<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-core, branch styhead</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=styhead</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=styhead'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2025-03-22T14:09:10+00:00</updated>
<entry>
<title>build-appliance-image: Update to styhead head revision</title>
<updated>2025-03-22T14:09:10+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2025-03-22T14:07:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=70dc28ac287bf35541270cae1d99130a0f6b7b5f'/>
<id>urn:sha1:70dc28ac287bf35541270cae1d99130a0f6b7b5f</id>
<content type='text'>
(From OE-Core rev: 2d94f4b8a852dc761f89e5106347e239382df5fb)

Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libxml2: upgrade 2.13.3 -&gt; 2.13.6</title>
<updated>2025-03-13T14:21:44+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2025-02-28T17:29:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=5b4f320c4465dc1cb221ebad7b55d3786f699824'/>
<id>urn:sha1:5b4f320c4465dc1cb221ebad7b55d3786f699824</id>
<content type='text'>
Handle CVE-2025-24928, CVE-2024-56171 and CVE-2025-27113.

(From OE-Core rev: 13929d3126572d3024afd58a914592e8e6ea8457)

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>build-appliance-image: Update to styhead head revision</title>
<updated>2025-02-21T22:08:09+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2025-02-21T22:06:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=11a8dec6e29ac0b2fd942c0fc00dd7fc30658841'/>
<id>urn:sha1:11a8dec6e29ac0b2fd942c0fc00dd7fc30658841</id>
<content type='text'>
(From OE-Core rev: 35ffa0ed523ba95f069dff5b7df3f819ef031015)

Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>systemd: set CVE_PRODUCT</title>
<updated>2025-02-12T14:29:33+00:00</updated>
<author>
<name>Mikko Rapeli</name>
<email>mikko.rapeli@linaro.org</email>
</author>
<published>2024-12-13T12:33:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=6b1572b4f2b571af70d3ace8de7cc15aab20273a'/>
<id>urn:sha1:6b1572b4f2b571af70d3ace8de7cc15aab20273a</id>
<content type='text'>
systemd.inc is used by systemd, systemd-boot and
systemd-tools-native recipes so make sure all
match to "systemd" product in CVE database. The
split between systemd, systemd-boot and
systemd-tools-native is specific to oe-core and
upstream just refers to systemd. Not limiting
to "systemd_project" vendor since multiple
vendor names have been used in the past.

(From OE-Core rev: d92c1ca1c89f140a731aec9f3389c2dad2f59829)

Signed-off-by: Mikko Rapeli &lt;mikko.rapeli@linaro.org&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit eb46ad379170f0a80ac2d061fa02c118f5ed1d31)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>build-appliance-image: Update to styhead head revision</title>
<updated>2025-01-13T13:51:50+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2025-01-13T13:49:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=ff9ca74e170480578fcdb1f7bcd897f0e69e46a5'/>
<id>urn:sha1:ff9ca74e170480578fcdb1f7bcd897f0e69e46a5</id>
<content type='text'>
(From OE-Core rev: 62dfe689246d648f9970a5476716e486b1a33765)

Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>expat: upgrade 2.6.3 -&gt; 2.6.4</title>
<updated>2025-01-13T13:49:08+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2024-11-11T19:04:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=efc539226865529cad106807fbf8cfaaba0fa18f'/>
<id>urn:sha1:efc539226865529cad106807fbf8cfaaba0fa18f</id>
<content type='text'>
Handle CVE-2024-50602

(From OE-Core rev: 690874991ca51b37bc0af262ba6c366ff72af13f)

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 5dc22afe3d2ea767f084b7c6e3625cb6edd66522)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>cve-update-nvd2-native: Handle BB_NO_NETWORK and missing db</title>
<updated>2025-01-13T13:49:08+00:00</updated>
<author>
<name>Mark Hatle</name>
<email>mark.hatle@amd.com</email>
</author>
<published>2024-11-12T21:23:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=3e7489546cf7c392f8a064e18b052b7746ba75b4'/>
<id>urn:sha1:3e7489546cf7c392f8a064e18b052b7746ba75b4</id>
<content type='text'>
The custom do_fetch routine is ignoring BB_NO_NETWORK, add a check for this
as the correct behavior for the user is to set:
  CVE_DB_UPDATE_INTERVAL = "-1"

If CVE_DB_UPDATE_INTERNAL is set to -1, check that a DB file exists, if not
we need to error so the user can deal with this.

Note, MIRRORs are NOT handled by this code.

(From OE-Core rev: 2bc4623a910dfa3a22cd054ea1e0f2dd59d74eea)

Signed-off-by: Mark Hatle &lt;mark.hatle@amd.com&gt;
Signed-off-by: Mathieu Dubois-Briand &lt;mathieu.dubois-briand@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 337c0806d2784d74bee8d6420fb8b4d48795d5fa)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>buildtools-docs-tarball: Add rsvg so we can handle svg files in docs</title>
<updated>2025-01-09T14:02:48+00:00</updated>
<author>
<name>Antonin Godard</name>
<email>antonin.godard@bootlin.com</email>
</author>
<published>2024-12-26T09:55:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=a1b9be34dba1c6fa369bbe5c1d3ec943f24d7379'/>
<id>urn:sha1:a1b9be34dba1c6fa369bbe5c1d3ec943f24d7379</id>
<content type='text'>
We need to convert svg into png in the docs build so add rsvg tools
to handle this.

(From OE-Core rev: 5dd1fdf4c3e8596c4e7c8cd57d371c2c1d4b0843)

Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Antonin Godard &lt;antonin.godard@bootlin.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>cve-update-nvd2-native: Tweak to work better with NFS DL_DIR</title>
<updated>2024-12-18T14:37:29+00:00</updated>
<author>
<name>Richard Purdie</name>
<email>richard.purdie@linuxfoundation.org</email>
</author>
<published>2024-12-18T11:56:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=bca4068948e4383cc18a24a3c224bbc339f7de2a'/>
<id>urn:sha1:bca4068948e4383cc18a24a3c224bbc339f7de2a</id>
<content type='text'>
After much debugging, the corruption issues on the autobuilder appear to
be due to the way sqlite accesses database files. It doesn't change the
file timestamp after making changes, which for reasons unknown, confuses
NFS. As soon as the file is touched, NFS becomes fine again accross the
whole cluster, as if by magic.

We could try and debug further but putting a "touch" call into the code
is easy and harmless. Lets hope this removes this annoying source of
errors.

(From OE-Core rev: 6e517366cda4c22547ed097ee58126f7dfc56a57)

Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>systemd-boot: drop intltool-native from DEPENDS</title>
<updated>2024-12-17T20:58:11+00:00</updated>
<author>
<name>Guðni Már Gilbert</name>
<email>gudni.m.g@gmail.com</email>
</author>
<published>2024-12-08T13:15:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=334ca4a275d7543ea8da2d60ff7aa20f67f2458c'/>
<id>urn:sha1:334ca4a275d7543ea8da2d60ff7aa20f67f2458c</id>
<content type='text'>
intltool was dropped as a dependency in v236
See commit for reference:
https://github.com/systemd/systemd/pull/7313/commits/c81217920effddc93fb780cf8f9eb699d6fe1319

(From OE-Core rev: 0df327ea64ec6a9e99c8f96e1dab52d3db3711b3)

Signed-off-by: Guðni Már Gilbert &lt;gudni.m.g@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
</feed>
