Bernd Kuhls
730f409379
package/python-boto3: bump version to 1.42.5
...
https://github.com/boto/boto3/blob/1.42.5/CHANGELOG.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
da1b964828
package/python-bleak: bump version to 2.0.0
...
https://github.com/hbldh/bleak/blob/v2.0.0/CHANGELOG.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
99acea3d87
package/python-bitarray: bump version to 3.8.0
...
https://github.com/ilanschnell/bitarray/blob/3.8.0/CHANGE_LOG
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
f13bdc0120
package/python-beniget: bump version to 0.5.0
...
https://github.com/serge-sans-paille/beniget/commits/0.5.0/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
ce223fb2e4
package/python-beautifulsoup4: bump version to 4.14.3
...
https://git.launchpad.net/beautifulsoup/tree/CHANGELOG
(from master branch, no 4.14.3 tag available)
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
e022386c7e
package/python-bcrypt: bump version to 5.0.0
...
Changelog: https://github.com/pyca/bcrypt/blob/5.0.0/README.rst
Fixes build with python 3.14.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
1be3962f8f
package/{avro-c, python-avro}: bump to version 1.12.1
...
https://avro.apache.org/blog/2025/10/16/avro-1.12.1/
Updated help text URL.
Upstream does not provide hashes anymore for avro-c.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
d075b6a238
package/python-autobahn: bump version to 25.11.1
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
e9becb42c2
package/python-attrs: bump version to 25.4.0
...
https://www.attrs.org/en/stable/changelog.html
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
85c346bd74
package/python-asyncclick: bump version to 8.3.0.7
...
https://github.com/python-trio/asyncclick/blob/main/CHANGES.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
3da9885722
package/python-asttokens: bump version to 3.0.1
...
Updated license hash:
9db9335648
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
976d69f6cd
package/python-arrow: bump version to 1.4.0
...
https://github.com/arrow-py/arrow/blob/1.4.0/CHANGELOG.rst
Switched _SETUP_TYPE to flit.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
793c116308
package/python-argon2-cffi: bump version to 25.1.0
...
https://github.com/hynek/argon2-cffi/blob/25.1.0/CHANGELOG.md
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
3195e244ff
package/python-argon2-cffi-bindings: bump version to 25.1.0
...
https://github.com/hynek/argon2-cffi-bindings/blob/25.1.0/CHANGELOG.md
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
a2fba76874
package/python-argcomplete: bump version to 3.6.3
...
https://github.com/kislyuk/argcomplete/blob/v3.6.3/Changes.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
09bcc5b9c1
package/python-apispec: bump version to 6.9.0
...
https://github.com/marshmallow-code/apispec/blob/6.9.0/CHANGELOG.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
22b0d124f2
package/python-alembic: bump version to 1.17.2
...
https://alembic.sqlalchemy.org/en/latest/changelog.html#change-1.17.2
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
023423b4a0
package/python-aiohttp: bump version to 3.13.2
...
Changelog: https://github.com/aio-libs/aiohttp/blob/v3.13.2/CHANGES.rst
Fixes build with python 3.14.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
ecf116f950
package/python-aiofiles: bump version to 25.1.0
...
https://github.com/Tinche/aiofiles/blob/v25.1.0/CHANGELOG.md
Added dependency to host-python-hatch-vcs to fix build error which would
be introduced by this bump.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
00108540f7
package/python-aiodns: bump version to 3.6.0
...
https://github.com/aio-libs/aiodns/releases/tag/v3.6.0
Updated URL in help text.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
6636c30dd2
package/python-aiocoap: bump version to 0.4.17
...
https://github.com/chrysn/aiocoap/blob/0.4.17/NEWS.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Bernd Kuhls
36b5896db8
package/python-aioconsole: bump version to 0.8.2
...
https://github.com/vxgmichel/aioconsole/releases/tag/v0.8.2
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 18:47:24 +01:00
Christian Hitz
55f1d00e80
package/libvncserver: install storepasswd tool
...
storepasswd is used to dynamically create a VNC password on target
Signed-off-by: Christian Hitz <christian.hitz@bbv.ch >
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2025-12-14 18:40:07 +01:00
Christian Hitz
707756a5a8
package/libvncserver: enable websocket server
...
Signed-off-by: Christian Hitz <christian.hitz@bbv.ch >
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2025-12-14 18:34:58 +01:00
Christian Hitz
3b62f17f32
package/libvncserver: bump to version 0.9.15
...
For more details on the version bump, see the release notes:
- https://github.com/LibVNC/libvncserver/releases/tag/LibVNCServer-0.9.15
Signed-off-by: Christian Hitz <christian.hitz@bbv.ch >
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2025-12-14 18:30:12 +01:00
Bernd Kuhls
3600d2fd4a
package/libvncserver: fix cmake 4 compatibility
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2025-12-14 18:29:22 +01:00
Bernd Kuhls
f11ac644ea
package/swtpm: needs gmp
...
Buildroot commit 2b449935c2 bumped swtpm
from version 0.8.2 to 0.10.1.
Upstream added gmp as dependency in version 0.9.0:
605e0ce880
This causes build errors which are fixed by adding host-gmp as
dependency.
Fixes:
https://autobuild.buildroot.net/results/d14/d14b2953e04b488b2f357386870d557d50190d34/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2025-12-14 18:05:03 +01:00
Michael Nosthoff
e513d6a5fd
package/grpc: remove BUILD_CSHARP_EXT option
...
the CSharp Extension was removed in grcp 1.47.0 [0] and the option in
the CMakeLists was dropped in 1.58.0 [1], which means that it is no
longer relevant since Buildroot commit
91d1207de0 , which bumped grpc from
1.51.1 to 1.66.1.
So remove this option for host-grpc as well.
Fixes:
CMake Warning:
Manually-specified variables were not used by the project:
gRPC_BUILD_CSHARP_EXT
[0] https://github.com/grpc/grpc/releases/tag/v1.47.0
[1] 3a2bd221ef
Signed-off-by: Michael Nosthoff <buildroot@heine.tech >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2025-12-14 18:03:16 +01:00
Bernd Kuhls
e6567407ff
package/libva-utils: bump version to 2.23.0
...
https://github.com/intel/libva-utils/blob/2.23.0/NEWS
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2025-12-14 17:38:11 +01:00
Bernd Kuhls
2a67cf2bca
package/libva: bump version to 2.23.0
...
https://github.com/intel/libva/blob/2.23.0/NEWS
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2025-12-14 17:38:10 +01:00
Giulio Benetti
d75b8c5b75
package/rtl8821au: bump to version 2025-12-13
...
With Kernel >= 6.18 introduced in [1] rtl8821au fails at build
time with error:
core/rtw_security.c:2008:13: error: conflicting types for 'sha256_init'; have 'void(struct sha256_state_rtk *)'
Fixes:
https://autobuild.buildroot.org/results/bc0ec5fe3acb37740b54eb1af1fe5d9284c87cf2/
[1] a06d79862a
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
[Julien: add details in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 17:03:46 +01:00
Thomas Petazzoni
bba86304b0
linux: select host-openssl for all architectures when building latest version
...
Since at least Linux 6.16, but possibly earlier, host-openssl is now
needed on the vast majority of CPU architectures.
A common reason to require host-openssl in the Kernel is to enable
Wireless Networking. This is now enabled in most defconfigs.
- When enabling CONFIG_NET [1]
- CONFIG_WIRELESS is enabled by default [2]
- For Wireless, CONFIG_CFG80211 is commonly enabled too [3]
- CONFIG_CFG80211_REQUIRE_SIGNED_REGDB is enabled by default
which selects SYSTEM_DATA_VERIFICATION [4]
- CONFIG_SYSTEM_DATA_VERIFICATION
select SYSTEM_TRUSTED_KEYRING [5]
- CONFIG_SYSTEM_TRUSTED_KEYRING adds system_certificates.o
which needs x509_certificate_list and extract-cert [6]
- and finally, extract-cert uses host-openssl [7]
Even if some architecture defconfigs (such as m68k) are not directly
enabling CONFIG_CFG80211 in the Kernel, there is still chances for
this option to be enabled by Kernel configuration fixups of selected
Buildroot package. This situation can happen in Buildroot
autobuilders.
Also, in some specific cases, host-openssl might be needed for
some other reasons (e.g. s390 arch defconfig enables
SYSTEM_DATA_VERIFICATION which ends up the same way).
Indeed, in order to fix build issues, we would have to add: armeb,
microblaze, loongarch, m68k, mips, mipsel, mips64, mips64el, powerpc,
powerpc64, powerpc64el, riscv, s390, and possibly others.
So intead, when "latest kernel" is used with the default architecture
configuration, always select host-openssl independently of the
selected architectures.
Fixes:
https://autobuild.buildroot.net/results/9a314e759f7640d760003e46f86153300478ec60/ (mipsel)
https://autobuild.buildroot.net/results/3bcc674ea5a7cdf031200b0cd2f9f71400ba391c/ (mips64el)
https://autobuild.buildroot.net/results/b24983fd91f408de56479b7d7d57fc9fd3333d7d/ (s390)
https://autobuild.buildroot.net/results/b262fc6f67a9fed55faffcdd580d89f4664e1e16/ (powerpc64)
https://autobuild.buildroot.net/results/45da1538457b18671fa18efe3e1aa57a15561370/ (m68k)
https://autobuild.buildroot.net/results/0a457375d2509f1b29a449dfa50f29fc7e56e568/ (armeb)
https://autobuild.buildroot.net/results/814ca5f048827a635dea0199878fa82d5012b649/ (loongarch64)
https://autobuild.buildroot.net/results/b684d0b37e5187aa9b31693356f8515857d19f7a/ (microblaze)
[1] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/net/Kconfig?h=v6.18.1#n6
[2] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/net/Kconfig?h=v6.18.1#n428
[3] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/net/wireless/Kconfig?h=v6.18.1#n17
[4] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/net/wireless/Kconfig?h=v6.18.1#n89
[5] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/init/Kconfig?h=v6.18.1#n2063
[6] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/certs/Makefile?h=v6.18.1#n6
[7] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/certs/extract-cert.c?h=v6.18.1#n21
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Reviewed-by: Romain Naour <romain.naour@smile.fr >
[Julien: add extra info in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 15:22:34 +01:00
Bernd Kuhls
97e2f63bdf
package/bpftrace: bump version to 0.24.2
...
https://github.com/bpftrace/bpftrace/blob/v0.24.2/CHANGELOG.md
Version 0.24.0 contains: "Add support for LLVM 21"
Buildroot commit d6a7c02263 bumped llvm to
the 21 series causing a build error with bpftrace:
CMake Error at CMakeLists.txt:168 (message):
Unsupported LLVM version found via
/home/autobuild/autobuild/instance-14/output-1/host/aarch64-buildroot-linux-gnu/sysroot/usr/include:
21
CMake Error at CMakeLists.txt:169 (message):
Only versions between 16 and 20 are supported
Fixes:
https://autobuild.buildroot.net/results/2bf/2bf26b4848796ab031ab0767b97aba63a35f1184/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 13:19:40 +01:00
Francois Perrad
61f5e2efca
package/perl: security bump to version 5.40.3
...
This commit fixes CVE-2025-40909:
Perl threads have a working directory race condition where file
operations may target unintended paths.
For release notes, see:
https://perldoc.perl.org/5.40.3/perl5403delta
Fixes:
https://www.cve.org/CVERecord?id=CVE-2025-40909
Signed-off-by: Francois Perrad <francois.perrad@gadz.org >
[Julien: add link to cve.org]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-14 11:56:15 +01:00
Bernd Kuhls
d39ec85091
package/samba4: bump version to 4.23.4
...
https://www.samba.org/samba/history/samba-4.23.4.html
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 22:09:19 +01:00
Bernd Kuhls
25fe2c4d28
package/fetchmail: bump version to 6.6.2
...
https://sourceforge.net/p/fetchmail/mailman/message/59270832/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 22:00:39 +01:00
Bernd Kuhls
fdce0b7d4a
package/libdrm: bump version to 2.4.131
...
Release notes:
https://lists.x.org/archives/xorg-announce/2025-December/003646.html
https://lists.x.org/archives/xorg-announce/2025-December/003647.html
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 21:48:28 +01:00
Bernd Kuhls
2170ed923d
package/cmake: bump version to 4.2.1
...
https://cmake.org/cmake/help/latest/release/4.2.html#id1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 21:05:24 +01:00
Dario Binacchi
856d88d9a0
package/cmocka: bump to version 2.0.0
...
The license file has been renamed [1].
Release notes:
https://gitlab.com/cmocka/cmocka/-/releases/cmocka-2.0.0
[1] 01cd73ee64
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com >
[Julien: add pgp signature comment in hash file]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 20:59:45 +01:00
Raphael Pavlidis
bbbc6c9d9e
package/x11r7/xwayland: add nettle and libmd as SHA1 providers
...
Xwayland can use either nettle or libmd for SHA1 support. When one of
these libraries is selected, use it as the SHA1 provider.
Also reorder the preferred SHA1 libraries to match the order used by
meson [1].
[1]: https://gitlab.freedesktop.org/xorg/xserver/-/blob/xwayland-24.1.9/meson.build?ref_type=tags#L235-239
Signed-off-by: Raphael Pavlidis <raphael.pavlidis@gmail.com >
[Julien: fix package path in commit title]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 20:05:27 +01:00
Dario Binacchi
14f279184e
package/pocketpy: bump to version 2.1.5
...
Release notes:
https://github.com/pocketpy/pocketpy/releases/tag/v2.1.5
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 19:06:42 +01:00
Alexis Lothoré
74d7259a33
support/testing: add basic runtime test for libldns/drill
...
Add a simple test ensuring that
- libldns is correctly built and installed
- drill is correctly built and installed
- drill is able to execute on the target
Reviewed-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 18:51:55 +01:00
Alexis Lothoré
70a689f9dc
package/libldns: add an option to build and install drill
...
The libldns library also comes with a CLI tool named drill, allowing to
perform DNS requests. Drill build is currently disabled by default.
Add a KConfig option to allow building and installing drill tool. Set
the default value to n to preserve the current behavior. Similarly to
linktest (see the comment in the .mk), drill fails to build correctly as
a static binary, so make the new option depend on non-static build.
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 18:51:53 +01:00
Giulio Benetti
1bd758209e
package/rtl8723ds: bump to version 2025-12-09
...
With Kernel >= 6.18 introduced in [1] rtl8723ds fails at build
time with error:
core/rtw_security.c:2183:13: error: conflicting types for 'sha256_init'; have 'void(struct rtl_sha256_state *)'
Fixes:
https://autobuild.buildroot.org/results/52081e3a500dd2566af145e8c6d793df7f72d025/
[1] a06d79862a
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
[Julien: add details in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 18:45:57 +01:00
Jon Henrik Bjørnstad
13bbd4ff47
package/qbee-agent: bump version to 2025.49
...
Signed-off-by: Jon Henrik Bjørnstad <jonhenrik@qbee.io >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 18:25:22 +01:00
Giulio Benetti
9ec337489a
package/rtl8192eu: bump to 2025-10-13 version on branch 5.11.2.1
...
This version allows to build with Linux 6.18.
Fixes:
In file included from core/crypto/sha256.c:11:
core/crypto/sha256.h:16:5: error: conflicting types for 'hmac_sha256'; have 'int(const u8 *, size_t, const u8 *, size_t, u8 *)' {aka 'int(const unsigned char *, long unsigned int, const unsigned char *, long unsigned int, unsigned char *)'}
Build failure still not occured in autobuilders.
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
[Julien: add details about the error being fixed]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 18:19:53 +01:00
Thomas Petazzoni
2d570f8369
arch: drop support for ARC big-endian
...
Alexey Brodkin from Synopsys says in [1]:
I think indeed, we may remove all the big-endian support for ARC.
Reasons are since introduction of ARC HS4x processors we no longer
support big-endian in any new processor IP, and even for older IP
which used to support big-endian it was rarely used... so basically
there's no good justification to spend any cycles on big-endian
support looking forward in this project. I.e. BE support in uClibc
could also be removed if it makes any difference.
Therefore, let's removed support for ARC big-endian.
[1] https://lore.kernel.org/buildroot/SJ2PR12MB818487232470DA4456967C73A1A3A@SJ2PR12MB8184.namprd12.prod.outlook.com/
Cc: Alexey Brodkin <Alexey.Brodkin@synopsys.com >
Cc: ARC Maintainers <arc-buildroot@synopsys.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Reviewed-by: Maxim Kochetkov <fido_max@inbox.ru >
[Julien:
- move legacy option to 2026.02 section
- add link to mailing list
- remove BR2_arceb from pkg-meson.mk to fix check-symbols error
]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 17:39:02 +01:00
Giulio Benetti
0f303f3abc
package/libnss: bump version to 3.119.1
...
For release note, see:
https://hg-edge.mozilla.org/projects/nss/file/tip/doc/rst/releases/nss_3_119_1.rst
For release 3.119.1 tarball change from nss-3.119.1.tar.gz to
nss-3_119_1.tar.gz so let's fix it accordingly.
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-12-13 16:59:38 +01:00
Thomas Perale
1167d0ff3d
docs/manual: mention CVE trailer
...
Adds documentation about adding a patch that address a vulnerability.
The patch-policy file now explain mention that patches that address a
vulnerability needs to include a `CVE:` trailer with the reference of
that vulnerability.
Until now only adding the reference to the `_IGNORE_CVES` variable was
necessary, so the documentation of this entry is modified as well to
point to the patch policy.
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-12-13 14:50:07 +01:00
Thomas Perale
9415529923
utils/generate-cyclonedx: add support for 'resolved_with_pedigree'
...
The CycloneDX specification for vulnerabilities defines four analysis
states ([1]) for cases where a vulnerability does not affect a component:
* resolved
* resolved_with_pedigree
* not_affected
* false_positive
Currently, the metadatas present in Buildroot does not allow an accurate
mapping of ignored CVEs to the appropriate CycloneDX vulnerability
categories. As a result, all ignored CVEs are currently marked as
'in_triage' by default.
This default analysis was established during the introduction of the
'generate-cyclonedx' script. The reasoning at the time was that SBOM
consumers might want to re-evaluate ignored vulnerabilities, as the
Buildroot infrastructure could not reliably determine their actual
state.
This patch adds support for automatically marking vulnerabilities as
'resolved_with_pedigree' when a Buildroot patch includes a 'CVE:''
tag in its header referencing the CVE identifier.
The 'CVE:' tag appears alongside the already required 'Upstream:', if
the patch address a security vulnerability and may be repeated if a
patch addresses multiple vulnerabilities.
If a vulnerability is addressed by multiple patches, each patch will need to
reference the vulnerability identifier.
For details on how CycloneDX handles 'resolved_with_pedigree', see
[1][2].
As an example, the CVE-2025-3198 from the binutils package will result
in the following pedigree for the binutils component:
```
{
"type": "unofficial",
"diff": {
"text": {
"content": "..."
}
},
"resolves": [
{
"type": "security",
"name": "CVE-2025-3198"
}
]
},
```
The `resolves` property is an array of issue the pedigree resolves. If
multiple are addressed by the same patch, then multiple identifier will be
present in this array.
In the listed vulnerabilities the entry for the CVE-2025-3198 looks like
this:
```
{
"id": "CVE-2025-3198",
"analysis": {
"state": "resolved_with_pedigree",
"detail": "The CVE 'CVE-2025-3198' has been marked as ignored by Buildroot"
},
"affects": [
{
"ref": "binutils"
}
]
}
```
[1] https://cyclonedx.org/docs/1.6/json/#vulnerabilities_items_analysis_state
[2] https://cyclonedx.org/docs/1.6/json/#components_items_pedigree_patches_items_resolves
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-12-13 14:50:06 +01:00