aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* main/linux-vanilla: upgrade to 4.19.36Natanael Copa2019-05-0610-62/+76
| | | | | | | | | also enable CONFIG_RANDOM_TRUST_CPU https://askubuntu.com/questions/1070433/will-ubuntu-enable-random-trust-cpu-in-the-kernel-and-what-would-be-the-effect/1071196#1071196 fixes #9960 (cherry picked from commit e67c2f8bcb163695a5917e059a2c7ba46726ee89)
* main/linux-vanilla: Enable CONFIG_UEVENT_HELPER for s390x.DDoSolitary2019-05-062-2/+3
| | | | | | The config option is required for busybox's mdev to work, or we'll get ".../lib/rc/sh/openrc-run.sh: line 21: can't create /proc/sys/kernel/hotplug: nonexistent directory" on boot. (cherry picked from commit 3c109eb5f41acef557f1d4dc2e8b90e4ba610ac9)
* main/linux-vanilla: remove KERNEL_NOBP on s390xTuan Hoang2019-05-062-2/+2
| | | | | | | | | CONFIG_KERNEL_NOBP should be off if CONFIG_EXPOLINE_AUTO is selected NOBP has been the first line of defense and is basically outdated by now (cherry picked from commit 212401a4ca0b7294979c648980da1fa20438fff9)
* main/linux-vanilla: add commonly used scsi modules for ppc64leMike Sullivan2019-05-062-4/+4
| | | | (cherry picked from commit 17f4278ce5180eb5214e370594ee72fc3b2e9179)
* main/linux-vanilla: enable ipset set type hash:ip,macThomas Liske2019-05-0610-19/+19
| | | | (cherry picked from commit affc173481ca6bc814aa1e89b0ef54fd741207a5)
* community/flatpak: security upgrade to 1.0.8prspkt2019-05-061-2/+4
| | | | - CVE-2019-10063
* community/shadow: fix conflict with util-linux-doc and coreutils-docNatanael Copa2019-05-061-2/+6
| | | | fixes #8665
* main/dovecot: security upgrade to 2.3.6 (CVE-2019-11494, CVE-2019-11499)J0WI2019-05-062-42/+7
| | | | | | Fixes #10388 Signed-off-by: Leonardo Arena <rnalrd@alpinelinux.org>
* scripts: add back rpi kernel to armhfCarlo Landmeter2019-05-061-1/+2
| | | | ref #10155
* main/haveged: rework init dependenciesMatt Merhar2019-05-062-3/+4
| | | | | | | | | | haveged does not require any network connectivity to function, and this errant dependency can cause the daemon to not start properly at boot. This also adds urandom / localmount, bringing the init script in sync with those from rng-tools and jitterentropy-rngd. (cherry picked from commit caec29f551955d6a6392943708652db0f8bc4a17)
* main/libpng: upgrade to 1.6.37Leo2019-05-061-7/+19
| | | | | | | | | | | - Add secfixes CVE-2019-7317 CVE-2018-14048 CVE-2018-14550 - Remove pkg-config detected depends_dev - Split $pkgname-static fixes #10362
* main/imagemagick: security upgrade to 7.0.8-44J0WI2019-05-061-2/+6
|
* community/imagemagick6: security upgrade to 6.9.10-44J0WI2019-05-061-2/+6
|
* community/openjdk8: security upgrade to 8.212.04J0WI2019-05-041-12/+16
|
* community/php7: security upgrade to 7.2.18 (CVE-2019-11036)Andy Postnikov2019-05-041-2/+6
|
* community/lua-resty-openidc: backport from edgeTimo Teräs2019-05-031-0/+21
|
* community/lua-resty-jwt: backport from edgeTimo Teräs2019-05-031-0/+21
|
* community/lua-resty-session: backport from edgeTimo Teräs2019-05-031-0/+21
|
* community/lua-resty-hmac: backport from edgeTimo Teräs2019-05-031-0/+30
|
* community/lua-resty-string: backport from edgeTimo Teräs2019-05-031-0/+28
|
* community/perl-test-nginx: backport from edgeTimo Teräs2019-05-032-0/+78
|
* community/lua-resty-http: upgrade to 0.13Franck Nijhof2019-05-031-3/+3
| | | | (cherry picked from commit 9379df6ef4c76e518ee954f5f9fcbb180409619d)
* main/bind: fix build on non-x86Natanael Copa2019-05-022-1/+136
| | | | | | | | | | fixes build error on various architectures: /usr/lib/gcc/s390x-alpine-linux-musl/8.3.0/../../../../s390x-alpine-linux-musl/bin/ld: ../../lib/ns/.libs/libns.so: undefined reference to `isc_atomic_xadd' https://lists.isc.org/pipermail/bind-users/2019-April/101673.html https://gitlab.isc.org/isc-projects/bind9/commit/d72f436b7d7c697b262968c48c2d7643069ab17f
* main/bind: security upgrade to 9.12.4_p1 (CVE-2018-5743,CVE-2019-6467)Natanael Copa2019-05-021-6/+40
| | | | | | | | | | | | | This release introduced 3 new tools with python dependency (dnssec-checkdns, dnssec-coverage and dnssec-keymgr). Move those tools to a subpackage, bind-dnssec-tools, to avoid unexpectedly pull in python as dependency for stable upgraders. There are other tools in bind-tools that belongs to bind-dnssec-tools, but we dont move those in a stable branch to avoid breaking things for current users. fixes #10368
* main/py3-ply: new aporttcely2019-04-301-0/+36
| | | | | | | https://www.dabeaz.com/ply/ Python Lex & Yacc needed by bind
* community/wireshark: security upgrade to 2.6.8Leonardo Arena2019-04-291-2/+9
| | | | | | CVE-2019-10894, CVE-2019-10895, CVE-2019-10896, CVE-2019-10899, CVE-2019-10901, CVE-2019-10903 Fixes #10322
* main/freeradius: security fixes (CVE-2019-11234, CVE-2019-11235)Leonardo Arena2019-04-252-3/+99
| | | | Fixes #10325
* community/zabbix: upgrade to 4.0.7Leonardo Arena2019-04-251-2/+2
|
* main/bind: bump pkgrelHenrik Riomar2019-04-231-1/+1
| | | | missing in last change
* main/openssh: after entropyHenrik Riomar2019-04-232-2/+3
| | | | (cherry picked from commit a858616e75eeaa241581db413c2f750611e938d3)
* main/unbound: after entropyHenrik Riomar2019-04-222-3/+3
| | | | (cherry picked from commit db18b4c886bd03a942e1c7bdbcf4e2e5d30fed7f)
* main/haveged: more samples in check()Henrik Riomar2019-04-222-3/+34
| | | | | | | | | Decrease the probability of a failing Chi-Square test by doubling the sample size used. While at it add openrc subpkg (cherry picked from commit 65662ceedf9c895da8e96d9cdba7a68f9cfe8740)
* main/haveged: add missing provideHenrik Riomar2019-04-222-2/+3
| | | | | | haveged provides entropy (cherry picked from commit c79b99c2f4aba28da0149805ecba283590cd9265)
* main/bind: fix slow startHenrik Riomar2019-04-222-2/+2
| | | | | | | named-checkconf needs entropy to start, or else it will take up to a minute to start at boot. (cherry picked from commit 62bda4345a9fc41bf290b11abcc58e31408e4e49)
* community/pdns-recursor: after entropyHenrik Riomar2019-04-222-3/+3
| | | | (cherry picked from commit 1947f2bd7d4c6ccda012321640dfb6041ddfe5f1)
* main/clamav: security upgrade to 0.100.3Leonardo Arena2019-04-171-2/+6
| | | | | | CVE-2019-1787, CVE-2019-1788, CVE-2019-1789 Fixes #10263
* community/freerdp: security upgrade to 2.0.0_rc4Leonardo Arena2019-04-171-3/+10
| | | | | | CVE-2018-8786, CVE-2018-8787, CVE-2018-8788, CVE-2018-8789 Fixes #10056
* main/wpa_supplicant: security fixesLeonardo Arena2019-04-1714-1/+1962
| | | | | | CVE-2019-9494, CVE-2019-9495, CVE-2019-9497, CVE-2019-9498, CVE-2019-9499 Fixes #10242
* main/wpa_supplicant: fix slow startHenrik Riomar2019-04-172-3/+3
| | | | wpa_supplicant needs entropy
* main/libxslt: security fix for CVE-2019-11068Natanael Copa2019-04-172-4/+129
| | | | fixes #10278
* main/libxslt: upgrade to 1.1.33Natanael Copa2019-04-171-2/+2
|
* main/samba: attempt to fix build on armv7Leonardo Arena2019-04-152-1/+41
| | | | https://bugzilla.samba.org/show_bug.cgi?id=12147
* main/samba: security upgrade to 4.8.11J0WI2019-04-151-3/+6
| | | | | | | | CVE-2018-14629, CVE-2019-3880 Fixes #10247 Signed-off-by: Leonardo Arena <rnalrd@alpinelinux.org>
* main/ldb: upgrade to 1.3.8J0WI2019-04-153-33/+26
|
* main/imagemagick: use the upstream source, not a mirrorLeonardo Arena2019-04-151-1/+1
|
* main/imagemagick: security upgrade to 7.0.8.38J0WI2019-04-151-3/+9
| | | | CVE-2019-9956, CVE-2019-10649, CVE-2019-10650
* main/tzdata: upgrade to 2019aJ0WI2019-04-151-4/+4
|
* community/php7: security upgrade to 7.2.17Leonardo Arena2019-04-151-2/+16
| | | | | | | | CVE-2019-9641 CVE-2019-9640 CVE-2019-9639 CVE-2019-9638 CVE-2019-9637
* main/bind: bump pkgrel for reverted committcely2019-04-151-1/+1
|
* main/bind: security upgrade to 9.12.3_p4tcely2019-04-151-4/+9
| | | | | | | | | | | | | | | | | | | https://ftp.isc.org/isc/bind9/9.12.3-P4/RELEASE-NOTES-bind-9.12.3-P4.html - CVE-2019-6465 - CVE-2018-5745 - CVE-2018-5744 - CVE-2018-5740 - CVE-2018-5738 - CVE-2018-5737 - CVE-2018-5736 Fixes #10166 BIND is open source software licenced under the terms of the Mozilla Public License, version 2.0 (see the LICENSE file for the full text). BIND 9.12 will be supported until at least May, 2019.