aboutsummaryrefslogtreecommitdiff
path: root/libs
Commit message (Collapse)AuthorAge
...
* glib2: use internal pcre2Rosen Penev2024-02-14
| | | | | | | For some strange reason, glib2 does not link properly with a static pcre2. Work around by bundling own copy. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* libstrophe: Specify correct PKG_LICENSEAndreas Gnau2024-02-14
| | | | | | | | libstrophe is dual-licensed as MIT OR GPL-3.0-only, which is also reflected by the SPDX-License-Identifier lines in the source files. Correct PKG_LICENSE in the Makefile accordingly. Signed-off-by: Andreas Gnau <andreas.gnau@iopsys.eu>
* redis: update to 6.2.14Rosen Penev2024-02-12
| | | | | | Fixes CVE-2022-24735 and CVE-2022-24736 Signed-off-by: Rosen Penev <rosenp@gmail.com>
* libusb-compat: update to 0.1.8krant2024-02-12
| | | | | | - Update package URL Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* zlog: update to 1.2.17Rosen Penev2024-02-11
| | | | | | | | | | | | Rework to use local tarballs. Smaller and more stable. Build with cmake. Faster and simpler. Needs a small patch though. License was updated. Fixes CVE-2021-43521 Signed-off-by: Rosen Penev <rosenp@gmail.com>
* libmicrohttpd: update to 0.9.77Rosen Penev2024-02-11
| | | | | | Fixes CVE-2023-27371 Signed-off-by: Rosen Penev <rosenp@gmail.com>
* libao: backport fix for CVE-2017-11548Rosen Penev2024-02-11
| | | | Signed-off-by: Rosen Penev <rosenp@gmail.com>
* yajl: backport CVE-2023-33460 fixRosen Penev2024-02-11
| | | | | | Removed old uclibc patches. Not relevant with modern musl or glibc. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* postgesql: update to 15.6Rosen Penev2024-02-12
| | | | | | Fixes CVE-2023-39417 and CVE-2023-39418 Signed-off-by: Rosen Penev <rosenp@gmail.com>
* confuse: fix CVE-2022-40320Rosen Penev2024-02-10
| | | | Signed-off-by: Rosen Penev <rosenp@gmail.com>
* giflib: fix CVEsRosen Penev2024-02-10
| | | | | | Patches taken from Fedora Signed-off-by: Rosen Penev <rosenp@gmail.com>
* avahi: backport CVE fixes from upstreamRosen Penev2024-02-10
| | | | Signed-off-by: Rosen Penev <rosenp@gmail.com>
* libvpx: update to 1.14.0Rosen Penev2024-02-10
| | | | | | Fixes CVE-2023-5217 Signed-off-by: Rosen Penev <rosenp@gmail.com>
* libssh2: update to 1.11.0Rosen Penev2024-02-10
| | | | | | Fixes CVE-2020-22218 Signed-off-by: Rosen Penev <rosenp@gmail.com>
* libx264: update to 2024-01-13 revisionkrant2024-02-10
| | | | | | | - Fix CPU type detection to enable asm on ARM - Refresh patches Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libfido2: update to 1.14.0krant2024-02-10
| | | | | | - Don't set default and remove obsolete CMake options Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libcbor: update to 0.11.0krant2024-02-10
| | | | Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* file: update to 5.45krant2024-02-10
| | | | | | - Remove default and non-existent configure options Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* cjson: update to 1.7.17krant2024-02-10
| | | | Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* json-glib: update to 1.8.0krant2024-02-10
| | | | | | - Don't set default Meson option Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libextractor: update to 1.13krant2024-02-10
| | | | | | | - Remove obsolete configure option - Remove patch and var override since MEM_SRCDST_SUPPORTED is always on Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* glib2: update to 2.78.4krant2024-02-09
| | | | | | | | | - Use HTTPS for package URL - Don't set default Meson options - Remove upstreamed patch - Refresh remaining patches Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* apr-util: update to 1.6.3krant2024-02-07
| | | | | | | - Remove upstreamed patches - Fix OS path leak in iconv configure script Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libfastjson: update to 1.2304.0krant2024-02-07
| | | | | | - Use HTTPS for source URL Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libffi: update to 3.4.4krant2024-02-07
| | | | | | | | - Use proper tarball URL - Use HTTPS for package URL - Don't set default configure option Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libinput: update to 1.25.0krant2024-02-07
| | | | | | | | - Switch sources to git since no proper tarball is available - Switch URL to HTTPS - Don't set default Meson options Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* xmlrpc-c: install dev files only with 1st variantEneas U de Queiroz2024-02-07
| | | | | | | | | | | | | This adds a variant check to run InstallDev only when the first variant is built. Otherwise, a dependent package may install the default version, even though the second variant ends up in the staging dir, causing downstream packages to miss library dependencies, such as: Package rtorrent-rpc is missing dependencies for the following libraries: libxmlrpc_xmlparse.so.3 libxmlrpc_xmltok.so.3 Signed-off-by: Eneas U de Queiroz <cotequeiroz@gmail.com>
* openldap: update to 2.6.7krant2024-02-07
| | | | | | | - Remove dead mirror URL - Clean-up configure args Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* lmdb: update to 0.9.32krant2024-02-07
| | | | | | | - Switch to git source URL - Rebase the patch Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* minizip: update to 4.0.4krant2024-02-07
| | | | | | | - Don't set default cmake option - Switch URL to the official one Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* apr: update to 1.7.4krant2024-02-07
| | | | | | | - Remove upstreamed patches - Fix bindir in apr-1-config to fix subversion build Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* alsa-ucm-conf: update to 1.2.11krant2024-02-07
| | | | Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* alsa-lib: update to 1.2.11krant2024-02-07
| | | | | | | - Change package URL to HTTPS - Refresh patches Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libarchive: update to 3.7.2krant2024-02-07
| | | | | | - Don't set CMake options matching the defaults Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* expat: update to 2.6.0krant2024-02-07
| | | | | | - Don't set default CMake options Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libmariadb: update to 3.1.23krant2024-02-07
| | | | | | | | - Replace dead source URL - Rebase the patch - Remove superfluous cmake option Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libid3tag: update to 0.16.3krant2024-02-06
| | | | | | | | | - Switch package URL to the new upstream - Switch PKG_SOURCE_PROTO to git - Switch to CMake build - Drop custom .pc file in favor of upstream version Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* oniguruma: bump to 6.9.9Eneas U de Queiroz2024-02-05
| | | | | | | | | | | | | | | | | | | | Featured changes: - Update Unicode version 15.1.0 - NEW API: ONIG_OPTION_MATCH_WHOLE_STRING - Fixed: (?I) option was not enabled for character classes (Issue #264). - Changed specification to check for incorrect POSIX bracket (Issue #253). - Changed [[:punct:]] in Unicode encodings to be compatible with POSIX definition. (Issue #268) - Fixed: ONIG_OPTION_FIND_LONGEST behavior --- 6.9.8 - Whole options - (?C) : ONIG_OPTION_DONT_CAPTURE_GROUP - (?I) : ONIG_OPTION_IGNORECASE_IS_ASCII - (?L) : ONIG_OPTION_FIND_LONGEST - Fixed some problems found by OSS-Fuzz Signed-off-by: Eneas U de Queiroz <cotequeiroz@gmail.com>
* opus: update to 1.4krant2024-02-05
| | | | | | | - Add patch to fix build on ARM - Use official source URL Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libsamplerate: update to 0.2.2krant2024-02-04
| | | | | | | - Update package/source URLs to official ones - Change license according to upstream Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* freetype: update to 2.13.2krant2024-02-04
| | | | | | - change package URL to HTTPS Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libmaxminddb: update to 1.9.1krant2024-02-04
| | | | Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libstrophe: update 0.13.0krant2024-02-04
| | | | | | | - Use common Github URL - Add missing zlib dependency Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libsndfile: update to 1.2.2krant2024-02-04
| | | | | | | | | | - Update package URL to the official one - Update source URL to the official one - Modernize CMake options - Fixup pkgconfig file - Enable mpg123 support per users request (+7kB) Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* treewide: assign PKG_CPE_IDFabrice Fontaine2024-02-04
| | | | Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
* leptonica: update to 1.84.1krant2024-02-04
| | | | | | | | - remove upstreamed patch - explicitly disable openjpeg to ignore host-installed library - fix .cmake and .pc paths Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* flac: update to 1.4.3krant2024-02-04
| | | | Signed-off-by: krant <aleksey.vasilenko@gmail.com>
* libs/libidn2: fix PKG_CPE_IDFabrice Fontaine2024-02-04
| | | | | | | | | | There is not a single CVE linked to libidn2_project:libidn2 so use gnu:libidn2 instead: https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:gnu:libidn2 Fixes: ceadbcbb64de727c3a974e552d9a723d532e4e40 (treewide: add PKG_CPE_ID for cvescanner) Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
* libs/expat: fix PKG_CPE_IDFabrice Fontaine2024-02-04
| | | | | | | | | | | There is not a single CVE linked to libexpat:expat so use libexpat_project:libexpat instead: https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:libexpat_project:libexpat Fixes: 70c62ef2d77aef5d8a27ccca2b147bc2a69dc7f8 (expat: update to version 2.2.7 (security fix)) Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
* libs/redis: fix PKG_CPE_IDFabrice Fontaine2024-02-04
| | | | | | | | | | There is not a single CVE linked to pivotal_software:redis so use redis:redis instead: https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:redis:redis Fixes: ceadbcbb64de727c3a974e552d9a723d532e4e40 (treewide: add PKG_CPE_ID for cvescanner) Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>