Commit Graph
38391 Commits
Author SHA1 Message Date
Ankur Tyagi 413d02b30e editorconfig-core-c: patch CVE-2026-40489
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-40489

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:56 +05:30
Ankur Tyagi 5910f812d1 editorconfig-core-c: ignore CVE-2024-53849
PR[1] mentioned in the NVD[2] is already part of the upstream version.

[1] https://github.com/editorconfig/editorconfig-core-c/pull/103
[2] https://nvd.nist.gov/vuln/detail/cve-2024-53849

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:55 +05:30
Ankur Tyagi 86a9ad852a dovecot: ignore already fixed CVEs
Upstream has confirmed that these vulnerabilities are fixed,
and Debian has also identified the relevant commits:

CVE-2025-59028: https://security-tracker.debian.org/tracker/CVE-2025-59028
CVE-2025-59032: https://security-tracker.debian.org/tracker/CVE-2025-59032
CVE-2026-27859: https://security-tracker.debian.org/tracker/CVE-2026-27859
CVE-2026-27851: https://security-tracker.debian.org/tracker/CVE-2026-27851
CVE-2026-33603: https://security-tracker.debian.org/tracker/CVE-2026-33603
CVE-2026-40016: https://security-tracker.debian.org/tracker/CVE-2026-40016
CVE-2026-40020: https://security-tracker.debian.org/tracker/CVE-2026-40020
CVE-2026-42006: https://security-tracker.debian.org/tracker/CVE-2026-42006

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:55 +05:30
Ankur Tyagi 53bbf2771b dool: patch CVE-2026-56652
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-56652

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:54 +05:30
Ankur Tyagi 2e1445decd dool: patch CVE-2026-56651
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-56651

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:54 +05:30
Ankur Tyagi cb309d1197 cockpit: mark CVE-2024-2947 patched
commit[1] fixing the CVE is part of the upstream version.

Details:
https://nvd.nist.gov/vuln/detail/cve-2024-2947

Fixes:
WARNING: cockpit-352-r0 do_sbom_cve_check_recipe: cockpit-352: Found unpatched CVEs: CVE-2024-2947

[1] https://github.com/cockpit-project/cockpit/commit/9c4cc9b6df632082538b53bdc8ee9ec1c5cad4da

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:53 +05:30
Ankur Tyagi dcdea72daf bcc: mark CVE-2024-2314 patched
Details:
https://nvd.nist.gov/vuln/detail/cve-2024-2314

Fixes:
WARNING: bcc-0.36.1-r0 do_sbom_cve_check_recipe: bcc-0.36.1: Found unpatched CVEs: CVE-2024-2314

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:53 +05:30
Ankur Tyagi 319e05d92a bubblewrap: mark CVE-2026-41163 patched
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-41163

Fixes:
WARNING: bubblewrap-0.11.2-r0 do_sbom_cve_check_recipe: bubblewrap-0.11.2: Found unpatched CVEs: CVE-2026-41163

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:53 +05:30
Ankur Tyagi 7a26befb15 capnproto: ignore CVE-2026-59704
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-59704

Fixes:
WARNING: capnproto-1.4.0-r0 do_sbom_cve_check_recipe: capnproto-1.4.0: Found unpatched CVEs: CVE-2026-59704

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:52 +05:30
Ankur Tyagi 3d4c0a43e7 proftpd: upgrade 1.3.9c -> 1.3.9d
Changelog:
https://github.com/proftpd/proftpd/blob/v1.3.9d/NEWS

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit f4b73e8ec1)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:52 +05:30
Jason Schonberg 9a79c379b9 php: upgrade 8.5.9 -> 8.5.10
This is a bug fix release.

Changelog: https://www.php.net/ChangeLog-8.php#8.5.10

Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit e5f8c8d53a)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:51 +05:30
Ankur Tyagi 581dced0d0 asyncmqtt: upgrade 10.3.0 -> 10.3.1
Changelog:
https://github.com/redboltz/async_mqtt/releases/tag/10.3.1

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 965ab7088d)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-15 07:51:51 +05:30
Abhishek Bachiphale a962aa88d3 thrift: fix CVE-2026-58662
Improper Validation of Specified Quantity in Input, Out-of-bounds Read
vulnerability in Apache Thrift C++ bindings. This issue affects Apache
Thrift: before 0.24.0.

Backport patch to fix CVE-2026-58662.

Reference:
[https://nvd.nist.gov/vuln/detail/cve-2026-58662]

Upstream Patch:
[https://github.com/apache/thrift/commit/f961cdb44249c293fcce6a840ffa1f7419fd88d0]

Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:18 +05:30
Ankur Tyagi f311c7bdfc python3-django: upgrade 5.2.16 -> 5.2.17
Release Notes:
https://docs.djangoproject.com/en/dev/releases/5.2.17/

CVE: CVE-2026-15307 CVE-2026-15337 CVE-2026-15830 CVE-2026-15920

Backport Changes:
- Django 5.2.17 requires setuptools >= 83, the first
  upstream release containing the fix [1]. Wrynose provides
  setuptools 82.0.1 with that fix backported, so retain the
  previous build requirement.

[1] https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 8a4bf31e7f)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:17 +05:30
Devansh Patel 5250a6f557 python3-cbor2: use exact CVE_PRODUCT mapping
The product-only "cbor2" mapping uses a wildcard vendor. Use
"agronholm:cbor2", its NVD dictionary CPE and NVD configuration
identity for the packaged source.

The generated CPE changes, but Wrynose sbom-cve-check 1.3.1 with its
pinned 2026-05-07 databases has no current CVE report delta. This
backport applies the change to version 5.9.0 rather than 6.1.4.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 7f59d247ee)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:17 +05:30
Himanshu Jadon d7e93ab171 suitesparse: avoid install rpath buildpaths QA
SuiteSparse adds -Wl,-rpath=$(INSTALL_LIB) while linking shared
libraries on Linux. In the OpenEmbedded build this value can resolve to
a build or install path under TMPDIR, so installed ELF files can keep an
absolute build path and fail buildpaths QA.

The packaged libraries do not need this install-tree rpath. Runtime
resolution is handled through normal package dependencies and the target
library search path. Keep the librt link and drop only the rpath entry.

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 47037e87d5)
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:16 +05:30
Himanshu Jadon 5a65844a4e suitesparse: fix CMake 4 configure failure
SuiteSparse 5.10.1 still carries bundled CMake entry points with
2.x minimum versions. CMake 4 rejects projects which request
compatibility with versions older than 3.5, so configure fails before
SuiteSparse can build.

Backport the upstream SuiteSparse change which raises the bundled
Mongoose, METIS and GKlib minimum version to 3.13. This version also
reaches two bundled GraphBLAS CMake entry points with the same old
minimum, so update those in the backport as well.

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit de2fc817a4)
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:16 +05:30
Khem Raj 14282a02be libhtml-tree-perl, libmodule-build-tiny-perl: Drop obsolete TMPDIR scrubbing
oe-core 3c2bb7bce1 ("cpan_build: disable .packlist and html doc") moved
--create_packlist=0 into cpan_build.bbclass and disabled html doc
generation there as well. Neither .packlist nor the html docs are
generated anymore, so the do_install:append() hooks that sed'ed TMPDIR out
of them now run find(1) over paths that no longer exist and hand sed an
empty argument list:

  find: '.../image/usr/share/doc/perl/html/site/lib/HTML/': No such file or directory
  sed: no input files
  WARNING: exit code 4 from a shell command.

Remove the now dead hooks.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 9dc293d14d)
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-26 07:13:01 +05:30
Devansh Patel 4ddd1e3945 python3-httplib2: correct CVE_PRODUCT mapping
The current product-only "httplib2" mapping generates a wildcard-vendor
product identity instead of the vendor assigned to the packaged project.

Use "httplib2_project:httplib2" for its exact NVD dictionary CPE and NVD
configuration identity. This changes the generated CPE, but sbom-cve-check
1.3.3 with the pinned NVD database snapshot has no current CVE report delta.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 0a8f71a643)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 13:03:48 +05:30
Devansh Patel ecbab436e2 python3-web3: add CVE_PRODUCT mapping
The current inherited "python:web3" mapping does not match the web3.py identities used by NVD and CVE List V5, so its source-aligned CVE is missed.

Use "ethereum:web3.py" for the CNA affected-data identity and "apeworx:web3.py" for the NVD dictionary CPE and configuration identity.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 19ecb40f50)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 13:01:24 +05:30
Ankur Tyagi a02e847fa2 swagger-ui: upgrade 5.32.13 -> 5.32.14
Changelog:
https://github.com/swagger-api/swagger-ui/releases/tag/v5.32.14

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:12 +05:30
Khem Raj f136fe167f samba: upgrade 4.23.8 -> 4.23.11
Stay within the 4.23.x stable series (do not touch the sibling
talloc/tdb/tevent/ldb recipes). This picks up two intervening point
releases:

- 4.23.9: bug-fix release (use-after-free in ACL claims/conditions
  handling, CTDB read-only record use-after-free/resource leak, RODC
  auth fixes, among others).
- 4.23.10: security release fixing CVE-2026-6949 (TSIG/DNS OOB write
  crash), CVE-2026-58216 (KDC kpasswd OOB read crash),
  CVE-2026-58218 (DNS TKEY cache-flood DoS), CVE-2026-58221 (LDAP
  privilege escalation via internal LDB special DNs),
  CVE-2026-58222 (LDAP Compare filter used as protected-attribute
  disclosure oracle) and CVE-2026-58224 (CTDB protocol
  bounds-checking gaps).
- 4.23.11: further bug fixes (DRS memory leak, pthreadpool fork race,
  RODC/NTLMv2 trust fixes, CephFS vfs crashes).

All 13 existing patches (including the musl-only pam/getpwent_r ones)
still apply cleanly against 4.23.11 with offset only, no fuzz, so none
needed to be reworked or dropped. LIC_FILES_CHKSUM for COPYING is
unchanged.

Build-verified with cleansstate + full build for qemux86-64.

AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit f971f62ef1)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:12 +05:30
Wang Mingyu 56fc67a07e swagger-ui: upgrade 5.32.12 -> 5.32.13
Changelog:
===========
- a11y: add aria-labels to copy-to-clipboard buttons
- a11y: add skip-to-operations link, banner and main landmarks
- a11y: close Authorization popup with Escape key and backdrop click
- a11y: name and state for dark-mode toggle button
- a11y: restore icon visibility in Windows High Contrast Mode
- a11y: topbar logo and dark-mode toggle visible in HCM
- a11y: use for model titles to convey emphasis semantically
- ci: bump cycjimmy/semantic-release-action to v6.0.0
- ci: fix Trivy security scan and add dependency vulnerability scan
- style: reduce padding on inline code blocks in markdown

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit e0346def92)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:11 +05:30
Ankur Tyagi 2af3c02179 swagger-ui: upgrade 5.32.11 -> 5.32.12
Also updated branch in the SRC_URI.

Changelog:
https://github.com/swagger-api/swagger-ui/releases/tag/v5.32.12

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit ff75d96062)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:11 +05:30
Ankur Tyagi 8990cb5a3c cjose: upgrade 0.6.2.7 -> 0.6.2.8
Drop patch that is part of the upstream version.

Changelog:
https://github.com/OpenIDC/cjose/releases/tag/v0.6.2.8

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit b7c1c19585)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:11 +05:30
Khem Raj 8eaa3ca840 python3-psycopg: upgrade 3.3.3 -> 3.3.4
Point release with bug fixes and minor improvements.

AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 207ed0a789)

Changelog:
https://www.psycopg.org/psycopg3/docs/news.html#psycopg-3-3-4

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:10 +05:30
Devansh Patel edca03fca9 python3-filelock: set CVE_PRODUCT
The inherited python:filelock mapping does not identify the tox-dev source packaged by this recipe, so filelock CVEs are missed.

Use tox-dev:filelock to match the source identity used by NVD and CNA.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 43fd2c88f1)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:01 +05:30
Ankur Tyagi 206b109aae gvfs: upgrade 1.60.1 -> 1.60.2
Changelog:
https://gitlab.gnome.org/GNOME/gvfs/-/blob/1.60.2/NEWS?ref_type=tags

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit fde2764851)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:00 +05:30
Wang Mingyu 46133d7aed gvfs: upgrade 1.60.0 -> 1.60.1
Changelog:
===========
* smb: Fix authentication fallback broken with Samba 4.24
* dav: Fix redirect handling to prevent HTTPS downgrade and credential leakage
* Some other fixes
* Translation updates

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 2f0fd5faeb)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:59:00 +05:30
Ankur Tyagi 628008e12b gdm: upgrade 50.1 -> 50.2
Changelog:
https://gitlab.gnome.org/GNOME/gdm/-/blob/50.2/NEWS?ref_type=tags

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 2a4ad6ae3a)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:59 +05:30
Ankur Tyagi 56e5e164b0 gnome-software: upgrade 50.0 -> 50.3
Also add UPSTREAM_CHECK variables to check for new releases.
Fixes:
$ devtool latest-version gnome-software
...
INFO: Current version: 50.0
INFO: Latest version:

Release Notes:
https://gitlab.gnome.org/GNOME/gnome-software/-/blob/50.3/NEWS?ref_type=tags

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit a5b12a47ca)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:59 +05:30
Ankur Tyagi 411e417600 file-roller: upgrade 44.5 -> 44.7
Also add UPSTREAM_CHECK variables to check for new releases.
Fixes:
$ devtool latest-version file-roller
...
INFO: Current version: 44.5
INFO: Latest version:

Release Notes:
https://gitlab.gnome.org/GNOME/file-roller/-/blob/44.7/NEWS?ref_type=tags

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit cabbb12e12)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:58 +05:30
Ankur Tyagi 0d7e0d0dbf firewalld: upgrade 2.2.1 -> 2.2.3
Changelog:
https://github.com/firewalld/firewalld/releases/tag/v2.2.2
https://github.com/firewalld/firewalld/releases/tag/v2.2.3

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:58 +05:30
Ankur Tyagi 6b815fe901 postfix: upgrade 3.10.12 -> 3.10.13
Changelog:
http://www.postfix.org/announcements/postfix-3.11.6.html

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:58 +05:30
Wang Mingyu aa6d643ec8 libsdl3: upgrade 3.4.4 -> 3.4.8
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit ac45e26afc)

Changelog:
https://github.com/libsdl-org/SDL/releases/tag/release-3.4.6
https://github.com/libsdl-org/SDL/releases/tag/release-3.4.8

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:57 +05:30
Khem Raj c6650604cf libsdl3-image: upgrade 3.4.2 -> 3.4.4
Point release with bug fixes and minor improvements.

AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit a1be7bcafa)

Changelog:
https://github.com/libsdl-org/SDL_image/releases/tag/release-3.4.4

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:57 +05:30
Ankur Tyagi fe0503d236 hiredis: upgrade 1.3.0 -> 1.3.1
Also update branch and include tag in the SRC_URI

Changelog:
https://github.com/redis/hiredis/releases/tag/v1.3.1

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:56 +05:30
Ankur Tyagi 56f07f3e89 thin-provisioning-tools: upgrade 1.3.1 -> 1.3.3
Changelog:
https://github.com/device-mapper-utils/thin-provisioning-tools/blob/v1.3.3/CHANGES

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 3a85fbdfef)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:56 +05:30
Deepak Rathore e4ed510b63 redis: avoid LTO for clang builds
In Redis 8.0.x, the build system adds -flto by itself when clang is
used with the default optimization setting. In OE clang builds, the
final link still goes through the cross binutils linker path. That path
does not stage LLVMgold.so, so redis-benchmark link fails with:

  x86_64-oe-linux-ld: ../lib/LLVMgold.so: error loading plugin

The failure is not seen with gcc because Redis does not add clang LTO in
that path. Also, changing OPTIMIZATION from the recipe is not a good fit
because it replaces Redis defaults and drops -fno-omit-frame-pointer.

Use Redis documented OPT variable only for clang builds. This avoids
the clang LTO path and keeps the frame-pointer flag. The gcc/default
build is left unchanged.

This local workaround can be removed later if LLVMgold/binutils-plugin
support is available in the toolchain path used by clang LTO builds.

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:55 +05:30
Hetvi Thakar fb2bca0962 libssh: upgrade 0.11.4 -> 0.11.5
Upgrade to the 0.11.5 security release to fix CVE-2026-15370 and CVE-2026-59843 through CVE-2026-59850.

Switch to the official GitLab mirror because the git.libssh.org endpoint no longer provides a usable Git repository for the new release.

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:55 +05:30
Hetvi Thakar 039e0dea33 python3-web3: Fix CVE-2026-40072
This patch applies the upstream v7 backport for
CVE-2026-40072. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/ApeWorX/web3.py/commit/d62e67d3b636bd4c5a929696c0f5c4167c31625b
[2] https://github.com/advisories/GHSA-5hr4-253g-cpx2

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:54 +05:30
Hetvi Thakar 34800488de python3-ujson: Fix CVE-2026-54911
This patch applies the upstream fix for CVE-2026-54911 to ujson
5.12.1. The upstream fix commit is referenced in [1], and the
public security advisory is referenced in [2].

[1] https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf
[2] https://github.com/ultrajson/ultrajson/security/advisories/GHSA-3j69-69wj-xqx2

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:54 +05:30
Wang Mingyu b9fb63c09a python3-httplib2: upgrade 0.31.2 -> 0.32.0
Changelog:
============
- Python support 3.8+ only
- decompression limited by size and ratio
- decoder foundation to support more compression algorithms

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 69b5baba27)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:53 +05:30
Hetvi Thakar 2fb2b9fb1d python3-twisted: Fix CVE-2026-42304
This patch applies the upstream 26.4.0rc2 backport for
CVE-2026-42304. The upstream fix merge is referenced in [1],
and the public CVE advisory is referenced in [2]. The individual
backported commit links are recorded in the patch headers.

[1] https://github.com/twisted/twisted/commit/2d196123264efb0027eecfe1b430be4a9babdbd8
[2] https://github.com/advisories/GHSA-grgv-6hw6-v9g4

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:53 +05:30
Hetvi Thakar 8519105eec python3-pyjwt: Fix CVE-2026-48526
This patch applies the upstream 2.13.0 backport for
CVE-2026-48526. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
[2] https://github.com/advisories/GHSA-xgmm-8j9v-c9wx

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:52 +05:30
Hetvi Thakar 5fd7815f34 python3-pyjwt: Fix CVE-2026-48525
This patch applies the upstream 2.13.0 backport for
CVE-2026-48525. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
[2] https://github.com/advisories/GHSA-w7vc-732c-9m39

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:52 +05:30
Hetvi Thakar 8a6759f036 python3-pyjwt: Fix CVE-2026-48524
This patch applies the upstream 2.13.0 backport for
CVE-2026-48524. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
[2] https://github.com/advisories/GHSA-fhv5-28vv-h8m8

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:51 +05:30
Hetvi Thakar 79accf77d2 python3-pyjwt: Fix CVE-2026-48523
This patch applies the upstream 2.13.0 backport for
CVE-2026-48523. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
[2] https://github.com/advisories/GHSA-jq35-7prp-9v3f

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:51 +05:30
Hetvi Thakar 242530c3e4 python3-pyjwt: Fix CVE-2026-48522
This patch applies the upstream 2.13.0 backport for
CVE-2026-48522. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
[2] https://github.com/advisories/GHSA-993g-76c3-p5m4

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:51 +05:30
Darsh Kelaiya d070b08b56 python3-aiohttp: fix CVE-2026-54280
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].

[1] https://github.com/aio-libs/aiohttp/commit/a762eda5242f6490d6ba667533193f8b473ad587
[2] https://github.com/advisories/GHSA-9x8q-7h8h-wcw9

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-08-24 12:58:50 +05:30