All posts by jzb

[$] Dependency-cooldown discussions warm up

Post Syndicated from jzb original https://lwn.net/Articles/1068692/

Efforts to introduce malicious code into the open-source supply
chain have been on the rise in recent years, and there is no indication that they
will abate anytime soon. These attacks are often found quickly, but not quickly
enough to prevent the compromised code from being automatically injected into other
projects or code deployed by users where it can wreak havoc. One method of avoiding
supply-chain attacks is to add a delay of a few days before pulling upates in what
is known as a “dependency cooldown”. That tactic is starting to find favor with
users and some language ecosystem package managers. While this practice is
considered a reasonable response by many, others are complaining that those
employing dependency cooldowns are free-riding on the larger community by letting
others take the risk.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1069105/

Security updates have been issued by Debian (firefox-esr, flatpak, ngtcp2, ntfs-3g, packagekit, python-geopandas, simpleeval, strongswan, and xdg-dbus-proxy), Fedora (chromium, cups, curl, jq, opkssh, perl-Net-CIDR-Lite, python-cbor2, python-pillow, tinyproxy, xdg-dbus-proxy, and xorg-x11-server-Xwayland), Slackware (libXpm and mozilla), SUSE (botan, chromium, clamav, cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-subscriptions, dovecot24, firefox, flatpak, freeipmi, gdk-pixbuf, glibc, gnome-remote-desktop, go1.25, go1.26, go1.26-openssl, google-cloud-sap-agent, gosec, graphicsmagick, haproxy, kernel, libpng16, libraw, libtasn1, libvncserver, ncurses, nebula, nodejs24, openssl-3, ovmf, pam, pcre2, perl-Authen-SASL, pgvector, plexus-utils, podman, python-cbor2, python-cryptography, python-django, python-gi-docgen, python-pypdf2, python-python-multipart, python311, python311-PyPDF2, python313, qemu, roundcubemail, rust1.94, sqlite3, strongswan, systemd, tar, tigervnc, util-linux, vim, webkit2gtk3, xorg-x11-server, xwayland, and zlib), and Ubuntu (commons-io, libcap2, ntfs-3g, and rapidjson).

Fedora Verified: a proposal to recognize Fedora contributor status

Post Syndicated from jzb original https://lwn.net/Articles/1068861/

The Fedora Project has been wrestling with the question of who should be able to vote in
Fedora elections
recently, with project membership being a major topic at
the Fedora Council face-to-face
held in early February. Now the
project is considering a new contributor status, “Fedora Verified”,
and is looking
to get input
on the idea from the community.

What are the proposed benefits? The primary motivation behind
“Fedora Verified” is to build trust-based recognition that grants
elevated, privileged rights within the project. Most notably, this
status would determine eligibility for strategic governance
activities, such as:

  • Voting in Fedora community elections.
  • Running for leadership or decision-making roles within the project
    (i.e., Fedora Council, FESCo, Mindshare Committee, EPEL Steering
    Committee).
  • (Potential, unplanned) Accessing specific shared project resources
    or educational opportunities (e.g., Red Hat training credits).

The blog post includes a list of proposed baseline metrics for
“Verified” status as well as open questions to be decided. A survey
on the topic
will be open until May 5.

Firefox 150 released

Post Syndicated from jzb original https://lwn.net/Articles/1068839/

Version
150
of the Firefox web browser has been released. Notable changes
include local-network-access
restrictions
being turned on for all users, the ability to
reorder, copy, delete, paste, and export pages from a PDF using
Firefox’s built-in viewer, as well as improvements in its split
view
feature, and more. See also the release
notes for developers
and list
of security fixes
in this release.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1068830/

Security updates have been issued by AlmaLinux (freerdp, kernel, and kernel-rt), Debian (mupdf, opam, simpleeval, and xdg-dbus-proxy), Mageia (firefox, thunderbird and libtiff), Red Hat (containernetworking-plugins, gvisor-tap-vsock, nodejs22, nodejs:20, nodejs:22, perl-XML-Parser, python3.11, python3.9, runc, and skopeo), and SUSE (bind, buildah, cockpit-subscriptions, container-suseconnect, containerd, corosync, cosign, docker, dovecot24, flatpak, freeipmi, gegl, GraphicsMagick, helm, ImageMagick, kubernetes, kubernetes-old, libpng15, LibVNCServer, ncurses, nodejs22, opensc, openvswitch, patterns-glibc-hwcaps, podman, python, python310, python312, python315, rekor, rootlesskit, roundcubemail, and runc).

Git 2.54.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1068703/

Git maintainer Junio Hamano has announced
Git 2.54.0, which includes contributions from 137 people; 66 of those
people are first-time contributors to the project. Changes include the
addition of Git history rewriting, Git’s web interface (gitweb)
has been taught to be mobile friendly“, and much more. See the
announcement for all improvements, additions, and bug fixes. Hamano
is now taking a short break:

I will go offline for a couple of weeks starting this evening,
hopefully after updating ‘next’ and possibly also pushing out the
first batch of the new cycle. There is no designated interim
maintainer this time, but I trust that the community can self
organize during my absense, if the shape of the release and the tree
turns out to be super bad ;-).

Arch Linux now has a reproducible container image

Post Syndicated from jzb original https://lwn.net/Articles/1068699/

Robin Candau has announced
the availability of a bit-for-bit reproducible container image for
Arch Linux:

The bit-for-bit reproducibility of the image is confirmed by digest
equality across builds (podman inspect --format '{{.Digest}}'
<image>
) and by running diffoci
to compare builds. We provide documentation on how to reproduce this
Docker image
(as we did for the WSL image as well).

Building the base rootFS for the Docker image in a deterministic way was
the main challenge, but it reuses the same process as for our WSL image
(as both share the same rootFS build system).

[…] This represents another meaningful achievement in our
“reproducible builds” efforts and we’re already looking forward to the
next step!

[$] Digging into drama at The Document Foundation

Post Syndicated from jzb original https://lwn.net/Articles/1066418/

The Document Foundation (TDF) is
the nonprofit entity behind the LibreOffice productivity suite. Most of the
time, the software takes the spotlight, but that has changed in the past few weeks, and
not for pleasant reasons. TDF has revoked
foundation membership status
from about 30 people who work for or have
contracting status with Collabora. In
response, Collabora has announced
plans to focus on a “entirely new, cut-down, differentiated Collabora Office
project and reduce its involvement with LibreOffice. TDF’s representatives claim that
its actions were necessary to maintain the foundation’s nonprofit status, while other
community members assert that this is part of a power grab. The facts seem to
indicate that there are legitimate issues to be addressed, but it is unclear
that TDF needed to go so far as to disenfranchise all Collabora-affiliated contributors.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1068681/

Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, delve, freerdp, giflib, go-rpm-macros, libarchive, and openexr), Debian (gimp, imagemagick, luanti, mapserver, mupdf, opam, perl, pillow, postgresql-13, and tiff), Fedora (aqualung, awstats, curl, incus, mac, mbedtls, mingw-LibRaw, python-msal, python3.11, python3.12, python3.15, smb4k, stb, and usd), Gentoo (DTrace and FUSE), Mageia (gdk-pixbuf2.0, giflib, polkit-122, python-cairosvg, and rsync), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, 389-ds-base, bind, freerdp, go-rpm-macros, kernel, libarchive, nodejs:20, openexr, perl:5.32, python, python3, squid:4, thunderbird, and uek-kernel), Slackware (tigervnc), and SUSE (aardvark-dns, avahi, bind, blender, Botan, bouncycastle, chromedriver, cpp-httplib-devel, flannel, gdk-pixbuf, GraphicsMagick, ignition, ImageMagick, jetty-annotations, jetty-minimal, kernel, kubo, leancrypto-devel, libcap, liblog4cxx-devel, libpng16-16, libraw, libraw-devel, NetworkManager, opam, openssl-3, openvswitch, openvswitch3, podman, polkit, python-cryptography, python-djangorestframework, python-Django, python-ecdsa, python311-Django, python311-jwcrypto, python311-Pillow, roundcubemail, skopeo, tempo-cli, and vim).

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1068400/

Security updates have been issued by AlmaLinux (.NET 8.0, .NET 9.0, freerdp, libarchive, and thunderbird), Debian (chromium, openssh, and thunderbird), Fedora (aurorae, bluedevil, breeze-gtk, buildah, cockpit, extra-cmake-modules, flatpak-kcm, grub2-breeze-theme, kactivitymanagerd, kcm_wacomtablet, kde-cli-tools, kde-gtk-config, kdecoration, kdeplasma-addons, kf6, kf6-attica, kf6-baloo, kf6-bluez-qt, kf6-breeze-icons, kf6-frameworkintegration, kf6-kapidox, kf6-karchive, kf6-kauth, kf6-kbookmarks, kf6-kcalendarcore, kf6-kcmutils, kf6-kcodecs, kf6-kcolorscheme, kf6-kcompletion, kf6-kconfig, kf6-kconfigwidgets, kf6-kcontacts, kf6-kcoreaddons, kf6-kcrash, kf6-kdav, kf6-kdbusaddons, kf6-kdeclarative, kf6-kded, kf6-kdesu, kf6-kdnssd, kf6-kdoctools, kf6-kfilemetadata, kf6-kglobalaccel, kf6-kguiaddons, kf6-kholidays, kf6-ki18n, kf6-kiconthemes, kf6-kidletime, kf6-kimageformats, kf6-kio, kf6-kirigami, kf6-kitemmodels, kf6-kitemviews, kf6-kjobwidgets, kf6-knewstuff, kf6-knotifications, kf6-knotifyconfig, kf6-kpackage, kf6-kparts, kf6-kpeople, kf6-kplotting, kf6-kpty, kf6-kquickcharts, kf6-krunner, kf6-kservice, kf6-kstatusnotifieritem, kf6-ksvg, kf6-ktexteditor, kf6-ktexttemplate, kf6-ktextwidgets, kf6-kunitconversion, kf6-kuserfeedback, kf6-kwallet, kf6-kwidgetsaddons, kf6-kwindowsystem, kf6-kxmlgui, kf6-modemmanager-qt, kf6-networkmanager-qt, kf6-prison, kf6-purpose, kf6-qqc2-desktop-style, kf6-solid, kf6-sonnet, kf6-syndication, kf6-syntax-highlighting, kf6-threadweaver, kgamma, kglobalacceld, kinfocenter, kmenuedit, knighttime, kpipewire, krdp, kscreen, kscreenlocker, ksshaskpass, ksystemstats, kwayland, kwayland-integration, kwin, kwin-x11, kwrited, layer-shell-qt, libexif, libkscreen, libksysguard, libplasma, nix, ocean-sound-theme, oxygen-sounds, pam-kwallet, plasma-activities, plasma-activities-stats, plasma-breeze, plasma-browser-integration, plasma-desktop, plasma-dialer, plasma-discover, plasma-disks, plasma-drkonqi, plasma-firewall, plasma-integration, plasma-keyboard, plasma-login-manager, plasma-milou, plasma-mobile, plasma-nano, plasma-nm, plasma-oxygen, plasma-pa, plasma-print-manager, plasma-sdk, plasma-setup, plasma-systemmonitor, plasma-systemsettings, plasma-thunderbolt, plasma-vault, plasma-welcome, plasma-workspace, plasma-workspace-wallpapers, plasma-workspace-x11, plasma5support, plymouth-kcm, plymouth-theme-breeze, podman, polkit-kde, powerdevil, qqc2-breeze-style, sddm-kcm, skopeo, spacebar, spectacle, thunderbird, and xdg-desktop-portal-kde), Mageia (cockpit-338), Oracle (capstone, cockpit, firefox, fontforge, freerdp, golang-github-openprinting-ipp-usb, kernel, nghttp2, nodejs:20, nodejs:24, openexr, and squid), Red Hat (gnutls, libarchive, libpng, libpng12, libpng15, libtiff, libvpx, libxslt, multiple packages, python, python3, python3.11, python3.12, and python3.9), Slackware (libxml2), SUSE (apache-pdfbox, azure-storage-azcopy, corosync, cups, freerdp, iproute2, libsdb2_4_2, libtpms, NetworkManager, openssl-1_1, ovmf, plexus-utils, python, python-CairoSVG, python-jwcrypto, python-PyJWT, python-pyOpenSSL, python-urllib3, python3, python314, rust1.93, shim, smc-tools, terraform-provider-local, terraform-provider-random, terraform-provider-tls, thunderbird, tiff, util-linux, and vim), and Ubuntu (libowasp-esapi-java, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gke, linux-gkeop, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gke, linux-gkeop, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux, linux-realtime, linux-aws-fips, linux-fips, linux-gcp-fips, linux-fips, linux-gcp-fips, linux-gcp, linux-gcp-6.17, linux-hwe-5.15, linux-intel-iot-realtime, linux-realtime, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-nvidia-tegra, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-realtime, linux-realtime-6.8, linux-realtime-6.17, ofono, and ruby-rack).

Forgejo 15.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1068001/

Version
15.0
of the Forgejo
code-collaboration platform has been released. Changes include
repository-specific access tokens, a number of improvements to Forgejo
Actions
, user-interface enhancements, and more. Forgejo 15.0 is
considered a long-term-support (LTS) release, and will be supported
through July 15, 2027. The previous LTS, version 11.0, will reach end
of life on July 16, 2026. See the announcement and release
notes
for a full list of changes.

KDE Gear 26.04 released

Post Syndicated from jzb original https://lwn.net/Articles/1067994/

Version 26.04 of
the KDE Gear collection of applications has been released. Notable changes
include improvements in the Merkuro
Calendar
schedule view and event editor, support for threads in the NeoChat Matrix chat client, as well as
the ability to add keyboard shortcuts in the Dolphin file manager “to nearly any
option in any menu, plugin or extension
“. See the changelog for
a full list of updates, enhancements, and bug fixes.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1067993/

Security updates have been issued by AlmaLinux (bind, bind9.16, bind9.18, cockpit, fence-agents, firefox, fontforge, git-lfs, grafana, grafana-pcp, kernel, nghttp2, nginx, nginx:1.24, nginx:1.26, nodejs:20, nodejs:22, nodejs:24, pcs, perl-XML-Parser, perl:5.32, resource-agents, squid:4, thunderbird, and vim), Debian (incus, lxd, and python3.9), Fedora (cef, composer, erlang, libpng, micropython, mingw-openexr, moby-engine, NetworkManager-ssh, perl, perl-Devel-Cover, perl-PAR-Packer, polymake, pypy, python-cairosvg, python-flask-httpauth, and python3.15), Mageia (kernel, kmod-virtualbox, kmod-xtables-addons and kernel-linus), Oracle (\cockpit, bind, bind9.16, bind9.18, firefox, git-lfs, go-toolset:ol8, grafana, grafana-pcp, grub2, kea, kernel, libtiff, nghttp2, nginx, nginx:1.24, nginx:1.26, nodejs22, nodejs24, nodejs:22, nodejs:24, perl-XML-Parser, python3.9, thunderbird, uek-kernel, and vim), Red Hat (delve, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, osbuild-composer, and rhc), SUSE (bind, Botan, cockpit, cockpit-subscriptions, expat, flatpak, glibc, goshs, himmelblau, kea, kernel, kubo, libpng16, libssh, log4j, mariadb, Mesa, netty, netty-tcnative, nfs-utils, nghttp2, nodejs20, openssl-3, pam, pcre2, python, python310, python311, python311-aiohttp, python311-rfc3161-client, python313, python36, rubygem-bundler, sqlite3, sudo, tigervnc, tomcat, tomcat10, tomcat11, util-linux, vim, and webkit2gtk3), and Ubuntu (dotnet8, dotnet9, dotnet10, frr, and linux-azure, linux-azure-4.15).

FSF clarifies its stance on AGPLv3 additional terms

Post Syndicated from jzb original https://lwn.net/Articles/1067771/

OnlyOffice CEO Lev Bannov has recently
claimed
that the Euro-Office fork of the
OnlyOffice suite violates the GNU Affero General Public License
version 3 (AGPLv3). Krzysztof Siewicz of the Free Software
Foundation (FSF) has published
an article
on the FSF’s position on adding terms to the AGPLv3. In
short, Siewicz concludes that OnlyOffice has added restrictions to
the license that are not compatible with the AGPLv3, and those
restrictions can be removed by recipients of the code.

We urge OnlyOffice to clarify the situation by making it unambiguous
that OnlyOffice is licensed under the AGPLv3, and that users who
already received copies of the software are allowed to remove any
further restrictions. Additionally, if they intend to continue to use
the AGPLv3 for future releases, they should state clearly that the
program is licensed under the AGPLv3 and make sure they remove any
further restrictions from their program documentation and source
code. Confusing users by attaching further restrictions to any of the
FSF’s family of GNU General Public Licenses is not in line with free
software.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1067718/

Security updates have been issued by AlmaLinux (capstone, cockpit, firefox, git-lfs, golang-github-openprinting-ipp-usb, kea, kernel, nghttp2, nodejs24, openexr, perl-XML-Parser, rsync, squid, and vim), Debian (imagemagick, systemd, and thunderbird), Slackware (libexif and xorg), SUSE (bind, clamav, firefox, freerdp2, giflib, go1.25, go1.26, helm, ignition, libpng16, libssh, oci-cli, rust1.92, strongswan, sudo, xorg-x11-server, and xwayland), and Ubuntu (rust-tar and rustc, rustc-1.76, rustc-1.77, rustc-1.78, rustc-1.79, rustc-1.80).