Commit Graph

39117 Commits

Author SHA1 Message Date
Leon Anavi c19c22ec7a python3-lief: Upgrade 0.17.3 -> 1.0.0
Upgrade to release 1.0.0:

- Add Android JNI Analyzer
- The DWARF import plugin now supports comments
- Add support for generating DWARF from firmware or binaries
  without a precise format or architecture
- Add support for accessing the bit size of bit-field declarations
- Add support for accessing Enum entries:
  lief.dwarf.types.Enum.entries()
- Add support for reading from or assigning a register to a function
  parameter
- Add support for reading from or assigning a description
  (DW_AT_description) to a lief.dwarf.Function, lief.dwarf.Variable,
  or lief.dwarf.LexicalBlock:
  lief.dwarf.Function.description()
  lief.dwarf.Variable.description()
  lief.dwarf.LexicalBlock.description()
- Enable the creation of nested lief.dwarf.editor.Function.LexicalBlock
- Add support for generating a C/C++ definition for a whole
  lief.dwarf.CompilationUnit ( lief.dwarf.CompilationUnit.to_decl()).
  The output of the following to_decl() functions can now be
  configured through the new lief.DeclOpt structure:
  lief.dwarf.Function.to_decl()
  lief.dwarf.Variable.to_decl()
  lief.dwarf.Type.to_decl()
  lief.dwarf.CompilationUnit.to_decl()
- Improve support and the API for LF_ENUM: lief.pdb.types.Enum
- Improve support and the API for LF_PROCEDURE: lief.pdb.types.Function
- Improve support and the API for LF_ARRAY: lief.pdb.types.Array
- Improve support and the API for simple types: lief.pdb.types.Simple
- Improve support and the API for LF_ONEMETHOD: lief.pdb.types.Method
- Add support for generating a C/C++ definition for a lief.pdb.Function
  ( lief.pdb.Function.to_decl()) and a lief.pdb.CompilationUnit
  ( lief.pdb.CompilationUnit.to_decl()), configurable with the new
  lief.DeclOpt structure.
- Add support for DT_AUXILIARY tag: lief.ELF.DynamicEntryAuxiliary
- Add support for DT_FILTER tag: lief.ELF.DynamicEntryFilter
- Add lief.ELF.parse_from_dump() to parse an ELF binary from a
  memory dump
- Add lief.COFF.Section.coff_string for accessing the full section
  name when this name does not fit in 8 bytes.
- Add support for writing big-endian Mach-O binaries
- Introduce an API for selecting a specific Mach-O binary by
  architecture from a FAT binary
- Add lief.MachO.FatBinary.create() to create a FAT binary from a
  list of lief.MachO.Binary objects targeting different architectures
- Add support for lief.MachO.ThreadLocalVariables
- Fix an extra byte being written after the thread state of an
  LC_UNIXTHREAD/LC_THREAD command, which shifted the following load
  commands by one byte
- Add support for editing the runtime tables of the
  LC_FUNCTION_VARIANTS command and committing the changes on write:
  lief.MachO.FunctionVariants
- Add a structured parser, editing API and writer for the
  LC_FUNCTION_VARIANT_FIXUPS command:
  lief.MachO.FunctionVariantFixups
- Add support for the LC_LAZY_LOAD_DYLIB_INFO command:
  lief.MachO.LazyLoadDylibInfo
- Add lief.MachO.parse_from_dump() to parse a Mach-O binary from a
  memory dump
- Add setters for lief.PE.ImportEntry.iat_value and
  lief.PE.ImportEntry.ilt_value
- Add lief.PE.Binary.offset_to_rva() to convert a raw offset into a RVA
- Add lief.PE.parse_from_dump() to parse a PE binary from a memory dump
- Update lief.Binary.offset_to_virtual_address() for PE binaries
  to return an absolute virtual address instead of a RVA
- Add support for adding an lief.PE.Import at a specific position:
  lief.PE.Binary.add_import()
- Improve support for EFI binaries, such as bzImage
- Add support for Objective-C categories: lief.ObjC.Category,
  accessible through lief.ObjC.Metadata.categories
- Add support for iterating over the operands of MIPS, PowerPC,
  eBPF and RISC-V instructions (Register, Immediate, Memory and
  PCRelative):
  lief.assembly.mips.Instruction.operands()
  lief.assembly.powerpc.Instruction.operands()
  lief.assembly.ebpf.Instruction.operands()
  lief.assembly.riscv.Instruction.operands()
- The Rust FFI no longer relies on autocxx and bindgen. It is now
  built on top of plain cxx, which simplifies the bindings and
  reduces the iteration time
- The Rust bindings directory has been renamed from api/rust/cargo/
  to api/rust/crates/
- Add support for the aarch64-linux-android and x86_64-linux-android
  targets
- Add LIEF_LIFETIMEBOUND annotations wrapping [[clang::lifetimebound]]
  to leverage Clang's lifetime analysis. This helps detect dangling
  references at compile time for methods that return references or
  iterators tied to an object's lifetime

This work was sponsored by GOVCERT.LU.

License-Update: Update years

Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-17 09:06:58 -07:00
Leon Anavi 573f9df8e1 python3-scikit-build-core: Upgrade 0.12.2 -> 1.0.3
Upgrade to release 1.0.3:

Fixes:

- Complete the setuptools SubCommand protocol
- Thread config_settings to the build command
- Keep source tree clean in strict editable mode

Documentation:

- Put uv first in installer tabs and add it to config-settings
- List choices for Literal options in the README table
- Touch up README options tables, setuptools docs
- Show the projects list as a card grid with language/binding badges
- Add high-star projects to the known projects list

CI and testing:

- Make linkcheck retry timeouts from slow hosts
- Forward -C config-settings in downstream editable install

Include a patch to rename directory name from ${module} __module__
to avoid error due to an unexpanded bitbake variable.

This work was sponsored by GOVCERT.LU.

Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-17 09:06:58 -07:00
Lian Wang cdeec3978f wolfssl: upgrade 5.9.1 -> 5.9.2
- Update SRCREV to v5.9.2-stable tag
- All security fixes from 5.9.2 release included

Signed-off-by: Lian Wang <lianux.wang@processmission.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-17 09:06:58 -07:00
Jörg Sommer dfa10cf870 zsh: Update 5.9.1 -> 5.9.2
Changelog https://zsh.sourceforge.io/releases.html

* Only minor changes.

Signed-off-by: Jörg Sommer <joerg.sommer@navimatix.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-17 09:06:58 -07:00
Jason Schonberg ff8ade4a7e webkitgtk3: upgrade 2.52.4 -> 2.52.5
Changelog: https://webkitgtk.org/2026/07/09/webkitgtk2.52.5-released.html

Note that while the changelog suggests that this is just a bugfix release,
there are a lot of CVEs which have been addressed in this release.

 CVE-2024-4367, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699,
CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713,
CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721, CVE-2026-43725,
CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734,
CVE-2026-43740, CVE-2026-43742, CVE-2026-43745

See : https://webkitgtk.org/security/WSA-2026-0004.html for details.

Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-17 09:06:58 -07:00
Peter Marko d63a31e4a9 libwebsockets: patch CVE-2026-10650
Pick patch mentioned in NVD report.

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:02 -07:00
Peter Marko 4707446843 libwebsockets: set status for CVE-2025-1866
Current cve-check code does not correctly decode the entry [1]:

"versions": [
    {
        "changes": [
            {
                "at": "patch 4.3.4",
                "status": "unaffected"
            }
        ],
        "lessThan": "<4.3.4",
        "status": "affected",
        "version": "0",
        "versionType": "git"
    }
]

[1] https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/1xxx/CVE-2025-1866.json

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:02 -07:00
Peter Marko 72f30c2fca nginx: upgrade 1.30.3 -> 1.30.4
This resolves CVE-2026-42533, CVE-2026-60005 and CVE-2026-56434.

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:01 -07:00
Peter Marko 11faaf4065 nginx: inherit upstream-version-is-even
Since mainline version has been deleted, devtool tries to upgrade stable
recipe to mainline version.
Prevent it by telling it that even version needs to be used.

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:01 -07:00
Trevor Gamblin c6e9a220b2 python3-ukkonen: use python_setuptools_build_meta
Use the newer setuptools build class to avoid an AttributeError thrown
after warnings about setuptools and related build modules:

|/home/tgamblin/workspace/ypbuilds/oe-nodistro-master-patchtest/build/tmp/work/x86-64-v3-oe-linux/python3-ukkonen/1.1.0/recipe-sysroot-native/usr/lib/python3.14/site-packages/setuptools/__init__.py:92: _DeprecatedInstaller: setuptools.installer and fetch_build_eggs are deprecated.
|!!
|
|        ********************************************************************************
|        Requirements should be satisfied by a PEP 517 installer.
|        If you are using pip, you can try `pip install --use-pep517`.
|
|        This deprecation is overdue, please update your project and remove deprecated
|        calls to avoid build errors in the future.
|        ********************************************************************************
|
|!!

...

|  File "/home/tgamblin/workspace/ypbuilds/oe-nodistro-master-patchtest/build/tmp/work/x86-64-v3-oe-linux/python3-ukkonen/1.1.0/recipe-sysroot-native/usr/lib/python3.14/site-packages/packaging/utils.py", line 96, in canonicalize_name
|    value = name.lower().replace("_", "-").replace(".", "-")
|            ^^^^^^^^^^
|AttributeError: 'NoneType' object has no attribute 'lower'

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:01 -07:00
Max Krummenacher e0eca5284e joe: Fix assign to stdin, use freopen instead
This fixes building with musl.
Upstream disscussion: https://github.com/joe-editor/joe/issues/115

Signed-off-by: Max Krummenacher <max.oss.09@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:01 -07:00
Peter Marko e77b376231 bdftopcf: remove dependency on libxfont
The recipe builds fine without it.
Commits [1] and [2] imported some of its headers in v1.1 so the
dependency became obsolete.

[1] https://cgit.freedesktop.org/xorg/app/bdftopcf/commit/?id=102696da8737fcb324034f673cd5815f28923311
[2] https://cgit.freedesktop.org/xorg/app/bdftopcf/commit/?id=140f7f6e071a239329d700aa24191a664be2bea2

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:01 -07:00
Leon Anavi ca387fb9cd python3-pydantic: Upgrade 2.12.5 -> 2.13.4
Upgrade to release 2.13.4:

- Bump libc from 0.2.155 to 0.2.185
- Adapt pydantic-core linker flags on macOS

This work was sponsored by GOVCERT.LU.

Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:01 -07:00
Leon Anavi a8b9cebb4c python3-pydantic-core: Upgrade 2.41.5 -> 2.46.4
Upgrade pydantic-core to version 2.46.4 as it required for newer
Pydantic versions.

This work was sponsored by GOVCERT.LU.

Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:00 -07:00
Chitti Babu Theegala 50bf64d177 boot-time-analysis-tools: add boot time profiling tools
Add two new recipes from the CentOS Automotive SIG
boot-time-analysis-tools project to enable boot time profiling
and measurement.

boot-time-analysis-tools:
  Python-based toolset for collecting, analyzing and visualizing system
  boot timing data from the systemd journal. Provides the 'boot_timings'
  CLI utility which queries D-Bus and the systemd journal to produce
  structured boot time reports. Depends on python3-dbus and python3-systemd
  for runtime journal and D-Bus access.

cntvct-log:
  Userspace C utility built with Meson that logs ARM CNTVCT_EL0 virtual
  counter timestamps to correlate hardware-level timing with systemd boot
  events. Installs cntvct@.service as a systemd template unit (disabled
  by default) for on-demand per-instance activation. The service preset
  file (98-cntvct-log.preset) is installed for system-preset-based enablement.

Both recipes fetch from the same upstream git repository:
  https://gitlab.com/CentOS/automotive/src/boot-time-analysis-tools

Signed-off-by: Chitti Babu Theegala <ctheegal@qti.qualcomm.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:00 -07:00
Wang Mingyu a21f36c865 xwud: upgrade 1.0.7 -> 1.0.8
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:00 -07:00
Wang Mingyu bec3f73dfb xwd: upgrade 1.0.9 -> 1.0.10
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:00 -07:00
Wang Mingyu 20c5d3d37d xstdcmap: upgrade 1.0.5 -> 1.0.6
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:00 -07:00
Wang Mingyu fb67b9e3e1 xsetroot: upgrade 1.1.3 -> 1.1.4
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:00 -07:00
Wang Mingyu cda194b059 xrefresh: upgrade 1.1.0 -> 1.1.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:15:00 -07:00
Wang Mingyu 7cceafcf4a xrdb: upgrade 1.2.2 -> 1.2.3
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:59 -07:00
Wang Mingyu 7abed187c5 xlsfonts: upgrade 1.0.8 -> 1.0.9
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:59 -07:00
Wang Mingyu 9ef8700069 xlsatoms: upgrade 1.1.4 -> 1.1.5
License-Update: Copyright year updated to 2009

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:59 -07:00
Wang Mingyu b630b992b8 xkbutils: upgrade 1.0.6 -> 1.0.7
License-Update: Copyright year updated to 2025

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:59 -07:00
Wang Mingyu af1e23cfde wireshark: upgrade 4.6.6 -> 4.6.7
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:59 -07:00
Wang Mingyu 263c798b3a thrift: upgrade 0.23.0 -> 0.24.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:59 -07:00
Wang Mingyu b676a8b203 python3-xxhash: upgrade 3.8.0 -> 3.8.1
Changelog:
=============
- Register the "benchmark" pytest mark to avoid PytestUnknownMarkWarning
- Update C extension docstrings and remove stale comments

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:58 -07:00
Wang Mingyu 687cf2b45a python3-virtualenv: upgrade 21.5.1 -> 21.6.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:58 -07:00
Wang Mingyu ea00a3bf35 python3-tzdata: upgrade 2026.2 -> 2026.3
License-Update: Copyright year updated to 2026

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:58 -07:00
Wang Mingyu 5c7090d01c python3-tqdm: upgrade 4.68.3 -> 4.68.4
Changelog:
===========
- trim to ncols even when '{bar}' not in bar_format
- fix tqdm.write when stdout=None

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:58 -07:00
Wang Mingyu 129794b97d python3-tox: upgrade 4.56.1 -> 4.56.4
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:58 -07:00
Wang Mingyu 682edf0b43 python3-thrift: upgrade 0.23.0 -> 0.24.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:58 -07:00
Wang Mingyu fe62dc0a47 python3-regex: upgrade 2026.6.28 -> 2026.7.10
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:57 -07:00
Wang Mingyu d51c96da35 python3-pymodbus: upgrade 3.13.1 -> 3.14.0
Changelog:
==========
- Remove self signed certificate from production.
- Correct inequality in validation error message
- Fix non-deterministic convert_from_registers
- Fix swapped SimDevice in ModbusDeviceContext
- Update CI actions and pyproject.
- Add ruff format check to ci.yml
- Remove 'useless-suppression' pylint
- Format test_client.py with ruff
- Update clean_workflows CI (node@20 problem).
- Ruff format (due to ruff upgrade).
- Fix ModbusServerContext initialization with dict devices parameter
- Support configured ASCII input delimiter
- Fix default no-response behavior for force listen only
- Use correct format character for DataType.REGISTERS 'h' -> 'H'

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:57 -07:00
Wang Mingyu e96bda586c python3-pikepdf: upgrade 10.9.1 -> 10.10.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:57 -07:00
Wang Mingyu 528436c936 python3-nltk: upgrade 3.9.4 -> 3.10.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:57 -07:00
Wang Mingyu 72d2b042d8 python3-huey: upgrade 3.1.1 -> 3.2.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:57 -07:00
Wang Mingyu 3041c28758 python3-google-auth: upgrade 2.55.1 -> 2.55.2
python3-google-auth
refreshed for 2.55.2

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:57 -07:00
Wang Mingyu d5883b05fe python3-filelock: upgrade 3.29.6 -> 3.29.7
Changelog:
==========
- asyncio: detect cross-instance reentrant deadlocks before the poll loop
- fix(soft_rw): evict non-regular write marker without reading it
- _util: drop the dead st_mtime=0 short-circuit in raise_on_not_writable_file

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:57 -07:00
Wang Mingyu d595190041 python3-discovery: upgrade 1.4.3 -> 1.4.4
Changelog:
 fix(spec): discover debug (Py_DEBUG) interpreters like python3.13-dbg

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:56 -07:00
Wang Mingyu 6a2331841a python3-croniter: upgrade 6.2.3 -> 6.2.4
Changelog:
===========
- Fix expand_from_start_time day-of-week low bound so Sunday wraps correctly
  for stepped day-of-week ranges (isoweekday() % 7 instead of weekday() + 1).
- Bump pinned GitHub Actions via dependabot.

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:56 -07:00
Wang Mingyu 62d4e07ca8 python3-coverage: upgrade 7.15.0 -> 7.15.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:56 -07:00
Wang Mingyu 85b3a04b09 python3-cmd2: upgrade 4.0.0 -> 4.1.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:56 -07:00
Wang Mingyu 9656ab7a40 python3-cmake: upgrade 4.3.4 -> 4.4.0
Changelog:
============
- ci: secure GitHub Actions workflows
- chore(ci): use manylinux clang install script
- [Bot] Update to CMake 4.4.0
- docs: polish docs and fix stale references

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:56 -07:00
Wang Mingyu 555c071d59 python3-ckzg: upgrade 2.1.7 -> 2.1.8
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:56 -07:00
Wang Mingyu 6feb5955b4 python3-bumble: upgrade 0.0.231 -> 0.0.232
Changelog:
===========
- CIG: Fix CIG parameters for unidirectional CIS
- Refine dependencies
- Fix race condition in PeriodicAdvertisingSync state transition
- transport/usb: Handle missing interruptEventHandler gracefully
- fix: exclude channel 76 from default CS channel_map (Core Spec 6.0 compliance)

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:55 -07:00
Wang Mingyu db3a1462af python3-bitarray: upgrade 3.8.2 -> 3.9.0
Changelog:
===========
  * add '.rotate()' method, rotate bitarray in-place by 'k' positions
  * expose the 'decodeiterator' class, and add '.skipbits()' method
    as well as '.index' data descriptor, see #252
  * fix 'random_p()' silently producing all-zero bitarrays for small 'n'
    when 'p=float("nan")'
  * improve integer argument handling in 'util.random_k()',
    'util.gen_primes()', 'util.pprint()' and 'util.int2ba()'
  * add 'python_requires >= 3.7' to package metadata
  * improve testing - use more of 'unittest''s functionality
  * add [Rule 90 example](../examples/rule90.py)

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:55 -07:00
Wang Mingyu 8529a1f028 python3-anyio: upgrade 4.14.1 -> 4.14.2
Changelog:
===========
- Changed ByteReceiveStream.receive() implementations to raise a ValueError
  when max_bytes is not a positive integer
- Fixed CapacityLimiter.total_tokens rejecting float("inf") when the limiter
  was instantiated outside of an event loop. The adapter setter checked for
  infinity by identity (value is math.inf), so only the exact math.inf singleton
  was accepted, while every backend setter (using math.isinf()) accepts any
  positive infinity
- Fixed to_process.run_sync() deadlocking when the worker function writes
  enough data to sys.stderr to fill the (undrained) pipe buffer. The worker
  process now redirects sys.stderr to os.devnull as well, matching the documented
  behavior
- Fixed TLSStream.wrap() matching an internationalized (unicode) host name
  against the peer certificate using IDNA 2003 (via the standard library)
  instead of IDNA 2008, which could cause the host name to be matched against the
  wrong certificate
- Fixed anyio.open_process() (and run_process()) ignoring the extra_groups
  argument, as it mistakenly passed the value of the group argument instead
- Fixed CapacityLimiter.acquire_nowait() and
  CapacityLimiter.acquire_nowait_on_behalf_of() raising trio.WouldBlock instead
  of anyio.WouldBlock on the trio backend when there are no tokens available
- Fixed CapacityLimiter on the asyncio backend over-granting tokens
  (borrowed_tokens exceeding total_tokens and available_tokens going negative)
  when a non-blocking acquire was made in the window between a token being
  released and the notified waiter resuming. The freed token is now reserved for
  the woken waiter right away, so the non-blocking acquire correctly raises
  WouldBlock
- Fixed unnecessary CPU spin when delivering cancellation from CancelScope on
  asyncio under certain conditions, including improper cancel scope nesting

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:55 -07:00
Wang Mingyu c13b1c4115 proftpd: upgrade 1.3.9b -> 1.3.9c
Changelog:
===========
- Issue 2135 - ExecEnviron values not passed due to regression since 1.3.8.d.
- Issue 2146 - Stack buffer overflow in MLSD/MLST handling for long path names.
- Issue 2158 - MaxTransfersPerUser no longer enforces configured limits.
- Issue 2163 - AdminControlsACLs for config, get actions not honored as they
  should be.
- Issue 2166 - Memcached/Redis-cached JSON TLS session/OCSP entries decoded
  into fixed buffers without bounds checking.
- Issue 2173 - RewriteMap unescape builtin use causes one-byte out-of-bounds
  write, fails to reject illegal characters.
- Issue 2188 - SQL group name lookup concatenates client-provided group names
  without escaping.
- Issue 2190 - Authenticated SFTP sessions can overflow the SFTP packet buffer.
- Issue 2210 - Default Controls socket ACLs unintentionally allow all users
  access for sending Controls requests.

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:55 -07:00
Wang Mingyu d18b472bd0 postfix: upgrade 3.11.4 -> 3.11.5
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-16 21:14:55 -07:00