Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/kamailio: add secinfo | Leonardo Arena | 2018-03-23 | 1 | -1/+3 | |
| | | | | Fixes #8719 | |||||
* | main/rsync: security upgrade to 3.1.3 (CVE-2018-5764) | Natanael Copa | 2018-03-20 | 5 | -144/+6 | |
| | | | | fixes #8677 | |||||
* | main/kamailio: lcr - fixed checking if there is more uris available for next_gw | Leonardo Arena | 2018-03-20 | 2 | -1/+29 | |
| | ||||||
* | main/kamailio: tmx - allocate space to store ending 0 for branch value | Leonardo Arena | 2018-03-20 | 2 | -1/+26 | |
| | ||||||
* | main/curl: upgrade to 7.59.0 | prspkt | 2018-03-19 | 1 | -3/+7 | |
| | | | | fixes #8645 | |||||
* | main/xen: upgrade to 4.8.3 | Henrik Riomar | 2018-03-19 | 40 | -4349/+4 | |
| | | | | | | | https://www.xenproject.org/downloads/xen-archives/xen-project-48-series/xen-483.html Also remove some patches that has been dropped from APKBUILD (earlier) but still included as files. | |||||
* | main/samba: security upgrade to 4.6.14 | Jakub Jirutka | 2018-03-15 | 1 | -2/+5 | |
| | ||||||
* | main/ruby-bundler: upgrade to 1.15.4 | Jakub Jirutka | 2018-03-14 | 1 | -2/+2 | |
| | ||||||
* | main/py-django: security upgrade to 1.11.11 | Leonardo Arena | 2018-03-12 | 1 | -3/+7 | |
| | | | | | | CVE-2018-7536, CVE-2018-7537 Fixes #8638 | |||||
* | main/xen: security fixes | Leonardo Arena | 2018-03-12 | 5 | -1/+396 | |
| | | | | | | CVE-2018-7540, CVE-2018-7541, CVE-2018-7542 Fixes #8615 | |||||
* | main/mosquitto: security upgrade to 1.4.15 | Daniel Sabogal | 2018-03-04 | 1 | -2/+6 | |
| | ||||||
* | community/php7: upgrade to 7.1.15 | Valery Kartel | 2018-03-03 | 1 | -2/+2 | |
| | ||||||
* | community/php5: upgrade to 5.6.34 | Valery Kartel | 2018-03-03 | 1 | -2/+2 | |
| | ||||||
* | main/postgresql: upgrade to 9.6.8 | Jakub Jirutka | 2018-03-02 | 1 | -2/+4 | |
| | ||||||
* | main/patch: security fix (CVE-2016-10713) | Leonardo Arena | 2018-02-28 | 2 | -1/+18 | |
| | | | | Partially fixes #8564 | |||||
* | main/patch: security fix (CVE-2018-6951) | Leonardo Arena | 2018-02-28 | 2 | -5/+40 | |
| | | | | | | | Partially fixes #8564 Patch for CVE-2018-6952 not yet available: https://savannah.gnu.org/bugs/index.php?53133 | |||||
* | main/squid: security upgrade to 3.5.27 | Leonardo Arena | 2018-02-28 | 2 | -20/+13 | |
| | | | | | | CVE-2018-1000024, CVE-2018-1000027 Fixes #8552 | |||||
* | main/libtasn1: security fix (CVE-2018-6003) | Leonardo Arena | 2018-02-28 | 2 | -2/+70 | |
| | | | | Fixes #8528 | |||||
* | main/xen: security fixes | Leonardo Arena | 2018-02-27 | 5 | -1/+306 | |
| | | | | | | | | | CVE-2017-17566, XSA-248 CVE-2017-17563, XSA-249 CVE-2017-17564, XSA-250 CVE-2017-17565, XSA-251 Fixes #8521 | |||||
* | main/libvorbis: security fixes (CVE-2017-14632, CVE-2017-14633) | dai9ah | 2018-02-27 | 3 | -2/+31 | |
| | | | | Fixes #8516 | |||||
* | main/curl: re-enable ssh support | Natanael Copa | 2018-02-27 | 1 | -1/+2 | |
| | | | | | | This was unintentionally disabled with the 7.58 upgrade. fixes #8575 | |||||
* | main/nodejs: add secfix comment for CVE-2016-5129 and CVE-2016-5180 | Natanael Copa | 2018-02-23 | 1 | -1/+5 | |
| | | | | | | | | CVE-2016-5129 was fixed with: https://github.com/nodejs/node/commit/e71129ebbc115f86f518ff71f3b35b5d88923d81#diff-a416e90888b99aad5d014b86a1ad585d CVE-2016-5180 was fixed with: https://github.com/nodejs/node/commit/23a851dfe61ceb5859779df12c5dfb8da3a7a0c0#diff-e37d7b61b3e6004aa59373f7cb76e40b | |||||
* | community/drupal7: security upgrade to 7.57 | Andy Postnikov | 2018-02-23 | 1 | -2/+2 | |
| | | | | https://www.drupal.org/SA-CORE-2018-001 | |||||
* | main/sqlite: security fix for CVE-2017-15286 | Natanael Copa | 2018-02-22 | 2 | -1/+22 | |
| | | | | fixes #8545 | |||||
* | main/python2: security upgrade to 2.7.14 (CVE-2017-1000158) | Natanael Copa | 2018-02-22 | 1 | -9/+9 | |
| | | | | fixes #8541 | |||||
* | main/xen: XSA-254 XPTI | Henrik Riomar | 2018-02-21 | 5 | -1/+1382 | |
| | | | | | | Add Xen page-table isolation (XPTI) for XEN 4.8.2 More info: http://xenbits.xen.org/xsa/xsa254/README.pti | |||||
* | community/shotwell: rebuild against libraw 0.18 | Natanael Copa | 2018-02-20 | 1 | -1/+1 | |
| | | | | libraw was upgraded due to security fix | |||||
* | main/libraw: security upgrade to 0.18.6 (CVE-2017-16910) | Natanael Copa | 2018-02-20 | 3 | -184/+3 | |
| | | | | fixes #8340 | |||||
* | main/quagga: upgrade to 1.2.4 | Timo Teräs | 2018-02-20 | 1 | -2/+2 | |
| | | | | (cherry picked from commit cacf8c7b23a8bca8e1ae7bf9b8f4ee3c29fdd06d) | |||||
* | main/libxcursor: security upgrade to 1.1.15 (CVE-2017-16612) | Natanael Copa | 2018-02-20 | 1 | -5/+7 | |
| | | | | fixes #8228 | |||||
* | main/irssi: security upgrade to 1.0.6 | Leonardo Arena | 2018-02-19 | 1 | -2/+17 | |
| | | | | | | | CVE-2018-5205, CVE-2018-5206, CVE-2018-5207, CVE-2018-5208, CVE-2018-7050, CVE-2018-7051, CVE-2018-7052, CVE-2018-7053, CVE-2018-7054 Fixes #8502 | |||||
* | main/quagga: security upgrade to 1.2.3 | Timo Teräs | 2018-02-16 | 1 | -2/+2 | |
| | | | | (cherry picked from commit 0ebf73b2c2c90ac66f1619b6104435d7ea730a3a) | |||||
* | main/postgresql: security upgrade to 9.6.7 | Jakub Jirutka | 2018-02-09 | 2 | -3/+21 | |
| | | | | | | | | | | | This upgrade contains one incompatible change in contrib/cube (packaged in -contrib subpackage). Explanation from https://www.postgresql.org/docs/10/static/release-9-6-7.html: > This is an incompatible change, but since the point of the operator > was to be used in KNN searches, it seems rather useless as-is. After > installing this update, any expression indexes or materialized views > using this operator will need to be reindexed/refreshed. | |||||
* | community/php7: upgrade to 7.1.14 | Andy Postnikov | 2018-02-08 | 1 | -2/+2 | |
| | ||||||
* | main/tiff: security fix CVE-2017-18013 | Leonardo Arena | 2018-02-08 | 2 | -2/+40 | |
| | | | | Fixes #8462 | |||||
* | main/bind: security upgrade to 9.11.2-P1 (CVE-2017-3145) | Leonardo Arena | 2018-02-08 | 1 | -3/+5 | |
| | | | | Fixes #8418 | |||||
* | main/curl: security upgrade to 7.58.0 | Leonardo Arena | 2018-02-08 | 1 | -4/+5 | |
| | | | | | | CVE-2018-1000005, CVE-2018-1000007 Fixes #8440 | |||||
* | community/wireshark: security upgrade to 2.2.12 | Leonardo Arena | 2018-02-08 | 1 | -6/+7 | |
| | | | | CVE-2017-17997, CVE-2018-5334, CVE-2018-5335, CVE-2018-5336 | |||||
* | community/php7: security upgrade to 7.1.13 | Leonardo Arena | 2018-02-07 | 1 | -5/+7 | |
| | | | | CVE-2018-5711 CVE-2018-5712 | |||||
* | community/php5: security upgrade to 5.6.33 | Leonardo Arena | 2018-02-07 | 2 | -33/+5 | |
| | | | | CVE-2018-5711 CVE-2018-5712 | |||||
* | main/mkinitfs: skip apk hooks | Henrik Riomar | 2018-01-31 | 2 | -3/+35 | |
| | | | | | | Skip pre/post apk hooks on diskless initramfs installation. (cherry picked from commit 8c9aa20b2f1445d63a2923145fffca1b40f1470a) | |||||
* | main/py-django-sorl-thumbnail: upgrade to 12.4.1 | Kaarle Ritvanen | 2018-01-30 | 1 | -4/+2 | |
| | ||||||
* | community/nextcloud: upgrade to 12.0.5 | Leonardo Arena | 2018-01-24 | 1 | -2/+2 | |
| | ||||||
* | main/libxml2: security upgrade to 2.9.5 (CVE-2017-16931) | Leonardo Arena | 2018-01-23 | 4 | -449/+6 | |
| | | | | Fixes #8397 | |||||
* | main/ncurses: security upgrade to 6.0-20171125 (CVE-2017-16879) | Leonardo Arena | 2018-01-23 | 1 | -14/+15 | |
| | | | | Fixes #8393 | |||||
* | main/apk-tools: upgrade to 2.7.5 | Timo Teräs | 2018-01-09 | 1 | -2/+2 | |
| | ||||||
* | community/postgresql-bdr-extension0.9: downgrade to 0.9.0 to maintain ↵ | Leonardo Arena | 2018-01-08 | 1 | -2/+2 | |
| | | | | compatibility with earlier Alpine versions | |||||
* | main/asterisk: upgrade to 14.7.5 | Timo Teräs | 2018-01-08 | 3 | -329/+90 | |
| | | | | | | | | | | | fixes #8354 AST-2017-009 Buffer overflow in pjproject header parsing can cause crash AST-2017-010 Buffer overflow in CDR's set user AST-2017-011 Memory leak in pjsip session resource AST-2017-012 Remote Crash Vulnerability in RTCP Stack AST-2017-013 DOS Vulnerability in Asterisk chan_skinny AST-2017-014 Crash in PJSIP resource when missing a contact header | |||||
* | main/awstats: security fix (CVE-2017-1000501) | Leonardo Arena | 2018-01-05 | 3 | -6/+149 | |
| | | | | Fixes #8373 | |||||
* | main/wget: security upgrade to 1.19.2 (CVE-2017-13089, CVE-2017-13090) | Leonardo Arena | 2018-01-05 | 2 | -33/+8 | |
| | | | | Fixes #8074 |