summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
* python3-django: upgrade 5.2.8 -> 5.2.9Gyorgy Sarvari2025-12-201-1/+1
| | | | | | | | | Includes fix for CVE-2025-13372 and CVE-2025-64460 Changelog: https://github.com/django/django/blob/5.2.9/docs/releases/5.2.9.txt Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* fetchmail: upgrade 6.5.2 -> 6.6.2Gyorgy Sarvari2025-12-201-2/+2
| | | | | | | | | | | Contains fix for CVE-2025-61962. License-Update: added a warning about linking against the newly relicensed WolfSSL. Changelog: https://gitlab.com/fetchmail/fetchmail/-/blob/6.6.2/NEWS Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* unbound: complete ptest supportGyorgy Sarvari2025-12-163-5/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The recipe had already an almost working ptest config which wasn't enabled, it just needed some small fixes to make it work: correct the output of the run-ptest script, and install some extra testdata. Execution is quick, single digit seconds: root@qemux86-64:/usr/lib/unbound/ptest/tests# ptest-runner START: ptest-runner 2025-12-16T11:53 BEGIN: /usr/lib/unbound/ptest Start of unbound 1.24.2 unit test. test authzone functions test negative cache functions test ub_random functions [...many lines...] PASS: ./testdata/val_unsecds_negcache.rpl PASS: ./testdata/val_unsecds_qtypeds.rpl PASS: ./testdata/val_wild_pos.rpl PASS: ./testdata/version_bind.rpl PASS: ./testdata/version_bind_hide.rpl PASS: ./testdata/views.rpl DURATION: 4 END: /usr/lib/unbound/ptest 2025-12-16T11:53 STOP: ptest-runner TOTAL: 1 FAIL: 0 Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* unbound: upgrade 1.22.0 -> 1.24.2Gyorgy Sarvari2025-12-162-52/+2
| | | | | | | | | | | | | | | | Contains fixes for CVE-2025-11411 and CVE-2025-5994. Drop patch that was incorporated in this release. Changelogs: https://github.com/NLnetLabs/unbound/releases/tag/release-1.24.2 https://github.com/NLnetLabs/unbound/releases/tag/release-1.24.1 https://github.com/NLnetLabs/unbound/releases/tag/release-1.24.0 https://github.com/NLnetLabs/unbound/releases/tag/release-1.23.1 https://github.com/NLnetLabs/unbound/releases/tag/release-1.23.0 Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* libcoap: ignore CVE-2025-50518Gyorgy Sarvari2025-12-161-0/+2
| | | | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2025-50518 The vulnerability is disputed by upstream, because the vulnerability requires a user error, incorrect library usage. See also an upstream discussion in a related (rejected) PR: https://github.com/obgm/libcoap/pull/1726 Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* python3-chromecast: upgrade 14.0.7 -> 14.0.9Tom Geelen2025-12-165-117/+2
| | | | | | | | | Changelog: https://github.com/home-assistant-libs/pychromecast/releases/tag/14.0.9 Drop obsolete patches. Signed-off-by: Tom Geelen <t.f.g.geelen@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* python3-aiohttp: add optional PACKAGECONFIG for the extras mentioned in the ↵Tom Geelen2025-12-161-1/+4
| | | | | | | build requirements Signed-off-by: Tom Geelen <t.f.g.geelen@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* python3-aiohttp: add BBCLASSEXTEND: native and nativesdk to the recipeTom Geelen2025-12-161-0/+2
| | | | | Signed-off-by: Tom Geelen <t.f.g.geelen@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* python3-aiohttp: upgrade 3.12.15 -> 3.12.2Tom Geelen2025-12-161-2/+2
| | | | | Signed-off-by: Tom Geelen <t.f.g.geelen@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* python3-async-timeout: add BBCLASSEXTEND for native and nativesdkTom Geelen2025-12-161-0/+2
| | | | | | Signed-off-by: Tom Geelen <t.f.g.geelen@gmail.com> Reviewed-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* openvpn: upgrade 2.6.16 -> 2.6.17Gyorgy Sarvari2025-12-161-1/+1
| | | | | | | | | | | | | | Changelog: - Windows/interactive service: fix erroneous exit on error that could be used by a local Windows users to achieve a local denial-of-service (CVE-2025-13751) - Windows/interactive service: improve service pipe robustness against file access races (uuid) and access by unauthorized processes (ACL). upgrade bundled build instruction (vcpkg and patch) for pkcs11-helper to 1.31, fixing a parser bug Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* minio: ignore irrelevant CVEsGyorgy Sarvari2025-12-161-0/+6
| | | | | | | | | | | | | The minio umbrella covers multiple projects. The recipe itself builds "minio client", which is a set of basic tools to query data from "minio server" - like ls, mv, find... The CVEs were files against minio server. Looking at the go mod list, this recipe doesn't use minio server even as a build dependency - so ignore the CVEs. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* botan: add ptest supportGyorgy Sarvari2025-12-163-3/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The test suite takes just around 30s to execute. Sample output: root@qemux86-64:~# ptest-runner START: ptest-runner 2025-12-15T19:02 BEGIN: /usr/lib/botan/ptest PASS: AES-128/CCM(10,2) PASS: AES-128/CCM(12,2) PASS: AES-128/CCM(14,2) PASS: AES-128/CCM(16,2) PASS: AES-128/CCM(16,3) PASS: AES-128/CCM(16,4) [...lots of lines...] PASS: XMSS/SHAKE_16_512 verify invalid signature PASS: XMSS/SHAKE_20_256 verify invalid signature PASS: XMSS/SHAKE_20_512 verify invalid signature PASS: ZFEC encoding/decoding Tests complete ran 3375688 tests in 28.38 sec all tests ok DURATION: 29 END: /usr/lib/botan/ptest 2025-12-15T19:02 STOP: ptest-runner TOTAL: 1 FAIL: 0 Tested also by forcing some tests to fail, which was also displayed correctly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* imagemagick: upgrade 7.1.2-8 -> 7.1.2-11Gyorgy Sarvari2025-12-161-1/+1
| | | | | | | Contains fix for CVE-2025-65955 Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* postgresql: upgrade 17.6 -> 17.7Gyorgy Sarvari2025-12-162-3/+3
| | | | | | | | | | It contains fixes for CVE-2025-12817 and CVE-2025-12818. Changelog: https://www.postgresql.org/docs/release/17.7/ Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* fio: ignore CVE-2025-10824Gyorgy Sarvari2025-12-161-0/+2
| | | | | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2025-10824 The upstream maintainer wasn't able to reproduce the issue[1], and the related bug is closed without further action. [1]: https://github.com/axboe/fio/issues/1981 Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* libwebsockets: upgrade 4.3.5 -> 4.5.2Peter Marko2025-12-163-1590/+5
| | | | | | | | | | | | | | | Handles CVE-2025-11677, CVE-2025-11678, CVE-2025-11679 and CVE-2025-11680. * drop patches included in this release * update license * add packageconfig for examples as those don't build License-Update: added new license, see: https://libwebsockets.org/git/libwebsockets/commit?id=e3dca87f23e8f783e1008b54829b39f9d7b083df Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* libopus: Make ne10 dependency to be target specific for arm/arm64Khem Raj2025-12-141-3/+3
| | | | | | | | | | | | This ends up in the native/nativesdk depchains especially when building on arm64 build hosts. Fixes errors e.g. WARNING: Nothing RPROVIDES 'nativesdk-libopus-dev' (but virtual:nativesdk:/srv/build/yoe/sources/meta-openembedded/meta-oe/recipes-multimedia/libopus/libopus_1.5.2.bb RDEPENDS on or otherwise requires it) No eligible RPROVIDERs exist for 'nativesdk-libopus-dev' Signed-off-by: Khem Raj <raj.khem@gmail.com>
* libconfig: drop recipeGyorgy Sarvari2025-12-143-63/+0
| | | | | | | | The recipe has been moved to oe-core: https://git.openembedded.org/openembedded-core/commit/?id=1a0196a794f8858c4715871558e97c3d69deb19e Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* nopoll: Upgrade to 0.4.7.b429Jason Schonberg2025-12-141-2/+1
| | | | | Signed-off-by: Jason Schonberg <schonm@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* kexec-tools-klibc: Update to latest 2.0.32 releaseKhem Raj2025-12-1435-461/+461
| | | | | | | | Add riscv64 support Rework klibc support patches Signed-off-by: Khem Raj <raj.khem@gmail.com> Cc: Andrea Adami <andrea.adami@gmail.com>
* uutils-coreutils: upgrade 0.4.0 -> 0.5.0Etienne Cordonnier2025-12-142-175/+121
| | | | | | | See https://github.com/uutils/coreutils/releases/tag/0.5.0 Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* wavpack: Delete unused patchesKhem Raj2025-12-142-61/+0
| | | | Signed-off-by: Khem Raj <raj.khem@gmail.com>
* vk-gl-cts: Delete unused patchKhem Raj2025-12-141-47/+0
| | | | Signed-off-by: Khem Raj <raj.khem@gmail.com>
* openocd: Delete unused patchKhem Raj2025-12-141-38/+0
| | | | Signed-off-by: Khem Raj <raj.khem@gmail.com>
* geany-plugins: Delete unused patchesKhem Raj2025-12-143-102/+0
| | | | Signed-off-by: Khem Raj <raj.khem@gmail.com>
* initramfs-kexecboot-klibc-image: Skip for riscv32Khem Raj2025-12-131-0/+2
| | | | | | klibc is not yet ported to riscv32 Signed-off-by: Khem Raj <raj.khem@gmail.com>
* packagegroups: Remove packages not yet ported onto riscv32Khem Raj2025-12-133-1/+6
| | | | Signed-off-by: Khem Raj <raj.khem@gmail.com>
* dav1d: update 1.5.1 -> 1.5.2Markus Volk2025-12-131-3/+2
| | | | | | | | | | | | | | | | | | | Changes for 1.5.2 'Sonic': -------------------------- 1.5.2 is a minor release of dav1d, focused on maintenance: - minor speed improvement in recon - improvements on loongarch symboles visibility and asm - mark C globals with small code model - reduce the code size of the frame header parsing (OBU) - minor fixes on tools and CI - fix compilation with nasm 3.00 Copyright year has been changed: https://github.com/videolan/dav1d/commit/04faac69004ac951b74ac7fea331f3790ec043b8 Signed-off-by: Markus Volk <f_l_k@t-online.de> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* ripgrep: limit libstd-rs DEPENDS to class-targetDeepesh Varatharajan2025-12-121-1/+1
| | | | | | | | Avoid pulling in a non-existent libstd-rs-native dependency by restricting libstd-rs to class-target builds. Signed-off-by: Deepesh Varatharajan <Deepesh.Varatharajan@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* c-ares: upgrade 1.34.5 -> 1.34.6Jason Schonberg2025-12-122-23/+1
| | | | | | | | | | | Drop memory leak patch which has already been included in this new version. The new version also includes a fix for CVE 2025-62408. Changelog: https://github.com/c-ares/c-ares/releases/tag/v1.34.6 Signed-off-by: Jason Schonberg <schonm@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* spandsp: Update to tip of trunkKhem Raj2025-12-113-44/+39
| | | | | | | New clang needs fixes which are in upstream tip, secondly refresh the patches to work with latest code Signed-off-by: Khem Raj <raj.khem@gmail.com>
* cockpit: upgrade 349 -> 352Jason Schonberg2025-12-111-1/+1
| | | | | | | | | | | | | | | | 352 Shown a warning if the last shutdown/reboot was unclean Bug fixes and translation updates 351 Firewall ports can be deleted individually 350 networking: fix renaming of bridges and other groups (RHEL-117883) bridge: fix OpenSSH_10.2p1 host key detection Signed-off-by: Jason Schonberg <schonm@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* Revert "proj: Fix do_package QA issue for unshipped bash-completion files"Peter Kjellerstedt2025-12-111-3/+1
| | | | | | | | | | | | | | | | | | This reverts commit 1175d5c8c13d73568d4ab55a3cf628456fcc1a7d. Since this recipe inherits bash-completion, adding ${datadir}/bash-completion to FILES:${PN} should not be needed (in addition to being the wrong thing to do as the files are expected to be packaged in the ${PN}-bash-completion package). The reason the problem addressed in commit 1175d5c8c13d73568d4ab55a3cf628456fcc1a7d turned up is due to the recent change to the bash-completion bbclass, where it started to use PACKAGE_BEFORE_PN. This clashed with the lib_package bbclass, which used to set rather than add to PACKAGE_BEFORE_PN, and since it is inherited after bash-completion, it overrid what bash-completion does. Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* conf/version-check.conf: skip version check for glslangYi Zhao2025-12-111-0/+1
| | | | | | | | | | | | | | There are two different types of tags in glslang git repo. One is the release tag of the project itself: 15.2.0, 14.3.0, etc. The other tag is for Vulkan SDK: vulkan-sdk-1.4.309, vulkan-sdk-1.4.304.1, etc. The vulkan sdk tag is used for glslang in openembedded-core because it needs to update in locksetup with vulkan, which leads to a mismatch between the runtime version and the build version. Set CHECK_VERSION_PV for it to skip the version check. Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* vulkan-cts: upgrade 1.4.4.0 -> 1.4.4.2Dmitry Baryshkov2025-12-114-36/+45
| | | | | | | | Upgrade Vulkan CTS to the point release, fixing several tests. While we are at it, refresh Vulkan-Video-Samples patches. Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* freediameter: Add 600s timeout via ctest driverKhem Raj2025-12-101-2/+2
| | | | | | | | | This helps tests not hitting timeout (120s default) especially testmesg_stress test can timeout on slower machines e.g. fully emulated ( non-kvm ) qemu machines e.g. qemuarm64 on x86_64 machine. Signed-off-by: Khem Raj <raj.khem@gmail.com>
* fd-find: Fix build on riscv32Khem Raj2025-12-102-3/+30
| | | | | Signed-off-by: Khem Raj <raj.khem@gmail.com> Cc: Deepesh Varatharajan <Deepesh.Varatharajan@windriver.com>
* aom: Upgrade to 3.13.1Khem Raj2025-12-102-4/+44
| | | | | | | * Fix build with nasm 3.01 * Improved VOD encoding and RTC encoding performance Signed-off-by: Khem Raj <raj.khem@gmail.com>
* opencv: fill in missing FastCV gapsDmitry Baryshkov2025-12-101-1/+6
| | | | | | | | | | | | | | | | | When OpenCV is being built with the "fastcv" packageconfig, several OpenCV libs are linked against the libfastcv.a. At runtime this lib will dlopen(libfastcvopt.so.1), providing a fallback to slow algorithms, etc. However as it is dlopen() rather than dynamic linking, there is no runtime dependency. In Yocto, if we enable a feature, we expect that all runtime dependencies are pulled in. Utilize the qcom-fastcv-binaries recipe provided by the meta-qcom layer and pull in libfastcvopt1 package as required. Cc: Pulkit Singh Tak <ptak@qti.qualcomm.com> Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* rwmem: Add HOMEPAGE variableWeisser, Pascal2025-12-101-0/+1
| | | | | | | Add HOMEPAGE variable to rwmem recipe. Signed-off-by: Weisser, Pascal <pascal.weisser.ext@karlstorz.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* can-utils: Add HOMEPAGE variableWeisser, Pascal2025-12-101-0/+1
| | | | | | | Add HOMEPAGE variable to can-utils recipe. Signed-off-by: Weisser, Pascal <pascal.weisser.ext@karlstorz.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* pointercal: Add HOMEPAGE variableWeisser, Pascal2025-12-101-0/+1
| | | | | | | Add HOMEPAGE variable to pointercal recipe. Signed-off-by: Weisser, Pascal <pascal.weisser.ext@karlstorz.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* vboxguestdrivers: Add HOMEPAGE variableWeisser, Pascal2025-12-101-0/+1
| | | | | | | Add HOMEPAGE variable to vboxguestdrivers recipe. Signed-off-by: Weisser, Pascal <pascal.weisser.ext@karlstorz.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* v4l-utils: Add HOMEPAGE variableWeisser, Pascal2025-12-101-0/+1
| | | | | | | Add HOMEPAGE variable to v4l-utils recipe. Signed-off-by: Weisser, Pascal <pascal.weisser.ext@karlstorz.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* polkit-group-rule.inc: Add HOMEPAGE variableWeisser, Pascal2025-12-101-0/+2
| | | | | | | Add HOMEPAGE variable to polkit-group-rule-* recipes. Signed-off-by: Weisser, Pascal <pascal.weisser.ext@karlstorz.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* upower: Add HOMEPAGE variableWeisser, Pascal2025-12-101-0/+1
| | | | | | | Add HOMEPAGE variable to upower recipe. Signed-off-by: Weisser, Pascal <pascal.weisser.ext@karlstorz.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* trace-cmd: Add HOMEPAGE variableWeisser, Pascal2025-12-101-0/+1
| | | | | | | Add HOMEPAGE variable to trace-cmd recipe. Signed-off-by: Weisser, Pascal <pascal.weisser.ext@karlstorz.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* libgpiod: Add HOMEPAGE variableWeisser, Pascal2025-12-101-0/+1
| | | | | | | | Add HOMEPAGE variable to libgpiod recipe. Signed-off-by: Weisser, Pascal <pascal.weisser.ext@karlstorz.com> Reviewed-by: Bartosz Golaszewski <brgl@bgdev.pl> Signed-off-by: Khem Raj <raj.khem@gmail.com>
* minicoredumper: fix 2038 year problem in timestamp handlingJiaying Song2025-12-102-0/+56
| | | | | | | | | | | | | | | | The minicoredumper has multiple 2038 year problems where 'long' type variables and strtol() function calls cause overflow on 32-bit systems when handling timestamps after 2038-01-19. This leads to incorrect timestamp formatting in core dump directory names (e.g., sleep40s.20380119.031407+0000.598). Fix by changing 'long timestamp' to 'time_t timestamp' and replacing strtol() with strtoll() to properly handle 64-bit timestamps on 32-bit systems. Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>