Container summary for bci/openjdk-devel


SUSE-CU-2024:5242-1

Container Advisory IDSUSE-CU-2024:5242-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-28.5 , bci/openjdk-devel:21.0.4.0 , bci/openjdk-devel:21.0.4.0-28.5 , bci/openjdk-devel:latest
Container Release28.5
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3726-1
ReleasedFri Oct 18 11:56:40 2024
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1231051
Description:

This update for glibc fixes the following issue:


SUSE-CU-2024:5241-1

Container Advisory IDSUSE-CU-2024:5241-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-28.3 , bci/openjdk-devel:21.0.4.0 , bci/openjdk-devel:21.0.4.0-28.3 , bci/openjdk-devel:latest
Container Release28.3
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3659-1
ReleasedWed Oct 16 15:12:47 2024
SummaryRecommended update for gcc14
Typerecommended
Severitymoderate
References1188441,1210959,1214915,1219031,1220724,1221601
Description:

This update for gcc14 fixes the following issues:
This update ships the GNU Compiler Collection GCC 14.2. (jsc#PED-10474)
The compiler runtime libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 13 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP5 and SP6, and provided in the 'Development Tools' module.
The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories.
To use gcc14 compilers use:


For a full changelog with all new GCC14 features, check out
https://gcc.gnu.org/gcc-14/changes.html



SUSE-CU-2024:5142-1

Container Advisory IDSUSE-CU-2024:5142-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-27.4 , bci/openjdk-devel:latest
Container Release27.4
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3609-1
ReleasedMon Oct 14 11:39:13 2024
SummaryRecommended update for SLES-release
Typerecommended
Severitymoderate
References1227100,1230135
Description:

This update for SLES-release fixes the following issues:


SUSE-CU-2024:5104-1

Container Advisory IDSUSE-CU-2024:5104-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-27.1 , bci/openjdk-devel:latest
Container Release27.1
The following patches have been included in this update:

SUSE-CU-2024:5037-1

Container Advisory IDSUSE-CU-2024:5037-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-26.13 , bci/openjdk-devel:latest
Container Release26.13
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3597-1
ReleasedFri Oct 11 10:39:52 2024
SummaryRecommended update for bash
Typerecommended
Severitymoderate
References1227807
Description:

This update for bash fixes the following issues:


SUSE-CU-2024:5036-1

Container Advisory IDSUSE-CU-2024:5036-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-26.12 , bci/openjdk-devel:latest
Container Release26.12
The following patches have been included in this update:

SUSE-CU-2024:4873-1

Container Advisory IDSUSE-CU-2024:4873-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-26.8 , bci/openjdk-devel:latest
Container Release26.8
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3528-1
ReleasedFri Oct 4 15:31:43 2024
SummaryRecommended update for e2fsprogs
Typerecommended
Severitymoderate
References1230145
Description:

This update for e2fsprogs fixes the following issue:


SUSE-CU-2024:4836-1

Container Advisory IDSUSE-CU-2024:4836-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-26.5 , bci/openjdk-devel:latest
Container Release26.5
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3501-1
ReleasedTue Oct 1 16:03:34 2024
SummarySecurity update for openssl-3
Typesecurity
Severityimportant
References1230698,CVE-2024-41996
Description:

This update for openssl-3 fixes the following issues:


Advisory IDSUSE-RU-2024:3504-1
ReleasedTue Oct 1 16:22:27 2024
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1230638
Description:

This update for glibc fixes the following issue:


SUSE-CU-2024:4774-1

Container Advisory IDSUSE-CU-2024:4774-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-26.1 , bci/openjdk-devel:latest
Container Release26.1
The following patches have been included in this update:

SUSE-CU-2024:4715-1

Container Advisory IDSUSE-CU-2024:4715-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-25.6 , bci/openjdk-devel:latest
Container Release25.6
The following patches have been included in this update:

SUSE-CU-2024:4678-1

Container Advisory IDSUSE-CU-2024:4678-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-25.4 , bci/openjdk-devel:latest
Container Release25.4
The following patches have been included in this update:

SUSE-CU-2024:4632-1

Container Advisory IDSUSE-CU-2024:4632-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-25.3 , bci/openjdk-devel:latest
Container Release25.3
The following patches have been included in this update:

SUSE-CU-2024:4608-1

Container Advisory IDSUSE-CU-2024:4608-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-25.1 , bci/openjdk-devel:latest
Container Release25.1
The following patches have been included in this update:

SUSE-CU-2024:4507-1

Container Advisory IDSUSE-CU-2024:4507-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-23.5 , bci/openjdk-devel:latest
Container Release23.5
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3300-1
ReleasedWed Sep 18 14:27:53 2024
SummaryRecommended update for ncurses
Typerecommended
Severitymoderate
References1229028
Description:

This update for ncurses fixes the following issues:


SUSE-CU-2024:4447-1

Container Advisory IDSUSE-CU-2024:4447-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-23.3 , bci/openjdk-devel:latest
Container Release23.3
The following patches have been included in this update:

SUSE-CU-2024:4440-1

Container Advisory IDSUSE-CU-2024:4440-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-23.1 , bci/openjdk-devel:latest
Container Release23.1
The following patches have been included in this update:

SUSE-CU-2024:4364-1

Container Advisory IDSUSE-CU-2024:4364-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-22.6 , bci/openjdk-devel:latest
Container Release22.6
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3239-1
ReleasedFri Sep 13 12:00:58 2024
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1229476
Description:

This update for util-linux fixes the following issue:


SUSE-CU-2024:4326-1

Container Advisory IDSUSE-CU-2024:4326-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-22.4 , bci/openjdk-devel:latest
Container Release22.4
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3216-1
ReleasedThu Sep 12 13:05:20 2024
SummarySecurity update for expat
Typesecurity
Severitymoderate
References1229930,1229931,1229932,CVE-2024-45490,CVE-2024-45491,CVE-2024-45492
Description:

This update for expat fixes the following issues:


Advisory IDSUSE-RU-2024:3245-1
ReleasedMon Sep 16 07:55:19 2024
SummaryRecommended update for maven, maven-resolver, sbt, xmvn
Typerecommended
Severitymoderate
References
Description:

This update for maven, maven-resolver, sbt, xmvn fixes the following issues:
maven-resolver was upgraded to version 1.9.22:


* Resolver-Supplier unusable in OSGi runtimes * Invalid Cookie set under proxy conditions * In typical setups, DefaultArtifact copies the same maps over and over again * Memory consumption improvements

* Import o.e.aether packages with the exact same version in OSGi metadata

* Removed excessive strictness of OSGi dependency metadata

maven was upgraded to version 3.9.9:

* Fixed search for topDirectory when using -f / --file for Maven 3.9.x * Fixed Maven not finding extensions for -f when current dir is root * Fixed warning for com.sun:tools:jar that refers to a non-existing file * Fixed profile activation based on OS properties for 'mvn site' * Fixed Resolver wrongly assuming it is deploying a plugin by presence of META-INF/maven/plugins.xml in JAR * Fixed missing or mismatching Trusted Checksum for some artifacts is not properly reported * Fixed regression causing Property not resolved in profile pluginManagement
sbt, xmvn:


Advisory IDSUSE-RU-2024:3247-1
ReleasedMon Sep 16 07:59:42 2024
SummaryRecommended update for hamcrest
Typerecommended
Severitymoderate
References
Description:

This update for hamcrest fixes the following issues:


* Breaking Changes:
+ From version 3.0, the jar distributed to Maven Central is now compiled to Java 1.8 bytecode, and is not compatible with previous versions of Java. Developers who use Java 1.7 earlier can still depend upon hamcrest-2.2.jar.
* Improvements: + FileMatchersTest simplification + License cleanup


SUSE-CU-2024:4287-1

Container Advisory IDSUSE-CU-2024:4287-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-22.1 , bci/openjdk-devel:latest
Container Release22.1
The following patches have been included in this update:

SUSE-CU-2024:4219-1

Container Advisory IDSUSE-CU-2024:4219-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-21.12 , bci/openjdk-devel:latest
Container Release21.12
The following patches have been included in this update:

SUSE-CU-2024:4150-1

Container Advisory IDSUSE-CU-2024:4150-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-21.10 , bci/openjdk-devel:latest
Container Release21.10
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3166-1
ReleasedMon Sep 9 12:25:30 2024
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1228042
Description:

This update for glibc fixes the following issue:


SUSE-CU-2024:4036-1

Container Advisory IDSUSE-CU-2024:4036-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-21.8 , bci/openjdk-devel:latest
Container Release21.8
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3106-1
ReleasedTue Sep 3 17:00:40 2024
SummarySecurity update for openssl-3
Typesecurity
Severitymoderate
References1220523,1220690,1220693,1220696,1221365,1221751,1221752,1221753,1221760,1221786,1221787,1221821,1221822,1221824,1221827,1229465,CVE-2024-6119
Description:

This update for openssl-3 fixes the following issues:


Other fixes:


Advisory IDSUSE-RU-2024:3131-1
ReleasedTue Sep 3 17:42:24 2024
SummaryRecommended update for mozilla-nss
Typerecommended
Severitymoderate
References1224113
Description:

This update for mozilla-nss fixes the following issues:


Advisory IDSUSE-RU-2024:3132-1
ReleasedTue Sep 3 17:43:10 2024
SummaryRecommended update for permissions
Typerecommended
Severitymoderate
References1228968,1229329
Description:

This update for permissions fixes the following issues:



SUSE-CU-2024:3935-1

Container Advisory IDSUSE-CU-2024:3935-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-21.5 , bci/openjdk-devel:latest
Container Release21.5
The following patches have been included in this update:

SUSE-CU-2024:3859-1

Container Advisory IDSUSE-CU-2024:3859-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-21.3 , bci/openjdk-devel:latest
Container Release21.3
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2967-1
ReleasedMon Aug 19 15:41:29 2024
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1194818
Description:

This update for pam fixes the following issue:


SUSE-CU-2024:3767-1

Container Advisory IDSUSE-CU-2024:3767-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-21.1 , bci/openjdk-devel:latest
Container Release21.1
The following patches have been included in this update:

SUSE-CU-2024:3677-1

Container Advisory IDSUSE-CU-2024:3677-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-20.6 , bci/openjdk-devel:latest
Container Release20.6
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2888-1
ReleasedTue Aug 13 11:07:41 2024
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1159034,1194818,1218609,1222285
Description:

This update for util-linux fixes the following issues:


SUSE-CU-2024:3612-1

Container Advisory IDSUSE-CU-2024:3612-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-20.3 , bci/openjdk-devel:latest
Container Release20.3
The following patches have been included in this update:

SUSE-CU-2024:3529-1

Container Advisory IDSUSE-CU-2024:3529-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-18.13 , bci/openjdk-devel:latest
Container Release18.13
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:2808-1
ReleasedWed Aug 7 09:49:32 2024
SummarySecurity update for shadow
Typesecurity
Severitymoderate
References1228770,CVE-2013-4235
Description:

This update for shadow fixes the following issues:


SUSE-CU-2024:3464-1

Container Advisory IDSUSE-CU-2024:3464-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-18.10 , bci/openjdk-devel:latest
Container Release18.10
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2779-1
ReleasedTue Aug 6 14:35:49 2024
SummaryRecommended update for permissions
Typerecommended
Severitymoderate
References1228548
Description:


This update for permissions fixes the following issue:


Advisory IDSUSE-RU-2024:2791-1
ReleasedTue Aug 6 16:35:06 2024
SummaryRecommended update for various 32bit packages
Typerecommended
Severitymoderate
References1228322
Description:


This update of various packages delivers 32bit variants to allow running Wine on SLE PackageHub 15 SP6.


SUSE-CU-2024:3463-1

Container Advisory IDSUSE-CU-2024:3463-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-18.3 , bci/openjdk-devel:latest
Container Release18.3
The following patches have been included in this update:

SUSE-CU-2024:3393-1

Container Advisory IDSUSE-CU-2024:3393-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-17.2 , bci/openjdk-devel:latest
Container Release17.2
The following patches have been included in this update:

SUSE-CU-2024:3343-1

Container Advisory IDSUSE-CU-2024:3343-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-16.17 , bci/openjdk-devel:latest
Container Release16.17
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2684-1
ReleasedWed Jul 31 20:04:41 2024
SummaryRecommended update for mozilla-nss
Typerecommended
Severitymoderate
References1214980,1222804,1222807,1222811,1222813,1222814,1222821,1222822,1222826,1222828,1222830,1222833,1222834,1223724,1224113,1224115,1224116,1224118,1227918,CVE-2023-5388
Description:

This update for mozilla-nss fixes the following issues:




Update to NSS 3.101.2:



update to NSS 3.101.1:

update to NSS 3.101:


Update to NSS 3.100:

Update to NSS 3.99:

Update to NSS 3.98:

Update to NSS 3.97:

Update to NSS 3.96.1:

Update to NSS 3.95:

Update to NSS 3.94:

Update to NSS 3.93:

Update to NSS 3.92:

Update to NSS 3.91:

Update to NSS 3.90.3:


SUSE-CU-2024:3313-1

Container Advisory IDSUSE-CU-2024:3313-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-16.14 , bci/openjdk-devel:latest
Container Release16.14
The following patches have been included in this update:
Advisory IDSUSE-feature-2024:2296-1
ReleasedThu Jul 4 06:29:20 2024
SummaryFeature update for jakarta-inject
Typefeature
Severitymoderate
References
Description:

This update for jakarta-inject fixes the following issues:


Advisory IDSUSE-SU-2024:2630-1
ReleasedTue Jul 30 09:12:44 2024
SummarySecurity update for shadow
Typesecurity
Severityimportant
References916845,CVE-2013-4235
Description:

This update for shadow fixes the following issues:


Advisory IDSUSE-SU-2024:2635-1
ReleasedTue Jul 30 09:14:09 2024
SummarySecurity update for openssl-3
Typesecurity
Severityimportant
References1222899,1223336,1226463,1227138,CVE-2024-5535
Description:

This update for openssl-3 fixes the following issues:
Security fixes:


Other fixes:


Advisory IDSUSE-RU-2024:2642-1
ReleasedTue Jul 30 10:03:52 2024
SummaryRecommended update for Java
Typerecommended
Severitymoderate
References
Description:

This update for Java fixes the following issues:
maven-shared-utils was updated to version 3.4.2:


* New features and improvements:
+ Made Commandline.addSystemEnvironment public and deprecated + Deprecated IsEmpty/IsNotEmpty methods + Deprecated newXmlWriter + Deprecated redundant isEmptyString method + Deprecated join methods now available in Java 8 String class + FileUtils: avoid getCanonicalPath() + Added build() method and document toString() method + Optionally inherit system environment variables by Commandline + Dropped plexus container default
* Bugs Fixed:
+ Removed trim parameter + Fixed blocking in StreamFeeder + Ignore MessageUtilsTest methods on unsupported platforms + Make copyFile succeed with source file having lastModified() = 0 + XmlWriterUtil platform independent and consistent + Poll data from input stream
plexus-io was updated to version 3.2.0 to 3.4.2:

* Drop legacy and make components pure JSR330 * Restore speed improvements * Plexus IO build is now reproducible * Various speed improvements * Plexus IO now requires Java 8

* Update sisu.inject to 0.9.0.M2 * Bumped guice from 5.1.0 to 6.0.0 * Bumped commons-io:commons-io from 2.11.0 to 2.15.1 * Bumped plexus-utils from 3.5.0 to 4.0.0 * Bumped org.codehaus.plexus:plexus-testing from 1.1.0 to 1.3.0

* Fix symbolic link are being resolved into absolute path * Fix symbolic links to directories are not recognized as directories * Fix issue related to symbolic link tests issue
plexus-interpolation was updated to version 1.27.0:

* Added support for PPC64LE * Added dependabot and release drafter configuration * Moved to Junit5

* Bumped plexus from 7 to 16 * Bumped maven-bundle-plugin from 3.0.1 to 5.1.9
plexus-cli was updated to version 1.7:

* Bumped plexus-components from 6.5 to 10.0 * Bumped checkstyle from 9.2 to 9.2.1 * Bumped plexus-container-default from 1.0-alpha-34 to 2.1.1 * Bumped checkstyle from 9.2.1 to 9.3 * Bumped commons-cli from 1.0 to 1.5.0 * Bumped maven-checkstyle-plugin from 3.1.2 to 3.3.0 * Bumped maven-shared-resources from 4 to 5 * Bumped apache/maven-gh-actions-shared from 1 to 3 * Updated to Parent pom 15 * Bumped commons-cli:commons-cli from 1.5.0 to 1.6.0 * Reuse plexus-pom action for CI * Bumped org.codehaus.plexus:plexus from 15 to 16 * Replace plexus-container-default with Sisu Plexus * Bumped org.codehaus.plexus:plexus-testing from 1.2.0 to 1.3.0
plexus-cipher was updated to version 2.1.0:

* Switched to java.util.Base64 * Moved code to Java 8 * Fixed insecure cryptography in PBECipher.java * Enabled missed decryption test and adjust to new algorithm
plexus-archiver was updated to version 4.9.2:

* Allow copy all files without timestamp checking by DirectoryArchiver * Provide fluent setter for usingDefaultExcludes flag in AbstractFileSet * Various dependencies were upgraded
plexus-interactivity was updated to version 1.3:

+ Ensure prompter does not double colon + Java 8 as mininum + Moved off plexus

* The class previously in plexus-interactivity-jdom artifact is folded into the main plexus-interactivity-api.
maven-shared-incremental:


Advisory IDSUSE-RU-2024:2647-1
ReleasedTue Jul 30 10:44:44 2024
SummaryRecommended update for Java
Typerecommended
Severitymoderate
References
Description:

This update for Java fixes the following issues:
antinject was updated to version 1.0.5:





* This release corrects the 1.0.2 release which was incorrectly done from the master branch with the jakarta.* packages. * It adds the Automatic-Module-Name=java.inject to the api jar manifest.

* Set Automatic-Module-Name to java.inject * Added OSGi bundle headers

* Added Automatic-Module-Name of jakarta.inject

* First Injection API release for Jakarta EE
cdi-api:

google-guice was updated to version 6.0.0:

* JEE Jakarta Transition:
+ Guice 6.0 adds support for jakarta.inject, the new namespace for the JSR330 spec (after the javax -> jakarta JEE transition). Guice 6.0 is intended to help users migrate their code to the jakarta namespace. It continues to fully support the javax.inject namespace while also mostly supporting the jakarta.inject namespace. The only part of Guice 6.0 that doesn't support jakarta.inject are the bind(..).toProvider methods. Those methods still require javax.inject or com.google.inject Providers. + The Guice 6.0 servlet & persist extensions only support the javax.servlet and javax.persistence namespaces respectively. + Guice 6.0 can help with incremental migrations to the jakarta.inject namespace, by incrementally replacing javax.inject references to jakarta.inject. This works everywhere, except for code where a jakarta Provider is passed to bind(..).toProvider. * Guice Core:
+ Adds jakarta.inject support. + Support Java 21 (via updating ASM to 9.5 and other changes). + Improve AOP support on JVMs such as Azul. + Fix a deadlock or crash associated with recursively loading just-in-time bindings. + Make PrivateModule.binder() non-private, to allow subclass customization, such as calling skipSources. + Fix an endloop loop (that can OOM) in singleton lock cycle detection. + Fix tests to pass on Windows, despite the different line separator. + Improvements to OSGi metadata. + Mark the JSR305 dependency as optional (since it's not required at runtime). + Fix Binder.requestInjection(TypeLiteral, T) to use the TypeLiteral. + Honor scoping annotations on concrete types when provisioned by their @ProvidedBy annotation + Add a way to tell if a class is 'enhanced' by Guice, and retrieve the original class. + Ensure the order of bind(...) statements does not matter when referring to JIT bindings. + Implement Matcher.and and Matcher.or as default methods directly in Matcher, so that the AbstractMatcher subclass isn't required. + Mark the error_prone_annotations dependency as optional.
* Servlet:
+ Fix an NPE if contextPath is null
* Persist: + Persist had a number of changes, some of which are backwards incompatible. Notably: injection of EntityManager no longer implicitly starts a unit of work (because this led to leaks). Users can opt-in to the legacy behavior by constructing the JpaPersistModule with a JpaPersistOptions that sets setAutoBeginWorkOnEntityManagerCreation to true. + EntityManager provisioning no longer automatically starts an unit of work. + Ignore multiple start/stop calls, rather than throwing an exception. + Support manually initiated rollbacks. + Don't wrap Object-defined methods (e.g: toString, finalize, equals, hashCode) in transactions.
gradle-bootstrap:

gradle:


maven-artifact-transfer, maven-doxia-sitetools, maven-doxia, maven-plugin-testing, maven-surefire:

maven-javadoc-plugin:

modello:

plexus-component-metadata and plexus-containers were updated to version 2.2.0:

* This will be needed for smooth upgrade to plexus-utils 4.0.0

* Improved documentation to switch to Sisu * Cleaned up poms after parent upgrade * Improved plexus-component metadata - removed dependency to plexus-container-default * Added deprecation information to Plexus components * Require Java 8 * Dropped plexus-container-default artefact * Require Maven 3.6.3+ * Switched to Junit5 * Bumped org.eclipse.sisu.plexus from 0.3.0.M1 to 0.9.0.M2

* Last version before deprecation * Requires Java 7 and Maven 3.2.5+ * Upgraded ASM to 9.2 * Security upgrade org.jdom:jdom2 from 2.0.6 to 2.0.6.1
plexus-utils was updated to version 4.0.0:

* Starting with version 4, XML classes (in org.codehaus.plexus.util.xml and org.codehaus.plexus.util.xml.pull) have been extracted to a separate plexus-xml: if you need them, just use this new artifact\
* Other changes:
+ Fixed false difference detected with CachingOutputStream/CachingWriter when streams are flushed + Dependency updates + Switched to Junit 5 plexus-xml was update to version 3.0.1:

* Bugs fixed:
+ Allow nulls for write elements in MXSerializer + Removed special chars from xml output
* Dependency updates:
+ Bumped org.codehaus.plexus:plexus from 17 to 18 + Bumped release-drafter/release-drafter from 5 to 6 + Bumped parent to 17 and updates
* Maintenance:
+ Switched to Junit 5 + Switched to shared gh actions setup from master branch
sbt:

sisu was updated to version 0.9.0.M3:

* Annotated new method * Updated workflow to run on Java 21 * Build with final Java 21 on GitHub * Switched to JUnit5 * Disabled annotation processor by default * Do not silently fail in case of class scanning exceptions * Updated to ASM 9.7 * Updated CONTRIBUTING.md * Aligned Plexus ASM version * Renamed release profile * Fixed Jacoco coverage repots in Sonar * Added a method to allow LifecycleManager to free keys * Licence change: From EPL1 to EPL2 * Updated documentation for exposed core extensions, fix anchors * Trigger Sonarcloud analysis from GHA

* Fixed SpaceScanner to use latest ASM API version * 3.7 is not an officially supported version therefore specify3.8 instead * Provide script to help upgrade embedded copy of ASM * ASM_9_4 * Require Java 8 * Sisu specific PreConstruct/PreDestroy annotations * Updated build plugins * ASM 9.5 * Aligned to latest Maven plugins * Moved release elements from oss-parent to local project * Create a 'no_asm' jar at release time which doesn't embed ASM

* Fixed CDI related issues * Build with Eclipse/Tycho 2.5.0 and Java 11 * Raise problem reporting logs to DEBUG, fixes #36 * Upgraded internal copy of ASM to 9.2 * Implemented PathTypeConverter * Added JUnit 5 annotations to InjectedTest setUp/tearDown * Fixed static parameters binding lookup * Run injection tests against multiple versions of Guice * Support using @priority on Providers * Use read lock when subscribing to publishers… * Cache binding lookups for single bean providers * Use AtomicReferenceFieldUpdater as it works better for large numbers of instances * Enabled Java CI workflow * Enabled CodeQL analysis * Replaced potentially-expensive regex with simple tokenizer * Allow Main to boot with extra bindings * Re-enabled various resource-related unit tests * Reworked globber pattern strategy to avoid use of regex * Use GlobberStrategy.PATTERN instead of regex for ServiceBindings filtering

* Make build work with Java17 * Aligned to latest Maven plugins * Moved release elements from oss-parent to local project

* Aligned logback with sisu.inject * Build with Eclipse/Tycho 2.5.0 and Java 11 * Support configuration of collections with complex generic types * Enabled Java CI workflow * Enabled CodeQL analysis
sisu-mojos:


Advisory IDSUSE-RU-2024:2667-1
ReleasedTue Jul 30 16:14:01 2024
SummaryRecommended update for libxkbcommon
Typerecommended
Severitymoderate
References1218640,1228322
Description:


This update of libxkbcommon fixes the following issue:


SUSE-CU-2024:3241-1

Container Advisory IDSUSE-CU-2024:3241-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-16.6 , bci/openjdk-devel:latest
Container Release16.6
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:2578-1
ReleasedMon Jul 22 12:36:15 2024
SummarySecurity update for java-21-openjdk
Typesecurity
Severityimportant
References1227298,1228046,1228047,1228048,1228051,1228052,CVE-2024-21131,CVE-2024-21138,CVE-2024-21140,CVE-2024-21145,CVE-2024-21147
Description:

This update for java-21-openjdk fixes the following issues:
Updated to version 21.0.4+7 (July 2024 CPU):


SUSE-CU-2024:3201-1

Container Advisory IDSUSE-CU-2024:3201-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-16.4 , bci/openjdk-devel:latest
Container Release16.4
The following patches have been included in this update:

SUSE-CU-2024:3132-1

Container Advisory IDSUSE-CU-2024:3132-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-15.3 , bci/openjdk-devel:latest
Container Release15.3
The following patches have been included in this update:

SUSE-CU-2024:3072-1

Container Advisory IDSUSE-CU-2024:3072-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-14.9 , bci/openjdk-devel:latest
Container Release14.9
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:2307-1
ReleasedFri Jul 5 12:04:34 2024
SummarySecurity update for krb5
Typesecurity
Severityimportant
References1227186,1227187,CVE-2024-37370,CVE-2024-37371
Description:

This update for krb5 fixes the following issues:


SUSE-CU-2024:3024-1

Container Advisory IDSUSE-CU-2024:3024-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-14.6 , bci/openjdk-devel:latest
Container Release14.6
The following patches have been included in this update:

SUSE-CU-2024:2991-1

Container Advisory IDSUSE-CU-2024:2991-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-14.5 , bci/openjdk-devel:latest
Container Release14.5
The following patches have been included in this update:
Advisory IDSUSE-SU-2019:2730-1
ReleasedMon Oct 21 16:04:57 2019
SummarySecurity update for procps
Typesecurity
Severityimportant
References1092100,1121753,CVE-2018-1122,CVE-2018-1123,CVE-2018-1124,CVE-2018-1125,CVE-2018-1126
Description:

This update for procps fixes the following issues:
procps was updated to 3.3.15. (bsc#1092100)
Following security issues were fixed:



Also this non-security issue was fixed:

The update to 3.3.15 contains the following fixes:


Advisory IDSUSE-RU-2020:225-1
ReleasedFri Jan 24 06:49:07 2020
SummaryRecommended update for procps
Typerecommended
Severitymoderate
References1158830
Description:

This update for procps fixes the following issues:


Advisory IDSUSE-RU-2020:2958-1
ReleasedTue Oct 20 12:24:55 2020
SummaryRecommended update for procps
Typerecommended
Severitymoderate
References1158830
Description:

This update for procps fixes the following issues:


Advisory IDSUSE-RU-2021:1169-1
ReleasedTue Apr 13 15:01:42 2021
SummaryRecommended update for procps
Typerecommended
Severitylow
References1181976
Description:

This update for procps fixes the following issues:


Advisory IDSUSE-RU-2021:1549-1
ReleasedMon May 10 13:48:00 2021
SummaryRecommended update for procps
Typerecommended
Severitymoderate
References1185417
Description:

This update for procps fixes the following issues:


Advisory IDSUSE-RU-2022:808-1
ReleasedFri Mar 11 06:07:58 2022
SummaryRecommended update for procps
Typerecommended
Severitymoderate
References1195468
Description:

This update for procps fixes the following issues:


Advisory IDSUSE-RU-2022:2944-1
ReleasedWed Aug 31 05:39:14 2022
SummaryRecommended update for procps
Typerecommended
Severityimportant
References1181475
Description:

This update for procps fixes the following issues:


Advisory IDSUSE-RU-2023:181-1
ReleasedThu Jan 26 21:55:43 2023
SummaryRecommended update for procps
Typerecommended
Severitylow
References1206412
Description:

This update for procps fixes the following issues:


Advisory IDSUSE-RU-2023:2104-1
ReleasedThu May 4 21:05:30 2023
SummaryRecommended update for procps
Typerecommended
Severitymoderate
References1209122
Description:

This update for procps fixes the following issue:


Advisory IDSUSE-SU-2023:3440-1
ReleasedMon Aug 28 08:57:10 2023
SummarySecurity update for gawk
Typesecurity
Severitylow
References1214025,CVE-2023-4156
Description:

This update for gawk fixes the following issues:


Advisory IDSUSE-SU-2023:3472-1
ReleasedTue Aug 29 10:55:16 2023
SummarySecurity update for procps
Typesecurity
Severitylow
References1214290,CVE-2023-4016
Description:

This update for procps fixes the following issues:
- CVE-2023-4016: Fixed ps buffer overflow (bsc#1214290).


Advisory IDSUSE-RU-2024:11-1
ReleasedTue Jan 2 13:24:52 2024
SummaryRecommended update for procps
Typerecommended
Severitymoderate
References1029961,1158830,1206798,1209122
Description:

This update for procps fixes the following issues:




* library: Incremented to 8:3:0 (no removals or additions, internal changes only) * all: properly handle utf8 cmdline translations * kill: Pass int to signalled process * pgrep: Pass int to signalled process * pgrep: Check sanity of SG_ARG_MAX * pgrep: Add older than selection * pidof: Quiet mode * pidof: show worker threads * ps.1: Mention stime alias * ps: check also match on truncated 16 char comm names * ps: Add exe output option * ps: A lot more sorting available * pwait: New command waits for a process * sysctl: Match systemd directory order * sysctl: Document directory order * top: ensure config file backward compatibility * top: add command line 'e' for symmetry with 'E' * top: add '4' toggle for two abreast cpu display * top: add '!' toggle for combining multiple cpus * top: fix potential SEGV involving -p switch * vmstat: Wide mode gives wider proc columns * watch: Add environment variable for interval * watch: Add no linewrap option * watch: Support more colors * free,uptime,slabtop: complain about extra ops




* library: Increment to 8:2:0
No removals or functions Internal changes only, so revision is incremented. Previous version should have been 8:1:0 not 8:0:1
* docs: Use correct symbols for -h option in free.1 * docs: ps.1 now warns about command name length * docs: install translated man pages * pgrep: Match on runstate * snice: Fix matching on pid * top: can now exploit 256-color terminals * top: preserves 'other filters' in configuration file * top: can now collapse/expand forest view children * top: parent %CPU time includes collapsed children * top: improve xterm support for vim navigation keys * top: avoid segmentation fault at program termination * 'ps -C' does not allow anymore an argument longer than 15 characters (bsc#1158830)


Advisory IDSUSE-feature-2024:1664-1
ReleasedThu May 16 07:56:10 2024
SummaryFeature update for Java
Typefeature
Severitymoderate
References
Description:

This update for byte-buddy, javadoc-parser, jurand, modulemaker-maven-plugin, open-test-reporting, plexus-xml fixes the following issues:
byte-buddy:


javadoc-parser:

jurand:

modulemaker-maven-plugin:

open-test-reporting:

plexus-xml:


Advisory IDSUSE-RU-2024:2000-1
ReleasedWed Jun 12 05:43:59 2024
SummaryRecommended update for Java
Typerecommended
Severitymoderate
References
Description:

This update for Java fixes the following issues:
javadoc-parser:

maven-filtering was updated to version 3.3.2:

+ pick correct hamcrest dependency + Prefer commons lang to plexus utils + MSHARED-1214: move tag back to HEAD + MSHARED-1216: Use caching output stream + Bump org.codehaus.plexus:plexus-utils from 3.0.16 to 3.0.24 in /src/test/resources + Fix typos and grammar + Fix 'licenced' typo in PR template + refactor IncrementalResourceFilteringTest + MSHARED-1340: Require Maven 3.6.3+ + Bump commons-io:commons-io from 2.11.0 to 2.15.1 + Bump org.apache.commons:commons-lang3 from 3.12.0 to 3.14.0 + MSHARED-1339: Bump org.apache.maven.shared:maven-shared-components from 39 to 41 + MSHARED-1290: Fix PropertyUtils cycle detection results in false positives + MSHARED-1285: use an up-to-date scanner instead the newscanner + Bump org.codehaus.plexus:plexus-testing from 1.2.0 to 1.3.0 + Bump org.codehaus.plexus:plexus-interpolation from 1.26 to 1.27 + Bump org.codehaus.plexus:plexus-utils from 3.5.1 to 4.0.0 + Bump release-drafter/release-drafter from 5 to 6 + Bump org.junit.jupiter:junit-jupiter-api from 5.10.1 to 5.10.2 + MSHARED-1351: Fix console message when origin is baseDir + MSHARED-1050: Fix ConcurrentModificationException for maven-filtering + MSHARED-1330: Always overwrite files

* Changes:
+ MSHARED-1175: Copying x resources from rel/path to rel/path + MSHARED-1213: Bug: filtering existing but 0 byte file + MSHARED-1199: Upgrade parent pom to 39 + MSHARED-1112: Ignore setting permissions on non existing dest files/symlinks + MSHARED-1144: remove rendundant error message

* Changes:
+ Fixed cloning of MavenResourcesExecution's instances using copyOf() method + MRESOURCES-258: Copying and filtering logic is delegated to FileUtils + replace deprecated methods + replace deprecated code in favor of Java 7 core and apache commons libraries declare dependencies + MSHARED-1080: Parent POM 36, Java8, drop legacy.
maven-plugin-tools:

modello was updated to version 2.4.0:

* New features and improvements:
+ Keep license structure + Support addition of license header to generated files + Make generated code - Java 8 based by default + threadsafety
* Bugs fixed:
+ Revert snakeyaml to 1.33 (as 2.x is not fully compatible with 1.x).

* Changes:
+ Kill off dead Plexus + Fix for #366

* Changes:
+ Parse javadoc tags in xdoc generator (only @since is supported atm) + Use generic in Xpp3Reader for JDK 5+ + Get rid of usage deprecated Reader/WriterFactory + Make spotless plugin work with Java 21 + Support java source property being discovered as 1.x + Fix thread safety issues by not using singletons for generators + Improve discovering javaSource based on maven.compiler properties, default as 8 + Switch Plexus Annotation to JSR-330 + Make spotless plugin work with Java 21

plexus-build-api was updated to version 1.2.0:
* Potentially breaking changes:
+ change package to org.codehaus.plexus.build
* New features and improvements:
+ Convert to JSR 330 component + Bump sisu-maven-plugin from 0.3.5 to 0.9.0.M2 + Switch to parent 13 and reformat + Use a CachingOutputStream when using the build context + Reuse plexus-pom action for CI + Add README and LICENSE + Remove ThreadBuildContext
* Bugs fixed:
+ Store Objects in the DefaultContext in a map + Let the DefaultBuildContext delegate to the legacy build-api
plexus-build-api0 was implemented at version 0.0.8:

plexus-xml:


Advisory IDSUSE-RU-2024:2079-1
ReleasedWed Jun 19 05:41:08 2024
SummaryRecommended update for Java
Typerecommended
Severitymoderate
References
Description:

This update for Gradle and Maven fixes the following issues:
gradle-bootstrap:


gradle:

maven-artifact-transfer:

maven-assembly-plugin, maven-doxia, maven-doxia-sitetools, maven-install-plugin, maven-javadoc-plugin, maven-plugin-testing, maven-resolver, maven:


Advisory IDSUSE-RU-2024:2086-1
ReleasedWed Jun 19 11:48:24 2024
SummaryRecommended update for gcc13
Typerecommended
Severitymoderate
References1188441
Description:

This update for gcc13 fixes the following issues:
Update to GCC 13.3 release


Advisory IDSUSE-RU-2024:2214-1
ReleasedTue Jun 25 17:11:26 2024
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1225598
Description:

This update for util-linux fixes the following issue:


Advisory IDSUSE-RU-2024:2239-1
ReleasedWed Jun 26 13:09:10 2024
SummaryRecommended update for systemd
Typerecommended
Severitycritical
References1226415
Description:

This update for systemd contains the following fixes:





Advisory IDSUSE-RU-2024:2255-1
ReleasedTue Jul 2 05:25:54 2024
SummaryRecommended update for Java
Typerecommended
Severitymoderate
References
Description:

This update for Java fixes the following issues:
maven-file-management:


maven-shared-io:
maven2:

maven-shared-utils was updated to version 3.3.4:

plexus-ant-factory:

plexus-bsh-factory:

plexus-cli:

plexus-i18n:

plexus-resources:

plexus-sec-dispatcher:

plexus-velocity:

tesla-polyglot:


Advisory IDSUSE-SU-2024:2277-1
ReleasedTue Jul 2 17:03:49 2024
SummarySecurity update for git
Typesecurity
Severityimportant
References1224168,1224170,1224171,1224172,1224173,CVE-2024-32002,CVE-2024-32004,CVE-2024-32020,CVE-2024-32021,CVE-2024-32465
Description:

This update for git fixes the following issues:


Advisory IDSUSE-OU-2024:2282-1
ReleasedTue Jul 2 22:41:28 2024
SummaryOptional update for openscap, scap-security-guide
Typeoptional
Severitymoderate
References
Description:


This update for scap-security-guide and openscap provides the SCAP tooling for SLE Micro 5.3, 5.4, 5.5.
This includes shipping openscap dependencies libxmlsec1-1 and libxmlsec1-openssl for SLE Micro.


SUSE-CU-2024:2800-1

Container Advisory IDSUSE-CU-2024:2800-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-11.15
Container Release11.15
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:2060-1
ReleasedTue Jun 18 13:11:47 2024
SummarySecurity update for less
Typesecurity
Severityimportant
References1222849,CVE-2024-32487
Description:

This update for less fixes the following issues:


Advisory IDSUSE-SU-2024:2066-1
ReleasedTue Jun 18 13:16:09 2024
SummarySecurity update for openssl-3
Typesecurity
Severityimportant
References1223428,1224388,1225291,1225551,CVE-2024-4603,CVE-2024-4741
Description:

This update for openssl-3 fixes the following issues:
Security issues fixed:


Other issues fixed:


SUSE-CU-2024:2682-1

Container Advisory IDSUSE-CU-2024:2682-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-11.12
Container Release11.12
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2024-1
ReleasedThu Jun 13 16:15:18 2024
SummaryRecommended update for jitterentropy
Typerecommended
Severitymoderate
References1209627
Description:

This update for jitterentropy fixes the following issues:


Updated to 3.4.1


SUSE-CU-2024:2617-1

Container Advisory IDSUSE-CU-2024:2617-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-11.9
Container Release11.9
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:1997-1
ReleasedTue Jun 11 17:24:32 2024
SummaryRecommended update for e2fsprogs
Typerecommended
Severitymoderate
References1223596
Description:

This update for e2fsprogs fixes the following issues:


SUSE-CU-2024:2607-1

Container Advisory IDSUSE-CU-2024:2607-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-10.8
Container Release10.8
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:1956-1
ReleasedMon Jun 10 04:50:39 2024
SummaryRecommended update for google-errorprone, guava
Typerecommended
Severitymoderate
References
Description:

This update for google-errorprone, guava fixes the following issues:
guava:


* Changes of version 33.1.0:
+ Updated our Error Prone dependency to 2.26.1, which includes a JPMS-ready jar of annotations. If you use the Error Prone annotations in a modular build of your own code, you may need to add a requires line for them. + base: Added a Duration overload for Suppliers.memoizeWithExpiration. + base: Deprecated the remaining two overloads of Throwables.propagateIfPossible. They won't be deleted, but we recommend migrating off them. + cache: Fixed a bug that could cause false 'recursive load' reports during refresh. + graph: Changed the return types of transitiveClosure() and reachableNodes() to Immutable* types. reachableNodes() already returned an immutable object (even though that was not reflected in the declared return type); transitiveClosure() used to return a mutable object. The old signatures remain available, so this change does not break binary compatibility. + graph: Changed the behavior of views returned by graph accessor methods that take a graph element as input: They now throw IllegalStateException when that element is removed from the graph. + hash: Optimized Checksum-based hash functions for Java 9+. + testing: Exposed FakeTicker Duration methods to Android users. + util.concurrent: Deprecated the constructors of UncheckedExecutionException and ExecutionError that don't accept a cause. We won't remove these constructors, but we recommend migrating off them, as users of those classes often assume that instances will contain a cause. + util.concurrent: Improved the correctness of racy accesses for J2ObjC users.
* Changes of version 33.0.0:
+ This version of guava-android contains some package-private methods whose signature includes the Java 8 Collector API. This is a test to identify any problems before we expose those methods publicly to users. Please report any problems that you encounter. + Changed various classes to catch Exception instead of RuntimeException even when only RuntimeException is theoretically possible. This can help code that throws undeclared exceptions, as some bytecode rewriters (e.g., Robolectric) and languages (e.g., Kotlin) do. + Added an Automatic-Module-Name to failureaccess, Guava's one strong runtime dependency. + reflect: In guava-android only, removed Invokable.getAnnotatedReturnType() and Parameter.getAnnotatedType(). These methods never worked in an Android VM, and to reflect that, they were born @Deprecated, @Beta, and @DoNotCall. They're now preventing us from rolling out some new Android compatibility testing. This is the only binary-incompatible change in this release, and it should have no effect in practice. Still, we bump the major version number to follow Semantic Versioning. + util.concurrent: Changed our implementations to avoid eagerly initializing loggers during class loading. This can help performance, especially under Android.
* Changes of version 32.1.3:
+ Changed Gradle Metadata to include dependency versions directly. This may address 'Could not find some-dependency' errors that some users have reported (which might be a result of users' excluding guava-parent). + collect: Changed Multisets.unmodifiableMultiset(set) .removeIf(predicate) to throw an exception always, even if nothing matches predicate. + graph: Fixed the behavior of Graph/ValueGraph views for a node when that node is removed from the graph. + io: Fixed Files.createTempDir and FileBackedOutputStream under Windows services, a rare use case. (The fix actually covers only Java 9+ because Java 8 would require an additional approach. Let us know if you need support under Java 8.) + net: Made MediaType.parse allow and skip over whitespace around the / and = separator tokens in addition to the ; separator, for which it was already being allowed. + util.concurrent: Tweaked Futures.getChecked constructor-selection behavior: The method continues to prefer to call constructors with a String parameter, but now it breaks ties based on whether the constructor has a Throwable parameter. Beyond that, the choice of constructor remains undefined. (For this and other reasons, we discourage the use of getChecked.)
* Changes of version 32.1.2:
+ Removed the section of our Gradle metadata that caused Gradle to report conflicts with listenablefuture. + Changed our Maven project to avoid affecting which version of Mockito our Gradle users see. + collect: Under J2CL, exposed ImmutableList and ImmutableSet methods copyOf and of for JavaScript usage. + net: Optimized InternetDomainName construction.
* Changes of version 32.1.1:
+ Fixed our broken Gradle metadata from 32.1.0. Sorry again for the trouble. If you use Gradle, please still read the release notes from that version: You may still see errors from the new checking that the metadata enables, and the release notes discuss how to fix those errors.
* Changes of version 32.1.0:
+ collect: Tweaked more nullness annotations. + hash: Enhanced crc32c() to use Java's hardware-accelerated implementation where available. + util.concurrent: Added Duration-based default methods to ListeningExecutorService. + Began updating Javadoc to focus less on APIs that have been superseded by additions to the JDK. We're also looking to add more documentation that directs users to JDK equivalents for our APIs. Further PRs welcome! + Fixed some problems with using Guava from a Java Agent. (But we don't test that configuration, and we don't know how well we'll be able to keep it working.) + Fixed BootstrapMethodError when using CacheBuilder from a custom system class loader. (As with the previous item, we're not sure how well we'll be able to keep this use case working.) + Suppressed a harmless unusable-by-js warning seen by users of guava-gwt.

google-errorprone, google-errorprone-annotations:

* Changes of version 2.26.1:
+ Fixes the module name: from 'com.google.errorprone.annotation' to 'com.google.errorprone.annotations'. Amends the OSGi build not to include 'Automatic-Module-Name' in the MANIFEST.MF for the 'annotations' project.
* Changes of version 2.26.0:
+ The 'annotations' artifact now includes a module-info.java for Java Platform Module System support. + Disabled checks passed to -XepPatchChecks are now ignored, instead of causing a crash. + New checks:
- SystemConsoleNull: Null-checking System.console() is not a reliable way to detect if the console is connected to a terminal. - EnumOrdinal: Discourage uses of Enum.ordinal()
+ Closed issues:
- Add module-info.java - 2.19.x: Exception thrown when a disabled check is passed to -XepPatchChecks - Ignore disabled checks passed to -XepPatchChecks - feat: add jpms definition for annotations - Add the 'compile' goal for 'compile-java9'
* Changes of version 2.25.0:
+ New checks:
- JUnitIncompatibleType: Detects incompatible types passed to an assertion, similar to TruthIncompatibleType - RedundantSetterCall: Detects fields set twice in the same chained expression. Generalization of previous ProtoRedundantSet check to also handle AutoValue.
+ Closed issues:
- Crash in UnnecessaryStringBuilder - Fix typos - Add support for specifying badEnclosingTypes for BadImport via flags - Some BugPattern docs are missing code examples - Remove incorrect statement from BugPattern index doc - Do not report NonFinalStaticField findings for fields modified in @BeforeAll methods
* Changes of version 2.24.1:
+ Add an assertion to try to help debug
* Changes of version 2.24.0:
+ New checks:
- MultipleNullnessAnnotations: Discourage multiple nullness annotations - NullableTypeParameter: Discourage nullness annotations on type parameters - NullableWildcard: Discourage nullness annotations on wildcards - SuperCallToObjectMethod: Generalization of SuperEqualsIsObjectEquals, now covers hashCode
* Changes of version 2.23.0:
+ New checks: DuplicateDateFormatField, NonFinalStaticField, StringCharset, StringFormatWithLiteral, SuperEqualsIsObjectEquals + Bug fixes and improvements
* Changes of version 2.22.0:
+ New checks:
- ClosingStandardOutputStreams: Prevents accidentally closing System.{out,err} with try-with-resources - TruthContainsExactlyElementsInUsage: containsExactly is preferred over containsExactlyElementsIn when creating new iterables - UnnecessaryAsync: detects unnecessary use of async primitives in local (and hence single-threaded) scopes - ReturnAtTheEndOfVoidFunction: detects unnecessary return statements at the end of void functions - MultimapKeys: Suggests using keySet() instead of iterating over Multimap.keys(), which does not collapse duplicates
+ Bug fixes and improvements: - Don't complain about literal IP addresses in AddressSelection - Prevent SuggestedFixes#renameMethod from modifying return type declaration - Fix UnusedVariable false positives for private record parameters - When running in conservative mode, no longer assume that implementations of Map.get, etc. return null - CanIgnoreReturnValueSuggester: Support additional exempting method annotations - UnusedVariable: exclude junit5's @RegisterExtension - Support running all available patch checks - Upgrade java-diff-utils 4.0 -> 4.12 - Flag unused Refaster template parameters - Support @SuppressWarnings('all') - Prevent Refaster UMemberSelect from matching method parameters - MissingDefault : Don't require // fall out comments on expression switches - Skip UnnecessaryLambda findings for usages in enhanced for loops - Fix bug where nested MissingBraces violations' suggested fixes result in broken code - Add support for specifying exemptPrefixes/exemptNames for UnusedVariable via flags - UnusedMethod: Added exempting variable annotations
* Changes of version 2.21.1: + Handle overlapping ranges in suppressedRegions + Add AddressSelection to discourage APIs that convert a hostname to a single address
* Changes of version 2.21.0:
+ New Checkers:
- AttemptedNegativeZero: Prevents accidental use of -0, which is the same as 0. The floating-point negative zero is -0.0. - ICCProfileGetInstance: Warns on uses of ICC_Profile.getInstance(String), due to JDK-8191622. - MutableGuiceModule: Fields in Guice modules should be final. - NullableOptional: Discourages @Nullable-annotated Optionals. - OverridingMethodInconsistentArgumentNamesChecker: Arguments of overriding method are inconsistent with overridden method.
+ Fixed issues:
- Avoid MemberName IOOBE on lambda parameters inside overriding methods - Improve LockOnNonEnclosingClassLiteral documentation - Security scan reported high CVE for com.google.guava:guava:31.1-jre - Upgrade guava to 32.0.1 - Proposal: checker to prevent other checkers from calling javac methods that changed across JDKs - Add support in ASTHelpersSuggestions for getEnclosedElements
* Changes of version 2.20.0:
+ This release is compatible with early-access builds of JDK 21. + New Checkers: InlineTrivialConstant, UnnecessaryStringBuilder, BanClassLoader, DereferenceWithNullBranch, DoNotUseRuleChain, LockOnNonEnclosingClassLiteral, MissingRefasterAnnotation, NamedLikeContextualKeyword, NonApiType + Fixes issues:
- Introduce MissingRefasterAnnotation checker - Fix minor typo in URepeated - Drop unused constant Template#AUTOBOXING_DEFAULT - Introduce command-line flag -XepAllSuggestionsAsWarnings - JDK21 compatibility - Add OSGi runtime metadata to error-prone's MANIFEST.MF files - Use EISOP Checker Framework version 3.34.0-eisop1 - NotJavadoc pattern does not allow Javadoc on module declarations - ErrorProneInjector incorrectly picks up the no-args constructor - Several high CVEs related to dependency com.google.protobuf:protobuf-java:3.19.2 - Upgrade protobuf-java to 3.19.6
* Changes of version 2.19.1:
+ This release fixes a binary compatibility issue when running on JDK 11
* Changes of version 2.19.0:
+ New Checkers: NotJavadoc, StringCaseLocaleUsage, UnnecessaryTestMethodPrefix + Fixes issues:
- Exclude inner classes annotated with @Nested from ClassCanBeStatic rule - Optimize VisitorState#getSymbolFromName - ClassCanBeStatic: Exclude JUnit @Nested classes - BadImport: flag static import of newInstance methods - Support given for enforcing DirectInvocationOnMock: issue 3396 - Handle yield statement case in ASTHelpers#targetType - Should ASTHelpers.getSymbol(Tree) be annotated with @Nullable? - Fix '@' character in javadoc code snippets - Replace guava cache with caffeine - Discourage APIs locale-dependent APIs like String.to{Lower,Upper}Case - Introduce StringCaseLocaleUsage check
* Changes of version 2.18.0:
+ New Checkers: InjectOnBugCheckers, LabelledBreakTarget, UnusedLabel, YodaCondition + Fixes issues:
- @SuppressWarnings('InlineFormatString') doesn't work - Refaster: support method invocation type argument inlining - java.lang.IllegalArgumentException: Cannot edit synthetic AST nodes with specific record constructor - Rename class to match filename - Optimize VisitorState#getSymbolFromName - refactor: refactor bad smell UnusedLabel - LambdaFunctionalInterface crash with IllegalArgumentException when processing an enum constructor taking a lambda - Fix JDK 20-ea build compatibility - UngroupedOverloads: ignore generated constructors - [errorprone 2.17.0] NPE in StatementSwitchToExpressionSwitch.analyzeSwitchTree - StatementSwitchToExpressionSwitch: handle empty statement blocks - StatementSwitchToExpressionSwitch: only trigger on compatible target versions - Fix Finalize bugpattern to match protected finalize() - Make MemoizeConstantVisitorStateLookups check suppressible
* Changes of version 2.17.0:
+ New Checkers: AvoidObjectArrays, Finalize, IgnoredPureGetter, ImpossibleNullComparison, MathAbsoluteNegative, NewFileSystem, StatementSwitchToExpressionSwitch, UnqualifiedYield + Fixed issues:
- InvalidParam warning on Javadoc for Java record components - UnusedMethod flags @JsonValue methods as unused - UnusedMethod: Add more JPA lifecycle annotations or make annotations configurable - UnusedMethod: Support additional exempting method annotations - Have InvalidParam support records - Fix -XepDisableAllWarnings flag when passed on its own - ASTHelpersSuggestions does not flag call to packge() on com.sun.tools.javac.code.Symbol.ClassSymbol - @SupressWarnings on record compact constructor causes crash
* Changes of version 2.16.0:
+ New Checkers: ASTHelpersSuggestions, CanIgnoreReturnValueSuggester, LenientFormatStringValidation, UnnecessarilyUsedValue + Fixed issues: - Avoid using non-ASCII Unicode characters outside of comments and literals - NullPointerException thrown during analysis - NPE analysing new style switch statement (2.14.0) - ImmutableChecker handles null types - Drop pre-JDK 11 logic from Refaster's Inliner class
* Changes of version 2.15.0:
+ New Checkers: BuilderReturnThis, CanIgnoreReturnValueSuggester, CannotMockFinalClass, CannotMockFinalMethod, DirectInvocationOnMock, ExtendsObject, MockNotUsedInProduction, NoCanIgnoreReturnValueOnClasses, NullArgumentForNonNullParameter, SelfAlwaysReturnsThis, UnsafeWildcard, UnusedTypeParameter
* Changes of version 2.14.0:
+ New checkers: BanJNDI, EmptyTopLevelDeclaration, ErroneousBitwiseExpression, FuzzyEqualsShouldNotBeUsedInEqualsMethod, Interruption, NullableOnContainingClass
* Changes of version 2.13.1:
+ Fix a crash in UnnecessaryBoxedVariable + Include the unicode character in the diagnostic message
* Changes of version 2.13.0:
+ Handle all annotations with the simple name Generated in -XepDisableWarningsInGeneratedCode + Reconcile BugChecker#isSuppressed with suppression handling in ErrorProneScanner + Fix a bug in enclosingPackage + Improve performance of fix application + Implicitly treat @AutoBuilder setter methods as @CanIgnoreReturnValue. + Remove some obsolete checks (PublicConstructorForAbstractClass, HashCodeToString)
* Changes of version 2.12.1:
+ This release adds an infrastructure optimization to AppliedFix source code processing.
* Changes of version 2.12.0:
+ New checks: BoxedPrimitiveEquality, DoubleBraceInitialization, IgnoredPureGetter, LockOnBoxedPrimitive, IncorrectMainMethod, LongDoubleConversion, RobolectricShadowDirectlyOn, StaticAssignmentOfThrowable, UnnecessaryLongToIntConversion, Varifier


SUSE-CU-2024:2598-1

Container Advisory IDSUSE-CU-2024:2598-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-10.7
Container Release10.7
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:1943-1
ReleasedFri Jun 7 17:04:06 2024
SummarySecurity update for util-linux
Typesecurity
Severityimportant
References1218609,1220117,1221831,1223605,CVE-2024-28085
Description:

This update for util-linux fixes the following issues:


Advisory IDSUSE-RU-2024:1954-1
ReleasedFri Jun 7 18:01:06 2024
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1221482
Description:

This update for glibc fixes the following issues:


SUSE-CU-2024:2556-1

Container Advisory IDSUSE-CU-2024:2556-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-10.2
Container Release10.2
The following patches have been included in this update:

SUSE-CU-2024:2536-1

Container Advisory IDSUSE-CU-2024:2536-1
Container Tagsbci/openjdk-devel:21 , bci/openjdk-devel:21-9.4
Container Release9.4
The following patches have been included in this update:
Advisory IDSUSE-RU-2018:2307-1
ReleasedThu Oct 18 14:42:54 2018
SummaryRecommended update for libxcb
Typerecommended
Severitymoderate
References1101560
Description:

This update for libxcb provides the following fix:


Advisory IDSUSE-RU-2018:2569-1
ReleasedFri Nov 2 19:00:18 2018
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1110700
Description:

This update for pam fixes the following issues:


Advisory IDSUSE-RU-2018:2607-1
ReleasedWed Nov 7 15:42:48 2018
SummaryOptional update for gcc8
Typerecommended
Severitylow
References1084812,1084842,1087550,1094222,1102564
Description:


The GNU Compiler GCC 8 is being added to the Development Tools Module by this update.
The update also supplies gcc8 compatible libstdc++, libgcc_s1 and other gcc derived libraries for the Basesystem module of SUSE Linux Enterprise 15.
Various optimizers have been improved in GCC 8, several of bugs fixed, quite some new warnings added and the error pin-pointing and fix-suggestions have been greatly improved.
The GNU Compiler page for GCC 8 contains a summary of all the changes that have happened:
https://gcc.gnu.org/gcc-8/changes.html
Also changes needed or common pitfalls when porting software are described on:
https://gcc.gnu.org/gcc-8/porting_to.html


Advisory IDSUSE-SU-2018:2825-1
ReleasedMon Dec 3 15:35:02 2018
SummarySecurity update for pam
Typesecurity
Severityimportant
References1115640,CVE-2018-17953
Description:

This update for pam fixes the following issue:
Security issue fixed:


Advisory IDSUSE-SU-2018:2861-1
ReleasedThu Dec 6 14:32:01 2018
SummarySecurity update for ncurses
Typesecurity
Severityimportant
References1103320,1115929,CVE-2018-19211
Description:

This update for ncurses fixes the following issues:
Security issue fixed:


Non-security issue fixed:


Advisory IDSUSE-SU-2018:3044-1
ReleasedFri Dec 21 18:47:21 2018
SummarySecurity update for MozillaFirefox, mozilla-nspr and mozilla-nss
Typesecurity
Severityimportant
References1097410,1106873,1119069,1119105,CVE-2018-0495,CVE-2018-12384,CVE-2018-12404,CVE-2018-12405,CVE-2018-17466,CVE-2018-18492,CVE-2018-18493,CVE-2018-18494,CVE-2018-18498
Description:

This update for MozillaFirefox, mozilla-nss and mozilla-nspr fixes the following issues:
Issues fixed in MozillaFirefox:


Issues fixed in mozilla-nss:

Issues fixed in mozilla-nspr:


Advisory IDSUSE-RU-2019:44-1
ReleasedTue Jan 8 13:07:32 2019
SummaryRecommended update for acl
Typerecommended
Severitylow
References953659
Description:

This update for acl fixes the following issues:


Advisory IDSUSE-SU-2019:571-1
ReleasedThu Mar 7 18:13:46 2019
SummarySecurity update for file
Typesecurity
Severitymoderate
References1096974,1096984,1126117,1126118,1126119,CVE-2018-10360,CVE-2019-8905,CVE-2019-8906,CVE-2019-8907
Description:

This update for file fixes the following issues:
The following security vulnerabilities were addressed:


Advisory IDSUSE-SU-2019:788-1
ReleasedThu Mar 28 11:55:06 2019
SummarySecurity update for sqlite3
Typesecurity
Severitymoderate
References1119687,CVE-2018-20346
Description:

This update for sqlite3 to version 3.27.2 fixes the following issue:
Security issue fixed:


Release notes: https://www.sqlite.org/releaselog/3_27_2.html


Advisory IDSUSE-SU-2019:1040-1
ReleasedThu Apr 25 17:09:21 2019
SummarySecurity update for samba
Typesecurity
Severityimportant
References1114407,1124223,1125410,1126377,1131060,1131686,CVE-2019-3880
Description:

This update for samba fixes the following issues:
Security issue fixed:



ldb was updated to version 1.2.4 (bsc#1125410 bsc#1131686):


Non-security issues fixed:


Advisory IDSUSE-SU-2019:1127-1
ReleasedThu May 2 09:39:24 2019
SummarySecurity update for sqlite3
Typesecurity
Severitymoderate
References1130325,1130326,CVE-2019-9936,CVE-2019-9937
Description:

This update for sqlite3 to version 3.28.0 fixes the following issues:
Security issues fixed:


Advisory IDSUSE-SU-2019:1368-1
ReleasedTue May 28 13:15:38 2019
SummaryRecommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root
Typesecurity
Severityimportant
References1134524,CVE-2019-5021
Description:

This update for sles12sp3-docker-image, sles12sp4-image, system-user-root fixes the following issues:


Advisory IDSUSE-SU-2019:1372-1
ReleasedTue May 28 16:53:28 2019
SummarySecurity update for libtasn1
Typesecurity
Severitymoderate
References1105435,CVE-2018-1000654
Description:

This update for libtasn1 fixes the following issues:
Security issue fixed:


Advisory IDSUSE-RU-2019:2142-1
ReleasedWed Aug 14 18:14:04 2019
SummaryRecommended update for mozilla-nspr, mozilla-nss
Typerecommended
Severitymoderate
References1141322
Description:


This update for mozilla-nspr, mozilla-nss fixes the following issues:
mozilla-nss was updated to NSS 3.45 (bsc#1141322) :


mozilla-nspr was updated to version 4.21


Advisory IDSUSE-SU-2019:2533-1
ReleasedThu Oct 3 15:02:50 2019
SummarySecurity update for sqlite3
Typesecurity
Severitymoderate
References1150137,CVE-2019-16168
Description:

This update for sqlite3 fixes the following issues:
Security issue fixed:


Advisory IDSUSE-SU-2019:2997-1
ReleasedMon Nov 18 15:16:38 2019
SummarySecurity update for ncurses
Typesecurity
Severitymoderate
References1103320,1154036,1154037,CVE-2019-17594,CVE-2019-17595
Description:

This update for ncurses fixes the following issues:
Security issues fixed:


Non-security issue fixed:


Advisory IDSUSE-SU-2019:3061-1
ReleasedMon Nov 25 17:34:22 2019
SummarySecurity update for gcc9
Typesecurity
Severitymoderate
References1114592,1135254,1141897,1142649,1142654,1148517,1149145,CVE-2019-14250,CVE-2019-15847,SLE-6533,SLE-6536
Description:



This update includes the GNU Compiler Collection 9.
A full changelog is provided by the GCC team on:
https://www.gnu.org/software/gcc/gcc-9/changes.html

The base system compiler libraries libgcc_s1, libstdc++6 and others are now built by the gcc 9 packages.
To use it, install 'gcc9' or 'gcc9-c++' or other compiler brands and use CC=gcc-9 / CXX=g++-9 during configuration for using it.

Security issues fixed:


Non-security issues fixed:


Advisory IDSUSE-SU-2019:3086-1
ReleasedThu Nov 28 10:02:24 2019
SummarySecurity update for libidn2
Typesecurity
Severitymoderate
References1154884,1154887,CVE-2019-12290,CVE-2019-18224
Description:

This update for libidn2 to version 2.2.0 fixes the following issues:


Advisory IDSUSE-SU-2019:3395-1
ReleasedMon Dec 30 14:05:06 2019
SummarySecurity update for mozilla-nspr, mozilla-nss
Typesecurity
Severitymoderate
References1141322,1158527,1159819,CVE-2018-18508,CVE-2019-11745,CVE-2019-17006
Description:

This update for mozilla-nspr, mozilla-nss fixes the following issues:
mozilla-nss was updated to NSS 3.47.1:
Security issues fixed:


mozilla-nspr was updated to version 4.23:


Advisory IDSUSE-RU-2020:362-1
ReleasedFri Feb 7 11:14:20 2020
SummaryRecommended update for libXi
Typerecommended
Severitymoderate
References1153311
Description:


This update for libXi fixes the following issue:


Advisory IDSUSE-RU-2020:525-1
ReleasedFri Feb 28 11:49:36 2020
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1164562
Description:

This update for pam fixes the following issues:


Advisory IDSUSE-RU-2020:689-1
ReleasedFri Mar 13 17:09:01 2020
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1166510
Description:


This update for PAM fixes the following issue:


Advisory IDSUSE-RU-2020:917-1
ReleasedFri Apr 3 15:02:25 2020
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1166510
Description:

This update for pam fixes the following issues:


Advisory IDSUSE-SU-2020:948-1
ReleasedWed Apr 8 07:44:21 2020
SummarySecurity update for gmp, gnutls, libnettle
Typesecurity
Severitymoderate
References1152692,1155327,1166881,1168345,CVE-2020-11501
Description:

This update for gmp, gnutls, libnettle fixes the following issues:
Security issue fixed:


FIPS related bugfixes:


Advisory IDSUSE-RU-2020:1226-1
ReleasedFri May 8 10:51:05 2020
SummaryRecommended update for gcc9
Typerecommended
Severitymoderate
References1149995,1152590,1167898
Description:

This update for gcc9 fixes the following issues:
This update ships the GCC 9.3 release.


Advisory IDSUSE-SU-2020:1294-1
ReleasedMon May 18 07:38:36 2020
SummarySecurity update for file
Typesecurity
Severitymoderate
References1154661,1169512,CVE-2019-18218
Description:

This update for file fixes the following issues:
Security issues fixed:


Non-security issue fixed:


Advisory IDSUSE-RU-2020:1328-1
ReleasedMon May 18 17:16:04 2020
SummaryRecommended update for grep
Typerecommended
Severitymoderate
References1155271
Description:

This update for grep fixes the following issues:


Advisory IDSUSE-SU-2020:1353-1
ReleasedWed May 20 13:02:32 2020
SummarySecurity update for freetype2
Typesecurity
Severitymoderate
References1079603,1091109,CVE-2018-6942
Description:

This update for freetype2 to version 2.10.1 fixes the following issues:
Security issue fixed:


Non-security issues fixed:









Advisory IDSUSE-RU-2020:1507-1
ReleasedFri May 29 17:23:52 2020
SummaryRecommended update for publicsuffix
Typerecommended
Severitymoderate
References1171819
Description:

This update for publicsuffix fixes the following issues:



















Advisory IDSUSE-SU-2020:1677-1
ReleasedThu Jun 18 18:16:39 2020
SummarySecurity update for mozilla-nspr, mozilla-nss
Typesecurity
Severityimportant
References1159819,1169746,1171978,CVE-2019-17006,CVE-2020-12399
Description:

This update for mozilla-nspr, mozilla-nss fixes the following issues:
mozilla-nss was updated to version 3.53

Release notes: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.53_release_notes
mozilla-nspr to version 4.25


Advisory IDSUSE-RU-2020:1852-1
ReleasedMon Jul 6 16:50:23 2020
SummaryRecommended update for fontforge, ghostscript-fonts, ttf-converter, xorg-x11-fonts
Typerecommended
Severitymoderate
References1169444
Description:

This update for fontforge, ghostscript-fonts, ttf-converter, xorg-x11-fonts fixes the following issues:
Changes in fontforge:


Changes in ttf-converter:

--shift-unicode-values: When passed 3 comma separated numbers a,b,c this shifts the unicode values of glyphs between a and b (both included) by adding c. Can be used more than once. * Add --bitmapTransform parameter to transform bitmap glyphs. (bsc#1169444) When used, all glyphs are modified with the transformation function and values passed as parameters. The parameter has three values separated by commas: fliph|flipv|rotate90cw|rotate90ccw|rotate180|skew|transmove,xoff,yoff * Add support to convert bitmap fonts (bsc#1169444) * Rename MediumItalic subfamily to Medium Italic * Show some more information when removing duplicated glyphs * Add a --force-monospaced argument instead of hardcoding font names * Convert `BoldCond` subfamily to `Bold Condensed` * Fixes for Monospaced fonts and force the Nimbus Mono L font to be Monospaced. (bsc#1169444 #c41) * Add a --version argument * Fix subfamily names so the converted font's subfamily match the original ones. (bsc#1169444 #c41)
Changes in xorg-x11-fonts:

Changes in ghostscript-fonts:


Advisory IDSUSE-RU-2020:2083-1
ReleasedThu Jul 30 10:27:59 2020
SummaryRecommended update for diffutils
Typerecommended
Severitymoderate
References1156913
Description:

This update for diffutils fixes the following issue:


Advisory IDSUSE-SU-2020:2116-1
ReleasedTue Aug 4 15:12:41 2020
SummarySecurity update for libX11
Typesecurity
Severityimportant
References1174628,CVE-2020-14344
Description:

This update for libX11 fixes the following issues:


Advisory IDSUSE-SU-2020:2373-1
ReleasedFri Aug 28 12:58:51 2020
SummarySecurity update for SUSE Manager 4.1.1
Typesecurity
Severitymoderate
References1136857,1165572,1169553,1169780,1170244,1170468,1170654,1171281,1172279,1172504,1172709,1172807,1172831,1172839,1173169,1173522,1173535,1173554,1173566,1173584,1173932,1173982,1173997,1174025,1174167,1174201,1174229,1174325,1174405,1174470,1174965,1175485,1175555,1175558,1175724,1175791,678126,CVE-2020-11022
Description:

This consolidated update includes multiple patchinfos for SUSE Manager Server and Proxy. This patchinfo is used for the codestream release only.


Advisory IDSUSE-SU-2020:2947-1
ReleasedFri Oct 16 15:23:07 2020
SummarySecurity update for gcc10, nvptx-tools
Typesecurity
Severitymoderate
References1172798,1172846,1173972,1174753,1174817,1175168,CVE-2020-13844
Description:

This update for gcc10, nvptx-tools fixes the following issues:
This update provides the GCC10 compiler suite and runtime libraries.
The base SUSE Linux Enterprise libraries libgcc_s1, libstdc++6 are replaced by the gcc10 variants.
The new compiler variants are available with '-10' suffix, you can specify them via:
CC=gcc-10 CXX=g++-10
or similar commands.
For a detailed changelog check out https://gcc.gnu.org/gcc-10/changes.html
Changes in nvptx-tools:


Advisory IDSUSE-RU-2020:2983-1
ReleasedWed Oct 21 15:03:03 2020
SummaryRecommended update for file
Typerecommended
Severitymoderate
References1176123
Description:

This update for file fixes the following issues:


Advisory IDSUSE-SU-2020:2995-1
ReleasedThu Oct 22 10:03:09 2020
SummarySecurity update for freetype2
Typesecurity
Severityimportant
References1177914,CVE-2020-15999
Description:

This update for freetype2 fixes the following issues:


Advisory IDSUSE-SU-2020:3091-1
ReleasedThu Oct 29 16:35:37 2020
SummarySecurity update for MozillaThunderbird and mozilla-nspr
Typesecurity
Severityimportant
References1174230,1176384,1176756,1176899,1177977,CVE-2020-15673,CVE-2020-15676,CVE-2020-15677,CVE-2020-15678,CVE-2020-15683,CVE-2020-15969
Description:

This update for MozillaThunderbird and mozilla-nspr fixes the following issues:



Advisory IDSUSE-RU-2020:3462-1
ReleasedFri Nov 20 13:14:35 2020
SummaryRecommended update for pam and sudo
Typerecommended
Severitymoderate
References1174593,1177858,1178727
Description:

This update for pam and sudo fixes the following issue:
pam:


sudo:


Advisory IDSUSE-RU-2020:3620-1
ReleasedThu Dec 3 17:03:55 2020
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References
Description:

This update for pam fixes the following issues:


Advisory IDSUSE-RU-2020:3772-1
ReleasedMon Dec 14 11:11:29 2020
SummaryRecommended update for hamcrest
Typerecommended
Severitymoderate
References1174544
Description:

This update for hamcrest fixes the following issue:


Advisory IDSUSE-RU-2020:3942-1
ReleasedTue Dec 29 12:22:01 2020
SummaryRecommended update for libidn2
Typerecommended
Severitymoderate
References1180138
Description:

This update for libidn2 fixes the following issues:


Advisory IDSUSE-RU-2021:65-1
ReleasedMon Jan 11 15:11:49 2021
SummaryRecommended update for hamcrest
Typerecommended
Severitylow
References1120493,1179994
Description:

This update for hamcrest fixes the following issues:


Advisory IDSUSE-RU-2021:220-1
ReleasedTue Jan 26 14:00:51 2021
SummaryRecommended update for keyutils
Typerecommended
Severitymoderate
References1180603
Description:

This update for keyutils fixes the following issues:


Advisory IDSUSE-RU-2021:293-1
ReleasedWed Feb 3 12:52:34 2021
SummaryRecommended update for gmp
Typerecommended
Severitymoderate
References1180603
Description:

This update for gmp fixes the following issues:


Advisory IDSUSE-OU-2021:339-1
ReleasedMon Feb 8 13:16:07 2021
SummaryOptional update for pam
Typeoptional
Severitylow
References
Description:

This update for pam fixes the following issues:


This patch is optional to be installed - it doesn't fix any bugs.


Advisory IDSUSE-RU-2021:924-1
ReleasedTue Mar 23 10:00:49 2021
SummaryRecommended update for filesystem
Typerecommended
Severitymoderate
References1078466,1146705,1175519,1178775,1180020,1180083,1180596,1181011,1181831,1183094
Description:

This update for filesystem the following issues:


This update for systemd fixes the following issues:


Advisory IDSUSE-SU-2021:1007-1
ReleasedThu Apr 1 17:47:20 2021
SummarySecurity update for MozillaFirefox
Typesecurity
Severityimportant
References1183942,CVE-2021-23981,CVE-2021-23982,CVE-2021-23984,CVE-2021-23987
Description:

This update for MozillaFirefox fixes the following issues:


Advisory IDSUSE-SU-2021:1282-1
ReleasedTue Apr 20 14:47:17 2021
SummarySecurity update for apache-commons-io
Typesecurity
Severitymoderate
References1184755,CVE-2021-29425
Description:

This update for apache-commons-io fixes the following issues:


Advisory IDSUSE-SU-2021:1409-1
ReleasedWed Apr 28 16:32:50 2021
SummarySecurity update for giflib
Typesecurity
Severitylow
References1184123
Description:

This update for giflib fixes the following issues:


Advisory IDSUSE-RU-2021:1563-1
ReleasedTue May 11 11:16:00 2021
SummaryRecommended update for maven
Typerecommended
Severitymoderate
References1184022
Description:

This update for systemtap fixes the following issues:


Advisory IDSUSE-RU-2021:1643-1
ReleasedWed May 19 13:51:48 2021
SummaryRecommended update for pam
Typerecommended
Severityimportant
References1181443,1184358,1185562
Description:

This update for pam fixes the following issues:


Advisory IDSUSE-RU-2021:1861-1
ReleasedFri Jun 4 09:59:40 2021
SummaryRecommended update for gcc10
Typerecommended
Severitymoderate
References1029961,1106014,1178577,1178624,1178675,1182016
Description:

This update for gcc10 fixes the following issues:


Advisory IDSUSE-RU-2021:2173-1
ReleasedMon Jun 28 14:59:45 2021
SummaryRecommended update for automake
Typerecommended
Severitymoderate
References1040589,1047218,1182604,1185540,1186049
Description:

This update for automake fixes the following issues:


This update for pcre fixes the following issues:

This update for brp-check-suse fixes the following issues:


Advisory IDSUSE-SU-2021:2320-1
ReleasedWed Jul 14 17:01:06 2021
SummarySecurity update for sqlite3
Typesecurity
Severityimportant
References1157818,1158812,1158958,1158959,1158960,1159491,1159715,1159847,1159850,1160309,1160438,1160439,1164719,1172091,1172115,1172234,1172236,1172240,1173641,928700,928701,CVE-2015-3414,CVE-2015-3415,CVE-2019-19244,CVE-2019-19317,CVE-2019-19603,CVE-2019-19645,CVE-2019-19646,CVE-2019-19880,CVE-2019-19923,CVE-2019-19924,CVE-2019-19925,CVE-2019-19926,CVE-2019-19959,CVE-2019-20218,CVE-2020-13434,CVE-2020-13435,CVE-2020-13630,CVE-2020-13631,CVE-2020-13632,CVE-2020-15358,CVE-2020-9327
Description:

This update for sqlite3 fixes the following issues:


Advisory IDSUSE-RU-2021:2885-1
ReleasedTue Aug 31 12:21:17 2021
SummaryRecommended update for publicsuffix
Typerecommended
Severitylow
References1189124
Description:

This update for publicsuffix fixes the following issues:


Advisory IDSUSE-RU-2021:3115-1
ReleasedThu Sep 16 14:04:26 2021
SummaryRecommended update for mozilla-nspr, mozilla-nss
Typerecommended
Severitymoderate
References1029961,1174697,1176206,1176934,1179382,1188891,CVE-2020-12400,CVE-2020-12401,CVE-2020-12403,CVE-2020-25648,CVE-2020-6829
Description:

This update for mozilla-nspr fixes the following issues:
mozilla-nspr was updated to version 4.32:



Mozilla NSS was updated to version 3.68:

update to NSS 3.67

update to NSS 3.66

update to NSS 3.65

update to NSS 3.64
disable_crypto_vsx.
  • bmo#1698320 - replace __builtin_cpu_supports('vsx') with
  • ppc_crypto_support() for clang.
  • bmo#1613235 - Add POWER ChaCha20 stream cipher vector
  • acceleration.
    Fixed in 3.63
    initialization to prevent build isses with GCC 4.8.
  • bmo#1683520 - [lib/freebl/ecl] P-384: allow zero scalars in dual
  • scalar multiplication.
  • bmo#1683520 - ECCKiila P521, change syntax of nested structs
  • initialization to prevent build isses with GCC 4.8.
  • bmo#1683520 - [lib/freebl/ecl] P-521: allow zero scalars in dual
  • scalar multiplication.
  • bmo#1696800 - HACL* update March 2021 - c95ab70fcb2bc21025d8845281bc4bc8987ca683.
  • bmo#1694214 - tstclnt can't enable middlebox compat mode.
  • bmo#1694392 - NSS does not work with PKCS #11 modules not supporting
  • profiles.
  • bmo#1685880 - Minor fix to prevent unused variable on early return.
  • bmo#1685880 - Fix for the gcc compiler version 7 to support setenv
  • with nss build.
  • bmo#1693217 - Increase nssckbi.h version number for March 2021 batch
  • of root CA changes, CA list version 2.48.
  • bmo#1692094 - Set email distrust after to 21-03-01 for Camerfirma's
  • 'Chambers of Commerce' and 'Global Chambersign' roots.
  • bmo#1618407 - Symantec root certs - Set CKA_NSS_EMAIL_DISTRUST_AFTER.
  • bmo#1693173 - Add GlobalSign R45, E45, R46, and E46 root certs to NSS.
  • bmo#1683738 - Add AC RAIZ FNMT-RCM SERVIDORES SEGUROS root cert to NSS.
  • bmo#1686854 - Remove GeoTrust PCA-G2 and VeriSign Universal root certs
  • from NSS.
  • bmo#1687822 - Turn off Websites trust bit for the “Staat der
  • Nederlanden Root CA - G3” root cert in NSS.
  • bmo#1692094 - Turn off Websites Trust Bit for 'Chambers of Commerce
  • Root - 2008' and 'Global Chambersign Root - 2008’.
  • bmo#1694291 - Tracing fixes for ECH.

  • update to NSS 3.62
    can corrupt 'cachedCertTable'
  • bmo#1690583 - Fix CH padding extension size calculation
  • bmo#1690421 - Adjust 3.62 ABI report formatting for new libabigail
  • bmo#1690421 - Install packaged libabigail in docker-builds image
  • bmo#1689228 - Minor ECH -09 fixes for interop testing, fuzzing
  • bmo#1674819 - Fixup a51fae403328, enum type may be signed
  • bmo#1681585 - Add ECH support to selfserv
  • bmo#1681585 - Update ECH to Draft-09
  • bmo#1678398 - Add Export/Import functions for HPKE context
  • bmo#1678398 - Update HPKE to draft-07

  • update to NSS 3.61
    values under certain conditions.
  • bmo#1684300 - Fix default PBE iteration count when NSS is compiled
  • with NSS_DISABLE_DBM.
  • bmo#1651411 - Improve constant-timeness in RSA operations.
  • bmo#1677207 - Upgrade Google Test version to latest release.
  • bmo#1654332 - Add aarch64-make target to nss-try.

  • Update to NSS 3.60.1:
    Notable changes in NSS 3.60:
    Update to NSS 3.59.1:
    PKCS11 modules
    Update to NSS 3.59:
    Notable changes:

    Bugfixes
    root certs when SHA1 signatures are disabled.
  • bmo#1644209 - Fix broken SelectedCipherSuiteReplacer filter to
  • solve some test intermittents
  • bmo#1672703 - Tolerate the first CCS in TLS 1.3 to fix a regression in
  • our CVE-2020-25648 fix that broke purple-discord (boo#1179382)
  • bmo#1666891 - Support key wrap/unwrap with RSA-OAEP
  • bmo#1667989 - Fix gyp linking on Solaris
  • bmo#1668123 - Export CERT_AddCertToListHeadWithData and
  • CERT_AddCertToListTailWithData from libnss
  • bmo#1634584 - Set CKA_NSS_SERVER_DISTRUST_AFTER for Trustis FPS Root CA
  • bmo#1663091 - Remove unnecessary assertions in the streaming
  • ASN.1 decoder that affected decoding certain PKCS8 private keys when using NSS debug builds
  • bmo#670839 - Use ARM crypto extension for AES, SHA1 and SHA2 on MacOS.

  • update to NSS 3.58
    Bugs fixed:

    update to NSS 3.57

    update to NSS 3.56
    Notable changes
    detection.
  • bmo#1652729 - Add build flag to disable RC2 and relocate to
  • lib/freebl/deprecated.
  • bmo#1656429 - Correct RTT estimate used in 0-RTT anti-replay.
  • bmo#1588941 - Send empty certificate message when scheme selection
  • fails.
  • bmo#1652032 - Fix failure to build in Windows arm64 makefile
  • cross-compilation.
  • bmo#1625791 - Fix deadlock issue in nssSlot_IsTokenPresent.
  • bmo#1653975 - Fix 3.53 regression by setting 'all' as the default
  • makefile target.
  • bmo#1659792 - Fix broken libpkix tests with unexpired PayPal cert.
  • bmo#1659814 - Fix interop.sh failures with newer tls-interop
  • commit and dependencies.
  • bmo#1656519 - NSPR dependency updated to 4.28

  • update to NSS 3.55
    Notable changes
    Relevant Bugfixes

    update to NSS 3.54
    Notable changes


    Bugs fixed
    Root Certification Authority; C=TW' root.
  • bmo#1645199 - Remove AddTrust root certificates.
  • bmo#1641718 - Remove 'LuxTrust Global Root 2' root certificate.
  • bmo#1639987 - Remove 'Staat der Nederlanden Root CA - G2' root
  • certificate.
  • bmo#1618402 - Remove Symantec root certificates and disable email trust
  • bit.
  • bmo#1640516 - NSS 3.54 should depend on NSPR 4.26.
  • bmo#1642146 - Fix undefined reference to `PORT_ZAlloc_stub' in seed.c.
  • bmo#1642153 - Fix infinite recursion building NSS.
  • bmo#1642638 - Fix fuzzing assertion crash.
  • bmo#1642871 - Enable SSL_SendSessionTicket after resumption.
  • bmo#1643123 - Support SSL_ExportEarlyKeyingMaterial with External PSKs.
  • bmo#1643557 - Fix numerous compile warnings in NSS.
  • bmo#1644774 - SSL gtests to use ClearServerCache when resetting
  • self-encrypt keys.
  • bmo#1645479 - Don't use SECITEM_MakeItem in secutil.c.
  • bmo#1646520 - Stricter enforcement of ASN.1 INTEGER encoding.

  • Advisory IDSUSE-RU-2021:3182-1
    ReleasedTue Sep 21 17:04:26 2021
    SummaryRecommended update for file
    Typerecommended
    Severitymoderate
    References1189996
    Description:

    This update for file fixes the following issues:


    Advisory IDSUSE-SU-2021:3490-1
    ReleasedWed Oct 20 16:31:55 2021
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1190793,CVE-2021-39537
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2021:3494-1
    ReleasedWed Oct 20 16:48:46 2021
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1190052
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2021:3510-1
    ReleasedTue Oct 26 11:22:15 2021
    SummaryRecommended update for pam
    Typerecommended
    Severityimportant
    References1191987
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2021:3529-1
    ReleasedWed Oct 27 09:23:32 2021
    SummarySecurity update for pcre
    Typesecurity
    Severitymoderate
    References1172973,1172974,CVE-2019-20838,CVE-2020-14155
    Description:

    This update for pcre fixes the following issues:
    Update pcre to version 8.45:


    Advisory IDSUSE-RU-2021:3799-1
    ReleasedWed Nov 24 18:07:54 2021
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1187153,1187273,1188623
    Description:

    This update for gcc11 fixes the following issues:
    The additional GNU compiler collection GCC 11 is provided:
    To select these compilers install the packages:


    to select them for building:

    The compiler baselibraries (libgcc_s1, libstdc++6 and others) are being replaced by the GCC 11 variants.


    Advisory IDSUSE-RU-2021:3891-1
    ReleasedFri Dec 3 10:21:49 2021
    SummaryRecommended update for keyutils
    Typerecommended
    Severitymoderate
    References1029961,1113013,1187654
    Description:

    This update for keyutils fixes the following issues:


    keyutils was updated to 1.6.3 (jsc#SLE-20016):

    Updated to 1.6:

    Updated to 1.5.11 (bsc#1113013)


    Advisory IDSUSE-SU-2021:3942-1
    ReleasedMon Dec 6 14:46:05 2021
    SummarySecurity update for brotli
    Typesecurity
    Severitymoderate
    References1175825,CVE-2020-8927
    Description:

    This update for brotli fixes the following issues:


    Advisory IDSUSE-SU-2021:3946-1
    ReleasedMon Dec 6 14:57:42 2021
    SummarySecurity update for gmp
    Typesecurity
    Severitymoderate
    References1192717,CVE-2021-43618
    Description:

    This update for gmp fixes the following issues:


    Advisory IDSUSE-RU-2022:12-1
    ReleasedMon Jan 3 15:36:04 2022
    SummaryRecommended update for cairo, jbigkit, libjpeg-turbo, libwebp, libxcb, openjpeg2, pixman, poppler, tiff
    Typerecommended
    Severitymoderate
    References
    Description:

    This recommended update for cairo, jbigkit, libjpeg-turbo, libwebp, libxcb, openjpeg2, pixman, poppler, tiff provides the following fix:


    Advisory IDSUSE-RU-2022:692-1
    ReleasedThu Mar 3 15:46:47 2022
    SummaryRecommended update for filesystem
    Typerecommended
    Severitymoderate
    References1190447
    Description:

    This update for filesystem fixes the following issues:


    Advisory IDSUSE-RU-2022:789-1
    ReleasedThu Mar 10 11:22:05 2022
    SummaryRecommended update for update-alternatives
    Typerecommended
    Severitymoderate
    References1195654
    Description:

    This update for update-alternatives fixes the following issues:


    Advisory IDSUSE-RU-2022:861-1
    ReleasedTue Mar 15 23:31:21 2022
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1182959,1195149,1195792,1195856
    Description:

    This update for openssl-1_1 fixes the following issues:
    openssl-1_1:

    glibc:
    linux-glibc-devel:

    libxcrypt:

    zlib:


    Advisory IDSUSE-RU-2022:936-1
    ReleasedTue Mar 22 18:10:17 2022
    SummaryRecommended update for filesystem and systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1196275,1196406
    Description:

    This update for filesystem and systemd-rpm-macros fixes the following issues:
    filesystem:


    systemd-rpm-macros:


    Advisory IDSUSE-RU-2022:1047-1
    ReleasedWed Mar 30 16:20:56 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1196093,1197024
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2022:1265-1
    ReleasedTue Apr 19 15:22:37 2022
    SummarySecurity update for jsoup, jsr-305
    Typesecurity
    Severityimportant
    References1189749,CVE-2021-37714
    Description:

    This update for jsoup, jsr-305 fixes the following issues:


    Changes in jsr-305:
    Changes in jsoup:


    Advisory IDSUSE-RU-2022:1281-1
    ReleasedWed Apr 20 12:26:38 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1196647
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:1409-1
    ReleasedTue Apr 26 12:54:57 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1195628,1196107
    Description:

    This update for gcc11 fixes the following issues:


    Advisory IDSUSE-RU-2022:1451-1
    ReleasedThu Apr 28 10:47:22 2022
    SummaryRecommended update for perl
    Typerecommended
    Severitymoderate
    References1193489
    Description:

    This update for perl fixes the following issues:


    Advisory IDSUSE-SU-2022:1565-1
    ReleasedFri May 6 17:09:36 2022
    SummarySecurity update for giflib
    Typesecurity
    Severitymoderate
    References1094832,1146299,1184123,974847,CVE-2016-3977,CVE-2018-11490,CVE-2019-15133
    Description:

    This update for giflib fixes the following issues:

    Update to version 5.2.1 * In gifbuild.c, avoid a core dump on no color map. * Restore inadvertently removed library version numbers in Makefile. Changes in version 5.2.0 * The undocumented and deprecated GifQuantizeBuffer() entry point has been moved to the util library to reduce libgif size and attack surface. Applications needing this function are couraged to link the util library or make their own copy. * The following obsolete utility programs are no longer installed: gifecho, giffilter, gifinto, gifsponge. These were either installed in error or have been obsolesced by modern image-transformmation tools like ImageMagick convert. They may be removed entirely in a future release. * Address SourceForge issue #136: Stack-buffer-overflow in gifcolor.c:84 * Address SF bug #134: Giflib fails to slurp significant number of gifs * Apply SPDX convention for license tagging. Changes in version 5.1.9 * The documentation directory now includes an HTMlified version of the GIF89 standard, and a more detailed description of how LZW compression is applied to GIFs. * Address SF bug #129: The latest version of giflib cannot be build on windows. * Address SF bug #126: Cannot compile giflib using c89 Changes in version 5.1.8 * Address SF bug #119: MemorySanitizer: FPE on unknown address (CVE-2019-15133 bsc#1146299) * Address SF bug #125: 5.1.7: xmlto is still required for tarball * Address SF bug #124: 5.1.7: ar invocation is not crosscompile compatible * Address SF bug #122: 5.1.7 installs manpages to wrong directory * Address SF bug #121: make: getversion: Command not found * Address SF bug #120: 5.1.7 does not build a proper library - no Changes in version 5.1.7 * Correct a minor packaging error (superfluous symlinks) in the 5.1.6 tarballs. Changes in version 5.1.6 * Fix library installation in the Makefile. Changes in version 5.1.5 * Fix SF bug #114: Null dereferences in main() of gifclrmp * Fix SF bug #113: Heap Buffer Overflow-2 in function DGifDecompressLine() in cgif.c. This had been assigned (CVE-2018-11490 bsc#1094832). * Fix SF bug #111: segmentation fault in PrintCodeBlock * Fix SF bug #109: Segmentation fault of giftool reading a crafted file * Fix SF bug #107: Floating point exception in giftext utility * Fix SF bug #105: heap buffer overflow in DumpScreen2RGB in gif2rgb.c:317 * Fix SF bug #104: Ineffective bounds check in DGifSlurp * Fix SF bug #103: GIFLIB 5.1.4: DGifSlurp fails on empty comment * Fix SF bug #87: Heap buffer overflow in 5.1.2 (gif2rgb). (CVE-2016-3977 bsc#974847) * The horrible old autoconf build system has been removed with extreme prejudice. You now build this simply by running 'make' from the top-level directory.
    The following non-security bugs were fixed:


    Advisory IDSUSE-RU-2022:1655-1
    ReleasedFri May 13 15:36:10 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1197794
    Description:

    This update for pam fixes the following issue:


    Advisory IDSUSE-RU-2022:1658-1
    ReleasedFri May 13 15:40:20 2022
    SummaryRecommended update for libpsl
    Typerecommended
    Severityimportant
    References1197771
    Description:

    This update for libpsl fixes the following issues:


    Advisory IDSUSE-RU-2022:1660-1
    ReleasedFri May 13 15:42:21 2022
    SummaryRecommended update for publicsuffix
    Typerecommended
    Severitylow
    References1198068
    Description:

    This update for publicsuffix fixes the following issue:


    Advisory IDSUSE-RU-2022:1887-1
    ReleasedTue May 31 09:24:18 2022
    SummaryRecommended update for grep
    Typerecommended
    Severitymoderate
    References1040589
    Description:

    This update for grep fixes the following issues:


    Advisory IDSUSE-RU-2022:1899-1
    ReleasedWed Jun 1 10:43:22 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severityimportant
    References1198176
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:2019-1
    ReleasedWed Jun 8 16:50:07 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1192951,1193659,1195283,1196861,1197065
    Description:

    This update for gcc11 fixes the following issues:
    Update to the GCC 11.3.0 release.


    Advisory IDSUSE-SU-2022:2294-1
    ReleasedWed Jul 6 13:34:15 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1196025,1196026,1196168,1196169,1196171,1196784,CVE-2022-25235,CVE-2022-25236,CVE-2022-25313,CVE-2022-25314,CVE-2022-25315
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-SU-2022:2361-1
    ReleasedTue Jul 12 12:05:01 2022
    SummarySecurity update for pcre
    Typesecurity
    Severityimportant
    References1199232,CVE-2022-1586
    Description:

    This update for pcre fixes the following issues:


    Advisory IDSUSE-RU-2022:2406-1
    ReleasedFri Jul 15 11:49:01 2022
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1197718,1199140,1200334,1200855
    Description:

    This update for glibc fixes the following issues:


    This readds the s390 32bit glibc and libcrypt1 libraries (glibc-32bit, glibc-locale-base-32bit, libcrypt1-32bit).


    Advisory IDSUSE-SU-2022:2533-1
    ReleasedFri Jul 22 17:37:15 2022
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741
    Description:

    This update for mozilla-nss fixes the following issues:
    Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4:


    Version update to NSS 3.79:

    Version update to NSS 3.78.1:

    Version update to NSS 3.78:

    Version update to NSS 3.77:

    Version update to NSS 3.76.1

    Version update to NSS 3.75

    Version update to NSS 3.74


    Version update to NSS 3.73.1:

    Version update to NSS 3.73

    Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures
    Version update to NSS 3.72

    Version update to NSS 3.71

    Version update to NSS 3.70

    Version update to NSS 3.69.1:

    NSS 3.69:

    Version Update to 3.68.4 (bsc#1200027)


    Mozilla NSPR was updated to version 4.34:


    Advisory IDSUSE-SU-2022:2595-1
    ReleasedFri Jul 29 16:00:42 2022
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741
    Description:

    This update for mozilla-nss fixes the following issues:
    Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4:


    Version update to NSS 3.79:

    Version update to NSS 3.78.1:

    Version update to NSS 3.78:

    Version update to NSS 3.77:

    Version update to NSS 3.76.1

    Version update to NSS 3.75

    Version update to NSS 3.74


    Version update to NSS 3.73.1:

    Version update to NSS 3.73

    Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures
    Version update to NSS 3.72

    Version update to NSS 3.71

    Version update to NSS 3.70

    Version update to NSS 3.69.1:

    NSS 3.69:

    Version Update to 3.68.4 (bsc#1200027)


    Advisory IDSUSE-SU-2022:2632-1
    ReleasedWed Aug 3 09:51:00 2022
    SummarySecurity update for permissions
    Typesecurity
    Severityimportant
    References1198720,1200747,1201385
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-SU-2022:2717-1
    ReleasedTue Aug 9 12:54:16 2022
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1198627,CVE-2022-29458
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2022:2796-1
    ReleasedFri Aug 12 14:34:31 2022
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for jitterentropy fixes the following issues:
    jitterentropy is included in version 3.4.0 (jsc#SLE-24941):
    This is a FIPS 140-3 / NIST 800-90b compliant userspace jitter entropy generator library, used by other FIPS libraries.


    Advisory IDSUSE-RU-2022:2939-1
    ReleasedMon Aug 29 14:49:17 2022
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1201298,1202645
    Description:

    This update for mozilla-nss fixes the following issues:
    Update to NSS 3.79.1 (bsc#1202645)



    Advisory IDSUSE-RU-2022:2994-1
    ReleasedFri Sep 2 10:44:54 2022
    SummaryRecommended update for lame, libass, libcdio-paranoia, libdc1394, libgsm, libva, libvdpau, libvorbis, libvpx, libwebp, openjpeg, opus, speex, twolame
    Typerecommended
    Severitymoderate
    References1198925
    Description:


    This update for lame, libass, libcdio-paranoia, libdc1394, libgsm, libva, libvdpau, libvorbis, libvpx, libwebp, openjpeg, opus, speex, twolame adds some missing 32bit libraries to some products. (bsc#1198925)
    No codechanges were done in this update.


    Advisory IDSUSE-RU-2022:3127-1
    ReleasedWed Sep 7 04:36:10 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1198752,1200800
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-SU-2022:3252-1
    ReleasedMon Sep 12 09:07:53 2022
    SummarySecurity update for freetype2
    Typesecurity
    Severitymoderate
    References1198823,1198830,1198832,CVE-2022-27404,CVE-2022-27405,CVE-2022-27406
    Description:

    This update for freetype2 fixes the following issues:


    Non-security fixes:


    Advisory IDSUSE-RU-2022:3262-1
    ReleasedTue Sep 13 15:34:29 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1199140
    Description:


    This update for gcc11 ships some missing 32bit libraries for s390x. (bsc#1199140)


    Advisory IDSUSE-SU-2022:3271-1
    ReleasedWed Sep 14 06:45:39 2022
    SummarySecurity update for perl
    Typesecurity
    Severitymoderate
    References1047178,CVE-2017-6512
    Description:

    This update for perl fixes the following issues:


    Advisory IDSUSE-SU-2022:3305-1
    ReleasedMon Sep 19 11:45:57 2022
    SummarySecurity update for libtirpc
    Typesecurity
    Severityimportant
    References1201680,CVE-2021-46828
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-SU-2022:3307-1
    ReleasedMon Sep 19 13:26:51 2022
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1189802,1195773,1201783,CVE-2021-36690,CVE-2022-35737
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-RU-2022:3328-1
    ReleasedWed Sep 21 12:48:56 2022
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References1202870
    Description:

    This update for jitterentropy fixes the following issues:


    Advisory IDSUSE-SU-2022:3353-1
    ReleasedFri Sep 23 15:23:40 2022
    SummarySecurity update for permissions
    Typesecurity
    Severitymoderate
    References1203018,CVE-2022-31252
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-SU-2022:3489-1
    ReleasedSat Oct 1 13:35:24 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1203438,CVE-2022-40674
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-RU-2022:3555-1
    ReleasedMon Oct 10 14:05:12 2022
    SummaryRecommended update for aaa_base
    Typerecommended
    Severityimportant
    References1199492
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2022:3784-1
    ReleasedWed Oct 26 18:03:28 2022
    SummarySecurity update for libtasn1
    Typesecurity
    Severitycritical
    References1204690,CVE-2021-46848
    Description:

    This update for libtasn1 fixes the following issues:


    Advisory IDSUSE-RU-2022:3787-1
    ReleasedThu Oct 27 04:41:09 2022
    SummaryRecommended update for permissions
    Typerecommended
    Severityimportant
    References1194047,1203911
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-RU-2022:3873-1
    ReleasedFri Nov 4 14:58:08 2022
    SummaryRecommended update for mozilla-nspr, mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1198980,1201298,1202870,1204729
    Description:

    This update for mozilla-nspr, mozilla-nss fixes the following issues:
    mozilla-nspr was updated to version 4.34.1:


    mozilla-nss was updated to NSS 3.79.2 (bsc#1204729):

    Other fixes that were applied:


    Advisory IDSUSE-SU-2022:3884-1
    ReleasedMon Nov 7 10:59:26 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1204708,CVE-2022-43680
    Description:

    This update for expat fixes the following issues:
    - CVE-2022-43680: Fixed use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (bsc#1204708).


    Advisory IDSUSE-RU-2022:3910-1
    ReleasedTue Nov 8 13:05:04 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for pam fixes the following issue:


    Advisory IDSUSE-RU-2022:3958-1
    ReleasedFri Nov 11 15:20:45 2022
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1198980,1201298,1202870,1204729
    Description:

    This update for mozilla-nss fixes the following issues:
    mozilla-nss was updated to NSS 3.79.2 (bsc#1204729)



    Advisory IDSUSE-SU-2022:4011-1
    ReleasedWed Nov 16 11:29:09 2022
    SummarySecurity update for jsoup
    Typesecurity
    Severitymoderate
    References1203459,CVE-2022-36033
    Description:

    This update for jsoup fixes the following issues:
    Updated to version 1.15.3:
    - CVE-2022-36033: Fixed incorrect sanitization of user input in SafeList.preserveRelativeLinks (bsc#1203459).


    Advisory IDSUSE-RU-2022:4076-1
    ReleasedFri Nov 18 15:00:38 2022
    SummaryRecommended update for jsoup
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for jsoup fixes the following issues:


    Advisory IDSUSE-SU-2022:4081-1
    ReleasedFri Nov 18 15:40:46 2022
    SummarySecurity update for dpkg
    Typesecurity
    Severitylow
    References1199944,CVE-2022-1664
    Description:

    This update for dpkg fixes the following issues:


    Advisory IDSUSE-RU-2022:4135-1
    ReleasedMon Nov 21 00:13:40 2022
    SummaryRecommended update for libeconf
    Typerecommended
    Severitymoderate
    References1198165
    Description:

    This update for libeconf fixes the following issues:



    Advisory IDSUSE-RU-2022:4233-1
    ReleasedFri Nov 25 18:19:33 2022
    SummaryRecommended update for publicsuffix
    Typerecommended
    Severitylow
    References
    Description:

    This update for publicsuffix fixes the following issues:


    Advisory IDSUSE-RU-2022:4256-1
    ReleasedMon Nov 28 12:36:32 2022
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:
    This update ship the GCC 12 compiler suite and its base libraries.
    The compiler baselibraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 11 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP3 and SP4, and provided in the 'Development Tools' module.
    The Go, D and Ada language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc12 compilers use:


    For a full changelog with all new GCC12 features, check out
    https://gcc.gnu.org/gcc-12/changes.html


    Advisory IDSUSE-RU-2022:4492-1
    ReleasedWed Dec 14 13:52:39 2022
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1198980,1201298
    Description:

    This update for mozilla-nss fixes the following issues:


    Advisory IDSUSE-SU-2022:4628-1
    ReleasedWed Dec 28 09:23:13 2022
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1206337,CVE-2022-46908
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-RU-2023:48-1
    ReleasedMon Jan 9 10:37:54 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1199467
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-SU-2023:119-1
    ReleasedFri Jan 20 10:28:07 2023
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1204272,1207038,CVE-2022-23491,CVE-2022-3479
    Description:

    This update for mozilla-nss fixes the following issues:


    Advisory IDSUSE-SU-2023:434-1
    ReleasedThu Feb 16 09:08:05 2023
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1208138,CVE-2023-0767
    Description:

    This update for mozilla-nss fixes the following issues:
    Updated to NSS 3.79.4 (bsc#1208138):
    - CVE-2023-0767: Fixed handling of unknown PKCS#12 safe bag types.


    Advisory IDSUSE-RU-2023:617-1
    ReleasedFri Mar 3 16:49:06 2023
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References1207789
    Description:

    This update for jitterentropy fixes the following issues:


    Advisory IDSUSE-RU-2023:732-1
    ReleasedTue Mar 14 18:06:09 2023
    SummaryRecommended update for jsoup, jsr-305
    Typerecommended
    Severitylow
    References
    Description:

    This update for jsoup, jsr-305 fixes the following issues:


    Advisory IDSUSE-feature-2023:775-1
    ReleasedThu Mar 16 15:58:55 2023
    SummaryFeature for updating the Java stack
    Typefeature
    Severitycritical
    References1047218,1062631,1120360,1133997,1134001,1145693,1171696,1172961,1173600,1177180,1177488,1177568,1179926,1180215,1182284,1182708,1182748,1182754,1184356,1184357,1184755,1186328,1187446,1188468,1188469,1188529,1190660,1190663,1193795,1195108,1195557,1198279,1198404,1198739,1198833,1201081,1201316,1201317,1203154,1203515,1203516,1203672,1203673,1203674,1203868,1204173,1204284,1204918,1205138,1205142,1205647,1206018,1206400,1206401,CVE-2019-17566,CVE-2020-11022,CVE-2020-11023,CVE-2020-11979,CVE-2020-11987,CVE-2020-11988,CVE-2020-13956,CVE-2020-15522,CVE-2020-1945,CVE-2020-26945,CVE-2020-28052,CVE-2020-2875,CVE-2020-2933,CVE-2020-2934,CVE-2020-8908,CVE-2021-2471,CVE-2021-26291,CVE-2021-27807,CVE-2021-27906,CVE-2021-29425,CVE-2021-33813,CVE-2021-36373,CVE-2021-36374,CVE-2021-37533,CVE-2021-42550,CVE-2021-43980,CVE-2022-2047,CVE-2022-2048,CVE-2022-23437,CVE-2022-24839,CVE-2022-28366,CVE-2022-29599,CVE-2022-37865,CVE-2022-37866,CVE-2022-38398,CVE-2022-38648,CVE-2022-38752,CVE-2022-40146,CVE-2022-40149,CVE-2022-40150,CVE-2022-42252,CVE-2022-42889,CVE-2022-45685,CVE-2022-45693
    Description:

    This feature update for the Java stack provides:
    ant:


    ant-antlr:

    ant-contrib:

    ant-junit:

    ant-junit5:

    antlr:

    antlr3:

    antlr4:

    aopalliance:

    apache-commons-beanutils:

    apache-commons-cli:

    apache-commons-codec:

    apache-commons-collections4:

    apache-commons-collections:

    apache-commons-compress:

    apache-commons-configuration:

    apache-commons-csv:

    apache-commons-daemon:

    apache-commons-dbcp:

    apache-commons-digester:

    apache-commons-el:

    apache-commons-exec:

    apache-commons-fileupload:

    apache-commons-io:

    apache-commons-jexl:

    apache-commons-lang3:

    apache-commons-logging:

    apache-commons-math:

    apache-commons-net:

    apache-commons-ognl:

    apache-commons-parent:

    apache-commons-pool2:

    apache-commons-text:

    apache-ivy:


    apache-logging-parent:

    apache-parent:

    apache-pdfbox:

    apache-resource-bundles:

    apache-sshd:

    apiguardian:

    aqute-bnd:

    args4j:

    asm3:

    atinject:

    auto:

    avalon-framework:

    avalon-logkit:

    aws-sdk-java:

    axis:

    base64coder:

    beust-jcommander:

    bnd-maven-plugin:

    bouncycastle:

    bsf:

    bsh2:

    cal10n:

    cbi-plugins:

    cdi-api:

    cglib:

    checker-qual:

    classmate:

    codemodel:

    codenarc:

    concurrentlinkedhashmap-lru:

    decentxml:

    dom4j:

    ecj:

    eclipse:

    eclipse-ecf:

    eclipse-egit:

    eclipse-emf:

    eclipse-jgit:
    eclipse-license:

    eclipse-swt:

    ed25519-java:

    ee4j:

    exec-maven-plugin:

    extra166y:

    ezmorph:

    felix-bundlerepository:

    felix-gogo-command:

    felix-gogo-runtime:

    felix-osgi-compendium:

    felix-osgi-foundation:

    felix-osgi-obr:

    felix-scr:

    felix-shell:

    felix-utils:

    fmpp:

    freemarker:

    geronimo-specs:

    glassfish-activation:

    glassfish-annotation-api:

    glassfish-dtd-parser:

    glassfish-fastinfoset:

    glassfish-jaxb-api:

    glassfish-jaxb:

    glassfish-jax-rs-api:

    glassfish-jsp:

    glassfish-servlet-api:

    glassfish-transaction-api:

    gmavenplus-plugin:

    gmetrics:

    google-errorprone-annotations:

    google-gson:

    google-guice:

    google-http-java-client:

    google-oauth-java-client:

    gpars:

    gradle-bootstrap:

    gradle:

    groovy:

    groovy18:

    guava20:

    guava:

    hamcrest:

    hawtjni-maven-plugin:

    hawtjni-runtime:

    http-builder:

    httpcomponents-client:

    httpcomponents-core:

    icu4j:

    isorelax:

    istack-commons:

    j2objc-annotations:

    jackson-modules-base:

    jackson-parent:

    jackson:

    jakarta-activation:

    jakarta-commons-discovery:


    jakarta-commons-modeler:

    jakarta-mail:

    jakarta-taglibs-standard:

    jandex:

    janino:

    jansi-native:

    jansi:

    jarjar:

    jatl:

    javacc-maven-plugin:

    javacc:

    java-cup:

    java-cup-bootstrap:
    javaewah:

    javamail:

    javapackages-meta:

    javapackages-tools:

    javaparser:

    javassist:

    jboss-interceptors-1.2-api:

    jboss-websocket-1.0-api:

    jcache:

    jcifs:

    jcip-annotations:

    jcsp:

    jctools:

    jdependency:

    jdepend:

    jdom:

    jdom2:

    jettison:

    jetty-minimal:

    jetty-websocket:

    jeuclid:

    jflex:

    jflex-bootstrap:
    jformatstring:

    jgit:

    jhighlight:

    jing-trang:

    jline:

    jline1:

    jna:

    joda-convert:

    joda-time:

    jsch-agent-proxy:

    jsch:

    json-lib:

    jsonp:

    jsr-311:

    jtidy:

    junit:

    junit5:

    jython:

    jzlib:

    kryo:

    kxml:

    libreadline-java:

    log4j:

    logback:

    lucene:

    maven:

    maven2:

    maven-antrun-plugin:

    maven-archiver:

    maven-artifact-resolver:

    maven-artifact-transfer:

    maven-assembly-plugin:

    maven-clean-plugin:

    maven-common-artifact-filters:

    maven-compiler-plugin:

    maven-dependency-analyzer:

    maven-dependency-plugin:

    maven-dependency-tree:

    maven-doxia:

    maven-doxia-sitetools:

    maven-enforcer:

    maven-file-management:

    maven-filtering:

    maven-install-plugin:

    maven-invoker:

    maven-jar-plugin:

    maven-javadoc-plugin:

    maven-mapping:

    maven-plugin-build-helper:

    maven-plugin-bundle:

    maven-plugin-testing:

    maven-plugin-tools:

    maven-remote-resources-plugin:

    maven-reporting-api:

    maven-resolver:

    maven-resources-plugin:

    maven-shared-incremental:

    maven-shared-io:

    maven-shared-utils:

    maven-source-plugin:

    maven-surefire:

    maven-verifier:

    maven-wagon:

    minlog:

    modello-maven-plugin:

    modello:

    mojo-parent:

    msv:

    multiverse:

    mx4j:

    mybatis-parent:

    mybatis:

    mysql-connector-java:

    nailgun:

    native-platform:

    nekohtml:

    netty3:

    netty-tcnative:

    objectweb-asm:

    objenesis:

    opentest4j:

    oro:

    osgi-annotation:

    osgi-compendium:

    osgi-core:

    os-maven-plugin:

    paradise:

    paranamer:

    parboiled:

    pegdown:

    picocli:

    plexus-ant-factory:

    plexus-archiver:

    plexus-bsh-factory:

    plexus-build-api:

    plexus-cipher:

    plexus-classworlds:

    plexus-cli:

    plexus-compiler:

    plexus-component-api:

    plexus-component-metadata:

    plexus-containers:

    plexus-i18n:

    plexus-interactivity:

    plexus-interpolation:

    plexus-io:

    plexus-languages:

    plexus-metadata-generator:

    plexus-resources:

    plexus-sec-dispatcher:

    plexus-utils:

    plexus-velocity:

    qdox:

    reflectasm:

    regexp:

    relaxngcc:

    relaxngDatatype:

    reload4j:

    replacer:

    rhino:

    sat4j:

    saxon9:

    sbt-launcher:

    sbt:

    scala-pickling:

    scala:

    servletapi4:

    signpost-core:

    sisu:

    slf4j:

    snakeyaml:

    spec-version-maven-plugin:

    stax2-api:

    stax-ex:

    stringtemplate4:

    string-template-maven-plugin:

    stringtemplate:
    tagsoup:

    template-resolver:

    tesla-polyglot:

    test-interface:

    testng:

    tomcat:

    treelayout:

    trilead-ssh2:

    tycho:

    univocity-parsers:

    utfcpp:

    velocity:

    werken-xpath:

    woodstox-core:

    wsdl4j:

    ws-jaxme:

    xalan-j2:

    xbean:

    xerces-j2:

    xml-commons-apis:

    xml-commons-resolver:

    xmlgraphics-batik:

    xmlgraphics-commons:

    xmlgraphics-fop:

    xml-maven-plugin:

    xmlstreambuffer:

    xmlunit:

    xmvn-connector:
    Rename xmvn-connector-aether to xmvn-connector and provide it as version 4.0.0. (jsc#SLE-23217)
    xmvn-connector-gradle:

    xmvn-connector-ivy:

    xmvn-mojo:

    xmvn-parent:

    xmvn-tools:

    xmvn:

    xpp2:

    xpp3:

    xsom:

    xstream:

    xz-java:

    zinc:


    Advisory IDSUSE-RU-2023:776-1
    ReleasedThu Mar 16 17:29:23 2023
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:
    This update ships gcc12 also to the SUSE Linux Enterprise 15 SP1 LTSS and 15 SP2 LTSS products.
    SUSE Linux Enterprise 15 SP3 and SP4 get only refreshed builds without changes

    This update ship the GCC 12 compiler suite and its base libraries.
    The compiler baselibraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 11 ones.
    The new compilers for C, C++, and Fortran are provided in the SUSE Linux Enterprise Module for Development Tools.
    To use gcc12 compilers use:


    For a full changelog with all new GCC12 features, check out
    https://gcc.gnu.org/gcc-12/changes.html


    Advisory IDSUSE-RU-2023:1648-1
    ReleasedTue Mar 28 17:35:00 2023
    SummaryRecommended update for maven-resolver
    Typerecommended
    Severitymoderate
    References1209461
    Description:


    This update for maven-resolver fixes a issue on Leap 15.4.


    Advisory IDSUSE-RU-2023:1831-1
    ReleasedThu Apr 13 11:06:04 2023
    SummaryRecommended update for jsr-305
    Typerecommended
    Severityimportant
    References
    Description:

    This update for jsr-305 provides the following fix: - Ship the correct versions of jsr-305 on SUSE Manager repositories (no source changes).


    Advisory IDSUSE-RU-2023:1939-1
    ReleasedFri Apr 21 11:14:30 2023
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1207209,1208242,1208999
    Description:

    This update for mozilla-nss fixes the following issues:


    Advisory IDSUSE-SU-2023:2097-1
    ReleasedThu May 4 09:11:06 2023
    SummarySecurity update for maven and recommended update for antlr3, minlog, sbt, xmvn
    Typesecurity
    Severityimportant
    References1193795,CVE-2021-42550
    Description:

    This update for antlr3, maven, minlog, sbt, xmvn fixes the following issues:
    maven:

    antlr3:
    minlog:

    sbt:

    xmvn:


    Advisory IDSUSE-SU-2023:2111-1
    ReleasedFri May 5 14:34:00 2023
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1210434,CVE-2023-29491
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-OU-2023:2165-1
    ReleasedWed May 10 20:16:54 2023
    SummaryOptional update for junit
    Typeoptional
    Severitymoderate
    References
    Description:

    This update for junit fixes the following issues:


    Advisory IDSUSE-feature-2023:2269-1
    ReleasedMon May 22 14:50:34 2023
    SummaryFeature update for javapackages-tools
    Typefeature
    Severitymoderate
    References
    Description:

    This update for javapackages-tools fixes the following issues:



    Advisory IDSUSE-RU-2023:2383-1
    ReleasedMon Jun 5 17:40:54 2023
    SummaryRecommended update for jansi
    Typerecommended
    Severitymoderate
    References1210877
    Description:

    This update for jansi contains the following fix:


    Advisory IDSUSE-RU-2023:2625-1
    ReleasedFri Jun 23 17:16:11 2023
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:


    * includes regression and other bug fixes


    Advisory IDSUSE-SU-2023:2765-1
    ReleasedMon Jul 3 20:28:14 2023
    SummarySecurity update for libcap
    Typesecurity
    Severitymoderate
    References1211418,1211419,CVE-2023-2602,CVE-2023-2603
    Description:

    This update for libcap fixes the following issues:


    Advisory IDSUSE-RU-2023:2788-1
    ReleasedThu Jul 6 11:51:02 2023
    SummaryRecommended update for mozilla-nspr, mozilla-nss
    Typerecommended
    Severitymoderate
    References1185116,1202118
    Description:

    This update for mozilla-nspr, mozilla-nss fixes the following issues:
    mozilla-nspr was updated to version 4.35


    mozilla-nss was update to NSS 3.90:


    update to NSS 3.89.1

    update to NSS 3.89

    update to NSS 3.88.1

    update to NSS 3.88

    update to NSS 3.87

    update to NSS 3.86

    update to NSS 3.85

    update to NSS 3.84
    update to NSS 3.83

    update to NSS 3.82

    update to NSS 3.81



    update to NSS 3.80
    by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record.
  • Mark 3.79 as an ESR release.
  • Bump nssckbi version number for June.
  • Remove Hellenic Academic 2011 Root.
  • Add E-Tugra Roots.
  • Add Certainly Roots.
  • Add DigitCert Roots.
  • Protect SFTKSlot needLogin with slotLock.
  • Compare signature and signatureAlgorithm fields in legacy certificate verifier.
  • Uninitialized value in cert_VerifyCertChainOld.
  • Unchecked return code in sec_DecodeSigAlg.
  • Uninitialized value in cert_ComputeCertType.
  • Avoid data race on primary password change.
  • Replace ppc64 dcbzl intrinisic.
  • Allow LDFLAGS override in makefile builds.

  • Advisory IDSUSE-RU-2023:2814-1
    ReleasedWed Jul 12 22:05:25 2023
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1185116,1202118
    Description:

    This update for mozilla-nss fixes the following issues:
    mozilla-nss was updated to NSS 3.90:



    update to NSS 3.89.1

    update to NSS 3.89

    update to NSS 3.88.1

    update to NSS 3.88

    update to NSS 3.87

    update to NSS 3.86

    update to NSS 3.85

    update to NSS 3.84

    update to NSS 3.83
    with retry configs in EncryptedExtensions and if not accepting ECH. Changed config setting behavior to skip configs with unsupported mandatory extensions instead of failing
  • Added ECH client support to BoGo shim. Changed
  • CHInner creation to skip TLS 1.2 only extensions to comply with BoGo
  • Added ECH server support to BoGo shim. Fixed NSS ECH server accept_confirmation bugs
  • Update BoGo tests to recent BoringSSL version
  • Bump minimum NSPR version to 4.34.1

  • update to NSS 3.82

    update to NSS 3.81



    update to NSS 3.80
    by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record.
  • Mark 3.79 as an ESR release.
  • Bump nssckbi version number for June.
  • Remove Hellenic Academic 2011 Root.
  • Add E-Tugra Roots.
  • Add Certainly Roots.
  • Add DigitCert Roots.
  • Protect SFTKSlot needLogin with slotLock.
  • Compare signature and signatureAlgorithm fields in legacy certificate verifier.
  • Uninitialized value in cert_VerifyCertChainOld.
  • Unchecked return code in sec_DecodeSigAlg.
  • Uninitialized value in cert_ComputeCertType.
  • Avoid data race on primary password change.
  • Replace ppc64 dcbzl intrinisic.
  • Allow LDFLAGS override in makefile builds.

  • Advisory IDSUSE-RU-2023:2847-1
    ReleasedMon Jul 17 08:40:42 2023
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1210004
    Description:

    This update for audit fixes the following issues:


    Advisory IDSUSE-RU-2023:2856-1
    ReleasedMon Jul 17 16:38:29 2023
    SummaryRecommended update for publicsuffix
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for publicsuffix fixes the following issues:


    Advisory IDSUSE-SU-2023:2882-1
    ReleasedWed Jul 19 11:49:39 2023
    SummarySecurity update for perl
    Typesecurity
    Severityimportant
    References1210999,CVE-2023-31484
    Description:

    This update for perl fixes the following issues:

    - CVE-2023-31484: Enable TLS cert verification in CPAN (bsc#1210999).


    Advisory IDSUSE-SU-2023:3090-1
    ReleasedTue Aug 1 10:24:13 2023
    SummarySecurity update for guava
    Typesecurity
    Severitymoderate
    References1179926,1212401,CVE-2020-8908,CVE-2023-2976
    Description:

    This update for guava fixes the following issues:
    Upgrade to guava 32.0.1:


    Advisory IDSUSE-feature-2023:3319-1
    ReleasedTue Aug 15 10:45:11 2023
    SummaryFeature update for Maven
    Typefeature
    Severitymoderate
    References1211198
    Description:

    This update for aopalliance, beust-jcommander, maven, maven-install-plugin, maven-resolver, maven-wagon, plexus-utils, sbt and xmvn fixes the following issues:
    aopalliance:

    beust-jcommander:

    maven:

    maven-install-plugin:

    maven-resolver:

    maven-wagon:

    plexus-utils:

    sbt:

    xmvn:


    Advisory IDSUSE-RU-2023:3410-1
    ReleasedThu Aug 24 06:56:32 2023
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1201519,1204844
    Description:

    This update for audit fixes the following issues:


    Advisory IDSUSE-SU-2023:3461-1
    ReleasedMon Aug 28 17:25:09 2023
    SummarySecurity update for freetype2
    Typesecurity
    Severitymoderate
    References1210419,CVE-2023-2004
    Description:

    This update for freetype2 fixes the following issues:


    Advisory IDSUSE-RU-2023:3611-1
    ReleasedFri Sep 15 09:28:36 2023
    SummaryRecommended update for sysuser-tools
    Typerecommended
    Severitymoderate
    References1195391,1205161,1207778,1213240,1214140
    Description:

    This update for sysuser-tools fixes the following issues:


    Advisory IDSUSE-SU-2023:3661-1
    ReleasedMon Sep 18 21:44:09 2023
    SummarySecurity update for gcc12
    Typesecurity
    Severityimportant
    References1214052,CVE-2023-4039
    Description:

    This update for gcc12 fixes the following issues:


    Advisory IDSUSE-SU-2023:3954-1
    ReleasedTue Oct 3 20:09:47 2023
    SummarySecurity update for libeconf
    Typesecurity
    Severityimportant
    References1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181
    Description:

    This update for libeconf fixes the following issues:
    Update to version 0.5.2.


    Advisory IDSUSE-RU-2023:4154-1
    ReleasedFri Oct 20 19:33:25 2023
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1107342,1215434
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2023:4162-1
    ReleasedMon Oct 23 15:33:03 2023
    SummarySecurity update for gcc13
    Typesecurity
    Severityimportant
    References1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,CVE-2023-4039
    Description:

    This update for gcc13 fixes the following issues:
    This update ship the GCC 13.2 compiler suite and its base libraries.
    The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
    The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc13 compilers use:


    For a full changelog with all new GCC13 features, check out
    https://gcc.gnu.org/gcc-13/changes.html

    Detailed changes:




    Advisory IDSUSE-SU-2023:4215-1
    ReleasedThu Oct 26 12:19:25 2023
    SummarySecurity update for zlib
    Typesecurity
    Severitymoderate
    References1216378,CVE-2023-45853
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-RU-2023:4310-1
    ReleasedTue Oct 31 14:10:47 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1196647
    Description:

    This Update for libtirpc to 1.3.4, fixing the following issues: Update to 1.3.4 (bsc#1199467)
    * binddynport.c honor ip_local_reserved_ports - replaces: binddynport-honor-ip_local_reserved_ports.patch * gss-api: expose gss major/minor error in authgss_refresh() * rpcb_clnt.c: Eliminate double frees in delete_cache() * rpcb_clnt.c: memory leak in destroy_addr * portmapper: allow TCP-only portmapper * getnetconfigent: avoid potential DoS issue by removing unnecessary sleep * clnt_raw.c: fix a possible null pointer dereference * bindresvport.c: fix a potential resource leakage
    Update to 1.3.3:


    Update to 1.3.2:

    Update to 1.3.1:


    Advisory IDSUSE-SU-2023:4458-1
    ReleasedThu Nov 16 14:38:48 2023
    SummarySecurity update for gcc13
    Typesecurity
    Severityimportant
    References1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039
    Description:

    This update for gcc13 fixes the following issues:
    This update ship the GCC 13.2 compiler suite and its base libraries.
    The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
    The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc13 compilers use:


    For a full changelog with all new GCC13 features, check out
    https://gcc.gnu.org/gcc-13/changes.html

    Detailed changes:




    Advisory IDSUSE-SU-2023:4527-1
    ReleasedWed Nov 22 14:38:50 2023
    SummarySecurity update for maven, maven-resolver, sbt, xmvn
    Typesecurity
    Severitymoderate
    References1162112,1216529,CVE-2023-46122
    Description:

    This update for maven, maven-resolver, sbt, xmvn fixes the following issues:


    Advisory IDSUSE-RU-2023:4617-1
    ReleasedThu Nov 30 09:37:04 2023
    SummaryRecommended update for javapackages-tools
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for javapackages-tools fixes the following issues:


    Advisory IDSUSE-SU-2023:4619-1
    ReleasedThu Nov 30 10:13:52 2023
    SummarySecurity update for sqlite3
    Typesecurity
    Severityimportant
    References1210660,CVE-2023-2137
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-RU-2023:4671-1
    ReleasedWed Dec 6 14:33:41 2023
    SummaryRecommended update for man
    Typerecommended
    Severitymoderate
    References
    Description:


    This update of man fixes the following problem:


    Advisory IDSUSE-RU-2023:4700-1
    ReleasedMon Dec 11 07:03:27 2023
    SummaryRecommended update for p11-kit
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for p11-kit fixes the following issues:


    Advisory IDSUSE-RU-2023:4723-1
    ReleasedTue Dec 12 09:57:51 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1216862
    Description:

    This update for libtirpc fixes the following issue:


    Advisory IDSUSE-SU-2023:4891-1
    ReleasedMon Dec 18 16:31:49 2023
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1201384,1218014,CVE-2023-50495
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2024:26-1
    ReleasedThu Jan 4 11:15:24 2024
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1214980
    Description:

    This update for mozilla-nss fixes the following issues:
    Mozilla NSS was updated to NSS 3.90.1


    Advisory IDSUSE-RU-2024:62-1
    ReleasedMon Jan 8 11:44:47 2024
    SummaryRecommended update for libxcrypt
    Typerecommended
    Severitymoderate
    References1215496
    Description:

    This update for libxcrypt fixes the following issues:


    Advisory IDSUSE-SU-2024:136-1
    ReleasedThu Jan 18 09:53:47 2024
    SummarySecurity update for pam
    Typesecurity
    Severitymoderate
    References1217000,1218475,CVE-2024-22365
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2024:163-1
    ReleasedFri Jan 19 05:47:04 2024
    SummaryRecommended update for google-guice
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for google-guice fixes the following issues:


    Advisory IDSUSE-SU-2024:238-1
    ReleasedFri Jan 26 10:56:41 2024
    SummarySecurity update for cpio
    Typesecurity
    Severitymoderate
    References1218571,CVE-2023-7207
    Description:

    This update for cpio fixes the following issues:


    Advisory IDSUSE-RU-2024:322-1
    ReleasedFri Feb 2 15:13:26 2024
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1107342,1215434
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-RU-2024:560-1
    ReleasedWed Feb 21 05:34:18 2024
    SummaryRecommended update for Java
    Typerecommended
    Severitymoderate
    References1215973,CVE-2023-37460
    Description:

    This update for Java fixes the following issues:
    plexus-archiver was updated from version 4.2.1 to 4.8.0:


    * Security issues fixed:
    + CVE-2023-37460: Avoid override target symlink by standard file in AbstractUnArchiver (bsc#1215973)
    * New features and improvements:
    + Added tzst alias for tar.zst archiver/unarchived
    * Bugs fixed:
    + Detect permissions for addFile
    * Maintenance:
    + Removed public modifier from JUnit 5 tests + Use https in scm/url + Removed junit-jupiter-engine from project dependencies + Removed parent and reports menu from site + Cleanup after 'veryLargeJar' test + Override project.url

    * Bugs fixed:
    + Don't apply umask on unknown perms (Win)

    * New features and improvements:
    + add umask support and use 022 in RB mode + Use NIO Files for creating temporary files + Deprecate the JAR Index feature (JDK-8302819) + Added Archiver aliases for tar.*
    * Maintenance:
    + Use JUnit TempDir to manage temporary files in tests + Override uId and gId for Tar in test + Bump maven-resources-plugin from 2.7 to 3.3.1

    * New features and improvements:
    + Fixed path traversal vulnerability The vulnerability affects only directories whose name begins with the same prefix as the destination directory. For example malicious archive may extract file in /opt/directory instead of /opt/dir.

    * Bugs fixed:
    + Fixed regression in handling symbolic links

    * Bugs fixed:
    + Normalize file separators before warning about equal archive entries

    * New features and improvements:
    + keep file/directory permissions in Reproducible Builds mode

    * New features and improvements:
    + Added zstd (un)archiver support
    * Bugs fixed:
    + Fixed UnArchiver#isOverwrite not working as expected

    * New features and improvements:
    + Drop legacy plexus API and use only JSR330 components

    * New features and improvements:
    + Require Java 8 + Refactor to use FileTime API + Rename setTime method to setZipEntryTime + Convert InputStreamSupplier to lambdas
    * Bugs fixed:
    + Reproducible Builds not working when using modular jar

    * New features and improvements:
    + Respect order of META-INF/ and META-INF/MANIFEST.MF entries in a JAR file

    * New features and improvements:
    + FileInputStream, FileOutputStream, FileReader and FileWriter are no longer used + Code cleanup

    * New features and improvements: + Speed improvements
    * Bugs fixed:
    + Fixed use of a mismatching Unicode path extra field in zip unarchiving

    * Bugs fixed:
    + Fixed unjustified warning about casing for directory entries

    * Bugs fixed:
    + DirectoryArchiver fails for symlinks if a parent directory doesn't exist
    objectweb-asm was updated to version 9.6:

    * New Opcodes.V22 constant for Java 22
    * Bugs fixed:
    + Analyzer produces frames that have different locals than those detected by JRE bytecode verifier + Invalid stackmap generated when the instruction stream has new instruction after invokespecial to + Analyzer can fail to catch thrown exceptions + `asm-analysis` Frame allocates an array unnecessarily inside `executeInvokeInsn` + Fixed bug in `CheckFrameAnalyzer` with static methods

    * New Opcodes.V21 constant for Java 21 * New readBytecodeInstructionOffset hook in ClassReader * Added more detailed exception messages * Javadoc improvements and fixes
    * Bugs fixed:
    + Silent removal of zero-valued entries from the line-number table

    * Changes:
    + New Opcodes.V20 constant for Java 20 + Added more checks in CheckClassAdapter + Javadoc improvements and fixes + `module-info` classes can be built without Gradle and Bnd + Parent POM updated to `org.ow2:ow2:1.5.1`
    * Bugs fixed:
    +`CheckClassAdapter` is no longer transparent for MAXLOCALS + Added public `getDelegate` method to all visitor classes + Analyzer does not compute optimal maxLocals for static methods + Fixed `SignatureWriter` when a generic type has a depth over 30 + Skip remap inner class name if not changed in Remapper
    maven-archiver was updated from version 3.5.0 to 3.6.1:

    * New Features:
    + Deprecated the JAR Index feature (JDK-8302819)
    * Task:
    + Refreshed download page + Prefer JDK features over plexus-utils, plexus-io

    * Task:
    + Require Java 8 + Drop m-shared-utils from deps
    maven-assembly-plugin was updated from version 3.3.0 to 3.6.0:

    * Bugs fixed:
    + finalName as readonly parameter makes common usecases very complicated + Symbolic links get copied with absolute path + Warning if using Maven 3.9.1 + Minimal default Manifest configuration of jar archiver should be respected
    * New Features:
    + Support Zstandard compression format
    * Improvements:
    + In RB mode, apply 022 umask to ignore environment group write umask + Added system requirements history
    * Task: + Dropped deprecated repository element + Support running build on Java 20 + Refresh download page + Cleanup declared dependencies + Avoid using deprecated methods of `plexus-archiver`

    * Bugs fixed:
    + File permissions removed during assembly:single since 3.2.0

    * Bugs fixed:
    + Fixed Excludes filtering
    * Task:
    + Fixed examples to refer to https instead of http

    * Bugs fixed:
    + Fixed error build with shared assemblies

    * Bugs fixed:
    + dependencySet includes filter with classifier breaks include of artifacts without classifier
    * Task:
    + Speed improvements + Update plugin (requires Maven 3.2.5+) + Assembly plugin resolves too much, even plugins used to build dependencies + Deprecated the repository element in assembly descriptor + Upgraded to Java 8, drop unused dependencies
    maven-common-artifact-filters was updated from version 3.0.1 to 3.3.2:

    * Bugs fixed:
    + PatternIncludesArtifactFilters raising NPE for patterns w/ wildcards and artifactoid w/ null on any coordinate

    * Bugs fixed:
    + Pattern w/ 4 elements may be GATV or GATC

    * Bugs fixed:
    + null passed to DependencyFilter in EclipseAetherFilterTransformerTest + PatternIncludesArtifactFilter#include(Artifact) + Common Artifact Filters pattern parsing with classifier is broken
    * Task:
    + Sanitized dependencies + Upgraded to Maven Parent 36, to Maven 3.2.5, to Java 8 and clean up dependencies

    * Improvements:
    + Big speed improvements for patterns that do not contain any wildcard

    * Bugs fixed:
    + Updated JIRA URL for maven-common-artifact-filters
    * Improvements:
    + Made build Reproducible

    * Bugs fixed:
    + Several filters do not preserve order of artifacts filtered
    maven-compiler-plugin was updated from version 3.10.1 to 3.11.0:
    Changes of 3.11.0:
    * New features and improvements:
    + Added a useModulePath switch to the testCompile mojo + Allow dependency exclusions for 'annotationProcessorPaths' + Use maven-resolver to resolve 'annotationProcessorPaths' dependencies + Upgrade plexus-compiler to improve compiling message + compileSourceRoots parameter should be writable + Change showWarnings to true by default + Warn about warn-config conflicting values + Update default source/target from 1.7 to 1.8 + Display recompilation causes + Added some parameter to pattern from stale source calculation + Added dedicated option for implicit javac flag
    * Bugs fixed:
    + Fixed incorrect detection of dependency change + Test with Maven 3.9.0 and fix the failing IT + Resolved all annotation processor dependencies together + Defining maven.compiler.release as empty string ends with NumberFormatException in testCompileMojo + Fixed missing dirs in createMissingPackageInfoClasses + Set Xcludes in config passed to actual compiler
    maven-dependency-analyzer was updated from version 1.10 to 1.13.2:

    * Changes and bugs fixed:
    + Made mvn dependency:analyze work with OpenJDK 11 + Fixed jdk8 incompatibility at runtime (NoSuchMethodError) + Upgraded asm to 8.0.1 + Use try with resources to avoid leaks + dependency:analyze recommends test scope for test-only artifacts that have non-test scope + remove reference to deprecated public mutable field + Updated JIRA URL + dependency:analyze should recommend narrower scope where possible + Remove dependency on jmock + Inline deprecated field + Added more JavaDoc + Handle different classes from same artifact used by model and test code + Included class names in used undeclared dependencies + Check maximum allowed Maven version + Get rid of maven-plugin-testing-tools for IT test + Require Maven 3.2.5+ + Analyze project classes only once + Fixed array parsing + CONSTANT_METHOD_TYPE should not add to classes + Inner classes are in same compilation unit as container class + Upgraded Parent to 36 + Cleanup IT tests + Replace Codehaus Plexus utils with java.nio.file.Files and Apache Commons + Fixed bug with 'non-test scoped test only dependencies found' + Bump asm from 9.4 to 9.5 + Refresh download page + Upgrade Parent to 39 + Build on JDK 19, 20 + Prefer JDK classes to Plexus utils + Replaced System.out by logger + Fixed java.lang.RuntimeException: Unknown constant pool type + Switched to JUnit 5 + Dependency improvements
    maven-dependency-plugin was updated from version 3.1.2 to 3.6.0:

    * Bugs fixed:
    + Obsolete example of -Dverbose on web page + Unsupported verbose option still appears in docs + dependency:go-offline does not use repositories from parent pom in reactor build + Fixed possible NPE + `dependency:analyze-only` goal fails on OpenJDK 14 + FileWriter and FileReader should be replaced + Dependency Plugin go-offline doesn't respect artifact classifier + analyze-only failed: Unsupported class file major version 60 (Java 16) + analyze-only failed: Unsupported class file major version 61 (Java 17) + copy-dependencies fails when using excludeScope=test + mvn dependency:analyze detected wrong transitive dependency + dependency plugin does not work with JDK 16 + skip dependency analyze in ear packaging + Non-test dependency reported as Non-test scoped test only dependency + 'Dependency not found' with 3.2.0 and Java-17 while analyzing + Tree plugin does not terminate with 3.2.0 + Minor improvement - continue + analyze-only failed: PermittedSubclasses requires ASM9 + Broken Link to 'Introduction to Dependency Mechanism Page' + Sealed classes not supported + Dependency tree in verbose mode for war is empty + Javadoc was not updated to reflect that :tree's verbose option is now ok + error dependency:list (caused by postgresql dependency) + :list-classes does not skip if skip is set + :list-classes does not use GAV parameters
    * New Features:
    + Reintroduce the verbose option for dependency:tree + List classes in a given artifact + dependency:analyze should recommend narrower scope where possible + Added analyze parameter 'ignoreUnusedRuntime' + Allow ignoring non-test-scoped dependencies + Added a option to unpack goals + Allow auto-ignore of all non-test scoped dependencies used only in test scope
    * Improvements:
    + Unused method o.a.m.p.d.t.TreeMojo.containsVersion + Minor improvements + GitHub Action build improvement + dependency:analyze should list the classes that cause a used undeclared dependency + Improve documentation of analyze - Non-test scoped + Turn warnings into errors instead of failOnWarning + maven-dependency-plugin should leverage plexus-build-api to support IDEs + TestListClassesMojo logs too much + Use outputDirectory from AbstractMavenReport + Removed not used dependencies / Replace parts + list-repositories - improvements + warns about depending on plexus-container-default + Replace AnalyzeReportView with a new AnalyzeReportRenderer
    * Task:
    + Removed no longer required exclusions + Java 1.8 as minimum + Explicitly start and end tables with Doxia Sinks in report renderers + Replace Maven shared StringUtils with Commons Lang3 + Removed unused and ignored parameter - useJvmChmod + Removed custom plexus configuration + Code refactor - UnpackUtil + Refresh download page
    maven-dependency-tree was updated from version 3.0.1 to 3.2.1:
    • Changes in 3.2.1:

    * Bugs fixed:
    + DependencyCollectorBuilder does not collect dependencies when artifact has 'war' packaging + Transitive provided dependencies are not removed from collected dependency graph
    * New Features:
    + DependencyCollectorBuilder more configurable
    * Improvements:
    + DependencyGraphBuilder does not provide verbose tree + DependencyGraphBuilders shouldn't need reactorProjects for resolving dependencies + Maven31DependencyGraphBuilder should not download dependencies other than the pom + Fixed `plexus-component-annotation` in line with `plexus-component-metadata` + Upgraded parent to 31 + Added functionality to collect raw dependencies in Maven 3+ + Annotate DependencyNodes with dependency management metadata + Require Java 8 + Upgrade `org.eclipse.aether:aether-util` dependency in org.apache.maven.shared:maven-dependency-tree + Added Exclusions to DependencyNode + Made build Reproducible + Migrate plexus component to JSR-330 + Drop maven 3.0 compatibility
    * Dependency upgrade:
    + Upgrade shared-component to version 33 + Upgrade Parent to 36 + Bump maven-shared-components from 36 to 37
    • Removed unnecessary dependency on xmvn tools and parent pom

    maven-enforcer was updated to version 3.4.1:
    • Update to version 3.4.1:

    * Bugs fixed:
    + In a multi module project 'bannedDependencies' rule tries to resolve project artifacts from external repository + Require Release Dependencies ignorant about aggregator build + banDuplicatePomDependencyVersions does not check managementDependencies + Beanshell rule is not thread-safe + RequireSnapshotVersion not compatible with CI Friendly Versions (${revision}) + NPE when using new syntax with maven-enforcer-plugin + Broken links on Maven Enforcer Plugin site + RequirePluginVersions not recognizing versions-from-properties + [REGRESSION] RequirePluginVersions fails when versions are inherited + requireFilesExist rule should be case sensitive + Broken Links on Project Home Page + TestRequireOS uses hamcrest via transitive dependency + plexus-container-default in enforcer-api is very outdated + classifier not included in output of failes RequireUpperBoundDeps test + Exclusions are not considered when looking at parent for requireReleaseDeps + requireUpperBoundDeps does not fail when packaging is 'war' + DependencyConvergence in 3.0.0 fails on provided scoped dependencies + NPE on requireReleaseDeps with non-matching includes + RequireUpperBoundDeps now follow scope provided transitive dependencies + Use currently build artifacts in IT tests + requireReleaseDeps does not support optional dependencies or runtime scope + Enforcer 3.0.0 breaks with Maven 3.8.4 + Version 3.1.0 is not enforcing bannedDependencies rules + DependencyConvergence treats provided dependencies are runtime dependencies + Plugin shouldn't use NullPointerException for non-exceptional code flow + NPE in RequirePluginVersions + ReactorModuleConvergence not cached in reactor + RequireUpperBoundDeps fails on provided dependencies since 3.2.1 + Problematic dependency resolution by new 'banDynamicVersions' rule + banTransitiveDependencies: failing if a transitive dependencies has another version than the resolved one + Filtering dependency tree by scope + Upgrading to 3.0.0 causes 'Could not build dependency tree' with repositories some unknown protocol + DependencyConvergence in 3.1.0 fails when using version ranges + Semantics of 'ignores' parameter of 'banDynamicVersions' is inverted + Omission of 'excludedScopes' parameter of 'banDynamicVersions' causes NPE + ENFORCER: plugin-info and mojo pages not found
    * New Features:
    + requireUpperBounds deps should have includes + Introduce RequireTextFileChecksum with line separator normalization + allow no rules + show rules processed + DependencyConvergence should support including/excluding certain dependencies + Support declaring external banned dependencies in an external file/URL + Maven enforcer rule which checks that all dependencies have an explicit scope set + Maven enforcer rule which checks that all dependencies in dependencyManagement don't have an explicit scope set + Rule for no version ranges, version placeholders or SNAPSHOT versions + Allow one of many files in RequireFiles rules to pass + Skip specific rules + New Enforcer API + New Enforcer API - RuleConfigProvider + Move Built-In Rules to new API
    * Improvements:
    + wildcard ignore in requireReleaseDeps + Improve documentation about writing own Enforcer Rule + RequireActiveProfile should respect inherited activated profiles + Upgrade maven-dependency-tree to 3.x + Improve dependency resolving in multiple modules project + requireUpperBoundDeps: add [] and colors to the output + Example for writing a custom rule should be upgraded + Along with JavaVersion, allow enforcement of the JavaVendor + Included Java vendor in display-info output + requireMavenVersion x.y.z is processed as (,x.y.z] instead of [x.y.z,) + Consistently format artifacts same as dependency:tree + Made build Reproducible + Added support for excludes/includes in requireJavaVendor rule + Introduce Maven Enforcer Extension + Extends RequirePluginVersions with banMavenDefaults + Shared GitHub Actions + Log at ERROR level when is set + Reuse getDependenciesToCheck results across rules + Violation messages can be really hard to find in a multi module project + Clarify class loading for custom Enforcer rules + Using junit jupiter bom instead of single artifacts. + Get rid of maven-dependency-tree dependency + Allow 8 as JDK version for requireJavaVersion + Improve error message for rule 'requireJavaVersion' + Include Java Home in Message for Java Rule Failures + Manage all Maven Core dependencies as provided + Mange rules configuration by plugin + Deprecate 'rules' property and introduce 'enforcer.rules' as a replacement + Change success message from executed to passed + EnforcerLogger: Provide isDebugEnabled(), isErrorEnabled(), isWarnEnabled() and isInfoEnabled() + Properly declare dependencies
    * Test:
    + Regression test for dependency convergence problem fixed in 3.0.0
    * Task:
    + Removed reference to travis or switch to travis.com + Fixed maven assembly links + Require Java 8 + Verify working with Maven 4 + Code cleanup + Refresh download page + Deprecate display-info mojo + Refresh site descriptors + Superfluous blanks in BanDuplicatePomDependencyVersions + Rename ResolveUtil to ResolverUtil
    maven-plugin-tools was updated from version 3.6.0 to version 3.9.0:
    - Changes of version 3.9.0:
    * Bugs fixed:
    + Fixed *-mojo.xml (in PluginXdocGenerator) is overwritten when multiple locales are defined + Generated table by PluginXdocGenerator does not contain default attributes
    * Improvements:
    + Omit empty line in generated help goal output if plugin description is empty + Use Plexus I18N rather than fiddling with
    * Task:
    + Removed reporting from maven-plugin-plugin: create maven-plugin-report-plugin
    * Dependency upgrade:
    + Upgrade plugins and components (in ITs)
    • Changes of version 3.8.2:

    * Improvements:
    + Used Resolver API, get rid of localRepository
    * Dependency upgrade:
    + Bump httpcore from 4.4.15 to 4.4.16 + Bump httpclient from 4.5.13 to 4.5.14 + Bump antVersion from 1.10.12 to 1.10.13 + Bump slf4jVersion from 1.7.5 to 1.7.36 + Bump plexus-java from 1.1.1 to 1.1.2 + Bump plexus-archiver from 4.6.1 to 4.6.3 + Bump jsoup from 1.15.3 to 1.15.4 + Bump asmVersion from 9.4 to 9.5 + Bump assertj-core from 3.23.1 to 3.24.2
    • Changes of version 3.8.1:

    * Bugs fixed:
    + Javadoc reference containing a link label with spaces are not detected + JavadocLinkGenerator.createLink: Support nested binary class names + ERROR during build of m-plugin-report-p and m-plugin-p: Dependencies in wrong scope + 'Executes as an aggregator plugin' documentation: s/plugin/goal/ + Maven scope warning should be logged at WARN level + Fixed Temporary File Information Disclosure Vulnerability
    * New features:
    + Support mojos using the new maven v4 api
    * Improvements:
    + Plugin descriptor should contain the requiredJavaVersion/requiredMavenVersion + Execute annotation only supports standard lifecycle phases due to use of enum + Clarify deprecation of all extractors but the maven-plugin-tools-annotations
    * Dependency upgrade:
    + Update to Maven Parent POM 39 + Bump junit-bom from 5.9.1 to 5.9.2 + Bump plexus-archiver from 4.5.0 to 4.6.1
    • Changes of version 3.7.1: * Bugs fixed:

    + Maven scope warning should be logged at WARN level
    • Changes of version 3.7.0:

    * Bugs fixed:
    + The plugin descriptor generated by plugin:descriptor does not consider @ see javadoc taglets + Report-Mojo doesn't respect input encoding + Generating site reports for plugin results in NoSuchMethodError + JDK Requirements in plugin-info.html: Consider property 'maven.compiler.release' + Parameters documentation inheriting @ since from Mojo can be confusing + Don't emit warning for missing javadoc URL of primitives + Don't emit warning for missing javadoc URI if no javadoc sources are configured + Parameter description should be taken from annotated item
    * New Features:
    + Added link to javadoc in configuration description page for user defined types of Mojos. + Allow only @ Deprecated annotation without @ deprecated javadoc tag + add system requirements history section + report: allow to generate usage section in plugin-info.html with true + Allow @ Parameter on setters methods + Extract plugin report into its own plugin + report: Expose generics information of Collection and Map types
    * Improvement:
    + plugin-info.html should contain a better Usage section + Do not overwrite generate files with no content change + Upgrade to JUnit 5 and @ Inject annotations + Support for java 20 - ASM 9.4 + Don't print empty Memory, Disk Space in System Requirements + simplification in helpmojo build + Get rid of plexus-compiler-manager from tests + Use Maven core artifacts in provided scope + report and descriptor goal need to evaluate Javadoc comments differently + Allow to reference aggregator javadoc from plugin report
    * Task:
    + Detect legacy/javadoc Mojo definitions, warn to use Java 5 annotations + Update level to Java 8 + Deprecate scripting support for mojos + Deprecate requirements parameter in report Mojo + Removed duplicate code from PluginReport + Prepare for Doxia (Sitetools) 2.0.0 + Fixed documentation for maven-plugin-report-plugin + Removed deprecated items from new maven-plugin-report-plugin + Improve site build + Improve dependency management + Plugin generator generation fails when the parent class comes from a different project
    * Dependency upgrade:
    + Upgrade Maven Reporting API/Impl to 3.1.0 + Upgrade Parent to 36 + Upgrade project dependencies after JDK 1.8 + Bump maven-parent from 36 to 37 + Upgrade Maven Reporting API to 3.1.1/Maven Reporting Impl to 3.2.0 + Upgrade plexus-utils to 3.5.0
    • Changes of version 3.6.4:

    * Restored compatibility with Maven 3 ecosystem * Upgraded dependencies
    • Changes of version 3.6.3:

    * Added prerequisites to plugin pom * Exclude dependency in provided scope from plugin descriptor * Get rid of String.format use * Fixed this logging as well * Simplify documentation * Exclude maven-archiver and maven-jxr from warning
    • Changes of version 3.6.2:

    * Deprecated unused requiresReports flag * Check that Maven dependencies are provided scope * Update ITs * Use shared gh action * Deprecate unsupported Mojo descriptor items * Weed out ITs * Upgrade to maven 3.x and avoid using deprecated API * Drop legacy dependencies * Use shared gh action - v1 * Fixed wording in javadoc
    • Changes of version 3.6.1:

    * What's Changed: * Added missing @OverRide and make methods static * Upgraded to JUnit 4.12 * Upgraded parent POM and other dependencies * Updated plugins * Upgraded Doxia Sitetools to 1.9.2 to remove dependency on Struts * removed Maven 2 info * Removed unneeded dependency * Tighten the dependency tree * Ignore .checkstyle * Strict dependencies for maven-plugin-tools-annotations * Improved @execute(goal...) docs * Improve @execute(lifecycle...) docs
    plexus-compiler was updated from version 2.11.1 to 2.14.2:
    • Changes of 2.14.2:

    * Removed:
    + Drop J2ObjC compiler
    * New features and improvements:
    + Update AspectJ Compiler to 1.9.21 to support Java 21 + Require JDK 17 for build + Improve locking on JavacCompiler + Include 'parameter' and 'preview' describe log + Switch to SISU annotations and plugin, fixes #217 + Support jdk 21 + Require Maven 3.5.4+ + Require Java 11 for plexus-compiler-eclipse an javac-errorprone and aspectj compilers + Added support to run its with Java 20
    * Bugs fixed:
    + Fixed javac memory leak + Validate zip file names before extracting (Zip Slip) + Restore AbstractCompiler#getLogger() method + Return empty list for not existing source root location + Improve javac error output parsing
    • Changes of 2.13.0:

    * New features and improvements:
    + Fully ignore any possible jdk bug + MCOMPILER-402: Added implicitOption to CompilerConfiguration + Added a custom compile argument replaceProcessorPathWithProcessorModulePath to force the plugin replace processorPath with processormodulepath + describe compiler configuration on run + simplify 'Compiling' info message: display relative path
    * Bugs fixed:
    + Respect CompilerConfiguration.sourceFiles in EclipseJavaCompiler + Avoid NPE in AspectJCompilerTest on AspectJ 1.9.8+
    * Dependency updates:
    + Bump maven-surefire-plugin from 3.0.0-M5 to 3.0.0-M6 + Bump error_prone_core from 2.11.0 to 2.13.1 + Bump github/codeql-action from 1 to 2 + Bump ecj from 3.28.0 to 3.29.0 + Bump release-drafter/release-drafter from 5.18.1 to 5.19.0 + Bump ecj from 3.29.0 to 3.30.0 + Bump maven-invoker-plugin from 3.2.2 to 3.3.0 + Bump maven-enforcer-plugin from 3.0.0 to 3.1.0 + Bump error_prone_core from 2.13.1 to 2.14.0 + Bump maven-surefire-plugin from 3.0.0-M6 to 3.0.0-M7 + Bump ecj from 3.31.0 to 3.32.0 + Bump junit-bom from 5.9.0 to 5.9.1 + Bump ecj from 3.30.0 to 3.31.0 + Bump groovy from 3.0.12 to 3.0.13 + Bump groovy-json from 3.0.12 to 3.0.13 + Bump groovy-xml from 3.0.12 to 3.0.13 + Bump animal-sniffer-maven-plugin from 1.21 to 1.22 + Bump error_prone_core from 2.14.0 to 2.15.0 + Bump junit-bom from 5.8.2 to 5.9.0 + Bump groovy-xml from 3.0.11 to 3.0.12 + Bump groovy-json from 3.0.11 to 3.0.12 + Bump groovy from 3.0.11 to 3.0.12
    * Maintenance:
    + Require Maven 3.2.5


    Advisory IDSUSE-SU-2024:597-1
    ReleasedThu Feb 22 20:07:11 2024
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1216198,CVE-2023-5388
    Description:

    This update for mozilla-nss fixes the following issues:
    Update to NSS 3.90.2:

    • CVE-2023-5388: Fixed timing attack against RSA decryption in TLS (bsc#1216198)


    Advisory IDSUSE-SU-2024:726-1
    ReleasedThu Feb 29 12:12:44 2024
    SummarySecurity update for Java
    Typesecurity
    Severityimportant
    References1220068,1220070,CVE-2024-25710,CVE-2024-26308
    Description:

    This update for Java fixes the following issues:
    apache-commons-codec was updated to version 1.16.1:

    • Changes in version 1.16.1:

    * New features:
    + Added Maven property project.build.outputTimestamp for build reproducibility
    * Bugs fixed:
    + Correct error in Base64 Javadoc + Added minimum Java version in changes.xml + Documentation update for the org.apache.commons.codec.digest.* package + Precompile regular expression in UnixCrypt.crypt(byte[], String) + Fixed possible IndexOutOfBoundException in PhoneticEngine.encode method + Fixed possible ArrayIndexOutOfBoundsException in QuotedPrintableCodec.encodeQuotedPrintable() method + Fixed possible StringIndexOutOfBoundException in MatchRatingApproachEncoder.encode() method + Fixed possible ArrayIndexOutOfBoundException in RefinedSoundex.getMappingCode() + Fixed possible IndexOutOfBoundsException in PercentCodec.insertAlwaysEncodeChars() method + Deprecated UnixCrypt 0-argument constructor + Deprecated Md5Crypt 0-argument constructor + Deprecated Crypt 0-argument constructor + Deprecated StringUtils 0-argument constructor + Deprecated Resources 0-argument constructor + Deprecated Charsets 0-argument constructor + Deprecated CharEncoding 0-argument constructor
    • Changes in version 1.16.0:

    * Remove duplicated words from Javadocs * Use Standard Charset object * Use String.contains() functions * Avoid use toString() or substring() in favor of a simplified expression * Fixed byte-skipping in Base16 decoding * Fixed several typos, improve writing in some javadocs * BaseNCodecOutputStream.eof() should not throw IOException. * Javadoc improvements and cleanups. * Deprecated BaseNCodec.isWhiteSpace(byte) and use Character.isWhitespace(int). * Added support for Blake3 family of hashes * Added github/codeql-action * Bump actions/cache from v2 to v3.0.10 * Bump actions/setup-java from v1.4.1 to 3.5.1 * Bump actions/checkout from 2.3.2 to 3.1.0 * Bump commons-parent from 52 to 58 * Bump junit from 4.13.1 to 5.9.1 * Bump Java 7 to 8. * Bump japicmp-maven-plugin from 0.14.3 to 0.17.1. * Bump jacoco-maven-plugin from 0.8.5 to 0.8.8 (Fixes Java 15 builds). * Bump maven-surefire-plugin from 2.22.2 to 3.0.0-M7 * Bump maven-javadoc-plugin from 3.2.0 to 3.4.1. * Bump animal-sniffer-maven-plugin from 1.19 to 1.22. * Bump maven-pmd-plugin from 3.13.0 to 3.19.0 * Bump pmd from 6.47.0 to 6.52.0. * Bump maven-checkstyle-plugin from 2.17 to 3.2.0 * Bump checkstyle from 8.45.1 to 9.3 * Bump taglist-maven-plugin from 2.4 to 3.0.0 * Bump jacoco-maven-plugin from 0.8.7 to 0.8.8.
    apache-commons-compress was updated to version 1.26:
    • Changes in version 1.26:

    * Security issues fixed:
    + CVE-2024-26308: Fixed allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress (bsc#1220068) + CVE-2024-25710: Fixed loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress (bsc#1220070)
    * New Features:
    + Added and use ZipFile.builder(), ZipFile.Builder, and deprecate constructors + Added and use SevenZFile.builder(), SevenZFile.Builder, and deprecate constructors + Added and use ArchiveInputStream.getCharset() + Added and use ArchiveEntry.resolveIn(Path) + Added Maven property project.build.outputTimestamp for build reproducibility
    * Bugs fixed: + Check for invalid PAX values in TarArchiveEntry + Fixed zero size headers in ArjInputStream + Fixes and tests for ArInputStream + Fixes for dump file parsing + Improved CPIO exception detection and handling + Deprecated SkipShieldingInputStream without replacement (nolonger used) + Reuse commons-codec, don't duplicate class PureJavaCrc32C (removed package-private class) + Reuse commons-codec, don't duplicate class XXHash32 (deprecated class) + Reuse commons-io, don't duplicate class Charsets (deprecated class) + Reuse commons-io, don't duplicate class IOUtils (deprecated methods) + Reuse commons-io, don't duplicate class BoundedInputStream (deprecated class) + Reuse commons-io, don't duplicate class FileTimes (deprecated TimeUtils methods) + Reuse Arrays.equals(byte[], byte[]) and deprecate ArchiveUtils.isEqual(byte[], byte[]) + Added a null-check for the class loader of OsgiUtils + Added a null-check in Pack200.newInstance(String, String) + Deprecated ChecksumCalculatingInputStream in favor of java.util.zip.CheckedInputStream + Deprecated CRC32VerifyingInputStream.CRC32VerifyingInputStream(InputStream, long, int) + FramedSnappyCompressorOutputStream produces incorrect output when writing a large buffer + Fixed TAR directory entries being misinterpreted as files + Deprecated unused method FileNameUtils.getBaseName(String) + Deprecated unused method FileNameUtils.getExtension(String) + ArchiveInputStream.BoundedInputStream.read() incorrectly adds 1 for EOF to the bytes read count + Deprecated IOUtils.read(File, byte[]) + Deprecated IOUtils.copyRange(InputStream, long, OutputStream, int) + ZipArchiveOutputStream multi archive updates metadata in incorrect file + Deprecated ByteUtils.InputStreamByteSupplier + Deprecated ByteUtils.fromLittleEndian(InputStream, int) + Deprecated ByteUtils.toLittleEndian(DataOutput, long, int) + Reduce duplication by having ArchiveInputStream extend FilterInputStream + Support preamble garbage in ZipArchiveInputStream + Fixed formatting the lowest expressable DOS time + Dropped reflection from ExtraFieldUtils static initialization + Preserve exception causation in ExtraFieldUtils.register(Class)
    • Changes in version 1.25:

    * For the full list of changes please consult: https://commons.apache.org/proper/commons-compress/changes-report.html#a1.25.0
    • Changes in version 1.24:

    * For the full list of changes please consult: https://commons.apache.org/proper/commons-compress/changes-report.html#a1.24.0
    • Changes in version 1.23:

    * For the full list of changes please consult: https://commons.apache.org/proper/commons-compress/changes-report.html#a1.23.0
    • Changes in version 1.22:

    * For the full list of changes please consult: https://commons.apache.org/proper/commons-compress/changes-report.html#a1.22
    apache-commons-io was updated to version 2.15.1:
    • Changes in version 2.15.1:

    * For the full list of changes please consult: https://commons.apache.org/proper/commons-io/changes-report.html#a2.15.1
    • Changes in version 2.15.0:

    * For the full list of changes please consult: https://commons.apache.org/proper/commons-io/changes-report.html#a2.15.0
    • Changes in version 2.14.0:

    * For the full list of changes please consult: https://commons.apache.org/proper/commons-io/changes-report.html#a2.14.0
    javapackages-meta:
    • Syncing the version with javapackages-tools 6.2.0
    • Remove unnecessary dependencies

    maven was updated to version 3.9.6:
    • Changes in version 3.9.6:

    * Bugs fixed:
    + Error message when modelVersion is 4.0 is confusing
    * Improvements:
    + Colorize transfer messages + Support ${project.basedir} in file profile activation + Allow to exclude plugins from validation
    * Tasks:
    + Maven Resolver Provider classes ctor change + Undeprecate wrongly deprecated repository metadata + Deprecated `org.apache.maven.repository.internal.MavenResolverModule` + maven-resolver-provider: introduce NAME constants.
    * Dependency upgrade:
    + Updated to Resolver 1.9.16 + Upgraded Sisu version to 0.9.0.M2 + Upgraded Resolver version to 1.9.18 + Upgraded to parent POM 41 + Upgraded default plugin bindings
    maven-assembly-plugin:
    • Explicitely require commons-io:commons-io and commons-codec:common-codes artifacts that are optional in apache-commons-compress

    maven-doxia was updated to version 1.12.0:
    * Changes in version 1.12.0:
    + Upgraded to FOP 2.2 + Fixed rendering links and paragraphs inside tables + Rewrite .md and .markdown links to .html + Upgraded HttpComponents: httpclient to 4.5.8 and httpcore to 4.4.11 + Escape links to xml based figureGraphics image elements + SECURITY: Use HTTPS to resolve dependencies in Maven Build + Removed old Maven 1 and 2 info + Updated commons-lang to 3.8.1 + Dropped dependency to outdated Log4j + Fixed Java 7 compatibility that was broken + Import tests from maven-site-plugin + Fixed crosslinks starting with a dot in markdown files + Replace deprecated class from commons-lang + Fill in some generic types
    maven-doxia-sitetools was updated to version 1.11.1:
    • Changes in version 1.11.1:

    * Bugs fixed:
    + CLIRR can't find previous version
    * Improvements:
    + Removed all   in default-site-macros.vm and replace by a space + Improved documentation on site.xml inheritance vs interpolation
    * Tasks:
    + Deprecated Doxia Sitetools Doc Renderer
    * Dependency upgrade:
    + Fixed javadoc issues with JDK 8 when generating documentation + Wrong coordinates for jai_core: hyphen should be underscore + Use latest JUnit version 4.13.2 + Upgraded Plexus Utils to 3.3.0 + Upgraded Plexus Interpolation to 1.26 + Upgraded Maven Doxia to 1.10 + Upgraded Maven Doxia to 1.11.1
    maven-jar-plugin was updated to version 3.3.0:
    • Changes in version 3.3.0:

    * Bugs fixed:
    + outputTimestamp not applied to module-info; breaks reproducible builds
    * Task:
    + Updated plugin (requires Maven 3.2.5+) + Java 8 as minimum
    * Dependency upgrade:
    + Upgraded Plexus Utils to 3.3.1 + Removed override for Plexus Archiver to fix order of META-INF/ and META-INF/MANIFEST.MF entries + Upgraded Parent to 36 + Updated Plexus Utils to 3.4.2 + Upgraded Parent to 37
    maven-jar-plugin was updated to version 3.6.0:
    • Changes from version 3.6.0:

    * Bugs fixed:
    + Setting maven.javadoc.isoffline seems to have no effect + javadoc site is broken for projects that contain modules + Alternative doclet page points to an SEO spammy page + [REGRESSION] Transitive dependencies of docletArtifact missing + Unresolvable link in javadoc tag with value ResourcesBundleMojo#getAttachmentClassifier() found in ResourcesBundleMojo + IOException --> NullPointerException in JavadocUtil.copyResource + JavadocReportTest.testExceptions is broken + javadoc creates invalid --patch-module statements + javadoc plugin can not deal with transitive filename based modules
    * Improvements:
    + Clean up deprecated and unpreferred methods in JavadocUtil + Cleanup dependency declarations as best possible + Allow building javadoc 'the old fashioned way' after Java 8
    * Tasks:
    + Dropped use of deprecated localRepository mojo parameter + Make build pass with Java 20 + Refresh download page
    * Dependency upgrade:
    + Updated to commons-io 2.13.0 + Updated plexus-archiver from 4.7.1 to 4.8.0 + Upgraded Parent to 40
    • Changes from version 3.5.0:

    * Bugs fixed:
    + Invalid anchors in Javadoc and plugin mojo + Plugin duplicates classes in Java 8 all-classes lists + javadoc site creation ignores configuration parameters
    * Improvements:
    + Deprecated parameter 'stylesheet' + Parse stderr output and suppress informational lines + Link to Javadoc references from JDK 17 + Migrate components to JSR 330, get rid of maven-artifact-transfer, update to parent 37
    * Tasks:
    + Removed remains of org.codehaus.doxia.sink.Sink
    * Dependency upgrades:
    + Upgraded plugins in ITs + Upgraded to Maven 3.2.5 + Updated Maven Archiver to 3.6.0 + Upgraded Maven Reporting API to 3.1.1/Complete with Maven Reporting Impl 3.2.0 + Upgraded commons-text to 1.10.0 + Upgraded Parent to 39 + Upgraded plugins and components
    maven-reporting-api was updated to version 3.1.1:
    • Restore binary compat for MavenReport

    maven-reporting-impl was updated to version 3.2.0:
    • Changes in version 3.2.0:

    * Improvement:
    + Render with a skin when report is run in standalone mode
    * Dependency upgrades:
    + Upgraded Maven Reporting API to 3.1.1 + Upgraded plugins and components in project and ITs
    maven-resolver was updated to version 1.9.18:
    • Changes in version 1.9.18:

    * Bugs fixed:
    + Sporadic AccessDeniedEx on Windows + Undo FileUtils changes that altered non-Windows execution path
    * Improvements:
    + Native transport should retry on HTTP 429 (Retry-After)
    * Task:
    + Deprecated Guice modules + Get rid of component name string literals, make them constants and reusable + Expose configuration for inhibiting Expect-Continue handshake in 1.x + Refresh download page + Resolver should not override given HTTP transport default use of expect-continue handshake
    maven-resources-plugin was updated to version 3.3.1:
    • Changes in version 3.3.1:

    * Bugs fixed:
    + Resource plugin's handling of symbolic links changed in 3.0.x, broke existing behavior + Resource copying not using specified encoding + java.nio.charset.MalformedInputException: Input length = 1 + Filtering of Maven properties with long names is not working after transition from 2.6 to 3.2.0 + Valid location for directory parameter is always required + Symlinks cause copying resources to fail + FileUtils.copyFile() fails with source file having `lastModified = 0`
    * New Features:
    + Added ability to flatten folder structure into target directory when copying resources
    * Improvements:
    + Make tests jar reproducible + Describe from and to in 'Copying xresources' info message
    * Task:
    + Dropped plexus legacy + Updated to parent POM 39, reformat sources + Updated plugin (requires Maven 3.2.5+) + Require Java 8
    * Dependency upgrade:
    + Upgraded maven-plugin parent to 36 + Upgraded Maven Filtering to 3.3.0 + Upgraded plexus-utils to 3.5.1 + Upgraded to maven-filtering 3.3.1
    sbt:
    • Fixed RPM package build with maven 3.9.6 and maven-resolver 1.9.18

    xmvn:
    • Modify the xmvn-install script to work with new apache-commons-compress
    • Recompiling RPM package to resolve package building issues with maven-lib


    Advisory IDSUSE-SU-2024:786-1
    ReleasedWed Mar 6 21:07:20 2024
    SummarySecurity update for giflib
    Typesecurity
    Severityimportant
    References1198880,1200551,1217390,CVE-2021-40633,CVE-2022-28506,CVE-2023-48161
    Description:

    This update for giflib fixes the following issues:
    Update to version 5.2.2

    • Fixes for CVE-2023-48161 (bsc#1217390), CVE-2022-28506 (bsc#1198880)
    • #138 Documentation for obsolete utilities still installed
    • #139: Typo in 'LZW image data' page ('110_2 = 4_10')
    • #140: Typo in 'LZW image data' page ('LWZ')
    • #141: Typo in 'Bits and bytes' page ('filed')
    • Note as already fixed SF issue #143: cannot compile under mingw
    • #144: giflib-5.2.1 cannot be build on windows and other platforms using c89
    • #145: Remove manual pages installation for binaries that are not installed too
    • #146: [PATCH] Limit installed man pages to binaries, move giflib to section 7
    • #147 [PATCH] Fixes to doc/whatsinagif/ content
    • #148: heap Out of Bound Read in gif2rgb.c:298 DumpScreen2RGB
    • Declared no-info on SF issue #150: There is a denial of service vulnerability in GIFLIB 5.2.1
    • Declared Won't-fix on SF issue 149: Out of source builds no longer possible
    • #151: A heap-buffer-overflow in gif2rgb.c:294:45
    • #152: Fix some typos on the html documentation and man pages
    • #153: Fix segmentation faults due to non correct checking for args
    • #154: Recover the giffilter manual page
    • #155: Add gifsponge docs
    • #157: An OutofMemory-Exception or Memory Leak in gif2rgb
    • #158: There is a null pointer problem in gif2rgb
    • #159 A heap-buffer-overflow in GIFLIB5.2.1 DumpScreen2RGB() in gif2rgb.c:298:45
    • #163: detected memory leaks in openbsd_reallocarray giflib/openbsd-reallocarray.c
    • #164: detected memory leaks in GifMakeMapObject giflib/gifalloc.c
    • #166: a read zero page leads segment fault in getarg.c and memory leaks in gif2rgb.c and gifmalloc.c
    • #167: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function at Line 321 of gif2rgb.c


    Advisory IDSUSE-SU-2024:305-1
    ReleasedMon Mar 11 14:15:37 2024
    SummarySecurity update for cpio
    Typesecurity
    Severitymoderate
    References1218571,1219238,CVE-2023-7207
    Description:

    This update for cpio fixes the following issues:

    • Fixed cpio not extracting correctly when using --no-absolute-filenames option the security fix for CVE-2023-7207 (bsc#1218571, bsc#1219238)


    Advisory IDSUSE-RU-2024:861-1
    ReleasedWed Mar 13 09:12:30 2024
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1218232
    Description:

    This update for aaa_base fixes the following issues:

    • Silence the output in the case of broken symlinks (bsc#1218232)


    Advisory IDSUSE-RU-2024:907-1
    ReleasedFri Mar 15 08:57:38 2024
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1215377
    Description:

    This update for audit fixes the following issue:

    • Fix plugin termination when using systemd service units (bsc#1215377)


    Advisory IDSUSE-RU-2024:929-1
    ReleasedTue Mar 19 06:36:24 2024
    SummaryRecommended update for coreutils
    Typerecommended
    Severitymoderate
    References1219321
    Description:

    This update for coreutils fixes the following issues:

    • tail: fix tailing sysfs files where PAGE_SIZE > BUFSIZ (bsc#1219321)


    Advisory IDSUSE-SU-2024:1129-1
    ReleasedMon Apr 8 09:12:08 2024
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1219559,1221289,CVE-2023-52425,CVE-2024-28757
    Description:

    This update for expat fixes the following issues:

    • CVE-2023-52425: Fixed a DoS caused by processing large tokens. (bsc#1219559)
    • CVE-2024-28757: Fixed an XML Entity Expansion. (bsc#1221289)


    Advisory IDSUSE-SU-2024:1133-1
    ReleasedMon Apr 8 11:29:02 2024
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1220061,CVE-2023-45918
    Description:

    This update for ncurses fixes the following issues:

    • CVE-2023-45918: Fixed NULL pointer dereference via corrupted xterm-256color file (bsc#1220061).


    Advisory IDSUSE-RU-2024:1253-1
    ReleasedFri Apr 12 08:15:18 2024
    SummaryRecommended update for gcc13
    Typerecommended
    Severitymoderate
    References1210959,1214934,1217450,1217667,1218492,1219031,1219520,1220724,1221239
    Description:

    This update for gcc13 fixes the following issues:

    • Fix unwinding for JIT code. [bsc#1221239]
    • Revert libgccjit dependency change. [bsc#1220724]
    • Remove crypt and crypt_r interceptors. The crypt API change in SLE15 SP3 breaks them. [bsc#1219520]
    • Add support for -fmin-function-alignment. [bsc#1214934]
    • Use %{_target_cpu} to determine host and build.
    • Fix for building TVM. [bsc#1218492]
    • Add cross-X-newlib-devel requires to newlib cross compilers. [bsc#1219031]
    • Package m2rte.so plugin in the gcc13-m2 sub-package rather than in gcc13-devel. [bsc#1210959]
    • Require libstdc++6-devel-gcc13 from gcc13-m2 as m2 programs are linked against libstdc++6.
    • Fixed building mariadb on i686. [bsc#1217667]
    • Avoid update-alternatives dependency for accelerator crosses.
    • Package tool links to llvm in cross-amdgcn-gcc13 rather than in cross-amdgcn-newlib13-devel since that also has the dependence.
    • Depend on llvmVER instead of llvm with VER equal to %product_libs_llvm_ver where available and adjust tool discovery accordingly. This should also properly trigger re-builds when the patchlevel version of llvmVER changes, possibly changing the binary names we link to. [bsc#1217450]


    Advisory IDSUSE-RU-2024:1429-1
    ReleasedWed Apr 24 15:13:10 2024
    SummaryRecommended update for ca-certificates
    Typerecommended
    Severitymoderate
    References1188500,1221184
    Description:

    This update for ca-certificates fixes the following issue:

    • Update version (bsc#1221184) * Use flock to serialize calls (bsc#1188500) * Make certbundle.run container friendly * Create /var/lib/ca-certificates if needed


    Advisory IDSUSE-RU-2024:1487-1
    ReleasedThu May 2 10:43:53 2024
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1211721,1221361,1221407,1222547
    Description:

    This update for aaa_base fixes the following issues:

    • home and end button not working from ssh client (bsc#1221407)
    • use autosetup in prep stage of specfile
    • drop the stderr redirection for csh (bsc#1221361)
    • drop sysctl.d/50-default-s390.conf (bsc#1211721)
    • make sure the script does not exit with 1 if a file with content is found (bsc#1222547)


    Advisory IDSUSE-RU-2024:1665-1
    ReleasedThu May 16 08:00:09 2024
    SummaryRecommended update for coreutils
    Typerecommended
    Severitymoderate
    References1221632
    Description:

    This update for coreutils fixes the following issues:

    • ls: avoid triggering automounts (bsc#1221632)


    Advisory IDSUSE-SU-2024:1762-1
    ReleasedWed May 22 16:14:17 2024
    SummarySecurity update for perl
    Typesecurity
    Severityimportant
    References1082216,1082233,1213638,CVE-2018-6798,CVE-2018-6913
    Description:

    This update for perl fixes the following issues:
    Security issues fixed:

    • CVE-2018-6913: Fixed space calculation issues in pp_pack.c (bsc#1082216)
    • CVE-2018-6798: Fixed heap buffer overflow in regexec.c (bsc#1082233)

    Non-security issue fixed:
    • make Net::FTP work with TLS 1.3 (bsc#1213638)


    Advisory IDSUSE-RU-2024:1763-1
    ReleasedThu May 23 04:34:48 2024
    SummaryRecommended update for ant, hamcrest, junit
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for ant, hamcrest, junit fixes the following issues:
    ant, ant-antlr, ant-junit5, ant-junit:

    • Put hamcrest on the classpath of ant-junit module

    hamcrest was updated to version 2.2:
    • Version 2.2:

    * This version simplifies the packaging of Hamcrest into a single jar. Other big changes include Java 9 module compatibility, along with numerous other improvements and bug fixes. * Breaking Changes: + Although the class API has not changed since Hamcrest 1.3, the way that the project is packaged has changed. Refer to the Hamcrest Distributables documentation for more information, and in particular the section on Upgrading from Hamcrest 1.x + The org.hamcrest.Factory annotation has been removed (it should not be used in client code)
    * Improvements: + AllOf/AnyOf: Pass the matchers to constructor using varargs + Matchers.anyOf: Fixed generic bounds compatibility for JDK 11 + AssertionError message is unhelpful when match fails for byte type + Use platform specific line breaks + The build now checks for consistent use of spaces
    * Bugs fixed and other changes: + Fixed compatibility issue for development with Android D8 + Fixed typo in license name + 1.3 compatible constructors for string matchers + Fixed for split packages with Java 9 modules + Documentation updates + Added implementation for CharSequence length matcher + Fixed for TypeSafeDiagnosingMatcher can't detect generic types for subclass + Renamed IsCollectionContaining to IsIterableContaining + Make Hamcrest an OSGI bundle + Added StringRegularExpression matcher + Fixed StringContainsInOrder to detect if a repeated pattern is missing + Added ArrayAsIterableMatcher + Fixed description for IsEqualIgnoringCase + Fixed JavaDoc examples + Upgraded to Java 7 + Build with Gradle + Deprecate IsCollectionContaining and IsArrayContainingXXX + Removed deprecated methods from previous release + Improve mismatch description of hasItem/hasItems + General improvements to mismatch descriptions + Several JavaDoc improvements and corrections + Deprecated several matcher factory methods of the for 'isXyz' + Fixed address doclint errors reported in JDK 1.8 + Fixed Iterable contains in order is null-safe + Added equalToObject() (i.e. unchecked) method + Fixed arrayContaining(null, null) cause NullPointerException * Fixed string matching on regular expressions * Fixed isCloseTo() shows wrong delta in mismatch description * Fixed add untyped version of equalTo, named equalToObject * Implement IsEmptyMap, IsMapWithSize * Fixed IsArray.describeMismatchSafely() should use Matcher.describeMismatch * Added Matcher implementation for files * Fixed NPE in IsIterableContainingInOrder
    junit:
    • Generate anew the ant build system using the maven pom.xml
    • Fetch sources from github by source service and filter out stale hamcrest binaries.
    • Port to hamcrest 2.2 unconditionally
    • Removed deprecated assertThat
    • Let ant build with --release 8 if the compiler knows that option. This allows us to avoid incompatible exception declarations in ObjectInputStream.GetField.get(String,Object) in java >= 20


    Advisory IDSUSE-SU-2024:1874-1
    ReleasedFri May 31 05:05:25 2024
    SummarySecurity update for Java
    Typesecurity
    Severityimportant
    References1187446,1224410,CVE-2021-33813
    Description:

    This update for Java fixes thefollowing issues:
    apiguardian was updated to vesion 1.1.2:

    • Added LICENSE/NOTICE to the generated jar
    • Allow @API to be declared at the package level
    • Explain usage of Status.DEPRECATED
    • Include OSGi metadata in manifest

    assertj-core was implemented at version 3.25.3:
    • New package implementation needed by Junit5

    byte-buddy was updated to version v1.14.16:
    • `byte-buddy` is required by `assertj-core`
    • Changes in version v1.14.16:

    * Update ASM and introduce support for Java 23.
    • Changes in version v1.14.15:

    * Allow attaching from root on J9.
    • Changes of v1.14.14:

    * Adjust type validation to accept additional names that are legal in the class file format. * Fix dynamic attach on Windows when a service user is active. * Avoid failure when using Android's strict mode.
    dom4j was updated to version 2.1.4:
    • Improvements and potentially breaking changes:

    * Added new factory method org.dom4j.io.SAXReader.createDefault(). It has more secure defaults than new SAXReader(), which uses system XMLReaderFactory.createXMLReader() or SAXParserFactory.newInstance().newSAXParser(). * If you use some optional dependency of dom4j (for example Jaxen, xsdlib etc.), you need to specify an explicit dependency on it in your project. They are no longer marked as a mandatory transitive dependency by dom4j. * Following SAX parser features are disabled by default in DocumentHelper.parse() for security reasons (they were enabled in previous versions): + http://xml.org/sax/properties/external-general-entities + http://xml.org/sax/properties/external-parameter-entities
    • Other changes:

    * Do not depend on jtidy, since it is not used during build * Fixed license to Plexus * JPMS: Add the Automatic-Module-Name attribute to the manifest. * Make a separate flavour for a minimal `dom4j-bootstrap` package used to build `jaxen` and full `dom4j` * Updated pull-parser version * Reuse the writeAttribute method in writeAttributes * Support build on OS with non-UTF8 as default charset * Gradle: add an automatic module name * Use Correct License Name 'Plexus' * Possible vulnerability of DocumentHelper.parseText() to XML injection * CVS directories left in the source tree * XMLWriter does not escape supplementary unicode characters correctly * writer.writeOpen(x) doesn't write namespaces * Fixed concurrency problem with QNameCache * All dependencies are optional * SAXReader: hardcoded namespace features * Validate QNames * StringIndexOutOfBoundsException in XMLWriter.writeElementContent() * TreeNode has grown some generics * QName serialization fix * DocumentException initialize with nested exception * Accidentally occurring error in a multi-threaded test * Added compatibility with W3C DOM Level 3 * Use Java generics
    hamcrest:
    • `hamcrest-core` has been replaced by `hamcrest` (no source changes)

    junit had the following change:
    • Require hamcrest >= 2.2

    junit5 was updated to version 5.10.2:
    • Conditional execution based on OS architectures
    • Configurable cleanup mode for @TempDir
    • Configurable thread mode for @Timeout
    • Custom class loader support for class/method selectors, @MethodSource, @EnabledIf, and @DisabledIf
    • Dry-run mode for test execution
    • Failure threshold for @RepeatedTest
    • Fixed build with the latest open-test-reporting milestone
    • Fixed dependencies in module-info.java files
    • Fixed unreported exception error that is fatal with JDK 21
    • Improved configurability of parallel execution
    • New @SelectMethod support in test @Suite classes.
    • New ConsoleLauncher subcommand for test discovery without execution
    • New convenience base classes for implementing ArgumentsProvider and ArgumentConverter
    • New IterationSelector
    • New LauncherInterceptor SPI
    • New NamespacedHierarchicalStore for use in third-party test engines
    • New TempDirFactory SPI for customizing how temporary directories are created
    • New testfeed details mode for ConsoleLauncher
    • New TestInstancePreConstructCallback extension API
    • Numerous bug fixes and minor improvements
    • Parameter injection for @MethodSource methods
    • Promotion of various experimental APIs to stable
    • Reusable parameter resolution for custom extension methods via ExecutableInvoker
    • Stacktrace pruning to hide internal JUnit calls
    • The binaries are compatible with java 1.8
    • Various improvements to ConsoleLauncher
    • XML reports in new Open Test Reporting format

    jdom:
    • Security issues fixed:

    * CVE-2021-33813: Fixed an XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request (bsc#1187446)
    • Other changes and bugs fixed: * Fixed wrong entries in changelog (bsc#1224410) * The packages `jaxen`, `saxpath` and `xom` are now separate standalone packages instead of being part of `jdom`

    jaxen was implemented at version 2.0.0:
    • New standalone RPM package implementation, originally part of `jdom` source package
    • Classpaths are much smaller and less complex, and will suppress a lot of noise from static analysis tools.
    • The Jaxen core code is also a little smaller and has fixed a few minor bugs in XPath evaluation
    • Despite the major version bump, this should be a drop in replacement for almost every project. The two major possible incompatibilities are: * The minimum supported Java version is now 1.5, up from 1.4 in 1.2.0 and 1.3 in 1.1.6. * dom4j, XOM, and JDOM are now optional dependencies so if a project was depending on them to be loaded transitively it will need to add explicit dependencies to build.

    jopt-simple:
    • Included jopt-simple to Package Hub 15 SP5 (no source changes)

    objectweb-asm was updated to version 9.7:
    • New Opcodes.V23 constant for Java 23
    • Bugs fixed * Fixed unit test regression in dex2jar. * Fixed 'ClassNode#outerClass' with incorrect JavaDocs. * asm-bom packaging should be 'pom'. * The Textifier prints a supplementary space at the end of each method that throws at least one exception.


    open-test-reporting:
    • Included `open-test-reporting-events` and `open-test-reporting-schema` to the channels as they are runtime dependencies of Junit5 (no source changes)

    saxpath was implemented at version 1.0 FCS:
    • New standalone RPM package implementation, originally part of `jdom` source package (openSUSE Leap 15.5 package only)

    xom was implemented at version 1.3.9:
    • New standalone RPM package implementation, originally part of `jdom` source package
    • The Nodes and Elements classes are iterable so you can use the enhanced for loop syntax on instances of these classes.
    • The copy() method is now covariant.
    • Adds Automatic-Moduole-Name to jar
    • Remove direct dependency on xml-apis:xml-apis artifact since these classes are now available in the core runtime.
    • Eliminate usage of com.sun classes to make XOM compatible with JDK 16.
    • Replace remaining usages of StringBuffer with StringBuilder to slightly improve performance.


    Advisory IDSUSE-RU-2024:1876-1
    ReleasedFri May 31 06:47:32 2024
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1221361
    Description:

    This update for aaa_base fixes the following issues:

    • Fix the typo to set JAVA_BINDIR in the csh variant of the alljava profile script (bsc#1221361)