Packages changed: AppStream (1.1.5 -> 1.2.0) ca-certificates-mozilla (2.84 -> 2.90) crypto-policies libcanberra libvirt newt perl-Cpanel-JSON-XS (4.440.0 -> 4.520.0) pipewire (1.6.8 -> 1.6.9) python-greenlet (3.5.5 -> 3.5.6) python313 (3.13.14 -> 3.13.15) python313-core (3.13.14 -> 3.13.15) rpm salt snappy (1.2.2 -> 1.3.0) spice-gtk suitesparse (7.14.0 -> 7.14.1) === Details === ==== AppStream ==== Version update (1.1.5 -> 1.2.0) Subpackages: AppStream-lang libAppStreamQt3 libappstream5 - Update to 1.2.0 * This release marks the libappstream-compose API as stable. * This release introduces a new, lightly sandboxed (on Linux) media worker for appstream-compose and switches to VIPS for image processing. * This release introduces My headline! markup for AppStream descriptions. Older versions will remove this markup, so only use it if your target clients have a recent version of AppStream. Features: * compose: Create AscMedia for isolated out-of-process media handling using asc-mediaworker * compose: Process images, fonts & videos via the media worker * Generalize path segment validation, use it in the compose media worker * compose: Switch from using GdkPixbuf to VIPS for image processing * compose: Harmonize supported formats, don't read XPM/TIFF/BMP * compose: Make JPEG-XL the default image output format * compose: Implement basic support for FreeBSD * compose: Rely on VIPS for SVG support, drop our dedicated librsvg path * compose: Make image-targets and image batch-processing public API * compose: Expose the source-icon convention and a hint-tag lookup as public API * compose: Drop unstable-API marker * compose: Don't create image thumbnails that aren't substantially smaller * compose: Only transfer pre-opened fds and no more directory fd to the worker * compose: Implement a basic sandbox for the mediaworker using Landlock * compose: Use RESTRICT_SELF_TSYNC and block UDP access on newer Landlock * compose: Mix the output image format type into the GCID * compose: Make AscUnit a proper abstract class * compose: Improve API documentation * Always sanitize whitespaces in keywords and drop empty ones * Assume a language element without percentage means full translation * news-to-metainfo: Support a details URL in the YAML variant * news-convert: Support inline Markdown in news text * news-convert: Support headers in XML<->YAML/NEWS/Markdown conversions * ascli: news-convert: Support standalone release XML as source/target * Whitespace-sanitize all description markup we read * Output descriptions as literals in YAML and wrap markup ourselves Specification: * docs: Document the appstreamcli news file conversion helper * Implement support for headings in description markup Bugfixes: * meson: Set _POSIX_C_SOURCE on Linux only * compose: Fix a race where units were deleting each other's icon directories * compose: Fix documentation and introspection annotation issues * compose: Drop dead public API, make some API private * compose: Sharpen with libvips instead of a hand-rolled unsharp mask * compose: Only read AVIF from HEIF containers, never HEIC * compose: Fix double-free crash when processing fonts * compose: Guard against bad locale in path names * compose: Ensure component-IDs are safe to use in filesystem paths * compose: Escape values for HTML reports, and create proper plain-text if needed * compose: Make missing-launchable-desktop-file an error * Fix a few translator hints that weren't picked up properly * Don't accept empty strings as URLs * its: Fix description inline markup translation for release data * validator: Fix improper use of variadic arguments * validator: Properly validate component-IDs with random UTF-8 characters * validator: Abort ID validation after the first invalid character * pool: Resolve crash if data locations are changed on a loaded pool * Fix wrong string comparison when detecting arm64 machines * ascli: Resolve crash when selection is cancelled in install/remove * Fix another crash when converting invalid description markup to Markdown * apt: Treat icon tarballs as hostile, instead of trusted * apt: Fix empty-directory check nuking the icon cache on every refresh * utils: Ensure we never ever follow symlinks when recursively deleting caches * xml: Only emit description enumerations for locales that are in them * cache: Never infinite-recurse when resolving addons for a component * yaml: Don't leave old header data around when parsing multiple YAML catalogs Miscellaneous: * compose: Stop leaking private symbols out of the shared library ... changelog too long, skipping 22 lines ... * ascli: Guard against bad bundle values when calling "install" ==== ca-certificates-mozilla ==== Version update (2.84 -> 2.90) - Updated to 2.90 state (bsc#1279961) - Removed: - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - certSIGN ROOT CA - Entrust Root Certification Authority - PKI Root Certification Authority - FIRMAPROFESIONAL CA ROOT-A WEB - GLOBALTRUST 2020 - Secure Global CA - SecureSign Root CA12 - SecureTrust CA - TeliaSonera Root CA v1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - XRamp Global Certification Authority - Added: - SECOM SMIME RSA Root CA 2024 - SECOM TLS ECC Root CA 2024 - SECOM TLS RSA Root CA 2024 - SecureSign Root CA16 - Telia EC Email Root CA v3 - Telia EC TLS Root CA v3 - Telia RSA Email Root CA v3 - Telia RSA TLS Root CA v3 ==== crypto-policies ==== Subpackages: crypto-policies-scripts - Add configure-python-interpreter.patch removing dependency on `python3-base`, all Python scripts are now dependent on the primary Python interpreter directly without `/usr/bin/python3` mediation. ==== libcanberra ==== Subpackages: canberra-gtk-play libcanberra-gtk-module-common libcanberra-gtk0 libcanberra-gtk2-module libcanberra-gtk3-0 libcanberra-gtk3-module libcanberra0 - Migrate to xz compression and manual service run ==== libvirt ==== Subpackages: libvirt-client libvirt-daemon-common libvirt-daemon-config-network libvirt-daemon-driver-network libvirt-daemon-driver-nodedev libvirt-daemon-driver-qemu libvirt-daemon-driver-secret libvirt-daemon-driver-storage libvirt-daemon-driver-storage-core libvirt-daemon-driver-storage-disk libvirt-daemon-driver-storage-iscsi libvirt-daemon-driver-storage-iscsi-direct libvirt-daemon-driver-storage-logical libvirt-daemon-driver-storage-mpath libvirt-daemon-driver-storage-rbd libvirt-daemon-driver-storage-scsi libvirt-daemon-lock libvirt-daemon-log libvirt-daemon-plugin-lockd libvirt-daemon-qemu libvirt-libs - qemu: Fix missing audit record and shutdown lifecycle event of VMs with shutdown times exceeding 40 seconds bsc#1280884 - qemu: Fix hot plugged host CPUs not being used bsc#1279562 ==== newt ==== - Use %python3_version instead of the obsolete %py3_ver. ==== perl-Cpanel-JSON-XS ==== Version update (4.440.0 -> 4.520.0) - updated to 4.520.0 (4.52) see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes 4.52 2026-09-12 (rurban) - OSX 10.9 fix for SIMD UTF-8 (Christian Carey) - Change my maintainer email to reini.urban@gmail.com 4.51 2026-09-11 (rurban) - Add faster SIMD UTF-8 validation (GH #213, Zhang Boyang) https://github.com/cyb70289/utf8, MIT. - Fix tests for yath (GH #255, with H.Merijn Brand): the test files now work with Test2::Harness instead of only Test::Harness, and a yath run is added to `make xtest` when yath is installed. - Skip one t/117_numbers.t test on Perls with 32-bit IVs (GH #254, Jeremy Hansen). 4.50 2026-09-08 (rurban) - Add $json->encode_to($fh, $data, [$type]) to stream encoded JSON directly to a filehandle instead of building the whole result in memory (GH #250, requested by yairlenga. designed 2016 in GH #58). Internally flushes a bounded 8k chunk buffer as it fills, keeping peak memory bounded for large data structures. - Encoder performance improvements suggested in GH #237 (17dec): * Large-integer encoding now uses a 100-digit lookup table instead of snprintf, roughly 2x faster for integers outside the existing branchless small-integer fast path (|value| > 59000). * encode_str now bulk-copies runs of consecutive bytes that need no escaping instead of a need()+store per byte, notably faster for strings with few or no characters to escape. Added eg/bench_large.pl with results. ==== pipewire ==== Version update (1.6.8 -> 1.6.9) Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-jack pipewire-lang pipewire-libjack-0_3 pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Update to version 1.6.9: * This is a bugfix release that is API and ABI compatible with the previous 1.6.x releases. * Highlights - Improve JACK object callbacks, avoid reporting old removed objects. - Tweak the resampler cutoff frequencies to preserve more high frequencies when upsampling. - More small fixes and improvements. * Modules - Fix RAOP encryption for OpenSSL >= 3. (#5370 (closed)) - Fix netjack2 discovery timeout. - Fix potential truncated audio in RAOP. - Fix potential metadata update problems. (#5445 (closed)) - Fix RAOP over TCP. - Fix potential overflows in client node buffer checks. (#5462) - Add node.network=true to network sinks and sources so that pavucontrol and others don't wake them up. (#3268 (closed)) * SPA - Fix opus audio info type. - Tweak the upsample cutoff frequencies to preserve more high frequencies when upsampling. (#5390 (closed)) - Fix filter-graph property notification in some cases. - Remove limits on filter-graph descriptions in audioconvert. - Improve dynamic reconfiguration of filter-graphs in audioconvert. - Improve passthrough format handling in audioconvert. - Improve the FC and LFE volumes when upmixing is enabled. - Fix v4l2 controls when one can not be read. - Require 0.6.0 libcamera now. - Improve format filtering in v4l2. * Pulse-server - Don't let a pending sibling message starve capture. - Fix name of ALSA source. - Fix potential crash with the active_port_name. (#5435 (closed)) * Bluetooth - Fix a potential leak when transport fails to start. - Fix potential crash when cleaning up iso-io transport. * JACK - Rework the object lookups to avoid removed objects from leaking. (#5356 (closed)) * GStreamer - Add fixes for state changes and other lockups. * ALSA Plugin - Generate poll errors when stopping. (#5444 (closed)) * Tools - Handle EOF correctly for encoded files in pw-cat. - Fix loopback channel and position handling. - Fix mp3 encoding in pw-record. - Support A-law in pw-record. - Disable libcamera support when building in Leap 16.1 or older since pipewire now needs at least libcamera 0.6.0 . ==== python-greenlet ==== Version update (3.5.5 -> 3.5.6) - Update to 3.5.6 * Correct a race condition that could lead to garbage collection unintentionally being disabled. See PR 529 by Yurii. ==== python313 ==== Version update (3.13.14 -> 3.13.15) Subpackages: python313-curses python313-dbm python313-tk python313-x86-64-v3 - Restore back macros.python3, we need it. - CVE-2026-19672: in tarfile, handle a member that leaves the destination and comes back (bsc#1276227, gh#python/cpython#156000) CVE-2026-19672-tarfile-outside-dirs.patch CVE-2026-17084: Don't consider Unicode codepoint attributes outside RFC 3454 (bsc#1276226) CVE-2026-17084-unicode-rfc3454.patch - Add sphinx9-runtime-node.patch fixing documentation build with Sphinx 9 by importing the extension's Node type at runtime. - Restore the self-contained structure of the python313 package in openSUSE Factory: * the package has started to rely on the separate virtual `python3` package for the generic interpreter entry points and for the `python3*` Provides (bsc#1258364). That structure is meant for the SUSE Linux family of distros, it does not belong to Factory * python313 provides python3, python3-base and the other `python3*` virtual names again * python313 owns the python3 and pydoc3 binaries, the python3.1(1) man page, python3-config, libpython3.so and the unversioned pkg-config files again * python313 uses the rpm-build-python generated `python(abi)` Provides - Update to 3.13.15 - Tools/Demos - gh-155218: Fix Argument Clinic generating the flags of the optional groups in different order on 32-bit and 64-bit platforms. - gh-155207: Argument Clinic now supports the --dry-run and - -diff options. They list the files which would be changed, or write a unified diff of the changes to the standard output, without modifying any file. - gh-64502: Fix Argument Clinic support of parameters with a default value used together with optional groups. Such parameters were always required in the generated parsing code. - gh-154580: Fix python-gdb.py raising UnicodeEncodeError when pretty-printing a non-ASCII str in a locale whose host charset cannot encode it, such as any non-ASCII string in the C locale. - Tests - gh-76595: Add C API tests for PyCapsule_Import(). - gh-154167: The test runner (regrtest) now restores the default SIGINT handler if it was inherited as ignored, so the test suite no longer hangs when run as a shell background job. - gh-154144: Fix building the _testcapi module on NetBSD. - gh-152548: Add the test.support.isolation.runInSubprocess() decorator to run a test method or TestCase subclass in a fresh interpreter subprocess, isolated from the rest of the test run. - gh-151626: Fix several tests in test.test_inspect, test.test_import, test.test_importlib, test.test_py_compile and test.test_compileall that failed when the test suite was run with PYTHONPYCACHEPREFIX set. These tests now neutralize the pycache prefix where they assume the default __pycache__ bytecode layout. - gh-151096: Fix test_embed failing when CPython is configured with a split exec prefix (--exec-prefix differing from --prefix). - Security - gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service (bsc#1271192, CVE-2026-15308). - gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings (bsc#1273148, CVE-2026-6879). - gh-152216: Update bundled libexpat to version 2.8.2. - gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback (bsc#1269959, CVE-2026-4360). - gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached (bsc#1269788, CVE-2026-11972). - gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree. - gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330 (bsc#1268977, CVE-2026-11940). - gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4. - gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values (bsc#1269066, CVE-2026-0864). - gh-143921: Reject NUL, CR and LF characters in IMAP commands. Other control characters are allowed and sent quoted (bsc#1257044, CVE-2025-15366). - Library ... changelog too long, skipping 525 lines ... - reproducible_stencils.patch ==== python313-core ==== Version update (3.13.14 -> 3.13.15) Subpackages: libpython3_13-1_0 libpython3_13-1_0-x86-64-v3 python313-base python313-base-x86-64-v3 python313-devel - Restore back macros.python3, we need it. - CVE-2026-19672: in tarfile, handle a member that leaves the destination and comes back (bsc#1276227, gh#python/cpython#156000) CVE-2026-19672-tarfile-outside-dirs.patch CVE-2026-17084: Don't consider Unicode codepoint attributes outside RFC 3454 (bsc#1276226) CVE-2026-17084-unicode-rfc3454.patch - Add sphinx9-runtime-node.patch fixing documentation build with Sphinx 9 by importing the extension's Node type at runtime. - Restore the self-contained structure of the python313 package in openSUSE Factory: * the package has started to rely on the separate virtual `python3` package for the generic interpreter entry points and for the `python3*` Provides (bsc#1258364). That structure is meant for the SUSE Linux family of distros, it does not belong to Factory * python313 provides python3, python3-base and the other `python3*` virtual names again * python313 owns the python3 and pydoc3 binaries, the python3.1(1) man page, python3-config, libpython3.so and the unversioned pkg-config files again * python313 uses the rpm-build-python generated `python(abi)` Provides - Update to 3.13.15 - Tools/Demos - gh-155218: Fix Argument Clinic generating the flags of the optional groups in different order on 32-bit and 64-bit platforms. - gh-155207: Argument Clinic now supports the --dry-run and - -diff options. They list the files which would be changed, or write a unified diff of the changes to the standard output, without modifying any file. - gh-64502: Fix Argument Clinic support of parameters with a default value used together with optional groups. Such parameters were always required in the generated parsing code. - gh-154580: Fix python-gdb.py raising UnicodeEncodeError when pretty-printing a non-ASCII str in a locale whose host charset cannot encode it, such as any non-ASCII string in the C locale. - Tests - gh-76595: Add C API tests for PyCapsule_Import(). - gh-154167: The test runner (regrtest) now restores the default SIGINT handler if it was inherited as ignored, so the test suite no longer hangs when run as a shell background job. - gh-154144: Fix building the _testcapi module on NetBSD. - gh-152548: Add the test.support.isolation.runInSubprocess() decorator to run a test method or TestCase subclass in a fresh interpreter subprocess, isolated from the rest of the test run. - gh-151626: Fix several tests in test.test_inspect, test.test_import, test.test_importlib, test.test_py_compile and test.test_compileall that failed when the test suite was run with PYTHONPYCACHEPREFIX set. These tests now neutralize the pycache prefix where they assume the default __pycache__ bytecode layout. - gh-151096: Fix test_embed failing when CPython is configured with a split exec prefix (--exec-prefix differing from --prefix). - Security - gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service (bsc#1271192, CVE-2026-15308). - gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings (bsc#1273148, CVE-2026-6879). - gh-152216: Update bundled libexpat to version 2.8.2. - gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback (bsc#1269959, CVE-2026-4360). - gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached (bsc#1269788, CVE-2026-11972). - gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree. - gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330 (bsc#1268977, CVE-2026-11940). - gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4. - gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values (bsc#1269066, CVE-2026-0864). - gh-143921: Reject NUL, CR and LF characters in IMAP commands. Other control characters are allowed and sent quoted (bsc#1257044, CVE-2025-15366). - Library ... changelog too long, skipping 525 lines ... - reproducible_stencils.patch ==== rpm ==== Subpackages: librpmbuild10 rpm-plugin-selinux - Don’t be dependent on python3-base, it is perfectly OK to use any Python interpreter for python-rpm-packaging. - Remove obsolete Python2-based removal of Python directories (why?) ==== salt ==== Subpackages: python313-salt salt-master salt-minion - Ignore release if not specified in the pkg state (bsc#1280289) - Added: * ignore-release-if-not-specified-in-the-pkg-state-bsc.patch - Stabilize testsuite - Added: * stabilize-testsuite-784.patch ==== snappy ==== Version update (1.2.2 -> 1.3.0) - Update to 1.3.0: * Fixed a uint32_t overflow when decompressor accepted an input with incorrect format * Significant RISC-V efficiency improvements * New API on providing your own memory context * Supporting compression levels (1-2) in C API * Various other small fixes - Refresh reenable-rtti.patch - Disable LiteralLengthU32Overflow test in 32 bit architectures ==== spice-gtk ==== Subpackages: libspice-client-glib-2_0-8 libspice-client-glib-helper libspice-client-gtk-3_0-5 - Add 3f85c57.patch: spice-widget: update cairo scale when output scale changes. ==== suitesparse ==== Version update (7.14.0 -> 7.14.1) Subpackages: libamd3 libcamd3 libccolamd3 libcholmod5 libcolamd3 libsuitesparseconfig7 libumfpack6 - Update to 7.14.1 * GraphBLAS 10.5.1: bug fix