aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* community/openjdk7: upgrade to 7.151.2.6.11Natanael Copa2018-06-151-11/+11
|
* community/openjdk7: bump pkgrel due to krb5 upgradeFrancesco Colista2018-06-151-1/+1
|
* community/openjdk8: upgrade to 3.8.0 (java 8u171b11)J0WI2018-06-132-19/+19
|
* community/openjdk8: upgrade to 3.7.0 (java 8u161b12)Timo Teräs2018-06-133-30/+17
| | | | | fixes #3678 ref https://github.com/alpinelinux/aports/pull/3678
* community/openjdk8: upgrade to icedtea 3.6.0, modernizeTimo Teräs2018-06-131-28/+27
| | | | | | | | | | | | | | | | | | | | | | | | | | | | S8165543: Better window framing S8169026, CVE-2017-10274: Handle smartcard clean up better S8169966: Larger AWT menus S8170218: Improved Font Metrics S8171252: Improve exception checking S8171261: Stability fixes for lcms S8174109, CVE-2017-10281: Better queuing priorities S8174966, CVE-2017-10285: Unreferenced references S8175940: More certificate subject checking S8176751, CVE-2017-10295: Better URL connections S8178794, CVE-2017-10388: Correct Kerberos ticket grants S8180024: Improve construction of objects during deserialization S8180711, CVE-2017-10346: Better invokespecial checks S8181100, CVE-2017-10350: Better Base Exceptions S8181323, CVE-2017-10347: Better timezone processing S8181327, CVE-2017-10349: Better X processing S8181370, CVE-2017-10345: Better keystore handling S8181432, CVE-2017-10348: Better processing of unresolved permissions S8181597, CVE-2017-10357: Process Proxy presentation S8181612, CVE-2017-10355: More stable connection processing S8181692, CVE-2017-10356: Update storage implementations S8183028, CVE-2016-10165: Improve CMS header processing S8184682, CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2016-9843: Upgrade compression library ref #8018, #8111
* community/openjdk8: bump icedtea to 3.5.1 and java to 8.144.01Daniel Isaksen2018-06-131-12/+12
|
* community/openjdk8: bump pkgrel due to krb5 upgradeFrancesco Colista2018-06-131-1/+1
|
* community/openjdk8: fix build on armhfNatanael Copa2018-06-131-1/+1
|
* community/openjdk8: upgrade to icedtea 3.5.0 / java 8 u141 b15Timo Teräs2018-06-133-130/+104
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | fixes #7579 S8163958, CVE-2017-10102: Improved garbage collection S8167228: Update to libpng 1.6.28 S8169209, CVE-2017-10053: Improved image post-processing steps S8169392, CVE-2017-10067: Additional jar validation steps S8170966, CVE-2017-10081: Right parenthesis issue S8171539, CVE-2017-10078: Better script accessibility for JavaScript S8172204, CVE-2017-10087: Better Thread Pool execution S8172461, CVE-2017-10089: Service Registration Lifecycle S8172465, CVE-2017-10090: Better handling of channel groups S8172469, CVE-2017-10096: Transform Transformer Exceptions S8173286, CVE-2017-10101: Better reading of text catalogs S8173697, CVE-2017-10107: Less Active Activations S8173770, CVE-2017-10074: Image conversion improvements S8174098, CVE-2017-10110: Better image fetching S8174105, CVE-2017-10108: Better naming attribution S8174113, CVE-2017-10109: Better sourcing of code S8174770: Check registry registration location S8174873: Improved certificate procesing S8175106, CVE-2017-10115: Higher quality DSA operations S8175110, CVE-2017-10118: Higher quality ECDSA operations S8176055: JMX diagnostic improvements S8176067, CVE-2017-10116: Proper directory lookup processing S8176760, CVE-2017-10135: Better handling of PKCS8 material S8178135, CVE-2017-10176: Additional elliptic curve support S8179101, CVE-2017-10193: Improve algorithm constraints implementation S8179998, CVE-2017-10198: Clear certificate chain connections S8181420, CVE-2017-10074: PPC: Image conversion improvements S8183551, CVE-2017-10074, PR3423: AArch64: Image conversion improvements S8184185, CVE-2017-10111: Rearrange MethodHandle arrangements
* main/gnupg: security fix (CVE-2018-12020)Leonardo Arena2018-06-132-3/+53
| | | | Fixes #8995
* main/freetype: security fix (CVE-2018-6942)Leonardo Arena2018-06-132-2/+44
| | | | Fixes #8989
* main/perl: security upgrade to 5.24.4Leonardo Arena2018-06-111-9/+13
| | | | | | CVE-2018-6797, CVE-2018-6798, CVE-2018-6913 Fixes #8803
* main/memcached: security fix (CVE-2018-1000115)Leonardo Arena2018-06-112-3/+74
| | | | Fixes #8831
* main/xen: security fixes XSA 258-262Henrik Riomar2018-06-1113-1/+1879
| | | | | | | | CVE-2018-10472 XSA-258 CVE-2018-10471 XSA-259 CVE-2018-8897 XSA-260 (depends on 4-patches from stable-4.8) CVE-2018-10982 XSA-261 CVE-2018-10981 XSA-262
* main/wavpack: add secfixesprspkt2018-06-113-2/+143
| | | | | | | | | | | fixes for: -CVE-2018-10536 -CVE-2018-10537 -CVE-2018-10538 -CVE-2018-10539 -CVE-2018-10540 Fixes #8913
* main/wavpack: security fixesLeonardo Arena2018-06-114-14/+231
| | | | | | CVE-2018-6767, CVE-2018-7253, CVE-2018-7254 Fixes #8594
* community/wireshark: security upgrade to 2.2.15Leonardo Arena2018-06-111-3/+33
| | | | | | | | | | | | | CVE-2018-11356, CVE-2018-11357, CVE-2018-11358 CVE-2018-11359, CVE-2018-11360, CVE-2018-11362 Additional secfixes from earlier releases after 2.2.12: CVE-2018-7320, CVE-2018-7321, CVE-2018-7322, CVE-2018-7323, CVE-2018-7324, CVE-2018-7325, CVE-2018-7326, CVE-2018-7327, CVE-2018-7328, CVE-2018-7329, CVE-2018-7330, CVE-2018-7331, CVE-2018-7332, CVE-2018-7333, CVE-2018-7334, CVE-2018-7335, CVE-2018-7336, CVE-2018-7417, CVE-2018-7418, CVE-2018-7419, CVE-2018-7420
* main/sdl2_image: security fixes. Fixes #8942Francesco Colista2018-06-0611-4/+347
| | | | | | | | | | | | | | | Security fiexes for the following CVEs: CVE-2017-2887 CVE-2017-12122 CVE-2017-14440 CVE-2017-14441 CVE-2017-14442 CVE-2017-14448 CVE-2017-14450 CVE-2018-3837 CVE-2018-3838 CVE-2018-3839
* main/xfsprogs: fix owner of filesNatanael Copa2018-06-061-7/+4
| | | | fixes #8968
* main/git: security upgrade to 2.13.7 (CVE-2018-11233,CVE-2018-11235)Natanael Copa2018-05-301-2/+5
| | | | fixes #8948
* main/binutils: backport fix for ppc64leNatanael Copa2018-05-302-1/+96
| | | | | | | | | | This fixes clang testsuite. Patch was taken from upstream binutils-2_30-branch https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=shortlog;h=refs/heads/binutils-2_30-branch Upstream report: https://sourceware.org/ml/binutils/2018-03/msg00183.html
* main/binutils: upgrade to 2.30Natanael Copa2018-05-302-94/+4
| | | | | fixes #7315 fixes #8881
* main/binutils: add mips supportNils Andreas Svee2018-05-304-35/+399
| | | | | | * Remove hash-style-gnu.patch in favor of the patch adding a configure flag for it from upstream * Add gold-mips.patch from Debian, which makes gold configure correctly for MIPS64 targets * Use CTARGET_ARCH instead of CARCH to correctly determine whether to enable the x86_64-pep target or not
* main/libressl: bump pkgrel due to revertNatanael Copa2018-05-301-1/+1
|
* Revert "main/libressl: add options -verify_{hostname,ip} to s_client"Natanael Copa2018-05-303-111/+3
| | | | | | fixes #8939 This reverts commit 1fae29db4daf9eb7f4e39aab7ce3bd37d18cc74e.
* main/busybox: properly fix wget https supportNatanael Copa2018-05-307-87/+341
| | | | | | | | | | | | | fix busybox wget https support by using an external ssl_client helper for https. Disable the use of external openssl. This was fixed to check certificates as a temporary solution. openssl can not produce any useful error messages on certificate errors. It is big. So we simply disable its use. We auto-install ssl_client if both libssl and busybox are installed. This is to keep backwards compatibility.
* main/busybox: wget: verify certificate when openssl helper is usedJakub Jirutka2018-05-292-0/+73
|
* main/busybox: wget: print warning when internal TLS code is usedJakub Jirutka2018-05-292-1/+89
|
* main/libressl: add options -verify_{hostname,ip} to s_clientJakub Jirutka2018-05-293-3/+111
|
* main/curl: fix crashes due to LibreSSL/OpenSSL engines conflictsJakub Jirutka2018-05-252-2/+47
|
* main/bind: security upgrade to 9.11.3Jakub Jirutka2018-05-241-2/+8
|
* main/tiff: fix CVE-2018-8905prspkt2018-05-242-2/+57
|
* main/tiff: fix CVE-2018-7456prspkt2018-05-242-2/+176
|
* main/sqlite: fix CVE-2018-8740Jakub Jirutka2018-05-212-1/+40
|
* main/curl: security upgrade to 7.60.0prspkt2018-05-201-3/+6
|
* main/postgresql: fix license and maintainerJakub Jirutka2018-05-141-2/+2
|
* main/postgresql: security upgrade to 9.6.9Jakub Jirutka2018-05-141-9/+11
| | | | | Fixes CVE-2018-1115 See https://www.postgresql.org/about/news/1851/
* main/wget: security upgrade to 1.19.5Andy Postnikov2018-05-101-4/+5
|
* community/php7: security upgrade to 7.1.17Andy Postnikov2018-05-031-3/+6
| | | | CVE-2018-5712
* main/jq: security fix (CVE-2016-4074). Fixes #8809Leonardo Arena2018-04-302-7/+45
|
* community/php5: security upgrade to 5.6.36Andy Postnikov2018-04-281-2/+6
| | | | CVE-2018-5712
* community/drupal7: security upgrade to 7.59Andy Postnikov2018-04-281-2/+4
| | | | CVE-2018-7602 https://www.drupal.org/SA-CORE-2018-004
* community/nextcloud: upgrade to 12.0.6Jakub Jirutka2018-04-181-2/+2
|
* main/clamav: security upgrade 0.99.4Leonardo Arena2018-04-112-40/+8
| | | | | | CVE-2018-0202, CVE-2018-1000085 Fixes #8695
* main/mariadb: security upgrade to 10.1.32Leonardo Arena2018-04-111-2/+12
| | | | | | | CVE-2017-10268, CVE-2017-10378, CVE-2017-15365, CVE-2018-2562 CVE-2018-2612, CVE-2018-2622, CVE-2018-2640, CVE-2018-2665, CVE-2018-2668 Fixes #8689
* community/tomcat-native: upgrade to 1.2.16Natanael Copa2018-04-021-3/+3
|
* main/tiff: fix CVE-2018-5784prspkt2018-04-023-3/+135
| | | | fixes #8702
* main/openssl: security upgrade to 1.0.2o and rebuild depending pkgsAndy Postnikov2018-04-014-5/+9
| | | | | | Fixes CVE-2017-3738, CVE-2018-0739, CVE-2018-0733 Rebuilds packages that link openssl statically.
* main/zsh: fix CVE-2018-1071, CVE-2018-1083Jakub Jirutka2018-03-313-6/+85
|
* community/php7: security upgrade to 7.1.16Andy Postnikov2018-03-311-2/+2
|