mbox series

[meta-security,0/8] Assorted updates 12/22

Message ID cover.1766420960.git.scott.murray@konsulko.com
Headers show
Series Assorted updates 12/22 | expand

Message

Scott Murray Dec. 22, 2025, 4:51 p.m. UTC
This patch series rolls up the contributed patches from the past few weeks,
a bump of suricata to 7.0.13 that I worked up, and after a bit of rework
to get it passing CI the contributed update of clamav to 1.4.3.  Note that
I had to disable building clamav on all 32-bit platforms due to what appears
to be an upstream limitation/bug.  If you need it on a 32-bit platform,
I'm open to carrying a patch, but a fix would ideally come via working with
upstream.

These changes are queued on the master-next branch if you would like to
check them out to test yourself.  I intend to merge these to master branch
at end of day tomorrow (Eastern Time, Dec. 23rd) unless there are objections.
I also plan to create the whinlatter branch at the same time to get that
going.  For scarthgap branch, I plan to look into backports of newer suricata
and clamav in the next week, but we'll have to see how that goes with older
Rust.

Scott


Changes:

Clayton Casciato (1):
  suricata: drop deprecated nss, nspr PACKAGECONFIGs

Hemant Jadhav (1):
  clamav: Add recipe for version 1.4.3

Scott Murray (2):
  suricata: update to 7.0.13
  scap-security-guide: update branch

Yi Zhao (3):
  libmhash: add UPSTREAM_CHECK_URI
  sssd: inherit github-releases class
  scap-security-guide: add UPSTREAM_CHECK_GITTAGREGEX

hongxu (1):
  openscap: switch to libpcre2

 .../recipes-security/sssd/sssd_2.10.2.bb      |    4 +-
 recipes-compliance/openscap/openscap_1.4.2.bb |    4 +-
 .../scap-security-guide_0.1.78.bb             |    3 +-
 .../packagegroup-core-security.bb             |    6 +-
 recipes-ids/suricata/suricata-crates.inc      | 1437 +++++++++--------
 ...{suricata_7.0.12.bb => suricata_7.0.13.bb} |    6 +-
 recipes-scanners/clamav/clamav-crates.inc     |  286 ++++
 recipes-scanners/clamav/clamav-git-crates.inc |    9 +
 recipes-scanners/clamav/clamav_0.104.4.bb     |  156 --
 recipes-scanners/clamav/clamav_1.4.3.bb       |  236 +++
 .../clamav/files/headers_fixup.patch          |   58 -
 .../clamav/files/oe_cmake_fixup.patch         |   39 -
 recipes-scanners/clamav/files/tmpfiles.clamav |    1 +
 .../clamav/files/volatiles.03_clamav          |    1 +
 recipes-security/libmhash/libmhash_0.9.9.9.bb |    2 +
 15 files changed, 1279 insertions(+), 969 deletions(-)
 rename recipes-ids/suricata/{suricata_7.0.12.bb => suricata_7.0.13.bb} (94%)
 create mode 100644 recipes-scanners/clamav/clamav-crates.inc
 create mode 100644 recipes-scanners/clamav/clamav-git-crates.inc
 delete mode 100644 recipes-scanners/clamav/clamav_0.104.4.bb
 create mode 100644 recipes-scanners/clamav/clamav_1.4.3.bb
 delete mode 100644 recipes-scanners/clamav/files/headers_fixup.patch
 delete mode 100644 recipes-scanners/clamav/files/oe_cmake_fixup.patch