Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/postgresql: security upgrade to 10.9 | Milan P. Stanić | 2019-07-04 | 1 | -2/+4 | |
| | | | | | | CVE-2019-10164 other upstream bugfixes fixes #10641 | |||||
* | main/patchwork: security fix (CVE-2019-13122) | Francesco Colista | 2019-07-04 | 2 | -3/+27 | |
| | ||||||
* | main/libvirt: security upgrade to 5.5.0 | Francesco Colista | 2019-07-03 | 3 | -13/+36 | |
| | | | | | | (CVE-2019-10161, CVE-2019-10166, CVE-2019-10167, CVE-2019-10168) Fixes #10620 | |||||
* | main/expat: security upgrade to 2.2.7 (CVE-2018-20843) | Natanael Copa | 2019-06-30 | 1 | -3/+5 | |
| | | | | fixes #10633 | |||||
* | main/py-django: security upgrade to 1.11.21 (CVE-2019-12308) | Natanael Copa | 2019-06-25 | 1 | -2/+4 | |
| | | | | fixes #10561 | |||||
* | community/pdns: security upgrade to 4.0.8 | J0WI | 2019-06-25 | 1 | -2/+5 | |
| | | | | | CVE-2019-10162 CVE-2019-10163 | |||||
* | main/bind: upgrade to 9.11.8 (CVE-2019-6471) | Kevin Daudt | 2019-06-23 | 2 | -137/+5 | |
| | | | | | Replace-atomic-operations.patch was an upstream patch that is now included in the release. | |||||
* | main/vim: backport fix for CVE-2019-12735 | Natanael Copa | 2019-06-22 | 2 | -2/+66 | |
| | | | | fixes #10562 | |||||
* | testing/wireguard-vanilla: rebuild against kernel 4.9.182-r0 | Natanael Copa | 2019-06-18 | 1 | -2/+2 | |
| | ||||||
* | main/zfs-vanilla: rebuild against kernel 4.9.182-r0 | Natanael Copa | 2019-06-18 | 1 | -1/+1 | |
| | ||||||
* | main/spl-vanilla: rebuild against kernel 4.9.182-r0 | Natanael Copa | 2019-06-18 | 1 | -1/+1 | |
| | ||||||
* | main/linux-vanilla: upgrade to 4.9.182 | Natanael Copa | 2019-06-18 | 7 | -22/+24 | |
| | ||||||
* | main/dbus: upgrade to 1.10.28 (CVE-2019-12749) | Natanael Copa | 2019-06-17 | 1 | -2/+6 | |
| | | | | fixes #10571 | |||||
* | main/glib: security fix for CVE-2019-12450 | Natanael Copa | 2019-06-17 | 2 | -2/+61 | |
| | | | | fixes #10578 | |||||
* | main/mariadb: security upgrade to 10.1.40 | J0WI | 2019-06-12 | 1 | -4/+7 | |
| | ||||||
* | community/php7: security upgrade to 7.1.30 | Andy Postnikov | 2019-06-12 | 1 | -4/+31 | |
| | ||||||
* | main/vim: security fix for CVE-2019-12735 | Kevin Daudt | 2019-06-05 | 2 | -2/+64 | |
| | | | | | | | Arbitrary code execution has been found in vim modelines. Upstream patch has been applied: https://github.com/vim/vim/commit/53575521406739cf20bbe4e384d88e7dca11f040.patch | |||||
* | main/monit: upgrade to 5.25.2, security fixes | Leonardo Arena | 2019-06-05 | 3 | -3/+90 | |
| | | | | | | CVE-2019-11454, CVE-2019-11455 Fixes #10494 | |||||
* | main/perl-email-address: security upgrade to 1.912 (CVE-2018-12558) | Leonardo Arena | 2019-06-05 | 1 | -5/+6 | |
| | | | | Fixes #10435 | |||||
* | main/hostapd: security fix (CVE-2019-9496) | Leonardo Arena | 2019-06-05 | 2 | -1/+62 | |
| | | | | Fixes #10335 | |||||
* | main/hostapd: security fix (CVE-2019-11555) | Leonardo Arena | 2019-06-05 | 3 | -2/+97 | |
| | | | | Fixes #10412 | |||||
* | main/wpa_supplicant: security fix (CVE-2019-11555) | Leonardo Arena | 2019-06-05 | 3 | -1/+97 | |
| | | | | Fixes #10417 | |||||
* | main/heimdal: security fix (CVE-2018-16860) | Leonardo Arena | 2019-06-04 | 2 | -3/+154 | |
| | | | | | | Fixes #10514 Clarify license | |||||
* | main/py-cryptography: upgrade to 2.1.4 | Leonardo Arena | 2019-06-03 | 1 | -3/+3 | |
| | | | | Required by certbot-0.19 | |||||
* | main/ca-certificates: upgrade to 20190108 | Natanael Copa | 2019-05-27 | 2 | -34/+3 | |
| | | | | fixes #9935 | |||||
* | main/ca-certificates: upgrade to 20180924 | Natanael Copa | 2019-05-27 | 2 | -3/+34 | |
| | ||||||
* | main/xen: XSA-297 | Henrik Riomar | 2019-05-17 | 9 | -1/+1216 | |
| | | | | | | | | | CVE-2018-12126 CVE-2018-12127 CVE-2018-12130 CVE-2019-11091 Signed-off-by: Leonardo Arena <rnalrd@alpinelinux.org> | |||||
* | main/postgresql: security upgrade to 10.8 | Jakub Jirutka | 2019-05-12 | 1 | -2/+5 | |
| | ||||||
* | main/ruby: upgrade to 2.4.6 | Natanael Copa | 2019-05-06 | 1 | -2/+9 | |
| | | | | | | | | | | | - CVE-2019-8320 - CVE-2019-8321 - CVE-2019-8322 - CVE-2019-8323 - CVE-2019-8324 - CVE-2019-8325 fixes #10289 | |||||
* | main/lua5.3: fix linenoise patch | Natanael Copa | 2019-05-06 | 2 | -9/+9 | |
| | | | | | | fixes #9644 (cherry picked from commit cde8024d0da937f5f7b0b9b329c1f27c14b00308) | |||||
* | main/lua5.3: upgrade to 5.3.5 and sec fix CVE-2019-6706 | Natanael Copa | 2019-05-06 | 2 | -12/+34 | |
| | | | | fixes #10255 | |||||
* | main/libpng: upgrade to 1.6.37 | Leo | 2019-05-06 | 1 | -10/+14 | |
| | | | | | | | | | | - Add secfixes CVE-2019-7317 CVE-2018-14048 CVE-2018-14550 - Remove pkg-config detected depends_dev fixes #10364 | |||||
* | community/openjdk8: security upgrade to 8.212.04 | J0WI | 2019-05-04 | 1 | -12/+16 | |
| | ||||||
* | main/bind: make sure all patches are applied | Natanael Copa | 2019-05-03 | 3 | -36/+34 | |
| | | | | This fixes builds on non-x86 | |||||
* | main/bind: security upgrade to 9.11.6_p1 (CVE-2018-5743,CVE-2019-6467) | Natanael Copa | 2019-05-03 | 2 | -6/+174 | |
| | | | | | | | | | | | | | | | | | This release introduced 3 new tools with python dependency (dnssec-checkdns, dnssec-coverage and dnssec-keymgr). Move those tools to a subpackage, bind-dnssec-tools, to avoid unexpectedly pull in python as dependency for stable upgraders. There are other tools in bind-tools that belongs to bind-dnssec-tools, but we dont move those in a stable branch to avoid breaking things for current users. Include patch to fix build on non-x86: https://gitlab.isc.org/isc-projects/bind9/commit/d72f436b7d7c697b262968c48c2d7643069ab17f https://lists.isc.org/pipermail/bind-users/2019-April/101673.html fixes #10370 | |||||
* | main/py3-ply: new aport | tcely | 2019-05-02 | 1 | -0/+39 | |
| | | | | | | | https://www.dabeaz.com/ply/ Python Lex & Yacc needed by bind | |||||
* | main/tzdata: upgrade to 2019a | J0WI | 2019-04-30 | 1 | -4/+4 | |
| | | | | ref #10202 | |||||
* | main/tzdata: upgrade to 2018i | Andy Postnikov | 2019-04-30 | 1 | -5/+5 | |
| | ||||||
* | main/tzdata: upgrade tzcode to 2018g | Sören Tempel | 2019-04-30 | 1 | -3/+3 | |
| | ||||||
* | main/tzdata: upgrade to 2018g | Pedro Filipe | 2019-04-30 | 1 | -8/+9 | |
| | ||||||
* | main/tzdata: upgrade to 2018f | Natanael Copa | 2019-04-30 | 1 | -3/+3 | |
| | ||||||
* | main/tzdata: add patch to fix implicit declaration compiler warnings | Sören Tempel | 2019-04-30 | 3 | -8/+39 | |
| | | | | | Not strictly needed but since this is code written by us, fixing it seems to be a good idea. | |||||
* | main/tzdata: upgrade to 2018d | Sören Tempel | 2019-04-30 | 1 | -4/+4 | |
| | ||||||
* | main/freeradius: security fixes (CVE-2019-11234, CVE-2019-11235) | Leonardo Arena | 2019-04-25 | 2 | -4/+100 | |
| | | | | Fixes #10327 | |||||
* | main/python3: security upgrade to 3.6.8 | Natanael Copa | 2019-04-22 | 3 | -16/+160 | |
| | | | | | | | | - CVE-2018-14647 - CVE-2018-20406 - CVE-2019-9636 fixes #10299 | |||||
* | community/openjdk8: add missing nss dependency | Dane Hammer | 2019-04-22 | 1 | -2/+2 | |
| | | | | | | Patches a0a5ffcea690a74b6f8c240d811be43542af60a6 to 3.7 See #10126 | |||||
* | main/clamav: security upgrade to 0.100.3 | Leonardo Arena | 2019-04-17 | 1 | -2/+6 | |
| | | | | | | CVE-2019-1787, CVE-2019-1788, CVE-2019-1789 Fixes #10265 | |||||
* | main/samba: security fix (CVE-2019-3880) | Stefan Reiff | 2019-04-17 | 2 | -1/+156 | |
| | | | | | | Fixes #10249 Signed-off-by: Leonardo Arena <rnalrd@alpinelinux.org> | |||||
* | main/libxslt: security fix for CVE-2019-11068 | Natanael Copa | 2019-04-17 | 2 | -4/+129 | |
| | | | | fixes #10280 | |||||
* | main/bind: security upgrade to 9.11.5_p4 | tcely | 2019-04-12 | 1 | -3/+8 | |
| | | | | | | | | | | | | | | | | | | https://ftp.isc.org/isc/bind9/9.11.5-P4/RELEASE-NOTES-bind-9.11.5-P4.html - CVE-2019-6465 - CVE-2018-5745 - CVE-2018-5744 - CVE-2018-5740 - CVE-2018-5738 Fixes #10168 With the release of BIND 9.11.0, ISC changed to the open source license for BIND from the ISC license to the Mozilla Public License (MPL 2.0). BIND 9.11 (Extended Support Version) will be supported until at least December, 2021. |