All posts by jake

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/1004543/

Security updates have been issued by AlmaLinux (cups, kernel, and kernel-rt), Debian (chromium, firefox-esr, and webkit2gtk), Fedora (curl, firefox, gimp, mupdf, openjpeg2, and valkey), Red Hat (389-ds-base, cups, firefox, iperf3, kernel, kernel-rt, libreswan, python3.11-urllib3, thunderbird, and webkit2gtk3), Slackware (firefox, seamonkey, and thunderbird), SUSE (apptainer, firefox-esr, libopenjp2-7, libruby3_4-3_4, openjpeg2, and tomcat10), and Ubuntu (firefox, linux-azure, linux-azure, linux-azure-4.15, linux-azure, linux-azure-6.8, linux-azure, linux-intel-iotg-5.15, linux-azure-5.15, python2.7, thunderbird, and xfpt).

[$] Emacs in Scheme

Post Syndicated from jake original https://lwn.net/Articles/1001929/

During EmacsConf 2024, which
was held online in early December 2024, Ramin Honary gave a talk about Project
Gypsum
, which is his effort to rewrite Emacs in Scheme. Unlike most other Emacs clones,
which simply replicate the key bindings, Gypsum is also implementing Emacs
Lisp
(or Elisp). Honary is initially targeting Guile, which is an
implementation of Scheme, but wants to make the code portable
to any implementation of R7RS Scheme.

Ruby 3.4 released

Post Syndicated from jake original https://lwn.net/Articles/1003547/

Continuing its tradition of yearly major releases on December 25, the Ruby programming-language project
has released
Ruby 3.4.0
(followed quickly by 3.4.1,
which simply updates the version number). Ruby 3.4 includes lots of
changes, including the addition of it as a
less-confusing shorthand for _1 as a block parameter, switching to
Prism as the default
parser
, adding the Happy Eyeballs
version 2
algorithm to the socket library,
just-in-time (JIT) compiler (YJIT) improvements, garbage-collection
modularization, and more.

[$] Tim Peters returns to the Python community

Post Syndicated from jake original https://lwn.net/Articles/1002340/

In the past, suspensions of Python core developers have effectively been
permanent because the recipients of the punishment chose not to return.
Things have played out quite differently after Tim Peters was suspended for three months back in August;
Peters has been posting to the Python discussion forum since his suspension
ended in early November and, generally, getting back to work as usual.
That does not mean that he—or others in the community—have accepted the way
he was treated, but he has largely made his peace with it. The incident is
still reverberating through the Python world, however.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/1003287/

Security updates have been issued by Debian (gst-plugins-base1.0, libxstream-java, php-laravel-framework, python-urllib3, and sqlparse), Fedora (chromium, libcomps, libdnf, mingw-directxmath, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, mingw-orc, ofono, prometheus-podman-exporter, python3-docs, python3.13, and webkitgtk), Mageia (mozjs78, thunderbird, and tomcat, tomcat packages), SUSE (aalto-xml, flatten-maven-plugin, jctools, moditect, netty, netty-tcnative, chromedriver, govulncheck-vulndb, grpc, kernel, python-aiohttp, python-python-sql, and vim), and Ubuntu (linux, linux-gkeop, linux-ibm, linux-ibm-5.15, linux-kvm,
linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle-5.15 and linux-aws, linux-aws-5.4, linux-bluefield, linux-ibm, linux-ibm-5.4,
linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp).

[$] Using Guile for Emacs

Post Syndicated from jake original https://lwn.net/Articles/1001645/

Emacs is, famously, an
editor—perhaps far more—that is extensible using its own
variant of the Lisp programming language, Emacs
Lisp
(or Elisp). This year’s
edition of EmacsConf
, which is an annual “gathering” that has been held
online for the past five years, had two separate talks on using a different
variant of Lisp, Guile,
for Emacs. Both projects would preserve Elisp compatibility, which is a
must, but they would use Guile differently. The first talk we will cover
was given by Robin Templeton, who described the relaunch of the Guile-Emacs project, which would replace
the Elisp in Emacs with a compiler using Guile. A subsequent article will look
at the other talk, which is about an Emacs clone written
using Guile.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/1002338/

Security updates have been issued by Debian (gst-plugins-base1.0, gstreamer1.0, and libpgjava), Fedora (bpftool, chromium, golang-x-crypto, kernel, kernel-headers, linux-firmware, pytest, python3.10, subversion, and thunderbird), Gentoo (NVIDIA Drivers), Oracle (kernel, perl-App-cpanminus:1.7044, php:7.4, php:8.1, php:8.2, postgresql, python3.11, python3.12, python3.9:3.9.21, python36:3.6, ruby, and ruby:2.5), SUSE (docker-stable, firefox-esr, gstreamer, gstreamer-plugins-base, gstreamer-plugins-good, kernel, python-Django, python312, and socat), and Ubuntu (mpmath).

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/1001863/

Security updates have been issued by Debian (libsoup2.4, python-aiohttp, and upx-ucl), Fedora (iaito, python3.11, python3.9, and radare2), Red Hat (ruby, ruby:2.5, and ruby:3.1), Slackware (mozilla-thunderbird), SUSE (govulncheck-vulndb, nodejs18, nodejs20, and socat), and Ubuntu (ofono and python-tornado).

[$] A Zephyr-based camera trap for seagrass monitoring

Post Syndicated from jake original https://lwn.net/Articles/998893/

In a session at
Open Source Summit Europe
(OSSEU) back in September, Alex Bucknall gave an overview of a camera “trap”—a
device to capture images in a non-intrusive way—that he helped develop
which is being used to monitor seagrass. He works for
the Arribada Initiative, which is a
non-profit organization
focused on creating open-source technology for studying wildlife and ecosystems.
The camera system uses the Zephyr
realtime operating system (RTOS) on an open platform that is designed to be
inexpensive and usable for multiple applications.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/1001433/

Security updates have been issued by AlmaLinux (redis:7, ruby, ruby:2.5, and ruby:3.1), Debian (avahi, ceph, chromium, gsl, jinja2, php7.4, renderdoc, ruby-doorkeeper, and zabbix), Fedora (chromium, python3.11, and uv), Gentoo (Asterisk, Cacti, Chromium, Google Chrome, Microsoft Edge. Opera, Dnsmasq, firefox, HashiCorp Consul, icinga2, OATH Toolkit, OpenJDK, PostgreSQL, R, Salt, Spidermonkey, and thunderbird), Mageia (kubernetes), Red Hat (grafana, grafana-pcp, osbuild-composer, and postgresql), SUSE (ansible-core, firefox, glib2, java-1_8_0-ibm, kernel-firmware, nanopb, netty, python310-django-ckeditor, python310-jupyter-ydoc, radare2, skopeo, and webkit2gtk3), and Ubuntu (tinyproxy).

Stable kernels 6.12.2, 6.11.11, and 4.19.325

Post Syndicated from jake original https://lwn.net/Articles/1000871/

Greg Kroah-Hartman has released the 6.12.2, 6.11.11, and 4.19.325 stable kernels. Note that both
6.11.11 and 4.19.325 are the last kernels in those series, “please move
off to a newer kernel version
“. In the 4.19.325 release notice, he has
a rather longer-than-usual message, including:

As a “fun” proof that this one is finished (and that any company saying
they care about it really should have their statements validated with
facts), I looked at the “unfixed” CVEs from this kernel release.
Currently it is a list 983 CVEs long, too long to list here.

You can verify it yourself by cloning the vulns.git repo at
git.kernel.org and running:

	./scripts/strak v4.19.325

Note, this does NOT count the hardware CVEs which kernel.org does not
track, and many are sill unfixed in this kernel branch.

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/1000870/

Security updates have been issued by Fedora (thunderbird, tuned, and webkitgtk), Mageia (python-aiohttp and qemu), Oracle (container-tools:ol8, firefox, java-1.8.0-openjdk, java-11-openjdk, kernel, kernel:4.18.0, krb5, pam, postgresql:16, python-tornado, python3:3.6.8, thunderbird, tigervnc, tuned, and webkit2gtk3), Red Hat (bzip2, postgresql, postgresql:13, postgresql:15, postgresql:16, python-tornado, and ruby:3.1), Slackware (python3), SUSE (postgresql, postgresql16, postgresql17, postgresql13, postgresql14, postgresql15, python-python-multipart, and python3), and Ubuntu (python-django and recutils).

NixOS 24.11 released

Post Syndicated from jake original https://lwn.net/Articles/1000469/

The most recent version of NixOS, 24.11,
was released
on November 30. It contains GNOME 47, Plasma 6.2, LLVM 19, and lots more:

The 24.11 release was made possible due to the efforts of 2669 contributors, who authored 49079 commits since the previous release. Our thanks go the contributors who also take care of the continued stability and security of our stable release.

NixOS is already known as the most up to date distribution while also being the distribution with the most packages. This release saw 8141 new packages and 20975 updated packages in Nixpkgs. We also removed 3970 packages in an effort to keep the package set maintainable and secure.