds X underflow in SBR low-power QMF assembly * Fix ssr_gc_function signature mismatch in ssr_gain_control * Fix signed overflow in estimate_current_envelope energy sum * Cap escape length in huffman_spectral_data_2 * Prevent num_bits_left underflow in ps_data extension parsing * Fix signed overflow in fixed-point sample rounding before saturation * Add sanity checks on the width in libfaad/specrec.c * Check the last swb_offset value is valid in libfaad/specrec.c * Return early from NeAACDecInit when the object type can't be supported * Fix null pointer dereferences in intra channel and long term prediction * Increase the ASC buffer from 10 to 64 bytes in frontend/mp4read.h ==== falkon ==== Version update (26.04.3 -> 26.08.0) Subpackages: falkon-kde - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add '[]' suffix to current instance window title * AdBlock: Use struct for AdBlockedRequest * Adblock: Specify resource type as MainFrame for popups * Adblock: Specify RequestType enum as a class * Add first-party url and increase adblock counter * Fix include order * Try to redo it with a bridge class * AdBlock: Add support for popup blocking * SuperMenu: Add SavePageAs action * Drop QTEST_DISABLE_KEYPAD_NAVIGATION from tests * TabManager: Remove handling of "State_Editing" * LocationCompleter: Allow numpad UP and DOWN arrows (kde#515403) * Always check return value when opening files * Check result of malloc * Do not allow contextless connects * Add missing context to the connects * Fix logic in createMenuAction to handle null QmlEngine case * Spell check prefs UI: expand list of languages instead of empty spacer * Remove duplicate call to qputenv() * adressProgressSettings -> addressProgressSettings * Correct spelling for "request" ==== ffmpegthumbs ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix OSS-Fuzz build ==== flatpak ==== Version update (1.18.0 -> 1.18.2) Subpackages: flatpak-selinux libflatpak0 system-user-flatpak - Update to version 1.18.2: + Bug fixes: - Validate GVariant structure of summaries before using generated variant readers - Fix crash in system helper when iterating cache directories - Avoid corrupted output from non-UTF-8 characters in error messages - Fix portal passing wrong file descriptor when sandbox-expose-fd-ro triggers fd remapping collision - Fix system helper tracking wrong D-Bus sender for pulls - Fix extensions not being populated in the sandbox due to unhandled EAGAIN from openat2 - Fix build failure with GLib versions older than 2.72 - Test infrastructure improvements - Update to version 1.18.1: + Security fixes: - Fix sandbox escape with full host filesystem read/write access via symlink attack on app data directories (GHSA-8688-9x26-hhxj) - Fix local root privilege escalation via revokefs symlink path traversal and commit tampering (GHSA-qrwq-7qwx-q9rp) - Fix arbitrary root write via symlink and path traversal in extra-data extraction (GHSA-fqx6-vh4p-42cg) - Fix arbitrary root write via path traversal in `flatpak build-init` (GHSA-8qxj-x646-phcm) - Fix arbitrary host file read via hardlink path traversal in OCI archive extraction (GHSA-9rww-v4mm-x4jg) - Fix path traversal via unvalidated architecture parameter in DeployAppstream (GHSA-v2gw-v9h5-9q4x) - Fix buffer overflow in OCI delta stream path names on 32-bit systems (GHSA-jr92-2v97-wgvc) - Fix fixed-filename writes to arbitrary locations via symlink attack on .ld.so (GHSA-99wv-m8rp-g58x) - Fix extension metadata path traversal allowing host filesystem probing and unintended mount locations (GHSA-w69g-9x8j-7p8f) - Fix anti-downgrade bypass allowing unprivileged users to downgrade system apps (GHSA-q4gr-vc25-57m5) + Bug fixes: - Fix portal flatpak-spawn environment handling regression - Fix negated permission strings for allow and share run options - Fix build failure when exporting metainfo releases.xml files - Fix crashes in the portal update monitor and OCI JSON handling - Error out if file forwarding of empty paths is attempted - Check OCI signatures from the mirrored repo in the system helper instead of fetching from the lookaside server - Apply TLS certs to OCI registry requests and propagate stream write failures to curl - Fix GI annotation for flatpak_instance_get_all - Cleanup of Bash completion - Numerous internal fixes for crashes, error handling, and hardening ==== flatpak-kcm6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - No code changes since 6.7.3 ==== fwupd ==== Subpackages: libfwupd3 typelib-1_0-Fwupd-2_0 - Add Requires: gnome-desktop-testing to fwupd-tests subpackage - Add fwupd-tests subpackage with installed tests for gnome-desktop-testing-runner. ==== gcab ==== Subpackages: libgcab-1_0-0 - Enable meson installed tests (-D tests=true) and add %check section ==== gcc16 ==== Version update (16.1.1+git9481 -> 16.2.0+git9497) Subpackages: cpp16 libgcc_s1 libgomp1 libstdc++6 - Disable cross-x86_64-gcc build for SLFO - Update to GCC 16.2 release (gcc-16.2.0+git9497) * accumulated bugfixes from the gcc-16 release branch - Disable multilibs for cross-x86_64-gcc ==== glib-networking ==== - Add glib-networking-tests subpackage with installed tests for gnome-desktop-testing-runner ==== glibmm2_4 ==== Version update (2.66.9 -> 2.66.10) - Update to version 2.66.10: + Drop G_GNUC_CONST as in GLib. + Gio: Emblem and DBus::ActionGroup: Don't derive gtkmm__Gxxx types. The underlying C classes are final types since GLib 2.89.2. + Meson build: Use Meson's pkgconfig module instead of using the * .pc.in templates. - Update to version 2.66.9+3: + Gio::DBus::ActionGroup: Improve the test whether GDBusActionGroup is final + Drop G_GNUC_CONST as in glib + Gio: Emblem and DBus::ActionGroup: Don't derive gtkmm__Gxxx types - Use source service to generate tarball. - Add mm-common and perl-XML-Parser BuildRequries: Needed now that we are using a git checkout. - Pass maintainer-mode=true to meson setup, needed since we are using a git checkout. ==== glslang ==== Version update (16.4.0 -> 16.5.0) - Update to release 16.5.0 * Implement `GLSL_EXT_split_barrier`/`SPV_EXT_split_barrier`, `GLSL_QCOM_multiple_wait_queues`, `GLSL_QCOM_image_processing3`, `GL_EXT_function_control_attributes`. ==== gnutls ==== - FIPS: Deprecate ECDSA siggen with less than 128-bit (bsc#1265613) * NIST SP 800-131Arev3 marked ECDSA siggen < 128-bit of security strength as deprecated after the deadline of 31 dic 2030. * Add gnutls-FIPS-Deprecate-ECDSA-with-less-that-128-bit.patch - FIPS: Mark SHA-224 and SHA3-224 as legacy (bsc#1265609, bsc#1265611) * NIST SP 800-131Arev3 has marked SHA-224 and SHA3-224 as legacy after the deadline of 31 dic 2030. * Add gnutls-FIPS-SHA224-SHA3224-Legacy-Status.patch - FIPS: Deprecate HMAC with keys less than 128-bit (bsc#1265610) * NIST SP 800-131Arev3 marked HMAC with keys less than 128-bits as disallowed after the deadline of 31 dic 2030. * Add gnutls-FIPS-Deprecate-HMAC-with-less-that-128-bit-keys.patch - FIPS: Deprecate RSA Signatures with less than 128-bit (bsc#1265612) * NIST SP 800-131Arev3 has marked RSA Signatures with less than 128-bit as deprecated after the deadline of 31 dic 2030. * Add gnutls-FIPS-Deprecate-RSAsig-with-less-that-128-bit.patch ==== graphene ==== - Add graphene-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gvfs ==== Version update (1.60.1 -> 1.60.2) Subpackages: gvfs-backends - Update to version 1.60.2: + build: Drop G_GNUC_PURE from *_get_type() functions + afp/dav/ftp/mtp/sftp: Harden input validation + common: Clear password strings from memory before freeing + mtp/onedrive/smb: Fix crashes in onedrive, mtp, and smb backends + Some other fixes + Updated translations. ==== gzip ==== - Fix CVE-2026-41992, global buffer overflow in the LZH decompression logic (CVE-2026-41992, bsc#1269623, bsc#1272554) * CVE-2026-41992.patch - Refresh patches to apply with -p1: * non-exec-stack.diff * zdiff.diff * zgrep.diff - Use %autosetup to apply patches ==== harfbuzz ==== Version update (14.2.1 -> 14.3.1) Subpackages: libharfbuzz-gobject0 libharfbuzz-subset0 libharfbuzz0 typelib-1_0-HarfBuzz-0_0 - Update to version 14.3.1: + Various fuzzing and build fixes. + Various subsetting fixes. + Fix AAT insertion at the end of the text. + Fix various rendering bugs in the experimental GPU library. + WASM shaper code can now read the user features. - Update to version 14.3.0: + Changes affecting shaping output: - Lookup order is now respected for mark positioning in the cross-direction (y in horizontal text, x in vertical text): marks no longer follow a cross-direction shift that a later lookup applies to the base. This improves compatibility with DirectWrite and Core Text. - Fix mark attachment to ligatures formed from decomposed glyphs. - The `calt` feature in Hangul text is now disabled only for the Jamos, not the whole buffer. + Support for partially instancing version of `avar` table, as well as `CFF2` table. + New fill-glyph paint operation and APIs for the common case of filling a glyph with a solid color. + New API to fetch assorted raw values from the `OS/2`, `head`, and `post` tables. + New experimental API to extract a font’s glyph dependency graph, that applications can use to compute glyph closures themselves without running the subsetter. + New subset flag to convert the charset of a subsetted CID-keyed `CFF` fonts into identity charset, and a matching `hb-subset` option. Useful for embedding fonts in PDF. + Command-line utilities now handle non-ASCII arguments correctly on Windows. + Various instancing and subsetting fixes. + Various fixes to the experimental `harfbuzz-vector`, `harfbuzz-raster` and `harfbuzz-gpu` libraries. + Various improvements to the HarfRust integration shaper. + Various build, CI, portability, and fuzzing fixes. + Various new APIs. ==== json-glib ==== - Add json-glib-tests subpackage with installed tests for gnome-desktop-testing-runner ==== kaccounts-integration ==== Version update (26.04.3 -> 26.08.0) Subpackages: libkaccounts6-2 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kaccounts-providers ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kactivitymanagerd6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kate ==== Version update (26.04.3 -> 26.08.0) Subpackages: kate-plugins - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * only add processId if we are not sandboxed (kde#522883) * use Utils::absoluteUrl to have same normalization as via the KateDocManager (kde#519737) * improve handling of view change with search bars & Co. (kde#488164) * ensure we work on a local copy of the session config (kde#520168) * Add missing include (kde#520771) * ensure we hide the buttons in the view space if no tabs & nav bar there (alternative implementation) (kde#515133) * Use proper working directory when invoking git (kde#519685) * Fix middle click on tab doesn't work when close button disabled (kde#519325) * add filename to location copy (kde#519077) * try to add suffix that matches the document mime-type (kde#518537) * Fix possible out of bound read (kde#515975) * Check for index validity (kde#513191) * Fix possible out of bound read (kde#518496) * Remove custom prettier formatter (kde#517926) * add hint that missing char means ignore for spell checking (kde#517428) ==== kde-cli-tools6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kde-gtk-config6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: kde-gtk-config6-gtk3 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kdecoration6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libkdecorations3-6 libkdecorations3private2 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kdegraphics-mobipocket ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * DocumentPrivate::init: return early if dec is not valid * Protect against malformed header size - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Don't check for size of parseEXTH twice * Harden bounds validation in DocumentPrivate::parseEXTH * Prevent integer underflow in DocumentPrivate::parseEXTH * ecm_generate_export_header: fix spurious } to USE_VERSION_HEADER arg ==== kdegraphics-thumbnailers ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix invalid memory access * Fix off by one access * Fix memory leak ==== kdenetwork-filesharing ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * filepropertiesplugin: fix build without systemd * Handle service being an alias ==== kdeplasma6-addons ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * applets/diskquota: Properly set ItemDelegate content (kde#523618) * [Vietnamese Lunar Calendar] Fix month offset after leap month * applets/kickerdash: add BugReportUrl * applets/colorpicker: correct bug report URL (kde#522459) * applets/mediaframe: Fix media not updating when watched file changes on disk (kde#521538) * Update version for new release 6.7.4 ==== kdialog ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kernel-default-base ==== Version update (7.1.6 -> 7.2.2) - Add 8021q (bsc#1274833) ==== kernel-source ==== Version update (7.1.6 -> 7.2.2) Subpackages: kernel-64kb kernel-default - Linux 7.2.2 (bsc#1012628). - inet: frags: strip GSO state from fragments before reassembly (bsc#1012628 CVE-2026-80590). - commit 820247d - Linux 7.2.1 (bsc#1012628). - ptp: vmclock: prevent read-only mappings from becoming writable (bsc#1012628). - futex: Fix might_sleep() warning in futex_pivot_pending() (bsc#1012628). - Bluetooth: hci_aml: validate firmware segment lengths (bsc#1012628). - Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 (bsc#1012628). - Bluetooth: ISO: zero the sockaddr before returning it in getname (bsc#1012628). - Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync (bsc#1012628). - Bluetooth: hci_sync: Fix accept list UAF during suspend (bsc#1012628). - Bluetooth: hci_event: validate LE Set CIG Parameters response (bsc#1012628). - Bluetooth: hci_event: fix LE list UAF on reset (bsc#1012628). - HID: input: read battery capacity from its actual report offset (bsc#1012628). - HID: hyperv: validate initial device info bounds (bsc#1012628). - HID: uclogic: fix use-after-free of inrange_timer on remove (bsc#1012628). - HID: sensor: custom: Fix use-after-free in enable_sensor (bsc#1012628). - HID: ft260: fix stack-use-after-return write in I2C read race (bsc#1012628). - HID: core: fix number/pointer type confusion on long items (bsc#1012628). - HID: rapoo: fix missing hid_is_usb() check (bsc#1012628). - HID: nintendo: stop device IO before hid_hw_stop on probe failure (bsc#1012628). - HID: nintendo: register input device after capabilities are set (bsc#1012628). - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (bsc#1012628). - HID: huawei: fix missing hid_is_usb() check (bsc#1012628). - HID: asus: fix missing hid_is_usb() check (bsc#1012628). - net/ionic: avoid OOB TX partner lookup for hwstamp RXQ (bsc#1012628). - HID: pidff: fix OOB write when hid->inputs is empty (bsc#1012628). - HID: core: fix OOB read of field->usage in hid_set_field() (bsc#1012628). - HID: magicmouse: do not keep a stale msc->input if no input is claimed (bsc#1012628). - HID: magicmouse: re-enable multitouch after reset-resume (bsc#1012628). - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (bsc#1012628). - HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C (bsc#1012628). - nvmet: pci-epf: put CQ ref on create_cq mapping failure (bsc#1012628). - nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() (bsc#1012628). - nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations (bsc#1012628). - nvmet-tcp: bound SGL data length before allocating command buffers (bsc#1012628). - nvmet-fc: fix invalid free in LS IOD error path (bsc#1012628). - nvmet-auth: zero the AUTH_RECEIVE response buffer (bsc#1012628). - dmaengine: fsl-edma: Add error handling for devm_kasprintf (bsc#1012628). - mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() (bsc#1012628). - ipv6: fix use-after-free in ip6_finish_output2() (bsc#1012628). - ipv4: reject undersized MTUs in ip_do_fragment() (bsc#1012628). - nfc: nci: free destination parameters when closing a connection (bsc#1012628). - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (bsc#1012628). - nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (bsc#1012628). - nfc: nci: add data_len bound checks to activation parameter extractors (bsc#1012628). - nfc: st21nfca: validate ATR_REQ length against the received frame (bsc#1012628). - nfc: pn533: purge fragmented skbs during cleanup (bsc#1012628). - nfc: llcp: reject PDUs shorter than the LLCP header (bsc#1012628). - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (bsc#1012628). - nfc: llcp: bound the connect_sn TLV walk to the skb (bsc#1012628). - nfc: microread: validate target discovery payload lengths (bsc#1012628). - nfc: fdp: bound the device-reported read length and fix an skb leak (bsc#1012628). - nfc: digital: clamp SENSF_RES length to the destination buffer (bsc#1012628). - xfs: restore nofs context unconditionally in xfs_trans_roll (bsc#1012628). - xfs: validate attr entry pointer before field access (bsc#1012628). ... changelog too long, skipping 2398 lines ... - commit 585bfaf ==== kf6-attica ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Attica6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-baloo ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-baloo-file kf6-baloo-imports kf6-baloo-kioslaves libKF6Baloo6 libKF6BalooEngine6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Install kcfg file * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-bluez-qt ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-bluez-qt-imports libKF6BluezQt6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove obsolete doxygen file * mediatypes.h services.h types.h: provide version macros to consumers * fix: resolve race condition in Bluetooth object manager initialization. * Update version to 6.29.0 ==== kf6-breeze-icons ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6BreezeIcons6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Add im-matrix icon * Rename icons for typst mimetype * Add tab icons for KWin Options KCM * add Android App Bundle icons * remove inkscape cruft from Android Package Archive icons * Update version to 6.29.0 ==== kf6-frameworkintegration ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-frameworkintegration-plugin libKF6Style6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-karchive ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Archive6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * kzip: write data in chunks * Documentation fixes * kzip: zip64 write support (kde#514117) * kzip: use qToLittleEndian * kzip: change some ints to qint64 to allow writing zip64 archives * kzip: fix opening zip64 archives * Update version to 6.29.0 ==== kf6-kauth ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6AuthCore6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kbookmarks ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Bookmarks6 libKF6BookmarksWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kcmutils ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kcmutils-imports libKF6KCMUtils6 libKF6KCMUtilsCore6 libKF6KCMUtilsQuick6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * kpluginmodel: Only write enabled state when not default * Run clang-format * kcmshell: React to KCModule::representsDefaultsChanged * Update version to 6.29.0 ==== kf6-kcodecs ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Codecs6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * [KEncodingProber] Improve const-correctness * [KEncodingProber] Explicitly initialize some structs * [KEncodingProber] Replace pointer to SMModel with reference * [KEncodingProber] Fix broken UTF16 filtering for MBCS * [KEncodingProber] Fix GB18030 false positive * [KEncodingProber] Extend unit tests, notably for japanese text * [KEncodingProber] Shortcut no longer active group probers * [KEncodingProber] Refactor UnicodeGroupProber * [KEncodingProber] Refactor Unicode/UTF prober * [KEncodingProber] Clean up comments and naming for MB mapping * [KEncodingProber] Make one virtual base method pure virtual * [KEncodingProber] Remove obsolete padding in state tables * [KEncodingProber] Replace debug printf with categorized logging output * [KEncodingProber] Add dedicated logging category * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kcolorscheme ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6ColorScheme6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kcompletion ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Completion6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * KCompletionBase/KCompletionMatches: move Q_DECLARE_PRIVATE to PRIVATE * KCompletionBox::eventFilter: minimize code executed when filter not hit * Update version to 6.29.0 ==== kf6-kconfig ==== Version update (6.28.0 -> 6.29.0) Subpackages: kconf_update6 kf6-kconfig-imports libKF6ConfigCore6 libKF6ConfigGui6 libKF6ConfigQml6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove unused variables in KConfig implementation * Revert "kwindowstatesaverquick: Do not force-show windows" (kde#522205) * Add test for KConfigLoader ctor that takes KConfigGroup * Use Qt for ASCII && alphanumeric detection * Read config files in system locations before user-writable config files * Add tests to document status quo * kreadconfig: Add option to dump default values * kreadconfig: Dump entries sorted by group name/entry key * Don't change immutable non-default entry when setting default entry * Add failing tests demonstrating wrong behavior * Add helper to set/override an environment variable for a test * Remove obsolete doxygen file * Always insert deleted key into internal map (kde#519481) * Ensure that deleted default entries are deleted * Fix generated setters for enum options with UseEnumTypes * Export StandardAction as Q_ENUM_NS * Update version to 6.29.0 ==== kf6-kconfigwidgets ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6ConfigWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * kviewstatemaintainer.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-kcontacts ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Contacts6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove dependency on KCoreAddons * addresseelist.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-kcoreaddons ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kcoreaddons-imports libKF6CoreAddons6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * kdirwatch: use certified KDE if style with {} * KDirWatch: fix/tweak determination of default * KDirWatch: expose additional verbosity as envvar * Don't let fromAppStreamFile() modify the application data * aboutData: Add support for AppStream URLs * Documentation fixes * aboutData: Improve fromAppStreamForApplication() usability * Update version to 6.29.0 ==== kf6-kcrash ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Crash6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * delete the char ptrs properly as arrays * load platform details ahead of time (kde#518503) * Update version to 6.29.0 ==== kf6-kdbusaddons ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kdbusaddons-tools libKF6DBusAddons6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kdeclarative ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kdeclarative-imports libKF6CalendarEvents6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * graphicaleffects: Avoid complicated matrix multiply * graphicaleffects: Make shader uniform "buf" identical * graphicaleffects: Use "coord" input on lanczos.frag shader * graphicaleffects: Fix Lanczos shader path * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kded ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Use correct type for desktop file * Update version to 6.29.0 ==== kf6-kdesu ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Su6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kdnssd ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kdoctools ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6DocTools6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update Turkish entities * Update version to 6.29.0 ==== kf6-kfilemetadata ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6FileMetaData3 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * autotests/ossfuzz: clone libpng from github to fix unreliable sourceforge downloads * Fix overflow in extractAudioProperties * taglib: Protect against UnknownFrame * types.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-kglobalaccel ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6GlobalAccel6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kguiaddons ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kguiaddons-imports libKF6GuiAddons6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Add missing since information * Add KSystemClipboard::ownsClipboard * waylandclipboard: Properly clean up device and manager * kiconutils: Fix overlay emblem size and placement on non-square icons * Update version to 6.29.0 ==== kf6-kholidays ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kholidays-imports libKF6Holidays6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * lunarphase.cpp - use the system timezone rather than utc * Support Hebrew Calendar holidays (kde#383896) * .clang-tidy - update * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-ki18n ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-ki18n-imports libKF6I18n6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kiconthemes ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kiconthemes-imports libKF6IconThemes6 libKF6IconWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Add notes to drop dependency on KWidgetsAddons for KF7 * Update version to 6.29.0 ==== kf6-kidletime ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kidletime-plugins libKF6IdleTime6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kimageformats ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * autotests: add AVIF and JXL with animation * KRA/ORA: merged in a single plugin and added metadata support * Readme: update supported formats * Test Readme: added JPG support * avif: enable decoding of files with invalid EXIF metadata * autotests: allow JPG as test source * QOI: check format only in lowercase * ossfuzz: optimize build, collect all HEIF subformats * fix HEIC writetest * ossfuzz: enable uncompressed codec in libheif * heif: declare read support for HIF * EXIF: add support for Windows Explorer tags * heif: increase Maximum number of child boxes limit * HEIF: keep reader callback table alive (kde#523105) * More HEIF-related tests. * heif: AVCI saving, JPEG in HEIF read support * IFF: support for ZIP compressed RGFX * Update version to 6.29.0 - Drop patch: * 0001-HEIF-keep-reader-callback-table-alive.patch ==== kf6-kio ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6KIO6 - Add upstream fix (kde#524239, boo#1275906) * 0001-kfileitemactions-fix-submenu-lifetime-using-main-men.patch - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Too many changes since 6.28.0, only listing bugfixes: * WidgetsAskUserActionHandler: show the SSL error dialog on the GUI thread (kde#519614) * file: strip local host from file:// URLs before accessing the path (kde#483297) ==== kf6-kirigami ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kirigami-imports libKirigamiPlatform6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Clickable link OverlaySheet QML type (kde#522348) * FormEntry/FormAction (cards): fix items alignments * FormGroup/flat: Consider also invisible items for implicitWidth * Fix tst_menudialog not actually doing anything * Make the GlobalDrawer correctly size to its contents again * Sensible height for license sheet * FormEntry: don't show invalid leading ind trailing icons * FormEntry: fix the subtitle when the contentITem doesn't have an indicator * Default to small size in FormAction * Same default width that kirigami-addons form has * Port AboutItem to the new form layout * FormEntry: items don't fill the width by default * ScrollablePage: Fix enter animation running when changing focus (kde#515811) * Work around missing support for QKeyShortcut in shortcut * Icon: use QUrl::toLocalFile() for file: URL sources * Icon: keep the aspect ratio of portrait images with roundToIconSize * PlatformTheme: Only emit color changes if color actually changes * Icon: snap the aspect-preserving painted size to device pixels * autotests: fix flaky keyboard list navigation test * autotests: fix flaky test_defaultFocusInScrollablePage * NavigationTabBar: add scrolling/shortcuts for tab switching * ToolBarPageHeader: Rephrase page.actions check to make more sense * Make qml generation deterministic by adding explicit dependencies * Port application template away from deprecated ki18n API * controls: Guard against re-setting the global header with the same URL in Page * Update version to 6.29.0 ==== kf6-kitemmodels ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kitemmodels-imports libKF6ItemModels6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kitemviews ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6ItemViews6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kjobwidgets ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6JobWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-knewstuff ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-knewstuff-imports libKF6NewStuffCore6 libKF6NewStuffWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-knotifications ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-knotifications-imports libKF6Notifications6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Fix since version in documentation * Ensure we have notifyrc file for platform notification configuration * Add API for showing the platform's notification configuration * Remove message extraction in KNotifications * Update version to 6.29.0 ==== kf6-knotifyconfig ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6NotifyConfig6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kpackage ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Package6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Remove obsolete doxygen file * Update version to 6.29.0 ==== kf6-kparts ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Parts6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kpty ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Pty6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kquickcharts ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-krunner ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Runner6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kservice ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Service6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Deprecate KSycoca::setupTestMenu * Fix static build by exporting resource targets * Remove LegacyDir from fallback applications.menu * Add fallback applications.menu file * ksycocatype.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-kstatusnotifieritem ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6StatusNotifierItem6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-ksvg ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-ksvg-imports libKF6Svg6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-ktexteditor ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6TextEditor6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * vi-mode: Avoid redundant BLOCK in the status bar * vi-mode: Fix synchronization of the view block selection * vi-mode: Fix block insert with tabs (kde#488801) * Drag pixmap: use devicePixelRatio of highest screen device pixel ratio * Drag pixmap: adapt hotspot to pixmap scaling * vi-mode: Add Ctrl-A command to insert mode * vi-mode: Implement column cursor swap for v-block mode * vi-mode: Update view selection when switching modes * vi-mode: Fix switching to vblock mode from another visual mode * vi-mode: Simplify switching to visual modes * vi-mode: Add the Date command * vi-mode: Fix cursor position after paste in insert mode * vi-mode: Fix cursor position after pasting block * vi-mode: Fix AltGr detection on Windows * renderer: Small refactoring of paintCaret method * renderer: Fix drawing of all the cursor styles * Change icon for search plugin display options * fix animation artifact during animation run * avoid initial draw * cleanup more painting * cleanup render hint setting * ensure we abort completion on config changes (kde#521492) * vi-mode: Fix count-paste of a block * Update version to 6.29.0 ==== kf6-ktextwidgets ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kunitconversion ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6UnitConversion6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kuserfeedback ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kuserfeedback-imports libKF6UserFeedbackCore6 libKF6UserFeedbackWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * CI - Flatpak - Update Runtime to 6.11 * Update version to 6.29.0 ==== kf6-kwallet ==== Version update (6.28.0 -> 6.29.0) Subpackages: kwalletd6 libKF6Wallet6 libKF6WalletBackend6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Drop kwalletmanager launching from kwalletd * Move org.freedesktop.secrets group to KConfigXT * ksecretd: Drop unused functions * ksecretd: Drop registering KWallet interface * Use correct internal function to query local wallet * Port to KConfigXT * Drop code for writing default wallet in kwalletd * Query NetworkWallet and LocalWallet from backend * Fix localWallet with external backend * kwalletd: Remove config fallback for networkWallet() * Actually set ok to true when defaultCollection succeeds * Drop unused internal pamOpen from kwalletd * Drop dead screensaver integration * kwalletd: fix use-after-move in retrieveCollection() returning null on first lookup (kde#522847) * kwallet-query: persist writes to new entries (kde#491898) * Update version to 6.29.0 ==== kf6-kwidgetsaddons ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6WidgetsAddons6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * KColorCombo: support d'n'dropping colors to set the color * KColorButton, KColorCombo: add contextmenu for Copy & Paste of color * KColorCombo: fix missing render update on changing color from code * Split off KColorMimeData copy into separate file, for shared internal usage * KColorButton: mark drag properly as copy-only * KUrlLabel: fix default value of useCursor flag to match docs & used corsor * KAssistantDialog: Merge "next" and "finish" buttons * Allow to test if on last visibile page * KColorButton: use chained constructor calls over duplicating logic * Update version to 6.29.0 ==== kf6-kwindowsystem ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-kwindowsystem-imports libKF6WindowSystem6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-kxmlgui ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6XmlGui6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Avoid duplicate aboutToShow connections on the Settings menu * KEditToolBar: show no-drop cursor with "Available" list for own items * Update version to 6.29.0 ==== kf6-modemmanager-qt ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6ModemManagerQt6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-networkmanager-qt ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-networkmanager-qt-imports libKF6NetworkManagerQt6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-prison ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-prison-imports libKF6Prison6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Include only needed headers instead of QtConcurrent module header * Update version to 6.29.0 ==== kf6-purpose ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-purpose-services libKF6Purpose6 libKF6PurposeWidgets6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * AlternativesView: Added a disabledPlugins property * Update version to 6.29.0 ==== kf6-qqc2-desktop-style ==== Version update (6.28.0 -> 6.29.0) - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * TextArea: Use Wrap instead of WordWrap * Use StyleItem for item view background painting * Allow QPA Platform Themes to avoid KIconEngine * Prevent TextField height changes when switching echo modes * Update version to 6.29.0 ==== kf6-solid ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Solid6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * udisks2: StorageAccess: if '/' is a mountpoint, return that as filePath() * solidnamespace.h: provide version macros to consumers * Update version to 6.29.0 ==== kf6-sonnet ==== Version update (6.28.0 -> 6.29.0) Subpackages: kf6-sonnet-imports libKF6SonnetCore6 libKF6SonnetUi6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-syndication ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6Syndication6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * Update version to 6.29.0 ==== kf6-syntax-highlighting ==== Version update (6.28.0 -> 6.29.0) Subpackages: libKF6SyntaxHighlighting6 - Update to 6.29.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.29.0 - Changes since 6.28.0: * Update dependency version to 6.29.0 * don't do a reload on language change (kde#523233) * Slint: Include upstream changes * RTF: Fix unbounded context stack growth * cmake.xml: update syntax for CMake 4.4 * Fix listening for language changes, just react on the app instance event * Update MIME types for shell scripts * Meson: add meson.options to recognized extensions * m3u: add m3u8 as one possible extension * cpp: Add qmqlintegration macros from Qt 6.5 * Update version to 6.29.0 - Drop patch: * 0001-Fix-listening-for-language-changes-just-react-on-the.patch ==== kgamma6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kglobalacceld6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libKGlobalAccelD6-0 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kinfocenter6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kio-extras ==== Version update (26.04.3 -> 26.08.0) Subpackages: libkioarchive6-6 trash_kcm - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * kcmtrash.cpp: fix trash settings not detecting multiple mounts (kde#469598) - Update to 26.07.90 * New feature release - Changes since 26.07.80: * workers: fill UDSEntry one value type at a time * smb: fix DFS namespace authentication (kde#510902) - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix incorrect display aspect ratio on SVG thumbnails with height > width * kio_thumbnail: poll wasKilled() in the directory thumbnail loops * Poll wasKilled() in worker transfer and listing loops * kio_filenamesearch: Skip content searches in /dev, /proc and /sys * Restore original "None" string in accordance with review comments * Update help tooltip in accordance with review comments * Web Search Keywords: Update tool tips and reduce duplication * Web Search Keywords: Show provider domain as tool tip for name column * Web Search Keywords: Allow the "Preferred" column to be sorted * Web Search Keywords: Add icons to action buttons * man: Accept a case insensitive or fuzzy match for the page name * sftp: avoid copying captured variables to pass to qScopeGuard * sftp: added an autotest suite using a paramiko-based sftp server * sftp: fixes for mime type detection and resuming files * proxykcm: fix auto configuration help button spacing * Use default DEFAULT_SEVERITY for logging * mtp: only handle portable media players that explicitly support MTP * D-Bus spec doesn't allow hyphens in object paths, exchanged for underscores, which are allowed (kde#516856) * Drop MinimumKeepSize from KCM * Drop MinimumKeepSize config from workers * filenamesearch: Treat any url with non empty path as invalid ==== kio-gdrive ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kmenuedit6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== knighttime6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libKNightTime0 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== konsole ==== Version update (26.04.3 -> 26.08.0) Subpackages: konsole-part - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Drop bogus ZLIB dependency * ViewManager: Add container loading back to createSession * EscapeSequenceUrlHotSpot: add Copy & Open actions (kde#520743) * Fix kitty graphics byteCount overflow - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Revert "Fix warnings from PreviewJob" - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * ViewSplitter: make sure restoreAll and hideRecurse set container visibility (kde#520395) * Implement Kitty keyboard protocol (kde#519627) * EditProfileMousePage: reword the open links setting (kde#481115) * Add automatic profile switching based on system theme (kde#449235) * Prevent QTabBar from closing tabs on middle mouse clicks * we could arrive here with already destructed currentTerminalDisplay() (kde#519274) * Fix duplicated Copy entry in Configure Keyboard Shortcuts dialog (kde#513011) ==== kpipewire6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: kpipewire6-imports libKPipeWire6 libKPipeWireDmaBuf6 libKPipeWireRecord6 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kpmcore ==== Version update (26.04.3 -> 26.08.0) Subpackages: libkpmcore13 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Rewrite NTFS updateBootSector code. (kde#523706) - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * kpmcore: list Qt6::Widgets in public interface, for public QWidget classes * Drop duplicated listing of one fs header * Add take ownership operation * Allow chown in external command whitelist * partwidget: ensure dark text on filesystem color * Change LUKS2 default sector size to 4096 considering most of user devices (SSDs and HDDs operate in 4K sectors). ==== kscreen6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * osd: trigger Configure button on Enter, too (kde#515214) * Update version for new release 6.7.4 ==== kscreenlocker6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libKScreenLocker6 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== ksshaskpass6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Handle when unknown host prompt has no period after the finger print * Support unknown RSA when it has a colon (kde#444862) * Don't offer to remember password without identifier * prompt: Fix password change prompts * Update version for new release 6.7.4 ==== ksystemstats6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kwalletmanager ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Disable UI for access control when unavailable - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * kwalletconfig.json: fix BugReportUrl * Bump KF_MIN_VERSION to 6.13 * Set a sensible default window size on first launch ==== kwayland-integration6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== kwayland6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libKWaylandClient6 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Add support for wl_fixes.ack_global_remove * Update version for new release 6.7.4 ==== kwin6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libkwin6 - Add patch to improve issues after unplugging outputs: * 0001-wayland-Increase-global-removal-timer-timeout-to-1-d.patch - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * kcms/xwayland: Add missing default indicator * effects/windowview: fix current desktop class border activation * debugconsole: show executable for unknown sources * backends/drm: don't remove GPUs without outputs (kde#519461) * effect/quickeffect: fix QuickSceneEffect module reload condition * scene/windowitem: also set suspended state for dpms off * x11window: also take screen locking and dpms into account for visibility * opengl/egldisplay: work around libepoxy failing when GPU resets happen (kde#500114,kde#519263) * backends/drm: release the scanout buffer of virtual layers in beginFrame (kde#523353) * plugins/eis: Set zones mapping_ids * autotests: check the right virtual tablet before removing it * core/gpumanager: add KWIN_RENDER_NODES environment variable * kcms/effects: Take into account system-wide defaults * Update version for new release 6.7.4 ==== layer-shell-qt6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libLayerShellQtInterface6 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== leancrypto ==== - Add to the devel subpackage leancrypto-devel also a requires on libleancrypto-fips. (bsc#1273211) - Workaround for armv6 build (leancrypto assumes 32-bit is armv7) ==== libalternatives ==== Version update (1.2+31.da24cd4 -> 2.0+0.4f22c01) Subpackages: alts libalternatives1 - Update to version v2.0+0.4f22c01: * add missing test * Capture saved_errno correctly * Check for null pointer * reset argv0 to original if execve() fails * Clarify value of argv0 * Return errno from failed exec() * Use basename for argv[0] resolution * Update unit test * Document behaviour changes - KeepArgv0 is default * Correct pointer in corner case * Add UpdateArgv0 option * Clarify priority as increasing with integer size - Functionality change: KeepArgv0 is default option unless another is specified. Functionality should now be same as with symlinks (bsc#1262785) ==== libapparmor ==== - add changes-since-5.0.2.diff - several profile updates - fix compability with Swig 4.5 (boo#1275508) - drop upstreamed nslookup.diff - refresh kerberosclient-usrmerge.diff - add dovecot.diff with several dovecot profile updates (boo#1265453) ==== libdvdread ==== Version update (7.0.1 -> 7.1.1) - update to 7.1.1: * reduce the number of symbols exported to avoid conflicts when linking * DVD-Audio support: * Allow CPRM and CSS decryption support to be available simultaneously * Add Audio Still Video Set (ASVS) IFO structures and readers * Add ASVS and SAMG support to public IFO open APIs * Expose ASVS IFO, backup and menu VOB files * Improve AOB/VOB stream type handling * Misc fixes on structures documentation * DVD-VR support: * Add DVD-VR IFO parsing (PGIT, PG_GI, PS_GI) * Add DVDOpenVideoRecording functions * Add ifoOpenVideoRecording support * Add CPRM decryption support * Add DVDProbeType auto-detection for DVD-Video, DVD-Audio and DVD-VR * Add support for user-defined cells and time maps * Harden parsing of missing or malformed DVD-VR metadata * Add DVDOpenFiles for caller-provided virtual filesystem implementations * Split the internal filesystem implementation into platform- specific helpers * Improve file and directory handling on Windows, macOS and iOS * Improve logger fallback behavior when no controlling terminal is available * Add audio and subpicture code extension enums * Fixes and hardening: * Hardened IFO parsing for oversized still video groups * Fix DVD-Audio ASVS/SAMG fallback handling * Fix DVD-VR cell entry point byte swapping * Fix DVDFileSeek validation for non-sector-aligned files * Fix partial-block size accounting * Fix resource leaks, null pointer checks and error paths ==== libebml ==== Version update (1.4.5 -> 1.4.7) - Update to version 1.4.7 * Fixed cmake rules for building with utf8cpp 4.x version 1.4.6: * Set EbmlHead as not allowed to be infinite (as per RFC 8794) * Fix leak on upper element found inside the last element * EbmlString::ReadFully: use automatic memory management/fewer allocations * EbmlUnicodeString: use std::string when reading instead of manual memory management * IOCallback: avoid reading more than 2^32 at once * Fix some includes that are not implicit in modern compilers * Download utfcpp automatically * Show a summary of build configuration when configuring CMake * Add a DEV_MODE CMake option to check more compiler errors (default off) ==== libevdev ==== Version update (1.13.6 -> 1.13.7) - update to 1.13.7: * Refuse devices with more than 256 slots * Fix off-by-one in slot_value() bounds check * include: sync with kernel 7.0 ==== libjpeg-turbo ==== - update to 3.2.0: * Fixed a regression introduced by 3.2 beta1[9] that broke Arm64EC Windows builds. * Hardened the PNG writer (which is used by djpeg and tj3SaveImage*()) against applications that may erroneously attempt to write sample values that are out of range for the specified output data precision. * Hardened the libjpeg API against hypothetical applications that may erroneously call jpeg_crop_scanline() with buffered-image mode and raw data output enabled. * Fixed a buffer overrun and subsequent segfault in jpegtran that occurred when attempting to use the -crop and -trim options to expand the width of an image narrower than one iMCU, discard partial iMCUs, and fill each block in the expanded region with the DC coefficient of the nearest block in the input image ("flatten.") - deleted sources * libjpeg-turbo-3.1.4.1.tar.gz.sig (not needed) - added sources * libjpeg-turbo-3.2.0.tar.gz.sig ==== libkdcraw ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKDcrawQt6-5 libkdcraw-qt6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Use KDE_INSTALL_TARGETS_DEFAULT_ARGS, KF_ one reserved for KF * Inline now one-value-only CMake variables * Remove no longer needed passing of namespace to KDcrawTargets export ==== libkexiv2-qt6 ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKExiv2Qt6-0 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Use KDE_INSTALL_TARGETS_DEFAULT_ARGS, KF_ one reserved for KF * Remove duplicated and unused OUTPUT_NAME arg for KExiv2 properties * Inline now one-value-only CMake variables * Remove no longer needed passing of namespace to KExiv2Targets export * Remove no longer used deprecation version ==== libkgapi6 ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6GAPICore6 libKPim6GAPIDrive6 libkgapi6-sasl2-kdexoauth2 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Add method to set person from kcontacts addressee * Improve addressee edit details handling * Fix conversions for addresses * Add conversion test * Fix qstring comparisons * Fix wrong data insert that breaks recurrent event exceptions * Don't leak auth jobs * Delete network replies * Delete jobs created by unit tests * src/core/CMakeLists.txt - remove unused/uninitialized variables ==== libkscreen6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libKF6Screen8 libKF6ScreenDpms8 libkscreen6-plugin - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Remove unused maxPriority variable in adjustPriorities() * fix: emit edrPolicyChanged() instead of getter in setEdrPolicy() * Update version for new release 6.7.4 ==== libksysguard6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: ksysguardsystemstats6-data libKSysGuardSystemStats2 libksysguard6-imports - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * systemstats: don't keep dangling SensorObject pointers in SensorContainer (kde#523562) * Update version for new release 6.7.4 ==== libmatroska ==== Version update (1.7.1 -> 1.7.2) - update to 1.7.2: * Do not allow infinite sizes on all Master elements except Segment+Cluster * Only allow `KaxSeekId` of 4 bytes length (as per RFC 9559). * KaxBlock: release read buffers on `EndOfStream` error. * Catch some allocation failures internally. * Deprecate `KaxTrackMinCache`/`KaxTrackMaxCache` elements (as per RFC 9559). * Deprecate `KaxTrackOverlay` element (as per RFC 9559). * Fix `MATROSKA_VIDEO_FIELDORDER_TOPFIELDSWAPPED`/ * `MATROSKA_VIDEO_FIELDORDER_BOTTOMFIELDSWAPPED` values. * Add missing `MatroskaChapProcessCodecID` enum. * [API break] remove `MatroskaChapterTranslateCodec`/`MatroskaT rackTranslateCodec`. * KaxSemantic: update enum comments to match RFC 9559. * Add `MATROSKA_CHAPTERSKIPTYPE_INTERMISSION` to `MatroskaChapterSkipType`. * Fix some includes that are not implicit in modern compilers. * Show a summary of build configuration when configuring CMake. * Add a DEV_MODE CMake option to check more compiler errors (default off). * Add a BUILD_EXAMPLES CMake option (default off). ==== libopenmpt ==== Version update (0.8.7 -> 0.8.9) - Update to version 0.8.9: * [Sec] Possible heap out-of-bounds write when loading SymMOD files containing WAV IMA ADPCM samples. See also https://github.com/OpenMPT/openmpt/security/advisories/GHSA-fxf7-wc37-p2cx * [Sec] Possible heap out-of-bounds read when loading custom tunings from MPTM files. - Charges in version 0.8.8: * IT: Due to an Impulse Tracker bug in Compatible Gxx mode, Envelope Carry may not resume the envelope from the correct position when there is both an instrument number and tone portamento next to a note. * XM: NitroTracker ignores instrument numbers where there is no note next to them, so they are no longer imported. Fixes various NitroTracker-made XMs such as notominous-a19.xm. * STK: Loosen heuristics a bit to allow STK.CRB-GreatMuzaxs6 to load. * GT2: Loading file versions 6 and later was broken since libopenmpt 0.8.0. ==== libostree ==== Version update (2026.2 -> 2026.4) Subpackages: libostree-1-1 - Update to 2026.4: * Revert the static delta decompression-size safety margin introduced in 2026.3, which turned out to reject legitimate large deltas at apply time -- most visibly, Flathub Firefox updates were failing with Decompressed delta part exceeds configured limit. Both the margin heuristic and the flat 512MiB per-part decompression cap it fed into have been dropped for now. This deliberately reopens a DoS (unbounded decompression of a given delta part) until a precise, per-part exact-size- based replacement lands in a future release. The LZMA decoder memory limit (100 MiB) from that same advisory's fix is unaffected and remains in place (boo#1273918) * core: fixed a bug that caused every other xattr entry to be skipped during validation, letting a crafted xattr array hide unsorted or duplicate entries in odd-indexed slots - Update to 2026.3: * Unbounded LZMA decompression in static delta processing allows denial of service via decompression (boo#1273918) * Heap buffer overflow via integer truncation in static delta bspatch on 32-bit systems (boo#1273917) ==== libplasma6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libPlasma7 libplasma6-components libplasma6-desktoptheme - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Use Wrap instead of WordWrap everywhere (kde#523614) * ExpandableListItem: resize properly when number of enabled contextual actions changes (kde#506295) * Update version for new release 6.7.4 ==== libpsl ==== Version update (0.23.1 -> 0.23.3) - Update to version 0.23.3: * meson: compile and run the copyright-year helper program with the native (build machine) compiler, so that cross builds no longer abort at configure time * No change to the library code itself - this package is built with the autotools build system, which is unaffected - Update to version 0.23.2: * Fix a configure.ac typo (LC_ALL=Cdate) that made COPYRIGHT_YEAR ignore SOURCE_DATE_EPOCH and fall back to the current build date, so the copyright year embedded in the installed libpsl.h and in the psl.1 manual page is reproducible again * meson: derive the copyright date with portable C code instead of invoking the external date command * Drop the empty README file in favour of README.md ==== librist ==== - Switch from mbedtls to gnutls ==== librsvg ==== - Disable librsvg --test reference, failing with new pango 1.58.2 ==== libseccomp ==== - `python` build should not install non-Python files. - replace deprecated 'setup.py install' with PEP 517 wheel install ==== libselinux ==== Subpackages: libselinux1 selinux-tools - fix swig 4.5.0 compatibility (bsc#1275512). adding libselinux-Replace-PyString_FromString-with-PyUnicod.patch - Drop man_selinux_disabled_mismatch_kernel_config.patch, current libselinux doesn't behave like this anymore ==== libselinux-bindings ==== - fix swig 4.5.0 compatibility (bsc#1275512). adding libselinux-Replace-PyString_FromString-with-PyUnicod.patch ==== libsoup ==== - Fix runtime dependency of libsoup-tests, correctly requiring libsoup-3_0-0 - Add libsoup-CVE-2026-12548.patch: Fix heap out-of-bounds read flaw when parsing multipart HTTP messages. (bsc#1272196, glgo#GNOME/libsoup!524) - Add libsoup-tests subpackage with installed tests for gnome-desktop-testing-runner ==== libssh ==== Subpackages: libssh-config libssh4 - Fix libssh ignores system wide crypto policies (bsc#1272547) * Add patch: libssh-cmake-Add-option-WITH_HERMETIC_USR.patch ==== libupnp ==== Version update (22.0.4 -> 22.0.6) Subpackages: libixml22 libupnp22 - Update to release 22.0.6 * Build fixes for OmniOS ==== liburing ==== Version update (2.14 -> 2.15) - exclude more tests: they fail on 7.2 so far - update to 2.15 * Classic BPF (cBPF) filter support. * New register helpers: io_uring_register_query() and io_uring_register_zcrx_ctrl() * Out-of-source build support. * Many other improvements, see: https://github.com/axboe/liburing/releases/tag/liburing-2.15 - disable some new tests for SLE 15 and 16 - keyring updated ==== libva ==== Version update (2.24.0 -> 2.24.1) Subpackages: libva-drm2 libva-wayland2 libva-x11-2 libva2 - update to 2.24.1: * va: include for getuid/getgid in secure_getenv fallback ==== libwacom ==== Version update (2.19.0 -> 2.19.1) Subpackages: libwacom-data libwacom9 - update to 2.19.1: * Build fixes for older systems and other arches ==== libxmlb ==== - Add libxmlb-tests subpackage with installed tests for gnome-desktop-testing-runner ==== live555 ==== Version update (2026.06.01 -> 2026.08.14) Subpackages: libBasicUsageEnvironment2 libUsageEnvironment3 libgroupsock33 - update to 2026.08.14: * Fixed a bug that could cause a problem with subclassed variants of H.264 or H.265 RTP sinks. * Fixed old code in "GroupsockHelper.cpp" that was using hardcoded numeric error numbers * Fixed a memory leak that could occur when parsing a SDP description that contains two or more * When adding protection against the use of 'stolen' RTSP session ids we forgot to do so for every "SETUP" command. This release fixes that. * Fixed a typo in "RTSPCommon.cpp": "smtpe" -> "smpte". * Updated the RTSP server implementation to return a "Unsupported Transport" error if a "SETUP" request does not include a "Transport:" header. * Added "-std=c++20" to the "CPLUSPLUS_FLAGS" line in each "config.*" file, so that "std::atomic_flag::test" will compile with compilers that support * Made the parsing of MP3 audio files more robust to protect against malformed MP3 data. * Minor change to "testProgs/testRTSPClient.cpp" to make compiling on Mac OS X happier. ==== llvm22 ==== - Add llvm-deterministic-loopunroll.patch for reproducible builds. - Remove soft limit on open files. Depending on the number of jobs, linking can sometimes open more than 1024 files (boo#1261761). ==== microos-tools ==== Version update (4.0+git28 -> 4.0+git29) Subpackages: selinux-autorelabel zypp-excludedocs zypp-no-multiversion zypp-no-recommends zypp-single-rpmtrans - Update to version 4.0+git29: * Move man-online to an own sub-package ==== milou6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== mozilla-nss ==== Version update (3.125 -> 3.126.1) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs - update to NSS 3.126.1 * bmo#2054719 - fix content type tag for CMS AuthEnvelopedData plaintext - update to NSS 3.126 * no public releasenotes - Move the test suite into a separate multibuild flavour: * the test suite is 1465s of a 1586s build, of which only 83s is compiling nss itself, and 1278 packages build depend on nss, so a large part of the distribution waits on it * the default flavour now builds and packages only, the new test flavour runs the same suite completely unchanged * the test flavour ships no packages, so a red run blocks no rebuild * the sqlite3 command line tool is only used by the test suite and is now required by that flavour alone - No shipped file changes: the FIPS integrity checksums are produced by shlibsign in build and again in the install post step, both of which run before check, so the test suite only ever consumed them ==== multipath-tools ==== Version update (0.15~1+230+suse.d36a6a70 -> 0.15.1+227+suse.6644513) Subpackages: kpartx libmpath0 - Update to version 0.15.1+227+suse.6644513 (see NEWS.md for details) * The `preferredip=`parameter for the `iet` prioritizer has been generalized. See multipath.conf(5) for details. - Upstream fixes for vulnerabilities: * DoS on mulipathd socket by blocking IPC send operations (GHSA-hmcm-9cq4-r2xm bsc#1277199) * DoS on multipathd socket by exhausting connections (GHSA-pvp6-c9p3-25fp bsc#1277203) * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (GHSA-g5mh-253r-jjw5 bsc#1277205) * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (GHSA-pxwh-g75c-95pc 1277208) * kpartx: Heap Out-of-Bounds Read in GPT Header Validation (GHSA-p6rh-9x9j-3hvx, bsc#1277209) * Path traversal in device-mapper-multipath failed_wwids management (GHSA-gr7q-prfc-q636 bsc#1277210) * libmpathpersist PRIN READ FULL STATUS parser — unbounded descriptor rewrite causes root heap overflow (GHSA-hj7j-qr9h-5fv6 bsc#1277212) - Bug fixes: * Fix use-after free error during shutdown (gh#opensvc/multipath-tools#152) * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155) ==== ncurses ==== Version update (6.6.20260613 -> 6.6.20260815) Subpackages: libncurses6 ncurses-utils terminfo-base - Add ncurses patch 20260815 + improve tic warnings for paired capabilities, including ich/ich1. + use xterm+tmux2 in xterm+nofkeys to match xterm patch #407 -TD + use ST in xterm+osc104 -TD + use ansi+sc -TD + modify test/dup_field.c to also demonstrate link_field(). + work around use of ^D for exiting test/ncurses except in the form test which uses ^D for movement (patch by Branden Robinson). + improve appearance of test/dup_field and test/move_field, adding a help-hint (patches by Branden Robinson). + improve formatting/style of manpages (patches by Branden Robinson). + add limit-checks in lib_screen.c and lib_ins_wch.c in case a 2-cell character is added at the right-margin (report by Miroslav Lichvar). + improve limit-check for extended names in _nc_read_termtype (report/patch by Yeo Jooho). + improve description of init_extended_color in man page (patch by Andrew Burgess). + modify test/Makefile.in to fix "make check" when ncurses is built in a non-source tree (report by Bruno Haible). - Add ncurses patch 20260808 + various improvements/fixes to test/dup_field.c + correct a check for FORM* in test/tracemunch + correct an ifdef in delscreen when using --enable-reentrant (report by Vassili Courzakis). + modify dup_field to allocate buffers needed for wide-character configuration of dup_field (report by Serhiy Storchaka). + correct masking of wide characters into chtype in winch (report by Serhiy Storchaka). - Add ncurses patch 20260801 + use ansi+csr in aaa+dec -TD + use ansi+idc in hurd, tw100, vt420 -TD + use ansi+erase in tw100 -TD + add vt100+tabs -TD + fix unbounded recursion in winsch if given a parameter which is not a valid character in the current encoding (report/analysis by Serhiy Storchaka). - Add ncurses patch 20260725 + use ansi+cpr in beterm -TD + use ansi+csr in aixterm, att6386, hirez100, iris-ansi -TD + use ansi+idc in vt220-base -TD + add ansi+sc -TD + fixes for compiler warnings/cppcheck. + amend 20260307 change to read_entry.c, to allow reading terminfo compiled in ncurses 6.1 and earlier (reports by Todd Richmond, Sven Joachim, cf: 20180331). - Add ncurses patch 20260718 + drop kbs from vt100+arrows and vt100+apparrows to increase usage -TD + add xterm+24fkeys -TD + fixes to escape comma and backslash consistently with infocmp for - g/-G options. - Add ncurses patch 20260711 + add otty -TD + add vt100+arrows, vt100+apparrows -TD - Add ncurses patch 20260704 + add zutty -TD + modify winch() and winsch() to use wcstombs() to convert 8-bit codes to Unicode when ncurses is configured to support Unicode but is not using UTF-8 encoding (report/analysis by Serhiy Storchaka). + fixes for compiler warnings/cppcheck. + fixes for scan-build, valgrind build/testing. + fix a memory leak in _nc_resolve_uses2 (report/testcase by Yufeng Wu, Zhijie Zhang, Qizhen Xu) + add a check for escaped nul in fmt_complex (report/testcase by Yufeng Wu, Zhijie Zhang, Qizhen Xu). + add a limit-check in _nc_tgetent (report by Utku Yildirim). + add a buffer-limit check in tgetstr. - Port ncurses-6.6.dif, ncurses-5.9-ibm327x.dif, and ncurses-6.5-ghostty.dif - Add ncurses patch 20260627 + add a makefile symbol for the names of the installed libraries to simplify parallel build of more than one configuration (patch by Luca Fancellu). + change misc/Makefile to eliminate "pc-files" stamp target (report by Luca Fancellu). + change internal type for file-descriptor to int, eliminate cast (report by Antonio Nino Diaz). + add xon to several entries, based on manuals and product descriptions -TD + revise adm36, based on manual -TD + add u6, u7, kdch1 to vp3a+ based on manual -TD + add u6, u7, home, cbt to adm20 based on manual -TD - Add ncurses patch 20260620 + add il1 to ibcs2 -TD + add ich1 to several entries, providing for support of non-curses applications via termcap only -TD + add ich/ich1 to teraterm2.3 based on ttsrcp23.zip source-code -TD + add ich/ich1 to x10term based on X.V10R4/xterm source-code -TD + add ich/ich1 to xterm-r6 based on source-code -TD + add ich/ich1 to mterm-ansi and decansi based on source-code -TD + add ich/ich1 to tek4025a, tek4105a, tek4106brl from manual -TD + modify infocmp, tic, and tgetent to omit ich1 (termcap "ic") while providing termcap data when smir/rmir (termcap "im/ei") are given. + reduce warning in tic regarding termcap applications which do not work with smir/rmir combined with ich1. ==== nghttp3 ==== - Add curl-impersonate.patch backporting backward compatible changes used by curl-impersonate project ==== ngtcp2 ==== Subpackages: libngtcp2-16 libngtcp2_crypto_gnutls8 libngtcp2_crypto_ossl0 - Require boringssl-devel >= 0.20260813 at build time: the previous 0.20210430 snapshot lacks SSL_set_quic_early_data_context, so configure rejected it with a misleading "boringssl was requested but not found" failure instead of an unresolvable dependency - Add ngtcp2-boringssl-shared.patch bulding the boringssl bridge as shared library - Enable building the boringssl bridge in Factory - Add curl-impersonate.patch backporting backward compatible changes used by curl-impersonate project ==== openexr ==== Version update (3.4.13 -> 3.4.14) Subpackages: libIex-3_4-33 libIlmThread-3_4-33 libOpenEXR-3_4-33 libOpenEXRCore-3_4-33 - version update to 3.4.14 * [CVE-2026-68514](https://www.cve.org/CVERecord?id=CVE-2026-68514) PyOpenEXR deep prefixed literal RGB key collision heap buffer overflow * [CVE-2026-68513](https://www.cve.org/CVERecord?id=CVE-2026-68513) PyOpenEXR prefixed literal RGB key collision heap buffer overflow * [CVE-2026-62986](https://www.cve.org/CVERecord?id=CVE-2026-62986) PyOpenEXR deep prefixed RGB stale lane disclosure * [CVE-2026-61703](https://www.cve.org/CVERecord?id=CVE-2026-61703) PyOpenEXR deep mixed RGB heap buffer overflow * [CVE-2026-61555](https://www.cve.org/CVERecord?id=CVE-2026-61555) empty multiView viewFromChannelName file crash * [CVE-2026-59985](https://www.cve.org/CVERecord?id=CVE-2026-59985) ILP32 OpenEXRCore RLE decode heap OOB read DoS * [CVE-2026-59984](https://www.cve.org/CVERecord?id=CVE-2026-59984) ILP32 B44 InputFile decode scratch buffer overflow * [CVE-2026-59983](https://www.cve.org/CVERecord?id=CVE-2026-59983) ILP32 DeepTiledInputFile sample count table decode OOB read * [CVE-2026-59982](https://www.cve.org/CVERecord?id=CVE-2026-59982) ILP32 DWAA InputFile packed AC buffer overflow * [CVE-2026-59981](https://www.cve.org/CVERecord?id=CVE-2026-59981) OpenEXRUtil SampleCountChannel row nonzero dataWindow heap OOB read * [CVE-2026-59189](https://www.cve.org/CVERecord?id=CVE-2026-59189) OpenEXRUtil DeepImageChannel row nonzero dataWindow heap OOB read * [CVE-2026-59187](https://www.cve.org/CVERecord?id=CVE-2026-59187) OpenEXR exrmetrics deep pixelmode heap buffer overflow * [CVE-2026-59186](https://www.cve.org/CVERecord?id=CVE-2026-59186) OpenEXR ILP32 TiledRgbaInputFile large tile Array2D heap OOB write * [CVE-2026-59184](https://www.cve.org/CVERecord?id=CVE-2026-59184) OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write * [CVE-2026-59183](https://www.cve.org/CVERecord?id=CVE-2026-59183) Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile Decoding - for other changes see CHANGES.md - fixes CVE-2026-59183 [bsc#1276428] CVE-2026-65979 [bsc#1276843] CVE-2026-68513 [bsc#1276845] CVE-2026-68514 [bsc#1276846] CVE-2026-68515 [bsc#1276848] CVE-2026-59184 [bsc#1276849] CVE-2026-59186 [bsc#1276850] CVE-2026-59187 [bsc#1276851] CVE-2026-59982 [bsc#1276853] CVE-2026-59189 [bsc#1276855] CVE-2026-59983 [bsc#1276856] CVE-2026-59984 [bsc#1276857] CVE-2026-59985 [bsc#1276858] CVE-2026-61555 [bsc#1276859] CVE-2026-62986 [bsc#1276861] CVE-2026-59981 [bsc#1276862] ==== openssh ==== Version update (10.4p1 -> 10.5p1) Subpackages: openssh-clients openssh-common openssh-server - Update to openssh 10.5p1: = Potentially-incompatible changes * Portable OpenSSH now requires ECC (Elliptic Curve Cryptography) support in libcrypto, including support for the NISTP521 curve. ECC is included in the default build configurations of all versions of all libcrypto implementations currently supported by OpenSSH, including LibreSSL, OpenSSL, BoringSSL and AWS LC. The --without-openssl build configuration is not affected. = Security * ssh-agent(1): fix an interaction between agent locking and the session-bind@openssh.com extension that is used to identify forwarded agents. These binding requests were refused when the agent was locked, with the result that operations that were intended to be limited to local use only could be performed remotely, including the ability to add PKCS#11 tokens and make use of keys that had destination restrictions applied. Reported by sn0x-sharma * ssh(1): avoid potential realloc use-after-free in the client if a remote forwarding is added via the local session multiplexing socket while a remote forwarding open request is pending with the server. Report and fix from Brian Mingus of Cognatory * sshd(8): make the authorized_keys "restrict" keyword apply correctly to tunnel forwarding too (which is administratively disabled by default). Reported by Erichen, Institute of Computing Technology, Chinese Academy of Sciences = New features * ssh-keygen(1): add ability to set or clear the touch-required and verify-required flags on FIDO private keys when resetting a private key's passphrase. * ssh(1): tweak ordering of certificates tried during pubkey authentication to prefer FIDO keys that do not require user presence (touch) first, and FIDO keys that require user verification via PIN or biometrics last. This effectively tries low-friction authenticators before higher friction ones. * ssh(1): add a "ssh -Z user@host" mode that prints the keys that will be tried for public key authentication in the order that they will be used. * sshd(8) use setproctitle(3) to identify sshd-session when its acting as a post-authentication monitor. = Bugfixes * ssh-keyscan(1): make reading the server banner a non-blocking operation to prevent a stuck server from blocking a many-host keyscan from proceeding. * sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the packet code as this provides context of the failing peer (address, port, user, etc). * sshd(8): when signing hostkey proofs for a client UpdateHostKeys request, allow each hostkey to perform at most one signature operation. * sshd(8) fix GSSAPI option names, that were broken during a servconf.c refactoring in openssh-10.4; bz3974. * ssh-keygen(1): pass back errors from ed25519 key generation, which theoretically can fail. GHPR702. * sshd(8): move check of public key type against allowed algorithms to before parsing of the key sent by the peer. This removes at least some key parsing and verification paths from the pre-auth attack surface. Suggested by Christopher Paul Rohlf of Anthropic. * ssh-keygen(1): fix double frees (impossible to reach outside of a test harness), and also use freezero where possible. From Christopher Paul Rohlf at Anthropic. * sshd(8): fix ChannelTimeout and RekeyLimit not being applied in sshd_config Match blocks. * sshd(8): in sshd config dump mode, write all directives in mixed case for consistency = Portability * sshd(8): re-allow PAMServiceName inside a Match block, which was incorrectly disabled during a refactoring in openssh-10.4. bz3987 - Drop patch which is already included upstream: * 0001-Fix-GSSAPI-server-option-names.diff - Rebase patches: * openssh-7.7p1-fips.patch * openssh-7.7p1-pam_check_locks.patch * openssh-8.0p1-gssapi-keyex.patch * openssh-8.1p1-audit.patch * openssh-9.6p1-crypto-policies-man.patch ==== openvpn ==== Version update (2.6.14 -> 2.7.5) Subpackages: openvpn-auth-pam-plugin - Update to version 2.7.5 * Multiple security fixes (CVE-2026-13379, CVE-2026-12996, CVE-2026-13117, CVE-2026-13122, CVE-2026-12932, CVE-2026-11771, CVE-2026-13698) * Improved DCO (Data Channel Offload) support built-in * Better multi-socket event handling * Enhanced DNS configuration handling * Windows openvpnserv improvements and fixes - Add debian packaging files (debian.control, debian.rules, debian.tar.xz, *.dsc) as Source entries - Remove all DCO patches (integrated or superseded in 2.7.5): * 0001-dco-better-naming-for-function-parameters.patch * 0001-dco_linux-extend-netlink-error-cb-with-extra-info.patch * 0001-Handle-missing-DCO-peer-by-restarting-the-session.patch * 0001-dco_linux-Introduce-new-uAPIs.patch * 0001-Implement-ovpn-version-detection.patch * 0001-dco_linux-fix-peer-stats-parsing-with-new-ovpn-kerne.patch * 0001-dco_linux-avoid-bogus-text-when-netlink-message-is-n.patch * 0001-dco-linux-avoid-redefining-ovpn-enums.patch - Change Recommends to ovpn-kmp (simplified) ==== orc ==== Version update (0.4.42 -> 0.4.43) - Update to version 0.4.43: + Add AVX512 support + neon: - add divluw rule (used in GStreamer's compositor, videomixer, gaudieffects and alpha-blending code paths) - add mulslq, mululq rules, shlq, shrsq, shruq (used in GStreamer's audio processing element) + orccodemem: Invalidate code chunks when recycling for QEMU + orcprogram-c: Allow negative constants + arm, neon: Split ARM and NEON logic into 32-bit and 64-bit + RISC-V: many fixes and enhancements, including some new rules + LoongArch: various fixes and enhancements + OpenBSD/FreeBSD improvements + Miscellaneous fixes ==== pango ==== Version update (1.58.0 -> 1.58.2) Subpackages: libpango-1_0-0 typelib-1_0-Pango-1_0 - Update to version 1.58.2: + Require harfbuzz 11 + Require glib 2.88 + CoreText: - Support variations - Support font features from descriptions + Renderer: Keep over/under/through lines in sync + Fixes for undefined behavior ==== partitionmanager ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Be a tiny bit more lenient with KPMcore versions - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add FreeBSD swap to kcfg file and UI config. (kde#522308) * Add "Take Ownership" action for mounted partitions * Updated description and button label for better UX (kde#504670) * Fixed position of "Label" Radio button (kde#514705) * Change the default preferred capacity to GiB ==== patterns-base ==== Subpackages: patterns-base-base patterns-base-bootloader patterns-base-minimal_base patterns-base-x11 - immutable_base: install transactional-wrapper by default on SLE (jsc#PED-15607) ==== patterns-kde ==== - Remove plasma6-session-x11 from the plasma 6 pattern (boo#1274552) ==== patterns-microos ==== Subpackages: patterns-microos-alt_onlyDVD patterns-microos-base patterns-microos-base-packagekit patterns-microos-base-zypper patterns-microos-basesystem patterns-microos-cloud patterns-microos-cockpit patterns-microos-defaults patterns-microos-desktop-common patterns-microos-desktop-kde patterns-microos-ima_evm patterns-microos-onlyDVD patterns-microos-ra_agent patterns-microos-ra_verifier patterns-microos-selinux patterns-microos-sssd_ldap - Remove patterns-microos-hardware, got obsoleted by patterns-base-hardware ==== permissions ==== Version update (1699_20260728 -> 1699_20260806) Subpackages: permctl permissions-config - Update to version 1699_20260806: * profiles: add spine cap_net_raw (bsc#1273300) - Update to version 1699_20260805: * profiles: Make uucp work even with latest chkstat (bsc#1273735) ==== pipewire ==== Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Add pipewire-tests subpackage with installed tests for gnome-desktop-testing-runner ==== plasma-branding-Kalpa ==== Version update (20260612 -> 20260819) - Version 20260819 * Revise cups dropin (boo#1268171) * Add missed locale1 declaration in sddm config - Drop 0001-add-missed-locale1-in-sddm-config.patch ==== plasma5support6 ==== Version update (6.7.3 -> 6.7.4) Subpackages: libPlasma5Support6 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Fix screen power management inhibition never being re-acquirable (kde#523605) * Update version for new release 6.7.4 ==== plasma6-activities ==== Version update (6.7.3 -> 6.7.4) Subpackages: libPlasmaActivities7 plasma6-activities-imports - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-activities-stats ==== Version update (6.7.3 -> 6.7.4) Subpackages: libPlasmaActivitiesStats1 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-browser-integration ==== Version update (6.7.3 -> 6.7.4) - Place native-messaging-hosts files in /usr/lib in addition to /usr/lib64 (boo#1275979) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-desktop ==== Version update (6.7.3 -> 6.7.4) Subpackages: plasma6-desktop-emojier - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 * Fix dragging onto grouped tasks when floating applets are enabled (kde#510643) * applets/kimpanel: Avoid unrefing a null engine descriptor * applets/{folder,showdesktop,minimizeall,kickoff,showActivityManager}: fix BugReportUrl * emojier: Focus emojiView on downPressed when using search (kde#523254) * kcms/gamecontroller: Fix std::out_of_range exception (kde#522886) * Update version for new release 6.7.4 ==== plasma6-integration ==== Version update (6.7.3 -> 6.7.4) Subpackages: plasma6-integration-plugin plasma6-integration-plugin-qt5 - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-nm ==== Version update (6.7.3 -> 6.7.4) Subpackages: plasma6-nm-openconnect plasma6-nm-openvpn - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-openSUSE ==== - Update to 6.7.4 ==== plasma6-pa ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-print-manager ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 * libkcups/plasmoid: Add a timer to reload the job queue when not empty (kde#512442) * Update version for new release 6.7.4 ==== plasma6-systemmonitor ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== plasma6-workspace ==== Version update (6.7.3 -> 6.7.4) Subpackages: plasma6-session plasma6-workspace-libs - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * libnotificationmanager: Return empty icon name in jobs model (kde#522846) * Move plasmaLocked property from KLookAndFeelManager to KCM * libklookandfeel: Drop Latte Dock integration * containmentlayoutmanager: guard against non-finite item geometry (kde#522039) * applets/digital-clock: apply font family to time zone label, too (kde#523164) * applets/digital-clock: Fix label not adjusting in size when showSeconds is changed (kde#523010) * startkde: Update LookAndFeelPackage in kdeglobals * CursorTheme/main.qml: Ensure the cursor icons and text fit combobox popup (kde#521187) * startkde: Drop plasma-svgelements purging code * kcms/color: Update ColorSchemeHash (kde#511740) * Update version for new release 6.7.4 ==== polkit-default-privs ==== Version update (1550+20260803.90784eb -> 1550+20260825.76d85e6) - Update to version 1550+20260825.76d85e6: * profiles: add lact profile-hook action (bsc#1274863) ==== polkit-kde-agent-6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== powerdevil6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Demote kameleon supported/enabled messages to debugs * Update version for new release 6.7.4 ==== procps ==== Version update (4.0.6 -> 4.0.7) Subpackages: libproc2-1 - Add patch procps-ng-4.0.7-sysctl_ipv6.patch (boo#1276206) * Really ignore stable_secret below /proc/sys/net/ipv6/conf - Extend the corrected patch procps-ng-3.3.8-readeof.patch to do open with O_NOATIME only for root - Update to procps-ng-4.0.7 * library version: inc revision to 2 now 1:2:0 internal: procps_pids_length off by one issue #412 external: fix slabinfo header extern 'C' declaration issue #415 internal: fix file descriptor leaks in api issue #421 internal: strv items are now escaped in api issue #429 internal: fix output if on seconds edge values merge !246 RHEL-60825 * pidof: Add -d aliased option issue #418 * pgrep: Don't treat empty list as 0 issue #427 * pmap: Fix testsuite for Alpha Debian #1141465 * ps: correct 'environ' output when file unavailable * ps: minimize potential EACCES with 'environ' files issue #431 * top: avoid batch mode segfault with maximum width issue #422 * w: Correctly check for end of tty using utmp issue #430 * watch: Dont remove 2 lines when using -t option issue #413 * watch: Handle resizing better issue #417 * watch: Restore LINES and COLUMNS env variables issue #432 - Port patches * procps-ng-3.3.11-pmap4suse.patch * procps-ng-3.3.8-petabytes.patch * procps-ng-3.3.8-readeof.patch * procps-ng-3.3.8-tinfo.dif * procps-ng-3.3.9-w-notruncate.diff * procps-ng-4.0.4-ignore-sysctl_conf.patch * procps-v3.3.3-read-sysctls-also-from-boot-sysctl.conf-kernelversion.diff - Remove patches now obsolete * procps-ng-4.0.4-pmapX-not-twice-anymore.patch * procps-v3.3.3-ia64.diff * glibc-2.43.patch * d9c96ec0.patch - Add patch procps-4.0.7-pmap-test.patch Simply add the leading zeros of an address for test_shm ==== python-Mako ==== Version update (1.3.12 -> 1.4.1) - Update to 1.4.1 * [bug] [installation] Fixed issue in the 1.4.0 packaging where the repository's internal tools/ directory was detected by setuptools package discovery and installed as a top-level tools package into site-packages, shadowing unrelated tools packages belonging to other applications. Package discovery is now limited to the mako package explicitly. - Update to 1.4.0 * [changed] [examples] The examples/bench folder has been removed as it used mostly long-obsolete template engines. The examples/wsgi/run_wsgi.py example has been updated to remove the use of the removed-in-Python-3.13 cgi module, and to be runnable as a module from the project root. * [changed] [installation] Minimum MarkupSafe dependency version bumped from 0.9.2 to 2.0. * [changed] [tests] The test suite now runs via nox. The old tox.ini remains however nox will be the only system that's maintained. * [changed] [installation] Project metadata has been migrated to PEP 621 pyproject.toml-based configuration. setup.cfg remains only for the [mako_testing] section used by Mako's own test suite. The build requirements now set the minimum setuptools version at 77.0.0 in order to build Mako from source. * [changed] [installation] Minimum Python version is now 3.10. Mako 1.4.0 has been tested up through Python 3.15.0b4. * bug] [ext] The minimum Lingua version supported by LinguaMakoExtractor is now 4.16. The test suite had continued to pin Lingua below 4 long after the extractor itself was repaired to work with Lingua 4 in version 1.2.0, with the result that the plugin was no longer covered by tests at all; the pinned version additionally imports pkg_resources at startup, which is not present in current setuptools releases and left the package unimportable. Lingua 4.16 resolves entry points using importlib.metadata, so no deprecated pkg_resources usage remains. * [bug] [exceptions] Fixed issue where formatting a traceback for an exception raised inside a template compiled from a string would emit DeprecationWarning: Module globals is missing a __spec__.loader on Python 3.15. Modules for such templates were created without a module spec, which Python's linecache module consults for every frame while a traceback is being built; the warning was raised from within traceback formatting itself, disrupting the error report for applications that configure warnings as errors. These modules are now given a spec with a loader that provides the generated module source, which additionally allows the generated source lines to be displayed in tracebacks produced by the standard library where previously no source was available. * [bug] [exceptions] A series of fixes involving syntax warnings and exceptions found during template lexing / compilation - run tests in multibuild flavor to not add new test dependencies to ring0 - disable 3 tests failing with Pygments 2.21.0 ==== python-gpg ==== - fix build with swig 4.5.0 adding gpgmepy-2.0.0-swig-4-5-0.patch ==== python-greenlet ==== Version update (3.5.3 -> 3.5.5) - Update to 3.5.5 * Link the C++ runtime statically into the Windows wheels again, as the Appveyor builds did through 3.3.0. Since 3.3.1 ``_greenlet.pyd`` imported ``MSVCP140.dll``, which no Windows CPython distribution ships, so importing greenlet failed on machines without the Visual C++ redistributable. See issue 525. Issue and pull request by Daniel Sticker. - from version 3.5.4 * Fix a crash (segfault) on free-threaded builds of Python 3.14 and later when the garbage collector runs while a greenlet that was started from a non-empty C-stack-reference state is active. See issue 515. Thanks to ddorian and Kumar Aditya. * Fix a potential use-after-free on free-threaded builds of Python 3.14 and later when the garbage collector runs while a greenlet is suspended holding a ``_PyCStackRef`` (for example, mid attribute resolution). See issue 515. Thanks to ddorian and Kumar Aditya. - Fix a deadlock on free-threaded builds when a greenlet switch happened while a ``PyCriticalSection`` was held -- for example inside asyncio's ``Task.__step``, which holds one on the running task for the duration of the step. See PR 519. Thanks to ddorian and Kumar Aditya. ==== python-pycairo ==== Version update (1.29.0 -> 1.29.1) - Update to 1.29.1: * Update dependencies (libpng, zlib) for the Windows wheels * Fix documentation build with Python 3.15 * Build wheels for Python 3.15 (except for 32bit Windows) * Fix a memory leak in ScaledFont.text_to_glyphs() * Fix some minor reference leaks ==== python-pyzmq ==== Version update (27.1.0 -> 27.2.0) - update to 27.2.0: * Lots of new type coverage. * Add `python3 -m zmq.curve_keygen` entrypoint for creating curve key pairs * Require Python 3.9 (drops Python 3.8) * Stop building wheels for free-threaded CPython 3.13 (cp313t) * Add wheels for free-threaded CPython 3.15 (cp315t) * Fix builds on Windows with Visual Studio 2026 * Fix builds with upcoming Cython release * Add more type coverage, fix some typing, typing compatibility with mypy 2.1 ==== python-tornado6 ==== Version update (6.5.7 -> 6.5.8) - update to 6.5.8 (bsc#1276210, bsc#1276211): * Form-encoded POST bodies are now subject to a limit of 1000 arguments by default. This prevents a CPU and memory denial of service attack. This limit can be overridden via the set_parse_body_config function. Thanks to Arpit Jain for reporting this issue. * Multipart parsing now rejects requests with an excessive number of parts earlier in the parsing process, limiting memory consumption. Thanks to afldl for reporting this issue. * The deprecated mixed-case arguments to RequestHandler.set_cookie now enforce the same restrictions on invalid characters that were introduced in Tornado 6.5.5 for the standard lowercase arguments. Thanks to sec-reex and Arpit Jain for reporting this issue. - drop python-tornado6-Fix-test_strip_headers_on_redirects.patch (upstream) ==== python-typing_extensions ==== Version update (4.15.0 -> 4.16.0) - permit flit-core 4 - Drop not needed patch py314-fix-tests.patch - Add upstream patch remove-obsolete-literal-deduplication-assertion.patch (gh#python/typing_extensions#785, bsc#1274786) - Update to 4.16.0: * Avoid a DeprecationWarning when deprecated is applied to a coroutine function on Python 3.14.0. * Make `typing_extensions.TypeAliasType`'s `__module__` attribute writable. Backport of CPython PR [#149172](https://github.com/python/cpython/pull/149172). * Fix setting of `__required_keys__` and `__optional_keys__` when inheriting keys with the same name. * Add support for `AsyncIterator`, `io.Reader`, `io.Writer` and `os.PathLike` protocols as bases for other protocols. * Fix incorrect behaviour on Python 3.9 and Python 3.10 that meant that calling `isinstance` with `typing_extensions.Concatenate[...]` or `typing_extensions.Unpack[...]` as the first argument could have a different result in some situations depending on whether or not a profiling function had been set using `sys.setprofile`. This affected both CPython and PyPy implementations. Patch by Brian Schubert. * Fix `__init_subclass__()` behavior in the presence of multiple inheritance involving an `@deprecated`*decorated base class. Backport of CPython PR [#138210](https://github.com/python/cpython/pull/138210) by Brian Schubert. * Raise `TypeError` when attempting to subclass `typing_extensions.ParamSpec` on Python 3.9. The `typing` implementation has always raised an error, and the `typing_extensions` implementation has raised an error on Python 3.10+ since `typing_extensions` v4.6.0. Patch by Brian Schubert. * Add the `bound`, `covariant`, `contravariant`, and `infer_variance` parameters to `TypeVarTuple`. * Officially support the `bound`, `covariant`, `contravariant` and `infer_variance` parameters to `ParamSpec`. Improve the validation of these parameters at runtime. * Rename `typing_extensions.Sentinel` to `typing_extensions.sentinel`, following the name that has been adopted for `builtins.sentinel` on Python 3.15. `typing_extensions.Sentinel` is retained as a soft*deprecated alias for backwards compatibility. * Add support for pickling sentinels. * Sentinels now preserve their identity when copied or deep*copied. * Deprecate passing `name` as a keyword argument or `repr` as a positional argument to the `sentinel` constructor. * The default repr of a sentinel `X = sentinel("X")` is now `X` rather than ``. * Deprecate arbitrary attribute assignments to sentinels. * Deprecate subclassing sentinels. * Add support for Python 3.15. ==== python313 ==== - Add reproducible_stencils.patch from gh#python/cpython!154988 - CVE-2026-0864: Normalize all line endings (CR, CRLF, and LF) in configparser (bsc#1269066, gh#python/cpython#143927) CVE-2026-0864-normalize-LFTAB-configparser.patch - CVE-2026-11972: Make tarfile._Stream.seek break at EOF (bsc#1269788, gh-151981) CVE-2026-11972-tarfile-Stream-seek-EOF.patch - CVE-2026-4360: Pass filter_function to TarFile._extract_one() during .extract() (bsc#1269959, gh#python/cpython#151987) CVE-2026-4360-filter_function-TarFile-extractone.patch - CVE-2026-15308: Fix quadratic complexity in incremental parsing in HTMLParser (bsc#1271192, gh#python/cpython#153030) CVE-2026-15308-HTMLParser-CPU-exhaust.patch ==== python313-core ==== Subpackages: libpython3_13-1_0 python313-base - Add reproducible_stencils.patch from gh#python/cpython!154988 - CVE-2026-0864: Normalize all line endings (CR, CRLF, and LF) in configparser (bsc#1269066, gh#python/cpython#143927) CVE-2026-0864-normalize-LFTAB-configparser.patch - CVE-2026-11972: Make tarfile._Stream.seek break at EOF (bsc#1269788, gh-151981) CVE-2026-11972-tarfile-Stream-seek-EOF.patch - CVE-2026-4360: Pass filter_function to TarFile._extract_one() during .extract() (bsc#1269959, gh#python/cpython#151987) CVE-2026-4360-filter_function-TarFile-extractone.patch - CVE-2026-15308: Fix quadratic complexity in incremental parsing in HTMLParser (bsc#1271192, gh#python/cpython#153030) CVE-2026-15308-HTMLParser-CPU-exhaust.patch ==== qalculate ==== Version update (5.11.0 -> 5.12.0) - Update to version 5.12 * LaTeX input and output (using latex() function, "$...$" syntax, and "to latex" or "-latex" in qalc) * Solve ax^b+cd^x=0 for real x * Solve equations with absolute value and complex x (xabs(x)=a, x^2abs(x)=a, and af(x)+babs(x)=c) * Improve simplification of a^(c/d)/b^(c/d) in exact mode (e.g. cbrt(12)/cbrt(4)=cbrt(3)) * Apply logical and bitwise operation entrywise to vectors and matrices * Allow symbols with suffix when input using backslash (e.g. \x_n = "x_n", with n shown as subscript in output) * Add argument for reverse conversion to roman(), bijective() and bcd() functions * Add tsp and tbsp abbreviations, change cup to exactly 240 mL (U.S. legal), and add U.S. customary cup, tablespoon, and teaspoon * Mixed units conversion improvements/fixes * Fix conversion of feet and inches when using ' and " (e.g. 5'2" to cm) * Fix ax+bln(x)=c where sgn(a)!=sgn(b) (only one solution were found) * Fix segfault when calculating limit for expression with sinh or cosh (also affects integrals with infinite lower or upper limit) * Fix RPN syntax for expressions with multiple functions * Add max history option to configure maximum number of expressions saved in history * Minor bug fixes and feature enhancements ==== qpdf ==== Version update (12.3.2 -> 12.4.1) - Update to version 12.4.1: - Update to 12.4.1: * Avoid generating JSON with leading zeroes when converting real numbers. * Detect and warn in check linearization when the cross-reference (xref) stream reports that the object containing a compressed object is itself a compressed object. * Improve uniformity and accuracy of progress reporting when writing linearized files and files with a large number of object streams. 10 - Update to 12.4.0: * Fix error message when --check encounters a PDF file with no pages. * Remove non-array/empty /Annots entries and non-dictionary annotations from copied pages in QPDFAcroFormDocumentHelper::fixCopiedAnnotations. * Fix failure in QPDFWriter when trailer /ID entries are invalid. * Limit the effect of QPDF::setMaxWarnings to the initial loading of the PDF file to prevent treating subsequent exceptions as recoverable. * Correctly handle page rotation values outside [0, 360] range in QPDFPageObjectHelper::getMatrixForTransformations. * Enforce conservative limits on the depth of direct objects created via QPDFObjectHandle::makeDirect to reduce stack overflow risk. * Enforce conservative limits on pages tree depth to prevent stack overflows. * Detect duplicate entries in the AcroForm field hierarchy earlier. * Rewrite zsh and bash shell completion functions to autogenerate from argument parsing metadata (job.yml) instead of invoking the executable. * Show linearization data even if linearization checks throw an exception. * Add REQUIRE_SHELLS CMake option to fail completion tests if new bash/zsh are missing (enabled by default in maintainer mode). * Deprecate external-libs on Windows in favor of vcpkg. ==== qqc2-breeze-style6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== qrca ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Tidy Readme and update copyright year * Use Kirigami Addons from the Flatpak runtime * Use KDE_INSTALL_TARGETS_DEFAULT_ARGS, KF_ one reserved for KF * Fix Android build with Qt 6.11 ==== qt6-base ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Concurrent6 libQt6Core6 libQt6DBus6 libQt6Gui6 libQt6Network6 libQt6OpenGL6 libQt6OpenGLWidgets6 libQt6PrintSupport6 libQt6Sql6 libQt6Test6 libQt6WaylandClient6 libQt6Widgets6 libQt6WlShellIntegration6 libQt6Xml6 qt6-network-tls qt6-networkinformation-connman qt6-networkinformation-glib qt6-networkinformation-nm qt6-printsupport-cups qt6-sql-sqlite qt6-wayland - Add patch to fix a regression in icon loading (kde#=524657, QTBUG-149431): * 0001-QIconLoader-Don-t-consider-fallbackThemeName-in-them.patch - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released - Add patch to fix incomplete docs (QTBUG-149045): * 0001-CMake-Handle-generated-headers-in-syncqt-scan-all-mo.patch ==== qt6-declarative ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6LabsAnimation6 libQt6LabsFolderListModel6 libQt6LabsPlatform6 libQt6LabsQmlModels6 libQt6LabsSettings6 libQt6LabsSharedImage6 libQt6LabsStyleKit6 libQt6LabsSynchronizer6 libQt6LabsWavefrontMesh6 libQt6Qml6 libQt6QmlCore6 libQt6QmlLocalStorage6 libQt6QmlMeta6 libQt6QmlModels6 libQt6QmlNetwork6 libQt6QmlWorkerScript6 libQt6QmlXmlListModel6 libQt6Quick6 libQt6QuickControls2-6 libQt6QuickControls2Impl6 libQt6QuickDialogs2-6 libQt6QuickDialogs2QuickImpl6 libQt6QuickDialogs2Utils6 libQt6QuickEffects6 libQt6QuickLayouts6 libQt6QuickParticles6 libQt6QuickShapes6 libQt6QuickTemplates2-6 libQt6QuickTest6 libQt6QuickVectorImage6 libQt6QuickWidgets6 qt6-declarative-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released - Drop patch, merged upstream: * 0001-QQmlTableInstanceModel-refactor-QModelIndex-calculat.patch ==== qt6-imageformats ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-location ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Location6 - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-multimedia ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Multimedia6 libQt6MultimediaQuick6 libQt6MultimediaWidgets6 libQt6Quick3DSpatialAudio6 libQt6SpatialAudio6 qt6-multimedia-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-positioning ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Positioning6 libQt6PositioningQuick6 qt6-positioning-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-qt5compat ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Core5Compat6 qt6-qt5compat-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-quick3d ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6Quick3D6 libQt6Quick3DAssetImport6 libQt6Quick3DAssetUtils6 libQt6Quick3DEffects6 libQt6Quick3DHelpers6 libQt6Quick3DHelpersImpl6 libQt6Quick3DParticleEffects6 libQt6Quick3DParticles6 libQt6Quick3DRuntimeRender6 libQt6Quick3DUtils6 libQt6Quick3DXr6 qt6-quick3d-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-quicktimeline ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-shadertools ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-speech ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6TextToSpeech6 qt6-texttospeech - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-svg ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-tools ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6UiTools6 qt6-tools-qdbus - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released - Add patch to make documentation more reproducible (QTBUG-145807): * 0001-QDoc-Use-deterministic-tiebreaker-for-shared-notifie.patch ==== qt6-virtualkeyboard ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6HunspellInputMethod6 libQt6VirtualKeyboard6 libQt6VirtualKeyboardQml6 qt6-virtualkeyboard-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-webchannel ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6WebChannel6 libQt6WebChannelQuick6 qt6-webchannel-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== qt6-webengine ==== Version update (6.11.1 -> 6.11.2) Subpackages: libQt6WebEngineCore6 libQt6WebEngineQuick6 libQt6WebEngineWidgets6 qt6-webengine-imports - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released - Drop patch, merged upstream: * 0001-Fix-AMD-VA-API-flickering-on-Wayland-by-allowing-mul.patch ==== qt6-webview ==== Version update (6.11.1 -> 6.11.2) - Update to 6.11.2 https://www.qt.io/blog/qt-6.11.2-released ==== rootlesskit ==== Version update (3.0.2 -> 3.1.0) - Update to version 3.1.0: * v3.1.0 * feat: support --port-driver=pesto for IPv4 * docs: refresh network driver benchmark table * fix: benchmark pasta, not slirp4netns * fix: correct field names in ParsePortSpec error messages * fix(pasta): block host loopback access from the namespace when `--disable-host-loopback` is set * Build(deps): Bump actions/setup-go from 6 to 7 * chore: update error message when the pasta binary dosen't exist * v3.0.2+dev ==== run0-wrappers ==== Version update (0.5.0+git20260717.efd7268 -> 0.5.0+git20260822.4d653d8) - Update to version 0.5.0+git20260822.4d653d8: * run0-sudo -E: skip invalid variable names [bsc#1274617] * run0-su: fix type in error message (#7) ==== sdbootutil ==== Version update (1+git20260714.d9bb736 -> 1+git20260825.c7a5a97) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper sdbootutil-tukit - Update to version 1+git20260825.c7a5a97: * Refactor free space calculation * Do not use /proc/cmdline in half configured systems * Warning when the recovery PIN is not validated * Show default and booted snapshots with marks * Improve detection of snapshot systems * Fix when searching for a boot entry * Fix boot order and boot order entry * Create the entries directory in the ESP * Fix get_final_pcr parser * Keep btrfs error and show it when fails * Fix set -e early exit instances * Fix measure-pcr-validator when there is no terminal * Don't include measure-pcr-validator in initrd if TPM2 is not used * Update predictions even if crypttab did not change * Improve PCR 15 signing * Detect NAME=VALUE passed as parameters and complain * When asking a password, require a terminal * Filter some warnings from pcrlock * Detect directories that are not part of the snapshot * Write bash completion errors to /dev/null * Detect when t-u apply is done and avoid data corruption * Detect pcr-oracle leftovers * Show in title that it's the initial version for transactional systems * Manually generate PCR7 measurements * Regenerate pcrlock.json when it is missing - Update to version 1+git20260813.357956d: * Do not update the predictions without a TPM2 enrollment (bsc#1273384) - Update to version 1+git20260812.305d9f2: * Do not supplement if GRUB2-EFI is installed (bsc#1272525) ==== sddm-kcm6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== sddm-qt6 ==== Version update (0.21.0 -> 0.21.0+git57) Subpackages: sddm-greeter-qt6 - Build from develop branch - Update to version 0.21.0+git57: * Fix error checking in XcbKeyboardBackend::initLayouts() * fix(greeter): show dark fallback background when image fails to load * Update Romanian translation * Update Kazakh translation * CI: Install the right package for "dnf builddep" command * sddm.service: conflicts with kmsconvt@ttyX * Display: also reuse session created by sddm-autologin * fixed wrong string literal assignment * Update Arabic Translation (#2067) * Do not manage setCursor with startProcess as latter adds X-specific logic * Delete QProcess objects only after waiting for process termination * xorg-user: Allow overriding -verbose Xorg option * Bump minimal timeout for waitForFinished() to 5 seconds * Remove use of qAsConst which is deprecated * Fix index check for UserModel * Update Traditional Chinese translation * CMake: Raise required version to 3.5 * Redesign login shell use in session scripts * Simplify Seat::displayStopped * Less strict [Section Header] parsing for session .desktop files * CI: Replace ubuntu 23.04 with 24.04 * Apply suggestions from review * Apply suggestions from code review * Update Japanese translation * Hebrew translation update * Update he.ts * Update es.ts * Updated spanish translation * If autologin is used, avoid starting a display server for the greeter * Reset daemonApp->first in the Display constructor * Load autologin configuration in Display::Display * Set Display::m_started early * Remove unused Display::m_relogin variable * xcb: use xcb_connection_has_error to check for failue * Fix for issue Suspicious code in PamHandle::end #1990 * CI: Drop building with clang on CentOS Stream9 * CI: Fix order of arguments for dnf * Update Czech translations * Add translation for Persian * Use xrdb to set Xcursor.theme and Xcursor.size * Introduce utmps support (#1962) * Switch back to greeter when logind emits SecureAttentionKey * Prevent the greeter display server from hanging if SwitchToGreeter() is sent to a seat when the greeter is already active * cmake: remove the final (Arch) PAM modules * cmake: drop Debian specific PAM modules * cmake: drop FreeBSD specific PAM modules * Docs: add QtVersion information to THEMING * Themes: set QtVersion=@QT_MAJOR_VERSION@ * Themes: fix deprecated signal handler declarations * Components: use Transitions instead of Behaviors * Themes: explicitly resolve image URLs * Themes: hide LayoutBox when keyboard model is empty or disabled * Mark keyboard backend as disabled on Wayland * UserSession: Only act on the VT when XDG_VTNR is set * Conditionalize more VT related calls * Allow non-root greeters and sessions to start on kernels without VTs * VirtualTerminal: Export defaultVtPath - Drop patches, now upstream: * 0001-CMake-Raise-required-version-to-3.5.patch * 0001-Redesign-login-shell-use-in-session-scripts.patch * 0001-Use-xrdb-to-set-Xcursor.theme.patch * 0001-Remove-unused-Display-m_relogin-variable.patch * 0002-Set-Display-m_started-early.patch * 0003-Load-autologin-configuration-in-Display-Display.patch * 0004-Reset-daemonApp-first-in-the-Display-constructor.patch * 0005-If-autologin-is-used-avoid-starting-a-display-server.patch - Refresh 0003-Leave-duplicate-symlinks-out-of-the-SessionModel.patch - Drop sddm-service-handle-plymouth.patch, plymouth-quit.service is wanted by multi-user.target already - Bundled themes use Qt 6 now, soften sddm-greeter-qt5 requirement to a suggests ==== selinux-policy ==== Version update (20260804 -> 20260826) Subpackages: selinux-policy-targeted - Update to version 20260826: * Fix NFS mount with xprtsec=tls / xprtsec=mtls (bsc#1275783) * named filetrans for netconfig (bsc#1275219) * Revert "Apply fix_unconfined.patch" (bsc#1275219) * sshd_session_t needs to access kanidm sshkeys (bsc#1275492) * Fix broken kanidm_sshkeys_t security context (bsc#1275492) * Initial policy for xrdp (bsc#1262291) - Update to version 20260820: * Label the postgresql executables correctly (bsc#1274861) - Update to version 20260810: * (open)SUSE only sendmail fixes (bsc#1273901) ==== serd ==== Version update (0.32.8 -> 0.32.10) - update to 0.32.10 * Address new warnings in clang-tidy 22 * Fix writing quotes at the end of long literals ==== setools ==== Version update (4.7.0 -> 4.7.1) - Fixup mcp flavor: make Name: explicitly unique per flavor. Change 'mcp' flavor to mcp-multibuild to cheat with the name for the subpackage (otherwise we get setools-mcp as source name, which requires us to conidionalize summary/description in the preamble) - Move sedta and seinfoflow to setools-console-analyses and exlude its build for SLE16 as python-networkx won't be available there (bsc#1273200). - Add mcp flavor to allow it to be excluded from ring0 - Update to version 4.7.1: * Add initial prompts to MCP server * Add file_contexts querying class * Change MCP server to use standalone FastMCP package - Make tests run only on x86_64 because of missing dependencies on other archs ==== shadow ==== Version update (4.20.0 -> 4.20.2) Subpackages: libsubid6 login_defs shadow-pw-mgmt - Update to 4.20.2: * lib/: Add missing include. * Remove unused build flag - Drop upstreamed shadow-4.20-stdint.patch ==== signon-kwallet-extension ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== skopeo ==== Version update (1.23.0 -> 1.24.0) - Update to version 1.24.0: * Bump Skopeo to v1.24.0 * Bump c/storage 1.64.0, c/image 5.41.0, c/common 0.69.0 * Update actions/stale action to v11 * ci: drop redundant make vendor from test_skopeo * Update module go.yaml.in/yaml/v3 to v3.0.5 * integration: use our own pause image * Update dependency podman-container-tools/automation to v20260722 * Update module github.com/containers/ocicrypt to v1.3.2 * Update actions/checkout action to v7.0.1 * .github/workflows/stale.yml: pin actions/stale * .github/workflows/issue_pr_lock.yml: update org name * .github/workflows: do not run cron jobs at midnight * remove .github/workflows/check_cirrus_cron.yml * Update actions/setup-go action to v7 * Update dependency podman-container-tools/automation to v20260707 * renovate: point config to new repo * ci: make the automation release renovate managed * Update module go.podman.io/common to v0.68.1 * Add support for selective signature removal and sparse manifest list stripping * Update module golang.org/x/term to v0.45.0 * Use go.yaml.in/yaml/v3 instead of gopkg.in/yaml.v3 * Update module github.com/containers/ocicrypt to v1.3.1 * Update module golang.org/x/crypto to v0.52.0 [SECURITY] * Update module golang.org/x/net to v0.55.0 [SECURITY] * Update dorny/paths-filter action to v4.0.2 * docs: include examples for --command-timeout duration format * Fix minor grammar error in skopeo.1.md * Update actions/setup-go action to v6.5.0 * Update actions/checkout action to v7 * Use correct SEE ALSO heading level in man pages * Fix the docker-archive: transport entry in skopeo-list-tags(1) * Drop a trailing period in skopeo-sync --help documentation * Remove a misplaced signatures sentence in skopeo-copy(1) * Update module golang.org/x/term to v0.44.0 * ci: pull skopeo_cidev image from ghcr instead of quay * [skip-ci] Update actions/checkout action to v6.0.3 * ci: switch self-hosted runners from Oracle to CNCF Ubuntu * Define IMAGE_TAG in the workflow * ci: add path-filter, Total Success, drop Cirrus leftovers * ci: address review feedback on workflow * ci: migrate PR-blocking checks from Cirrus to GitHub Actions * Bump to the next dev, v1.24.0-dev ==== sndiff ==== Version update (0.2.2~2 -> v0.3~0) - Update to version v0.3~0: * Fix empty diff for non-root configs and selecting snapshot 0 * Add support for multiple snapper configs ==== spectacle ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 * Scan for QR code when editing existing image (kde#521097) * Fix QTimer construction in annotation sync * Update version for new release 6.7.4 ==== srt ==== Version update (1.5.6 -> 1.5.7) - Update to version 1.5.7: + Security Notice: - This release includes important security hardening and multiple vulnerability fixes identified during extensive security audits of the SRT codebase. Several issues could allow memory corruption, protocol state manipulation, resource exhaustion, or misuse of auxiliary tools and CI infrastructure. - Users are strongly encouraged to upgrade to this version to benefit from these security improvements and protocol hardening measures. + Security Improvements: - Handshake and Encryption Security: . Fully remediated the KMREQ processing vulnerability by validating all incoming KM message lengths before they reach internal conversion and copy routines, protecting both HSv4 and HSv5 negotiation paths. . Completed the remediation of the encryption downgrade vulnerability by preventing post-establishment KMRSP messages from modifying the security state of already secured sessions. Additional protections were added for both HSv4 and HSv5 negotiation paths. . Added minimum MSS enforcement during connection negotiation to prevent undersized payload buffers that could otherwise lead to heap corruption and information disclosure during handshake generation. . Hardened handshake state processing to correctly derive connection state from the live connection status and prevent unintended state rollback caused by late or malformed handshake exchanges. - Data Plane Protection: . Fixed validation of ACK control messages to prevent send-buffer corruption caused by forged or malformed acknowledgements. Additional bounds checking now ensures that sequence number ranges remain valid before buffer state updates occur. . Added protection against invalid DROPREQ ranges. Reversed ranges and invalid sequence number distances are now rejected before modifying receiver buffer state. . Corrected receive-path connection status handling to prevent non-addressed packets from affecting unrelated connection attempts. - FEC Robustness: . Added payload-size validation in FEC clipping operations to prevent out-of-bounds writes when processing oversized payloads. . Introduced minimum-size validation for FEC control packets, eliminating integer-underflow conditions that could occur when processing malformed packets. . Added upper bounds for peer-supplied FEC configuration values and improved error handling to prevent excessive memory allocation during connection establishment. - Bonding Reliability: . Fixed a use-after-free condition in the bonding BACKUP send path. Internal member context tracking now safely handles members removed while locks are temporarily released, preventing dangling references during failover processing. - Application Hardening: . Added validation of remotely supplied filenames in the srt-file-transmit utility. Path separators, parent directory references, and platform-specific path manipulation patterns are now rejected before files are created. + Build and CI Security Enhancements: - Replaced the dynamic Codecov script download mechanism with a pinned and integrity-verified version. - Pinned ABI compatibility checker dependencies to specific versions and removed reliance on mutable default branches. - Improved GitHub workflow supply-chain protection by pinning third-party actions, container images, and external dependencies to known revisions. + Stability Improvements: - Fixed local connection teardown handling following rejected late handshakes, ensuring the local endpoint correctly terminates invalid connection states. - Improved error handling for FEC initialization failures and memory allocation exceptions, providing graceful connection rejection instead of abrupt failures. + Test Coverage: - Additional negative and security-focused test coverage has been added for: . Malformed KMRSP messages. . Encryption downgrade scenarios. . ACK validation. . DROPREQ malformed and reversed ranges. . FEC oversized payloads and invalid configurations. . Connection cleanup and shutdown paths. ==== sysextmgr ==== Version update (1.0.0+git20260429.bf44eec -> 1.3.0+git20260820.0628c3a) - Update to version 1.3.0+git20260820.0628c3a: * Release version 1.3.0 * ID_LIKE is optional, don't error out * Update ci-opensuse. remove outdated meson*.yml * Add a PCRE2 regular expression filter to list - Update to version 1.2.0+git20260817.3f4cd50: * Release version 1.2.0 * Remove .sysext for extension-release, too. * Ignore dangling symlinks in /etc/extensions * Fix manifest name for .sysext.raw images * Unlink meta data file in cache on error * Relax sysextmgr.service so that dissect does not need mountfsd * sysextmgr.service: Add CacheDirectory so it's writeable * Add bash completion for sysextmgrcli - Update to version 1.1.0+git20260811.c3fa27f: * Release version 1.1.0 * Support images ending with .sysext.raw ==== systemsettings6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * Update version for new release 6.7.4 ==== thin-provisioning-tools ==== - Refresh the vendored Rust crates: 62 changed version, two added (jiff-core, palette_math), three dropped (fast-srgb8 and the proc-macro-error2 pair); upstream sources are unchanged. - Re-derive License from the crates actually linked into the shipped binary: Apache-2.0 AND GPL-3.0-only AND MIT AND MPL-2.0 AND Unicode-3.0, and install each linked crate's licence text next to COPYING. - Move %check into a separate "test" multibuild flavour, so a test failure no longer blocks the binaries that the 88 dependent packages build against. - Add thin-provisioning-tools-tests-clap-single-alias.patch: the refreshed clap renders "alias" instead of "aliases" for a single alias, which broke two hardcoded thin_delta help assertions (gh#jthornber/thin-provisioning-tools#328). ==== timezone ==== - Install "right" files in SLES/Leap 16.x (bsc#1273508) ==== u-boot-rpiarm64 ==== Subpackages: u-boot-rpiarm64-doc - Add beaglevfire flavor ==== udisks2 ==== Version update (2.11.1 -> 2.11.2) Subpackages: libudisks2-0 - Update to 2.11.2 (CVE-2026-7867): * This is a bugfix release with a security fix, several crash and memory leak fixes, and mount options update. * Security fix: - CVE-2026-7867: An unprivileged D-Bus caller could use the 'as-user' Filesystem.Mount() option combined with fstab entries containing 'user' or 'users' mount options to mount on behalf of another user without polkit authorization. * Changes from 2.11.1: - udiskslinuxnvmenamespace: Report cancellation as error in format job - udiskslinuxprovider: Fix memory leak on spurious uevents - udiskslinuxprovider: Initialize GError pointer in sleep signal handler - udisksdaemonutil: Fix missing NULL terminator in resolve_links() - udiskslinuxdriveata: Add missing D-Bus method completion for SecurityEraseUnit - udiskslinuxfilesystem: Fix missing goto after mount state check in handle_resize - udiskslinuxfilesystem: Fix missing goto after mount state check in handle_repair - udiskslinuxfilesystem: Fix missing goto after mount state check in handle_check - udiskslinuxfilesystem: Fix mounted check in filesystem update - udiskslinuxmountoptions: Fix integer overflow in UID/GID option parsing - udiskslinuxmountoptions: Fix static buffer and hardcoded limit in is_uid_in_gid - doap: Update storaged.org https link - udisksmodulemanager: Fix broken module error check - lvm2: Fix NULL dereference in VG create uevent trigger loop - mount options: Sync exfat allowed options with the latest kernel - udiskslinuxfilesystem: Separate real caller identity from as-user target - udiskslinuxfilesystem: Rework fstab mount authorization for as-user - udiskslinuxfilesystem: Log real caller uid for as-user mounts - udisksdaemonutil: Pass as-user target to polkit details - tests: Add security tests for as-user mount authorization - tests: Trigger controller rescan after namespace re-attach in test_ns_detach - tests: Temporarily skip NTFS3 configurable mount options test ==== util-linux ==== Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 - Fix post installation message conditions (bsc#1268886#c17). ==== util-linux-systemd ==== Subpackages: lastlog2 liblastlog2-2 - Fix post installation message conditions (bsc#1268886#c17). ==== vim ==== Version update (9.2.0780 -> 9.2.0901) Subpackages: vim-data-common vim-small - gvim.desktop: Remove deprecated values - Update to 9.2.0901: 9.2.0781: tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir 9.2.0782: tests: missing cleanup in test_mksession.vim 9.2.0783: tests: personal spell files leak into later tests 9.2.0784: crash when borrowing statusline highlight in silent Ex mode 9.2.0785: WinResized not triggered when the whole Vim is resized 9.2.0786: filetype: Containerfile is not recognized 9.2.0787: regexp: code 0x1ecb duplicated for equivalence class 9.2.0788: filetype: hip files are not recognized 9.2.0789: 'statuslineopt' status line too high after a window is minimized 9.2.0790: 'completeslash' breaks :find completion with 'findfunc' 9.2.0791: wincol() counts from right side for 'rightleft' 9.2.0792: runtime(netrw): Explore without optional dir broken 9.2.0793: If session restored a tiny window, restore fails 9.2.0794: extend() and extendnew() don't handle NULL expr2 properly 9.2.0795: popup menu shadow is not cleared when the menu shrinks 9.2.0796: Visual block reselection wrong with 'virtualedit' 9.2.0797: Memory leak in get_qfline_items() on alloc failure 9.2.0798: Memory leak in compile_expr6() on alloc failure 9.2.0799: Memory leak in compile_def_function_body() on alloc failure 9.2.0800: Memory leak in call_func() on alloc failure 9.2.0801: Memory leak in f_getreginfo() on alloc failure 9.2.0802: Memory leak with list_append_dict/dict_add_list on alloc failure 9.2.0803: Memory leak on alloc failure with taglist/gettagstack() 9.2.0804: wincol() is wrong for a double-wide character with 'rightleft' 9.2.0805: screenpos() "curscol" is wrong with 'rightleft' 9.2.0806: 'showcmd' may show internal command keys 9.2.0807: MS-Windows: ellipsis character is garbled 9.2.0808: getregionpos: double-free on alloc failure 9.2.0809: getframelayout() uses wrong function to free lists 9.2.0810: add_llist_tags() uses wrong function to free dict 9.2.0811: mksession writes terminal command unquoted 9.2.0812: :argdelete with pattern leads to wrong argidx() 9.2.0813: dict_add_func() may corrupt funcref count on failure 9.2.0814: Vim9: E1041 when reloading an autoload script with exported variables 9.2.0815: deeply nested regexp patterns may cause stack overflow 9.2.0816: GTK4: Memory leak in gui_gtk_set_dnd_targets() 9.2.0817: crash when building a stacktrace during an autocommand 9.2.0818: tests: client-server test fails without X11 server 9.2.0819: MS-Windows: sixel image shown as raw text in the console 9.2.0820: GUI: hidden popup image is displayed and not erased 9.2.0821: filetype: msmtp system-wide rc file not detected 9.2.0822: GTK4: crash menu id is null in gui_mch_destroy_menu() 9.2.0823: tests: Test_clientserver_servlist_list may fail 9.2.0824: Makefile: Make tags depends on configure 9.2.0825: regexp: submatch in a look-behind is empty with the NFA engine 9.2.0826: highlighting for broken terminals can be improved 9.2.0827: :startinsert enters Insert mode in a non-modifiable buffer 9.2.0828: GTK4: hardware rendering can be improved 9.2.0829: Sessions do not preserve script version for expression options 9.2.0830: the completion menu is not used on terminals without colors 9.2.0831: diff highlighting hard to read with syntax enabled 9.2.0832: socketserver: remote commands can be processed in reverse order 9.2.0833: GTK4: menu mnemonics do not work properly 9.2.0834: cleared last search pattern is restored from viminfo 9.2.0835: features in version.c are not sorted 9.2.0836: filetype: .git-blame-ignore-revs file is not recognized 9.2.0837: Using wrong colors in hl_blend_attr() 9.2.0838: searchcount() returns wrong cached maxcount 9.2.0839: [security]: arbitrary code execution via keyword lookup 9.2.0840: [security]: code injection in netrw via bookmarks 9.2.0841: [security]: heap overflow when adding > 65535 text properties 9.2.0842: [security]: stack buffer overflow in socket server 9.2.0843: [security]: popup: opacity mask indexed out of bounds 9.2.0844: [security]: use-after-free on json decode error 9.2.0845: [security]: arbitrary Ex command execution during C omni-completion 9.2.0846: [security]: heap buffer overflow in set_sofo() 9.2.0847: [security]: vimball: code execution via .VimballRecord file 9.2.0848: tagfunc "cmd" with a generic Ex command corrupts the tag entry 9.2.0849: filetype: osquery config files are not recognized 9.2.0850: MS-Windows: commands from a client can be lost 9.2.0851: Focus autocommands triggered inconsistently 9.2.0852: GTK: ligatures not correctly displayed 9.2.0853: popup: popup images do not support scaling 9.2.0854: memory leak when reading a spell file with SN_SAL and SN_SOFO 9.2.0855: 'showcmd' not redrawn with empty mapping triggered on timeout 9.2.0856: GTK4: undercurl rendering is inefficient 9.2.0857: popup: opacity popup over a terminal is not cleared when closed 9.2.0858: MS-Windows GUI: white flash when VimEnter is slow 9.2.0859: GTK2: Link error 9.2.0860: filetype: xilinx design constraint files are not recognized 9.2.0861: GTK4: bleed region updates in jumps 9.2.0862: Missing test change from v9.2.0857 9.2.0863: MS-Windows GUI: window contents can be missing when VimEnter is slow 9.2.0864: Using some dead code in Wayland feature 9.2.0865: GTK4: non-hardware accelerated UI is too slow 9.2.0866: MS-Windows: ":language messages" only works once 9.2.0867: MS-Windows: messages are not in the display language 9.2.0868: GTK: Window Manager hint prevents giving focus to dialog 9.2.0869: buf_copy_options() can lose the P_INSECURE flag 9.2.0870: filetype: marko files are not recognized 9.2.0871: screen line is lost when splitting a 'winfixheight' window 9.2.0872: popup with opacity does not use the font of the highlight group 9.2.0873: :redrawstatus does not update the ruler of the last window 9.2.0874: fold size is compared against 'foldminlines' of the wrong window 9.2.0875: GTK4: GUI does not support command-line arguments 9.2.0876: GTK4: compile error with disabled netbeans feat 9.2.0877: Vim9: crash when a closure assigns to a variable declared in a loop ... changelog too long, skipping 24 lines ... 9.2.0901: textprop: wrong cursor line with truncated virtual text ==== wget ==== - Fix server-controlled unbounded MD5 loop in FTP OPIE [bsc#1276962; CVE-2026-16599] * CVE-2026-16599.patch - Fix segmentation fault in metalink4, bsc#1273449 * Fix-segfault-in-retrieve_from_metalink-when-a-metalink.patch ==== wpa_supplicant ==== Version update (2.11 -> 2.12) - Update to v2.12: * support RSN overriding (e.g., WPA3-Personal Compatibility Mode) * EHT/IEEE 802.11be/Wi-Fi 7 - more complete support - fix message validation issues that could enable DoS attacks - fix group key rekeying * enable SAE group 20 by default if SAE-EXT-KEY is enabled * reject unexpected SAE password identifier to avoid DoS attack against a specific STA * mandate use of SAE H2E when using password identifiers * assign VLAN when using SAE with PMKSA caching * support SPP A-MSDU negotiation * support IEEE 802.11bi functionality - changing SAE password identifiers - EPPKE - IEEE 802.1X/EAP in Authentication frames - Association frame encryption - PMKID privacy * remove the driver interface for now obsolete Host AP driver * remove the driver interface for now obsolete Atheros WEXT interface * move supported, basic, and Beacon TX rate configuration to be at BSS level instead of per-radio for all BSSs * fix various issues in Multiple-BSSID functionality * support OpenSSL 3.0 API changes * EAP-TEAP: protocol changes based on RFC 9930; this is not compatible with previous versions * support Automated Frequency Coordination (AFC) on the 6 GHz band * improve GAS/ANQP processing to support larger ANQP responses * a large number of other fixes, cleanup, and extensions * Remove included patches: - 0001-wpa_gui-Port-to-Qt6.patch - CVE-2025-24912.patch - CVE-2026-58374.patch - Require-network_ctx-and-AKMP-match-for-accepting-PMK.patch - SAE-Fix-crash-due-to-NULL-pointer-dereference-in-H2E.patch - mesh-Reject-AMPE-MIC-element-with-length-AES_BLOCK_S.patch - wpa_supplicant_support_pem_encoded_chain.patch * Refresh patches: - Revert-Mark-authorization-completed-on-driver-indica.patch - wpa_supplicant-alloc_size.patch - wpa_supplicant-flush-debug-output.patch - wpa_supplicant-sigusr1-changes-debuglevel.patch - Update build config * CONFIG_HE_OVERRIDES=y (Support HE overrides) * CONFIG_IPV6=y * CONFIG_SAE_PK=y (SAE Public Key, WPA3-Personal) * CONFIG_IEEE80211BE=y (enable native support for Wi-Fi 7) * CONFIG_PMKSA_PRIVACY=y (PMKSA caching privacy support) * CONFIG_IEEE8021X_AUTH=y (IEEE P802.11bi/D4.0, 12.16.5 ) * CONFIG_TLS_ENGINE_TRUSTED_PATH=y - Add RADIUS-Fix-Message-Authenticator-attribute-validatio.patch https://w1.fi/security/2026-5 ==== xdg-dbus-proxy ==== Version update (0.1.7 -> 0.1.8) - Update to version 0.1.8: + Fix broadcast messages bypassing path/interface/member checks + Improvements to the existing testing infrastructure + Add tests for owning names, issuing method calls, receiving messages - Add xdg-dbus-proxy-tests subpackage with installed tests for gnome-desktop-testing-runner ==== xdg-desktop-portal-kde6 ==== Version update (6.7.3 -> 6.7.4) - Update to 6.7.4: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.4 - Changes since 6.7.3: * screencast: Implement v5; provide mapping_id for eis users * globalshortcuts: Do not register shortcuts on session creation (kde#523063) * Update version for new release 6.7.4 ==== zstd ==== Subpackages: libzstd1 - Move the tests into a multibuild flavor: * speed up build from 1092s to 167s - important for bootstrap * only apply the constraint to tests for faster scheduling