openSUSE Recommended Update: Recommended update for file
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:3182-1
Rating: moderate
References: #1189996
Affected Products:
openSUSE Leap 15.3
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for file fixes the following issues:
- Fixes exception thrown by memory allocation problem (bsc#1189996)
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-3182=1
Package List:
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
file-5.32-7.14.1
file-debuginfo-5.32-7.14.1
file-debugsource-5.32-7.14.1
file-devel-5.32-7.14.1
libmagic1-5.32-7.14.1
libmagic1-debuginfo-5.32-7.14.1
python2-magic-5.32-7.14.1
python3-magic-5.32-7.14.1
- openSUSE Leap 15.3 (noarch):
file-magic-5.32-7.14.1
- openSUSE Leap 15.3 (x86_64):
file-devel-32bit-5.32-7.14.1
libmagic1-32bit-5.32-7.14.1
libmagic1-32bit-debuginfo-5.32-7.14.1
References:
https://bugzilla.suse.com/1189996
openSUSE Recommended Update: Recommended update for lshw
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:1292-1
Rating: moderate
References: SLE-19399
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that has 0 recommended fixes and contains one
feature can now be installed.
Description:
This update for lshw fixes the following issues:
- Update to version B.02.19.2+git.20210619 (jsc#SLE-19399) This update was
imported from the SUSE:SLE-15-SP2:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-1292=1
Package List:
- openSUSE Leap 15.2 (noarch):
lshw-lang-B.02.19.2+git.20210619-lp152.2.9.1
- openSUSE Leap 15.2 (x86_64):
lshw-B.02.19.2+git.20210619-lp152.2.9.1
lshw-debuginfo-B.02.19.2+git.20210619-lp152.2.9.1
lshw-debugsource-B.02.19.2+git.20210619-lp152.2.9.1
lshw-gui-B.02.19.2+git.20210619-lp152.2.9.1
lshw-gui-debuginfo-B.02.19.2+git.20210619-lp152.2.9.1
References:
openSUSE Recommended Update: Recommended update for openhpi
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:1299-1
Rating: moderate
References: #1185173 #1190042
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that has two recommended fixes can now be
installed.
Description:
This update for openhpi fixes the following issues:
- Use /run not /var/run for PID file creation (bsc#1185173)
- Remove group rights on config file (bsc#1190042)
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-1299=1
Package List:
- openSUSE Leap 15.2 (x86_64):
libopenhpi4-3.8.0-lp152.3.3.1
libopenhpi4-debuginfo-3.8.0-lp152.3.3.1
openhpi-3.8.0-lp152.3.3.1
openhpi-clients-3.8.0-lp152.3.3.1
openhpi-clients-debuginfo-3.8.0-lp152.3.3.1
openhpi-daemon-3.8.0-lp152.3.3.1
openhpi-daemon-debuginfo-3.8.0-lp152.3.3.1
openhpi-debuginfo-3.8.0-lp152.3.3.1
openhpi-debugsource-3.8.0-lp152.3.3.1
openhpi-devel-3.8.0-lp152.3.3.1
References:
https://bugzilla.suse.com/1185173https://bugzilla.suse.com/1190042
openSUSE Security Update: Security update for grafana-piechart-panel
______________________________________________________________________________
Announcement ID: openSUSE-SU-2021:3175-1
Rating: moderate
References: #1172125
Cross-References: CVE-2020-13429
CVSS scores:
CVE-2020-13429 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVE-2020-13429 (SUSE): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Affected Products:
openSUSE Leap 15.3
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for grafana-piechart-panel fixes the following issues:
- CVE-2020-13429: Fixed XSS via the Values Header option in the
piechart-panel (bsc#1172125).
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-3175=1
Package List:
- openSUSE Leap 15.3 (noarch):
grafana-piechart-panel-1.6.1-3.6.1
References:
https://www.suse.com/security/cve/CVE-2020-13429.htmlhttps://bugzilla.suse.com/1172125
openSUSE Security Update: Security update for php-composer
______________________________________________________________________________
Announcement ID: openSUSE-SU-2021:1289-1
Rating: important
References: #1185376 #1187416
Cross-References: CVE-2021-29472
CVSS scores:
CVE-2021-29472 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
openSUSE Leap 15.2
openSUSE Backports SLE-15-SP3
openSUSE Backports SLE-15-SP2
openSUSE Backports SLE-15-SP1
______________________________________________________________________________
An update that solves one vulnerability and has one errata
is now available.
Description:
This update for php-composer fixes the following issues:
- Require php-mbstring as requested in boo#1187416
- Version 1.10.22
* Security: Fixed command injection vulnerability in
HgDriver/HgDownloader and hardened other VCS drivers and downloaders
(GHSA-h5h8-pc6h-jvvx / CVE-2021-29472), boo#1185376
- Version 1.10.21
* Fixed support for new GitHub OAuth token format
* Fixed processes silently ignoring the CWD when it does not exist
- Version 1.10.20
* Fixed exclude-from-classmap causing regex issues when having too many
paths
* Fixed compatibility issue with Symfony 4/5
- Version 1.10.17
* Fixed Bitbucket API authentication issue
* Fixed parsing of Composer 2 lock files breaking in some rare conditions
- Version 1.10.16
* Added warning to validate command for cases where packages provide/
replace a package that they also require
* Fixed JSON schema validation issue with PHPStorm
* Fixed symlink handling in archive command
- Version 1.10.15
* Fixed path repo version guessing issue
- Version 1.10.14
* Fixed version guesser to look at remote branches as well as local
ones
* Fixed path repositories version guessing to handle edge cases where
version is different from the VCS-guessed version
* Fixed COMPOSER env var causing issues when combined with the global
command
* Fixed a few issues dealing with PHP without openssl extension (not
recommended at all but sometimes needed for testing)
- Version 1.10.13
* Fixed regressions with old version validation
* Fixed invalid root aliases not being reported
- Version 1.10.12
* Fixed regressions with old version validation
- Version 1.10.11
* Fixed more PHP 8 compatibility issues
* Fixed regression in handling of CTRL-C when xdebug is loaded
* Fixed status handling of broken symlinks
- Version 1.10.10
* Fixed create-project not triggering events while installing the root
package
* Fixed PHP 8 compatibility issue
* Fixed self-update to avoid automatically upgrading to the next major
version once it becomes stable
- Version 1.10.9
* Fixed Bitbucket redirect loop when credentials are outdated
* Fixed GitLab auth prompt wording
* Fixed self-update handling of files requiring admin permissions to
write to on Windows (it now does a UAC prompt)
* Fixed parsing issues in funding.yml files
- Version 1.10.8
* Fixed compatibility issue with git being configured to show signatures
by default
* Fixed discarding of local changes when updating packages to include
untracked files
* Several minor fixes
- Version 1.10.7
* Fixed PHP 8 deprecations
* Fixed detection of pcntl_signal being in disabled_functions when
pcntl_async_signal is allowed
- Version 1.10.6
* Fixed version guessing to take composer-runtime-api and
composer-plugin-api requirements into account to avoid selecting
packages which require Composer 2
* Fixed package name validation to allow several dashes following each
other
* Fixed post-status-cmd script not firing when there were no changes to
be displayed
* Fixed composer-runtime-api support on Composer 1.x, the package is now
present as 1.0.0
* Fixed support for composer show --name-only --self
* Fixed detection of GitLab URLs when handling authentication in some
cases
- Version 1.10.5
* Fixed self-update on PHP <5.6, seriously please upgrade
* Fixed 1.10.2 regression with PATH resolution in scripts
- Version 1.10.4
* Fixed 1.10.2 regression in path symlinking with absolute path repos
- Version 1.10.3
* Fixed invalid --2 flag warning in self-update when no channel is
requested
- Version 1.10.2
* Added --1 flag to self-update command which can be added to automated
self-update runs to make sure it won't automatically jump to 2.0 once
that is released
* Fixed path repository symlinks being made relative when the repo url
is defined as absolute paths
* Fixed potential issues when using "composer ..." in scripts and
composer/composer was also required in the project
* Fixed 1.10.0 regression when downloading GitHub archives from non-API
URLs
* Fixed handling of malformed info in fund command
* Fixed Symfony5 compatibility issues in a few commands
- Version 1.10.1
* Fixed path repository warning on empty path when using wildcards
* Fixed superfluous warnings when generating optimized autoloaders
- Version 1.10.0
* Breaking: composer global exec ... now executes the process in the
current working directory instead of executing it in the global
directory.
* Warning: Added a warning when class names are being loaded by a PSR-4
or PSR-0 rule only due to classmap optimization, but would not
otherwise be autoloadable. Composer 2.0 will stop autoloading these
classes so make sure you fix your autoload configs.
* Added new funding key to composer.json to describe ways your package's
maintenance can be funded. This reads info from GitHub's FUNDING.yml
by default so better configure it there so it shows on GitHub and
Composer/Packagist
* Added composer fund command to show funding info of your dependencies
* Added bearer auth config to authenticate using Authorization: Bearer
<token> headers
* Added plugin-api-version in composer.lock so third-party tools can
know which Composer version was used to generate a lock file
* Added support for --format=json output for show command when showing a
single package
* Added support for configuring suggestions using config command, e.g.
composer config suggest.foo/bar some text
* Added support for configuring fine-grained preferred-install using
config command, e.g. composer config preferred-install.foo/* dist
* Added @putenv script handler to set environment variables from
composer.json for following scripts
* Added lock option that can be set to false, in which case no
composer.lock file will be generated
* Added --add-repository flag to create-project command which will
persist the repo given in --repository into the composer.json of the
package being installed
* Fixed issue where --no-dev autoload generation was excluding some
packages which should not have been excluded
* Added support for IPv6 addresses in NO_PROXY
* Added package homepage display in the show command
* Added debug info about HTTP authentications
* Added Symfony 5 compatibility
* Added --fixed flag to require command to make it use a fixed
constraint instead of a ^x.y constraint when adding the requirement
* Fixed exclude-from-classmap matching subsets of directories e.g. foo/
was excluding foobar/
* Fixed archive command to persist file permissions inside the zip files
* Fixed init/require command to avoid suggesting packages which are
already selected in the search results
* Fixed create-project UX issues
* Fixed filemtime for vendor/composer/* files is now only changing when
the files actually change
* Fixed issues detecting docker environment with an active open_basedir
- Version 1.9.3
* Fixed GitHub deprecation of access_token query parameter, now using
Authorization header
- Version 1.9.2
* Fixed minor git driver bugs
* Fixed schema validation for version field to allow dev-* versions too
* Fixed external processes' output being formatted even though it should
not
* Fixed issue with path repositories when trying to install feature
branches
- Version 1.9.1
* Fixed various credential handling issues with gitlab and github
* Fixed credentials being present in git remotes in Composer cache and
vendor directory when not using SSH keys
* Fixed composer why not listing replacers as a reason something is
present
* Fixed various PHP 7.4 compatibility issues
* Fixed root warnings always present in Docker containers, setting
COMPOSER_ALLOW_SUPERUSER is not necessary anymore
* Fixed GitHub access tokens leaking into debug-verbosity output
* Fixed several edge case issues detecting GitHub, Bitbucket and GitLab
repository types
* Fixed Composer asking if you want to use a composer.json in a parent
directory when ran in non-interactive mode
* Fixed classmap autoloading issue finding classes located within a few
non-PHP context blocks (?>...<?php)
- Version 1.9.0
* Added a --no-cache flag available on all commands to run with the
cache disabled
* Added PHP_BINARY as env var pointing to the PHP process when executing
Composer scripts as shell scripts
* Added a use-github-api config option which can set the no-api flag on
all GitHub VCS repositories declared
* Added a static helper you can preprend to a script to avoid process
timeouts, "Composer\\Config::disableProcessTimeout"
* Added Event::getOriginatingEvent to retrieve an event's original event
when a script handler forwards to another one
* Added support for autoloading directly from a phar file
* Fixed loading order of plugins to always initialize them in order
of dependencies
* Fixed various network-mount related issues
* Fixed --ignore-platform-reqs not ignoring conflict rules against
platform packages
- Version 1.8.6
* Fixed handling of backslash-escapes handling in compoesr.json when
using the require command
* Fixed create-project not following classmap-authoritative and
apcu-autoloader config values
* Fixed HHVM version warning showing up in some cases when it was not in
use
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-1289=1
- openSUSE Backports SLE-15-SP3:
zypper in -t patch openSUSE-2021-1289=1
- openSUSE Backports SLE-15-SP2:
zypper in -t patch openSUSE-2021-1289=1
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2021-1289=1
Package List:
- openSUSE Leap 15.2 (noarch):
php-composer-1.10.22-lp152.2.3.1
- openSUSE Backports SLE-15-SP3 (noarch):
php-composer-1.10.22-bp153.2.3.1
- openSUSE Backports SLE-15-SP2 (noarch):
php-composer-1.10.22-bp152.2.3.1
- openSUSE Backports SLE-15-SP1 (noarch):
php-composer-1.10.22-bp151.3.3.1
References:
https://www.suse.com/security/cve/CVE-2021-29472.htmlhttps://bugzilla.suse.com/1185376https://bugzilla.suse.com/1187416
openSUSE Recommended Update: Recommended update for release-notes-sles
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:3173-1
Rating: low
References: #1187693 #1188305 #1188511 #1189786 #933411
SLE-13565 SLE-17703 SLE-17881
Affected Products:
openSUSE Leap 15.3
______________________________________________________________________________
An update that has 5 recommended fixes and contains three
features can now be installed.
Description:
This update for release-notes-sles fixes the following issues:
- Added note about NVIDIA vGPU support (jsc#SLE-17881)
- Added note about Intel technologies (bsc#1189786)
- Added note about ODBC drivers (jsc#SLE-17703)
- Added note about NVIDIA BlueField-2 tech preview (jsc#SLE-13565)
- Added note about kubevirt-virt-* (bsc#1187693)
- Fixed typo in note about compat-libpthread-nonshared (bsc#1188511)
- Removed mention of SES (bsc#1188305)
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-3173=1
Package List:
- openSUSE Leap 15.3 (noarch):
release-notes-sles-15.3.20210903-3.9.1
References:
https://bugzilla.suse.com/1187693https://bugzilla.suse.com/1188305https://bugzilla.suse.com/1188511https://bugzilla.suse.com/1189786https://bugzilla.suse.com/933411
openSUSE Recommended Update: Recommended update for yast2-country
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:1290-1
Rating: important
References: #1188406 #1189461
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that has two recommended fixes can now be
installed.
Description:
This update for yast2-country fixes the following issues:
- AutoYaST: allow empty /profile/timezone/timezone setting meaning to keep
the UTC default. (bsc#1188406)
- Move the keyboards database to 'lib/' to make the module compatible with
the 'self-update' mechanism. (bsc#1189461)
This update was imported from the SUSE:SLE-15-SP2:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-1290=1
Package List:
- openSUSE Leap 15.2 (i586 x86_64):
yast2-country-4.2.23-lp152.2.9.1
yast2-country-data-4.2.23-lp152.2.9.1
References:
https://bugzilla.suse.com/1188406https://bugzilla.suse.com/1189461
openSUSE Recommended Update: Recommended update for salt
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:3161-1
Rating: moderate
References: #1168327 #1188259 #1188647 #1189040
Affected Products:
openSUSE Leap 15.3
______________________________________________________________________________
An update that has four recommended fixes can now be
installed.
Description:
This update for salt fixes the following issues:
- Fix wrong relative paths resolution with Jinja renderer when importing
subdirectories
- Don't pass 'shell="/sbin/nologin"' to 'onlyif/unless' checks
(bsc#1188259)
- Add missing 'aarch64' to rpm package architectures
- Fix failing tests for 'CMDRunRedirect'
- Fix failing unit test for systemd
- Fix error handling in openscap module (bsc#1188647)
- Better handling of bad public keys from minions (bsc#1189040)
- Add standalone formulas configuration for salt minion and remove
salt-master requirement (bsc#1168327)
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-3161=1
Package List:
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
python3-salt-3002.2-50.1.12.1
salt-3002.2-50.1.12.1
salt-api-3002.2-50.1.12.1
salt-cloud-3002.2-50.1.12.1
salt-doc-3002.2-50.1.12.1
salt-master-3002.2-50.1.12.1
salt-minion-3002.2-50.1.12.1
salt-proxy-3002.2-50.1.12.1
salt-ssh-3002.2-50.1.12.1
salt-standalone-formulas-configuration-3002.2-50.1.12.1
salt-syndic-3002.2-50.1.12.1
salt-transactional-update-3002.2-50.1.12.1
- openSUSE Leap 15.3 (noarch):
salt-bash-completion-3002.2-50.1.12.1
salt-fish-completion-3002.2-50.1.12.1
salt-zsh-completion-3002.2-50.1.12.1
References:
https://bugzilla.suse.com/1168327https://bugzilla.suse.com/1188259https://bugzilla.suse.com/1188647https://bugzilla.suse.com/1189040
openSUSE Feature Update: Feature update for SUSE Manager 4.2.2 Proxy
______________________________________________________________________________
Announcement ID: openSUSE-FU-2021:3166-1
Rating: moderate
References:
Affected Products:
openSUSE Leap 15.3
______________________________________________________________________________
An update that has 0 feature fixes can now be installed.
Description:
This update provides the following package to SUSE Manager 4.2.2 Proxy
golang-github-prometheus-prometheus:
- golang-github-prometheus-prometheus is added to SUSE Manager Proxy as L3
supported.
Patch Instructions:
To install this openSUSE Feature Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-3166=1
Package List:
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
golang-github-prometheus-prometheus-2.27.1-3.10.1
References: