mbox series

kirkstone-next merge request: Feb 28th

Message ID a7d682bd-3f5d-4b16-af5e-b762bbf64420@gmail.com
State Accepted, archived
Headers show
Series kirkstone-next merge request: Feb 28th | expand

Pull-request

https://git.openembedded.org/meta-openembedded kirkstone-next

Message

akuster808 Feb. 28, 2024, 1:22 p.m. UTC
The following changes since commit 8609de00952d65bb813a48c535c937324efeb18a:

   Revert "libcroco: Add fix for CVE-2020-12825" (2024-02-07 18:41:41 -0500)

are available in the Git repository at:

   https://git.openembedded.org/meta-openembedded kirkstone-next

for you to fetch changes up to fda737ec0cc1d2a5217548a560074a8e4d5ec580:

   mbedtls: Upgrade 3.5.0 -> 3.5.2 (2024-02-28 08:18:18 -0500)

----------------------------------------------------------------
Fathi Boudra (1):
       python3-django: upgrade from 4.2.7 to 4.2.10

Meenali Gupta (1):
       graphviz: fix CVE-2023-46045

Soumya Sambu (2):
       mbedtls: upgrade 2.28.5 -> 2.28.7
       mbedtls: Upgrade 3.5.0 -> 3.5.2

Vijay Anusuri (1):
       squid: Backport fix for CVE-2023-49286 and CVE-2023-50269

Yogita Urade (1):
       mariadb: fix CVE-2023-22084

virendra thakur (1):
       nodejs: Set CVE_PRODUCT to "node.js"

  .../mbedtls/{mbedtls_2.28.5.bb => mbedtls_2.28.7.bb} |  6 +-
  .../mbedtls/{mbedtls_3.5.0.bb => mbedtls_3.5.2.bb} |  7 ++-
  .../recipes-daemons/squid/files/CVE-2023-49286.patch            | 87 
+++++++++++++++++++++++++++
  .../recipes-daemons/squid/files/CVE-2023-50269.patch            | 62 
++++++++++++++++++++
  meta-networking/recipes-daemons/squid/squid_4.15.bb             | 2 +
  meta-oe/recipes-dbs/mysql/mariadb.inc                           | 1 +
  meta-oe/recipes-dbs/mysql/mariadb/CVE-2023-22084.patch          | 91 
+++++++++++++++++++++++++++++
  meta-oe/recipes-devtools/nodejs/nodejs_16.20.2.bb               | 2 +
  .../recipes-graphics/graphviz/graphviz/CVE-2023-46045-1.patch   | 38 
++++++++++++
  .../recipes-graphics/graphviz/graphviz/CVE-2023-46045-2.patch   | 39 
+++++++++++++
  .../recipes-graphics/graphviz/graphviz/CVE-2023-46045-3.patch   | 31 
++++++++++
  meta-oe/recipes-graphics/graphviz/graphviz_2.50.0.bb            | 3 +
  .../{python3-django_4.2.7.bb => python3-django_4.2.10.bb} |  2 +-
  13 files changed, 364 insertions(+), 7 deletions(-)
  rename meta-networking/recipes-connectivity/mbedtls/{mbedtls_2.28.5.bb 
=> mbedtls_2.28.7.bb} (91%)
  rename meta-networking/recipes-connectivity/mbedtls/{mbedtls_3.5.0.bb 
=> mbedtls_3.5.2.bb} (93%)
  create mode 100644 
meta-networking/recipes-daemons/squid/files/CVE-2023-49286.patch
  create mode 100644 
meta-networking/recipes-daemons/squid/files/CVE-2023-50269.patch
  create mode 100644 meta-oe/recipes-dbs/mysql/mariadb/CVE-2023-22084.patch
  create mode 100644 
meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-1.patch
  create mode 100644 
meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-2.patch
  create mode 100644 
meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-3.patch
  rename meta-python/recipes-devtools/python/{python3-django_4.2.7.bb => 
python3-django_4.2.10.bb} (77%)

Comments

Khem Raj Feb. 28, 2024, 4:24 p.m. UTC | #1
merged into kirkstone, thanks Armin

On Wed, Feb 28, 2024 at 5:22 AM akuster808 <akuster808@gmail.com> wrote:
>
> The following changes since commit 8609de00952d65bb813a48c535c937324efeb18a:
>
>    Revert "libcroco: Add fix for CVE-2020-12825" (2024-02-07 18:41:41 -0500)
>
> are available in the Git repository at:
>
>    https://git.openembedded.org/meta-openembedded kirkstone-next
>
> for you to fetch changes up to fda737ec0cc1d2a5217548a560074a8e4d5ec580:
>
>    mbedtls: Upgrade 3.5.0 -> 3.5.2 (2024-02-28 08:18:18 -0500)
>
> ----------------------------------------------------------------
> Fathi Boudra (1):
>        python3-django: upgrade from 4.2.7 to 4.2.10
>
> Meenali Gupta (1):
>        graphviz: fix CVE-2023-46045
>
> Soumya Sambu (2):
>        mbedtls: upgrade 2.28.5 -> 2.28.7
>        mbedtls: Upgrade 3.5.0 -> 3.5.2
>
> Vijay Anusuri (1):
>        squid: Backport fix for CVE-2023-49286 and CVE-2023-50269
>
> Yogita Urade (1):
>        mariadb: fix CVE-2023-22084
>
> virendra thakur (1):
>        nodejs: Set CVE_PRODUCT to "node.js"
>
>   .../mbedtls/{mbedtls_2.28.5.bb => mbedtls_2.28.7.bb} |  6 +-
>   .../mbedtls/{mbedtls_3.5.0.bb => mbedtls_3.5.2.bb} |  7 ++-
>   .../recipes-daemons/squid/files/CVE-2023-49286.patch            | 87
> +++++++++++++++++++++++++++
>   .../recipes-daemons/squid/files/CVE-2023-50269.patch            | 62
> ++++++++++++++++++++
>   meta-networking/recipes-daemons/squid/squid_4.15.bb             | 2 +
>   meta-oe/recipes-dbs/mysql/mariadb.inc                           | 1 +
>   meta-oe/recipes-dbs/mysql/mariadb/CVE-2023-22084.patch          | 91
> +++++++++++++++++++++++++++++
>   meta-oe/recipes-devtools/nodejs/nodejs_16.20.2.bb               | 2 +
>   .../recipes-graphics/graphviz/graphviz/CVE-2023-46045-1.patch   | 38
> ++++++++++++
>   .../recipes-graphics/graphviz/graphviz/CVE-2023-46045-2.patch   | 39
> +++++++++++++
>   .../recipes-graphics/graphviz/graphviz/CVE-2023-46045-3.patch   | 31
> ++++++++++
>   meta-oe/recipes-graphics/graphviz/graphviz_2.50.0.bb            | 3 +
>   .../{python3-django_4.2.7.bb => python3-django_4.2.10.bb} |  2 +-
>   13 files changed, 364 insertions(+), 7 deletions(-)
>   rename meta-networking/recipes-connectivity/mbedtls/{mbedtls_2.28.5.bb
> => mbedtls_2.28.7.bb} (91%)
>   rename meta-networking/recipes-connectivity/mbedtls/{mbedtls_3.5.0.bb
> => mbedtls_3.5.2.bb} (93%)
>   create mode 100644
> meta-networking/recipes-daemons/squid/files/CVE-2023-49286.patch
>   create mode 100644
> meta-networking/recipes-daemons/squid/files/CVE-2023-50269.patch
>   create mode 100644 meta-oe/recipes-dbs/mysql/mariadb/CVE-2023-22084.patch
>   create mode 100644
> meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-1.patch
>   create mode 100644
> meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-2.patch
>   create mode 100644
> meta-oe/recipes-graphics/graphviz/graphviz/CVE-2023-46045-3.patch
>   rename meta-python/recipes-devtools/python/{python3-django_4.2.7.bb =>
> python3-django_4.2.10.bb} (77%)
>