-
Notifications
You must be signed in to change notification settings - Fork 53
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Weekly portage-stable package updates 2023-07-03 #963
Weekly portage-stable package updates 2023-07-03 #963
Conversation
8c2dc53
to
098f04a
Compare
098f04a
to
74a5b72
Compare
CI passed. @dongsupark: Could you help me here with the binutils CVE fixes? I'm not sure I got them right. Thanks! |
Build action triggered: https://github.com/flatcar/scripts/actions/runs/5482921333 |
This PR also moves ncurses to portage-stable and updates openssh in overlay. |
Yes, it is already correct. |
Cool, so looking at flatcar/Flatcar#1053, CVE-2023-1972 and CVE-2023-2222 are still to be fixed? |
Oh, sorry. I missed one. However, CVE-2023-2222 is already fixed in binutils 2.40. |
2396ae4
to
5ad509b
Compare
Thanks, updated the changelog. |
It's from Gentoo commit a8d934769ffbdcab11a222ca978aad6b2ca2ee2e.
It's from Gentoo commit 7d84b6a194c63a687847147f72a5ce23f3cd0385.
It's from Gentoo commit 66156cb8007a8ee705a6a425693478753b33b86d.
It's from Gentoo commit 229d28a525799ae2f65b1a2cd206b07189241026.
It's from Gentoo commit c9f4376eb1b1ac1134fa71e74c52b53c594635c2.
It's from Gentoo commit cb8b981252e741096e9bf492471ba6fc6430b852.
It's from Gentoo commit eaa3e3d36f9b2638bd830dc03081aeff20788c2d.
It's from Gentoo commit 7101d1560334b0ae3f3376bf80fb59ffc63cfab0.
It's from Gentoo commit 41380cfb2273eee7424b09700cc2f60a00b220e6.
It's from Gentoo commit a373f2bb83fa3c4f7cd9d1a32fd3c3e81357d489.
We can reintroduce it to package update automation once all the selinux packages are kept in sync.
This reverts commit dd8c642794b4bfe3ae4febc614672a4703f36987. This is to avoid having semodule utils package to be out of sync with the rest of the selinux packages.
It became stable for amd64 too.
Signed-off-by: Sayan Chowdhury <[email protected]>
It's from Gentoo commit 7a8c3fa265d02fa74b8881a4dca3cfeb9d8a938c. The modifications we did were upstreamed (under different USE flags that we already properly set up), so no point it keeping the package in overlay.
It's from Gentoo commit 43348efe8ab4717f8de578efba367fa040c5f8db.
It's from Gentoo commit 283c5b9f3c228c265a8913f0f29d98c6e3a9781b.
It's from Gentoo commit 912850f59174a65693859c4a171ef5e98fbdab6b.
- Mark the package as stable. - Remove the socket unit's rate limiting. - Fixes to configuration handling. We are trying to upstream these changes, so this package will be eventually moved to portage-stable. But updating it in coreos-overlay for now to drop the use of the obsolete cygwin USE flags. Upstream PR: gentoo/gentoo#31615
We still use the single config file. The change for using drop-in files will come later.
It's from Gentoo commit 59bbe6a1e11645b4e6865c1575ade11ec21bc940.
5ad509b
to
bdf020c
Compare
CI: http://jenkins.infra.kinvolk.io:8080/job/container/job/sdk/910/cldsv
--
app-arch/bzip2: [PROD] [DEV]
app-crypt/rhash:
app-editors/vim: [PROD] [DEV]
app-editors/vim-core: [PROD] [DEV]
app-emulation/qemu: [PROD] [DEV]
app-portage/portage-utils
app-shells/bash: [PROD] [DEV]
dev-db/sqlite: [PROD] [DEV]
devl-lang/lua: [PROD] [DEV]
dev-lang/perl:
dev-lang/python: [DEV]
dev-libs/elfutils: [PROD] [DEV]
dev-libs/glib: [PROD] [DEV]
dev-libs/libassuan: [PROD] [DEV]
dev-libs/libgpg-error: [PROD] [DEV]
dev-libs/libksba: [PROD] [DEV]
dev-libs/libpcre2: [PROD] [DEV]
dev-libs/nettle: [PROD] [DEV]
dev-libs/oniguruma: [PROD] [DEV]
dev-python/cython:
dev-python/docutils:
dev-python/inflect:
dev-python/jaraco-functools:
dev-python/platformdirs:
dev-python/pydantic:
dev-python/setuptools:
dev-python/typing-extensions:
dev-util/b2:
dev-util/bpftool: [PROD] [DEV]
dev-util/cmake:
dev-util/gdbus-codegen:
dev-util/glib-utils:
dev-util/meson:
dev-util/pahole [DEV]
dev-util/perf:
dev-util/pkgconf:
dev-util/re2c:
dev-util/strace: [PROD] [DEV]
eclass/acct-group:
eclass/acct-user:
eclass/cmake:
eclass/distutils-r1:
eclass/elisp-common:
eclass/python-utils-r1:
eclass/toolchain:
licenses:
media-libs/libpng:
net-analyzer/nmap: [PROD] [DEV]
net-libs/libpcap: [PROD] [DEV]
net-misc/curl: [PROD] [DEV]
net-misc/iputils: [PROD] [DEV]
net-misc/openssh (OVERLAY): [PROD] [DEV]
profiles:
sys-apps/acl: [PROD] [DEV]
sys-apps/coreutils: [PROD] [DEV]
sys-apps/ethtool: [PROD] [DEV]
sys-apps/iproute2: [PROD] [DEV]
sys-apps/kbd: [DEV]
sys-apps/kexec-tools: [PROD] [DEV]
sys-apps/less: [PROD] [DEV]
sys-apps/man-pages: [DEV]
sys-apps/net-tools: [PROD] [DEV]
sys-apps/nvme-cli: [PROD] [DEV]
sys-apps/portage: [DEV]
sys-apps/sandbox: [DEV]
sys-apps/util-linux: [PROD] [DEV]
sys-devel/autoconf:
sys-devel/binutils: [PROD] [DEV]
sys-devel/crossdev:
sys-devel/gcc: [PROD] [DEV]
sys-devel/gcc-config: [DEV]
sys-devel/gettext: [PROD] [DEV]
sys-fs/e2fsprogs: [PROD] [DEV]
sys-kernel/linux-headers: [PROD] [DEV]
sys-libs/binutils-libs: [PROD] [DEV]
sys-libs/ncurses: [PROD] [DEV]
addwrite /dev/ptmx
to avoid sandbox failuressys-libs/readline: [PROD] [DEV]
virtual/libc: [DEV]
virtual/os-headers: [DEV]
--