aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* main/kamailio: add secinfoLeonardo Arena2018-03-231-1/+3
| | | | Fixes #8719
* main/rsync: security upgrade to 3.1.3 (CVE-2018-5764)Natanael Copa2018-03-205-144/+6
| | | | fixes #8677
* main/kamailio: lcr - fixed checking if there is more uris available for next_gwLeonardo Arena2018-03-202-1/+29
|
* main/kamailio: tmx - allocate space to store ending 0 for branch valueLeonardo Arena2018-03-202-1/+26
|
* main/curl: upgrade to 7.59.0prspkt2018-03-191-3/+7
| | | | fixes #8645
* main/xen: upgrade to 4.8.3Henrik Riomar2018-03-1940-4349/+4
| | | | | | | https://www.xenproject.org/downloads/xen-archives/xen-project-48-series/xen-483.html Also remove some patches that has been dropped from APKBUILD (earlier) but still included as files.
* main/samba: security upgrade to 4.6.14Jakub Jirutka2018-03-151-2/+5
|
* main/ruby-bundler: upgrade to 1.15.4Jakub Jirutka2018-03-141-2/+2
|
* main/py-django: security upgrade to 1.11.11Leonardo Arena2018-03-121-3/+7
| | | | | | CVE-2018-7536, CVE-2018-7537 Fixes #8638
* main/xen: security fixesLeonardo Arena2018-03-125-1/+396
| | | | | | CVE-2018-7540, CVE-2018-7541, CVE-2018-7542 Fixes #8615
* main/mosquitto: security upgrade to 1.4.15Daniel Sabogal2018-03-041-2/+6
|
* community/php7: upgrade to 7.1.15Valery Kartel2018-03-031-2/+2
|
* community/php5: upgrade to 5.6.34Valery Kartel2018-03-031-2/+2
|
* main/postgresql: upgrade to 9.6.8Jakub Jirutka2018-03-021-2/+4
|
* main/patch: security fix (CVE-2016-10713)Leonardo Arena2018-02-282-1/+18
| | | | Partially fixes #8564
* main/patch: security fix (CVE-2018-6951)Leonardo Arena2018-02-282-5/+40
| | | | | | | Partially fixes #8564 Patch for CVE-2018-6952 not yet available: https://savannah.gnu.org/bugs/index.php?53133
* main/squid: security upgrade to 3.5.27Leonardo Arena2018-02-282-20/+13
| | | | | | CVE-2018-1000024, CVE-2018-1000027 Fixes #8552
* main/libtasn1: security fix (CVE-2018-6003)Leonardo Arena2018-02-282-2/+70
| | | | Fixes #8528
* main/xen: security fixesLeonardo Arena2018-02-275-1/+306
| | | | | | | | | CVE-2017-17566, XSA-248 CVE-2017-17563, XSA-249 CVE-2017-17564, XSA-250 CVE-2017-17565, XSA-251 Fixes #8521
* main/libvorbis: security fixes (CVE-2017-14632, CVE-2017-14633)dai9ah2018-02-273-2/+31
| | | | Fixes #8516
* main/curl: re-enable ssh supportNatanael Copa2018-02-271-1/+2
| | | | | | This was unintentionally disabled with the 7.58 upgrade. fixes #8575
* main/nodejs: add secfix comment for CVE-2016-5129 and CVE-2016-5180Natanael Copa2018-02-231-1/+5
| | | | | | | | CVE-2016-5129 was fixed with: https://github.com/nodejs/node/commit/e71129ebbc115f86f518ff71f3b35b5d88923d81#diff-a416e90888b99aad5d014b86a1ad585d CVE-2016-5180 was fixed with: https://github.com/nodejs/node/commit/23a851dfe61ceb5859779df12c5dfb8da3a7a0c0#diff-e37d7b61b3e6004aa59373f7cb76e40b
* community/drupal7: security upgrade to 7.57Andy Postnikov2018-02-231-2/+2
| | | | https://www.drupal.org/SA-CORE-2018-001
* main/sqlite: security fix for CVE-2017-15286Natanael Copa2018-02-222-1/+22
| | | | fixes #8545
* main/python2: security upgrade to 2.7.14 (CVE-2017-1000158)Natanael Copa2018-02-221-9/+9
| | | | fixes #8541
* main/xen: XSA-254 XPTIHenrik Riomar2018-02-215-1/+1382
| | | | | | Add Xen page-table isolation (XPTI) for XEN 4.8.2 More info: http://xenbits.xen.org/xsa/xsa254/README.pti
* community/shotwell: rebuild against libraw 0.18Natanael Copa2018-02-201-1/+1
| | | | libraw was upgraded due to security fix
* main/libraw: security upgrade to 0.18.6 (CVE-2017-16910)Natanael Copa2018-02-203-184/+3
| | | | fixes #8340
* main/quagga: upgrade to 1.2.4Timo Teräs2018-02-201-2/+2
| | | | (cherry picked from commit cacf8c7b23a8bca8e1ae7bf9b8f4ee3c29fdd06d)
* main/libxcursor: security upgrade to 1.1.15 (CVE-2017-16612)Natanael Copa2018-02-201-5/+7
| | | | fixes #8228
* main/irssi: security upgrade to 1.0.6Leonardo Arena2018-02-191-2/+17
| | | | | | | CVE-2018-5205, CVE-2018-5206, CVE-2018-5207, CVE-2018-5208, CVE-2018-7050, CVE-2018-7051, CVE-2018-7052, CVE-2018-7053, CVE-2018-7054 Fixes #8502
* main/quagga: security upgrade to 1.2.3Timo Teräs2018-02-161-2/+2
| | | | (cherry picked from commit 0ebf73b2c2c90ac66f1619b6104435d7ea730a3a)
* main/postgresql: security upgrade to 9.6.7Jakub Jirutka2018-02-092-3/+21
| | | | | | | | | | | This upgrade contains one incompatible change in contrib/cube (packaged in -contrib subpackage). Explanation from https://www.postgresql.org/docs/10/static/release-9-6-7.html: > This is an incompatible change, but since the point of the operator > was to be used in KNN searches, it seems rather useless as-is. After > installing this update, any expression indexes or materialized views > using this operator will need to be reindexed/refreshed.
* community/php7: upgrade to 7.1.14Andy Postnikov2018-02-081-2/+2
|
* main/tiff: security fix CVE-2017-18013Leonardo Arena2018-02-082-2/+40
| | | | Fixes #8462
* main/bind: security upgrade to 9.11.2-P1 (CVE-2017-3145)Leonardo Arena2018-02-081-3/+5
| | | | Fixes #8418
* main/curl: security upgrade to 7.58.0Leonardo Arena2018-02-081-4/+5
| | | | | | CVE-2018-1000005, CVE-2018-1000007 Fixes #8440
* community/wireshark: security upgrade to 2.2.12Leonardo Arena2018-02-081-6/+7
| | | | CVE-2017-17997, CVE-2018-5334, CVE-2018-5335, CVE-2018-5336
* community/php7: security upgrade to 7.1.13Leonardo Arena2018-02-071-5/+7
| | | | CVE-2018-5711 CVE-2018-5712
* community/php5: security upgrade to 5.6.33Leonardo Arena2018-02-072-33/+5
| | | | CVE-2018-5711 CVE-2018-5712
* main/mkinitfs: skip apk hooksHenrik Riomar2018-01-312-3/+35
| | | | | | Skip pre/post apk hooks on diskless initramfs installation. (cherry picked from commit 8c9aa20b2f1445d63a2923145fffca1b40f1470a)
* main/py-django-sorl-thumbnail: upgrade to 12.4.1Kaarle Ritvanen2018-01-301-4/+2
|
* community/nextcloud: upgrade to 12.0.5Leonardo Arena2018-01-241-2/+2
|
* main/libxml2: security upgrade to 2.9.5 (CVE-2017-16931)Leonardo Arena2018-01-234-449/+6
| | | | Fixes #8397
* main/ncurses: security upgrade to 6.0-20171125 (CVE-2017-16879)Leonardo Arena2018-01-231-14/+15
| | | | Fixes #8393
* main/apk-tools: upgrade to 2.7.5Timo Teräs2018-01-091-2/+2
|
* community/postgresql-bdr-extension0.9: downgrade to 0.9.0 to maintain ↵Leonardo Arena2018-01-081-2/+2
| | | | compatibility with earlier Alpine versions
* main/asterisk: upgrade to 14.7.5Timo Teräs2018-01-083-329/+90
| | | | | | | | | | | fixes #8354 AST-2017-009 Buffer overflow in pjproject header parsing can cause crash AST-2017-010 Buffer overflow in CDR's set user AST-2017-011 Memory leak in pjsip session resource AST-2017-012 Remote Crash Vulnerability in RTCP Stack AST-2017-013 DOS Vulnerability in Asterisk chan_skinny AST-2017-014 Crash in PJSIP resource when missing a contact header
* main/awstats: security fix (CVE-2017-1000501)Leonardo Arena2018-01-053-6/+149
| | | | Fixes #8373
* main/wget: security upgrade to 1.19.2 (CVE-2017-13089, CVE-2017-13090)Leonardo Arena2018-01-052-33/+8
| | | | Fixes #8074