Thomas Petazzoni
2febca71f7
package/c-icap-modules: fix build with GCC 15.x
...
Add a patch fixing prototype issues with GCC 15.x. The patch cannot be
submitted upstream because the problematic code has completely changed
in newer releases.
No autobuilder failures because they were hidden by 'c-icap' not
building with GCC 15.x.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 23:13:34 +02:00
Thomas Petazzoni
b832fce891
package/c-icap: add patches to fix GCC 15.x build issues
...
Patches 0003 and 0004 are upstream backport. Patch 0005 isn't because
the code has completely changed upstream in newer releases.
Fixes:
https://autobuild.buildroot.net/results/e9b4d9033f0283b133b58049a03b5f0b595e30db/
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 23:13:25 +02:00
Julien Olivain
9b8b2d4478
support/testing/tests/boot/test_edk2.py: switch to neoverse-n2 cpu
...
The SBSA Reference Platform was updated to neoverse-n2 (armv9.0a)
in Qemu v9.1 [1].
The Armv9-A and Neoverse N2 core support was added in Buildroot
commit [2].
Since the test_edk2 uses the Qemu sbsa-ref machine, this commit
aligns it to use the neoverse-n2 cpu.
[1] b1d592e7b0
[2] 9845bd4541
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 23:04:26 +02:00
Julien Olivain
e028c2cdc9
support/testing/tests/package/test_fwts.py: switch to neoverse-n2 cpu
...
The SBSA Reference Platform was updated to neoverse-n2 (armv9.0a)
in Qemu v9.1 [1].
The Armv9-A and Neoverse N2 core support was added in Buildroot
commit [2].
Since the test_fwts uses the Qemu sbsa-ref machine, this commit
aligns it to use the neoverse-n2 cpu.
[1] b1d592e7b0
[2] 9845bd4541
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 23:04:10 +02:00
Julien Olivain
64f6d524c5
configs/qemu_aarch64_sbsa: switch to neoverse-n2 (armv9.0a)
...
The SBSA Reference Platform was updated to neoverse-n2 (armv9.0a)
in Qemu v9.1 [1].
The Armv9-A and Neoverse N2 core support was added in Buildroot
commit [2].
This commit switches qemu_aarch64_sbsa_defconfig from using
Neoverse N1 (armv8.2a) to the Neoverse N2 CPU (armv9.0a).
For reference:
BR2_neoverse_n1:
# cat /proc/cpuinfo
processor : 0
BogoMIPS : 2000.00
Features : fp asimd evtstrm aes pmull sha1 sha2 crc32 atomics fphp asimdhp cpuid asimdrdm lrcpc dcpop asimddp ssbs
CPU implementer : 0x41
CPU architecture: 8
CPU variant : 0x4
CPU part : 0xd0c
CPU revision : 1
[...]
BR2_neoverse_n2:
# cat /proc/cpuinfo
processor : 0
BogoMIPS : 2000.00
Features : fp asimd evtstrm aes pmull sha1 sha2 crc32 atomics fphp asimdhp cpuid asimdrdm jscvt fcma lrcpc dcpop sha3 sm3 sm4 asimddp sha512 sve asimdfhm dit uscat ilrcpc flagm sb paca pacg dcpodp sve2 sveaes svepmull svebitperm svesha3 svesm4 flagm2 frint svei8mm svebf16 i8mm bf16 dgh rng bti
CPU implementer : 0x41
CPU architecture: 8
CPU variant : 0x0
CPU part : 0xd49
CPU revision : 3
[...]
[1] b1d592e7b0
[2] 9845bd4541
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 23:03:35 +02:00
Thomas Petazzoni
21ea33c764
package/libfreeimage: fix build with GCC 14.x
...
Take two patches from the Debian jxrlib package, and integrate them to
fix the build of the bundled jxrlib library found in the libfreeimage
package.
libfreeimage isn't exactly well maintained: its last version 3.18.0 is
quite old (July 2018), there's a fairly large number of tickets in the
bug tracker claiming to be CVE
reports (https://sourceforge.net/p/freeimage/bugs/ ), it is still using
SVN as the version control system.
However, it is used as an optional dependency for CEGUI, and a
mandatory dependency for Ogre. However, it no longer seems to be a
dependency for more recent versions of Ogre. But in any case it cannot
simply be dropped.
Fixes:
https://autobuild.buildroot.net/results/452462285bf93b13f092fb41696952f415e75b2f/
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 22:51:13 +02:00
Thomas Petazzoni
be466c265b
package/chocolate-doom: bump to 3.1.1 to fix GCC 15.x issues
...
Changes in 3.1.0:
https://github.com/chocolate-doom/chocolate-doom/releases/tag/chocolate-doom-3.1.0
Changes in 3.1.1:
https://github.com/chocolate-doom/chocolate-doom/releases/tag/chocolate-doom-3.1.1
The SDL2_mixer and SDL2_net dependencies are now optional since 3.1.0,
so adjust the packaging accordingly.
Also, the license file was renamed upstream in commit:
91a66a7ecb
So _LICENSE_FILES and the .hash file are also updated to reflect
that change.
Fixes:
https://autobuild.buildroot.net/results/90a01c5925e7f5f50b3ea06d6ea7b0da66814a15/
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
[Julien: fix license file and hash]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 22:13:01 +02:00
Thomas Perale
6e81b51f68
package/jasper: add patch for CVE-2025-8835
...
This fixes the following vulnerability:
- CVE-2025-8835:
A vulnerability was found in JasPer up to 4.2.5. Affected by this
vulnerability is the function jas_image_chclrspc of the file
src/libjasper/base/jas_image.c of the component Image Color Space
Conversion Handler. The manipulation leads to null pointer dereference.
It is possible to launch the attack on the local host. The exploit has
been disclosed to the public and may be used. The identifier of the
patch is bb7d62bd0a2a8e0e1fdb4d603f3305f955158c52. It is recommended to
apply a patch to fix this issue.
For more information see:
- https://nvd.nist.gov//vuln/detail/CVE-2025-8835
- bb7d62bd0a
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 21:45:10 +02:00
Thomas Perale
860c35d1ac
package/jasper: add patch for CVE-2023-51257
...
This fixes the following vulnerability:
- CVE-2023-51257:
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and
before allows a local attacker to execute arbitrary code.
For more information see:
- https://nvd.nist.gov//vuln/detail/CVE-2023-51257
- aeef5293c9
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 21:45:04 +02:00
Thomas Perale
a2c906ee3b
package/lua/5.1.5: add patch for CVE-2014-5461
...
This CVE is specific for the version 5.1.5 still present in Buildroot.
It has been fixed in 5.2.3 and thereby doesn't affects the other
versions available in Buildroot.
- CVE-2014-5461
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through
5.2.x before 5.2.3 allows context-dependent attackers to cause a denial
of service (crash) via a small number of arguments to a function with a
large number of fixed arguments.
For more information see:
- https://security-tracker.debian.org/tracker/CVE-2014-5461
- https://udd.debian.org/patches.cgi?src=lua5.1&version=5.1.5-11
A patch present in Debian is used to address this vulnerability.
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 21:34:16 +02:00
James Hilliard
ccf9182abb
package/python-pydantic: bump to version 2.11.9
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 21:31:13 +02:00
Titouan Christophe
9c365fee97
package/opencv4 (-contrib): security bump to v4.12.0
...
This fixes the following vulnerability:
- CVE-2025-53644:
OpenCV is an Open Source Computer Vision Library. Versions prior to
4.12.0 have an uninitialized pointer variable on stack that may lead
to arbitrary heap buffer write when reading crafted JPEG images.
Version 4.12.0 fixes the vulnerability.
https://www.cve.org/CVERecord?id=CVE-2025-53644
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 21:08:04 +02:00
Thomas Perale
c9d185e182
package/zziplib: fix deprecated CPE
...
The CPE 'zziplib_project:zziplib' is deprecated in favour of
'gdraheim:zziplib'.
See https://nvd.nist.gov/products/cpe/detail/FB4124F9-087E-454D-B5D4-642FF08B23A8
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
85c71fee3f
package/x11r7/xserver_xorg-server: fix deprecated CPE
...
The CPE 'x.org:xorg-server' is deprecated in favour of
'x.org:x_server'.
See the following:
- https://nvd.nist.gov/products/cpe/detail/F6729083-29EE-4772-9DFF-80B43980D6BE
- https://nvd.nist.gov/vuln/detail/CVE-2025-26601
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
[Julien: fix "xorg-server:x_server" to "x.org:x_server" in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
fdb540a00e
package/python-aiohttp-session: fix deprecated CPE
...
The CPE 'aiohttp-session_project:aiohttp-session' has been deprecated in
favour of 'aiohttp-session:aiohttp-session'.
See https://nvd.nist.gov/products/cpe/detail/667389BF-3561-49F9-A61A-6C86C7B82922
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
[Julien: add https:// prefix to url in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
843707ba1e
package/modsecurity2: fix deprecated CPE
...
The CPE 'trustwave:modsecurity' has been deprecated in favour of
'owasp:modsecurity'.
See the following:
- https://nvd.nist.gov/products/cpe/detail/B305D665-44EC-44A6-8C46-C68BFDAD7C38
- https://nvd.nist.gov/vuln/detail/CVE-2025-48866
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
4ac3c1de56
package/iputils: fix deprecated CPE
...
The CPE 'iputils_project:iputils' has been deprecated in favour of
'iputils:iputils'.
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
ff492a2c87
package/upx: fix deprecated CPE
...
The CPE 'upx_project:upx' has been deprecated in favour of 'upx:upx'.
See the following:
- https://nvd.nist.gov/products/cpe/detail/36CA8E94-4A35-4373-8D69-22313060322B
- https://nvd.nist.gov/vuln/detail/CVE-2020-24119
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
2f993d55e8
package/python-cryptography: fix deprecated CPE
...
The CPE 'cryptography_project:cryptography' has been deprecated in
favour of 'cryptography.io:cryptography'.
See the following:
- https://nvd.nist.gov/products/cpe/detail/2EBA50FC-F3F9-40D5-82BD-EFB67F761153
- https://nvd.nist.gov/vuln/detail/cve-2023-49083
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
6c5f1b6414
package/pango: fix deprecated CPE
...
The CPE 'pango:pango' has been deprecated in favour of 'gnome:pango'.
See https://nvd.nist.gov/products/cpe/detail/19B77822-6C34-41C8-8160-367D56AD1569
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
0bbefd60f7
package/gnuplot: fix deprecated CPE
...
The CPE 'gnuplot_project:gnuplot' has been deprecated in favour of
'gnuplot:gnuplot'.
See the following:
- https://nvd.nist.gov/products/cpe/detail/DB68C9F5-3330-4749-A6F5-61FF041037CC
- https://nvd.nist.gov/vuln/detail/cve-2025-31178
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
cf480bda61
package/cpp-httplib: fix deprecated CPE
...
The CPE 'cpp_httplib_project:cpp-httplib' has been deprecated in favour
of 'yhirose:cpp-httplib'.
See https://nvd.nist.gov/products/cpe/detail/5D557BEA-8246-464C-AB90-EA9495A0732A
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
143bb15d6e
package/boinc: fix deprecated CPE
...
The CPE 'rom_walton:boinc' has been deprecated in favour of
'universityofcalifornia:boinc_client'.
See https://nvd.nist.gov/products/cpe/detail/DAC161C5-2154-44BF-916A-EACB524E8B8F
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
Thomas Perale
505cd0d367
package/asterisk: fix deprecated CPE ID
...
The CPE 'asterisk:open_source' has been deprecated in favour of
'sangoma:asterisk'.
See the following for more information:
- https://nvd.nist.gov/products/cpe/detail/7FC01D7D-5AE9-42A8-B31E-A99E745E5BE5
- https://github.com/asterisk/asterisk/security
- https://nvd.nist.gov/vuln/detail/CVE-2024-42491
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 19:32:33 +02:00
James Hilliard
53eb75ef53
utils/scanpypi: remove python six module
...
We dropped support for python2 a while back in [1], as such we
can remove the python six module which was only needed for
backwards comaptibility with python2.
[1] 2743ce00ca
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
[Julien: add commit ref removing python2 support]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:51 +02:00
James Hilliard
6448c3b425
package/python-distlib: bump to version 0.4.0
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:51 +02:00
James Hilliard
b08d65ac39
package/python-expandvars: bump to version 1.1.2
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:51 +02:00
James Hilliard
85fef1bb91
package/python-mypy-extensions: bump to version 1.1.0
...
Migrate from setuptools to flit build backend.
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:51 +02:00
James Hilliard
aca5611af7
package/python-mypy: bump to version 1.18.1
...
Add new python-pathspec runtime/build dependency.
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:51 +02:00
James Hilliard
b4ad6e6f8b
package/python-poetry-core: bump to version 2.2.0
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:51 +02:00
James Hilliard
234b38ffdd
package/python-pypa-build: bump to version 1.3.0
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:51 +02:00
James Hilliard
9f2f93df4e
package/python-selenium: bump to version 4.35.0
...
License hash changed due to year update:
c62597e5cd
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
3d3f4768df
package/python-maturin: bump to version 1.9.4
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
598b20ca0a
package/python-uswid: bump to version 0.5.2
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
431545111a
package/python-cython: bump to version 3.1.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
6ea8e60e49
package/python-typing-extensions: bump to version 4.15.0
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
bb825488db
package/python-starlette: bump to version 0.47.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
6cde2a46ff
package/python-sentry-sdk: bump to version 2.38.0
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
a5c151f70d
package/python-qrcode: bump to version 8.2
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
9a54553b85
package/python-pytz: bump to version 2025.2
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
2e480a8825
package/python-pypika-tortoise: bump to version 0.6.2
...
Migrate pep517 build backend from poetry to pdm-backend.
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
b117d439bd
package/python-pymodbus: bump to version 3.11.2
...
License hash changed due to year update:
c1e7f3b706
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
8595b5da17
package/python-pycparser: bump to version 2.23
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
37e0d69f54
package/python-pyaml: bump to version 25.7.0
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
34386548d3
package/python-multidict: bump to version 6.6.4
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
d2a540a537
package/python-lxml: bump to version 6.0.1
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
117b45c2d8
package/python-httpcore: bump to version 1.0.9
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
ddaffc4aa9
package/python-grpclib: bump to version 0.4.8
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
James Hilliard
c95f07d59a
package/python-gobject: bump to version 3.54.2
...
License hash changed due to formatting changes:
e80a612fd7
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 18:42:50 +02:00
Fiona Klute (WIWA)
44e0ba2bd2
package/python-trove-classifiers: bump to version 2025.9.11.17
...
package/python-cffi 2.0.0 (bumped in commit
07903d2b27 ) fails to build due to an
unknown trove-classifier:
* Getting build dependencies for wheel...
configuration error: `project.classifiers[8]` must be trove-classifier
DESCRIPTION:
`PyPI classifier <https://pypi.org/classifiers/ >`_.
GIVEN VALUE:
"Programming Language :: Python :: Free Threading :: 2 - Beta"
OFFENDING RULE: 'format'
DEFINITION:
{
"type": "string",
"format": "trove-classifier"
}
For more details about `format` see
https://validate-pyproject.readthedocs.io/en/latest/api/validate_pyproject.formats.html
The list of trove classifiers Setuptools checks against is provided by
package/python-trove-classifiers. Upstream has added the classifier as
of version 2025.5.8.15 [1], as well as a bunch of others [2], so
update to fix the problem.
[1] 331838aaea
[2] https://github.com/pypa/trove-classifiers/compare/2025.1.15.22...2025.9.11.17
Fixes:
- 07903d2b27
- https://autobuild.buildroot.org/results/45b57a919182ae3f9ea0db9b0fa430a72e1e3cdf/
Signed-off-by: Fiona Klute (WIWA) <fiona.klute@gmx.de >
[Julien: add link to autobuilder failure]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-09-17 13:57:40 +02:00