Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Weekly portage-stable package updates 2024-07-01 #2070

Merged
merged 317 commits into from
Jul 16, 2024

Conversation

github-actions[bot]
Copy link

@github-actions github-actions bot commented Jul 1, 2024

CI (with SDK) 🟢: http://jenkins.infra.kinvolk.io:8080/job/container/job/sdk/1556/cldsv/

Closes flatcar/Flatcar#1383
Closes flatcar/Flatcar#1446
Closes flatcar/Flatcar#1447
Closes flatcar/Flatcar#1452
Closes flatcar/Flatcar#1454
Closes flatcar/Flatcar#1456
Closes flatcar/Flatcar#1457


--

  • changelog
  • image diff

Flatcar Buildbot added 12 commits July 16, 2024 09:37
It's from Gentoo commit 680eae567c767a6924f93029e556384443581004.
It's from Gentoo commit 2633a561c341f8ee2e74e9653df2a605c3141956.
It's from Gentoo commit 962eb609a997b28764d0639a2e16de2ab2c273ec.
It's from Gentoo commit fd6381b61a9d790cc4d2ca5742806f0417ce698b.
It's from Gentoo commit 0aed818694558f1641f289cba6247e995747afe4.
It's from Gentoo commit bfdbc4f3fb370910abb62328147c8ad855afb623.
It's from Gentoo commit 34b6854ce5a33aa288aedf825a5d258a45a4294b.
It's from Gentoo commit 7fcaf377ac8f4add0ae23adffbb33bd067af9509.
It's from Gentoo commit 09bf61ced9f91e8460b2227f15b2256618ffaf29.
It's from Gentoo commit 7607deb671dad94c3f7a8af3bb47fcea43eefa22.
It's from Gentoo commit 885e8b3941b4617906768a9358979fd5e4da01a7.
It's from Gentoo commit 3d9fa0c0a95893194c74be8f7b39534545669488.
@tormath1 tormath1 force-pushed the buildbot/weekly-portage-stable-package-updates-2024-07-01 branch from 0deda3e to b21b4f4 Compare July 16, 2024 07:38
@tormath1 tormath1 marked this pull request as ready for review July 16, 2024 07:46
@tormath1 tormath1 requested a review from a team July 16, 2024 07:47
Copy link
Member

@dongsupark dongsupark left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.

A minor issue below:

- libcap-ng ([0.8.5](https://github.com/stevegrubb/libcap-ng/releases/tag/v0.8.5))
- libdnet ([1.18.0](https://github.com/ofalk/libdnet/releases/tag/libdnet-1.18.0))
- libgpg-error ([1.49](https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgpg-error.git;a=blob;f=NEWS;h=8ac4bf36113fe9254a361e2bc8d0ed52383839ce;hb=faed9c271ad22bbd2ed265d8e11badb53b7a2f32))
- libnl (3.9.0)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A missing link.

- libnl ([3.9.0](http://lists.infradead.org/pipermail/libnl/2023-December/002436.html))

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch. I seen it in the image changes but I thought the link was just not existing as it happens a few times.

krnowak and others added 6 commits July 16, 2024 12:38
this is required to apply split-usr patch

Signed-off-by: Mathieu Tortuyaux <[email protected]>
this revert: gentoo/gentoo@eb13455

Signed-off-by: Mathieu Tortuyaux <[email protected]>
This is required to build our current set of policies

Commit-Ref: gentoo/gentoo@49d3de6

Signed-off-by: Mathieu Tortuyaux <[email protected]>
@tormath1 tormath1 force-pushed the buildbot/weekly-portage-stable-package-updates-2024-07-01 branch from b21b4f4 to 7a5633c Compare July 16, 2024 10:38
@tormath1 tormath1 merged commit 22a0007 into main Jul 16, 2024
1 check failed
@tormath1 tormath1 deleted the buildbot/weekly-portage-stable-package-updates-2024-07-01 branch July 16, 2024 10:38
- glib ([CVE-2024-34397](https://nvd.nist.gov/vuln/detail/CVE-2024-34397))
- libxml2 ([CVE-2024-34459](https://nvd.nist.gov/vuln/detail/CVE-2024-34459))
- git ([CVE-2024-32002](https://nvd.nist.gov/vuln/detail/CVE-2024-32002), [CVE-2024-32004](https://nvd.nist.gov/vuln/detail/CVE-2024-32004), [CVE-2024-32020](https://nvd.nist.gov/vuln/detail/CVE-2024-32020), [CVE-2024-32021](https://nvd.nist.gov/vuln/detail/CVE-2024-32021), [CVE-2024-32465](https://nvd.nist.gov/vuln/detail/CVE-2024-32465))
- intel-microcode ([CVE-2023-45733](https://nvd.nist.gov/vuln/detail/CVE-2023-45733), [CVE-2023-45745](https://nvd.nist.gov/vuln/detail/CVE-2023-45745), [CVE-2023-46103](https://nvd.nist.gov/vuln/detail/CVE-2023-46103), [CVE-2023-47855](https://nvd.nist.gov/vuln/detail/CVE-2023-47855))
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A missing CVE, manually added to release notes draft:

- wget ([CVE-2024-38428](https://nvd.nist.gov/vuln/detail/CVE-2024-38428))

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
3 participants