Packages changed: AppStream MicroOS-release (20250602 -> 20250604) bolt (0.9.8 -> 0.9.9) container-selinux (2.237.0 -> 2.238.0) dhcpcd (10.2.3 -> 10.2.4) fuse-overlayfs (1.14 -> 1.15) gnome-desktop (44.1 -> 44.3) gnome-software (48.1 -> 48.2) gpg2 (2.5.6 -> 2.5.7) iproute2 (6.14 -> 6.15) iputils (20240905 -> 20250602) less libssh libunwind libupnp (1.14.20 -> 1.14.22) libzypp (17.37.2 -> 17.37.3) ncurses (6.5.20250524 -> 6.5.20250531) ntfs-3g_ntfsprogs openSUSE-build-key openblas_openmp polkit-default-privs (1550+20250514.1208790 -> 1550+20250603.5d84a17) protobuf-c (1.5.1 -> 1.5.2) python-jsonschema (4.23.0 -> 4.24.0) sdbootutil (1+git20250505.f4890e9 -> 1+git20250529.307d6ff) systemd (257.5 -> 257.6) wpa_supplicant === Details === ==== AppStream ==== Subpackages: libAppStreamQt3 libappstream5 - Make qt6 the default qt flavor and qt5 the flavor built separately and disable the qt5 flavor in SLE16 where we don't want to have Qt5 libraries. ==== MicroOS-release ==== Version update (20250602 -> 20250604) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== bolt ==== Version update (0.9.8 -> 0.9.9) - update to 0.9.9: * Several CI improvements and fixes * Fixed memory leak in boltctl * The unused codes were removed from daemon * Fixed a NULL syspath variable causes SIGSEGV ==== container-selinux ==== Version update (2.237.0 -> 2.238.0) - Update to version 2.238.0: * label /run/sysctl.d correctly on creation ==== dhcpcd ==== Version update (10.2.3 -> 10.2.4) - Update to 10.2.4 * compat: use timingsafe_bcmp if available * IPv6: Sort routers by reachability correctly. * definitions: define ND Route Information option * IPv6: Clear previous address RA flags on receipt of a RA. ==== fuse-overlayfs ==== Version update (1.14 -> 1.15) - update to 0.15: * main: lookup upperdir only for created directories * main: allow escaped colons in directory paths * main: use extended override xattr to support devices * remove unsupported option "lazytime" ==== gnome-desktop ==== Version update (44.1 -> 44.3) Subpackages: libgnome-desktop-3-20 libgnome-desktop-3_0-common libgnome-desktop-4-2 typelib-1_0-GnomeBG-4_0 typelib-1_0-GnomeDesktop-4_0 - Update to version 44.3: + Stop using ratio character for time in the wall-clock. + Fix variable initialization. + Only parse XML files as slideshows. + Updated translations. ==== gnome-software ==== Version update (48.1 -> 48.2) - Update to version 48.2: + Improve memory fragmentation after checking for updates. + Updated translations. ==== gpg2 ==== Version update (2.5.6 -> 2.5.7) - Update to 2.5.7: * gpg: Allow updating a SHA-1 key certification w/o using the --force-sign-key option. [T7663] * gpg: The group key flag has now been fully implemented. [rG8833a34bf0] * gpg: Make combination of show-only-fpr-mbox and show-unusable-uid work. [rGd5a4a2dc89] * gpg: Do not allow compressed key packets on import. [T7014] * gpgsm: Allow an empty subject DN also during import. [T7171] * agent: Recover the old behavior with max-cache-ttl=0. [T6681] * agent: Fix ECC key on smartcard for composite KEM with PQC. [T7648] * scd: Fix a harmless read buffer over-read in a function used by PKCS#15 cards. [T7662] * gpg-mail-tube,wks: Support templates for mail content. [T7381] * Use the KEM interface of Libgcrypt for encryption/decryption. [T7649] - Remove patches: * gnupg-agent-Recover-the-old-behavior-with-max-cache-ttl-0.patch * gnupg-dirmngr-Don-t-install-expired-sks-certificate.patch - Update gpg2.keyring ==== iproute2 ==== Version update (6.14 -> 6.15) - Update to release 6.15 * tc_util: Add support for 64-bit hardware packets counter * iprule: Allow specifying ports in hexadecimal notation * iprule: Add port mask support * iprule: Add DSCP mask support ==== iputils ==== Version update (20240905 -> 20250602) - Update to version 20250602 Security release, fixes CVE-2025-47268 and CVE-2025-48964. https://github.com/iputils/iputils/releases/tag/20250602 - Remove html man page (required to avoid a build failure) - Remove patches from this release (iputils-CVE-2025-47268.patch, 0001-Fix-ping-man-page-syntax-error.patch) - Fix bsc#1243284 - ping on s390x prints invalid ttl * Add iputils-invalid-ttl-s390x.patch * Fix ipv4 ttl value when using SOCK_DGRAM on big endian systems ==== less ==== - Extend detection and preview for "Java archive data" (eg. .jar), "Android package" (eg. .apk) and "ASCII cpio archive" (eg. .obscpio) in lessopen.sh - Fix rpm preprocessing: Remove escaped quotes from $TMPF_pre in lessopen.sh ==== libssh ==== Subpackages: libssh-config libssh4 - Fix hang in torture_session test (bsc#1243799) * Add patch libssh-tests-Fix-an-issue-where-torture_session-request-a-SIGTERM-too-early.patch ==== libunwind ==== - 0001-Fix-unw_is_signal_frame-for-RISC-V.patch: Fix unw_is_signal_frame for RISC-V ==== libupnp ==== Version update (1.14.20 -> 1.14.22) Subpackages: libixml11 libupnp17 - Update to release 1.4.22 * Resolve FTBFS on musl - Update to release 1.4.21 * IXML fuzzer fixes * Bind SSDP UDP response to port 1900 ==== libzypp ==== Version update (17.37.2 -> 17.37.3) - Do not warn about no mirrors if mirrorlist was switched on automatically. (bsc#1243901) - Relax permission of cached packages to 0644 & ~umask (bsc#1243887) - version 17.37.3 (35) ==== ncurses ==== Version update (6.5.20250524 -> 6.5.20250531) Subpackages: libncurses6 ncurses-utils terminfo-base - Add ncurses patch 20250531 + improve logic in misc/run_tic.in for constructing symbolic link when $DESTDIR is set. ==== ntfs-3g_ntfsprogs ==== Subpackages: libntfs-3g89 ntfs-3g ntfsprogs - Migrate away from update-alternatives (bsc#1240095). - Upon installation of the newer packages, the old alternatives are purged from the system. ==== openSUSE-build-key ==== - added gpg-pubkey-287a0027-682477e3.asc: New RSA 4k Backports for SLE 16.x series. ==== openblas_openmp ==== - For SLES16 target POWER9 instead of POWER8 which fixes the issue with the reported sgemm testsuite fails. [bsc#1239545] ==== polkit-default-privs ==== Version update (1550+20250514.1208790 -> 1550+20250603.5d84a17) - Update to version 1550+20250603.5d84a17: * profiles: add ModemManager CellBroadcast action (bsc#1243684) ==== protobuf-c ==== Version update (1.5.1 -> 1.5.2) - Update to release 1.5.2 * Chase compatibility issues with Google protobuf 30.0-rc1 * protoc-gen-c: Explicitly construct strings where needed for protobuf 30.x ==== python-jsonschema ==== Version update (4.23.0 -> 4.24.0) - update to 4.24.0: * Fix calculation of evaluated properties by @V02460 in #1351 * Support for Python 3.8 has been dropped, as it is end-of-life. ==== sdbootutil ==== Version update (1+git20250505.f4890e9 -> 1+git20250529.307d6ff) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper sdbootutil-tukit - Update to version 1+git20250529.307d6ff: * Remove noarch for main package * Copy measure-pcr-prediction if missing in ESP * Compile and install uhmac * Use uhmac instead of openssl for HMAC * uhmac: add Rust tool for HMAC * Re-enable riscv64 arch * Support non-secure boot installations * Rework removable media detection * jeos-firstboot-enroll: fix typo in msgbox * Measure GPT of the disk with ESP, not the disk with root * jeos-firstboot-enroll: show final error message ==== systemd ==== Version update (257.5 -> 257.6) Subpackages: libsystemd0 libudev1 systemd-boot systemd-experimental udev - Import commit c929295b4c1fb3cd6b9963bc7588fbc3e597ab86 (merge of v257.6) For a complete list of changes, visit: https://github.com/openSUSE/systemd/compare/8e9840a2897e36ae3f926f8d10a2b0d7e4102c67...c929295b4c1fb3cd6b9963bc7588fbc3e597ab86 ==== wpa_supplicant ==== - Update build config: * Disable support for Wired equivalent privacy (WEP) * Enable 802.11r-2008 (Fast BSS Transition) * Enable 802.11ax support - Build wpa_gui with qt6 instead of qt5 - Add patch from hostap upstream to port wpa_gui to use qt6: * 0001-wpa_gui-Port-to-Qt6.patch